Justin Brodley

@jbrodley
159 Followers
365 Following
12 Posts
Podcast: www.thecloudpod.net
Host, IT Executive and overall SaaS, Devops and Cloud engineer.
197: AWS throws another $35B on the tire fire in us-east-1 https://www.thecloudpod.net/podcast/197-aws-throws-another-35b-on-the-tire-fire-in-us-east-1 This week we talk about the new AWS region down under, the expansion of US-East-1 (or tire-fire-1) and Layoffs in tech #cloud #podcast https://www.thecloudpod.net/?p=13226
AWS Throws Another $35B On The Tire Fire In Us-east-1

On this episode of The Cloud Pod, the team talks about the new AWS Melbourne Region in Australia, Investment in US-East-1 Region, the layoff of employees by Microsoft and Google, the mutually beneficial expansion of the partnership between AWS and Stripe, as well as the role of security and GRC in the CCOE.

The Cloud Pod
Ah I see Google Cloud Next has chosen end of August. All of those with school children trying to get your last minute summer break are now getting to bring your kids to San Francisco. cloud.withgoogle.com/next #thecloudpod
We are looking for a freelancer to write our weekly show notes plus interview show notes to tcp talks. Bonus if you are open to transcribing too. Send me a message if interested! #podcast #shownotes
196: The Cloud Pod plays with all the stuff it found in the cleanroom https://www.thecloudpod.net/podcast/196-the-cloud-pod-plays-with-all-the-stuff-it-found-in-the-cleanroom This week we talk about Azures OpenAI offering, AWS Cleanrooms going GA, and we continue to talk Cloud Center of Excellence, this week all about IAM/Access management. #cloud #podcast https://www.thecloudpod.net/?p=12341
The Cloud Pod Plays With All The Stuff It Found In The Cleanroom

On this episode of The Cloud Pod, the team sits to talk about AWS's new patching policies, the general availability of Azure OpenAI, and the role of addressing IM or access management challenges in ensuring the seamless transition to the Cloud.

The Cloud Pod
195: The Cloud Pod can’t wait for Azure Ultra Fungible Storage (Premium)! On The Cloud Pod this week, Amazon announces massive corporate and tech lay offs and S3 Encrypts New Objects By Default, BigQuery multi-statement transactions are now generally available, and Microsoft announces acquisition of Fungible to accelerate datacenter innovation. #cloud #podcast
One of the most important books in the cloud and DevOps movement. Available for free today only!! Jump on this; required reading for my cloud and DevOps teams! https://www.amazon.com/dp/B078Y98RG8 (I understand its on other booksellers for free as well.. just search for it) #cloud
Amazon.com

I’ve been enjoying the community here but I need to uplevel my mobile app experience. I’m using the official mastodon client but does anyone have good recommendations.

LASTPASS NEWS ALERT AND COMMENTARY:
LastPass attackers know your name and billing address and all websites you have saved passwords for, and if your master password isn't sufficiently strong may be possible to brute-force open everything on attacker's machines.

PLEASE READ BEFORE PROCEEDING: https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/

The fact LastPass doesn't encrypt website URLs is a known flaw it appears they never fixed on purpose, going back almost 6 years:
https://hackernoon.com/psa-lastpass-does-not-encrypt-everything-in-your-vault-8722d69b2032

This eventual possible security breach was planned-for as part of LastPass' design for username and password protection. This doesn't break the core offering.
But it has stripped away multiple layers of protection and will hasten my looking at @bitwarden

It's impossible to be completely secure in a massive offering. However I have always disagreed with their decision to not 100% encrypt all metadata, and this event shows that was a foolish choice when seen against the inevitable of the entropy our complex electronic systems.

In the end, a password manager is still right choice in comparison to alternative. And a cloud-native offering like LastPass strongly hedges against data loss by normal users trying to manage their own vault. That is an undersold primary risk, not hackers. Still, very disappointed.

Current password setup:
- Primary vault is LastPass with 2FA
- Core fallback "key" accounts like email that allow pw reset are only in a KeyPass db file with 20char password, synced via OneDrive+2FA.
- This is then further backed-up with BackBlaze, using 40char encryption key

Security Incident December 2022 Update - LastPass

We are working diligently to understand the scope of the incident and identify what specific information has been accessed.

The LastPass Blog
I've come over to mastadon. Still getting used to it, but the discussions are really good that I've seen so far.