Sign in

Rob Winch

@rwinch.github.io
499 followers 110 following 27 posts

Open source enthusiast; Project Lead for Spring Security

PostsRepliesMedia
Rob Winch @rwinch.github.io · 27/02/2026
I'm honored to be speaking with @starbuxman.joshlong.com at @devnexus.bsky.social about Bootiful #SpringSecurity For additional information see devnexus.org/events/booti... I hope to see you there! #Spring #Java #devnexus
devnexus.org
Bootiful Spring Security
042
Rob Winch @rwinch.github.io · 19/11/2025
til - Regex special characters like . do not need escaped in character classes e.g. [a.] means a or . not a or anything www.regular-expressions.info/charclass.ht...
042
Rob Winch @rwinch.github.io · 10/10/2025
I've done a lot of cleanup on #SpringSecurity MFA support this past week. The updates (along with improved docs) can be seen in the reference docs.spring.io/spring-secur...
docs.spring.io
143
Rob Winch @rwinch.github.io · 30/09/2025
#SpringSecurity 7 added MFA support docs.spring.io/spring-secur... tldr Add following to require both password and one time token `@EnableGlobalMultiFactorAuthentication(authorities = { GrantedAuthorities.FACTOR_PASSWORD_AUTHORITY, GrantedAuthorities.FACTOR_OTT_AUTHORITY })`
docs.spring.io
Adaptive Authentication :: Spring Security
084
Rob Winch @rwinch.github.io · 11/09/2025
Exciting News! Spring Authorization Server is moving to #SpringSecurity 7.0 spring.io/blog/2025/09...
spring.io
Spring Authorization Server moving to Spring Security 7.0
Level up your Java code and explore what Spring can do for you.
0198
Rob Winch @rwinch.github.io · 09/09/2025
Ever wanted to be able to change how the built in #SpringSecurity hasRole hasAuthority, etc methods work but continue to use the existing DSL? Enter AuthorizationManagerFactory.... docs.spring.io/spring-secur... Thanks x.com/sjohnr for your PR github.com/spring-proje...
docs.spring.io
Authorization Architecture :: Spring Security
0133
Reposted by Rob Winch
Daniel Garnier-Moiroux @garnier.wf · 04/08/2025
Neat episode of a Bootiful Podcast from @starbuxman.joshlong.com with @rwinch.github.io , the lead of @spring.io Security. Great insights on how the design and product decisions are made in an OSS project, and the timeframes for these. podcasts.apple.com/gb/podcast/s...
podcasts.apple.com
Spring Security lead Rob Winch on Spring Security 7.0, SpringOne 2025, and more
Podcast Episode · A Bootiful Podcast · 31/07/2025 · 44m
0122
Rob Winch @rwinch.github.io · 17/06/2025
Just pushed support for Spring Security OAuth + Interface REST Client integration docs.spring.io/spring-secur... #SpringFramework #SpringSecurity
docs.spring.io
HTTP Interface Integration :: Spring Security
071
Rob Winch @rwinch.github.io · 17/06/2025
I'll be presenting "Secure All The Things With Spring Security" with @starbuxman.joshlong.com at #SpringOne #VMwareExplore I hope to see you there! event.vmware.com/flow/vmware/...
event.vmware.com
Content Catalog | Las Vegas | VMware Explore
0154
Reposted by Rob Winch
Tommy Ludwig @tommyludwig.bsky.social · 25/04/2025
Anyone have any realistic use of Java's Scoped Values they can share? Yes, I know it's still a preview feature, but I can hope there are some eager people out there.
143
Rob Winch @rwinch.github.io · 18/04/2025
Interesting post infosec.exchange/@briankrebs/... - AI bots are used to commit financial aid fraud at universities - rise in bots enrolling prevents some students from registering for classes - teachers worry when the bots drop (after bot gets aid) it might cause them to lose their job
010
Rob Winch @rwinch.github.io · 16/04/2025
I'm glad to see that funding for the CVE program has been extended www.bleepingcomputer.com/news/securit... I'm interested to see what happens with the foundation going forward. tldr - CVE Program funding was going to expire, foundation was setup to preserve it, CVE Program funding was extended
093
Rob Winch @rwinch.github.io · 21/03/2025
Trying MacOS again Key binding suggestions for moving window left/right/top/bottom half screen, full screen, to next/previous display, & to next/previous "spaces" (desktops or in linux it was workspace)? Ideally bindings use arrows, are similar to each other, and don't collide with default bindings
100
Rob Winch @rwinch.github.io · 03/03/2025
It's frustrating when authenticating to website (e.g. website.com) to be redirected to an external domain (e.g. website.idp.com) & expect website.com's credentials. Shame on both the website & the IdPs that follow this practice which primes users to be phished.
030
Rob Winch @rwinch.github.io · 05/02/2025
I'm not speaking @devnexus.bsky.social this year, but I'm going as an attendee. If you will be there, I'd love to meet up. Hope to see you there!
060
Rob Winch @rwinch.github.io · 13/01/2025
Linux user trying to figure out macos - How can I have the menu bar & doc on all displays AND have "Displays have separate Spaces" unchecked? NOTE: I do not want separate spaces per display because then I have to switch a space per display. I prefer switch space updates all monitors at once.
020
Rob Winch @rwinch.github.io · 06/01/2025
I'm very excited that @spring.io is switching from a Contributor License Agreement to a Developer Certificate of Origin! We're looking forward to seeing more & simplified contributions from you! If you have any questions, reach out to us in our issue trackers. spring.io/blog/2025/01...
spring.io
Hello DCO, Goodbye CLA: Simplifying Contributions to Spring
Level up your Java code and explore what Spring can do for you.
14621
Rob Winch @rwinch.github.io · 05/12/2024
Fantastic news to see the @antora.org collector has hit GA!
020
Rob Winch @rwinch.github.io · 05/12/2024
Good advice for protecting against / recovering Hijacked Gmail (& other) Accounts www.forbes.com/sites/daveyw... - Setup recovery phone & email to your account - For Gmail, if attacker changes your recovery phone number, then you have7 days to use that original number to regain control
forbes.com
Gmail Takeover Hack Attack—Google Warns You Have Just 7 Days To Act
As Gmail users complain hackers have compromised accounts, changing passwords and passkeys in the process, Google advises they have 7 days to regain control—here’s how.
010
Reposted by Rob Winch
Jenna McLaughlin @jennamclaughlin.bsky.social · 04/12/2024
President Biden's deputy natsec advisor for cyber and emerging tech Anne Neuberger told reporters that Chinese hackers got into (at least) 8 U.S. telcos in a broad spying campaign that affected "dozens of countries" since it began. The latest on All Things Considered: www.npr.org/2024/12/04/n...
npr.org
514159
Rob Winch @rwinch.github.io · 04/12/2024
I changed my username to rwinch.github.io so that I had a verified domain with a username that I'm well known by. How did I do it?
bsky.social
How to verify your Bluesky account - Bluesky
Here's how to verify your Bluesky account by setting your website as your username.
3367
Rob Winch @rwinch.github.io · 04/12/2024
Chinese is hacking US telco so stop using SMS - Use 3rd party apps that do end to end encryption (eg WhatsApp) - RCS iPhone <-> Android is not encrypted - Use phone that auto updates in timely fashion - Use MFA www.forbes.com/sites/zakdof... HT @starbuxman.joshlong.com
forbes.com
FBI Warns iPhone And Android Users—Stop Sending Texts
US officials urge citizens to use encrypted messaging and calls wherever they can—here’s what you need to know.
043
Rob Winch @rwinch.github.io · 04/12/2024
Join @starbuxman.joshlong.com and I as we discuss #SpringSecurity 6.4 x.com/starbuxman/s...
x.com
x.com
042