Security, hax0ry, Cloud, DevSecOps or whatever the cool kids are calling it these days. Anything posted does not reflect the views or opinions of my employer.
I’m super biased, but that’s a great looking flask!
Every year, we send all our customers a little gift from @ThinkstCanary - because... we can, and want to say thanks.
This year, it’s the Rambler from @YETICoolers
Come help us keep Cash App's ecosystem of financial services and our Customers' money safe!
We're the Cash Security team and we're redefining how security works with the rest of the organization. We spend 80% of our time writing code and 20% teaching how to think about security.
The “conventional wisdom” on Apple for the past decade is that they needed to enter completely new markets to grow. As the world’s first $2T company, it turns out continuing to build better and better products and services works just fine.
U2F + Context Aware Access + Advanced Protection + Default-Deny App Exec is overpowered.
Can't oauth phish
Can't phish mfa
Can't exec malware on the box to steal a session
As far as I can tell an attacker needs a full exploit chain/RCE+Privesc during an active session.
There are many lessons that SaaS and software providers can take from @ThinkstCanary, but if you take two, make it these:
- There’s no substitute for this kind of transparency in garnering trust
- Smart security engineering addresses constraints well!
Max wrote up a quick blog post discussing our internal "broker" (which we place between our own servers and 3rd party API's).
It's worth a quick skim, and its worth pondering if you have (or need) something similar in your org.
https://t.co/png0trhkv0