Applying Usability and Transparency to Security – Hannah Sutor – ASW #311
Hannah Sutor is passionate about all things digital identity and security. She currently works as a Principal Product Manager at GitLab, focusing on authentication and authorization in a DevSecOps context.
Hannah has spoken at various conferences on digital identity, privacy, cybersecurity, and devops workflows. She is passionate about balancing security and usability, and building secure software. She is a participant in OpenSSF working groups and serves on the board of IDPro. She lives outside of Denver, Colorado, USA, and decompresses with nature and vigorous workouts.
- Want to shape the future of identity? Identiverse 2025 is looking for dynamic speakers like you to share groundbreaking ideas with over 3,000 identity and access management leaders. Join the most influential voices in IAM and help drive innovation in our industry. Submit your presentation proposal today at securityweekly.com/idvcfp
Ancient Curl Bug, AWS re:Invent, Malware in NPM, Census III Report, MS OTP – ASW #311
Mike Shema
- A twenty-five years old curl bug | daniel.haxx.se
- Auditing the Ruby ecosystem’s central package repository | Trail of Bits Blog
- Top AWS re:Invent Announcements for Security Teams 2024 | Wiz Blog
- Open Source Usage Trends and Security Challenges Revealed in New Study
Download the report here
- WorstFit!
Noting this because it falls into the category of parsing, defaults, and choosing between failure modes.
- Open Source Malware Reaches More Than 778500 Packages, According to Sonatype Researchers
The report is behind a regwall. I've included it here to talk about the phrase, "...npm, exemplifies the risk contained in public repositories, representing 98.5% of the malicious packages Sonatype has identified in the past year."
John Kinsella
- Microsoft MFA found to be lax, bypassable
Folks at Oasis Security found out that Microsoft was allowing 3 minutes to accept a MFA token - 2.5 minutes longer than specified in RFC-6238. This gave attackers six times as long to attempt to brute force the value.
- Getting PCIE memory access via SD card reader
This might be a little more hardware hacking than appsec, but is still a good read on some of the history of memory card interfaces and DMA attacks. End-of-day, they've created a custom board to insert into a SD card reader that provides access to the laptop's memory via PCI Express.









