Andy Kennedy

4 Followers
83 Following
151 Posts

Dreaming out loud most of the time, cloud solutions architect the rest of the time.

Current interests:
- Confidential computing
- Cloud Security

My bank uses phone SMS as its standard "2-factor authentication" -- better than nothing at all but GROSSLY insecure compared to encrypted messaging that it refuses to supply.

I paid extra for an RSA dongle, but when I log in there's an option to use SMS, which makes the dongle completely pointless.

Crap security is standard in the banking industry -- because contrary to pious words, it doesn't give a damn about your financial privacy.

https://www.nbcnews.com/tech/security/make-sure-texts-calls-are-encrypted-fbi-security-warning-rcna182810

How to make sure texts, calls are encrypted after FBI security warning

Federal officials warned that a massive Chinese hacking operation against American telecommunications companies hasn’t yet been fully expelled.

NBC News

Great example of using Cloudflare to scale globally

Troy Hunt: Closer to the Edge: Hyperscaling Have I Been Pwned with Cloudflare Workers and Caching

https://www.troyhunt.com/closer-to-the-edge-hyperscaling-have-i-been-pwned-with-cloudflare-workers-and-caching/?__readwiseLocation=

Closer to the Edge: Hyperscaling Have I Been Pwned with Cloudflare Workers and Caching

I've spent more than a decade now writing about how to make Have I Been Pwned (HIBP) fast. Really fast. Fast to the extent that sometimes, it was even too fast: The response from each search was coming back so quickly that the user wasn’t sure if it was

Troy Hunt

Billie Jean King took tennis equity to the top of sport. She never got comfortable there - The Athletic

https://www.nytimes.com/athletic/5918466/2024/11/15/billie-jean-king-tennis-equality-equity-interview/

Billie Jean King took tennis equity to the top of sport. She never got comfortable there

At 80, the tennis figurehead has had as much impact on sport as perhaps anyone in her lifetime. She isn't ready to stop now.

The Athletic
Life Lessons from the First Half-Century of My Career

Communications of the ACM

Elevating Security with Arm CCA –
Armv9-A has recently been enhanced with realm management extension (RME), which provides an architecture designed to protect code and data using the techniques of confidential computing on different form factors.

Communications of the ACM

https://cacm.acm.org/practice/elevating-security-with-arm-cca/

Elevating Security with Arm CCA – Communications of the ACM

Google Now Offering Up to $250,000 for Chrome Vulnerabilities

Google has significantly increased the rewards for Chrome browser vulnerabilities, offering up to $250,000 for remote code execution bugs.

SecurityWeek
Avoiding downtime: modern alternatives to outdated certificate pinning practices http://blog.cloudflare.com/why-certificate-pinning-is-outdated/
Avoiding downtime: modern alternatives to outdated certificate pinning practices

The number of outages caused by certificate pinning is increasing. We’ll explore why certificate pinning hasn’t kept up with modern standards and recommend alternatives to improve security while reducing management overhead.

The Cloudflare Blog
Whoops! The Internet Broke.

Massive outages caused by a cloud-computing bug are the new normal.

The Atlantic
Looking forward to the opportunity to speak at InfoSec Manchester Meetup. https://www.eventbrite.co.uk/e/infosec-manchester-june-20th-2024-tickets-899243490487?aff=oddtdtcreator
InfoSec Manchester June 20th 2024

Inviting some of the industry's leading speakers to share the InfoSec experiences and knowledge.

Eventbrite
When your patch management becomes the recycling bin (if you are lucky) - Netgear WNR614 flaws allow device takeover, no fix available https://www.bleepingcomputer.com/news/security/netgear-wnr614-flaws-allow-device-takeover-no-fix-available/
Netgear WNR614 flaws allow device takeover, no fix available

Researchers found half a dozen vulnerabilities of varying severity impacting Netgear WNR614 N300, a budget-friendly router that proved popular among home users and small businesses.

BleepingComputer