Staff Cloud Engineer at Zoox

Zoox is hiring Staff Cloud Engineer

@cwebber @avuko

Would have been even more impressive had it been an
#AWS, #GCP or #Azure facility.
Deploying a Server on the Google Compute Cloud

Learn how to move a web site to Google Compute Engine, using FreeBSD and Nginx. Then set up TLS certificates for HTTPS.

Bob's Pages of Travel, Linux, Cybersecurity, and More

Be aware: Cloud buckets can be hijacked.

If I understand this article correctly, then the globally unique name of the cloud bucket is the only method of verifying the correct target of a data stream. It feels like a major oversight. But then again security issues often feel that way in hindsight.

Source: https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/
#cybersecurity #security #infosec #cloud #aws #gcp #azure

The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration

Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs.

Unit 42