this goes out to the stoic non-posters
every day this app presents you the worst, dumbest takes ever conceived
every day you resist the urge to dunk on them, breathe deep, and scroll past
stay strong soldier
Cybersecurity is a team sport.
If you're playing the blame game with IT instead of figuring out how to work together to incrementally improve security, 2010 called - you're needed there.
Folks it's 2024 and the new NIST draft for digital identity is asking you to STOP the madness of 30/90 days password resets and moving it from a
recommendation โ to a REQUIREMENT
Microsoft admins here's what you need to do:
โ Turn on risk based conditional access policy
โ Stop periodic password resets
= Reduced help desk calls + happy users
It's a win, win.
If you are not licensed for Entra ID P2 then you can still use the logs and trigger a workflow to get your users to change their password.
Thanks to @blackroomsec for the call out.
I remember when I had to audit the Yara we were running because of resource usage costs. And I pulled the logs of who had what rules and how many. One of my analysts had over 700. When I asked him about it, he said, โYeah. And every one of โems a bangerโ
At some point either cybersecurity is an essential industry of incalculable societal infrastructure importance and justified public interest, or itโs a luxury. Pick one.
1995: After writing the initial version of the yet-to-be-released SSH, Tatu Ylonen emailed a request to IANA for SSH to be assigned port 22, receiving approval and assignment mere hours later. Yes, people of 2024, 29 years ago that's how things got done!
โIโm going to try to get this AI to make me fall madly in love with it so we can prevent it doing that to someone with privileged access to critical infrastructure.โ
โOops it worked!โ
*badges into AI server room*
@MalwareJake My flatmates have youtube open while they game.. half of the movie trailers/video game videos they have been excited for recently are AI fakes... and i have not the heart to break it to them
Cool trick I learned from @0gtweet today: you can look up windows error codes, even in the -DEC form instead of hex, via certutil ๐คฏ Dont know if this was common knowledge but I used to convert it to hex and google it everytime