We're excited to announce LaunchDarkly Federal—the first FedRAMP®-authorized feature management platform. This means we can help public sector agencies develop software faster and release with less risk.
Learn more: https://t.co/7Z1Wn8WBnZ
Seven years ago @benadida noticed @clever devolved chaos whenever we had an issue, and created a “flare” process to make sure we quickly triaged & carefully learned from issues.
1,383 flares later, the process is stronger than ever.
Read all about it: https://t.co/qFZax1rWFB
You have a vulnerability problem. You run a scanner. Now you have two problems - vulnerabilities and a mess of scanner results to process.
https://t.co/YruFm0I7PZ
Back in the day this used the original core Twitter SMS infrastructure. It led to issues where you could only use an phone number for a single account, you could send Tweets via 40404 after enrolling in 2FA, etc.
You have a #vulnerability problem. You run a scanner. Now you have two problems - vulnerabilities and a mess of scanner results to process. @alsmola, Director of Security @LaunchDarkly, shares a vulnerability management pipeline at #QConSF: https://t.co/pEyYeh2g0g
I have *always* been interested in how people change their minds. I think it started with my Dad's story - he was a conservative, religious Jew until he was 18, then he had an argument with a union activist on a picket line. 1/
This is why security teams should frame user-facing changes as:
"Check out this new way of doing x, y, and z - it will improve your life"
-instead of-
"You need to start doing x, y, and z - or else"
The world is easier to understand when you realize some people have high reactance - they just don’t like being told what to do & if they feel restricted by rules, they do the opposite.
If you make people high in reactance sign an agreement not to cheat, they actually cheat more
How we are meeting the challenge of enabling business velocity while also achieving security? Hear real advice from @JuliaaMarieee, @travismcpeak, Aditi Gupta, @alsmola & @nasthagiri.
🇺🇸 In-Person #QConSF: https://t.co/k2g4fUxV0j
🌎 Online #QConPlus: https://t.co/LIXcqxeBBx
Coolio played at my high school’s charity celebrity basketball game (MCed by Kato Kaelin) and headlined the party that bankrupted my college fraternity. I felt oddly connected to him. RIP.
Excited to run back the @LocoMocoSec talk we gave on Vulnerability Inbox Zero for the Practical Security track at @QConSF on October 26th! https://t.co/K4xauGztjv
@manicode Doesn't specify the domain of controls, which means you need to maintain your own mapping (e.g. cloud vs. endpoint vs. self-hosted servers - see https://t.co/b8DWK2ch1l)
A big compliance challenge is context. Asking that you "use strong passwords" or "encrypt all data" can apply to anything. The physical devices your employees use? The cloud resources of your product? Or the SaaS that glues everything together?