Cyber Mixology

Cyber Mixology, my personal blog about Cyber Security, Leadership, Mixology, and more. I’m Steve Edwards (call me sedward5), a husband, father, n00b, and the Director of Detection and Response Engineering at Expel. Previously I worked at Attentive Mobile, Cisco Secure, Duo Security, and Eastern Michigan University. I blog from time to time and use this site as a reference for myself.

What I’m mixing up

See posts across all of the interests of my the Chief Cyber Mixologist. Typically I like to post about my thoughts and experiences as a neurodivergent people leader working in cyber security. I also enjoy making craft cocktails, I post recipes of my own as well is some classics that I like to make for myself. Take a look in the header for topics in a specific category or take a look below at my most recent posts.


Reviewing US Banks’ Web and Email Security

I have had an account with the same bank for a really long time. Perhaps the time has come to switch to a new bank. After all in 2016 my bank still doesn’t offer two factor authentication, EMV cards, and several other modern features that I see…

Read More

Raise your MASSACRE Score with HAProxy

Recently, Mark Stanislav gave a talk on holistic authentication security for companies who have implemented two-factor authentication. He developed a scoring system, MASSACRE, which quantifies the presence of several different security features on a web site; cookie flags, response headers, etc.. This inspired me to see if I could…

Read More

HTTP Security Headers in Apache

HTTP offers several headers that can help protect website visitors. OWASP has a great description of them here. Based on that I’d like to quickly share a few configuration changes I make to Apache web servers. In the httpd.conf I add the following directives to the document…

Read More

Using HAProxy with CAS

We recently had trouble replacing an older CAS server with a new system. The new server would not forward to the requested service after authenticating and the service could not verify the service ticket. We decided to use HAProxy with CAS for the front-end so we could…

Read More

Tomcat SSL Tips

With POODLE being in the news recently, I decided it would be a good idea to look at my overall SSL configuration while closing the door to this issue. What better way to do that than by arbitrarily assigning a letter grade to my servers with the…

Read More

ePHI Storage Compliance

Digital storage of electronic protected health information is a treacherous path for a small company to walk. The health insurance portability and accountability act enforces a number of requirements on the security controls required for the storage of such sensitive data. Unfortunately, the language used in not…

Read More
1 2 3 4 6 7 8 9 10

If you like my content or have any questions or feedback feel free to connect with me on social media or leave a comment on a post. Thanks for reading and subscribing.