All Jupiter Broadcasting Shows

Rebuilding it Better | TechSNAP 362


Listen Later

It’s a TechSNAP introduction to Terraform, a tool for building, changing, and versioning infrastructure safely and efficiently.

Plus a recent spat of data leaks suggest a common theme, Microsoft’s self inflicted Total Meltdown flaw, and playing around with DNS Rebinding attacks for fun.

The Under Armour Hack Was Even Worse Than It Had To Be

Under Armour Inc (UAA.N) (UA.N) said on Thursday that data from some 150 million MyFitnessPal diet and fitness app accounts was compromised in February, in one of the biggest hacks in history, sending shares of the athletic apparel maker down 3 percent in after-hours trade.

Panerabread.com Leaks Millions of Customer Records

The data available in plain text from Panera’s site appeared to include records for any customer who has signed up for an account to order food online via panerabread.com.

  • No, Panera Bread Doesn’t Take Security Seriously
  • tl;dr: In August 2017, I reported a vulnerability to Panera Bread that allowed the full name, home address, email address, food/dietary preferences, username, phone number, birthday and last four digits of a saved credit card to be accessed in bulk for any user that had ever signed up for an account. This includes my own personal data! Despite an explicit acknowledgement of the issue and a promise to fix it, Panera Bread sat on the vulnerability and, as far as I can tell, did nothing about it for eight months. When Brian Krebs publicly broke the news, other news outlets emphasized the usual “We take your security very seriously, security is a top priority for us” prepared statement from Panera Bread. Worse still, the vulnerability was not fixed at all — which means the company either misrepresented its actual security posture to the media to save face or was not competent enough to determine this fact for themselves. This post establishes a canonical timeline so subsequent reporting doesn’t get confused.

    Total Meltdown?

    Meet the Windows 7 Meltdown patch from January. It stopped Meltdown but opened up a vulnerability way worse ... It allowed any process to read the complete memory contents at gigabytes per second, oh - it was possible to write to arbitrary memory as well.

    Terraform

    HashiCorp Terraform enables you to safely and predictably create, change, and improve infrastructure. It is an open source tool that codifies APIs into declarative configuration files that can be shared amongst team members, treated as code, edited, reviewed, and versioned.

    • Terraforming 1Password
    • Compared to the JSON or YAML files used by CloudFormation, Terraform HCL is both a more powerful and a more readable language. Here is a small example of a snippet that defines a subnet for the application servers. As you can see, the Terraform code is a quarter of the size, more readable, and easier to understand.

      Feedback
      • Whonow: A malicious DNS server for executing DNS Rebinding attacks on the fly
      • ...more
        View all episodesView all episodes
        Download on the App Store

        All Jupiter Broadcasting ShowsBy Jupiter Broadcasting

        • 4.9
        • 4.9
        • 4.9
        • 4.9
        • 4.9

        4.9

        89 ratings


        More shows like All Jupiter Broadcasting Shows

        View all
        The Changelog: Software Development, Open Source by Changelog Media

        The Changelog: Software Development, Open Source

        288 Listeners

        Coder Radio by The Mad Botter

        Coder Radio

        152 Listeners

        The Vergecast by The Verge

        The Vergecast

        3,718 Listeners

        LINUX Unplugged by Jupiter Broadcasting

        LINUX Unplugged

        272 Listeners

        Talk Python To Me by Michael Kennedy

        Talk Python To Me

        582 Listeners

        Unfilter by Chris Fisher

        Unfilter

        152 Listeners

        Late Night Linux by The Late Night Linux Family

        Late Night Linux

        164 Listeners

        Ask Noah Show by Noah J. Chelliah

        Ask Noah Show

        38 Listeners

        Home Assistant Podcast by HK Media

        Home Assistant Podcast

        69 Listeners

        Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

        Syntax - Tasty Web Development Treats

        989 Listeners

        Darknet Diaries by Jack Rhysider

        Darknet Diaries

        8,093 Listeners

        Late Night Linux Family All Episodes by The Late Night Linux Family

        Late Night Linux Family All Episodes

        47 Listeners

        Self-Hosted by Jupiter Broadcasting

        Self-Hosted

        142 Listeners

        2.5 Admins by The Late Night Linux Family

        2.5 Admins

        97 Listeners

        Oxide and Friends by Oxide Computer Company

        Oxide and Friends

        67 Listeners

        Diggnation (Rebooted) by Kevin Rose

        Diggnation (Rebooted)

        195 Listeners