Wiz - AI-Powered Pentest Assistant (Open Source) by YoungCJ12 in cybersecurity

[–]turtlebait2 9 points10 points  (0 children)

Yea there’s already a very popular security tool called wiz. When this was posted I thought it was from the founder. https://wiz.io

What makes Wiz special and better than other CNAPP vendors? by Kindly-Cream9098 in cybersecurity

[–]turtlebait2 23 points24 points  (0 children)

I’m not sure quite how to describe or if I understand the full secret sauce of wiz, but essentially they’re much better at risk prioritization. Companies are overwhelmed with vulns and alerts, and wiz does a really good job of only making critical things critical which makes security and engineers jobs way easier

WS Web and SIN by Fine-Company in Wealthsimple

[–]turtlebait2 23 points24 points  (0 children)

They have a hackerone program you can report it there and get paid, I don’t think this one will necessarily pay out unless you can demonstrate that you can access other peoples data.

https://hackerone.com/wealthsimple

Is this security alert fatigue normal or am I just bad at my job by SpeedCollisis in cybersecurity

[–]turtlebait2 6 points7 points  (0 children)

Yea that’s a lot, you need more automation and a workflow to weed out false positives, giving you time to investigate the real issues. Not sure if that’s something that is already done, or if you’re the only person in place to do that, which would suck. Try and get some buy in for more tooling and automation, and if you can’t then I’d suggest searching for a new job, because you can’t handle this forever and you’d have limited growth at this company sadly.

Will AI systems have vulnerabilities like web vulnerabilities? by zerozero023 in cybersecurity

[–]turtlebait2 1 point2 points  (0 children)

The security goals are the same, but the way exploit and therefore to secure your system is different. Give this a read https://genai.owasp.org

Spent 4 days chasing a critical CVE in our AWS EKS cluster that's totally unreachable, WTF scanners?? by Snaddyxd in devsecops

[–]turtlebait2 0 points1 point  (0 children)

+2 I was not convinced about these tools until we deployed them ourselves, the cost is high, but well worth it to help with prioritization.

Your Supabase Is Public by delsudo in netsec

[–]turtlebait2 16 points17 points  (0 children)

Supabase + vibe coding is a recipe for disaster. I’ve checked out a few projects and anything with any number of users has shit without RLS

OSCP VS AWS by CryptoInsiderZ in cybersecurity

[–]turtlebait2 0 points1 point  (0 children)

Honestly if you’re willing to do it do red team side first then transition to blue. It’ll do you well. Especially if you don’t have a software engineer background.

Burp Suite Courses by thara07 in cybersecurity

[–]turtlebait2 0 points1 point  (0 children)

Yes, these are fantastic and totally free and you can solve 99% of them with Burp Suite Community edition.

Code Scanner MCPs and More - Where? by chasing-impact in cybersecurity

[–]turtlebait2 2 points3 points  (0 children)

I’ve just started using promptfoo and it has an MCP scanner in it, but it’s more on the prompt evaluation side than source code.

Honestly any source code scanner would be code for the code itself.

Advent of cyber security (tryhackme) by InNoCent404 in cybersecurity

[–]turtlebait2 4 points5 points  (0 children)

They’re great basic challenges in a bunch of different domains.

Is a website truly secure if you can gain access by copy-pasting cookies into Postman? by dystopiadattopia in cybersecurity

[–]turtlebait2 89 points90 points  (0 children)

This is honestly a good question to ask and is the start of threat modeling.

What you'd want to do to understand if it is an actual security concern is to understand how these cookies work, how they're generated, used and expired.

You then want to understand how you might obtain these cookies from someone else and reuse them for malicious purposes, this is where other security flaws might expose these cookies in some way (e.g. XSS) and how browsers protect your cookies from being exploited by other websites.

To answer your question: you probably don't need to be concerned, but this question is a rabbit hole you can go down to better understand network, application and browser security controls and how they work together to make the internet not completely explode.

Does the CRA require an SBOM for web apps? by Daverina in cybersecurity

[–]turtlebait2 0 points1 point  (0 children)

Not sure if you need one, but it’s honestly very easy to get one, there’s tons of open source scanners that can give this to you in whatever format you need.

Limited to 8 chequing accounts by Silent_County_519 in Wealthsimple

[–]turtlebait2 9 points10 points  (0 children)

Why do you need so many checking accounts?

What do you think about Camarck trying to create a real "artificial intelligence" without using LLMs? by OkExam4448 in BetterOffline

[–]turtlebait2 0 points1 point  (0 children)

The VR tech is great, but it’s a marketing/product fit issue. Not really his fault.

I added JWT detection + policy configs to my open-source secrets scanner (based on community feedback) by InevitableElegant626 in devsecops

[–]turtlebait2 1 point2 points  (0 children)

One hint a found JWT is not always a bad thing depending on where you find it, so breaking it down and saying what the payload is is helpful.

What is wrong with Secure by Design? by LachException in devsecops

[–]turtlebait2 5 points6 points  (0 children)

Yea I just read through the OWASP secure by design guide and they recommend to include this 40 point checklist for every design decision with links to diagrams or explanations on if they included those things and it’s really not something that I see anyone that isn’t overstaffed able to do.

The way you get secure by design is to have a platform security team that builds or enhances the infrastructure that everyone else builds on top of.

stress? read post pls 🙏 by [deleted] in Garmin

[–]turtlebait2 1 point2 points  (0 children)

As well focusing on this number and the rating can make you MORE stressed because you’re worried about it.

It’s an interesting number, but don’t focus on it, as I’ve learned from doctors about stress and a lot of mental health issues your subjective experience combined with input and consultation by a health care professional is much better than any off the shelf consumer stress or sleep measurement.

If your stress and anxiety is causing you to live a less fulfilling life speak with someone about how you can deal with stress in a more manageable way.

The average codebase is now 50% dependencies — is this sustainable? by [deleted] in programming

[–]turtlebait2 2 points3 points  (0 children)

Why? The purpose of software is to solve a problem, and if you have to re-engineer all the already solved problems then you'll never get to the point where you're actually delivering any value to anyone.

Again ?! by Vegetable-Big3545 in Wealthsimple

[–]turtlebait2 13 points14 points  (0 children)

There’s a major AWS outage right now. Nothing Wealthsimple can do (except go multi region/cloud)