We are happy and proud that some of our specialists joined the national team of Poland in this greatest cyber-exercise in the World! Congratulations to all teams! 👏👏👏
Spread the word! We just released version 1.1.0 of the #OWASP#MSTG. We would like to thank all of our contributors for their hard work!
Come and check it out at https://t.co/3wRyZNMNw4 .
@certbund The main issue with the MS telemetry is that you CANNOT DISABLE it, if you let your MS hosts to use automatic updates. Of course, you can blackhole IPs, disable services, follow hardenings etc. But a single update can add a completely new telemetry mechanism you have not foreseen
OK I'm not sure how I missed this, but it's great – a collection of more than 300 vulnerabilities in Linux software, *with* test cases to reproduce and a VM environment with the right version of the software installed! https://t.co/511sv9zjKy
@Fox0x01@roadsec Awesome presentation, thanks for sharing! Helps to realise why some people (myself included) find themselves much more productive when working at late night rather than during a day - not a 'night owl' style of person but the state of 'no distractions' is the key to deep work.
@MirekMaj @jbswiatkowska @KrzysztofSurgut Dlatego na całym świecie jest tylko garstka firm, które są w stanie realizować tego typu badania profesjonalnie. Może właśnie takimi obszarami powinna zająć się @enisa_eu? W końcu zapewnienie zaufania do sprzętu leży w interesie całej Unii Europejskiej.
@MirekMaj @jbswiatkowska @KrzysztofSurgut Tak, ale takiego know-how nie zbuduje się niskokosztowo, jak np. w przypadku RE software'u czy pentestów. Sam mikroskop elektronowy to minimum $100K i to początek kosztów. Nie znam firmy, która by chciała wejść w ten obszar nie widząc szans, że on się zwróci.
@jbswiatkowska @KrzysztofSurgut@MirekMaj Ustawa ustawą, ale jaka instytucja w PL będzie gotowa ponieść koszt rzędu setek tysięcy PLN lub nawet kilku mln za profesjonalne badanie hardware'u? Podczas gdy np. MSW lub MON ma braki w podstawowym uposażeniu?
@jbswiatkowska @KrzysztofSurgut@MirekMaj Inżynieria wsteczna układów elektronicznych o dużym stopniu złożoności (np. procesorów) jest możliwa, ale KOSZTOWNA. Wymaga specjalistycznego (i drogiego) sprzętu i zbudowania know-how, które jest niedostępne na rynku. Inwestycja - kilkanaście lub nawet klkadziesiąt mln zł?
@jeremiahg Even in the case of confirmed breach, people cannot truly know what data about them was stolen. Privacy in the cloud does not exist - most people just do not realise that.