security
1. you can't secure something if you don't understand how it works (to a reasonable degree)
2. people like setting rules not following them
3. people like rules for others but not for themselves
4. securing infra is more difficult if it's not been deployed in a 'reasonably safe' state to start with.
5. securing something in use is much harder than doing it in a lab
6. data is like oil, it gets everywhere
7. most security is about good organisation, most people don't like admin work so they tend to not like being organised
8. you can't control everything, you have to understand that 100% security isn't a real thing
9. monitoring costs money and hopefully you never really need to use it
10. if someone is doing response they need authority to take action otherwise you are just watching a car crash and saying: oh dear
A great X feature would be creating groups for accounts I follow (like Bookmark Folders). Add options to view a feed of the group's latest posts and take bulk actions (e.g., notifications, unfollow). #XFeedback@X@engineering
I’m wondering if the new car design has negated the benefits of the slipstream. This could have a negative impact on F1’s “closer racing” goal. Pretty wild. #F1#BahrainGP
One of the biggest differences I regularly observe between high and low performing SOCs: expectations surrounding the burden of evidence. Assuming the correct question, analysts achieve an evidence-based answer. 1/
@AccidentalCISO I often point out that IT’s mission is to implement tech securely to meet business needs and security’s mission is to protect the organization from harm via tech. Usually sits well with IT. They often don’t understand we have different missions.
A threat actor can choose speed or stealth, but a defender can remove stealth as an option.
Hypothesis: threat actors forced to choose speed will make more frequent mistakes and reach a decision point they cannot answer quickly enough, resulting in their containment.
So excited to announce the BSides Security Conference in Bryan/College Station, Texas. I am helping to run and plan this event. The CFP is open through December 31st! Please submit if you are interested and help bring a cybersecurity event to this area!👩💻👨💻
Finding the real IP behind Cloudflare has never been so easy. Here you are a tool to search on @shodanhq starting from a simple favicon
https://t.co/HAGJo6fuWi
#OSINT
@QW5kcmV3@thegrugq Agree with you both. Being detected isn't necessarily a mistake. When put in undesirable operating conditions, they have to make a decision to accept the risk, even if it means being detected. So I see it as: the more risk they have to accept, the more opportunity for us.
Video summary from the 2019 @SANSInstitute#SOCSummit
https://t.co/mLLBtScT6H
Please retweet, and those who were present (or attended the webcast online) share your own #TODO action items.