<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Jan Harrie on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/jan-harrie/</link>
    <description>Recent content in Jan Harrie on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 28 Nov 2019 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/jan-harrie/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>BASTA! Autumn 2019 – Security in DevOps</title>
      <link>https://insinuator.net/2019/11/basta-autumn-2019-security-in-devops/</link>
      <pubDate>Thu, 28 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/basta-autumn-2019-security-in-devops/</guid>
      <description>&lt;p&gt;Some time ago I had the pleasure to speak at the &lt;a href=&#34;https://basta.net/&#34;&gt;BASTA!&lt;/a&gt; Autumn 2019 conference. There, I promised to publish my &lt;a href=&#34;https://insinuator.net/wp-content/uploads/2019/11/201909_BASTA_DevOps-Sc_v1.0.pdf&#34;&gt;slides&lt;/a&gt; such that they can be used as a reference for developers and security guys like me. And with this blog post I would like to hold up to my promise.&lt;/p&gt;&#xA;&lt;p&gt;Overall, the talk was about the challenges of “How to bring security into modern DevOps processes”. Hence, I demonstrated how security can be integrated more or less seamlessly into the modern agile software development workflow. I proposed some risk-depended recommendations about which measurements should be established, for example, within the CI pipeline.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DevSecCon19 London – How to Secure OpenShift Environments and What Happens If You Don´t</title>
      <link>https://insinuator.net/2019/11/devseccon19-london-how-to-secure-openshift-environments-and-what-happens-if-you-dont/</link>
      <pubDate>Tue, 19 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/devseccon19-london-how-to-secure-openshift-environments-and-what-happens-if-you-dont/</guid>
      <description>&lt;p&gt;This week I was at &lt;a href=&#34;https://www.devseccon.com/london-2019/&#34;&gt;DevSecCon in London&lt;/a&gt; to present my current research on Red Hat OpenShift. In this talk, I gave a brief introduction to OpenShift, demonstrated some threats that exist for such environments, and dived into different configuration issues that may affect the security of OpenShift environments. The implications of misconfigurations of such an environment have been shown in live demos.&lt;/p&gt;&#xA;&lt;p&gt;You can find the slides for my talk here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Catching fire with Docker, DevOps &amp;amp; Security in Enterprise Environments</title>
      <link>https://insinuator.net/2019/01/catching-fire-with-docker-devops-amp-security-in-enterprise-environments/</link>
      <pubDate>Fri, 04 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/catching-fire-with-docker-devops-amp-security-in-enterprise-environments/</guid>
      <description>&lt;p&gt;Docker has become the go-to technology in enterprise- and DevOps contexts. Yet, before mastering a skill, there is the thumb rule: one must learn the basics to have solid fundament before building a house on top.&lt;/p&gt;&#xA;&lt;p&gt;Simon and I start from the very beginning. We introduce you to the fundamental concepts of containers starting at process isolation and extending our tour to the whole ecosystem of Docker and further associated technologies. We will cover Docker, microservices, containers, DevOps, continuous integration/deployment/delivery – all those fancy buzzwords that can be read in the context of modern software development methodologies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>H2HC2018 – Attacking VMware NSX</title>
      <link>https://insinuator.net/2018/11/h2hc2018-attacking-vmware-nsx/</link>
      <pubDate>Fri, 02 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/h2hc2018-attacking-vmware-nsx/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://twitter.com/uchi_mata&#34;&gt;Matthias&lt;/a&gt; and &lt;a href=&#34;https://twitter.com/NodyTweet&#34;&gt;I&lt;/a&gt; had the pleasure to give a talk at the &lt;a href=&#34;https://www.h2hc.com.br/&#34;&gt;H2HC2018&lt;/a&gt; in São Paulo, Brazil about attacking VMware NSX. The talk is an introduction to VMware NSX for security researchers, and it discusses possible attack vectors including the management, controlling, and data exchange planes. We demonstrated how to prepare a fuzzing and debugging setup for the ESXi kernel and the kernel modules. It should be noted that &lt;a href=&#34;https://twitter.com/Syyyrius&#34;&gt;Olli&lt;/a&gt; was also supporting the research.&lt;br&gt;&#xA;The slides can be found &lt;a href=&#34;https://insinuator.net/wp-content/uploads/2018/11/H2HC_HarrieLuft_AttackingVMwareNSX-1.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
