Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Rory McCune

@raesene@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Containers, Security, Kubernetes, Hillwalking

1033 Followers
340 Following
12 Posts
Joined October 28, 2022
Personal Site:
https://www.mccune.org.uk/
Blog:
https://raesene.github.io/
Container Security Site:
https://www.container-security.site
GitHub:
https://github.com/raesene/
Open post
Rory McCune @raesene@infosec.exchange
· 2mo ago
The video for my "Talk about giving talks" that I presented at Steelcon earlier this month, is now live. This is a talk I've wanted to give for a while now and it's my attempt to coalesce the lessons learned over 16 years of conference speaking experience down into one hour. https://youtu.be/jBSANnzGjHE?si=Y0T9b4NmMPE2Ljqr

A Talk About Giving Talks - Rory McCune

3
0
0
0
Open post
Rory McCune @raesene@infosec.exchange
· 7mo ago

If you're using GCP and have enabled Gemini on any of your projects, this one is worth reading, as you may have some checking to do. https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules

Google API Keys Weren
trufflesecurity.com

Google API Keys Weren

Google spent over a decade telling developers that Google API keys (like those used in Maps, Firebase, etc.) are not secrets. But that

6
0
10
0
Open post
Rory McCune @raesene@infosec.exchange
· 6mo ago

Next in my series of blogs on unpatchable Kubernetes vulnerabilities is out. This time it's about TOCTOUs and SSRF

https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2020-8562/

Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8562 | Datadog Security Labs
securitylabs.datadoghq.com

Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8562 | Datadog Security Labs

A look at how Kubernetes CVE-2020-8562 allows attackers to bypass API server proxy protections using DNS rebinding

3
0
3
0
Open post
Rory McCune @raesene@infosec.exchange
· 5mo ago

Some Sunday morning thoughts on the rise of personal software and the implications for security.

https://raesene.github.io/blog/2026/05/10/personal-software-and-baremetalvmm/

raesene.github.io
2
0
0
0
Open post
Rory McCune @raesene@infosec.exchange
· 7mo ago

One of the points I make in Kubernetes Security a lot is that talking about security defaults is hard as each distribution has its own idea of what works for their users.

One of the most surprising of these is Microk8s' choice to not enable RBAC by default. I wrote up a bit about it, here. https://raesene.github.io/blog/2026/03/11/microk8s-rbac-default/

raesene.github.io

Variance of defaults - Microk8s RBAC · Raesene's Ramblings

Things that occur to me

3
0
0
0
Open post
Rory McCune @raesene@infosec.exchange
· 7mo ago

Kubernetes SIG-Security docs have been doing some work to refresh the OWASP Kubernetes Top 10, to help cluster operators and users have a clear idea of where to start with Kubernetes security. It's taken a little longer than expected, but we have our draft top 10 out now. Any feedback very welcome

https://owasp.org/www-project-kubernetes-top-ten/

owasp.org
3
0
3
0
Open post
Rory McCune @raesene@infosec.exchange
· 7mo ago

As the hardware price hikes start impacting server hosting costs, could be a good time to look out those old laptops and desktop you're hoarding (or that could just be me) and see if you can self-host!

3
0
1
0
Open post
Rory McCune @raesene@infosec.exchange
· 8mo ago

I have a feeling that we're entering an era of "personal software" where people write and run their own tools just intended for their personal use.

With all of the activity on coding agents like Claude code, it's interesting to see what impact it will have on the software market. It's always been a bit true that selling software to developers or IT professionals is tricky as they have the temptation to just build their own, and I can really see LLMs accelerating that trend.

To provide a concrete example, a tool I've wanted for years is one that lets me create firecracker backed micro-VMs on my local host so I can test things out and try tools that might be malicious in a more isolated environment than you get with standard Linux container isolation.

Unfortunately that's not a use-case that the firecracker project are really focused on and while there are some tools that look at this area, none of them really seem complete. It's also not an area of programming that I'm familiar enough with to try and code, but I know the problem domain well.

So I thought I'd try out Claude code to see if it could work it out, and honestly it's gone surprisingly well. I've now got something that works for me and has pretty much all the functionality I need. I've probably spent half a day prompting, reviewing, and testing.

Now is this a tool I'd recommend other people use.... no. But it does what I need and I'm expecting it to be pretty useful for my work! If you want to see it, the code is here https://github.com/raesene/baremetalvmm

github.com
3
0
2
0
Open post
Rory McCune @raesene@infosec.exchange
· 6mo ago

Just released another entry in my blog series looking at the unpatchable vulnerabilities of Kubernetes.

Whilst the CVEs are quite old, understanding them is useful, both to understand if you need to apply mitigations and also for some of the low-level Kubernetes implementation details they involve.

https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2020-8561/

Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8561 | Datadog Security Labs
securitylabs.datadoghq.com

Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8561 | Datadog Security Labs

A look at how Kubernetes CVE-2020-8561 works

1
0
3
0
Open post
Rory McCune @raesene@infosec.exchange
· 7mo ago

Really looking forward to Securi-Tay from the Abertay Ethical Hacking Society tomorrow.

If you're there and interested in hearing what 20 years of speaking experience has taught me and how you can hopefully improve your next talk, I'm on at 11:30am in track 3!

https://securi-tay.co.uk/schedule

securi-tay.co.uk
0
0
1
0
Open post
Rory McCune @raesene@infosec.exchange
· 2mo ago
I've been taking some time to dig in to Kubernetes' z-pages support and some of the things to know if you want to use them for debugging and configuration review. No massive revelations but I learned a thing or two while doing it, so I wrote them down :) https://raesene.github.io/blog/2026/07/20/show-us-zee-pages/
raesene.github.io

Show us Zee Pages · Raesene's Ramblings

Things that occur to me

0
1
0
0
Open post
Rory McCune @raesene@infosec.exchange
· 2mo ago
Replying to
@jerry@infosec.exchange Unless you get their cyber-approvals thing done, It's totally useless for anything vaguely security related as it just hits a guardrail. I couldn't even get it to discuss vulnerability hunting without hitting a block. what's possible more interesting/scary is that kimi K3, a model which is pretty good at offensive stuff and has no guardrails that I've found so far, is going open weights today, so any provider with enough hardware can run their own instance without any trace hitting the cloud.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:14:13 UTC