Skip Navigation
CrowdStrike broke Debian and Rocky Linux months ago, but no one noticed
  • Setting the update policy to N-2 (or any other configuration) would not have avoided the issue. The Falcon sensor itself wasnā€™t updated, which is what the update policy controls. As it turns out, you cannot control the content channel updates - you simply always get the updates.

  • What are You Working on Wednesday
  • My preference is for the native AWS WAF as we already use it. The rub comes from how the cluster is architected which would mean weā€™d have an ALB ingress per application - the prohibitive cost is purely the extra ALBs that would be created. Though I literally just heard itā€™s not going to be as bad as initially forecast so ĀÆ_(惄)_/ĀÆ

    My original curiosity was if any of the K8s specific WAFs are any good, for example Prophaze.

  • What are You Working on Wednesday
  • Trying to find a suitable WAF for AWS EKS. Any suggestions?

    One of the teams has a cluster built with the nginx ingress which uses classic load balancers. Shifting them to the AWS ingress (which uses ALBs enabling our AWS WAF to apply) looks like itā€™ll be massively expensive due to the blow out in load balancer costs - but it gets us a WAF we already use across everything else. Other option is to find a WAF specifically for EKS and shift all clusters to that.

  • What are some good/useful software that you use that aren't well known/talked about?
  • My bad, just noticed you asked for Windows, this is MacOS.

    Rectangle - just a simple and reliable MacOS window manager. They do have a paid version which gives you a few extra features, but I used the free one for a long time before buying to support and get access to one of the paid features.

  • recommended search engine?
  • Search engine or browser? For browsers Iā€™ll use Firefox, but if Iā€™m logging into anything Iā€™ll usually use Chrome or Safari. Iā€™ll also use Tor browser sometimes.

    On the search engine side, Iā€™ll generally use DuckDuckGo but Iā€™m trying out Kagi to see if itā€™s worth paying for.

  • just wait, it could get worse....
  • Iā€™ve read that it turned out to be a nothing burger primarily because there was a concerted effort to address the problem. That said, yeah, nothing melted down so functionally there was no issue.

  • InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/ā€žInitialsā€ (https://github.com/dicebear/dicebear) by ā€žDiceBearā€, licensed under ā€žCC0 1.0ā€ (https://creativecommons.org/publicdomain/zero/1.0/)ST
    starneld @infosec.pub
    Posts 0
    Comments 11