Tag: Security and privacy
-
Securing Kafka infrastructure at Uber
Posted on June 27, 2022, Level intermediate Resource Length medium
Uber has one of the largest deployments of Apache Kafka® in the world. It empowers a large number of real-time workflows at Uber, including pub-sub message buses for passing event data from the rider and driver apps, as well as financial transaction events between the backend services. By Prateek Agarwal, Ryan Turner, and KK Sriramadhesikan.
Tags architecture-and-apis security-and-privacy devops-and-ci-cd software-engineering data-and-analytics
-
Automating AWS IAM remediation in Python
Posted on June 20, 2022, Level advanced Resource Length long
Since automating IAM remediation requires recurring parsing of JSON documents, modulating your parsing function(s) will save you time as you work on each control. If you have controls that pertain to trust policies, you will need a separate function to parse those out since the format differs from that of permission policies. By Cody Bench.
Tags backend-development product-and-design security-and-privacy software-engineering leadership-and-career
-
IAM policy types: How and when to use them
Posted on June 3, 2022, Level beginner Resource Length long
You manage access in AWS by creating policies and attaching them to AWS Identity and Access Management (IAM) principals (roles, users, or groups of users) or AWS resources. AWS evaluates these policies when an IAM principal makes a request, such as uploading an object to an Amazon Simple Storage Service (Amazon S3) bucket. Permissions in the policies determine whether the request is allowed or denied. By Matt Luttrell and Josh Joy.
Tags security-and-privacy leadership-and-career
-
Secure communication with light particles
Posted on May 25, 2022, Level beginner Resource Length long
Researchers are developing an anti-eavesdropping quantum network. By Technische Universitat Darmstadt.
Tags miscellaneous leadership-and-career data-and-analytics cloud-and-infrastructure security-and-privacy
-
How a Man-in-the-Middle attack works
Posted on May 22, 2022, Level beginner Resource Length medium
Man-in-the-middle (or MitM) attacks can occur when an attacker has the ability to intercept communications over the network. This allows the attacker to read -- and potentially modify -- these communications. By Rob Behnke.
Tags security-and-privacy cloud-and-infrastructure frontend-and-mobile product-and-design
-
Demand for cybersecurity skills rises as quantum computing threats tighten
Posted on May 19, 2022, Level beginner Resource Length short
There is a major shortage of cybersecurity professionals, with the equivalent of a major city worth of workers missing from the workforce. (ISC)2, the world's largest professional organization for cybersecurity workers, estimates in the paper linked above that the cybersecurity workforce will have to increase by 65% to meet demand. By Nils Gerhardt.
Tags miscellaneous leadership-and-career security-and-privacy
-
What exactly should we be logging?
Posted on May 15, 2022, Level intermediate Resource Length medium
As a security architect and the technical leader for the Logging Made Easy project, I am often asked "what logs should I be collecting?" I absolutely hate the standard 'it depends' response. So, I've been answering with a question of my own: "For what?" This has led to a number of interesting discussions on the topic of who should be logging what, and when. By Adam B.
Tags security-and-privacy devops-and-ci-cd software-engineering leadership-and-career how-to
-
Your complete guide to SSL/TLS and HTTPS
Posted on May 10, 2022, Level beginner Resource Length medium
Between the ever-increasing global cybersecurity threats and Google's tightening security standards, it's more important than ever for business owners to take active measures to safeguard their sites. Otherwise, you're putting both yourself and your customers at risk. Not good. By David Wahlstrom.
Tags security-and-privacy how-to cloud-and-infrastructure leadership-and-career
-
Rapid event notification system at Netflix
Posted on May 3, 2022, Level intermediate Resource Length medium
Netflix has more than 220 million active members who perform a variety of actions throughout each session, ranging from renaming a profile to watching a title. Reacting to these actions in near real-time to keep the experience consistent across devices is critical for ensuring an optimal member experience. By Ankush Gulati, David Gevorkyan.
Tags data-and-analytics devops-and-ci-cd security-and-privacy
-
Increasing the security bar in Ingress-NGINX v1.2.0
Posted on May 2, 2022, Level intermediate Resource Length medium
The Ingress may be one of the most targeted components of Kubernetes. An Ingress typically defines an HTTP reverse proxy, exposed to the Internet, containing multiple websites, and with some privileged access to Kubernetes API (such as to read Secrets relating to TLS certificates and their private keys). By Ricardo Katz (VMware), James Strong (Chainguard).
Tags devops-and-ci-cd security-and-privacy
-
MySQL 8: Password verification policy
Posted on April 28, 2022, Level intermediate Resource Length medium
The artcicle discusses the password verification-required policy introduced in MySQL 8.0.13. With this feature, it is possible to require that attempts to change an account password be verified by specifying the existing current password to be replaced. By Brian Sumpter.
Tags backend-development data-and-analytics leadership-and-career security-and-privacy devops-and-ci-cd
-
How to automate security metrics without upsetting your colleagues
Posted on April 12, 2022, Level beginner Resource Length short
The need for greater automation in security metrics and measurement is clear to most people in our industry. Security teams have the luxury of access to an enormous amount of security data, giving insight into every aspect of their environments. By Nik Whitfield.
Tags security-and-privacy leadership-and-career miscellaneous data-and-analytics