Andrew van der Stock :verified:

OWASP Executive Director, OWASP Top 10 and Application Security Verification Standard co-lead. Dad. Cats. AppSec.

Andrew van der Stock :verified:vanderaj@infosec.exchange
2025-04-16

@briankrebs As OWASP Executive Director, I have reached out to MITRE to see how we can help. We have a European Foundation in the process of being set up, and hundreds of thousands of worldwide volunteers. I'm sure that if we can preserve the records, we can help stabilize the issue and hopefully, fix some of the issues with resources at MITRE to maintain the backlog of CVEs.

Andrew van der Stock :verified: boosted:
Sam Stepanyan :verified: 🐘securestep9@infosec.exchange
2024-06-27

If you are an #OWASP member and you are attending the OWASP Global AppSec Lisbon Conference don't forget to collect the OWASP Challenge Coin from the Members Lounge! (Room:5B-CCL)

Not a member yet? Go to the OWASP website and click "Join" 👉owasp.org/membership/

Andrew van der Stock :verified:vanderaj@infosec.exchange
2024-02-25

Time to go to DC

Andrew van der Stock :verified:vanderaj@infosec.exchange
2023-10-31

Watching @nielstanis talk on WASM security at OWASP #GlobalAppsec2023

Andrew van der Stock :verified: boosted:
Dare Obasanjocarnage4life@mas.to
2023-10-16

We’re now in the find out stage of mandatory return to office.

Unispace found that nearly half (42%) of companies with return-to-office mandates witnessed a higher level of employee attrition than they had anticipated. And almost a third (29%) of companies enforcing office returns are struggling with recruitment. In other words, employers knew the mandates would cause some attrition, but they weren’t ready for the serious problems that would result.

fortune.com/2023/08/01/researc

Andrew van der Stock :verified: boosted:
Katy Anton :verified:katyanton@infosec.exchange
2023-08-13

Great to see #OWASP Booth 2416D at #BlackHat - and catch up with both current and previous Board members @bilcorry @infosecvandana @vanderaj.

Andrew van der Stock :verified: boosted:
ghorwood↙↙↙ghorwood
2023-05-12

the great things about orms is that, as complexity of the query increases, there's this magic line where they go from being 20% easier to use than sql to 500% more difficult, and you never know where that line is until you hit it.

Andrew van der Stock :verified:vanderaj@infosec.exchange
2023-02-24

PSA. Computers are not typewriters. Please stop double tapping space after full stops. kthxbye.

Andrew van der Stock :verified:vanderaj@infosec.exchange
2023-02-24

Fixed the OWASP Top 10 2021 - it no longer uses ' or '1'='1, but a MySQL sleep(). This is safer instead of selecting all records, and in many cases more accurate as a SQL injection locator.

Andrew van der Stock :verified: boosted:
lcamtuf :verified: :verified: :verified:lcamtuf@infosec.exchange
2023-02-13

The aliens who keep sending all these peace delegations might be getting concerned by now

Andrew van der Stock :verified:vanderaj@infosec.exchange
2023-02-12

@zak Fedora 38 is about to get unfiltered Flatpaks, so a lot of the software compat issues that have never really been an issue for me (I use it primarily for hobby development), should go away in April.

fedoraproject.org/wiki/Changes

Andrew van der Stock :verified: boosted:
Zack Whittakerzackwhittaker
2023-02-12

~this week in security~ just went out:

• VMware ESXi servers hit by ransomware
• Russian ransomware actors sanctioned
• FBI's surveillance powers under threat
• EFF infiltrates Dark Caracal APT
• U.K. wants to ban 'bespoke' encrypted phones
• Reddit hacked

Sign up: this.weekinsecurity.com

Read more: mailchi.mp/zackwhittaker/this-

Andrew van der Stock :verified:vanderaj@infosec.exchange
2023-02-12

@zak I've been a RH / Fedora user since the 1990's. I like the bleeding edge nature of Fedora, and it's got a nice stable KDE spin. Ubuntu had a unique selling point with Unity, but since they went to Gnome desktop, there's basically no difference between Ubuntu and any other Debian based distro with Gnome. And if you don't use CLIs often, Fedora offers basically the same but a more modern Gnome desktop. The only downside to Fedora is if you don't like upgrading (the equivalent of dist-upgrade) every six months, then Fedora may not be for you. However, it's not a big deal, and 10-20 minutes later, it's ready to rock again for another six months, and you have the absolute latest pretty much everything.

Andrew van der Stock :verified:vanderaj@infosec.exchange
2023-02-12

@mainframed767 Of these, only the last one makes sense, but then only for those who actively seek out encounters. RTO makes no sense for the majority of organizations. I've been to so many offices where everyone has noise cancelling headphones on. What's the point?

Andrew van der Stock :verified:vanderaj@infosec.exchange
2023-02-12

@securingdev I use VMs for that type of work, and my go to remains Firefox under Fedora or Kali.

Andrew van der Stock :verified:vanderaj@infosec.exchange
2023-02-12

@ceresbzns No more or less than any other browser. You have to assume that modern browsers have telemetry. Firefox is at least honest about it, not sure of Edge or Chrome.

Andrew van der Stock :verified:vanderaj@infosec.exchange
2023-02-12

@edbro It's not my research, it's here: youtube.com/watch?v=MAu2KYrNgY

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst