A company may be choosing between hiring an information security consultancy, or running a public “bug bounty” program. This post compares those two options. Warning: I’m still relatively new to working in a consultancy, so my thoughts on this may be immature.
I originally wanted to publish this on the company blog, until I realized that company blogs are for assertive statements of reality as opposed to missives about professional growth and realizations. So this post is coming here instead!
My first foray into IoT soil moisture sensing. Describes calibrating a moisture sensor, connecting it to a Cricket IoT esp32 board, and receiving mqtt moisture readings on Home-Assistant.
Paypal promotes its “smart buttons” as a way to integrate purchasing on websites.1 However, by default, all of their purchasing logic, including purchase amounts for specific items, happens in the browser via javascript. This means that an attacker could edit javascript and modify payment amounts. That’s a problem if the vendor sets up webhook automation for paypal purchases to trigger business…
I want to blog about a wider collection of topics. For years I’ve been timid to publish beyond a small set of topics related to my work – security, analytics, pedagogy, etc. I’ll call these the “professional” posts. But I have a lot of random hobbies, and I want to archive them somehow! Like woodworking, electronics, gardening, home automation, and church/religion stuff. I’ll call these…