Raphael Waller

3.5K posts

Raphael Waller banner
Raphael Waller

Raphael Waller

@rwllr

Graduate Electronics/Computer Engineering student, full time senior sysadmin. Looking for more hours in the day and more things to automate.

London, UK Katılım Ocak 2010
196 Takip Edilen94 Takipçiler
Raphael Waller
Raphael Waller@rwllr·
@IAMERICAbooted Infostealers can also be mitigated with application whitelisting. For the 99% something like aaronlocker though we use Threatlocker and their SOC
English
0
0
1
10
EZ
EZ@IAMERICAbooted·
@rwllr yep! there's one more reason at least but this is one of the ones I was thinking about. infostrealers can dump authn cookies from browsers and replay the tokens from an external perspective :) This can be mitigated with session timers
English
2
0
8
720
EZ
EZ@IAMERICAbooted·
Who can tell me what benefit having Named Locations/IP Allowlists when you already have FIDO2 for authn to SaaS? Think like an attacker. I'll wait, hopefully not too long.
English
13
2
36
6.9K
Raphael Waller
Raphael Waller@rwllr·
@LahavHarkov The craziest thing is that I'm pretty sure they actually consult for other regions and faiths helping them implement it within their own communities.
English
0
0
1
79
Lahav Harkov
Lahav Harkov@LahavHarkov·
Imagine if the response to this was “how can I get my Muslim community to engage in more volunteer work?” (And I’m sure many already do.) There are much more Muslims than Jews in the UK. It would redound to everyone’s benefit. Instead, she lies out of racism and resent.
Dr Rahmeh Aladwan@doctor_rahmeh

Jews are the only group who operate their own ambulances (hatzola) and police (shomrim) in Britain. They do this in 14 other countries, mostly European. In the US, Hatzola has been accused of tending to jews while non-jews have died at the same scene. Why the apartheid?

English
4
21
148
6.1K
Bastien Perez
Bastien Perez@bastienperez_·
📣 For years, Microsoft has been fairly permissive with Entra ID P1/P2 feature usage: you could buy a single license and it would effectively “unlock” features for the entire tenant. This creates a lack of visibility to know whether tenants are complying with licensed feature usage limits, such as: * Conditional Access (minimum Entra ID P1) * Risk-based policies (Entra ID P2) Microsoft has updated its page to track license usage and identify “spikes” (overages). 🔺 Where to find it: Entra ID portal > Licenses > License usage (Preview) Direct link: #view/Microsoft_AAD_IAM/LicensesMenuBlade/~/LicenseUtilization" target="_blank" rel="nofollow noopener">entra.microsoft.com/#view/Microsof… The real question: will Microsoft eventually start going after the €€ from tenants that exceed their limits? Wait and see…
Bastien Perez tweet media
English
8
19
100
12.2K
Raphael Waller
Raphael Waller@rwllr·
@IAMERICAbooted @DeeOakster It depends who you are. For most SMB's they're not defending against a determined adversary and just need to be better than most against someone who doesn't typically know what they're doing.
English
0
0
1
24
EZ
EZ@IAMERICAbooted·
@DeeOakster Um, I beg to differ. IME, the "bad guys" know it better and are not inhibited by silos, administrative burden, or politics in their endeavors :)
English
2
0
10
495
EZ
EZ@IAMERICAbooted·
If a Global Admin gets compromised, it should be treated like a scorched earth scenario. The possibilities for backdoor are endless, especially if they disabled the audit logs.
English
7
14
117
10K
Raphael Waller
Raphael Waller@rwllr·
@fabian_bader @NathanMcNulty I guess the standard is still under active development and so things like the ability to mark it as non exportable. But as an admin I'd like to be able to 'trust' GPW for standard users.
English
1
0
1
15
Fabian Bader
Fabian Bader@fabian_bader·
@rwllr @NathanMcNulty It's not a can't do but a decision not to do so. Technically synced Passkeys would support attestation, but since they roam around and are even exportable to other passkey providers, nobody is attesting
English
1
0
1
26
Nathan McNulty
Nathan McNulty@NathanMcNulty·
Good flow diagram for the upcoming passkey changes Two things to be aware of: 1) If you are not enforcing attestation, you are not truly enforcing your AAGUID key restrictions 2) If you start enforcing attestation, existing passkeys are not attested, only newly registered ones
Matt Levy | Microsoft Security MVP@MattChatt42

Struggling to understand the impact of the upcoming passkey rollout in Microsoft Entra tenants (MC1221452)? ME TOO. So I had this flow diagram created.

English
3
19
73
10.4K
Nathan McNulty
Nathan McNulty@NathanMcNulty·
@fabian_bader My recommendations: 1. Inventory your settings 2. If not attested, inventory passkeys 3. Enable passkey profiles, set default profile to enforce attestation, create new profile without attestation (allows synced) 4. Set all users to default only, add exception group for synced
Nathan McNulty tweet media
English
4
0
3
834
Raphael Waller retweetledi
Hooman Bakhshi
Hooman Bakhshi@BakhshiHooman·
Friends! Iran 🇮🇷 is experiencing one of the darkest periods of her history. I am trying to be the voice of voiceless! I will never forget who stood up for us during this terrible time. #FreeIran
Hooman Bakhshi tweet media
English
2
25
263
13.2K
Raphael Waller
Raphael Waller@rwllr·
@IAMERICAbooted Consider Business Premium and Microsoft Defender and Purview Suites for Business Premium bundle
English
1
0
0
200
EZ
EZ@IAMERICAbooted·
Im looking to build a new E5 test tenant. The licensing costs 700-800$ per year per user. In partner tenants, your limited to what features you can use. Anyone interested? I'd like about 5-10 licensed users. I'll pay for 2 E5 licenses.
English
8
0
22
4.9K
EZ
EZ@IAMERICAbooted·
idk who is who in this account. I'm going to be creating a new account. If anyone I normally interact with would like to come along, let me know.
English
83
0
91
2K
Raphael Waller
Raphael Waller@rwllr·
@IAMERICAbooted @arpeyton The settings catalog is I believe just a wrapper to make things easy and stop us breaking it. We had to manually configure because the catalog wasn't built out fully at the time.
English
1
0
0
26
Raphael Waller
Raphael Waller@rwllr·
@IAMERICAbooted @arpeyton It's THE MDM settings specification. Apple MDM's use them too, and I'm fairly certain they were around in Windows Mobile 6.5
English
1
0
0
19
EZ
EZ@IAMERICAbooted·
For those that dont know, Microsoft doesnt recommend installing stuff with OMA-URIs anymore :p
English
2
0
5
472
Raphael Waller
Raphael Waller@rwllr·
@SwiftOnSecurity The difficulty is scale. The number of Hilton corporate employees is really low. Franchisee employees make up the vast majority of staff. And franchisees and owners are the real hotel chain customers and who they need to keep happy.
English
1
0
1
148
SwiftOnSecurity
SwiftOnSecurity@SwiftOnSecurity·
I do sympathize with Hilton's problem here because they are under immense cyber attack on customers, and establishing a root of trust with the hilton.com domain does make sense. Just a big crap sandwich. In a prev company we used to only forward a "dealer-###@" mail
English
1
1
28
6.1K
SwiftOnSecurity
SwiftOnSecurity@SwiftOnSecurity·
InfoSec/Brand Protection tabletop scenario: A front office manager at a franchised chain hotel location has an account on your root corporate brand domain and tells the government to kick rocks. They make headlines on every conservative news media front page.
SwiftOnSecurity tweet mediaSwiftOnSecurity tweet mediaSwiftOnSecurity tweet media
English
3
14
129
20.5K
Raphael Waller
Raphael Waller@rwllr·
@IAMERICAbooted @ar4nier I've only ever looked at my following tab and never any of the algorithm. It means the content I read is only people I've consciously decided to follow or things they've consciously decided are worth sharing.
English
1
0
1
20
EZ
EZ@IAMERICAbooted·
X infosec is really great for one thing: learning the people you never want to work with because they are toxic.
English
3
0
33
1.3K
Farbod Esnaashari
Farbod Esnaashari@Farbod_E·
My mom's reaction to James Harden scoring 55 points: "Oh my God! You have to give him a raise!"
English
4
5
163
5.5K