AppSec stof 

15 Followers
30 Following
28 Posts
@jerry a lot if 1.2, even some 1.1, ciphers are fine
Disabling an entire protocol is what bad security tools and uneducated people tell you
Just serve a set of ciphers not known to be weak and a few other tweaks like SCSV and DNSSEC, also if you're going to be relying on those nasty ACME issues DV certs maybe use your own CSR and at least get a v3 with must staple flag
TLS has too many knobs and levers....
@jerry its mine, link in the bio
The pic mentions CBC which obviously isn't TLS1.3
and my message talked about bad actors using the least secure methods available, which is what the tool looks for too
Happy to go offline to chat, you don't seem to be paying attention to the details so whenever you're ready, happy to help you out if i can too, no drama

@jerry as many others have pointed out, that's not a high confidence report

Besides, bad actors don't negotiate the 'best' available, they connect with the most exploitable option

My tool wasn't too impressed either

I totally forgot about that "hollywood" command   
A little hacker in the making
@doot Carbon and Macadamia chiilin outside
AWS Verified Access Preview — VPN-less Secure Network Access to Corporate Applications | Amazon Web Services

Today, we announced the preview of AWS Verified Access, a new secure connectivity service that allows enterprises to enable local or remote secure access for their corporate applications without requiring a VPN. Traditionally, remote access to applications when on the road or working from home is granted by a VPN. Once the remote workforce is […]

Amazon Web Services

99 little bugs in the code,
99 little bugs,
Take one down, patch it around,
142 little bugs in the code
https://aws.amazon.com/about-aws/whats-new/2022/10/amazon-ec2-enables-patching-guest-operating-system-application-replace-root-volume/

#aws   
#PatchYourShit    
#patchmanagement   

Amazon EC2 enables easier patching of guest operating system and applications with Replace Root Volume

Amazon Web Services, Inc.

@LitMoose as a couch surfer I can relate

The issue is the same thing we face with #AI #ML

The #developer coded with unconscious bias

Then the company shipped it with no employee caring what the company software actually looks like, they simply don't care enough to even use the things they sell that pays their wages

Work ethics have been this way for as long as I've been working, and I expect the next 24+ years will be no different

“Knock, knock. Who’s there?” very long pause… “Java.”

https://docs.aws.amazon.com/lambda/latest/dg/snapstart.html​
#java #aws #sre #reinvent #reinvent2022

#stargate has it all
Adventure
Dry humour
Space
Ancient history (mythology mostly)
Action scenes
Witty
Short stories
Loooong story arcs
Interesting characters
Clever twists
Love interest
Self detrimental humour
Oh the puns!