ChrFolini Profile Banner
Christian Folini Profile
Christian Folini

@ChrFolini

Followers
3K
Following
31K
Media
415
Statuses
5K

Author of the #ModSecurity Handbook 2ed, forme OWASP @CoreRuleSet project co-lead and trainer. Program chair @SwissCyberStorm and board National Cyber Strategy

Berne, Switzerland
Joined December 2010
Don't wanna be here? Send us removal request.
@ChrFolini
Christian Folini
7 months
Bye Twitter!. It's been fun for a while. But lately, the information vs noise ratio stinks. I'm calling it a day. Please find me over at Bluesky at
0
0
0
@ChrFolini
Christian Folini
8 months
Enjoying my time at hashtag#GoHack24 in Zurich. I introduced the new "Chaos Fortress Plugin" for the @coreruleset WAF. It makes use of the new plugin architecture in order to break the feedback loop for the attackers and delays the responses. Slides:
1
0
4
@ChrFolini
Christian Folini
9 months
Everybody was super busy at the @OWASP project summit in the UK, but the industrious work attitude exhibited by the @OWASP_ASVS project put everything else in shadow. CC @manicode @JoshCGrossman.
@manicode
Jim Manico from Manicode Security
9 months
The @OWASP_ASVS working group iput a lot of work into the access control section (v4) to make it verifiable. We removed a lot of the “should’s and design issues” to just the basic list of “musts”. Your feedback is always appreciated.
0
1
3
@ChrFolini
Christian Folini
9 months
RT @swisscyberstorm: Want to reminisce about a talk you attended at @swisscyberstorm 2024? Browse through the slides of almost all talks! T….
0
1
0
@ChrFolini
Christian Folini
9 months
Tweet media one
0
0
3
@ChrFolini
Christian Folini
9 months
New problem: copy & pasting multi-language UTF-8 code. If the first line is Arabic, behavior of editor becomes really difficult to manage. Correlated problem: With the Arabic, I am not sure if it was reversed when pasting. :).
0
0
0
@ChrFolini
Christian Folini
9 months
RT @monica_amgwerd: Tatsächlich wurde ich cyber-ritterlich eingeladen🎩 Thank you @ChrFolini and @swisscyberstorm I had a blast and am honor….
0
1
0
@ChrFolini
Christian Folini
9 months
RT @lukOlejnik: At @swisscyberstorm 🇨🇭, I discussed how AI/LLM will bring new risks to influence operations, propaganda, and cyber attacks.….
0
7
0
@ChrFolini
Christian Folini
9 months
Look at all the pains @SecEvangelism took on her to attend @swisscyberstorm!. #SCS24.
@SecEvangelism
Chris Kubecka 🇵🇷🇨🇿🇳🇱 🇺🇦 secevangelism bsky
9 months
@vgatewoo Tried running out of it to catch my bus/taxi for my train, missed it. Had internet on the French side, none on the swiss side because it's not in the EU. Crazy airport!. About to enjoy a tasty beverage with @ChrFolini all worth it!.
0
0
1
@ChrFolini
Christian Folini
9 months
This is quite literally your last chance to get a ticket for the @swisscyberstorm conference tomorrow. Details on the amazing lineup here:.
Tweet media one
2
1
19
@ChrFolini
Christian Folini
9 months
I'm currently ROFL looking at AI images generated by @monica_amgwerd for her @swisscyberstorm talk on Tuesday. The idea is we not only need cool people at Security Conferences, but we need them as active citizens to secure our democracy. Tickets at
Tweet media one
2
3
7
@ChrFolini
Christian Folini
9 months
Top prize for the @swisscyberstorm raffle on October 22 after the conference:. Famous LEGO Rivendell set with a f**g 6K pieces!. Tickets for the raffle (and the conference) :
Tweet media one
1
0
8
@ChrFolini
Christian Folini
10 months
Team Switzerland 🇨🇭 is currently in the 5th position at the European Cybersecurity Challenge #ECSC. This is going to be a super-tight as the Poles are closing in.
5
0
3
@ChrFolini
Christian Folini
10 months
RT @swisscyberstorm: Speakers of @swisscyberstorm 2024:.@MayaBundt, Fabian Willi (@SwissRe): "An Insider Perspective on Cyber Insurance – Y….
0
1
0
@ChrFolini
Christian Folini
10 months
Many uptime agents, health checks and many attackers send HTTP requests with numeric host headers, which is officially illegal. If you can make sure your tools and agents behave properly, you can be sure a numeric host header is an attacker. And then you can block it. #WAFtip.
1
0
3
@ChrFolini
Christian Folini
10 months
I'm impressed the British are returning Chagos islands to Mauritius. There are strings attached and everything, but this is a big step to undo a wrong.
0
0
0
@ChrFolini
Christian Folini
10 months
Switzerland has a new law that forces public government to release all software developed for public government under an open source license (-> EMOTA). The law is now active and the federal chancellery just released a big heap of guides and checklists.
bk.admin.ch
The publication of open source software raises questions about rights, licences, security, organisation and costs. The Federal Chancellery is therefore producing tools and checklists to provide...
4
39
86
@ChrFolini
Christian Folini
10 months
One of the most anticipated @swisscyberstorm talks: @reversemode on cyber security in nuclear reactors. Years ago, a network guy told me the only reason steering panels of 🇨🇭reactors aren't hooked on the net is bc the technology predates the internet. Curious to learn more!.
1
1
7