home.social

#securitytheatre — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securitytheatre, aggregated by home.social.

  1. I now (finally) got back a response from Kiwibank on my formal complaint to them, for sending extensive information on mortgages and mortgage applications to clients (us) by plain text email (with PDF attachments).

    In a way I *knew* it would come out this way. A lot of weasle words making statements that they're compliant with the Credit Contracts and Consumer Finance Act 2003 (LOL, > 20 years old), having extensive 'controls in place' and using 'transit protection'. As if they could control what happens on a service provider's side with (A) the content of the emails, and (B) them actually *also* transmitting them on with transit encryption.

    Even if it is compliant, it just should not be *acceptable* by the point of view on how to conduct business.

    How naive do they think people are who are *explicitly* asking about these issues?

    This is some serious #SecurityTheatre they're pulling off.

    Now I need to come off of my rage, or my freediving training will not be effective tonight ...

    #Kiwibank #privacy

  2. Is Node.js the future of backend development, or just a beautifully wrapped grenade?

    Lately, I see more and more backend systems, yes, even monoliths, built entirely in Node.js, sometimes with server-side rendering layered on top. These are not toy projects. These are services touching sensitive PII data, sometimes in regulated industries.

    When I first used Node.js years ago, I remember:
    • Security concepts were… let’s say aspirational.
    • Licensing hell due to questionable npm dependencies.
    • Tests were flaky, with mocking turning into dark rituals.
    • Behavior of libraries changed weekly like socks, but more dangerous.
    • Internet required to run a “local” build. How comforting.

    Even with TypeScript, it all melts back into JavaScript at runtime, a language so flexible it can hang itself.

    Sure, SSR and monoliths can simplify architecture. But they also widen the attack surface, especially when:
    • The backend is non-compiled.
    • Every endpoint is a potential open door.
    • The system needs Node + a fleet of dependencies + a container + prayer just to run.

    Compare that to a compiled, stateless binary that:
    • Runs in a scratch container.
    • Requires zero runtime dependencies.
    • Has encryption at rest, in transit, and ideally per-user.
    • Can be observed, scaled, audited, stateless and destroyed with precision.

    I’ve shipped frontends that are static, CDN-delivered, secure by design, and light enough to fit on a floppy disk. By running them with Node, I’m loading gigabytes of unknown tooling to render “Hello, user”.

    So I wonder:
    Is this the future? Or am I just… old?

    Are we replacing mature, scalable architectures with serverless spaghetti and 12-factor mayhem because “it works on Vercel”?

    Tell me how you build secure, observable, compliant systems in Node.js.
    Genuinely curious.
    Mildly terrified and maybe old.

    #NodeJS #BackendSecurity #SecureCoding #PII #Compliance #SoftwareArchitecture #ServerSideRendering #TypeScript #Java #Kotlin #Golang #Erlang #Ruby #Scalability #Observability #DevSecOps #LegacyVsModern #SecureByDesign #CompiledLanguages #CloudArchitecture #StatelessDesign #SecurityTheatre #TechSatire #LinkedInTechRant

  3. My bank, sending me a code which is to be shared with a provider to enable payment: "NEVER SHARE THIS CODE!"

    Me: <feeling apprehensive> shares code with provider to enable payment.

    🤔

    #ModernBanking
    #SecurityTheatre
    #onlinepayments

  4. @bojkotiMalbona
    Sounds like #dataCollection for the purposes of compromising all known computer systems that a dissenter might need to access.

    Its likely #overrreach, #securityTheatre and an abuse of privacy and privilege of course.

    There are almost no #ethical paid jobs left in tech — maybe some #gameDev, and maintaining *some* existing systems.

    #APAB #itsMore1984