Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @glennzw
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @glennzw
-
Prikvačeni tweet
Hey Twitter, I built a thing, and I think it's pretty cool. FishCrypt is a server side database field encryption utility. PoC demo: https://fishcrypt.herokuapp.com/ (sign up and send me a message!) Code: https://github.com/glennzw/fishcrypt …
#golang#infosec#webdevPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Glenn Wilkinson proslijedio/la je Tweet
A reminder (in case you're slow like me) that Twitter is now supporting full app-based 2FA for accounts in all regions and you no longer have to provide a phone number for SMS-based 2FA. Go get at em!pic.twitter.com/V4gXJ0NNus
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Also, I have learned that you can have unidirectional cables. I bought an "HDMI DisplayPort" cable hoping to use the above mentioned Apple dongle, but the cable only works one way! (DisplayPort output to HDMI input, not the other way). This lesson took about 18 hours to learn
pic.twitter.com/ioocUaCLYY
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I've found some adapters that split the USB-C / TB into two, but the description says you can only feed one screen on a Mac.pic.twitter.com/wsDKyTkuU9
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
* I currently have one monitor via USB-C/TB to DisplayPort * I have the Apple USB-C Digital AV Multiport Adapter, but that's only HDMI (and I've learned you can't do HDMI -> DP, well easily/cheaply) I can't find the equivalent adapter with a DisplayPort outpic.twitter.com/RApaiOFLJB
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Nerds of Twitter; how can I plug my MacBook Pro into two DisplayPort monitors? Other requirement is to have power (via USB C / TB) and a spare USB port (keyboard/mouse).
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Me: I’ll just let my tea brew for a minute while I debug that line of code 40mins later: (will I die if I drink this black tar?)pic.twitter.com/ZbHhTxneH8
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I think tech bros solutionism often drags us backwards by pushing us forward in the wrong direction.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The case for dumb cities; “For many of our challenges, we don’t need new technologies or new ideas; we need the will, foresight and courage to use the best of the old ideas,” "redirect some of our energy toward building 'excellent dumb cities.'"https://www.theguardian.com/cities/2020/jan/15/the-case-for-making-low-tech-dumb-cities-instead-of-smart-ones …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Database Encryption Poll; Devs: Do you encrypt user fields when building apps? or Hackers: Have you bust into a system and seen field level encryption in use? RT for good karma.
#infosec#webdev#pentest#hackersgonnahackHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Oh and to see a little under the hood here's what's stored in the database. If the db was compromised you'd see hashed password and encrypted private key. Of course if I had a weak password (maybe I do in this instance!) you could crack it and then get my private key.pic.twitter.com/QJ9NrVQoek
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I know you're all waiting with bated breath
Here's my solution to the above problem:https://twitter.com/glennzw/status/1221777328424001542 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I'd be super interested to hear how other people address encryption of user data. I did a bit of Googling, but got frustrated so built my own thing. I'd be very happy for someone to point out that it's been done already, or that my solution sucks. It's all about learning :) /end
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
What's cool is it's all server side so no browser/JS requirements. Just four functions: CreateKeys EncryptData DecryptPrivateKey DecryptData UpdatePassword The server can see your data, but not at rest, only in memory, so slight trade off.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
When the user logs in their private key can be decrypted server side with their password and stored client side (e.g browser storage, cookie, hidden field). User can then decrypt their data with their decrypted private key (done server side in memory with the supplied priv key).pic.twitter.com/6bvRaSYmAY
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Inbound data for the user can be encrypted with their public key.pic.twitter.com/rimJLkkHa3
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FishCrypt basically wraps the tricky key generation/protection stuff. You can create a pair of keys in your webapp when a user signs up, with the private key being symmetrically encrypted with the user's password. Public and encrypted private key can be stored in the database.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The problem I've been looking at is how to best secure user data in a db, whilst maintaining usability. Full DB encryption is good, but no use if the server/db is compromised. Encrypting database fields per user with asymmetric encryption is cool, but tricky.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
But this is so awesome. I can now hit arbitrary subdomains and get certs for them, e.g: https://www.site.com https://foobar.site.com https://singehackslikeapotato.site.com I'm in love with
@caddyserver
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
