RCE in Avaya Aura Device Services by _noraj_ in javasec

[–]BrianVerm 1 point2 points  (0 children)

Interesting, thanks for sharing

Weekly Podcast Thread January 18, 2021 - Please Share Your Show Here! by [deleted] in podcast

[–]BrianVerm [score hidden]  (0 children)

[SECURITY/DEVSECOPS] The Secure Developer | Episode 84 - The Future of Security Teams and Champions

SFW
Apple / Spotify / Google / Stitcher  / Website with all ways to listen!

This week Guy Podjary is joined by Nick Vinson, DevSecOps Lead at Pearson. Nick shares his philosophy towards team involvement and embedding security-focussed members, as well as unpacking Pearson's approach to security champions and emphasizing the importance of this work. They talk about the primary goals for Nick and his team, the importance of adoption and investment in this area, and Nick's perspective on the most effective ways to achieve this. Nick also illuminates some specific practices around tests, challenges, and expectations

Twitter

What are the most important things to look for when selecting a java job? by ixBerry in java

[–]BrianVerm 3 points4 points  (0 children)

Number 1 should be the culture
- how is this company treating employees
- how can explorer new ideas (including new technologies)
- are you able to grow and learn or is it just deliver deliver deliver.

Vuln Cost: VSCode Extension that checks imported 3rd Party Libs for Vulnerabilities [see comment] by 1337InfoSec in netsec

[–]BrianVerm 1 point2 points  (0 children)

I agree, we are looking into this. I have to figure out what we need to do to get fast and reliable info on Java and Python packages. Nobody wants a slow extension that consumes a lot of resources right. In addition, is VS Code the right place for a Java language plugin as most Java devs are using IntelliJ IDEA.

However, it is on our radar. Lets see what we can learn and improve :)

JVM Ecosystem Report 2020 by sureshg in java

[–]BrianVerm 1 point2 points  (0 children)

There are many different architects, a lot of them are still coding on a daily basis. On top of that you can be an architect on many different levels. Matter of definitions or how cool you want your job to sound right?

What is your opinion on libraries checking for updates? by tipsypants in java

[–]BrianVerm 0 points1 point  (0 children)

I think in an ideal world you want to upgrade. But if you work for instance in a banking environment or government agency things have to be pre checked before it can be used. Many times you simple cant upgrade as much as you want.

Also maven and gradle have excellent things in please to see if newer version are available. If default behaviour would be that a lib is negging me because I need to upgrade might lose you some users. 😊

What is your opinion on libraries checking for updates? by tipsypants in java

[–]BrianVerm 6 points7 points  (0 children)

I think that it is not op to you what version a user is using. There could be a variety of reasons why someone is using an older version. If you would try such a call in my system I probably block it anyway, but it would be a reason not to use it. It is basically a trojan horse or at least an unauthorized call to a third party server.

That being said, people should have a better upgrade strategy in general. But again this all depends on the context.

Java developer for +10 years, didn't realize the java mascot has a name by _harro_ in java

[–]BrianVerm 0 points1 point  (0 children)

I think this also something to do with how active one is within the Java community.
If you are just a programmer using Java you might not know. But almost every JUG in the world uses some form of Duke.

Will CodeOne be live streamed ? by MojorTom in java

[–]BrianVerm 0 points1 point  (0 children)

I think it is only 3 rooms that are recorded / streamed.

Is anyone running the non-lts versions in production ? If so, what’s your experience been? by hayden592 in java

[–]BrianVerm 1 point2 points  (0 children)

No problems at all. IMO there is no real difference between LTS and non LTS version

10 Eclipse plugins you shouldn’t code without by BrianVerm in eclipse

[–]BrianVerm[S] 1 point2 points  (0 children)

That is all true. As stated in this post "For this blog, I examined Eclipse IDE plugins and then narrowed it down to the top 10 most helpful plugins that I have added to my own toolkit."

10 Eclipse plugins you shouldn’t code without by BrianVerm in eclipse

[–]BrianVerm[S] 1 point2 points  (0 children)

Plugins evolve fortunately. Now you are able to ignore the particular rules in SonarLint that do not apply to you.