<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://halimer.com/feed.xml" rel="self" type="application/atom+xml" /><link href="https://halimer.com/" rel="alternate" type="text/html" /><updated>2026-08-26T12:24:22+00:00</updated><id>https://halimer.com/feed.xml</id><title type="html">Josh Hammer’s Blog</title><subtitle>From life to work and everything in between, these are my words and my thoughts.</subtitle><author><name>Josh Hammer</name></author><entry><title type="html">My Grandmother’s Eulogy</title><link href="https://halimer.com/my-grandmothers-eulogy/" rel="alternate" type="text/html" title="My Grandmother’s Eulogy" /><published>2024-09-02T01:23:53+00:00</published><updated>2024-09-02T01:23:53+00:00</updated><id>https://halimer.com/my-grandmothers-eulogy</id><content type="html" xml:base="https://halimer.com/my-grandmothers-eulogy/"><![CDATA[<p>Here is my first life post, though sadly, it is discussing the passing of my Grandmother. June 14th, 2024, was my Grandmother’s funeral. While I have also spoken at my grandfather’s funeral, this one felt different; maybe it was because she was my last grand relative or perhaps because I had spent so much time with her over my life. To honor and remember, I wanted to post my eulogy from her funeral so I could always return and remember. Whenever I read it, I am reminded of her, what a fantastic woman, nurse, mother, grandmother, sister, and friend she was, and how big her love for her family is.</p>

<p>Below is the eulogy I wrote and mostly said:</p>

<p>Emily was born in Poland and is part of the greatest generation. At 12, she came to the US via ship and arrived at the port of Newark.</p>

<p>Even though she should have been in the 7th Grade, she was placed in the 4th. She excelled in school. As she learned English when she was here, she was an excellent speller, the chagrin of her classmates. She attended NJ State Teacher’s College and was the first in her family to graduate college.</p>

<p>Emily Achieved a BS in health education and an RN in 1945. She answered her nation’s call and was a member of the US Corps of Nursing (sort of an ROTC program). WWII ended before she graduated in August 1945. She would have been commissioned as an Army 2LT in the Army Nurse Corps.</p>

<p>After the war, she married Moe in 1947, and if you ever see the pictures, you can see how beautiful she was on the outside. She and her sister Bea, who passed, had sibling rivalry over their appearance, though I think Emily was prettier.</p>

<p>She worked as a nurse at Beth Israel Hospital while living in Marine Park, both in Brooklyn. Eventually, they moved to their home in Windsor Park, which is where so many family events were held, both before grandmother status and after, once again, biased to the latter half.</p>

<p>This is where she had her precious poodle, Brandy, who I heard was really smart from Ellen. It also cost Emily extra money because she needed to double park by Brandy’s salon. She hosted mahjong games with her friends and continued playing even in the digital age.</p>

<p>My memories of Emily are of her love of family. Whether parading me around at the beauty parlor on the weekends as a kid - I think my parents appreciated it as much as I did - or coming to take care of me when I was home sick from school to fun road trips up to CT to visit Ellen Gary, Erica, and Jon.</p>

<p>In addition to love, there was food, which may be the same thing. While she kept a kosher home, she did not have a kosher stomach. When we went out to breakfast, she would get two eggs, bacon, and sometimes sausage. She would also bring bacon, egg, and cheese when she babysat when I was homesick. And yes, she would share.</p>

<p>In her retirement, she traveled the US and overseas, visiting her children and grandchildren. She also played a lot of slots in AC and shared her winnings with her grandchildren. I remember always saying she was squandering our inheritance.</p>

<p>As she got older and found it more challenging to go up three flights, she moved to Manlius. She was closer to Ellen, Gary, Erica, and Jon. I know that they enjoyed the convenience of having their grandmother close by. Grandma also made new friends in Manlius, a wonderful woman named Pearl, with whom Erica hit the nail on the head, saying they were like the golden girls.</p>

<p>Emily lived just shy of a century, and even as she aged, her heart kept growing. She welcomed all new members to our family: my wife, Jon’s wife, and Erica’s husband.</p>

<p>GM was never able to spend away her inheritance, no matter how much she joked about it, because her inheritance to us is her love of all of us, and we will have that forever.</p>

<p><img src="/assets/images/2024/09/Emily-scaled.jpg" alt="Emily" /></p>

<p><img src="/assets/images/2024/09/Emily1-scaled.jpeg" alt="Emily and family" /></p>

<p><img src="/assets/images/2024/09/Emily2-scaled.jpeg" alt="Emily and family" /></p>

<p><img src="/assets/images/2024/09/IMG_2765-scaled.jpeg" alt="Family photo" /></p>]]></content><author><name>Josh Hammer</name></author><category term="Life" /><category term="family" /><category term="Life" /><summary type="html"><![CDATA[Here is my first life post, though sadly, it is discussing the passing of my Grandmother. June 14th, 2024, was my Grandmother’s funeral. While I have also spoken at my grandfather’s funeral, this one felt different; maybe it was because she was my last grand relative or perhaps because I had spent so much time with her over my life. To honor and remember, I wanted to post my eulogy from her funeral so I could always return and remember. Whenever I read it, I am reminded of her, what a fantastic woman, nurse, mother, grandmother, sister, and friend she was, and how big her love for her family is.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://halimer.com/assets/images/2024/09/Emily-scaled.jpg" /><media:content medium="image" url="https://halimer.com/assets/images/2024/09/Emily-scaled.jpg" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Are leaked credentials really developers’ fault?</title><link href="https://halimer.com/are-leaked-credentials-really-developers-fault/" rel="alternate" type="text/html" title="Are leaked credentials really developers’ fault?" /><published>2024-04-21T20:00:03+00:00</published><updated>2024-04-21T20:00:03+00:00</updated><id>https://halimer.com/are-leaked-credentials-really-developers-fault</id><content type="html" xml:base="https://halimer.com/are-leaked-credentials-really-developers-fault/"><![CDATA[<p>In <a href="https://arstechnica.com/security/2023/11/developers-cant-seem-to-stop-exposing-credentials-in-publicly-accessible-code/">Developers can’t seem to stop exposing credentials in publicly accessible code</a>, the author talks about how credentials continue to be leaked in source code and alludes to developers as the cause. I don’t think that is the intent of the author, but for those who are not developers I hope to clarify so you don’t get misled. Developers are people and people are fallible, but the problem is more complicated.</p>

<p>Developers start writing code in one of two high-level ways. First is the blank canvas, where a developer creates an empty code repository with a blank file. The other is using an existing project to add to it or fix it. In this case a developer will clone an existing repository. The common tool that developers use for code management and storage is Git. It tracks changes in source code, much like track changes in a word document plus versioned cloud storage.</p>

<p>Whether you start with a blank canvas or clone a repository you will have an ignore file. This file, <code class="language-plaintext highlighter-rouge">.gitignore</code>, tells Git which files to ignore. To help developers get started many Git services like GitHub and Bitbucket provide ignore-file templates based on the programming language you use. However, those tools only allow you to select one programming language for your ignore file, so if you are using more than one language you will have to add to it accordingly. While this is useful for ignoring superfluous files, because most programming languages do not have a standard for credential files it still falls on the developer to determine where to store credentials and how to ignore them.</p>

<p>So now we see the main problem developers face: they have to be careful not to accidentally include or save files with credentials, and there are no standards in most languages. However, the question we should be asking is why developers do not have standards or still have to store credentials at all. In my view the reason goes back to the fact we in the security space have not innovated in IAM, specifically authentication. We started with username and password and honestly have not moved much further past that. Due to that we still leave the burden of managing usernames and passwords to the user, and developers are users too.</p>

<p>I hope we in the security space can truly help to innovate on authentication the same way we have done with firewalls and antivirus. Passkey technology is a step in the right direction, though I do not know if it will be enough or if it will help developers manage server-to-server authentication, which is the problem I have been speaking about.</p>]]></content><author><name>Josh Hammer</name></author><category term="Uncategorized" /><category term="authentication" /><category term="cloudsecurity" /><category term="cybersecurity" /><category term="IAM" /><category term="security" /><summary type="html"><![CDATA[In Developers can’t seem to stop exposing credentials in publicly accessible code, the author talks about how credentials continue to be leaked in source code and alludes to developers as the cause. I don’t think that is the intent of the author, but for those who are not developers I hope to clarify so you don’t get misled. Developers are people and people are fallible, but the problem is more complicated.]]></summary></entry><entry><title type="html">Security v. Compliance</title><link href="https://halimer.com/security-v-compliance/" rel="alternate" type="text/html" title="Security v. Compliance" /><published>2024-04-20T21:43:31+00:00</published><updated>2024-04-20T21:43:31+00:00</updated><id>https://halimer.com/security-v-compliance</id><content type="html" xml:base="https://halimer.com/security-v-compliance/"><![CDATA[<p>Throughout my career I have seen compliance lumped in with security and it makes me cringe. Security and compliance can complement one another but compliance does not make you secure and security doesn’t make you compliant. Let’s explain the difference with an example.</p>

<p>If you travel on an airplane in the United States and want to put a lock on your luggage it has to be TSA (Travel Security Administration) approved. This approval ensures that the lock can be opened by a universal “master” key thus allowing TSA agents to open and re-lock the lock. So you’re probably thinking that is not too bad, it is only TSA agents. However, a while ago pictures of the “master” keys were leaked and shortly after people with 3D printers could also open your luggage. Here is a GitHub repository with those images: <a href="https://github.com/Xyl2k/TSA-Travel-Sentry-master-keys">https://github.com/Xyl2k/TSA-Travel-Sentry-master-keys</a>.</p>

<p><img src="/assets/images/2024/04/eaa8f8a0-5703-11e5-9c47-d89b8d40b115.jpg" alt="TSA master keys" /></p>

<p>So, a compliant TSA lock doesn’t really keep your luggage secure. So compliance doesn’t necessarily make you secure.</p>]]></content><author><name>Josh Hammer</name></author><category term="Uncategorized" /><category term="compliance" /><category term="security" /><summary type="html"><![CDATA[Throughout my career I have seen compliance lumped in with security and it makes me cringe. Security and compliance can complement one another but compliance does not make you secure and security doesn’t make you compliant. Let’s explain the difference with an example.]]></summary></entry></feed>