Please enable JavaScript to use this page!

AllTalks site logo
πŸ”

Provable access control: Know who can access your AWS resources

The AWS Automated Reasoning Group focuses on strengthening the security foundations of AWS and provides customers with tools to verify their own security posture. In this session, we discuss the evolution of automated reasoning technology at AWS and how it works in the services in which it is embedded, including Amazon Simple Storage Service (Amazon S3), AWS Config, and Amazon Macie. Learn what's ahead for automated reasoning at AWS and the customer problems it continues to solve in the security and broader cloud space.


AWS re:Invent

59 min

Security best practices for the Amazon EC2 instance metadata service

Mark Ryland

The Amazon EC2 instance metadata service (IMDS) provides a rich set of relevant data to software on that instance. The IMDS ability to perform introspection about the runtime environment, as well as …

YaTalks

28 min

DDoS-Π°Ρ‚Π°ΠΊΠ° MΔ“ris ΠΈ ΠΊΠ°ΠΊ ЯндСкс Π΅Ρ‘ ΠΏΠ΅Ρ€Π΅ΠΆΠΈΠ»

Π”ΠΌΠΈΡ‚Ρ€ΠΈΠΉ Носов

ΠšΠ°ΠΆΠ΅Ρ‚ΡΡ, Ρ‡Ρ‚ΠΎ ΡƒΠΆΠ΅ всС ΡΠ»Ρ‹ΡˆΠ°Π»ΠΈ ΠΎ самой ΠΌΠ°ΡΡˆΡ‚Π°Π±Π½ΠΎΠΉ DDoS-Π°Ρ‚Π°ΠΊΠ΅ Π² истории ΠΈΠ½Ρ‚Π΅Ρ€Π½Π΅Ρ‚Π° β€” MΔ“ris. ΠžΡ‡Π΅Π½ΡŒ ΠΌΠ½ΠΎΠ³ΠΎΠ΅ Π² этой истории ΠΏΠΎΠΊΠ° Π΅Ρ‰Ρ‘ ΠΏΡ€ΠΎΡ…ΠΎΠ΄ΠΈΡ‚ Β«ΠΏΠΎΠ΄ Π³Ρ€ΠΈΡ„ΠΎΠΌ сСкрСтно». Но сСйчас ΠΌΡ‹ Π³ΠΎΡ‚ΠΎΠ²Ρ‹ ΠΏΠΎΠ΄Π΅Π»ΠΈΡ‚ΡŒΡΡ большой час…

YaTalks

29 min

ГСномная паспортизация россиян Π² Ρ€Π΅ΠΆΠΈΠΌΠ΅ экспонСнты с Ρ‚ΠΎΡ‡ΠΊΠΈ зрСния бэкСнда

Π’Π»Π°Π΄ΠΈΠΌΠΈΡ€ ГусСв

Genotek Π±Ρ‹Π» создан Π² 2010 Π³ΠΎΠ΄Ρƒ, Ρ‡Ρ‚ΠΎΠ±Ρ‹ ΠΏΡ€Π΅Π΄ΠΎΡΡ‚Π°Π²ΠΈΡ‚ΡŒ Ρ‡Π΅Π»ΠΎΠ²Π΅ΠΊΡƒ Π³Π΅Π½Π΅Ρ‚ΠΈΡ‡Π΅ΡΠΊΡƒΡŽ ΠΈΠ½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΡŽ ΠΎ Π΅Π³ΠΎ Π·Π΄ΠΎΡ€ΠΎΠ²ΡŒΠ΅, мСдицинских рисках, способностях ΠΈ Π³Π΅Π½Π΅Π°Π»ΠΎΠ³ΠΈΠΈ, ΠΈ ΡΠ΄Π΅Π»Π°Ρ‚ΡŒ ΠΏΠ΅Ρ€ΡΠΎΠ½ΠΈΡ„ΠΈΡ†ΠΈΡ€ΠΎΠ²Π°Π½Π½ΡƒΡŽ ΠΌΠ΅Π΄ΠΈΡ†ΠΈΠ½Ρƒ доступной для…

ITeaConf

32 min

ΠœΠΎΠ½ΠΎΠ»ΠΈΡ‚ -> микросСрвис -> ?

АндрСй ΠœΠ΅Π»ΠΈΡ…ΠΎΠ²

Разбивая наш JavaScript-ΠΌΠΎΠ½ΠΎΠ»ΠΈΡ‚ (ΠΊΡƒΠ΄Π° Π±Π΅Π· Π½Π΅Π³ΠΎ) ΠΌΡ‹ ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΈ Osome Π΄Π²ΠΈΠ½ΡƒΠ»ΠΈΡΡŒ дальшС микросСрвисов ΠΈ сразу ΠΏΠ΅Ρ€Π΅Π²Π΅Π·Π»ΠΈ всё Π½Π° Ρ„ΡƒΠ½ΠΊΡ†ΠΈΠΈ, ΠΎΡ‚ΠΊΠ°Π·Π°Π²ΡˆΠΈΡΡŒ ΠΎΡ‚ Koa, Express, Nest ΠΈΠ»ΠΈ ΠΈΠ½Ρ‹Ρ… Ρ€Π΅ΡˆΠ΅Π½ΠΈΠΉ. Нашим Π½ΠΎΠ²Ρ‹ΠΌ фрСй…

NDC DevOps

59 min

It's A Trap!

Sam Newman

The growth of the public cloud market is obvious to everyone. But what’s less well known is that enterprises are still growing the infrastructure and services they run for themselves. A host of reaso…

NDC DevOps

58 min

Top Secret Cloud Native Security Lessons

Ben Hall

Cloud native technologies such as Kubernetes, Docker, Istio and more are becoming the foundations of software development and infrastructure deployments. With these new technologies, a new set of les…

JSConf Budapest

23 min

StrangerDanger: Finding Security Vulnerabilities Before They Find You!

Liran Tal

Open source modules on the NPM ecosystem are undoubtedly awesome. However, they also represent an undeniable and massive risk. You’re introducing someone else’s code into your system, often with litt…

YaTalks

62 min

99,99: Ρ‡Ρ‚ΠΎ ΡΠ΄Π΅Π»Π°Ρ‚ΡŒ, Ρ‡Ρ‚ΠΎΠ±Ρ‹ ваш сСрвис стал Π½Π°Π΄Ρ‘ΠΆΠ½Ρ‹ΠΌ

Π”ΠΌΠΈΡ‚Ρ€ΠΈΠΉ Носов, Π•Π²Π³Π΅Π½ΠΈΠΉ Росинский, АлСксандр АфСнов, НарСк ВатСвосян

ΠŸΠΎΠ³ΠΎΠ²ΠΎΡ€ΠΈΠΌ ΠΎ космичСской ΡΡ‚Π°Π±ΠΈΠ»ΡŒΠ½ΠΎΡΡ‚ΠΈ ΠΈ отказоустойчивости. БСрвисы со ΡΡ‚Π°Π±ΠΈΠ»ΡŒΠ½ΠΎΡΡ‚ΡŒΡŽ 99.99. Π’ΠΎΠ·ΠΌΠΎΠΆΠ½ΠΎ Π»ΠΈ это? Если Π΄Π°, Ρ‚ΠΎ ΠΊΠ°ΠΊ это Ρ€Π΅Π°Π»ΠΈΠ·ΠΎΠ²Π°Π½ΠΎ Π² Ρ€Π°Π·Π½Ρ‹Ρ… компаниях. Нас с Π²Π°ΠΌΠΈ ΠΆΠ΄Ρ‘Ρ‚ дискуссия ΠΎ Ρ‚ΠΎΠΌ: Как …

DotNext

49 min

Deserialization vulns: past, present, and future

ΠœΠΈΡ…Π°ΠΈΠ» Π©Π΅Ρ€Π±Π°ΠΊΠΎΠ²

ЭкспСрт ΠΈΠ· ΠΌΠΈΡ€Π° security вновь расскаТСт, ΠΊΠ°ΠΊ Ρ‚Π°ΠΌ опасно ΠΈ Ρ‡Ρ‚ΠΎ с этим Π΄Π΅Π»Π°Ρ‚ΡŒ. Уязвимости Π² процСссС дСсСриализации Π½Π΅Π΄ΠΎΠ²Π΅Ρ€Π΅Π½Π½Ρ‹Ρ… Π΄Π°Π½Π½Ρ‹Ρ… извСстны Π±ΠΎΠ»Π΅Π΅ 10 Π»Π΅Ρ‚, Π²ΠΊΠ»ΡŽΡ‡Π΅Π½Ρ‹ Π² OWASP Top 10 ΠΈ Π·Π° послСдниС н…

TechTrain

67 min

Π­Π²ΠΎΠ»ΡŽΡ†ΠΈΡ способов сохранСния ΠΊΠΎΠ½Ρ„ΠΈΠ΄Π΅Π½Ρ†ΠΈΠ°Π»ΡŒΠ½ΠΎΠΉ ΠΈΠ½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΠΈ Π² сСкрСтС

АлСксандра Калинина

ΠšΠ°ΠΆΠ΄Ρ‹ΠΉ программист Π² своСй ΠΆΠΈΠ·Π½ΠΈ встрСчаСтся с ΠΈΠ½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΠ΅ΠΉ, ΠΊΠΎΡ‚ΠΎΡ€ΡƒΡŽ Π½Π΅ΠΎΠ±Ρ…ΠΎΠ΄ΠΈΠΌΠΎ Π΄Π΅Ρ€ΠΆΠ°Ρ‚ΡŒ Π² сСкрСтС: ΠΏΠ°Ρ€ΠΎΠ»ΠΈ ΠΊ ΡƒΡ‡Π΅Ρ‚ΠΊΠ°ΠΌ, сСкрСтныС ΠΊΠ»ΡŽΡ‡ΠΈ доступа, CVV ΠΊΠΎΠ΄ ΠΎΡ‚ ΠΊΠ°Ρ€Ρ‚ΠΎΡ‡ΠΊΠΈ, Π² ΠΊΠΎΠ½Ρ†Π΅ ΠΊΠΎΠ½Ρ†ΠΎΠ². Однако Π½Π΅ ΠΊΠ°ΠΆΠ΄Ρ‹ΠΉ сраз…

AWS re:Invent

56 min

National Australia Bank: Automating governance in Financial Services

Christopher Miras, Yuri Belenky

National Australia Bank (NAB) is migrating hundreds of sensitive, regulated financial workloads to the cloud. This session focuses on the automated approach that NAB has taken to evolve and scale its…

MinskJS

20 min

БСзопасный input. Π‘Π±ΠΎΡ€ Π΄Π°Π½Π½Ρ‹Ρ… пластиковой ΠΊΠ°Ρ€Ρ‚Ρ‹ Π² iframe

Π­Π΄ΡƒΠ°Ρ€Π΄ Π’ΠΈΡ‚ΠΎΠ²

Β«Π”ΠΎΠΊΠ»Π°Π΄ ΠΎΠ± отрисовкС Ρ„ΠΎΡ€ΠΌΡ‹ Π² iframeΒ», β€” скаТСтС Π²Ρ‹. И Π΄Π°, ΠΈ Π½Π΅Ρ‚. Π‘ΡƒΠ΄Π΅Ρ‚ Π½Π΅ Ρ‚ΠΎΠ»ΡŒΠΊΠΎ Ρ„ΠΎΡ€ΠΌΠ°, Π΄Π° ΠΈ iframe Π±ΡƒΠ΄Π΅Ρ‚ Π½Π΅ ΠΎΠ΄ΠΈΠ½, ΠΏΠΎΡΠΊΠΎΠ»ΡŒΠΊΡƒ ΠΎΡ‚Ρ€ΠΈΡΠΎΠ²Π°Ρ‚ΡŒ Ρ„ΠΎΡ€ΠΌΡƒ β€” это Π΄Π°Π»Π΅ΠΊΠΎ Π½Π΅ всё. Π’Ρ‹ ΡƒΠ·Π½Π°Π΅Ρ‚Π΅, Ρ‡Ρ‚ΠΎ Π½ΡƒΠΆΠ½ΠΎ ΡΠ΄Π΅Π»Π°Ρ‚ΡŒ для бС…

swampUP

25 min

Lesson Learned From Cloud Migrations: Planning is Everything

Chris Short

β€œMigrating to the cloud saves money!” β€œNot running your own infrastructure reduces your bottom line!” β€œLift and shift is a legitimate first step towards moving to the cloud!” These are all potential …