DevTestSecOps
138 subscribers
469 photos
29 videos
37 files
695 links
Forwards and notes on development, testing, security, and operations from @q587p.

About me: studied as System Architect, worked as a SysAdmin, working now as an Test Automation Engineer. Also, I'm interested in hacking (and everything related to it).

జ్
Download Telegram
#web

Really? 🙃

“The #Google #Chrome engineering team is going to disable the alert() function in a future version because it’s often used by scammers to trick users. This is going to be a breaking change to the web platform so go update your apps & debugging tools before the change rolls out.”

https://twitter.com/carnage4life/status/1423121207059120137?s=28
#Google launched a new https://sre.google/ to learn about how #SRE is done at google: a balance between details like disk driver IO scheduling to the big picture of service capacity.

Available: books, courses, experts, and how it all applies in the cloud.
Anatomy of an Incident

Get the inside scoop on #Google approach to incident management for production services in this report. It covers all the stages of the #incident management lifecycle: preparedness, response, recovery, and mitigation

https://static.googleusercontent.com/media/sre.google/en//static/pdf/Anatomy_Of_An_Incident.pdf
#security #hack #OAuth

Dylan from truffleSecurity talks about a simple hole (it seems a bit loud to call it a vulnerability) that allows users of companies that use #Google authorization in services like Slack or Zoom to continue to have access even after being fired and having their access removed.

The hole is that such services use email as the user ID. But, obviously, you can create several different email addresses that receive the same emails (e.g. by adding words after "+"):

https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/
👏1👨‍💻1
Forwarded from 587: saved | #УкрТґ
😁1👌1💯1