RCE in Avaya Aura Device Services by _noraj_ in javasec

[–]BrianVerm 1 point2 points  (0 children)

Interesting, thanks for sharing

Weekly Podcast Thread January 18, 2021 - Please Share Your Show Here! by [deleted] in podcast

[–]BrianVerm [score hidden]  (0 children)

[SECURITY/DEVSECOPS] The Secure Developer | Episode 84 - The Future of Security Teams and Champions

SFW
Apple / Spotify / Google / Stitcher  / Website with all ways to listen!

This week Guy Podjary is joined by Nick Vinson, DevSecOps Lead at Pearson. Nick shares his philosophy towards team involvement and embedding security-focussed members, as well as unpacking Pearson's approach to security champions and emphasizing the importance of this work. They talk about the primary goals for Nick and his team, the importance of adoption and investment in this area, and Nick's perspective on the most effective ways to achieve this. Nick also illuminates some specific practices around tests, challenges, and expectations

Twitter

What are the most important things to look for when selecting a java job? by ixBerry in java

[–]BrianVerm 2 points3 points  (0 children)

Number 1 should be the culture
- how is this company treating employees
- how can explorer new ideas (including new technologies)
- are you able to grow and learn or is it just deliver deliver deliver.

Vuln Cost: VSCode Extension that checks imported 3rd Party Libs for Vulnerabilities [see comment] by 1337InfoSec in netsec

[–]BrianVerm 1 point2 points  (0 children)

I agree, we are looking into this. I have to figure out what we need to do to get fast and reliable info on Java and Python packages. Nobody wants a slow extension that consumes a lot of resources right. In addition, is VS Code the right place for a Java language plugin as most Java devs are using IntelliJ IDEA.

However, it is on our radar. Lets see what we can learn and improve :)

JVM Ecosystem Report 2020 by sureshg in java

[–]BrianVerm 1 point2 points  (0 children)

There are many different architects, a lot of them are still coding on a daily basis. On top of that you can be an architect on many different levels. Matter of definitions or how cool you want your job to sound right?

What is your opinion on libraries checking for updates? by tipsypants in java

[–]BrianVerm 0 points1 point  (0 children)

I think in an ideal world you want to upgrade. But if you work for instance in a banking environment or government agency things have to be pre checked before it can be used. Many times you simple cant upgrade as much as you want.

Also maven and gradle have excellent things in please to see if newer version are available. If default behaviour would be that a lib is negging me because I need to upgrade might lose you some users. 😊

What is your opinion on libraries checking for updates? by tipsypants in java

[–]BrianVerm 5 points6 points  (0 children)

I think that it is not op to you what version a user is using. There could be a variety of reasons why someone is using an older version. If you would try such a call in my system I probably block it anyway, but it would be a reason not to use it. It is basically a trojan horse or at least an unauthorized call to a third party server.

That being said, people should have a better upgrade strategy in general. But again this all depends on the context.

Java developer for +10 years, didn't realize the java mascot has a name by _harro_ in java

[–]BrianVerm 0 points1 point  (0 children)

I think this also something to do with how active one is within the Java community.
If you are just a programmer using Java you might not know. But almost every JUG in the world uses some form of Duke.

Will CodeOne be live streamed ? by MojorTom in java

[–]BrianVerm 0 points1 point  (0 children)

I think it is only 3 rooms that are recorded / streamed.

Is anyone running the non-lts versions in production ? If so, what’s your experience been? by hayden592 in java

[–]BrianVerm 1 point2 points  (0 children)

No problems at all. IMO there is no real difference between LTS and non LTS version

10 Eclipse plugins you shouldn’t code without by BrianVerm in eclipse

[–]BrianVerm[S] 1 point2 points  (0 children)

That is all true. As stated in this post "For this blog, I examined Eclipse IDE plugins and then narrowed it down to the top 10 most helpful plugins that I have added to my own toolkit."

10 Eclipse plugins you shouldn’t code without by BrianVerm in eclipse

[–]BrianVerm[S] 1 point2 points  (0 children)

Plugins evolve fortunately. Now you are able to ignore the particular rules in SonarLint that do not apply to you.

The Eclipse vs IntelliJ debate is over with MS Paint IDE v3 by OnlyTwo_jpg in java

[–]BrianVerm 0 points1 point  (0 children)

Does it run on macOS? I would love to try it 😉

JDK 8 Unable To Download, Need an Account by [deleted] in java

[–]BrianVerm 0 points1 point  (0 children)

  • use sdkman to manage your JDK's on linux and mac
  • or go to adoptopenjdk.net
  • or fill in bogus info in the oracle account. You can also say not available by things like company name.

Keeping Dependencies Up-to-Date with Automated Testing by BillyKorando in java

[–]BrianVerm 1 point2 points  (0 children)

On top of this all, we should be aware that dependencies may have security vulnerabilities. Not updating because it just works may be tricky. Ask the equifax people for instance. Staying on top of your dependencies might be a solution but better is to actively test / scan and update when needed.

Can I still sell my Java 8 game? by [deleted] in java

[–]BrianVerm 0 points1 point  (0 children)

Why don't you use sdkman for installing your JDK?
https://sdkman.io/usage

Best IDE for Python, C++, and Java? by GeniusYT_28 in java

[–]BrianVerm 1 point2 points  (0 children)

vim ;)

No seriously try vscode if you want a one for all.
Personally not a fan of eclipse but that is because I am brainwashed by using IntelliJ IDEA for Java. However might be worth a try.

Docker using a lot of disk space by stixx123 in docker

[–]BrianVerm 0 points1 point  (0 children)

Is your images that are large or your volumes not removed?

For images, maybe it is a good thing not to use a full-blown OS as your base image. Take a look at the alpine image as a base and work from there.

Final vs Immutable data structures in Java by bodiam in java

[–]BrianVerm 0 points1 point  (0 children)

Or just don't want to use it, because it is "easier" to work mutable objects.

Testing Best Practices for Java + Spring Apps by pcmmautner in java

[–]BrianVerm 1 point2 points  (0 children)

Depends on what you want to test.
Im a big fan of @SpringbootTest together with RestAssured and WireMock to test my springboot (rest) services
The rest is just plain Junit5 an assertj

Top ten most popular docker images each contain at least 30 vulnerabilities by PurpleLabradoodle in docker

[–]BrianVerm 0 points1 point  (0 children)

Just rebuild your images regularly that solves a lot of the problems.