<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Forem: David Calvert</title>
    <description>The latest articles on Forem by David Calvert (@0xdc).</description>
    <link>https://forem.com/0xdc</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F881913%2F554734d8-abb6-4706-b616-a4dfff87a32a.jpg</url>
      <title>Forem: David Calvert</title>
      <link>https://forem.com/0xdc</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://forem.com/feed/0xdc"/>
    <language>en</language>
    <item>
      <title>Time to strengthen your password hygiene!</title>
      <dc:creator>David Calvert</dc:creator>
      <pubDate>Thu, 05 Jan 2023 13:28:51 +0000</pubDate>
      <link>https://forem.com/0xdc/time-to-strengthen-your-password-hygiene-52o5</link>
      <guid>https://forem.com/0xdc/time-to-strengthen-your-password-hygiene-52o5</guid>
      <description>&lt;p&gt;It’s 2023, happy new year!&lt;/p&gt;

&lt;p&gt;If you were still a LastPass user in December, I hope that the &lt;a href="https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/" rel="noopener noreferrer"&gt;terrible news&lt;/a&gt; didn’t ruin your Christmas and New Year's Eve parties. No matter if you are concerned by the breach or not, the beginning of the year is always a good opportunity for everyone to take good resolutions, why not choose to strengthen your password hygiene!?&lt;/p&gt;

&lt;h2&gt;
  
  
  What happened?
&lt;/h2&gt;

&lt;p&gt;LastPass got hacked again, “an unauthorized party gained access to a third-party cloud-based storage service, which LastPass uses to store archived backups of our production data”.&lt;br&gt;
Ouch!&lt;/p&gt;

&lt;p&gt;On December 23, 2022, I received this email sent to every LastPass user:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Dear LastPass Customer,&lt;/p&gt;

&lt;p&gt;We recently notified you that an unauthorized party was able to gain access to a third-party cloud-based storage service which is used by LastPass to store backups. Earlier today, we posted an update to our blog with important information about our ongoing investigation. This update includes details regarding our findings to date, recommended actions for our customers, as well as the actions we are currently taking.&lt;/p&gt;

&lt;p&gt;We thank you for your patience and continued support of LastPass.&lt;/p&gt;

&lt;p&gt;The Team at LastPass&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;I was busy preparing Christmas and didn’t have time to look into further details, so I didn’t do anything that day. But a few days later, it all changed when I saw the headlines... If you are still a LastPass user, I strongly recommend you to read the official &lt;a href="https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/" rel="noopener noreferrer"&gt;incident notice&lt;/a&gt; from LastPass, &lt;a href="https://www.wired.com/story/lastpass-breach-vaults-password-managers/" rel="noopener noreferrer"&gt;this article&lt;/a&gt; from Wired, &lt;a href="https://blog.1password.com/not-in-a-million-years/" rel="noopener noreferrer"&gt;this article&lt;/a&gt; from 1password and these toots (&lt;a href="https://infosec.exchange/@epixoip/109570449317277575" rel="noopener noreferrer"&gt;toot #1&lt;/a&gt;, &lt;a href="https://infosec.exchange/@epixoip/109585049354200263" rel="noopener noreferrer"&gt;toot #2&lt;/a&gt;) from &lt;a href="https://infosec.exchange/@epixoip" rel="noopener noreferrer"&gt;Jeremi M Gosney&lt;/a&gt;, or &lt;a href="https://duckduckgo.com/?q=lastpass+breach" rel="noopener noreferrer"&gt;any other source&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;There are still a lot of unanswered questions, and LastPass is not providing many details and numbers about the breach. The situation is already pretty bad, and it will only get worse in the coming weeks or months. Attackers have plenty of time to prepare for step 2, especially when they will be able to crack the vaults or even sooner with the unencrypted metadata they already have.&lt;/p&gt;

&lt;p&gt;LastPass has been my password manager for years, but even with a strong password, I didn’t feel safe and didn’t trust the service anymore. This is why I decided to make a move, and I think you should too!&lt;/p&gt;

&lt;h2&gt;
  
  
  What to do?
&lt;/h2&gt;

&lt;p&gt;Many recommended picking another service, and while it's not mandatory yet, it's probably the best thing to do right now. Changing all your passwords is a real burden, but if you are, or if you were a LastPass user, I think you should!&lt;/p&gt;

&lt;p&gt;I have been using &lt;a href="https://1password.com" rel="noopener noreferrer"&gt;1password&lt;/a&gt; at work, and I’m both familiar and satisfied with the service so far. Before making the switch, I wanted to try &lt;a href="https://bitwarden.com" rel="noopener noreferrer"&gt;Bitwarden&lt;/a&gt; following the recommendation of a friend, and I have to say that it’s a pretty solid option, especially if you’re looking for a &lt;a href="https://bitwarden.com/pricing/" rel="noopener noreferrer"&gt;free&lt;/a&gt;, or cheap option. After comparing the two services side by side, I prefer the user experience of 1password, and I also believe that it will be the best option for the other members of my family, that’s why I finally decided to choose it over Bitwarden.&lt;/p&gt;

&lt;p&gt;If you’re considering a switch, I recommend trying them both before making a choice.&lt;/p&gt;

&lt;h2&gt;
  
  
  Call to action
&lt;/h2&gt;

&lt;p&gt;If you are a LastPass user:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;read the articles mentioned earlier&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;rotate all your passwords to the maximum strength available&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;use Two-Factor Authentication (2FA) everywhere it's available (try to avoid text-based when possible)&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;consider a &lt;a href="https://www.nitrokey.com" rel="noopener noreferrer"&gt;Nitrokey&lt;/a&gt; or a &lt;a href="https://www.yubico.com" rel="noopener noreferrer"&gt;YubiKey&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;regularly check &lt;a href="https://haveibeenpwned.com/" rel="noopener noreferrer"&gt;https://haveibeenpwned.com&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In all cases, you can still:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;use a password manager if it’s not already the case&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;check the strength of all your passwords and take action accordingly&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;rotate your important passwords from time to time, always to the maximum strength&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;use Two-Factor Authentication (2FA) everywhere it's available (try to avoid text-based when possible)&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;consider a &lt;a href="https://www.nitrokey.com" rel="noopener noreferrer"&gt;Nitrokey&lt;/a&gt; or a &lt;a href="https://www.yubico.com" rel="noopener noreferrer"&gt;YubiKey&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;regularly check &lt;a href="https://haveibeenpwned.com/" rel="noopener noreferrer"&gt;https://haveibeenpwned.com&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Final words
&lt;/h2&gt;

&lt;p&gt;Best wishes for 2023, I hope that, like me, you will start the year with better password hygiene!&lt;/p&gt;

&lt;p&gt;Feel free to follow me on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;GitHub : &lt;a href="https://github.com/dotdc" rel="noopener noreferrer"&gt;https://github.com/dotdc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Mastodon : &lt;a href="https://hachyderm.io/@0xDC" rel="noopener noreferrer"&gt;https://hachyderm.io/@0xDC&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Twitter : &lt;a href="https://twitter.com/0xDC_" rel="noopener noreferrer"&gt;https://twitter.com/0xDC_&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;LinkedIn : &lt;a href="https://www.linkedin.com/in/0xDC" rel="noopener noreferrer"&gt;https://www.linkedin.com/in/0xDC&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👋&lt;/p&gt;

</description>
      <category>emptystring</category>
    </item>
    <item>
      <title>Creativity, Inc.</title>
      <dc:creator>David Calvert</dc:creator>
      <pubDate>Mon, 19 Sep 2022 06:06:35 +0000</pubDate>
      <link>https://forem.com/0xdc/creativity-inc-mpo</link>
      <guid>https://forem.com/0xdc/creativity-inc-mpo</guid>
      <description>&lt;h2&gt;
  
  
  Introduction
&lt;/h2&gt;

&lt;p&gt;Before joining Powder in late 2021, I got to read their blog, to learn more about the company. Among their blog posts, "&lt;a href="https://powderapp.medium.com/powder-how-we-defines-our-company-values-d5f28e20407e"&gt;How we defined our company values&lt;/a&gt;" particularly got my attention. The article describes how they defined their culture and shared values during Powder's first off-site. The Pixar culture described in &lt;a href="https://www.goodreads.com/book/show/18077903-creativity-inc"&gt;Creativity, Inc&lt;/a&gt; was cited as a reference there, and was used as a foundation to bootstrap Powder's own culture. Because she knows I love those kinds of books, my wife got me a copy for my birthday earlier this year, and I finally got time to read it this summer.&lt;/p&gt;

&lt;h2&gt;
  
  
  Description
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;"As a young man, Ed Catmull had a dream: to make the world’s first computer-animated movie. He nurtured that dream first as a Ph.D. student at the University of Utah, where many computer science pioneers got their start, and then forged an early partnership with George Lucas that led, indirectly, to his founding Pixar with Steve Jobs and John Lasseter in 1986. Nine years later and against all odds, Toy Story was released, changing animation forever.&lt;/p&gt;

&lt;p&gt;Since then, Pixar has dominated the world of animation, producing such beloved films as Monsters, Inc., Finding Nemo, The Incredibles, Up, and WALL-E, which have gone on to set box-office records and garner twenty-seven Academy Awards. The joyousness of the storytelling, the inventive plots, the emotional authenticity: In some ways, Pixar movies are an object lesson in what creativity really is. Now, in this book, Catmull reveals the ideals and techniques, honed over years, that have made Pixar so widely admired―and so profitable.&lt;/p&gt;

&lt;p&gt;Creativity, Inc. is a book for managers who want to lead their employees to new heights, a manual for anyone who strives for originality, and the first-ever, all-access trip into the nerve center of Pixar Animation Studios―into the story meetings, the postmortems, and the 'Braintrust' sessions where art is born. It is, at heart, a book about how to build and sustain a creative culture―but it is also, as Pixar co-founder and president Ed Catmull writes, 'an expression of the ideas that I believe make the best in us possible.'"&lt;/p&gt;

&lt;p&gt;&lt;em&gt;From the cover of Creativity, Inc&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Thoughts and feelings
&lt;/h2&gt;

&lt;p&gt;In the book, Ed Catmull describes all the steps that led him to found Pixar and build the first computer-animated movie. When you think about it, this must have been a very long shot back then. Ed Catmull includes a lot of details on their journey, and how it could have turned south. I found the story amazing because you really feel that the odds were against them, but they've finally made it with their determination, hard work and also, let's be honest, a bit of luck.&lt;/p&gt;

&lt;p&gt;After the release of Toy Story in 1995, Ed Catmull's dream was fulfilled. I can imagine his feelings during this particular moment, and the crisis that comes after it: what to do once you've accomplished your dream? He needed a new quest, so he focused on developing a healthy and creative culture for Pixar and remove all the obstacles along the way. His new goal was to enable trust, gain candor and remove fears in order to embrace creativity at Pixar.&lt;/p&gt;

&lt;p&gt;I love the small cliffhanger during the making of Toy Story 2, when someone accidentally deleted the movie's footage using the &lt;code&gt;/bin/rm -rf *&lt;/code&gt; command. Following Murphy's law, they realized that the backup system hadn't been working for weeks! As a system engineer, I've often been responsible for backups and was even the technical lead of a backup platform with more than 3500 client servers. Even if such an incident had never happened to me, I felt their pain, until I found out that they got a lucky star! Galyn Susman, the movie's supervising technical director, had set up an automated backup sync every week when she took some time off for the birth of her second child 6 months earlier. Good news for them, she forgot to disable it, so they were back on track!&lt;/p&gt;

&lt;p&gt;The merger with Disney is also a huge step! I was really amazed to see how Steve Jobs, Robert Iger, John Lasseter and Ed Catmull handled this together. They made sure that the merger will work for themselves, sure, but also for every employee of Pixar and Disney Animation. This is for sure, a really good leadership lesson.&lt;/p&gt;

&lt;p&gt;The book ends with an unusual description of Steve Jobs, Ed Catmull's thoughts for managing a creative culture and his acknowledgments.&lt;/p&gt;

&lt;h2&gt;
  
  
  Favorite quotes
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;"Experiments are fact-finding missions that, over time, inch scientists toward greater understanding."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;blockquote&gt;
&lt;p&gt;"Everyone says they want to hire excellent people, but in truth we don't really know, at first, who will rise up to make a difference."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;blockquote&gt;
&lt;p&gt;"The best way to predict the future is to invent it."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Final works
&lt;/h2&gt;

&lt;p&gt;To sum it up, it's a really good read! I'm pretty sure that most people can get something from this book, to name a few: learn how to build a company's culture, leadership advices, Pixar's history, a good tale from the Silicon Valley...&lt;/p&gt;

&lt;p&gt;If you like what I do, feel free to follow me on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;GitHub : &lt;a href="https://github.com/dotdc"&gt;https://github.com/dotdc&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Twitter : &lt;a href="https://twitter.com/0xDC_"&gt;https://twitter.com/0xDC_&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;LinkedIn : &lt;a href="https://www.linkedin.com/in/0xDC"&gt;https://www.linkedin.com/in/0xDC&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👋&lt;/p&gt;

</description>
      <category>books</category>
      <category>culture</category>
      <category>tales</category>
      <category>review</category>
    </item>
    <item>
      <title>0xDC is live! 🎉</title>
      <dc:creator>David Calvert</dc:creator>
      <pubDate>Fri, 02 Sep 2022 11:16:48 +0000</pubDate>
      <link>https://forem.com/0xdc/0xdc-is-live-361a</link>
      <guid>https://forem.com/0xdc/0xdc-is-live-361a</guid>
      <description>&lt;p&gt;&lt;a href="https://0xdc.me"&gt;https://0xdc.me&lt;/a&gt;&lt;/p&gt;

</description>
      <category>blog</category>
      <category>devops</category>
      <category>opensource</category>
      <category>cloud</category>
    </item>
    <item>
      <title>Is your Kubernetes API Server exposed? Learn how to check and fix!</title>
      <dc:creator>David Calvert</dc:creator>
      <pubDate>Thu, 07 Jul 2022 08:40:42 +0000</pubDate>
      <link>https://forem.com/0xdc/is-your-kubernetes-api-server-exposed-learn-how-to-check-and-fix-4f3g</link>
      <guid>https://forem.com/0xdc/is-your-kubernetes-api-server-exposed-learn-how-to-check-and-fix-4f3g</guid>
      <description>&lt;p&gt;I just published "Is your Kubernetes API Server exposed? Learn how to check and fix!"&lt;/p&gt;


&lt;div class="ltag__link"&gt;
  &lt;a href="https://medium.com/@dotdc/is-your-kubernetes-api-server-exposed-learn-how-to-check-and-fix-609ab9638fae" class="ltag__link__link"&gt;
    &lt;div class="ltag__link__pic"&gt;
      &lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--0STohJlu--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://miro.medium.com/fit/c/96/96/1%2A-jr05aRsofQSbeSt_siqBA.jpeg" alt="David Calvert"&gt;
    &lt;/div&gt;
  &lt;/a&gt;
  &lt;a href="https://medium.com/@dotdc/is-your-kubernetes-api-server-exposed-learn-how-to-check-and-fix-609ab9638fae" class="ltag__link__link"&gt;
    &lt;div class="ltag__link__content"&gt;
      &lt;h2&gt;Is your Kubernetes API Server exposed? Learn how to check and fix! | by David Calvert | Jul, 2022 | Medium&lt;/h2&gt;
      &lt;h3&gt;David Calvert ・ &lt;time&gt;Aug 21, 2022&lt;/time&gt; ・ 
      &lt;div class="ltag__link__servicename"&gt;
        &lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--hnDHPsJs--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev.to/assets/medium-f709f79cf29704f9f4c2a83f950b2964e95007a3e311b77f686915c71574fef2.svg" alt="Medium Logo"&gt;
        Medium
      &lt;/div&gt;
    &lt;/h3&gt;
&lt;/div&gt;
  &lt;/a&gt;
&lt;/div&gt;


</description>
      <category>kubernetes</category>
      <category>cybersecurity</category>
      <category>api</category>
      <category>security</category>
    </item>
    <item>
      <title>A set of modern Grafana dashboards for Kubernetes</title>
      <dc:creator>David Calvert</dc:creator>
      <pubDate>Fri, 24 Jun 2022 05:32:10 +0000</pubDate>
      <link>https://forem.com/0xdc/a-set-of-modern-grafana-dashboards-for-kubernetes-5f56</link>
      <guid>https://forem.com/0xdc/a-set-of-modern-grafana-dashboards-for-kubernetes-5f56</guid>
      <description>&lt;p&gt;Sharing my first article on Medium! It's about a set of modern Grafana dashboards I made for Kubernetes.&lt;/p&gt;


&lt;div class="ltag__link"&gt;
  &lt;a href="https://medium.com/@dotdc/a-set-of-modern-grafana-dashboards-for-kubernetes-4b989c72a4b2" class="ltag__link__link"&gt;
    &lt;div class="ltag__link__pic"&gt;
      &lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--KlR7tpA_--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://miro.medium.com/fit/c/48/48/1%2A-jr05aRsofQSbeSt_siqBA.jpeg" alt="David Calvert"&gt;
    &lt;/div&gt;
  &lt;/a&gt;
  &lt;a href="https://medium.com/@dotdc/a-set-of-modern-grafana-dashboards-for-kubernetes-4b989c72a4b2" class="ltag__link__link"&gt;
    &lt;div class="ltag__link__content"&gt;
      &lt;h2&gt;A set of modern Grafana dashboards for Kubernetes | by David Calvert | Medium&lt;/h2&gt;
      &lt;h3&gt;David Calvert ・ &lt;time&gt;Aug 21, 2022&lt;/time&gt; ・ 
      &lt;div class="ltag__link__servicename"&gt;
        &lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--hnDHPsJs--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev.to/assets/medium-f709f79cf29704f9f4c2a83f950b2964e95007a3e311b77f686915c71574fef2.svg" alt="Medium Logo"&gt;
        Medium
      &lt;/div&gt;
    &lt;/h3&gt;
&lt;/div&gt;
  &lt;/a&gt;
&lt;/div&gt;


</description>
      <category>kubernetes</category>
      <category>monitoring</category>
      <category>devops</category>
      <category>opensource</category>
    </item>
  </channel>
</rss>
