As a current security engineer...I can concur as well
"No text-based MFA is not sufficient..."
"Yes you'd have to download an app."
"Yes....an app on your phone."
"No, we can't track you."
"NO WE'RE NOT DISABLING LOGGING"
So happy I got to experience #DefCon30 & extremely grateful for a unique experience @sec_defcon was able to provide. Competing only added to the experience and we're already planning next year's trip. Thanks again @_sn0ww,@JC_SoCal, and your whole team of bandits. #DC615
Congrats to team Spilt Beans (aka Split Beans) for taking home the @defcon black badge for vishing at @sec_defcon competition! This was my favorite #DEFCON30 village, hands down!
Itβs true. OAN was indeed banned. I can confirm because I saw it go down.
I was at the voting village yesterday afternoon when I noticed Chanel Rion approached a table with 2 hackers diving into a vote tabulator. Her cameraman was near by.
She started asking them questions 1/n
I'll be at #defcon. If you want to meet up I'll be at the pool at the Linq 10a-4pm tomorrow (Thursday). Go get your badge then come hang with me. You can say you're with me if they ask.
@_sysengineer Anywho, remote user gets machine, hardwires a net connection, sees it doesn't recognize her username, and assumes it's broken. New machine is shelved with the power brick & net connection still plugged in..
..calls in 6 months later to complain about her old machine dying.ππ
@_sysengineer Story time:
No pic, but mine was ~6months for an endpoint. Before better help was hired for a client for stricter compliance adherence, new machines went out without much regard to the dated/OoW ones. Naturally, sales users hate change or LOB interruption because, well, $$$...