Caligin Tsukihara is a user on octodon.social. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

Caligin Tsukihara @caligin@octodon.social

Oh, its actually a sponsored talk about a report-sharing-collaborative-tables-and-numbers-and-red-and-green-arrows tool. all make sense now.

"Shift left is not enough, you need to expand and make everyone aware and on board that they need to apply security at all phases" -- wait, isn't that what shift left means?

"Devs don't like having to run SASTs and having to do a lot of stuff, you need to give them just the small things that they need to really do to pass their security audit."
This sounds like encouraging the very wrong practice of security by boxticking and it's a very bad message to send out.

Whoops noticed just now that I keep getting the hashtags wrong swapping with lol

Speaker showing a diagram with an agile sdlc lifecycle in a circle, at some point there is "feature complete? Yes another iteration / no exit" ... but projects/products never end! They either die or need maintenance and evolution.

"Shift left is relative to context, is your thinking model right-to-left? Or maybe top-to-bottom?"

ohgawd please stop saying docker! he managed to say it 12 times in 4 phrases

Animated diagrams from an isometric view though, slick af! I'm genuinely impressed.

Every sponsored talk ever: "Hey, I'm not here to sell our product, but here's a brief commercial of our product, and here are the tech details:"
*Spends 40 minutes showing slick diagrams and repeating that it integrates with anything and everything*

"People are wonderful... attack vectors."

Subresource Integrity: you can have the browser verify hashes of resources included in a page
developer.mozilla.org/en-US/do

Project is in its infancy, needs contributions!

TIL wildcards on IAM principals are way more dangerous than I though (means literally any principal on any account not just yours).

"If you don't have a threat model, you're gambling."

"Blue team: would you spend 80% protecting the network and 20% the applications or vice versa?"
*audience raising hands"
"Who chose the 80net20app won."