Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 687
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boostshabe ein Ticket für die #BSidesBerlin übrig #cbase einfach melden
stopped visiting the bird site 2 days ago and so far, no regrets.
powerful datavis can be simple and non-graphical.
here's a project of mine from a good while ago: "autocomplete" for passwords, based on all passwords extracted from the "collection leaks".
One of the more difficult challenges of hunting for bugs in CI/CD environments is working out if code execution is a feature or a bug 😑
So I've unfollowed everyone on the bird space and removed all DMs. I was mainly following #infosec and #hacker folk with a smattering of #homelab #solar and #space related accounts, which I am slowly finding here. Leaving my bird followers in place so if they migrate here they can use one of the automated processes that finds who they are following there, and potentially find me. Feels good.
Hot Take: we should stop putting those "for educational purposes only" disclaimers on offensive security software. They are not legally binding and probably provide no real protection. Plus every OSS license already has a no-liability clause. Continuing to put those disclaimer on software has the same energy as those "confidential email, do not distribute" disclaimers people put on their outgoing emails; which are also not legally binding because reading a disclaimer is not the same as signing a legal document.
we pwned @tailscale ❤️
ft. @jamie
https://emily.id.au/tailscale
Mastodon in a week has gone from “I can read all posts in 15 minutes” to “i can’t keep up”. Well done.
the Berkeley Packet Filter (BPF) is a subsystem of many Unix operating systems wherein all packets are sent to a server in Berkeley, California, which has the firewall rules on it.
Ooooohkay, who are the fun and irreverent people you're following here? Bonus points for sweary and witty.
I need some levity among the intellectualism in my feed.
Shitposting meta
Shitposting in the fediverse: so much joy.
Birdsite shitposting seems mostly about Mr. Musk nowadays.
“Boost my toot” sounds weirdly sexual.
SHITPOSTING
is an anagram of
TOP INSIGHTS
hot take: you should be suspicious about anyone who unironically boasts about being on the forbes 30 under 30 list.
1. it's actually like 600 under 30 and they know it
2. it's largely meaningless cuz (at least back in the day) all you had to do was be friends with someone who worked at Forbes to make the list in some of the categories that Forbes didn't know much about
3. if you actually try to get on the list, you probably value self-promotion/networking more than you should
i am on the list for completely dumb reasons and i hope people stop taking it seriously.
There’s been a lot of discussion about a rule we recently instituted regarding security testing on the infosec.exchange instance. I understand the value or pen testing as much or more than most people, and I’m fully cognizant that pen tests are happening all the time and I’m not getting the report. I get it. But there are now 28,000 people using this service to communicate. I know there are vulnerabilities waiting to be discovered. Finding blog post fodder by fuzzing instances that are already running hot due to explosive growth is not super helpful. But at the same time, I WANT that testing to happen.
As a result, I am going to set up two instances tomorrow that only federate with each other. This is where I’d prefer legitimate security testing be performed. I’ll also be using it as the QA environment to test new updates and settings prior to deploying to the production instance. I’ll moderate signups because I don’t want it accidentally becoming fediverse 2.0 in the ongoing rush for the doors at twitter, but will accept anyone who wants to join, with clear indications that it’s a sandbox and should not be considered safe.
Thanks for patience as we continue to find out way.
If anyone knows any entry level/ junior prodsec folks looking for a gig, HMU. Fully remote anywhere in the US.



