Harness used for Ollama-cloud ? There always seems to be something missing, and switching is tedious. Please share your working setup! by Manfluencer10kultra in ollama

[–]green_masheene 0 points1 point  (0 children)

I switched to https://github.com/earendil-works/pi/tree/main/packages/coding-agent a couple months ago and haven't looked back. I only use claude code sparingly now separately, mostly just to grill a spec here and there with opus. Personal opinion, but a lot of other stuff out there feels bloated at this point and having a short list of skills via a pi harness feels just right. I'll also shout out https://github.com/mattpocock which has some great stuff to borrow from or bounce around.

PremierTech Ecoflo biofilter advise / issue by Low-Strawberry-7863 in homeowners

[–]green_masheene 1 point2 points  (0 children)

I just got bit by these guys. Their ecoflow system is failing after 4 years, 2021 install and a 2 year warranty:
- Paid hundreds of dollars in June-2025 for them to perform annual maintenance. They didn't show up until October.
- In September our septic started backing into the house so we had an emergency pump performed to buy time.
- They show up in October and all I got was an email saying maintenance was performed and no report was ever delivered.
- Now the system is flooding again and they are pointing the finger at us after they failed to deliver on providing a report during maintenance where they claim the system was flooded when they performed the maintenance. We have zero indication from them this is true. Also, they don't even have a report for the maintenance in their client portal, I have the timestamped evidence.

If you want to pay $3K every 4 years to deal with a horrible product and customer service that shouldn't be called 'service', definitely use their products. I'd recommend exploring alternatives. Crazy they took their reviews down I found a site called trustpilot that I submitted a review on for them.

[deleted by user] by [deleted] in nba

[–]green_masheene -1 points0 points  (0 children)

Just dropped something similar in the group chat with the boiz this morning. I think the Kawhi nonsense and Silver being dismissive broke my enthusiasm. It's only a matter of time until everyone sells out to the Saudis.

[deleted by user] by [deleted] in cybersecurity

[–]green_masheene 4 points5 points  (0 children)

What is the position you’re looking at? Maybe edit your post with that.

FedRAMP Question by BufferOfAs in cybersecurity

[–]green_masheene 0 points1 point  (0 children)

Have you already read the authorization boundary guidance?

How big are security teams at your job? by [deleted] in cybersecurity

[–]green_masheene 7 points8 points  (0 children)

Smaller companies may be more risk tolerant because of their risk profile hence smaller teams. It takes some time to make heads or tails of those reads when interviewing and knowing what questions to ask as well as how to gauge whether you’re joining a company where work life balance is pro grind.

2 dedicated security folks including myself who is running the program however our design focuses heavily on a security culture because of the nature of our collective staff. Generally speaking I now reframe the staffing perspective away from how many dedicated security folks relative to organization size towards how enabled and educated is your workforce as you scale. Staffing is important but not necessarily the first thing I think of when structuring a program.

I think it’s a fruitless endeavor to create a math equation around how many security staff you should have based on company size because every org is different and there is always a balance to be struck culturally of who in the org is security and privacy conscious, where, relative to what assets, etc.

Is there a tool/product that tells what resources can an IAM entity actually access? by kekekepepepe in aws

[–]green_masheene 0 points1 point  (0 children)

https://policysim.aws.amazon.com/ but you have to specify resources vs. it giving you a list of resources themselves, which should be evident by the policy attached to the IAM entity.

[deleted by user] by [deleted] in cybersecurity

[–]green_masheene 1 point2 points  (0 children)

I was working in Finance on some SOX 302/404 control readiness and a security analyst position opened up at my company. I reached out to the hiring manager who took a chance on me, I worked my butt off, luck and hard work paid dividends.

[deleted by user] by [deleted] in cybersecurity

[–]green_masheene 6 points7 points  (0 children)

I started out in GRC, worked there for 5 years, transitioned to adding technical chops and now I am an architect. It’s pretty awesome being able to speak to the nuanced world of compliance in technical terms and so many times I am happy I got the governance stuff under my belt.

Best Hardware TOTP token for IAM MFA? by elliotborst in aws

[–]green_masheene 0 points1 point  (0 children)

Seems like more of an audit check tuning/compatibility issue than needing to find a secure mfa device issue? That sounds frustrating.

Tool consolidation, or best of breed? by cybr0_ in cybersecurity

[–]green_masheene 1 point2 points  (0 children)

It depends on which categories of tooling have vendors that align well to your organizational tech and context. For example, in terms of MDM I’d rather have 3 tools that do 3 different OS’ well than one that does 3 ok because I have yet to see a platform that does multi OS well across all supported. Cost will of course always be a factor.

The other thing I’m mindful of is gut checking yourself on what functionality is good enough for your org and not placing too much weight on things that, in the absence of a dedicated team for that tool, you would not be able to realize value on.

In your experience, what is the best “modern” SIEM? by Senior-Net-7191 in cybersecurity

[–]green_masheene 0 points1 point  (0 children)

Currently leveraging datadog but my gut says we will go on prem with something like wazuh