Checkout this #offsec Sr. engineer role if you are interested in proactively identifying vulns and weaknesses in AI infra - a full stack cutting edge platform -- DC/CSPs, FW ,OS , NW, Storage, K8S, WebApps, #AIModels#securityjob#offsecjob#Pentesting
tls-scan
An Internet scale, blazing fast SSL/TLS scanner ( non-blocking, event-driven )
A program to scan TLS based servers and collect X.509 certificates, ciphers and related information. It produces results in JSON format. tls-scan is a single thre… https://t.co/FXf9YALoJT
This feature can now keep the remote sudo two-factor authentication (TouchID, FIDO/U2F) more secure! https://t.co/Z3Hb3jXSWg
#pam-ssh-agent-auth #security#touch2sudo
#OpenSSH 8.2 https://t.co/4iBG27tLvF This is something I've been waiting for long time - "allow forwarding a different agent socket to the path
specified by $SSH_AUTH_SOCK" - Now by using a different ssh-agent, we can selectively expose keys to remote hosts (for sudo auth)
@tqbf An alternative option is to use SSH keys to establish end to end secure tunnel and pass what ever you want, but both parties should be online for that to work. Here is one implementation: https://t.co/HOJ9fIn9z8
@SwiftOnSecurity @CiPHPerCoder It is super inconvenient for devs to maintain PGP keys just to encrypt something that occurs rarely. I prefer SSH keys for this purpose as engineers have that handy. If the intent is to share secrets between users/systems, check out this design & tool https://t.co/HOJ9fIn9z8
Shall your secrets remain secrets!
Do your team resort to (#insecure) email/slack/IM to share sensitive key materials?
Have you tried #GPG?
Check out https://t.co/HOJ9fIn9z8 - A #secure, usable middle ground option, that relies on #SSH keys to share secrets with your co-workers!
Super proud of the @gmail team for launching MTA-STS today. We started this standard way back in 2015 as a way to ensure nation states and telcos can't strip encryption off of email, following the analysis from @zakirbpd et al. https://t.co/tiTzQWb31P