Fuel efficient routes.


The fuel-efficient routes debuted two years ago for users in the United States and are now available in Europe, Egypt, and Canada. Google promises to launch it in India and Indonesia by December 31. It will also support two-wheelers in these two countries, considering that many people in these regions use a motorcycle.

Google isn’t stopping here and says it’ll also provide users with alternative means of transportation when searching for directions. In other words, the company wants to make people use their cars less and stick with public transportation to reduce emissions.

The feature will debut in France, with Google Maps to display public transit and walking directions right next to driving routes when searching for driving directions to a destination. The alternative modes of transportation will only show up when “travel times are comparable and practical.”

For example, if traffic conditions for a driving route are so bad that it takes 15 minutes to arrive at the destination, but you could arrive at the address within a 20-minute walk, Google Maps would suggest leaving your car at home for the trip. Public transportation could also be faster, so users in France will see more suggestions in Google Maps. The feature will start rolling out “in the near future,” which can mean anything from later this year to some point in 2024.

Read more at.

https://www.autoevolution.com/news/good-news-for-google-maps-users-as-new-gen-features-now-available-for-more-222616.html

Should organizations be making MVP (Minimum Viable Product) or MVSP (Minimum Viable SECURE Product) ?


Summary

I always love when Agile Principles are integrated into Application Security. Recently, I came across the concept of MVSP (Minimum Viable Secure Product). Now, if you are in Agile Methodology of Software Development, you may very well know what is an MVP (Minimum Viable Product). The famous Picture of what we know as providing the client the minimum version of usable product, with time, so that he could experience it while the product is finalized into a more refined version of it.

So what’s an MVSP? (Minimum Viable Secure Product)

  • The MVSP lists down the absolute minimum security checks, or controls that must, at a minimum, be implemented to ensure a reasonable Secure Product
  • It is in the form of Checklist, so it’s implementation is quite easy. 
  • It has a broader scope, ranging from 
    • Secure Product Development
    • Secure HTTPS from the Start
    • Using Secure Libraries
    • Encryption
    • Logging
    • Employee Awareness
    • Production / DR, 
    • Vendor Management, 
    • Patch Management, 
    • Periodic VA / PT, and plethora of other  
  • It is simple, and targeted on STARTUPs, or those organizations, which aren’t focused on hiring the services of Security firm for their Security / SOC Services. It lists the basic checks to be performed, when making the product, when deploying the product, and when running the product in Production. 
  • Best of all, this MVSP is backed by Google, SalesForce, Okta, Slack, Vanta, and C2Sec

How can I read more about it ? 

Head over to https://mvsp.dev/

And see the checklist over at 

https://mvsp.dev/mvsp.en/index.html

The MSVP is derived from the checklists of Google’s Vendor Security Assessment Questionnaire (VSAQ) (https://github.com/google/vsaq) (https://vsaq-demo.withgoogle.com/ ) , and Dropbox’s Vendor Security Model Contract (VSMC) ( https://github.com/dropbox/vsmc ).

These checklists of Google is quite comprehensive, and organizations could use them when selecting a Software Vendor of their choice. The comments in Dropbox’s Vendor Security Contract also looks like they have been experiencing the ill behaviors from the industry.

If you wish to contribute to this project, you can raised your voices on https://github.com/vendorsec/mvsp/issues

What the Industry is already talking about: 

https://security.googleblog.com/2021/10/launching-collaborative-minimum.html

https://infosecforhumans.com/what-is-the-minimum-security-viable-product-mvsp-and-why-should-i-care/

https://www.securitymagazine.com/articles/97240-minimum-viable-secure-product-mvsp-a-vendor-neutral-security-baseline

https://www.darkreading.com/operations/how-infosec-should-use-the-minimum-viable-secure-product-checklist

https://www.scmagazine.com/news/zero-trust/google-tech-industry-proposes-minimum-viable-secure-product-baseline-for-b2b-software

Now back to original title, should Organizations be making MVP and / or MVSP?

I think, in Agile Software Industry, particularly in Pakistan, we have been burnt, we have been bitten by ignoring the security requirements to be baked into a product from the start. We have been involving Security professionals when product is launched in Soft mode, and we want to have a Penetration Test and / or Vulnerability Assessment of how our product is doing. That too happens in the end, when our product is in Soft Launch, and we are running everything on http mode.

It’s high time, that we should be thinking about making MVSP (Minimum Viable SECURE Product) from start. Security must be baked in to the Products, right from the start. Plus if we follow the checklist backed by Google / Dropbox, we would be adding in quite a Secure value in our Product Management roadmap from the start.

Let me know in comments, about what do you think about MVSP and it’s implementation.

Alternatively, if you would like to implement MVSP in your Product, give me a ping, and we’ll discuss.

Missed out on the Event on *Pakistani Universities and Online Education during Covid 19 Crisis? * You can always watch it offline at either Facebook or YouTube. Here are the links. *Facebook*. https://m.facebook.com/story.php?story_fbid=305966197092405&id=1487226818214322 *YouTube* https://youtu.be/sILgQRz5iko Also we present complete playlist of Agile Nights on YouTube. https://m.youtube.com/playlist?list=PLduru4yrOGuVKmzDhrUmOhIP1qgylF9-C Have a listen / watch to all the sessions, we have been doing since we all were home bound. #SalmanKhwaja


Missed out on the Event on *Pakistani Universities and Online Education during Covid 19 Crisis? *

You can always watch it offline at either Facebook or YouTube.

Here are the links.

Facebook.

https://ift.tt/2Nk6LeY

YouTube

Also we present complete playlist of Agile Nights on YouTube.

Have a listen / watch to all the sessions, we have been doing since we all were home bound. Via Salman, Khwaja Official
#SalmanKhwaja