Scott Massari

2.7K posts

Scott Massari banner
Scott Massari

Scott Massari

@scottmassari

Cybersecurity, motorcycles, rock climbing, snowboarding, powerlifting. Lover of all things Cleveland, Detroit, and in-between. Enzo's Dad.

The Glass City Katılım Nisan 2009
738 Takip Edilen265 Takipçiler
Scott Massari retweetledi
@·
This is CrowdStrike's Director of Overwatch, so I hope to help spread the word. I believe CS stopped these changes from being pushed out so machines late to the party wont get the faulty driver. Command in Safe Mode: del "C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys"
English
50
894
3.1K
664.8K
Scott Massari
Scott Massari@scottmassari·
@NathanMcNulty @techspence Maddening that it's still pervasive across the entire industry! With a few decades under my belt, I can count on one hand the number of vendors/products/solutions that actually achieved it.
English
0
0
1
10
Nathan McNulty
Nathan McNulty@NathanMcNulty·
@techspence We don't know how to use what we have, so if we buy the most expensive thing out there, it should practically manage itself, right?
English
3
0
7
859
spencer
spencer@techspence·
More complex security solutions are not necessarily better...more complex = more moving parts = more changes for things to go wrong
English
17
7
51
58.3K
Nicole Hoffman
Nicole Hoffman@threathuntergrl·
Final day of RSA Conference in sunny San Francisco. Join me at 9:40 am in Moscone West 3022 for my presentation with Michael Marriott for an overview of the identity threat landscape. If you missed the book signing, I have a few extra copies with me. Also, today is my birthday!🎂
Nicole Hoffman tweet media
English
1
1
13
638
Scott Massari retweetledi
@·
tl;dr on the OpenSSL vuln: it seemed bad originally, but then OpenSSL realized it wasn't critical after all. Treat it like any other software flaw and follow your normal patching cycle. Unlikely to be exploited in real-world configurations.
English
0
12
35
0
Scott Massari
Scott Massari@scottmassari·
@NathanMcNulty Definitely! I bet a lot of orgs are still pushing mobile VPN clients unnecessarily.
English
1
0
1
0
Nathan McNulty
Nathan McNulty@NathanMcNulty·
@scottmassari I see people implementing Microsoft Tunnel so their users can access internal web apps on their phones, and I want to scream Azure App Proxy can expose APIs too! People just need to know it exists and play with it.
English
1
0
4
0
Scott Massari
Scott Massari@scottmassari·
What a cool poc. Azure App Proxy is such a great tool, very flexible. Underated as a digital transformation component, I've seen a lot of orgs that gloss by it when it's likely the best option.
Nathan McNulty@NathanMcNulty

Last night, I got Apache Guacamole published through Azure Application Proxy to share some of my lab machines in a test tenant, and it's so dang cool RDP and SSH right in the browser, no Remote Desktop Services licensing (or crazy farm configuration and certs) Loving this :)

English
1
0
3
0
Scott Massari
Scott Massari@scottmassari·
@303Rsa @SteveSyfuhs Curious what you saw as the advantages over the AzureB2C offering, especially with the cost benefit for certain existing customers(first 50k mua free/month)?
English
1
0
0
0
Rsa_303
Rsa_303@303Rsa·
@SteveSyfuhs I love Azure Ad for everything but as a Microsoft only business we felt forced to use Auth0 for our B2C app. Magic link like technology woulfbe great. Some polish and time and perhaps Azure Ad will get feature parity
English
1
0
0
0
Steve Syfuhs
Steve Syfuhs@SteveSyfuhs·
I guess Okta is getting desperate.
Steve Syfuhs tweet media
English
4
0
21
0
Scott Massari
Scott Massari@scottmassari·
@SwiftOnSecurity It's not uncommon, unfortunately. In an early leadership role I was shocked that it was expected to essentially have a bell curve when doing yearly reviews.
English
0
0
0
0
SwiftOnSecurity
SwiftOnSecurity@SwiftOnSecurity·
Yearly reviews were not to determine merit but kill aspiration.
English
13
28
201
0
SwiftOnSecurity
SwiftOnSecurity@SwiftOnSecurity·
I was negged for years in my reviews. I was never good enough. There was always unoverlookable flaws. I later realized as much as I nominally liked my supervisor, they were forced to mark me as 3/5 on knowledge. I left that job for x the pay and awarded Microsoft MVP month later.
English
12
15
254
0
Dave Kennedy
Dave Kennedy@HackingDave·
That moment where you try to take a picture of 50 cent and trying to make sure he doesn’t notice and immediately makes eye contact with you 😂😂😂
Dave Kennedy tweet media
English
29
2
160
0
Scott Massari
Scott Massari@scottmassari·
@notshenetworks @TechEmiiily @taterstiltskin Many women powerlifters/bodybuilders also track, so their coaches can make accurate, data driven changes in diet/load. Some do it to also track when certain variables have caused missed periods (e.g. diet induced hormone impact).
English
1
0
4
0
shenetworks
shenetworks@shenetworks·
@TechEmiiily @taterstiltskin I love the implication that married women aren’t interested in tracking their period or fertility lmao it’s almost like they have no idea what the f they’re doing
English
1
0
12
0
shenetworks
shenetworks@shenetworks·
Shut up how about that
English
5
0
25
0
Scott Massari
Scott Massari@scottmassari·
@ChicagoCyber I would lean towards hyok plus tokenization. Have seen byok be misconstrued, e.g. it's not enough to protect from subpoena request when talking O365 (actually need double key encryption). But yes we as industry professionals need to push on vendors to drive that baseline standard
English
0
0
0
0
Scott Massari
Scott Massari@scottmassari·
@a_r_i_t @mattblaze Admin for everyone on a shared account and forget firewalls and MFA, because every company will be exposed to malware one way or another. Boards should stop worrying about the risk.
English
0
0
0
0
Ari Trachtenberg
Ari Trachtenberg@a_r_i_t·
@mattblaze At this point ... almost all of us are going to get exposed to COVID one way or another. What value is there in obsessing over the risk?
English
11
0
0
0