
Andrew Hoffman
@and1hof
Followers
165
Following
3
Media
5
Statuses
39
Software Engineer & Security Researcher. Author of Web Application Security: Exploitation and Countermeasures (O'Reilly, 2020).
Seattle, WA
Joined September 2015
I am separating my manual and automated tweets. Follow @and1hofbot for reminders whenever I upload a new YouTube video. Follow this account to hear my thoughts and ideas.
1
0
0
This morning I released a deep-dive and technical breakdown of a sophisticated XSS vulnerability that was exploited against 80+ govs last year. It uses an unusual & uncommon XSS sink. #appsec #infosec #CyberSecurity.
0
0
0
I just released an important blog post regarding a new and upcoming SCA feature that all next-gen platforms will have. #infosec #cybersecurity .
1
0
0
In any other industry suggesting “hash and salt” to a co-worker means you want to get brunch at the local diner. #CybersecurityAwarenessMonth.
0
0
0
Regression testing is essential for a good long term security posture. Fix the vulnerability once, write a test and than block merge if a developer ever reopens the bug. #CybersecurityAwarenessMonth2022.
1
0
1
The goal of a threat model should be four-fold. a) identify threats, b) identity mitigations, c) identify delta between "a" and "b", and finally e) document knowledge #CybersecurityAwarenessMonth.
0
0
2
RT @ACouedelo: Great Explainer about Zero Trust Architecture by @and1hof . He made me realize that I had missed some elements in my researc….
0
1
0
Don’t forget to vote in the upcoming midterm elections. As a US citizen, these elections are your best voice into changing outdated laws, introducing new ones and of course preserving and improving our democracy! #Midterms2022.
0
0
0
RT @DanaEpp: I’m giving away the perfect API Hacker’s library to one of my readers - @hAPI_hacker’s “Hacking APIs”, @DafyddStuttard’s “The….
0
20
0
I am releasing a comprehensive video on #ZeroTrust architecture in 1 hour on my YouTube channel (and1hof). Head on over to YT and check it out #CybersecurityAwarenessMonth
0
0
1
RT @cianmaher0: "Graphics are the first thing finished in a video game" . Here's a Thunderjaw from an early build of Horizon: Zero Dawn htt….
0
4K
0
Yes, you too can design an app that is difficult to hack as long as your architects evaluate security cost benefit trade offs alongside functionality requests. It’s much harder to secure an app after it’s been built. #cybersecurity.
0
0
0