I build and secure things. The DevOps guy, turned VP Eng. Infrastructure as Code all the things!
#devops #aws #identity #security
I mostly observe, but learn so much from all of you.
| Website | https://lukewaite.ca |

I build and secure things. The DevOps guy, turned VP Eng. Infrastructure as Code all the things!
#devops #aws #identity #security
I mostly observe, but learn so much from all of you.
| Website | https://lukewaite.ca |
Another day, another CloudFlare thing. Trying to submit an abuse report on a phishing domain that they are providing services to. No way to report without also sending the report to the owner of the website.
What even is the point?
Hello Mr Bad Actor? I've done a bunch of work to track down and try to report your malicious website, which doesn't even load without tracking parameters from the originating phishing email, here is a report please don't do it again.
Somebody sent me this blog my way today so I had a dig into it for a few hours. https://medium.com/@amitassaraf/the-story-of-extensiontotal-how-we-hacked-the-vscode-marketplace-5c6e66a0e9d7
Yes, Amit is right. Visual Studio Marketplace is a clusterfuck.
β
anybody can verify themselves using just a domain name
β
anybody can set any display name
β
extensions allow RCE, no sandboxing or limits at all
β
full access to developer + build
β
anybody can link any GitHub repo, even if it has nothing to do with the extension
β
Iβve already found malware - backdoors, beacons etc etc
30 minutes. 30 minutes is how long it took us to develop, publish, and polish a Visual Studio Code (The most popular IDE on the planet with over 15m monthly users) extension that changes your IDEβsβ¦
I've said it before and I'll say it again - the two top SaaS app features that I, as a person responsible for Security and IT want to see in your app - above all else:
1. Single Sign On with SCIM Support either included or at a price that is not insane.
2. An invoice that comes to me in email, attached as a PDF, so I can auto-populate expense reports and not have to waste time logging into every frigging app every frigging month to get it.
Thank you for your time.
Iβve been out of the CISO world for 3.5 months now, and thatβs given me a lot of perspective. Iβve had a chance to reflect on what Iβve learned over 30 years in IT and spoke to a bunch of people recently.
I can summarize what organizations need to do to better secure their data, prevent ransomware and whatnot:
Stop fucking around.
I think that will be the title of my book.
8 dead, 2,700 injured after simultaneous pager explosions in Lebanon
Lithium-ion batteries may have been triggered to explode.