@dalias really?
da_667@infosec.exchange
Indlæg
-
I'm going to say something that's been festering in my mind for a while now. -
I'm going to say something that's been festering in my mind for a while now.@dalias I absolutely want executives in cuffs for failing to secure data that I have no choice but to trust to them, that is mostly immutable. They get paid ridiculous sums of money for the job, but there are zero consequences for that failure. and if that means an executive gets jail time for failing to patch a box, I would welcome it. At the same time, I would absolutely welcome them getting imprisoned for the collection of PII, especially biometric data that they, historically never needed
When I acquired my credit card in the early 2000s, I never once needed to take a picture of my license, or take a picture of myself for some credit card company to verify my identity. They tell you that the data isn't stored, but if it isn't, then why did they need it in the first place?
-
I'm going to say something that's been festering in my mind for a while now.@munin I'm doing cardio walking. slightly different from the treadmill. Not quite so intense, but it involves a lot more parts of the body, and by the end of it, I've worked up a healthy sweat.
I'm glad you're thriving or at least getting healthier
-
I'm going to say something that's been festering in my mind for a while now.@munin since I've started getting my health in order, my cardio sessions have gotten longer and longer. I'm up to 60 minutes of cardio six days a week now, and I'm starting to add handweights to my workouts to get a bit of resistance training in with the cardio as well.
while still in awful shape, I'm the healthiest I've been in six years.
-
I'm going to say something that's been festering in my mind for a while now.@munin if nothing else, the catharsis is nice, and its great to know that I'm not alone.
-
I'm going to say something that's been festering in my mind for a while now.@munin I faced burnout a long time ago. The only thing I can be is a professional by measure of my peers. I do the best I can with the power I'm given. and if others choose to do nothing with it? I don't care anymore. Which is awful to say but here we are.
-
I'm going to say something that's been festering in my mind for a while now.@fxchip Every time I see that "Credit monitoring" mail come into my inbox, I know that somebody, somewhere suffered an extremely dereliction of their duty to protect sensitive data, and that this letter is the equivalent of the "We're sorry" commercial.
-
I'm going to say something that's been festering in my mind for a while now.@fxchip don't fucking get me started about equifax breach and credit scores. Man, credit scores never existed before the 80s. Just another case of the boomers having fucked us all yet again.
-
I'm going to say something that's been festering in my mind for a while now.It has always been the privilege of the corporations and the rich to define what responsibility is. I'm here to tell you don't give them what they aren't willing to give us.
-
I'm going to say something that's been festering in my mind for a while now.nobody is held liable when breaches occur and your PII gets stolen for the fifth time in a single year.
And then we read the inevitable report that it was a third-party managed system that was 6 months behind in patches that got popped. Or it was a risk assessment result that they said "they would get to that eventually" and never did.
You start throwing executives in cuffs for failing to do their duty and sure as shit things would start changing.
-
I'm going to say something that's been festering in my mind for a while now.Is what I said right? am I a fucking loon for having said it? I don't care. I haven't seen any improvements over the past 20 years I've been here and I'm fresh out of fucks to give when so-called professionals telling me that the way we've been doing things for so long, which has produced nothing positive so far as I have seen, should be maintained, stop questioning it.
-
I'm going to say something that's been festering in my mind for a while now.I'm going to say something that's been festering in my mind for a while now. In my two decades of practice in information security, I have yet to see responsible disclosure result in measurably better security posture.
Code quality hasn't improved, patch management hasn't improved, minimum viable product hasn't improved, automated security updates, especially for IoT devices... Jesus Fucking Christ haven't improved. The cost of failure for organizations losing your data due to gross negligence has in no way improved, why should responsibility be the domain of the security researcher when nobody else is willing to share in that responsibility?
I'm half-tempted to say if you have 0-days you might as well get paid for them than be responsible. Because even with a tilted playing field, nothing has measurably improved since I've been here and I would argue with "vibe coding" and the tech industry's view of "Let the AI handle it" that software quality is the worst it has been since the 90s. I lived through windows millennium edition. I've seen shit you wouldn't believe.
"Hardware's fucked because we can't buy any, software is fucked because the LLMs trained by reddit and stack overflow are in charge now. You might as well fucking guess at this point."