Comment on Hack Series: Is your Ansible Package Configuration Secure? by [tl;dr sec] #88 - Testing 2FA Implementations, Cloud Visibility/Enforcement, Altar of the Algorithm - tl;dr sec
![Comment on Hack Series: Is your Ansible Package Configuration Secure? by [tl;dr sec] #88 - Testing 2FA Implementations, Cloud Visibility/Enforcement, Altar of the Algorithm - tl;dr sec 图片 1](https://reed-1375047569.cos.ap-shanghai.myqcloud.com/article/image/26/261c5cd7bd239507b03d4bd5beb41cccbcf1b2aa182c8cfd8f0c612f47e48c02.png)
[…] Hack Series: Is your Ansible Package Configuration Secure? Include Security’s Laurence Tennant describes his top 10 tips for auditing Ansible code as well as two subtle ways in which package managers may not verify signatures. Also, Ansible doesn’t natively provide a way to see the exact commands that are being run, but Laurence provides a handy strace command (in this case, looking for calls to apt) […]
评论
?
参与讨论