Partner & National Public Sector Cyber Leader at KPMG Canada || Friendly neighborhood cyber-man, always preaching #pragmaticsecurity || Views are my own
Please keep an eye out for misinformation and disinformation on Twitter — particularly during times of crisis. Only share news from trusted sources, and don’t tweet any news that isn’t confirmed by reputable news organizations.
Great summary on how misinformation spreads rapidly via social media. Our human instinct to correct falsehoods is actually what drives more interaction, which in turn gives it more (perceived) credibility.
TLDR: Don't engage!
Just got off phone with a client. Log4j is in their network. Vendor claims patch will be available next release... which is multiple months from now.
Here's what you do if you're in this situation.
1. Keep calm. There's no need to panic.
2. Carefully read this thread.
1/?
Many non-Indigenous people will be acknowledging Orange Shirt Day for the first time this year.
So I wanted to share a few important points / thoughts:
For the record – Zero Trust is a real thing and overarching philosophy. But of course vendors will turn anything into meaningless soup. It's architecture not product-based and you can't just implement it.
Realized that I haven't used the Twitters in a while, so what better day to sign in and say one important thing: Please vote! #elxn44vote
And if you're still not sure about who to vote for, you can always follow these wise words:
@iamcelinacc This month alone has been so devestating and heart-breakingly painful. It pains me even more to think that this is just the tip of the iceberg. Our country has a ton of work to do.
@MichaelKlubal@jaimieboyd Thanks to you both as well! Had a great time. I think we all need to share successes and failures more across sectors so that the entire country can benefit from these learnings!
Great thread on app privacy. He's bang on about the silly conspiracy theory that your phone is "listening" to you...it doesn't have to, because you already give it so much other valuable information anyway!
I'm back from a week at my mom's house and now I'm getting ads for her toothpaste brand, the brand I've been putting in my mouth for a week. We never talked about this brand or googled it or anything like that.
As a privacy tech worker, let me explain why this is happening. 🧵
1/ Unless the USG dramatically changes its approach to reviewing software, just doing more "vetting" of vendors will be 100% useless in catching issues like SolarWinds.
Currently, it's all designed to raise the "floor" and avoid table-stakes stuff.