Joe Tiedeman

Joe Tiedeman

Technology and Security

  • Home
    • About
    • GitHub
    • LinkedIn
    • X
  • Snyk is shutting down the securityheaders.com API

    Snyk is shutting down the securityheaders.com API

    For many in the web security community, securityheaders.com has been a familiar and trusted tool for years. Originally created by Scott Helme, it helped raise the baseline for HTTP security headers across the web, not through flashy reports, but by making the right things visible and measurable. Over time, the project evolved: In April 2025,…

    Joe Tiedeman

    2026-01-22
    Cybaa, security
    security, technology, cybersecurity
  • Zone Files: The Only Authoritative Source and Why They’re Still Hard

    Zone Files: The Only Authoritative Source and Why They’re Still Hard

    When people talk about “total domain coverage”, they’re often talking past one another. Some mean registration. Some mean DNS resolution. Some mean recent activity. These are related, but they are not the same thing. A zone file is the registry’s authoritative publication. It shows which domains are delegated in DNS under a top-level domain (TLD)…

    Joe Tiedeman

    2026-01-02
    DNS
    cybersecurity, technology
  • Why You Should Enable Apple’s Stolen Device Protection Today

    Why You Should Enable Apple’s Stolen Device Protection Today

    Smartphones have become far more than communication devices – they’re the keys to our digital lives. Banking apps, email, photos, passwords, health data, even the ability to unlock your front door or car – all of it may be accessible through your iPhone. That makes losing it to theft or opportunistic “shoulder surfing” more dangerous…

    Joe Tiedeman

    2025-10-03
    security
    Apple, cybersecurity, iphone, security, technology
  • Why Domain Monitoring is Essential for Microsoft Entra Security

    Why Domain Monitoring is Essential for Microsoft Entra Security

    When we think about protecting Microsoft Entra tenants, the conversation often revolves around user identities, conditional access, and multi-factor authentication. Those are all critical – but one piece is often overlooked: verified domains. These domains are the foundation of your organisation’s identity. They determine how email flows, which services are trusted, and ultimately, how people…

    Joe Tiedeman

    2025-09-08
    Cybaa
    azure, Cybaa, cybersecurity, Email, Microsoft, security, technology
  • Don’t let your domains dangle in Microsoft 365

    Don’t let your domains dangle in Microsoft 365

    Expired Domains in Microsoft 365: A Hidden Backdoor to Your Tenant Microsoft 365 tenants typically use custom verified domains (like cybaa.io) for user identities and email addresses. Over time, domains may be retired, perhaps after a rebrand, acquisition, or project sunset, and their registrations allowed to expire. If such expired domains remain listed as verified in…

    Joe Tiedeman

    2025-06-07
    Uncategorized
    azure, cloud, cybersecurity, entra, Microsoft, security
  • Should banks use push notifications for all transactions?

    Recently I received notifications from Starling for card transactions totalling £450 that were not made by me (annoyingly they didn’t go through 3-D Secure for some reason, so for all intents and purposes were successful and £450 had been stolen from me. Fortunately multiple subsequent transactions to the same merchant, Taptap Send which appears to…

    Joe Tiedeman

    2025-01-24
    Uncategorized
  • Don’t install a VPN to get around the TikTok ban!

    Even though it sounds as if Trump might be temporarily lifting the ban on TikTok as one of his first acts when he returns to office, there are a lot of people saying that in order to regain access they need to use a VPN. I have no doubt that this will lead to shady…

    Joe Tiedeman

    2025-01-19
    Uncategorized
    china, news, social-media, technology, tiktok
  • mx.microsoft is coming!

    Microsoft is gearing up for a significant shift in its email security infrastructure, replacing the familiar “mail.protection.outlook.com” with a new set of subdomains under mx.microsoft. This exciting move, starting in March 2024, brings with it a powerful security duo: SMTP DANE and DNSSEC. But before you dive into technical details, let’s unpack what this means…

    Joe Tiedeman

    2024-02-23
    Uncategorized
    Email, Microsoft, MX, Office 365, security
  • Azure Spot Instances or how to scale cheaply

    TL;DR I was looking for an inexpensive way to get access to a lot of CPU compute, as inexpensively as I could in order to process a load of data for an upcoming research project, knowing that the compute would be needed for an extended period of time (weeks/months rather than hours/days) and being budget…

    Joe Tiedeman

    2023-11-18
    azure, infrastructure as a service
    azure, Cost, iaas

Create a website or blog at WordPress.com

  • Subscribe Subscribed
    • Joe Tiedeman
    • Already have a WordPress.com account? Log in now.
    • Joe Tiedeman
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar