Thomas H. Ptacek

6.7K Followers
278 Following
1.3K Posts
Full of passionate intensity.
All I have to say about this is never, ever, ever, ever say anything measured about 3B1B on this Internet. Maybe some other Internet. Not this one. When there was only one set of footprints in the sand, that was 3B1B carrying me!
@frew No that's just what Australians sound like.

So... yeah... we found a guest to talk to us about zero day markets and exploit pricing. He's... credible, I think?

(David and I tacked an "SCW: After Dark" bit at the end because he couldn't make the original interview).

https://securitycryptographywhatever.com/2024/06/24/mdowd/

Zero Day Markets with Mark Dowd

We have Mark Dowd on, founder of Aziumuth Security and one of the authors of The Art of Software Security Assessment, to talk about the market for zero day v...

@rennerocha GRU had a status-paged incident last night --- it wasn't out of capacity, but rather a deployment broke placement logic. The problem was exclusive to GRU. It'll be on the infra log this week.

I understand that this would bother if you were deploying more instances of a critical app that absolutely had to be in GRU, but it's the nature of what we do that individual regions --- we have almost 40 --- are going to experience transient issues. This was one we had a lot of control over, but >half of what we run into isn't like that.

@rennerocha @flydotio Hey there! I'm betting you were deploying in GRU last night?
@tyler I do not, but this is a super interesting subject to me and I've done some pentest work in the space. If you find a good resource, let me know.
Moss wrote a little bit of code and now it's arguably easier to give a Fly Machine access to an AWS resource than it is to give it to an ECS task. https://fly.io/blog/oidc-cloud-roles/
AWS without Access Keys

How we made it a lot easier and more secure for your apps on Fly.io to work with other clouds.

Fly
@lcamtuf @alex Now you understand deletionism.
@alex People have written to ask me about helping them set up Wikipedia pages, and EVERY TIME I have responded by trying to talk them out of it. I feel bad for the pages I started for security peeps. I even feel bad for Mary Ann Davidson. Why are you in an encyclopedia at all? Madness!
Just finished recording the next SCW, at 8:30PM on a Saturday, because our guest was in Australia, and I am extremely psyched about this one.