Brutkey

Bill
@Sempf@infosec.exchange

I break web applications. Front man for the cover band Thundersnow.


Notes
14189
Following
0
Followers
0
Blog
https://sempf.net
Amazon
https://www.amazon.com/William-Sempf/e/B00DDON3UO
OWASP
https://owasp.org/www-chapter-columbus/
Github
https://github.com/sempf
Amateur Radio
KE8PCT
Header
Medeco Biaxial
Bill
@Sempf@infosec.exchange

#introductions

Hi, I'm Bill. I was just gonna paste my bio in here but you can google that. Couple of things:

1) Yes, Bill is my first name and Sempf is my last. Not hiding.

2) I am an application security person specializing in vulnerability assessment and remediation on a number of platforms. Can't fix something? Look me up.

3) I've been around Mastodon for a while but I have 10,000 user accounts and need to go clean them up. Gah what a mess.

4) What to expect from me here: rad memes, links to interesting vulns (usually in the late evening EST when I do research), general tomfoolery, oxford commas.

Yes, I am a Twitter refugee.


Bill
@Sempf@infosec.exchange

Hanging spaghetti squash update:

#gardening

Bill
@Sempf@infosec.exchange

Wow, the state teachers retirement system sent me an email telling me that they are implementing multi-factor authentication. Finally.

Bill
@Sempf@infosec.exchange

The good news is I actually found what I was looking for doing that and got the login script to work. So I complain all I want, but in reality, everything works out okay in the end. I think I'm going to go have a gummi.

Bill
@Sempf@infosec.exchange

Oh look my very most favorite thing! Debugging JavaScript in the browser!

🤬🤬

We could have made browser scripting so elegant and powerful. Instead we have JavaScript.

Bill
@Sempf@infosec.exchange

There is a non-zero chance that I need to work on the accuracy of my Optimus rain gauge.

Bill
@Sempf@infosec.exchange
Bill
@Sempf@infosec.exchange

#woo

Bill
@Sempf@infosec.exchange

Woo apparently Patch Tuesday was a thing today huh? Gonna pour one out for DevOps later.

Bill
@Sempf@infosec.exchange

Some research on how password recovery has to mature in the face of passwordless authentication. Hmm, wonder if the OWASP team on that gas plans.

https://www.darkreading.com/endpoint-security/researchers-warn-hidden-risks-passwordless-account-recovery

#authentication #vulnerability

Bill
@Sempf@infosec.exchange