I find myself at a point where I'm encountering irreconcilable differences between my moral, ethical, and technical objections to the use of LLMs, and my employer's leadership's desire to force the use of LLMs into every aspect of day to day operations. As a result, I find myself #OpenToWork .

I have decades of experience in the #SysAdmin / #SRE / #DevOps / #CICD / #CloudComputing range of skills. Currently acting as a subject matter expert on #Kubernetes , #Terraform , and #Observability . Mostly supporting #GCP platforms these days, but I am comfortable pivoting to other #cloud platforms like #AWS or even #OnPrem . Can do #ProjectManagement and #TeamLeadership. Experienced in #DevSecOps and #FedRAMP processes.

I would strongly prefer to deal with no LLM tooling at all, but will settle for having to use it less than in the current environment.

Location: #Canada (remote), #WaterlooRegion (Ontario) (hybrid).

#FediHire #FediHired #GetFediHired

"For years, reviewers said, Microsoft had tried and failed to fully explain how it protects sensitive information in the cloud as it hops from server to server across the digital terrain. Given that and other unknowns, government experts couldn’t vouch for the technology’s security.

Such judgments would be damning for any company seeking to sell its wares to the U.S. government, but it should have been particularly devastating for Microsoft. The tech giant’s products had been at the heart of two major cybersecurity attacks against the U.S. in three years. In one, Russian hackers exploited a weakness to steal sensitive data from a number of federal agencies, including the National Nuclear Security Administration. In the other, Chinese hackers infiltrated the email accounts of a Cabinet member and other senior government officials.

The federal government could be further exposed if it couldn’t verify the cybersecurity of Microsoft’s Government Community Cloud High, a suite of cloud-based services intended to safeguard some of the nation’s most sensitive information.

Yet, in a highly unusual move that still reverberates across Washington, the Federal Risk and Authorization Management Program, or FedRAMP, authorized the product anyway, bestowing what amounts to the federal government’s cybersecurity seal of approval. FedRAMP’s ruling — which included a kind of “buyer beware” notice to any federal agency considering GCC High — helped Microsoft expand a government business empire worth billions of dollars."

https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government

#Microsoft #FedRAMP #USA #Trump #CyberSecurity #Cloud #CloudComputing

Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway.

A federal program created to protect the government against cyber threats authorized a sprawling Microsoft cloud product, despite the company’s inability to fully explain how it protects sensitive data.

ProPublica

IT-Security-Leute der US-Regierung sollten die MS-Cloud auf Tauglichkeit für geheime Daten prüfen. Wertung:

"Pile of shit"
“lack of proper detailed security documentation”
“lack of confidence in assessing the system’s overall security posture”

Auch wird der Vergleich zu #AWS und #GCP gezogen - dort wäre das Design auf die Anforderungen angepasst, Microsoft hätte einfach bestehendes irgendwie zurechtgegaffat.

Wurde nach politischem Druck natürlich trotzdem für geheime Dokumente zugelassen.

https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government

#azure #microsoft #microslop #FedRAMP

Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway.

A federal program created to protect the government against cyber threats authorized a sprawling Microsoft cloud product, despite the company’s inability to fully explain how it protects sensitive data.

ProPublica
Federal cyber experts called Microsoft's cloud a "pile of shit," approved it anyway

One Microsoft product was approved despite years of concerns about its security.

Ars Technica

A rather technical deep dive into verification systems run by #Persona, followed by some interesting questions that deserve answers.

Persona seems to use the same code base for a #KYC system that verifies potential customers that want to sign up with #OpenAI to use GPT-5; as well as for another system that does #FedRAMP security assessments for #US government agencies (including automated notifications of agencies in special cases).

(Read "0x11 - the architecture" first)

https://vmfunc.re/blog/persona/

via @raptor

#security #privacy #ageverification

the watchers: how openai, the US government, and persona built an identity surveillance machine that files reports on you to the feds

53MB of source code leaked from a government endpoint. 269 verification checks. biometric face databases. SAR filings to FinCEN. and the same company that verifies your ChatGPT account.

vmfunc.re

Today we're announcing Container Reachability, delivering full-stack reachability across application and base layers.

The results?
90% reduction in container vulnerability false positives
Evidence-based prioritization of vulnerabilities
A unified platform for SCA,SAST, and container scanning

www.endorlabs.com/learn/introducing-full-stack-reachability-container-scanning-that-actually-reduces-noise

#ContainerSecurity #DevSecOps #FedRAMP

📰 ColorTokens Xshield Platform Gains FedRAMP Moderate Authorization, Boosting Federal Zero Trust Adoption

ColorTokens' Xshield platform has achieved FedRAMP Moderate Authorization! 🇺🇸 This allows U.S. federal agencies to accelerate Zero Trust adoption with a validated microsegmentation solution to stop lateral movement. #FedRAMP #ZeroTrust #CyberSecur...

🔗 https://cyber.netsecops.io/articles/colortokens-xshield-platform-achieves-fedramp-moderate-authorization/?utm_s…

ColorTokens Xshield Platform Gains FedRAMP Moderate Authorization, Boosting Federal Zero Trust Adoption

ColorTokens Xshield, a microsegmentation platform, has received FedRAMP Moderate Authorization, enabling U.S. federal agencies to adopt it for Zero Trust security.

CyberNetSec.io
🌘 為何 FedRAMP 授權與 CMMC 第二級已成為政府合約 AI 的必備入場券
➤ 安全即生產力:定義政府標案 AI 的合規新標準
https://blog.procurementsciences.com/psci_blogs/why-fedramp-authorization-and-cmmc-level-2-are-now-table-stakes-for-govcon-ai
在政府合約(GovCon)領域,人工智慧已從邊緣的實驗性工具,轉變為貫穿機會搜尋、合規追蹤與提案開發的核心引擎。隨著 AI 處理的資料涉及定價策略、過往實績及受控非機密資訊(CUI),資訊安全不再是選配,而是生存的基石。Procurement Sciences 指出,僅宣稱「符合標準」已不足夠,唯有透過取得正式的 FedRAMP 授權與 CMMC 第二級認證,才能在處理高敏感度的政府標案時,確保資料的完整性與合規性。本文深入分析了安全合規如何轉化為競爭優勢,並強調真正的安全 AI 平臺必須在不犧牲易用性的前提
#雲端安全 #政府合約 (GovCon) #人工智慧合規 #資安架構 #FedRAMP
Why FedRAMP Authorization and CMMC Level 2 Are Now Table Stakes for GovCon AI

Learn about all what goes into the Autogen AI pricing model and how much it might cost your business to use the software.

Why FedRAMP Authorization and CMMC Level 2 Are Now Table Stakes for GovCon AI

Learn about all what goes into the Autogen AI pricing model and how much it might cost your business to use the software.