#DEFCON Evacuation Update, 8am Sunday Edition:
Last night we were asked to evacuate the building due to a report of a suspicious package. Local police and fire departments conducted a thorough investigation and ultimately determined that the package was safe. They also conducted additional sweeps of the building as a precaution before allowing our team to return and prepare for today’s con.
We are working quickly to keep the original schedule on track, but please check here for additional updates before arriving at DEF CON in case we need to notify you of any changes to the schedule.
Organisations, regardless of size, can only patch about 1/10 vulnerabilities per month. Thus, “patch harder” is now proven bad advice, your only* gains are to prioritise patching of exploitable vulns. This is one of the conclusions from @wadebaker’s team in their epic report (available at https://t.co/yUW1tmf14h).
The below graph shows a strong correlation along the 1/10 line which means you’d have to do something extraordinary to break out of it. Explained with much better statistical rigour by Wade on LinkedIN (https://t.co/vprlPcU7TF)
It’s advice that’s been given for over a decade by the @sensepost team, but now there’s finally strong data to back it up. Thanks @cyentiainst.
* assuming a non-negligent patching regime
@FrankEijsink At the same time if I compare to how Japan drivers striked (by not charging customers) compared to NS, I don’t think this is how they can gain empathy and show customer care even in difficult times.
@FrankEijsink Next to that I decided now to use only car to go Schiphol as I have zero confidence in NS which I had always low confidence in (delays, cancellations, filthy trains, etc). I agree that thanks to technology the need for travel is less. /2
@bugch3ck @shad0wbits Looks like I missed that one. There are indeed hundreds of AS400 internet accessible. While QSECOFR is protected, usually QPGMR or even QUSER might be your best friends to get in.