Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 687
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boosts
Birdsite
Always impressed to see people talking BS and getting away with it.
Referral bounty & hiring
We’re paying referral bounties, up to six figures, details here:
https://www.lutasecurity.com/referralbounty
Questions: email info@Lutasecurity.com
We’re always hiring these listed roles, plus others depending on your experience (US only, remote, Contract to permanent):
https://www.lutasecurity.com/careers
Questions: email careeers@Lutasecurity.com
Sysdig out with a report on zomg supply chain attacks and #SBOM in dockerhub images.
Dead me doing a talk on it in 2015 citing other people’s research on it with different buzzwords of the day.
https://speakerdeck.com/barnbarn/security-for-non-unicorns-2?slide=59
#HiP22
Second chance for time travelers & "Verpeilte"
We have extended the CfP until 04.12.2022 23:42:00 and the second round of ticket sales will start on 06.12.2022 at 12 noon
I am amused that SignalApp joined mastodon.
The fediverse is everything they stand against.
- federation instead of centralization
- open, community driven protocol
- using pseudonyms
- multiple implementations of client and server software
Not sure what I mean, check out their blog post on these topics: https://signal.org/blog/the-ecosystem-is-moving/
As for the multiple implementations, Signal denied a request to have a 100% open source fork of their app in F-droid. See for yourself:
https://github.com/signalapp/Signal-Android/issues/9966#issuecomment-681943985
Want to be more #mindful? Drop meditation and buy a #moonlander keyboard instead, and every single key press will be an extremely conscious action in the Now. 🧘
Google has now migrated maps.google.com to www.google.com/maps thus if you grant Geoloc permission in your browser, every G-service on www.google.com can track your location.
Hey folks in #Berlin & #infosec
I'll be speaking at BSides Berlin THIS Saturday. Consider joining us: the tickets are crazy cheap at 15€ and the people are nice (at least those that I bring along).
More at https://bsides.berlin/
Oh, and I'll be talking about HTML Sanitizers again.
habe ein Ticket für die #BSidesBerlin übrig #cbase einfach melden
stopped visiting the bird site 2 days ago and so far, no regrets.
powerful datavis can be simple and non-graphical.
here's a project of mine from a good while ago: "autocomplete" for passwords, based on all passwords extracted from the "collection leaks".
One of the more difficult challenges of hunting for bugs in CI/CD environments is working out if code execution is a feature or a bug 😑
So I've unfollowed everyone on the bird space and removed all DMs. I was mainly following #infosec and #hacker folk with a smattering of #homelab #solar and #space related accounts, which I am slowly finding here. Leaving my bird followers in place so if they migrate here they can use one of the automated processes that finds who they are following there, and potentially find me. Feels good.
Hot Take: we should stop putting those "for educational purposes only" disclaimers on offensive security software. They are not legally binding and probably provide no real protection. Plus every OSS license already has a no-liability clause. Continuing to put those disclaimer on software has the same energy as those "confidential email, do not distribute" disclaimers people put on their outgoing emails; which are also not legally binding because reading a disclaimer is not the same as signing a legal document.
we pwned @tailscale ❤️
ft. @jamie
https://emily.id.au/tailscale
Mastodon in a week has gone from “I can read all posts in 15 minutes” to “i can’t keep up”. Well done.
the Berkeley Packet Filter (BPF) is a subsystem of many Unix operating systems wherein all packets are sent to a server in Berkeley, California, which has the firewall rules on it.


