Even after so many years in the IT and CyberSec spheres I still get a little caught off guard when people whole heartedly believe a single process or product being implemented means you're secure.
Hosted my first public training session last night. The session focused on identifying common online scam tactics and was hosted at a library. It was scheduled for 45 minutes but I stayed for 2 hours just answering questions. It was great to hear people engage with the topic.
Today's a great day to make even a small step to improving your personal security or privacy. Do a password audit, switch to a more secure app or service, delete some unused accounts, make the move!
Seriously its like:
Cyberspace Royalty Outreach Success Manager
Must know how to engineer in all the clouds.
Must do on call break fix IT repair.
Must have 30 years experience as CISO at Google.
Must make coffee for the office.
Hybrid (1 day from home)
$25 per hour
#CyberSecurity job postings are so strange to me. If they can't fit you into an Analyst or Engineer job you suddenly start getting some WILD titles and responsibilities.
@blackroomsec ... That network segmentation is good enough to say something is secure. I think that's a good example of someone who is great at their job (network segmentation is tricky and can be complex) but doesn't necessarily see the cyber security big picture.
@blackroomsec For example you may work for a security focused MSP but I'd they hired you to do a specific job (ex: marketing) they may hire your for your capabilities in that space not as a security focused hire.
I've had conversations with infrastructure teams who are absolutely convinced...
@SecurePeacock I've had a lot of arguments in my career related to scoping. A lot of times it feels like scoping down to a limited subset of services, machines, or processes for an audit makes turning a blind eye to other bad behaviors outside that scope more palatable due to lack of auditing.
@snyksec Thanks for the reply but to be clear the link provided does not work. It goes to discord but drops me to a dead page that says I don't have access to any text channels.
twitter have rolled out audio calls on twitter using STUN.
Be warned if you call someone the recipient (and anyone in the traffic path) can see your egress IP.
Apple private relay does not cover this.
Hot take: If you are running a CTF and you have multiple complaints about not receiving the access info by the day of, sending people to a discord server that requires you to have the access email in question to gain access for support is probably not a great idea.
@snyksec Also this link won't work unless you have the email they sent for the invite. The link in the email brings you to a slide to select what channels you want to join. So if you are joining to get support for gaining access you won't be able to get support.
@snyksec To anyone trying to get it we ended up resigning up with private emails instead of our business ones. We immediately got the invite and got in. Not sure if the system used to mail out the invites is on a major blacklist somewhere but it seems corp emails don't like it.