Bruber CloudSecOps :donor:

20 years of slinging code. Moved to Application Security. Now leading a kick-ass Cloud Security team. The animal I channel is the octopus since it will occasionally punch passing fish for no reason. Proud member of the Jewish Space Laser Corps, Mishuggah Division. Proudly owned by my wife, two sons, and two cats.

Supports LGBTQ+, environment, BIPoC, women's rights, actually, all human rights.

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2025-03-09

@jerry a few days ago I saw it was renamed again, this time to the Gulf of SpaceX Debris

Bruber CloudSecOps :donor: boosted:
2025-01-26

the CDC now recommends getting an aquarium and growing your own leeches

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2025-01-25

It's been a minute since I've posted anything relevant.

Back in August, we made a recommendation to our leadership to realign our teams so we could better support our internal customers. As a result, on Jan 1st I picked up two more engineers on my team and took over our Cloud Security operations. We're still doing a lot of traditional AppSec work from an advisory and/or training perspective, but now we get to play in the Cloud space.

Its been a wild ride, gutting and building out a whole new program. Hopefully by end of the fiscal year, we'll have a solid new program built to scale with all processes at least partially automated.

#appsec #cloudsec

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2025-01-25

@tinker we've had food rescue for years, but we do have an ICE Watch now. City announced that local PD will not be assisting ICE. Not really newsworthy, as helping ICE would constitute work, which they haven't been doing for several years. That's a different story for a different day.

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2025-01-13

@stux laundering money so Donold doesn't shitcan the government AWS contracts, which are far more valuable.

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2025-01-05

@georgetakei we have a beer fridge named Bev, and a dishwasher named Roxanne because it leaves the red light on while it's running. Our Roomba is named Roombot as it's not nearly as smart.

Bruber CloudSecOps :donor: boosted:
yawnbox :rebel:yawnbox@disobey.net
2024-12-28

@btanderson

Data classification to understand what data a company actually has, and why

Maximising data minimization so there's less data to secure

Purging unneeded data so there's less data to get hacked

Understanding present and future data handling responsibilities to avoid massive fines

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2024-12-22

@xek mea culpa. I posted in ignorance, not malice. You're right. Body image issues are things I've never had to deal with personally. I should have known better.

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2024-12-22

There's a good reason why I don't do #offsec. I don't have enough self control to keep myself from hacking the self-checkout machines to yell "it puts the lotion in the basket!" when a customer scans skin lotion.

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2024-12-21

For me, habits take 2-4 weeks of repetition to become normalized. I pick one per month to focus on. YMMV.

That being said, my basic hygiene was tackled 55+ years ago 😆

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2024-12-20

So I am not a financial person, but I was thinking of what could happen if the Federal government could
1. establish a list of the top 10 most critical medications from a health and cost perspective under patent,
2. buy out the remaining patent using the present value of the sum of profit to the company patent holder.

This could potentially
1. allow immediate generic production
2. reduce the cost of medication to individuals, insurers, and Medicare/Medicaid
3. transfer money spent on medication directly or copays back to the economy in the form of discretionary spend. Meds aren't subject to sales tax, but other purchases are so States with sales tax would benefit.
4. give drug manufacturers a larger amount of money up front.

I'd think the shift in money would offset the government buyout over time through additional taxes paid from the extra money in the economy instead of being paid to purchase meds.

I'd love to see this investigated and beta tested on one medication to see if it's a viable idea.

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2024-12-10

@JoshCGrossman just dealing with yet another AuthZ issue this week. IMHO, trying to code AuthZ as a decorator would be a challenge because of differences in AuthZ scope between endpoints.

From a functional AuthZ perspective, say I have multiple endpoints, and some of them allow GET for any AuthN use, but the PUT and PATCH are restricted to managers, and DELETE is admin only.

From a resource perspective, what if I'm a manager and I should only have AuthZ for my direct reports, not all employees?

If one set of endpoints deals with employee objects, and another with address objects, how would your decorator handle AuthZ for different object types?

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2024-09-03

Three loops of Climb Practice Route #5 today

20.9mi 1,729ft 1hr47min

Fun short climb ride for Labor Day. I normally ride 30-70mi for endurance training, so this was my first dedicated climbing ride. It was fun and challenging. There will be more.

#BicyclePittsburgh #BikePittsburgh #Bicycling412

ridewithgps.com/trips/21755583

Bruber CloudSecOps :donor: boosted:
2024-08-25

If you're over 45, get a colonoscopy.

I know someone in her 60s who recently had her first colonoscopy. They found a tumor, requiring surgery to remove a section of her colon. She had no symptoms before, and is an otherwise healthy and active person.

The pathology report showed that the tumor had just penetrated the outer wall of her colon. If she'd waited longer, it would have metastasized. An earlier colonoscopy could have nipped it as a polyp.

Just do it. It could save your life.

Bruber CloudSecOps :donor: boosted:
Amit Serper :donor: 🎗️0xamit@infosec.exchange
2024-08-23

Kamala Harris acknowledges the rape of Israeli women on October 7th during her #DNC2024 speech 👏👏👏👏🇺🇲🇮🇱
Excited that my first time voting in the USA would be for her.

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2024-08-23
Bruber CloudSecOps :donor:bp4151@infosec.exchange
2024-08-09

Apparently I missed the memo that today was Feces-Fan Unification Day

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2024-07-20

#crowdstrike fallout.

Having spent 16 hours online yesterday from start to complete remediation and full operations restored, our genius leadership scheduled a retro for mid-day Sunday. No complaints about Friday, as that's part of the gig. Seriously pissed about losing a weekend day for no reason though.

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2024-07-08

Hey folks,

As many of you know, I am diabetic, and over the past several years, many medications, including but not limited to those for diabetes, have been difficult to find due to worldwide shortage.

MedHound is my idea to help patients find meds that are in shortage using crowdsourcing. The local development group I'm working with entered it into the Create the Future competition. If you can, please register, vote, and share!

contest.techbriefs.com/2024/en

#diabetes #mounjaro #ozempic #weygovy #zepbound

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst