Luke Waite πŸ‡¨πŸ‡¦ 

132 Followers
195 Following
273 Posts

I build and secure things. The DevOps guy, turned VP Eng. Infrastructure as Code all the things!

#devops #aws #identity #security

I mostly observe, but learn so much from all of you.

Websitehttps://lukewaite.ca
AWS is currently offering big discounts for Black Friday, to unlock them simply open up your AWS console, search for EC2 instances that have been running since 2015 with the word β€œtemp” in the name, and terminate them.

Another day, another CloudFlare thing. Trying to submit an abuse report on a phishing domain that they are providing services to. No way to report without also sending the report to the owner of the website.

What even is the point?

Hello Mr Bad Actor? I've done a bunch of work to track down and try to report your malicious website, which doesn't even load without tracking parameters from the originating phishing email, here is a report please don't do it again.

Cyber Security has 2 modes: Gamer outrun LEDs and the driest mono-spaced document you've ever seen

Somebody sent me this blog my way today so I had a dig into it for a few hours. https://medium.com/@amitassaraf/the-story-of-extensiontotal-how-we-hacked-the-vscode-marketplace-5c6e66a0e9d7

Yes, Amit is right. Visual Studio Marketplace is a clusterfuck.

βœ… anybody can verify themselves using just a domain name
βœ… anybody can set any display name
βœ… extensions allow RCE, no sandboxing or limits at all
βœ… full access to developer + build
βœ… anybody can link any GitHub repo, even if it has nothing to do with the extension
βœ… I’ve already found malware - backdoors, beacons etc etc

1/6 | How We Hacked Multi-Billion Dollar Companies in 30 Minutes Using a Fake VSCode Extension

30 minutes. 30 minutes is how long it took us to develop, publish, and polish a Visual Studio Code (The most popular IDE on the planet with over 15m monthly users) extension that changes your IDE’s…

Medium
Isn’t a security blanket something that does nothing except comfort small children? Kinda like Cisco these days…
Pepperidge Farm remembers.

I've said it before and I'll say it again - the two top SaaS app features that I, as a person responsible for Security and IT want to see in your app - above all else:

1. Single Sign On with SCIM Support either included or at a price that is not insane.

2. An invoice that comes to me in email, attached as a PDF, so I can auto-populate expense reports and not have to waste time logging into every frigging app every frigging month to get it.

Thank you for your time.

I’ve been out of the CISO world for 3.5 months now, and that’s given me a lot of perspective. I’ve had a chance to reflect on what I’ve learned over 30 years in IT and spoke to a bunch of people recently.

I can summarize what organizations need to do to better secure their data, prevent ransomware and whatnot:

Stop fucking around.

I think that will be the title of my book.

11 dead, thousands injured in explosive supply chain attack on Hezbollah pagers

Pagers beeped, then blew up.

Ars Technica