Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

via the unique cartoon-stylings of Daniel Stori at turnoff.us

Daniel Stori's 'To DevOps Or Not To DevOps' →

June 25, 2020 by Marc Handelman in Daniel Stori, DevOps, SecDevOps Humor, Security
June 25, 2020 /Marc Handelman
Daniel Stori, DevOps, SecDevOps Humor, Security

via the astounding cartoonery of Daniel Stori of turnoff.us!

Daniel Stori's Depressed Developer #43 In 'Bedtime Story' →

April 02, 2019 by Marc Handelman in DevOps, Sarcasm, Satire, DevSecOps Humor, SecDevOps, SecDevOps Humor
April 02, 2019 /Marc Handelman
DevOps, Sarcasm, Satire, DevSecOps Humor, SecDevOps, SecDevOps Humor

DOES2018, Hart Rossman's 'Handling Security Objections to DevOps - AWS' →

December 01, 2018 by Marc Handelman in DevOps, Security and DevOps
December 01, 2018 /Marc Handelman
DevOps, Security and DevOps
fitr.jpg

Directionless Security and Devops

November 08, 2018 by Marc Handelman in DevOps, Security Dev Teams

via Gary Southwell, writing at HelpNet Security, comes this interesting self-help(ish) posting, detailing a method to faciltate enhanced (read better) inter-operability between Security Teams and DevOps Organizations. Might be interesting to see the outcome of implementation of this advice, in a real-world setting...

November 08, 2018 /Marc Handelman
DevOps, Security Dev Teams

So-Called 'Cybersecurity' Impetus For Agile Dev Adoption

September 13, 2018 by Marc Handelman in Security Engineer, Popeye, DevOps, Olive Oyl, Information Security

via Zeljka Zorz, Managing Editor, whilst writing at HelpNet Security comes word of how opposites may in fact attract... That is, Agile Development efforts being stimulated by Cybersecurity efforts... The reality: Just another way to flog security products.

September 13, 2018 /Marc Handelman
Security Engineer, Popeye, DevOps, Olive Oyl, Information Security

CircleCity Con 2018, Stephen Deck's 'Abuse Case Testing in DevOps' →

July 29, 2018 by Marc Handelman in Conferences, Education, Information Security, DevOps, Circle City Con
July 29, 2018 /Marc Handelman
Conferences, Education, Information Security, DevOps, Circle City Con

OWASP APPSEC Cali 2018, Clint Gibler's 'SecDevOps: Current Research and Best Practices' →

April 10, 2018 by Marc Handelman in OWASP, Application Security, Conferences, Education, Information Security, DevSecOps, DevOps, SecOps, SecDevOps, Infosec Coding
April 10, 2018 /Marc Handelman
OWASP, Application Security, Conferences, Education, Information Security, DevSecOps, DevOps, SecOps, SecDevOps, Infosec Coding

OWASP APPSEC Cali 2018, James Wickett's 'The Path Of DevOps Enlightenment For InfoSec' →

April 09, 2018 by Marc Handelman in OWASP, Application Security, Conferences, Education, DevOps, DevSecOps, SecDevOps, SecOps, Information Security
April 09, 2018 /Marc Handelman
OWASP, Application Security, Conferences, Education, DevOps, DevSecOps, SecDevOps, SecOps, Information Security

via the eponymous Daniel Stori at turnoff.us

Daniel Stori's 'My Adorable, Useless Code' →

February 09, 2018 by Marc Handelman in Satire, Sarcasm, Security Humor, DevOps
February 09, 2018 /Marc Handelman
Satire, Sarcasm, Security Humor, DevOps

AWS, Automating Security in Cloud Workloads with DevSecOps →

January 29, 2018 by Marc Handelman in AWS, DevSecOps, DevOps, Security Operations, Security Automation, Security Architecture
January 29, 2018 /Marc Handelman
AWS, DevSecOps, DevOps, Security Operations, Security Automation, Security Architecture

Converge 2017, Chris Romeo's 'AppSec Behaviors for DevOps Breed Security Culture Change' →

June 21, 2017 by Marc Handelman in Conferences, Education, DevOps, Rugged DevOps
June 21, 2017 /Marc Handelman
Conferences, Education, DevOps, Rugged DevOps

BSides Nashville 2015, Ron Parker's 'Agile and Security Oil and Water' →

May 13, 2017 by Marc Handelman in All is Information, Code, Agile Development, Rugged DevOps, Rugged Security, DevSecOps, DevOps

Worth a repeat, should be a must watch for the DevOps and Agile 'teams' out there...

May 13, 2017 /Marc Handelman
All is Information, Code, Agile Development, Rugged DevOps, Rugged Security, DevSecOps, DevOps

"the Art of Secure Application Deployment" →

September 19, 2016 by Marc Handelman in SecDevOps, Rugged Security, DevOps

In my opinion, there is absolutely no 'art' in securely deployed applications...

Not withstanding this, the subject of this post is the well engineered conversational interview over at Linux.com, with Tim Mackey, an evangelist at Black Duck Software; in which the two participants in the conversation hold forth in 'DevOps and the Art of Secure Application Deployment' (scribed by Amber Ankerholz). Worth the read.

September 19, 2016 /Marc Handelman
SecDevOps, Rugged Security, DevOps

OWASP, DevOops, I Did It Again →

November 19, 2015 by Marc Handelman in All is Information, DevOps, DevSecOps, Information Security
November 19, 2015 /Marc Handelman
All is Information, DevOps, DevSecOps, Information Security
0.jpg

DevOps, The Security Mythos →

July 22, 2015 by Marc Handelman in All is Information, DevOps, Rugged DevOps, Information Security

The remarkable truth about Information Security within DevOps driven organizations, and why, per se, those organizations are not secure with the utilization of DevOps integration of Development and Operations teams leading to continuous deployments. If you read anything about DevOps today, read George V. Hulme's interview of Adam Muntner an Application Security Engineer at Mozilla and the creator of FuzzDB (the interview is also posted at Adam's Blog). Absolutely Outstanding.

July 22, 2015 /Marc Handelman
All is Information, DevOps, Rugged DevOps, Information Security

Bring Your Own Exploit →

July 20, 2015 by Marc Handelman in All is Information, Rugged DevOps, DevOps, Developers Developers

DevOps' writer Chris Riley (Chris - aka @HoardingInfo) is a technologist and DevOps analyst for Fixate IO), regales us with s tale of the Rugged DevOps crypt - at least from the viewpoint of semi-like-minded security operators...

July 20, 2015 /Marc Handelman
All is Information, Rugged DevOps, DevOps, Developers Developers

All Your Automatonic Security Are Not Belong To Us →

June 22, 2015 by Marc Handelman in All is Information, Complexity, Automation, DevSecOps, DevOps

Well crafted thought piece appearing over at Darkmatters, a Norse blog, written by the inimitable Pete Herzog, regaling us with the truth of robotic security. Today's MustRead.

"The problem is that automating security creates a paradox. You see, in security, automation works best as a tool and not a wielder of tools. You see, your security automation is in charge of making periodic and systematic changes to controls and then verifying those changes." via Darkmatters, a Norse Security blog, by Pete Herzog

June 22, 2015 /Marc Handelman
All is Information, Complexity, Automation, DevSecOps, DevOps

DevSecOps Edition, 10+ Hours of Information Security + DevOps Video →

June 04, 2015 by Marc Handelman in All is Information, Application Security, Automation, Code, DevOps, Information Security, Education, DevSecOps

The kind folks at DevOps have made their video collection of HD quality Security DevOps content from RSAC 2015 available (with the only catch of a registration form). Highly recommended.

'DevOps Connect was co-produced by DevOps.com and Sonatype, through the Nexus Community Project. The day started with a keynote delivered by Gene Kim and Joshua Corman, setting the stage for 13 more presentations.' - via Devops' Alan Shimel

June 04, 2015 /Marc Handelman
All is Information, Application Security, Automation, Code, DevOps, Information Security, Education, DevSecOps

Corman's 'Cultural Change of DevOps' →

April 22, 2015 by Marc Handelman in All is Information, DevOps, Infosec DevOps, Rugged DevOps
April 22, 2015 /Marc Handelman
All is Information, DevOps, Infosec DevOps, Rugged DevOps

Über Alles? →

April 03, 2015 by Marc Handelman in All is Information, Blatant Stupidity, DevOps, Enterprise Management, Information Security, Infosec Policy

Interesting Uber vs. John Doe (in this case GitHub) case, whence Uber issues what is fundamentally a Your Papers Please subpoena through a magistrate and demands records closely held by GitHub through the courts.

In this case, access has been granted by the magistrate permitting examination of the two Gists at GitHub, containing the unfortunate error made by Uber employees (whence an Uber developer/dba included internal passwords on a very public Gistto internal databases.

Uber argued (successfully - mh) during the hearing that the two Gist posts (both of which have been offline since the lawsuit was filed) should have had very little traffic, and the data on who visited them "should generally reveal people, who were affiliated with Uber and who worked on the Uber code near the time of the unauthorized download." - via El Reg's Kieren McCarthy

April 03, 2015 /Marc Handelman
All is Information, Blatant Stupidity, DevOps, Enterprise Management, Information Security, Infosec Policy
  • Newer
  • Older