Showing posts with label opensource. Show all posts
Showing posts with label opensource. Show all posts

Friday, October 25, 2019

ATO 2019 - Inclusion event (a report)

This was the second year that ATO hosted a pre-conference track on diversity and inclusion. It was a sold out event with a free but separate registration (for booking, budgets, and accounting). I attended last year as well.

As I began writing up this report, I noticed the title of the event does not include the word diversity. According to the wayback machine, the main title was the same last year but it felt like the word diversity was included in most of the promotion of the event. Last year did have "A Conversation" as part of the title and incorporated much discussion on the definitions and differences in diversity, inclusion, and equity. This year the title was simply Inclusion in Open Source & Technology [1] and the presentations had a lot more actionable examples of how a project, organization, team, or individual can be more inclusive.

I really like the format of this event. They have a series of short talks which this year were basically people's stories of how they felt included or actions they thought there should be more of so others feel more included. Later there is a Q&A session for everyone to further explore these topics and suggestions.

This year also included a screening of the second episode of the Chasing Grace Project and a Q&A with the producer. I cannot seem to remember which event I was at when I had the opportunity to screen the first episode. I am looking forward to the complete series being available to a wider audience.

Last year I remember feeling a mix of depression and optimism. There were a lots of examples showing how those paying attention have expanded the types of diversity beyond gender and race and how many opportunities do exist. There were also a lot of stats showing how slow the progress is happening and where it is even going backwards. In many ways I felt like I was hearing the same things I've heard all my life and that is a tiring thought.

This year was, at least for me, a lot more positive. I think mostly because the discussions were not so much around statistics and abstract items which still need to be done, but rather a lot of examples of activities that have helped and could help:

  • The young high school student asked for more everyday roles models like parents and teachers sponsoring club activities. Representation at the C-level is important but not as important has having someone in room learning technology along side the students.
  • The older but not ready to retire gentleman reminding people that having had to change technologies so many times, older people bring a lot of experience and can still learn new things - sometimes even learning faster. Most of us also accept (even enjoy) being managed by more youthful enthusiasm as long as we are not just dismissed as a dinosaur. 
  • The consultants that help D&I committees  proactively create company communities and both networking and educational opportunities. 
  • The examples of how to reach out of your comfort bubble, grow your own network, and be an ally.
I came away reminded that I am where I am and still an Open Source consultant and educator because the of the welcoming and supportive people I have gotten to work with. People who treat other people as people. People who can work as part of a team. People who want to do the right thing and give the right people the credit they deserve. These people were rarely official mentors and many have never thought of themselves as an ally but by being good humans, they were an ally to me.

The little things matter. They matter when they produce the thousand paper cuts that drive people away. They matter when they appear from an ally and encourage inclusion.

-SML


[1] Note: at the time of writing the URL for this event was for the current year. At some time in the future it may be replaced with the next year details. I do not know if it will be archived. I was able to submit the page to the wayback machine.

Thursday, October 24, 2019

ATO 2019 - an event report

ATO 2019 was a good year.

For a number of years now, each October, thousands of technical folks converge in Raleigh for All Things Open. The "all things" includes a lot of developers talking about opensource platforms, tools, stacks, and applications but it also includes topics on open hardware, open government, open education, and building communities in addition to projects and products.

For a couple of years, I felt there was too much of a programmer focus for me and I wasn't finding new things in the community tracks. It is local though and so with expectations set, I continue to support a great  conference and enjoy the hallway track with a number of people I "see" mostly online even though I was not previously finding a lot of talks for my sysadmin or infosec interests.

I know several local people that have not attended the past couple of years because of this trend and I bring it up because this year was a bit different. While I attended expecting to once again content either repetitive (of other years and other conferences) or too dev focused, I was pleasantly surprised. There were full tracks both days for Security and Linux/Infrastructure. [1]

I attended a few of the security sessions, two that stood out were:

Prepping for the Zero Day Attack 
Eric Starr discussed a CI/CD pipeline that includes checking for vulnerabilities with both source code analysis and container scanning. He shared experiences where unit tests were disable "to speed up the deployments" which later turned into disasters. He was practical in his approach where some of the scans take hours to run. If the deployment or test cycle is shorter than a day, maybe those scans get run daily instead of with each change but do NOT eliminate them just because they take too long! He mentioned tools that work for his project but regularly pointed out what type of tool it was and that the specific tool used is not important. I would add that the best or right tool is any one you will use though you may be limited by what will work in your environment.

Insecurities and Vulnerabilities: How to Keep the National Vulnerability Database Current
I really enjoyed this one! Rob Tompkins shared his experience reporting CVE as part of an opensource project security team. When I teach about tools such as openscap and Red Hat Insights which include information from the NVD and then suggest remediations, it is helpful to understand how the information gets into this database. This example along with a talk from OSCON years ago about reporting embargoed security issues helps me also explain how an administrator should go about reporting a suspected vulnerability with correct documentation. This is a topic I am now adding to my "write and article on this" list.

Next door, at the Linux/Infrastructure room, by title, I would be interested in Getting Started with Flatpak and possibly Platform Agnostic and Self Organizing Software Packages . Also the What You Most Likely Did Not Know About Sudo…  and maybe the Terminal Velocity: Work faster in your shell  talks.

With these tracks, I would encourage a few of my more "Ops" friends to rethink attending this conference, especially if they are local to the area. I also have some new ideas for articles to write and possible presentations at future events.

Oh, they also have great book signings scattered across both days!

-SML

[1] Note: at the time of writing the URLs for the tracks were for the current year. At some time in the future these will be replaced with the next year tracks. I do not know if they will be archived. I was able to submit the parent tracks page for the wayback machine.

Wednesday, October 23, 2019

Writing Summary - late summer 2019

I've done some (ok, very little) writing for opensource.com in the past and I still have some notes for more articles that keep getting pushed aside. This site is almost 10 years old, community driven (with Red Hat Sponsorship), and tries to cover a variety of open topics, products, projects, and distributions.

This summer, some of the staff from that project switched over to help Red Hat start a new blog for system administrators called Enable Sysadmin. As the name implies it is focused on system administration topics and as a corporate blog it can also be a bit more Red Hat product specific. In addition to a small staff, a few part time contractors, and a number of Red Hat employee contributors, they do accept and encourage community contributions.

I have enjoyed being one of the early authors. Of course, like all my writing projects, I have plenty more ideas in my head and not enough focus to get them organized in a timely manner.

So far I have written two articles about using SSH keypairs, two articles about SELinux, and a short article about cybersecurity awareness month.

How to manage multiple SSH key pairs

Passwordless SSH using public-private key pairs

Accessing SELinux policy documentation

Four semanage commands to keep SELinux in enforcing mode

Security advice for sysadmins: Own IT, Secure IT, Protect IT

-SML

Friday, June 28, 2019

Red Hat Summit 2019: My notes

My notes from sessions at Red Hat Summit 2019 are for my reference and as documentation for any submitted continuing education credits.

The Ansible party was awesome as usual (even if was a part of the Smart Management party). Great food at Legal Harborside with lots of people I wanted to see.

I'm glad I watched most keynotes remotely. The one I did attend in person reminded me of how cold that space is and how many people where chemical scents that trigger my asthma.

Ran into more cool people at the Red Hat Women’s Leadership Community Luncheon.

Remaining notes include sessions attended as a reminder of which slides or videos to reference for more details as well as topics, commands, and keyword to dig into in the future.

Keynote recordings are available in the YouTube channel.

Session descriptions have links (where available) to slide decks.

On Demand session recordings require a login.

5/7: Red Hat security roadmap : It's a lifestyle, not a product

  • Speaker: Mark Thacker, Red Hat
  • Slides available
  • Recording available

5/7: The current and future state of security: A discussion of security challenges (Birds of a feather)

5/7: Successfully implementing DevSecOps: Lessons learned

  • Speakers: William Henry, Red Hat; Deven Phillips, Red Hat, Inc.; Lucy Kerner, Red Hat
  • UBI - Universal Base Image
  • https://github.com/rht-labs/labs-ci-cd
  • Case Study: Homeland Security in Innovative Labs
  • Look at pipeline box on Heritage slide.

5/7: Security: Emerging technologies and open source

  • Speaker: Mike Bursell, Red Hat; Nathaniel McCallum
  • Slides available
  • Recording available

5/8: Top 10 security changes in Red Hat Enterprise Linux 8

  • Speaker: Mark Thacker, Red Hat
  • Slides Available
  • Recording Available


5/8: Security and compliance automation: Demos of current capabilities and future technologies

  • Speakers: Shawn Wells; Chris Reynolds, Red Hat; Gabriel Alford, Red Hat Inc
  • Included pipelines with Ansible Tower, SCAP, and Open Controls.

5/9: Red Hat on Red Hat: Transitioning Red Hat IT to hybrid cloud infrastructure using OpenStack and Ceph Storage

  • Speakers: Brian Atkisson, Red Hat, Inc.; Matthew Carpenter, Red Hat, Inc.
  • Slides Available

5/9: Evolution of a Linux system identity and authentication stack

  • Speaker: Dmitri Pal, Red Hat, Inc.
  • Slides Available

5/9: A practical introduction to container security using CRI-O (LAB)

-SML

Tuesday, March 5, 2019

20 Years Ago: Remembering my first RHCE exam

When, where, and why

I learned about network operating systems working in a person computer (PC) helpcenter. After several years talking to customers and being an escalation point for other support engineers, I moved into the training department.

I was responsible for training the technicians using both in house written materials for our own hardware products and partner materials for most of the software. When I started working with Linux, I was already teaching official material for OS/2 Warp Server and SCO Unix in additional to some material for Microsoft, Banyan Systems, and Novell products.

When IBM invested in Linux, my position in a training department and my Unix background made me a lead on the team facilitating a plan to get the PC Helpcenters around the world up to speed in supporting four Linux distributions. We needed to quickly ramp up on Red Hat, Caldera, SUSE, and TurboLinux. I became the point person for Train-the-Trainer sessions on all four distributions in addition to having the responsibility of getting the North America support center trained.

The Red Hat office, with their brand new Training and Certification team, was located halfway between my office and my home so of course I started by attending their Red Hat Certified Engineer course. That was 20 years ago. To be precise, it was Mar 1-5, 1999.



The course

The course was similar to other technical training course which I had attended and taught. The RH300 RHCE Course was new and it was the only course offered at the time. In those years, the authors and the instructors were the same people.

It was a lot of information for a single week and it required a good foundation of prerequisite knowledge. Some things have not changed in 20 years!


The exam

I could not find the course or exam descriptions from 1999 but the Internet Archives Way Back Machine does show the spring of 2000 Prep Guide: https://web.archive.org/web/20000407183013/http://www.redhat.com/services/training/training_examprep.html

My memory is that most items did not change much in that first year.

The format:

Like now, the the exam was on that Friday. It was mostly hands on but not entirely since the first iteration included a multiple choice section. It was three parts:


  • Installation Lab Exam - 2.5 hours
  • Written Exam - 1 hour
  • Debug Lab Exam - 2.5 hours
  • PASS requires: avg of 80 or higher, with no single score lower than 50 pts.


I think my class did the installation in the morning with debug in the afternoon. The written section was in between followed by a lunch break. Soon after, the lab sections were swapped out in the daily schedule. I suspect it was quicker to grade the debug than the installation lab and systems needed to be reset for each section. My class did not need a reset since we took the exam on zip drives. Yup, you heard that correctly, ZIP drives. They were removed, labeled, and graded later. The email with my score report is dated March 19th. Two weeks later!


The objectives:

Objectives that are still seen today included:

  • Red Hat installation and network configuration
  • filesystem layouts and user management
  • boot issues and boot loader options
  • package management and automated installation
  • various network service configuration and security

Of course at that time, it was network-scripts files, ext2, NIS, LILO, rpm, squid, tcp_wrappers, and ipchains instead of the nmcli, xfs, GRUB, yum, systemd, and firewalld.

There were also some "get off my lawn" objectives:

  • We had to understand XFree86 configuration and get graphical login managers working
  • We used boot floppies for rescue. Yes, Floppies!
  • And we had to "be able to configure, build, and install the Linux kernel and modules from source".

The version:


  • My exam in March 1999 was on Red Hat Linux 5.2.
  • GNOME was technology preview and the kernel was 2.0.36.
  • A month later Red Hat Linux 6.0 was released.
  • The 2.2 kernel and glibc 2.1 were major new features and GNOME was the default GUI.


What Came Next

I became a Red Hat Certified Instructor through a partner program and immediately started sharing the wonders of Open Source with a whole new set of users. I added Red Hat Certified Examiner credentials a year later.

The first class I taught using Red Hat Training materials was written for RHL 6.0 and delivered in Scotland. That, though, is a story for another article.

Friday, March 1, 2019

FeBRRRRuary reading and writing

Stuff I wrote:

Getting started with Vim visual mode at opensource.com turned out to be very popular.

Fedora IoT Docs are Live for the Fedora Community Blog is a summary report for the majority of my February writing.

A technical reboot, recharge, upgrade, and expansion of the Fedora IoT Documentation took up most of my time and provided an opportunity to spend the dreary month working from home instead of commuting.

New bookmarks:

Specifically for the Fedora IoT project, I did a lot a reading in the month as well. Here are a few of the items I bookmarked. Some inspired my hacking and writing, some are saved for future adventures:

Getting to Know Fedora Silverblue

Raspberry Pi improvements in Fedora 29

Fedora IoT with Peter Robinson | OpenHours ep 133 video from 96Boards Open Hours.

How to turn on an LED with Fedora IoT

Turn a Raspberry Pi 3B+ into a PriTunl VPN

Set the holiday mood with your Raspberry Pi

How to build fully automated musical lights [Halloween/Christmas]

Home Assistant Installation on Docker.

Mozilla IoT Gateway


Wednesday, January 10, 2018

Watching the meltdown.

I have been watching Meltdown and Spectre unfold from the sidelines. Other than applying available updates, I'm just watching and absorbing the process of the disclosure. This one appears mid way along a long road.

I teach mostly administrators. I teach some developers. I teach those in, or desiring to be in, infosec. I like teaching security topics. I think securing systems requires more people thinking about security from the beginning of design and as an everyday, no big deal part of life. A question I ask with these newsworthy issues is what normal practices can mitigate even part of the problems?  There are two big basics - least privilege and patch management - to always keep in mind. Issues like ShellShock and Venom were mostly mitigated from the beginning with SElinux enabled (least privilege) and WannaCry had little impact on those systems patched long ago when the SMB bug was first found and fixed.

However, in some cases, both exploits and accidents come from doing something that no one else thought of trying. This is why I like open source. There is the option (not always used) for more people trying different things and finding better uses as well as potential flaws. Any type of cooperation and collaboration can be the source of some of these findings including pull requests, conference talks, or corporations working with academic research projects.

Spectra and Meltdown are not the first bug of their kind, nor the last. Anything that grabs or holds more information than is requested - such as cache or speculation - is bound to eventually grab and expose something it shouldn't. Or allow some type of injection. I gave some kudos to the team getting the credit for this discovery and got some push back from a friend defending another friend that gave a related talk at a conference in 2016. Maybe not enough credit is given to those that speculated (pun intended) on this type of problem in the past. This timeline lists several and some retweets from people I trust to be smarter than me in this topic point to ideas even older.


The Google Project Zero team is getting the recognition because of a variety of pieces in a big puzzle. Right place, right time. Privilege from the backing of a large company. Their use of the embargo and disclosure process working across the industry. A new proof of concept and published paper. Indications of ways to exploit it at scale. A mitigation. It all comes together and suddenly more than just the researchers realize the scope of the risk that has been taken. Intel is getting more than their share of the blame too when people recognize a company name faster than a general concept or part of a computer. And, yes, in some cases there is also too much fluff and fear in the reporting.

The embargo and disclosure process is pretty interesting too. I sat in a talk a couple of years ago about how a large company deals with this in the open source world and Mike Bursell has a post with thoughts about it again in reference to this case. I actually had an idea something big was coming from the combination of noise and speculation about patches being submitted and who was NOT talking about them.

We are still discovering the full impact of the CPU design decisions made. Sure, they are serious, especially as more people are able to automate attacks against the vulnerability, but they are also nothing to panic about. This is not just an Intel problem. It is a market driven quest for more power with less money and despite various risks. We are all to blame. Apply the patches, monitor the impact, invest in the next generation of inventors and inventions. In other words, business as usual.

The choices were made in favor of optimization, so will things be a little slower now? Probably for many people, but not everyone. Will we get over it? I would think so.

What will happen in the long run with the latest news? I predict many people will choose performance over security. I predict a few years from now when someone finds a scalable way to exploit one or more of the variations, people will have forgotten that they should have updated bios, firmware, and kernels today. If we are lucky, they will have the latest patches already deployed and just need to make some configuration changes. But when has luck worked out as the best security practice?

Links I have collected helping me to understand:

SANS Institute webcast.


Fedora Magazine KTPI overview.

OpenStack, What you need to know.

Project Zero technical overview.

xkcd

My favorite analogy thread - the library comparison - (more were rounded up here).






-SML

Tuesday, December 26, 2017

Holiday week

This is a holiday week. Most of my clients are shutdown for the whole week. Even the local library has a few extra days closed.  It means it should also be a week of personal time for me. Of course, as a small business owner who runs the company on a calendar year cash basis, it is the week I make sure all the paperwork is in order for end of year accounting and taxes. It is also a week where I can use self paced and online learning to catch up on some work related but non-billable professional development. 

While this blog was created to share the more personal and fun side of my professional life shared, it was still intended to stay professional. Sometimes the two mix and this week I am going to try to keep my writings less technical and more personal.

I will start with reading lists. All the year end best reads are out and I am looking for something fun.

NPR has 374 to choose from in their Book Concierge app.

TechGirlz suggested A Mighty Girl list.

Opensource.com has 10 must-read DevOps resources (see I can't stay away from work related topics completely)

I also need to get a copy of Despite the Height (and see if I can get it signed at a game this season).

-SML

Friday, December 22, 2017

Year in Review - reconnecting with Cloudera Training

I already wrote about Red Hat adventures of the past year but that is not the only part of my (professional) world. I also do some work with Apache Hadoop, mostly in partnership with Cloudera, Inc. I did not make any of the big data conferences this year but I did reconnect with Cloudera Training and Certification.

Apache Hadoop just had a release update but I am not sure when enough changes will trigger a major update to the downstream enterprise products.

The big news of the year for Cloudera as a company was the IPO (unfortunately they did not have a friends offering but hey, it isn't the big boom days either).


Over the past couple of years Cloudera has been moving their certifications to hands-on. This is a "good thing".


The big new class of the year is the Big Data Architecture Workshop which I have not yet had the chance to attend but am very interested (anyone care to sponsor me?). I do need to learn a bit more of the data science developer side first.


This year I had a chance to see some of the Cloudera Training OnDemand training (which they launched in 2016) and continue to contribute to some of their course materials.

A couple of related topics that I would like to explore in the coming months.
  • Integrating Cloudera Manager and FreeIPA. CM recognizes AD and direct admin connections to an MIT KDC but for FreeIPA it needs a custom script. 
  • Expore how the open Ambari manager works with securing hadoop clusters when using FreeIPA for the KDC. It appears to have been available as experimental since Ambari 2.4 according to this article.
  • Investigate Hadoop ecosystem and similar products  with Containers. Such as Machine Learning on OpenShift and Kubernetes and Big Data and Apache Spark on OpenShift Pt. I (2016)

It can be interesting to see the different and similar ways that companies manage curriculum development. Some day maybe I will see if I can get the permissions needed to share my amusements. Of course I have an opinion on which ways are better - just let me check on who is paying my fees for this week....  😇

I'll end with a plug for the Cloudera Training 2018 schedule since I hope that they sell enough seats to need me to teach! :)






Thursday, December 21, 2017

Year in Review - Red Hat training activity

I have been a certified instructor since the beginning of the program in 1999. I have contracts with delivery partners and am required to keep up on my skills and other information around the program.  This a roundup of information from 2017 which is relevant to this part of my world.

Sunday, December 17, 2017

ATO2017 - A (late) summary

Just a few thoughts on All Things Open 2017:
(and a record of sessions attended for CISSP continuing education credits).

This event - which happened way back in October - just keeps growing. It is already almost too big!

Sunday: I made it to the early checkin and social in the evening. The location for the social is a cute place. It hosts local art and for the October dates, some spooky themes. Many thanks to Red Hat - specifically the Red Hat Open Source Stories team - for the sponsorship. I am not sure how many people realized that their videos (which are amazing!) were running on the TVs around the space.

Monday: After scoring a pair of socks from OpenSource.com, I focused on the Security track with the following sessions:

securing-microservices-with-istio

secdevops

openid-connect-the-client-is-not-always-right

preventing-cloud-data-breaches-with-open-source

I also attended one security related talk from the DevOps track:

enterprise-devops-bridging-the-infosec-gap

Chatter on twitter was coming mostly from the the community track which was nice since those talks always have some good stuff in them but I would have liked to hear a bit more about the other technical talks I was skipping. That is the problem with SO MANY tracks. It can be hard to choose where to invest your time.

Tuesday: I attended a couple talks in the Education track and explored the hallway a bit. Unfortunately one of the talks I had to leave due to asthma triggered by (chemical) cologne worn by another attendee. I never really got to feeling all that great the rest of day and headed out early to go home.

jupyterhub-for-distance-learning

using-an-api-scavenger-hunt-to-engage-api-newbies

I was also asked about the Fedora branded long sleeve white button up shirt I was wearing.  Info is here:
https://fedoraproject.org/wiki/ButtonUp

Some slides from the conference are posted at:
https://www.slideshare.net/AllThingsOpen/presentations/

A comment on the focus and participation.
I overhead a conversation at lunch one of the two days that despite the name of "ALL" things open, this conference was very developer focused. I think that is and always has been  the intent of this conference. The person who was a bit disappointed is more of an admin and ops person.  I do remember having a few more interesting admin and community options in previous years but that may have more to do with what I was looking for those years. Also this year was in competition with a big conference in Europe that altered the attendance some. This is not necessarily a bad thing. Seeing the same people at all the conferences can result in really good talks by experienced presenters but it can also mean that there is not enough growth and encouragement for new talent in the industry.

As long as this a local, low cost, and fits my schedule, I will continue to attend and offer to speak. Even if it is more developer focused than my usual activities.

Save the dates:  Oct 21-23, 2018.

-SML

Thursday, October 12, 2017

Taking Stock, Making Plans.

My company has a couple of projects that are about to wrap up. In both cases the client has hired a full time employee to pick up the work. This is great for them and normal for my business but it does mean finding "the next big thing" around the holidays.

My company is small. Really small. OK, it is just me. So I have the flexibility to take my time finding the next big project. I still have smaller, recurring contracts to carry through.

Before I get into what kind of excitement I want from my next big thing, I am looking forward to taking a few weeks off and maybe getting to a few of the many "if only I had the time" projects that are on my list. At least spending *some* time on wish items in between searching for the next big thing.

I often wish I could be more diligent about writing  and presenting. Writing here and even contributing to opensource.com. Presenting at conferences which I have done in the past, but also at local meetups. The small groups are a lot more fun! I had a couple of conference proposals that did not make the cut recently but that I think are still valuable. One I even planned to write an article on and still just have not gotten it done. It is on the list.

As I have watched my Goddaughter grow up, I have meant to get more involved in sharing my knowledge with kids. I took her to a Kid's Day event before a Red Hat Summit one year and we had a blast. Since I first explored the CISSP certification I have had the interest to go through the Safe and Secure Online training so I can look for volunteer opportunities. I also think the Techgirlz program is awesome (I might be a bit biased since a fellow instructor went to work there) and they have a local chapter. It is on the list.

When I got started contributing to open source communities it was with the Fedora Project and specifically the Docs team. I have not been anywhere near as active with Fedora lately and I miss it. I still consider myself an active Ambassador with each class I teach but I have not really contributed through content or formal activities lately. I am actually looking for a new challenge though, rather than returning to an old stomping ground, and probably with a smaller project. I dabbled in an Apache Hadoop ecosystem project for a bit and I still follow that mailing list but I never really got into that community. Melding open source and security is ideal, though I have really enjoyed the past year where I jumped into automation with Ansible and containers with OpenShift. The search continues.

Then of course there is the true time off - something that never really happens when you own your own business - where I can get things done around the house. The builtin bookcase that is already planned, the office cleaned out with all the old equipment donated, the yard spruced up, some light reading, etc.  Also all on the list.

-SML

Sunday, May 7, 2017

Red Hat Summit 2017

A quick recap with self reminders of session links.

Sunday night was dinner with a couple of other instructors. Always a blast.

Monday night was the Ansible (Red Hat Management) Social. The venue (Coppersmith) was really cool. Their description is as a vintage warehouse but it looked to me like it had once been a firehouse.  The kitchen was in a pair of old food trucks welded together. And there was draft cider.

Tuesday was the start of the main activities. It was great to see the community groups in the center of things instead of a separate room like recent years. Also Training and Certification had various booths on the main floor instead of upstairs by the labs. For the print your own shirt, they added a RHCP option but I stuck with the skyline. I have enough other items with the RHCP logo on it.

I am not a fan of conferences in the Seaport district - the hotel and food options (for me and my allergies) are not as good as the older parts of town - but I understand the event the outgrown the Hynes. The extra room did result in a more spread out expo hall that actually appeared smaller than past years. Lines for sessions were also a bit smaller. I never heard the full numbers but I got the impression there was lower attendance as well. I also did not hear as much of an international flavor as previous year.

Tuesday evening I made an appearance at the Containers and Cloud party at Legal Test Kitchen (yummy shrimp!) before heading over to the RHCP party at Harpoon Brewery. They also had a draft craft cider.

Wednesday night we bailed on the Red Sox game. It was cold and windy and I wasn't sure what I would be able to eat. We went to Legal Seafood (again) and made it an early night. On Thursday at Summit I was able to pick up the ball caps with the Fenway logo on them.  There were a couple of other Boston themed giveaways on the expo floor that I was able to score on the final day as well. Specifically, a really nice glass with a Boston map.

The plane up on Saturday morning was about 1/3 hatters and the Friday morning plane home was more like half hatters.  We were all ready to sleep for the weekend.  I did a lot more hallway track this year than in the past but I did catch a few security related sessions.

Sessions:
Keynotes and general sessions were live streamed and are available on the Red Hat Summit YouTube channel.

Red Hat Security Roadmap included some information on upstream projects that Red Hat is focusing on and contributing to including TPM (2.0 and virtual), PKCS#11, NBDE, USB Guard. They also mentioned the ongoing work with OpenSCAP and a new site for container health index.

The Fury and the Sound: A mock disaster security vulnerability fable was a fun panel type presentation which walked through a mock vulnerability with reps from project managements, infosec, exec office, and IT.

Automating security compliance for physical, virtual, cloud, and container environments with Red Hat CloudForms, Red Hat Satellite, and Ansible Tower by Red Hat included some demos of using CloudForms to launch OpenSCAP scans and provide remediation with playbooks located in Ansible Tower.

-SML

Wednesday, March 8, 2017

International Women's Day

In honor of International Women's Day, I would like to thank some of the allies that have helped me live a life doing something I love and getting paid for it.

First and most of all is my Dad.

  • A man who taught me to make pancakes and made my school lunches. 
  • A man that sat with me (and cleaned up) when I was sick at 2am. 
  • An engineer who taught me to love logic puzzles. 
  • A business man who showed by example how to manage people. All kinds of people. In the realm of manufacturing and quality control.
  • A man who encouraged me and supported me when I was told directly by my teenage boy classmates and even indirectly by one of my teachers that "girls can't pay drums". 
My Mom also supported me and told me I could do anything, be anything that I wanted to be. She was a biology, pre-med major so there was no shortage of science knowledge in our home.

I was lucky to have some great role models in high school as well. A biology and life science teacher was a favorite. Also strong female role models teaching Calculus and Physics. Oh, and a band director that encouraged me to audition for several regional and state honor bands (several of which picked me).

My first full time job had its struggles but I can think of a couple of people that stood up for me, eventually.

As I moved into technical training I found most resistance came from students at the beginning of class.  There is a specific look on their faces as they walk into the classroom on day one and wonder what this chick can teach them about Linux. After 20 years I don't see that very often anymore.  I like to think that it is a good sign for the world in general. I never had a problem proving myself before the end of class - at least for the class in general - and for those few students that just didn't like me for no clear reason, the managers handling those complaints always backed me up.

Since I have been an independent consultant I have had the privilege of working with a few really great companies.  Red Hat, Cloudera, and /training/etc stand out with supportive environments for diversity, including "Women in Tech".  My thanks to several curriculum team members, several fellow instructors, and most of the scheduling and quality managers for their support over the years.

If I name names, I will miss somebody really important. But here are a few that stand out for specific events. Mom and Dad, Amy, Jay, Steve, Joe, Henry, Randy, George, Will,  Susan, Tom, Mike, Nate, Mark, Paul, Wade, Marc, Chris, Matt, and a bunch of others too: Thank You!  And all the other just all around good people that I have had the opportunity to work with or chat with or learn from or follow: Thank You!  And anyone else who has been a good citizen of a diverse community: Thank You!

-SML



Wednesday, November 2, 2016

Conferences 2016 (recaps and reminders)

Note to readers: This is primarily for reference for myself and for the reporting of CPEs for certifications I hold.

2016 Red Hat Summit

The RHCP party at the ballgame was awesome!
Full Schedule

Two talks that I specifically took notes in:

1 Hour Red Hat Summit - Slide presentation
Matthew Micene
Greg DeKoenigsberg
Lots of cool stuff!!! Where is the video?

Red Hat security roadmap
1 Hour Red Hat Summit - Slide presentation
Josh Bressers
Slides available for download.


Red Hat Summit 2017 is back in Boston May 2-4, 2017
[December 2, 2016: Last day to submit a proposal]


2016 Raleigh InfoSeCon - Friday October 21st

I volunteered this year which makes for a long day but I did sit in a few good talks.
I was laughing as the "Cyber Threats and Trends 2016 (FBI)" talked about potential problems from Maria just as the DDOS news was being updated with the connection.

2016 All Things Open - October 26 - 27

Great two days. And spectacular weather. I wish I would have battled the traffic to get a T-shirt from early registration and see Totty at the pre-party.   
With the increase in attendance, the rooms are still packed even with more sessions to choose from and lots of conflicts. Can't wait until a sponsor steps up to allow at least some sessions to be recorded and viewed later. I did find a few talks had been recorded. One on the Asian Penguins club was well done. The other on encrypted data in mysql was too hard to hear to be useful. (Please use the mic when being recorded even if those in the room can hear you without amplification).
  • The keynotes were great. 
  • I attended technical talks on Spark and Vault. 
  • I had some fun with Blinky Flashy Things, Security with Tolkien, and listening to Bob Young talk about startups.
  • I now have three new (signed) books to read.
  • I feel less guilty about not writing as much as I want to since I now know I am just stuck in the reading/research phase of writing according to Rikki (with the help of Stephen King).
Looking forward to next year. ATO and InfoSeCon are the same week in October so that will help my schedule some.  I need to decide on something to talk about...

-SML

Thursday, October 1, 2015

Strata Sessions and Events

Sessions

The choices of session at Stata Hadoop (NYC) this year were plentiful. I was not surprised by the number of talks around getting value out of data (analysis) but I was also happy with the number of talks that fall in my admin category or otherwise discuss how the services work. I would have preferred a few more categorized with security tag. The developer talks on the newly announced projects - RecordService and Kudu specifically - should have been in much bigger rooms. People had to be turned away.

Lack of food options for those with allergies

The Strata Hadoop conference sponsors provide food through the venue for lunch and expo socials. There was a distinct lack of allergen labels on food and limited choices. For a registration that asked about food allergies or preferences, there was not much choice for gluten free,kosher, or vegan. There were some vegetarian options.

The morning keynote area had some fruit (apples, oranges, bananas) with the supplied coffee. Other breaks that I saw did not have anything I could eat - lots of pastries in the morning and some rich and sugary treats in the afternoon. The evening Booth Crawl event was as expected with mostly beer and wine but the food was also not at all allergy friendly. Mostly I saw pasta, cheese plates, and Mexican style chips and dip. I did find a bag a chips to eat and I saw a hotdog stand (but didn't risk it). I also found a corner with some mixed drinks.

The first lunch had some options but not well marked, I had to find a supervisor and ask what I could eat and that was pretty limited. OSCON did a much better job in Portland by providing a separate serving area in addition to clear labeling of gluten free and vegan options (I'm still waiting for dairy free labeling to reach similar frequency). Lunch on the second day was a complete disappointment. It was soup and sandwiches and even the salad had croutons. No gluten free options at all. What is the point of asking people if they want GF at registration if the information is just ignored anyway?

Off site events

I did not make it to Data Dash.  It was a rain or shine event and it was raining but more importantly it was dark. I really am solar powered - early morning and late night events are most often slept through.  There was also the issue of timing. To make it to the event and back to the hotel for a shower, I would not have made it to the keynotes.  I am glad I attended that set of keynotes.

Data after Dark - High Line Hop was a combination of an off-site evening party and a pub crawl.  At other conferences I have attended these two events are separate with the pub crawl following the evening event. That means the pup crawls usually start well after my body gives up and send me "home" to sleep. Since it was a main event, each sponsors provided some combination of drinks, food,and swag. Also at each event was a wristband - collect enough to turn in at the main conference the next day for a hoodie. Initially I was told, get all 7 but later I saw a sign that said get 5 of the 7. I actually popped into all the venues. I am sure it would have been more fun if I was here with a crowd of people I already knew - or if I had any of that type of social skills at all. Still, after a nice walk to the area along the High Line, it was an opportunity to see the inside of some popular NYC hostpots:

The three bars at The Park are interconnected. I entered the Red Room first and found it to be kinda dark. . There are also several small changes in levels so that means step down in the dark.  Seems like a bad combo for bar.  Of these three, it was also the most crowded with everyone hanging right around the bar area at the entrance. After winding through Red Room, The Garden is open and light. This feels like a really nice place to hang out on nice evening. There was also some food provided but it was more pasta so not for me. Finally, there is a steep metal stairs up to The Penthouse which is back into a darker venue, though not as dark as the Red Room. There were some fancy looking deserts provided here.

After exiting The Park venues, I headed next door to Avenue. This venue has a couple of floors. I did not go upstairs but was told there was a second bar up there in addition to some seating. It was very loud and I scrammed fast.

Originally I was going to pop into the 4 that were together, then stop by the Cloudera sponsored venue and head out.  I'm glad I decided to keep exploring. I made a quick walk through Gaslight. I think this would be cool if I could eat pizza. I stayed a while at Catch NYC. This venue was sponsored by Bloomberg and was the "classy" venue. It was also the least populated while I was there. The had some food out but it all appeared to have dairy. We were upstairs and could watch the kitchen at work. I saw a few plates headed downstairs. I think it might be a place that could cater to my needs for a sit down meal.  The music here was also a bit loud but I sat and watched the world go by for a bit.

Finally, I headed to Tao. Very crowded, very loud, very bar scene.I wandered through and then tried to squeeze back out. Another group came in, saw the crowd,and turned around breaking a path back out for all of us.  I suggested they try Catch if they wanted a bit more room.

Overall, I logged many steps and my legs were very tired.

-SML

Strata Keynotes

I am attending my first #StrataHadoop Conference in NYC.

The Wed morning keynotes were well done. Lots of speakers, many sponsors, but each was short and about Data in general (not just a sales pitch). The keynotes were all streamed and are available for viewing.


Here are a few of the highlights that caught my interest:

First up was Mike Olson from Cloudera. It was the expected "Recent accomplishments, Big announcements, Exciting Future" talk. Not surprising is the growth of Spark and Kafka. I was also already aware of the new RecordService announcement. I still have to look up a few of the other mentioned partnerships like CounterTack Sentinel and work with healthcare ERM security. Also new projects such as Ibis and Kudu. 
He ended by pointing out that Hadoop is now 10 years old.

The second keynote was my favorite. AnnMarie Thomas (School of Engineering and Schulze School of Entrepreneurship, University of St. Thomas) talked about creative ways to encourage and teach STEM. While not specifically pointed out, it had a very clear message about the benefits of diversity in teams - any team.  Her students work with playdough to sculpt circuitry, experience circus training to learn higher math of physics, gain new perspectives by sharing knowledge with preschool children, and compare digital and human observations with cooking.  All really cool projects. This presentation gave me some ideas to add to my search for non-programming STEM projects for youth that I wrote about a few months ago.

Next up there was an amusing talk by Joseph Sirosh (Microsoft) discussing the How Old Robot. This was followed by Ron Kasabian (Intel) and Michael Draugelis (Penn Medicine) talking about the Trusted Analytic Platform and Penn Signals.  I think I dozed off a bit during the Tim Howes (ClearStory Data) talk.

Joy Johnson (AudioCommon) talked about Music Science followed by a related discussion of data in creative decisions by David Boyle (BBC Worldwide). These were interesting just not in my primary focus. I just do not have enough brain cells for all nifty research out there.

I enjoyed the talk by Jim McHugh (Cisco) on Data from the edge. Can I drive the race car next time? I did not realize that with all the wearables and small device sensors, that the Tour de France still mostly tracked progress with a guy on the back of a moterbike and chalkboard.  Next year there will be GPS devices on all the bikes and in the support vehicles. From the support vehicles, the data gets uploaded "real time" to a helicopter and from there down to a central van analytic truck. Teams, and more importantly, press (and there by fans) can get more acurate real time data of the race progress. 

DJ Patil (White House Office of Science and Technology Policy) talked about efforts to open data in a machine readable format. He pointed out that machine readable format does not mean PDF. He also asked that any training efforts make use of these open data sets. He continued to discuss some specific projects available and wrapped up with a plea to integrate data ethics into all programs and all training - not just as an add on or after thought or separate requirement - as a normal part of every step of every use of any data sets.

Katherine Milkman (Wharton School at the University of Pennsylvania) discusses improving decisions. I liked the examples of temptation bundling and the choice architecture, specifically the keyboard stairs in Stockholm. There was also a reference to the book Nudge. 

The final presentation was by Jeff Jonas (IBM) He was the founder of another company acquired by IBM and has a background in fraud detection analytics.  He discussed how context is important. His evil puzzle experiment is as fascinating as the space time boxes for asteroid hunting. 

-SML

Being the speaker

I am the speaker all the time. I teach. I present material most weeks. I'm paid know my stuff. People pay to learn stuff. While I mostly teach materials written by a large team of other people, I have also often been on those teams. With so many years of experience both writing and presenting material, why have I not been a speaker at conferences more frequently?

For me, a large part is figuring out a topic. Much of what I teach is multi-day classes. Most conference presentations are about 40 minutes with maybe another 10 for questions. What topics do I love to talk about can be narrowed down to a short presentation? What do people really want to hear? What is new or not talked about enough?

So I finally come up with some ideas. Am I describing it correctly to get chosen? How do I convince the committee? Do any of them know me or is the choice from the description only? Have I specified the correct "level" for the conference notes?

And then a talk is accepted. Now I have to actually finish the presentation materials. Bullets are bad. Pictures are good. Once again, have I specified the correct level or otherwise described my presentation correctly? Will anyone attend? What if I get asked a question I cannot answer? Why does the pre-conference attendee list include [leader in field X] as planning to attend my intro talk!?!  Why am I doing this? For free?

I think I need to go listen to Major's “Be an inspiration, not an impostor” talk. He wrote both about his talk at Texas Linux Fest and a followup FAQ.

My first conference talk was at a local information security conference. It was a smallish event and a small crowd attended my session but it went well. I felt that I had covered what I intended and at the level I had expected. I was even asked to submit a topic for the following year.

This year I presented at LinuxCon and was surprised at the response. They moved rooms as the interest shown in the talk increased. I ended up with 95 people attending my "SELinux, Its about the Labels" talk. That is a lot. The keynotes hold about 900 people. The Linux Security Summit at the end of the week was in a smaller room with about 100 people. Intimidating. It went well though - at least I think it did. I had a few people come up and ask questions at the end of the talk and a few others recognize me and mention the talk later in the week. No one flamed me in person or on social media. That is a win.

I am giving the same talk again next month and I learned a few things and will be tweaking the presentation but only a small amount.

-SML

Linux Security Summit


Continuing my notes and link references from August....

Before leaving Seattle, I stayed for part of the Linux Security Summit.

Paul Moore gave a great review of the summit.

I have to agree that Konstantin's keynote was exceptional. Check out the Presentation, referenced video, and released policies.

The CC3 talk was fine but just not anything I am remotely working with at the moment.

Stephen Smalley's SELinux on Android talk was informative for me. It gave me some ideas and links to look at before my next talk.

Rethinking Audit went too deep in the kernel source for me but I followed the discussion - or at least most of it.

The afternoon included a nap but I did return for the discussion on the Core Infrastructure Initiative. There is a lot of work to do here but the concept has some promise.

On Friday morning I popped into the Samsung talk before checking out and heading to the airport. I was a bit disappointed as it seems to me they are reinventing the wheel to have a security framework on their platform. I did note a couple of capabilities they are trying to get into the kernel so I do see the relevance of speaking at the summit. It did not seem deep enough - or "source code" enough to interest the kernel developers, and was too much overview to interest my ops side.

-SML

Wednesday, September 30, 2015

LInuxCon 2015 - Seattle

More catching up...

LinuxCon Day1 

As usual I was awake early, very early. So a walk and a Whole Foods breakfast were accomplished in time to catch all the keynotes. The first was a snooze. I understand large sponsors getting time with a captive audiance but I really wish they would not just give a sales pitch.  They could have announced their new offering in under 5 minutes, listed the related talks and booth locations, and talked about something more interesting than price points of a mainframe.

The second keynote was "How Collaborative Systems are Reinventing Capitalism" byRobin Chase, Founder of Zipcar and Author of Peers Inc.  It was an interesting talk but not what I expected for a LinuxCon audience. By the end the loose ends did eventually tie her Peers, Inc. concept to Open Source collaboration with the idea for Peers, Peers where both innovative user experience and innovative platform environments.

The final keynote of Day 1 was "Full Sail Ahead: What’s Next For Container Technology" presented by several Docker employees and complete with live demos - always a fascinating thing made even more impressive by running smoothly. A key element here was the introduction to notary options - verified and signed containers not just trusted repositories.

Also announced at the keynotes was the Core Infrastructure Initiative which was also discussed more at the Linux Security Summit a few days later.

I ducked into a few talks on Monday including "Why be a Rock Star Developer when you can be a Willie Nelson" by Rikki Endsley but mostly I just worked the hallway track and got my slides finalized and uploaded.

The Monday Evening event, open to Speakers and VIPs, was at Chihuly Garden and Glass I was very excited for this event.  The glass is spectacular.

LinuxCon Day 2

Day 2 turned into a security day for me. 

The first Keynote was a video conference with Bruce Schneier, renowned security technologist and CTO, Resilient Systems where he discussed "Attacks, Trends and Responses". Mostly he talked about the Sony attack and how that has affected the security playing field.

In addition to my talk, I popped into a couple of other security related sessions:


Evening Booth Crawl was crowded and I did not find any food or drink that fits my dietary restrictions. I did finally find a quieter area and some good conversation.

LinuxCon Day 3

The most notable sessions from Day 3 were Repeatable Processes for Building Secure Containers with Ryan Jarvinen & Dan Walsh (which was really an introduction to OpenShift 3) and Container Security - Past, Present & Future presented by Serge Hallyn from Canonical.

Lunch with the Linux Foundation Instructors was a highlight of the day. I was actually most surprised that Rock Bottom Brewery could find something I could eat.  The afternoon booth drawings were a bust and I was just plain tired by the time of the evening event at the EMP Museum. My favorite was the Animation Art of Chuck Jones "What's Up Doc?" exhibit. 

-SML