Joubin 🛡️

#AppSec guy. Ex #OWASP Board member and #Sacramento Chapter Lead. Dad to two boys. Run #Security #Architecture for the US Central Bank

Joubin 🛡️joubin@defcon.social
2025-05-13

@caseyliss @siracusa @marcoarment an #askatp: I have a 49” ultra-wide Samsung display that I drive with a Kensington dock with only a USB-C going to my Mac. I now have a second Mac and need a KVM. I feel like I’ve tried everything and nothing works at full resolution (5120x1440). Do you have any recommendations for people with larger monitors and multiple Macs?
I’m getting by switching the USB cable back and forth. But rather have a button.

Joubin 🛡️joubin@defcon.social
2025-03-12

@siracusa - I also don’t care about speakers and went with two mini HomePods. Have you considered that? Works really well in my view.

Joubin 🛡️joubin@defcon.social
2024-07-21

@overcastfm - love the new app! Please bring back streaming tho - even if only for private podcasts or podcasts that have metadata denoting they don’t have ad-insertion.

Joubin 🛡️ boosted:
2024-07-20

"Linux would have prevented this!" literally true because my former colleague KP Singh wrote a kernel security module that lets EDR implementations load ebpf into the kernel to monitor and act on security hooks and Crowdstrike now uses that rather than requiring its own kernel module that would otherwise absolutely have allowed this to happen, so everyone please say thank you to him

Joubin 🛡️joubin@defcon.social
2024-07-20

@mjg59 can you link me to source or doc of what you’re referencing?

Joubin 🛡️joubin@defcon.social
2023-10-15

@overcastfm is there a product roadmap for overcast anywhere? Is transcript generation and note taking anywhere on there?

Joubin 🛡️joubin@defcon.social
2023-10-14

@caseyliss @atpfm #askatp

Re ATP 556:

apps.apple.com/app/id148476450 does the job for me for backing up my iCloud library. It properly downloads Optimized photos, downloads them, and even waits for iOS/photos to clear caches to make room.

Joubin 🛡️joubin@defcon.social
2023-09-03

You said agree, but what you’re saying wasn’t my intent. To me, before your reply, I was okay with libcurl doing this. But interesting response. @bagder, how do you feel if the default remained what you have today, but what @lattera is suggesting can be a global environment variable that must be explicitly set to get the old behavior back. Something like `CURL_ALLOW_INSECURE_TOR`?

Joubin 🛡️joubin@defcon.social
2023-08-31

@lattera @bagder @jordan as a unbiased third-party let me chime in here for a second… The point of the spec is to not falsely give users of applications, a sense of security and privacy, when the ecosystem of said application leaks information when communicating with Tor. I think the fixes you’re looking for should be placed in the upstream application, trying to utilize curl or its libraries, so that they are compliant with what the Tor project expects.

Joubin 🛡️joubin@defcon.social
2023-08-24

@atpfm ios 17 has everything you guys talked about a while ago!

Limited access to photos and warning about locations!

Joubin 🛡️joubin@defcon.social
2023-07-30

@frichetten I see where you’re going with this. But we also have the likes of project zero and many other attempts to publicize security research. Why do we think cloud will be different? I can see MSFT doing that to stop the bleeding. Hard to see GCP, IBM, and AWS doing that at the same time.

Good read tho… only time will tell. Like you, I hope you’re wrong :)

Joubin 🛡️joubin@defcon.social
2023-07-30

@evacide Elon wanted to call PayPal X, xPayPal first then just X. He’s been sitting on this for a while. He’s not gonna drop it :)

Joubin 🛡️ boosted:
2023-07-30

We've updated the insecure deserialization Web Security Academy topic with instructions on how to make ysoserial work on Java 16+. Full credit to this excellent article on the topic:

codewhitesec.blogspot.com/2023

portswigger.net/web-security/d

Joubin 🛡️joubin@defcon.social
2023-07-28

@caseyliss have you thought of bitwarden… it’s pretty nice and cross platform.

Joubin 🛡️joubin@defcon.social
2023-07-28

@TheJesusFish this is really good to know!

Joubin 🛡️joubin@defcon.social
2023-07-21

@ironicbadger
1x2tb
5x3tb
3x8tb

Joubin 🛡️joubin@defcon.social
2023-07-19

@ironicbadger I have a bunch of hdd 3-8 tb. I don’t feel like wiping them. Can I donate it to self hosted or JB? Ping me if you’re interested!

Joubin 🛡️joubin@defcon.social
2023-07-14

@nasser @rmondello are we sure this isn’t broken CSS?

Joubin 🛡️joubin@defcon.social
2023-06-29

Is there someone @GrapheneOS that can keep advocating to release iMessage for #GrapheneOS only with marketing message like “Vanilla android isn’t privacy centric enough for us… but Graphene is”

Anyways.. back to reality!

Joubin 🛡️joubin@defcon.social
2023-06-05

Facetime Apple TV made more sense during COVID lockdowns... missed oppertunity.

#WWDC23 #wwdc

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst