#infosec in industrial control systems _can_ work. But only if you’re willing to learn. Traditional IT-centric tools can halt operations (& more catastrophic consequences) in a plant.
But partnering with engineers & operators can lead to sustainable OT-specific security. Try it!
We wrote an enormous report about what we found, which we’ll release after the holidays. The TL;DR is kind of depressing:
Authorities don’t need to break phone encryption in most cases, because modern phone encryption sort of sucks. 3/
It’s easy to toggle permissions for phone apps @pgmaynard thinks there should be an easy #opensource option for computers #cybersecurity
https://t.co/wOgO4Mdkj7
The schedule for the eBPF summit is now available with an amazing line-up of speakers as well as an extraordinary lightning talks session. Make sure to register in order to attend.
https://t.co/9cATPXoLQC
Well, it was accepted 'Big Fish, Little Fish, Critical Infrastructure: An Analysis of Phineas Fisher and the 'Hacktivist' Threat to Critical Infrastructure' - https://t.co/EmstF38ZU7. Added you guys into the acknowledgements (@riskybusiness, @Metlstorm)
@riskybusiness@Metlstorm - Writing an academic paper on Phineas, and how she's the new hotness in ICS security - you guys motivated me, lets see if it gets accepted, oh and of course it will have ATT&CK. (Looks Like Disney plus are friends with Phineas Fisher.)
Public message to ransomware gangs: Stay the f away from medical organizations. If you target hospital computer systems during the pandemic, we will use all of our resources to hunt you down.
@edking2 just read your medium series, Namespaces in Go. (Learnt a lot) If you were to develop an application from scratch, that plans to take advantage of sandboxing. Would you advocate using Go, or an alternative that allows you easier access to lower levels of the OS?