Koto
kkotowicz.bsky.social
Koto
@kkotowicz.bsky.social
Security ninja wannabe / board game geek / photon catcher
Interesting. I wonder what's the motivation for projects to opt-in to this, and how many did already. Sounds like it would incur prohibitive costs on the company and the bug hunter (explaining technical security bugs to lawyers is orders of magnitude more involved than to security engineers).
January 23, 2025 at 10:36 AM
Do I hear CSP? :)
December 10, 2024 at 9:20 AM
To this day I think my demise will be through some npm shenanigans. And it's fair, I deserve it. It should Javascript->RCE.
December 4, 2024 at 8:50 PM
Interesting choice! Most, myself included, prefer Blindsight. Both are really good though, still waiting for the grand finale that will likely never come :)
November 25, 2024 at 7:10 PM
For posterity - nope, it does not :/
November 21, 2024 at 10:57 PM
You totally should rename it to Cevisshe :)
November 21, 2024 at 8:09 AM
@webappsec.dev has go.bsky.app/Uf8dZhz, it's a good one.
November 21, 2024 at 6:25 AM
Maybe, but that metric is not likely even correlated to 'most commonly exploited'.
November 18, 2024 at 1:44 PM
not yet, no.
November 17, 2024 at 12:15 PM