<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on Nyghtowl</title>
    <link>https://nyghtowl.com/tags/security/</link>
    <description>Recent content in Security on Nyghtowl</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <copyright>&lt;a href=&#34;https://creativecommons.org/licenses/by-nc-sa/4.0/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CC BY-NC-SA 4.0&lt;/a&gt;</copyright>
    <lastBuildDate>Fri, 17 Jul 2020 22:05:26 +0000</lastBuildDate>
    <atom:link href="https://nyghtowl.com/tags/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How to End User OAuth for GCP</title>
      <link>https://nyghtowl.com/posts/2020/07/how-to-end-user-oauth-for-gcp/</link>
      <pubDate>Fri, 17 Jul 2020 22:05:26 +0000</pubDate>
      <guid>https://nyghtowl.com/posts/2020/07/how-to-end-user-oauth-for-gcp/</guid>
      <description>&lt;h3 id=&#34;how-to-end-user-oauth-forgcp&#34;&gt;How to End User OAuth for GCP&lt;/h3&gt;&#xA;&lt;p&gt;Let’s talk about end user authentication. I’ve been digging into the authentication space a bit and have some takeaways to share.&lt;/p&gt;&#xA;&lt;p&gt;When you access a GCP service, there is authentication to determine who you are, authorization to determine what you can do and auditing that logs what you did. IAM is where you setup roles for authorization in regards what you can do in a project.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cyber Security for the Previous Generation</title>
      <link>https://nyghtowl.com/posts/2018/10/cyber-security-for-the-previous-generation/</link>
      <pubDate>Mon, 29 Oct 2018 23:08:53 +0000</pubDate>
      <guid>https://nyghtowl.com/posts/2018/10/cyber-security-for-the-previous-generation/</guid>
      <description>&lt;h3 id=&#34;cyber-security-for-previous-generation&#34;&gt;Cyber Security for Previous Generation&lt;/h3&gt;&#xA;&lt;p&gt;After being tech support for my mom, sorting out my parents affairs when my father got cancer and my mom got Alzheimers, I’ve gathered some insights on the vulnerability of the previous generation to cyber threats like phishing, spoofing and identity theft.&lt;/p&gt;&#xA;&lt;p&gt;This is my security perspective and it will be different for each person. Take what works and adapt. The goal is to raise awareness that helping the previous gen stay safe is as important for them as much as it can help keep you safe. And yes these tips can be applied to every generation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>What to Do When You are Hacked</title>
      <link>https://nyghtowl.com/posts/2013/06/what-to-do-when-you-are-hacked/</link>
      <pubDate>Thu, 20 Jun 2013 12:42:29 +0000</pubDate>
      <guid>https://nyghtowl.com/posts/2013/06/what-to-do-when-you-are-hacked/</guid>
      <description>&lt;p&gt;I am someone who practices pretty decent technical security hygiene, but I had my Yahoo account hacked this week (despite using two factor identification).  This post focuses on sharing what I did to deal with the attack, what I think went wrong and some steps and resources you can use for security.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Summary of attack…&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The attacker logged in at 4:57PM PST and sent off 28 emails to about 5 recipients in each email from 4:58PM to 5:05PM. I learned about the attack from a friend at 5:08PM and logged in and changed my password at 5:10PM. The attacker appeared to pull email addresses from my account (I’m guessing from my contacts and sent file folders) to use in the spam emails.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
