Josiah Bruner's Avatar

Josiah Bruner

@josiahbruner.com.bsky.social

Security engineer at jellyfish.co. Co-founder of riskytrees.com. aka @JosiahBruner@ioc.exchange

33 Followers  |  157 Following  |  4 Posts  |  Joined: 07.02.2024  |  1.7457

Latest posts by josiahbruner.com on Bluesky

Preview
terraform-provider-aws-iam-validator/examples at main ยท JosiahOne/terraform-provider-aws-iam-validator Minimal terraform provider to validate AWS IAM policies - JosiahOne/terraform-provider-aws-iam-validator

It supports terraform functions and datasources. Examples here: github.com/JosiahOne/te...

06.09.2025 15:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Terraform Registry

I've gotten so sick of debugging slightly invalid IAM policies in terraform code that I decided to write a provider that lets you automatically validate policies at planning time using AWS IAM policy validation APIs.

If this sounds interesting, check out: registry.terraform.io/providers/Jo...

06.09.2025 15:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
When Security Engineering is Neither Security, nor Engineering โ€” RiskyTrees Welcome, dear reader, to the first โ€“ and perhaps last โ€“ opinion-style blog post I will ever write. This post is intended for folks who take an interest in the security industry (which Iโ€™ve now been i...

I decided to articulate some thoughts on where I think security engineering needs some maturing, after finally hitting a decade in the software industry: riskytrees.com/blog/when-security-engineering-is-neither-security-nor-engineering.

11.06.2025 20:46 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
We are deeply disappointed that the Court failed to require the strict First Amendment scrutiny required in a case like this, which wouldโ€™ve led to the inescapable conclusion that the government's desire to prevent potential future harm had to be rejected as infringing millions of Americansโ€™ constitutionally protected free speech. We are disappointed to see the Court sweep past the undisputed content-based justification for the law โ€“ to control what speech Americans see and share with each other โ€“ and rule only based on the shaky data privacy concerns.

The United Statesโ€™ foreign foes easily can steal, scrape, or buy Americansโ€™ data by countless other means. The ban or forced sale of one social media app will do virtually nothing to protect Americans' data privacy โ€“ only comprehensive consumer privacy legislation can achieve that goal. Shutting down communications platforms or forcing their reorganization based on concerns of foreign propaganda and anti-national manipulation is an eminently anti-democratic tactic, one that the US has previously condemned globally.

We are deeply disappointed that the Court failed to require the strict First Amendment scrutiny required in a case like this, which wouldโ€™ve led to the inescapable conclusion that the government's desire to prevent potential future harm had to be rejected as infringing millions of Americansโ€™ constitutionally protected free speech. We are disappointed to see the Court sweep past the undisputed content-based justification for the law โ€“ to control what speech Americans see and share with each other โ€“ and rule only based on the shaky data privacy concerns. The United Statesโ€™ foreign foes easily can steal, scrape, or buy Americansโ€™ data by countless other means. The ban or forced sale of one social media app will do virtually nothing to protect Americans' data privacy โ€“ only comprehensive consumer privacy legislation can achieve that goal. Shutting down communications platforms or forcing their reorganization based on concerns of foreign propaganda and anti-national manipulation is an eminently anti-democratic tactic, one that the US has previously condemned globally.

EFF Statement on U.S. Supreme Court's Decision to Uphold TikTok Ban:

17.01.2025 16:01 โ€” ๐Ÿ‘ 333    ๐Ÿ” 115    ๐Ÿ’ฌ 14    ๐Ÿ“Œ 11
Preview
โ€œAre you still eating that?โ€ (Access Control at Jellyfish) | Jellyfish Blog Our customerโ€™s security is paramount. Learn about Jellyfish's defences in our AWS environment and how we keep our customer data safe.

I had the privilege of working with Jellyfish's wonderful IT team to build a pretty slick approach for just-in-time, capability-based IAM access control scheme in AWS. If you're curious what that means or how it works, check out our blog post: jellyfish.co/blog/are-you...

16.03.2024 12:21 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@josiahbruner.com is following 20 prominent accounts