CISO at @sardineai. Treasurer of @OWASP Board of Directors. (he/him) qatta' mIghtaHghach.

Phoenix, AZ
Joined July 2009
Stumbled upon a new TV series called “Paper Empire” that looks interesting, but appears to not have a home for watching it. vimeo.com/362690658
My kids have no idea why this is so funny. Great cameo by Anthony Michael Hall on Goldbergs.
Paying @WEXIncNews via a check in the mail is free, but paying online is a $20 fee? This feels like a tax on younger people who (rightly) have eschewed checks for modern payment systems. Joke is on @WEXIncNews because my bank will mail a check to them for free.
This is why you do NOT let @realhamed anywhere near your smart speaker: Baby Shark EDM Remix.
1
1
8
Replying to @paxwhitmore
I’m partial to the surly doctor from Voyager.
Replying to @paxwhitmore
I do love Picard. The pilot is ok, not great, but also not ST:TNG S1E1 bad.
1
Replying to @iMeluny
I’m sure the conversation went like this: Privacy: We need to build out a CCPA automated system. Eng: To scale properly, how many thousands per day will use it? P: Maybe a few dozen a week? E: Call us when you hit your first thousand.
I’m sure Plaid does, but for my bank, Plaid wants my credentials.
1
I signed up for a new financial service and it wanted me to link my bank account via Plaid. #nope PSA: entering your banking credentials into Plaid means you’re giving it to Plaid, not your bank. Super-bad idea, do not do this! And if you have, change your banking password.
1
Replying to @mkonda
Some retailers are posting warnings about buying gift cards for non-gift purposes.
1
Bil Corry retweeted
Ouch. The Safari tracking prevention has privacy vulnerabilities allowing worse tracking than what it was trying to prevent. Privacy engineering is *hard*. Honestly, I don't see a robust way around this one, though I haven't had enough time to sit down and really chew on it.
Apple/Safari Intelligent Tracking Prevention is a mechanism intended to improve privacy. It was found to have privacy vulnerabilities allowing sites to track the user (and fingerprint), and to stealing web browser history of a user. Incredible find. arxiv.org/pdf/2001.07421.pdf
2
50
95
Bummer @netflix. Good luck with the phishing...
Netflix phishing. The typos did not fool the spam filter.
1
1
Replying to @skamille
What’s your personal email? I want to get in on this.
Bil Corry retweeted
This story is bananas. theguardian.com/technology/2…
11
82
6
237
Bil Corry retweeted
GGvulnz — How I hacked hundreds of companies through Google Groups medium.com/@milanmagyar/ggvu…
2
5
Totally get that. The mix of how many employees you have, how many different states you want to support, and how many benefits you want to offer will change which model will work best. Cost, liability, nexus, speed, ease, interest on escrowed taxes, etc all factor in as well.
1
Personally, the big advantage was shifting legal liability and being able to onboard anyone in all 50 states quickly, versus wanting to hire an employee in a new state that required onboarding the state first, then could hire the employee.
1
Best to get tax+legal advice from your trusted advisors. Some q's: do you want to setup payroll reporting in numerous states? Will direct employees establish nexus for income taxes? Do you want your own HR and the liability of following many state laws, or outsource it?
1