Edgar Gonzalez

22.8K posts

Edgar Gonzalez banner
Edgar Gonzalez

Edgar Gonzalez

@edgar

Current iteration: Director of Engineering @StreetEasy (Zillow) • Previously: Director DevOps & Data @BlueApron • Co-founder & CTO @ Piictu 🦣 @[email protected]

New York, NY Katılım Mart 2007
718 Takip Edilen3.1K Takipçiler
Edgar Gonzalez retweetledi
Jessica Carrillo
Jessica Carrillo@JessyCarrillo·
El resumen de lo que ocurrió hoy en la Corte del Distrito Sur de Nueva York con la audiencia de presentación de Nicolás Maduro y Cilia Flores.
Español
33
388
1.3K
238.2K
Edgar Gonzalez retweetledi
The Nobel Prize
The Nobel Prize@NobelPrize·
BREAKING NEWS The Norwegian Nobel Committee has decided to award the 2025 #NobelPeacePrize to Maria Corina Machado for her tireless work promoting democratic rights for the people of Venezuela and for her struggle to achieve a just and peaceful transition from dictatorship to democracy. #NobelPrize
The Nobel Prize tweet media
English
24.5K
51.9K
184.7K
68.7M
Luis Carlos 🏴‍☠️ One Piece
Si con la @CatedraPop decía que podíamos empaquetar contenidos complejos en formato de cultura pop, ver a Amal y George Clooney hacer una gala para hablar de derechos humanos es simplemente admirable. Es como compartir el foco y la plataforma para poner temas duros en agenda. John Stewart lo llamó "los Oscar de la valentía". Ahí en el vídeo aparece Nadia Murad @NadiaMuradBasee, premio Nobel de la Paz, activista iraquí y sobreviviente de ISIS; Memory Banda @thememorybanda, quien lleva adelante la lucha en Malawi por acabar con los matrimonios infantiles y los "campos de educación" de niñas para que sean esposas desde los 9 años de edad; las Mujeres del Sol @women_ofthesun y las Mujeres que Luchan por la Paz @WomenWagePeace, dos organizaciones de Palestina e Israel que trabajan juntas: y la grande y extraordinaria Dolores Huerta @DoloresHuerta, heroína de los derechos civiles en Estados Unidos, defensora de migrantes y campesinos, creadora de la consigna "Sí se puede" y maestra de vida que aún puede armar una huelga en plena sala de premiaciones a sus 94 años de edad. Nos presentaron artistas como John Oliver, John Krasinski y Emily Blunt, Meryl Streep, Cate Blanchett, John Stewart, además de Melinda Gates y la ex primera dama de USA, Michelle Obama @MichelleObama. Acá hay unas fotos:
Luis Carlos 🏴‍☠️ One Piece tweet mediaLuis Carlos 🏴‍☠️ One Piece tweet mediaLuis Carlos 🏴‍☠️ One Piece tweet mediaLuis Carlos 🏴‍☠️ One Piece tweet media
The Hollywood Reporter@THR

The Clooneys pose on the carpet with this years honorees at #TheAlbies

Español
198
517
2.1K
124.5K
Edgar Gonzalez
Edgar Gonzalez@edgar·
NIST is updating their password guidelines, finally getting rid of - password rotations - complexity rules - adopt phrasing instead
BlackRoomSec@blackroomsec

Please share this far and wide. As far and wide as you can. NIST Password Guidelines for 2024 are in the process of being updated. This is a HUGE pet-peeve of mine (when vendors in particular are still operating like its 2017 and keep changing passwords every 60 days, STOP DOING THIS, it's outdated and has been shown to put you MORE at risk than less -- NIST explains why it does in this document, meticulously outlining user behavior**) so I'm sharing this in the hopes all of you will pass it along to your bosses. The Special Publication series governing passwords is SP 800-63 "Digital Identity Guidelines". The 2024 version is 800-63-4. Here: pages.nist.gov/800-63-4/ The companion docs are also on that link. They are 800-63A, 800-63B and 800-63C. These are different documents for different scenarios in play at your org. The previous update was in2020. The changes in the 2020 version from the 2017 version were numerous but one of them was that the password verification method should NO LONGER require passwords be changed at specific intervals (i.e. every 60 days) but in the following circumstances instead: 1. After a breach/compromise 2. User request 2024 repeats this and adds a bunch more guidlines but here is a screenshot of page 13 of the new 800-63-4 (note the # 4 after it) which outlines how your systems should now and moving forward, be handling passwords. This goes for Active Directory, too. All your systems which have passwords should align with these guidelines provided there isn't another standard or framework you must adhere to which overrules this. Most frameworks, however, have moved away from arbitrary password resets and complexity rules. **We cybersec researchers and hackers use wordlists from breaches in a variety of different ways. Hackers use them in tooling to crack passwords whereas researchers use breach dumps to see the kinds of passwords users are creating and the psychology behind them. Using complexity rules gets you the user psychology of: Password1 Password2 and so on Use phrasing instead and allow for spaces, which is important. Humans type phrases with spaces. They also mention phish-resistant methods and most vendors are on-board with MS going to be turning off all Legacy Auth next month, across all free accounts and tenancies. I'm so excited for the new changes! Ok I'm off my soapbox. Share the love! Thank you!

English
0
0
3
3.4K
Edgar Gonzalez
Edgar Gonzalez@edgar·
@jordimirobruix @anibal 💯 Por cierto, nginx es un excelente software, moviendo >40% del tráfico. Tal vez uno de sus pocos inconvenientes es tener que usar LUA para extenderlo
Español
1
0
1
72
Freddy Montes
Freddy Montes@fmontes·
Listo para darle enviar.
Freddy Montes tweet media
Español
30
692
4K
211.2K