Life Coach, Conspiracy Theorist, and Absurdist. I do AppSec in my non-spare time for money. My opinions are now your opinions, but at least you are now right!

Joined March 2012
345 Photos and videos
18 Apr 2024
There is one thing that he points out that I really like. Reducing the cognitive load on developers. Everyone is all about teaching developers about security. That is a good idea. But if we can give developers some security features for free even better.
An underrated aspect of AppSec and Secure Coding is not exposing the insecure functionality in the first place. Let's say you have a XML parsing library that may be used by devs wrongly/insecurely. By disabling certain functions in the library, its not vulnerable to XML Injection anymore Instead of constantly training them to figure out security params, having a wrapper library (custom) that automatically disables insecure functionality is way more effective. It's: * easier to use * easier to enforce (in SAST, CI, SBOM, etc) * easier to train on * reduces cognitive load for devs in the long run * and more secure Keep it simple.
1
6
317
17 Apr 2024
Apparently things get better when people and companies are accountable for their shit. Good blog by @Jo3Ram
17 Apr 2024
I've been meaning to blog a bit more. I authored this post in an attempt to consolidate my thoughts following the recent $MSFT and CVE-2024-3400 news. We need all need to be better. #SoftwareLiabilityReform medium.com/@JoeChrist/where-…
1
127
Join @semgrep community for a live panel on "Building a Successful Security Champions Program: What Does it Take?" with AppSec veterans Chris Romeo @edgeroute, Dustin Lehr @DustinLehr1, Devin Rudnicki, and Ray Leblanc @Raybeorn ow.ly/WngS50QBpRN #SecurityChampions #AppSec
3
8
788
Join @semgrep community for a live panel on "Building a Successful Security Champions Program: What Does it Take?" with AppSec veterans Chris Romeo @edgeroute, Dustin Lehr @DustinLehr1, Devin Rudnicki, and Ray Leblanc @Raybeorn ow.ly/WngS50QBpRN #SecurityChampions #AppSec
1
3
11
855
Join @semgrep community for a live panel on "Building a Successful Security Champions Program: What Does it Take?" with AppSec veterans Chris Romeo @edgeroute, Dustin Lehr @DustinLehr1, Devin Rudnicki, and Ray Leblanc @Raybeorn ow.ly/WngS50QBpRN #SecurityChampions #AppSec
1
5
712
Join @semgrep community for a live panel on "Building a Successful Security Champions Program: What Does it Take?" with AppSec veterans Chris Romeo @edgeroute, Dustin Lehr @DustinLehr1, Devin Rudnicki, and Ray Leblanc @Raybeorn ow.ly/WngS50QBpRN #SecurityChampions #AppSec
2
5
954
Join @semgrep community for a live panel on "Building a Successful Security Champions Program: What Does it Take?" with AppSec veterans Chris Romeo @edgeroute, Dustin Lehr @DustinLehr1, Devin Rudnicki, and Ray Leblanc @Raybeorn ow.ly/WngS50QBpRN #SecurityChampions #AppSec
1
2
5
1,041
Join @semgrep community for a live panel on "Building a Successful Security Champions Program: What Does it Take?" with AppSec veterans Chris Romeo @edgeroute, Dustin Lehr @DustinLehr1, Devin Rudnicki, and Ray Leblanc @Raybeorn ow.ly/WngS50QBpRN #SecurityChampions #AppSec
5
11
1,610
15 Feb 2024
AppSec interviews are like “please threat model this app that i am going to poorly explain to you” and then they are like you missed this one threat that we consider important
2
138
29 Jan 2024
Me to legacy security people:

ALT The Office Michael Scott GIF

1
39
26 Jan 2024
I very much dislike the term Cloud Application Security.
1
1
68
26 Jan 2024
Where is the AI? Or DevSecOps? Can we vote on new terms that don’t mean anything different from the old ones?
1
42
26 Jan 2024
Why do non AppSec security people always think they can build appsec programs so easily? Like shit, why didn’t we think about putting a scanning in out pipelines
4
7
351
26 Jan 2024
If web technology never made it past 2011 AppSec would be so easy with our current AppSec tooling.
1
35
24 Jan 2024
So we tried bug bounties, dev sec ops, and now threat modeling. When are we actually gonna start doing app sec and securing things?
1
1
92
24 Jan 2024
Damn i forgot secure champions. Can we go home yet?
1
2
53
16 Nov 2023
Security tool vendors, stop failing your customers. Build something great. For appsec tools, they need to be usable and bring value to both the dev and security teams. Also all your pricing models suck, be more flexible.
2
1
218
16 Nov 2023
Also what is the point of having a pricing page when every customer gets a “discount”? Just put the real prices in your page
1
53
16 Nov 2023
Don’t talk about building partnerships. Just tell me how your tool will make my life easier and more importantly my devs lives easier.
43