📢 MAMIP (Monitor AWS Managed IAM Policies)
Policies changed since last week:
Get notified of policy change using this Twitter bot. 🐦


In 2016, @dagrz gave one of the greatest cloud security talks ever, filled with new techniques that have been rediscovered repeatedly in the years since. I've remastered it from video obtained from an audience member and the slide deck. youtube.com/watch?v=8ZXRw4…

The playlist from the conference is now up! youtube.com/playlist?list=…

The @fwdcloudsec 2021 talk videos are now up on YouTube. ☁️🔓📺
Check out all the great speakers from the playlist: youtube.com/playlist?list=…

💚I love that in AWS I can have two ongoing email threads with senior leaders. One about critical infrastructure decisions and the other bantering about pumpkin spice everything. Our quirkiness is legit. 🎃☕

🗒️ #Kubernetes Security Checklist and Requirements
A checklist by @vinumsec covering:
* AuthN and AuthZ
* Secrets
* Cluster config
* Auditing and logging
* OS config
* Network security
* Secure configuration of workloads
* Securely building images
github.com/Vinum-Security…

Now that GitHub->AWS OIDC federation is almost here, I want more controls on the AWS side of things.
Without them, I don't see large orgs being as enthusiastic about this feature as solo yolo devs. tldr:
1. Trust policy boundaries
2. Claim-tag mappings
awsteele.com/blog/2021/10/1…

⚠️ Risk-Based Security Decision Making at @netflix
This presentation on Thursday sounds 👌
* How Netflix uses risk to make informed decisions
* Deep dive into app risk quantification
* Using ML to scale expert knowledge
* + more
H/T @travismcpeak
eventbrite.com/e/risk-based-s…

Oh man. That feeling when OWASP tweets your name ☺️ feelsgoodman.png
Super excited for this talk!

On @Owasp_DevSlop, Kinnaird McQuade- @kmcquade3 will go over what sole practitioners need to build out their own "lean but mean" cloud security toolkit. RSVP on Meetup ed.gr/dnw4l
Sponsored by: datadoghq

Myself and several others are getting 504 when trying to access the console on the east coast.
Anyone else?
edit:
AND WE'RE BACK PEOPLE
edit:
health now shows errors:
8:30 AM PDT We are investigating increased error rates and latencies for the AWS Management Console.
Yeah... latency.
edit: …
Yes, please.
Hi, I’m Corey Quinn. I’m an AWS billing consultant and professional shitposter. Some of you might know me from Last Week In AWS, the snarky newsletter I write. (Some of you don’t know me. You are the lucky ones.)
What a few of you know is that every …
Network Load Balancer (NLB) now supports version 1.3 of the Transport Layer Security (TLS) protocol, enabling you to optimize the performance of your backend application servers while helping to keep your workloads secure. TLS 1.3 on NLB works by offloading encryption and decryption of TLS traffic from your application servers …
I'm a software engineer, I know what ec2, dynamo, rds, elb, and all these services are but when it comes to putting a cloudformation or cdk infra as code script together I just get stuck. The amount of configuration variables and details you need to be aware of are just …
Many of you tried to help me when I was having trouble launching a site, as I'm new to AWS so this post is just an update. The struggle I was having was a certificate request kept timing out. It turns out that because I had deleted and recreated my …
- 🖊️ This newsletter was fwd to you? Subscribe here
- 💌 Want to suggest new content: contact me or reply to this email
- ⚡️ Powered by Mailbrew
- 🐦 Follow me on Twitter or hire me.