Secure All Software

Home
Notes
Website
Archive
About
Burn your API keys!
Looking at API keys as a threat to your companies existence opens up the idea of using application identities and create temporary credentials based on…
Mar 29, 2024 • Andreas Tiefenthaler
Open Source Security
Innovation and risk lie in the vast landscape of open-source software (OSS).
Apr 5, 2024 • Andreas Tiefenthaler
You are doing it wrong! Kubernetes Image Tags
9 out of 10 deployments are doing it wrong, can you guess why?
Sep 15, 2023 • Andreas Tiefenthaler
Are we loosing at dependencies?
How did we get into this complex mess?
Feb 16, 2024 • Andreas Tiefenthaler
Gone Phishing
There is always a new way to phish people and cause damage. Developers and DevOps Engineers are more targeted than ever. Sometimes it comes as the wolf…
Sep 27, 2023 • Andreas Tiefenthaler
Supply-chains, Lockfiles and Rants
Supply chain attacks are in all news (at least in mine). These kind of attacks happen in plain sight and use available infrastructure to do harm.
Jul 28, 2023 • Andreas Tiefenthaler
Kubernetes Fort Knox
Your Arsenal Against Modern Cyber Threats
Sep 1, 2023 • Andreas Tiefenthaler
Are Software and DevOps engineers becoming dumber?
I recently saw a (on purpose) controversial post on Linkedin titled “Are Software engineers becoming dumber?” The idea was that 20 years ago, we didn’t…
Mar 22, 2024 • Andreas Tiefenthaler
Solving CI/CD Bottlenecks - Some Practical Tips
Tired of waiting for computers to do their stuff?
May 31, 2024 • Andreas Tiefenthaler
Secure All Software - Who owns security? Issue #14
Is it me or is it you?
Jun 15, 2023 • Andreas Tiefenthaler
Secure All Software [#14] - Signing Containers
Container image tags are overly trusted and rarely validated. Cryptographic signing is available. Here are a few ways to do it.
Jun 23, 2023 • Andreas Tiefenthaler
Security for Engineering Leaders (on a budget)
Software startups often operate on tight budgets, making low or no-cost security measures particularly appealing.
May 3, 2024 • Andreas Tiefenthaler
© 2026 Substack Inc · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture