Uploaded June 2021 | Updated September 2026, 1 week ago
Apple is under fire on a number of fronts. The biggest issue this week is several bills introduced in the US. A key issue? The ability to "sideload" apps on your iPhone.
Is that safe? What's the downside? Learn more in this short...
References:
- The WSJ on the push in the US Congress and the EU, wsj.com/articles/apples-fight-for-control-over-apps-moves-to-congress-and-eu-11624440601?mod=searchresults_pos1&page=1
- Ars Technica interview with Tim Cook, arstechnica.com/gadgets/2021/06/apples-tim-cook-sideloading-is-not-in-the-best-interests-of-the-user
- My post on new privacy features from WWDC21, markn.ca/2021/privacy-at-wwdc21
Index:
- [0:00] Under pressure
- [0:10] What is sideloading?
- [0:22] App Store protections
- [0:44] The ecosystem
#shorts
Apple is under fire on a number of fronts. The biggest issue this week is several bills introduced in the US. A key issue? The ability to "sideload" apps on your iPhone.
Is that safe? What's the downside? Learn more in this short...
References:
- The WSJ on the push in the US Congress and the EU, wsj.com/articles/apples-fight-for-control-over-apps-moves-to-congress-and-eu-11624440601?mod=searchresults_pos1&page=1
- Ars Technica interview with Tim Cook, arstechnica.com/gadgets/2021/06/apples-tim-cook-sideloading-is-not-in-the-best-interests-of-the-user
- My post on new privacy features from WWDC21, markn.ca/2021/privacy-at-wwdc21
Index:
- [0:00] Under pressure
- [0:10] What is sideloading?
- [0:22] App Store protections
- [0:44] The ecosystem
#shorts

![Should Political Ads Be Allowed Back on Facebook? #shorts
Facebook is now allowing political ads back in the US. Is this a good move? Does a temporary ban do anything?
This short takes a look...
Index:
- The question [0:00]
- Pay-to-play [0:15]
- Echo chamber [0:35]
#shorts Should Political Ads Be Allowed Back on Facebook? #shorts](https://i.ytimg.com/vi/fFgDnNuOWIA/mqdefault.jpg)
![What You Need To Know About the Colonial Pipeline Attack #shorts
Colonial Pipeline is recovering from a ransomware cyberattack. With any attack that has this level of visibility theres a ton of assumptions and people leaping to conclusions...especially around attribution.
We dont have a lot of information about the attack. Thats completely normal at this stage.
The team at Colonial Pipeline is working through their incident response process. Attribution doesnt happen until the later stages of that process (if ever!) but a critical step is containment.
Thats what prompted the pipeline closure and—while difficult—its good that they took that step to reduce any potential damage.
Ransomware very often tries to encrypt any and all systems it can reach. Stopping the spread most likely saved the team an even bigger headache down the line
Learn more in this short
Index:
- [0:00] The attack
- [0:04] The response
- [0:31] Shutting down
- [0:41] #hugops What You Need To Know About the Colonial Pipeline Attack #shorts](https://i.ytimg.com/vi/fIvgfI7JU3E/mqdefault.jpg)



![Google Gathers FLoC of Privacy Bull💩 #shorts
Users are starting to revolt against third-party tracking cookies. Thats good. Google is responding to that pressure. Also good.
But is the technical solution to 3rd party cookies just as bad? Worse?
We explore the issue in this short...
Index:
- Privacy sandbox [0:00]
- FLoC [0:13]
- Cohorts [0:25]
#shorts Google Gathers FLoC of Privacy Bull💩 #shorts](https://i.ytimg.com/vi/gQpS7KqAwk8/mqdefault.jpg)
![Can We Improve How Lyft Handled Service Discovery on AWS In 2016? (Reaction)
In late 2016, Lyft did an AWS This is My Architecture video. It was one of the first. In the video they explained how they tackled the problem of discovering what microservices were available and healthy in their environment.
Now, a few years later, I react to that video and see whats stood the test of time, what could be done simpler given todays technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review.
The original video: https://youtu.be/sjpP2ynkCbo
More on the AWS Well-Architected Framework is at https://aws.amazon.com/architecture/well-architected/
Follow me on Twitter at https://twitter.com/marknca
Read my AWS Hero bio at https://aws.amazon.com/developer/community/heroes/mark-nunnikhoven/
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at https://markn.ca/courses/#mastering-the-well-architected-framework
Index:
- [00:00] Series intro
- [00:41] Problem statement
- [02:59] Service discovery intro
- [05:01] Request flow
- [06:46] Discovery service
- [08:45] Inter-service comms
- [11:45] Resiliency
- [14:10] Datastore choice
- [16:23] Review
- [16:55] Can we improve? Can We Improve How Lyft Handled Service Discovery on AWS In 2016? (Reaction)](https://i.ytimg.com/vi/gZm7YmRLaRc/mqdefault.jpg)


![Twitter Shows Slow MFA Adoption, Is Security Unusable? #shorts
Multi-factor authentication (MFA or 2FA) is a fantastic security control. It makes it a lot harder for attackers to gain access to your accounts.
So why isnt it used more? Lets explore in this short...
References:
- Twitter Transparency Report, https://transparency.twitter.com/en/reports/account-security.html#2020-jul-dec
- Coverage of the report by Bleeping Computer, Twitter reveals surprisingly low two-factor auth (2FA) adoption rate
https://www.bleepingcomputer.com/news/security/twitter-reveals-surprisingly-low-two-factor-auth-2fa-adoption-rate/
- Excellent discussion thread from Rachel Tobac, https://twitter.com/RachelTobac/status/1417984118810238976
Index:
- [0:00] MFA?
- [0:17] Twitters uptake data
- [0:31] Two problems
#shorts Twitter Shows Slow MFA Adoption, Is Security Unusable? #shorts](https://i.ytimg.com/vi/hRWtPkmLVm4/mqdefault.jpg)