from/prod
← All companies

THE COMPANY INDEX TRACKED BLOG

Latacora

Ideas, decisions, and lessons from the team.

latacora.singles (opens on the source site)LinkedIn X
25Posts tracked
3 weeks agoLatest publication
0.5Posts / month over the last 12 months

Latest writing

20 of 25 posts

Fire the slop cannons (safely): on coding agents and sandboxing (opens on the source site)

Last time, we covered AI risks inside and against your organization, and how to reduce them. In this post, we’ll touch on some specific risks and mitigations for using coding agents. Coding agents are a specific case of “AI in your organization,” so the guidance from the prior post still applies. But developers writing code with agents typically have more access to sensitive data and systems than other folks at your organization, and coding agents are often granted broad permissions to do things like “run arbitrary code,” so it’s worth going beyond the basics to control and restrict coding…

Read at the source

Slopportunity knocks: how AI impacts security practices for startups (opens on the source site)

Latacora has spent lots of time talking with startups about AI and how security practices need to evolve to keep up. It comes up in conversations with current and prospective clients, with people we meet at conferences, and occasionally, with random baristas who don’t even know we work in security. From what we can gather, AI is kind of a big deal right now. This is probably not news to you. If you’re reading Latacora’s blog, you’re probably (a) interested in security, (b) interested in startups, and (c) have heard plenty of hot takes about how AI is going to hack the planet, or whatever. So…

Read at the source

Stytch & Latacora: A Security Partnership Retrospective (opens on the source site)

From growing startup to Twilio integration # Stytch and Latacora worked side by side to ensure that the developers and end users relying on Stytch’s platform benefited from a security program built for the sensitivity and criticality of the data involved. This journey, which began in February 2021, saw Stytch grow from an ambitious startup building passwordless authentication infrastructure into a mature platform, ultimately acquired by Twilio.

Read at the source

Latacora Achieves AWS Advanced Tier Services Partner Status (opens on the source site)

We are thrilled to announce a major milestone for Latacora: we have achieved the Amazon Web Services (AWS) Advanced Tier Services Partner status within the AWS Partner Network (APN). This designation reflects Latacora’s technical expertise and diligence in delivering exceptional cloud security and compliance solutions to our clients, and confirms that we have successfully completed a rigorous validation process demonstrating a proven track record of customer success delivered by a team of AWS-certified professionals with specialized technical capabilities.

Read at the source

Writing MCP servers in Clojure with Ring and Malli (opens on the source site)

Introduction # Large language models, agents, and Model Context Protocol (MCP) are impossible to escape in today’s tech climate. At Latacora, we take a thoughtful and pragmatic approach towards new technologies like these. Are they going to solve all the world’s problems? No. Is it important that we understand them and be able to build software that integrates into emerging ecosystems? Yes! Internally we’ve built a MCP server to query our Datomic databases using natural language, but now we’re open sourcing the underlying Clojure library so others can easily build robust MCP servers for the…

Read at the source

OIDC workload identity on AWS (opens on the source site)

Update: after years of being on the wish list of a ton of top AWS teams, AWS released a built-in version of this feature about two weeks after we published this. Never let it be said gentle ribbing doesn’t work. Also, thanks AWS! We meant it when we said that the only thing better than having something easy to deploy was not needing to deploy anything at all. Everything in this post about workload identity is still relevant but you should probably use upstream’s implementation unless you have a good reason not to (for example, private validators for whom you need a VPC endpoint).

Read at the source

ECS on EC2: Covering Gaps in IMDS Hardening (opens on the source site)

Introduction # AWS ECS is a widely-adopted service across industries. To illustrate the scale and ubiquity of this service, over 2.4 billion Amazon Elastic Container Service tasks are launched every week (source) and over 65% of all new AWS containers customers use Amazon ECS (source). There are two primary launch types for ECS: Fargate and EC2. The choice between them depends on factors like cost, performance, operational overhead, and the variability of your workload.

Read at the source

Bit by bit: how Latacora helped Notion build security that scales (opens on the source site)

Security rarely tops the priority list for startups - but that doesn’t make it optional. Running a startup is no small feat. Facing enormous pressure to address a never-ending list of priorities (finding market fit, fundraising, launching new features, scaling infrastructure, etc.) security often becomes a “later” issue……until it can’t be. Even when companies know they need help, the breadth of the problem can be intimidating. Application security, cloud infrastructure, third-party vendors, compliance, cryptography: any resource-constrained startup will be hard-pressed to find a unicorn hire…

Read at the source

Privacy for the newly appointed (and already exasperated) DPO (opens on the source site)

Every other week, regulators around the world bombard their constituents with new data protection laws and acronyms. As the person who was just voluntold you’re now responsible for privacy at your startup, in addition to all your other duties and without any additional resources, how can you possibly be expected to keep up—let alone contextualize that information to maintain compliance? Privacy, at its core, is an ethical issue, which means the solution to your privacy challenges is deceptively simple: do the right thing and be transparent with your customers. That’s it. That’s what everyone…

Read at the source

Lessons in logging, part 2: mapping your path to a mature security program with logs and audit trails (opens on the source site)

This post is the second in a series about logging and audit trails from a security perspective. For the first post in the series, see Lessons in Logging: Chopping Down Security Risks Using Audit Trails If you’re looking to level up your security practices, logging is a good place to focus your attention. Just as logging is a core pillar of observability, comprehensive audit trails are a core pillar of a strong security program. Logs and audit trails are separate but overlapping concepts, and most companies can improve their security posture by investing in this area.

Read at the source

Datomic and Content Addressable Techniques: An Ultimate Data Wonderland (opens on the source site)

Latacora collects and analyzes data about services our clients use. You may have read about our approach to building security tooling, but the tl;dr is we make requests to all the (configuration metadata) read-only APIs available to us and store the results in S3. We leverage the data to understand our clients' infrastructure and identify security issues and misconfigurations. We retain the files (“snapshots”) to support future IR/forensics efforts. This approach has served us well, but the limited scope of a snapshot meant there was always a problem of first needing to figure out which files…

Read at the source

Latacora & Vanta - Howdy (Managed Service) Partner! (opens on the source site)

Exciting news! Latacora is teaming up with Vanta to supercharge your compliance game. We now combine Latacora’s security expertise with Vanta’s compliance platform to help you reach your compliance goals faster than ever. As a Vanta managed service provider (MSP), Latacora can help you tackle your compliance goals quickly and efficiently, freeing you to focus on growing your business and building trust with your customers. Here’s the scoop on why using Vanta through Latacora is a game-changer:

Read at the source

Cryptographic Right Answers: Post Quantum Edition (opens on the source site)

One of our favorite blog posts is our “crypto right answers” post. It’s intended to be an easy-to-use guide to help engineers pick the best cryptography choices without needing to go too far down a rabbit hole. With post-quantum cryptography (PQC) recently transitioning from an academic research topic to a more practical cryptography concern we figured it’s time for an update of our cryptography recommendations. One thing that makes recommending PQC challenging is that historically, we’ve been able to provide “better” answers for classical cryptography. Faster and bigger hashes, stronger…

Read at the source

Real World Crypto 2024 (opens on the source site)

We traveled to Toronto this year to attend RWC 2024. The conference was held in TIFF Lightbox located in the city’s downtown; the venue is the headquarters for the Toronto Film Festival and contains five cinema rooms. RWC is a single-tracked conference and there’s no hard requirement that talks are backed by papers. Each RWC includes the Levchin prize ceremony for major achievements in applied cryptography, several invited talks and the lightning talks session.

Read at the source

A case for password hashing with delegation (opens on the source site)

When people talk about PBKDFs (Password Based Key Derivation Functions), this is usually either in the context of secure password storage, or in the context of how to derive cryptographic keys from potentially low-entropy passwords. The Password Hashing Competition (PHC, 2013-2015) was an open competition to derive new password hashing algorithms, resulting in Argon2 hash as its winner. Apart from achieving general hash security, many of the candidates focused on achieving resistance to parallel attacks on available hardware such as GPUs.

Read at the source

Lessons in logging: chopping down security risks using audit trails (opens on the source site)

This post is the first in a series about logging and audit trails from a security perspective. For the next post in the series, see Lessons in Logging, Part 2: Mapping Your Path to a Mature Security Program with Logs and Audit Trails At Latacora, we bootstrap security practices. We partner with companies that frequently have minimally developed security programs, work with them to figure out the right security practices for their current size, and then help them evolve and scale those practices as their business matures.

Read at the source

Our Approach to Building Security Tooling (opens on the source site)

Introduction # Most “security tools” today are typically composed by code that consumes an API and applies predefined logic to identify issues. This is generally accomplished by: Fetching a subset of the endpoints exposed by the service / API being audited (that is, the information required for the evaluation logic, such as a list of the EC2 instances deployed in an AWS account, as well as their configuration) Storing the data retrieved Evaluating this data to produce “findings” (this is the added value provided by the tool) Integrating third party tools into our monitoring platform isn’t…

Read at the source

Frequently Asked Questions from Strange Loop 2023 (opens on the source site)

The last Strange Loop conference was held September 21-22, 2023 at St. Louis Union Station. The conference is targeted towards developers; the speakers are often sharing their knowledge on new and inventive ways to use technology. At our sponsor booth at Union Station, attendees asked two (okay, three) questions most often: What is Latacora? Your name is on the lanyards, and I’m curious to know what you do. Why sponsor Strange Loop? Can I take a plant? The first one isn’t hard for the folks from our team: Latacora is a consultancy that bootstraps security for startups. We have a team of…

Read at the source

Remediating AWS IMDSv1 (opens on the source site)

2024-12-17 Updated to include Declarative Policies Compute resources in AWS (for example, EC2 instances, ECS tasks/services, etc.) get access to AWS credentials, such as temporary instance role credentials, via the Instance Metadata Service (IMDS). The compute resources use these credentials to access other AWS services such as SQS, DynamoDB and Secrets Manager. Introduction: Problems with IMDSv1 # There was originally only one version of IMDS, now called “v1,” which unfortunately many people still use. The technical risks and high profile incidents (the Capital One breach comes to mind)…

Read at the source

The SOC2 starting seven (opens on the source site)

So, you plan to sell your startup’s product to big companies one day. Congratu-dolences! Really, that’s probably the only reason you should care about this article. If that’s not you, go forth and live your life! We’ll ask no more of your time. For the rest of you: Industry people talk about SOC2 a lot, and it’s taken on a quasi-mystical status, not least because it’s the product of the quasi-mystical accounting industry. But what it all boils down to is: eventually you’ll run into big-company clients demanding a SOC2 report to close a sale. You know this and worry about it.

Read at the source

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.