mattrpav Profile Banner
Matt Pavlovich Profile
Matt Pavlovich

@mattrpav

Followers
347
Following
844
Media
33
Statuses
980

CTO at HYTE / hybrid messaging / hybrid microservices / Created https://t.co/YudT7NJ3wP / hiking cycling mountain biking

Austin, TX
Joined April 2009
Don't wanna be here? Send us removal request.
@mattrpav
Matt Pavlovich
2 years
Just submitted @OpenJDK enhancement request (#9076208) to define an allow list of CIDR addresses for creating outbound network connections. This would provide immediate mitigation for an entire class of exploits that target Java-based systems.
0
0
0
@mattrpav
Matt Pavlovich
2 years
Can we just skip passkeys and go straight to ssl keys (or gpg)?
0
0
1
@mattrpav
Matt Pavlovich
3 years
I recall reading that Loom favors ReentrantLock vs synchronize. Not sure if that will be the case when finalized, but worth looping back on.
@PeterLawrey
Peter Lawrey
3 years
@omniprof The only way ReentrantLock helps is using tryLock(), otherwise it has the same behaviour.
0
0
0
@mattrpav
Matt Pavlovich
3 years
Slack private GitHub repo compromised https://t.co/rQbDuWqMoN We moved to private hosting with #gitea on Kubernetes
0
1
1
@jrrickard
jrrickard
3 years
Happy Kubernetes 1.25 Release Day. I’ll be cutting the release today and I couldn’t be more excited.
4
19
137
@mattrpav
Matt Pavlovich
3 years
Security— https|ssh key git repos. ldaps authn and authz. GPG signed commits.
0
0
1
@mattrpav
Matt Pavlovich
3 years
@giteaio provides everything we need to securely run our development operation.
1
1
3
@mattrpav
Matt Pavlovich
3 years
Good-bye @GitHub. Hello @giteaio
1
2
6
@TheUplinkTV
The Uplink
4 years
If you still have Log4j questions, especially surrounding Apache ActiveMQ, you'll want to check out this security bulletin from HYTE. #log4j #log4shell #activemq https://t.co/XWO74tANtb
0
1
1
@mattrpav
Matt Pavlovich
4 years
HYTE Technologies, Inc. latest information on Log4Shell information and impacts to HYTE MQ and Apache ActiveMQ #log4shell #activemq #hytemq https://t.co/uwlIlSAM6v
0
0
0
@gunnarmorling
Gunnar Morling 🌍
4 years
Proceed with caution when using externally hosted services promising you an easy way to find out whether you're affected by #Log4Shell. Wouldn't be surprised to see kind of "reverse honeypots" popping up, aiming at harvesting addresses of vulnerable systems. #log4jRCE
2
16
52
@mattrpav
Matt Pavlovich
4 years
Ignore the custom Java Agents and the "hot fix" java classes. Set the property at startup to mitigate the security issue: -Dlog4j2.formatMsgNoLookups=true. #log4j #log4j2 #CVE-2021-44228 #log4shell
0
0
0
@schneider_chris
Christian Schneider (クリス)
4 years
@egonwillighagen @NewsOsgi @BridgeDbProject @sonatype There are several ways. I prefer to use bnd-maven-plugin like this: https://t.co/EgLHfoidYG In a multi module project you only do that on the parent and use bnd.bnd files to configure the bundles.
0
2
5
@mattrpav
Matt Pavlovich
4 years
I enjoyed the round table with fellow @ApacheActiveMQ committers on @feathercast https://t.co/bg4hW1LVXD
0
2
2
@mattrpav
Matt Pavlovich
4 years
This is cool. #Ubuntu 1 device has a firmware upgrade available. Run `fwupdmgr get-upgrades` for more information.
0
0
0
@mattrpav
Matt Pavlovich
4 years
0
0
0
@mattrpav
Matt Pavlovich
4 years
JDK 11 support added to ActiveMQ
@jbonofre
Jean-Baptiste Onofré
4 years
Just merged my PR about JDK11 full build support in #apache #activemq @TheASF . Now, I'm moving forward on others updates (Spring 5, log4j2, etc) \o/. I will also share some details about the BookKeeper/ZooKeeper store PoC that I'm doing now.
0
0
2
@mattrpav
Matt Pavlovich
4 years
This +1000. Adding this would also drastically improve the value of static code analysis.
@ID_AA_Carmack
John Carmack
4 years
Everyone knows the C standard library is full of minefields and bad decisions from 40 years ago. Adopting a few hundred new functions that have been battle-tested, and making them standard for everyone should be far easier, and possibly more valuable, than language tweaks.
0
0
0