clojure-europe

For people in Europe... or elsewhere... UGT https://indieweb.org/Universal_Greeting_Time
dharrigan 2021-03-30T05:37:02.471500Z

Morning!

djm 2021-03-30T06:11:42.471700Z

👋

slipset 2021-03-30T06:22:13.473300Z

@orestis we switched from “native” mongo ObjectIds to randomly generated ObjectIds because you can “guess” the possible values of the next couple of ObjectIds, which makes for an attack surface.

slipset 2021-03-30T06:22:52.473600Z

(defn gen-id! []
  (format "%024x" (BigInteger. 96 (SecureRandom.))))

slipset 2021-03-30T06:46:03.474300Z

Oh, and if you’re a saas thingy, do consider using https://www.hackerone.com. It’s like an ongoing pen-test

orestis 2021-03-30T08:17:27.478500Z

Is this a company that does pen tests? Or something more like https://www.zaproxy.org/

slipset 2021-03-30T10:29:21.479Z

You could look at hackerone as a pentest platform.

slipset 2021-03-30T10:29:51.479200Z

They help set up bounty programs, and have a bunch of hackers which try to hack orgs (like ardoq)

slipset 2021-03-30T10:30:02.479400Z

When the hackers find security holes, we pay them.

slipset 2021-03-30T10:30:55.479600Z

The hackers are incentivised to learn the app, and they find so much more than your yearly pentest does.

slipset 2021-03-30T10:33:22.479900Z

And your org is incentivised to keep the app secure, as it pays for every security bug found.

orestis 2021-03-30T11:05:32.481200Z

Oh that’s nice. We had a pentest which found some things but missed some glaring ones. Cost an arm and a leg and was very stressful since it was time bound.

orestis 2021-03-30T11:06:40.483200Z

Is there a pricing guidance on what to expect? I would hope the costs are bounded and there’s NDAs... a bunch of random “hackers” trying to get in sounds scary if they’re not bound by some contract.

2021-03-30T07:01:37.474600Z

Morning

2021-03-30T07:02:54.474700Z

Is it wrong that I make hackerone rhyme with macaroni

😄 2
2021-03-30T07:06:42.474800Z

And a very good day to @borkdude especially

borkdude 2021-03-30T07:18:02.475300Z

good day!

ordnungswidrig 2021-03-30T07:18:12.475500Z

Good morning!

slipset 2021-03-30T07:19:07.475800Z

macarone?

slipset 2021-03-30T07:19:18.476Z

I see no problem with that.

simongray 2021-03-30T07:25:58.476700Z

morning

thomas 2021-03-30T08:00:58.477200Z

mogge

reefersleep 2021-03-30T12:58:36.483700Z

Good morning :hugging_face:

raymcdermott 2021-03-30T13:19:49.484500Z

morning, feels like lunch already 🍝

1
2021-03-30T13:35:28.484800Z

spooky

thomas 2021-03-30T13:57:31.484900Z

Lunch? I haven't even woken up yet properly!!! You crazy man 😉

😛 1
jasonbell 2021-03-30T14:52:31.485600Z

Morning