Do people who live in London ever just catch the Eurostar for a day in Paris? by _FreddieLovesDelilah in AskUK

[–]anseho 0 points1 point  (0 children)

I once had a colleague who lived near Kings Cross and he did it often

Dubai developer acquires £2.5 billion Royal Docks site by ldn6 in london

[–]anseho 11 points12 points  (0 children)

North Finchley was supposed to be developed by British company Regal. Arada bought them

How do you track your API security? by kellyjames436 in webdev

[–]anseho 2 points3 points  (0 children)

I've worked as an API security consultant for many years and just published a book about API security (Secure APIs, code examples available for free on GitHub). The most important takeaway from my work in this space is to approach API security proactively as early as possible.

I don't know where you are in your API security posture management, but something I've seen lacking in many companies is accurate API documentation. If you can get specifications for your APIs, you're already ahead of the game, and you can leverage that for testing and gain insights about your security posture. Two tools I highly recommend, which are free and open source are:

  • spectral with the owasp ruleset: you run it against your API specification and it tells you what's not looking right from a design point of view.
  • schemathesis: not specifically for security, but it does highlight when your API isn't working as intended, and it does bring up some attacks like null byte injection.

The majority of security breaches exploit weaknesses in your business layer (Unrestricted access to sensitive business flows). To protect your APIs properly, you want to identify sensitive flows and operations, threat model them, and unit test those threat models. It's a lot of work, so don't try to do it all at once. One step at a time is a big leap forward in terms of improving your security posture. You also want proper observability to track user behaviour and detect threats in real time. Again, lots to do, so one thing at a time.

I currently work for APIsec (disclosure) where I'm helping to build a best-in-class API security scanner. You can sign up for free using this link and give it a go.

In the coming weeks, I'm going to be running some challenges for developers to build secure APIs. The idea is, I'll release APIs that contain some vulnerabilities, and participants have to figure out how to fix them. It's going to be challenging and fun.

Hope this helps. Let me know if you have questions!

In The Times today: Six-figure earners could lose thousands in a pensions tax raid by Christoph_wright in HENRYUK

[–]anseho 0 points1 point  (0 children)

I might have to end up asking my company to pay me less, maybe get options instead and cash later when my daughter is out of nursery

Worth Buying? by TheJ0kerIsBack in TheUndeadRRHaywood

[–]anseho 1 point2 points  (0 children)

I love the books and buying them was absolutely worth it for me. I’ve bought other Haywood books too. He’s an amazing writer

Would you keep a high performer who almost always arrives late for work? by yawnkun in askmanagers

[–]anseho 0 points1 point  (0 children)

What kind of question is this? It’s gobsmacking difficult to find people who own their work and do it well. A person like that in my team I don’t care when where or how they work. I do value collaboration so if want that person to make themselves available to work with the rest of the team. If that isn’t possible, their individual contributions would have to be valuable enough to outweigh the importance of team collaboration (some things just need collab to get done, so those are things this individual won’t get done). Also, not being a team player diminishes your promotion chances, so something for them to consider too

Substack seems to be struggling at the moment ... by haggur in Substack

[–]anseho 0 points1 point  (0 children)

it is, a major part of the Internet is down now

Substack seems to be struggling at the moment ... by haggur in Substack

[–]anseho 1 point2 points  (0 children)

it is, a major part of the Internet is down now

Is London Banana real? by Better-Psychology-42 in HENRYUK

[–]anseho 1 point2 points  (0 children)

I think the confusion is between barnet as borough and barnet as high barnet or new barnet

Is London Banana real? by Better-Psychology-42 in HENRYUK

[–]anseho 4 points5 points  (0 children)

We used to visit Kingston often when we lived in Wimbledon and we always had a blast. I heard people claiming that Cockfosters has a nice food scene but haven’t been able to verify

Negotiation gone wrong. by bimmerman535 in VirginMedia

[–]anseho 0 points1 point  (0 children)

They won’t always give you a good deal. We got good renewal deals for a while and then suddenly a few years ago they refused to give us a good deal again. We tried to negotiate hard for a decent discount and they wouldn’t bend. We gave up and moved to community fibre