• 0 posts
  • 17 comments
Joined 3 years ago
Cake day: June 9th, 2023
  • If you want it to stand out don’t automate the compute and networking that’s so standardized these days that anyone can do it, Automated those IAM permissions.

    I know that when hiring nothing gets me more excited about a candidate than them understanding how to securely bootstrap an environment.

  • The problem is how many random characters can you remember in your head?

    A good encryption key would be around 32 characters to form a 256 bit encryption key.

    You can do a fun game of encrypt the encryption key with a password but that’s just another vulnerability in the chain.

    I recommend getting a PGP key stored on a yubikey and then encrypt all your notes with it since it’s all in markdown, I store my notes on Google drive and keep them decrypted in memory so that I can still use Obsidian.

  • Some form of compute with a recurring job that checks for a DNS address or domain.

    Choose a domain that needs to be regularly paid for as a target.

    Reason I would choose something you pay for as the trigger is because not paying a bill after your death is one thing that will be actioned on no matter what.

  • The magic of the bad server is they have an R&D budget plus ops team so some waste while testing is covered, you tend to pay for mistakes on the good (home) server :P

    Plus getting feedback from a good team beats a rubber duck XD