Screaming in the Cloud

Helping Securing the Python with Mike Fiedler


Listen Later

On this Screaming in the Cloud In this episode of Screaming in the Cloud, Corey Quinn is joined by AWS container hero and security engineer at the Python Software Foundation, Mike Fiedler. They delve into the intricacies of Python's ecosystem, discussing the evolution of PyPI, its significance, and the ongoing battles against security threats like account takeover attacks and typo-squatting. Mike sheds light on his role in maintaining the security and reliability of the Python Package Index, the importance of 2FA, and the collaborative efforts with security researchers. Corey and Mike also explore the challenges and philosophies surrounding legacy systems versus greenfield development, with insights on maintaining critical infrastructure and the often-overlooked aspects of social engineering.



Show Highlights

(0:00) Introduction

(0:47) The Duckbill Group sponsor read

(1:21) Breaking down the Python nomenclature and its usability

(5:49) Figuring out how Boto3 is one of the most downloaded packages

(6:43) Why Mike is the only full-time security and safety engineer at the Python Software Foundation

(9:53) How the Python Software Foundation affords to operate

(14:17) Mike's stack security work

(16:14) The Duckbill Group sponsor read

(16:57) Having the "impossible job" of stopping supply chain attacks

(21:00) The dangers of social engineering attacks

(24:44) Why Mike prefers to work on legacy systems

(33:30) Where you can find more from Mike



About Mike Fiedler

Mike Fiedler is a highly analytical, forward-thinking Information Technology professional. His broad-based background includes systems administration and engineering in global environments. Mike is technically astute and versatile with ability to quickly learn, master, and leverage new technologies to meet business needs and has a track record of success in improving performance, stability, and security for all infrastructure and product initiatives.

Mike is also bilingual, speaks English and Hebrew, and he loves solving puzzling problems.



Links

  • Mike’s Mastadon: https://hachyderm.io/@miketheman
  • Mike’s Bluesky: https://bsky.app/profile/miketheman.com
  • Mike’s Python Software Foundation blog posts: https://blog.pypi.org/
  • The Python Package Index Safety & Security Engineer: First Year in Review: https://blog.pypi.org/posts/2024-08-16-safety-and-security-engineer-year-in-review/



Sponsor

The Duckbill Group: duckbillgroup.com 

...more
View all episodesView all episodes
Download on the App Store

Screaming in the CloudBy Corey Quinn

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

92 ratings


More shows like Screaming in the Cloud

View all
Hanselminutes with Scott Hanselman by Scott Hanselman

Hanselminutes with Scott Hanselman

377 Listeners

Software Engineering Radio - the podcast for professional software developers by se-radio@computer.org

Software Engineering Radio - the podcast for professional software developers

272 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

284 Listeners

The Cloudcast by Massive Studios

The Cloudcast

152 Listeners

Thoughtworks Technology Podcast by Thoughtworks

Thoughtworks Technology Podcast

40 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

621 Listeners

AWS Podcast by Amazon Web Services

AWS Podcast

201 Listeners

CoRecursive: Coding Stories by Adam Gordon Bell - Software Developer

CoRecursive: Coding Stories

189 Listeners

Techmeme Ride Home by Brian McCullough

Techmeme Ride Home

941 Listeners

Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

Kubernetes Podcast from Google

181 Listeners

Practical AI by Practical AI LLC

Practical AI

192 Listeners

AWS Morning Brief by Corey Quinn

AWS Morning Brief

77 Listeners

The Stack Overflow Podcast by The Stack Overflow Podcast

The Stack Overflow Podcast

62 Listeners

Oxide and Friends by Oxide Computer Company

Oxide and Friends

47 Listeners

The Pragmatic Engineer by Gergely Orosz

The Pragmatic Engineer

53 Listeners