Earlier quoted context omitted.
Download the epub version and on the Linux command-line execute `tar -zxvf srs-epub.epub` then cd into unpacked `OEBPS/` folder and there's your HTML files. Not exactly what you are looking for, but you can browse the content in a web browser.
That doesn't work, unless you have an unusual Linux setup: $ tar -zxvf srs-epub.epub gzip: stdin has more than one entry--rest ignored tar: Child returned status 2 tar: Error is not recoverable: exiting now But you can do "unzip srs-epub.epub".
New Google SRE book: Building Secure and Reliable Systems
91–100 of 227 posts
Re: New Google SRE book: Building Secure and Reliable Systems
#92I scanned the introduction, but failed to see any concrete information on the expertise of the authors on security. Can anybody speak to the expertise of the authors on security? In particular, I am interested in specific projects or initiatives they directed or lead. The state of systems before and after these projects. If there were any long-term regressions after their involvement. To be even more concrete if poss…
> Can anybody speak to the expertise of the authors on security? I think a cursory LinkedIn or social media search for any of the title authors or chapter authors will demonstrate their credentials. There were many people involved in this book, all of whom carry the necessary credentials and experience. > Personal questions for the responder: Guidelines help us scale, but at the end of the day, some services are uniq…
Yes, guidelines are not the end-all-be-all and you can never be sure, but when a civil engineer approves a bridge, they assert that they are confident that human lives can be trusted to the bridge (in certain configurations). They can do this with reasonable confidence because they have seen systems that have stood the test of time that prove out the techniques that they are applying. That is what I am interested in, do you/they have that level of confidence? What justifies that confidence? What systems prove out the techniques that were used? Did any techniques they invent stand the test of time (this provides evidence they can invent new techniques)?
Re: New Google SRE book: Building Secure and Reliable Systems
#93Re: New Google SRE book: Building Secure and Reliable Systems
#94Earlier quoted context omitted.
You seem much more interested in the authors than in the book.
Indeed I am. Would you trust the contents of a book on a technical topic if the authors are not, in fact, subject matter experts? Would you read a book on cancer treatment by a doctor of theology with no medical training? To use a less egregious example, a neurologist with no training in oncology or experience with brain cancer? Knowing the expertise of the authors is very important, especially if you are not a subje…
Re: New Google SRE book: Building Secure and Reliable Systems
#95What would be the equivalent trio of books for the SWE?
Re: New Google SRE book: Building Secure and Reliable Systems
#96Any tips for the vast majority of SRE groups where people are paid a fraction of google employees and never given any time to fix things?
If your leadership declines to take you up on this, escalate. If that fails, you must choose between continuing to do the repetitive operational work as instructed or leaving.
Re: New Google SRE book: Building Secure and Reliable Systems
#97Earlier quoted context omitted.
It is quite obvious from how many CVE entries you can find for each one.
That doesn't obviously follow. CVE entries are both a function of security and interest. My github projects don't have any CVEs, not because they aren't woefully insecure to anyone who bothers to investigate deeply, but because no one cares. "Android" is installed on more devices than any other OS in the world. So it stands to reason that there would be more interest in finding exploits in android than in OS's that a…
Re: New Google SRE book: Building Secure and Reliable Systems
#98Earlier quoted context omitted.
So no general purpose OS or browser then? It's also not obvious to me that clearpath is more secure than android, mostly because I can't actually find any information about what it is, there's only marketing jargon :/
It is quite obvious from how many CVE entries you can find for each one.
Re: New Google SRE book: Building Secure and Reliable Systems
#99Earlier quoted context omitted.
You seem much more interested in the authors than in the book.
Indeed I am. Would you trust the contents of a book on a technical topic if the authors are not, in fact, subject matter experts? Would you read a book on cancer treatment by a doctor of theology with no medical training? To use a less egregious example, a neurologist with no training in oncology or experience with brain cancer? Knowing the expertise of the authors is very important, especially if you are not a subje…
In other words, your question is misformed. The abilities of the list of 3 technical authors in this case isn't relevant, the question that matters is if you believe Google's security organization and apparatus is competent.
If you do, then the specific individuals who could or could not "game" experience is irrelevant, what matters is that the book was written and reviewed by multiple people who all generally agree on the guidance.
Re: New Google SRE book: Building Secure and Reliable Systems
#100Earlier quoted context omitted.
You seem much more interested in the authors than in the book.
Indeed I am. Would you trust the contents of a book on a technical topic if the authors are not, in fact, subject matter experts? Would you read a book on cancer treatment by a doctor of theology with no medical training? To use a less egregious example, a neurologist with no training in oncology or experience with brain cancer? Knowing the expertise of the authors is very important, especially if you are not a subje…