Building IT infra for 20+ years. ❤️🔥 for cloud foundations infra: security, networking, governance, scalability, ops, automation. Naturally born red teamer.
@itsguilleojeda Yeah I agree with the problem statement but not sure if X-ray is way to go. Any serious app will require something with much better DX/UX. If you spend money - why not go for something more mature.
A few weeks ago I wrote how vulns in cloud service providers were going to be more and more common as the industry matures. This week’s @CloudSecList seems to exemplify that with several entries involving all 3 major providers.
After watching 289 talks, I can now confidently share my re:Invent 2022 recap 🕵️♂️
Verdict: I am whelmed. Not underwhelmed or overwhelmed, just whelmed.
Since there were a bunch of other "unboxing" recaps already, here's a thread with an ✨actionable✨ recap.
I’ve been playing with GPT-3 for months now so let me save you a bit of time.
It’s a bullshitter.
I mean this in the technical philosophical sense. It produces words that are precisely engineered to sound convincing with zero guarantees that they’re related to reality.
I wrote a short post on finding/abusing exposed EBS snapshots. Somewhat unique to these is that you can enumerate all public ones via the API. It's important to have capabilities to detect/respond when resources are exposed in your cloud environments. https://t.co/PgXidkYaSq
I've been neck-deep in AWS billing data all day and all the technical debt AWS has here is somewhat amusing.
And, also, I feel for them so hard.
Some things that stand out 🧵
Step Functions Distributed Maps are awesome 💫
Combined with DynamoDB Parallel scans, they enable blazingly fast, whole-table data migrations and transformations.
Here's a CDK-based PoC of a migrations framework I have in mind and will be working on 👇
https://t.co/k7BgYpwr6h
This sounds really interesting. I'm curious how it authenticates back to the AWS mothership? If it's the same auth scheme as SSM, an adversary could potentially kill it/send uninteresting responses.
@FunWithTheCloud Also lattice can’t really talk to anything without some sort of “breakout” that you need to spin on EC2 if you need to talk to a EP that’s currently not supported on Lattice 😒
EFS team is on 🔥 this year with two crazy releases! Cold storage and elastic throughput. Both of these are game changing for EFS customers and make EFS an affordable option for workloads that might have broken the bank before.
Sometimes I want to sign up for an unpaid internship at AWS just so I can rebuild SSO and Cognito but not in Java from 2009. I would accept profit sharing from the literal oceans of cash they would get from providing an AWS native auth solution THAT ALLOWS YOU TO LOGOUT.