@voltone@fosstodon.org

Joined November 2009
15 Photos and videos
18 Dec 2024
Your periodic reminder that Erlang distribution protocol is cool, but it is not cool to expose it to the internet: erlef.org/blog/security/epmd…

3
9
227
Bram Verburg retweeted
Our Working Groups had worked hard this year! 👏 🔍Take a look at some great initiatives of the Security WG: - They have published its “Web Application Security Best Practices for BEAM languages”: erlef.github.io/security-wg/… - They have sponsored an EEF stipend to develop and certify an OpenID Connect client library, along with supporting libraries for integration with Cowboy, Plug and Phoenix. For next year, they would like to: expand Web App Best Practices document to other BEAM-based web frameworks; help push forward other educational resources; improve security tooling for BEAM languages and renew efforts to provide solid SBoM (software bill-of-materials) tooling support for BEAM projects. There is a lot to be done and they are always looking for contributors! More info about this WG: erlef.org/wg/security #WeBeamTogether #Erlang #MyElixiStatus
3
4
659
Bram Verburg retweeted
13 Oct 2023
To those unfamiliar, the Security Working Group of the @TheErlef does a fantastic work documenting the best security practices of both Erlang and Elixir, web and non-web: erlef.github.io/security-wg/ 👏👏👏 #MyElixirStatus
41
140
10,118
Bram Verburg retweeted
🚨 Attention, Community! 🚨 The EEF's Security Working Group has just released a new document detailing best practices for secure development of web applications using BEAM languages. Don't miss it! shorturl.at/hwEQ5 #Erlang #MyElixirStatus

11
23
2,133
Reminder: if your AWS RDS database connections fail after upgrading to Erlang/OTP 26 it is probably due to certificate validation, and fixing that is just one Hex package away
I released a Hex package for verification of AWS RDS server certificates. More info in this post: elixirforum.com/t/aws-rds-ca…
1
16
50
10,743
And if your AWS RDS connections so work with OTP 26 it probably means you did not enable SSL; go and fix that!
1
4
368
I just release v1.1 with Rebar3 build support and an Erlang API module, for instance for use with the ‘pgo’ Postgres driver
1
120
17 Apr 2023
Excited to be speaking at #GOTOaar 2023! I'll be exploring the security benefits and potential of concurrency oriented functional languages such as #erlang and #elixir. Get 10% off your conference pass with my code: bram10. See you there!
3
8
2,439
25 Feb 2023
Client-Side Enforcement of LiveView Security - a classical web app vulnerability making a comeback? blog.voltone.net/post/31

3
8
38
5,431
Bram Verburg retweeted
Episode 134: We get a glimpse into @TheErlef’s Security Working Group with @voltonez. We learn about existing resources and get hints of the future. Bram shares some cool security tips and insights as well! #Erlang #ElixirLang @ElixirLang @erlang_org podcast.thinkingelixir.com/1…

7
7
3,637
Bram Verburg retweeted
Finally another Elixir meetup happening in NL! meetu.ps/e/LvtwX/9Dn6d/i featuring @voltonez and @peerstr ! #myelixirstatus

1
3
3
16 Nov 2021
If anyone here is interested in joining the @TheErlef Security WG call at 3pm GMT tomorrow (Wednesday), DM me for the Zoom link. More info in the group’s channel over on EEF Slack
4
4
If you are running a server using a Let’s Encrypt certificate and you want maximum interoperability with Erlang/Elixir clients (rather than old Android devices), run certbot with ‘--preferred-chain "ISRG Root X1"’
1
2
8
Newer Erlang/OTP versions can process the longer default chain as well, but not everyone has upgraded yet
Bram Verburg retweeted
21 Sep 2021
The latest Nerves systems (released Aug 11th) have this fix. It's getting close to Sep 30th, so don't delay upgrading if this affects you.
22 Jul 2021
Erlang/OTP 24.0.4 and 23.3.4.5 are out, with improved support for cross-signed certificates. I will try to write a follow-up to blog.voltone.net/post/29 soon, on getting ready for DST Root CA X3 expiration Sep 30th
1
2
Bram Verburg retweeted
Episode 64: @voltonez explains how an expiring Internet root certificate can break Elixir and Erlang systems at the end of September! We learn what this does and does not affect, the update options, and more on the "root" cause. #ElixirLang @ElixirLang thinkingelixir.com/podcast-e…

8
15
30 Aug 2021
Update on the #erlang #elixirlang impact of DST Root CA X3 expiry next month blog.voltone.net/post/30: patches by @erlang_org and good news for Hackney users

10
26
22 Jul 2021
Erlang/OTP 24.0.4 and 23.3.4.5 are out, with improved support for cross-signed certificates. I will try to write a follow-up to blog.voltone.net/post/29 soon, on getting ready for DST Root CA X3 expiration Sep 30th

9
45
18 May 2021
This is a long one: Erlang/OTP impact of DST Root CA X3 expiration blog.voltone.net/post/29 - I suspect I'll have to write some follow-up posts to clarify the proposed solutions for avoiding downtime on September 30th

1
6
8
18 May 2021
Talk to me at #CodeBEAMv this week, if you want more details
1