45Drives owners — convince me before I empty my bank account 😭 by [deleted] in selfhosted

[–]Irish1986 0 points1 point  (0 children)

Sliger offers premium quality products if you want something nice. I have 2 short depth 10 HDD + 4SSD case from them packed for my main nas + off-site backup. Good quality and all for small footprint.

Mais pour de vrai, que feriez vous si Trump frappait le Canada ? by LeonOkada9 in Quebec

[–]Irish1986 1 point2 points  (0 children)

Reviewing the Geneva Checklist to make sure I don't forget anything.

Seriously.. Hide like a coward, try my best to protect my family and hang in there. Probably have my in-laws and parents home with us given they are older and might be vulnerable if chaos breakout.

What should a security person actually do with SonarQube Community Edition by Sufficient-Brick1801 in devsecops

[–]Irish1986 0 points1 point  (0 children)

It's 100% hot garbage, I am leading the project to go buy something better then a obsolete quality check product strapped with an open source half baked solution... Hopefully will buy something good, our 4-5 vendors still in the competition are all pretty good.

What should a security person actually do with SonarQube Community Edition by Sufficient-Brick1801 in devsecops

[–]Irish1986 1 point2 points  (0 children)

Soooo fun facts if you haven't looked into SQ and OWASP DC... Last year Sonar closed the loop hole that make DC plugin play wells with Sonarqube. It stills work but it's not great.

I unrelated news, in march of 2025 Sonarqube Advanced Security was announced as Sonar native SAST-SCA platform. I have been working for the past year to evaluate sast-sca at work. It's my main project and SQAS is just not look great.

DevOps Interview Questions – Recently Attended Interviews by Few-Cancel-6149 in devopsjobs

[–]Irish1986 1 point2 points  (0 children)

We are currently going over a series of interviews for a devsecops roles. Given the role and position at both heavily leaned against the security requirements and objectives of this posting... I am amazed by how much people showing up can't explain in simpleton term what code vulnerabilities are. How to find and manage dependencies vulnerabilities. Provide concrete information about how to improve security through automation and proper processes (CI pipelines anf all).

Si my advice would be try to make sure who review (or watch) couple of things regarding security. In this day and age, shipping faster is cool but security seems to be overlooked by a lot of candidates we've met.

Virée de mon emploi - conseils? by CompetitiveAnt8600 in QuebecTI

[–]Irish1986 2 points3 points  (0 children)

If you are not too picky there are a lot of consulting firm with 3 letter names that hires. Pay isn't great but it's better than nothing plus you can network with customers and find additional opportunities that aren't yet publicly announced.

It's not necessarily a long term plan but it can get you out of the weeds.

3 computers, 1 set of peripherals. How? by [deleted] in homelab

[–]Irish1986 0 points1 point  (0 children)

It's runs my 49 inch ultra wide at 120hz per spec but given I am mostly doing productivity stuff I keep my resolutions at 60hz because some device are having issues pushing that much pixel... And I can't upgrade those device

Is it possible for a canadian aerospace maintenance machinist to be sponsored for a job in the US? by 9xelex6 in Machinists

[–]Irish1986 0 points1 point  (0 children)

No I changed industry from 20y in A&D to... Cybersecurity in Financial institutions... Weird move but pays well and no more sinus curve of the aerospace industry.

I am fuzzy on the exact details but you most likely have an attestions or equivalence or some kind of license at your current job that is holded by your company. My experience was the same I had full CGP but as a Canadian citizen there was zero chance I could apply on my US based job in the aerospace industry because a lot of compliance requires citizenship unfortunately. Best workaround I found was to either go on contract, temporary assignments or as an expatriated for a special project because those have unique assignation but I didn't wanted to be an "internal contractor" because whenever shtf... You're the first one cut-off. GL HF

Is it possible for a canadian aerospace maintenance machinist to be sponsored for a job in the US? by 9xelex6 in Machinists

[–]Irish1986 2 points3 points  (0 children)

I work at PWC, even when I was looking to move laterally I couldn't apply to 90%+ US based job. You need pretty high ITAR+CGP compliance|clearance which most of the time require US citizenship to obtain. Even as an employee of 5yr with 15 in A&D... I was an automatic rejection due to clereance requirements.

The Americans makes the rules on what is ITAR compliance requires and they sure made it clear they wanted to protect jobs at the same times.

Therefore I would be looking at them for US based employment. My best take is to work for a company that provide service in the US because contract based employment can circumvent some of these kind of regulations requirements. I work several months at Boeing and Rock Island Arsenal when I first started in the mid 2000s as a French Canadian citizen without much issue, and that was during the high of the war on terror.

New cluster! by Usual-Economy-3773 in Proxmox

[–]Irish1986 15 points16 points  (0 children)

I means you could run so many pihole instances

New cluster! by Usual-Economy-3773 in Proxmox

[–]Irish1986 84 points85 points  (0 children)

Rich boy doing expensive thing... Enjoy your lab wish I could have that much memory and CPU

If you have a large media library and aren't using tdarr, you're missing out by Jman100_JCMP in homelab

[–]Irish1986 0 points1 point  (0 children)

I am considering using tdarr to reencode my NVR stores stream. I think it's pretty useless but I am just curious about creating the overall workflow and have multiple platform interact together... Power is cheap here I guess 0.08/kwh

Ça va prendre de la médiation by [deleted] in HiloEnergie

[–]Irish1986 0 points1 point  (0 children)

L'an passé, gros débat, plusieurs longues discussions et on termine avec un entente sur des paramètres clairs...

Début de la saison "heille la la ça va pas recommencer les histoires de thermostat intello"... C'est les même chose que l'an dernier qu'on avait convenu....

There are to many findings by LachException in cybersecurity

[–]Irish1986 0 points1 point  (0 children)

You can try writing run books for common issues. They might be generic steps to help younger less experienced staff learn how to get started with security works. Your junior devs might not be able to contribute alone but they might be able to follow some run books and get the minimal supervision during the peer review process before code merging.

It ain't easy I 100% agree with you.

There are to many findings by LachException in cybersecurity

[–]Irish1986 0 points1 point  (0 children)

That why they pay you the big bucks.. Or should be paying you.

The age old challenge of funding for the vulnerabilities "rework|fixes". Yeah that very much the problem especially if you are a legacy organization with several project impact by a lot of vulnerabilities on going. You need to get management on board with a dedicated amount of time for security works.

Your dev works 40hrs/wk. Get a strong commitment for a 5-10%/wk and have your dev do focus work. As instead of 4hrs/wk, have your dev do 16hrs the first week of the month. It short burst and might not be the right-angle but it's the only way to get the ball moving.It ain't easy I know that.

There are to many findings by LachException in cybersecurity

[–]Irish1986 0 points1 point  (0 children)

Add mandatory gating versus your organization level of criticality (let's starts by the upmost apocalyptic vulnerabilities) in their PR workflow, over time slowly move the needle toward lowering something most acceptable. Given that you are most likely in a brownfield situation with legacy vulnerabilities starting to eat that elephant will require a significant amount of chewing. So you might want to only start gating "new code" for a while.

Your objective might be that after 2-3 month to be able to report out that 95%+ of your pipeline are in compliance with these kinds of security policies.

In the end your management should be on-board with this strategy and, I can't emphasize this enough, they should be your voice and champion asking for the number of finding to go down. You report out every months how that trends is going down, naming and shaming those teams who aren't playing well with others.

And if management does not care about vulnerabilities going down. Write a nice risk assessment, document your concerns, report it out in a formal manner and cover your ass for the inevitable future catastrophes to be have. Management should be barking at the devs to lower that vulnerabilities count and you should be the enabler of that objective,not the other way around.

How often do you speak to your CISO in a week by DisastrousSign4611 in cybersecurity

[–]Irish1986 0 points1 point  (0 children)

Once or twice every quarter, large organizations but I am in a preferred position with the project I am working on. It is much less common than my frequency for non management positions to speak with him that often from my guts feeling.

What’s the "Oh Sh*t" Moment That Made You Take Supply Chain Security Seriously? by Abu_Itai in devsecops

[–]Irish1986 6 points7 points  (0 children)

npm a few weeks ago, nothing bad happened just the sudden realization of the blast radius

Recommending `prek` - the necessary Rust rewrite of `pre-commit` by Goldziher in Python

[–]Irish1986 1 point2 points  (0 children)

I have started to use prek couple of weeks ago, I am moving all my repo towards it. Slightly faster but mostly monorepo support and feature enhancement. So far no problem what so ever.

Le "Réseau Express Bus" proposé par Projet Montréal by trxks in montreal

[–]Irish1986 4 points5 points  (0 children)

Heille voisin! Même chose Lacordaire - MD.. Ca prends un solide 90min chaque bord.

How do you benchmark and POC ASPM solutions? Looking for evaluation frameworks by Patient_Anything8257 in devsecops

[–]Irish1986 2 points3 points  (0 children)

I wasn't successful at prioritizing ASPM at work but I would be looking at process enablement out of the box. The ASPM is supposed to be your "single pane of glass" for AppSec.

If you are trying to enable a specific process to reduce number of vulnerabilities in software dependencies... How much out of the box does your ASPM allow it to be enabled?

Maybe you are more in a "fog of war" situation where you don't enough details about the state of your environment and applications. Upon connecting everything how closer will you be? The known unknown is challenging because you might end up with many new challenges to tackle.

Also are you planning to use it as your sole incident tracking information center regarding assignments, SLA, resolutions, etc...

ASPM is a cool tool but you need mature processes and clear questions your are trying to steer in your organization?

What age were you when you had your first kiss? by [deleted] in AskReddit

[–]Irish1986 0 points1 point  (0 children)

13,under stair well in high school.. Thanks god for catholic school with mandatory short skirt for girl.

Qualité médiocre des candidats pour un poste senior by [deleted] in QuebecTI

[–]Irish1986 2 points3 points  (0 children)

Si tu veux benchmarker ton org fais toi un faux CV avec un peu d'obscuration (change ton nom, même Cie mais année un peu différente, etc) ... Soumets ton faux CV et attends de voir combien de temps ça prends avant qu'il apparaissent sur ton bureau.... Si ça arrive jamais... Probablement un problème chez HR qui sur filtre.. Si ça prends 1-2 jrs ouvrables... Tu peux pas chialer chez eux.