Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @BrkSchoenfield
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @BrkSchoenfield
-
Nice
#ThreatModeling summary: “You don’t need to classify a threat accurately or precisely to design a mitigation for it — and its mitigations that count most in the end”https://twitter.com/theblacklabguy/status/1221719181684543489 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I cannot count the number of times I’ve encountered static credentials. It isn’t 1988. Today’s toolset easily finds these. Which means you’ve just given attackers access everywhere to whatever you thought was protected. Just. Don’t. Do. It.https://twitter.com/CVEnew/status/1220402105497812994 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Unsure what functionality (esp. security) is in that source code?
@Microsoft have released a source analyzer to enumerate: https://github.com/Microsoft/ApplicationInspector/wiki … (Thanks to@StegoPax for tweeting)Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hoist by my own petard: I lead Cisco Infosec’s 1st SaaS product security architecture programme. Linksys also. Configuring an ancient Linksys guest wifi router, the router refused my 7 character WPA2 password: must be 8! The person who required 8 worked with me. Ahem
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Brook Schoenfield proslijedio/la je Tweet
As a thought exercise, before saying “The system is broken!,” instead consider that the system may be working exactly as designed. Instead genuinely ask yourself, “how that might be possible?” Doing so can be quite revealing.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Brook Schoenfield proslijedio/la je Tweet
If you're running AWS, you can automate checking your environment up against the
#CIS top 20 controls with this guide by@pacohopehttp://ow.ly/Cm8330q8kZaHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Wanna be a great security architect? The practice of architecture is your foundation! https://www.cnpatterns.org/development-design …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Brook Schoenfield proslijedio/la je Tweet
Security culture is how developers act towards security decisions when no one is looking.https://twitter.com/iamdevloper/status/1215221158808903681 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Brook Schoenfield proslijedio/la je Tweet
Your most important architecture decisions might be the ones you didn’t know you made.https://architectelevator.com/architecture/important-decisions/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Brook Schoenfield proslijedio/la je Tweet
Thank you to all who attended my "Hands-On Threat Modeling Workshop" today
@CodeMash 2020. It was the first time I walked through some tools in a workshop in a while and I hope it was helpful. Slides and examples here: https://github.com/rhurlbut/CodeMash2020 …#CodeMash2020#CodeMashHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Just talked to
@jayjacobs &@BenJamesEdwards about EPSS. EPSS could become a game changer for harried Ops folks managing backlogs of#CVE. There’s a need for some dev to operationalize. I suggest folks take a look:https://www.kennaresearch.com/tools/epss-calculator/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Key secure design pattern:https://twitter.com/jimmesta/status/1214278765259264000 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Where did this idea originate: security contribution measured by total CVE filed? That’s just dumb. Ignore anyone who asks for your CVEs. They demonstrate their misunderstanding of what it is that we do, how we measure it
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Counting CVE? What about all the incredibly skilled internal bug hunters? None of their findings which are often fixed before release will ever be assigned a CVE (and mustn’t).
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Of course, bug hunters can also help to remove exploitable conditions in running software. Also useful.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Research must improve secure design patterns. As
@adamshostack so wisely points out: design without critique cannot/will never improve.Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
The vast majority of CVE NEVER get exploited. Our’s is not a race to uncover potentially useful conditions. Period. I sincerely hope that total CVE is not a goal for researchers.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I might have missed the context? But assessing a person’s security usefulness based upon number of filed CVE? That’s a useless metric. Plus, such would discount the contributions of the vast majority of the industry.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Brook Schoenfield proslijedio/la je Tweet
You can’t vouch for your own bug. You will always see it as the most beautiful bug that ever did bug. Doesn’t matter if you’re the one who does the thing, or even if you’re right. If it needs a vouch, recuse yourself. It’s ok. It’ll hold up on its own, or not. Learn either way.https://twitter.com/kim_crawley/status/1213580904603492357 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.