Brutkey

Rob O :verified:
@nerdpr0f@infosec.exchange

Teaching faculty. Security researcher. Red team, DevOps, AppSec. An academic but not an academic. nerdprof @ Twitter


Notes
69
Following
0
Followers
0

Rob O :verified:
@nerdpr0f@infosec.exchange

The final for my web class involves assessing a small POC fake social media site (I didn't make v1 of it).

One of the findings in the fake web application is SQL injection. And... it's not in any of the parameters, it's in the headers. You have to actually know what you're doing to find it and I have a clause that the PoC for the finding needs Burp suite.

I tell them the endpoint that it's on, but not where it is. They also have all the source code for the web app, so they can find issues through source code analysis.

It's always interesting to see the results of this.

Rob O :verified:
@nerdpr0f@infosec.exchange

I am so absolutely sick of Hinton and Kurzweil. If any regular people talked like this, we'd be concerned about their mental health.

https://www.cnn.com/2025/08/13/tech/ai-geoffrey-hinton

Rob O :verified:
@nerdpr0f@infosec.exchange

The plumbers I use seem to have a very interesting policy as an institution. Every single time they call to let me know they're on the way regardless of time of day, they let me know they're passing a Tim Horton's and ask if I want anything.

I assume this is a tactic to subtly indicate that they're going to be stopping to get something for themselves, which I'm fine with, but I seriously wonder how much Tim Horton's are the plumbers from this shop are consuming that this happens every single time.

Rob O :verified:
@nerdpr0f@infosec.exchange

I am increasingly thinking the next 5 years of tech is going to be dominated by cloud repatriation.

https://www.theverge.com/news/757461/microsoft-github-thomas-dohmke-resignation-coreai-team-transition

Rob O :verified:
@nerdpr0f@infosec.exchange

@Sempf@infosec.exchange I think there might be a similar clinic program either at Case Western or Baldwin Wallace too.

Rob O :verified:
@nerdpr0f@infosec.exchange

- People are talking about how streaming is bad.

- There's open discussion of how to pirate media, what software there is, how to avoid detection, etc.

- The general consensus seems to be that social media is largely bad.

- South park is relevant again.

..... Did I step through a time machine?