Ron Brash

3.6K posts

Ron Brash banner
Ron Brash

Ron Brash

@ron_brash

ICS/embedded and cybersecurity researcher, water sports fanatic, chihuahua owner, maintainer of things, and sharer of knowledge.

Canada Katılım Ağustos 2010
968 Takip Edilen1.2K Takipçiler
Ron Brash retweetledi
vx-underground
vx-underground@vxunderground·
In you missed it (I did, I don't know how), Microsoft is aiming to phase out UAC and replace it with a more secure thingie called "Administrative Protection". They're doing this because UAC currently has over 81 bypasses and, for reasons unknown to me, Microsoft decided to scrap UAC in totality and redo the entire thing from the ground up. Why? I have literally no idea. Maybe you stinky nerds can educate me. AP is now in preview mode for Windows Insider builds (testing stuff). Big brain security researchers from Google Project Zero poked it with a stick and discovered eight vulnerabilities that allowed them to bypass AP. Microsoft has since patched it. AP has yet to be deployed to Windows 11 as of this writing. AP on paper, when reading about it, seems like a good idea and seems like it unironically would be a massive security improvement for Windows. However, the new architecture would bamboozle some legacy applications. Making it work with older stuff will require lots of science from Microsoft. Additionally, and maybe I'm being a bit pessimistic, I am concerned Microsoft will vibe code slop their new security module and make it one massive cluster fuck disaster. Please read the research performed by Tirando (can't find his social media profile) and the other nerds at Project Zero. It's interesting. They're all very talented security researchers and make feel like an imbecile. projectzero.google/2026/26/window…
English
53
148
1.6K
98.9K
Ron Brash
Ron Brash@ron_brash·
Two drone remotes. Two vendors
Ron Brash tweet mediaRon Brash tweet media
English
0
0
0
35
Ron Brash
Ron Brash@ron_brash·
@Secure_ICS_OT We also need companies to be hiring vs laying off/downsizing, and changing from "shareholder value focus" to what is integral to the business.
English
0
0
0
24
Secure ICS OT
Secure ICS OT@Secure_ICS_OT·
If you are an ICS/OT controls professional I highly recommend taking ICS/OT cybersecurity training. Be it SANS, ISA, or whatever. We need more ICS/OT folks picking up the cybersecurity skills so that people with ICS/OT experience are at the table guiding decisions.
English
3
1
10
313
Ron Brash
Ron Brash@ron_brash·
@RobTerrin Buying Vanta and compliance tooling makes more sense too, and building integrations into all cloud tools, SOAR and IR. But this... Seems like a hail mary - it's almost like SNOW is having issues getting data to it's existing features. If so, will this solve it..imho, no.
English
1
0
1
38
Ron Brash
Ron Brash@ron_brash·
@RobTerrin Feels a bit Microsofty - buy various products, don't execute (or take forever to GTA). It also feels like a bad vision/let's buy to buy - it would make more sense for Cisco to buy, eol a competitor, and build an integrated AM/IDS system + Splunk offering.
English
2
1
1
70
Ron Brash retweetledi
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
Many confuse a minimum nonviable demo with a product
English
7
4
61
3.8K
geoff
geoff@GeoffreyHuntley·
@evilsocket just drop it full disclosure style there is no such thing as responsible discourse the responsibility falls on the resolver responsible resolution
English
3
1
105
3.1K
Simone Margaritelli
Simone Margaritelli@evilsocket·
Months ago i disclosed 4 distinct vulnerabilities to the TP-Link security team. They asked to wait for disclosure, saying they would publish patches and assign CVEs by the end of November. Guess? It did not happen and they are now not responding to my emails...writeup next week.
English
25
59
1.2K
47.2K
Ron Brash retweetledi
Secure ICS OT
Secure ICS OT@Secure_ICS_OT·
Secure ICS OT tweet media
ZXX
2
2
10
240
Ron Brash
Ron Brash@ron_brash·
@furt_tech After PHP 5, and when it became object orientated - the world changed. But also, we are from God's language land (c) so... We know never trust anything typed or not... So also a reason for us
English
1
0
2
27
Ron Brash
Ron Brash@ron_brash·
@shehackspurple The harder question... How do we get people who did write software before, and now are vibing... To care about security? (Actually quality/engineering but I digress)
English
1
0
1
13
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
How do we get people who are now releasing software, who previously did not because they don't have the skill, to care about Security? People who aren't software engineers. How do we reach them? How do we secure them? I need your advice. #appsec #ai youtu.be/Zj1uwsmWuAw?si…
YouTube video
YouTube
English
6
1
19
1.8K
Ron Brash
Ron Brash@ron_brash·
@P4LSEC Probably accurate. Make sure it has solid ventilation and you constantly clean for dust... That's been my secret with even the Korean stuff (LG & Samsung are shite these days too)
English
1
0
1
51
JΔCΞ
JΔCΞ@P4LSEC·
My deep freezer from 1987 (38 years!) is finally dying. Just ordered a Chinese replacement, what are the chances it’ll last 10 years?
JΔCΞ tweet media
English
2
0
1
158
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
I don’t give a shit about CVEs anymore. It’s more interesting to proactively address whole classes of vulnerabilities at scale, and think of ways to implement controls in an org without disruption. CWE > CVE
English
16
2
125
5.4K
Ron Brash
Ron Brash@ron_brash·
@Turbo81 The fascinating bit. We will be slaves to AI, but AI needs power, so we make the power. But AI consumes more power, literally and figuratively.
English
1
0
0
23
WarMonitor🇺🇦🇬🇧
WarMonitor🇺🇦🇬🇧@WarMonitor3·
The world will be and is already starting to buy Ukrainian drone tech. The Ukrainians are way ahead of the rest.
English
128
291
3.3K
76.9K
Ron Brash
Ron Brash@ron_brash·
@dsnakenbacon @UK_Daniel_Card Yes many of us often are waking up and wanting to quit cyber after feeling like people are too focused on the wrong things, racing head, or not doing what needs to be done... Are not good precursors for a meeting. Try to put some distance in there and good luck.
English
0
0
3
46
DS
DS@dsnakenbacon·
@UK_Daniel_Card Feeling this today as I'm about to head into a conversation that might ultimately result in my resignation. I wonder if folks that say this stuff have worked in business/technical envs that have gone through years of M&A while trying to support constant change and innovation.
English
2
1
4
1.1K
mRr3b00t
mRr3b00t@UK_Daniel_Card·
some people think that there's some kind of magic wall between IT / Security & business/people/politics... if you think in silos sure.... but then that's not reality, reality is not neat boxes, IT and Security ARE People & Politics & technology and physics and science and art etc. describing technology as easy is the most ridiculous take ever... that CPU you are using.... just make a new one by hand, its EASY!!! (so you say!)
mRr3b00t@UK_Daniel_Card

IT and Security are hard.... it's easy to forget that..... because its way fucking harder to do than talk about!

English
5
1
36
5.2K