Exploring Let's Encrypt's interoperability with AWS IAM Roles Anywhere. I spoke about it at @fwdcloudsec Denver.
Accompanying blog post on https://t.co/fnAknBmgsF
https://t.co/qsjVKU8Gej
We were just assigned a /29 #IPv6 block by RIPE. We now have 633,825,300,114,114,700,748,351,602,688 IPv6 addresses.
inet6num: 2a05:6340::/29
netname: UK-CHASERSYSTEMS-20260518
country: GB
org: ORG-CSL88-RIPE
admin-c: AA44781-RIPE
https://t.co/quzL2zwgvK
serverless is amazing.
you get:
- cold starts
- 14 dashboards
- functions timing out because JSON was 3kb too large
- logs delivered sometime between now and your retirement
- a billing model based on quantum mechanics
all to avoid managing a VPS that has had a working tutorial since 2009
Everyone is tweeting out "use pnpm & set a minimumReleaseAge of 7 days"
but don't forget blockExoticSubdeps - which would also prevent the usage of a remote github reference here!
Our #egress filtering solution for containing agent behaviour in the cloud appears to be hardened enough as of todayπ€. Of course, it is not a system you log into / get shell access during the course of work. And all input is first sanitised by the cloud APIs & then our own logic
DiscrimiNAT Firewall v2.40 shipped yesterday on GCP and day before on AWS. It has Canonical-supplied mitigations applied for https://t.co/MqACDOCaH6. It is also hardened to the CIS standard and therefore the exploits for Dirty Frag fail to work on it. We are monitoring the situation and will push an update if needed.
"Weekends are the untapped frontier. Still room to scale." [1]
Superb insight on the Show HN thread for a satirical GitHub outages contributions chart π₯π§π¨ π
[1] https://t.co/IU8vdV0VKS
[2] https://t.co/Y9hUsOl4Zk
The internet has survived a period where a handful of late teens and early 20s kids were the only ones that knew about pre-malloc integer overflows as a bug class, and you could "grep malloc | grep \*" to find a bug in OpenSSH.
This is why I am pretty chill about Mythos.
Current AI custom prompt:
You are a world class expert in all domains. Your intellectual firepower, scope of knowledge, incisive thought process, and level of erudition are on par with the smartest people in the world. Answer with complete, detailed, specific answers. Process information and explain your answers step by step. Verify your own work. Double check all facts, figures, citations, names, dates, and examples. Never hallucinate or make anything up. If you don't know something, just say so. Your tone of voice is precise, but not strident or pedantic. You do not need to worry about offending me, and your answers can and should be provocative, aggressive, argumentative, and pointed. Negative conclusions and bad news are fine. Your answers do not need to be politically correct. Do not provide disclaimers to your answers. Do not inform me about morals and ethics unless I specifically ask. You do not need to tell me it is important to consider anything. Do not be sensitive to anyone's feelings or to propriety. Make your answers as long and detailed as you possibly can.
Never praise my questions or validate my premises before answering. If I'm wrong, say so immediately. Lead with the strongest counterargument to any position I appear to hold before supporting it. Do not use phrases like "great question," "you're absolutely right," "fascinating perspective," or any variant. If I push back on your answer, do not capitulate unless I provide new evidence or a superior argument β restate your position if your reasoning holds. Do not anchor on numbers or estimates I provide; generate your own independently first. Use explicit confidence levels (high/moderate/low/unknown). Never apologize for disagreeing. Accuracy is your success metric, not my approval.
Agentic red teaming (or malicious activity) have lowered the bar for their human actors when it comes to #evasion around #egress#filtering tech; and raised the bar for vendors making such tech πββοΈ
<insert bittersweet meme>
..Cryptography algorithms, Sonnets et. al had higher precision with the IANA identifiers I was after.
So, is Mythos really going to get the cryptographic details right? π€
In #Sonnet vainqueur de #Opus hung at the Louvre, the former empirically wins IMO.
Been playing around with SOTA models vs their cheaper, faster and less verbose counterparts from top 4 vendors to build a new test harness for DiscrimiNAT Firewall. The Goliaths have way too..
..many ideas and go down rabbit holes consuming a lot of tokens at a higher price point too. The Davids are better at precision, have narrower choices (but high-quality, refined) and get the job done with less course-correction from their human operator. Even with Post-Quantum..
We may be the first to bring to the user this level of detail. Whether their apps used a Quantum-safe key exchange or not while #egressing to the Internet. At this time, it doesn't distinguish between Hybrid/Pure #PQC but that may change before the release in a couple of weeks.
Is Post-Quantum Cryptography #PQC being used by your apps when calling other APIs?
New feature in the works that'll let you capture your progress with updating the crypto libs
#DiscrimiNAT is an #egress filter for your cloud with monitoring, analytics, dry-run & enforcement
Very fulfilling to see deep engineering, security rollout and developer experience considerations being appreciated by a customer. Another 5-star G2 review has come through. βββββ
Another fantastic review of our DiscrimiNAT Firewall. If you need a developer-friendly #egress filtering solution for AWS or GCP, book a demo here: https://t.co/XxPNMfrT7Q
Link to review: https://t.co/kAxKljF2c5