ContentPosts from @dawnalvarez494..
Link
@faun shared a link, 3 years, 2 months ago
FAUN.dev()

Azure B2C Crypto Misuse and Account Compromise

The Azure B2C service from Microsoft had a cryptographic flaw that allowed an attacker to create an OAuth refresh token with the contents for any user account. This vulnerability was reported to Microsoft by Praetorian in March 2021 and July 2022. Microsoft applied two changes in December 2022 and F.. read more  

Link
@faun shared a link, 3 years, 2 months ago
FAUN.dev()

Escaping misconfigured VSCode extensions

This two-part blog series explores how the security of Visual Studio Code (VSCode) extensions can lead to the compromise of a user’s local machine, demonstrating vulnerabilities in Microsoft’s SARIF viewer and Live Preview extensions. The author discovered a high-severity bug in both extensions tha.. read more  

Escaping misconfigured VSCode extensions
Link
@faun shared a link, 3 years, 2 months ago
FAUN.dev()

Code Scanning in GitHub

GitHub Code Scanning is a feature that helps identify vulnerabilities in code. To set it up, go to the repository settings and click on "Code security and analysis" and then "Code scanning". After the analysis is complete, any findings will be displayed next to the security link at the top of the .. read more  

Code Scanning in GitHub
Link
@faun shared a link, 3 years, 2 months ago
FAUN.dev()

CloudNativeSecurityCon 2023: 3 key areas to watch

Cloud native security is indeed becoming increasingly crucial as more organizations move to the cloud, and open-source software is more widely used. The following three key areas will be vital in 2023, and beyond: eBPF: The programmability of the Linux kernel, made possible by eBPF, has enabled a n.. read more  

CloudNativeSecurityCon 2023: 3 key areas to watch
Link
@faun shared a link, 3 years, 2 months ago
FAUN.dev()

Microsoft Azure vs. Amazon Web Services: Cloud Comparison

In this article, Mark Fairlie provides a comparison of two leading Infrastructure as a Service providers, Amazon Web Services and Microsoft Azure. The article coversa comprehensive list of services offered by both companies, including app modernization, compute, gaming, data analytics, migration, n.. read more  

Microsoft Azure vs. Amazon Web Services: Cloud Comparison
Link
@faun shared a link, 3 years, 2 months ago
FAUN.dev()

Hosting Python Web Apps on Azure: A Price-Off

In this article, Pamela Fox, a Microsoft Cloud Advocate, shares her experience of porting her old Google App Engine apps to Azure and hosting them on a personal Azure account. She compares the costs of hosting two low-traffic websites, pamelafox.org and translationtelephone.com, on Azure Container .. read more  

Link
@faun shared a link, 3 years, 2 months ago
FAUN.dev()

Leveraging Defender for Containers to simplify policy management in your Kubernetes Clusters

This blog post discusses how Azure Policy for Kubernetes, deployed as part of Defender for Containers, can be used to manage policies for Kubernetes clusters. The blog explains how the Azure Policy for Kubernetes leverages Gatekeeper with Open Policy Agent (OPA) to ensure that cluster configurations.. read more  

Leveraging Defender for Containers to simplify policy management in your Kubernetes Clusters
Link
@faun shared a link, 3 years, 2 months ago
FAUN.dev()

3 Things in Azure I Wish GCP Have

In summary: 1) Azure Files share with SMB and NFS protocols allows you to pay only for what you use, unlike GCP's Filestore which requires provisioning with a minimum size of 1TB for HDD and 2.5TB for SSD, making it expensive for storing few GBs. 2) Azure Policy offers built-in policies for regula.. read more  

Link
@faun shared a link, 3 years, 2 months ago
FAUN.dev()

We stand to save $7m over five years from our cloud exit

David Heinemeier Hansson, co-founder of Basecamp and creator of Ruby on Rails, shared in an article that his company is planning to fully exit the cloud by the end of the summer and expects to save about $7 million in server expenses over the next five years by doing so. He explained thatthey spent.. read more  

Story
@nataliiapolomkina shared a post, 3 years, 2 months ago
Mailtrap

Email Hosting Guide

In a nutshell, an email hosting provider is a company renting out space in one of its servers for users to store their emails. There is a large pool of email hosting services out there for businesses to pick and choose from. Professional email hosting providers usually vary in terms of what they offer, such as disk space, trial period, pricing, supporting authentication protocols, and so on.

Perhaps the only case where an everyday regular person pays for any email service is when you have a ton of vacation photos that force you to get a family email hosting plan. However, if you are a business that deals with sensitive data, and with today’s strict privacy laws such as GDPR most data are sensitive, you most probably do need a dedicated email server hosting. After all, no one wants to pay a hefty fine for a data breach or unintentional mishandling.