icd
6K posts

icd
@wan0net
"I didn't do it. Nobody saw me do it. You can't prove anything." - Bart Simpson @wan0net.42 on Signal
AU Katılım Haziran 2014
235 Takip Edilen880 Takipçiler

Cyber things people say I don't listen to because research and experience in business:
DO NOT USE PUBLIC WIFI:
I USE PUBLIC WIFI!!! why? because I've done research and can show that largely speaking it's reasonable safe... you know that's why basically every shop /restaurant you walk into offers it! what do you think they are trying to get sued?
DO NOT USE USB DRIVES
I literally have to use USB drives to transfer data and to rebuild systems (e.g. create USB media).
DO NOT CLICK LINKS
this one is just stupid! I have: PDNS, WEB content filtering, browser APIs and EDR.... plus I need to click links to work! what am I going to do otherwise? pay myself to just sit here doing nothing?
AVOID USB KEYS FROM THE FLOOR
what kind of world do you live in where the occurs on a frequent basis? I've never ever ever found a USB drive just laying on the floor when I'm walking around, and if I did at work I'd be handing that as it's lost property!!
can you think of any more cyber insane stuff people say?
I must be missing some!!!
English

@thebleucheese @SwiftOnSecurity And the fact you have this attitude is exemplify what Tay says.
English

@wan0net @SwiftOnSecurity there is probably no such thing as good development then. the alternative is massive cost and unpalatable time to market for consumer and most b2b products. work like that WAS done or attempted at times in prior decades but the market has always selected against it.
English

The correct answer is a fully validated and controlled execution environment needing no antivirus but we've made an industry of bandaids for a fundamental error in our approach.
John Marcum@PJ_Marcum
So what’s gonna change due to this? What are the lessons learned? Will anyone drop CrowdStrike?
English

@thebleucheese @SwiftOnSecurity There is, it’s called safety critical systems.
English

ItCrowdStrike has since "clarified" (crowdstrike.com/blog/technical…):
1. It was not a "driver" but a (kernel loaded) "configuration file" that updated how Falcon "evaluated named pipe execution"
2. It was not related to null bytes (i.e. zeros) in the file
Clear?
Toby Murray@tobycmurray
If twitter reports are to be believed, it looks as if CrowdStrike pushed an invalid kernel drover that was simply full of zeros, rather than a valid (presumably) PE format. That is somewhat at odds with CrowdStrike’s contention that this was a “content update”.
English
icd retweetledi

Here’s the thing folks. I’ve been coding 32 years. When something like this happens it’s an organizational failure. Yes, some human wrote a bad line. Someone can “git blame” and point to a human and it’s awful. But it’s the testing, the Cl/CD, the A/B testing, the metered rollouts, an oh shit button to roll it back, the code coverage, the static analysis tools, the code reviews, the organizational health, and on and on. It’s always one line of code but it’s NEVER one person. Implying inclusion policies caused a bug is simplistic, reductive, and racist. Engineering is a team sport. Inclusion makes for good teams. Good engineering practices makes for good software. Engineering practices failed to find a bug multiple times, regardless of the seniority of the human who checked that code in. Solving the larger system thinking SDLC matters more than the null pointer check. This isn’t a “git gud C++ is hard” issue and it damn well isn’t an DEI one.
English

@grandMa5ter @_sarahyo You’re Scottish until you win something then you’re British.
English

Will I be getting up at 5am to watch the match? I don’t watch football often but I do come from a football crazy family and used to have a season ticket when I was little, so hell yes I’ll be getting up to (hopefully) see football come home. #EURO2024 🏴
English

Finally got around to setting up ludus.cloud on my homelab.
Looking really promising 🥰
Relatively smooth setup on an existing Proxmox host too, just one config change due to existing vm storage file system.
Looking forward to digging in further.
English
icd retweetledi


@fancy_4n6 @fr0gger_ Mine regularly get attacked by a puppy who just wants to show he loves me, so I don’t have as many as I’d like.
English

@fr0gger_ I have put most of mine in a box sadly as there are too many to wear and have in my wardrobe!
English

@grandMa5ter @Asher_Wolf I’d also suggest that if anyone has a significant number of data scientists, and a clear view of ethics that is bound by law, it’s them.
English

@raymatp07 @InsiderPhD You said the above as a bad example, but I think there are benefits.
It's also funny that you call it absurd which is kinda of the behaviour that was being called out through the idea. You can give an opinion on an idea in a constructive way.
English

@InsiderPhD I know some appeals are just plain stupid or inconsiderate but that logic is just absurd. It is like saying that tech reviewers shouldnt review AI products unless they have coded machine learning before.
English

Everyone should have to do a stint in triage before they can appeal submissions
sean@seanyeoh
@thedawgyg it should be mandatory training program for bug bounty hunters to have to try and fix one production bug before being able to request remediation.
English







