Yet Another Nifty Gadget

Work from home has come a long way. While office spaces facilitated many technologies and tools which we haven’t really given much thought about, working from home makes you realize the value of some of the gadgets we used every day to communicate.

A typical office would’ve had a conference phone (those triangle shaped ones) that have a multi-microphone configuration and quality amplified audio output, allowing a group on people in a meeting room to comfortably communicate with a remote party, and have a clear audio conversation.

Some offices may take this a step further and have a video conferencing configuration that also relays visual data from the conference room and vice versa, paired with a quality audio configuration… fancy stuff, however in most cases underutilized.

While most modern laptops have quality audio features, if you are like me with a multi-monitor configuration in your home office, you probably don’t want to disconnect your laptop and take it with you to the kitchen to refill your water bottle, only so you don’t miss out on key ongoing conversations.

well, you may also use your ear-pods to get some freedom of motion, however you may encounter audio quality issues the further you go from your laptop, as ear-pod Bluetooth reception has limited range capabilities.

This is were devices like the Anker PowerConf S3 portable conference speaker come in play.

As I researched for the most suitable conferencing gadget that suits my needs, this was the best fitting! A very portable device, with a respectable battery life, long range Bluetooth, multi-microphone configuration (with directional sense illustrated by lights which is pretty cool), double-talk support, and a very clear and loud speakerphone, to have the freedom of motion, yet crystal clear conference calls.

The Anker PowerConf S3 is also capable of pairing with more than one device at a time (i.e. with your laptop and your smart phone), and, if desired, can be connected via USB instead of Bluetooth. There are many other models made by Anker with varying features and price tags, available on Anker’s Products page.

I’ve been using this device for my daily casual work and personal calls, and it has been a great experience, with an impressive signal strength, covering end to end of the house, paired with an enjoyable audio quality.

Highly recommended, and I’m sure the higher spec’d models are even better!

Back up and running in Cloud Native

Finally had the time to rebuild and refresh the blog site. gotsudo.com in now full Cloud Native running in AWS (has always been, however in a more traditional server-based installation).

The recent migration included an AWS Lightsail service that provides various bundles of OS/applications, which in my case is WordPress running on Linux. Various tiers are also available to fit every budget out there.

I decided to take things a step further, and serve the public facing version of the website in a static configuration, leveraging AWS S3 to host the site files, with AWS CloudFront caching layer sitting upfront for the parent gotsudo.com address.

This allows me to limit access to the actual WordPress site running in Lightsail, transforming it to a true authoring and publishing site, rather than a public front-facing one.

Various WordPress plugins are available that can easily produce a static version of the website, and can also integrate with AWS services (or any other CSP) to auto publish files into S3 or any other repository of choice. While these make things much easier and more integrated, I decided to air-gap the systems, allowing me to selectively produce the published files and upload them to S3 using other means of tailored automation.

Later on, I may add some more integrations to the site, however at this point I’m quite happy with how far it came over a busy weekend’s time.

Tech Audits

What systems do security and availability audits cover? A fair question!

Well, the hard truth is that it is your responsibility to identify this as a system owner; and not the duty of an auditor. Don’t sit around waiting for auditors to show up and expect them to answer this question.

Simply put, everything and anything within your ecosystem that may interrupt business continuity should be part of the audit. This can easily include systems that do not even reside in your ‘PROD VPC’, or even be tagged as ‘Production’.

You’ll be surprised how many times it comes down to a small neglected server that sits in the corner and very few folk know about, yet holds a critical role in your supply chain processing, or mailing important notifications and updates to clients.

Do a true/practical risk assessment, identify your systems, minimize your exceptions, properly document your findings, and present them as the lay of the land; your auditors will be very thankful.

Hold my beer!

Company: “Our data is encrypted at rest, and in transit. We are SOC2 assessed and HIPAA compliant. Our Cyber team conducts quarterly audits, our Security Ops are 24/7, and our employees go through quarterly security training.”

That one developer about to run a wild query exporting all data to a CSV file: “Hold my beer!”

Invest in Data Access Controls