Luke Waite πŸ‡¨πŸ‡¦ 

132 Followers
195 Following
273 Posts

I build and secure things. The DevOps guy, turned VP Eng. Infrastructure as Code all the things!

#devops #aws #identity #security

I mostly observe, but learn so much from all of you.

Websitehttps://lukewaite.ca
@SecureOwl @acarsdrama crazy thought here, but maybe it’s the people transmitting sensitive data in the clear that create the privacy and security issues, rather than those listening

@merill Maester has always been on my #todo list so I thought I would give it a try after seeing this…

I went and specifically looked for this test result, and it shows as attached. Does this mean I'm running an older version with less verbose errors, or that something is broken in the testing itself?

AWS is currently offering big discounts for Black Friday, to unlock them simply open up your AWS console, search for EC2 instances that have been running since 2015 with the word β€œtemp” in the name, and terminate them.

Another day, another CloudFlare thing. Trying to submit an abuse report on a phishing domain that they are providing services to. No way to report without also sending the report to the owner of the website.

What even is the point?

Hello Mr Bad Actor? I've done a bunch of work to track down and try to report your malicious website, which doesn't even load without tracking parameters from the originating phishing email, here is a report please don't do it again.

Cyber Security has 2 modes: Gamer outrun LEDs and the driest mono-spaced document you've ever seen
@jerry configuration via llm terminal with no documented commands
@SecureOwl banner ads in a product you pay for? That’s a fun new low

Somebody sent me this blog my way today so I had a dig into it for a few hours. https://medium.com/@amitassaraf/the-story-of-extensiontotal-how-we-hacked-the-vscode-marketplace-5c6e66a0e9d7

Yes, Amit is right. Visual Studio Marketplace is a clusterfuck.

βœ… anybody can verify themselves using just a domain name
βœ… anybody can set any display name
βœ… extensions allow RCE, no sandboxing or limits at all
βœ… full access to developer + build
βœ… anybody can link any GitHub repo, even if it has nothing to do with the extension
βœ… I’ve already found malware - backdoors, beacons etc etc

1/6 | How We Hacked Multi-Billion Dollar Companies in 30 Minutes Using a Fake VSCode Extension

30 minutes. 30 minutes is how long it took us to develop, publish, and polish a Visual Studio Code (The most popular IDE on the planet with over 15m monthly users) extension that changes your IDE’s…

Medium
Isn’t a security blanket something that does nothing except comfort small children? Kinda like Cisco these days…