Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
markcurphey
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
markcurphey
4y ago
A few weeks ago, it seemed like everyone in the tech industry was glued to Mudge’s congressional testimony. Not only is he one of the most irreproachable people in the security space, the drama around Twitter is fun, partially because Elon
2.
▲
How the Joe Sullivan case will affect the information security industry
(blog.crashoverride.com)
3 points
by
markcurphey
4y ago
|
2 comments
3.
▲
by
markcurphey
4y ago
100%. Sounds like a great OWASP project to capture those best practices doesn't it ? Want to volunteer ? ;-)
4.
▲
by
markcurphey
4y ago
Certainly 'will' is a huge issue, the biggest IMO. I def on't disagree it can be done but my experience and from interviews recently people just don't know. People don't know where their containers are deployed. The
5.
▲
by
markcurphey
4y ago
Def don't need to eat crow. Never heard that phrase before funny. It's just my opinion. I often get it wrong and there are def a few ways to think about it here. 100% agree on getting more visibility and ammunition and 100% agree
6.
▲
by
markcurphey
4y ago
Point taken and there are two trains of thought. The way I think about it is that it's a double edged sword. If you have already trusted a dependancy then trusting an update is a risk but less than the risk of having known vulnerable v
7.
▲
by
markcurphey
4y ago
I was actually involved in a load of Log4J responses. I was the founder of sourceclear, the first SCA security pure play. I do get your point but what I see time and time again are things like a repo being built to say a war file and no one
8.
▲
by
markcurphey
4y ago
I was referring to things like Maven, WebPack and NPM. I should have made that clearer. What I have seen is in general supply chain in more mature tech and certainly OS tool chains doesn't have that issue or is certainly more aware of