Hacker Newsnew | past | comments | ask | show | jobs | submit | kevincloudsec's commentslogin

the fine is 0.6% of last year's profit. the lobbying budget probably costs more.

cloud providers design for software failures and network partitions. they do not design for drone strikes. the redundancy model assumes your availability zones won't get hit by the same military operation.

Thats what regions are for... AZ downtime is one thing, if you loose the region, you should be able to bring up your services in another region.

the ban covers all foreign-made consumer routers but practically every router is manufactured abroad, even the ones sold by American companies. the only domestic exception is Starlink, iirc

hack back assumes you know who hit you. attribution in cyber is hard enough for the NSA

second breach in a month from the same initial credential compromise. the first rotation didn't fully revoke access. the attacker walked right back in. no persistence needed.

telling users on a cybersecurity website to click past certificate warnings is training them to do the exact thing every security awareness program says never to do. DISA runs the security standards that every defense contractor has to comply with...

The requirements for vendors are based on NIST standards and frameworks. They do not have to apply DISA STIGs to their own systems. And the mandatory annual cybersecurity awareness training for anyone with a CAC does include teaching users not to click through these warnings. DoD users wouldn't typically see this page at all.

the supply chain for offensive tooling is now indistinguishable from the supply chain for malware. take care of your security team!

the product got deployed across the government while the security review was still in progress. then fedramp approved it because it was already everywhere. seem like i saw a lobbyist or two with a broom sweeping something under a rug...

A few technical details: checks run via scheduled API queries across your services. No agents or collectors run in your account. The cross-account role is scoped to read/list calls only. Findings are stored historically so you can see when issues appeared and when they were resolved.

I think you might have made a mistake on the post? Is not linking you to the actual site or product

Thanks for the heads up. The links are in the text body. Demo dashboards here: https://awsight.com/demo.html and main site: https://awsight.com. I posted as a text submission so I could include context.

three states passing the same template bill in three months isn't organic legislation

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: