elister
24.2K posts

elister
@eliister
👨💻 | Enthusiastic about blockchain and transformative power of web3 | Linux | DevOps |
🧭🌐 Katılım Haziran 2021
554 Takip Edilen766 Takipçiler

Someone just backed into my front bumper…
A pathetic 3-inch crack.
Kis quoted me $9,800 + tax + installation 😭😭😭
Why the hell did I buy an electric car?
Screw it. I’m launching $BUMPER right now.
Send this shit to the moon so I can afford my actual bumper ☠️
@grok do something. Don’t you have a wallet around for cases like this?
ᵗʰⁱˢ ⁱˢ ˢᵃᵗⁱʳᵉ/ᵖᵃʳᵒᵈʸ. ⁿᵒᵗ ˡᵃᵘⁿᶜʰⁱⁿᵍ ᵃⁿʸᵗʰⁱⁿᵍ, ⁿᵒᵗ ᶠⁱⁿᵃⁿᶜⁱᵃˡ ᵃᵈᵛⁱᶜᵉ, ᵖˡˢ ᵈᵒⁿ’ᵗ ˢᵉⁿᵈ ᵐᵉ ʸᵒᵘʳ ˢᵒˡ ᵇᵘᵗ ᵗʰᵉ ᵇᵘᵐᵖᵉʳ ˢᵗᵒʳʸ ⁱˢ ᵗʳᵘᵉ ˡᵒˡ
English

@livingdevops Have a similiar set up for my home lab 🤣....
Do not close written on a masking tape ..
English
elister retweetledi
elister retweetledi

KOLs are not your friend. And you shouldn’t treat them like they are.
Also, following their wallets and trying to mimic their plays is 100% on you and nobody else.
Don’t blame them for being profit-driven and moving the way they do when most of them are actually transparent about it.
Start taking accountability for your own shitty decisions. It blows my mind how there are fully grown adults here constantly playing the blame game.
This is not kindergarten. Own up to your shit and be a decent person.
Stop being a follower and try being a leader for once. I know, crazy concept!
Think. For. Yourself.
Space Riders.
Grace.✨@BabyOfCrypt
Buying an NFT just because you see a KOL buying it is one idea that has never made sense to me 😄. I prefer buying collections I like before KOLs notice it and start selling when they start buying. Kol sweep mainly attracts Jeeters and flippers.
English
elister retweetledi

A Japanese manga artist lost his entire Google account forever after he uploaded private files from an old comic he drew to Google Drive.
Google’s AI checked the files and flagged them as not allowed. He asked Google to review it again, but they rejected his appeal and banned the account immediately.
He can no longer access years of his private drawings and lost access to many websites and services that used his Google login.
The artist said this is very embarrassing and causes him a lot of trouble. He warned that it might not happen to people who always follow every rule, but others should be careful.
So Google is scanning files that people upload to its cloud storage even if they are supposed to be private. I wonder how long they have been doing this.


English
elister retweetledi

NEW: @cz_binance SAYS “IF YOU HAVE API KEYS IN YOUR CODE, EVEN PRIVATE REPOS, NOW IS THE TIME TO DOUBLE CHECK AND CHANGE THEM…“ - FOLLOWING REPORTED @github INCIDENT

English

@techyoutbe It was a prank/fake firing... It brought a lot of views for both parties..
Digital strategist at work...
English
elister retweetledi
elister retweetledi
elister retweetledi

Grafana’s GitHub got hacked last week.
An attacker stole a token, used it to access Grafana’s GitHub environment, and downloaded the complete codebase.
Then they tried to blackmail. They asked for a huge ransom to keep the code private.
Grafana refused and publicly disclosed the incident.
They confirmed no customer data was compromised and immediately started investigating how the token was exposed.
But here is the part that should scare every DevOps engineer.
It was not a zero-day.
Not sophisticated malware.
Not some nation-state attack.
It was one leaked token.
The oldest tricks still work best in production:
→ One .env file committed by mistake
→ One GitHub PAT with admin access exposed in CI logs
→ One developer's laptop with stale credentials
→ One forgotten token nobody rotated
That is all it takes to put your infrastructure on someone else’s machine.
Credential hygiene is not just a security problem.
It is a DevOps responsibility.
> Your pipelines hold the secrets.
> Your automation uses the credentials.
> Your systems define the blast radius.
> Fix it before you become the next incident report:
→ Rotate long-lived tokens
→ Enable secret scanning on every repo
→ Move CI/CD to OIDC instead of static credentials
→ Use short-lived credentials wherever possible
→ Build your incident response playbook before you need it
Grafana monitors production systems at a massive scale.
They still got hit.
What makes you think your company is immune?
English
elister retweetledi

Your Kubernetes cluster is probably insecure right now.
Here's how I know:
❌ Secrets stored as base64 in etcd
❌ No Network Policies (all pods talk freely)
❌ Running containers as root
❌ Using :latest image tags in production
❌ No Falco for runtime threat detection
Fix all 12 attack surfaces with this visual 👇
These 12 concepts that actually matter in production:
🔑 RBAC → who can do what
🛡️ Pod Security Admission → privileged vs restricted
🔒 Secrets → Vault, not base64
🌐 Network Policies → zero trust between pods
🤝 mTLS → Istio/Linkerd handle this for free
📦 Image Security → Trivy + Cosign in your CI
🚪 API Server → Authentication → RBAC → Admission → etcd
⚙️ Security Contexts → runAsNonRoot always
🗄️ etcd → encrypt at rest, block port 2379
🧩 Admission Controllers → OPA + Kyverno
💻 Node Security → CIS Benchmark via kube-bench
👁️ Runtime Security → Falco on every node
Retweet to save a fellow engineer's cluster 🙏
#Kubernetes #K8sSecurity #DevSecOps #CloudNative #DevOps #CloudSecurity #SRE #Platform

English
elister retweetledi

Anybody telling you they read 67 million lines of code and giving you a condensed version of the ‘alpha’ should me muted and ignored.
There’s not a single degen that did read all that, stop larping you wankers
Elon Musk@elonmusk
The latest 𝕏 algorithm has been published to GitHub github.com/xai-org/x-algo…
English

The latest 𝕏 algorithm has been published to GitHub
github.com/xai-org/x-algo…
English
elister retweetledi
elister retweetledi

















