Post

@speakjava Let me know when you have the correct answer :)
English

@speakjava You may explain how Israeli intelligence hacked the Iranian atomic power plant centrifuges that were not connected to the net.
English

@speakjava Remind them this: vulncat.fortify.com/en/detail?id=d…. A hacker can craft a request message with this specific double and hang their machine if they don't update.
English

@speakjava What about “I hope you have slightly different update policy of your firewall”? 😉
English

@speakjava How about changing the context to something everybody should understand, e.g. airport customs.
English

@speakjava Ask them if they have any firewall exceptions.
English

@speakjava It depends on your relationship with him. If he is your customer then the old saying applies: "The customer is not always right, but he always has the last word".
English

@speakjava Just ask them if they are also not using any Anti-Virus software just because they are behind a firewall.
Walldorf, Deutschland 🇩🇪 English

@speakjava There's always some surface to attack. How about - - there's more concerning exposure than 2m old jdk? And time to retest that build which has "just" security patch simply doesn't worth it? :)
English

@speakjava Not updating is totally ok as long as the app is on a machine that is turned off, in a sealed high-security safe 10 m underground. :)
English

@speakjava Ask a friendly hacker to send them a screenshot of their desktop.
English

@speakjava There are some hackers using waterwalls, which make firewalls totally inoperable. There are ofc alternatives, one might use an airwall to make the firewall even stronger or combine it with an earthwall to stop the waterwall...1/2
English

@speakjava Showing an example of how it could be exploited even behind a firewall.
English

@speakjava Maybe with statistics.. the majority of attacks/breaches come from inside errors.
English

@speakjava Remember Germany, 1989? Walls aren't as impenetrable as some people might want you to believe. If there's a will, there is a way.
Willich, Deutschland 🇩🇪 English

@speakjava The great irony of life is, good counsel given to someone whose tail is not on fire yet, is usually looked upon as BS. So it’s better, to focus energies elsewhere.
English

@speakjava Is there a danger from malicious users inside the organisation/firewall?
English

@speakjava Why would there be any irritation on your side (and indication of impoliteness)? Just keep the answer merit-based.
English

@speakjava Me:"Are you sure? Ok is upon to you: i'll write a document signed by You were all your decisions are documented together with my proposition..." - Be Correct + Pecunia non olet!😎🖖
English

@speakjava Tell them it is exactly similar to keeping an expired medecine in shelf for emergency purpose.
English

@speakjava POC || GTFO w/ an example vuln. Doesn’t have to be the same language. Demonstrate knowledge and show how history repeats itself.
English

@speakjava Tell them they'd be better off doing something less technical :)
English

@speakjava You just respond normally with the prefix "With all due respect, Sir" and then you can say something like "you are a halfwit" or whatnot.
English

@speakjava «Defense in depth» is neither a galaxy name nor a novel tittle ;)
English










