Corey Quinn Profile picture
Jul 26, 2022 56 tweets 19 min read Read on X
We're 20 minutes away from the start of #awsreinforce. I'm in San Francisco, it is dark outside, but at least I'm not in Boston.

This is my livetweet thread of the event. e Inforce Welcome to the Livestream WE'LL BEGIN SHORTLY
I'm ready for this, Cloud Economist style A monitor with 8 different windows ready to rock this thing.
For actually intelligent takes rather than jokes, be sure to check out @marknca's livetweet thread.
Starts with a prepared video set to "Balance in the Universe" by Evandro Marconi Rocco. Scale your permissions progra using AWS Identity Services
And @stephenschmidt takes the stage with an "ADHD is not a disability" shirt.

Respect. A DIMBI [MUSİC) [APPLAUSEI
266 sessions over 2 days, or roughly half a session per @awscloud service. 5 Tracks 266 Sessions FROM. THAT INCLUDES SOME 5 Launches
Here are the 5 #reInforce tracks. Not to be confused with the 6 pillars of the Well Architected Framework, or the 4 million dollars you lost on deploying the first version of Macie. Governance, Risk and Compliance Tracks Data Protection and P
Now @StephenSchmitd refuses to shut the hell up about CrossFit. NEW Circuit training 88 88 THREE SECTIONS OF CONTENT ALONG W
"Challenge Coins" is the best description ever for the money you pay for your AWS bill overages. Challenge coins IS GOOD OLD SWAG. WE HAVEZ
Now a slide with Singapore and Laramie (Wyoming) on a globe to juxtapose a megacity with a hick town that nobody could possibly give less of a shit about.

Apologies to both of the people in Laramie angrily riding their horses to Nebraska to find wifi so they can yell at me. Laramie WYOMING Singapore CUSTOMER ACTIVITIES FROM APIS TO L
Talking about the value of scale; the things they learn from one company apply to other customers globally.

Also highlighting the defense in depth approach that AWS takes. He's correct; they're very very good at this.
Now talking about GuardDuty; apparently the people in the front row look like they have extra money or something.
"Products and services aren't shipped without a security review first."

Azure should take notes here. Security Guardians Ambassadors for security throughout the a
And now "some lessons I have learned at CISO of AWS before becoming Amazon's CSO" says @stephenschmidt.

Wrong answers only?
Talking about the immoral invasion of Ukraine by Russia. Good on him for not shying away from calling that out. AWS Snowball of essential data migrated government ata migra
And now @stephenschmidt passes the microphone and baton to new @awscloud CISO @mosescj58. CJ on stage
Steve pronounces it a "See Eye Ess Oh."
CJ pronounces it as "Sizz-oh."

CISO is pronounced "See-Soh" and nobody at @awscloud can pronounce acronyms properly to save their lives. #amihasthreesyllables
Talking about how important security is, which... is all well and good, yes, but the audience has ponied up $1099 a head to be at the AWS security conference in Boston. I think we can kinda accept that the audience gets that this matters by this point.
First time I can recall seeing "Neurodiversity" on a slide from @awscloud. Neurodiversity INTROVERSION, EXTROVERSION,
Four best practices to go with the five tracks and six pillars of the Well Architected Framework. BEST PRACTICES Least privilege Vulnerability reporting )nsom
"If you're on vacation, your access should be as well."

*laughs in startup and being owned by your job*
It's not ransomware, it's a post-paid penetration test. #branding RELATED SESSIONS: TDR352 1 TDR332 TDR431 Ransomware mitigati
#awsreinforce is sponsored by our friends at Log4J. 30010 ocoo LESSONS LEARNED oo L0G'lJ 1 2 3 4 5 Limit outboun
Relaunching the security competency.

I always found that a weird way to frame it. If you ask me about someone and I say they're "competent," you can view that as a tepid reference... Security Competency Re-Launch New service and software categ
Wall of logos of new security competency partners. IBM is included; wonder who they bought... New Software Security Competency Partners ALERT LOGIC *DEVO
We've now entered an impenetrable thicket of acronyms like MSSP, a slurry of terms of art, and yup: it's a security conference all right.
Launching today: a preview of AWS Marketplace Vendor Insights.

I kinda don't think they're going to, y'know. Warn you which ones are terrifying. NEW PREVIEW: AWS MARKETPLACE VENDOR INSIGHTS Simplify vendor
AWS Audit School continues to be a thing that exists. Cloud Audit Academy (CAA) Designed to educate assurance, ris
I wish their security awareness training was something I could use to just check the box here, but it's not that built out unfortunately.

I would pay them for this. Security Awareness Training Plus multi-factor authentication
I wonder if I'm one of the threats in their Threat Modeling Workshop. Threat Modeling Workshop Introduction to background of threa
Now @LenaSmart8 takes the stage. She's the CISO of @MongoDB.

"Security is very important. This one time we weren't secure enough and this jackhole company offered a crappy rebranded substandard version of our product for sale. Can you imagine that?" (Not really.) Lena Smart Chief Information Security Officer, MongoDB [APPL
WHOA. She just said "multi-cloud" on stage at an AWS keynote. AMAZING. Flexibility of our o document model Help users tackle these
Oh no MongoDB tried to catch all the AWS services as if they were Pokemon! AWSSgvtesToÖO( $ IbrgoDB AWS GER AWS Access AWS AWS Service
Congratulations, @MongoDB; achievement unlocked! ACHIEVEMENT UNLOCKED! Treating AWS Services Like Pokémon Yo
Three parts of the management cycle to go with the four best practices, five tracks and six pillars of the Well Architected Framework. Landing Zone AWS Services Toolbox aws 0 MongoDB. Session Man
Now Kurt Kufeld, VP of Platform at AWS. How the hell he follows someone as awesome on stage as @LenaSmart8 is beyond me.

I'd just give up and go home in his shoes. zon weo bervıces  [Müsıc] [APPLAUSE]
A bold aspiration quote from a man who owns the entirety of the @awscloud billing system within his purview. It's a technical marvel that shows in exacting detail exactly where the puck was two days ago. Ill skate to where the puck is going to be, not where it has
Now @awscloud is selling both sides of the arms race: post-quantum cryptography as well as the quantum computers (Braket) to break the crypto. 0(01 O '0 010 1011010100 OOIÄO 0011010010111010 U co 11 O o
KMS, ACM, and Secrets Manager support hybrid post-quantum key agreement today.

"What about Systems Manager Parameter Store?"
"What about you not being such a cheap bastard, Quinnypig?"
I missed the launch of AWS LibCrypto last year, probably because I'm nowhere near smart enough to know how that stuff works. OPEN-SOURCE CRYPTOGRAPHIC LIBRARY AWS-LibCrypto with TLS in
Kurt is now talking about using automated reasoning to determine things like "is this S3 bucket open to the public."

That sounds hard. I use the red screamy warning in the @awscloud S3 console instead, it's way easier.
AWS uses "Provable Security."

I use "Probable Security" as in "it's probably fine." 0000 Provable security In AWS services S3 verification for S
New term of art just dropped. YOINK.
Now Kurt is talking about IAM. OH MY GOD IT'S FULL OF STARS AWS Identity and Access Management ACCESS TO YOUR DATA IN AW
"Please, turn on Block Public Access."

Cool, let me move this ONE SPECIFIC PUBLIC BUCKET to another account without breaking all of my shit and I absolutely would. CALL TO ACTION Block Public Access YOU AND I'VE ALREADY MENT
"Please, enable MFA."

Okay, please enable multiple MFA devices per account and I absolutely will. CALL TO ACTION Enable MFA SECURITY BEST PRACTICE. MSA -- MF
You can order free MFA keys from @awscloud if you spend more than $100 a month. If you don't spend that much, don't enable MFA and wait a bit. For qualified customers as part of a National CybersecuriW I
IAM Roles Anywhere launched two weeks ago. Lost opportunity to call it "AWS Bakery." Because there will be... rolls everywhere.

I'm here all week. NEW AWS (AM) Roles Anywhere Management Extends the capabilit
It lets you get IAM credentials for anything that has a signed certificate. We know how to manage those already (we don't but we trick ourselves into believing otherwise). Great for off-prem stuff / using IAM as a free database.
Launch today: Amazon Detective for Elastic Kubernetes Service (EKS).

The first issue is Amazon Detective and the Case of Where Did All The Money Go? lazo Amazon Detective for Elastic Kubernetes Sewice (EKS) NE
Launch today: Amazon GuardDuty Malware Protection.

When GuardDuty detects suspicious activity, it snapshots the EBS volume and then scans the snapshot in an AWS service account.

Yes it costs, but it's also something existing customers have to opt in for. I strongly suggest it. NEW Amazon GuardDuty Malware Protection Delivers agentless d
Works within Security Hub. Which is awesome except that "being secure" shouldn't be an investment decision in this way. NEW AWS Security Hub and Amazon GuardDuty fin vare Protectio
AWS Training and Certification has ways to learn security. So does REALLY screwing it up the first time. Those lessons STICK. LEARN SECURITY WITH AWS Training and Certification NEW Getti
Kurt Kufeld pauses, and grabs a guitar. He begins covering Iron Maiden: Wickr Man. // wickr an AWS Company nonunications and meet regulatory Se
New sessions covering those releases for those attending #reinforce in person. Don't forget to attend these sessions! TDR210 DPP210 GRC210
And @mosescj58 closes with a George Bernard Shaw quote, so I'll do the same:

“Happy is the man who can make a living by his hobby."

Thanks for reading. lastweekinaws.com is the newsletter; if you've enjoyed this, please sign up. It's free. "If you have an apple and I have an apple and We exchan

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Corey Quinn

Corey Quinn Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @QuinnyPig

Jul 10
I'm at the AWS Summit in NYC, where I believe that nicknames are for friends--and Gennifer Artificial Intelligence is no friend of mine.

Good morning.
Thirsty much? Image
A game / challenge at the AWS Startups booth: how long can an AWS employee go without mentioning GenAI? Someone just made it all the way to one minute, ten seconds! Image
Read 49 tweets
Jun 27
Oh god I have to take a technical cert too.

Okay. Let's do Networking Specialty. Practice question 1:

Correct answer is B. Image
"Wrong!" says the answer key, "it's B because network load balancers don't support client IP preservation." Image
Except that they do. They absolutely do. They have for the past year. I'm just a boy, standing in front of an AWS Cert team, asking them to do their damn jobs. Image
Read 4 tweets
Apr 17
Today's cloud marketing story is called "The Tale of Hot Rebecca," and is a truthful recounting of dinner last night.

Strap in; it's a fun ride.
Back in my early 20s, I had a number of friends / acquaintances in my (primarily Jewish) social circle named "Rebecca." It was kind of a problem.

("Can't we spray for them?"
"…not since the 1940s.")
So every Rebecca got an adjective, much like the seven dwarves. One of them asked me once what her adjective was, and I responded in a fit of unadulterated honesty, "you're Hot Rebecca" because honestly? Damn.
Read 9 tweets
Apr 9
Made it to the #GoogleCloudNext keynote seating finally. Let's see how this goes now that the world is starting to wake up to a "much of the AI hype is unwarranted" reality.
Boeing: "HOW ARE THEY DOING IT?!"
Airbus: "We bought a torque wrench?"
Boeing: "No, how are you being a featured customer testimonial at #GoogleCloudNext?"
Airbus: "Oh, that? We made a strategic decision to not be walking poster children for corporate negligence." Image
In any case, fear not. I am here for this. Image
Read 39 tweets
Feb 13
And now, some DevOps / SRE / Sysadmin / Ops / ENOUGH already tips I learned from early in my career--brought to us by our friends at Chex™ Mix. All of these are great ideas that you should implement immediately... Image
DNS is notoriously unreliable, so use configuration management to sync all of the servers' /etc/hosts files. Boom, no more single point of failure.
Future-proofing is an early optimization, so don't do it. Every network should be a /24 because that's how developers think. I mean come on, what are the odds you'll ever have more than 253 hosts in a network?
Read 14 tweets
Feb 1
And the Amazon earnings are out for Q4. A miss on @awscloud revenue by $20 million because analysts didn't expect one of you to turn off a single Managed NAT Gateway.

Let's explore deeper into their press release.
For 2023, AWS sold $90.8 billion of services, most of which were oversized EC2 instances because you all refuse to believe Compute Optimizer when it tells you there are savings to be had if you're just a smidgen more reasonable.
Word frequency in the earnings release:
Customer: 87
Employee: 11
Generative: 16
Cloud: 24
Serverless: 3
DynamoDB: 2
Union: 0
Read 13 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(