@reporturi@Scott_Helme You mentioned that the customer had their password recently breached. Did they not have MFA?
Not enforcing MFA? You also offer Passkeys now.
If it was a stolen session, then the password wouldn't be necessary.
Assuming that's the part you want to cost-effectively improve on...
@reporturi@Scott_Helme You love to "roll your own" security controls, which you do well, but would you recommend others to use a 3rd party such as Okta instead?
To further improve your sweet setup, I'm assuming you need to implement/refine:
@haveibeenpwned@troyhunt Who is to blame here, with breaches due to the cPanel/WHM exploit?
Not much that could have been done to prevent such an 0day, right?
Exploited for months before a patch was made available.
I guess that’s why they voluntarily self-submitted, believing it wasn’t their fault…?
@TwilightZer0 Thought so… wish it will mention such on-screen.
Not sure if you have chanced repo source URLs too.
At the moment they are using the store apps with vpn, but was trying to see if AliveGr had updates itself.
Something I need to work on updating one day. Perhaps once v3 is out
@TwilightZer0 Will Greek channels work? Had become unreliable late last year. Had to move to store apps and get vpn for some channels (Rik, Ert)…
So check for AliveGr updates? And Kodi?
@Scott_Helme Some host(s) have not automated, charging £100 setup fee each time, to setup up their WAF etc…
Not sustainable. Been telling the one we are using to automate…