Michael Chan

905 posts

Michael Chan

Michael Chan

@mchancloud

Father of two boys, guitar and uke player. Identity, GenAI, and security architect. My opinions are my own.

Chicago, IL 加入时间 Mart 2014
311 关注1.1K 粉丝
置顶推文
Michael Chan
Michael Chan@mchancloud·
🔐If you ever need to call the AWS IAM or STS APIs, or want a snapshot of your IAM resources (users, roles, and policies), or just want to learn more on IAM's behavior, check out my two-part blog on this topic! aws.amazon.com/blogs/security…
English
1
10
47
3.7K
Michael Chan
Michael Chan@mchancloud·
@canva If this isn't reflective of your sales culture, then I'd appreciate a DM on how we can resolve this. My job is to review vendors on their AI-related security controls, and up to now all vendors have willingly complied, enterprise version or not. @canva thoughts?
English
0
0
0
60
Michael Chan
Michael Chan@mchancloud·
Hey @canva, you told us that you wouldn't answer security questions "without purchase of the Enterprise version". Is this reflective of your attitude towards customers who care about security, privacy, and compliance especially with the concerns everyone has around AI? Do better!
English
2
0
0
167
Michael Chan
Michael Chan@mchancloud·
I'd recommend this anyone needed to skill up on AWS IAM!
English
0
0
0
206
Michael Chan
Michael Chan@mchancloud·
A 🪲 bug with Google Search's AI Overview feature? Either way its completely incoherent.... in repudiateas in scowlas in spurnas in turn downas..!
Michael Chan tweet media
English
0
0
0
142
Michael Chan
Michael Chan@mchancloud·
Happy holidays everyone! Wishing you all a happy and secure Christmas season. Gingerbread house kit courtesy of @wiz_io and @SolvangBakery.
Michael Chan tweet mediaMichael Chan tweet media
English
0
0
5
396
Michael Chan 已转推
kat traxler
kat traxler@NightmareJS·
As of next year, #google will require premium subscriptions for things like IAM Recommender, Role Insights, etc. This is the OPPOSITE of their mantra calling for shared fate instead of the shared responsibility model. A massive loss in credibility.
kat traxler tweet media
GCP Weekly@gcpweekly

Policy Intelligence update on September 28, 2023 cloud.google.com/policy-intelli… #googlecloud After January 15, 2024, some Policy Intelligence features will only be available for customers with organization-level activations of Security 1/2

English
4
10
45
19.6K
Michael Chan 已转推
Peter C
Peter C@itspeterc·
Big pricing change to a valuable GCP security feature for least-privilege IAM. Requiring the org-level SCC Premium bundle instead of a pay-as-you-go per-service price will be prohibitively expensive and detrimental to security for many customers in the long run. @philvenables
GCP Weekly@gcpweekly

Policy Intelligence update on September 28, 2023 cloud.google.com/policy-intelli… #googlecloud After January 15, 2024, some Policy Intelligence features will only be available for customers with organization-level activations of Security 1/2

English
1
4
22
10.2K
Michael Chan
Michael Chan@mchancloud·
Shame on you @googlecloud. Your competitor's AWS IAM Access Analyzer is free, and will likely remain so. If you cared about customer security, you're certainly not showing it.
English
0
1
3
198
Michael Chan
Michael Chan@mchancloud·
"What will require SCC Premium: IAM Recommender, including lateral movement insights, role recommendations for non-basic roles, recommendations for custom roles, and recommendation for Google Cloud Storage buckets. Policy Analyzer at scale (above 20 queries per day)."
English
1
0
0
208
Michael Chan
Michael Chan@mchancloud·
😠Wondering today why @googlecloud charges for security features that @awscloud gives away for free. Shouldn't customer security be paramount? "What will require Security Command Center Premium: IAM Recommender, including lateral movement insights, role recommendations ..."
English
4
4
5
1.6K
Ben Bridts‏
Ben Bridts‏@benbridts·
"This open source solution that AWS made will configure a landing zone for you" will keep making me sad about the direction Control Tower ended up taking
English
2
0
6
1.1K
Michael Chan
Michael Chan@mchancloud·
Coming from someone reviewing the security controls that can be enabled in Azure, this isn't too comforting. AWS I know has a strong security culture, but much less sure about Microsoft.
Wiz@wiz_io

🔒 What happened? While releasing open-source training datasets, Microsoft's AI research team accidentally left the vault door open 👀 Over 38TB of data (!), including personal backups of employee workstations, private keys, and internal Microsoft Teams messages, were exposed.

English
0
1
0
433
Michael Chan
Michael Chan@mchancloud·
Google's use of the vuln list cloudvulndb.org to claim better security than other CSP's is a classic example of misusing statistics by not understanding how the data has been curated and represented. @0xdabbad00
Michael Chan tweet media
English
2
2
9
726
Michael Chan
Michael Chan@mchancloud·
@alexadevs I was owed a May 13th payment, but its after 90 days, and according to your policy my money is now forfeit! I really hope this is not the case. I have upcoming payments as well :| Talking with Alexa support has not helped either.
English
0
0
0
94
Michael Chan
Michael Chan@mchancloud·
Hey @alexadevs, my Alexa skill has earned $$ the past few months, but it's never been credited to my bank account even though I've provided the info as asked in the developer console. Can you assist? I hope no other devs have this issue!
English
1
0
0
265