Often I see the top expenses are SIEM and CSPM.
No reason why Prisma/Wiz need to be this expensive, & should eventually be replaced.
But if you take Splunk away from me I quit. I don’t love it but I do not want to deal with replacing it.
Adobe Acrobat Pro costs $239/year.
Someone open-sourced a full PDF suite with 50+ tools. Merge, split, sign, redact, OCR, compress, convert, everything Acrobat charges for.
Runs 100% locally. Your files never leave your machine.
78k stars. 100% open source
My CISO called me at 3 AM last Tuesday.
"We caught someone."
I asked, "Caught them doing what?"
He said, "Typing."
Let me explain.
We have an employee in IT. Great worker. Always online. Never complained. Perfect Slack etiquette.
One problem.
His keystrokes were arriving 110 milliseconds late.
One hundred and ten milliseconds.
That's 0.11 seconds.
The average American remote worker has 20-40ms of latency.
This guy? 110ms. Every. Single. Keystroke.
My security team ran the numbers.
That latency doesn't come from a bad router in Ohio.
That latency comes from Pyongyang.
Our "Senior DevOps Engineer" was a North Korean operative.
Running his work laptop through a laptop farm.
In America.
While he worked from a government building.
In North Korea.
He passed the interview. He passed the background check. He passed the vibe check.
He did not pass the speed of light.
Here's what people don't understand about physics:
Light travels 186,000 miles per second.
But it still has to go through China.
And China adds latency.
Since April, Amazon has caught 1,800 of these attempts.
Eighteen hundred.
I called an emergency meeting with my board.
I said, "We need to implement Keystroke Velocity Auditing across all remote employees."
They said, "That sounds invasive."
I said, "You know what else is invasive? The Democratic People's Republic of Korea in your Jira tickets."
They approved the budget.
We now monitor keystroke timing to the microsecond.
If your latency exceeds 60ms, you get a call from HR.
If it exceeds 100ms, you get a call from the FBI.
We've already flagged 47 employees.
Turns out 44 of them just have bad Wi-Fi.
3 of them are "still under investigation."
The lesson?
You can fake a resume.
You can fake a background check.
You can fake an American accent on Zoom.
But you cannot fake the speed of light.
Physics is the ultimate background check.
Hire accordingly.
we built DeepWiki, a free encyclopedia of all GitHub repos
some numbers:
- 30k repos already indexed
- processed 4 billion+ lines of code
- the indexing alone cost $300k+ in compute spend
A bug in Cloudflare (and just the nature of how CDNs work) let an attacker learn the broad location of Discord, Signal, Twitter users by just sending them an image, according to a researcher. It works because you check which data center cached the image https://t.co/4rs3pUIeNK
"Top 50 Techniques & Procedures"
https://t.co/fPDez3dryo
Real world malware delivery and initial access techniques (red teaming). Good source of inspiration.
Excited to share my new project: AttackRuleMap
This project maps #AtomicRedTeam simulations to open-source detection rules like #SigmaRules and #Splunk ESCU rules (maybe more in the future).
Currently for Windows, with plans to support more platforms.
https://t.co/O52271h4BW
I found the GitHub repo "A Compiler Writing Journey" and was glad to see the compiler building from the ground up - documented with each step in detail.
For any compiler enthusiast, these steps provide valuable insights worth sharing.
Checkmate: An open-source tool for monitoring server uptime, performance, and infrastructure, with features like website and Docker monitoring, and real-time alerts
Announcing llama-ocr – a free + open source OCR tool!
It takes documents (images for now) & outputs markdown, and does really well for complex receipts, PDFs with tables/charts, ect...
Powered by Llama 3.2 vision on @togethercompute & available on npm today!