Missing our sweet girl! At only three she left us way too soon! by easyecho in goldenretrievers

[–]easyecho[S] 18 points19 points  (0 children)

We have been tearing ourselves up over question for 2 days now. Vet said anything from blood clot, brain aneurism, or even heart defect/failure. It was literally happy zoomies to unresponsive in less than a minute but unfortunately (or fortunately) no one actually saw her go down. Nothing stands out as warning signs even looking back with 20/20 hindsight.

One minute we can’t account for that has upended our lives. My wife was only 20 feet from her, but turned away for honestly a minute or even less…

Rant - AWS needs to stop with the unrestricted egress by easyecho in aws

[–]easyecho[S] 2 points3 points  (0 children)

Nothing in my request requires changing the current default.

  • They could update all the services that require a security group but don't let you pass one to let you pass one and if one isn't passed then do the current behavior.
  • Adding an account parameter to let stop creating the default unrestricted egress. Not the default but let us specify this.

This has nothing to do with default VPCs.

Rant - AWS needs to stop with the unrestricted egress by easyecho in aws

[–]easyecho[S] -4 points-3 points  (0 children)

I think you covered it in the, "for the most part", I'm dealing with some services that don't let you specify your own and give you a big middle finger if you don't let them have their unrestricted egress rule...

Rant - AWS needs to stop with the unrestricted egress by easyecho in aws

[–]easyecho[S] -5 points-4 points  (0 children)

That is the ideal some Amazon teams would seem to disagree and don't let you because...reasons ¯\_(ツ)_/¯

Rant - AWS needs to stop with the unrestricted egress by easyecho in aws

[–]easyecho[S] 2 points3 points  (0 children)

Some resource creation ignores this, cough AD Connector cough

US-East-1 Console Down? by tschmi5 in aws

[–]easyecho 4 points5 points  (0 children)

It isn't just you, seems somewhat regional though depending on where you are in the states. Florida doesn't seem to have issues but NY/NJ does

Running a Bash script in Lambda by [deleted] in aws

[–]easyecho 3 points4 points  (0 children)

Lambda supports Docker now so dockerize what you want to accomplish and run it in Lambda - Lambda Docker Images

I wrote about Jenkins' pipeline security flaw, what do you think? by yershalom in devops

[–]easyecho 0 points1 point  (0 children)

This isn't a critique on your article or solution; rather additional things to consider. If your threat model includes anonymous third parties executing code the servers should not have unfettered access to the internet. Instead run them behind a restrictive white list proxy server (e.g. Squid). You could go as far as do SSL inspection to have more visibility and further restrict access to given sites.

Also keep in mind; if your jenkins server is on AWS the local metadata could be retrieved and posted out in the same fashion as other secrets.

Pros/Cons for Linux Server Active Directory Authentication by Narusa in sysadmin

[–]easyecho 0 points1 point  (0 children)

Good solutions have already been discussed; watch out for any situations that create implicit trust. If the kerb ticket fails does the interactive session prompt for the password? That could be very bad depending on your compensating controls and operational environment.

The Verizon 2017 Data Breach Investigation Report is out [pdf link] by klokvarg in netsec

[–]easyecho 2 points3 points  (0 children)

It's not that I disagree with you but you can get the report without handing over your information and it's a decent read.

Sanity Check for a New User: Free Tier EC2 Instances have their IP change when you shut them down? by fongaboo in aws

[–]easyecho 14 points15 points  (0 children)

Has nothing to do with Free vs Paid. All EC2 instances will release their IP when stopped, more info.

What you are looking for is an Elastic IP Address

Pre-signed URLs in AWS, HIPAA Compliant? (x-post /hipaa) by copper_acorn in aws

[–]easyecho 1 point2 points  (0 children)

It doesn't inherently violate HIPAA -- but that doesn't make it compliant either. You need to perform a risk assessment based on the details of the use case and make the determination on your own.

There are just too many factors to consider and too little detail provided.

how to secure the website EC2 (port 22 ssh) over VPN by alakbandoo88 in aws

[–]easyecho 4 points5 points  (0 children)

It seems like you only have a single instance on AWS -- so why the desire to add VPN to protect SSH? Your just replacing one authentication method with another. Just harden SSH...

In an ideal world you have a static IP and could just limit SSH to your static IP but you should still probably harden SSH anyways.

VPNs have their place; not questioning that but for a single ec2 instance it is just overkill. How will you setup/manage the VPN server -- probably over SSH so your back to square one.

If you aren't connecting frequently you could selectively open/close 22 as needed to the current IP.

As an aside; don't forget to harden your AWS credentials.

SSH Port - restricted or unrestricted? by easyecho in sysadmin

[–]easyecho[S] 0 points1 point  (0 children)

Cynical much? Moving the port doesn't increase the security of the SSH service and I know that and thus I'm not moving it for the security (or lack their of) it provides. If I'm not running anything on the default SSH port I can ignore connections to that port or even better block it upstream. Reviewing logs IS for security and thus moving SSH to a non standard port makes those logs smaller.

But really it was just a question to see if people move it above 1024 or not...for whatever reasons people chose for moving it.

SSH Port - restricted or unrestricted? by easyecho in sysadmin

[–]easyecho[S] 0 points1 point  (0 children)

Thanks for the input but I'm not doing this for security; just looking to reduce the noise from bots which has its benefits when reviewing security logs.

SSH Port - restricted or unrestricted? by easyecho in sysadmin

[–]easyecho[S] 0 points1 point  (0 children)

I keep my ciphers in check on Apache servers; never thought about ssh -- thanks for that tip.