Corey Quinn Profile picture
Jul 26 56 tweets 19 min read
We're 20 minutes away from the start of #awsreinforce. I'm in San Francisco, it is dark outside, but at least I'm not in Boston.

This is my livetweet thread of the event. e Inforce Welcome to the Livestream WE'LL BEGIN SHORTLY
I'm ready for this, Cloud Economist style A monitor with 8 different windows ready to rock this thing.
For actually intelligent takes rather than jokes, be sure to check out @marknca's livetweet thread.
Starts with a prepared video set to "Balance in the Universe" by Evandro Marconi Rocco. Scale your permissions progra using AWS Identity Services
And @stephenschmidt takes the stage with an "ADHD is not a disability" shirt.

Respect. A DIMBI [MUSİC) [APPLAUSEI
266 sessions over 2 days, or roughly half a session per @awscloud service. 5 Tracks 266 Sessions FROM. THAT INCLUDES SOME 5 Launches
Here are the 5 #reInforce tracks. Not to be confused with the 6 pillars of the Well Architected Framework, or the 4 million dollars you lost on deploying the first version of Macie. Governance, Risk and Compliance Tracks Data Protection and P
Now @StephenSchmitd refuses to shut the hell up about CrossFit. NEW Circuit training 88 88 THREE SECTIONS OF CONTENT ALONG W
"Challenge Coins" is the best description ever for the money you pay for your AWS bill overages. Challenge coins IS GOOD OLD SWAG. WE HAVEZ
Now a slide with Singapore and Laramie (Wyoming) on a globe to juxtapose a megacity with a hick town that nobody could possibly give less of a shit about.

Apologies to both of the people in Laramie angrily riding their horses to Nebraska to find wifi so they can yell at me. Laramie WYOMING Singapore CUSTOMER ACTIVITIES FROM APIS TO L
Talking about the value of scale; the things they learn from one company apply to other customers globally.

Also highlighting the defense in depth approach that AWS takes. He's correct; they're very very good at this.
Now talking about GuardDuty; apparently the people in the front row look like they have extra money or something.
"Products and services aren't shipped without a security review first."

Azure should take notes here. Security Guardians Ambassadors for security throughout the a
And now "some lessons I have learned at CISO of AWS before becoming Amazon's CSO" says @stephenschmidt.

Wrong answers only?
Talking about the immoral invasion of Ukraine by Russia. Good on him for not shying away from calling that out. AWS Snowball of essential data migrated government ata migra
And now @stephenschmidt passes the microphone and baton to new @awscloud CISO @mosescj58. CJ on stage
Steve pronounces it a "See Eye Ess Oh."
CJ pronounces it as "Sizz-oh."

CISO is pronounced "See-Soh" and nobody at @awscloud can pronounce acronyms properly to save their lives. #amihasthreesyllables
Talking about how important security is, which... is all well and good, yes, but the audience has ponied up $1099 a head to be at the AWS security conference in Boston. I think we can kinda accept that the audience gets that this matters by this point.
First time I can recall seeing "Neurodiversity" on a slide from @awscloud. Neurodiversity INTROVERSION, EXTROVERSION,
Four best practices to go with the five tracks and six pillars of the Well Architected Framework. BEST PRACTICES Least privilege Vulnerability reporting )nsom
"If you're on vacation, your access should be as well."

*laughs in startup and being owned by your job*
It's not ransomware, it's a post-paid penetration test. #branding RELATED SESSIONS: TDR352 1 TDR332 TDR431 Ransomware mitigati
#awsreinforce is sponsored by our friends at Log4J. 30010 ocoo LESSONS LEARNED oo L0G'lJ 1 2 3 4 5 Limit outboun
Relaunching the security competency.

I always found that a weird way to frame it. If you ask me about someone and I say they're "competent," you can view that as a tepid reference... Security Competency Re-Launch New service and software categ
Wall of logos of new security competency partners. IBM is included; wonder who they bought... New Software Security Competency Partners ALERT LOGIC *DEVO
We've now entered an impenetrable thicket of acronyms like MSSP, a slurry of terms of art, and yup: it's a security conference all right.
Launching today: a preview of AWS Marketplace Vendor Insights.

I kinda don't think they're going to, y'know. Warn you which ones are terrifying. NEW PREVIEW: AWS MARKETPLACE VENDOR INSIGHTS Simplify vendor
AWS Audit School continues to be a thing that exists. Cloud Audit Academy (CAA) Designed to educate assurance, ris
I wish their security awareness training was something I could use to just check the box here, but it's not that built out unfortunately.

I would pay them for this. Security Awareness Training Plus multi-factor authentication
I wonder if I'm one of the threats in their Threat Modeling Workshop. Threat Modeling Workshop Introduction to background of threa
Now @LenaSmart8 takes the stage. She's the CISO of @MongoDB.

"Security is very important. This one time we weren't secure enough and this jackhole company offered a crappy rebranded substandard version of our product for sale. Can you imagine that?" (Not really.) Lena Smart Chief Information Security Officer, MongoDB [APPL
WHOA. She just said "multi-cloud" on stage at an AWS keynote. AMAZING. Flexibility of our o document model Help users tackle these
Oh no MongoDB tried to catch all the AWS services as if they were Pokemon! AWSSgvtesToÖO( $ IbrgoDB AWS GER AWS Access AWS AWS Service
Congratulations, @MongoDB; achievement unlocked! ACHIEVEMENT UNLOCKED! Treating AWS Services Like Pokémon Yo
Three parts of the management cycle to go with the four best practices, five tracks and six pillars of the Well Architected Framework. Landing Zone AWS Services Toolbox aws 0 MongoDB. Session Man
Now Kurt Kufeld, VP of Platform at AWS. How the hell he follows someone as awesome on stage as @LenaSmart8 is beyond me.

I'd just give up and go home in his shoes. zon weo bervıces  [Müsıc] [APPLAUSE]
A bold aspiration quote from a man who owns the entirety of the @awscloud billing system within his purview. It's a technical marvel that shows in exacting detail exactly where the puck was two days ago. Ill skate to where the puck is going to be, not where it has
Now @awscloud is selling both sides of the arms race: post-quantum cryptography as well as the quantum computers (Braket) to break the crypto. 0(01 O '0 010 1011010100 OOIÄO 0011010010111010 U co 11 O o
KMS, ACM, and Secrets Manager support hybrid post-quantum key agreement today.

"What about Systems Manager Parameter Store?"
"What about you not being such a cheap bastard, Quinnypig?"
I missed the launch of AWS LibCrypto last year, probably because I'm nowhere near smart enough to know how that stuff works. OPEN-SOURCE CRYPTOGRAPHIC LIBRARY AWS-LibCrypto with TLS in
Kurt is now talking about using automated reasoning to determine things like "is this S3 bucket open to the public."

That sounds hard. I use the red screamy warning in the @awscloud S3 console instead, it's way easier.
AWS uses "Provable Security."

I use "Probable Security" as in "it's probably fine." 0000 Provable security In AWS services S3 verification for S
New term of art just dropped. YOINK.
Now Kurt is talking about IAM. OH MY GOD IT'S FULL OF STARS AWS Identity and Access Management ACCESS TO YOUR DATA IN AW
"Please, turn on Block Public Access."

Cool, let me move this ONE SPECIFIC PUBLIC BUCKET to another account without breaking all of my shit and I absolutely would. CALL TO ACTION Block Public Access YOU AND I'VE ALREADY MENT
"Please, enable MFA."

Okay, please enable multiple MFA devices per account and I absolutely will. CALL TO ACTION Enable MFA SECURITY BEST PRACTICE. MSA -- MF
You can order free MFA keys from @awscloud if you spend more than $100 a month. If you don't spend that much, don't enable MFA and wait a bit. For qualified customers as part of a National CybersecuriW I
IAM Roles Anywhere launched two weeks ago. Lost opportunity to call it "AWS Bakery." Because there will be... rolls everywhere.

I'm here all week. NEW AWS (AM) Roles Anywhere Management Extends the capabilit
It lets you get IAM credentials for anything that has a signed certificate. We know how to manage those already (we don't but we trick ourselves into believing otherwise). Great for off-prem stuff / using IAM as a free database.
Launch today: Amazon Detective for Elastic Kubernetes Service (EKS).

The first issue is Amazon Detective and the Case of Where Did All The Money Go? lazo Amazon Detective for Elastic Kubernetes Sewice (EKS) NE
Launch today: Amazon GuardDuty Malware Protection.

When GuardDuty detects suspicious activity, it snapshots the EBS volume and then scans the snapshot in an AWS service account.

Yes it costs, but it's also something existing customers have to opt in for. I strongly suggest it. NEW Amazon GuardDuty Malware Protection Delivers agentless d
Works within Security Hub. Which is awesome except that "being secure" shouldn't be an investment decision in this way. NEW AWS Security Hub and Amazon GuardDuty fin vare Protectio
AWS Training and Certification has ways to learn security. So does REALLY screwing it up the first time. Those lessons STICK. LEARN SECURITY WITH AWS Training and Certification NEW Getti
Kurt Kufeld pauses, and grabs a guitar. He begins covering Iron Maiden: Wickr Man. // wickr an AWS Company nonunications and meet regulatory Se
New sessions covering those releases for those attending #reinforce in person. Don't forget to attend these sessions! TDR210 DPP210 GRC210
And @mosescj58 closes with a George Bernard Shaw quote, so I'll do the same:

“Happy is the man who can make a living by his hobby."

Thanks for reading. lastweekinaws.com is the newsletter; if you've enjoyed this, please sign up. It's free. "If you have an apple and I have an apple and We exchan

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Corey Quinn

Corey Quinn Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @QuinnyPig

Jul 21
"Why is @Amazon acquiring @OneMedical bad news?"

Let's explore.

1. Horizontal integration at Amazon scale of a company that now has the right to access my medical records under HIPAA opens up a huge problem for abuse.
2. Amazon has a policy against using seller-specific data to “aid [its'] private label business,” but Jeff Bezos testified to Congress that he “can't guarantee” that such a policy has “never been violated.”

Now extend that to your medical data.
3. With access to health care now under attack in a variety of states, do you want your medical data handled by a company who has warehouses and customers in those states (read as: vulnerable to pressure)?
Read 10 tweets
Jul 19
I've been meaning to tear apart a job description to lay bare its subtext for a while now--and what luck! We're hiring a Principal Cloud Economist, and @mike_julian is asleep and thus unable to stop me.

Oh yes, this is a thread.
The specific role lives at apply.workable.com/duckbillgroup/… should you wish to follow along. Let's skin this puppy!
Job descriptions start with the most important things first, so when a job description starts with basically jerking the company off, you kinda know what to expect.

This talks about the client work, and it's accurate. "Recommending RI / SP purchases," this is not. Description Share this job < As a Principal Cloud Economist,
Read 39 tweets
Jul 12
Hello, New York. I'm here in person at the #awssummit, and this is my keynote livetweet thread.

Thanks for joining me. We'll get started in a few minutes. Corey sitting at a table outside with text nws INFINIDASH IS
The usual sponsor scroll slides are up. I hope to one day be sponsored to the point where these companies all slap their logos on me until I'm decked out like a race car. a large screen with text on it with text GOLD SPONSORS A avta group of people on a stage with text htol GLOBAL SPONSORS a group of people sitting in front of a large screen with te
And we're starting with a video talking about how deeply important the @awscloud and @intel partnership is. Since Intel is sponsoring this keynote surely they won't tell a Graviton3 story that makes Intel look bad! a group of people looking at a screen with a logo on it with
Read 47 tweets
Jul 9
Okay. It is time:

ngl.link/lastweekinaws
Really hard to say. I kinda... don't watch many movies or TV shows. This drives @bequinning nuts. Anonymous question: "Y...
AWS Faberge EggBox anonymous question: "A...
Read 80 tweets
Jul 8
On this Friday afternoon I have something to show you folks regarding my "Last Tweet in AWS" threading Twitter client.

Of course this is a thread, and of course I'm using the client to do it.
Last week I went to @Monitorama and attempted to livetweet while also providing alt-text for images. It was frankly a disaster; talks move way too fast for me to be able to competently do that–but I also wasn't willing to pull a "eh, that's hard, screw accessibility."
Note the new checkbox at the bottom of the image. That's right, by default it will auto-populate on image upload with alt-text powered by Machine Learning®.

Specifically, @Azure's Computer Vision API. It's the best of the ones I've sampled so far. The Last Tweet in AWS clien...
Read 9 tweets
Jul 7
With the general availability of M1 Mac instances on EC2 as of today, I want to clear up some confusion I've seen about running macOS on EC2.

Thread time!
You need to reserve a "Dedicated Host" before you can launch a macOS AMI. Once reserved, you cannot unreserve it for 24 hours. This is an Apple license restriction that @awscloud cannot avoid.
The Intel Macs thus cost a minimum of $26 to instantiate, and will cost that much per day.

"Wait, does that mean it's a rip-off since a few months of that easily pays for the Mac itself?"

NAY!
Read 9 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(