Elektrine lite

← Feed

Rory McCune

raesene@infosec.exchange

<p>Containers, Security, Kubernetes, Hillwalking</p>

Posts

  • Post #3961383

    I&#39;ve been taking some time to dig in to Kubernetes&#39; z-pages support and some of the things to know if you want to use them for debugging and configuration review. No massive revelations but I learned a thing or two while doing it, so I wrote them down :) https://raesene.github.io/blog/2026/07/20/show-us-zee-pages/

  • Post #3957418

    The video for my &quot;Talk about giving talks&quot; that I presented at Steelcon earlier this month, is now live. This is a talk I&#39;ve wanted to give for a while now and it&#39;s my attempt to coalesce the lessons learned over 16 years of conference speaking experience down into one hour. https://youtu.be/jBSANnzGjHE?si=Y0T9b4NmMPE2Ljqr

  • Post #2378878

    Some Sunday morning thoughts on the rise of personal software and the implications for security. https://raesene.github.io/blog/2026/05/10/personal-software-and-baremetalvmm/

  • Post #1726628

    I have a feeling that we&#39;re entering an era of &quot;personal software&quot; where people write and run their own tools just intended for their personal use. With all of the activity on coding agents like Claude code, it&#39;s interesting to see what impact it will have on the software market. It&#39;s always been a bit true that selling software to developers or IT professionals is tricky as they have the temptation to just build their own, and I can really see LLMs accelerating that trend...

  • Post #1726625

    As the hardware price hikes start impacting server hosting costs, could be a good time to look out those old laptops and desktop you&#39;re hoarding (or that could just be me) and see if you can self-host!

  • Post #1726623

    Really looking forward to Securi-Tay from the Abertay Ethical Hacking Society tomorrow. If you&#39;re there and interested in hearing what 20 years of speaking experience has taught me and how you can hopefully improve your next talk, I&#39;m on at 11:30am in track 3! https://securi-tay.co.uk/schedule

  • Post #1726621

    One of the points I make in Kubernetes Security a lot is that talking about security defaults is hard as each distribution has its own idea of what works for their users. One of the most surprising of these is Microk8s&#39; choice to not enable RBAC by default. I wrote up a bit about it, here. https://raesene.github.io/blog/2026/03/11/microk8s-rbac-default/

  • Post #1116936

    Next in my series of blogs on unpatchable Kubernetes vulnerabilities is out. This time it&#39;s about TOCTOUs and SSRF https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2020-8562/

  • Post #951240

    Just released another entry in my blog series looking at the unpatchable vulnerabilities of Kubernetes. Whilst the CVEs are quite old, understanding them is useful, both to understand if you need to apply mitigations and also for some of the low-level Kubernetes implementation details they involve. https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2020-8561/

  • Post #679467

    Kubernetes SIG-Security docs have been doing some work to refresh the OWASP Kubernetes Top 10, to help cluster operators and users have a clear idea of where to start with Kubernetes security. It&#39;s taken a little longer than expected, but we have our draft top 10 out now. Any feedback very welcome https://owasp.org/www-project-kubernetes-top-ten/

  • Post #448187

    If you&#39;re using GCP and have enabled Gemini on any of your projects, this one is worth reading, as you may have some checking to do. https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules