CISO at @sardineai. Treasurer of @OWASP Board of Directors. (he/him) qatta' mIghtaHghach.

Phoenix, AZ
Joined July 2009
Today at 3pm Pacific, I'm hosting an online dialog on building ethical products. How do we ensure our product is safe and non-harming? How do we square the ethical considerations with the business requirements? Free ticket required. @owasp #GlobalAppsec events.bizzabo.com/OWASPGlob…
3
1
6
members @owasp please take a moment to vote. You should have an email titled "2020 OWASP Global Board of Directors Election" with your ballot. @bilcorry, @knoblochmartin, @pushlesp (I think?) and @haral are your candidates owasp.org/www-board/election…
4
1
6
GIF
“median number of onsite interviews was two and the median number of job offers was just one” Does this mean the selection happens prior to the onsite, and the onsite is to confirm choice or choose between a few candidates?
1
Ouch. Seriously though, run next year or encourage those that you are excited about to run next year.
1
3
Hi @owasp members, please check your email and vote. You may need to search for it in spam/promotions/updates. Your ballot is called "2020 OWASP Global Board of Directors election". Your ballot is unique to you and you alone! Only 8.35% of members have voted, which is very low
3
17
1
13
I'm releasing a tool that I used internally to compare various HTML parsers in browsers (DOMParser, template.innerHTML and others) and to easily test sanitizers (like DOMPurify). It is called LiveDOM++. livedom.lab.xss.academy/
3
90
289
@audible_com FYI, the "Buy 3 Extra Credits" mechanism isn't working. Specifically, this page: audible.com/extra-credit/pur… Redirects to this page: audible.com/extra-credits It isn't possible to buy 3 extra credits. And yes, I have 0 credits and am a Premium Plus member.
Want to commiserate about shopping for appsec tools? In a little more than an hour, I'm hosting an online networking chat at the @owasp Global Appsec conference. Register for a free ticket and join me! events.bizzabo.com/OWASPGlob…
1
2
Thanks all for background. And especially for the dev spouse that got us a workaround!
2
Replying to @bilcorry @mikewest
I was asking about the reason behind the choice. Sorry, should have been more clear.
1
Replying to @mikewest
It’s not a bug, but a security feature apparently. I run into it because I teach hacking using Burp and Web Goat (running on localhost). Chrome doesn’t allow proxies on localhost by default.
1
Replying to @mikewest
It’s Chrome where it doesn’t work (requires extra effort to configure around the proxy block). Works fine on Firefox, but guessing now that too will need the workaround.
1
Replying to @mikewest
Is this why using Burp and similar proxies don’t work on localhost?
1
Replying to @kingthorin_rm
Ha, maybe. Or maybe I just don’t remember what my mortgage and car payments are because they’re auto paid and I was too lazy to go look.
1
I thought I'd sign up for an account at "My Social Security" but couldn't verify my own identity and was locked out. I guess that's better than the opposite problem?
1
2
Replying to @ericgeller
I really thought this was going to be a piece from The Onion.
I know what I’m going to talk about at the next Cybersecurity Awareness Month presentation.
This tweet is unavailable
1
Bil Corry retweeted
Test Your Skills on the CMD+CTRL Cyber Range 📅 Week of October 19 👤👤Limited seats available 🏆 Prizes will be awarded Learn more: events.bizzabo.com/OWASPGlob… | #GlobalAppSec #OWASP
5
16
Like games? Want to support charity? Subscribe to Humble Bundle's monthly Choice program and you get a bunch of games each month and you support charity. That's how I have most of my 648 games. Check it out (referral link): humblebundle.com/subscriptio…