Walmart baked in house bread is close to the never molds variety. It uses modern GMO wheat with added preservatives and shortcut chemicals to reduce prep time from days to hours. Not to mention added sugars. Defending it would be like defending Subways "fresh baked bread" which isn't even legally allowed to be called bread in certain European countries. At one point they were caught putting the stuff in foam yoga mats in their bread.
In my opinion, that "bread" is a very distant cousin of homemade sourdough spelt (or whatever locally sourced whole grains was available) traditional known as bread.
Thanks! Glad it was helpful. I didnt have any similar realization until I had worked in the field for awhile amd honestly didnt have anyone to tell so i probably rambled. Good summary. Lean more into WAF, EDR and observability before a honeypot but yeah both are valid.
By no means am I the microservices guy. Im more of a self hosted person than anything and used to always be a monolith guy and would still prefer that in many situations. But now I would at least "wrap" the monolith with supplemental self hosted microservices.
But TLDR this is the logic as I understand it and the key thing. Dont cast your pearls before swine. Its basically biblical. Lol jk jk. But really put a cheap reverse proxy with a honey pot and some alerting... or even better a WAF and/or EDR then catch and isolate them when they compromise your front end and garbage honey pot before they can even move laterally internally.
The longer slightly more technical answer is a malicious actor compromises one utility they likely made a lot of noise doing it which is key to securing the assets. First a lot of malicious activity can be mitigated with a proactive WAF. There are a few free solutions here
Crowdsec WAF (ModSecurity, i think is another, working from memory could be wrong) has a decent signature detection and shared banned list. If you couple it with proper alerting you should be able to see, watch and isolate attackers in near real time. So even if they get the reverse Proxy and you messed up alerting on WAF, if you have layers of security, you still have your fall back EDR (like elk stack) alert for when proxyUser starts issuing ping commands and performing asset discovery. So you should see it days before they escalate privileges (unless 0 day or nation state etc).
They will still do damage you are absolutely right. But let's assume a tiered microservice approach for a functioning SAAS app where you have something like pocketbase for Auth, Umami for analytics, Stripe for payments and Postgres for paid api data. Even an issue in pocketbase / Auth doesn't necessarily mean they get all your paid api data because hopefully you have per user rate limits on postgres and backend services (should your pocketbase user even be reading or writing to your paid data tables? Additionally alerting should provide observability into admin sign ins from new /suspicious locations, or multiple other suspicious behavior such as one user signing into multiple accounts, seeking priv escalation and so on.) But the main thing, they don't get any cardholder data and that is a huge win. In fact if you are storing cardholder data PCI compliance requires segmentation.
Additionally look at actual CVEs related to pocketbase and you will find a lot to do with OATH so in this case its simple. Disable OATH for best security. Put a WAF in front of your app using something like traefik with crowdsec or ModSecurity with an nginx reverse proxy to catch bad actors when they try to abuse your non existent OATH endpoint and ban them instantly. You catch a lot of bad actors with that trap.
Or to take it back to your first example, if I have a segmented service that is compromised. I want to catch and isolate them before they even realize they are in a rootless podman container by taking advantages of the natural footguns that any script or malicious actor would naturally stumble into. For instance if my "reverseProxyUser" or any process in that entire container uses the sudo command that is a 10/10 fire type alert. That im pretty sure you could even automatically isolate or spin down with a few scripts, something like Argo or probably even off the shelf EDR.
Is it perfect, no. Any determined actor will find a way into any system given enough time. But a layered approach like this is best in my opinion. Of course it needs modified for every system this is just one example.
You can do the same thing with a monolith and good scripting. It isnt exclusive to microservices. Its just natively built that way in the instances that I am aware of thanks to the prominence of Kubernetes really. At least I think that's why.
Edit: i can't type / got interrupted mid reply. Its half decent now.
Separation of concerns is a major benefit that shouldn't be overlooked with security implications. Assuming you are properly restricting access to each worker node / "tier", when one tier inevitably becomes compromised; it doesn't result in the complete compromise of the entire monolith.
I'm to the far left of Bernie Sanders and I "bitched and moaned" about being denied a primary and you should too.
I dont see how this is equivalent at all to someone taking away my basic rights. Im not saying this isn't weird because it definitely is but it was the democrats who stood on my neck in these two situations.
30%. All true Muricans! know that checks worth more than $100,000 must be at least 4ft wide and can only delivered by the courier Publishers Clearing House.
Thanks for the recipe. It looks a bit like an einkorn rye sourdough I make on occasion. I still have a big bucket of rye berries in there so I think I mill some and try this out. It looks tasty.
I have no idea who this senator is but he isn't wrong. If your product ships with insecure defaults and isn't covered with giant red warnings everywhere then you are the asshole. If you happen to be a multi billion dollar company who has the resources to make it right but refuses to eve. after decades of the same shit then you don't deserve to be a company any longer.
At this point I think the city of Shiraz should make me an ambassador because of how hard I push Sharazi salad.
Every potluck im out there hustling Shirazi.
Even when its a bunch of racist old white folks. I let them try my "cucumber tomato" salad. Of course when they love it, I rug pull them and hit em with the "its Iranian!"
American here who learned the forbidden arts of fresh made whole grain sourdough. Ive never eaten store bought bread the same. It really is like a whole new food. First time I tried it I knew I had to learn to make it.
The Norwegians also have this crisp bread knekkebrod that every American i know think it tastes bland but I love them. I have considered life in Europe due to the fact they still have real bread readily available.
The only other things in this category for me are chinese fresh made hand pulled noodles (Biang Biang Mian is a good one) and garden ripened tomatoes. Sounds like a great excuse to do a tour of European China towns.
Walmart baked in house bread is close to the never molds variety. It uses modern GMO wheat with added preservatives and shortcut chemicals to reduce prep time from days to hours. Not to mention added sugars. Defending it would be like defending Subways "fresh baked bread" which isn't even legally allowed to be called bread in certain European countries. At one point they were caught putting the stuff in foam yoga mats in their bread.
In my opinion, that "bread" is a very distant cousin of homemade sourdough spelt (or whatever locally sourced whole grains was available) traditional known as bread.