On the ITU side, they have made improvements including allowing a plain fully qualified domain name as the subject of a certificate, as an alternative to sequence of set of attributes.
700 karma · joined January 18, 2011
I'm a engineer working at General Motors on a variety of software and hardware projects.
I used to a security engineer at Apple working on iCloud and Apple Cloud Services.
I used to be a Principal Security Engineer at Amazon Web Services.
I used to work in AWS Cryptography and was primarily responsible for Amazon Trust Services, their public CA. My old group also owns AWS CloudHSM, AWS Key Management Service, and some new things. Previously I worked on EC2 and have dabbled in various other parts of AWS.
See http://www.peterbowen.org/ Contact me at pzbowen@gmail.com or peter.z.bowen@gm.com
[ my public key: https://keybase.io/pzb; my proof: https://keybase.io/pzb/sigs/ncn-SquIIOKO-pD9o-CvE96l2zUzrvskCwZ-vo8q8lU ]
On the ITU side, they have made improvements including allowing a plain fully qualified domain name as the subject of a certificate, as an alternative to sequence of set of attributes.
https://www.icann.org/en/registry-agreements?sort-column=top...
I don't have access to an EC2 instance to check, but you should be able to see the PCIe topology to determine how many physical cards are likely in i4i and im4gn and their PCIe connections. i4i claims to have 8 x 3,750 AWS Nitro SSD, but it isn't clear how many PCIe lanes are used.
Also, AWS claims "Traditionally, SSDs maximize the peak read and write I/O performance. AWS Nitro SSDs are architected to minimize latency and latency variability of I/O intensive workloads [...] which continuously read and write from the SSDs in a sustained manner, for fast and more predictable performance. AWS Nitro SSDs deliver up to 60% lower storage I/O latency and up to 75% reduced storage I/O latency variability [...]"
This could explain the findings in the article - they only meared peak r/w, not predictability.
[0] https://perspectives.mvdirona.com/2019/02/aws-nitro-system/ [1] https://aws.amazon.com/ec2/nitro/ [2] https://d1.awsstatic.com/events/reinvent/2019/REPEAT_2_Power...
Not to say the rest of the spec is notably better. If fully implemented, it requires supporting escape codes in strings to change character sets. I've never seen valid escape codes in real world data, but it probably exists.
As the original article shows, ASN.1 has lots of other challenges and complexity. Trying to write a code generator that supports all the complexity is no trivial task and the only open source one I've seen only generates C code. Protobuf has the advantage of having modern language support (including multiple type safe and memory safe languages).
.cs was the first removed TLD as far as I was able to find.
It has one USB Type-C in with 3 USB Type-C out plus 4 USB Standard-A out. One of the C outputs supports downstream charging. Should just be a matter of time until hubs using this chip are widely available.
https://www.amazon.com/UPTab-10Gbps-60hz-Power-Delivery/dp/B... is an example
I would strongly recommend looking at weasyprint (http://weasyprint.org/ ) for HTML to PDF. It gives much better PDF output and offers CSS print support, so you get page control.
(Disclosure, I work with AWS)
Many HSMs also add advanced authentication capabilities, such as M-of-N access control and/or hardware authenticators (e.g. you need 3 of 5 smart cards to use the HSM). The other key feature usually found in HSMs but not smart cards is backup/cloning without exporting the key (in PKCS#11 terms). This means that the key can be moved between HSMs with all the protections in place. I've yet to see a smart card that does this.
There is no question that there would be value in having a hardware platform that has certain security features, but that alone doesn't meet the requirements of most users of HSMs and Smart cards. The primary use cases I've seen are allowing a third party to have assurance of protection of data stored in the device and assurance of the rules for accessing the data. In most cases this assurance comes from a combination of the hardware itself and the software/firmware running on the hardware. A hardware platform only solves half the problem that most purchasers of HSMs and smart cards are asking vendors to solve.
However, when you apply to big companies, don't go in saying "I want to be a senior engineer". That means different things at different companies. Quora has some great answers on how the ladders work at the big players; you will see that "Senior" can mean 10+ years of experience at some places. Feel free to send me an email if you want more info about one of the places you mentioned.
I would not be surprised if Aristotle wasn't one of the six customers to which Georgia sent the data. They have been collecting voter data for years; I worked there for a few months more than 15 year ago, and they already had a nationwide database mostly loaded from 9-track tape.
That was basically SA gold. If you are higher tier (e.g. LH HON Circle), then add things like free full service restaurant and private passport control to the list.