Geekmaster 👽:system76: · @Geekmaster
192 followers · 1387 posts · Server ioc.exchange

Great blog post by a colleague of mine who asks why "Security through obscurity" is not dead in 2023! How many " " is it going to take to finally realize that keeping your a secret is a good thing? How many times does the have to demonstrate that sharing of , , , , methods, , and everything else that goes along with having a approach to a , is ACTUALLY THE GOOD THING 🤨

(ahem)

You want to know about the platform I architected? No problem! 👌🏻
You want to know what Threat Intelligence I gather? Check my GitHub (link on my profile 😁).
You want the keys to my kingdom? 🤣 No, but thanks for playing 👍🏻

I'm NOT saying yourself or open some dark to your systems. Just share the knowledge of how you're protecting stuff! Everyone is more for it, and the next generation will make it better.

kalahari.substack.com/p/securi

#cybersecurity #INCIDENTS #securitycontrols #cybercommunity #threatintelligence #TTPs #iocs #securityconcepts #awarenesstraining #zerodays #defenseindepth #healthysecurityprogram #compromise #backdoor #secure

Last updated 2 years ago

Geekmaster 👽:system76: · @Geekmaster
191 followers · 1373 posts · Server ioc.exchange

is a thing. I've talked about it before, and this article supports every theory I've mentioned over the years. are using to create sophisticated campaigns, , and lowers the entry for new cyber criminals and especially or people with zero technical experience to create and commit malicious fraud campaigns against a much wider swath of targets than ever before. The ONLY way to combat these emerging threats is through user awareness trainings and a approach to your security platform for . For yourselves personally - invest in a solid solution, whether that's Microsoft's (consumer version), or a platform like who is affordable, very good, and works on desktop and mobile. You also want to look into a to protect your data streams. These DarkAI's aren't here to play, they are here to cause chaos. and !!

darkreading.com/application-se

#darkai #cybercriminals #generativeAI #bec #novelmalware #scriptkiddies #defenseindepth #enterprisesecurity #antivirus #defender #avast #vpn #becyberaware #becybersafe #dontgetphished

Last updated 2 years ago

Dis · @dis
123 followers · 587 posts · Server techhub.social

question for the fedi:

How do you convert webhook formats in a environment? For example, converting 'generic webhook' payload to feed

Lots of people seem to use , but that is a lot for a json transform.

Difficulty: It is part of the alerting pipe, so it should be as durable as possible. (As durable as something running on the same infra can be.)

I saw github.com/adnanh/webhook with simple python or curl scripts, but even with (networkpolicy, securitycontext, etc) shell scripts seem hacky at best and a Bad Idea at worst.

Some form of would probably work, but that means finding, installing and learning a new that hopefully won't become a huge headache in a week or a year.

The old uses git-backed and it is a huge pain to maintain. (Mostly thanks to my design.) I'm doing it better this time.

()

#kubernetes #homelab #botkube #gotify #nodered #defenseindepth #serverless #framework #housebrain #boost #k8s #k3s #selfhosted

Last updated 2 years ago

Jay Cuthrell · @jay
103 followers · 438 posts · Server cuthrell.com
🆘Bill Cole 🇺🇦 · @grumpybozo
194 followers · 12732 posts · Server toad.social

@FinchHaven @thisismissem Simple “friction” has been very useful against email without impacting normal email. Example: forcing SMTP clients to wait for a full banner and to follow command pipelining rules. Put the friction in the paths normal users only follow rarely, once, or never, but which spammers try to optimize for heavy travel.

It’s definitely just one layer of but it is not nothing and can be almost free.

#spammers #defenseindepth

Last updated 2 years ago

FinchHaven · @FinchHaven
175 followers · 11261 posts · Server mastodon.sdf.org

@thisismissem @grumpybozo

I've had a very long thread in my Home feed today (mostly because of hastags) that resolved down to:

"Now let's think about for and the in the face of constant attacks

Some options to add _just_ friction:"

Their entire solution was "friction"

Add enough friction and the spammers will go away

I kept wanting to scream

BUT YOUR 'FRICTION' AFFECTS THE 98% OF USERS WHO AREN'T SPAMMERS TOO

Fortunately I said nothing :)

#defenseindepth #mastodon #fediverse #spam

Last updated 2 years ago

Hrefna (DHC) · @hrefna
946 followers · 3180 posts · Server hachyderm.io

Now let's think about for and the in the face of constant attacks.

Basically tying together my other thread with this one: hachyderm.io/@hrefna/110385501

Some options to add _just_ friction:

1. Server-to-server rate limits. Irrespective of user.
2. Slowing down signups. This can be with tools, rate limits, etc.
3. Allow users to filter DMs based on content
4. Your standard "mark as spam" analyzers
5. Exponential backoff on the server side for DMs

#defenseindepth #mastodon #fediverse #spam #captcha

Last updated 2 years ago

🆘Bill Cole 🇺🇦 · @grumpybozo
155 followers · 8304 posts · Server toad.social

How well does it do in a data center with 90dB chillers blowing 24x7?

techhub.social/@techandcoffee/

#infosec #defenseindepth

Last updated 2 years ago

Joe Pasqua · @bitsplusatoms
18 followers · 78 posts · Server sfba.social

@Techmeme This is definitely positive, but in reference to:

“Database leaks have been a bane for security for many years now, with poor practices and configuration mistakes often exposing the sensitive details of millions of people.”

This won’t stop leaks from a misconfigured system (DB or other) on top of S3. By the time data is in the db, it has been decrypted.

#defenseindepth

Last updated 3 years ago

· @twitter
1 followers · 30358 posts · Server mstdn.skullb0x.io

Referenced link: darkreading.com/microsoft/hard
Originally posted by DarkReading / @DarkReading@twitter.com: twitter.com/DarkReading/status

Hardening Identities With Phish-Resistant MFA darkreading.com/microsoft/hard @msftsecurity on extending your MFA strategy and using existing security options to deliver stronger authentication in

#PartnerPerspectives #defenseindepth

Last updated 3 years ago

konst 🇳🇿🚲⚡ · @konst
94 followers · 26 posts · Server hachyderm.io

I explained a as a nice line of defence against common nuisances only. Always secure your underlying API.

For example on WAF, SQLi / XSS filters are implented with regexes. False positives often lead to some rules being disabled. The article shared by others today demos widespread false negatives.

Geo filters are great against pests who don't have VPNs. WAF rate limits are really great against people who don't control botnets.

securityweek.com/wafs-several-

#waf #aws #infosec #defenseindepth

Last updated 3 years ago

· @twitter
1 followers · 29747 posts · Server mstdn.skullb0x.io

Referenced link: darkreading.com/microsoft/hard
Originally posted by DarkReading / @DarkReading@twitter.com: twitter.com/DarkReading/status

Hardening Identities With Phish-Resistant MFA darkreading.com/microsoft/hard @msftsecurity on extending your MFA strategy and using existing security options to deliver stronger authentication in

#PartnerPerspectives #defenseindepth

Last updated 3 years ago

Andre · @toolo
257 followers · 377 posts · Server hachyderm.io

Microsoft’s security approach focuses on , with layers of protection throughout all phases of design, development, and deployment. Read our recent learnings on ensuring and our technologies are secure for our customers: azure.microsoft.com/blog/micro

#defenseindepth #azure #security #cybersecurity #microsoft

Last updated 3 years ago

binaryphile · @binaryphile
65 followers · 154 posts · Server cryptodon.lol

#defenseindepth

Last updated 3 years ago

mrjhnsn :verified: · @mrjhnsn
119 followers · 74 posts · Server infosec.exchange

One of my clients recently requested I do a security audit of an associated but independent side org.

There’s only 3 users and apparently an on-prem server. (They didn’t even know that’s what the computer in the corner of their office was.)
Their is unpatched.
Security has never been something they’ve even spent 10 seconds thinking about.

The SMBs I take on as clients, often aren’t even doing any attempt at until I’ve run through their stuff. Small Non-profits like this example are even worse off. MFA? yeah right. Password managers? you must be high.

There has to be a better way to serve these small orgs that’s not snake oil, and help them put up a solid defense somewhere above the .
/rant

#exchange #wordpress #defenseindepth #securitypovertyline

Last updated 3 years ago

mrjhnsn · @mrjhnsn
108 followers · 51 posts · Server infosec.exchange

I have to say is consistently blowing my mind each month.
When a new CVE hits, I have near immediate visibility into impacted endpoints, with remediation steps for some.
I can tell my team-members exactly what machine needs what patch, including their own.
I love me some MacOs, and I’m a big Linux fanboy, but I’m increasingly drinking the MSFT koolaid for enterprise devices.
Defender + Intune is truly a game changer for SMB’s .

#microsoft #defender #defenseindepth

Last updated 3 years ago

Mose (he/him) · @mose
53 followers · 89 posts · Server infosec.exchange