Artwork

Content provided by Braxton Ehle and Sound Security. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Braxton Ehle and Sound Security or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Episode 26 - Too BLESSed to be Stressed

39:21
 
Share
 

Archived series ("Inactive feed" status)

When? This feed was archived on March 26, 2022 20:28 (2+ y ago). Last successful fetch was on August 24, 2019 01:53 (5y ago)

Why? Inactive feed status. Our servers were unable to retrieve a valid podcast feed for a sustained period.

What now? You might be able to find a more up-to-date version using the search function. This series will no longer be checked for updates. If you believe this to be in error, please check if the publisher's feed link below is valid and contact support to request the feed be restored or if you have any other concerns about this.

Manage episode 156050042 series 1175089
Content provided by Braxton Ehle and Sound Security. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Braxton Ehle and Sound Security or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Discussed Articles 1) How Netflix Gives All Its Engineers SSH Access To Instances Running In Production One of the ways Netflix enables engineering velocity is with a culture of 'freedom and responsibility' that empowers individuals with the freedom to do what is needed to get the job done. As a result, the security teams at Netflix focus on reducing developer friction, making it hard to do the wrong thing, and then rely on auditing, automated analysis, and alerting to keep things safe. Russell Lewis reviews a few approaches used in the industry to secure SSH bastions (aka jumpboxes) and evaluates them through the lens of Netflix’s security culture. * https://speakerdeck.com/rlewis/how-netflix-gives-all-its-engineers-ssh-access-to-instances-running-in-production * https://github.com/netflix/bless 2) Chrome Defaults To HTML5 Over Adobe Flash Starting in Q4 In which we discuss Google's continued efforts to kill off Flash and how long Google will continue to be a chaotic force for good on the Internet * https://threatpost.com/chrome-defaults-to-html5-over-adobe-flash-starting-in-q4/118109/ 3) Clearing up Some Misconceptions Around the 'ImageTragick' Bug A discussion of the underlying issues that lead to the impact of the ImageMagick vulnerabilities and whether it's always the right choice to rely on third-party modules for basic functionality. * https://lcamtuf.blogspot.nl/2016/05/clearing-up-some-misconceptions-around.html * https://github.com/oneuijs/You-Dont-Need-jQuery * http://www.theregister.co.uk/2016/03/23/npm_left_pad_chaos/ * https://github.com/rubysec/bundler-audit * https://jenssegers.com/63/automatically-check-your-composer-file-for-security-vulnerabilities * https://github.com/OSSIndex/DevAudit 4) Honorable Mention: 'Demonically Clever' Backdoor Hides In a Tiny Slice of a Computer Chip * https://www.wired.com/2016/06/demonically-clever-backdoor-hides-inside-computer-chip/ * https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf
  continue reading

32 episodes

Artwork
iconShare
 

Archived series ("Inactive feed" status)

When? This feed was archived on March 26, 2022 20:28 (2+ y ago). Last successful fetch was on August 24, 2019 01:53 (5y ago)

Why? Inactive feed status. Our servers were unable to retrieve a valid podcast feed for a sustained period.

What now? You might be able to find a more up-to-date version using the search function. This series will no longer be checked for updates. If you believe this to be in error, please check if the publisher's feed link below is valid and contact support to request the feed be restored or if you have any other concerns about this.

Manage episode 156050042 series 1175089
Content provided by Braxton Ehle and Sound Security. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Braxton Ehle and Sound Security or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Discussed Articles 1) How Netflix Gives All Its Engineers SSH Access To Instances Running In Production One of the ways Netflix enables engineering velocity is with a culture of 'freedom and responsibility' that empowers individuals with the freedom to do what is needed to get the job done. As a result, the security teams at Netflix focus on reducing developer friction, making it hard to do the wrong thing, and then rely on auditing, automated analysis, and alerting to keep things safe. Russell Lewis reviews a few approaches used in the industry to secure SSH bastions (aka jumpboxes) and evaluates them through the lens of Netflix’s security culture. * https://speakerdeck.com/rlewis/how-netflix-gives-all-its-engineers-ssh-access-to-instances-running-in-production * https://github.com/netflix/bless 2) Chrome Defaults To HTML5 Over Adobe Flash Starting in Q4 In which we discuss Google's continued efforts to kill off Flash and how long Google will continue to be a chaotic force for good on the Internet * https://threatpost.com/chrome-defaults-to-html5-over-adobe-flash-starting-in-q4/118109/ 3) Clearing up Some Misconceptions Around the 'ImageTragick' Bug A discussion of the underlying issues that lead to the impact of the ImageMagick vulnerabilities and whether it's always the right choice to rely on third-party modules for basic functionality. * https://lcamtuf.blogspot.nl/2016/05/clearing-up-some-misconceptions-around.html * https://github.com/oneuijs/You-Dont-Need-jQuery * http://www.theregister.co.uk/2016/03/23/npm_left_pad_chaos/ * https://github.com/rubysec/bundler-audit * https://jenssegers.com/63/automatically-check-your-composer-file-for-security-vulnerabilities * https://github.com/OSSIndex/DevAudit 4) Honorable Mention: 'Demonically Clever' Backdoor Hides In a Tiny Slice of a Computer Chip * https://www.wired.com/2016/06/demonically-clever-backdoor-hides-inside-computer-chip/ * https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf
  continue reading

32 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide