marknca
Zoom.us & The Real Cybersecurity Problem
updated
But, what I find interesting is that these types of features aren't "flashy" enough to make a big launch or announcement. While the original blog post is solid and explains the functionality, how can we—the larger community, not just AWS—better advocate for and promote these features?
If people aren't using them, wouldn't it make more sense just to remove them from the codebase?
#shorts
The library recently reported a major security vulnerability. That has teams scrambled to contain the issue and fix the problem.
That requires a lot of heavy lifting by teams to figure out WHERE log4j is and then to actually FIX the problem.
If you're interested in the technical details, check out:
- From the log4j project, logging.apache.org/log4j/2.x/security.html
- CRN on some of the applications affected, crn.com/slide-shows/security/10-technology-vendors-affected-by-the-log4j-vulnerability
- Wired on the long term impacts of the issue, wired.com/story/log4j-log4shell
Now, a few years later, I react to that video and see what's stood the test of time, what could be done simpler given today's technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review.
The original video: youtu.be/g0M0PN2bFFA
More on the AWS Well-Architected Framework is at https://aws.amazon.com/architecture/w...
Follow me on Twitter at twitter.com/marknca
Read my AWS Hero bio at https://aws.amazon.com/developer/comm...
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at markn.ca/courses/#mastering-the-well-architected-framework
Now, a few years later, I react to that video and see what's stood the test of time, what could be done simpler given today's technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review.
The original video: youtu.be/g0M0PN2bFFA
More on the AWS Well-Architected Framework is at https://aws.amazon.com/architecture/w...
Follow me on Twitter at twitter.com/marknca
Read my AWS Hero bio at https://aws.amazon.com/developer/comm...
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at markn.ca/courses/#mastering-the-well-architected-framework
I walk you through the highlights of the Lens and explain the key areas of concern for these types of designs.
This lesson on the Streaming Media Lens is part of my course on the entire framework. That course is over 4 hours in length and help you understand the value of the framework and how to use it to build a success cloud team.
Mastering The AWS Well-Architected Framework on A Cloud Guru: https://acloud.guru/learn/aws-well-architected-framework
The AWS Well-Architected Framework: docs.aws.amazon.com/wellarchitected
The Streaming Media Lens: docs.aws.amazon.com/wellarchitected/latest/streaming-media-lens/streaming-media-lens.html
Follow Mark on Twitter: twitter.com/marknca
More great content at: markn.ca
We see how to set it up, how to ensure that your EC2 instances and ECR registries are being inspected, and how to handle a vulnerability finding.
Vulnerability management is a critical information security process and one that'll help shut the door on hackers and cybercriminals. This service is strong addition to your cybersecurity toolkit.
Follow Mark on Twitter at twitter.com/marknca
Learn more about what happened at AWS re:Invent 2021 at markn.ca/2021/reinvent
This service connects robots from multiple vendors using a unified data plane and allowing your to create complex applications that span your entire fleet of robots.
More in this short.
Follow my AWS re:Invent 2021 coverage markn.ca/2021/aws-reinvent
Follow me on Twitter at twitter.com/marknca
#short
Now, a few years later, I react to that video and see what's stood the test of time, what could be done simpler given today's technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review.
The original video: youtu.be/sMP2LsgtGQM
More on the AWS Well-Architected Framework is at https://aws.amazon.com/architecture/w...
Follow me on Twitter at twitter.com/marknca
Read my AWS Hero bio at https://aws.amazon.com/developer/comm...
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at markn.ca/courses/#mastering-the-well-architected-framework
Now, a few years later, I react to that video and see what's stood the test of time, what could be done simpler given today's technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review.
The original video: youtu.be/S9gbsfGaJ_c
More on the AWS Well-Architected Framework is at https://aws.amazon.com/architecture/w...
Follow me on Twitter at twitter.com/marknca
Find me online at markn.ca
Read my AWS Hero bio at https://aws.amazon.com/developer/comm...
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at markn.ca/courses/#mastering-the-well-architected-framework
Now DevSecOps is a thing...isn't it? Security is a huge concern of everyone. No one really debates that. The debate is how to improve security overall.
In this video, we look at the biggest mistake security teams make when trying to get involved in modern development with DevSecOps.
Find me on Twitter 🐦 at twitter.com/marknca
Find me on the web 🌍 at markn.ca
Now, a few years later, I react to that video and see what's stood the test of time, what could be done simpler given today's technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review...at least I would normally.
This "This is My Architecture" video was a bit different in that it really just highlighted a fantastic new (at the time) open source project. That project has grown over the years and is a very strong tool that can help you apply smart policies in your AWS environment.
The original video: youtu.be/7psvM3r_wCg
More on the AWS Well-Architected Framework is at https://aws.amazon.com/architecture/w...
Follow me on Twitter at twitter.com/marknca
Read my AWS Hero bio at https://aws.amazon.com/developer/comm...
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at markn.ca/courses/#mastering-the-well-architected-framework
Now, a few years later, I react to that video and see what's stood the test of time, what could be done simpler given today's technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review.
The original video: youtu.be/VcSQu-bca-M
More on the AWS Well-Architected Framework is at https://aws.amazon.com/architecture/w...
Follow me on Twitter at twitter.com/marknca
Read my AWS Hero bio at https://aws.amazon.com/developer/comm...
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at https://markn.ca/courses/#mastering-t...
Index:
- [00:00] Intro
- [00:34] Introductions
- [01:15] Problem statement
- [02:32] New team
- [04:20] Folder structure
- [05:56] Centralized rules
- [07:20] Deployment privileges
- [09:38] Approval process
- [10:27] Reducing red tape
- [12:24] Can we improve?
Now, a few years later, I react to that video and see what's stood the test of time, what could be done simpler given today's technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review.
The original video: youtu.be/s9y_TeEfs10
More on the AWS Well-Architected Framework is at https://aws.amazon.com/architecture/w...
Follow me on Twitter at twitter.com/marknca
Read my AWS Hero bio at https://aws.amazon.com/developer/comm...
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at https://markn.ca/courses/#mastering-t...
Index:
- [00:00] Intro
- [00:27] Introductions
- [01:15] Problem statement
- [03:43] Segmentation
- [05:21] Device events
- [08:19] Aligning to users
- [10:36] Tuning data for write
- [12:55] Can we improve?
In this video, we'll explore why passwords are hard to manage, what cybersecurity myths are holding us back, how hackers attack passwords, and how to make passwords that are actually strong and usable at the same time!
Index:
- [00:00] Intro
- [00:21] Password Math
- [01:11] Memory Failures
- [02:07] Hackers
- [03:53] Using Our Advantage
- [05:13] Holding Us Back
- [05:59] 2FA & MFA
- [06:39] Too Many Passwords
- [08:18] Putting It All Together
Now, a few years later, I react to that video and see what's stood the test of time, what could be done simpler given today's technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review.
The original video: youtu.be/-S5gs8AGKCw
More on the AWS Well-Architected Framework is at aws.amazon.com/architecture/well-architected
Follow me on Twitter at twitter.com/marknca
Read my AWS Hero bio at aws.amazon.com/developer/community/heroes/mark-nunnikhoven
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at markn.ca/courses/#mastering-the-well-architected-framework
Index:
- [00:00] Intro
- [00:40] Problem statement
- [01:30] Batch processing
- [02:26] AWS services used
- [03:36] Data isolation
- [04:42] EMR limitations
- [06:21] Predictive analytics
- [07:21] Improvements?
- [16:23] Review
- [16:55] Can we improve?
This is a tricky area because builders are usually focused on making sure their solution works first, then they look to performance. Cost is usually way, way down the list. If it even makes the list.
The solution the Financial Times came up with is quite clever and delivered results quickly for them.
Now, a few years later, I react to that video and see what's stood the test of time, what could be done simpler given today's technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review.
The original video: youtu.be/beN1m9AOsQ0
More on the AWS Well-Architected Framework is at aws.amazon.com/architecture/well-architected
Follow me on Twitter at twitter.com/marknca
Read my AWS Hero bio at aws.amazon.com/developer/community/heroes/mark-nunnikhoven
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at markn.ca/courses/#mastering-the-well-architected-framework
Index:
- [00:00] Intro
- [00:41] Financial Times intro
- [01:04] Problem statement
- [02:19] Feedback loop
- [03:20] Simple workflow
- [05:42] Serverless solution
- [06:30] Specific goals
- [07:20] Incentives
- [08:50] Staying current
- [09:40] Can we improve?
In this stream, we're going to build another tiny cloud project. This time, it's a quick command line tool to take an audio or video file, send it to the Google Cloud, and get a detailed text transcription back.
(* Also super useful for subtitles! )
It does not appear (at the time of publication) that any user data was leaked.
What will the impact be? Will this cause even more streamers to leave? Learn more in this short...
References:
- Twitch hack: source code and creator payouts part of massive leak - The Verge, theverge.com/2021/10/6/22712250/twitch-hack-leak-data-streamer-revenue-steam-competitor
- All the Big Streamers That Have Left Twitch for YouTube, gamerant.com/twitch-big-streamers-left-youtube-drlupo-timthetatman
- Twitch's response on Twitter, twitter.com/Twitch/status/1445770441176469512
Index:
- [0:00] Breached
- [0:11] Source leaked
- [0:20] #hugops
- [0:33] The real problem
#shorts
Specifically, they drilled down on a clever use of DNS records to create a very flexible system that allows services to continue in the event of some pretty significant disaster.
Few companies operate at Netflix's scale (even their scale back then) but this technique is broadly applicable for any team that needs to failover in the event of either disaster or even a simple failure.
Now, a few years later, I react to that video and see what's stood the test of time, what could be done simpler given today's technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review.
The original video: youtu.be/WDDkLOT8SCk
More on the AWS Well-Architected Framework is at aws.amazon.com/architecture/well-architected
Follow me on Twitter at twitter.com/marknca
Read my AWS Hero bio at aws.amazon.com/developer/community/heroes/mark-nunnikhoven
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at markn.ca/courses/#mastering-the-well-architected-framework
Index:
- [00:00] Intro
- [00:24] Problem statement
- [02:10] Evacuating a region
- [03:10] Geo-routing
- [04:39] Intelligent failover
- [06:11] How a failover works
- [07:26] Record choice
- [08:13] Restoration
- [09:10] Tracking state
- [10:03] Can we improve?
Now, a few years later, I react to that video and see what's stood the test of time, what could be done simpler given today's technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review.
The original video: youtu.be/sjpP2ynkCbo
More on the AWS Well-Architected Framework is at aws.amazon.com/architecture/well-architected
Follow me on Twitter at twitter.com/marknca
Read my AWS Hero bio at aws.amazon.com/developer/community/heroes/mark-nunnikhoven
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at markn.ca/courses/#mastering-the-well-architected-framework
Index:
- [00:00] Series intro
- [00:41] Problem statement
- [02:59] Service discovery intro
- [05:01] Request flow
- [06:46] Discovery service
- [08:45] Inter-service comms
- [11:45] Resiliency
- [14:10] Datastore choice
- [16:23] Review
- [16:55] Can we improve?
This is a handy feature that I'd like on my Mac as well. But it's not out yet, so let's have some fun and build a little tool to do the same thing!
We're going to using a couple of Google Cloud services to build out a simple command line application that takes an image file and returns any text inside.
In the first step, we narrowed the options down to Amazon DynamoDB, Azure CosmosDB, and Google Firestore. You can watch that at youtu.be/hiTuasfMk8c.
In this second step, I'm working my way through the docs to get a sense of how each of these services work. Will they be a good fit for me? Lots of work before even the first line of code is written but it's important to do this before committing to a path.
During this livestream, I walk through my thought process and share it with you.
Index:
- [00:00] The set up
- [03:47] Google Firestore
- [12:43] Azure Cosmos DB
- [18:36] Amazon DynamoDB
- [23:17] Conclusion
In this first step, I'm making what is probably the most important architectural decision: the database powering everything.
I know I want a serverless design but how do I pick the best database for this project?
During this livestream, I walk through my thought process and share it with you.
Index
- [00:00] Hey!
- [03:05] Problem statement
- [07:10] Google Cloud
- [12:24] Azure
- [17:39] AWS
- [28:30] What's next?
They were showing—again—how AWS treats security internally. It's a fascinating look, not at the technical aspects of security, but at how a security practice should be setup organizationally and the tenets that drive it.
This is not only how cloud security practices should be setup, but ALL security practices.
Index:
- [00:00] Traditional security teams
- [00:32] AWS re:Inforce 2021
- [01:37] Since 2017...
- [02:36] Distributed knowledge
- [03:45] One simple truth
- [04:18] Some centralization
- [05:14] A practice explained
Learn more in this short...
References:
- coverage from TheRecord, "Microsoft announces new 'Super Duper Secure Mode' for Edge
, https://therecord.media/microsoft-announces-new-super-duper-secure-mode-for-edge/
- the research note from the team, "Super Duper Secure Mode", microsoftedge.github.io/edgevr/posts/Super-Duper-Secure-Mode
- more on the V8 (JavaScript engine) from Wikipedia, en.wikipedia.org/wiki/V8_(JavaScript_engine)
Index:
- [0:00] The experiment
- [0:12] Why?
- [0:33] Computing platform
#shorts
At the same time, we see a new ransomware supergroup called BlackMatter emerge with a pledge not to attack critical infrastructure like this.
What does this mean for ransomware? For you?
More in this short...
Index:
- [0:00] Lazio attack
- [0:16] Risky move
- [0:26] BlackMatter supergroup
- [0:42] Profit
#shorts
More in this short...
Index:
- [0:00] The hack
- [0:20] Risk analysis
- [0:35] Data
#shorts
So why isn't it used more? Let's explore in this short...
References:
- Twitter Transparency Report, transparency.twitter.com/en/reports/account-security.html#2020-jul-dec
- Coverage of the report by Bleeping Computer, "Twitter reveals surprisingly low two-factor auth (2FA) adoption rate"
bleepingcomputer.com/news/security/twitter-reveals-surprisingly-low-two-factor-auth-2fa-adoption-rate
- Excellent discussion thread from Rachel Tobac, twitter.com/RachelTobac/status/1417984118810238976
Index:
- [0:00] MFA?
- [0:17] Twitter's uptake data
- [0:31] Two problems
#shorts
Learn more in this short...
References:
- from the Washington Post, "Takeaways from the Pegasus Project", washingtonpost.com/investigations/2021/07/18/takeaways-nso-pegasus-project
- also from the Washington Post, "Private Israeli spyware used to hack cellphones of journalists, activists worldwide", washingtonpost.com/investigations/interactive/2021/nso-spyware-pegasus-cellphones
- The Guardian's coverage, "The Pegasus project", theguardian.com/news/series/pegasus-project
- from PBS, "THE PEGASUS PROJECT Live Blog: Major Stories from Partners", pbs.org/wgbh/frontline/article/the-pegasus-project-live-blog-major-stories-from-partners
- Amnesty International with, "Pegasus Project: Apple iPhones compromised by NSO spyware", amnesty.org/en/latest/news/2021/07/pegasus-project-apple-iphones-compromised-by-nso-spyware
- "Independent Peer Review of Amnesty International's Forensic Methods for Identifying Pegasus Spyware - The Citizen Lab", citizenlab.ca/2021/07/amnesty-peer-review
- "Apple Now Has Over 1 Billion Active iPhones Worldwide, 1.65 Billion Total Devices", macrumors.com/2021/01/27/apple-active-devices-worldwide-january-2021
Index:
- [0:00] The Pegasus Project
- [0:16] Nation states
- [0:28] Security research
#shorts
More in this short...
References:
- "Biden’s Cybersecurity Team Gets Crowded at the Top", from Wired, wired.com/story/biden-cybersecurity-inglis-easterly-cisa-nsa
- Garrett M. Graff on Twitter, twitter.com/vermontgmg
Index:
- [0:00] New US appointments
- [0:11] Primer
- [0:20] Too many leaders?
- [0:35] Culture change
#shorts
StopRansomware.gov collects resources for individuals and business trying to prevent ransomware and those impacted by an attack.
RansomWhe.re tracks payments made to ransomware cryptocurrency wallets.
Learn more in this short...
References:
- https://StopRansomware.gov from the US federal government
- https://RansomWhe.re from the Krebs Stamos Group
- Coverage of the US government site launch, "$10 million rewards bolster White House anti-ransomware bid", apnews.com/article/technology-joe-biden-europe-business-government-and-politics-cd21d84b5fd070421f871610b40e91d0
- "Ransomwhere" project tracks payment demands, finance.yahoo.com/finance/news/ransomwhere-project-tracks-payment-demands-132133459.html
Index:
- [0:00] 2 New Resources
- [0:06] StopRansomware.gov
- [0:24] RansomWhe.re
#shorts
More in this short...
References:
- Tweet from Lawrence Abrams, twitter.com/LawrenceAbrams/status/1414929050729074714?s=20
- Kevin Beaumont on the issue, twitter.com/GossiTheDog/status/1414947622633279493?s=20
- Coverage from the NY Times, nytimes.com/2021/07/13/us/politics/russia-hacking-ransomware-revil.html
- Bank Info Security on the list of Kaseya victims, bankinfosecurity.com/list-victims-kaseya-ransomware-attack-grows-a-17013
- The Avaddon shutdown where keys were made available, bleepingcomputer.com/news/security/avaddon-ransomware-shuts-down-and-releases-decryption-keys
Index:
- [0:00] ⏰
- [0:09] Gone for good?
- [0:17] Keys
- [0:29] Why?
- [0:43] 🔦
#shorts
More in this short...
References:
- "Ransomware Costs Double in Q4 as Ryuk Sodinokibi Proliferate" by Coveware, coveware.com/blog/2020/1/22/ransomware-costs-double-in-q4-as-ryuk-sodinokibi-proliferate
- Ransomware Report: Sophos State of Ransomware Report 2021, secure2.sophos.com/en-us/content/state-of-ransomware.aspx
-- Cybereason, "Report: Ransomware Attacks and the True Cost to Business", cybereason.com/blog/report-ransomware-attacks-and-the-true-cost-to-business
- Kevin Beaumont (@GossiTheDog) on Twitter, twitter.com/gossithedog/status/1414549083495272453?s=21
Index:
- [0:00] Kaseya
- [0:10] Back to normal?
- [0:32] Continued risk
- [0:42] Long road
#shorts
Hackers can still easily use this to run their code on your systems if you're using a feature called "Point and Print" (and a lot of people are). Where does that leave defenders?
More in this short...
References:
- Brian Krebs has a post on the out-of-band patch; "Microsoft Issues Emergency Patch for Windows Flaw", krebsonsecurity.com/2021/07/microsoft-issues-emergency-patch-for-windows-flaw
- From BleepingComputer, "Microsoft's incomplete PrintNightmare patch fails to fix vulnerability", bleepingcomputer.com/news/microsoft/microsofts-incomplete-printnightmare-patch-fails-to-fix-vulnerability
- Security Update Guide from the Microsoft Security Response Center, msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
- "Introduction to Point and Print - Windows drivers" from the Microsoft docs, docs.microsoft.com/en-us/windows-hardware/drivers/print/introduction-to-point-and-print
Index:
- [0:00] The vulnerability
- [0:17] Point and Print
- [0:29] Make a choice
#shorts
Unique occurrence or the new normal?
More in this short...
Index:
- [0:00] Profit
- [0:12] Land & expand
- [0:30] The supply chain
- [0:41] Reinvest
#shorts
Is there any way to stop these hacks? Can we trace the money hackers are making? Why is ransomware so effective? Just how big is the the criminal underground running these schemes?
This video essay gives you an overview of the crime, the technical details, the challenges in fighting, and more.
All of the references cited in the video are available at markn.ca/2021/ransomware
Follow me on social:
- 🐦 Twitter: twitter.com/marknca
- 👔 LinkedIn: linkedin.com/in/marknca
- 👩💻 Web: https://marknca
Index:
- [00:00] What is ransomware?
- [00:25] How big is the problem?
- [03:37] How does it work?
- [05:31] The technical side
- [07:36] Changes over time
- [09:29] Who is doing this?
- [11:50] How are reacting?
- [13:12] What are companies doing?
- [17:15] Can companies recover?
- [17:32] ??? Should you pay ???
- [19:37] What's next?
The really sneaky part? Other than stealing your log in, these apps worked!
More in this short...
References:
- Dan Goodin writing for Ars Technica on the issue, arstechnica.com/gadgets/2021/07/google-boots-google-play-apps-for-stealing-users-facebook-passwords
- the Facebook helps docs on removing 3rd party connections, facebook.com/help/170585223002660
Index:
- [0:00] Sneaky apps
- [0:15] Remove ads
- [0:30] Disconnect apps from Facebook
#shorts
Learn more about what's going on in this short...
References:
- Coverage from The Verge, theverge.com/2021/7/2/22560435/microsoft-printnightmare-windows-print-spooler-service-vulnerability-exploit-0-day
- The Record with a great overview https://therecord.media/poc-released-for-dangerous-windows-printnightmare-bug/
- The vulnerability details, nvd.nist.gov/vuln/detail/CVE-2021-1675
Index:
- [0:00] PrinterNightmare
- [0:08] The spooler
- [0:26] Whoops
- [0:34] What you can do about it
#shorts
One of those updates may stall adoption though. Lear more in this short...
References:
- Microsoft's Windows 11 page, microsoft.com/en-us/windows/windows-11
- The Verge on the TPM requirement, theverge.com/2021/6/25/22550376/microsoft-windows-11-tpm-chips-requirement-security
- More on the update experience from Microsoft, blogs.windows.com/windowsexperience/2021/06/24/introducing-windows-11
- DWIZZLE with a summary of what TPMs enable on Windows, twitter.com/dwizzzlemsft/status/1408509390563405826?s=21
Index:
- [0:00] Windows 11
- [0:10] Upgrade requirements
- [0:23] What is a TPM?
- [0:39] A welcome security push
#shorts
There is a remote code execution vulnerability (a/k/a the attack can run programs on your device) in these out of support devices.
What does this mean for your backup? Learn more in this short.
References:
- WD's support article, westerndigital.com/support/productsecurity/wdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduo
- Ars Technica on the issue, arstechnica.com/gadgets/2021/06/mass-data-wipe-in-my-book-devices-prompts-warning-from-western-digital
- Verge's coverage, theverge.com/2021/6/24/22549677/wd-my-book-live-data-deletion-unplug-lan-cable-threat-actor
Index:
- [0:00] Remotely wiped
- [0:07] Out of support
- [0:30] Backup server
- [0:38] How to move forward
#shorts
Is that safe? What's the downside? Learn more in this short...
References:
- The WSJ on the push in the US Congress and the EU, wsj.com/articles/apples-fight-for-control-over-apps-moves-to-congress-and-eu-11624440601?mod=searchresults_pos1&page=1
- Ars Technica interview with Tim Cook, arstechnica.com/gadgets/2021/06/apples-tim-cook-sideloading-is-not-in-the-best-interests-of-the-user
- My post on new privacy features from WWDC21, markn.ca/2021/privacy-at-wwdc21
Index:
- [0:00] Under pressure
- [0:10] What is sideloading?
- [0:22] App Store protections
- [0:44] The ecosystem
#shorts
Index:
- [0:00] Texas grid
- [0:18] The deal
- [0:40] Get back control
References:
- The Verge on the issue, theverge.com/2021/6/18/22540015/psa-energy-saver-program-smart-thermostat-adjust-temperature-heat?scrolla=5eb6d68b7fedc32c19ef33b4
- New release from ERCOT, http://www.ercot.com/news/releases/show/225210
#shorts
We don't have a lot of information about the attack. That's completely normal at this stage.
The team at Colonial Pipeline is working through their incident response process. Attribution doesn't happen until the later stages of that process (if ever!) but a critical step is "containment."
That's what prompted the pipeline closure and—while difficult—it's good that they took that step to reduce any potential damage.
Ransomware very often tries to encrypt any and all systems it can reach. Stopping the spread most likely saved the team an even bigger headache down the line
Learn more in this short
Index:
- [0:00] The attack
- [0:04] The response
- [0:31] Shutting down
- [0:41] #hugops
A lot of people asked if I would be continuing my videos and posts in any new role I took on. The answer is unequivocally yes.
While I do have a lot of internal responsibilities, I'll be more active than ever in the community! I have a mountain 🏔 of new topics to learn about and share with you. But, more important than that, I want to know what YOU want to learn about!
...and thank you for all your continued support.
More about Lacework at lacework.com
It's not perfect but it's a huge step forward for privacy and a big blow to Ad Tech.
Learn more in this short...
Learn more about this feature from Apple at youtu.be/Ihw_Al4RNno
Index:
- [0:00] iOS 14.5 is here!
- [0:08] App Tracking Transparency
- [0:16] IDFA
- [0:26] Facebook doesn't like this
- [0:39] Stop all tracking...mostly
#shorts
Learn more in the short...
Index:
- Who are the victims? [0:00]
- Whistleblower [0:17]
- Three principles [0:24]
#shorts
But is the technical solution to 3rd party cookies just as bad? Worse?
We explore the issue in this short...
Index:
- Privacy sandbox [0:00]
- FLoC [0:13]
- Cohorts [0:25]
#shorts
We explore the issue in this short...
Index:
- Privacy labels [0:00]
- Google lists everything [0:05]
- Why use it? [0:16]
No need to panic but it is time to update. This issue is being actively exploited in the wild. A/k/a hackers are taking advantage of it.
This short shows you how...
Index:
- Here we go again [0:00]
- Details [0:05]
- How to update [0:20]
#shorts
No need to panic but it is time to update before hackers take advantage.
This short shows you how...
Index:
- The update [0:00]
- Details [0:06]
- How to update [0:08]
#shorts


