SlideShare a Scribd company logo
Why We Can’t Have Nice Things
A Tale of Woe, and Hope for the Future
Pete Cheslock
@petecheslock
@petecheslock
@petecheslock
WallofConfusion
Dev Ops
Sec
@petecheslock
@petecheslock
DevOps
Sec
@hijinksensue
@petecheslock
@petecheslock
Pete Cheslock
Not an InfoSec
Twitters: @petecheslock
theshipshow.com
threatstack.com
– President Josiah Bartlet
"The most costly
disruptions always
happen when
something we take
completely for
granted stops
working for a
minute."
@petecheslock
@petecheslock
@petecheslock
@petecheslock
@petecheslock
@petecheslock
@petecheslock
@petecheslock
@petecheslock
@petecheslock
It’s time that we recognize that all
these new tools which are helping to
enable our teams to work so well are
also introducing new attack vectors.
@petecheslock
risk = (threat) x (probability)
x (business impact)
http://sysadvent.blogspot.com/2014/12/day-24-12-days-of-secdevops.html
- Jen Andre
@petecheslock
What data are you sending?
What happens if that system
is compromised?
@petecheslock
WE TAKE SECURITY
SERIOUSLY
http://blog.b3k.us/2012/01/24/some-rules.html
“These are not features: Security, Availability, Performance.”
- Benjamin Black
@petecheslock
@petecheslock
@petecheslock
@petecheslock
https://github.com/codahale/sneaker

https://vaultproject.io

https://github.com/square/keywhiz

https://github.com/LuminalOSS/credstash

https://github.com/oleiade/trousseau - Storing sensitive data

https://github.com/cloudflare/redoctober - High value secrets

https://github.com/jschauma/jass - really helpful tool for sharing of
secrets using SSH keys.
@petecheslock
@petecheslock
@petecheslock
Keep It Simple
Skip the ITIL IR Plan for now
Why We Can't Have Nice Things, A Tale of Woe and a Hope For the Future
@petecheslock
@petecheslock
@petecheslock
@petecheslock
@petecheslock
“FWIW, I have most of a sub-key implementation done, but that
still won’t solve your problem, as it will be years before that
implementation is widely deployed…”
@petecheslock
Compile your Source
Build a Package
Sign the Package
Test the Package
Deploy the Package
You can’t hate the curl bash and be OK deploying from Github
@petecheslock
aptly
deb-s3
freight/sync to s3
packagecloud.io
@petecheslock
@petecheslock
@petecheslock
@petecheslock
https://www.ssllabs.com/ssltest/
@petecheslock
@petecheslock
Safe Access to Production
@petecheslock
– Mark Burgess
“Every time someone logs onto a system
interactively, they compromise everyone's
knowledge of that system”
@petecheslock
Trust, but Verify.
@petecheslock
auditd + OSSEC
…and SELinux
http://stopdisablingselinux.com/
@petecheslock
Controlled Access Protection Profile
http://www.commoncriteriaportal.org/files/ppfiles/capp.pdf
Labeled Security Protection Profile
http://www.commoncriteriaportal.org/files/ppfiles/lspp.pdf
National Industrial Security Program Operating Manual (NISPOM)
http://www.fas.org/sgp/library/nispom.htm
Security Technical Implementation Guides
http://iase.disa.mil/stigs/Pages/index.aspx
Why We Can't Have Nice Things, A Tale of Woe and a Hope For the Future
@petecheslock
@petecheslock
@petecheslock
Start Small
Identify High Risks
@petecheslock
Security Culture is People
@petecheslock
@petecheslock

More Related Content

PDF
Everyone has a plan until... Automacon16
PPTX
DevOpsDays PGH: How to Fail With One Weird Trick
PDF
Mere Paas Teensy Hai (Nikhil Mittal)
PDF
Risk of Solutionism in the IoT is squared to Solutionism in Web
PDF
Beyond copy paste with System Science and Sapiens
PDF
Programmer's Bookshelf - Remote Edition
PDF
How To Run a 5 Whys (With Humans, Not Robots)
PDF
7 Ways to Make Good Teams Great
Everyone has a plan until... Automacon16
DevOpsDays PGH: How to Fail With One Weird Trick
Mere Paas Teensy Hai (Nikhil Mittal)
Risk of Solutionism in the IoT is squared to Solutionism in Web
Beyond copy paste with System Science and Sapiens
Programmer's Bookshelf - Remote Edition
How To Run a 5 Whys (With Humans, Not Robots)
7 Ways to Make Good Teams Great

Viewers also liked (20)

PPT
The Future of Digital Textbooks, Tools of Change, 2010
PDF
Mane wk8 term 1 13pdf
PDF
Wenerei wk 2 term 3 13
PDF
Taite wk 2 term 3 13 pdf
PDF
Mane wk 10 term 2 2013
PDF
Mane wk 10 term 2 2013pdf
PDF
Taite wk 9 term 2 13
PDF
Wenerei wk 10 term 2 2013 pdf
PDF
Paraere wk 7 term 2 pdf
PPT
Valentine's day 1
PDF
Turei wk 7 term 2
PDF
Wenerei wk 10 term 2 2013 pdf1
PDF
Everything obfuscurity taught me about monitoring
PDF
Mane wk 4 term 2
PDF
Mane wk 7 term 2
DOCX
DOC
Rev.u.3
PPTX
ANZ Law Seminar _Law resources overview V2
The Future of Digital Textbooks, Tools of Change, 2010
Mane wk8 term 1 13pdf
Wenerei wk 2 term 3 13
Taite wk 2 term 3 13 pdf
Mane wk 10 term 2 2013
Mane wk 10 term 2 2013pdf
Taite wk 9 term 2 13
Wenerei wk 10 term 2 2013 pdf
Paraere wk 7 term 2 pdf
Valentine's day 1
Turei wk 7 term 2
Wenerei wk 10 term 2 2013 pdf1
Everything obfuscurity taught me about monitoring
Mane wk 4 term 2
Mane wk 7 term 2
Rev.u.3
ANZ Law Seminar _Law resources overview V2
Ad

Similar to Why We Can't Have Nice Things, A Tale of Woe and a Hope For the Future (20)

PDF
Make it Fixable (CppCon 2018)
PDF
Make It Fixable (Sikkert NOK 2017)
PDF
Make it Fixable, Living with Risk (Paranoia 2017)
PDF
You Give Us The Fire We'll Give'em Hell!
PDF
Make It Fixable, Living with Risk (NDC London 2018)
PDF
DevSecOps for Developers, How To Start (ETC 2020)
PDF
Deja vu security Adam Cecchetti - Security is a Snapshot in Time BSidesPDX ...
PDF
Make it Fixable (NDC Copenhagen 2018)
PDF
The Future of DevSecOps
PPTX
2024 Security Outlook & Essential Security Practices
PPTX
Community IT Webinar - IT Security for Nonprofits
PPTX
Open Source Insight: You Can’t Beat Hackers and the Pentagon Moves into Open...
PPTX
Jack Whitsitt - Yours, Anecdotally
PDF
Fostering Maturity Through a Security Lifecycle: An OSS Case Study
PPTX
Allianz Global CISO october-2015-draft
PPTX
Top 15 security predictions for 2017
PPTX
Why 'positive security' is a software security game changer
PPTX
Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More ...
PDF
Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)
Make it Fixable (CppCon 2018)
Make It Fixable (Sikkert NOK 2017)
Make it Fixable, Living with Risk (Paranoia 2017)
You Give Us The Fire We'll Give'em Hell!
Make It Fixable, Living with Risk (NDC London 2018)
DevSecOps for Developers, How To Start (ETC 2020)
Deja vu security Adam Cecchetti - Security is a Snapshot in Time BSidesPDX ...
Make it Fixable (NDC Copenhagen 2018)
The Future of DevSecOps
2024 Security Outlook & Essential Security Practices
Community IT Webinar - IT Security for Nonprofits
Open Source Insight: You Can’t Beat Hackers and the Pentagon Moves into Open...
Jack Whitsitt - Yours, Anecdotally
Fostering Maturity Through a Security Lifecycle: An OSS Case Study
Allianz Global CISO october-2015-draft
Top 15 security predictions for 2017
Why 'positive security' is a software security game changer
Open Source Insight: Paraskevidekatriaphobia, Web APIs, Jeep Hacking, More ...
Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)
Ad

More from Pete Cheslock (9)

PDF
How to keep the people you need
PDF
Pick Any Three: Good, Fast, or Safe - Devops from Scratch
PDF
DevOpsDays - Pick any Three - Devops from scratch
PDF
The Vasa Redux
PDF
A Tale of Two Workflows - ChefConf 2014
PPTX
Recruiting is Broken - How Do We Fix It
PPTX
Rubix cube
PPTX
Sonian, Open Source and Sensu
PPTX
Chef boston-workflows
How to keep the people you need
Pick Any Three: Good, Fast, or Safe - Devops from Scratch
DevOpsDays - Pick any Three - Devops from scratch
The Vasa Redux
A Tale of Two Workflows - ChefConf 2014
Recruiting is Broken - How Do We Fix It
Rubix cube
Sonian, Open Source and Sensu
Chef boston-workflows

Recently uploaded (20)

PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPT
Teaching material agriculture food technology
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
Cloud computing and distributed systems.
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Empathic Computing: Creating Shared Understanding
PDF
Encapsulation theory and applications.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
Network Security Unit 5.pdf for BCA BBA.
MYSQL Presentation for SQL database connectivity
20250228 LYD VKU AI Blended-Learning.pptx
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Teaching material agriculture food technology
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
NewMind AI Weekly Chronicles - August'25-Week II
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Reach Out and Touch Someone: Haptics and Empathic Computing
MIND Revenue Release Quarter 2 2025 Press Release
Encapsulation_ Review paper, used for researhc scholars
Cloud computing and distributed systems.
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Unlocking AI with Model Context Protocol (MCP)
Dropbox Q2 2025 Financial Results & Investor Presentation
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Empathic Computing: Creating Shared Understanding
Encapsulation theory and applications.pdf
Building Integrated photovoltaic BIPV_UPV.pdf

Why We Can't Have Nice Things, A Tale of Woe and a Hope For the Future