Grant Taylor

@DrScriptt

I like most things unix like and learning how they work so that I can add them to my toolbox for future endeavors. Check for my mainframe tweets.

Vrijeme pridruživanja: kolovoz 2010.

Tweetovi

Blokirali ste korisnika/cu @DrScriptt

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @DrScriptt

  1. Prikvačeni tweet
    24. ruj 2018.

    A couple of my colleagues and I are buddy reading the second edition of TCP/IP Illustrated, Volume 1 The Protocols

    Prikaži ovu nit
    Poništi
  2. proslijedio/la je Tweet
    31. sij

    When people ask "I am curious about mainframes, what should I check out?" the answer is always and

    Poništi
  3. proslijedio/la je Tweet
    prije 18 sati
    Prikaži ovu nit
    Poništi
  4. proslijedio/la je Tweet
    prije 18 sati

    18/ And when you know your stuff is safe, your next challenge is to convince your customers that you can be trusted, even though you’re just a startup. One tip there is to get experienced advisors to join you, validating your security process and vouching for you. Good luck! /end

    Prikaži ovu nit
    Poništi
  5. proslijedio/la je Tweet
    prije 18 sati

    17/ Make sure your developers can identify and fix the common security vulnerabilities. Then have your app security tested. Have your network pentested. Have your code audited.

    Prikaži ovu nit
    Poništi
  6. proslijedio/la je Tweet
    prije 18 sati

    16/ Make sure you exactly know who can move money in the company, and make sure they know how modern Business Email Compromise attacks work. These attacks are way more complex than traditional fake billing scams.

    Prikaži ovu nit
    Poništi
  7. proslijedio/la je Tweet
    prije 18 sati

    15/ Make sure you can change passwords and access rights as needed. It’s especially easy to get burned with shared passwords you use for your corporate social media accounts. Force a password change on public company accounts whenever someone who had access leaves the company.

    Prikaži ovu nit
    Poništi
  8. proslijedio/la je Tweet
    prije 18 sati

    14/ In the fast-moving environment of a startup, people come and go all the time. Make sure your people do not take their access rights with them. Make sure you can lock people out of your repositories and cloud systems.

    Prikaži ovu nit
    Poništi
  9. proslijedio/la je Tweet
    prije 18 sati

    13/ Update prompts are annoying, but almost always the reason for the update is security. So update your OS. Update your applications. Update your apps. This seems obvious, but updating can fail for surprising reasons.

    Prikaži ovu nit
    Poništi
  10. proslijedio/la je Tweet
    prije 18 sati

    12/ This happens often because online backups are deleted or encrypted by the attacker. This is why cloud backup and Time Machine systems alone are not good enough for backup. Have regular off-line backups that will survive even if your office building burns down.

    Prikaži ovu nit
    Poništi
  11. proslijedio/la je Tweet
    prije 18 sati

    11/ Ransomware continues to be one of the biggest problems we see. Recovering from ransomware attacks would be easy if you’d always have an up-to-date backup of your data. Surprisingly, many companies cannot restore their data when they are attacked.

    Prikaži ovu nit
    Poništi
  12. proslijedio/la je Tweet
    prije 18 sati

    10/ Do note that Mac users fall for phishing just as easily as Windows users — and iPhone and Android users fall even better, as there are fewer safeguards on those, and detecting a fraudulent lookalike URL is harder on a smaller screen.

    Prikaži ovu nit
    Poništi
  13. proslijedio/la je Tweet
    prije 18 sati

    9/ When I walk around startup events, everybody seems to be rocking a MacBook. Macs are great for security, but probably not for the reason most people think. As Mac market share hovers only around 10% , criminals keep focusing only on Windows with their attacks.

    Prikaži ovu nit
    Poništi
  14. proslijedio/la je Tweet
    prije 18 sati

    8/ Make sure everybody has their mobile devices locked by default (Face ID / Touch ID is fine). Make sure your people enable two-factor authentication where possible, with an Authenticator app. And do not force regular password changes on your users for no reason.

    Prikaži ovu nit
    Poništi
  15. proslijedio/la je Tweet
    prije 18 sati

    7/ At the end of your next all-hands dev meeting, open on the projector and let everybody watch for five minutes. That should do it.

    Prikaži ovu nit
    Poništi
  16. proslijedio/la je Tweet
    prije 18 sati

    6/ Actually, forget that. Just make sure all your developers use a password manager. Also, make sure everybody understands the risks of posting Private API keys to GitHub or pasting AWS Access keys to Pastebin.

    Prikaži ovu nit
    Poništi
  17. proslijedio/la je Tweet
    prije 18 sati

    5/ …but you need to use the cloud right. The easiest way to screw up with cloud servers or cloud storage is to lose credentials. Make sure your developers use strong, unique passwords on all cloud services.

    Prikaži ovu nit
    Poništi
  18. proslijedio/la je Tweet
    prije 18 sati

    4/ Most startups today choose to go for cloud services such as AWS, Azure and GCE. Amazon, Microsoft and Google are investing hundreds of millions of dollars into their security. Breaking into the servers that run the largest cloud providers is hard...

    Prikaži ovu nit
    Poništi
  19. proslijedio/la je Tweet
    prije 18 sati

    3/ Do not invent stuff which has been invented already. There are trusted and tested principals that will save you time and make you safer. Definitely do not develop things such as encryption or hashing algorithms by yourself. Just don’t.

    Prikaži ovu nit
    Poništi
  20. proslijedio/la je Tweet
    prije 18 sati

    2/ Speed is the enemy of security. The faster you move, the faster you develop, the faster you deploy — the less time you have for bug checking, quality assurance and testing. Security is not something you can add to a ready product, it has to be built in from the design phase.

    Prikaži ovu nit
    Poništi
  21. proslijedio/la je Tweet
    prije 18 sati

    1/ Practically every startup ends up writing code, even if technology wouldn't be the main focus of the company. Here’s a checklist I made to help you and your hot new startup avoid the most common infosec pitfalls. [thread]

    Prikaži ovu nit
    Poništi

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·