Linux.conf.au 2022 – Avoiding DNS Pain
Once again, I was extremely fortunate to be speaking at Linux.conf.au. This year, I spoke on avoiding common DNS pain points by following a “DNS as code approach” with DNSControl.
This is a topic that I really enjoy speaking on, DNS is often overlooked when we move to a DevOps/DevSecOps operating model, but I am glad to say that we can make things better. I appreciated all the wonderful questions during the session. The Linux.conf.au crowd are always a great community to be part of.
You can check out the video here:
February 2020 Melbourne Microsoft Cloud and Datacenter Meetup
Just before I speak at Ignite The Tour Sydney, I will be presenting a preview of my talk to the Melbourne Microsoft Cloud and Datacenter Meetup on February 10th.
Our February 2020 meetup has an exciting double line up with Richard Benwell from Squared Up talking about how to effectively monitor your applications with Azure Monitor. Richard will show us how to get started, get some quick wins and create some killer Azure dashboards.
The event is hosted by Servian in their lovely offices in Tower 5, 727 Collins St in Docklands. I look forward to seeing everyone there.
Bank Grade Security at Microsoft Ignite The Tour Sydney
I am extremely excited to announce that I am presenting my talk, Bank Grade Security at Microsoft Ignite The Tour in Sydney next month. I have received such wonderful feedback from this talk when I presented it at DDD Melbourne, DDD Sydney and NDC Sydney. Speaking at a Microsoft event like this has been a dream for a long time and I am excited to share it with an even wider audience.
If you are attending The Tour in Sydney, please register for the session (session code BRK30215). In the session I will be talking about how Australian Banks rate in terms of the use of security practices like SSL/TLS configuration hardening, the use of HTTP security headers and their support for security.txt files. The results will probably surprise you.
This talk will be updated with the latest results of my analysis, if you have seen the session, please come and see how the banks have hopefully improved. The session will be of interest to everyone including developers, security and operations teams.
Voting for DDD Melbourne is now live
DDD Melbourne is a fantastic developer focused conference. Last year I had the privilege to present my Boring Security Talk to an amazing audience at Melbourne’s Town Hall. This year over 400 people will attend the event at the Melbourne Convention Centre.
DDD Melbourne is a fantastic developer focused conference. Last year I had the privilege to present my Boring Security Talk to an amazing audience at Melbourne’s Town Hall. This year over 400 people will attend the event at the Melbourne Convention Centre.
One of the things that makes all DDD conferences great is that the sessions are selected via an the attendees voting for what they would like to hear. This year there are 155 sessions to choose from, ranging from web development, design, data and security.
If you have purchased a ticket, the next step is to go and vote for your 6 favourite sessions. If you haven’t purchased a ticket yet, what are you waiting for? Go and buy a ticket.
The Boring Security Talk at the Global Azure Bootcamp 2019
This weekend I spoke at the Global Azure Bootcamp 2019. This was another great day, this year hosted at Swinburne University.
This weekend I spoke at the Global Azure Bootcamp 2019. This was another great day, this year hosted at Swinburne University.
I presented a longer version of my talk, The Boring Security Talk. The longer format lets me get into some extra details. The extra time also provides some time to talk about some of the latest security incidents that have occured in the last few months.
I have put together a list of links and reference materials:
- Hackers exploit Jenkins servers, make $3 million by mining Monero
- DHS: Multiple US gov domains hit in serious DNS hijacking wave
- Advice on Mitigating DNS Infrastructure Tampering
- A Deep Dive on the Recent Widespread DNS Hijacking Attacks
- DNS Squatting with Azure App Services
- Microsoft loses control over Windows Tiles subdomain
- DNSControl
- Managing DNS with DNSControl, CloudFlare, DNSimple, GitHub, VSTS, Key Vault and Docker
- MX Toolbox
- PostMark DMARC reporting
- Report URI DMARC monitoring
- Phishing Scorecard
- UK ICO, USCourts.gov... Thousands of websites hijacked by hidden crypto-mining code after popular plugin pwned
- Malicious Docker Containers Earn Cryptomining Criminals $90K
- Postmortem for Malicious Packages Published on July 12th, 2018
- Malicious remote code execution backdoor discovered in the popular bootstrap-sass Ruby gem
- Pipdig Update: Dishonest Denials, Erased Evidence and Ongoing Offences
Slides and Content from The Boring Security Talk at CrikeyCon VI
Last weekend I spoke at CrikeyCon VI. I am always excited to attend and present at CrikeyCon, the attendees are fantastic and overall the organisers have created an amazing conference ❤.
Droopy the CrikeyCon Mascot
Last weekend I spoke at CrikeyCon VI. I am always excited to attend and present at CrikeyCon, the attendees are fantastic and overall the organisers have created an amazing conference ❤.
This year I presented The Boring Security Talk. This session covers a variety of issues, DNS, Email, CI/CD and dependency management.
You can view the slides here. I will update this past when the video becomes available.
I have put together a list of links and reference materials:
- Hackers exploit Jenkins servers, make $3 million by mining Monero
- DHS: Multiple US gov domains hit in serious DNS hijacking wave
- Advice on Mitigating DNS Infrastructure Tampering
- A Deep Dive on the Recent Widespread DNS Hijacking Attacks
- DNS Squatting with Azure App Services
- DNSControl
- Managing DNS with DNSControl, CloudFlare, DNSimple, GitHub, VSTS, Key Vault and Docker
- MX Toolbox
- PostMark
- Phishing Scorecard
- UK ICO, USCourts.gov... Thousands of websites hijacked by hidden crypto-mining code after popular plugin pwned
- Malicious Docker Containers Earn Cryptomining Criminals $90K
- Postmortem for Malicious Packages Published on July 12th, 2018
- Malicious remote code execution backdoor discovered in the popular bootstrap-sass Ruby gem
- Pipdig Update: Dishonest Denials, Erased Evidence and Ongoing Offences
If you want to catch this presentation in person, you will be able to see it at the Azure Global Bootcamp in Melbourne.
Update - You can now watch the https://www.youtube.com/watch?v=5OlMEi_vcgY!
Tickets now available: 2019 Global Azure Bootcamp Melbourne
I am excited to announce that tickets are now avavailable for the Global Azure Bootcamp - Melbourne! This year the bootcamp will be on Saturday 27th of April 2019.
Global Azure Bootcamp Logo
I am excited to announce that tickets are now avavailable for the Global Azure Bootcamp - Melbourne! This year the bootcamp will be on Saturday 27th of April 2019.
The Global Azure Bootcamp is a free one-day global event organised entirely by users in the community for Azure users around the world who gathered to share essential Azure and Cloud Computing skills and ideas at the seventh annual Global Azure Bootcamp in 2019. We are hosting this event in Melbourne, Australia, but there are many locations, in fact more than 100 other locations worldwide, where the Global Azure Bootcamp will be hosted on the same day.
This is an educational event, and we want it to be an opportunity for everyone to gain new skills. The focus of the event is to teach essential Azure skills to anyone in the technology community who wants to advance their cloud knowledge and the goal of the event is to show people the benefits of Azure while strengthening the Azure community.
Tickets are available via EventBrite, and typically sell out very quickly. We will be maintaining a waiting list once we run out of tickets.
Videos from NDC Sydney 2018
I forgot to post in December that the video from my NDC Sydney session, The Boring Security Talk, is available on YouTube and Vimeo.