Captain

joined 1 year ago
MODERATOR OF
[–] Captain@infosec.pub 1 points 1 year ago

Well done, congratz!

[–] Captain@infosec.pub 1 points 1 year ago

Awesome, congratulations!

I've heard good things about the AWS Security Specialty certificate too. I've done a course for it which was great, though I never bothered to take the certificate (I don't feel the need for it). Have you considered it?

 

A very interesting approach. Apparently it generates lots of results: https://twitter.com/feross/status/1672401333893365761?s=20

4
submitted 1 year ago* (last edited 1 year ago) by Captain@infosec.pub to c/ai_infosec@infosec.pub
 

They used OpenSSF Scorecard to check the most starred AI projects on GitHub and found that many of them didn't fare well.

The article is based on the report from Rezilion. You can find the report here: https://info.rezilion.com/explaining-the-risk-exploring-the-large-language-models-open-source-security-landscape (any email name works, you'll get access to the report without email verification)

[–] Captain@infosec.pub 1 points 1 year ago

Getting rid of long living access keys is such a win.

Adding an SCP to block creation is mentioned last in the blog post, but I'd sat that's the first thing one should do. That way the problem won't grow as you remove the existing ones (which might take a lot of time).

Good blog post indeed! Not exactly ground breaking but considering how common the problem is I don't blame them for writing it.

[–] Captain@infosec.pub 3 points 1 year ago (1 children)

They say it's cloud breach by I didn't see what kind of cloud breach. Did I just miss it or was it not mentioned?

[–] Captain@infosec.pub 1 points 1 year ago

"Beyond the AWS Security Maturity Roadmap" by Rami and "Google Cloud Threat Detection: A Study in Google Cloud" by Day were my favourites. Though I've only seen about half so far.

I say most, if not all, are good but since the talks often are niche it depends on what you're after.

[–] Captain@infosec.pub 3 points 1 year ago (6 children)

Looks like you're right. It's not mentioned on that page but here he says he's the one running it.

view more: next ›