Cybersecurity is a broken industry. We rely on products that were designed to be sold, not used. And the incentives are completely screwed up.
I made this video about all of the ways things are bad, how we accidentally make it worse, and why new technology won't fix it.
In you missed it (I did, I don't know how), Microsoft is aiming to phase out UAC and replace it with a more secure thingie called "Administrative Protection".
They're doing this because UAC currently has over 81 bypasses and, for reasons unknown to me, Microsoft decided to scrap UAC in totality and redo the entire thing from the ground up. Why? I have literally no idea. Maybe you stinky nerds can educate me.
AP is now in preview mode for Windows Insider builds (testing stuff). Big brain security researchers from Google Project Zero poked it with a stick and discovered eight vulnerabilities that allowed them to bypass AP. Microsoft has since patched it. AP has yet to be deployed to Windows 11 as of this writing.
AP on paper, when reading about it, seems like a good idea and seems like it unironically would be a massive security improvement for Windows. However, the new architecture would bamboozle some legacy applications. Making it work with older stuff will require lots of science from Microsoft. Additionally, and maybe I'm being a bit pessimistic, I am concerned Microsoft will vibe code slop their new security module and make it one massive cluster fuck disaster.
Please read the research performed by Tirando (can't find his social media profile) and the other nerds at Project Zero. It's interesting. They're all very talented security researchers and make feel like an imbecile.
https://t.co/o2JleSUzWw
@Secure_ICS_OT We also need companies to be hiring vs laying off/downsizing, and changing from "shareholder value focus" to what is integral to the business.
@RobTerrin Buying Vanta and compliance tooling makes more sense too, and building integrations into all cloud tools, SOAR and IR. But this... Seems like a hail mary - it's almost like SNOW is having issues getting data to it's existing features. If so, will this solve it..imho, no.
@RobTerrin Feels a bit Microsofty - buy various products, don't execute (or take forever to GTA). It also feels like a bad vision/let's buy to buy - it would make more sense for Cisco to buy, eol a competitor, and build an integrated AM/IDS system + Splunk offering.
@furt_tech After PHP 5, and when it became object orientated - the world changed. But also, we are from God's language land (c) so... We know never trust anything typed or not... So also a reason for us
@shehackspurple The harder question... How do we get people who did write software before, and now are vibing... To care about security? (Actually quality/engineering but I digress)
@P4LSEC Probably accurate. Make sure it has solid ventilation and you constantly clean for dust... That's been my secret with even the Korean stuff (LG & Samsung are shite these days too)
@Turbo81 The fascinating bit. We will be slaves to AI, but AI needs power, so we make the power. But AI consumes more power, literally and figuratively.