Sign in

Koto

@kkotowicz.bsky.social
1.6K followers 428 following 18 posts

Security ninja wannabe / board game geek / photon catcher

PostsRepliesMedia
Koto @kkotowicz.bsky.social · 25/01/2025
Just when you think CVEs cannot get more ridiculous... 🤣
031
Reposted by Koto
Faith Erin Hicks @faitherinhicks.bsky.social · 14/01/2025
I would like this comic I drew in 2017 to stop being relevant pleeeaaaaase
I wake up in the morning.
I sit at my computer.
The internet screams at me that the world is on fire.
I am overwhelmed by the deluge of bad news and faceplant in front of the computer.
64307146412
Reposted by Koto
Matthew Green @matthewdgreen.bsky.social · 07/01/2025
Telegram: not an encrypted messaging app ;) blog.cryptographyengineering.com/2024/08/25/t...
blog.cryptographyengineering.com
Is Telegram really an encrypted messaging app?
This blog is reserved for more serious things, and ordinarily I wouldn’t spend time on questions like the above. But much as I’d like to spend my time writing about exciting topics, som…
267
Reposted by Koto
Gynvael Coldwind @gynvael.bsky.social · 28/12/2024
Want to support security researchers from Dragon Sector in covering legal costs piling up after they went public with logic bombs in train firmware? IBAN for donations is available here: www.ccc.de/en/updates/2... Talks for context media.ccc.de/v/37c3-12142... streaming.media.ccc.de/38c3/relive/...
03618
Koto @kkotowicz.bsky.social · 10/12/2024
TIL about Chersterton's Fence fs.blog/chestertons-... - it puts a nice label to an intuition that I find very useful to apply in practice - from refactoring code, through process engineering. Understand first why the mess exists, in that form, before attempting to clean it up and revolutionize.
fs.blog
Chesterton’s Fence: A Lesson in Thinking
A core component of making great decisions is understanding previous decisions. If we don’t understand how we got “here,” we run the risk of making things much worse.
131
Koto @kkotowicz.bsky.social · 04/12/2024
I don't often post about my work but bughunters.google.com/blog/6355265... is actually super cool thing my team is doing. These short term redteams focused on just stealing our passwords were always amazing to highlight how severely broken complex systems are. The internal writeups are so, so fun!
bughunters.google.com
Blog: The Great Google Password Heist: 15 years of hacking passwords to test our security (and build team culture!)
The Leaving Tradition in Google's security team, which could be described as a type of small-scale offensive security exercise, is a great (and fun) example of team culture. Curious? See this blog pos...
0189
Reposted by Koto
renniepak @renniepak.nl · 04/12/2024
Pro tip for if you have XSS but you can only use upper case: aem1k.com/transliterat... transliterate.js by @aemkei.bsky.social works great!
aem1k.com
transliterate.js
Translate any JavaScript code to foreign writing systems. Created by Martin Kleppe aka @aemkei.
0216
Reposted by Koto
Thomas Ptacek @sockpuppet.org · 27/11/2024
There's no such thing as a "9.2" or "9.8" vulnerability. There's more science in Pitchfork's 0.0-10.0 album rating scale than in CVSS. I am completely serious. Pitchfork reviewers actually put their reviews in context with previous reviews by the artist. That's how bad CVSS is: worse than Pitchfork.
44510
Reposted by Koto
Freddy @freddyb.bsky.social · 27/11/2024
Modern solutions against cross-site attacks (frederikbraun.de/modern-solut...): An article about cross-site leak attacks and browser-based defenses. You will also learn why web security best practices is always opt-in and finally how YOU can get increased security controls.
frederikbraun.de
Modern solutions against cross-site attacks
Modern solutions against cross-site attacks
03419
Koto @kkotowicz.bsky.social · 27/11/2024
Not sure how I missed that, but we now actually have Ken Thompson's C compiler backdoor code from the classic "Reflections on Trusting Trust". An excellent writeup by @swtch.com - research.swtch.com/nih.
research.swtch.com
research!rsc: Running the “Reflections on Trusting Trust” Compiler
0103
Reposted by Koto
James Kettle @jameskettle.com · 25/11/2024
Custom lists are super cool! I enjoy reading social posts, but want to make sure I never miss a quality writeup or technique. To achieve this, I'm building a 'high signal web security' list of topic-focused accounts, which you can pin next to 'Following' if you want :) bsky.app/profile/jame...
25416
Koto @kkotowicz.bsky.social · 21/11/2024
1..2..3 testing testing. Does BlueSky support UltraHDR images?
a photo of a building at break of dawn, high contract, with bright windows.
120
Reposted by Koto
Gynvael Coldwind @gynvael.bsky.social · 20/11/2024
We're doing a cool online talk tomorrow btw – hexarcana.ch/workshops/cv...
hexarcana.ch
CVEs of SSH
A talk about recent high-profile issues related to the SSH ecosystem.
2218
Koto @kkotowicz.bsky.social · 20/11/2024
This hit close to home.
031
Reposted by Koto
Johan Carlsson @joaxcar.bsky.social · 15/11/2024
Read this! Beautiful blog post, and so much to learn from it mizu.re/post/explori...
mizu.re
Exploring the DOMPurify library: Bypasses and Fixes. Tags:Article - Article - Web - mXSS
Exploring the DOMPurify library: Bypasses and Fixes
0198
Koto @kkotowicz.bsky.social · 17/11/2024
Time to make some smart introductory websec post here, no? I guess all I have is: Hello world, good bye XSS?
060
Reposted by Koto
Lukas Weichselbaum @webappsec.dev · 17/11/2024
I'm in the process of creating a *web security* starter pack and need your help finding more webbies here. Please share and recommend folks passionate about web security in comments below so we can get this community started here 🙂 go.bsky.app/Uf8dZhz
165525
Koto @kkotowicz.bsky.social · 17/11/2024
Photos from a stroll through Atarazanas Food Market in #malaga - it turned out to be an extremely vibrant, colorful, lively place. #photography
050
Reposted by Koto
Lukas Weichselbaum @webappsec.dev · 16/11/2024
If you're into web security take a look at my LocoMocoSec keynote slides from this summer about "Google's Recipe for Scaling (Web) Security": speakerdeck.com/lweichselbau...
1218