<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:cc="http://cyber.law.harvard.edu/rss/creativeCommonsRssModule.html">
    <channel>
        <title><![CDATA[Stories by Colin Bitterfield on Medium]]></title>
        <description><![CDATA[Stories by Colin Bitterfield on Medium]]></description>
        <link>https://medium.com/@cbitterfield?source=rss-f8e598d5fbb1------2</link>
        <image>
            <url>https://cdn-images-1.medium.com/fit/c/150/150/0*fYTNx-JvoHw8BbM5</url>
            <title>Stories by Colin Bitterfield on Medium</title>
            <link>https://medium.com/@cbitterfield?source=rss-f8e598d5fbb1------2</link>
        </image>
        <generator>Medium</generator>
        <lastBuildDate>Tue, 21 Jul 2026 19:38:11 GMT</lastBuildDate>
        <atom:link href="https://medium.com/@cbitterfield/feed" rel="self" type="application/rss+xml"/>
        <webMaster><![CDATA[yourfriends@medium.com]]></webMaster>
        <atom:link href="http://medium.superfeedr.com" rel="hub"/>
        <item>
            <title><![CDATA[The Great American Betrayal: How H1-B and F1 Visas Enabled $600 Billion Wealth Transfer While…]]></title>
            <link>https://cbitterfield.medium.com/the-great-american-betrayal-how-h1-b-and-f1-visas-enabled-600-billion-wealth-transfer-while-05a806c3890a?source=rss-f8e598d5fbb1------2</link>
            <guid isPermaLink="false">https://medium.com/p/05a806c3890a</guid>
            <category><![CDATA[american-workers]]></category>
            <category><![CDATA[foreign-workers]]></category>
            <category><![CDATA[cybersecurity]]></category>
            <category><![CDATA[national-security]]></category>
            <dc:creator><![CDATA[Colin Bitterfield]]></dc:creator>
            <pubDate>Wed, 24 Sep 2025 20:54:52 GMT</pubDate>
            <atom:updated>2025-09-24T20:54:52.101Z</atom:updated>
            <content:encoded><![CDATA[<h3>The Great American Betrayal: How H1-B and F1 Visas Enabled $600 Billion Wealth Transfer While Handing Critical Infrastructure to Foreign Adversaries</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AfNhoQxtqsSfugN7x_LvQQ.png" /></figure><h3>The Great American Betrayal: How H1-B and F1 Visas Enabled $600 Billion Wealth Transfer While Handing Critical Infrastructure to Foreign Adversaries</h3><p>The $100,000 annual fee President Trump imposed on H1-B visas represents the most aggressive attempt yet to address a program that has systematically transferred hundreds of billions of dollars in American wages to foreign workers while displacing millions of US employees. The policy, which took effect September 21, 2025, finally puts a real cost on what has become one of the largest wealth transfer schemes in American history — but the fees are insufficient and miss the broader F1-H1-B pipeline that has created America’s greatest national security vulnerability.</p><p><strong>Note: The $100,000 fee applies to the initial 3-year H1-B visa application, not an annual payment.</strong></p><p><strong>PART I: THE CASE — THE SCALE OF THE BETRAYAL</strong></p><p><strong>Executive Summary: America’s Greatest Strategic Vulnerability</strong></p><p>On Friday evening, September 19, 2025, President Trump signed a proclamation that fundamentally altered the H1-B visa landscape¹. The new $100,000 fee — described by the White House as targeting companies that “spam the system and drive down wages” — comes after decades of documented abuse that has displaced American workers while funneling tens of billions annually to India and China through below-market wages and remittances.</p><p>The timing reflects growing evidence of the program’s transformation from addressing skill shortages to enabling systematic worker replacement. As Trump’s proclamation noted, unemployment in computer occupations jumped from 1.98% in 2019 to 3.02% in 2025, even as companies laid off 85,000 American workers while hiring 34,000 new H1-B workers in 2022 alone².</p><p><strong>However, the H1-B program represents only half the problem.</strong> When combined with 1.6 million F1 student visa holders, America currently hosts <strong>2.2 million foreign nationals in strategic educational and employment positions</strong>, creating the largest peacetime transfer of strategic capabilities in American history.</p><p><strong>The National Security Catastrophe: Foreign Control of America’s Digital Defense</strong></p><p><strong>CRITICAL ALERT: 81% of cybersecurity functions are outsourced — the highest outsourcing rate of any technology sector.</strong> This represents the most dangerous transfer of national security capabilities in American history.</p><p>The scale of combined F1-H1-B dependency extends far beyond economic displacement to pose an existential national security threat. With approximately 600,000 H1-B workers and 1.6 million F1 students currently in the United States, the vast majority concentrated in critical technology sectors, America has essentially handed control of its digital infrastructure to foreign nationals who maintain primary loyalty to their home countries.</p><p><strong>The Complete Foreign Workforce Analysis: 2.2 Million Strategic Positions</strong></p><p>When combined with the 1.6 million F1 student visa holders, <strong>America currently hosts 2.2 million foreign nationals in strategic educational and employment positions</strong>, with the vast majority from India (73% of H1-B, 29.4% of F1) and China (12% of H1-B, 24.6% of F1).</p><p><strong>The F1-to-H1-B Pipeline:</strong></p><ul><li><strong>896,000 F1 students in STEM fields</strong> (56% of all international students)</li><li><strong>95,384 students on STEM OPT</strong> gaining work experience</li><li><strong>~65,000 new H1-B positions</strong> approved annually (mostly STEM)</li><li><strong>~600,000 total H1-B workers</strong> currently employed</li></ul><p>This creates a systematic 6–10 year pathway from foreign university training directly into America’s most critical technology positions.</p><p><strong>H1-B Workers Control Critical Infrastructure</strong></p><p>The cybersecurity workforce employs approximately 182,800 information security analysts according to the Bureau of Labor Statistics, but <strong>81% of cybersecurity functions are outsourced</strong> — meaning foreign workers control America’s digital defense systems. With 3.5 million unfilled cybersecurity positions globally, this dependency has created a national security emergency where:</p><ul><li><strong>Foreign nationals design America’s cybersecurity protocols</strong></li><li><strong>Hostile nation citizens control access to critical infrastructure</strong></li><li><strong>America’s digital defense strategies are visible to adversaries</strong></li><li><strong>Cybersecurity incident response is managed by foreign entities</strong></li></ul><p><strong>Complete H1-B Worker Distribution by Security Risk (Total: ~600,000 workers)</strong></p><p><strong>🔴 CRITICAL NATIONAL SECURITY POSITIONS (77,340 workers — 12.9%)</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NYJwOjQENDODQxHCoXwN8Q.png" /></figure><p><strong>🟡 HIGH NATIONAL SECURITY RISK POSITIONS (186,420 workers — 31.1%)</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C7suxADkXQokQMnzax9uIw.png" /></figure><p><strong>CRITICAL FINDING:</strong> <strong>263,760 H1-B workers (44.0%) occupy CRITICAL to HIGH national security risk positions</strong>, with direct access to America’s most sensitive technology infrastructure.</p><p><strong>F1 Student Distribution by National Security Criticality (Total: ~1.6 million students)</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YzCxg1lfFvLGvveVe6wViA.png" /></figure><p><strong>CRITICAL FINDING:</strong> <strong>661,150 F1 students (41.3% of all international students)</strong> are studying in fields with CRITICAL to HIGH national security implications, primarily from India and China.</p><p><strong>The AI Infiltration Crisis: Foreign Control of America’s Most Strategic Technology</strong></p><p>Beyond cybersecurity vulnerabilities lies an even more insidious threat: the systematic foreign penetration of America’s artificial intelligence infrastructure. With AI becoming the defining technology of the 21st century — projected to contribute $15.7 trillion to the global economy by 2035 — America’s dependence on foreign workers in this critical sector represents the transfer of our most strategic technological advantage.</p><p><strong>Combined AI/ML Pipeline Analysis:</strong></p><ul><li><strong>32,800 F1 students in AI/Machine Learning</strong> (2.1% of all international students)</li><li><strong>189,750 F1 students in Computer Science</strong> (11.9% of all international students)</li><li><strong>24,500 H1-B workers in AI/ML roles</strong> (4.1% of all H1-B workers)</li><li><strong>27,875 H1-B Software Engineers</strong> (many in AI-adjacent roles)</li></ul><p><strong>Total AI-Related Foreign Nationals: ~275,000</strong></p><p>This represents <strong>37% of America’s estimated AI engineering workforce</strong>, with the vast majority from countries with documented histories of intellectual property theft and strategic competition with the United States.</p><p><strong>Major Tech Companies’ AI Vulnerability:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6Be6k4JOEHQBx63b9Vyckg.png" /></figure><p><strong>The implications are catastrophic:</strong> foreign nationals from strategic competitor countries control significant portions of America’s AI development, from algorithm architecture to training data access to deployment strategies.</p><p><strong>The $600 Billion Wealth Transfer: Economic Warfare Through Legal Channels</strong></p><p><strong>Annual Wealth Transfer Breakdown:</strong></p><p>The scale of wealth transfer through combined F1-H1-B programs becomes clear when examining multiple economic flows:</p><p><strong>Direct Remittances:</strong></p><ul><li><strong>$35 billion annually</strong> to India from H1-B workers (28% of India’s $125B total)</li><li><strong>$50 billion annually</strong> to China from all sources (significant H1-B portion)</li><li><strong>$85+ billion total</strong> in direct remittances from foreign workers</li></ul><p><strong>Wage Suppression:</strong></p><ul><li><strong>83% of H1-B positions</strong> certified at below-median wages</li><li><strong>Level 1 workers earn 17% below market rates</strong></li><li><strong>Level 2 workers earn 34% below market rates</strong></li><li><strong>$15–25 billion annually</strong> in suppressed American wages</li></ul><p><strong>Educational Revenue:</strong></p><ul><li><strong>$43.8 billion annually</strong> from F1 students to American universities</li><li>Creates institutional dependency on foreign students</li><li>Subsidizes foreign access to cutting-edge research</li></ul><p><strong>Intellectual Property Theft:</strong></p><ul><li><strong>$225–600 billion annually</strong> in documented IP theft (mostly China)</li><li><strong>H1-B and F1 workers provide legal access</strong> to facilitate systematic theft</li><li><strong>Technology transfer</strong> through academic and corporate networks</li></ul><p><strong>Total Economic Impact: $600+ Billion Annually</strong></p><p><strong>The Foreign Education Subsidy Advantage</strong></p><p>A critical dimension involves the unfair competitive advantage foreign nationals receive through government-subsidized education and <strong>additional taxpayer subsidies through FICA tax exemptions</strong>:</p><p><strong>Educational Cost Comparison:</strong></p><ul><li><strong>Indian technical institutes (IITs)</strong>: $1,000–3,000 annually</li><li><strong>Chinese universities</strong>: Near-free engineering education for citizens</li><li><strong>American universities</strong>: $50,000–80,000 annually for equivalent programs</li><li><strong>American student debt burden</strong>: $37,000 average, up to $100,000+ for advanced degrees</li></ul><p><strong>Hidden Taxpayer Subsidy Through FICA Tax Exemptions:</strong> <strong>F1 students provide companies with a 15.3% total cost advantage over hiring American workers</strong> through Social Security and Medicare tax exemptions:</p><ul><li><strong>F1 visa holders are EXEMPT from FICA taxes</strong> (Social Security and Medicare) for their first 5 calendar years in the US</li><li><strong>Companies save 7.65%</strong> in employer FICA contributions (6.2% Social Security + 1.45% Medicare)</li><li><strong>Students save 7.65%</strong> in employee FICA contributions, making them willing to accept lower wages</li><li><strong>Total advantage: 15.3%</strong> cost reduction compared to hiring American workers</li><li><strong>Duration: Up to 5 years</strong>, covering most degree programs plus OPT periods</li></ul><p><strong>H1-B Workers Pay Full FICA Taxes:</strong></p><ul><li><strong>H1-B visa holders are REQUIRED to pay FICA taxes</strong> same as US citizens (15.3% total)</li><li><strong>No exemptions available</strong> based on H1-B visa status</li><li><strong>Immediate transition</strong>: When F1 students change to H1-B status, FICA taxes begin immediately</li></ul><p><strong>The F1-to-H1-B Tax Arbitrage:</strong> This creates a systematic 10-year cost advantage for foreign nationals:</p><ol><li><strong>Years 1–5</strong>: F1 status with 15.3% FICA tax exemption advantage</li><li><strong>Years 6–10</strong>: H1-B status with 20–34% below-market wage advantage</li><li><strong>American workers</strong>: Pay full FICA taxes from day one AND face wage suppression from foreign competition</li></ol><p><strong>Taxpayer Subsidization of Foreign Worker Preference:</strong> This system forces American taxpayers to subsidize companies’ preference for foreign workers:</p><ul><li><strong>Social Security and Medicare programs</strong> receive less funding due to F1 exemptions</li><li><strong>American workers pay higher relative tax rates</strong> while competing against tax-exempt foreign workers</li><li><strong>Companies receive taxpayer-funded cost advantages</strong> for choosing foreign over American workers</li><li><strong>Educational institutions become dependent</strong> on international student revenue while displacing American students</li></ul><p>This creates systematic competitive disadvantage where debt-free, tax-exempt foreign workers can underbid American workers who must service educational debt while paying full tax rates from the start of their careers.</p><p><strong>Corporate Giants’ Billion-Dollar Bills — But Fees Are Still Too Low</strong></p><p>The immediate impact on major H1-B employers reveals both the program’s scale and the inadequacy of Trump’s proposed fees:</p><p><strong>Top H1-B Employers Analysis:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ggYj4nv6v0_JDNQ7sT6NiA.png" /></figure><p><strong>🔴 CRITICAL POLICY FAILURE: $100K FEES INSUFFICIENT TO CHANGE BEHAVIOR</strong></p><p><strong>The harsh reality is that Trump’s $100,000 H1-B fee, while generating headlines, is insufficient to eliminate the systematic displacement of American workers.</strong> For major technology companies generating tens of billions in annual profits, these fees represent operational expenses rather than behavioral deterrents.</p><p><strong>Critical Clarification: The $100,000 fee applies to the initial 3-year H1-B visa, making the effective annual cost only $33,333 per worker.</strong></p><p><strong>Economic Analysis Reveals Continued Profitability of Displacement:</strong></p><p>Even with the $100K one-time fee, companies save money compared to paying correct American wages:</p><ul><li><strong>Average H1-B underpayment</strong>: $34,890 annually per worker (20% below market rates)</li><li><strong>3-year total savings from wage suppression</strong>: $104,670 per worker</li><li><strong>$100K visa fee</strong>: Still $4,670 cheaper than paying correct wages over 3 years</li><li><strong>Annual effective cost</strong>: Only $33,333 per year vs. $34,890 in annual wage savings</li><li><strong>Net result</strong>: Companies still save $1,557 annually per worker while continuing systematic displacement</li></ul><p><strong>Required Fee Levels for Genuine Reform:</strong></p><ul><li><strong>Minimum H1-B fee needed</strong>: $157,000 per 3-year visa (50% above wage suppression savings)</li><li><strong>Effective annual cost</strong>: $52,333 per year (above the $34,890 annual wage savings)</li><li><strong>Current proposed fee</strong>: $100,000 (insufficient by $57,000)</li><li><strong>F1 fee should be</strong>: $40,000 annually (currently proposed $25,000 too low)</li></ul><p><strong>Documented Displacement at Industrial Scale</strong></p><p>Trump’s proclamation references specific examples of displacement: one software company approved for 5,000 H1-B workers while announcing 15,000 layoffs; another IT firm approved for 1,700 H1-B workers while laying off 2,400 Americans in Oregon.</p><p>These patterns echo documented cases from the 2010s. At Disney World in 2014, 250 IT workers spent their final 90 days training H1-B replacements from Indian consulting firms, with one displaced worker testifying to Congress: “Never in my life did I imagine that I could be sitting at my desk and somebody would be flown in from another country, sit at my same desk and chair, and take over what I was doing.”</p><p><strong>The F1-to-Displacement Pipeline:</strong></p><ol><li><strong>281,675 F1 students in Computer Science</strong> (42% from India, 28% from China)</li><li><strong>95,384 students on STEM OPT</strong> gaining work experience at American companies</li><li><strong>Transition to H1-B status</strong> for permanent displacement of American workers</li><li><strong>Knowledge transfer to offshore operations</strong> in home countries</li></ol><p><strong>The Cybersecurity Crisis: Escalating Breaches Under Foreign Control</strong></p><p><strong>With 81% of cybersecurity functions outsourced to foreign nationals, America has experienced a dramatic escalation in cyber incidents coinciding with increased foreign workforce penetration in critical security roles.</strong></p><p><strong>Annual Cybersecurity Incidents vs. IP Theft Prosecutions (2014–2024)</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NCDvT2uWe2VwwbgVY5ajHA.png" /></figure><p><strong>Key Correlations:</strong></p><ul><li><strong>400% increase in cyber incidents</strong> (2014–2021) coinciding with peak H1-B displacement</li><li><strong>IP theft prosecutions increased 688%</strong> (2014–2024) as foreign workforce expanded</li><li><strong>Major breaches increasingly involve foreign contractors</strong> with legitimate access</li></ul><p><strong>Documented Intellectual Property Theft: The $225–600 Billion Annual Heist</strong></p><p>The FBI’s counterintelligence data reveals the true scope of technology transfer to hostile nations. FBI Director Christopher Wray reports the FBI opens a new Chinese counterintelligence investigation every 12 hours, with over 1,000 cases involving Chinese nationals.</p><p><strong>Recent Major Cases:</strong></p><ul><li><strong>Google AI Technology Theft</strong>: Chinese Google engineer Linwei Ding charged with stealing 1,000+ files of AI technology, including TPU and GPU trade secrets</li><li><strong>Operation CuckooBees</strong>: Chinese APT 41 stole trillions in IP from 30 companies, including fighter jet blueprints and pharmaceutical formulas</li><li><strong>Academic-to-Corporate Pipeline</strong>: Multiple cases show F1 students transitioning to H1-B status while maintaining systematic technology transfer</li></ul><p><strong>The F1-H1-B Intelligence Network:</strong> The combination creates unprecedented intelligence collection opportunities:</p><ul><li><strong>Academic research access</strong> through F1 status at top universities</li><li><strong>Corporate insider access</strong> through H1-B employment</li><li><strong>Long-term relationship building</strong> over 6–10 year periods</li><li><strong>Legal framework</strong> protecting information gathering activities</li></ul><p><strong>Congressional Recognition and Systematic Failure</strong></p><p>Bipartisan congressional investigations between 2015–2017 documented extensive displacement, but failed to address the educational pipeline component. Representative Judy Chu stated: “Replacing American workers with temporary foreign workers for the purpose of driving wages down most definitely must not be the program’s intent.”</p><p>Despite overwhelming evidence — record fraud settlements, congressional testimony, extensive documentation — enforcement remained minimal, highlighting regulatory capture that market-based mechanisms must now circumvent.</p><p><strong>PART II: THE SOLUTIONS — COMPREHENSIVE REFORM BLUEPRINT</strong></p><p><strong>Trump’s Fee Structure: Right Direction, Insufficient Scale</strong></p><p>President Trump’s $100,000 H1-B fee represents recognition of the systematic abuse, but analysis reveals the fees are insufficient to change corporate behavior. <strong>Comprehensive reform requires both higher fees and structural changes to address the F1-H1-B pipeline.</strong></p><p><strong>Corrected Fee Structure for Behavioral Change:</strong></p><p><strong>H1-B Visa Fees:</strong></p><ul><li><strong>Current proposed</strong>: $100,000 per 3-year visa ($33,333 annually — insufficient)</li><li><strong>Required minimum</strong>: $157,000 per 3-year visa ($52,333 annually — above wage suppression savings)</li><li><strong>Recommended</strong>: $175,000 per 3-year visa ($58,333 annually — to ensure American workers are clearly more attractive)</li></ul><p><strong>F1 Visa Fees:</strong></p><ul><li><strong>Current proposed</strong>: $25,000 annually (too low)</li><li><strong>Required minimum</strong>: $40,000 annually</li><li><strong>For critical fields</strong>: $50,000 annually (AI, cybersecurity, quantum computing)</li></ul><p><strong>Combined Revenue Potential:</strong></p><ul><li><strong>H1-B fees</strong>: $14.9 billion every 3 years ($4.97 billion annually at corrected rates)</li><li><strong>F1 fees</strong>: $19.8 billion annually</li><li><strong>Total</strong>: $24.8 billion annually for American workforce development</li></ul><p><strong>Immediate National Security Measures</strong></p><p><strong>Emergency Security Reviews</strong></p><p><strong>All foreign nationals currently in CRITICAL positions must undergo immediate comprehensive background checks:</strong></p><ul><li><strong>Temporary suspension</strong> from critical systems during 30-day review</li><li><strong>FBI background investigation</strong> with polygraph examination</li><li><strong>Financial audit</strong> including international transfers and family contacts</li><li><strong>Communication monitoring</strong> of international contacts and social media</li><li><strong>Automatic termination</strong> if any security concerns identified</li><li><strong>No exceptions</strong> for length of service or past clearances</li></ul><p><strong>Mandatory Annual Security Review Requirements</strong></p><p><strong>🔴 CRITICAL POSITIONS</strong> (Annual FBI Background Check + Polygraph):</p><ul><li>All cybersecurity roles (analysts, engineers, architects)</li><li>AI/ML development and research positions</li><li>Critical infrastructure roles (power, water, transportation, finance)</li><li>Defense contractor positions with security clearance</li><li>Positions with access to classified or proprietary algorithms</li></ul><p><strong>🟡 HIGH-RISK POSITIONS</strong> (Annual FBI Background Check):</p><ul><li>Software engineering at major technology companies</li><li>Database administrators with sensitive data access</li><li>Cloud architects and DevOps engineers</li><li>Network administrators and system engineers</li><li>University research with defense funding</li></ul><p><strong>Background Check Requirements:</strong></p><ol><li><strong>Foreign Contact Verification</strong>: All family, associates, professional contacts</li><li><strong>Financial Audit</strong>: Bank accounts, investments, debt, money transfers</li><li><strong>Communication Monitoring</strong>: Social media, messaging, international communications</li><li><strong>Travel Pattern Analysis</strong>: All international travel and contacts made</li><li><strong>Technology Access Logging</strong>: Systems accessed, data downloaded, information shared</li><li><strong>Professional Network Mapping</strong>: Colleagues, mentors, associations in home countries</li></ol><p><strong>Structural Program Reforms</strong></p><p><strong>H1-B Program Overhaul</strong></p><p><strong>Automatic Visa Termination:</strong> H1-B visas automatically terminate after 36 months maximum, eliminating current six-year extensions that enable indefinite worker replacement.</p><p><strong>Mandatory Job Market Testing:</strong> Companies must demonstrate genuine inability to fill positions by posting all H1-B jobs on USAJobs.gov for minimum 180 days before filing petitions.</p><p><strong>Skills Training Requirements:</strong> Companies must demonstrate active, funded programs to train American workers for identical roles, with specific timelines, budgets, and measurable outcomes for transferring skills.</p><p><strong>Prevailing Wage Reform:</strong> Mandate wages at 90th percentile of regional rates to eliminate underpayment advantages that make displacement profitable.</p><p><strong>American Worker Priority:</strong> Companies must offer identical relocation packages and student loan repayment benefits to American workers in comparable positions.</p><p><strong>F1 Program Restrictions</strong></p><p><strong>Duration Limits:</strong> F1 visas limited to three years maximum, eliminating indefinite education extensions that serve as backdoor immigration pathways.</p><p><strong>Critical Field Restrictions:</strong> F1 students from strategic competitor nations face enrollment restrictions in:</p><ul><li>Artificial Intelligence and Machine Learning</li><li>Cybersecurity and Information Security</li><li>Quantum Computing and Advanced Physics</li><li>Advanced Engineering with dual-use applications</li><li>Computer Science with defense applications</li></ul><p><strong>Elimination of FICA Tax Arbitrage:</strong> <strong>Employers must pay the full 7.65% employer portion of FICA taxes for all F1 students regardless of student exemption status.</strong> This critical reform would:</p><ul><li><strong>Eliminate the 7.65% employer cost advantage</strong> companies currently receive for hiring F1 students over Americans</li><li><strong>Remove economic incentive</strong> for systematic preference of foreign students in hiring decisions</li><li><strong>Generate additional Social Security/Medicare revenue</strong> to offset the impact of student exemptions</li><li><strong>Level the playing field</strong> between American workers and F1 students from an employer cost perspective</li><li><strong>Maintain student exemption</strong> for the employee portion while eliminating employer subsidy</li></ul><p><strong>Implementation:</strong> Companies employing F1 students must remit the full employer FICA contribution (7.65%) to the Treasury, with funds specifically allocated to Social Security and Medicare trust funds. This eliminates taxpayer subsidization of corporate hiring preferences while maintaining the student benefit.</p><p><strong>University Accountability Requirements:</strong></p><ul><li>Limit F1 enrollment from competitor nations to 10% per critical program</li><li>Report all research collaborations with foreign entities</li><li>Demonstrate American student priority in competitive programs</li><li>Maintain technology transfer restrictions for international students</li></ul><p><strong>Enhanced Corporate Transparency</strong></p><p><strong>Mandatory SEC Reporting Requirements for All Publicly Listed Companies:</strong></p><p>All publicly traded companies must provide quarterly SEC filings with the following detailed employment disclosures:</p><p><strong>Core Employment Metrics (Via IRS W-2 Reporting):</strong></p><ul><li><strong>Total W-2 employees by unique SSN</strong> (no distinction between part-time/full-time)</li><li><strong>W-2 employees by citizenship status</strong> (US citizens vs. work authorization holders)</li><li><strong>H1-B visa holders by job category</strong> and average compensation</li><li><strong>Monthly workforce changes</strong>: Workers displaced, laid off, terminated, or hired</li></ul><p><strong>Economic Class Distribution Reporting:</strong> All public companies must disclose employee compensation distribution by economic class:</p><p><strong>Government Assistance Recipients:</strong></p><ul><li><strong>Number of employees receiving Medicaid</strong> or other government-sponsored health insurance</li><li><strong>Number of employees receiving SNAP</strong> (Supplemental Nutrition Assistance Program/Food Stamps)</li><li><strong>Number of employees receiving Section 8 housing assistance</strong> or other housing subsidies</li><li><strong>Number of employees receiving WIC</strong> (Women, Infants, and Children nutrition program)</li><li><strong>Number of employees receiving TANF</strong> (Temporary Assistance for Needy Families)</li><li><strong>Number of employees receiving EITC</strong> (Earned Income Tax Credit)</li><li><strong>Number of employees receiving Childcare assistance</strong> or subsidies</li><li><strong>Number of employees receiving utility assistance</strong> programs</li><li><strong>Total employees receiving any form of government assistance</strong> (unduplicated count)</li><li><strong>Percentage of workforce requiring government assistance</strong> to meet basic needs</li><li><strong>Estimated annual taxpayer cost</strong> to subsidize underpaid workforce</li></ul><p><strong>Minimum Wage Workers:</strong></p><ul><li><strong>Number of employees at federal minimum wage</strong> ($7.25/hour or $15,080 annually)</li><li><strong>Number of employees at state/local minimum wage</strong> by jurisdiction</li><li><strong>Percentage of total workforce</strong> earning minimum wage rates</li></ul><p><strong>Living Wage Workers:</strong></p><ul><li><strong>Number of employees earning living wage</strong> (defined as sufficient to cover basic needs without government assistance)</li><li><strong>Living wage calculations by geographic region</strong> where employees work or reside</li><li><strong>Gap analysis</strong> showing employees below living wage thresholds</li></ul><p><strong>Middle Class Workers:</strong></p><ul><li><strong>Number of employees earning middle class wages</strong> (annual salary equal to 1/2 of median house price)</li><li><strong>Geographic calculation basis</strong>: National median house price OR zip code median where employee works/resides (for remote workers)</li><li><strong>Current thresholds</strong>:</li><li><strong>National</strong>: ~$220,000 annually (1/2 of ~$440,000 national median home price)</li><li><strong>By zip code</strong>: Varies by local housing markets (e.g., San Francisco ~$600K, Cleveland ~$85K)</li><li><strong>Middle class percentage</strong> of total workforce by location</li></ul><p><strong>High Earners:</strong></p><ul><li><strong>Number of employees earning $300,000-$500,000 annually</strong> including:</li><li>Base salary in this range</li><li>Total compensation (salary + bonuses) in this range</li><li>Valued stock options/equity bringing total compensation into this range</li><li><strong>Number of employees earning $500,000-$750,000 annually</strong> (all compensation sources)</li><li><strong>Number of employees earning $750,000-$1,000,000 annually</strong> (all compensation sources)</li><li><strong>Number of employees earning $1,000,000-$2,000,000 annually</strong> (all compensation sources)</li><li><strong>Number of employees earning $2,000,000-$5,000,000 annually</strong> (all compensation sources)</li><li><strong>Number of employees earning over $5,000,000 annually</strong> (all compensation sources)</li><li><strong>Executive vs. non-executive breakdown</strong> for each compensation band</li><li><strong>Total high earners over $300,000</strong> (unduplicated count across all bands)</li></ul><p><strong>America First Executive Compensation Requirements:</strong> For all publicly traded companies, <strong>CEO and C-Suite bonus compensation must be tied to America First performance metrics</strong>, not just financial profits:</p><p><strong>Mandatory Bonus Criteria (Minimum 60% of total bonus calculation):</strong></p><ul><li><strong>American Job Creation</strong>: 25% of bonus tied to net increase in W-2 American citizen employees</li><li><strong>Living Wage Achievement</strong>: 20% of bonus tied to percentage of workforce earning living wage or higher</li><li><strong>Middle Class Job Creation</strong>: 15% of bonus tied to employees achieving middle-class compensation (½ of local median home price)</li></ul><p><strong>Bonus Penalties for Anti-American Practices:</strong></p><ul><li><strong>10% bonus reduction</strong> for every 1% of workforce on government assistance programs</li><li><strong>25% bonus reduction</strong> for any mass layoffs followed by H1-B hiring within 24 months</li><li><strong>50% bonus reduction</strong> for offshoring jobs to foreign countries</li><li><strong>100% bonus forfeiture</strong> for documented worker displacement schemes or systematic preference for foreign workers</li></ul><p><strong>Traditional Financial Metrics (Maximum 40% of bonus calculation):</strong></p><ul><li>Profit margins, stock performance, revenue growth may comprise no more than 40% of total bonus structure</li></ul><p><strong>Public Disclosure Requirements:</strong></p><ul><li><strong>Quarterly reporting</strong> of all bonus calculation components and actual payments</li><li><strong>Detailed explanation</strong> of how America First metrics were achieved or missed</li><li><strong>Comparison with peer companies</strong> on worker compensation and citizenship ratios</li></ul><p><strong>The Boeing Lesson — Why Profit-Only Incentives Fail:</strong> Boeing’s executives received massive bonuses while:</p><ul><li><strong>Cutting American engineering jobs</strong> and outsourcing to foreign contractors</li><li><strong>Prioritizing short-term profits</strong> over long-term safety and quality</li><li><strong>346 people died</strong> in two 737 MAX crashes due to cost-cutting measures</li><li><strong>American aerospace leadership</strong> was compromised by foreign dependency</li></ul><p><strong>America First compensation would have prevented this by:</strong></p><ul><li><strong>Penalizing job cuts</strong> and foreign outsourcing in bonus calculations</li><li><strong>Rewarding investment</strong> in American engineering talent and manufacturing capability</li><li><strong>Aligning executive incentives</strong> with national competitiveness rather than just quarterly profits</li><li><strong>Creating accountability</strong> for long-term American industrial strength</li></ul><p><strong>Contractor and Outsourcing Transparency:</strong></p><ul><li><strong>Number of 1099 contractors</strong> with access to data systems or customer information</li><li><strong>Outsourced contractors by location</strong> (domestic vs. offshore)</li><li><strong>Foreign contractors with system access</strong> by country of origin and access level</li><li><strong>Percentage of critical functions</strong> performed by contractors vs. W-2 employees</li><li><strong>Contractor compensation ranges</strong> by function and location</li></ul><p><strong>Technology Access and Security:</strong></p><ul><li><strong>Foreign nationals with access</strong> to proprietary systems, customer data, or intellectual property</li><li><strong>Contractors with administrative privileges</strong> on corporate networks</li><li><strong>Third-party access to sensitive data</strong> including cloud services and integrated platforms</li><li><strong>Security clearance status</strong> of all personnel with classified or sensitive access</li></ul><p><strong>Displacement and Workforce Planning:</strong></p><ul><li><strong>American workers displaced</strong> in connection with H1-B hiring or offshore outsourcing</li><li><strong>Jobs eliminated</strong> vs. jobs created by geographic region</li><li><strong>Skills training programs</strong> and measurable outcomes for American worker development</li><li><strong>Severance costs</strong> and displacement-related expenses</li></ul><p><strong>Economic Impact Analysis:</strong></p><ul><li><strong>Wage distribution changes</strong> year-over-year by economic class</li><li><strong>Geographic wage analysis</strong> comparing local vs. remote worker compensation</li><li><strong>Housing affordability metrics</strong> for workforce by location</li><li><strong>Income inequality ratios</strong> within the company (CEO pay vs. median worker pay)</li></ul><p><strong>Investment and Policy Disclosure:</strong></p><ul><li><strong>Total visa fees paid</strong> annually for H1-B and other work authorization programs</li><li><strong>Offshore outsourcing contracts</strong> by value and function type</li><li><strong>Corporate policies</strong> regarding American worker priority and training requirements</li><li><strong>International workforce strategy</strong> and foreign talent dependency ratios</li></ul><p><strong>Standardized Reporting Format:</strong> All companies must use standardized SEC forms enabling investor comparison of:</p><ul><li><strong>Economic class distribution</strong> across different companies and industries</li><li><strong>True employment composition</strong> (W-2 vs. contractor ratios)</li><li><strong>Foreign workforce dependency</strong> across different business functions</li><li><strong>American worker displacement patterns</strong> and replacement strategies</li><li><strong>Real job creation</strong> vs. contractor relationships that extract value</li><li><strong>Wage progression opportunities</strong> within company structure</li></ul><p><strong>Geographic Calculation Methodology:</strong></p><ul><li><strong>Remote workers</strong>: Use zip code of employee’s primary residence</li><li><strong>Office workers</strong>: Use zip code of primary work location</li><li><strong>Hybrid workers</strong>: Use zip code providing most accurate housing cost comparison</li><li><strong>Multi-location workers</strong>: Use location where employee spends &gt;50% of work time</li><li><strong>Housing price data</strong>: Updated quarterly using official real estate indices</li></ul><p><strong>Investor Protection Through Transparency:</strong> This reporting enables investors to:</p><ul><li><strong>Assess taxpayer subsidization</strong> of corporate profits through underpaid workers</li><li><strong>Evaluate true cost of employment</strong> including government assistance burden</li><li><strong>Identify corporate welfare recipients</strong> that privatize profits while socializing worker support costs</li><li><strong>Assess wage sustainability</strong> and employee retention risks</li><li><strong>Evaluate genuine middle-class job creation</strong> vs. exploitation of low-wage workers</li><li><strong>Understand economic impact</strong> on local communities where companies operate</li><li><strong>Compare workforce equity</strong> across competing companies</li><li><strong>Assess operational risks</strong> from foreign workforce dependency</li><li><strong>Identify companies creating genuine economic opportunity</strong> vs. value extraction</li></ul><p><strong>Enforcement and Penalties:</strong></p><ul><li><strong>False reporting penalties</strong>: Automatic SEC violations for misrepresenting employment data</li><li><strong>Whistleblower protections</strong>: Enhanced protections for employees reporting workforce misrepresentation</li><li><strong>Audit requirements</strong>: Mandatory annual third-party audits of employment reporting for companies with &gt;10,000 employees</li><li><strong>Public database</strong>: SEC maintains searchable public database of all workforce reporting data</li><li><strong>Geographic verification</strong>: Cross-reference with IRS data to verify employee location reporting</li></ul><p>This transparency requirement would expose companies that claim job creation while paying poverty wages, reveal true middle-class job creation impact, show the stark compensation gaps between executives earning millions and workers struggling to afford housing in the same communities where they work, <strong>and force disclosure of how many “profitable” companies are actually subsidized by taxpayers through government assistance programs for their underpaid workers</strong>.</p><p><strong>Mandatory Displacement Severance:</strong> Companies eliminating American positions within 24 months of hiring H1-B workers must provide:</p><ul><li>24 months base severance for all displaced workers</li><li>Additional 2 months per year of service beyond 5 years</li><li>Full health insurance continuation during severance period</li><li>Career transition services and job placement assistance</li><li>Accelerated vesting of retirement benefits and stock options</li></ul><p><strong>American Workforce Development Initiative</strong></p><p><strong>H1-B Fee Revenue Investment Strategy</strong></p><p><strong>$49 billion in annual revenue should fund comprehensive American worker competitiveness:</strong></p><p><strong>Debt-Free STEM Education:</strong></p><ul><li><strong>$98,000 per graduate</strong>: Fund 500,000 debt-free American STEM graduates annually</li><li><strong>Student loan elimination</strong>: Target existing debt for Americans in high-demand technical fields</li><li><strong>Skills-focused curriculum</strong>: Emphasize current industry practices over theoretical coursework</li></ul><p><strong>Corporate Training Mandates:</strong></p><ul><li>Companies using H1-B workers must establish corresponding American training programs</li><li>Specific targets for transitioning work from foreign to American workers</li><li>University partnerships offering internships, co-ops, direct employment pathways</li></ul><p><strong>Regional Skills Centers:</strong></p><ul><li>Establish training centers in areas with high H1-B concentration</li><li>Focus on AI, cybersecurity, advanced manufacturing, biotechnology</li><li>Provide pathways from training directly to employment at competitive wages</li></ul><p><strong>Competitive Advantage Restoration</strong></p><p><strong>Educational Cost Reduction:</strong></p><ul><li>Federal grants for American students in critical STEM fields</li><li>Partnerships between government agencies and universities</li><li>Direct funding for practical skills development programs</li></ul><p><strong>American Innovation Incentives:</strong></p><ul><li>Tax credits for companies hiring American workers over foreign alternatives</li><li>R&amp;D tax benefits tied to American worker employment ratios</li><li>Government contract preferences for companies with majority American technical workforces</li></ul><p><strong>International Coordination and Enforcement</strong></p><p><strong>Allied Nation Coordination</strong></p><p><strong>Democratic Partner Standards:</strong> Coordinate with countries sharing democratic values to ensure responsible actors maintain technological leadership while authoritarian regimes face systematic disadvantages.</p><p><strong>Technology Transfer Restrictions:</strong> Implement export controls treating AI algorithms and training methodologies as controlled dual-use technologies, with enhanced monitoring of foreign nationals’ access.</p><p><strong>Academic Research Restrictions:</strong> Universities receiving federal funding prohibited from employing foreign nationals from strategic competitor nations in research with potential military or surveillance applications.</p><p><strong>Enforcement Mechanisms</strong></p><p><strong>Department of Justice Investigations:</strong> Launch immediate investigations into companies with documented patterns of worker displacement identified in congressional hearings and whistleblower complaints.</p><p><strong>Real-Time Monitoring Systems:</strong></p><ul><li>Track all H1-B and F1 holder movements between companies</li><li>Monitor technology access patterns and data downloads</li><li>Flag suspicious patterns for immediate investigation</li><li>Coordinate with intelligence agencies on threat assessment</li></ul><p><strong>Visa Revocation Authority:</strong> Immediate termination capability for any visa holder showing security concerns, with no appeal process during active investigation.</p><p><strong>Technology Sovereignty Restoration</strong></p><p><strong>American AI Dominance Initiative</strong></p><p><strong>National AI Workforce Program:</strong></p><ul><li>Train 1 million Americans in AI development over 5 years</li><li>Focus on military, cybersecurity, and critical infrastructure applications</li><li>Guarantee employment pathways in government and defense contractors</li></ul><p><strong>Secure AI Development:</strong> All AI research with potential military applications restricted to American citizens with appropriate security clearances.</p><p><strong>AI Export Controls:</strong> Treat advanced AI capabilities as strategic weapons, with strict controls on foreign access to development tools, training data, and deployment methodologies.</p><p><strong>Critical Infrastructure Protection</strong></p><p><strong>American-Only Requirements:</strong> Phase in requirements for American citizenship in:</p><ul><li>All cybersecurity positions protecting critical infrastructure</li><li>All AI development roles with potential military applications</li><li>All positions with access to classified or proprietary government systems</li><li>All senior technical roles at defense contractors</li></ul><p><strong>Infrastructure Independence:</strong> Reduce dependency on foreign technical workers through:</p><ul><li>Accelerated training programs for American cybersecurity professionals</li><li>Premium compensation packages to attract American talent</li><li>Career pathway programs from military service to civilian cybersecurity roles</li></ul><p><strong>Conclusion: Restoring American Technological Sovereignty</strong></p><p>The Great American Betrayal through H1-B and F1 visas has created the largest peacetime transfer of strategic capabilities in history. <strong>The $600 billion wealth transfer and foreign control of critical infrastructure represent existential threats that demand comprehensive, immediate action.</strong></p><p><strong>Trump’s $100,000 H1-B fee represents recognition of the problem but fails to provide sufficient deterrent to change corporate behavior.</strong> The proposed solutions outlined above offer a comprehensive pathway to:</p><ol><li><strong>Eliminate the economic incentive</strong> for systematic worker displacement</li><li><strong>Restore American control</strong> of critical technology infrastructure</li><li><strong>End the systematic wealth transfer</strong> to strategic competitor nations</li><li><strong>Create the world’s most competitive</strong> debt-free American technical workforce</li><li><strong>Ensure American technological dominance</strong> in the AI age</li></ol><p><strong>The choice facing America is stark:</strong> Implement comprehensive reform now to restore technological sovereignty, or accept permanent technological dependence on nations that view America’s decline as their opportunity.</p><p><strong>The correlation between foreign workforce expansion and escalating cyber threats, combined with massive IP theft, demands immediate action. America cannot afford to wait while foreign nationals continue controlling critical infrastructure and advanced technology development.</strong></p><p><strong>This is America’s last chance to reverse the Great American Betrayal before foreign control of our most strategic capabilities becomes irreversible. The solutions exist — the question is whether America has the will to implement them.</strong></p><p><strong>References and Data Sources</strong></p><ol><li>White House. “Restriction on Entry of Certain Nonimmigrant Workers.” Presidential Proclamation, September 19, 2025.</li><li>Economic Policy Institute. “Tech and outsourcing companies continue to exploit the H-1B visa program at a time of mass layoffs.” 2023.</li><li>Business Standard. “NRIs in US may soon have to pay ₹5,000 tax on every ₹1 lakh sent to India.” May 16, 2025.</li><li>Fortune. “Over 70% of H-1B visa holders are Indian citizens.” September 22, 2025.</li></ol><p><strong>Key Data Sources:</strong></p><ul><li>U.S. Citizenship and Immigration Services (USCIS) H1-B Employer Data Hub</li><li>U.S. Department of Labor Labor Condition Application Database</li><li>Institute of International Education (IIE) Open Doors Report 2024</li><li>Department of Homeland Security SEVIS Records</li><li>Economic Policy Institute Immigration Research</li><li>FBI Counterintelligence Division Reports</li><li>U.S. Trade Representative IP Theft Assessments</li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=05a806c3890a" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Installing Azure CLI on macOS 15 Without Homebrew: Microsoft Did It Again]]></title>
            <link>https://cbitterfield.medium.com/installing-azure-cli-on-macos-15-without-homebrew-microsoft-did-it-again-fb47dffe8b51?source=rss-f8e598d5fbb1------2</link>
            <guid isPermaLink="false">https://medium.com/p/fb47dffe8b51</guid>
            <category><![CDATA[installing-azure-cli]]></category>
            <category><![CDATA[azure]]></category>
            <category><![CDATA[azure-devops]]></category>
            <dc:creator><![CDATA[Colin Bitterfield]]></dc:creator>
            <pubDate>Tue, 22 Jul 2025 19:19:20 GMT</pubDate>
            <atom:updated>2025-07-22T19:19:20.651Z</atom:updated>
            <content:encoded><![CDATA[<p>A tale of incomplete scripts, virtualenv nightmares, and why MacPorts saves the day</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NUPpseU1Ta7tMvjxPXBDyQ.png" /></figure><h3>The Problem: Microsoft’s “One Size Fits None” Approach</h3><p>Microsoft did it again. 🎭</p><p>You know that feeling when you’re trying to install Azure CLI on your pristine macOS 15 system, and Microsoft’s official installation script assumes you’re living in a Homebrew-only world? Yeah, that feeling. It’s 2025, and apparently, Microsoft still thinks there’s only one package manager on macOS.</p><p><em>Spoiler alert: There isn’t.</em></p><h3>Why Homebrew Makes Me Reach for the Antacid</h3><p>Before we dive into the solution, let’s talk about why some of us avoid Homebrew like it’s a Windows Vista installation disk:</p><h3>Homebrew: The “Friendly” Dictator</h3><ul><li><strong>Opinionated Installation Paths</strong>: Everything goes to /opt/homebrew (Apple Silicon) or /usr/local (Intel). No flexibility.</li><li><strong>Automatic Updates</strong>: Surprise! Your Python just got updated and broke your entire development environment.</li><li><strong>Single Version Philosophy</strong>: Want Python 3.9 and 3.10 simultaneously? Good luck with that.</li><li><strong>Binary Packages</strong>: Less control over compilation flags and optimization.</li></ul><h3>MacPorts: The Swiss Army Knife</h3><p>Enter <a href="https://www.macports.org/">MacPorts</a> — the package manager that actually respects your choices:</p><ul><li><strong>Prefix Flexibility</strong>: Everything lives cleanly in /opt/local by default, but you can change it</li><li><strong>Source-Based</strong>: Compiles packages with your specific system optimizations</li><li><strong>Multiple Versions</strong>: Want Python 3.8, 3.9, AND 3.10? No problem!</li><li><strong>Variants</strong>: Customize packages with specific features enabled/disabled</li><li><strong>Clean Dependency Management</strong>: No mysterious symlink forests</li></ul><h3>Microsoft’s Script: A Comedy of Errors</h3><p>So there I was, trying to install Azure CLI 2.75 on my MacPorts-powered macOS 15 system. Microsoft’s official script? Let me count the ways it failed:</p><h3>Error #1: The Great Virtualenv Disaster</h3><p>bash</p><pre>ERROR: The executable /usr/local/lib/azure-cli/bin/python3.10 is not functioning<br>ERROR: It thinks sys.prefix is &#39;/private/tmp/tmp0dza4yyf/virtualenv-16.7.11&#39; (should be &#39;/usr/local/lib/azure-cli&#39;)<br>ERROR: virtualenv is not compatible with this system or executable</pre><p>Microsoft’s brilliant solution? Use a crusty old virtualenv package (version 16.7.11) from 2019 that’s about as compatible with modern Python as Internet Explorer is with modern web standards.</p><h3>Error #2: Package Manager Blindness</h3><p>The script cheerfully assumes you’re using Homebrew and completely ignores:</p><ul><li>MacPorts at /opt/local</li><li>Custom Python installations</li><li>Any package manager that isn’t Homebrew</li></ul><h3>Error #3: Python Version Russian Roulette</h3><p>Want to choose which Python version to use? Microsoft says: “Take what we give you and like it!” The script grabbed whatever Python it found first, regardless of whether it was suitable.</p><h3>Error #4: Living in the Python Past</h3><p>Here’s where Microsoft really shows their commitment to staying current: their Azure CLI installer only supports Python 3.8, 3.9, and 3.10.</p><p><em>Wait, what?</em></p><p>Yes, you read that correctly. In 2025, Microsoft’s installer completely ignores:</p><ul><li><strong>Python 3.11</strong> (released October 2021 — over 3 years old!)</li><li><strong>Python 3.12</strong> (released October 2023 — the current stable version)</li><li><strong>Python 3.13</strong> (released October 2024 — the latest and greatest)</li></ul><p>Because apparently, Microsoft operates on “Internet Explorer time” where adopting new standards takes half a decade. Meanwhile, the Python community has moved on, enjoying performance improvements, better error messages, and new language features that Microsoft’s Azure CLI will never see.</p><p>Want to use Python 3.12’s improved error tracebacks or 3.13’s new REPL? Too bad! Microsoft has decided you don’t need those fancy modern features. They’re probably still testing Python 3.11 for “enterprise readiness.” 🙄</p><h3>The Solution: An Enhanced Installer That Actually Works</h3><p>After banging my head against Microsoft’s script for the umpteenth time, I decided to fix it myself. Because apparently, that’s what we do now.</p><h3>Key Improvements Made</h3><h4>1. Modern Virtual Environment Creation</h4><p>python</p><pre># OLD (Microsoft&#39;s way - broken):<br># Downloads ancient virtualenv package, fails spectacularly</pre><pre># NEW (the way that actually works):<br>def create_virtualenv(tmp_dir, install_dir, python_path):<br>    &quot;&quot;&quot;Create virtual environment using Python&#39;s built-in venv module.&quot;&quot;&quot;<br>    cmd = [python_path, &#39;-m&#39;, &#39;venv&#39;, install_dir]<br>    exec_command(cmd)</pre><p><strong>Translation</strong>: Use Python’s built-in venv module like a reasonable person instead of downloading packages from the Paleozoic Era.</p><h4>2. Intelligent Package Manager Detection</h4><p>python</p><pre>def _get_macos_package_manager():<br>    &quot;&quot;&quot;Detect which package manager is available on macOS.&quot;&quot;&quot;<br>    # Check for MacPorts<br>    if os.path.isfile(&#39;/opt/local/bin/port&#39;):<br>        return &#39;macports&#39;, [&#39;sudo&#39;, &#39;port&#39;, &#39;install&#39;], &#39;/opt/local&#39;<br>    <br>    # Check for Homebrew (Apple Silicon)<br>    if os.path.isfile(&#39;/opt/homebrew/bin/brew&#39;):<br>        return &#39;homebrew-arm&#39;, [&#39;brew&#39;, &#39;install&#39;], &#39;/opt/homebrew&#39;<br>    <br>    # Check for Homebrew (Intel)<br>    if os.path.isfile(&#39;/usr/local/bin/brew&#39;):<br>        return &#39;homebrew-intel&#39;, [&#39;brew&#39;, &#39;install&#39;], &#39;/usr/local&#39;</pre><p><strong>Translation</strong>: Actually check what package manager people are using instead of assuming everyone drinks the Homebrew Kool-Aid.</p><h4>3. Smart Python Version Selection</h4><p>python</p><pre># Prioritization: MacPorts &gt; Homebrew &gt; System Python<br>def sort_key(path):<br>    score = 0<br>    if PREFERRED_PYTHON_VERSION in version:<br>        score += 1000  # Python 3.10 preferred<br>    if &#39;/opt/local/&#39; in path:  # MacPorts<br>        score += 100<br>    elif &#39;/opt/homebrew/&#39; in path or &#39;/usr/local/&#39; in path:  # Homebrew<br>        score += 50<br>    return -score</pre><h4>4. Future-Ready Python Support</h4><p>python</p><pre># Current (conservative approach):<br>SUPPORTED_PYTHON_VERSIONS = [&#39;3.8&#39;, &#39;3.9&#39;, &#39;3.10&#39;]<br>PREFERRED_PYTHON_VERSION = &#39;3.10&#39;</pre><pre># Future enhancement potential:<br># SUPPORTED_PYTHON_VERSIONS = [&#39;3.8&#39;, &#39;3.9&#39;, &#39;3.10&#39;, &#39;3.11&#39;, &#39;3.12&#39;, &#39;3.13&#39;]<br># PREFERRED_PYTHON_VERSION = &#39;3.12&#39;  # Latest stable</pre><p><strong>Translation</strong>: While Microsoft clings to Python 3.10 like it’s the last version ever released, the enhanced installer can easily be updated to support modern Python versions. Because some of us like to live in 2025, not 2021.</p><h3>The Installation Experience: Before vs. After</h3><h3>Before (Microsoft’s Script):</h3><p>bash</p><pre>$ python3 install_azure_cli.py<br>Error: virtualenv incompatible<br>Error: sys.prefix confusion<br>Error: general sadness and frustration</pre><h3>After (Enhanced Script):</h3><p>bash</p><pre>$ python3 install_azure_cli.py<br>-- Enhanced Azure CLI Installer v1.0.0<br>-- Original by Microsoft Corporation<br>-- Enhanced by Colin Bitterfield &lt;colin@bitterfield.com&gt;<br>-- Azure CLI Version: 2.75.0<br>-- Detected MacPorts at /opt/local<br>-- Found Python executables in &#39;/opt/local/bin&#39;:<br>--   Python 3.10: /opt/local/bin/python3.10<br>-- Multiple Python versions found:<br>--   1: 3.10 - /opt/local/bin/python3.10 (PREFERRED, MacPorts)<br>--   2: 3.9 - /opt/local/bin/python3.9 (MacPorts)<br>--   3: 3.9 - /usr/bin/python3 (System)<br>===&gt; Select Python version (1-3): 1<br>-- Creating virtual environment using built-in venv module<br>-- Installation successful!</pre><p><em>Chef’s kiss</em> 👌</p><h3>Why MacPorts + Enhanced Installer = Developer Happiness</h3><h3>MacPorts Advantages for Azure CLI:</h3><ol><li><strong>Clean Installation</strong>: Everything in /opt/local, no system pollution</li><li><strong>Multiple Python Versions</strong>: Keep 3.8, 3.9, 3.10, 3.11, 3.12, AND 3.13 simultaneously (unlike Microsoft’s limited support)</li><li><strong>Latest Python Support</strong>: Use modern Python versions while Microsoft catches up to 2021</li><li><strong>Optimized Builds</strong>: Compiled specifically for your Mac</li><li><strong>Dependency Isolation</strong>: No conflicts with system packages</li><li><strong>Easy Cleanup</strong>: sudo port uninstall actually removes everything</li></ol><h3>Enhanced Script Benefits:</h3><ol><li><strong>Automatic MacPorts Detection</strong>: Finds and prioritizes your MacPorts Python</li><li><strong>Modern Virtual Environments</strong>: Uses Python’s built-in venv module</li><li><strong>Dependency Management</strong>: Installs MacPorts packages (openssl, libffi, pkgconfig) if needed</li><li><strong>User Choice</strong>: Select exactly which Python version to use</li><li><strong>Future-Proof</strong>: Won’t break when Microsoft updates their dependencies</li></ol><h3>Getting Started: The Right Way</h3><h3>1. Install MacPorts (If You Haven’t Already)</h3><p>Visit <a href="https://www.macports.org/install.php">macports.org</a> and download the installer for macOS 15.</p><h3>2. Install Python via MacPorts</h3><p>bash</p><pre># Install Python 3.10 (Microsoft&#39;s &quot;latest&quot; supported version)<br>sudo port install python310</pre><pre># Or go wild with actual modern Python versions<br>sudo port install python311 python312 python313</pre><pre># Install multiple versions (because you can!)<br>sudo port install python39 python310 python311 python312</pre><pre># Set Python 3.12 as default (if you want to live in the future)<br>sudo port select --set python3 python312</pre><pre># Set Python 3.10 as default (if you want Azure CLI compatibility)<br>sudo port select --set python3 python310</pre><p><strong>Pro Tip</strong>: MacPorts supports Python versions that Microsoft has never heard of. While Microsoft is still “evaluating” Python 3.11 for “enterprise readiness,” MacPorts users are already enjoying Python 3.13’s performance improvements and new features.</p><h3>3. Use the Enhanced Azure CLI Installer</h3><p>bash</p><pre># Download the enhanced installer<br>git clone https://github.com/cbitterfield/azure-cli-installer-enhanced.git<br>cd azure-cli-installer-enhanced</pre><pre># Test your system (optional)<br>./test_installer.py</pre><pre># Install Azure CLI<br>python3 install_azure_cli.py</pre><h3>4. Test Your Installation</h3><p>bash</p><pre># Login to Azure<br>az login</pre><pre># Verify installation<br>az --version</pre><pre># Show your account<br>az account show</pre><h3>The Technical Deep Dive</h3><h3>Virtual Environment Modernization</h3><p>The original script downloaded a tar.gz file of virtualenv 16.7.11 (released in 2019!) and tried to extract and run it. This approach:</p><ul><li>Downloads unnecessary code</li><li>Uses outdated virtualenv logic</li><li>Fails with modern Python installations</li><li>Has SHA256 verification that nobody updates</li></ul><p>The enhanced script simply uses Python’s built-in venv module, which:</p><ul><li>Ships with Python 3.3+</li><li>Is maintained by the Python core team</li><li>Has no external dependencies</li><li>Actually works</li></ul><h3>Package Manager Intelligence</h3><p>Microsoft’s script had zero package manager detection. It just assumed Homebrew and failed silently on MacPorts systems.</p><p>The enhanced version:</p><ol><li>Detects MacPorts at /opt/local</li><li>Detects Homebrew on Apple Silicon (/opt/homebrew)</li><li>Detects Homebrew on Intel (/usr/local)</li><li>Scans multiple Python installation paths</li><li>Gives users clear choices with recommendations</li></ol><h3>Dependency Handling</h3><p>The enhanced installer automatically handles native dependencies:</p><p><strong>MacPorts</strong>:</p><p>bash</p><pre>sudo port install openssl libffi pkgconfig</pre><p><strong>Homebrew (if detected)</strong>:</p><p>bash</p><pre>brew install openssl libffi pkg-config</pre><p><strong>Manual guidance</strong> for edge cases.</p><h3>The Results: A Success Story</h3><p>After implementing these fixes:</p><ul><li>✅ Azure CLI installs cleanly on macOS 15</li><li>✅ MacPorts Python versions are properly detected and prioritized</li><li>✅ Virtual environments work without sys.prefix errors</li><li>✅ Dependencies install automatically via the correct package manager</li><li>✅ Users can choose their preferred Python version</li><li>✅ No more fighting with Microsoft’s assumptions</li></ul><h3>Conclusion: Sometimes You Have to Fix It Yourself</h3><p>Microsoft’s Azure CLI is a powerful tool, but their installation script feels like it was written by someone who’s never heard of package managers other than Homebrew, and who thinks Python 3.10 is “cutting edge technology.” Classic Microsoft move — build something useful, then make the installation experience unnecessarily painful for anyone not following the “blessed path,” while simultaneously ignoring three years of Python evolution.</p><p>Let’s be honest: Microsoft supporting only up to Python 3.10 in 2025 is like Internet Explorer supporting only CSS2 in 2010. The world has moved on, but Microsoft is still “evaluating enterprise readiness” of Python versions that have been stable for years.</p><p>Fortunately, with a little elbow grease and some respect for user choice, we can make it work properly. The enhanced installer proves that you can support multiple package managers, give users options, and use modern Python practices all in the same script.</p><p><strong>Bottom Line</strong>: If you’re a MacPorts user who values control over your development environment, don’t let Microsoft’s Homebrew-centric worldview stop you from using Azure CLI. Use the enhanced installer, enjoy your clean MacPorts setup, and get back to building awesome things on Azure.</p><p>Because life’s too short to fight with broken installation scripts. 🚀</p><h3>Resources</h3><ul><li><strong>Enhanced Azure CLI Installer</strong>: <a href="https://github.com/cbitterfield/azure-cli-installer-enhanced">GitHub Repository</a></li><li><strong>MacPorts</strong>: <a href="https://www.macports.org/">Official Website</a></li><li><strong>MacPorts Installation</strong>: <a href="https://www.macports.org/install.php">Installation Guide</a></li><li><strong>Microsoft’s Original (Flawed) Installer</strong>: <a href="https://learn.microsoft.com/en-us/cli/azure/install-azure-cli-macos?view=azure-cli-latest">Azure CLI macOS Documentation</a></li></ul><p><em>Author: Colin Bitterfield — Information Security Engineer, Python Enthusiast, and Occasional Fixer of Microsoft’s Broken Scripts</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=fb47dffe8b51" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[I’ll Never Use Geometry After High School — I was wrong]]></title>
            <link>https://cbitterfield.medium.com/ill-never-use-geometry-after-high-school-i-was-wrong-ee186296298a?source=rss-f8e598d5fbb1------2</link>
            <guid isPermaLink="false">https://medium.com/p/ee186296298a</guid>
            <category><![CDATA[starlink]]></category>
            <category><![CDATA[math]]></category>
            <dc:creator><![CDATA[Colin Bitterfield]]></dc:creator>
            <pubDate>Mon, 08 Jan 2024 21:11:11 GMT</pubDate>
            <atom:updated>2024-01-08T21:11:11.730Z</atom:updated>
            <content:encoded><![CDATA[<h3>I’ll Never Use Geometry After High School — I was wrong</h3><p>I am working on adding “Starlink” to my RV and needed to make a bushing for the pole mount to connect it to a chainlink fence pole. $20 v $150 mast. I have a number of 3d printers including resin based ones.</p><p>So the problem starts with both a metric to sae conversion along with how to do practical geometry.</p><p>The “Starlink” version of a <a href="https://shop.starlink.com/products/us-consumer-mount-pipeadapter-gen2">pipe adapter </a>can be found on their website.</p><p>The <a href="https://www.lowes.com/pd/Galvanized-Steel-Chain-Link-Fence-Top-Rail/999989216?cm_mmc=shp-_-c-_-prd-_-lum-_-ggl-_-LIA_LUM_211_Siding-And-Specialty-Panels-_-999989216-_-local-_-0-_-0&amp;gad_source=1&amp;gclid=CjwKCAiA7t6sBhAiEiwAsaieYp9GONkiwUxuAbAffzFVomqPpycHvUM7GMtcGRaqX1jXsItP2Vgf0RoC9F4QAvD_BwE&amp;gclsrc=aw.ds">chainlink</a> rail can be found at Lowes or Home Depot</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Mm6_nvQrtID-YM2urjS_dQ.png" /><figcaption>chainlink rail</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MF1IuY0x1Dmonj4zOWZZvA.png" /><figcaption>SAE (btw. not accurate, they got metric and smaller)</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NM36jstUNGuy4TBovRFUQg.png" /><figcaption>Bottom View of the Adapter.</figcaption></figure><p>“designed to attach to any pole with a max diameter of 2.5&quot; (64 mm)”</p><p>Notice that were are already playing with conversions. (Use 64mm) for the 1 3/8&quot; convert and round down. Turns into 34.925 mm (I used 34.9). The issue is the inner dimension of the adapter is 74 mm not 64mm and you need to take the wall thickness into account.</p><p>Notice that we need to create a top (with larger areas) and a bottom with smaller areas and then connect them with a CADD loft. Also if you notice we will need to drill some holes for screws and that they will be on 120 degree centers.</p><p>I came up with this the first time but quickly realized an error.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xcI-VjrYOSrrDKrXzTI8Cg.jpeg" /><figcaption>Mistake</figcaption></figure><p>It takes some very interesting math to make this work out.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Hal1iL_hfWqf_wP9wpEgUw.png" /><figcaption>Finished math with error</figcaption></figure><p>The centerline for each of the three spokes is 0, 120, 240 degrees and 32mm (radius).</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*OoZUzRyTFYNNgdd6SexVdA.png" /><figcaption>We need to fine the number of degrees</figcaption></figure><p>The problem is we need the centerline for construction but we need the degrees or radians for 1/2 the distance on each side.</p><p>The problem is we need to find the number of degrees to start and end the tab wedge using the construction line as reference. We need the total number of degrees for the tab (8.2mm) at 37.2 mm from the centerline.</p><blockquote><a href="https://www.youtube.com/watch?v=F77BrIfYbqE"><strong>Find the central angle given the arc length and radius</strong></a></blockquote><h3>Given the following values</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*RBTzyvziXB_-wjaDVJ7Emg.png" /></figure><p>Arc Length (S) = Radius (r) * Theta (⍉)</p><p>8 mm = 37.2 mm * ⍉</p><p>8 / 37.2 mm = (37.2mm * ⍉) / 37.2 mm</p><p>0.21505376344086 (radians) = ⍉</p><p>radians to degrees:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/890/1*TVqtCQzlug_TmrZw4W8E_A.png" /><figcaption>Radians to Degrees</figcaption></figure><p>A central angle calculator to check the work is located <a href="https://www.omnicalculator.com/math/central-angle">here</a>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/736/1*kmWDrCRqVxO07jAo1AytNw.png" /><figcaption>Central Angle Calculator</figcaption></figure><h3>Now let’s plug this back into our CADD program.</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lV8ifseMysTK6ljUZl_cAA.png" /><figcaption>Note the tab should be 8mm (and we get 7.98 mm)</figcaption></figure><p>In the CADD program, all of the parameters are defined as variables so we can make adjustments to the variables and the sketch will update accordingly. This shows one of three of the tabs. (<em>dash lines are for construction and are not part of the 3d part)</em></p><p>CADD replicates the tab area for 3 around the circle so you don’t need to draw the other lines.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*14_mARCYgzzSQGTZ-BhWWw.png" /><figcaption>So now we have the bottom circle.</figcaption></figure><p>The important part here is that you can use variables in CADD and adjust but you have to know the formulas. This program is smart enough that I could have put the formula in for all of it and had it calculate radians and us that in the sketch.</p><p>This is what the final part will look like (Test section 2mm)</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/826/1*UwBdiKEaJEd64tsEmSXvOw.png" /><figcaption>3d part for test jig</figcaption></figure><p>When the design is done, I will complete the part and slice the bottom and top sections for a 4mm jig to test the print prior to final 3d print to avoid wasting materials.</p><p>This bushing is printed with ABS like resin that is hardened with UV light. For long term survivability outdoors it will need to be painted with UV resistant paint.</p><p>The top central angle:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/718/1*smEYHKSZ3BjWae_umJqwbw.png" /><figcaption>Top Central Angle</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*3JfphlxIyF6cnEO2u8-V-Q.png" /><figcaption>Math</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*X_SgzUEXGRh86N_Mz2cJ-w.png" /><figcaption>Top Jig</figcaption></figure><p>The final product looks like this</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yUKCD5m5119KzzpSA9KJow.png" /><figcaption>Final Product</figcaption></figure><p>In conclusion high school math is still useful 40 years later. It is also very relevant to 3D printing.</p><p>I created an equation so that I could just change arc length and the entire 3d object would update automatically. This helps with the final finish. Also I needed to reduce the size of the inner dimension by a 1/2 mm.</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=ee186296298a" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[AI Code Generation is not ready for prime time]]></title>
            <link>https://cbitterfield.medium.com/ai-code-generation-is-not-ready-for-prime-time-9cca8135fb04?source=rss-f8e598d5fbb1------2</link>
            <guid isPermaLink="false">https://medium.com/p/9cca8135fb04</guid>
            <category><![CDATA[chatgpt]]></category>
            <category><![CDATA[code-generator]]></category>
            <category><![CDATA[llm]]></category>
            <dc:creator><![CDATA[Colin Bitterfield]]></dc:creator>
            <pubDate>Thu, 18 May 2023 17:11:27 GMT</pubDate>
            <atom:updated>2023-05-18T17:11:27.270Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/100/1*XtpndQW5EKH_9BV0P4whtA.jpeg" /><figcaption>Image by Anna Maria Weaver © 2023</figcaption></figure><p>Over the last year, I have been asked about the security concerns with AI-Generated source code and “code assistants” like Tab9, CodePilot, and other LLM-based AI Generators. Overall my initial take on these services is they are emerging technology that is not ready to be implemented by enterprise commercial shops. I can see a fear that the use of AI Generators is a “game changer” in competition failure to adopt could put you out of business. On the flip side of that, early adoption could destroy your reputation and put you out of business. Just ask <a href="https://www.darkreading.com/vulnerabilities-threats/samsung-engineers-sensitive-data-chatgpt-warnings-ai-use-workplace">Samsung</a> they now ban the use of all AI Generators.</p><p>Initially, any of these services should be vetted by ISO/SOC/NIST vendor due diligence requirements. This article is my findings based on looking at AI code generation through a security and compliance lens.</p><p>Many of us remember Elize from the 1980s. The source code has been missing since the 1960s. Perhaps it is being resurrected in a new form.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/751/1*JCSlJnIF-TJClkBXW4HxAQ.png" /><figcaption>Eliza image courtesy of Wikipedia</figcaption></figure><p>The value in these AI generators could potentially be very high and profitable for the company that gets it right and the customers that can leverage it. The image below was generated for this article from “text to images”. I tried a couple of different sites for this to create royalty-free art for this article. I can see this aspect really cutting into Adobe, Getty, and other stock art places. It gives people an alternative for self-publishing and license issues. The image below does not come without specific limitations. See the<a href="https://www.canva.com/policies/ai-product-terms/"><em> terms of service</em></a><em>.</em></p><p>This brings up one of the primary issues: “copyright”. In terms of service, even though I generated the image it’s not mine based on copyright. After a lot of research, the reason why became apparent. If someone else uses the same site and more or less the same request, they have a very high likelihood of getting the same image. This is very important and I will touch on it later in the article.</p><figure><img alt="AI Generated Image" src="https://cdn-images-1.medium.com/max/1024/1*XzKA4MA6HVTmUNcBkI1aaA.png" /><figcaption>AI-Generated Robot by Canva image generator</figcaption></figure><p>AI Generators have the potential to do a lot of grunt work in programming. But the real danger is that people might ask the “AI” to do their work for them and not have the capacity to understand that work, validate it, or perhaps even understand it. This might create a critical risk with “AI” dependency or induce unknown security vulnerabilities.</p><p>I see these areas that have a high potential for use and misuse:</p><ol><li>Software Development / DevOPS (Code Generation for applications and Infrastructure as Code IaC). This poses some new challenges but brings back a lot of challenges from outsourcing development to “unknown” programmers using a specification.</li><li>Marketing / Sales: Image generation, customer correspondence creation, and similar tasks.</li><li>Legal/HR: Policy and contract creation.</li><li>Finance: Analyzing complex financials.</li><li>Data Science: Analyzing big data.</li></ol><p>The issue with these business functions using this technology is quite connected to the immaturity of the technology and the companies selling the technology.</p><p><strong>Things that don’t exist or don’t exist well currently:</strong></p><ol><li>Corporate Policies on how, what, where, and when AI Generation should be used.</li><li>Rules of Attribution and Copyright</li><li>Legal cases and precedence in any or all industries. (licenses, copyrights, attribution, training, acceptable uses).</li><li>Liability Law for the AI Generator (some are limited to $100 in total limitations)</li><li>Rules of Compentcy inside of the AI. — Requirement for ISO/SOC/NIST shops.</li><li>Best practices by the industry</li><li>Non-Disclosure Agreements and other business contracts including sections for AI-generated or access content.</li><li>Ability to purge “accidentally disclosed information” from the AI/LLM model with proof of removal.</li><li>Ability to segment by the company their “AI”. — This is a very important concept.</li><li>The ability to control “AI Lying and Hallucinations” — Yes that is a thing.</li><li>The ability to attribute the AI’s knowledge source (and all kinds of privacy and non-disclosure issues)</li><li>Well-documented and attributable risks and vulnerabilities.</li><li>Lack of <a href="https://www.bclplaw.com/en-US/topics/2023-state-by-state-artificial-intelligence-legislation-snapshot.html">current government regulations</a> on the subject. California and Virginia are leading the way on this.</li></ol><p>A pause to remember the rules about robots (aka AIs) from Isaac Asimov</p><h3>Isaac Asimov’s “Three Laws of Robotics”</h3><ol><li>A robot may not injure a human being or, through inaction, allow a human being to come to harm.</li><li>A robot must obey orders given it by human beings except where such orders would conflict with the First Law.</li><li>A robot must protect its own existence as long as such protection does not conflict with the First or Second Law.</li></ol><p>This is an important takeaway. The AI (aka LLMs) being marketed don’t have anything like baseline ethics programming. The current round of AIs will make up the results.</p><p>“Google CEO Sundar Pichai says ‘hallucination problems’ still plague A.I. tech and he doesn’t know why” <a href="https://fortune.com/2023/04/17/google-ceo-sundar-pichai-artificial-intelligence-bard-hallucinations-unsolved/">[link]</a></p><p>We have all watched Science Fiction or read it. The robot (AI) going insane and killing everyone is a major plot in most of these stories. Just like Sky Net creating “Terminators”. This should give everyone (even Eli Musk tweets about it) a pause for how this technology is implemented, deployed, used, and regulated.</p><h3>The point of the article is why AI is not ready for prime time.</h3><p>The current batch of AI Generators (SaaS vendors) have huge limitations and liabilities. They are used as “slaves” by employees to augment the employee’s work. The largest potential misuse other than unauthorized disclosure of confidential or proprietary information is when incompetent people use them “to be competent”.</p><p><strong><em>One of the cornerstones to contract law is “respondeat superior”, which is Latin for “let the superior answer,” is a theory that holds employers responsible for the actions of their employees.</em></strong></p><p>For instance, if a junior developer with little experience asks the AI Generator to write a program (or even a function) that they themselves can’t write, how could they supervise or validate that the code does not contain security vulnerabilities or other risks?</p><p>Apparently, one of the AIs (based on an article) passed the bar. That doesn’t make it a lawyer. Because the AI generates code, it doesn’t make it a programmer.</p><p>SOC2, ISO, and NIST all require that employees are competent to do their work and receive job-based training and security awareness training based on job roles. Furthermore, all types of workforce must conform to the same level of training regardless of status. (Employee, Contractor, or outsourced vendor). This is done in a variety of ways by vetting suppliers, checking IDs and credentials of the workforce, and so on.</p><p>If we extend this to AI Generators of any kind, we must also validate their competency to work. None of the generators, I looked at seem to have figured this out.</p><h3>Consider general employee/contractor requirements just to work:</h3><ol><li>Credentials / Education including the verification of them.</li><li>Verifying they are who they say they are. (Is the AI Generator outsourced internally to another vendor?)</li><li>Training and Compentcy. How much programming time does the AI have? How was it trained?</li><li>Ethics requirements: Plagiarism, Lying, Stealing, violating employee handbook things.</li><li>Regulatory training. In many industries, people have to receive and know regulatory requirements like Sarbanes-Oxley or Export Controlled Requirements. It is unclear if these generators are trained on industry or general legal requirements.</li><li>In programming, for instance, developers are required to know and develop with security by design. For example not writing code vulnerable to SQL Injection or other OWASP requirements. Or perhaps to be aware of PI, PII, or PCI-type data and not use it inappropriately.</li><li>Non-Disclosure, Non-Compete contracts to keep employees from selling company secrets.</li></ol><h4><strong>The current AI Generator vendors are simply too immature in the technology to be leveraged appropriately by Fortune 1000-level companies or companies in highly regulated industries.</strong></h4><p>For this technology to be readily usable there are a few things that need to happen:</p><ol><li>The AI used by one company needs to have its knowledge base firewalled, or anonymized from other users and that base of knowledge needs to be proprietary to the company using the AI. AIs have a high probability of generating the same answer for multiple clients. It’s like sharing a key engineer between two competing companies.</li><li>The issue of AI Hallucination or lying needs to be resolved. The AI should say, I don’t know if it doesn’t. I wonder if this behavior is induced by the creator&#39;s own ethics or personality.</li><li>Copyright law / Patent law regarding the work product of the AI needs to be legally enforceable and defined.</li><li>AI Generators need a way to remove knowledge if accidentally disclosed.</li><li>AIs need to have some certification process for industry standards to allow companies to perform due diligence on them. For instance, this “AI” is trained not to write code that would violate security by design standards. All of the code used to train this AI was legally obtained and not scanned from odd internet sources. This might even include some testing on programming code. “Ask the AI to generate a series of code blocks and then test them for accuracy”</li><li>AI’s need to be able to attribute their sources in work products and maintain proper license control. If the AI utilizes a GNU 3 licensed library that requires attribution then it should put the proper attribution in the code.</li><li>Product liability for AIs needs to be worked out. If you are a consultant to a company you probably need the proper liability insurance.</li><li>Logging and attribution. AI vendors need to be able to report on which employees did what with the AI and what they generated with it.</li><li>A set of industry standards like CIS for using AI Generation.</li><li>AI Vendor safeguards (ability to forget and purge, notification if PII is uploaded, notification or protection if secret keys or credentials are uploaded, etc.)</li><li>Style and personality controls. Writing code or documents has a style to it. The AI should conform to corporate cultural norms. Especially if generating baseline policy documents.</li><li>AIs need to be more interactive and ask questions to clarify not just run with a request that is not fully understood. Same for any programmer or workforce person.</li><li>Industry protocols and norms need to be developed. This includes a review process.</li></ol><h3>In Summary:</h3><p>My top ten list of why AI Generators should not currently be used in the Enterprise (other than for researching how they work). There is a general risk of employees using “AI” to improve their work product against company policy. This is a very high-risk aspect.</p><ol><li>AI Generators are “shared” employees with no non-disclosure or non-compete agreement. They will likely provide the same (cut and paste) answer to anyone that asks. If you place your proprietary code in for optimization; your competitor might get it out when they ask.</li><li>AI Generators are frequently trained on data sets that don’t belong to the vendor training them.</li></ol><h4><a href="https://www.theverge.com/2023/2/6/23587393/ai-art-copyright-lawsuit-getty-images-stable-diffusion">Getty Images sues AI art generator Stable Diffusion in the US for copyright infringement</a></h4><p>3. AI Generators can’t be validated as “Competent” or “Trained” this could cause an issue with certification under industry standards.</p><p>4. AI Generators can’t provide source attribution or license validation.</p><p>5. AI Generation by lesser competent people could slip through without proper review.</p><p>6. AI Generators a biased in some method by their creator and may be biased against the organization&#39;s culture or value set. (It’s not settable at this time)</p><p>6. AI Generators lack sufficient security controls, customer segregation, and reporting.</p><p>7. Total lack of best practices in the industry</p><p>8. AIs don’t understand and are not programmed to comply with ethics or industry regulation.</p><h3>Next Steps:</h3><p>My thoughts:</p><ol><li>Ban this use of AI Generators in all aspects of corporate work products by policy and implement security controls like DNS firewalls to remove access.</li><li>Implement a well-written policy banning the “UnAuthorized” use of the technology.</li><li>Implement technical controls to block the use of the technology. (Google Workspace blocks on OAUTH, DNS Firewalls, MDM)</li><li>Create a working group internally to create policies, protocols, and procedures for vetting the AI Generators and use them. Including a review process.</li><li>Create security awareness training that clearly and simply informs the workforce of the risks.</li><li>Approve with proper due diligence the workgroup or interested employees&#39; web-based access with conditions.</li><li>Have your privacy, legal, or compliance team monitor state and federal regulations regarding this technology.</li><li>Vet AI Vendors very carefully. I would not approve an AI Vendor unless they met at least the following conditions:</li></ol><ul><li>Certification (ISO, SOC2, NIST)</li><li>Could demonstrate data deletion (forgetting) of confidential data from the LLM and all datasets and backups.</li><li>Could provide detailed logs (automatically to my S3 bucket or SEIM) about what users did what.</li><li>Could provide proof of license attribution regarding source materials.</li><li>Generated attribution in the code or document.</li><li>Had clear copyright on generated materials.</li><li>Could verify that my “answers” are going to wind up with my competitor somehow. (My own AI has my knowledge base)</li><li>Had at least 1M in liability insurance</li><li>Was trained on materials that were properly licensed for the purpose of training and can demonstrate this.</li><li>And some control to prevent AI Hallucinations.</li><li>Had a method of notification if a Zero-day exploit was propagated by the code generated.</li><li>Had some internal methods for checking the code provided against OWASP 10/20, industry best practices, normal SDLC checking of code, and was certified not to induce OWASP-based vulnerabilities.</li><li>Had clear terms of service that my data does not become their IP just because I uploaded it.</li><li>Prevented my “asks” from being seen by other companies’ employees.</li></ul><h3>Clear Risks</h3><ol><li>Copyright and license infringement and liability.</li><li>Competition receiving proprietary code.</li><li>PII or other confidential data disclosed. (Imaging if restricted financial data was uploaded by the CFO and he asked the AI to analyze and report. Then the unreleased financials are available to anyone researching the company.)</li><li>Unauthorized disclosure or transfer of information in all forms.</li><li>Regulatory litigation. (Violation of Automated Decision Making, GDPR, Sarbanes-Oxley)</li><li>Litigation is based on inaccurate or biased information in code or documents.</li><li>Product Liability based on AI-generated work product.</li><li>Zero-day exploits based on AI hallucinations. I read an article where first the AI lied about the code repository and then researchers create that library in GitHub and then AI decided to download the repository to its body of knowledge but the code was tainted to see if malicious code could be injected.</li><li>Seeing “queries” for research could give a competitor proprietary information.</li><li>Over-dependence on the use of AI.</li></ol><p>A thought that popped into my head on this is “What about required legal reporting?” What would happen if the AI gained a legal requirement to report criminal information? Back to a CFO uploading financial data to analyze, what if he lies to the SCC and the AI that can read the report has a required reporting on the difference between what it knows (the real numbers) and the published SCC information? Automated whistleblowing.</p><h3>Research Examples</h3><p>I performed some research for this article.</p><p>The <a href="https://codepal.ai/">https://codepal.ai/</a> site worked pretty well on generating some Python code and a Docker file. However, there were some key mistakes. As I changed how I wrote the requirement, the answers changed and were not always correct.</p><p>In the Python example, I asked it to write a function that executes some OS commands and presented the results. It did not properly create the function. It was close enough for me to finish but was by no means a final answer. The second code I had it write was a function to scan a directory avoiding hidden files recursively and present the results for directories that had a matching name. The code was pretty close to final on that one.</p><h4>Directory Function:</h4><pre>def find_directories(directory_path, directory_name):<br>    &quot;&quot;&quot;<br>    This function searches for all directories with a specific name in a given directory path.<br>    It does not include hidden directories.<br>    <br>    Parameters:<br>    directory_path (str): The path of the directory to search in<br>    directory_name (str): The name of the directory to search for<br>    <br>    Returns:<br>    list: A list of directory paths that match the specified directory name<br>    &quot;&quot;&quot;<br>    try:<br>        # Check if the directory path exists<br>        if not os.path.exists(directory_path):<br>            raise ValueError(&quot;Directory path does not exist&quot;)<br>        <br>        # Initialize an empty list to store the matching directories<br>        matching_directories = []<br>        <br>        # Loop through all directories in the directory path<br>        for dirpath, dirnames, filenames in os.walk(directory_path):<br>            # Check if the directory is hidden<br>            if os.path.basename(dirpath).startswith(&#39;.&#39;):<br>                continue<br>            <br>            # Check if the directory name matches the specified name<br>            if directory_name in dirnames:<br>                # Add the directory path to the list of matching directories<br>                matching_directories.append(os.path.join(dirpath, directory_name))<br>        <br>        # Return the list of matching directories<br>        return matching_directories<br>    except ValueError as e:<br>        # Log the error<br>        print(f&quot;Error: {e}&quot;)<br>        return []</pre><p>The docker file forgot to add key code without which the docker build hung indefinitely</p><pre>ARG DATE_TIMEZONE=UTC<br>ARG DEBIAN_FRONTEND=noninteractive</pre><p>It was also unable to create a proper start script for the service or run commands for the container.</p><h4>Request:</h4><pre>runs ssd as a service. Copy a file named ubuntu.txt and install all of the packages in the file. Copy a file named graphics-kat.py, make it executable and put it in /usr/local/bin. Add /usr/local/bin to the PATH variable for the system.  Copy a filename requirements.txt and install all of the python libraries contained in the file. Mount three NFS shares named SOURCE, PROJECT, AND FINISHED and provide environment variables to pass the NFS Server mount points. Create a user named “graphics_kat”. Copy a file named authorized_keys to graphics_kat’s .ssh directory and set the correct permissions for login with an ssh key. Create the MAINTAINER TAG with my information. Supports CUDA and has cuda tools installed.  Create a start script that displays system logs and shows docker run instructions on startup. Install sudo and place the user graphics_kat in the sudo group. Create the start script dynamically in the docker file.<br></pre><h4>Results:</h4><pre>FROM ubuntu:latest<br><br># MAINTAINER TAG<br>MAINTAINER &lt;Your Name&gt; &lt;Your Email&gt;<br><br># Copy ubuntu.txt and install packages<br>COPY ubuntu.txt /tmp/<br>RUN apt-get update &amp;&amp; apt-get install -y $(cat /tmp/ubuntu.txt)<br><br># Copy graphics-kat.py, make it executable and put it in /usr/local/bin<br>COPY graphics-kat.py /usr/local/bin/<br>RUN chmod +x /usr/local/bin/graphics-kat.py<br><br># Add /usr/local/bin to the PATH variable for the system<br>ENV PATH=&quot;/usr/local/bin:${PATH}&quot;<br><br># Copy requirements.txt and install python libraries<br>COPY requirements.txt /tmp/<br>RUN pip install -r /tmp/requirements.txt<br><br># Mount three NFS shares<br>ENV SOURCE_MOUNT_POINT=&quot;&lt;NFS Server mount point for SOURCE&gt;&quot;<br>ENV PROJECT_MOUNT_POINT=&quot;&lt;NFS Server mount point for PROJECT&gt;&quot;<br>ENV FINISHED_MOUNT_POINT=&quot;&lt;NFS Server mount point for FINISHED&gt;&quot;<br>RUN mount -t nfs $SOURCE_MOUNT_POINT /source<br>RUN mount -t nfs $PROJECT_MOUNT_POINT /project<br>RUN mount -t nfs $FINISHED_MOUNT_POINT /finished<br><br># Create a user named “graphics_kat”<br>RUN useradd -m graphics_kat<br><br># Copy a file named authorized_keys to graphics_kat’s .ssh directory and set the correct permissions for login with an ssh key<br>COPY authorized_keys /home/graphics_kat/.ssh/<br>RUN chown -R graphics_kat:graphics_kat /home/graphics_kat/.ssh/<br>RUN chmod 600 /home/graphics_kat/.ssh/authorized_keys<br><br># Supports CUDA and has cuda tools installed<br>RUN apt-get install -y nvidia-cuda-toolkit<br><br># Create a start script that displays system logs and shows docker run instructions on startup<br>RUN echo &#39;#!/bin/bash \n\<br>echo &quot;Displaying system logs...&quot; \n\<br>echo &quot;Docker run instructions...&quot; \n\<br>exec &quot;$@&quot;&#39; &gt; /usr/local/bin/start.sh<br><br># Install sudo and place the user graphics_kat in the sudo group<br>RUN apt-get install -y sudo<br>RUN usermod -aG sudo graphics_kat<br><br># Set permissions for start.sh<br>RUN chmod +x /usr/local/bin/start.sh<br><br># Set entrypoint<br>ENTRYPOINT [&quot;/usr/local/bin/start.sh&quot;]<br><br># Set default command<br>CMD [&quot;/bin/bash&quot;]</pre><p>I would have assumed it could have done a better job on the Ubuntu requirement which I run across all the time. It should have been able to create a better and more complete run script and give me an example of how to run the container. That part is normal and common.</p><p>On the good side, it got the SSH permissions right and has very readable code that is properly documented.</p><p>On the odd side, it knows who I am because I signed up and paid for access. When I asked to add my information to the docker file maintainer it was unable to do that.</p><p>I will test the CUDA integration later to see if that works.</p><h3>Value Proposition</h3><p>From my limited tests and use of various code generators, they can be very useful as a starting point to solve routine and standard problems that (we) programmers face every day.</p><p>For instance, I have created that directory function a number of times slightly tweaked each time for what I was working on. Not having to store a GIST and modify it as a starting point is useful and speeds up development. I have found over the last few years that I have to solve the same issue for each program I write and I maintained a small repository of useful functions for cut and paste.</p><p>I think there is a potential for a lot of value if the vendors can improve on security, privacy, and regulatory issues.</p><p>In the course of my daily work, I frequently need a starting point for code or documents. I usually use a Google Search for “free” based templates or examples as a starting point. That is usually very time-consuming. Getting an understandable and working template in a minute would save me hours of research.</p><p>I think in the area of code optimization and analysis for vulnerabilities this technology could be huge especially if Microsoft could incorporate good parts with GitHub actions (Synk does some of this now) to provide a recommendation during the pull request. (like, your code could be optimized if you did …) or your code could be compromised by abnormal input into this…</p><h3>Dangers on the Horizon</h3><p>The risk of lesser competent people using AI Generators to produce work products under their moniker is a strong risk. I think this will lead to a requirement for better vetting of people that write work products (developers, lawyers, sales, marketing). Most of the time persons in this category don’t know, abide or check for copyrights, licenses, and other related issues.</p><p>AI Generators pose a great starting point but they are not the final solution to any task and all products generated need to be reviewed by a competent person in that field.</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=9cca8135fb04" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Secure Delete in OSX (Ventura)]]></title>
            <link>https://cbitterfield.medium.com/secure-delete-in-osx-ventura-eac7b422ae02?source=rss-f8e598d5fbb1------2</link>
            <guid isPermaLink="false">https://medium.com/p/eac7b422ae02</guid>
            <category><![CDATA[secure-erase]]></category>
            <category><![CDATA[finder]]></category>
            <category><![CDATA[ventura]]></category>
            <dc:creator><![CDATA[Colin Bitterfield]]></dc:creator>
            <pubDate>Mon, 27 Mar 2023 19:07:06 GMT</pubDate>
            <atom:updated>2023-03-27T19:11:01.247Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/386/1*LwDAR-w4V0-d5dvp6NmNBA.png" /><figcaption>Secure erase ?</figcaption></figure><p>Recently, I was asked how to securely delete the free space of a file on OSX. Back in the OSX El Captain days finder had an option “Secure Erase” for the trash can. That option has been removed on all of the modern OSX versions due to how SSDs work. Most of the articles I read still point back to older versions.</p><p>How to securely delete files on a Mac System from the command line or finder.</p><p>After some research, I found the binary (srm) secure remove for all OSX/Linux systems. There is a binary for Windows in the repository.</p><p><a href="https://sourceforge.net/projects/srm/">secure rm</a></p><p>Secure rm can be installed with <a href="https://ports.macports.org/port/srm/details/">MacPorts</a> or possibly <a href="https://brew.sh/">HomeBrew</a>. It can also be installed via compiling with XCode tools in under a minute.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/100/1*nVSm35n0Ig8Aq5Uq6KXTLg.png" /></figure><h3>Step 1: Install XCode or XCode CLI.</h3><p>XCode is apples native compiler (like GCC). If you are going to compile anything from source code at least the CLI tools need to be installed.</p><p>Either install the full application from the<a href="https://apps.apple.com/us/app/xcode/id497799835?mt=12"> Apple App Store</a> or use the following CLI commands.</p><pre>xcode-select --install<br>sudo xcodebuild -license accept</pre><h3>Step 2: Download the SRM package</h3><p><a href="https://sourceforge.net/projects/srm/files/1.2.15/srm-1.2.15.tar.gz/download">Download Source Package</a></p><p>Download with wget</p><pre>wget -O srm-1.2.15.tar.gz https://sourceforge.net/projects/srm/files/1.2.15/srm-1.2.15.tar.gz/download</pre><h3>Step 3: Compile</h3><pre>tar -zxvf srm-1.2.15.tar.gz<br>cd srm-1.2.15<br>./configure<br>make all <br>sudo make install </pre><p>The binary will install to /usr/local/bin by default. Change this with ./configure if desired.</p><h3>Examples of Secure Deletion</h3><h4>Type of Deletion explained</h4><pre>--simple <br> Overwrite the file with a single pass of 0x00 bytes.  This is the default mode.<br><br>--openbsd<br>OpenBSD compatible rm.  Files are overwritten three times, first with the byte 0xFF, then 0x00, and then<br>              0xFF again, before they are deleted.<br><br>--dod<br>US Dod compliant 7-pass overwrite.<br><br>--doe<br>US DoE compliant 3-pass overwrite.  Twice with a random pattern, finally with the bytes &quot;DoE&quot;.  See<br>              http://cio.energy.gov/CS-11_Clearing_and_Media_Sanitization_Guidance.pdf for details.<br><br>--gutmann<br> Use the 35-pass Gutmann method.  See http://en.wikipedia.org/wiki/Gutmann_method for details.<br><br>--rcmp<br>Royal Canadian Mounted Police compliant 3-pass overwrite.  First pass writes 0x00 bytes.  Second pass<br>              writes 0xFF bytes.  Third pass writes &quot;RCMP&quot;.  See https://www.cse-cst.gc.ca/en/node/270/html/10572 for<br>              details.</pre><h4>Example 1: Delete a single file</h4><pre>srm --dod srm-1.2.15.tar.gz </pre><h4>Example 2: Delete a group of files</h4><p>add “-vvv” for more information</p><pre> srm -vvv --dod test?<br><br>Output<br>srm: removing test1<br>srm: file size: 2097152, buffer_size=4096<br>srm: buffer_size=1048576<br>srm: US DoD mode<br>pass 7 sync                        srm: removing test2<br>srm: file size: 2097152, buffer_size=4096<br>srm: buffer_size=1048576<br>srm: US DoD mode<br>pass 7 sync                        srm: removing test3<br>srm: file size: 2097152, buffer_size=4096<br>srm: buffer_size=1048576<br>srm: US DoD mode<br>pass 7 sync                        srm: removing test4<br>srm: file size: 2097152, buffer_size=4096<br>srm: buffer_size=1048576<br>srm: US DoD mode<br>pass 7 sync <br></pre><h4>Example 3: Recursively delete a folder(directory)</h4><pre>srm -vvv -r --dod ./srm-1.2.15/<br><br>output (snip)<br>srm: removing ./srm-1.2.15/srm.sln<br>srm: file size: 1988, buffer_size=4096<br>srm: buffer_size=1048576<br>srm: US DoD mode<br>pass 7 sync                        srm: removing ./srm-1.2.15/srm.spec<br>srm: file size: 947, buffer_size=4096<br>srm: buffer_size=1048576<br>srm: US DoD mode<br>pass 7 sync                        srm: removing ./srm-1.2.15/install-sh<br>srm: file size: 13663, buffer_size=4096<br>srm: buffer_size=1048576<br>srm: US DoD mode<br>pass 7 sync                        srm: removing ./srm-1.2.15/configure.ac<br>srm: file size: 1763, buffer_size=4096<br>srm: buffer_size=1048576<br>srm: US DoD mode<br>pass 7 sync                        srm: removing ./srm-1.2.15/INSTALL<br>srm: file size: 371, buffer_size=4096<br>srm: buffer_size=1048576<br>srm: US DoD mode<br>pass 7 sync                        srm: removing ./srm-1.2.15/test/fill.o<br>srm: file size: 2240, buffer_size=4096<br>srm: buffer_size=1048576<br>srm: US DoD mode<br>pass 7 sync                        srm: removing ./srm-1.2.15/test/fill_test<br>srm: file size: 39638, buffer_size=4096<br>srm: buffer_size=1048576<br>srm: US DoD mode</pre><h3>Taking it one step further and adding to finder with “Automator”</h3><p>This is a bit of a work in progress and will be tailored to individual needs</p><h4>Step 1: Open Automator and select Quick Action</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/539/1*HIO_LmdhGOiWdItkuK0yFg.png" /><figcaption>Automator Quick Action</figcaption></figure><h4>Step 2: Wire up the finder to Apple Script</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/997/1*7AftX2wr-YlC5uhe_goGOw.png" /><figcaption>Apple Script</figcaption></figure><h4>Step 3: Add the following code (Apple Script)</h4><pre>on isDirectory(someItem) -- someItem is a string<br> set filePosixPath to quoted form of (POSIX path of someItem)<br> set fileType to (do shell script &quot;file -b &quot; &amp; filePosixPath)<br> if fileType ends with &quot;directory&quot; then return true<br> return false<br>end isDirectory<br><br><br><br>on run {thePaths, parameters}<br> set the_results to {}<br> set srmLocation to &quot;/opt/local/bin/srm&quot;<br> -- Update the initial progress information<br> set thePathCount to length of thePaths<br> <br> --get delete method<br> set DeleteMethods to {&quot;simple&quot;, &quot;openbsd&quot;, &quot;dod&quot;, &quot;doe&quot;, &quot;gutmann&quot;, &quot;rcmp&quot;}<br> set theDeleteMethod to choose from list DeleteMethods with prompt &quot;Select your secure delete method:&quot; default items {&quot;dod&quot;}<br> theDeleteMethod<br> <br> <br> set theDeleteMethodSetting to &quot;--&quot; &amp; theDeleteMethod<br> <br> set beginning of the_results to &quot;Delete Method &quot; &amp; theDeleteMethodSetting<br> <br> repeat with a from 1 to length of thePaths<br>  <br>  -- Update the progress detail<br>  set progressNotify to (theDeleteMethod as text) &amp; &quot; deletion of Path &quot; &amp; a &amp; &quot; of &quot; &amp; thePathCount<br>  <br>  set theCurrentListItem to item a of thePaths<br>  -- Process the image<br>  set theFilePath to POSIX path of theCurrentListItem<br>  --display notification theFilePath &amp; &quot;has been secure erased.&quot; with title &quot;Secure Erase&quot; subtitle &quot;Processing is complete.&quot;<br>  set the_results to the_results &amp; &quot;\n processing \n&quot; &amp; theFilePath  &amp; &quot;\n&quot; as text<br>  <br>  <br>  <br>  if isDirectory(theFilePath) then<br>   set the_results to the_results &amp; &quot;Directory \n&quot;<br>   set theResult to do shell script srmLocation &amp; &quot; --verbose --verbose --recursive &quot; &amp; theDeleteMethodSetting &amp; &quot; &quot; &amp; quote &amp; theFilePath &amp; quote<br>   <br>  else<br>   set theResult to do shell script srmLocation &amp; &quot; --verbose --verbose --verbose &quot; &amp; theDeleteMethodSetting &amp; &quot; &quot; &amp; quote &amp; theFilePath &amp; quote<br>   <br>  end if<br>  set the_results to the_results &amp; theResult &amp; &quot;\n&quot; as text<br>  <br>  display notification theResult with title theFilePath subtitle progressNotify<br>  <br>  -- Increment the progress<br>  <br>  <br>  -- Pause for demonstration purposes, so progress can be seen<br>  delay 1<br>  <br> end repeat<br> <br> set the_results to the_results &amp; &quot;Paths Processed &quot; &amp; thePathCount as text<br> <br> display dialog the_results<br> return thePaths<br>end run</pre><h4>Save this action as “Secure Erase”</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/679/1*2kcBverE2V2ZkGbSQXc9Bw.png" /><figcaption>Secure Erase</figcaption></figure><h4>Run the action</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/342/1*D9GrYrvts7UXJdUA6Xg8_w.png" /><figcaption>Choose the erase method</figcaption></figure><h4>The results should look like this:</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/419/1*syohLuvtc29RUEqSTpi7ng.png" /><figcaption>Results</figcaption></figure><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=eac7b422ae02" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Setup your MacBook Pro Ready for Developing in Ventura (OSX 13)]]></title>
            <link>https://cbitterfield.medium.com/setup-your-macbook-pro-ready-for-developing-in-ventura-osx-13-dad5596e0a51?source=rss-f8e598d5fbb1------2</link>
            <guid isPermaLink="false">https://medium.com/p/dad5596e0a51</guid>
            <dc:creator><![CDATA[Colin Bitterfield]]></dc:creator>
            <pubDate>Mon, 20 Mar 2023 20:09:47 GMT</pubDate>
            <atom:updated>2023-03-20T20:16:25.302Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f_16Cu0P55zR6bzT-Xsh-A.png" /><figcaption>Mozart ponders security by design</figcaption></figure><p>When you change laptops, upgrade OSX, or set up a new employer laptop, there is a litany of installation and configurations just to get working. I find myself reviewing my previous notes and “remembering” all of my settings. I do a lot of python development, so I am including setting up PyCharm Community and AWS CLI in this configuration guide.</p><p><em>Disclaimer: Actual Mileage and Preferences will vary</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/100/1*nVSm35n0Ig8Aq5Uq6KXTLg.png" /><figcaption>Image by Anna Maria Weaver</figcaption></figure><h3>Step 1: Install internet downloadable (free) applications.</h3><p>Choose the applications required for your environment.</p><ul><li><a href="https://www.macports.org/">MacPorts</a> — Provides CLI Linux tools to OSX (Python 3.10, Jupyter Notebook, etc)</li><li><a href="https://www.titanium-software.fr/en/onyx.html">OnyX</a> — OnyX is a multifunction utility that you can use to verify the structure of the system files; run miscellaneous maintenance and cleaning tasks; configure parameters in the Finder, Dock, Safari, and some Apple applications; delete caches; remove certain problematic folders and files; rebuild various databases and indexes; and more.</li><li><a href="https://www.google.com/chrome/?brand=CHBD&amp;gclid=CjwKCAjwiOCgBhAgEiwAjv5whPPCH-jGJpYneCTDJC7gEPNy7-w6vieUJlaJAfksa7dqGnUvedRKixoCzV0QAvD_BwE&amp;gclsrc=aw.ds">Chrome</a> — browser</li><li><a href="https://docs.github.com/en/desktop/installing-and-configuring-github-desktop/installing-and-authenticating-to-github-desktop/installing-github-desktop">GitHub Desktop</a></li><li><a href="https://www.mozilla.org/en-US/firefox/new/">Firefox</a> — browser</li><li><a href="https://iterm2.com/">iTerm2 </a>— Better Terminal</li><li><a href="https://www.docker.com/products/docker-desktop/">Docker</a> Desktop</li><li><a href="https://www.onenote.com/download">OneNote</a> (if you use it)</li><li><a href="https://www.virtualbox.org/">Virtual Box</a> (VirtualBox is a type-2 hypervisor for x86 virtualization)</li><li><a href="https://www.jetbrains.com/pycharm/download/#section=mac">PyCharm</a> — Community Version (or <a href="https://www.jetbrains.com/">JetBrain</a> Products)</li><li><a href="https://visualstudio.microsoft.com/vs/mac/">Visual Studio (</a>If you use it)</li><li><a href="https://www.neooffice.org/">NeoOffice</a> (Replacement for MS Office or Libre Office). This is a $29 version of Microsoft Office and is useful if your company uses Google Workspace.</li><li><a href="https://apps.apple.com/us/app/slack-for-desktop/id803453959?mt=12">Slack</a> — Messanger</li><li><a href="https://zoom.us/DOWNLOAD">Zoom</a> — Video Conferencing (Might just need to have it)</li><li><a href="https://developer.apple.com/downloads/index.action">XCode</a> — At least the CLI tools for compiling MacPorts and source code. You will also need to accept the license. The full application can be downloaded <a href="https://apps.apple.com/us/app/xcode/id497799835?mt=12">here</a> from the APP Store</li><li><a href="https://1password.com/">1Password</a> — Password Manager (or <a href="https://www.keepersecurity.com/">Keeper</a>, or <a href="https://www.google.com/aclk?sa=l&amp;ai=DChcSEwiP89Pkkev9AhWhDK0GHcXwDVsYABAAGgJwdg&amp;sig=AOD64_14hZIRtoEC0Uiv64jcT7onvD44Cw&amp;q&amp;adurl&amp;ved=2ahUKEwibpMrkkev9AhXGKEQIHVGsB3EQ0Qx6BAgGEAE">LastPass</a>). I have changed to 1Password for ISO/NIST Compliance. Most of the companies I work for have this as a corporate application (the personal version is free with the corporate version). This allows you to have access to your personal passwords at work. The other really nice feature is a <a href="https://www.google.com/aclk?sa=l&amp;ai=DChcSEwi55_OKkuv9AhVCHH0KHcpsCLYYABAAGgJwdg&amp;sig=AOD64_1KUb_0OzwIFwPoew8U1G_Tevq5tQ&amp;q&amp;adurl&amp;ved=2ahUKEwjulOuKkuv9AhVUDEQIHYW7APEQ0Qx6BAgEEAE">CLI version.</a> The CLI version is installed with MacPorts.</li><li><a href="https://sqlitebrowser.org/dl/">SQLite Browser</a> — If you use SQLite databases. JetBrains also has <a href="https://www.google.com/aclk?sa=l&amp;ai=DChcSEwiNw46gk-v9AhWfLK0GHesDCkwYABAAGgJwdg&amp;sig=AOD64_17CVagh5n6UcFy0Ry8uyv4Rv6mTg&amp;q&amp;adurl&amp;ved=2ahUKEwiGgIagk-v9AhXuJ0QIHS2sAAEQ0Qx6BAgGEAE">DataGrip</a> but that’s a paid option. The <a href="https://www.google.com/aclk?sa=l&amp;ai=DChcSEwjP7oeqk-v9AhXqH60GHfVHDkUYABAAGgJwdg&amp;sig=AOD64_0lRtlX3ce8uCU1mLASNEx0IgMdJA&amp;q&amp;adurl&amp;ved=2ahUKEwjo0YCqk-v9AhXpC0QIHVMeAEoQ0Qx6BAgGEAE">PyCharm Professional </a>can also link databases but is also a paid option</li><li><a href="https://mrrsoftware.com/namechanger/">Namechanger</a> — I Like the program for changing large numbers of files. Easier than the command line and remembering regex.</li></ul><h3>Step 2: Install XCode or XCode CLI.</h3><p>XCode is apples native compiler (like GCC). If you are going to compile anything from source code at least the CLI tools need to be installed.</p><p>Either install the full application from the<a href="https://apps.apple.com/us/app/xcode/id497799835?mt=12"> Apple App Store</a> or use the following CLI commands.</p><pre>xcode-select --install<br>sudo xcodebuild -license accept</pre><h3>Step 3: Install Open Source Binaries from MacPorts.</h3><p>I install a bunch of tools that I always use. What I like about MacPorts over HomeBrew is the ability to install binaries for the whole computer, not just a user. I use multiple logins for my personal MacBook when I am consulting or working on a specific project for a customer. This allows me to not have to re-install everything for each user on the computer.</p><p>I use Python, AWS CLI2, Boto3, NPM, SQLite3, QT4/QT5, FFMpeg, and ImageMagic. I have also stayed with the BASH shell even though Apple wants me to change to zsh. I have too much time with BASH to switch. It is best to use the MacPorts installation if it exists for Python Libraries and other extensions. These will update together with the platform if installed.</p><p>At this time I am using Python 3.10 and NPM9. (Change the version to your version). Comment out any packages you are not using from the script.</p><p>After all of the installations, you will need to update the global paths in OSX. There are some “gotchas” after an OSX Upgrade or possibly an update. MacPorts will add a line to your local shell startup file. This will change later.</p><p>Make sure that MacPorts (port command) is on the path. Open a terminal window and type the following:</p><pre>sudo port selfupdate</pre><p>This will yield the following results if everything is good.</p><pre>LAPTOPNAME:~ colin$ sudo port selfupdate<br>---&gt;  Updating MacPorts base sources using rsync<br>MacPorts base version 2.8.1 installed,<br>MacPorts base version 2.8.1 downloaded.<br>---&gt;  Updating the ports tree<br>---&gt;  MacPorts base is already the latest version<br></pre><p>This is the script I use, tailor as needed. It is best to either do this one by one or create the script. The issue is if you cut and paste this, the “sudo” command will timeout along the way and hang up. If you create the script and run it with “sudo” the whole script will be in “sudo” and you can go get coffee.</p><pre>#!/bin/bash<br># Install Non-Pythonic builds<br>sudo -H port -N install qt5 <br>sudo -H port -N install ImageMagick<br>sudo -H port -N install sqlite3 sqlite3-tools <br>#sudo -H port -N install mongo<br>sudo -H port -N install texlive-xetex<br>sudo -H port -N install pandoc<br>sudo -H port -N install AtomicParsley<br>sudo -H port -N install mediainfo<br>sudo -H port -N install texlive-xetex<br>sudo -H port -N install pandoc<br>sudo -H port -N install cmake<br>sudo -H port -N install py-numpy<br>sudo -H port -N install ffmpeg-devel +gpl2 +gpl3 +nonfree<br>sudo -H port -N install libdvdnav<br>sudo -H port -N install lsdvd<br>sudo -H port -N install x264transcode<br>sudo -H port -N install HandBrake<br>sudo -H port -N install HandBrake71<br>sudo -H port -N install HandBrakeCLI<br>sudo -H port -N install 1password-cli<br>sudo -H port -N install dlib<br>sudo -H port -N install opencv4<br>sudo -H port -N install py-pyqt5<br>sudo -H port -N install sqlite3-tcl<br>sudo -H port -N install pandoc<br><br># INSTALL NODEJS AND NPM<br>sudo -H port install -N npm9<br>sudo -H port install -N nodejs19<br>sudo -H npm install --save-dev webpack webpack-cli<br><br># Install Python and libraries<br><br># Install Basic Python first<br>sudo -H port -N install python310<br>sudo -H port -N install py310-pip<br># This installs basic python 310 at the same time<br>sudo -H port select --set pip pip310<br>sudo -H port select --set pip3 pip310<br>sudo -H port select --set python python310<br>sudo -H port select --set python3 python310<br><br># Install Jypyter Lab 310<br># There are some various issues where you might want to install Jupyter <br># Manually (with PIP) most of the time this is fine.<br>sudo -H port -N install py-jupyter py310-jupyterlab<br><br># Install Additional Python Modules directly.<br>sudo -H port -N install py310-yaml<br>sudo -H port -N install py310-xmltodict<br>sudo -H port -N install py310-beautifulsoup4 py310-soupsieve<br>sudo -H port -N install py310-openssl<br>sudo -H port -N install py310-validators  <br>sudo -H port -N install py310-numpy py310-Pillow <br>sudo -H port -N install py310-opencv4<br>sudo -H port -N install py310-awscli2<br><br># Select Versions<br>sudo -H port select --set cython cython310<br>sudo -H port select --set ipython py310-ipython<br>sudo -H port select --set ipython3 py310-ipython<br>sudo -H port select --set pygments py310-pygments<br><br># Load DBUS<br>sudo -H port load dbus<br><br><br># Install Python Modules not in MacPorts<br>sudo -H pip3 install ffmpeg-python</pre><p><strong>Note:</strong></p><p>If you don’t use “sudo”, then it will be installed for the local user only. There is also maintenance work you do with the port command. “port selfupdate” and “port upgrade outdated”</p><h3>Step 4: Customize your operating system&#39;s global settings.</h3><p><strong>Create the file $HOME/.bash_profile</strong></p><p>This creates colorization and reads in the .bash_rc (non-interactive profile)</p><pre># Bash Profile<br># # Interactive Login <br>if [ -f ~/.bashrc ]; then<br> . ~/.bashrc<br>fi<br><br># Colorize the shell<br>export CLICOLOR=1<br>export LSCOLORS=GxFxCxDxBxegedabagaced</pre><p><strong>Create the file $HOME/.bashrc</strong></p><pre># Bash non-interactive settings<br># Allow Biometric login for 1Password CLI<br>export OP_BIOMETRIC_UNLOCK_ENABLED=true</pre><h4>Modify the global paths.</h4><p>You may need to do both steps depending on how OSX interacts with python versions that are not native. After any major upgrade to OSX, it’s best to check your path variables.</p><h4>Method 1: (After)</h4><p>Install the paths to /etc/paths.d. This will append these paths to the existing paths. (AFTER). If you get the wrong python version, use method 2 to put them (BEFORE). Note the manpath variable needs to be set regardless of version.</p><pre>sudo sh -c &quot;echo &quot;/opt/local/bin&quot; &gt; /etc/paths.d/mac-ports&quot;<br>sudo sh -c &quot;echo &quot;/opt/local/sbin&quot; &gt; /etc/paths.d/mac-ports&quot;<br>sudo bash -c &quot;echo &#39;MANPATH=/opt/local/share/man:\$MANPATH&#39; &gt; /etc/manpaths.d/mac-ports&quot;</pre><h4>Method 2: (Before)</h4><pre>sudo sed -i ‘’ -e $’1i\\\n/opt/local/bin’ /etc/paths<br>sudo sed -i ‘’ -e $’2i\\\n/opt/local/sbin’ /etc/paths</pre><h4>Test to see if it works:</h4><pre>python3 --version</pre><p>It should return the correct version. If it doesn’t verify the path with “which python3”</p><h3>Step 5: Configure SSH.</h3><pre>mkdir $HOME/.ssh<br>chmod 700 $HOME/.ssh<br>touch $HOME/.ssh/config<br>touch $HOME/.ssh/authorized_keys<br>touch $HOME/.ssh/known_hosts<br><br># Set permissions<br>chmod 600 .ssh/authorized_keys<br>chmod 600 .ssh/known_hosts<br>chmod 600 .ssh/config</pre><h4>Generate a key pair</h4><pre>ssh-keygen -t rsa -b 4096</pre><h4>Results:</h4><pre>LAPTOPNAME:.ssh colin$ ssh-keygen -t rsa -b 4096<br>Generating public/private rsa key pair.<br>Enter file in which to save the key (/Users/colin/.ssh/id_rsa): <br>Enter passphrase (empty for no passphrase): <br>Enter same passphrase again: <br>Your identification has been saved in /Users/colin/.ssh/id_rsa<br>Your public key has been saved in /Users/colin/.ssh/id_rsa.pub<br>The key fingerprint is:<br>SHA256:ujBhWvMctWsE6HMMkW2LbMREznU/30zZL1DNAHeckao colin@LAPTOPNAME.local<br>The key&#39;s randomart image is:<br>+---[RSA 4096]----+<br>|   ++o. .   ..+*=|<br>|   o++o. .   o *+|<br>|   o=o... o . + .|<br>|   .+o.o . o *  .|<br>|   .B + S   o + .|<br>|   + B + . E   . |<br>|  . o + o        |<br>|     o o         |<br>|      .          |<br>+----[SHA256]-----+</pre><p>I generally don’t use a passphrase. There are good reasons to use them if you are working with more sensitive information.</p><p>Now set the permissions on your keys. They should have been correct, but we want to make sure.</p><pre>chmod 600 .ssh/id_rsa<br>chmod 600 .ssh/id_rsa.pub</pre><h4>Create an ssh “config” file.</h4><p>This makes life a lot easier especially if you have to use a proxy (bastion host)</p><p>edit the file “$HOME/.ssh/config”</p><pre># SSH Config file<br>#<br># Hosts you connect to go here<br>Host myserver<br>  hostname my.server.com<br>  port 22<br>  IdentityFile ~/.ssh/id_rsa<br>  User colin<br><br>Host myserver<br>  hostname 192.168.1.10<br>  port 22<br>  IdentityFile ~/.ssh/santaclause_rsa<br>  User santaclause<br><br># General Settings<br>#########################################################################################<br>Host *<br>  # Compression yes<br>  # ControlMaster auto<br>  # ControlPath ~/.ssh/ssh-ctrl_%r@%h:%p<br>  ForwardAgent yes<br>  LogLevel quiet<br>  ServerAliveCountMax 4<br>  ServerAliveInterval 240<br>  StrictHostKeyChecking no<br>  UserKnownHostsFile=/dev/null<br>  AddKeysToAgent yes<br>  User colin<br>  IdentityAgent &quot;~/Library/Group Containers/2BUA8C4S2C.com.1password/t/agent.sock&quot;<br><br>##########################################################################################<br># Proxy Configuration<br>##########################################################################################<br>Host *+*<br>  ProxyCommand ssh -T -A $(echo %h |cut -d+ -f1) nc $(echo %h |cut -d+ -f2) %p 2&gt;/dev/null<br></pre><p><strong>Note:</strong></p><p>You can add a default user to the general settings (“User”) and you can send all known hosts to /dev/null if the hosts change and you don’t want notifications.</p><p>Customize as needed. <a href="https://www.howtouselinux.com/post/ssh-config-file-with-examples">Examples are here</a></p><h3>Configure GIT if used</h3><p>Git no longer allows passwords for access. If you are using git you will need to have a token setup. Additionally, you can configure HTTP or SSH (use SSH config).</p><pre># Add your name and email address.<br>git config --global user.name &quot;John Doe&quot;<br>git config --global user.email johndoe@example.com<br>git config --global color.ui true</pre><p>Create a personal access token. <a href="https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/creating-a-personal-access-token">Instructions are here</a></p><p><strong>The token becomes your password. Be sure to put it in your password manager for future reference.</strong></p><h3>Aliases</h3><p>A note for people new to OSX or Linux CLIs. When you have a preference for commands you want to run, using an alias is useful. I use them to start/stop docker containers or just customize a command for my usual preferences.</p><p>For instance, if you want to run “ls -lah” instead of “ls” because that is the version you use most frequently. We could also create a custom command ll to be ls -lah.</p><pre>alias ls=&quot;ls -lah&quot;<br>alias ll=&quot;ls -la&quot;</pre><p>This will change the ls command to ls -lah. Add this line to your $HOME/.bashrc file we created earlier</p><pre># Add to .bashrc <br># alias alias_name=&quot;command_to_run&quot;<br><br># Long format list<br>alias ll=&quot;ls -la&quot;<br><br># Print my public IP<br>alias myip=&#39;curl ipinfo.io/ip&#39;</pre><h3>Security By Design</h3><p>One of the requirements for companies to be certified in SOC2, ISO 27001, NIST 800–171, NIST 800–53, HITRUST, and others is security by design. This involves having a “well” setup laptop. (Windows or Mac)</p><p><em>Security by design is an approach to software and hardware development that seeks to make systems as free of vulnerabilities and impervious to attack as possible through such measures as continuous testing, authentication safeguards, and adherence to best programming practices.</em></p><p><strong>Basic things:</strong></p><ul><li>Turn on automatic updates for the operating system, browsers, and key applications. Only turn this off if there is a possibility for disaster from updates. If it’s turned off, set a schedule on your calendar to check and update the applications at least monthly.</li><li>Only use CIS level 1 hardened containers and VMs for development work. It’s easier to do this than it is to figure out how to harden something already working.</li><li>Never put passwords, keys, or other secrets into Github or in code.</li><li>Never “Hack” something “To make it work”. Understand the settings and where the vendor wants them set.</li><li>When writing code use a linter to make sure your code is good and to standard.</li><li>Make sure libraries that you include “pip install xxx” are licensed for the work you do. Just because it is open source doesn’t mean it can be used for government work or commercial work.</li><li>Use <a href="https://snyk.io/blog/snyk-code-now-available-free-sast/">Snyk freemium</a> for checking or something similar.</li><li>Import only the part of the library you need in python from xxx import yyyy.</li><li>Don’t be in the password business if you can avoid it. (Auth0 for instance)</li><li><strong>If you write a web application, make sure it supports cut-and-paste from at least two different password managers.</strong></li><li>Don’t bind yourself to specific versions of languages (python 3.8 v 3.10 v generic 3.x). Upgrading to the new version should never be an issue.</li></ul><h3>References:</h3><ul><li><a href="https://www.cyberciti.biz/faq/apple-mac-osx-terminal-color-ls-output-option/">How to enable colorized output for ls command in MacOS X Terminal - nixCraft</a></li><li><a href="https://www.macports.org/">The MacPorts Project</a></li><li><a href="https://developer.1password.com/docs/cli/about-biometric-unlock/?utm_medium=organic&amp;utm_source=oph&amp;utm_campaign=macos">About the 1Password app integration | 1Password Developer</a></li><li><a href="https://www.macports.org/">The MacPorts Project</a></li><li><a href="https://www.jetbrains.com/">JetBrains: Essential tools for software developers and teams</a></li><li><a href="https://mrrsoftware.com/namechanger/">NameChanger - MRR Software</a></li><li><a href="https://www.titanium-software.fr/en/onyx.html">OnyX</a></li><li><a href="https://iterm2.com/">iTerm2 - macOS Terminal Replacement</a></li><li><a href="https://snyk.io/blog/snyk-code-now-available-free-sast/">Snyk Code is now available for free | Snyk</a></li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=dad5596e0a51" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Create a python module shell in under 5 minutes]]></title>
            <link>https://cbitterfield.medium.com/create-a-python-module-shell-in-under-5-minutes-762d2d30dcea?source=rss-f8e598d5fbb1------2</link>
            <guid isPermaLink="false">https://medium.com/p/762d2d30dcea</guid>
            <category><![CDATA[python-programming]]></category>
            <category><![CDATA[python3]]></category>
            <dc:creator><![CDATA[Colin Bitterfield]]></dc:creator>
            <pubDate>Wed, 09 Dec 2020 14:19:37 GMT</pubDate>
            <atom:updated>2020-12-09T14:19:37.082Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1000/0*znXp3wVTi7lhF4hm.jpg" /><figcaption>Python is like the pyramids it takes forever to get setup</figcaption></figure><p>I routine create python modules for security work and personal fun projects. Getting a directory structure prepared and prepped takes way too long manually. Recently I found a tool called <a href="https://github.com/toptive/generator-toptive-python">“toptive python”</a> that runs in <a href="https://yeoman.io/">Yeomn</a>. It creates a shell, docker file, documentation and a complete skeleton for a well formed python module. Credit to “<a href="https://fgriberi.github.io/">Franco Riberi</a>”</p><p><a href="https://yeoman.io/">The web&#39;s scaffolding tool for modern webapps | Yeoman</a></p><p>I use MacPorts to install NPM and yo.</p><p>$ sudo port install npm</p><p>$ sudo npm install -g yo</p><p>Then I installed Toptive-Python</p><p>$ npm install -g generator-toptive-python</p><p>For a little background, I use <a href="https://www.jetbrains.com/idea/">IntellJ Idea</a> as my IDE but this will work for any IDE.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/574/1*p2ba2EEf2EaJYoUyx6dMsw.png" /></figure><h3>Now on to creating a shell repository in git hub.</h3><p>Example:</p><p><strong>Repository Name: medium-shell</strong></p><h4>Open your favorite browser and negotiate to <a href="https://www.github.com">Github</a></h4><p><strong>Example:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/861/1*sSi0_aohGa43ck63ZsOb2A.png" /><figcaption>Create Repository</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zNfEF_D1RN8oI1VOqGWWQA.png" /><figcaption>Repository Created</figcaption></figure><h4>Open your terminal program</h4><p>$ cd ${project_directory}</p><h4>Run Topotive-Python</h4><p>yo toptive-python</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/536/1*HMUUBDlZ5osGrjO7w38X8g.png" /><figcaption>Creating the Shell</figcaption></figure><h4>Uploading the initial shell to GitHub and creating the repository initialization.</h4><ul><li>See GitHub Instruction from initial creation for more information.</li></ul><p>razzamataz:IdeaProjects colin$ cd medium-shell/<br>razzamataz:medium-shell colin$ git init<br>Initialized empty Git repository in /Users/colin/IdeaProjects/medium-shell/.git/<br>razzamataz:medium-shell colin$ git add *<br>razzamataz:medium-shell colin$ git commit -m “first commit medium shell”<br>[master (root-commit) f2088a8] first commit medium shell<br> 31 files changed, 968 insertions(+)<br> create mode 100644 AUTHORS.rst<br> create mode 100644 CHANGELOG.rst<br> create mode 100644 CONTRIBUTING.rst<br> create mode 100644 Dockerfile<br> create mode 100644 LICENSE.rst<br> create mode 100644 MANIFEST.in<br> create mode 100644 Makefile<br> create mode 100644 README.rst<br> create mode 100644 docs/Makefile<br> create mode 100644 docs/authors.rst<br> create mode 100755 docs/conf.py<br> create mode 100644 docs/contributing.rst<br> create mode 100644 docs/history.rst<br> create mode 100644 docs/index.rst<br> create mode 100644 docs/installation.rst<br> create mode 100644 docs/make.bat<br> create mode 100644 docs/readme.rst<br> create mode 100644 docs/usage.rst<br> create mode 100644 medium-shell/__init__.py<br> create mode 100644 medium-shell/medium-shell.py<br> create mode 100644 requirements/dev.txt<br> create mode 100644 requirements/prod.txt<br> create mode 100644 requirements/test.txt<br> create mode 100644 setup.cfg<br> create mode 100644 setup.py<br> create mode 100644 stests/__init__.py<br> create mode 100644 stests/common_resources.robot<br> create mode 100644 stests/default_suite.robot<br> create mode 100644 tox.ini<br> create mode 100644 utests/__init__.py<br> create mode 100644 utests/test_python_boilerplate.py<br>razzamataz:medium-shell colin$ git branch -M main<br>razzamataz:medium-shell colin$ git remote add origin <a href="mailto:git@github.com">git@github.com</a>:cbitterfield/medium-shell.git<br>razzamataz:medium-shell colin$ git push -u origin main<br>Enumerating objects: 37, done.<br>Counting objects: 100% (37/37), done.<br>Delta compression using up to 16 threads<br>Compressing objects: 100% (32/32), done.<br>Writing objects: 100% (37/37), 13.05 KiB | 2.61 MiB/s, done.<br>Total 37 (delta 0), reused 0 (delta 0)<br>To github.com:cbitterfield/medium-shell.git<br> * [new branch] main -&gt; main<br>Branch ‘main’ set up to track remote branch ‘main’ from ‘origin’.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*HGgzbQSqN-AcKWTexRBJPw.png" /><figcaption>Repository is ready for use.</figcaption></figure><p><a href="https://github.com/cbitterfield/medium-shell">Link to the actual repository I created.</a></p><p>The python tool “<a href="https://pypi.org/project/bumpversion/">Bumpversion</a>” is very useful here as well.</p><p>This shell is well formed and has everything you need in place to integrate with <a href="https://travis-ci.org/">Travis</a> and CICD pipelines.</p><h4>Installing Bumpversion with MacPort Python</h4><p>$ sudo port install py38-pip</p><p>— -&gt; Some of the ports you installed have notes:<br> py38-pip has the following notes:<br> To make the Python 3.8 version of pip the one that is run when you execute the commands without a version suffix, e.g. ‘pip’,<br> run:<br> sudo port select — set pip pip38<br> sudo port select — set pip3 pip38<br><strong>$ sudo port select — set pip pip38</strong><br>Selecting ‘pip38’ for ‘pip’ succeeded. ‘pip38’ is now active.<br><strong>$ sudo port select — set pip3 pip38</strong><br>Selecting ‘pip38’ for ‘pip3’ succeeded. ‘pip38’ is now active.</p><p><strong>$ pip install — upgrade bumpversion</strong><br>Defaulting to user installation because normal site-packages is not writeable<br>Collecting bumpversion<br> Using cached bumpversion-0.6.0-py2.py3-none-any.whl (8.4 kB)<br>Collecting bump2version<br> Using cached bump2version-1.0.1-py2.py3-none-any.whl (22 kB)<br>Installing collected packages: bump2version, bumpversion<br> WARNING: The scripts bump2version and bumpversion are installed in ‘/Users/colin/Library/Python/3.8/bin’ which is not on PATH.<br> Consider adding this directory to PATH or, if you prefer to suppress this warning, use — no-warn-script-location.<br>Successfully installed bump2version-1.0.1 bumpversion-0.6.0</p><ul><li><strong>Note for a Mac with MacPorts and your local bin file to your .profile, .zprofile, .bashrc or similar file. (Not recommended to add to global profile)</strong></li></ul><p><strong>I use bash even though OSX 11.0 has recommended Zshell. Too many years of BASH programming to relearn.</strong></p><p><strong>$ echo “/Users/${USER}/Library/Python/3.8/bin” &gt;&gt; ~/.profile</strong></p><h4>Install Python virtualenv if not already installed.</h4><p><strong>Example:</strong></p><p><strong>$ sudo port install py38-virtualenv</strong><br>Password:<br> — -&gt; Computing dependencies for py38-virtualenv<br>The following dependencies will be installed:<br> py38-appdirs<br> py38-distlib<br> py38-filelock<br> py38-six<br> virtualenv_select<br>Continue? [Y/n]: y</p><p>…</p><p>— -&gt; Some of the ports you installed have notes:<br> py38-virtualenv has the following notes:<br> The executable is installed as ‘/opt/local/bin/virtualenv-3.8’. To symlink it to ‘/opt/local/bin/virtualenv’, run:</p><p>sudo port select — set virtualenv virtualenv38<br>$ sudo port select — set virtualenv virtualenv38<br>Selecting ‘virtualenv38’ for ‘virtualenv’ succeeded. ‘virtualenv38’ is now active.</p><h3>Congratulations: You are now ready to code.</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/840/0*Sv2G2-xMmJxOUJe1.jpg" /><figcaption>Time to code</figcaption></figure><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=762d2d30dcea" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Setting up your MAC OSX 11 to use the AWS CLI and other python tools for accessing Amazon Web…]]></title>
            <link>https://cbitterfield.medium.com/setting-up-your-mac-osx-11-to-use-the-aws-cli-and-other-python-tools-for-accessing-amazon-web-6801de8a6855?source=rss-f8e598d5fbb1------2</link>
            <guid isPermaLink="false">https://medium.com/p/6801de8a6855</guid>
            <dc:creator><![CDATA[Colin Bitterfield]]></dc:creator>
            <pubDate>Mon, 30 Nov 2020 19:35:36 GMT</pubDate>
            <atom:updated>2020-12-02T20:46:28.307Z</atom:updated>
            <content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*eR0c10iwK_uD5-tSg38xXA.jpeg" /><figcaption>Desert in Israel</figcaption></figure><h3>Setting up your MAC OSX 11 to use the AWS CLI and other python tools for accessing Amazon Web Services (AWS)</h3><p>Every time that I change work laptops or upgrade my laptop to a new version of MAC OSX, I need to remove and reconfigure parts of MAC Ports and get things going. This is a short guide to getting things working for new OSX users working with the Amazon Command Line Interface (AWS CLI).</p><figure><img alt="Coffee Mug" src="https://cdn-images-1.medium.com/max/100/0*qVC_DXAKnNnMTlmK.jpeg" /><figcaption>Image by Anna Maria Weaver</figcaption></figure><p>First step is to make sure that you have working credentials for a user account. For this we will need to create some IAM objects in your AWS Account. If you have root access or its equivalent, please login with those credentials. We will create the following objects:</p><blockquote>Group named “ReadOnlyAdmin” &lt;- Assigned RO Admin level credentials.<br>User named “roadmin” &lt;- Added to Group<br>Keys for the User “roadmin”</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*g71ZZsHKm7eYkm_W4WFl3w.png" /><figcaption>AWS IAM Manager</figcaption></figure><p>Choose Create New Group</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*06owz-1TOHMDe1gkiry-gg.png" /></figure><p>Enter Security Audit In the Policy and select it.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Q2-66DowJ1RKokl6x2yP5A.png" /><figcaption>Attach Security Audit Policy</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*VR5ZCgInT5k9vSWvR0Kg8Q.png" /><figcaption>Review the Group</figcaption></figure><p>Create the Group</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*eyu0jGL_RQ9dwjPHo9_RFw.png" /></figure><p><strong>Now we create the User and add the user to the group.</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*eP7VpGPVd02WbRtzqLufFg.png" /></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xQnxmM3HFeN3bQ8FXC4sIg.png" /><figcaption>Add user step 1</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wAYKHonXVYGcDKy1jB0Iww.png" /><figcaption>Add user to group</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AD5yQ--cmaOkxaWOQGg-SA.png" /><figcaption>Add tags if needed</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mqCMGifIbnrGIb7N1UtKSA.png" /><figcaption>Review New User</figcaption></figure><p>Very important. Download the keys now. They will not be available later.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f4U39kiptSlzUEFcBfQ2bA.png" /><figcaption>Download the CSV with the keys</figcaption></figure><p>Very important. Download the keys now. They will not be available later.</p><p><strong>At this point you should have the following handy:</strong></p><ol><li><strong><em>Username</em></strong></li><li><strong><em>Access Key</em></strong></li><li><strong><em>Secret Key</em></strong></li><li><strong><em>Default Region (us-east-2)<br><br>(Where are you working, us-east-1, us-east-2, us-west-1 and so on). I am working in us-east-2 (so that will be my default.</em></strong></li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/428/1*klOITzuia0gjql-0Iv9sJw.png" /><figcaption>www.macports.org</figcaption></figure><p><a href="https://www.macports.org/">The MacPorts Project</a></p><h3>Installation of <a href="https://www.macports.org/">MAC Ports</a> for Python, Jupyter, and AWS CLI</h3><ol><li>Download the MAC Ports installer from: <a href="https://github.com/macports/macports-base/releases/">https://github.com/macports/macports-base/releases/</a></li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8Mb81BdMRCBF90tqDLOMGg.png" /></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5veg4rn4L7U-jf7YD3usdg.png" /></figure><p>Setup the environment variables</p><p>Mac PORTS binaries and man pages are located under the /opt/local directory. There are two ways to accomplish setting the variables automatically. You can add them to the users profile or the global profiles. I prefer to add things globally so that other users can also use them. We need to set the following variables:</p><ol><li>PATH</li><li>MANPATH</li></ol><p>Run this command in the terminal window to create the appropriate path. You will need to close your terminal window and reopen to get the new changes after.</p><h4>Adding the binaries after system binaries use this method:</h4><blockquote><em>sudo sh -c “echo “/opt/local/bin” &gt; /etc/paths.d/mac-ports”</em></blockquote><p>You can test if it worked by running this command</p><blockquote>env | grep PATH</blockquote><p><strong>Results:</strong></p><p>PATH=/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin:/opt/local/Library/Frameworks/Python.framework/Versions/3.8/bin:<strong>/opt/local/bin</strong></p><h4>Adding the binaries before system binaries use this method.</h4><ul><li>Note: After updates or upgrades you may need to run this</li></ul><p>sudo sed -i ‘’ -e $’1i\\\n/opt/local/bin’ /etc/paths</p><p>sudo sed -i ‘’ -e $’2i\\\n/opt/local/sbin’ /etc/paths</p><h4>Add the MANPATH Variable to the system</h4><p>sudo bash -c &quot;echo &#39;MANPATH=/opt/local/share/man:\$MANPATH&#39; &gt; /etc/manpaths.d/mac-ports&quot;</p><p>You are all set to have easy access to MacPorts now.</p><h3>Next we will add all of the tools we will need for developing AWS Python applications or access it with Jupyter Notebook.</h3><ol><li>Open the terminal window</li><li>run: sudo port install py38-awscli<br><em> </em><em>— -&gt; Computing dependencies for py38-awscli<br>The following dependencies will be installed:<br> awscli_select<br> bzip2<br> expat<br> gettext<br> libedit<br> libffi<br> libiconv<br> libyaml<br> ncurses<br> openssl<br> py38-asn1<br> py38-botocore<br> py38-certifi<br> py38-colorama<br> py38-dateutil<br> py38-docutils<br> py38-ipaddress<br> py38-jmespath<br> py38-roman<br> py38-rsa<br> py38-s3transfer<br> py38-setuptools<br> py38-six<br> py38-tz<br> py38-urllib3<br> py38-yaml<br> python38<br> python3_select<br> python_select<br> sqlite3<br> xz<br> zlib<br>Continue? [Y/n]: Y</em></li><li>Set the Python as primary if you so desire:<br><em>python38 has the following notes:<br> To make this the default Python or Python 3 (i.e., the version run by the ‘python’ or ‘python3’ commands), run one or both of:</em></li><li><strong><em>sudo port select --set python python38<br> sudo port select --set python3 python38</em></strong></li><li>Install Jupyter Lab (aka Notebook)<br> sudo port install py38-jupyterlab</li></ol><p>— -&gt; Computing dependencies for py38-jupyterlab<br>The following dependencies will be installed:<br> ipython3_select<br> ipython_select<br> py38-appnope<br> py38-argon2-cffi<br> py38-async_generator<br> py38-attrs<br> py38-backcall<br> py38-bleach<br> py38-cffi<br> py38-chardet<br> py38-decorator<br> py38-defusedxml<br> py38-entrypoints<br> py38-idna<br> py38-ipykernel<br> py38-ipython<br> py38-ipython_genutils<br> py38-jedi<br> py38-jinja2<br> py38-json5<br> py38-jsonschema<br> py38-jupyter_client<br> py38-jupyter_core<br> py38-jupyterlab_pygments<br> py38-jupyterlab_server<br> py38-markupsafe<br> py38-mistune<br> py38-nbclient<br> py38-nbconvert<br> py38-nbformat<br> py38-nest_asyncio<br> py38-notebook<br> py38-packaging<br> py38-pandocfilters<br> py38-parsing<br> py38-parso<br> py38-pexpect<br> py38-pickleshare<br> py38-prometheus_client<br> py38-prompt_toolkit<br> py38-ptyprocess<br> py38-pycparser<br> py38-pygments<br> py38-pyrsistent<br> py38-requests<br> py38-send2trash<br> py38-terminado<br> py38-testpath<br> py38-tornado<br> py38-traitlets<br> py38-wcwidth<br> py38-webencodings<br> py38-zmq<br> pygments_select<br> zmq</p><p>— -&gt; Some of the ports you installed have notes:<br> py38-ipython has the following notes:<br> To make this the default IPython or IPython3 (i.e., the version run by the ‘ipython’ or ‘ipython3’ commands), run one or both of:</p><p>sudo port select --set ipython py38-ipython<br> sudo port select --set ipython3 py38-ipython</p><p>py38-pygments has the following notes:<br> To make the Python 3.8 version of Pygments the one that is run when you execute the commands without a version suffix, e.g. ‘pygmentize’, run:</p><p>port select --set pygments py38-pygments</p><h3>Configure AWS CLI for access to your AWS Account and test.</h3><p>Configure:</p><p>From a terminal window run the following command. Remember to have your user keys handy.</p><p>$ aws configure --profile roadmins<br>AWS Access Key ID [None]: NZ7JN2HX3KC89PC79V09<br>AWS Secret Access Key [None]: !bAivY20SDQCFaB^A!G5VAy597va5ZufwVQGdab@<br>Default region name [None]: us-east-2<br>Default output format [None]: text</p><p><strong>I am using a “profile” to avoid conflict with other user keys on my system. Each seperate user key pair can be a profile. If this is your first an only, you can omit the </strong><strong>--profile part to configure the default profile.</strong></p><p>Test:</p><p>Run this command to test<br>aws --profile roadmins ec2 describe-vpcs</p><p><strong>Results should be similar:</strong></p><p>VPCS 172.31.0.0/16 dopt-06a3366d default True 971650852359 available vpc-5f318134<br>CIDRBLOCKASSOCIATIONSET vpc-cidr-assoc-7410a21f 172.31.0.0/16<br>CIDRBLOCKSTATE associated<br>VPCS 10.1.0.0/16 dopt-06a3366d default False 971650852359 available vpc-028ffd91330d05253<br>CIDRBLOCKASSOCIATIONSET vpc-cidr-assoc-0c4bf677e28d16205 10.1.0.0/16<br>CIDRBLOCKSTATE associated<br>TAGS Name atc-vpc01</p><p>** I am assuming this is a new account without EC2s and other objects. So we will get a list of available VPCs because that exists in every new account.</p><h3>Additional Reading and recommendations</h3><ol><li>Add your AWS ssh keys to .ssh/config and configure for easy access</li><li>Using Jupyter Notebook for accessing the AWS Cli</li><li>Additional tools that are useful in Jupyter notebook and MAC Ports: ImageMagick, Pillow, FFMEG, SQLite and any other linux tool you might want including tools like gnu versions of build-in tools (i.e. ggrep or gawk)</li></ol><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=6801de8a6855" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Installing SuiteCRM in the Cloud]]></title>
            <link>https://cbitterfield.medium.com/installing-suitecrm-in-the-cloud-23c2a9e8c611?source=rss-f8e598d5fbb1------2</link>
            <guid isPermaLink="false">https://medium.com/p/23c2a9e8c611</guid>
            <category><![CDATA[startup]]></category>
            <category><![CDATA[jumpcloud]]></category>
            <category><![CDATA[lets-encrypt]]></category>
            <category><![CDATA[suitecrm]]></category>
            <category><![CDATA[lamp]]></category>
            <dc:creator><![CDATA[Colin Bitterfield]]></dc:creator>
            <pubDate>Thu, 26 Dec 2019 04:01:28 GMT</pubDate>
            <atom:updated>2019-12-26T04:01:28.726Z</atom:updated>
            <content:encoded><![CDATA[<p>I am working with several small businesses with business development and automation issues. We evaluated SalesForce.com and some other CRM solutions. For a startup, the question is always a cost-related one. Most small businesses cannot purchase every cloud service they need until they hit at least 20–30 people, and even then, the cost of the service cuts into the growth budget.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/100/1*XtpndQW5EKH_9BV0P4whtA.jpeg" /><figcaption>Image by Anna Maria Weaver</figcaption></figure><p>We called Sales and found out it will cost at lease $900.00/year per person. The other issue is that even with one salesperson, there is at least one or two other people that need access to the CRM data. The overall cost to start could be $2,700.00. My customer asked me if there were some alternatives. I checked out Godaddy (application) offering, among other openSource offerings. After some evaluation of openSource products currently being developed, we landed on SuiteCRM. I spoke to my friends over at Atlantic.NET for server costing, and they have a $10/month no-contract plan. So we opted for this option. Atlantic.NET also offers managed solutions and compliance managed solutions.</p><p><a href="https://www.atlantic.net">Customized Hosting Solutions For Your Business | Atlantic.Net</a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/145/1*CZw4yg0ZtDuDGJG1odghaA.png" /><figcaption>Atlantic.Net basic server</figcaption></figure><p>The $10/month server is a starter server. We chose Ubuntu (Bionic Beaver) 18.04 LTS for the most extended support. The Ubuntu 16.04.6 LTS (Xenial Xerus) is also an excellent choice. Both will be supported way into the future. Ubuntu created a long term support Linux option. It makes it a compelling argument for business.</p><p>SuiteCRM: “Our feature-rich enterprise-ready alternative to Salesforce provides all the benefits of CRM at substantially lower costs with the freedoms and flexibility of Open Source.”</p><p><a href="https://suitecrm.com/">SuiteCRM - Open Source CRM Software Application for Businesses</a></p><p>The compelling argument is that it can grow to a fully supported alternative to SalesForce.</p><p>SuiteCRM publishes the following requirements.</p><h3>Recommended installation pre-requisites</h3><ul><li>PHP</li><li>JSON</li><li>XML Parsing</li><li>MB Strings Module</li><li>Writable SugarCRM Configuration File (config.php)</li><li>Writeable Custom Directory</li><li>Writable Modules Sub-Directories and Files</li><li>Writable Upload Directory</li><li>Writable Data Sub-Directories</li><li>Writable Cache Sub-Directories</li><li>PHP Memory Limit (at least 128M)</li><li>ZLIB Compression Module</li><li>ZIP Handling Module</li><li>PCRE Library</li><li>IMAP Module</li><li>cURL Module</li><li>Upload File Size</li><li>Sprite Support</li></ul><p>The translation is there is not full documentation of the installation. This will eventually lead to a research project and discovering where it doesn’t work. This article is a shortcut to getting up in a few hours.</p><p>It is my opinion that a better way to put requirements is to have a list of commands for RHEL(yum) or DEB (apt). I have a personal preference for using Percona MySQL. I think it is a much faster implementation of MySQL, and the license is free. Be aware that not all free downloadable versions are free for commercial use (aka Oracle Version).</p><p><strong><em>Notice: The 7.11 version says it supports Elastic Search. The smaller node I am using is too small for that. You need two cores and 8GB ram to run that.</em></strong></p><p>Note:</p><p>Whenever you are installing a LEMP or LAMP configuration, you will need several user names and passwords.</p><ul><li>Linux Username (initially with password; SSH Key in production, set password to crazy long string)</li><li>MySQL root password ( native mode, must web applications do not support the new password version yet)</li><li>MySQL application username &amp; password (Use current NIST Guidelines)</li><li>Application admin user/password</li><li>Application regular user/password — Sometimes</li></ul><p>Linux Preparation</p><p>These instructions are not a full hardening guide. Please consult with CIS Benchmarks to harden your system before going into production and subsequently getting hacked. We are going to do a few security steps. Just to prevent problems.</p><ol><li>Install pre-requisite software</li><li>Create a user</li><li>Create a banner message</li><li>Enable local firewall</li><li>Enable local antivirus</li><li>Enable 2FA (Google Auth) access</li><li>Remove all remote access by passwords.</li><li>Configure Apache to run</li></ol><pre># Install pre-requisite software</pre><pre># Percona SQL Server (MySQL)</pre><pre>sudo wget <a href="https://repo.percona.com/apt/percona-release_latest.$(lsb_release">https://repo.percona.com/apt/percona-release_latest.$(lsb_release</a> -sc)_all.deb<br>sudo dpkg -i percona-release_latest.$(lsb_release -sc)_all.deb</pre><pre>sudo apt-get update<br># This will prompt you for a root password.<br>sudo apt-get install percona-server-server-5.7 -y</pre><pre># Apache2<br><a href="https://www.server-world.info/en/command/html/apt.html">apt</a> -y install apache2</pre><pre># PHP7<br>apt -y install php php-cgi libapache2-mod-php php-common php-pear php-mbstring php-xml php-imap php-curl php-zip php-json php-mysql php-gd</pre><pre># OS Packages<br>apt -y curl zip unzip sudo libpam-google-authenticator ufw sysvbanner certbot python-certbot-apache openjdk-8-jdk</pre><pre># Update, Upgrade and remove old</pre><pre>apt update<br>apt upgrade -y<br>apt autoremove</pre><p>At this point, take a moment to restart your server, in case the kernel has changed during the update process.</p><h4>Create a user for this application:</h4><pre># Update the Linux SKEL<br>mkdir /etc/skel/.ssh<br>touch /etc/skel/.ssh/authorized_keys<br>mkdir /etc/skel/html</pre><pre># Create a location for this application<br>mkdir /data<br>useradd -c &#39;Suite CRM Application&#39; -m -d /data/suitecrm --uid 3000 - -s /bin/bash suitecrm</pre><pre># Set Crazy Password<br>SITE_PASS=${SITE_PASS:-$(&lt; /dev/urandom tr -dc _A-Z-a-z-0-9 | head -c&quot;${1:-32}&quot;;echo)}<br>printf  &#39;%s\n%s\n&#39; &quot;${SITE_PASS?}&quot; &quot;${SITE_PASS?}&quot; | passwd suitecrm<br>unset SITE_PASS</pre><pre># Put your public key in authorized_keys<br>cat &gt; ~suitecrm/.ssh/authorized_keys</pre><pre># Set ssh permissions<br>chmod 700 ~suitecrm/.ssh<br>chmod 600 ~suitecrm/.ssh/authorized_keysb</pre><pre># Create groups and group access<br>usermod -a -G suitecrm www-data<br>chown -R suitecrm:suitecrm /data</pre><h4>Create Basic Banner Message</h4><pre>banner SuiteCRM &gt; /etc/update-motd.d/20-message</pre><pre>cat &lt;&lt; EOF &gt; /etc/issue.net<br>&gt; <br>&gt; ==============================================================<br>&gt; === Authorized Used only Contact (xxx) xxx-xxxx for help  ====<br>&gt; ==============================================================<br>&gt; EOF</pre><p>My recommendation is always to set a banner message with a phone number. Implementing the machine banner is the first step towards CIS Level 1 hardening</p><h4>Enable local firewall</h4><blockquote>UFW is standard on Ubuntu</blockquote><pre>sudo ufw allow proto tcp from any to any port 80,443</pre><p>Port 22 is enabled by default. The best method is to enable a few ports and IPs in as practicable.</p><h4>Install AntiVirus</h4><p>It is a lengthy process. Sophos and ClamAV are excellent choices for free AV.</p><pre>See sophos instructions for installation</pre><p><a href="https://secure2.sophos.com/en-us/products/free-tools/sophos-antivirus-for-linux/download.aspx">Download Sophos Linux On-Access Malware Scanning Tool</a></p><h4>Enable 2FA (Google Auth) access</h4><p><a href="https://www.linkedin.com/post/edit/6606348453519900672/">https://www.linkedin.com/post/edit/6606348453519900672/</a></p><p>You need to have an authenticator app on your phone or tablet: Google Authenticator, LastPass Authenticator, Okta Verify, OneLogin, or others.</p><p>Fast Method:</p><pre># As root (answer yes to all questions)<br>google-authenticator</pre><pre># As suitecrm (or your user account) answer yes to all<br>su - suitecrm</pre><h4>Now configure Linux for use:</h4><p>Add Group group to limit SSH access to:</p><pre>groupadd -g 2000 ssh_login<br>usermod -a -G ssh_login root<br>usermod -a -G ssh_login suitecrm</pre><pre>-- Plus any other user that will need to login.</pre><p>File: /etc/ssh/sshd_config<br>Patch file to apply: <strong>patch -v sshd_config &lt; sshd_patch</strong></p><pre>--- sshd_config 2019-12-25 22:45:41.226235267 +0000<br>+++ _sshd_config 2019-12-25 22:43:47.317481104 +0000<br>@@ -53,12 +53,12 @@<br> #IgnoreRhosts yes</pre><pre># To disable tunneled clear text passwords, change to no here!<br>-#PasswordAuthentication yes<br>+PasswordAuthentication no<br> #PermitEmptyPasswords no</pre><pre># Change to yes to enable challenge-response passwords (beware issues with<br> # some PAM modules and threads)<br>-ChallengeResponseAuthentication no<br>+ChallengeResponseAuthentication yes</pre><pre># Kerberos options<br> #KerberosAuthentication no<br>@@ -106,7 +106,11 @@<br> #VersionAddendum none</pre><pre># no default banner path<br>-#Banner none<br>+Banner /etc/issue.net<br>+AllowGroups ssh_login<br>+<br>+# Turn on 2FA Authentication<br>+AuthenticationMethods publickey,keyboard-interactive</pre><pre># Allow client to pass locale environment variables<br> AcceptEnv LANG LC_*</pre><p>If you are unfamiliar with a patch, copy the above text into a file named sshd_patch and then run the command. Careful regarding smart cut and paste</p><h4>File: /etc/pam.d/ssh</h4><p>Patch file to apply: <strong>patch -v sshd &lt; sshd_pam_patch</strong></p><pre>--- sshd 2019-12-25 22:55:08.989319574 +0000<br>+++ sshd_new 2019-12-25 22:55:03.193291733 +0000<br>@@ -1,7 +1,7 @@<br> # PAM configuration for the Secure Shell service</pre><pre># Standard Un*x authentication.<br>-<a href="http://twitter.com/include">@include</a> common-auth<br>+#@include common-auth</pre><pre># Disallow non-root logins when /etc/nologin exists.<br> account    required     pam_nologin.so<br>@@ -53,3 +53,7 @@</pre><pre># Standard Un*x password updating.<br> <a href="http://twitter.com/include">@include</a> common-password<br>+<br>+# Enable google authenticator<br>+auth required pam_google_authenticator.so nullok<br>+</pre><h4>Reference:</h4><pre><a href="https://www.server-world.info/en/note?os=Ubuntu_18.04&amp;p=httpd&amp;f=1">https://www.server-world.info/en/note?os=Ubuntu_18.04&amp;p=httpd&amp;f=1</a></pre><p>Database Installation</p><p>Creating a database is relatively straightforward. The exception is when your installation sets the mysql.sock somewhere the server can’t see or when the password is the new and more secure method, and the application doesn’t support it.</p><pre>mysql -u root -p  [ Use your root password when prompted ]<br>mysql&gt; create database suitecrm_db;<br>mysql&gt; CREATE USER &#39;suitecrm&#39;@&#39;localhost&#39; IDENTIFIED BY &#39;user_password&#39;;<br>mysql&gt; GRANT ALL PRIVILEGES ON suitecrm_db.* TO &#39;suitecrm&#39;@&#39;localhost&#39;;<br>mysql&gt; flush privileges;</pre><p>Apache Installation</p><h4>Get an SSL Certificate (free) but legitimate</h4><pre>systemctl stop apache2<br>certbot certonly --standalone -d <a href="http://www.yourdomain.com">www.yourdomain.com</a></pre><p>There are lots of how-to guides about setting this up to (auto-update)</p><pre>IMPORTANT NOTES:<br> - Congratulations! Your certificate and chain have been saved at:<br>   /etc/letsencrypt/live/www.yourdomain.com/fullchain.pem<br>   Your key file has been saved at:<br>   /etc/letsencrypt/live/www.yourdomain.com/privkey.pem<br>   Your cert will expire on 2020-03-24. To obtain a new or tweaked<br>   version of this certificate in the future, simply run certbot<br>   again. To non-interactively renew *all* of your certificates, run<br>   &quot;certbot renew&quot;</pre><h4>Create a virtual host file</h4><p>FILE: /etc/apache2/sites-available/001-suitecrm.conf</p><p>We set up a port 80 with a redirect to 443</p><pre># HTTP Redirect<br>&lt;VirtualHost www.yourdomain.com:80&gt;<br>        ServerName <a href="http://www.yourdomain.com">www.yourdomain.com</a><br>        ServerAlias <a href="http://www.yourdomain.com">www.yourdomain.com</a><br>        ServerAdmin webmaster@www.yourdomain.com<br>        DocumentRoot /data/suitecrm/html</pre><pre>        #LogLevel info ssl:warn<br>        ErrorLog ${APACHE_LOG_DIR}/www.yourdomain.com/error.log<br>        CustomLog ${APACHE_LOG_DIR}/www.yourdomain.com/access.log combined<br>        RewriteEngine on<br>        RewriteCond %{SERVER_NAME} =www.yourdomain.com<br>        RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]<br>&lt;/VirtualHost&gt;<br></pre><pre>#HTTPS Server<br>&lt;VirtualHost www.yourdomain.com:443&gt;<br>   ServerName <a href="http://www.yourdomain.com">www.yourdomain.com</a><br>   ServerAlias <a href="http://www.yourdomain.com">www.yourdomain.com</a><br>   ServerAdmin webmaster@localhost<br>   DocumentRoot /data/suitecrm/html</pre><pre>   #LogLevel info ssl:warn</pre><pre>   ErrorLog ${APACHE_LOG_DIR}/www.yourdomain.com/error.log<br>   CustomLog ${APACHE_LOG_DIR}/www.yourdomain.com/access.log combined</pre><pre>   ServerName <a href="http://www.yourdomain.com">www.yourdomain.com</a><br>   SSLCertificateFile /etc/letsencrypt/live/www.yourdomain.com/fullchain.pem<br>   SSLCertificateKeyFile /etc/letsencrypt/live/www.yourdomain.com/privkey.pem<br>   Include /etc/letsencrypt/options-ssl-apache.conf</pre><pre>        &lt;Directory /data/www.yourdomain.com/html&gt;<br>                Options All -Indexes -ExecCGI +Includes +MultiViews<br>                &lt;IfModule mod_dav.c&gt;<br>                        DAV Off<br>                &lt;/IfModule&gt;<br>                AllowOverride All<br>                Require all granted</pre><pre>        &lt;/Directory&gt;<br></pre><pre>&lt;/VirtualHost&gt;</pre><pre>&lt;/IfModule&gt;</pre><p>Activate the site: Make sure to enable the SSL module.</p><pre>cd /etc/apache2/sites-enabled<br>ln -s ../sites-available/001-suitecrm.conf</pre><pre>a2enmod rewrite<br>a2enmod ssl</pre><pre>apachectl -t [Make sure you don&#39;t have typos]</pre><pre>systemctl restart apache2</pre><p>Put a quick test file into place to verify it all works</p><pre>cd ~suitecrm/html<br>cat &gt; index.html<br>it works<br>[CTRL][C]</pre><pre># After you verify it works, delete the index.html file.</pre><p>SuiteCRM installation</p><p>Download the ZIP file: SuiteCRM-7.11.10.zip and copy it to your user account.</p><pre>scp SuiteCRM-7.11.10.zip <a href="http://www.yourdomain.com:~/">www.yourdomain.com:~/</a></pre><p>This file is a zip archive. You can unzip it on your local machine and use SFTP to push it up. Or use a two-step method to get rid of the enclosing directory</p><pre># Assuming your zip file is in ~suitecrm<br># Remove the HTML directory first, be caureful<br>cd ~/suitecrm<br>rm -rf html<br>unzip SuiteCRM-7.11.10.zip<br>mv SuiteCRM-7.11.10 html<br>chmod -R 775 html</pre><p>Go to your web server *www.yourdomain</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*d6BDgsxFM7eWxucT1A1mGg.png" /></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mDjnhGkiKkmvd3XfIwlrow.png" /><figcaption>A few more things to do.</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WRWHg1-c7wxmwN78johIpA.png" /></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uFJUWwe0NyS4t9a-d3XhWA.png" /><figcaption>Almost there</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fAOmogri1qpgKGDZXLwJeg.png" /></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-Q8fQ2gr00Wlsg131XcPDQ.png" /></figure><p>Some final housekeeping issues.</p><h4>Add the cron job</h4><pre># m h  dom mon dow   command<br>* * * * *  cd /data/suitecrm/html; php -f cron.php &gt; /dev/null 2&gt;&amp;1</pre><h4>Modify PHP.ini</h4><pre>vi /etc/php/7.2/apache2/php.ini</pre><pre>change:<br>; Maximum allowed size for uploaded files.<br>; <a href="http://php.net/upload-max-filesize">http://php.net/upload-max-filesize</a><br>upload_max_filesize = 2M</pre><pre>to</pre><pre>; Maximum allowed size for uploaded files.<br>; <a href="http://php.net/upload-max-filesize">http://php.net/upload-max-filesize</a><br>upload_max_filesize = 10M</pre><h4>Configure your email server:</h4><pre><a href="https://www.yourdomain.com/index.php?module=EmailMan&amp;action=config">https://www.yourdomain.com/index.php?module=EmailMan&amp;action=config</a></pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pYrZQXg0e74ViDuWZZhj5g.png" /></figure><p>At this point, the installation is complete. We spent some extra time to put a little security in place. If you would like to enable SSO for your small business. JumpCloud provides SAML/SSO for ten users for free.</p><p><a href="https://www.jumpcloud.com">Active Directory and LDAP Reimagined - JumpCloud</a></p><p>The SSO configuration with SAML2 did not work as expected. I have opened an issue with SuiteCRM. Once, I have additional information. I will update this article.</p><p>References:</p><ul><li><a href="https://support.jumpcloud.com/support/s/article/single-sign-on-sso-with-sugarcrm1-2019-08-21-10-36-47">JumpCloud Support Community</a></li><li><a href="https://support.jumpcloud.com/support/s/article/configuring-user-attributes-for-saml-connectors-2019-08-21-10-36-47#Configuring%20User%20Attributes">JumpCloud Support Community</a></li><li><a href="https://support.sugarcrm.com/Knowledge_Base/Password_Management/Configuring_SAML_Attribute_Mapping_for_SugarIdentity/">Configuring SAML Attribute Mapping for SugarIdentity</a></li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=23c2a9e8c611" width="1" height="1" alt="">]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Common Infrastructure Security Mistakes Made by Startups]]></title>
            <link>https://cbitterfield.medium.com/common-infrastructure-security-mistakes-made-by-startups-975a09b85f02?source=rss-f8e598d5fbb1------2</link>
            <guid isPermaLink="false">https://medium.com/p/975a09b85f02</guid>
            <category><![CDATA[startup-lessons]]></category>
            <category><![CDATA[security]]></category>
            <category><![CDATA[cloudsploit]]></category>
            <category><![CDATA[infrastructure]]></category>
            <category><![CDATA[aws]]></category>
            <dc:creator><![CDATA[Colin Bitterfield]]></dc:creator>
            <pubDate>Mon, 23 Dec 2019 02:41:51 GMT</pubDate>
            <atom:updated>2019-12-23T02:41:51.470Z</atom:updated>
            <content:encoded><![CDATA[<p>Throughout my career, I observe that we are solving the same security issues over and over. The technology may change, but the problems don’t.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/100/1*XtpndQW5EKH_9BV0P4whtA.jpeg" /><figcaption>Image by Anna Maria Weaver</figcaption></figure><p>In the military, we used two concepts two describe problems of technology: 1. People, Process, and Technology 2. Prescriptive v Kinistec.</p><p>These concepts will help to shape the way I describe common mistakes. In a prescriptive manner, we follow written guides for every aspect; alternatively, in the Kinesthetic learning method, we feel our way through the issues and deal with them based on how they make us learn through experiences (or gut instinct). Less experienced professionals use the latter by building consensus or dealing with high priority reactive issues. More experienced professionals are likely to follow proven written methodologies. Both perspectives have different advantages and disadvantages. In the concept of people, process, and technology, we demonstrate an understanding that all problems cannot be solved by only adding more people, more technology, or more intricate procedures. On the process side, the issue is demonstrated by how easily we are all driven crazy by telemarketers with scripts or every sale and interaction, followed by an in-depth survey.</p><p>The problem with many of these mistakes is it creates an ever-increasing technical debt against which security is consistently de-prioritized for business growth. The Agile methodology compound and exasperates the issues. The result is a set of data breaches and hacks that are always effective using standard techniques. The fact that the <a href="https://www.veracode.com/directory/owasp-top-10">OWASP 10</a> issues haven’t changed much in the last ten years is a testament to this.</p><p>2019 was a banner year for data breaches. If you take a look at this list, you can see a well-known set of problems.</p><p><a href="http://techgenix.com/2019-data-breaches/">Great year for hackers: Top 2019 data breaches so far</a></p><ol><li>Unsecured Webpage / Database / Service</li><li>Changing URL information</li><li>Commonly used passwords</li><li>Github w/AWS Keys</li><li>OWASP top 10</li></ol><p>Mistake 1. Governance</p><p>Startup companies are just so happy that they got funding or got an application to be saleable that they ignore basic business functions like having policies.</p><p><a href="https://www.cisecurity.org/controls/cis-controls-list/">The 20 CIS Controls &amp; Resources</a></p><p>At a minimum, all companies need to have the following written Guidance:</p><ol><li>Acceptable Use Policy</li><li>Password creation and maintenance Policy</li><li>Policy on Background Checks for employees with elevated access. (this can include Customer Service Representatives)</li><li>Security Framework</li><li>Secure Coding Practices</li><li>Standards and Review Procedures</li><li>Change Control Procedures</li><li>Key and Cryptographic rotation procedures</li><li>“Don’t put your passwords and keys in GitHub.”</li></ol><p>When a company is 1–10 people working in a small space, these issues are settled by group consensus and yelling across the room, “What do you think we should do?”</p><p>As the business grows, customers and vendors may ask questions related to security and processes. I pulled this language from a public RFP.</p><blockquote><em>Data Security. Evaluate and assess current enterprise database security controls for mission critical applications located within the Finance, Fire, Human Resources, and Water Services Departments. Assessment should focus on controls for both regulatory and legal compliance (HIPAA, PCI, PII) as well as controls protecting Restricted City Information (RCI) following the NIST Cybersecurity Framework, per </em><a href="http://www.nist.gov/itl/csd/launchcybersecurity-framework-021214.cfm"><em>http://www.nist.gov/itl/csd/launchcybersecurity-framework-021214.cfm</em></a><em> and </em><a href="http://www.nist.gov/cyberframework/upload/cybersecurity-framework021214.pdf"><em>http://www.nist.gov/cyberframework/upload/cybersecurity-framework021214.pd</em></a><em>f</em></blockquote><p>Eventually, the sales process requires a company to tell its “security” story. Making sure your companies story will sell is essential.</p><p>Mistake 2:</p><p>Choose standards before anything gets built.</p><p>In the United States, we have national standards. In other countries, they have regulations as well. The NIST Standards are about 80–90% of most others. So following it will make it easier to do business domestically and internationally.</p><p>Read the full Executive Order on America’s Cybersecurity Workforce at <a href="https://www.whitehouse.gov/presidential-actions/executive-order-americas-cybersecurity-workforce/">https://www.whitehouse.gov/presidential-actions/executive-order-americas-cybersecurity-workforce/</a>.</p><p>My recommendations are as follows:</p><ol><li>NIST 800–53r4 or r5 when it comes out.</li><li>NICE: NIST 800–181 (a cut down version of 800–53)</li><li>CIS Hardening standards for all technology that has them. (AWS, Azure, GCP, Linux, Windows, Docker, etc) <a href="https://www.cisecurity.org/cis-benchmarks/">https://www.cisecurity.org/cis-benchmarks/</a>. These are guides, not checklists.</li><li>Vendor Best Business Practices (AWS has a long list of these)</li></ol><blockquote>The NICE Cybersecurity Workforce Framework (NICE Framework), <a href="https://doi.org/10.6028/NIST.SP.800-181">NIST Special Publication 800–181</a>, is a national-focused resource that categorizes and describes cybersecurity work. The NICE Framework establishes a taxonomy and common lexicon that describes cybersecurity work and workers irrespective of where or for whom the work is performed. The NICE Framework is intended to be applied in the public, private, and academic sectors.</blockquote><p>Mistake 3:</p><p><strong>IP address management or lack of it</strong></p><p>A common misconception is that you don’t need network engineering in the cloud. Most companies want to multi-hat someone that is a programmer, cybersecurity (enterprise-level), network guy, terraform programmer, and AWS expert. These are vastly different disciplines, and knowing just a little can have some disastrous problems in technical debt.</p><p>Everybody decides that they will rule the world and use a Class “A” address 10.0.0.0/8 everywhere in AWS. What they fail to understand is that all of that space, approximately 16.7 million IPs, needs to be tracked and can’t be duplicated anywhere in their organization.</p><p>When you spin up an AWS environment and assign 10.0.0.0/0 to each account, you can create a security tooling nightmare. Most tools still focus on IP addresses, not AWS ARNs. Proper Management of IP space will simply “oodles” of problems.</p><p>Case in point:</p><p>Almost every home and guest wireless networks use space from RFP 1918. (Private Addresses).<a href="https://tools.ietf.org/html/rfc1918">https://tools.ietf.org/html/rfc1918</a></p><h4>Recommendation 1: Don’t use the following address space anywhere in a startup. Avoiding some IP ranges helps you track rouge systems.</h4><p>Home Routers: 192.168.0.0/16</p><p>Default AWS Space: 172.16.0.0/12</p><p>Widely used Class A portion: 10.0.0.0/16</p><p>These addresses are widely used by well-known retailer’s like Starbucks and in almost every hotel</p><h4>Recommendation 2:</h4><p>Subnet your 10.0.0.0 network into/16 or more. Subnetting will give you approximately 254 class “B” networks of 65,000 hosts.</p><p>Allocation Guidelines:</p><p>Corporate Offices: 10.1.0.0/16.</p><p>Guest Networks and VPN connector space: 10.2.0.0/16</p><p>Unrouteable Docker and Kubernetes internal networks: 10.255.0.0/16. Sub allocate this as much as possible.</p><p>10.3.0.0/16: AWS Root Account</p><p>10.3–254.0.0/16: AWS Sub accounts.</p><p>Use a /21 or 21 for each VPC (that is 4–8k of address space)</p><p>Make sure that Development, Test, and QA don’t have overlapping allocation. Avoid all temptation to use hardcoded IPs in your architecture and create IP identical environments.</p><p>Mistake 4:</p><p>Initial lack of Single Sign or and Over-reliance on O365/gSuite directories. To maintain the level of security required under almost any framework, you need to have centralized control over access to all cloud services, workstations, and OS based VMs. These must also have Two Factor(2FA) authentication.</p><p>Recently, I found <a href="https://jumpcloud.com/">JumpCloud </a>that provides a free single sign-on for up to 10 users. After that, I recommend <a href="https://www.okta.com">Okta</a> and <a href="https://www.onelogin.com">OneLogin</a>.</p><p><strong>Case in point:</strong></p><p>Without variation, every AWS deployment starts with regular user accounts and off the wall IAM policies. Later there is a massive re-engineering effort to use a singles sign-on provider.</p><p><strong>Recommendation:</strong></p><p>Make sure that all of your vendors support SAML or LDAP for SSO.</p><p>Mistake 5:</p><p>Bad Cloud Architecture and capacity planning</p><p>Design your architecture to scale with your project growth. Don’t just add more “stuff” as needed.</p><p>The SDLC model of Development, Staging/QA, and Production is valid in all models. CI/CD is no different.</p><p><strong>Recommendation:</strong></p><p>Create at least the following AWS account structures:</p><ul><li>Root Account</li><li>Development Account</li><li>Staging Account</li><li>Production Account</li><li>Security and AdHoc Account.</li></ul><p>Use complete automation to spin out the accounts and not the console. Configuration Management is another critical factor in security frameworks. Terraform is free and is very easy to use.</p><p><strong>Recommendation:</strong></p><ul><li>Know before you grow. — Do a costing model</li><li>Make sure you are using the correct services. (RDS v EC2 w/database).</li><li>Engage the AWS transformation teams before you start. They will frequently review your plan for free.</li></ul><p>Mistake 6:</p><p>Too much reliance on vendors and too many vendors.</p><p>When it comes to security, using the shared security model to avoid doing the security work and oversight does not protect your company from the front page of the Wall Street Journal.</p><p>Do due diligence in your cloud vendors. If they store your customer’s information, they must comply with the standards required for wherever your clients are. They also must have the same or higher standards for access to data with their employees as you do.</p><p>Outsourcing your SOC and Infrastructure still has to have oversight and due diligence. Auditors will not accept, “They handle all that security stuff.”</p><p>Mistake 7.</p><p>Patch and Vulnerability program/system/methods for all of your infrastructure and IT systems. Antivirus and endpoint systems like Crowstike are not a common operating picture for risk.</p><p>In all cases, systems must be secure against published vulnerabilities. There are only two ways this happens is by scheduled updates or instance replacements.</p><p><strong>Recommendation:</strong></p><p>Even when your company is small, have a policy of patching all systems, including desktops within 30 days for Critical and High Vulnerabilities. Sixty days for everything else.</p><p>If you can’t patch a system because it will break a production, there are legitimate wats to deal with that besides ignoring it. You can create a mitigating control or process. You can accept the risk and work on fixing the production issue. The critical factor for security is recognizing the requirement, creating mitigations, and documenting the situation. Documentation will help you pass any security compliance audits.</p><p><strong>Recommendation:</strong></p><p>The Tenable suite of products is useful in providing a real-time solution to may of these issues to include continuous monitoring and oversight.</p><p><a href="https://www.tenable.com">Tenable® - The Cyber Exposure Company</a></p><p>Mistake 8:</p><p>Lack of endpoint security controls in the production environment.</p><p><strong>Recommendation:</strong></p><p>Pick a solution that can support your corporate systems and workstations in addition to your cloud-based OS VM/EC2.</p><p>Solutions Sophos, Crownstrike, and others are all good.</p><p>File Integrity Monitoring and Antivirus/Malware scanning are requirements for NIST Compliance and CIS Hardening. However, it does not have to be a traditional on-demand scanner. It can be a once a week scan. There are free products (ClamAV, AIDES) and others.</p><p>Mistake 9:</p><p>Not hardening production systems and corporate workstations.</p><p><strong>Recommendation:</strong></p><p>Workstations:</p><p>- Data at Rest FIPS-140–2 encryption</p><p>- Bios Passwords</p><p>- Centralized management and configuration</p><p>Production Systems:</p><p>- CIS Level 1 hardening and Central Management</p><p>- Scheduled updates, patches or replacement</p><blockquote>It is 1000 times easier to develop on hardened platforms, then it is to harden production platforms in uses.</blockquote><p><strong><em>Little known fact:</em></strong></p><p>It is tough to prosecute a hacker or person for unauthorized use of a system without a legally approved banner and Acceptable Use Policy.</p><p>Mistake 10:</p><p>Not understanding the connection between Cyber Security and Business Development and Business Risk.</p><p>A good cybersecurity program, even if your company is three people working in a garage, gives your company an advantage in RFPs. It can enhance your business grown and be a “Force Multiplier” for the business. Customers read about the hacks and lack of security all the time. Having a good program makes your product or application more desirable. It can also reduce your insurance costs and liability.</p><p><strong>Case in Point: Twitter</strong></p><blockquote><a href="https://www.washingtonpost.com/national-security/former-twitter-employees-charged-with-spying-for-saudi-arabia-by-digging-into-the-accounts-of-kingdom-critics/2019/11/06/2e9593da-00a0-11ea-8bab-0fc209e065a8_story.html">Former Twitter employees charged with spying for Saudi Arabia by digging into the accounts of kingdom critics</a>.</blockquote><p>Does Twitter have liability in the murder or wrongful death of this reporter? The employees of Twitter potentials were accessories before the fact in this murder. Perhaps Twitter may or may not have vetted its employees or had internal controls on their access to the data.</p><blockquote><a href="https://www.bbc.com/news/world-europe-45812399">On 2 October 2018, Jamal Khashoggi, a US-based journalist and critic of Saudi Arabia’s government, walked into the country’s consulate in Istanbul, where he was murdered.</a></blockquote><p>Mistake 11:</p><p>Depending on “Free” stuff for your business.</p><p>Thirty years ago, n Unix operating system could cost $1000 or more. Now, we have Linux virtually free. In past days software came with support and a back end of people making sure it was stable and secure. Today, the “community” finds problems and hacks. Patches and fixes happen when “community” reaches consensus. You have no legal recourse on anything you get for free. Paying for AWS does not protect you for an opensource software package.</p><p>There are many useful opensource products to help a startup company. There are also paid-for choices that can reduce development time and increase security. Free is free for the code, not for the time to learn, understand, and implement. (and in some cases remediate and re-architect.</p><p><strong>Something to consider:</strong></p><p>Look for opensource products that have the capability to moving up to a supported version. For instance, Terraform and Terraform Enterprise. JumpCloud free for ten users, and without reconfiguration the ability to grow.</p><p>Also, don’t let a vendor talking you into a free trial that turns into a paid product unless you understand the long-term cost. For instance, AWS free trial is more or less a single server for a year and associated services. If you start there and develop a production system, you will be there for a long time. Make sure your business model can support the growth of cost in the same manner that the business grows. In AWS, there is a typical pattern of EC2 -&gt; Docker -&gt; Kubernetes -&gt; GCP evaluation due to cost and lack of understanding of how things scale and their associated fees.</p><p>Consider the most basic “Free Stuff of All,” the Internet. We get it for free from StarBucks, McDonald’s, WeWork, Airports, Major Cities, and more.</p><blockquote>WeWork’s Lax Wi-Fi Security</blockquote><blockquote>Security issues with WeWork’s Wi-Fi network were first introduced in August 2019 in a <a href="https://www.fastcompany.com/90391748/weworks-wi-fi-network-is-easy-to-hack">Fast Company report,</a> which noted that the company “used the same weak passwords and outdated Wi-Fi system throughout all its branches”. WeWork’s lack of password security has gotten to the point that it has regularly been featured on the list of the worst passwords that anyone can possibly use. The report described that WeWork’s Wi-Fi weak security is “laughably weak” and “downright dangerous.”</blockquote><blockquote>The “laughably weak” Wi-Fi at WeWork now has resulted in exposing the sensitive documents and data of it’s New York’s Financial District members.</blockquote><p><a href="https://www.perimeter81.com/blog/wi-fi/weak-wework-wi-fi-network-security-leaves-tenants-records-exposed/">Weak Wi-Fi Security at WeWork Exposes Data | Perimeter 81</a></p><p>Mistake 12:</p><p>Microservices and Data Comingling as it affects customers, cost, and sales.</p><p>Typically, developers are not well informed with issues of regulation, security, or costs. After something is in production, the business folks will tell them to reduce costs. They always come up with some microservice strategy with docker/Kubernetes. However, this always leads to data co-mingling of customer data (including logs). Some regulations regarding the Government, HIPPA, Financial systems frown on customers’ data co-mingling with other customers.</p><p>All systems consist of data and data that is protected by regulatory law. Regulations like PCI, PII, HIPPA, and more, requires two things:</p><p>- Data in-transit encryption</p><p>- Data at-rest encryption.</p><p>If you co-mingle your customer’s data, you may not be able to serve other customers.</p><p>If you use microservices and SSL offloading, then the data may pass through some systems unencrypted. This situation may require a considerable number of risk acceptance steps if it is accepted at all.</p><p>Mistake 13:</p><p>Treasure Maps and Booty</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZuxIuMcUVGdCOpm2yVCt7A.jpeg" /><figcaption>Can you find your data before the hackers do?</figcaption></figure><p>Where is your data?</p><p>How many copies are there?</p><p>If you have an eCommerce application, you may or may not have PCI information, depending on how you process payments. However, you most certainly have PII and PI data that requires protection under another standard like COPA or FERPA.</p><p>Making a copy of production data for developers to work with is risky. Especially if the data has a name, address, phone, number, security questions, logs, and purchases, hackers can use this for identity theft. Or perhaps someone could use it for stalking a famous person.</p><p><strong>Recommendation:</strong></p><p>Take the time to create a development set of data that is approved. It can be an automated pull of production that changes out PI/PII data for anonymizing.</p><p>Know where every copy is stored, how it is protected, and if you have backups.</p><p>Have a standard and a policy even if there are two of you,</p><p>Mistake 14:</p><p>Reconstruction</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/381/1*2hbFirKPNzVT6itl4uWxGQ.jpeg" /><figcaption>Where do you start?</figcaption></figure><p>Disaster Recovery and Continuity of Operations.</p><p>Most startups don’t consider this until they are so big that figuring it out requires hiring a person for this.</p><p>In simple terms, know how to duplicate your production environment from scratch. If you created your AWS architecture with the console as it evolved, then you don’t know what it will take to duplicate.</p><p>A startup should be able to use a set of offline or in another region backup to regenerate a production environment in 24 hours.</p><p><strong>Case in Point: World Trader Center 9/11/2001</strong></p><p>Most financial companies had their backup data centers in the opposite tower with a fiber connection. They had their hot and warm sites destroyed at the same time. They had to revert to their cold sites in New Jersey and rollback the data to the last good backup.</p><p><strong>Recommendation:</strong></p><ol><li>Be able to create your root and production AWS Accounts with terraforming and no console. Including links to your SSO provider.</li><li>Maintain code and data backups online and under control, even if that is an SSD in your safe.</li><li>Practice spinning up a new account and recovering the data once a year.</li><li>Github is excellent, but where is the physical location of the data? What if it is the same AWS data center that has a problem?</li></ol><p>Mistake 15:</p><p>The acquisition of shiny objects.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/500/1*5eTJoKPDMBcf22Pit0GSjA.jpeg" /><figcaption>marketoonist.com</figcaption></figure><p><a href="https://www.focus-works.com/shiny-object-syndrome">Shiny Object Syndrome - Focus Works</a></p><blockquote>Engineers, marketing people, programmers and office techs love chasing the next shiny new thing. It seems like every week, we can learn about a new technology, software, or media platform that promises to be the much better and easier thing to use than what we have. I call the instant reaction to this the “Shiny Object Syndrome.”</blockquote><p>The more technologies, vendors, and complexity you create, the number of risks you add to your company increases.</p><p>There is an adage. If you own a hammer, then every problem is a nail. When you are hiring developers, they will want to shift the design the language or technology they used last, want to learn more about, or think will help their career.</p><p>If shifts in technology are unmanaged and focused on personalities, it can damage a company’s capabilities and growth.</p><p><strong>Recommendation:</strong></p><p>Pick your technology changes carefully. Make sure that any new technology does what you want without introducing a new problem. There are a plethora of unintended consequences that can occur. New technology for performance can lead to instability or increased costs.</p><p>Mistake 16:</p><p>Let your fingers do the walking: Yellow Pages</p><p><strong>Ignoring DNS related issues</strong></p><p>Most developers have a consumer-level understanding of how the Internet works and how data exfiltration can occur. Developers are good at what they do.</p><p>A few attacks and hacks related to DNS:</p><ol><li>BotNets</li><li>DDOS</li><li>MTM</li><li>DNS Data Exfiltration</li><li>RansomWare</li></ol><p><a href="https://blog.fosec.vn/dns-data-exfiltration-what-is-this-and-how-to-use-2f6c69998822">DNS Data exfiltration — What is this and How to use?</a></p><p>Route53 is useful for what it does. It is not a DNS firewall.</p><p>One of the most common security issues is Phishing by all its names and variations. I have heard no end of junior security engineer lecture me on the education of end-users, tricking them, consequences, and so on. When I was in the military, we had to take a 3 hours online class every year about knowing when it’s a phishing email. I receive many hundred emails on multiple accounts. I correspond with people from around the world some that have English skills that good use a little polish. Generally speaking, no matter how much education or ability an end-user has or anyone who is acting like an end-user at the time of the email has, they will fail prey 7–20% of the time. (This includes security professionals). The result for the Enterprise is we have to train people on phishing for compliance, to lower our cybersecurity insurance, and to perform due diligence in our security framework. It also requires us to find another defense.</p><p>Phishing mostly works when someone clicks on a link. A click either downloads malware or runs malware as an attachment. Most of the email systems like O365 and others filter out the malware attachments. By using a DNS firewall, we can eliminate the clickable threat. Most DNS Firewall services have a real-time feed that updates to prevent this clicks.</p><p>Besides, botnets and some malware use DNS for a Command and Control C2 system. If they can’t reach their controller, they can’t get activated. A DNS firewall provides reporting for actions that attempt communication to a controller and prevents them at the same time.</p><p>Most home internet providers provide some level of DNS firewall. If we use (8.8.8.8) Google DNS on workstations then, we bypass all levels of filtering and firewalls. There are cases that require avoiding our standard DNS procedures for testing, but it should not be the rule.</p><p><strong><em>Little Known Fact:</em></strong></p><p>Companies like <a href="https://www.bitsight.com">BitSight</a>, track the click-through to bad sites and report on this (about you) to other companies. BitSight will accept IP markers for guest networks.</p><p>Your IP usage belongs to your company. If your guest network allows full access to the Internet, all actions are yours and tracked.</p><p>For guest wireless networks, always makes sure they are using a protected DNS firewall and use different external IP ranges than regular employees. If employees use it, have them use it with a username and a password; then, have it change external IPs based on authentications.</p><p>Mistake 17:</p><p><strong>“to close the stable door after the horse has bolted.”</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/260/1*U2_u3gmMVlf78jD7v-pWRA.jpeg" /></figure><p>Lack of VPN usage and understanding regarding cloud security.</p><p>In the current “Startup View” of the world, everything is a cloud service. Infrastructure from AWS/Azure/GCP, HR/Payroll from UltiPro, Benefits from SWIFT, and this list goes on. The new paradigm of the inclusive Internet and Business centers in apartment buildings creates new challenges.</p><p>Where are hackers located? Sometimes it is from upper Moldovia, and sometimes it is from a compromised desktop in San Clara, CA, on the Xfinity network.</p><p>Use VPN access when not in your office if you own your network. If you use a place like WeWork, always use a VPN.</p><p><a href="https://www.perimeter81.com/">The Zero Trust Secure Network as a Service | Perimeter 81</a></p><p>There are many providers like Permiter 81 that provide Zero trust access solutions. In a very general sense, you can have almost any Cloud Provider white list your Office or VPN IPs so that the whole rest of the world can’t access your SaaS services. Public based VPNs provide an additional level of protection. Unlike using the AWS VPN internal services, it connects and provisions based on your SSO provider.</p><p><strong>Recommendation:</strong></p><p>When setting up a VPN:</p><ol><li>Limit concurrent user sessions.</li><li>VPNs are not for service accounts; they are for people.</li><li>Site2Site VPN is for services.</li><li>Check usage to ensure people are not connecting for extraordinary periods or moving extraordinary amounts of data.</li><li>Retain user access and session logs according to your data retention policy, or at least 90 days.</li></ol><p>By using a VPN provider, you can also limit the number of points of access to your corporate and cloud services, which reduces your attack surface.</p><p>Mistake 18:</p><p>Fight as you train, train as you fight</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/200/1*653Jc8BrC4qF_IUwhk0chQ.jpeg" /><figcaption>Technology Obstacle Course Simplified</figcaption></figure><p>We use the manta, “Fight as you train, train as you fight.” We translate this to any industry, “don’t do anything in development or staging that you don’t want in production.”</p><p>This concept is general, but failing it very costly.</p><p><strong>Case in point:</strong></p><p>Don’t let developers work on non-hardened OS Images or Docker Images. If it is allowed, they will find some way to create code that does not work after security is applied. Security needs to evolve with the development needs, not created after. The best practice is development on standard and secured images.</p><p>Layer the application development like icing on a cake. Don’t try to slide a cake under the icing</p><p>Develop your business and technical process end to end with security in place. Don’t just stop when you “get it working.”</p><p>Jenkins systems that are unsecured are just as prevalent as AWS keys in Github.</p><p>Mistake 19:</p><p>Use your Gym Membership</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/236/1*dc3IPplU9xjN56KHCbE1lw.jpeg" /><figcaption>Use what you pay for</figcaption></figure><p>Although this sounds funny, how many people have a gym membership that they pay for and never use. Even if they go, how many people know all of the services available to them under their membership plan.</p><p>This translates to, Use what you are paying for to the fullest and don’t get talked into “Best of Breed” solution sets.</p><p>You don’t buy a car in pieces, chassis from one vendor, engine from another transmission from a third, and computer systems from a fourth. Just because they all said, “Conforms to Open Standards.”</p><ul><li>Review your security tooling annually</li><li>Fully utilize your tooling.</li><li>Make sure it all works together.</li><li>Reduce the number of “places” people have to look for information</li><li>Create a common operating picture for your company</li></ul><p>Do all of this while you are at the beginning. It only gets harder as things get more complicated.</p><p>Mistake 20:</p><p>Rogues, Thieves, and Dreamers</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/236/1*wymW9as46TFrmIw2MTeTfg.jpeg" /></figure><p>I can’t tell you the number of times a developer, financial person, security engineer, or some other team member tells me how their project can’t conform to the company guidelines. What they mean is they don’t know how to do it, or it’s too much work for them to do it, or perhaps some other variation.</p><p>There is a minimal set of security standards that must be applied to even be in this market place.</p><ul><li>Central User Management</li><li>System Hardening / Layered Defenses</li><li>Infrastructure Hardening / East-West Security</li><li>Edge Hardening / North-South Security</li><li>External Defenses</li><li>Good Housekeeping Practices (user remove, data purges, etc.)</li><li>DR/CooP capabilities</li></ul><p><strong>There is no credible case to step outside of this.</strong></p><p>Every AWS account should be pre-hardened to a standard before you create a service.</p><p>Every OS/VM/EC2/Docker image needs hardening before its use, including how the base OS (or in ZERO os systems) Software is updated.</p><p>If the standard doesn’t work for the new project, use a process to update the rule. Don’t create a long list of edge cases with different standards.</p><p>Implementation of baseline controls is a must from AWS to VPNs, including Coffee Pots, Refrigerators, and animated dolls.</p><p>Mistake 21:</p><p><strong>Isaac Asimov’s “Three Laws of Robotics”</strong></p><ul><li>A <strong>robot</strong> may not injure a human being or, through inaction, allow a human being to come to harm.</li><li>A <strong>robot</strong> must obey orders given it by human beings except where such orders would conflict with the First Law.</li><li>A <strong>robot</strong> must protect its own existence as long as such protection does not conflict with the First or Second Law.</li></ul><h3>Translation: Don’t forget about IoT in the workplace.</h3><p>In a modern workplace, tons of IT “stuff” exists. IoT equipment is easy to overlook. Sometimes it just walks in. Here are some crazy ones to look for and make sure they have at least a password on them. IoT is not limited to WiFi, BlueTooth, Zigbee, and other protocols are also used. If it can have an App, it’s connected.</p><ul><li>Security Systems, Cameras, Elevators</li><li>Coffee Makers, Dishwashers, Refrigerators, Game Systems</li><li>Copier, Fax, Printer Multifunction devices.</li><li>Vendor provided equipment(postage machines)</li><li>Loyalty Systems, Guest Checking Systems</li><li>Conference Room Equipment and TVs.</li></ul><p>Think about if someone got control of your TV and recorded every presentation. Perhaps used the Office printer as a scanner sniffing device and emailed copies of every document printed.</p><p>A lot of very inexpensive equipment as “very inexpensive” security.</p><p>Mistake 22:</p><p>The world is listening</p><p>There is no law against anyone sniffing wireless signals and gaining information from them.</p><p>WiFi is ubiquitous in the workplace. Cisco provides an excellent series of tools to secure wifi.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/501/1*GrTiNBXDWQ2meWUdPSOOzw.png" /><figcaption>Precise Location Tracking of Rogue Access Points and Clients with the Cisco Location Appliance and Cisco WCS</figcaption></figure><p>Basic Rules:</p><ol><li>No access without credentials</li><li>Protect DNS</li><li>Don’t allow old devices or Rooted Devices to connect.</li><li>Log Connections and usage for at least 90 days.</li><li>Track for rogue equipment if practical.</li><li>SSID for the company should not be the company name.</li><li>Guest SSID should also not be the company name or the word “Guest.”</li><li>Don’t put encryption levels (WPA, for instance) in the SSID.</li><li>Every security domain and location should have a different external address.</li><li>All Wifi Equipment needs updating within 30 days or less. Don’t forget about it in a closet.</li></ol><blockquote>Wireless LANs (WLANs) bring incredible productivity and new efficiencies to organizations of all sizes. Advances in WLAN features and capabilities allow organizations to offer the benefits of wireless to their employees without sacrificing security. Properly deployed, WLANs can be as secure as wired networks. This paper discusses the five steps to creating a secure WLAN infrastructure. <a href="https://www.cisco.com/c/dam/global/sv_se/assets/pdfs/smb/cdccont_0900aecd804909a5.pdf">link</a></blockquote><p>Mistake 23:</p><p>Liberté, égalité, fraternité</p><p>The IT department and corporate infrastructure is not subject to different rules, policies and leadership.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/156/1*Cq9T72l9L8jA8b4fCTVDQQ.jpeg" /></figure><p>I see this one a lot in the DOT COM startup world. The product engineering side grows until they need to hire enough people to have a corporate team. Because the engineering team did not conform to standards, they set up a situation of us v them. When the company grows to an Enterprise level, the teams merge with varying levels of success.</p><p>When a company starts with baseline security from the beginning, it provides freedom to grow unrestricted by technical debt. All aspects of engineering and corporate are equally important. All security professionals belong to the same fraternity. If a burglar or nefarious individual make their way into the corporate side, they sidestep to the product engineering environment.</p><p>Without governance and baseline controls, applied from the beginning, the company acquires technical debt that is very expensive and hard to pay.</p><p>Mistake 24:</p><p><a href="https://en.wikipedia.org/wiki/File:Yertle_the_Turtle_and_Other_Stories_cover.png">Yertle the Turtle</a> and other stories.</p><p><a href="https://aws.amazon.com/compliance/shared-responsibility-model/">The Shared Responsibility Model (AWS)</a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/270/1*3_9U568-Tt-HuUN0O2830Q.png" /><figcaption>Credit Dr. Suess</figcaption></figure><p>AWS responsibility “Security of the Cloud” — AWS is responsible for protecting the infrastructure that runs all of the services offered in the AWS Cloud. This infrastructure is composed of the hardware, software, networking, and facilities that run AWS Cloud services.</p><p>Many professionals think that the OS instances in EC2 are secured or that AWS performs some magic related to security. They are not responsible for making sure your account, neither is Azure or GCP, is secure meets a standard or protected in any way. They are also not responsible if your EC2s crash or reboot.</p><p>Before using “Infrastructure as a Service” read the SLAs for each service that you use.</p><p>Amazon’s business is to provide a service for money and get you to spend as much money as you want with them.</p><p>It is easier to build your service or application on a solid foundation; then it is to fix the <a href="https://www.sfchronicle.com/bayarea/article/Expert-panel-endorses-plan-to-stabilize-SF-s-14382917.php">Millennium Tower</a>. As an example, the building cost $350 million to build and now will take $100 million to fix, if it is fixable at all. A better initial foundation cost is a fraction of the repair bill.</p><p>IT systems are very similar. Build it secure, and it will scale as large as you want. These structures were technology for security.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/590/1*_vIio4JkNmHiU8MWFj5q9w.jpeg" /><figcaption>A testament to solid foundations and scaleable technology</figcaption></figure><p>Mistake 25:</p><p>A submarine with a screen door</p><p>AWS Accounts are not ready to go. They need to be secured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/200/1*-N-KVaK0GQGiQ41TiGFTFA.jpeg" /><figcaption>A real submarine with a screen door. It does exist</figcaption></figure><p>AWS provides great services. They have great people and innovative technology. A new account is very far from secure. Much like this screen door.</p><p>I ran an initial scan on a new AWS account courteous of <a href="https://cloudsploit.com/">CloudSplot</a>. They provide a free account for startups to check out their security posture. Their service offers a series of features that help find and fix security issues.</p><p><a href="https://cloudsploit.com/">CloudSploit | Cloud Security as a Service</a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/505/1*AvLgnZm24vFuIp9J7ZvC4g.png" /></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*CubAP19XRkEkHDV7xJlsww.png" /><figcaption>results from our initial scan</figcaption></figure><p>I will place the CSV scan results on Github along with Terraform projects that go with these articles.</p><p><a href="https://github.com/cbitterfield/odessa_media">cbitterfield/odessa_media</a></p><p>In summary, the issues of infrastructure security only get harder to implement over time. Each of these issues is root in People, Process, and Technology and none of them can be solved by downloading a how-to guide 2 years after production work started. One of the key concepts in security work is due diligence. Even if you do everything right, your company still can experience a breach. But if you have done everything right along the way, you have a much better story to tell to your investors and customers.</p><p>My next article will feature wiring up a new AWS account with Terraform to resolve the security issues and create a method for deploying the same security to all sub-accounts.</p><img src="https://medium.com/_/stat?event=post.clientViewed&referrerSource=full_rss&postId=975a09b85f02" width="1" height="1" alt="">]]></content:encoded>
        </item>
    </channel>
</rss>