Of course obscurity is not security blah blah blah. Still I can’t help feeling that writeups like this could backfire down the line.
Of course obscurity is not security blah blah blah. Still I can’t help feeling that writeups like this could backfire down the line.
It's just like when talking about secure communication, you explain exactly how the public/private key exchange works, what algorithms are used, and how the entire handshake takes place. You don't say "We are keeping those details secret just in case it might aid some hacker".
The added benefit of everybody examining the process and agreeing that it's sound and secure is just too great to give up.
I think it's really great that they've talked about this, it's quite rare to hear about these kinds of internal migrations, and it's something I do a lot with clients but it's not really glamorous enough to talk about.
The difference between StackLeap and sites like acloud.guru is that I'm focussing on the day to day stuff rather than high level concepts you need to know to pass the certification exams.
I'm hoping to launch a beta in the next few weeks.
You might not be ready for that level of integration, but see if you can get a demo or trial.
I would love to go into more details about the environment and some of the things we did to build on top of the default AWS security settings. It was too much information for this post, maybe we will do another one that focuses on security.
If they listed out security group and IAM configurations, or how exactly they’re connecting through the bastion, then it would be a little more risky, yes.
By sharing this with the world, you are encouraged to face any vulnerabilities that you may have overlooked.