“No practical definition of freedom would be complete without the freedom to take the consequences. Indeed, it is the freedom upon which all the others are based."
@drethelin Little of both. I have definitely encountered scammers; every good dentist I've ever been to has told me my wisdom teeth are fine, and every time I move it takes three tries to find a dentist thay doesn't tell me they do and I should go to a very specific oral surgeon for it.
@patio11 I had a similar issue once, after much troubleshooting the third tech on day 3 went down to the junction shed down the road and called me going "....so I found the problem, someone pulled the jumper off your line to use it somewhere else"
@LauraMiers@kristinaEBP From experience unless you subscribe directly to the lists from the gov agencies to get notified the odds of hearing about the vast majority of recalls in the US are basically 0
@techspence We also need more tools built with these concepts from the ground up to make it easier to implement them too. Entra is making strides, but in a lot of environments it's still tacking a bunch of stuff together to make it work.
@0xTib3rius I think a lot of my skepticism of the claims that the security side will get better comes from the fact that static code analysis tools have existed as their own market for a long time, and they still can't detect a lot of this with 100% accuracy.
@0xTib3rius If you've got an LLM that you claim definitely will never produce SQL injection, then inherently *on some level* you're claiming to have created an analysis tool that can 100% detect SQL injection, right?
@bettersafetynet Thats probably between 40 and 60% of the reports I've seen. Special callout to the one not too long agk where they included a vuln scan finding *and* the fact that they had tried to exploit it and failed and concluded it was a likely false positive (it was)
@SwiftOnSecurity But if you don't explain that, and how the thing works, and the methodology of *getting* to that point naturally in favor of just fixing the problem (because you're experienced and want to get back to 'more important things'), then they just learn that's the thing you poke first
@SwiftOnSecurity It's one of the easiest traps for someone experienced to fall into, cause it's obvious why I went straight to this thing over here, right? It's always that. Except it's not, it's that I've seen this same problem 300 times and 200 of those it was this, so that's the first check.
@SwiftOnSecurity Since no one had ever explained what they were doing they had assumed the guys who fixed it were just trying stuff. I see the same issue in numerous areas - if experienced people dont explain why, you end up with a sort of cargo cult problem.
@SwiftOnSecurity I used to teach black box troubleshooting techniques to audio students and it was fascinating to see people learn.
One of the more interesting things I discovered was that a lot of them were just doing what they saw people do, which to them was just try things.
@blackroomsec When I owned endpoints at one point we had to post a notice reminding everyone that a fork was not an appropriate tool with which to attempt self-repair of your USB ports.