TechSNAP

TechSNAP

By Jupiter BroadcastingNewsTech News
Download on the App Store

TechSNAP episodes

  • 394: All About Azure

    Wes is joined by a special guest to take a look back on the growth and development of Azure in 2018 and discuss some of its unique strengths.

    Special Guest: Chad M. Crowell.

    Links:

    • Under the sea, Microsoft tests a datacenter that’s quick to deploy, could provide internet connectivity for years
  • An Azure Infrastructure Year in Review
  • Azure File Sync now generally available
  • Microsoft's Newest OS is Based on Linux
  • Azure Sphere
  • What is Azure Stack?
  • Azure Outage Proves the Hard Way Availability Zones are a Good Idea
  • Microsoft Azure Infrastructure and Deployment on Linux Academy
  • — In this course, we will cover an introduction to the Azure portal, followed by how to build infrastructure and deploy that infrastructure in real world scenarios.
  • Chad Crowell on Twitter
  • 27 min
  • 393: Back to our /roots

    In a special new year’s episode we take a moment to reflect on the show’s past, its future, and say goodbye to an old friend.

    Links:

    • Jim Salter
    — Jim Salter (@jrssnet) is an author, public speaker, small business owner, mercenary sysadmin, and father of three—not necessarily in that order. He got his first real taste of open source by running Apache on his very own dedicated FreeBSD 3.1 server back in 1999, and he's been a fierce advocate of FOSS ever since.
  • Jim Salter on Twitter
  • Dropbox Flaws | TechSNAP | 1
  • PSN Breech Details | TechSNAP 3
  • 2089 Days Uptime | TechSNAP 300
  • 23 min
  • 392: Keeping up with Kubernetes

    A security vulnerability in Kubernetes causes a big stir, but we’ll break it all down and explain what went wrong.

    Plus the biggest stories out of Kubecon, and serverless gets serious.

    Links:

    • Everything that was announced at KubeCon
  • CNCF to Host etcd
  • — The Cloud Native Computing Foundation Technical Oversight Committee voted to accept etcd as an incubation-level hosted project.
  • Introduction to Knative
  • — Knative is a framework from the folks at Google and Pivotal focused on “serverless” style event driven functions.
  • IBM Embraces Knative to Drive Serverless Standardization
  • — Knative is not the first open-source functions-as-a-service effort that IBM has backed. Back in 2016, IBM announced the OpenWhisk effort, which is now run as an open-source project at the Apache Software Found.
  • How Google Is Improving Kubernetes Container Security
  • — "We go beyond what's in open source and put additional restrictions in place to secure users"
  • Demystifying Kubernetes CVE-2018-1002105
  • — With a specially crafted request, users that are authorized to establish a connection through the Kubernetes API server to a backend server can then send arbitrary requests over the same connection directly to that backend, authenticated with the Kubernetes API server’s TLS credentials used to establish the backend connection.
  • The silent CVE in the heart of Kubernetes apiserver
  • Crossplane: An Open Source Multicloud Control Plane
  • security.christmas
  • — This year we will prepare you for the Christmas celebration, by giving you small presents of knowledge every day, which will teach you about the world of security.
  • Introducing the Helm Hub
  • — This hub provides a means for you to find charts hosted in many distributed repositories hosted by numerous people and organizations.
    28 min
  • Episode 391: Firecracker Fundamentals

    We break down Firecracker Amazon’s new open source kvm powered, virtual machine monitor, and explore what makes it different from the options on the market now.

    Plus some good news for OpenBGP and the wider internet community, and a handy tool for inspecting docker images.

    Links:

    • Firecracker – Lightweight Virtualization for Serverless Computing
    — Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant containers and functions-based services.
  • Firecracker
  • — Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant containers and functions-based services.
  • Firecracker Design Docs
  • Firecracker Roadmap
  • QEMU
  • — QEMU is a generic and open source machine emulator and virtualizer.
  • Qemu : Security vulnerabilities
  • VENOM Vulnerability
  • — VENOM, CVE-2015-3456, is a security vulnerability in the virtual floppy drive code used by many computer virtualization platforms. This vulnerability may allow an attacker to escape from the confines of an affected virtual machine (VM) guest and potentially obtain code-execution access to the host.
  • s2n
  • — s2n is a C99 implementation of the TLS/SSL protocols that is designed to be simple, small, fast, and with security as a priority.
  • OpenBGPD - Adding Diversity to the Route Server Landscape
  • — Thanks to the RIPE NCC Community Project Fund we were able to revive the OpenBGPD daemon and bring more diversity to the Route Server landscape.
  • OpenBGPD
  • — OpenBGPD is a FREE implementation of the Border Gateway Protocol, Version 4. It allows ordinary machines to be used as routers exchanging routes with other systems speaking the BGP protocol.
  • LSI Questions from Anton
  • ServeTheHome
  • Sennheiser Headset Software Could Allow Man-in-the-Middle SSL Attacks
  • — When users have been installing Sennheiser's HeadSetup software, little did they know that the software was also installing a root certificate into the Trusted Root CA Certificate store.  To make matters worse, the software was also installing an encrypted version of the certificate's private key that was not as secure as the developers may have thought.
  • evilginx2: Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
  • dive: A tool for exploring each layer in a docker image
  • 22 min
  • Episode 390: What’s Up with WireGuard

    WireGuard has a lot of buzz around it and for many good reasons. We’ll explain what WireGuard is specifically, what it can do, and maybe more importantly, what it can’t.

    Special Guest: Jim Salter.

    Links:

    • How to easily configure WireGuard
    — At its core, all WireGuard does is create an interface from one computer to another.
  • Jessie Frazelle's Blog: Installing and Using Wireguard, obviously with containers
  • — What is cool about Wireguard is it integrates into the Linux networking stack.
  • WireGuard Didn't Make it To The Mainline Linux Kernel This Cycle
  • — The code continues to be improved upon but looks like it came up just short of making it into this current development cycle.
  • WireGuard VPN review: A new type of VPN offers serious advantages
  • — Fewer lines of code, simpler setup, and better algorithms make a strong case.
  • The Current Status of WireGuard VPNs - Are We There Yet?
  • Using a free VPN? Why not skip the middleman and just send your data to President Xi?
  • Feedback from Cody
  • NRE Labs
  • — NRE Labs is a no-strings-attached, community-centered initiative to bring the skills of automation within reach for everyone
  • Introduction to Antidote
  • — Antidote is an open-source project aimed at making automated network operations more accessible with fast, easy and fun learning.
  • StackStorm
  • — From simple if/then rules to complicated workflows, StackStorm lets you automate DevOps your way.
  • wireguard-private-networking: Build your own multi server private network using wireguard and ansible
  • Algo: Set up a personal IPSEC or WireGuard VPN in the cloud
  • 35 min
  • Episode 389: The Future of HTTP

    Wes is joined by special guest Jim Salter to discuss Google's recent BGP outage and the future of HTTP.

    Plus the latest router botnet, why you should never go full UPnP, and the benefits of building your own home router.

    Special Guest: Jim Salter.

    Links:

    • Google goes down after major BGP mishap routes traffic through China
    — Google lost control of several million of its IP addresses for more than an hour on Monday in an event that intermittently made its search and other services unavailable to many users.
  • Internet Vulnerability Takes Down Google
  • China has been 'hijacking the vital internet backbone of western countries'
  • RPKI - The required cryptographic upgrade to BGP routing
  • HTTP/3
  • — The protocol that's been called HTTP-over-QUIC for quite some time has now changed name and will officially become HTTP/3.
  • HTTP/3: Come for the speed, stay for the security
  • The Road to QUIC
  • Botnet pwns 100,000 routers using ancient security flaw
  • — Researchers have stumbled on another large botnet that’s been quietly hijacking home routers while nobody was paying attention
  • BCMPUPnP_Hunter: A 100k Botnet Turns Home Routers to Email Spammers
  • From Zero to ZeroDay Journey: Router Hacking
  • The Ars guide to building a Linux router from scratch
  • 44 min
  • Episode 388: The One About eBPF

    We explain what eBPF is, how it works, and its proud BSD production legacy.

    eBPF is a technology that you’re going to be hearing more and more about. It powers low-overhead custom analysis tools, handles network security in a containerized world, and powers tools you use every day.

    Links:

    • Chris Goes to MeetBSD
  • ​Linus Torvalds talks about coming back to work on Linux | ZDNet
  • — BPF has actually been really useful, and the real power of it is how it allows people to do specialized code that isn't enabled until asked for.
  • The Kernel Report - Jonathan Corbet
  • BPF - the forgotten bytecode
  • — All this changed in 1993 when Steven McCanne and Van Jacobson published the paper introducing a better way of filtering packets in the kernel, they called it "The BSD Packet Filter" (BPF)
  • The BSD Packet Filter
  • eBPF: Past, Present, and Future
  • — The Extended Berkeley Packet Filter, or eBPF, has rapidly been adopted into a number of Linux kernel systems since its introduction into the Linux kernel in late 2014. Understanding eBPF, however, can be difficult as many try to explain it via a use of eBPF as opposed to its design. Indeed eBPF's name indicates that it is for packet filtering even though it now has uses which have nothing to do with networking.
  • Using eBPF in Kubernetes
  • — Cilium is a networking project that makes heavy use of eBPF superpowers to route and filter network traffic for container-based systems. By using eBPF, Cilium can dynamically generate and apply rules—even at the device level with XDP—without making changes to the Linux kernel itself
  • Why is the kernel community replacing iptables with BPF?
  • — The Linux kernel community recently announced bpfilter, which will replace the long-standing in-kernel implementation of iptables with high-performance network filtering powered by Linux BPF, all while guaranteeing a non-disruptive transition for Linux users.
  • bpftrace (DTrace 2.0) for Linux 2018
  • — Created by Alastair Robertson, bpftrace is an open source high-level tracing front-end that lets you analyze systems in custom ways. It's shaping up to be a DTrace version 2.0: more capable, and built from the ground up for the modern era of the eBPF virtual machine.
  • The bpftrace One-Liner Tutorial
  • BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more
  • — BCC is a toolkit for creating efficient kernel tracing and manipulation programs, and includes several useful tools and examples.
  • Linux eBPF Tracing Tools
  • — This page shows examples of performance analysis tools using enhancements to BPF (Berkeley Packet Filter) which were added to the Linux 4.x series kernels, allowing BPF to do much more than just filtering packets. These enhancements allow custom analysis programs to be executed on Linux dynamic tracing, static tracing, and profiling events.
  • eBPF Vulnerability (CVE-2017-16995): When the Doorman Becomes the Backdoor
  • Ultimate Plumber
  • — Ultimate Plumber is a tool for writing Linux pipes with instant live preview
  • BSD Now 073: Pipe Dreams
  • — Interview w/ David Maxwell about Pipecut, text processing, and commandline wizardry.
    37 min
  • Episode 387: Private Cloud Building Blocks

    We bring in Amy Marrich to break down the building blocks of OpenStack. There are nearly an overwhelming number of ways to manage your infrastructure, and we learn about one of the original tools.

    Plus a few warm up stories, a war story, and more.

    Special Guest: Amy Marrich.

    Links:

    • James Stanley - Someone used my IPFS gateway for phishing
  • Scaling Engineering Teams via Writing Things Down and Sharing
  • — I have recently been talking at small and mid-size companies, sharing engineering best practices I see us use at Uber, which I would recommend any tech company adopt as they are growing. The one topic that gets both the most raised eyebrows, as well the most "aha!" moments is the one on how the planning process for engineering has worked since the early years of Uber.
  • Say hello to Kata Containers
  • — Kata Containers bridges the gap between traditional VM security and the lightweight benefits of traditional Linux containers.
  • Disappearing videos and disappointed grandmothers
  • — Here's another story about broken things with some of the details changed just a little. If it sounds familiar, it's probably because your company also did it at some point.
    34 min
  • Episode 386: What Makes Google Cloud Different

    We bring on our Google Cloud expert and explore the fundamentals, demystify some of the magic, and ask what makes Google Cloud different.

    Plus how Google hopes Roughtime will solve one of the web’s biggest problems, some great emails, and more!

    Special Guest: Matt Ulasien.

    Links:

    • Cloudflare Embraces Google Roughtime, Giving Internet Security a Boost
    — The internet infrastructure firm Cloudflare will now support a free timekeeping protocol known as Roughtime, which helps synchronize the internet's clocks and validate timestamps.
  • Roughtime: Securing Time with Digital Signatures
  • — Roughtime lacks the precision of NTP, but aims to be accurate enough for cryptographic applications, and since the responses are authenticated, man-in-the-middle attacks aren’t possible
  • Google Cloud rolls out security feature for container images
  • — All container images built using Cloud Build, Google's fully-managed CI/CD platform, will now be automatically scanned for OS package vulnerabilities
  • Tweets by Matthew Ulasien (@mulasien)
  • Google Cloud Weekly | 10.03.2018
  • Matthew Ulasien - Quora
  • Google Certified Professional Cloud Architect
  • Feedback: Can't Even Google This One!
  • Feedback: The Button Pusher Problem
  • Feedback: Can I monitor that?
  • Pingdom
  • Site24x7
  • prometheus/blackbox_exporter: Blackbox prober exporter
  • Kubernetes the Hard Way - Course
  • How do Kubernetes Deployments work? An adversarial perspective.
  • — What is happening when a Deployment rolls out a change to your app? What does it actually do when a Pod crashes or is killed? What happens when a Pod is re-labled so that it's not targeted by the Deployment?
  • Kubernetes: The Surprisingly Affordable Platform for Personal Projects
  • — I think that Kubernetes makes sense for small projects and you can have your own Kubernetes cluster today for as little as $5 a month.
  • Kubernetes for personal projects? No thanks!
  • — I have read multiple times this article about running Kubernetes to run small projects and thought I could share why I think that might not be a great idea.
  • KubeDirector: The easy way to run complex stateful applications on Kubernetes
  • — KubeDirector is an open source project designed to make it easy to run complex stateful scale-out application clusters on Kubernetes.
  • Kubernetes On Bare Metal
  • — This guide will take you from nothing to a 2 node cluster, automatic SSL for deployed apps, a custom PVC/PV storage class using NFS, and a private docker registry.
  • Introducing DigitalOcean Kubernetes in Limited Availability
  • 35 min
  • Episode 385: 3 Things to Know About Kubernetes

    Kubernetes expert Will Boyd joins us to explain the top 3 things to know about Kubernetes, when it’s the right tool for the job, and building highly available production grade clusters.

    Plus the privacy improvements that could be coming to HTTPS, and a new SSH auditing tool hits the open source scene.

    Special Guest: Will Boyd.

    Links:

    • Open Sourcing HASSH
    — HASSH is a network fingerprinting standard invented within the Detection Cloud team at Salesforce.
  • ESNI: A Privacy-Protecting Upgrade to HTTPS
  • — Today, Cloudflare is announcing a major step toward closing this privacy hole and enhancing the privacy protections that HTTPS offers. Cloudflare has proposed a technical standard for encrypted SNI, or “ESNI,” which can hide the identities of the sites you visit—particularly when a large number of sites are hosted on a single set of IP addresses
  • What's new in Kubernetes 1.12?
  • Kubernetes the Hard Way
  • — Kubernetes The Hard Way guides you through bootstrapping a highly available Kubernetes cluster with end-to-end encryption between components and RBAC authentication.
  • Install Minikube
  • Creating a single master cluster with kubeadm
  • 10 open-source Kubernetes tools for highly effective SRE and Ops Teams
  • Clonezilla
  • — Clonezilla is a partition and disk imaging/cloning program similar to True Image or Norton Ghost.
    24 min

About TechSNAP

From the publisher's feed

Systems, Network, and Administration Podcast. Every two weeks TechSNAP covers the stories that impact those of us in the tech industry, and all of us that follow it. Every episode we dedicate a…

More shows like TechSNAP

Packet Protector by Packet Pushers

Packet Protector

7 Listeners