Live data from Hacker News

New Google SRE book: Building Secure and Reliable Systems

landing.google.com

91–100 of 227 posts

Re: New Google SRE book: Building Secure and Reliable Systems

#91
post #67
post #58

Earlier quoted context omitted.

Download the epub version and on the Linux command-line execute `tar -zxvf srs-epub.epub` then cd into unpacked `OEBPS/` folder and there's your HTML files. Not exactly what you are looking for, but you can browse the content in a web browser.

That doesn't work, unless you have an unusual Linux setup: $ tar -zxvf srs-epub.epub gzip: stdin has more than one entry--rest ignored tar: Child returned status 2 tar: Error is not recoverable: exiting now But you can do "unzip srs-epub.epub".

[deleted]

Re: New Google SRE book: Building Secure and Reliable Systems

#92
post #57

I scanned the introduction, but failed to see any concrete information on the expertise of the authors on security. Can anybody speak to the expertise of the authors on security? In particular, I am interested in specific projects or initiatives they directed or lead. The state of systems before and after these projects. If there were any long-term regressions after their involvement. To be even more concrete if poss…

> Can anybody speak to the expertise of the authors on security? I think a cursory LinkedIn or social media search for any of the title authors or chapter authors will demonstrate their credentials. There were many people involved in this book, all of whom carry the necessary credentials and experience. > Personal questions for the responder: Guidelines help us scale, but at the end of the day, some services are uniq…

Generic credentials and experience provide very little information to me on their expertise. The CSO of JP Morgan, James Cummings, was highly experienced and credentialed when JP Morgan was breached in 2014 in one of the largest data breaches in history. The CSO of Equifax, Susan Mauldin, was highly experienced when Equifax was breached. The head of security for Windows at Microsoft is probably highly credentialed and experienced, but we all make fun of the insecurity of Windows. This is why I am interested in the specific projects they worked on and how they stack up. It is much harder to game the system if there is concrete, auditable evidence backing their expertise.

Yes, guidelines are not the end-all-be-all and you can never be sure, but when a civil engineer approves a bridge, they assert that they are confident that human lives can be trusted to the bridge (in certain configurations). They can do this with reasonable confidence because they have seen systems that have stood the test of time that prove out the techniques that they are applying. That is what I am interested in, do you/they have that level of confidence? What justifies that confidence? What systems prove out the techniques that were used? Did any techniques they invent stand the test of time (this provides evidence they can invent new techniques)?

Re: New Google SRE book: Building Secure and Reliable Systems

#94
post #86
post #70

Earlier quoted context omitted.

You seem much more interested in the authors than in the book.

Indeed I am. Would you trust the contents of a book on a technical topic if the authors are not, in fact, subject matter experts? Would you read a book on cancer treatment by a doctor of theology with no medical training? To use a less egregious example, a neurologist with no training in oncology or experience with brain cancer? Knowing the expertise of the authors is very important, especially if you are not a subje…

But why this unusual level of scrutiny? The book is published and endorsed by both Google and O'Reilly, two of the most respected brands in this domain. Why are they not a satisfactory "third or first-party confirmation of expertise" but random commenters on Hacker News would be?

Re: New Google SRE book: Building Secure and Reliable Systems

#95
post #93

What would be the equivalent trio of books for the SWE?

I know some of the content contributors for the book and some of my work is discussed it it’s text. I’m a SWE and a huge amount of the material in the book is directly relevant to development.

Re: New Google SRE book: Building Secure and Reliable Systems

#96
post #83

Any tips for the vast majority of SRE groups where people are paid a fraction of google employees and never given any time to fix things?

Tech debt is most easily measurable in repetitive operational work. Measure it. Bring a story to your leaders: "We are spending 60 hours per week doing repetitive task X. With 200 hours of work, we could eliminate this work. It would pay for itself in a month."

If your leadership declines to take you up on this, escalate. If that fails, you must choose between continuing to do the repetitive operational work as instructed or leaving.

Re: New Google SRE book: Building Secure and Reliable Systems

#97
post #84

Earlier quoted context omitted.

It is quite obvious from how many CVE entries you can find for each one.

That doesn't obviously follow. CVE entries are both a function of security and interest. My github projects don't have any CVEs, not because they aren't woefully insecure to anyone who bothers to investigate deeply, but because no one cares. "Android" is installed on more devices than any other OS in the world. So it stands to reason that there would be more interest in finding exploits in android than in OS's that a…

It is also very seldom updated, my dummy GitHub projects have more updates than many common Android brands, so whatever security Pixel devices sell, it is hardly a reflection of what most consumers outside North America get to use.

Re: New Google SRE book: Building Secure and Reliable Systems

#98
post #84

Earlier quoted context omitted.

So no general purpose OS or browser then? It's also not obvious to me that clearpath is more secure than android, mostly because I can't actually find any information about what it is, there's only marketing jargon :/

It is quite obvious from how many CVE entries you can find for each one.

That’s a frankly foolish way of measuring security. It doesn’t come in quatloos. CVEs aren’t inverse security points, especially if different systems have different communities or levels of scrutiny.

Re: New Google SRE book: Building Secure and Reliable Systems

#99
post #86
post #70

Earlier quoted context omitted.

You seem much more interested in the authors than in the book.

Indeed I am. Would you trust the contents of a book on a technical topic if the authors are not, in fact, subject matter experts? Would you read a book on cancer treatment by a doctor of theology with no medical training? To use a less egregious example, a neurologist with no training in oncology or experience with brain cancer? Knowing the expertise of the authors is very important, especially if you are not a subje…

Heather Adkins is the Director of Information Security at Google, and my understanding as an author she stands in for a much larger list of SMAs who are members of the security org.

In other words, your question is misformed. The abilities of the list of 3 technical authors in this case isn't relevant, the question that matters is if you believe Google's security organization and apparatus is competent.

If you do, then the specific individuals who could or could not "game" experience is irrelevant, what matters is that the book was written and reviewed by multiple people who all generally agree on the guidance.

Re: New Google SRE book: Building Secure and Reliable Systems

#100
post #86
post #70

Earlier quoted context omitted.

You seem much more interested in the authors than in the book.

Indeed I am. Would you trust the contents of a book on a technical topic if the authors are not, in fact, subject matter experts? Would you read a book on cancer treatment by a doctor of theology with no medical training? To use a less egregious example, a neurologist with no training in oncology or experience with brain cancer? Knowing the expertise of the authors is very important, especially if you are not a subje…

Are you involved in the security community? It isn’t like the names on the book are only known within Google.
Post reply on HN