forgive my indulgence but 2020's been a big year for @shmuplations, so here's a look back at everything that went up over the last twelve months—there's a lot of stuff I'm sure you all read & other things you'd be forgiven for missing, so let's recap (thread)
https://t.co/orlgPTDsKK
https://t.co/QnQl8KI9IX
More from Software
Some lay the blame for this on @boicy with the whole microservices thing.
(Admittedly, @nicolefv, @jezhumble and @realgenekim didn’t help when they statistically proved that he might have been onto something with all that de-coupling and team-alignment…)
However I don’t blame him at all.
I think he saved us; bringing us back to the path of value-delivery and independent services, but now with added independent teams.
But one thing is clear. Microservices need more architecture, not less (as do other forms of #Accelerate-style software organisation).
(See https://t.co/B2hWmXhIqe if you need convincing)
I mean, all those pesky slices we need to carve up our monoliths (or were they big balls of mud?) That’s a significant amount of work right there…
First, that time when an AWS employee posted confidential AWS customer information including including AWS access keys for those customer accounts to
Fresh data breach news-
— Chris Vickery (@VickerySec) January 23, 2020
Amazon AWS engineer exposes work-related keys, passwords, and documents marked "Amazon Confidential" via public Github repository: https://t.co/7gkIegnslx
Discovered within 30 minutes of exposure by my team at @UpGuard.
Discovery by @SpenGietz that you can disable CloudTrail without triggering GuardDuty by using cloudtrail:PutEventSelectors to filter all events.
"Disable" most #AWS #CloudTrail logging without triggering #GuardDuty:https://t.co/zVe4uSHog9
— Rhino Security Labs (@RhinoSecurity) April 23, 2020
Reported to AWS Security and it is not a bug.
Amazon launched their bug bounty, but specifically excluded AWS, which has no bug bounty.
Amazon Vulnerability Research Program - Doesn't include AWS D:https://t.co/stJHDG68pj#BugBounty #AWS
— Spencer Gietzen (@SpenGietz) April 22, 2020
Repeated, over and over again examples of AWS having no change control over their Managed IAM policies, including the mistaken release of CheesepuffsServiceRolePolicy, AWSServiceRoleForThorInternalDevPolicy, AWSCodeArtifactReadOnlyAccess.json, AmazonCirrusGammaRoleForInstaller.
You May Also Like
RT-PCR corona (test) scam
Symptomatic people are tested for one and only one respiratory virus. This means that other acute respiratory infections are reclassified as
4/10
— Dr. Thomas Binder, MD (@Thomas_Binder) October 22, 2020
...indication, first of all that testing for a (single) respiratory virus is done outside of surveillance systems or need for specific therapy, but even so the lack of consideration of Ct, symptoms and clinical findings when interpreting its result. https://t.co/gHH6kwRdZG
2/12
It is tested exquisitely with a hypersensitive non-specific RT-PCR test / Ct >35 (>30 is nonsense, >35 is madness), without considering Ct and clinical context. This means that more acute respiratory infections are reclassified as
6/10
— Dr. Thomas Binder, MD (@Thomas_Binder) October 22, 2020
The neither validated nor standardised hypersensitive RT-PCR test / Ct 35-45 for SARS-CoV-2 is abused to mislabel (also) other diseases, especially influenza, as COVID-19.https://t.co/AkFIfTCTkS
3/12
The Drosten RT-PCR test is fabricated in a way that each country and laboratory perform it differently at too high Ct and that the high rate of false positives increases massively due to cross-reaction with other (corona) viruses in the "flu
External peer review of the RTPCR test to detect SARS-CoV-2 reveals 10 major scientific flaws at the molecular and methodological level: consequences for false positive results.https://t.co/mbNY8bdw1p pic.twitter.com/OQBD4grMth
— Dr. Thomas Binder, MD (@Thomas_Binder) November 29, 2020
4/12
Even asymptomatic, previously called healthy, people are tested (en masse) in this way, although there is no epidemiologically relevant asymptomatic transmission. This means that even healthy people are declared as COVID
Thread web\u2b06\ufe0f\u2b07\ufe0f
— Dr. Thomas Binder, MD (@Thomas_Binder) December 16, 2020
The fabrication of the "asymptomatic (super) spreader" is the coronation of the total nons(ci)ense in the belief system of #CoronasWitnesses.
Asymptomatic transmission 0.7%; 95% CI 0%-4.9% - could well be 0%!https://t.co/VeZTzxXfvT
5/12
Deaths within 28 days after a positive RT-PCR test from whatever cause are designated as deaths WITH COVID. This means that other causes of death are reclassified as
8/8
— Dr. Thomas Binder, MD (@Thomas_Binder) March 24, 2020
By the way, who the f*** created this obviously (almost) worldwide definition of #CoronaDeath?
This is not only medical malpractice, this is utterly insane!https://t.co/FFsTx4L2mw
The story doesn\u2019t say you were told not to... it says you did so without approval and they tried to obfuscate what you found. Is that true?
— Sarah Frier (@sarahfrier) November 15, 2018
In the spring and summer of 2016, as reported by the Times, activity we traced to GRU was reported to the FBI. This was the standard model of interaction companies used for nation-state attacks against likely US targeted.
In the Spring of 2017, after a deep dive into the Fake News phenomena, the security team wanted to publish an update that covered what we had learned. At this point, we didn’t have any advertising content or the big IRA cluster, but we did know about the GRU model.
This report when through dozens of edits as different equities were represented. I did not have any meetings with Sheryl on the paper, but I can’t speak to whether she was in the loop with my higher-ups.
In the end, the difficult question of attribution was settled by us pointing to the DNI report instead of saying Russia or GRU directly. In my pre-briefs with members of Congress, I made it clear that we believed this action was GRU.