Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ericalexander0
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
151.
▲
by
ericalexander0
5y ago
Surprised at how much focus there is on backups as the solution. You'll never fully recover from those backups. Backups won't help you avoid fines, lawsuits, lost customers, and lost time. I run an open data set on data breaches.
152.
▲
by
ericalexander0
5y ago
Why do you sweep? https://ericalexander.org/post/devops-and-ransomware/
153.
▲
by
ericalexander0
5y ago
I like zero trust. It's a great defense in depth tool. The bigger problem is we see cyber as something unique, when it's plain old quality. What worked in quality (Deming & Goldratt) also works in cyber.
154.
▲
by
ericalexander0
6y ago
No right answers without more context. Many people struggle as they leave college and their social circle behind. Friendships are bonds found through shared experiences. Seek new shared experiences to form new bonds. The classic "How t
155.
▲
by
ericalexander0
6y ago
Forgot json. Python Devs want to just json.loads and then v=json['key'], but it's not that easy with C#/.NET.
156.
▲
by
ericalexander0
6y ago
Most SREs are comfortable with Python, but our product is written in C#, and we can reduce SRE blockers while increasing collaboration by getting our SREs comfortable with C#/.NET. Here's what I've learned through the process
157.
▲
by
ericalexander0
6y ago
Five dysfunctions of a team is a great book on why trust is important.
158.
▲
by
ericalexander0
6y ago
Neat. Adding to this dataset. https://ericalexander.org/SecurityBreach/#/
159.
▲
by
ericalexander0
6y ago
Ransomware will continue to rise exponentially in 2021 ( https://ericalexander.org/SecurityBreach/#/ ) - that's easy to see. What's the tipping point? Better assessments from Cyber insurance providers? Hig
160.
▲
DevOps and Ransomware
(ericalexander.org)
3 points
by
ericalexander0
6y ago
|
0 comments
161.
▲
by
ericalexander0
6y ago
Look for companies that meet at the confluence of just out of reach solutions with generative cultures. Those with deep order knowledge of a problem can see opportunity that first order thinking misses. If they establish the right culture o
162.
▲
by
ericalexander0
6y ago
Reminds me of SPADE: https://firstround.com/review/square-defangs-difficult-decis... Also, in some ways similar to Goldratt's evaporating clouds: https://en.wikipedia.org/wiki/Evaporating_Clou
163.
▲
by
ericalexander0
6y ago
Link to the statement: https://youtu.be/ARS5sh9Ut7M I don't think the kitchen/chef analogy is questioning if Tesla can make a car. He's questioning if the company can scale to compete in all markets Toyota cu
164.
▲
by
ericalexander0
6y ago
Doubt there's any available. Drop catchers will grab all 3 letters. Best bet is to check the domain auction sites. Why .org when there's so many tlds to choose from?
165.
▲
by
ericalexander0
6y ago
Sign of a new trend? Most ransomware teams use traditional tactics: phishing to establish beach head, pivot to hunt down admin creds, game over. Some teams make opportunistic use of perimeter vulnerabilities (ie pulse VPN). Most companies s
166.
▲
by
ericalexander0
6y ago
Seems GitOps discussions often miss the security and compliance value. How much time do security and compliance teams invest in identifying current configuration state? Are those practices antiquated if configuration state is immutable and
167.
▲
by
ericalexander0
6y ago
Deming demonstrated similar with his bead experiment. https://youtu.be/ckBfbvOXDvU
168.
▲
by
ericalexander0
7y ago
Echoing recommendations for The Goal & The Phoenix Project. Beyond The Goal is also a great resource. More of a lecture by Goldratt that covers TOC and Critical Chain. He was a very entertaining speaker.
169.
▲
by
ericalexander0
7y ago
Dee Hock, the founding CEO of Visa, described a similar approach as chaordic leadership. http://www.griequity.com/resources/integraltech/GRIBusinessM...
170.
▲
by
ericalexander0
7y ago
Daily notes posted in slack where a bot logs to elastic search. Notes reviewed in our retros and the useful/actionable is logged in a wiki and or jira. Wiki notes are reviewed in our annual retro.
171.
▲
by
ericalexander0
7y ago
Catalog of breaches here: https://ericalexander.org/SecurityBreach/#/
172.
▲
by
ericalexander0
7y ago
Strikes me as heavily influenced by Deming. Was he?
173.
▲
by
ericalexander0
8y ago
https://www.reddit.com/r/securitybreach/ Sub-reddit for cataloging breaches with detail relevant to defenders.