@OrwellNGoode We I.T. folks have manual door locks, no appliances on the WIFI, no ring cameras, no Alexa or Google Home to listen in all the time. We use VPN's, nothing with windoze on it, and custom firmware on the router. If we, the experts, do this; ask yourself why that is.
@WigglePig @synx508@devnetsecops@alexbloor Those policies are designed to appeal to specific voters, who believe that education was better back in the good old days, when it was all exams. They're not based on any evidence of what works better from an educational point of view.
@PBulteel@_chrisdunne@Scott_Helme Yes waiting for the software to be updated to incorporate an Acme client is the fix. The post I replied too suggested you could magically fix it by moving your software to the cloud.
@Scott_Helme@_chrisdunne@PBulteel I'm not saying that any of this is bad, will personally be really happy when we are at 45 days and it's all fully automated. Just pointing out that the change here will impact orgs with lots of Enterprise IT solutions faster than the software will adapt.
@Scott_Helme@_chrisdunne@PBulteel It's not really a public web site problem, that stuff is easily automated. However most Enterprise IT is web based these days, and because of the changes in the browser UX, you have to use TLS for everything internally these days to avoid the warnings etc.
@Scott_Helme@_chrisdunne@PBulteel These are certs so that business users can access the non-admin functions of the software via a browser. It's basically a web app, but comes as a packaged piece of software. I've seen products that don't provide a key, just generate a CSR for you to take to your CA.
@PBulteel@_chrisdunne@Scott_Helme My concern is the software that's been designed in a way that makes it near impossible to automate cert rotation. Given typical software release/upgrade cycles, IT teams are going to be stuck picking up the burden with those systems in the short term.
In April, @samwcyo and I discovered a way to bypass airport security via SQL injection in a database of crewmembers. Unfortunately, DHS ghosted us after we disclosed the issue, and the TSA attempted to cover up what we found.
Here is our writeup:
https://t.co/g9orwwgoxt
@Scott_Helme@stebets@troyhunt@reporturi You're both talking to somebody who has to live with it, rather than someone who writes the policy. Amusingly, the parallels with IT security are massive. Having to request permission before being able to gain privs, because there's a risk, so somebody wrote a policy.