HN user

ramimac

1,825 karma

Security, for the Internet, at Wiz

https://ramimac.me

Posts104
Comments83
View on HN
www.wiz.io 8d ago

AsyncAPI Supply Chain Compromise via GitHub Actions

ramimac
4pts0
crossingriver.substack.com 1mo ago

Who Has the Hardest Fist in China's AI Valuation Race?

ramimac
3pts0
aresluna.org 2mo ago

A Guide to Keyboard Customization

ramimac
4pts0
alexgaynor.net 3mo ago

If [static analysis] could have, why didn't it?

ramimac
2pts1
blog.yossarian.net 3mo ago

Brocards for Vulnerability Triage

ramimac
2pts0
telnyx.com 3mo ago

Telnyx package compromised on PyPI

ramimac
133pts135
ironicsans.ghost.io 4mo ago

It's Their Mona Lisa

ramimac
75pts17
harpers.org 5mo ago

Child's Play: Tech's new generation and the end of thinking

ramimac
451pts265
blog.sshh.io 6mo ago

Building Multi-Agent Systems (Part 3)

ramimac
1pts0
joshua.hu 8mo ago

Okta's NextJS-0auth troubles

ramimac
372pts152
www.figma.com 9mo ago

Visibility at scale: How Figma detects sensitive data exposure

ramimac
2pts0
www.bonnycode.com 9mo ago

If Managers Were Angels

ramimac
1pts0
www.wiz.io 9mo ago

Dismantling a Critical Supply Chain Risk in VSCode Extension Marketplaces

ramimac
1pts0
josnyder.com 1y ago

Eleven Missing Terraform Features

ramimac
5pts0
fenrisk.com 1y ago

Supply Chain Attacks on Linux Distributions

ramimac
26pts1
www.wiz.io 1y ago

GitHub Action supply chain attack: reviewdog/action-setup

ramimac
5pts1
cybersect.substack.com 1y ago

History: What Happened with Ciscogate

ramimac
3pts0
harper.blog 1y ago

My LLM Codegen Workflow

ramimac
3pts0
thirtythings.timiajiboye.com 1y ago

Thirty Things

ramimac
1pts0
block.github.io 1y ago

Codename Goose

ramimac
19pts0
samcurry.net 1y ago

Hacking Subaru: Tracking and controlling cars via the admin panel

ramimac
548pts320
jackdanger.com 1y ago

Big Bets

ramimac
4pts0
blog.silentsignal.eu 1y ago

Story of a Pentester Recruitment

ramimac
6pts0
oaklandsok.github.io 1y ago

Systematizing Systematization of Knowledge

ramimac
2pts0
sok-offensive-ai.github.io 1y ago

SoK: On the Offensive Potential of AI

ramimac
5pts0
asteriskmag.com 1y ago

A User's Guide to Building a Subculture

ramimac
3pts0
buildingslack.com 1y ago

The death of Glitch, the birth of Slack

ramimac
124pts37
militarycryptography.xyz 1y ago

(Re)-Introducing La Cryptographie Militaire

ramimac
2pts0
embracethered.com 1y ago

Security ProbLLMs in XAI's Grok

ramimac
6pts0
code.cash.app 1y ago

Encryption using data-specific keys

ramimac
1pts0

Upon issue creation another workflow spins up three independent coding agents to analyze the finding.

I'm curious

1) what the current statistics are for consensus

2) how the agents may/may not perform independently

3) what the agent profiles are and how they differ (model, harness, prompt/persona, all three?)

GuardDuty does what AWS says it will do

What do you view as AWS' commitments around GuardDuty? I see pretty clear positioning by AWS of GuardDuty as a one-and-done solution for threat detection.

Top level marketing claims include:

* "Protect against ransomware and other types of malware" - which is why I looked at how viable GuardDuty would be against the most common form of S3 "ransomware"

* "Detect suspicious activity in your generative AI workloads" - but they don't actually have coverage of the vast majority of GenAI Services

* "Continuous monitoring across AWS accounts and workloads without added cost" - except the service is expensive (if worthwhile for the foundational data sources!) and has unpredictable costs

competing product/service

I see canary infrastructure as complimentary to Guardduty (w/ foundational data sources) - which is explicitly stated in the piece!

nb: I'm the author, in case it's non-obvious!

Agreed - I find the credential exfil alerts meaningful. I appreciate that AWS has invested in making them better in recent years (bypass details in https://hackingthe.cloud/aws/avoiding-detection/steal-keys-u...)!

I also find the DNS based cryptomining detections pretty handy, and high enough signal.

Great point on VPC Flow Logs! With the move to SKU off various GuardDuty features (S3 protection, Runtime, etc.) ... it'd be nice if GuardDuty monitoring of VPC Flow logs were more configurable

There is a lot of advice in this thread that doesn't actually address your circumstances, or is just bad.

I recommend reading: 1. https://devd.me/log/posts/startup-security/ - relatively short and prescriptive 2. http://scrty.io/ - start with http://scrty.io/foundations + https://medium.com/starting-up-security/you-dont-need-a-chie... + https://medium.com/starting-up-security/starting-up-security...

I see the value just from a search perspective -- take as an example:

* I'm looking to stay 8 days in Paris in fairly peak season

* There is no good availability for a single Airbnb for 8 days

* This lets me see good matches of "3 in spot one, 5 in spot two" as well as "4 and 4" etc. without needing to do a lot of filtering by availability and digging into individual listings