averagesecurityguy

Christian | Husband | Father | Security Engineering Manager | Developer

2025-06-27

@b0rk take a look at github.com/asggo/wasp. Itโ€™s not a templating library but has a lot of boilerplate for building a basic, secure web app in Golang. It uses template/html in what I think is an easy way.

averagesecurityguy boosted:
Zak :1password:zak@infosec.exchange
2025-06-26

It's pretty rare that an ad ever gets through the various filters that I have set up, but when one does, it's almost always for a VPN. I'm sure that I don't have to tell most of you this, but unless you're dealing with regionally locked content, you almost certainly don't need a personal VPN.

#security #privacy

averagesecurityguy boosted:
Numoriannumorian
2025-06-26

We just kicked off the soft-launch of Cheksuite โ€” our SaaS web vulnerability scanner. We're onboarding early users now. API scanning and powerful AI features coming soon. Read more: blog.numorian.com/introducing-

averagesecurityguy boosted:
rgegriff (On a new server)rgegriff@masto.hackers.town
2025-06-25

"Incident Commander" is a really cool sounding title they give you to make up for the fact that your day is gonna SUUUUUUCK

averagesecurityguy boosted:
craque sprung ๐Ÿณ๏ธโ€๐ŸŒˆdtauvdiodr@c.im
2025-06-25

Hot take: If your company holds "lunch-n-learn" sessions, your company doesn't support learning on the company dime.

averagesecurityguy boosted:
Julia Evansb0rk@jvns.ca
2025-06-24

delighted to announce that my new zine "The Secret Rules of the Terminal" is out today!!

You can get it for $12 USD here: wizardzines.com/zines/terminal

The Secret Rules of the Terminal, by Julia Evans - The cover illustration depicts three people doing arcane terminal magic in a temple with a smoking censer in the background. Each of the three people has curly brown hair and light brown skin. They are all wearing dresses, billowing cloaks, and utility belts with keyboard symbols on them. The one on the left holds a palette of paints and a brush. The one on the right has a staff with a $ symbol on it and a starfish at the top. The one in the centre has a sword and is reading from a book whose cover says โ€œ>_โ€ and โ€œ./โ€, which rests on a lectern with a smiling snake wrapped around it.
averagesecurityguy boosted:
2025-06-24

Poll: Assuming you have no plans to leave the house that day ... at what percentage of battery level on your primary mobile device do you start to get uncomfortable, and think you should charge it?

Assume you will not have access to a charger or external power pack while away (If you do end up having to leave).

(If your number is somewhere in between, choose the next lower number)

(Please RT to improve sample size.)

averagesecurityguy boosted:
2025-06-23

EDIT: Thanks all!! I'm passing along your suggestions.

Anyone know an open-source project, even a small one, that needs API docs created or improved? Asking for a #technicalWriting pro who wants more experience with API documentation. #FOSS #techcomm (bonus points if it hits interests like politics, food, beer, auto racing, mapping/OSM, civil engineering, social good...)

averagesecurityguy boosted:
2025-06-23

I've now applied for 84 jobs since January. I've had two interviews. No offers.

Since tech jobs are thin and unemployment is running out, I've been applying for bartending jobs locally.

Today I left my resume at 7 breweries with tap rooms and offered home brew. Got one "maybe in a few weeks".

Here's my resume: docs.google.com/document/d/1Hg

#jobs #jobsearch #JobsForMastodon #GetFediHired

2025-06-23

There have been a number of times I said to myself, "I should build a web application that does some cool thing," and then I would realize that is easier said than done. First, I don't like complicated frameworks, whether it's a server framework, a JavaScript front-end framework, or a CSS framework. I got my start on the Internet when people were still writing HTML, CSS, and vanilla JS and using server-side rendering. I really miss the simplicity of those days.

I contemplated relearning PHP but I have spent a number of years using Go and really liked the simplicity of their web server. The idea of routers, handlers, and HTML templates was simple enough that I thought it may work for what I want. I've spent the last few months build out a simple Go based web application starter pack (WASP) that can serve as the basis for any number of web applications.

WASP is not a framework as much as it is a boiler plate server that can be extended with your own routes, handlers, and HTML templates. It includes password-based authentication, a simple authorization scheme with unauthenticated, authenticated, and admin users, and session management. It also includes tests that cover all of the core functionality and that can be extended to cover your new functionality.

If you are familiar with Go's web server concepts and want a good base to build your next web application, give WASP a try. github.com/asggo/wasp

#golang #webapp #security

2025-06-23

@Sempf it kinda sounds like you donโ€™t have a meeting on Teams in 15 minutes. ๐Ÿ˜‚

2025-06-22

There have been a number of times I said to myself, "I should build a web application that does some cool thing," and then I would realize that is easier said than done. First, I don't like complicated frameworks, whether it's a server framework, a JavaScript front-end framework, or a CSS framework. I got my start on the Internet when people were still writing HTML, CSS, and vanilla JS and using server-side rendering. I really miss the simplicity of those days.

I contemplated relearning PHP but I have spent a number of years using Go and really liked the simplicity of their web server. The idea of routers, handlers, and HTML templates was simple enough that I thought it may work for what I want. I've spent the last few months build out a simple Go based web application starter pack (WASP) that can serve as the basis for any number of web applications.

WASP is not a framework as much as it is a boiler plate server that can be extended with your own routes, handlers, and HTML templates. It includes password-based authentication, a simple authorization scheme with unauthenticated, authenticated, and admin users, and session management. It also includes tests that cover all of the core functionality and that can be extended to cover your new functionality.

If you are familiar with Go's web server concepts and want a good base to build your next web application, give WASP a try.
github.com/asggo/wasp

averagesecurityguy boosted:
Gina HรคuรŸgefoosel@chaos.social
2025-06-22

I rarely subtoot, but when I do just to say: if an open source project that your commercial project depends on breaks something in your software stack, causing you trouble, no matter how much, that's your problem and your problem alone.

"The software is provided as is" is a part of OSS licenses for a reason, and unless we have a contract that says otherwise, I'm not part of your bloody "supply chain".

averagesecurityguy boosted:
Lorin Hochstein :verified:norootcause@hachyderm.io
2025-06-20

Hot take: I think itโ€™s both easier and more impactful to identify and address obstacles to dev productivity in an org than it is to measure dev productivity

2025-06-14

@carnage4life Reminds me of coal company scrip, en.m.wikipedia.org/wiki/Compan. Seems like a bad idea.

averagesecurityguy boosted:
2025-06-10

I am looking for remote #work in #devops, backend #development, #infosec, #linux things, etc. I'm capable of a lot of different roles. I'd just like to do work that feeds my family and makes a difference in the world. Contract or full time are both fine. I speak both English and conversational Portuguese (BR).

I'm updating my resume but I'll have it available on request. Boosts appreciated. ๐Ÿ’œ

2025-06-09

@zak later today solving all the infosec problems.

2025-06-08

@maldr0id these are hilarious.

averagesecurityguy boosted:
K. Reid Wightman :verified: ๐ŸŒป :donor:reverseics@infosec.exchange
2025-05-31

The u-pick strawberry place has a name-the-baby-alpaca contest. So I submitted Jerry.

White mama alpaca nuzzling a newborn brown alpaca.
2025-05-30

@yossarian I used zizmor for the first time today. Itโ€™s definitely going into my AppSec toolbelt. Thank you for the great tool.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst