<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>RivasSec | DevSecOps, Kubernetes, AWS IAM</title><link>https://rivassec.com/</link><description>Infrastructure. Security. Insight.</description><atom:link href="https://rivassec.com/feeds/all.rss.xml" rel="self"/><lastBuildDate>Sat, 15 Aug 2026 00:00:00 -0700</lastBuildDate><item><title>The DevSecOps Guide: Hardening, IAM, and Incident Response</title><link>https://rivassec.com/devsecops-guide.html</link><description>&lt;p&gt;A hub for the DevSecOps writing on rivassec.com: IAM blast radius, TLS, incident response, and controls that hold up in production.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Sat, 15 Aug 2026 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2026-08-15:/devsecops-guide.html</guid><category>DevSecOps</category><category>devsecops</category><category>security</category><category>iam</category><category>kubernetes</category><category>incident-response</category><category>tls</category></item><item><title>When the Output Carries the Signal: Claude, SynthID-Text, and the New Detection Attack Surface</title><link>https://rivassec.com/claude-synthid-text-watermark-attack-surface.html</link><description>&lt;p&gt;Claude's planned text watermark is embedded through token selection rather than hidden characters. Once enterprises automate on its detector, that provenance feature becomes a security control plane with spoofing, evasion, oracle, key-management, supply-chain, and policy-abuse requirements.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Fri, 14 Aug 2026 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2026-08-14:/claude-synthid-text-watermark-attack-surface.html</guid><category>Artificial Intelligence</category><category>AI Security</category><category>Anthropic</category><category>Claude</category><category>SynthID</category><category>Watermarking</category><category>EU AI Act</category><category>Adversarial ML</category></item><item><title>IAM Blast Radius Is an Architecture Problem, Not a Policy Problem</title><link>https://rivassec.com/iam-blast-radius-architecture-problem.html</link><description>&lt;p&gt;Most IAM reviews start too late, after the account structure and trust boundaries are set. Least privilege isn't fewer actions; it's smaller failure domains.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Tue, 21 Jul 2026 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2026-07-21:/iam-blast-radius-architecture-problem.html</guid><category>DevSecOps</category><category>aws</category><category>iam</category><category>devsecops</category><category>cloud-security</category><category>threat-modeling</category></item><item><title>The Discovery Layer Is Broken: Hiring as an Observability Problem</title><link>https://rivassec.com/hiring-discovery-layer-broken.html</link><description>&lt;p&gt;The senior engineering market has a routing failure, not a talent shortage: resumes and funnels index for keywords and discard the signal seniors depend on.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Sat, 11 Jul 2026 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2026-07-11:/hiring-discovery-layer-broken.html</guid><category>DevSecOps</category><category>careers</category><category>devsecops</category><category>hiring</category></item><item><title>Prompt Injection Will Become a Supply Chain Evasion Technique</title><link>https://rivassec.com/prompt-injection-supply-chain-evasion.html</link><description>&lt;p&gt;Prompt injection's threat model is older than the term. The mechanism is new, the objective is the evasion goal attackers have pursued for decades.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Fri, 12 Jun 2026 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2026-06-12:/prompt-injection-supply-chain-evasion.html</guid><category>Threat Intelligence</category><category>ai</category><category>supply-chain</category><category>prompt-injection</category><category>evasion</category><category>defensive-architecture</category></item><item><title>Bandit-Clean Pwnagotchi Plugins: How `subprocess` Goes From Risk to Routine</title><link>https://rivassec.com/pwnagotchi-plugin-bandit-hardening.html</link><description>&lt;p&gt;Hardening a Pwnagotchi plugin against Bandit B602/B603/B607: shutil.which() full paths, argv-list calls, input validation, and the nosec discipline.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Wed, 10 Jun 2026 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2026-06-10:/pwnagotchi-plugin-bandit-hardening.html</guid><category>DevSecOps</category><category>pwnagotchi</category><category>python</category><category>bandit</category><category>subprocess</category><category>security</category><category>supply-chain</category><category>hardening</category></item><item><title>TLS Has Three Jobs. Forget the Rest.</title><link>https://rivassec.com/tls-three-jobs.html</link><description>&lt;p&gt;TLS gets easier when you stop walking the handshake and name what it's for. It does three jobs; anchor those and it becomes design, not memorization.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Thu, 04 Jun 2026 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2026-06-04:/tls-three-jobs.html</guid><category>DevSecOps</category><category>tls</category><category>cryptography</category><category>security</category><category>infrastructure</category><category>pki</category><category>mtls</category><category>operations</category></item><item><title>Adoption Is a Security Control: Notes from Paving a Road</title><link>https://rivassec.com/paved-road-adoption-as-control.html</link><description>&lt;p&gt;A control developers route around isn't a control. Field notes on making the secure path the easy path: 40% less remediation time, 27% less pipeline latency.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Thu, 21 May 2026 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2026-05-21:/paved-road-adoption-as-control.html</guid><category>DevSecOps</category><category>devsecops</category><category>platform-security</category><category>paved-road</category><category>pulumi</category><category>ci-cd</category><category>cloud-security</category></item><item><title>The Teensy That Failed in Public: An EFI Brute Force, Hours Late</title><link>https://rivassec.com/teensy-efi-bruteforce-hours-late.html</link><description>&lt;p&gt;In 2013 Hackaday called my MacBook EFI brute force a failure; hours later it worked. Three rate-limiting defenses, each leaking at a different seam.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Thu, 21 May 2026 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2026-05-21:/teensy-efi-bruteforce-hours-late.html</guid><category>Projects</category><category>hardware</category><category>mac</category><category>efi</category><category>teensy</category><category>security-research</category><category>hackaday</category><category>hacker-news</category><category>open-source</category></item><item><title>IAM Roles That Fail Loud: Small Defaults, Big Difference</title><link>https://rivassec.com/iam-safe-defaults-fail-loud.html</link><description>&lt;p&gt;A small Pulumi library that treats IAM safety as a precondition: mandatory permissions boundary, no wildcard trust, no wildcard actions, every opt-out explicit.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Tue, 12 May 2026 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2026-05-12:/iam-safe-defaults-fail-loud.html</guid><category>DevSecOps</category><category>aws</category><category>iam</category><category>pulumi</category><category>python</category><category>devsecops</category></item><item><title>The Trust Decay: Why Modern Hiring Has Become an Adversarial System</title><link>https://rivassec.com/trust-decay-adversarial-hiring.html</link><description>&lt;p&gt;The tech hiring pipeline has shifted from talent discovery to risk mitigation. In 2026, the engineers who get hired are the ones who are hardest to doubt.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Mon, 04 May 2026 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2026-05-04:/trust-decay-adversarial-hiring.html</guid><category>DevSecOps</category><category>careers</category><category>devsecops</category></item><item><title>Never Lose Connection: Multi-Phone Bluetooth Tethering for Pwnagotchi</title><link>https://rivassec.com/pwnagotchi-bluetooth-tethering.html</link><description>&lt;p&gt;bt-tether-multi is a Pwnagotchi plugin for intelligent multi-phone Bluetooth tethering with automatic WAN failover and silent-disconnect recovery in the field.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Tue, 22 Jul 2025 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2025-07-22:/pwnagotchi-bluetooth-tethering.html</guid><category>Projects</category><category>pwnagotchi</category><category>bluetooth</category><category>networking</category><category>python</category></item><item><title>Elasticsearch Snapshot Verification, Minimal Privileges</title><link>https://rivassec.com/elasticsearch-secure-snapshot-verification.html</link><description>&lt;p&gt;Verify Elasticsearch snapshots without manage_snapshot: minimal API key, Prometheus-friendly script, and a public tools repo for hardened monitoring automation.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Sun, 20 Apr 2025 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2025-04-20:/elasticsearch-secure-snapshot-verification.html</guid><category>DevSecOps</category><category>elasticsearch</category><category>prometheus</category><category>observability</category><category>iam</category></item><item><title>Hardening Kubernetes Deployments</title><link>https://rivassec.com/hardening-k8s.html</link><description>&lt;p&gt;Pod-level Kubernetes guardrails aligned with the Pod Security Standards Restricted profile: non-root, no caps, read-only FS, NetworkPolicies, SA hardening.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Sat, 19 Apr 2025 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2025-04-19:/hardening-k8s.html</guid><category>Kubernetes Security</category><category>kubernetes</category><category>hardening</category><category>devsecops</category></item><item><title>Taming the OOM Killer: Process Priorities on Linux</title><link>https://rivassec.com/oom-killer-process-prioritization.html</link><description>&lt;p&gt;The Linux OOM Killer decides what dies under memory pressure. Protect sshd, mysqld, and other critical processes with oom_score_adj via a small script.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Fri, 18 Apr 2025 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2025-04-18:/oom-killer-process-prioritization.html</guid><category>DevSecOps</category><category>linux</category><category>oom-killer</category><category>sysadmin</category><category>hardening</category><category>devsecops</category></item><item><title>Catching a Nation-State Proxy: OSINT on Twitter</title><link>https://rivassec.com/venezuela-twitter-proxy-osint.html</link><description>&lt;p&gt;In 2012 I traced a state-aligned Twitter proxy tied to Venezuela's ruling party. OSINT lessons for spotting subtle, credential-phishing nation-state infra.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Thu, 17 Apr 2025 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2025-04-17:/venezuela-twitter-proxy-osint.html</guid><category>Threat Intelligence</category><category>osint</category><category>threat-intelligence</category><category>phishing</category><category>devsecops</category></item><item><title>The 208.5-Day Kernel Bug: Uptime, Overflow, and Risk</title><link>https://rivassec.com/208-day-kernel-bug-lessons.html</link><description>&lt;p&gt;A 2012 Linux kernel bug caused CPU lockups after 208.5 days of uptime due to an integer overflow in sched_clock(). RHEL 5/6 lesson: patch and observe uptime.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Wed, 16 Apr 2025 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2025-04-16:/208-day-kernel-bug-lessons.html</guid><category>DevSecOps</category><category>kernel</category><category>linux</category><category>bug</category><category>devsecops</category></item><item><title>The 2012 Leap Second: When Time Broke Java and the Cloud</title><link>https://rivassec.com/leap-second-chaos-2012.html</link><description>&lt;p&gt;The 2012 leap second broke Reddit, Yelp, Java apps, and more. A retrospective on how fragile timekeeping bit the cloud, and what SRE teams should do today.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Oliver Rivas</dc:creator><pubDate>Tue, 15 Apr 2025 00:00:00 -0700</pubDate><guid>tag:rivassec.com,2025-04-15:/leap-second-chaos-2012.html</guid><category>Incident Retrospectives</category><category>kernel</category><category>linux</category><category>java</category><category>ntp</category><category>sre</category></item></channel></rss>