Blog
Jemurai's Digital Stream of Consciousness
-
Jemurai and OSS
Today we added a section to our website to highlight open source software that we have been working on.
-
Update on SecurityProgram.io
In late March we announced our new offering securityprogram.io. In this post we want to provide an update around what we’ve been working on through May and how it works.
-
User Auditing with GAA
If you read the story about Samsung exposing SmartThings and AWS keys in code, which I came across through a Philippe De Ryck twitter post this AM, you might wonder how on earth those repositories came to be public. It turns out, that’s not that uncommon - and we wrote an open source tool to help clients work through this issue. This post introduces the tool and approach.
-
Encrypting Large Files
We have a client that is doing interesting data science that depends on processing very large files (100GB) that are also transferred between parties.
-
Package managers
Over the past few weeks we’ve been talking a lot internally at Jemurai about how package managers and the code repositories we use (often what people think of as open source) affect our security.
-
Announcing securityprogram.io
At Jemurai, we do a lot of custom projects building and breaking things and helping teams build more secure code.
-
Exploring CloudTrail
We had a customer ask us to dig for some indicators of compromise in their AWS account. We are already using our JASP tool to help them to check security configurations in general, so we took the opportunity to formalize some of what we’re doing into a tool which we plan to open source once we clean it up. This post presents some of the types of things that are challenging to just check in JASP and how we’re thinking about the tool.
-
Sharing Files with S3 Safely
It seems to me like back in the day, all the companies we worked with shared files with FTP. Remember FTP? A surprising number of enterprise integrations patters depended on FTP and eventually SFTP.
-
Managing Dependencies
A common question came up again this week working with a developer (and friend) at a partner that does custom software development.
-
Oops! A discussion about priorities and risk
Risk February 05, 2019This post is about a case where we didn’t follow our own advice or industry best practices and it bit us. But then interesting other things ensued and we learned some things.
Want to stay up to date with the lastest from Jemurai?
Sign up for our monthly newsletter!