Matt Topper

6.5K posts

Matt Topper

Matt Topper

@topperge

Dad. Founder @UberEther Identity and Access Management geek. Always curious.

Detroit, MI Katılım Haziran 2007
1.6K Takip Edilen1.3K Takipçiler
Matt Topper retweetledi
Ryan Hurst
Ryan Hurst@rmhrisk·
As an industry, we transitioned from no focus on security to expecting an underfunded and under-tooled discipline to handle the topic for an entire organization. From there, we started to shift the responsibility to produce and deploy software securely back onto developers and operators. We did this without providing them the tools or training to perform these jobs effectively. We’ve also neglected creating and deploying the kind of tools that enable an organization to assess if their SDL and overall security programs are effective, instead focusing on tactical tools without considering their effectiveness. At the same time, we’ve continued to rely on blind faith that vendors are doing the right thing and have failed to hold them accountable for repeated mistakes. In essence, we have regressed back to where we started, with voices in the corner screaming about how we need to be making informed decisions to mitigate threats proactively instead of chasing the latest novelty. We can’t have it both ways. Either security teams continue to exist, work closely with the product and operations teams, and grow proportional to the teams they support, or we build the kind of products that allow security teams to assess what’s happening at scale, augmenting developers with expert systems that enable them to access the knowledge to design and build secure systems from the get-go. We must stop papering over issues and make the right thing the easy thing.
English
0
1
6
890
Ryan Hurst
Ryan Hurst@rmhrisk·
My middle son is doing ground school via a community college in Washington and is having a hard time finding a air school just that will give him his flight training without doing their ground school. Any pilots I’m the greater seattle area with advice?
English
1
1
0
866
Matt Topper
Matt Topper@topperge·
@_ChezDaniela @Dave_Maynor Isn't that the Microsoft approach? Sorry to we messed up. Pay us more for those E5 licenses so you can tell us the next time it happens.
English
0
0
1
36
Varys
Varys@_ChezDaniela·
@Dave_Maynor How things really work ⬇️ (this was sarcastic by the way 🙃)
Varys tweet media
English
1
0
0
280
David Maynor
David Maynor@Dave_Maynor·
At this point single factor auth seems more secure than using Okta. #mgmhack
English
4
2
28
7.7K
Matt Topper
Matt Topper@topperge·
@rmhrisk I'm sorry sir, we do zero trust in this org. I don't need to know where the root of trust is established.
English
1
0
1
136
Ryan Hurst
Ryan Hurst@rmhrisk·
Do you know where your cryptographic keys are? If you store them in PKCS#12 or JKS files I bet you don't :)
English
1
0
6
991
Matt Topper
Matt Topper@topperge·
@HackingDave Just put in a 7-11 on the corner and make that part of the exercise program.
English
0
0
1
32
Dave Kennedy
Dave Kennedy@HackingDave·
I just definitely got busted. FedEx delivered a box that the packaging of what I ordered was on the side. Erin: “um did you buy a commercial grade hot dog maker with bun warmer???!!” Me: so listen…
GIF
English
36
7
271
25.6K
Matt Topper
Matt Topper@topperge·
Bubbles, anchors, and end links. This is why I can't sleep tonight.
English
0
0
1
158
Matt Topper
Matt Topper@topperge·
@lorenc_dan Also, are they going to mention the key used expired in 2021? I haven't seen anything in the write ups saying they fixed that issue yet.
English
1
0
1
59
Matt Topper
Matt Topper@topperge·
@lorenc_dan So sadly true, the response to customers has been "See, we told you that you should have been paying for E5 licenses. Do you want to write that check now?
English
0
0
1
49
Matt Topper
Matt Topper@topperge·
@arynncrow Hopefully it was don't in a medical facility and you didn't wake up in a bathtub full of ice. Glad everything turned out OK. Maybe we can find a way to get @tomsegura to sign your appendix?
English
1
0
1
72
Arynn Crow
Arynn Crow@arynncrow·
Update: I’m doing alright. Thanks to folks who have reached out to check in. The nurses told me I’d be shocked how many people leave their appendix in Vegas 🤣
Paradise, NV 🇺🇸 English
5
0
10
510
Eli Nesterov
Eli Nesterov@elinesterov·
Did you know it is pronounced “jot” not “j-w-t”
English
1
0
1
194
Ryan Hurst
Ryan Hurst@rmhrisk·
Ryan Hurst: (noun) A person who exhibits a strong affection for neglected infrastructure, specifically with an emphasis on often-dismissed elements of various fundamental security assumptions.
English
2
0
8
847
Matt Topper
Matt Topper@topperge·
@MalwareJake @BrianVarnerVA This is what normally ends up happening but it's one of those fun questions for the auditors that don't suck. All 3 of them. I kid, I kid.
English
0
0
1
58
Jake Williams
Jake Williams@MalwareJake·
@topperge @BrianVarnerVA If for no other reason than not dealing with auditor questions, I'd use another account. Pragmatically, this comes with significant verification challenges, so I'm unsure why anyone would want to do it.
English
1
0
0
47
Jake Williams
Jake Williams@MalwareJake·
I'm 100% convinced that you can't secure an environment without threat modeling access to your control planes. It is frankly insane to have a single SSO account be in scope for Slack, email, and the enterprise AWS portal.
English
20
31
220
49.5K
Matt Topper
Matt Topper@topperge·
@BrianVarnerVA @MalwareJake It's a debate that I've seen regularly. If it's the same identifier for the account but a different credential is it was same account? Comes around the same discussions with step up auth, MFA, passkeys, etc.
English
1
0
0
145
Matt Topper
Matt Topper@topperge·
@lorenc_dan I actually posted something similar in the @idpro_org slack channels as a perfect exercise between the IAM and SOC teams.
English
0
0
1
103
Dan Lorenc
Dan Lorenc@lorenc_dan·
Tabletop scenario. A vendor you use to store PII with confirms reports that there is an exploitable vulnerability that allows unauthenticated access to your account. Third-parties have been aware of the vulnerability since March. It won't be fixed for at least two months.
Dan Lorenc tweet media
English
2
8
17
3.7K
SMB Attorney
SMB Attorney@SMB_Attorney·
A lawyer dies and goes to Heaven. "There must be some mistake," the lawyer argues. "I'm only 55." "According to our calculations, you're 82." says St. Peter. "How'd you get that?" the lawyer asks. Answers St. Peter, "We added up your time sheets."
English
28
34
847
144.4K
Ian Anderson
Ian Anderson@ian_infosec·
SEC adopts a new rule consultants everywhere:
Ian Anderson tweet media
English
4
1
46
3.4K
Matt Topper
Matt Topper@topperge·
@rmhrisk It's incredible how many threat models can be thrown out the window with a ball peen hammer. Also much easier approach if the target is work from home. Sometimes I hate that my brain works this way.
English
0
0
1
27
Ryan Hurst
Ryan Hurst@rmhrisk·
When designing key management strategies for high-net-worth individuals or businesses my top threats almost always include thuggery, extortion, and collusion.
English
3
2
16
3.2K