1.2K ⭐️ OWASP WrongSecrets: game packed with real life examples of how to NOT store secrets in your software. 🔒🔑
@owasp
https://t.co/V3upZf1EJS
#starhistory#GitHub#OpenSource
@andrzej_js @donkersgood It's not that easy, as IAM and networking are the control planes. My point: using knative instead of SFN won't save you. There are a lot of factors at play in a migration and K8s adds to those. Apps developed on certain infra tend to stay there. Nice read: https://t.co/76iqG1VZ3u
@andrzej_js @donkersgood It's not just about state, it's about IAM, networking, CI/CD tooling, LCM, your team's knowledge, and much more. "Running clusters 101" doesn't begin to cut it. If it's okay to choose managed for your data (which is probably hardest to migrate), why would it not be OK for FaaS?
@andrzej_js @donkersgood@elonmusk You can run k8s anywhere, but you're still locked in to it. Esp. with advanced use it's never as simple as "just swapping orchestrators". It'll make it at least as hard as moving between clouds. For portability layered, loosely coupled software is probably still most important.
Took the #AWS t4g.nano ARM instance for a spin with AL2022. Turns out it's ~54% faster than my old t3.nano with AL2 at DNS resolution. It's also 20% cheaper. Not bad! @awscloud
@BJFdeHaan and I wrote another blog on cloud security! This time we do a deep dive on AWS IAM with ten pitfalls. Want to find out more? Check https://t.co/vYMqxRBLBh
#AWS#IAM#security#cybersecurity
@BJFdeHaan and I just wrote a blog on some of the security pointers we faced when working with Terraform on AWS. Want to know more? Check https://t.co/8dVvUcflW3
Some people say secrets management is a big indicator of your security maturity. So what do you need to think of when managing your secrets? @commjoenie and I highlighted 10 pointers in our blog: https://t.co/GyVkZOZE1y.
@Apple is implementing new anti-tracking features on iPhone – a major win for privacy! For #DataPrivacyDay@Mozilla is sending @Apple a thank you signed by more than 40,000 supporters. Learn more: https://t.co/4Uuxv2UXFS
A lot is written about the SDLC & security automation. But what if you just want to focus on the secure deployment itself? My colleague @BJFdeHaan and I wrote a blog about it at https://t.co/HLPcGecR7o.
Likely, a lot of the code you run is not code you wrote. But what does that mean in terms of security?
Open source packages make interesting targets. I've summarized the most interesting statistics and key takeaways from a review of supply chain attacks.
https://t.co/RUo5c0aZHK
@OConijn Ik was was aan het experimenteren met OrgFormation. Toffe tool! Vraagje: is er al support voor een CloudTrail organization trail? Zo ja, hoe? Zo nee, hoe kan ik helpen dit te maken?
@WebCareCD hi! We gebruiken de canal digitaal app op onze tv, en specifiek bij national geographic valt steeds na een paar minuten het geluid weg. Enig idee hoe dit op te lossen?
We are excited to announce the first #OWASP#Serverless Top 10 call for data. Help us better understand serverless applications risks.
We need you! https://t.co/RK2cCvwCE6
And don’t miss out the Serverless Top 10 talk on #OWASP#GlobalAppSec@OWASP_IL