collin

346 posts

collin

collin

@libber

Katılım Eylül 2007
528 Takip Edilen2K Takipçiler
collin
collin@libber·
@frgx Totally agree. Have you ever done a big program scale “go delete surface area” stuff? I’ve only done it adhoc typically as the result of a point audit or cluster of vulns
English
1
0
0
63
Devdatta Akhawe
Devdatta Akhawe@frgx·
@libber But, IMO, under appreciated in most places (I know not you; but a lot of written stuff misses this) is how "prevent" is the biggest leverage. Have _fewer_ dependenices; those you do, have very few with attack surface (e.g., move to a sandbox or don't let them listen on internet)
English
2
0
1
33
collin
collin@libber·
Golden opportunity to convert this vulnpocalypse hype into properly funding vuln mgmt (the least exciting, often most lacking part of a security program) This is our chance as an industry!
English
3
1
7
959
collin
collin@libber·
@frgx A flight with no internet + this pleasant nerdsnipe = this long answer: collingreene.com/vuln_mgmt.html I'm organizationally sheltered but in a big company the above is what I think ideal looks like
English
1
0
3
52
collin
collin@libber·
@mhlakhani True. This organization wall is just begging to have vulns chucked over it
English
0
0
0
102
Hasnain Lakhani
Hasnain Lakhani@mhlakhani·
@libber But see @libber that would require me to actually do work instead of complaining “those devs don’t fix my vulns” and where’s the fun in that?!
English
1
0
1
94
collin
collin@libber·
@tqbf + pass them on to your children
English
0
0
0
44
Zack Korman
Zack Korman@ZackKorman·
Here’s a thread about how I approached getting ISO27001 certified at Pistachio, written for people who hate these things as much as I do. As @IceSolst says, ACAB includes auditors.
English
13
15
101
14.5K
collin
collin@libber·
@intoverflow Extremely cool. I've long harbored a dream of a coffee table hacking tales book with the benefit of full knowledge + hindsight of 10 interesting breaches or events or something. If this project is that, I want to read it even more!
English
0
0
3
49
Tim Carstens Ⓥ✨ is hacking 🤖
Working on a new history project. A preview: In 1988, a Cornell grad student releases his secret project — a worm — and quickly realizes he fucked up So he asks his friend, US Olympic rower Andrew Sudduth, to anonymously send this note From: foo@bar To: TCP/IP mailing list
Tim Carstens Ⓥ✨ is hacking 🤖 tweet media
English
5
1
8
787
collin
collin@libber·
The differences between performing privacy and security work in a big company for my fellow computer security people. collingreene.com/security_and_p… I'm still newer to privacy work so this is my "most likely to be wrong" writeup, feedback welcome
English
0
0
5
302
Phil Venables
Phil Venables@philvenables·
Regulatory Harmonization - Let’s Get Real Most cybersecurity controls are already relatively aligned. The calls for action on harmonization are really problems induced by obligations from other technology risk domains or broader. In many cases, focusing on reducing compliance toil is the right approach. philvenables.com/post/regulator…
English
1
1
11
1.6K
collin
collin@libber·
@jeffvanderstoep Good writeup. Agree that vuln prevention > discovery > response. Curious about 1. How is "old" vs "new" code designated? 2. How is a specific vuln connected to only old or new code? Or am I misunderstanding 3. No counterfactual here right? ex to find/fix vulns in the old code
English
0
0
0
101
Jeff Vander Stoep
Jeff Vander Stoep@jeffvanderstoep·
I’m super excited about this blogpost. The approach is so counterintuitive, and yet the results are so much better than anything else that we’ve tried for memory safety. We finally understand why. security.googleblog.com/2024/09/elimin…
English
6
74
274
54.7K
collin
collin@libber·
@_noid_ I’ve perfected coffee for myself. Foamed fairlife milk + coconut milk + maple syrup x 3 shots expresso
English
1
0
1
135
Hot Fiendish Dr. Noid Summer
Alright folks, I'm having a shitty day. Tell me something good you've got going on in your world right now. Let me hear about your wins and hopefully that turns my day around.
English
16
2
21
3.3K
collin
collin@libber·
@dinodaizovi I like this so much. This fundamental uncomfortable truth then has weird side effects 1. Buy more snake oil products, because it can't hurt! 2. Use this compliance framework, to at least CYA 3. Build cool stuff, because its fun and pseudo-justifiable.
English
1
0
1
108
Dino A. Dai Zovi
Dino A. Dai Zovi@dinodaizovi·
The number one reason why good security is hard is that the feedback loop on decisions is long and the signal is low fidelity. It's not clear how many incidents were prevented or mitigated from which foundational decisions years prior. This wrecks the incentives to be proactive.
English
5
14
37
5.2K
Misha Davidov 🏳️‍⚧️
Upside: In the morning I get to take a ride in this brand new Rolls Royce Phantom Extended II! Downside: It's to a surgery center. Upside: It's to get a new face! Downside: It's going to take ~7 hours. Upside: Finally being myself. bbiab.
Misha Davidov 🏳️‍⚧️ tweet media
San Francisco, CA 🇺🇸 English
6
0
24
3.9K
collin
collin@libber·
@swagitda_ Walking 1:1s when weather cooperates and under desk treadmill in this wfh world are both very pleasant
English
1
0
2
182
Kelly Shortridge
Kelly Shortridge@swagitda_·
given all the documented benefits of walking on creativity and brainstorming, has anyone tried like… walking offsites? not power walking but the ideal three mile per hour stroll
English
7
2
27
6.2K
Dom Narducci
Dom Narducci@dnathe4th·
Today in nominative determinism // @wolfejosh
Team USA@TeamUSA

.@USA_Taekwondo Paraympian Evan Medell is a man on mission. “The only reason I’m back is to win gold [at Paris 2024]. That’s it. That’s all I’m trying to do.”

English
1
0
2
814
collin
collin@libber·
@IAmMandatory 'write a short story about a hacker in iambic pentameter' Was a top 5 prompt for me today in messing around
English
1
0
2
0
mandatory.bsky.social
mandatory.bsky.social@IAmMandatory·
ChatGPT is coming for both STEM and the arts, this shit is impressive as hell.
mandatory.bsky.social tweet mediamandatory.bsky.social tweet media
English
2
12
45
0