Hi folks!
Nothing much to share this week, except that I hope you enjoy the read :-)
Cheers!
Supported by 1Password.
Hi folks!
Nothing much to share this week, except that I hope you enjoy the read :-)
Cheers!
There's a whole lot in there. From the article:
The executive order aims to:
They published a 60-page PDF here. Way to go CISA.
It's a weakness that enables attackers to register domains of companies that no longer exist, after which they can access data from third parties where the Google sign in flow was used. It was known for a while but only recently has Google validated it as an actual problem.
"According to the FTC's complaint, GoDaddy's unreasonable security practices included failing to use MFA, manage software updates, log security-related events, segment its network, monitor for security threats, and failing to inventory and manage assets. "
Good Lord. I was never a fan of GoDaddy but that's just insanely irresponsible for a hosting and domain provider.
If you're an engineer, it's really worth checking out 1Password's developer tools. It can manage secrets for your infrastructure and CI/CD pipeline, manage SSH keys, and inject tokens into CLI scripts. Play around with it and see how it can fit in your development flow. (Sponsored)