Profile avatar
april.social
Staff Security Engineer at some random tech company, previously Mozilla, Dropbox, and (pre-Elon) Twitter. Has read @kateconger.bsky.social’s autobiography. web @ grayduck.mn // also github.com/april
1,423 posts 13,767 followers 203 following
Regular Contributor
Active Commenter

as someone who used to work at twitter and who spent the last half-decade working with T&S teams, this whole aaron thing (where the bluesky head of trust liked a porn scam post) almost stretches incredulity. imagine designing a social media network in the 2020’s with public likes.

was asked a really interesting question in an interview yesterday: given a budget, which areas of security spending produce the greatest and worst (or negative) ROI? my answer: positive: SSO/OAuth, hardware keys worst: DAST, DLP, honorable mention to poorly configured IDS’s what’s your answer?

Handling Cookies is a Minefield: Inconsistencies in the HTTP cookie specification and its implementations have caused a situation where countless websites (including Facebook, Netflix, Okta, WhatsApp, Apple, etc.) are one small mistake away from locking their users out. grayduck.mn/2024/11/21/h...

close, it’s actually: input -> unexpected condition -> unhandled exception

“hey babe, what do you wanna watch tonight?” “I dunno, something red maybe?”

happy halloween everyone, please enjoy this costume my son wore a couple years back of himself dressed up as a TI-89 calculator (costume designer: my talented wife)

finally a vehicle that will protect me from kindergarteners with hammers 😮‍💨

new septum piercing who dis

apple having “video effects” such as rising balloons on by default in macOS Sonoma has got to be one of the greatest trolls of all time. (as my therapist discovered during our session yesterday)

dear diary, thankfully nobody will ever know that my 10-year-old son just kicked my ass at DDR. 😮‍💨

I appreciate Amazon having such a generous limit. As someone who types 60 words per minute for 17 hours per day, I was worried I wouldn’t be able to publish my three daily novels. arstechnica.com/information-...

the new iOS live voicemail feature is going to save me from having to deal with an absolutely immense about of bullshit

teens are based