What if we stop treating security testing as a separate thing?
Prioritize using your existing unit, integration, and end-to-end testing frameworks to cover security cases
Prioritize using your existing unit, integration, and end-to-end testing frameworks to cover security cases
Applying Hartmut Rosa's concepts of controllability and resonance to the security space
The sooner you start doing it, the easier it is to get done!
tl;dr A BGP-based feature of the AWS Direct Connect service allowed a third party to inject an incorrect route for an external IP assigned to me, effectively hijacking my AWS-sourced traffic.
Notes, photos, and maps from a few days in the Aotearoa mountains
It started simply enough...
Code signing, what is it good for?
One way to pass time during a pandemic
A SQL-like abstraction over all your cloudy things
A story of cloud, automation, but mostly just contributing to open source - in several acts
Perhaps we do not share the same definition of "critical"?
"Give a small boy a hammer and he will find that everything he encounters needs a pounding."
(Small camper, big dream.)
1) Don't be a jerk, and 2) consider the alternatives
Sometimes, you just have to take that one step...
General impressions, and a little Python to validate the signature on incoming alerts.
Calculating IP range reversals with Python 3's ipaddress
Automated, low-effort security is the best kind
I suspect this isn't really how you're supposed to do things, but hey.. works for me
Powershell is an ugly hammer but it occasionally drives a nail effectively, or at least saves a bunch of copy-paste-reformat busy-work
Get me off this never-ending hamster wheel of pain
Getting incoming message counts out of Exchange Online
Balancing, estimation, & trade-offs
Because you don't always need GitHub to git
Some open-ended questions
Determining if an updated Amazon Linux (or Red Hat / CentOS) system requires a reboot
Smart decisions in the early stages...
An argument against DevSecOps (SecDevOps?) & secure development lifecycles
Modern medicine & stubborn preemies FTW.
Spamming web servers with HTTP GETs since the mid-2000s.
Just say no to multi-monitor madness. Or - at least - be capable of working without it.
Security regulation that doesn't suck.
Dealing with 'informational' risk penetration test findings, one at a time...