Three Devs and a Maybe

Three Devs and a Maybe

By Michael Budd, Fraser Hart, Lewis Cains, Edd MannTechnologyEducation
Download on the App Store

Three Devs and a Maybe episodes

  • 144: Build, Provision and Deploy in the Cloud with Thijs Feryn

    In this weeks episode we are joined by Thijs Feryn to discuss his upcoming PHP UK conference talk.

    We start of the show highlighting what drew him to a Tech. evangelist role, bridging the gap between code/infrastructure and the ideas behind ‘Infrastructure as Code’.
    From here we move on to discuss system and infrastructure provisioning automation tools such Ansible and Terraform.
    This leads on to adding Packer into the mix, moving towards immutable infrastructure, testing these automation tools and how history has a way of repeating itself.
    Finally, we touch upon the philosophy behind DevOps, focusing on empathy and its core values CAMS.

    Show Links
    • Thijs Feryn - Technical evangelist, speaker, author, blogger, vlogger
    • Build, provision & deploy in the Cloud with Packer, Ansible & Terraform - PHPUK 2018 - Thijs Feryn
    • Ansible is Simple IT Automation
    • Terraform by HashiCorp
    • Packer by HashiCorp
    • Terraform Module Registry
    • Snowflake Server
    • Phoenix Server
    • The Phoenix Project - A Novel About IT, DevOps, and Helping Your Business Win
    • Gene Kim
    • What is DevOps?
    • CAMS - DevOps Dictionary
    • 48 min
    • 143: Symmetric and Asymmetric Encryption with Scott Arciszewski

      In this weeks episode we are lucky to be joined again by Scott Arciszewski.

      We start off the show by discussing the difference between Symmetric and Asymmetric Encryption, what Authenticated Encryption is and how secret-keys are exchanged using Diffie-Hellman.
      From here, we move on to highlight how Elliptic-curve cryptography works, what DNSCrypt is and why prime numbers are so important in cryptography.
      Finally, we touch upon multi-factor authentication, how one time passwords work, SMS vulnerabilities and how to manage password recovery.

      Show Links
      • Scott Arciszewski on Twitter
      • You Wouldn’t Base64 a Password - Cryptography Decoded - Paragon Initiative Enterprises Blog
      • Sealed boxes - libsodium
      • Diffie-Hellman Key Exchange - YouTube
      • The Padding Oracle Attack - why crypto is terrifying
      • paragonie/EasyRSA - Simple and Secure Wrapper for phpseclib
      • Can you explain Bleichenbacher’s CCA attack on PKCS#1 v1.5?
      • ZF2015-10 - Potential Information Disclosure in Zend\Crypt\PublicKey\Rsa\PublicKey
      • Why should I use Authenticated Encryption instead of just encryption? - Cryptography Stack Exchange
      • defuse/php-encryption - Simple Encryption in PHP.
      • paragonie/paseto - Platform-Agnostic Security Tokens
      • Trapdoor functions
      • Discrete Logarithm Problem
      • Practical Invalid Curve Attacks
      • DNS Security with DNSCrypt - OpenDNS
      • Public key infrastructure
      • How I exploited ACME TLS-SNI-01 issuing Let’s Encrypt SSL-certs for any domain using shared hosting
      • paragonie/multi_factor - Vendor-Agnostic Two-Factor Authentication
      • Signal Protocol
      • Split Tokens - Token-Based Authentication Protocols without Side-Channels - Paragon Initiative Enterprises Blog
      • paragonie/gpg-mailer - GnuPG-encrypted emails made easy
      • Email Self-Defense - a guide to fighting surveillance with GnuPG encryption
      • 1 hr 4 min
      • 142: Domain Modeling Made Functional with Scott Wlaschin

        In this weeks episode we chat to Scott Wlaschin about his new book ‘Domain Modeling Made Functional’.

        We start off the show discussing how the book came to be, the process of writing a book and melding the worlds of Domain Modeling/Functional Programing.
        This leads us on to highlight what Domain Driven Design is, the importance of communication and the difference between the solution/problem space to garner a shared model.
        Finally, we touch upon some of the common patterns that come out of modeling domains such as - how Entities and Value Objects provide identity, maintaing invariants using Aggregates, and communication between modals via Anti-Corruption Layers.

        Show Links
        • Scott Wlaschin on Twitter
        • Domain Modeling Made Functional - The Pragmatic Bookshelf
        • F# for fun and profit
        • Domain Driven Design - F# for fun and profit
        • The Tale of State and Behaviour, Part 1 with Scott Wlaschin - Three Devs and a Maybe
        • The Tale of State and Behaviour, Part 2 with Scott Wlaschin - Three Devs and a Maybe
        • Programming Like Functions Matter with Jimmy Burrell and Scott Wlaschin - Three Devs and a Maybe
        • Scott Wlaschin - F# and Domain Driven Design - YouTube
        • Dan North - Accelerating Agile, hyper-performing teams without the hype
        • Domain-Driven Design - Tackling Complexity in the Heart of Software
        • Rich Hickey - Effective Programs - YouTube
        • The Design of Everyday Things - Donald A. Norman
        • About Face - The Essentials of Interaction Design - Alan Cooper
        • Crossing the Chasm - Marketing and Selling Technology Products to Mainstream Customers - Geoffrey A. Moore
        • The Innovator’s Dilemma - When New Technologies Cause Great Firms to Fail - Clayton M. Christensen
        • 1 hr 9 min
        • 141: Web Application Security, Part 2 with Scott Arciszewski

          In this weeks episode we continue our discussion with Scott Arciszewski about all things Security and Cryptography.

          We start off the show by highlighting what a SQL injection attack is and the differences between (emulated) prepared statements.
          This leads us on to look into how to securely handle file uploads, what a reverse shell is and how to defend yourself against XSS/CSRF attacks.
          From here we touch upon the recent inclusion of libsodium into PHP, why mcrypt should be avoided, and the side-channel vulnerabilities that brought way to Meltdown and Spectre.
          Finally, we mention how computers generate seemingly random numbers, what a Web Application Firewall (WAF) is, and how WARD goes about protecting your systems.

          Show Links
          • Scott Arciszewski on Twitter
          • Paragon Initiative Enterprises
          • The 2018 Guide to Building Secure PHP Software
          • Are PDO prepared statements sufficient to prevent SQL injection?
          • Preventing SQL Injection in PHP Applications
          • paragonie/easydb - Easy-to-use PDO wrapper for PHP projects.
          • Security at the expense of usability comes at the expense of security.
          • Security B-Sides Orlando 2017
          • TimThumb WebShot Code Execution Exploit (Zeroday)
          • Reverse shell !?!
          • paragonie/anti-csrf - Full-Featured Anti-CSRF Library
          • Using Libsodium in PHP Projects
          • paragonie/sodium_compat - Pure PHP polyfill for ext/sodium
          • libsodium
          • It Turns Out, 2017 is the Year of Simply Secure PHP Cryptography
          • The ECB Penguin
          • Cache-timing attacks on AES
          • Side-Channel Attacks on Everyday Applications
          • Meltdown and Spectre
          • PCID is now a critical performance/security feature on x86
          • If You’re Typing the Word MCRYPT Into Your PHP Code, You’re Doing It Wrong
          • Myths about /dev/urandom
          • PHP - random_bytes
          • PHP - random_int
          • Ward - Web Application Realtime Defender
          • 1 hr
          • 140: Web Application Security, Part 1 with Scott Arciszewski

            In this weeks episode we chat with Scott Arciszewski about all things Security and Cryptography.

            We start off the show by explaining how he got interested in this field of work, correcting PHP security related answers on Stack Overflow and why he focuses on PHP security.
            From here, we move on to highlight what the OWASP Top Ten is, how you can distill many security principles into data/code seperation and what is involved in a software audit.
            This leads us on to discuss what HTTPS actually is, touching on TLS, PKI’s, Ciphersuites, and reported attacks against TLS and ECB.
            Finally, we highlight some important browser security features that can be used, pushing new software releases in a secure manor, thoughts on Cryptocurrencies and how everyone wants to solve their problem with a blockchain at this time.

            Show Links
            • Scott Arciszewski on Twitter
            • Paragon Initiative Enterprises
            • The 2018 Guide to Building Secure PHP Software
            • RPG Maker
            • Hack This Site!
            • The Enigma Group
            • PHP Password Hashing
            • Problematic PHP Cryptography Advice in Popular Questions - Meta Stack Overflow
            • Usage Statistics of Server-side Programming Languages for Websites
            • Hardened-PHP Project
            • The Month of PHP Security
            • Psalm - a static analysis tool for PHP
            • OWASP Top Ten Project
            • Burp Suite Scanner
            • OWASP Zed Attack Proxy Project
            • On The Design and Implementation of a Stealth Backdoor for Web Applications
            • Padding oracle attack
            • Public key infrastructure
            • PCI Council pushes back TLS 1.0 End of Life Date to June 2018
            • The ECB Penguin
            • Attacks against Transport Layer Security
            • DigiNotar SSL certificate hack amounts to cyberwar, says expert
            • Is TLS Fast Yet?
            • Content Security Policy - An Introduction
            • Subresource Integrity
            • CMS Airship - Secure PHP CMS for the Modern Web
            • paragonie/chronicle - Public append-only ledger microservice built with Slim Framework
            • Zcash - All coins are created equal.
            • 47 min
            • 139: Mobile Internet isn't Cheap! with Joe Watkins

              In this episode we catch up with Joe Watkins to discuss all things PHP.

              We start off discussion with his recent move to Spain, the pain of getting a good Internet connection and PHP TestFest.
              This leads us on to highlight some recent work he is doing with adding PHP bindings to Bicoin’s Secp256k1 library and a Generic Traits idea.
              From here we touch upon the additions that made it into PHP 7.2 and some that have already been accepted for 7.3.
              Finally, we get Joe’s opinion on a couple of RFC’s (Call-site pass-by-reference and Operator functions).

              Show Links
              • Accessing the internet is giving me a headache, until I look out the window…
              • Musings, ninja ones - Test Etiquette
              • PHP TestFest
              • krakjoe/wkhtmltox - Converting HTML to X since 2017
              • Secp256k1 - Bitcoin Wiki
              • bitcoin-core/secp256k1 - Optimized C library for EC operations on curve secp256k1
              • How to find and patch a bug in PHP source - Sammy Kaye Powers
              • Writing tests for PHP source - Sammy Kaye Powers
              • PHP 7.2.0 Release Announcement
              • PHP - libsodium
              • Lightweight Directory Access Protocol
              • PHP - pack
              • PHP - unpack
              • PHP RFC - UUID
              • PHP RFC - Explicit call-site pass-by-reference
              • PHP RFC - Operator functions
              • 46 min
              • 138: Everything Serverless with Andy Raines

                In this weeks episode we chat to Andy Raines about all things Serverless.

                We start off by discussing what Serverless actually means, advantages of using such a model, design constraints it employs and how it scales.
                From here we touch upon the history of how we got to the compute/infrastructure we use today: from on-premise servers, IaaS, PaaS and FaaS/BaaS.
                This leads us on to highlight the 12-factor app methodology, how immutability has vast benefits in many contexts and how FaaS platforms work under-the-hood.
                Finally, we mention the Serverless PHP project Andy is working on, the motivations behind it and future development he would like to see take place.

                Show Links
                • Andy Raines on Twitter
                • Getting Started With Serverless PHP - SkillsCast
                • Getting started with PHP Serverless - A Cloud Guru
                • araines/serverless-php - PHP for AWS Lambda via Serverless Framework
                • AWS Lambda - Serverless Compute
                • IaaS vs CaaS vs PaaS vs FaaS - Choosing the Right Platform
                • Infrastructure as a Service (IaaS)
                • Platform as a Service (PaaS)
                • Function as a Service (FaaS)
                • Backend as a Service (BaaS)
                • How AWS came to be - TechCrunch
                • Amazon EC2 Reserved Instances
                • The Twelve-Factor App
                • Serverless Architectures
                • Amazon API Gateway
                • Keeping Functions Warm - How To Fix AWS Lambda Cold Start Issues
                • Understanding AWS Lambda Performance
                • Serverless - The Serverless Application Framework
                • Facebooks Parse developer platform is shutting down today - TechCrunch
                • Apache OpenWhisk
                • Azure Functions
                • 1 hr 8 min
                • 137: Putting all your Fish in one Basket

                  In this weeks episode Mick and Edd first touch upon the many new services/features that have been released at AWS re:Invent.

                  We then move on to discuss Serverless architecture, Server architectural patterns, Amazon Cognito and security/encryption that is available within Amazon Web Services.
                  This leads us on to highlight the impact of relying on a single company for all your compute/infrastructure needs and ‘putting all your fish in one basket’.
                  Finally, Mick tells us what Santa might be bringing him for Christmas.

                  Show Links
                  • re:Invent 2017 - New Products and Services
                  • Amazon SageMaker - Accelerating Machine Learning
                  • Amazon Lightsail adds load balancers with integrated certificate management
                  • AWS DeepLens - Get Hands-On Experience with Deep Learning With Our New Video Camera
                  • Amazon Comprehend - Continuously Trained Natural Language Processing
                  • Amazon Transcribe - Accurate Speech To Text At Scale
                  • AWS IoT One Click
                  • Amazon Aurora - Auto-Scaling Serverless Database Service
                  • Key Management Service - Amazon Web Services
                  • Environment Variables - AWS Lambda
                  • Create a Lambda Function Using Environment Variables To Store Sensitive Information
                  • Protecting Data Using Encryption - Amazon Simple Storage Service
                  • Ada (programming language)
                  • Bring your own encryption
                  • ‘Memes as a Service’ using Lambda, Serverless and ImageMagick
                  • Creating a ‘Winning’ Audio Lambda Service using Serverless, Polly and compiled SOX
                  • Scheduling EC2 Instances using Lambda and CloudWatch Events
                  • The History of Pets vs Cattle and How to Use the Analogy Properly
                  • Snowflake Server
                  • Phoenix Server
                  • Immutable Server
                  • AWS Elastic Beanstalk - Deploy Web Applications
                  • Heroku - Cloud Application Platform
                  • Serverless - The Serverless Application Framework powered by AWS Lambda and API Gateway
                  • Amazon Cognito - Simple and Secure User Sign Up and Sign In
                  • awslabs/serverless-application-model: prescribes rules for expressing Serverless applications on AWS.
                  • JSON Web Tokens
                  • Learn Electronics with Raspberry Pi
                  • Dynamic Content Delivery - Amazon CloudFront
                  • AWS WAF - Web Application Firewall
                  • Lambda@Edge - AWS Lambda
                  • 45 min
                  • 136: Delving into Cryptocurrencies with Jay Smith

                    In this episode we are lucky to have cryptocurrency proponent and trader Jay Smith on the show.

                    We start off by talking about how he got introduced to cryptocurrencies and trading, highlighting what trading actually is, and the two different schools of thought (fundamental vs. technical analysis).
                    From here we move on to chat about how innovations such as Bitcoin are changing the way we view money/bank, the underlying technologies that make it possible (Blockchain), and the game-theory/incentives behind it for each participant to continue ‘playing the game’.
                    Conversation then moves on to touch upon alternative cryptocurrencies (alt-coins) and the different use-cases/advancements they are making in the space.
                    Finally, we highlight Bitcoins scaling dilemma, how all routes seem to effect decentralisation in some shape or form, and how he stores his private keys.

                    Show Links
                    • Jaynemesis - Accessible Copy Trading
                    • Jaynemesis - eToro
                    • Pizza for bitcoins?
                    • Introduction to Fundamental Trading
                    • Introduction to Technical Trading
                    • Ivan on Tech - YouTube
                    • Bitcoin Improvement Proposals
                    • Dash Crypto Currency
                    • What’s the difference between hyperinflation and inflation?
                    • Inflation, measuring the cost of living - Khan Academy
                    • Learn Cryptography - 51% Attack
                    • Genesis block - Bitcoin Wiki
                    • Zimbabwean dollar
                    • Monero - secure, private, untraceable
                    • Ethereum Project
                    • ERC-20 Token Standard - GitHub
                    • How Blockchain Tech Could Move Self-Driving Cars Into the Fast Lane
                    • ParkByte
                    • Analysis of the DAO exploit
                    • SegWit
                    • Lightning Network - Bitcoin Wiki
                    • Bitcoin Cash - Peer-to-Peer Electronic Cash
                    • Bitcoin Gold - GPU Bitcoin Mining (Official Website)
                    • Litecoin.com - Open source P2P digital currency
                    • Charlie Lee on Twitter
                    • Payment channels - Bitcoin Wiki
                    • What is a pre-mined coin?
                    • Exodus - Manage Blockchain Assets
                    • 1 hr 11 min
                    • 135: Let's AWS Everything!

                      In this week’s episode Edd and Mick catch-up after another long hiatus (sorry about that).

                      We start off by discussing principles mentioned in the Clean Coder book, gaining confidence in code by way of tests, and Elon Musk’s dream of putting a person on Mars.
                      Leading on from this, Edd talks about his continued venture into the internals of Bitcoin, Hardware wallets, ASIC mining USB sticks and Merkle Trees.
                      We then highlight MyBuilder’s recent switch from dedicated servers to the AWS stack, highlighting the pros n’ cons of both approaches and some gotcha’s encountered along the way.
                      Finally, we mention some security audit and monitoring tools that have proven useful for keeping an eye on the (ever increasing) servers present in a typical setup.

                      Show Links
                      • Elon Musk - How the Billionaire CEO of SpaceX and Tesla is Shaping our Future
                      • Zip2
                      • Elon Musk talks about to put a Man on Mars - YouTube
                      • The Clean Coder - A Code of Conduct for Professional Programmers
                      • Integration Contract Tests
                      • Clean Coders - Training videos. With personality. For software professionals.
                      • Running PHPUnit tests in parallel with Jenkins and Ant
                      • Bitcoin and Cryptocurrency Technologies Online Course - YouTube
                      • Edd Mann - YouTube
                      • TREZOR Bitcoin Wallet - The original and most secure hardware wallet.
                      • Bitcoin USB-Stick Miner, up to 25 GH/s (33 GH/s max)
                      • Amazon Web Services (AWS) - Cloud Computing Services
                      • Amazon Simple Storage Service (S3)
                      • DigitalOcean Spaces - Cloud Object Storage
                      • Amazon CloudFront - Content Delivery Network (CDN)
                      • Amazon Relational Database Service (RDS)
                      • Making Sense of AWS EC2 Instance Type Pricing
                      • Why buying Provisioned IOPS on RDS may be a mistake
                      • The Misunderstood t2 Instance Type
                      • A Cloud Guru - Cloud computing certification training for the Amazon Cloud
                      • Lynis - Security auditing tool for Unix/Linux systems
                      • AIDE - Advanced Intrusion Detection Environment
                      • Email notifications upon available package updates with cron-apt
                      • 49 min

                      About Three Devs and a Maybe

                      From the publisher's feed

                      Join us each week as we discuss all things software development. Frequently joined by a far more intelligent guest on the show's topic, we by no means know everything, but love what we do. Topics…