@doot@glitterkitten.co.uk Carbon and Macadamia chiilin outside
AppSec stof 
#father #husband #bootstrap #founder #snowboarding #hiking #surfing #kayak #music #ancienthistorybuff #astronomybuff #coder #security #researcher #curious of everything else interesting
In that order regardless of online representations
I totally forgot about that "hollywood" command :tux:
A little hacker in the making
“Knock, knock. Who’s there?” very long pause… “Java.”
https://docs.aws.amazon.com/lambda/latest/dg/snapstart.html
#java #aws #sre #reinvent #reinvent2022
What a headline!
VPN "less Secure Network Access"
https://aws.amazon.com/blogs/aws/aws-verified-access-preview-vpn-less-secure-network-access-to-corporate-applications/
Let the pic do the talking
#aws #vpn #cybersecurity
There's a 'grain' of truth in every joke
#AWS fine-grained permissions and #authorization is no joke
Or is it?
https://aws.amazon.com/verified-permissions/
Any practitioner can tell you that #authz is entirely about 'actions', guess what the one thing about AWS #IAM they didn't include in this service derived from IAM policy document format and #API?..
For me personally, cloud security isn’t a worry. My data is such a mess that no one would find anything anyway
Worked for Medibank!
https://aws.amazon.com/blogs/aws/preview-amazon-security-lake-a-purpose-built-customer-owned-data-lake-service/
#aws #datalake #cybersecurity #datasecurity
Why are mausoleums the the best place to store sensitive information?
Their contents are encrypted at rest
https://aws.amazon.com/blogs/aws/announcing-aws-kms-external-key-store-xks/
99 little bugs in the code,
99 little bugs,
Take one down, patch it around,
142 little bugs in the code
https://aws.amazon.com/about-aws/whats-new/2022/10/amazon-ec2-enables-patching-guest-operating-system-application-replace-root-volume/
#aws :calculator: :crazy:
#PatchYourShit :blobpeek: :microsoft:
#patchmanagement :git:
:ablobfoxbongo:
@LitMoose@infosec.exchange as a couch surfer I can relate
The issue is the same thing we face with #AI #ML
The #developer coded with unconscious bias
Then the company shipped it with no employee caring what the company software actually looks like, they simply don't care enough to even use the things they sell that pays their wages
Work ethics have been this way for as long as I've been working, and I expect the next 24+ years will be no different
@jerry@infosec.exchange a lot of 1.2, even some 1.1, ciphers are fine
Disabling an entire protocol is what bad security tools and uneducated people tell you
Just serve a set of ciphers not known to be weak and a few other tweaks like SCSV and DNSSEC, also if you're going to be relying on those nasty ACME issued DV certs maybe use your own CSR and at least get a v3 with must staple flag
TLS has too many knobs and levers....
@jerry@infosec.exchange its mine, link in the bio
The pic mentions CBC which obviously isn't TLS1.3
and my message talked about bad actors using the least secure methods available, which is what the tool looks for too
Happy to go offline to chat, you don't seem to be paying attention to the details so whenever you're ready, happy to help you out if i can too, no drama
@jerry@infosec.exchange as many others have pointed out, that's not a high confidence report
Besides, bad actors don't negotiate the 'best' available, they connect with the most exploitable option
My tool wasn't too impressed either
My #NewYear2023 resolution
1920x1080 as usual :blobpats:
Maybe an upgrade is due :battery_broken:
This will be a hand-me-down or dedicated :kali_linux_r:
🪰🪲
We added bugs to our home page (on purpose)
🪰🪲
https://www.trivialsec.com/
🪰🪲
Keep or exterminate?
🪰🪲🪰🪲🪰🪲
Today, after years of coding, I made my first money as a Programmer
I sold my laptop
Meanwhile my code is used by the largest and most profitable businesses, and they call it;
https://aws.amazon.com/about-aws/whats-new/2022/11/aws-supply-chain-preview/
#aws #opensource #sca #sbom
@cvwise@infosec.exchange i have an Arch box here with some pretty similar period ports, isolated in all known ways to access it remotely doing backups pull-style. Very reliable
Old hardware never looses usefulness
Do you collect #vulnerabilities?
What do you do next?
Alert a #developer channel?
Store in excel
Keep in #DevOps pipeline logs
Review in a vulnerability management process
Report with pretty graphs and scream at dev teams to patch the fraking software faster?
Really, what works for you, actually works?