Podcasts about FIPS

  • 160PODCASTS
  • 262EPISODES
  • 46mAVG DURATION
  • 1WEEKLY EPISODE
  • Sep 14, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about FIPS

Latest podcast episodes about FIPS

CISSP Cyber Training Podcast - CISSP Training Program
CCT 370: CISSP Cryptography, FIPS Validation, and Post-Quantum (Domain 3)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Sep 14, 2026 38:32 Transcription Available


Send us Fan MailA compliance deadline can change your security posture without changing a single bit of your encryption. We start with a simple sticker-on-the-windshield analogy that maps directly to what's happening with FIPS 140 validations: your VPN can keep encrypting, your database can keep protecting data, and yet an assessor can still mark you down because “working” is not the same as “validated.”We walk through the practical CISSP Domain 3 lesson behind the noise: the difference between an algorithm claim (we use AES-256), a configuration claim (we run in FIPS mode), and an evidence claim (we hold an active FIPS 140 validation on the CMVP list). With FIPS 140-2 certificates moving to historical status and FIPS 140-3 testing queues stretching beyond 500 days, the manager move is not wishful thinking. It's documenting the gap, treating it as risk, and getting formal risk acceptance with executive sign-off plus a real remediation plan, especially if you're facing CMMC or customer security assessments.From there we connect the dots across cryptographic life cycle management, cryptographic agility, and the real places crypto fails: key management and implementation. We cover HSM storage, rotation, dual control versus split knowledge, PKI revocation choices (CRL, OCSP, OCSP stapling), common cryptanalysis categories, and why side-channel and fault-injection attacks hit modules rather than “the math.” We then get clear on quantum risk, harvest now decrypt later, and what NIST's post-quantum standards (ML-KEM, ML-DSA, SLH-DSA) mean for your migration plan starting with a cryptographic inventory.Subscribe for more CISSP exam-ready training, share this with a teammate who owns compliance evidence, and leave a review if it helped. What would fail first in your environment: the crypto itself, or the proof you can show an auditor?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Business of Tech
Silent Disqualification Risks Rise as UK Platforms and US Buyers Automate MSP Selection

Business of Tech

Play Episode Listen Later Sep 11, 2026 12:28


The episode reveals a structural shift toward eligibility thresholds and silent disqualification in the managed services sector, driven primarily by large vendors and regulatory buyers. Companies now establish non-negotiable numerical thresholds—such as cloud revenue minimums or cryptography certifications—as criteria that MSPs must meet to maintain channel access or bid eligibility. Key organizations shaping these dynamics include Microsoft, which has reduced its global distributor base by two-thirds, and regulatory buyers who increasingly rely on FIPS 140-3 cryptography validation as a procurement gate.The most consequential development discussed is Microsoft's reduction of its distributor partners from approximately 180 to roughly 60, based on a $30 million annual cloud solution provider revenue threshold per region, or $1 million for direct bill partners, according to Scott Frew of iAsset. Concurrently, regulated buyers are disqualifying MSPs whose tools lack FIPS 140-3 validated cryptography, a certification that requires third-party verification and is referenced by procurement officials as a hard requirement. The Managed Services Journal and vendor press releases provide evidence that this filtering mechanism now operates prior to any sales engagement, largely outside the control or even awareness of affected MSPs.Supporting developments reinforce this threshold-driven landscape. CompareIT in the UK has launched an AI-driven platform to assess over 8,000 MSPs on up to 197 criteria, allowing buyers to shortlist providers before direct interactions. Vendors are responding by integrating compliance features (such as Datto RMM adding FIPS 140-3 support) without extra cost, turning compliance into a baseline rather than a differentiator. Third-party products and partnerships are emerging—like RYTHMz' SCOUTz or the Senteon and SPECTRA alliance—to supply objective evidence of eligibility, making attestation a commodity and part of a burgeoning industry.For MSPs and IT leaders, the operational implication is a shift from sales-driven competition to eligibility-driven access. Risks arise from losing channel relationships, not keeping up with compliance requirements, or being silently excluded from consideration in regulated deals. Ensuring a clear owner for validation data, maintaining up-to-date records of distributor status, and proactively verifying the business's public profile now represent concrete governance requirements. Eligibility is becoming a precondition for market participation—those who manage it systematically maintain market access while others are removed without notification.00:00 Three Thresholds, Three Weeks 03:42 Cheaper Than A Conversation06:06 You'll Never Get The No09:12 Why Do We Care?Supported by:WebPros(CometBackup)HaloPSA

ChannelBuzz.ca
The Buzz: Cisco Canada launches sovereign critical infrastructure, ScanSource buys MicroAge for $220.5 million, and ESET Canada names cybersecurity scholarship winners

ChannelBuzz.ca

Play Episode Listen Later Aug 25, 2026 5:03


Today’s headline news for Canadian IT solution providers: [Cisco Canada]: The company this morning launched its Sovereign Critical Infrastructure portfolio, making Canada the first market outside EMEA to receive the offering. The company says the configurable portfolio spans core networking, security, compute, collaboration, and Splunk analytics, with air-gapped deployment options where required. According to Cisco Canada, the offering is aligned with ITSG-33 and most of the on-premises portfolio is IPv6-ready, FIPS 140-2/3 certified, and Common Criteria certified. Bell is the lead quoted partner. Read more on Cisco [ScanSource]: The distributor announced last week it will acquire value-added reseller and managed service provider MicroAge in a $220.5 million all-cash transaction expected to close on Sept. 30. The deal adds more than 2,400 U.S. customers and over 200 employees, and brings MicroAge’s hardware, professional services, and consulting expertise to ScanSource’s partners. Read more on Channel Dive [ESET Canada]: The company yesterday announced the winners of its 2026 Women in Cybersecurity Scholarship, naming Arthure Gélinas, Tsidkenu Tomori, and Sulaksa Jeevakumar as the three Canadian recipients. The program has awarded more than $50,000 to 14 women in Canada since expanding north in 2021. Read more on Business Insider [CrowdStrike]: The company is expanding Project QuiltWorks to midmarket companies through partners including Arrow Electronics, Pax8, and TD Synnex. CrowdStrike says the initiative integrates its AI-driven vulnerability discovery with partner services to deliver enterprise-grade protection to SMBs. Read more on Channel Dive [Palo Alto Networks]: The company and NTT Data say they have signed a three-year strategic pact targeting $1 billion in joint cybersecurity revenue, with NTT Data bringing more than 2,000 certified professionals and 20 cyber defense centers to the alliance. Read more on Channel Dive [Auvik]: The Canadian IT management platform provider says it promoted channel veteran Daniel Ochoa to chief revenue officer, with a mandate to expand the partner network and focus on AI-powered capabilities across North America, Latin America, and EMEA. Read more on Channel Dive [ChannelPro]: The publication unveiled its Top 20 MSPs for 2026, recognizing providers driving innovation, leadership, and impact in the channel. Read more on ChannelE2E Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Tuesday, August 25, 2026, and here’s what’s happening in the channel today. Cisco Canada this morning launched its Sovereign Critical Infrastructure portfolio, making Canada the first market outside EMEA to receive the offering. The company says the configurable portfolio spans core networking, security, compute, collaboration, and Splunk analytics, with air-gapped deployment options where required and control over access to systems and data sitting with the customer. According to Cisco Canada, the offering is aligned with ITSG-33, the foundation for Authority to Operate on mission-critical services, and most of the on-premises portfolio is IPv6-ready, FIPS 140-2/3 certified, and Common Criteria certified. The launch comes as Canadian organizations in critical sectors face increasing pressure to maintain control over their data and digital infrastructure amid rising sovereignty concerns. For channel partners, the move creates opportunities around assessment, deployment, and ongoing management of sovereign environments, particularly for regulated and government customers that need to demonstrate compliance with strict data residency and control standards. IT distributor ScanSource announced last week it will acquire value-added reseller and managed service provider MicroAge in a $220.5 million all-cash transaction expected to close on Sept. 30. The deal adds more than 2,400 U.S. customers and over 200 employees to ScanSource, and brings MicroAge’s hardware resale, professional services, and consulting expertise under the distributor’s umbrella. ScanSource Chairman and CEO Mike Baur told Channel Dive the acquisition is aimed at augmenting channel partners that lack their own customer service and support organizations, with plans to effectively rent MicroAge’s resources to partners who only pay if something closes. The deal reflects ScanSource’s broader strategy to cross-pollinate its technology advisor base with the MSP and VAR capabilities needed to deliver integration, implementation, and ongoing management services. Baur also noted that MicroAge’s Octum.ai consulting business could help technology advisors fill the AI expertise gap they currently face. For Canadian partners, the convergence of distribution and managed services is a signal that the traditional boundaries between partner types are eroding faster than many expected, and that distributors are increasingly willing to touch the end customer directly. ESET Canada yesterday announced the winners of its 2026 Women in Cybersecurity Scholarship, naming Arthure Gélinas, Tsidkenu Tomori, and Sulaksa Jeevakumar as the three Canadian recipients. According to ESET, the program has awarded more than $50,000 to 14 women in Canada since expanding north in 2021, with this year’s awards totaling $15,000 across three scholarships. Bob Bonneau, country manager at ESET Canada, said the recipients demonstrated an impressive combination of skill, leadership, and a genuine desire to make a difference in the industry. The winners will be recognized at a celebration at ESET’s Markham headquarters on Thursday, continuing a commitment that ESET says is one of the earliest initiatives of its kind in the cybersecurity industry. The three recipients come from the Greater Toronto Area, Montreal, and Ottawa, reflecting a geographic spread that ESET says mirrors the growth of cybersecurity hubs across the country. For the Canadian channel, the scholarship underscores the ongoing need to build a more diverse cybersecurity talent pipeline as demand continues to outpace supply, and it highlights a concrete way vendors can contribute to that pipeline beyond short-term hiring initiatives. In Brief – CrowdStrike expands Project QuiltWorks to midmarket companies through partners including Arrow Electronics, Pax8, and TD Synnex. Palo Alto Networks and NTT Data say they have signed a three-year strategic pact targeting $1 billion in joint cybersecurity revenue. Auvik promoted channel veteran Daniel Ochoa to chief revenue officer, with a mandate to expand the partner network and AI-powered capabilities. ChannelPro unveiled its Top 20 MSPs for 2026, recognizing providers driving innovation, leadership, and impact. Full details and links in the show notes or the blog post. Later today on In The Channel, my conversation with Raj Juneja, President of Cisco Canada, on the company’s new sovereign critical infrastructure portfolio for Canada. And if you haven’t heard it yet, check out my conversation with Tony Anscombe from ESET on why breached SMBs feel more confident, and where MSPs fit in the insurance collision. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.

ChannelBuzz.ca
Cisco brings sovereign infrastructure to Canada with air-gapped portfolio

ChannelBuzz.ca

Play Episode Listen Later Aug 25, 2026 19:00


Raj Juneja, president of Cisco Canada In this episode of In The Channel, we speak with Raj Juneja, president of Cisco Canada, about the launch of Cisco’s Sovereign Critical Infrastructure portfolio in Canada – the second market worldwide after EMEA, where it debuted last September. The portfolio spans Cisco’s networking, security, compute, collaboration, and Splunk offerings, configured for air-gapped, on-premises deployment. The differentiator is trust-based licensing: Cisco can’t remotely access, control, or disable the products – control sits entirely with the customer. It’s certified to FIPS 140-2/3 and Common Criteria standards, and aligned with Canada’s ITSG-33 framework. Juneja confirmed the offering is open to the full partner ecosystem, not restricted to any one partner, with certifications consistent with existing Cisco portfolio requirements. Distribution plays its usual role. Target customers are government, financial services, healthcare, and AI providers – organizations that need to run sensitive systems without cloud connectivity or foreign vendor access. IDC research shows more than half of Canadian organizations are increasing scrutiny of their critical system providers, but intent is running well ahead of deployment. Partner economics details are expected in the coming weeks. The launch comes as HPE has been active in sovereign infrastructure in Canada, and the federal government funds sovereign AI compute through ISED’s AI Sovereign Compute Infrastructure Program. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last sixteen years. I’m Robert Dutt, editor at ChannelBuzz.ca and your host for the show. This morning on The Buzz, we covered the news: Cisco launched its Sovereign Critical Infrastructure portfolio in Canada. Here’s what that actually means and why it matters for the channel. Cisco has taken its core networking, security, compute, collaboration and Splunk portfolio and configured it for air-gapped, on-premises deployment – systems that sit in facilities customers own and run, with no connection to the outside internet. The key differentiator is what Cisco calls trust-based licensing. Cisco can’t remotely access, control or disable the products. That control sits entirely with the customer. This is aimed at government, financial institutions, healthcare and other critical infrastructure providers – organizations that need to run sensitive systems without depending on constant cloud connectivity or foreign vendor access. The portfolio is certified to FIPS 140-2/3 and Common Criteria standards, and is aligned with Canada’s ITSG-33 framework for achieving Authority to Operate on mission-critical government systems. Canada is the second market for this portfolio after EMEA, where it launched last September. This comes at a time when data sovereignty has become a board-level priority. IDC says that more than half of Canadian organizations are increasing scrutiny of their critical systems providers, but intent is running well ahead of deployment. That gap between wanting sovereignty and actually having it is where the channel plays. For partners, the big questions are about access, economics and the services opportunity. To help answer those, I spoke with Raj Juneja, president of Cisco Canada. Let’s get right into it – my chat with Raj Juneja. Robert Dutt: Raj, thanks for taking the time. I appreciate it. Raj Juneja: More than happy to take the time, Robert. I’m looking forward to the conversation. Robert Dutt: The announcement talks about the infrastructure being available through Cisco and its partners, and Bell is front and centre in the announcement. Is this an opportunity that’s open to the broader partner ecosystem, or is it limited to a set of partners? Regardless of which way that goes, what does a partner need? What are the “you must be this tall to ride the ride” specifications in terms of specializations, certifications and clearances to sell and deploy the portfolio? Raj Juneja: This is not, in any way, shape or form, limited or restricted to any one particular partner. This announcement is really about addressing the demand we’ve been receiving from our customers to have more control and autonomy over their digital infrastructure and their data. We’re happy to bring this to our partner community, but there is nothing that limits or restricts it to any one specific partner. The certifications that partners hold – if you’re speaking specifically to partner-oriented certifications – are no different from what we currently have for the rest of our portfolio. Robert Dutt: So it’s broadly available. Basically, if you’ve got customers who are interested in this, you have access to it, by the sounds of it. Raj Juneja: That is absolutely our intention. We’re not looking to restrict this in any way. It’s an offering – the portfolio that we have today – that’s being offered in a different form to address the needs of our customers for control and the ability to manage their infrastructure on their own. Robert Dutt: Especially for smaller partners, are distributors at play here? If so, what role do you see them playing both at launch and further out, as this has a chance to develop an ecosystem around it? Raj Juneja: Distribution serves an incredible purpose in our channel community. As I said before, I don’t see this being any different in terms of the way we go to market and leverage our existing, broad set of distribution partners today. This is intended to address the needs of customers who are looking for control and choice over their own digital infrastructure and data. Ultimately, the path they take to acquire the technology will be no different from how they currently buy today. Robert Dutt: Let’s talk a little bit about the commercial model here. Can you elaborate on what trust-based licensing means and how it differs from the usual Cisco model? Raj Juneja: Trust-based licensing effectively means that, when you don’t have any connection to the cloud, there is no capability for us to remotely disable the products. Nor is there any requirement for license governance or administration. This goes back to the choice and control that we talked about. The onus is primarily on customers to ensure that they are adhering to the licensing they’ve acquired from Cisco. Effectively, the only way we can offer the air-gapped licensing that we have is through trust-based licensing. Robert Dutt: In terms of partner economics, is this pretty much the same as any Cisco engagement? What can you tell me about revenues in terms of subscription, perpetual licensing or something new? Basically, how do partners earn on this? Is it the same as ever, or is it a combination of one-time and recurring revenue? Raj Juneja: I can tell you that there will be more clarity on the specifics around partner profitability as the announcement comes out. The main thing to take note of is that, typically, when we offer new solutions and bring them to market, our partner ecosystem has a clear path to get the technology into the hands of the customer base. Profitability is always top of mind for Cisco. I think there will be greater clarity in the coming weeks, but we’re very excited about being the first country after EMEA to launch this. Robert Dutt: Air-gapped, on-premises infrastructure is a pretty complex thing to deploy and manage. What do you see as the split for partners between product and services? In terms of the services side, is Cisco seeing this as a “deploy and hand it over” kind of engagement, or is it also going to be a “deploy and manage” managed services opportunity for partners? Raj Juneja: Because it’s in the hands of our customers, it’s going to depend very much on how they want to configure the choice and control they have. That goes back to working very closely with the partner ecosystem to determine the role partners will play. Our partners have been coming to us and seeking the ability to solve these demands for our customer base. They are ready and willing to help customers configure and adapt, as they’ve done in the past with other on-premises deployments. I see this following similar lines and being very similar to the way our partner ecosystem has helped customers deploy other on-premises solutions. Robert Dutt: So there’s nothing precluding this from being delivered as a managed service. It comes down to what customers are comfortable with and what they want – and, in some cases, what is legally available to them, given the type of infrastructure issues we’re talking about. Raj Juneja: Correct. Robert Dutt: Splunk is central to the security and observability story, and I know it’s a subject near and dear to your heart in particular. My understanding is that Splunk has traditionally been a data platform that benefits from connectivity to the cloud. How much of that capability exists in an air-gapped environment, and what do partners need to deliver to support that? How do they help customers get to the cloud when appropriate? Raj Juneja: Just to correct you, Splunk is offered both on-premises and in a cloud version, and has been for quite some time. I don’t think this will be any different in terms of requirements. Splunk is already configurable to be handled in an on-premises manner. In fact, we have a number of customers that leverage that choice and control in an on-premises fashion. That’s why the on-premises version of Splunk exists today: for customers that are heavily regulated. For customers and verticals that are looking for choice and control and want to take a hybrid approach, it will be in their hands to determine what data they want ingested and how they want Splunk configured on-premises to control that data, versus what they want to continue leveraging through our cloud-based offering. It can absolutely work in a hybrid fashion. Robert Dutt: You mentioned a little earlier that partners have been coming to you asking about sovereign capabilities. Can you quantify that or give me some colour around what you’re hearing from partners in terms of customer demand for sovereign AI? What are you seeing and hearing when you’re talking to customers about demand for sovereign AI today? Raj Juneja: Absolutely. There’s no question that, when you look at AI data centres and AI providers, and specifically at what’s happening in Canada with the AI for All strategy, it comes down to addressing questions around control, data and where that data resides. Those questions have been coming forward to our partner community as well as to Cisco. When it comes to AI-based offerings, Sovereign Critical Infrastructure is intended to help address that choice and control for AI providers. It allows them to take their AI offerings to market in a way that addresses on-premises requirements or hybrid deployments, because they may also be leveraging hyperscalers in certain cloud-based environments. Robert Dutt: You mentioned earlier that Canada will be the first market beyond EMEA to roll out this particular offering. My understanding is that it’s been available in EMEA for eight or nine months. As you’ve had a chance to talk to your peers in Cisco’s EMEA regions, is there anything you’ve learned that adds colour to how this is coming to market, or to the shape of the opportunity they’re seeing, that you think would be relevant to Canada? Raj Juneja: As I said before, Canada has big ambitions for AI, as does the rest of the world. There’s no question that the ability to turn that ambition into reality is dependent on having the right infrastructure. The demand that EMEA has been seeing, and the reason we’re so excited about launching this in Canada, is specifically about turning that ambition into reality. There is an acceleration in the ability to run AI workloads in data centres and AI factories. The key is the security and autonomy we’ve talked about – deploying AI on your own terms. That has led to the demand. EMEA has been the first beneficiary of that, and I was very excited when Canada was chosen as the second country or region to address this demand and help meet the needs of our customer base. Robert Dutt: Without getting too far into the weeds or potentially tipping your hand on the future, who do you think will be the early, slam-dunk customers? Who are the customers you can point partners toward today and say, “Go get it”? Raj Juneja: The thing with sovereignty is that it’s not one-size-fits-all. It really comes down to choice and control. If you look at government, it’s very much focused on that control piece. Government is absolutely going to be an interested party. But if you look at regulated industries such as financial services and healthcare, you’ll see that they still have requirements around adhering to regulations. Having the ability to exercise choice and control is also very important to them. I see this addressing multiple industries and verticals. I think this is a great opportunity not only for Cisco, but also for our partner ecosystem. Robert Dutt: Let’s talk about the competitive environment to bring it home. HPE has been talking about sovereign infrastructure in Canada for a while now. Microsoft has a story there as well. What’s Cisco’s answer to the “Why Cisco?” question, whether that’s against peer competitors or a “build it yourself” solution? Is the edge the breadth of the portfolio, the trust-based licensing, the partner model, or something else? What’s the wedge for Cisco? Raj Juneja: I can’t really comment on our competition or on what they are doing or choose to do. For us, we’ve been a supplier of leading-edge technology in Canada for more than 30 years. This is our opportunity to provide even more industry-leading technology to that customer base. The keys here are really the choice and control customers are looking for. I see a great opportunity for our long-standing Cisco customers to consider another offering from Cisco. For customers that are looking for Cisco to become an infrastructure provider when they weren’t previously leveraging us, I think this presents a great opportunity for them to consider Cisco. Robert Dutt: Given the current opportunity and market situation, I think anything around sovereignty is going to be really interesting to watch over the balance of this year and into next year. I’ll be very interested to see how this hits the market as it gets out there. Thank you for taking the time ahead of launch to tell us what you can at this point. Raj Juneja: Thanks very much. I enjoyed the conversation. Robert Dutt: There you have it, Raj Juneja from Cisco Canada. I’d like to thank Raj for his time. It was obviously a busy launch day for him and his team. To everyone listening, thanks for tuning in. Here are my takeaways. Cisco is making a meaningful bet here. The trust-based licensing model, where Cisco genuinely can’t touch the systems once they’re deployed, is a real differentiator. The fact that the offering is open to the full partner ecosystem, and not just a handful of larger partners, is good news for the channel. The services opportunity around deploying and managing air-gapped infrastructure is significant, and the Splunk integration gives partners that already carry Cisco networking a cross-sell story. Some questions remain, though. Partner economics – how partners actually earn on this – is still unclear, with Raj pointing to more details in the coming weeks. The competitive picture is also wide open. HPE has been aggressive on sovereign infrastructure in Canada. Microsoft has its own sovereignty offerings, and the federal government is actively funding sovereign AI compute. Cisco’s breadth – networking, security, compute, collaboration and Splunk in one stack – is the pitch. But we’ll need to see how that plays out in customer decisions. If you’re a partner with public sector or regulated-industry customers, this is worth understanding now. The demand is real, it’s running ahead of deployment, and the opportunity to help close that gap is where the channel plays. If you enjoyed this episode, follow or subscribe to the podcast. You can find us on Apple Podcasts, Spotify, YouTube and most podcast directories. Ratings and reviews are always appreciated, and they help other people in the channel find the show. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

The Tech Trailblazers Startup Podcast
Founders on Fire: with John Morello from Minimus

The Tech Trailblazers Startup Podcast

Play Episode Listen Later Aug 17, 2026 20:02


In this episode of the Founders on Fire series by the Tech Trailblazers Awards, host Rose Ross is joined by John Morello, CTO and co-founder of Minimus—the winners of the Container Trailblazer Award.Following their success with Twistlock (acquired by Palo Alto Networks), John and his returning founding team are tackling one of container security's most persistent challenges: vulnerable upstream images. John explains how Minimus strips away unneeded components from popular open-source images to eliminate vulnerabilities, drastically shrink attack surfaces, and seamlessly automate image migration using AI developer agents.In this episode, we cover: The Container Vulnerability Problem: Why official container images often ship with hundreds of vulnerabilities and unnecessary software components that expand the attack surface. Zero-CVE Baseline Images: How Minimus builds thousands of hardened images directly from upstream sources—slashing disc size by 90% and reducing vulnerabilities and attack surface area by up to 99%. The Minimus Community Edition: Providing friction-free access to thousands of free, hardened container images (including FIPS, CIS, and FedRAMP compliant options) without sign-up walls or sales pitches. AI Agent Integration: How detailed prompt frameworks allow AI agents to automatically discover, configure, and migrate legacy Dockerfiles to secure Minimus images with over 95% automation. Supply Chain Protection: How Minimus proxies package downloads (such as npm and Pip) to implement guardrails against typosquatting, unusual committer behaviour, and supply chain poisoning attacks.

The Vonu Podcast
Cloak & Dagger w/ Arjen FULL EPISODE (FIPS, Tollgate, Nostr, & More)[P.A.Z.NIA Radio Network]

The Vonu Podcast

Play Episode Listen Later Aug 2, 2026 163:24


On this full upload of the August 1st, Cloak & Dagger, Thane is pleased to welcome Arjen, a developer within the Nostr/FIPS community. He's also one of the lead guys on Tollgate, a way to monetize and make traditional Internet more grassroots, but with far more expansive visions beyond. In… The post Cloak & Dagger w/ Arjen FULL EPISODE (FIPS, Tollgate, Nostr, & More)[P.A.Z.NIA Radio Network] appeared first on The Vonu Podcast.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 360: SSA Whistleblower and the Thumb Drive: What CISSP Asset Security Tells Us About This Disaster

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jul 6, 2026 23:28 Transcription Available


Send us Fan MailImagine hearing a claim that the most sensitive identity data in the United States could be sitting on a personal thumb drive. That allegation is still unverified and under investigation, but it gives us a rare chance to see CISSP Domain 2 asset security in real time, with consequences that go far beyond a typical data breach.I walk through what's being reported about Social Security Administration data access and potential copying, then I put on the Domain 2 lens: data classification and handling requirements, who the true data owner is, what custodians should be enforcing, and how processors should be limited by scope, purpose, and time. We talk about why “high” impact data under FIPS 199 should automatically trigger stricter controls, and how failures in encryption, logging, and data loss prevention can let sensitive datasets slip outside organizational boundaries.We also dig into the part most teams get wrong: the data lifecycle. If you cannot execute secure disposal and verify it, you cannot “close Pandora's box.” Using NIST SP 800-88, we break down clear, purge, and destroy, connect it to real operational controls like removable media restrictions, and turn the whole story into practical exam guidance and CISO-level program lessons you can use with leadership.Subscribe for more CISSP-ready breakdowns, share this with someone studying Domain 2, and leave a review so more security pros can find the show. What is the first control you would fix in your own environment?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Geekzone Podcast
GZ130: WATCH - Flackerer

Geekzone Podcast

Play Episode Listen Later Jun 28, 2026 101:00 Transcription Available


Jetzt isses nicht so, dass Geekosaurier unbedingt die ganze Welt brennen sehen wollen, aber trotzdem podcasten wir sogar aus dem Fegefeuer. Zumindest fühlt es sich manchmal so an, und das ist nichtmal übertrieben. Trotz der widrigen Umstände bekommt ihr bei uns leicht und fast luftig verpackt nicht nur den besten Tanz der Teufel, der nicht Tanz der Teufel ist, sondern auch den besten Stephen King, der kein Stephen King ist. Falls das jetzt zu verwirrend ist, fragt mal den Christian, der erklärt sowas auch dem Tax gern für Dumme. Verwirrung ist eh King in dieser Episode, wenn der aus Hirnschmelze von Fips gefundene Catweasel Peter so hart verwirrt, dass es sogar den kühlenden Vibrator übertönt... also nehmt Euch ein Eis, räumt den Kühlschrank aus und machts euch darin gemütlich - und dann ab mit der neuen GeekZone. Trailer Time: - [The End of Oak Street](https://www.youtube.com/watch?v=3oB9AxspVow) (alle) Themen: - Lee Cronin‘s The Mummy (Christian) - Scream 7 (Christian, Sidekick: Philipp) - Fazit: Widow's Bay Season 1 (Christian, Sidekick: Philipp) - Good Luck, Have Fun, Don't Die! (Philipp, Sidekick: Christian) - Mortal Kombat 2 (Philipp) - Spider-Noir (Philipp, Sidekick: Tax) - The Boroughs (Tax, Sidekick: Philipp, Christian) - MagentaTV (Peter) Quickies: - Better Call Saul (Peter) - Your Friends & Neighbors (Philipp) - Wolfs (Philipp) - Maximum Pleasure Guaranteed (Philipp) - Shrinking (Philipp) - Kino - Star Wars: The Mandalorian and Grogu (Tax) - Bodies (Christian) [Unsere letterboxd Liste 2026](https://letterboxd.com/ckatzorke/list/geekzone-2026/) [Unsere serializd Liste 2026](https://www.serializd.com/list/474625)

Rust in Production
ClickHouse with Alexey Milovidov and Austin Bonander

Rust in Production

Play Episode Listen Later Jun 18, 2026 60:11 Transcription Available


There's a particular kind of pressure that comes with maintaining software at the very bottom of someone else's stack. ClickHouse lives in exactly that spot: roughly 1.5 million lines of mostly C++ and tens of millions of tests every single day.So what happens when you start introducing Rust into a codebase like that? Not as a rewrite, but linked into a C++ server with a CMake build process that has to be reproducible and FIPS compliant? In today's episode, we get into the messy, interesting reality. We talk about the question of whether the hardest part is Rust the language or Rust the ecosystem.My guests come at this from two very different angles. Alexey Milovidov is the creator of ClickHouse and its CTO. He started the project back in 2009 and has spent decades thinking about performance, correctness, and what it actually takes to build a production database. Austin Bonander is a Senior Software Engineer at ClickHouse and a renowned open-source maintainer of sqlx. He works close to the Rust tooling and the CLI. Together we talk about where Rust fits inside a C++ monolith, what it would take for Rust to earn a rewrite of core components, supply-chain and compliance headaches, and whether Rust is heading for the same accumulation of regrets that every "trendy" language eventually accumulates.

Hotelier.de-Podcast - #MehrWertWissen für die Hotellerie und Gastronomie
Zwischen Revenue, Distribution und 35 Jahren Treue bei Meininger #121

Hotelier.de-Podcast - #MehrWertWissen für die Hotellerie und Gastronomie

Play Episode Listen Later Jun 15, 2026 78:09 Transcription Available


Es gibt viele Meininger-Mitarbeiter, die dort lange arbeiten. COO Thomas Hagemann, mein erster Gast der Hotelgesellschaft, ist acht Jahre im Unternehmen. Steffi und Isabell sogar seit knapp 20 bzw. 15 Jahren. Es gibt einige weitere Beispiele, aber woran liegt das? Was macht die Gruppe, die 1999 in der Meininger Straße in Berlin an den Start ging, so attraktiv? Ein weiteres Thema sind natürlich die Lebensläufe von Steffi und Isabell. Was hat erstgenannte mit gerade mal 19 Jahren für ein Jahr vom beschaulichen Perleberg ins laute New York verschlagen? Isabell hat ein Studium angefangen und nicht beendet, um 2011 bei Meininger eine Ausbildung wie auch später ein duales Studium zu absolvieren. Warum war das die bessere 'Fortbildung'? Und schließlich schnacken wir über die Fachgebiete der beiden: Revenue Management und Distribution. Was früher zusammengehörte, sind heute bei Meininger getrennte Bereiche. Wie gelingt es Steffi und Isabell, diese im Ergebnis wieder zusammenzuführen, damit bei Meininger die richtige Rate über den richtigen Kanal zum richtigen Gast kommt? Gutes Hören beim zweiten Meininger-Podcast im zweiten Fips auf dem Parkplatz des Meininger Hotels Airport Berlin...

ITSPmagazine | Technology. Cybersecurity. Society
Connecting Secure Storage to the Bigger Security Picture | A Brand Highlight at Infosecurity Europe 2026 with Jeanclaude Toma, Chief Executive Officer of Apricorn

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 12, 2026 6:38


At Infosecurity Europe 2026, Jeanclaude Toma, Chief Executive Officer of Apricorn, joins Sean Martin to reframe where secure storage fits in the security conversation. After roughly four decades building hardware-encrypted drives, Apricorn wants the market to treat storage as a security decision rather than a hardware afterthought. How does a storage device become a security control? Toma points to the device itself: no one reaches the data without the code. Access requires a PIN entered on the drive, and the encrypted vault stays closed to everyone else. The protection travels with the drive and does not depend on the host system. Apricorn builds to FIPS certification requirements, hardens against environmental stress down to the connector, and tests repeatedly so compliance arrives built in. Why does this matter at the macro scale? Toma joined Apricorn three months ago to expand the portfolio and connect storage to the broader security marketplace, from military, government, and aerospace settings to the enterprise. He also hints at new form factors still under wraps. Listen in to hear why Apricorn treats the business and operations behind the product as seriously as the product itself. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Jeanclaude Toma, Chief Executive Officer, Apricorn LinkedIn: https://www.linkedin.com/in/jeanclaude-toma/ RESOURCES Learn more about Apricorn: https://apricorn.com Infosecurity Europe 2026 coverage from ITSPmagazine: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Jeanclaude Toma, Apricorn, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, hardware-encrypted storage, FIPS certified storage, secure data storage, encrypted USB drives, data protection, Infosecurity Europe 2026, secure peripherals, PIN authenticated storage Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

GREY Journal Daily News Podcast
How Is DHS Cyber Modernization Changing Federal Procurement?

GREY Journal Daily News Podcast

Play Episode Listen Later Jun 12, 2026 1:44


The Department of Homeland Security is pushing cyber modernization across civilian agencies through CISA programs such as zero trust implementation, Continuous Diagnostics and Mitigation, and Trusted Internet Connections 3.0. Budget requests have kept CISA funding near $3 billion, supporting multi-year investments in detection, response, and workforce. Leadership from Secretary Alejandro Mayorkas, CISA Director Jen Easterly, and DHS CIO Eric Hysen emphasizes joint defense, binding directives, and cross-component coordination. Workforce constraints persist despite the Cyber Talent Management System, prompting greater use of training and managed services. Acquisition relies on vehicles like FirstSource III, PACTS III, GSA MAS, NASA SEWP, and CDM DEFEND task orders. Compliance requirements now center on OMB secure software guidance, NIST control baselines, FIPS 140-3, and FedRAMP. Vendors that map capabilities to CISA's Zero Trust Maturity Model and prepare attestations and authorizations can better align to agency buying priorities.Learn more on this news by visiting us at: https://greyjournal.net/news/ Hosted on Acast. See acast.com/privacy for more information.

Nodesignal - Deine Bitcoin-Frequenz
Nodesignal-Talk - E284 - Meshnetzwerke 2.0

Nodesignal - Deine Bitcoin-Frequenz

Play Episode Listen Later Jun 5, 2026 82:18 Transcription Available


In der heutigen Folge sprechen Thorsten und Zetti mit Meshimouse aka Curemici in einem Follow-Up über Meshnetzwerke. Eine erste Folge zu dem Thema ist im vergangenen Jahr erschienen. Aufgrund der entstandenen Dynamik rund um Meshnetzwerke, insbesondere auch durch den Fokus einer der letzten Sovereign Engineering Kohorten, war wieder Zeit für eine neue Folge zu dem Thema. Meshimouse gibt ein Update zum Reticulum, einen Deepdive in eine neue Android App, die als mobiler Reticulum Client fungiert, was bei Meshtastic passiert ist und gibt einen Ausblick auf die kommenden Entwicklungen. Von und mit: - Curemici- Zettizettler- Thorsten ⚡️- Thorsten ⚡️(Cutting)Hier könnt ihr uns eine Spende über Lightning da lassen: ⚡️nodesignal@getalby.comZusätzlich haben wir auch einen Silent Payment Link: sp1qq0a2rles9y32ffmj0eawvjglgqsgj7hq99ers580l98k42a7rh9szq3sa50fh2e5lwf22fxcjy0qw88u72vlj328qr39da245sq4nrskuqvvv5l4Neben dem Podcast findet ihr uns auch auf YouTubeFür Feedback und weitergehenden Diskussionen kommt gerne in die Telegramgruppe von Nodesignal und bewertet uns bei Spotify und Apple Podcasts, das hilft uns sehr. Folgt uns auch gerne bei Nostr:npub1n0devk3h2l3rx6vmt24a3lz4hsxp7j8rn3x44jkx6daj7j8jzc0q2u02cy und Twitter.Blockzeit: 952011Vorgängerfolge: Episode 1: Folge E246: Nodesignal-Talk – E246 – Selbstsouveräne Kommunikation mit Meshtastic, Reticulum & BitchatArte Sendung über MeshStartpunkt ReticulumZen of Reticulum - Die Philosopie hinter ReticulumColumba - Android Reticulum ClientMeshChatX - Reticulum Desktop Client + Android + Webserver + Nomadnet-Server (MU, MD, HTML) - gibt es auch für den Umbrel-NodeRatspeak - Reticulumg Client für Textnachrichten und Sprache - Rust-ImplementierungReticulum im Browser - ad-hoc MessengermicroRNode Firmware - C++ Reticulum Implentierung, laufähig auf Dev-Boards/RNodesrngit - GIT - Verteilte Software-Entwicklung über ReticulumHAMSTR - (Amatuerfunk, Reticulum Nostr-RelayRRC- Reticulum Relay Chat (Client jetzt auch in Nomad Network integrier)Internet Browsen über Reticulum als ProxyBlackbox Offline Mesh Tools - Offline Node mit Bitcoin und Ecash WalletsTimestamps:00:00 Begrüßung und Einführung02:03 Die Grundlagen von Mesh-Netzwerken05:49 Anwendungsfälle und Notwendigkeit von Mesh-Netzwerken08:44 Dezentralisierung und Souveräne Kommunikation18:19 Updates zu Reticulum23:07 Entwicklung von Reticulum und zentrale Entwickler30:46 Die Columba-App und ihre Funktionen43:24 Private Netzwerke und Telefonie mit Reticulum47:57 Zukünftige Entwicklungen und Gruppen-Chats51:25 Identitäten im Reticulum Netzwerk55:58 Desktop-Anwendungen und Netzwerk-Topologie58:57 Retikulum-Tools und ihre Anwendungen01:00:51 Entwicklung von Meshtastic und MeshCore01:06:39 Kombinationen im Kontext von Bitcoin01:10:26 FIPS und weitere zukünftige Entwicklungen01:18:26 Abschluss und Ausblick auf die Zukunft

Geekzone Podcast
GZ128: PLAY - Vulvarine & Speiderman

Geekzone Podcast

Play Episode Listen Later Jun 5, 2026 126:08 Transcription Available


Ahhh, it's this time of the year... wenn die Pressekonferenzen und Showcases sich die Klinke in die Hand geben gibts für passionierte Laberbacken wie uns natürlich besonders viel zu erzählen - soooo schön. Also, für uns. Und hoffentlich auch für Euch, denn wenn Peter & Tax sich die Lizenz zum Töten abholen, der Fips mit diversen Mutanten, Iron Man und C3PO unterwegs ist und Christian mit Peter über optisch grenzwertige Indie-Titel fachsimpeln... da geht einem einfach das Herz auf, weil es auch abseits der großen Games, die sich alle vor GTA verstecken wollen, noch so viele gute Titel gibt... nebenher lernt ihr auch eine ganze Menge über die Abgrenzung zwischen "Trial and Error" und "Spielen und Ausprobieren" und erlebt, wie Tax ob der visuellen Präsentation des ein oder anderen Games geradezu sprachlos ist - ob aus Begeisterung oder schlicht Verzweiflung bleibt abzuwarten - in drei Tagen gehts übrigens schon mit einer Mini-Zone zu den restlichen Neuvorstellungen weiter - also stay tuned and enjoy! - Short Recap: PlayStation State of Play (alle) - Real Life Fun: Disney Land Paris für Geekz (Philipp) - Reanimal vs. Little Nightmares 3 (Philipp) - Schroedingers Cat Burglar (Philipp) - Darwin Paradox (Tax) - James Bond - 007 First Light (Tax, Sidekick: Peter) - Mina the Hollower (Peter, Sidekick: Christian) - Vampire Crawlers vs Deepest Chamber: Resurrection (Christian) - Dead Reset (Christian) Quickies: - Motorslice (Philipp) - Status: Saros (Peter) - Mixtape (Peter) - Monolith (Peter) - Replaced Fazit (Christian) [Geekzone 2026 bei Backloggd](https://backloggd.com/u/katzenmann/list/geekzone-play-2026/)

Hotelier.de-Podcast - #MehrWertWissen für die Hotellerie und Gastronomie
MICE olé: Bernd Fritzges und Uwe Krohn im neuen Fips Junior #120

Hotelier.de-Podcast - #MehrWertWissen für die Hotellerie und Gastronomie

Play Episode Listen Later Jun 1, 2026 91:51 Transcription Available


Fips hat eine Podcast-Epoche geschrieben. 24 Folgen wurden ihn ihm aufgenommen. Dann kam leider der Zeitpunkt, wo der Oldie jemanden brauchte, der mehr Ahnung vom Innenleben eines Wohnmobils hatte. Und dann kamen Bernd Fritzges und Uwe Krohn. In Hollenstedt, wo Bernd seit langer Zeit wohnt und ich in der Nähe aufgewachsen bin, trafen wir uns zu dritt. Mal schauen, was sie mit Mice Desk vorhaben und wie die Historie von Hotelier.de sich so gemacht hat. Die Fips-Geschichte faszinierte beide besonders. Während des Gesprächs schrieben sich Bernd und Uwe eine WhatsApp - die Geburtsstunden von Fips Junior. Natürlich schnacken wir auch über diese Story - aber wir erfahren auch viel über Uwe Krohn. Z. B. wie seine Hotelkarriere bei Dieter Müller sowie dessen damaligen Astron Hotels begann und sich über 20 Jahre bei H-Hotels fortsetzte. Bernd Fritzges Karriere war durch seinen Großvater wie auch Vater geprägt, die beide Großgastronomen in Berlin bzw. Hamburg waren. So legte Bernd dann auch mit nur 18 Jahren los und ging schnell eigene gastronomische Wege. Irgendwann ergriff ihn das Veranstaltungsgen komplett und schreitete in dem Verband der Veranstaltungsorganisatoren VDVO sowie MICE DESK bis heute fort. Viel spannender Gesprächsstoff also für einen witzigen Ohrenschmaus! Wir wünschen 'Gutes Hören'!

NDR 2 - Wir sind die Freeses
Wir sind die Freeses: Fips!

NDR 2 - Wir sind die Freeses

Play Episode Listen Later Apr 30, 2026 2:45


Fips Asmussen war für Heiko "Snäcki" Postel eine echte Ikone. Bester Mann. Heiko hatte alle Cassetten und wenn er erstmal auf den Komiker angesprochen wird, gibt es für ihn kein Halten mehr. Dann sprudeln die Pointen nur so. Svenni ist hin und weg.

Geekzone Podcast
GZ123: WATCH - Tabaluga im MCU

Geekzone Podcast

Play Episode Listen Later Mar 29, 2026 108:02


Jetzt isses so - und das kann ich nicht beschönigen - einige Mitglieder dieses Podcasts müssen leider in die Nachprüfung, um ihre Nerd-Cards zu verlängern. Entgegen aller anderslautenden Behauptungen ist Tabaluga - bisher - nie Teil des MCU gewesen. Wobei der ja theoretisch ein Bio-Mutant sein könnte und... nein, das führt zu sehr vom Thema weg, denn - all you need is love! Und Christians Liebe zu fliegenden Körperteilen und Partygewalt endet überraschenderweise in bedingunsloser Romantik. Derweil kann Peter (nachdem er als es bereits dunkel war, durch Vorstadtstrassen heimwärts ging) einen Teil seiner Nerd-Card überraschend doch wieder restaurieren - was der Versuch durch Gewaltkonsum in Christians Lovezone zu gelangen doch alles verändern kann. Der Rest war natürlich auch nicht untätig, denn Tax hat seine Rolle als HDR-Inspektor natürlich auch ausgelebt, aber dabei auch auf die anderen Schauwerte geachtet und hoffentlich nicht den Fips beim verrichten der Notdurft am Flussufer beobachtet.In diesem Sinne, habt Spaß mit der Folge und schmückt schön euren Baum, damit die Zahnfee weiss, wo sie die Eier verstecken muss! Trailer Time: - [The Furious](https://www.youtube.com/watch?v=Avky8dVaqAI) - [Spider-Man: Brand New Day](https://www.youtube.com/watch?v=8TZMtslA3UY) - [Dune Part 3](https://www.youtube.com/watch?v=3_9vCamtuPY) - [Harry Potter TV-Series](https://www.youtube.com/watch?v=9g0UKRT7cbI) - [The End Of Oak Street](https://www.youtube.com/watch?v=uxlrNo5QDdQ) Themen: - LotR Return of the King mit Orchester in München (Peter) - The Running Man (Christian, Sidekick: Philipp) - Silent Night Deadly Night (Christian, Sidekick: Philipp) - Together (Christian) - U Are the Universe (Christian) - Predator: Badlands (Tax) - Bring Her Back (Tax) - Daredevil Born Again Staffel 2 (Philipp) - Scrubs Revival 2026 (Philipp) Quickies: - War Machine (Christian, Sidekick: Philipp) - Baby Assassins Everyday (Christian) - 28 Years Later The Bone Temple (Christian) - Kacken an der Havel (Philipp) - Young Sherlock (Philipp) - Terrifier (Peter) - Weapons (Peter, Sidekick: Tax) [Unsere letterboxd Liste 2026](https://letterboxd.com/ckatzorke/list/geekzone-2026/) [Unsere serializd Liste 2026](https://www.serializd.com/list/474625)

Hotelier.de-Podcast - #MehrWertWissen für die Hotellerie und Gastronomie
Fips Junior und der erste Messestand für Hotelier.de #117

Hotelier.de-Podcast - #MehrWertWissen für die Hotellerie und Gastronomie

Play Episode Listen Later Mar 27, 2026 24:33


Als Wolfgang Ahrens und ich uns 2007 auf den Weg machten, war www.hotelier.de eine unbekannte Website mit minimalsten Umsatz. 19 Jahre später ist unsere Seite aus der HOGA-Medienlandschaft nicht mehr wegzudenken: Das Newsportal inklusive einmaligem Branchenlexikon, LinkedIn mit bald 20,000 Followern, der Podcast mit jetzt 117 Folgen, viele persönliche Kontakte führten jetzt erstmalig zu einem Stand auf der Internorga! Und dies mit einem sehr guten Bekannten: Dem rollenden Podcast-Studio Fips! Der trägt jetzt den Zusatz 'Junior', denn sein Vorgänger führt sein Rentendasein bei einem anderen liebevollen Besitzer weiter. Wie kam es zum neuen Wohnmobil und zum Internorga-Stand? Wurde das Ziel erreicht, ein Hoteltreffpunkt zu werden? Wer war so alles da? Wie lief die Taufe von Fips Junior ab? Die zweitwichtigste Frage, die alle gestellt haben: Wie waren die Nächte in der Halle A3 am Stand 805 - haben wir gut geschlafen? ;-) Und das wichtigste zum Schluss: Gibt es 2027 eine erneute Hotelier.de Schnack- und Ruheoase auf der Internorga? Gutes Hören!

The Mixtape with Scott
The Mixtape with Scott (Featuring Caitlin Myers) Season 5: Episode 1 of The Odd Couple!

The Mixtape with Scott

Play Episode Listen Later Mar 10, 2026 53:07


The Odd CoupleThe Mixtape with Scott is back. Season 5. Season 5 of the Mixtape with Scott is going to be different, and fun, and different, and creative! It'll be called The Odd Couple. And it'll be called “The Mixtape with Scott (Featuring Caitlin Myers)”. It'll have different naming conventions until Caitlin pick one we like! Let me tell you all about it.I started the podcast around four years ago as a way of creating an oral history of economics while also tracing out the history of the credibility revolution through Orley Ashenfelter, his students, and the Industrial Relations Section at Princeton. I tacked on a bunch of other things too along the way like “the students of Gary Becker” and “economist in the tech industry”, as well as any number of eddies I wanted to swim in along the way. And after 130 interviews, I more or less felt like I had tapped my creativity out. I largely came to understand the evolution of causal inference a particular way, which I wrote up across several substacks, as well as added throughout my new book, Causal Inference: the Remix (proofs came to me today in fact). It was very rewarding. Maybe one day I'll write up the interviews as a book (even Claude Code cannot yet do that), but for now, I'm just ready to move on, as 130 interviews is a lot.But move on to what? Well, that's what I want to tell you about now. Today's episode is the first episode in a season I'm calling “The Odd Couple” featuring the brilliant economist, Caitlin Myers. And the concept is simple:Caitlin Myers and me will start a research project together which is only performed on the podcast. And we will use Claude Code to do this project on the air. While doing it, we will talk and laugh and share our thoughts about what we are doing. Think of Bob Ross talking while he paints trees. Only instead of trees, it's estimated dosage parameters of abortion clinic closures' effect on marriage using continuous diff-in-diff. And instead of a brush, we are using Claude Code who is using R, python and Stata. But other than those trivial details, it is exactly like Bob Ross, or maybe the View. The Odd Couple featuring Caitlin Myers, Scott Cunningham and Claude CodeCaitlin Myers is the John G. McCullough Professor of Economics at Middlebury College in beautiful Vermont. And she is, at the time of this writing, arguably one of the leading economists working on reproductive policy in the United States, maybe the world. She's been published a lot on the topic for a very long time, including this article in the Journal of Political Economy, our JHR on abortion clinic closures, and numerous others. You can find it all at her slick website. She's also been a contributor to the public good by creating public data repositories. She built this dashboard. She knows where every clinic opened and closed and when, going back decades. She's meticulously described each and every relevant law regulating abortion access. If you've read a paper in the last ten years about abortion services, there's a good chance a design by Caitlin, or data she helped curate and distribute, was somehow connected to it. Her influence in this space has been massive.But in addition to being great, she's also funny, thoughtful, and thinks really well on her feet. Which is one of the reasons I thought it would be great to have her as my research partner and conversation partner on the podcast. Because I think if this concept is going to work, a lot of planets have to align, and I had been thinking for a very long time that if there was such a square peg to fit a square hole, it would be her.I would say that Caitlin and I are right at that sweet spot of professional acquaintances bordering on friends. That's the type of person who you make a point to find when you are at a conference and get a drink with even if you aren't at that moment writing a paper together. It's that person who you shared a little about your private life with when you were on a car ride together to the airport. It's that person who you text memes of Beyonce giving out high fives for no good reason. It's that person you want to send a note to in class saying “Will you be my friend? Circle yes or no”. No one does this on the airSo the idea of this podcast is that she and I are going to extend an old study of ours with Jason Lindo and Andrea Schlosser published in the Journal of Human Resources called “How Far Is Too Far?” It studied what happened when Texas passed HB2 in 2013 and nearly half the state's abortion clinics closed overnight. We used the sudden, geographically uneven changes in driving distance to the nearest clinic to estimate the causal effect of access on abortion rates. The punchline was that distance matters, the effects are non-linear, and congestion at the surviving clinics matters too.But what we want to do is extend the research design in a couple of ways. First, we want to study the effect that the abortion clinic closures had on marriage. While Caitlin has studied the effect of abortion access on marriages, no one has look at the clinic closures on marriage using, more specifically, the “travel distance design” as I call it. Secondly, we are going to be learning how to estimate treatment effect parameters, as well as what those estimands even mean, using the new conditionally accepted (at the AER — woo hoo fellas!) continuous diff-in-diff estimator by Callaway, Goodman-Bacon and Sant'Anna estimator. This estimator already has over a thousand cites and it's only just now conditionally accepted — it's not even really really accepted. It's like the AER is saying it likes you, but does it really really like you? Not until it's accepted you does the AER really really like you. Right now it's a conditional accept which is more like a situationship. Anyway, I'm rooting that these two get hitched, and so we're going to be using their estimator with this travel distance design to estimate a bunch of estimands that we're going to learn about together. So that's fun.The AI angleAnd then third, and maybe the goofiest of all — Claude Code. We are going to do all of this using Claude Code. The hope being that we can wrap our hands around just how to use this thing to do good, and not evil. And I think this is the funnest (most fun?) part because Caitlin is probably the more pessimistic towards AI, whereas I am the most optimistic, which on average means we are aloof to AI. And Claude is probably going to sometimes agree with me, sometimes with Caitlin, and sometimes just want to say we all have a great point. Anyhow, we are going to be doing this project together using Claude Code so that listeners and viewers can better see how we use Claude Code for practical empirical research, and how we go about trying to get it to not jump the electric fence, or if it does, not cause mayhem. But as I said, Caitlin and I have very different priors on this. I'm the AI optimist and she's the AI skeptic. While we have both been using Claude Code for months, and we've both seen what it can do, and we both agree we're in the early innings of something that fundamentally changes how research gets done, I think we both have fundamental opinions and concerns that sometimes overlap with each other and other times don't. But she is, I think like me, curious to a fault. She wouldn't be doing this if she weren't — but she thinks AI is, in her words, an existential threat to humanity. And she is not being dramatic. She means it. And that's not an uncommon worry among people, nor is it an uncommon position to take that people simultaneously are angry or upset about AI and want to better understand Claude Code's utility for practical empirical research. That's just the times that we are in that both of those can be true at the same time for the same person. She's the person at the table asking the hard questions about what happens when these tools get good enough that the verification problem becomes the only problem.So you have one person who thinks this is going to be incredible and one person who thinks it might end civilization, and we're both using the same tool to do the same project. That tension is real, it's productive, and it's part of what you'll hear.And here's the thing about podcasting with Claude Code running in the background: there's a lot of time while it's working. It's reading files, writing scripts, compiling things, running pipelines. And during that time, Caitlin and I are talking. About AI, about science, about what we're seeing in real time on the screen, about the project, about whether what just happened was impressive or terrifying or both, or just about life, about the meaning of being a researcher, about our worries and hopes and where, and so on. And we are joking around and bantering. It's like The View if The View had two economists staring at a terminal.What to expectEpisodes will drop as we work through the project. Some will be data work — the kind of session where we're elbow-deep in county FIPS codes and file format inconsistencies. Some will be methodological — working through the continuous diff-in-diff framework, figuring out what the identifying assumptions actually require. Some will be the conversations that happen in between — about AI, about the future of empirical research, about what it means to do science in public.I don't know how many episodes this will be. I don't know what we'll find. I don't know if the marriage result will be a null or something real or something we can't interpret. As they say in therapy, it's about the journey not the destination! This podcast is about the journey, which is to say it's about the joy researchers get from doing research, not necessarily from completing it. And it's a podcast of two people talking while they do it.The Mixtape with Scott is back. Season 5. The Odd Couple. Featuring Caitlin Myers. We're making the sausage, and you're invited to watchScott's Mixtape Substack is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber. Get full access to Scott's Mixtape Substack at causalinf.substack.com/subscribe

Citadel Dispatch
CD193: FIPS - FIXING THE INTERNET

Citadel Dispatch

Play Episode Listen Later Mar 6, 2026 57:48 Transcription Available


FIPS is an open source mesh networking project that enables devices to connect directly to each other without relying on any central servers or infrastructure. Today's internet depends on companies and governments that can monitor, censor, or shut down communication at will. FIPS solves this by giving every node a cryptographic identity and encrypting all traffic automatically, so no one in the middle can see or block what you're doing. Nodes discover each other and route messages through the mesh on their own, and regular apps like browsers and SSH clients work on top of it without any special setup.Arjen on Nostr: https://primal.net/p/npub1hw6amg8p24ne08c9gdq8hhpqx0t0pwanpae9z25crn7m9uy7yarse465grJonathan on Nostr: https://primal.net/p/npub19wavu4f7l6l43h24jyskn7fvzy37kcfp67aqjtmv2qgy4lp34nhsda8p6k FIPS Repo: https://gitworkshop.dev/npub1y0gja7r4re0wyelmvdqa03qmjs62rwvcd8szzt4nf4t2hd43969qj000ly/relay.ngit.dev/fips Tollgate: https://tollgate.meSovereign Engineering: https://sovereignengineering.io/ EPISODE: 193BLOCK: 939631PRICE: 1465 sats per dollar(02:03) Introducing FIPS and the goal of a middleman free internet(04:16) Why static IPs fail for hosting and how FIPS reframes identity(05:51) Decoupling transport and routing: protocol-agnostic design(06:50) Peer discovery across Wi‑Fi, Bluetooth, and local broadcast(07:43) Future global routing ideas and decentralized discovery(09:05) Local mesh handshakes, Noise encryption, and Bloom filters(11:02) Community meshes, resilience, and mixed transports(11:42) Starlink and bridging meshes over the wider internet(13:21) Use case: protest resilience and reconnecting to the world(14:08) Origins: conferences, Sovereign Engineering, and NoDNS(16:04) From NoDNS to FIPS: faster updates, remaining gaps(17:10) Economics: sats for peering and incentive-aware routing(18:00) Abuse, DDoS surfaces, and defenses via npubs and rate limits(19:45) Learning from mesh hype cycles and bootstrapping adoption(22:32) Lowering app friction: make existing apps work over FIPS(25:12) DNS trick: IPv6 mapping and transparent transport(27:08) Backwards compatibility as a must-have for scale(28:08) Rethinking data flow with Nostr streams and local hosting(30:12) Offline-to-online spectrum and graceful reconciliation(31:10) Status update: early servers, testers, and bandwidth limits(32:20) Physical constraints: MTU, Bluetooth, LoRa(36:00) Reality checks: pitfalls, past meshes, and expectations(38:12) New primitives: Nostr, Blossom, eCash; Jonathan's role(40:37) Identity concerns, key rotation, and operational practices(46:10) Hosting sensitive services: hot keys(48:09) Self-hosting privately, Tor comparisons, and latency(49:37) Observation, Tollgate incentives, and community privacy(50:40) Tollgate legal concerns and community norms(53:21) Call to action, testing FIPS, and packaging plans(55:10) Closing thoughtsmore info on the show: https://citadeldispatch.comlearn more about me: https://odell.xyz

Rabbit Hole Recap
RABBIT HOLE RECAP #398: BITCOIN IS THE BEST MONEY

Rabbit Hole Recap

Play Episode Listen Later Feb 27, 2026 86:23


https://rhr.tv/stream • Zoom scam https://therecord.media/north-korean-hackers-targeted-crypto-exec-clickfix • Numo – Bitcoin Tap-to-Pay POS App for Android (Lightning & Ecash, Zero Fees)https://numopay.org/ • Mail Mike: AI Agent with Bitcoin Lightning Wallet – Prompt Injection Bounty Challengehttps://primal.net/e/nevent1qqs9jsvekaswngjd3nxldz832nm2ddmjjrlhk7hddzh8luv2rf3gprcdap9fa • FIPS: Free Internetworking Peering System – Nostr Keypair Mesh Networking Protocolhttps://primal.net/e/nevent1qqsvd3nzk5p92fzp9z7p34m50039dwee0aemrvk9cl2jpng3kawsz0q6wuh7w • Russia to Scale Internet Filtering with AI Roskomnadzor, Russia's internet regulator, is building an AI-powered censorship system with a 2.27 billion ruble ($29 million) budget. According to analysts, the system will use AI to instantly block mirror sites hosting banned content and, more ominously, to identify the people creating those mirrors. The move would further restrict the space for dissent and independent online information in Russia. FinancialFreedomReport.org • Large-scale Online Deanonymization with LLMs (arXiv Paper)https://arxiv.org/abs/2602.16800 • Anthropic Exposes Industrial-Scale Distillation Attacks on Claude by DeepSeek, Moonshot AI & MiniMaxhttps://x.com/anthropicai/status/2025997928242811253 • Man Accidentally Gains Control of 7,000 Robot Vacuums (DJI Romo Security Bug)https://www.popsci.com/technology/robot-vacuum-army/ • The 2028 Global Intelligence Crisis – AI-Driven White-Collar Job Displacement Thought Experimenthttps://www.citriniresearch.com/p/2028gic • US Strike on Mexico By…? (Polymarket Prediction Market)https://polymarket.com/event/us-strike-on-mexico-by • RFK Jr. (Sec. Kennedy): Pesticides Are Toxic by Design – Supporting Trump's Regenerative Agriculture Transitionhttps://x.com/seckennedy/status/2025760500793909389 • Rep. Thomas Massie: End Pre-Harvest Glyphosate Spraying on Wheathttps://xcancel.com/repthomasmassie/status/2025932814533697629 3:54 - Daylight savings 6:59 - Dashboard 8:44 - ID snow shoveling 9:54 - Jane Street 16:34 - Zoom scam 19:44 - Anthropic 27:34 - Numo 36:54 - Raising kids 41:49 - Mail Mike 44:54 - FIPS 46:34 - HRF Story of the Week 51:49 - DJI robots 57:14 - Citrini AI blog 1:07:39 - Boosts 1:09:09 - Glyphosates 1:13:54 - Bitcoin updates 1:16:39 - Cartel war? 1:20:09 - Block cutting employees Shoutout to our sponsors: Coinkite https://coinkite.com/ Strike https://strike.me/ Stakwork https://stakwork.ai/ Salt of the Earth https://drinksote.com/rhr Follow Marty Bent: Twitter https://twitter.com/martybent Nostr https://primal.net/marty Newsletter https://tftc.io/martys-bent/ Podcast https://tftc.io/podcasts/ Follow Odell: Nostr https://primal.net/odell Newsletter https://discreetlog.com/ Podcast https://citadeldispatch.com/

KuppingerCole Analysts
Analyst Chat #285: Future-Proofing Authentication in a Post-Quantum World

KuppingerCole Analysts

Play Episode Listen Later Feb 2, 2026 33:44


Quantum computing isn’t just a future threat to encryption, it’s a direct risk to identity and authentication. In this week's episode, Matthias is joined by Jonathan Care to explore why identity is the quantum bullseye and what organizations must do now to prepare for a post-quantum world. You’ll learn: ✅ Why authentication protocols depend entirely on cryptography✅ How “harvest now, decrypt later” (HNDL) already puts identity data at risk✅ Why identity, not data encryption, is the weakest point in a quantum future✅ What post-quantum cryptography standards (FIPS 203, 204, 205) change — and what they don’t✅ How Passkeys and FIDO2 are quietly becoming post-quantum ready✅ Why PKI, certificates, federation, and non-human identities face massive scale challenges✅ What crypto agility really means for IAM and Zero Trust✅ A practical 4-phase roadmap for CISOs to start preparing today The biggest risk isn’t a future quantum computer — it’s the long-lived certificates and identity data issued today.

KuppingerCole Analysts Videos
Analyst Chat #285: Future-Proofing Authentication in a Post-Quantum World

KuppingerCole Analysts Videos

Play Episode Listen Later Feb 2, 2026 33:44


Quantum computing isn’t just a future threat to encryption, it’s a direct risk to identity and authentication. In this week's episode, Matthias is joined by Jonathan Care to explore why identity is the quantum bullseye and what organizations must do now to prepare for a post-quantum world. You’ll learn: ✅ Why authentication protocols depend entirely on cryptography✅ How “harvest now, decrypt later” (HNDL) already puts identity data at risk✅ Why identity, not data encryption, is the weakest point in a quantum future✅ What post-quantum cryptography standards (FIPS 203, 204, 205) change — and what they don’t✅ How Passkeys and FIDO2 are quietly becoming post-quantum ready✅ Why PKI, certificates, federation, and non-human identities face massive scale challenges✅ What crypto agility really means for IAM and Zero Trust✅ A practical 4-phase roadmap for CISOs to start preparing today The biggest risk isn’t a future quantum computer — it’s the long-lived certificates and identity data issued today.

The Azure Security Podcast
Episode 123: Agentic Identity

The Azure Security Podcast

Play Episode Listen Later Jan 21, 2026 36:17 Transcription Available


In this episode, Michael, Sarah and Mark talk to Nick Wryter about agentic AI identity, with a big focus on least privilege issues. We also cover news about:Microsoft AI TourAzure Database for PostgresSQLAzure MCP Server for Azure Confidential LedgerApplication Gateway, FIPS 140-2 and TLSOutbound internet access from VMsAzure NetApp Files and Ransomware protectionAzure Cosmos DB Mirroringhttps://aka.ms/azsecpod

Technology Tap
Security Governance Explained: Key Policies and Procedures for IT Skills Development

Technology Tap

Play Episode Listen Later Jan 15, 2026 27:19 Transcription Available


professorjrod@gmail.comIn this episode of Technology Tap: CompTIA Study Guide, we delve into the critical role of security governance in building secure organizations. Learn how governance frameworks—comprising policies, standards, procedures, and playbooks—transform strategic intent into consistent, auditable actions that both teams and auditors rely on. Whether you're preparing for your CompTIA exam or aiming to develop essential IT skills, understanding these governance principles is key to effective tech exam prep and technology education. Join us as we break down complex concepts in an easy-to-understand way, helping you succeed in your IT certification journey and beyond.We start with clear definitions that make exam questions and real-world decisions easier. Policies set high-level rules and expectations. Standards add measurable technical requirements like encryption strength and logging baselines. Procedures translate both into step-by-step action, and playbooks coordinate who does what, in what order, using which tools. Along the way, we compare external frameworks such as ISO 27001, NIST 800, PCI DSS, and FIPS with internal standards that tailor controls to your environment.Privacy law isn't a side quest; it shapes everything. We demystify GDPR, CCPA, FERPA, HIPAA, and COPPA, and clarify roles that exams love to test: the data owner who sets classification and usage, the data controller who defines purpose and lawful basis, the data processor who acts for the controller, and the data custodian who protects and maintains data without deciding how it's used. You'll learn practical cues to spot each role fast and avoid common pitfalls.Finally, we dig into change management as a risk control function. Its goal is to minimize risk while implementing changes, with impact analysis, approvals, testing, and rollback plans. Automation and orchestration can speed response and reduce error, but only when guided by policy and enforced by standards. Expect memorable exam tips, grounded examples, and a framework you can use right away on the job.If this helped sharpen your Security+ prep or your day-to-day practice, subscribe, share the show with a colleague, and leave a quick review. Your feedback helps more learners tap into technology with confidence.Support the showArt By Sarah/DesmondMusic by Joakim KarudLittle chacha ProductionsJuan Rodriguez can be reached atTikTok @ProfessorJrodProfessorJRod@gmail.com@Prof_JRodInstagram ProfessorJRod

FedScoop Radio
HPE's Bob Friday on how AI and cloud are transforming federal network modernization

FedScoop Radio

Play Episode Listen Later Dec 2, 2025 8:49


Bob Friday, Chief AI Officer for HPE Networking, discusses how federal agencies are rethinking network modernization in the face of rising complexity, new security demands, and the accelerating influence of AI. Friday shares what he's hearing from federal IT leaders about their most urgent challenges—cloud migration hurdles, stringent security requirements like FedRAMP and FIPS, and the staffing constraints shaping today's modernization efforts. He also breaks down the technology trends driving HPE's approach, including the shift to real-time AI-ops, the organizational changes required to fully leverage agentic AI, and how HPE's acquisition of Juniper Networks strengthens the push toward a “self-driving network.”

CISSP Cyber Training Podcast - CISSP Training Program
CCT 298: Determining Data Controls - CISSP

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Nov 17, 2025 36:27 Transcription Available


Send us a textCheck us out at:  https://www.cisspcybertraining.com/Get access to 360 FREE CISSP Questions:  https://www.cisspcybertraining.com/offers/dzHKVcDB/checkoutGet access to my FREE CISSP Self-Study Essentials Videos:  https://www.cisspcybertraining.com/offers/KzBKKouvA graphing calculator running ChatGPT might make headlines, but our real job is keeping sensitive data from walking out the door. We break down the data states that matter most—at rest, in transit, and in use—and show how to pair encryption, access control, and monitoring without drowning in complexity. Along the way, we share a pragmatic blueprint for classification and labeling that teams actually follow, from visual tags and watermarks to tightly governed upgrade and downgrade paths that keep owners accountable.From there, we zoom out to strategy. Risk tolerance drives control selection, so we talk through scoping and tailoring: how to apply NIST and ISO 27001 sensibly, where GDPR and HIPAA come into play, and why focused logging beats “collect everything” fantasies. You'll hear the real differences between DRM and DLP—licensing and usage enforcement versus data path control—and when each tool earns its keep. We also lay out transfer procedures that work in the wild: SFTP with verified keys, email encryption, FIPS‑validated USBs, and restricted cloud shares with time‑boxed access.Cloud isn't a blind spot when a CASB sits between your users and SaaS. We explain how a CASB delivers visibility into shadow IT, enforces policy across apps, integrates with identity for conditional access, and even helps you rein in egress costs. Tie it all together and you get a layered, test‑ready approach that helps you pass the CISSP while protecting what matters most. If this helped sharpen your plan, follow the show, share it with a teammate, and leave a quick review so we can keep building tools that move you forward.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 289: Practice CISSP Questions - Role Based, Mandatory, Discretionary and ABAC (Domain 5)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Oct 16, 2025 18:25 Transcription Available


Send us a textQuantum isn't a distant sci‑fi threat—it's shaping security decisions right now. We open with what NIST's new post‑quantum FIPS 203/204/205 actually mean for your crypto roadmap, why “harvest now, decrypt later” raises the stakes for long‑lived data, and how the 2035 federal mandate will ripple through contractors, audits, and CMMC. Then we get practical, translating policy pressure into the access decisions you make every day and the concepts you'll see on the CISSP exam.We break down mandatory access control (labels, clearance, strict need‑to‑know), discretionary access control (owner grants, permission creep), role‑based access control (job functions, least privilege at scale), attribute‑based access control (context, dynamic conditions), and rule‑based control (fine‑grained logic and exceptions). Along the way, we highlight the keywords that unlock tricky multiple‑choice items—“classification,” “owner,” “job role,” “attributes,” “rules”—so you can map questions to the correct model fast. More importantly, we explain how to combine models without creating chaos: use RBAC for baseline entitlements, layer ABAC for context and risk signals, lean on rule-based policies for surgical exceptions, and reserve MAC for highly classified domains where enforcement must be absolute.If attackers are stockpiling ciphertext for a quantum tomorrow, the answer is a two‑track plan: crypto agility to adopt quantum‑resistant algorithms and disciplined access governance to limit blast radius today. We share actionable cues for exam success, practical design tips for avoiding privilege escalation, and a reminder that good security is repeatable security—clear roles, auditable policies, and continuous review.Subscribe for weekly CISSP prep you can use on the job, share this with a teammate who's wrangling access models, and leave a review to help others find the show. Your support also fuels our charity‑funded training that gives back while you level up.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Feds At The Edge by FedInsider
Ep. 211 Empowering Agencies with Optimized Operations (preview)

Feds At The Edge by FedInsider

Play Episode Listen Later Aug 6, 2025 22:57


Here is the link to the free webinar on August 27, 2025 2pm EDT Empowering Agencies with Optimized IT Operations preview Cybersecurity teams are facing a “perfect storm” - more attacks, fewer defenders, and outdated infrastructure.  This week on Feds At The Edge, we offer a sneak peek into an upcoming webinar that will teach you how to truly see what's happening on your network- moving beyond basic monitoring to actionable observation.  Brian Chamberlain, Account Executive, USMC/USN, SolarWinds, Chamberlain breaks down why simple monitoring isn't enough. Without pinpointing blind spots or knowing where to start, agencies waste time, increase risk, and rack up costs. He explores:      Automation: Threats move too fast for humans to manage alone.         Hierarchy: How to prioritize  what matters most.           Compliance: Practical takes on NIST 800-207, FIPS 140-2, and Common Criteria.           AI in Action: How artificial intelligence can reveal inefficiencies and free humans to focus on decisions.   

Heimat lesen
#25 Arthur Achleitner: Geschichten aus den Bergen (25)

Heimat lesen

Play Episode Listen Later Jul 20, 2025 26:31


Zwei rivalisierende Dackel, drei kartenspielende Dörfler und eine gebratene Kalbshaxe bilden das Spannunsgegeflecht in der Geschichte 'Wodan und Fips'; Ein totgeglaubter Jagdgehilfe, der unerwartet wieder aufersteht; dazu ein 'Konkurrenzschießen' in Hohenschwangau - drei Berggeschichten aus dem unerschöpflichen Fundus des Alpenschilderers Arthur Achleitner.

Hotelier.de-Podcast - #MehrWertWissen für die Hotellerie und Gastronomie
Martin Stockburger: Vom Luxus- zum Koncepthotelier #102

Hotelier.de-Podcast - #MehrWertWissen für die Hotellerie und Gastronomie

Play Episode Listen Later Jul 17, 2025 78:59


Martin Stockburger hat einen langen, schönen Ritt durch die Luxushotellerie hinter sich. Auf diesem hat er als Azubi im Steigenberger Inselhotel Konstanz sowie als Trainee z. B. in den Hotels Bareiss und Atlantic Hamburg so einiges mitgenommen. Auch war Martin in Frankreich, der Schweiz und Spanien tätig, bis ihn die Luxusreise zu Le Méridien nach Frankfurt und Köln führte. Und dann kamen acht Jahre Althoff Hotels in verschiedenen Führungspositionen. Warum verlässt man 2017 dieses schick gemachte Bett? Wegen einer Idee: Koncept Hotels. Hier sollte eine neue Art der Hotellerie entstehen, die einzigartig digitalisiert, sozial fair und lokal verankert ist und trotzdem Geld macht. - Inwieweit ist das gelungen? - Warum kann man in seinem Erstlings-Haus am Kölner Altermarkt beim Einchecken keine Kondome kaufen, auch wenn man ein 5-Mark-Stück dabei hat? - Wünscht Martin sich ab und zu ein Hotelzimmer ohne WLAN aber mit dem guten alten Zimmerservice? - Und warum man nie, nie, nie Karnevalskostüm statt Uniform sagen sollte ;-) Gutes Hören beim Podcast Nr. 102 im Fips auf einem herrlichen Campingplatz am Rhein.

Ask Noah Show
Ask Noah Show 448

Ask Noah Show

Play Episode Listen Later Jun 28, 2025 53:59


This week we ask the question, when is it okay to leverage technology you don't understand, and when should you work to acquire the underlying domain knowledge? -- During The Show -- 00:52 Intro Cut from the same cloth 02:12 When to Leverage Tools Will always be jobs for deep understanding Lets Encrypt shortening life of certs AWX story Why AWX Short term damage control Advice for someone else You have to understand the manual process Is it still possible to dig down? Clicking through UI skill set How much time do you spend down the rabbit hole 23:09 News Wire Open ZFS 2.3.3 - phoronix.com (https://www.phoronix.com/news/OpenZFS-2.3.3) Open ZFS 2.2.8 - phoronix.com (https://www.phoronix.com/news/OpenZFS-2.2.8-Released) Darktable 5.2 - darktable.org (https://www.darktable.org/2025/06/darktable-5.2.0-released/) QtCreator 17 - qt.io (https://www.qt.io/blog/qt-creator-17-released) Nano 8.5 - gnu.org (https://lists.gnu.org/archive/html/info-gnu/2025-06/msg00003.html) MKVToolNix 93.0 - mkvtoolnix.download (https://mkvtoolnix.download/windows/releases/93.0/) Linux 6.14 EOL - endoflife.date (https://endoflife.date/linux) Plasma 6.4 - kde.org (https://kde.org/announcements/plasma/6/6.4.0/) KDE Frameworks 6.15 - kde.org (https://kde.org/announcements/frameworks/6/6.15.0/) IceWM 3.8 - phoronix.com (https://www.phoronix.com/news/IceWM-3.8-Released) Sway 1.15 - github.com (https://github.com/swaywm/sway/releases/tag/1.11) WSL 2.6 Open Source - phoronix.com (https://www.phoronix.com/news/Microsoft-WSL-2.6-Open-Source) PostmarketOS 25.06 - postmarketos.org (https://postmarketos.org/blog/2025/06/22/v25.06-release/) Rocky Linux 10.0 - rockylinux.org (https://rockylinux.org/news/rocky-linux-10-0-ga-release) Kali Linux 2025.02 - kali.org (https://www.kali.org/blog/kali-linux-2025-2-release/) Amazon Linux 2023 FIPS 140-3 - aws.amazon.com (https://aws.amazon.com/blogs/compute/amazon-linux-2023-achieves-fips-140-3-validation/) PAM & Udisks Flaws - thehackernews.com (https://thehackernews.com/2025/06/new-linux-flaws-enable-full-root-access.html) Mistral 3.2 - venturebeat.com (https://venturebeat.com/ai/mistral-just-updated-its-open-source-small-model-from-3-1-to-3-2-heres-why/) MiniMax M1 - theregister.com (https://www.theregister.com/2025/06/17/minimax_m1_model_chinese_llm/) 24:40 AI vs Privacy Users don't want sensitive data retained Claims order creates "mass surveillance program" If it's on the internet, it's public Expectation of using AI Will this change the way people use these tools Responsibility is on the professional Approaching 50/50 AI/Human internet data Data mining and model training ARSTechnica (https://arstechnica.com/tech-policy/2025/06/judge-rejects-claim-that-forcing-openai-to-keep-chatgpt-logs-is-mass-surveillance/) 41:00 Framework 12 inch Laptop Designed to be repaired Framework presenter pulled off the keyboard live 13 inch vs 15 inch laptops Touch screen 2 in 1 Productivity on the plane Phoronix (https://www.phoronix.com/review/framework-laptop-12) -- The Extra Credit Section -- For links to the articles and material referenced in this week's episode check out this week's page from our podcast dashboard! This Episode's Podcast Dashboard (http://podcast.asknoahshow.com/447) Phone Systems for Ask Noah provided by Voxtelesys (http://www.voxtelesys.com/asknoah) Join us in our dedicated chatroom #GeekLab:linuxdelta.com on Matrix (https://element.linuxdelta.com/#/room/#geeklab:linuxdelta.com) -- Stay In Touch -- Find all the resources for this show on the Ask Noah Dashboard Ask Noah Dashboard (http://www.asknoahshow.com) Need more help than a radio show can offer? Altispeed provides commercial IT services and they're excited to offer you a great deal for listening to the Ask Noah Show. Call today and ask about the discount for listeners of the Ask Noah Show! Altispeed Technologies (http://www.altispeed.com/) Contact Noah live [at] asknoahshow.com -- Twitter -- Noah - Kernellinux (https://twitter.com/kernellinux) Ask Noah Show (https://twitter.com/asknoahshow) Altispeed Technologies (https://twitter.com/altispeed)

South Side Sox: for Chicago White Sox fans
Sharing Sox 146 — First international edition — 2025-06-17

South Side Sox: for Chicago White Sox fans

Play Episode Listen Later Jun 18, 2025 48:30


After some jerk sabotaged a cable in his neighborhood the day before, West Coast correspondent Will Allan was able to fire up his copper wire to connect with duty geezer and father, Leigh ... on the Isle of Man! Yes, No. 146 is the first international edition of Sharing Sox and most likely the only international podcast in the South Side Sox/Sox Populi annals. The never-before MLB podcast from the Isle of Man began with talk of the Andrew Vaughn-Aaron Civale trade — including Civale's possible trade value a month from now. That led to other possible trade values of White Sox gettables, including Luis Robert Jr., Mike Tauchman, Miguel Vargas, Mike Vasil and Adrian Houser ... which led to the wild difference between ERAs and FIPs for Vasil and Houser. Then it was onto great praise for Chase Meidroth offset by great concern over the hole at first base (Leigh again brought up the idea of plunking Andrew Benintendi there). The podcast ended up with the Athletic feature about the deadened ball flying about four feet shorter this year. Please support our White Sox writing and podcasts.   Learn more about your ad choices. Visit megaphone.fm/adchoices

Hotelier.de-Podcast - #MehrWertWissen für die Hotellerie und Gastronomie
Nr. 100 mit 13 Grußworten, 4 Freunden und 1 Erdbeerbowle

Hotelier.de-Podcast - #MehrWertWissen für die Hotellerie und Gastronomie

Play Episode Listen Later Jun 5, 2025 115:19


Wenn sich bei mir im Oberstübchen eine Idee einnistet, macht sie sich das nicht lange gemütlich und muss umgesetzt werden! Einfach mal so einen Podcast zu starten, ist allerdings bei arg begrenztem Wissen um diesen schwierig. Aber es gelang mit Anschubhilfe und somit dürfen wir die Nr. 100 ins Leben rufen! Dafür habe ich mir 4 Freunde nach Buxtehude-Dammhausen eingeladen, die schon mal (oder auch öfter) zu Gast waren: 1000-Sascha Dalig, Sonnenschein Anna Heuer, Miss Lautlach Isabella Owen und Superknipse Thomas Loris (die Namen erklären sich im Podcast von selbst, glaubt mir). Man ergänze dies durch 13 unfassbar wertschätzende Grußworte von Konstantin Ballek, Philipp von Bodman, Suzann Heinemann, Kathrina Heun, Philipp Sebastian Ingenillem, Corinna und Peter Joehnk, Mario Krar, Caroline von Kretschmann, Arne Mundt, Oliver Ratajczak und Marcus Smola und serviere dazu 2 Liter selbst gemachte Erdbeerbowle und fertig ist ein launig-lustiger Schnack durch 100 Folgen Hotelier.de-Podcast. Gutes Hören!

LINUX Unplugged
616: From Boston to bootc

LINUX Unplugged

Play Episode Listen Later May 25, 2025 90:37 Transcription Available


Fresh off Red Hat Summit, Chris is eyeing an exit from NixOS. What's luring him back to the mainstream? Our highlights, and the signal from the noise from open source's biggest event of the year.Sponsored By:Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices! 1Password Extended Access Management: 1Password Extended Access Management is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps. Support LINUX UnpluggedLinks:

Cup o' Go
Go gets audited, and Ian Lance Taylor talks about 19 years on the Go team

Cup o' Go

Play Episode Listen Later May 23, 2025 53:53 Transcription Available


Go gets auditedBlog: Go Cryptography Security Audit by Roland Shoemaker and Filippo ValsordaDeeper dive into FIPS in Episode 89 with Alex Scheel✋ Proposal declined: x/exp/xiter: new package with iterator adapters⛺ Gophercamp video: Your code deserves better: give it a linter by Gabriel Augendre

Hotelier.de-Podcast - #MehrWertWissen für die Hotellerie und Gastronomie
Constantin Rehberg: Missionen erfüllt - zurück in die Hotellerie #99

Hotelier.de-Podcast - #MehrWertWissen für die Hotellerie und Gastronomie

Play Episode Listen Later May 23, 2025 31:27


Constantin hat sich von Lüneburg auf den Weg nach Buxtehude gemacht. Dort sitzt er als vierter Podcast-Gast im Fips und schaut in den Garten voller Grünlinge, Spatzen und Stare. Diese kümmern sich z. T. nur einen halben Meter entfernt um das Futter für ihre Kleinen und sich. Friedlicher kann eine Podcast-Umgebung kaum sein, auch wenn es stürmt sowie teils hagelt. Drei Jahre nach unserem Erstling wagen wir einen zweiten. Wir schauen, was sich beim Bargeld getan hat: Wird es eines Tages ganz abgeschafft sein? Wie war die Reise mit Senior Serviced Co-Living-Anbieter Lively wie auch Service-Apartment-Anbieter Stayery und warum enden die jetzt?

Oracle University Podcast
Oracle GoldenGate 23ai Security Strategies

Oracle University Podcast

Play Episode Listen Later May 20, 2025 16:13


GoldenGate 23ai takes security seriously, and this episode unpacks everything you need to know. GoldenGate expert Nick Wagner breaks down how authentication, access roles, and encryption protect your data.   Learn how GoldenGate integrates with identity providers, secures communication, and keeps passwords out of storage. Understand how trail files work, why they only store committed data, and how recovery processes prevent data loss.   Whether you manage replication or just want to tighten security, this episode gives you the details to lock things down without slowing operations.   Oracle GoldenGate 23ai: Fundamentals: https://mylearn.oracle.com/ou/course/oracle-goldengate-23ai-fundamentals/145884/237273 Oracle University Learning Community: https://education.oracle.com/ou-community LinkedIn: https://www.linkedin.com/showcase/oracle-university/ X: https://x.com/Oracle_Edu   Special thanks to Arijit Ghosh, David Wright, Kris-Ann Nansen, Radhika Banka, and the OU Studio Team for helping us create this episode.   --------------------------------------------------------------   Episode Transcript: 00:00 Welcome to the Oracle University Podcast, the first stop on your cloud journey. During this series of informative podcasts, we'll bring you foundational training on the most popular Oracle technologies. Let's get started! 00:25 Lois: Hello and welcome to the Oracle University Podcast! I'm Lois Houston, Director of Innovation Programs with Oracle University, and with me is Nikita Abraham, Team Lead: Editorial Services.  Nikita: Welcome, everyone! This is our fourth episode on Oracle GoldenGate 23ai. Last week, we discussed the terminology, different processes and what they do, and the architecture of the product at a high level. Today, we have Nick Wagner back with us to talk about the security strategies of GoldenGate. 00:56 Lois: As you know by now, Nick is a Senior Director of Product Management for GoldenGate at Oracle. He's played a key role as one of the product designers behind the latest version of GoldenGate. Hi Nick! Thank you for joining us again. Can you tell us how GoldenGate takes care of data security? Nick: So GoldenGate authentication and authorization is done in a couple of different ways. First, we have user credentials for GoldenGate for not only the source and target databases, but also for GoldenGate itself. We have integration with third-party identity management products, and everything that GoldenGate does can be secured. 01:32 Nikita: And we must have some access roles, right? Nick: There's four roles built into the GoldenGate product. You have your security role, administrator, operator, and user. They're all hierarchical. The most important one is the security user. This user is going to be the one that provides the administrative tasks. This user is able to actually create additional users and assign roles within the product. So do not lose this password and this user is extremely important. You probably don't want to use this security user as your everyday user. That would be your administrator. The administrator role is able to perform all administrative tasks within GoldenGate. So not only can they go in and create new extracts, create new replicats, create new distribution services, but they can also start and stop them. And that's where the operator role is and the user role. So the operator role allows you to go in and start/stop processes, but you can't create any new ones, which is kind of important. So this user would be the one that could go in and suspend activity. They could restart activity. But they can't actually add objects to replication. The user role is really a read-only role. They can come in. They can see what's going on. They can look at the log files. They can look at the alerts. They can look at all the watches and see exactly what GoldenGate is doing. But they're unable to make any changes to the product itself. 02:54 Lois: You mentioned the roles are hierarchical in nature. What does that mean? Nick: So anything that the user role does can be done by the operator. Anything that the operator and user roles can do can be done by the administrator. And anything that the user, operator, and administrator roles do can be done by the security role. 03:11 Lois: Ok. So, is there a single sign-on available for GoldenGate? Nick: We also have a password plugin for GoldenGate Connections. A lot of customers have asked for integration with whatever their single sign-on utility is, and so GoldenGate now has that with GoldenGate 23ai. So these are customer-created entities. So, we have some examples that you can use in our documentation on how to set up an identity provider or a third-party identity provider with GoldenGate. And this allows you to ensure that your corporate standards are met. As we started looking into this, as we started designing it, every single customer wanted something different. And so instead of trying to meet the needs for every customer and every possible combination of security credentials, we want you to be able to design it the way you need it. The passwords are never stored. They're only retrieved from the identity provider by the plugin itself. 04:05 Nikita: That's a pretty important security aspect…that when it's time to authenticate a user, we go to the identity provider. Nick: We're going to connect in and see if that password is matching. And only then do we use it. And as soon as we detect that it's matched, that password is removed. And then for the extract and replicats themselves, you can also use it for the database, data source, and data target connections, as well as for the GoldenGate users. So, it is a full-featured plugin. So, our identity provider plugin works with IAM as well as OAM. These are your standard identity manager authentication methods. The standard one is OAuth 2, as well as OIDC. And any Identity Manager that uses that is able to integrate with GoldenGate. 04:52 Lois: And how does this work? Nick: The way that it works is pretty straightforward. Once the user logs into the database, we're going to hand off authentication to the identity provider. Once the identity provider has validated that user's identity and their credentials, then it comes back to GoldenGate and says that user is able to log in to either GoldenGate or the application or the database. Once the user is logged in, we get that confirmation that's been sent out and they can continue working through GoldenGate. So, it's very straightforward on how it works. There's also a nice little UI that will help set up each additional user within those systems. All the communication is also secured as well. So any communication done through any of the GoldenGate services is encrypted using HTTPS. All the REST calls themselves are all done using HTTPS as well. All the data protection calls and all the communication across the network when we send data across a distribution service is encrypted using a secure WebSocket. And there's also trail file encryption at the operating system level for data at REST. So, this really gives you the full level of encryption for customers that need that high-end security. GoldenGate does have an option for FIPS 140-2 compliance as well. So that's even a further step for most of those customers. 06:12 Nikita: That's impressive! Because we want to maintain the highest security standards, right? Especially when dealing with sensitive information. I now want to move on to trail files. In our last episode, we briefly spoke about how they serve as logs that record and track changes made to data. But what more can you tell us about them, Nick? Nick: There's two different processes that write to the trail files. The extract process will write to the trail file and the receiver service will write to the trail file. The extract process is going to write to the trail file as it's pulling data out of that source database. Now, the extract process is controlled by a parameter file, that says, hey, here's the exact changes that I'm going to be pulling out. Here's the tables. Here's the rows that I want. As it's pulling that data out and writing it to the trail files, it's ensuring that those trail files have enough information so that the replicat process can actually construct a SQL statement and apply that change to that target platform. And so there's a lot of ways to change what's actually stored in those trail files and how it's handled. The trail files can also be used for initial loads. So when we do the initial load through GoldenGate, we can grab and write out the data for those tables, and that excludes the change data. So initial loads is pulling the data directly from the tables themselves, whereas ongoing replication is pulling it from the transaction logs. 07:38 Lois: But do we need to worry about rollbacks? Nick: Our trail files contain committed data only and all data is sequential. So this is two important things. Because it contains committed data only, we don't need to worry about rollbacks. We also don't need to worry about position within that trail file because we know all data is sequential. And so as we're reading through the trail file, we know that anything that's written in a prior location in that trial file was committed prior to something else. And as we get into the recovery aspects of GoldenGate, this will all make a lot more sense. 08:13 Lois: Before we do that, can you tell us about the naming of trail files? Nick: The trail files as far as naming, because these do reside on the operating system, you start with a two-letter trail file abbreviation and then a nine-digit sequential value. So, you almost look at it as like an archive log from Oracle, where we have a prefix and then an affix, which is numeric. Same kind of thing. So, we have our two-letter, in this case, an ab, and then we have a nine-digit number. 08:47 Transform the way you work with Oracle Database 23ai! This cutting-edge technology brings the power of AI directly to your data, making it easier to build powerful applications and manage critical workloads. Want to learn more about Database 23ai? Visit mylearn.oracle.com to pick from our range of courses and enroll today! 09:12 Nikita: Welcome back! Ok, Nick. Let's get into the GoldenGate recovery process. Nick: When we start looking at the GoldenGate recovery process, it essentially makes GoldenGate kind of point-in-time like. So on that source database, you have your extract process that's going to be capturing data from the transaction logs. In the case of Oracle, the Oracle Database is actually going to be reading those transaction logs from us and passing the change records directly to GoldenGate. We call them an LCR, Logical Change Record. And so the integrated extract and GoldenGate, the extract portion tells the database, hey, I'm now going to be interested in the following list of tables. And it gives a list of tables to that internal component, the log mining engine within the database. And it says, OK, I'm now pulling data for those tables and I'm going to send you those table changes. And so as the extract process gets sent those changes, it's going to have checkpoint information. So not only does it know where it was pulling data from out of that source database, but what it's also writing to the trail file. The trail files themselves are all sequential and they have only committed data, as we talked about earlier. The distribution service has checkpoint information that says, hey, I know where I'm reading from in the previous trail file, and I know what I've sent across the network. The receiver service is the same thing. It knows what it's receiving, as well as what it's written to the trail file and the target system. The replicat also has a checkpoint. It knows where it's reading from in the trail file, and then it knows what it's been applying into that target database.  This is where things start to become a little complicated. Our replicat process in most cases are parallel, so it'll have multiple threads applying data into that target database. Each of those threads is applying different transactions. And because of the way that the parallelism works in the replicat process, you can actually get situations where one replicat thread might be applying a transaction higher than another thread. And so you can eliminate that sequential or serial aspect of it, and we can get very high throughput speeds to the replicat. But it means that the checkpoint needs to be kind of smart enough to know how to rebuild itself if something fails. 11:32 Lois: Ok, sorry Nick, but can you go through that again? Maybe we can work backwards this time?  Nick: If the replicat process fails, when it comes back up, it's going to look to its checkpoint tables inside that target database. These checkpoint tables keep track of where each thread was at when it crashed. And so when the replicat process restarts, it goes, oh, I was applying these threads at this location in these SCNs. It'll then go and read from the trail file and say, hey, let me rebuild that data and it only applies transactions that it hasn't applied yet to that target system. There is a synchronized replicat command as well that will tell a crashed replicat to say, hey, bring all your threads up to the same high watermark. It does that process automatically as it restarts and continues normal replication. But there is an option to do it just by itself too. So that's how the replicat kind of repairs and recovers itself. It'll simply look at the trail files. Now, let's say that the replicat crashed, and it goes to read from the trail files when it restarts and that trail profile is missing. It'll actually communicate to the distribution, or excuse me, to the receiver service and say, hey, receiver service, I don't have this trail file. Can you bring it back for me? And the receiver service will communicate downstream and say, hey, distribution service, I need you to resend me trail find number 6. And so the distribution service will resend that trail file so that the replicat can reprocess it. So it's often nice to have redundant environments with GoldenGate so we can have those trail files kind of around for availability. 13:13 Nikita: What if one of these files gets corrupted? Nick: If one of those trail files is corrupt, let's say that a trail file on the target site became corrupt and the replicat can't read from it for one reason or another. Simply stop the replicat process, delete the corrupt trail file, restart the replicat process, and now it's going to rebuild that trail file from scratch based on the information from the source GoldenGate environment. And so it's very recoverable. Handles it all very well. 13:40 Nikita: And can the extract process bounce back in the same way? Nick: The extract process can also recover in a similar way. So if the extract process crashes, when it restarts itself, there's a number of things that it does. The first thing is it has to rebuild any open transactions. So it keeps all sorts of checkpoint information about the oldest transaction that it's keeping track of, any open transactions that haven't been committed, and any other transactions that have been committed that it's already written to the trail file. So as it's reprocessing that data, it knows exactly what it's committed to trail and what hasn't been committed. And there's a number of ways that it does this.  There's two main components here. One of them is called bounded recovery. Bounded recovery will allow you to set a time limit on transactions that span a certain length of time that they'll actually get flushed out to disk on that GoldenGate Hub. And that way it'll reduce the amount of time it takes GoldenGate to restart the extract process. And the other component is cache manager. Cache manager stores uncommitted transactions. And so it's a very elegant way of rebuilding itself from any kind of failure. You can also set up restart profiles so that if any process does crash, the GoldenGate service manager can automatically restart that service an x number of times across y time span. So if I say, hey, if my extract crashes, then attempt to restart it 100 times every 5 seconds. So there's a lot of things that you can do there to make it really nice and automatic repair itself and automatically resilient.  15:18 Lois: Well, that brings us to the end of this episode. Thank you, Nick, for going through the security strategies and recovery processes in such detail. Next week, we'll look at the installation of GoldenGate. Nikita: And if you want to learn more about the topics we discussed today, head over to mylearn.oracle.com and take a look at the Oracle GoldenGate 23ai Fundamentals course. Until next time, this is Nikita Abraham… Lois: And Lois Houston signing off! 15:44 That's all for this episode of the Oracle University Podcast. If you enjoyed listening, please click Subscribe to get all the latest episodes. We'd also love it if you would take a moment to rate and review us on your podcast app. See you again on the next episode of the Oracle University Podcast.

The Cloud Pod
293: Terraform Apply – Output Pizza

The Cloud Pod

Play Episode Listen Later Feb 26, 2025 69:53


Welcome to episode 293 of The Cloud Pod – where the forecast is always cloudy! This week we've got a lot of new and, surprise, a new installment of Cloud Journey AND and aftershow – so make sure to stay tuned for that! We've got undersea cables, Go 1.24, Wasm, Anthropic and more.  Titles we almost went with this week: Lets Go! Under Sea cables make AI go BRRRRRR The CloudPod says it will grow the listeners by 10x by 2027 A big thanks to this week's sponsor: We're sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You've come to the right place! Send us an email or hit us up on our slack channel for more info.  General News 01:30 Go 1.24 is released!  Go 1.24 has been released with a bunch of improvements!  Go now fully supports generic type aliases. It also includes several performance improvements to the runtime that have reduced CPU overhead by 2-3% on average across a suite of representative benchmarks. (Say that 5 times fast.) Tool improvements around tool dependencies for a module.  The standard library now includes new mechanisms to facilitate FIPS-140-3 compliance. And you know we love some good FIPS-140-3 compliance.  Lastly, it includes some improved WebAssembly support – which we'll talk about later.  04:46 Unlocking global AI potential with next-generation subsea infrastructure Meta announced their most ambitious subsea cable endeavor: Project Waterworth.  Once the cable is completed, the project will reach five major continents and span over 50,000 KM (longer than the earth’s circumference) making it the world’s longest subsea cable project using the highest-capacity technology available.  It will bring connectivity to the US, India, Brazil, South Africa, as well as other key regions.  Waterworth will be a multi-billion dollar, multi-year investment to strengthen the scale and reliability of the world's digital highways by opening three new oceanic corridors with the abundant, high-speed connectivity needed to drive AI innovation around the world. Meta has apparently developed 20 subsea cables over the last decade, including multiple deployments of industry leading subsea cables of 24 fiber pairs, compared to the typical 8 to 16 pairs of other new systems . They are also deploying a first of its kind routing system, maximizing the cable load in deep waters at depths up to 7,000 meters and using enhanced burial techniques in high-risk fault areas, such as shallow waters near the coast, to avoid damage from ship anchors and other hazards.  They wrap up the article by basically saying t

Feds At The Edge by FedInsider
Ep. 187 Using Security Intelligence to Protect Healthcare IT

Feds At The Edge by FedInsider

Play Episode Listen Later Feb 12, 2025 58:44


Protecting healthcare IT presents challenges that do not appear in other areas. Today, we examine three areas of concern: interoperability, unique aspects of the attack surface, and the impact of IoT devices. Medical records need to be transferred between hospitals and between medical systems. This provides tremendous flexibility, but it also has risks. Jennifer Franks from the GAO cites a recent report that showed an increase in medical cyber-attacks due to interconnection. She notes that personal information, like medical information, unlike other systems, does not change over time. As a result, legacy systems must be protected. Dr. Joe Ronzio notes the VA  controls over 170 hospitals; getting an inventory of all the medical devices is a significant challenge. Each time a medical device is upgraded or replaced, a process must start to understand the new threat environment that presents. Medical devices can be protected with encryption, but this is another system that is subject to upgrades. Dr. Joe Ronzio describes a situation in which he is upgrading an encryption system called FIPS 140 to a newer model. Gaps in that process can cause vulnerabilities.    

Root Causes: A PKI and Security Podcast
Root Causes 454: 2024 Lookback - Post quantum cryptography (PQC)

Root Causes: A PKI and Security Podcast

Play Episode Listen Later Jan 2, 2025 7:45


2024 was an eventful year for post quantum cryptography (PQC). This includes FIPS standards, the PQC onramp, and the dawn of widespread interest among IT professionals.

Cup o' Go

Cup o' Go

Play Episode Listen Later Nov 23, 2024 61:20 Transcription Available


This week Jonathan and Shay go deep into FIPS, cryptography, and security, and interview Alex Scheel about it as well!ProposalsGo moves toward FIPS-140

ITSPmagazine | Technology. Cybersecurity. Society
The 3-2-1 Rule for Cyber Resiliency | 7 Minutes on ITSPmagazine | An Apricon Short Brand Innovation Story with Kurt Markley

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Nov 21, 2024 7:03


Companies, organizations and governments have massive volumes of data, and the primary focus for its security is placed on that which is stored in the cloud, but many are not following best practices of taking the extra steps necessary to ensure their backed up data is secure, complete and uncorrupted. This story is to talk about using the 3-2-1 rule for cyber resiliency (keep three copies of data, on two different formats–both encrypted, one of which is stored off-site and offline) and discuss anecdotes of what can happen when cyber resilience plans are not put in place or followed.Data is the most important asset an organization has, whether it's a business, organization or a government. At the same time, the frequency of cyber attacks that compromise data are increasing. Ransomware continues to be a plague, with some reports showing more than 14 publicly claimed attacks daily for the first half of 2024. Having a plan to thwart cyberattack is only part of the strategy. Equally important is how to rapidly recover and restore operations after a ransomware disruption has occurred. Share anecdote about OVHcloud data center that burned down in 2021 with backups in it – all assets destroyed and websites down for days. also might be good to mention the latest ransomware attack on university of texas healthcare that is still not fully operational, 3 weeks after the attack and counting. it is unknown if they paid the ransom, but if they did and they're still not operational, that goes to show how unreliable the ransomed data is. Apricorn's own research shows that only half of U.S. respondents are conducting automatic backups to both a central repository AND a personal repository. Additionally, more than 25% of survey respondents were unable to recover all of their data successfullyIf attackers are successfully breaching data and holding it for ransom, organizations have to be able to recover complete backups of their data in order to a) avoid paying the ransom and b) assure the original data needed for restoration of operations is complete and intact, which statistics show, frequently is corrupted and incomplete when ransom is paid. One of the easiest and most effective ways to rapidly restore operations after a ransomware attempt is to keep multiple copies of integrity-checked data so you can fully recover it if it's compromised. The 3-2-1 rule is a proven cyber resilience best practice. The 3-2-1 rule calls for keeping at least three copies of your data on two different types of media, with one being encrypted and offsite. This is where Apricorn comes into play - we make the highest grade, portable data encryption products on the market. Our products are security focused - 100% software free, FIPS certified, non-Chinese chips and so many unique features such as admin AND user forced enrollment, programmable PIN lengths, brute force defense, self destruct PINS and more.Learn more about Apricorn: https://itspm.ag/apricomebvNote: This story contains promotional content. Learn more.Guest: Kurt Markley, Managing Director, America's, Apricorn [@apricorn_info]On LinkedIn | https://www.linkedin.com/in/kurt-markley-1596054/ResourcesSecuring Data with Hardware Encrypted USB Drives: https://itspm.ag/apricoy0dmLearn more and catch more stories from Apricorn: https://www.itspmagazine.com/directory/apricornLearn more about 7 Minutes on ITSPmagazine Short Brand Story Podcasts: https://www.itspmagazine.com/purchase-programsNewsletter Archive: https://www.linkedin.com/newsletters/tune-into-the-latest-podcasts-7109347022809309184/Business Newsletter Signup: https://www.itspmagazine.com/itspmagazine-business-updates-sign-upAre you interested in telling your story?https://www.itspmagazine.com/telling-your-story

Access Control
Governing the Future: Federal Cybersecurity in the Age of Edge and AI

Access Control

Play Episode Listen Later Oct 22, 2024 40:35 Transcription Available


In this episode, Intel Federal CTO Steve Orrin discusses securing edge devices, enabling trusted AI, and navigating cybersecurity challenges in the public sector. Discover strategies for protecting sensitive data, complying with regulations, and ensuring the trustworthiness of cutting-edge technologies critical to government missions.

Charis Christian Center Podcast
Special Guest Rich Fips

Charis Christian Center Podcast

Play Episode Listen Later Oct 20, 2024 33:01


Join Rich Fips as he shares his teaching. The post Special Guest Rich Fips appeared first on Charis Christian Center.

Root Causes: A PKI and Security Podcast
Root Causes 415: What Can I Do with These New FIPS PQC Standards?

Root Causes: A PKI and Security Podcast

Play Episode Listen Later Aug 27, 2024 19:33


NIST recently released PQC algorithmic standards in FIPS-203, FIPS-204, and FIPS-205 (ML-KEM, ML-DSA, and SLH-DSA). We describe what is necessary for enterprises to begin using these algorithms.

The Azure Podcast
Episode 503 - Secure Future Initiative

The Azure Podcast

Play Episode Listen Later Aug 21, 2024


In this episode of the Azure Podcast, Cale, Evan, and Sujit engage in a comprehensive discussion about the Secure Future Initiative at Microsoft. They explore how this initiative influences our use of Azure and why it's beneficial for customers to consider implementing similar strategies in their own Azure environments.   Media file: https://azpodcast.blob.core.windows.net/episodes/Episode503.mp3 YouTube: https://youtu.be/TyvkKhdRR5k Resources: https://www.microsoft.com/en/microsoft-cloud/resources/secure-future-initiative#tabx6a6ce2c0327741938ac10b008d5cff64 https://learn.microsoft.com/en-us/azure/well-architected/security/design-patterns SFI Updates   Other resources: https://azure.microsoft.com/en-us/updates/v2/Volume-enhancements https://azure.microsoft.com/en-us/updates/v2/Dedicated-log-analytics-tables-in-Application-Gateway https://azure.microsoft.com/en-us/updates/v2/ANF-Double-Encryption-at-rest https://azure.microsoft.com/en-us/updates/v2/FIPS-mutability-support-in-AKS https://azure.microsoft.com/en-us/updates/v2/CNI-Powered-by-Cilium-Azure-CNI-Overlay-support-AKS https://azure.microsoft.com/en-us/updates/v2/New-features-in-AKS-extension-for-Visual-Studio-Code https://azure.microsoft.com/en-us/updates/v2/Enable-multifactor-authentication-for-your-tenant-by-15-October-2024  (also below) https://azure.microsoft.com/en-us/updates/v2/generally-available-azure-chaos-studio-supports-a-new-network-isolation-fault-for-virtual-machines https://azure.microsoft.com/en-us/updates/v2/High-Scale-mode-Container-Insights

The Daily Decrypt - Cyber News and Discussions
Key Takeaways from the Ticketmaster breach and Amazon re:Inforce in Philadelphia

The Daily Decrypt - Cyber News and Discussions

Play Episode Listen Later Jun 13, 2024


In today's episode, we explore recent major cybersecurity upgrades aimed at safeguarding the American healthcare system, including a new initiative by Microsoft to provide critical cybersecurity resources to rural hospitals. Additionally, we delve into the Ticketmaster-Snowflake data breach perpetrated by ShinyHunters, targeting 560 million users and exposing key vulnerabilities in cloud environments. Lastly, we cover AWS's new and improved security features announced at the re:Inforce conference, which include added multi-factor authentication options, expanded malware protection for Amazon S3, and updated AI apps governance. Read more at: https://www.helpnetsecurity.com/2024/06/12/american-healthcare-cybersecurity/ https://thehackernews.com/2024/06/lessons-from-ticketmaster-snowflake.html https://www.helpnetsecurity.com/2024/06/12/aws-security-features/ Thanks to Jered Jones for providing the music for this episode. https://www.jeredjones.com/ Logo Design by https://www.zackgraber.com/ Tags Microsoft, Cyberattacks, Healthcare systems, Rural hospitals, ShinyHunters, Breach, Data, Cybersecurity, AWS, FIDO2 passkeys, Malware protection, Cloud environment Search Phrases How Microsoft is protecting rural hospitals from cyberattacks Cybersecurity initiatives for rural healthcare by Microsoft ShinyHunters data breach impact on cloud security Essential measures to prevent cyberattacks in cloud environments Latest AWS security features from re:Inforce conference How FIDO2 passkeys enhance cloud environment security Updated malware protection for AWS S3 buckets Microsoft and Biden-Harris Administration cybersecurity efforts Impact of ShinyHunters breach on data security practices Advanced multi-factor authentication in AWS cloud environments Major cybersecurity upgrades announced to safeguard American healthcare https://www.helpnetsecurity.com/2024/06/12/american-healthcare-cybersecurity/ Rising Threats: Cyberattacks on American healthcare systems soared 128% from 2022 to 2023, leading to significant disruptions in hospital operations and payment systems. Actionable Insight: Healthcare professionals should stay vigilant and ensure their organizations have updated cybersecurity measures to mitigate risks. Impact of Recent Attacks: In early 2024, a major cyberattack affected one-third of healthcare claims in the U.S., delaying payments and services. Critical Implication: Entry to mid-level cybersecurity professionals should focus on protecting payment systems and ensuring quick recovery plans are in place. Government Initiatives: The Biden-Harris Administration launched several initiatives to bolster healthcare cybersecurity, including a new gateway website and voluntary performance goals. Actionable Insight: Healthcare institutions should leverage these resources to enhance their cybersecurity posture. Collaboration for Solutions: In May 2024, the White House gathered industry leaders to discuss cybersecurity challenges and promote secure-by-design solutions. Engagement Suggestion: Ask listeners how their organizations collaborate with other entities to share threat intelligence and improve security. ARPA-H UPGRADE Program: The Advanced Research Projects Agency for Health introduced the UPGRADE program, investing over $50 million in tools to defend hospital IT environments. Actionable Insight: IT teams should explore participation in this program to access cutting-edge cybersecurity tools and support. Rural Hospital Support: Cyber disruptions severely impact rural hospitals. Leading tech companies, including Microsoft and Google, committed to providing free or discounted cybersecurity resources to these institutions. Critical Implication: Rural hospital IT staff should take advantage of these offers to strengthen their defenses against cyberattacks. Microsoft's Cybersecurity Program: Microsoft announced a program offering up to 75% discounts on security products, free cybersecurity assessments, and training for rural hospitals. Actionable Insight: Rural healthcare providers should engage with Microsoft's program to improve their cybersecurity measures and resilience. Google's Contributions: Google will offer endpoint security advice and discounted communication tools to rural hospitals, along with a pilot program to tailor security solutions to their needs. Engagement Suggestion: Prompt listeners to consider what specific cybersecurity challenges their rural hospitals face and how these new initiatives could assist them. Continued Efforts: The White House and industry leaders emphasize the importance of private-public partnerships to ensure the security and functionality of healthcare systems nationwide. Efficiency Tip: Cybersecurity professionals should stay informed about these partnerships and actively participate to benefit from shared knowledge and resources. Lessons from the Ticketmaster-Snowflake Breach https://thehackernews.com/2024/06/lessons-from-ticketmaster-snowflake.html ShinyHunters Breach: Last week, hacker group ShinyHunters allegedly stole 1.3 terabytes of data from 560 million Ticketmaster users. The breach could expose massive amounts of personal data and has sparked significant concern. Listener Question: How can we ensure our data is safe with such large-scale breaches happening? Actionable Insight: Regularly update passwords and enable multi-factor authentication (MFA) on all accounts. Live Nation Confirms Breach: Live Nation confirmed the breach in an SEC filing, stating unauthorized activity occurred in a third-party cloud database. An investigation is ongoing, and law enforcement is involved. Listener Question: What steps should companies take immediately after discovering a breach? Actionable Insight: Initiate a comprehensive investigation, notify affected parties, and work with law enforcement. Santander Also Affected: ShinyHunters claim to have data from Santander, affecting millions of customers and employees in Chile, Spain, and Uruguay. The breach involved a third-party provider. Listener Question: Should we be worried about third-party services? Actionable Insight: Ensure third-party services adhere to stringent security protocols and regularly review their security measures. Snowflake Connection: Both Ticketmaster and Santander used Snowflake for their cloud databases. Snowflake warned of increased cyber threats targeting customer accounts, urging users to review logs for unusual activity. Listener Question: What can companies do to safeguard their cloud data? Actionable Insight: Enforce MFA, set network policies to limit access, and regularly rotate credentials. Snowflake's Response: Snowflake's CISO clarified their system wasn't breached; single-factor authentication vulnerabilities were exploited. They recommend MFA and network policy rules for enhanced security. Mitiga's Research: Mitiga found the attacks exploited environments without two-factor authentication, primarily using commercial VPN IPs to execute attacks. Listener Question: How can we protect against these types of attacks? Actionable Insight: Implement and enforce MFA, utilize corporate SSO, and regularly monitor for unusual login activity. Cloud Security Challenges: Modern cloud environments limit some security controls. Ensure platforms offer APIs for privileged identity management and integrate with corporate security. Listener Question: What should we look for in a cloud service provider? Actionable Insight: Choose providers that support MFA, SSO, password rotation, and centralized logging. Non-Human Identities: Protecting non-human identities like service accounts is challenging but necessary. Snowflake provides guidance on securing these accounts. Listener Question: How do we secure non-human identities? Actionable Insight: Use strong, unique passwords and rotate credentials frequently for service accounts. Cost of Cyber Attacks: Cybercriminals aim to maximize profit through mass, automated attacks like credential stuffing. Simple security measures can make these attacks less feasible. Listener Question: What simple measures can we take to protect against cyber attacks? Actionable Insight: Implement SSO, MFA, and regular password rotation to increase the cost and complexity for attackers. Remember, these insights are not just theoretical—they can help you strengthen your organization's security posture today!` AWS unveils new and improved security features https://www.helpnetsecurity.com/2024/06/12/aws-security-features/ Key Information and Actionable Insights Multi-Factor Authentication (MFA) Upgrades: New Option: AWS introduces support for FIDO2 passkeys as an additional MFA method. Security Assurance: FIDO2 security keys offer the highest level of security, ideal for environments with stringent regulatory requirements (FIPS-certified devices). Considerations: Evaluate passkey providers' security models, especially for access and recovery. Enhanced Access Management: IAM Access Analyzer Update: Now assists in identifying and removing unused roles, access keys, and passwords. Permissions Management: Helps set, verify, and refine unused permissions to maintain a streamlined and secure access environment. Malware Protection for Amazon S3: GuardDuty Expansion: Now detects malicious file uploads in S3 buckets. Configuration Options: Teams can set up post-scan actions like object tagging or use Amazon EventBridge to manage malware isolation processes. AI Apps Governance: Audit Manager Update: New AI best practice framework simplifies evidence collection and ongoing compliance audits. Standard Controls: Includes 110 pre-configured controls organized under domains such as accuracy, fairness, privacy, resilience, responsibility, safety, security, and sustainability. Additional Improvements: Log Analysis: Simplified through natural language queries that produce SQL queries (currently in preview). Network Services Integration: Streamlined process for incorporating firewalls, IDS/IPS, and other network services into customers' WANs.

Speak Up For The Ocean Blue
The Alliance for Seafood Solutions: Promoting Sustainability and Social Responsibility

Speak Up For The Ocean Blue

Play Episode Listen Later May 17, 2024 63:55


This episode features Ryan Bigelow, the Director of Projects for the Conservation Alliance for Seafood Solutions. He discusses the seafood industry, the alliance's role, and the importance of conservation. From consumer to industry perspectives, the conversation delves into the challenges of sustainable seafood practices. Tune in to learn about the Seafood Watch program and how to make informed seafood choices for a better ocean. Website: https://solutionsforseafood.org/ The Conservation Alliance for Seafood Solutions is dedicated to improving sustainability in the seafood industry by fostering collaboration between NGOs and businesses. With approximately 150 members from 22 countries worldwide, the Alliance works towards enhancing the sustainability of seafood. It serves as a platform for experts from various organizations to address key topics such as improving fisheries, social responsibility in seafood, and advancing sustainability efforts. One of the primary functions of the Alliance is to provide guidance and resources for businesses seeking to enhance their sustainability practices in the seafood industry. By closely collaborating with NGOs and businesses, the Alliance aims to ensure all stakeholders are aligned in promoting sustainable seafood practices. The organization also facilitates discussions, collaborations, and the sharing of best practices to drive positive change within the industry. Through initiatives like Fishery Improvement Projects (FIPs), the Alliance supports fisheries in their journey towards sustainability by setting goals and timelines for improvement. Additionally, the Alliance places a strong emphasis on social responsibility within the seafood industry, addressing issues such as human rights violations, unsafe working conditions, and gender inequity. By integrating social responsibility considerations into sustainability efforts, the Alliance recognizes the interconnected nature of environmental and social issues within the seafood supply chain. The Conservation Alliance for Seafood Solutions plays a crucial role in promoting sustainability and responsible practices in the seafood industry by fostering collaboration, providing guidance, and advocating for the integration of social responsibility principles into sustainability initiatives. The Alliance for Seafood Solutions, led by Director of Projects Ryan Bigelow, provides essential guidance on various seafood industry topics, with a focus on sustainable seafood practices. Working with a diverse group of NGOs and businesses, the Alliance aims to improve global sustainability standards. This guidance is vital for businesses looking to enhance their sustainability efforts and align with industry standards. Additionally, the Alliance actively supports fishery improvement projects (FIPs) to address environmental and social issues within fisheries, such as overfishing. By providing guidance on participating in FIPs, the Alliance helps fisheries progress towards sustainable practices. Another significant aspect of the Alliance's work is addressing social responsibility in fisheries, including human rights violations and unsafe working conditions. The Alliance emphasizes integrating social responsibility into seafood sustainability efforts to ensure these issues are addressed alongside environmental concerns. The Alliance collaborates with industry stakeholders, NGOs, and experts to develop comprehensive guidance documents that address the complex challenges faced by the seafood industry. By bringing together diverse perspectives and expertise, the Alliance promotes responsible and ethical practices in the seafood supply chain. Building trust with industry partners is a crucial aspect of the Alliance's work. By collaborating with businesses in the seafood industry, the Alliance promotes sustainability and addresses social responsibility issues. Active listening, collaboration, and providing valuable resources without immediate financial expectations are key strategies to build trust and engage effectively with industry partners towards shared goals.

The Evolution of Confidence
Why I left med sales, commercial real estate + living through house fips

The Evolution of Confidence

Play Episode Listen Later May 10, 2024 27:22


Live Q&A episode. Learn why I left med sales, the current state of commercial real estate, living through house flips and how to make money in today's market. Marijuliette.com 954 326 4476 --- Send in a voice message: https://podcasters.spotify.com/pod/show/marijuliette/message