HN user

adricnet

138 karma

I've been reading HN for over a year. I now have an account to see what that's like.

More about me at http://adric.net

[ my public key: https://keybase.io/adricnet; my proof: https://keybase.io/adricnet/sigs/pckfHDbj28D371GY2Wvt2EOt5IiEVsGi0L9zdHmjutk ]

Posts0
Comments104
View on HN
No posts found.

Thanks for the share this looks great!

It aligns quite well with the study (in diagrams and commented assembly) of x86 in POC || GTFO starting in pocorgtfo04.pdf chapter 3 provided by Shikhin Sethi.

I do agree. That's actually part of why I called out the language: maintaining balance (as well as not cussing in front of the wrong people) are critical skills for security professionals and sorely lacking in many would-be candidates.

His educational advice was good but the attitude he shares via diction is unhelpful at best especially to folks who do not _yet_ have an awesome job in infosec.

Thanks, have a great weekend, cheers,

adric

The advice is pretty good overall, but the excessive profanity is unprofessional and distracting.

It is interesting that he values "SANS" certifications, but not the courses for them.

Besides my own rambling[1] you might find these resources valuable instead:

* https://tisiphone.net/category/security-education/

* https://krebsonsecurity.com/category/how-to-break-into-secur...

* https://s3ctur.wordpress.com/2017/06/19/breaking-into-infose...

[1] http://dfirnotes.net/ etc.

hth,

adric

_The Week_ is quite good (US or UK). They have people read many of the things you don't have time to (including _The Economist_ :) ) and pull highlights from them across a broad range of topics.

Yes, but that was consumer / education market gear first (iMac) as I recall.

More or less back on topic ... I bought a HP Probook for my on-the-road studies/work last cycle because I needed a portable that I could do _work_ with and repairability, matte screen, mouse buttons, VGA, HDMI, and whole lot of other things were much more important to me than width or mass or shiny. It came with Windows and it's well supported.

I would like to get another 17" macbook pro someday (mine is pretty old and 80% retired), and this move and the messaging around it suggests that Apple doesn't care to make one. It's no surprise, but it still stings a bit, and as noted else where it is breathtakingly clumsy for their remaining mac business (as is that press conference).

In line with the principle of charity I'd like to point out that your declaration here that network IDS provides only "minor cost savings" is controversial to the point of almost being aggressive towards folks working in information security. In the same vein, I'm simply disregarding the politically charged motive you assign to the technology.

If that was your intent (to start a political argument), then so be it, but if instead of picking a fight you would like to understand the problem space better there are plenty of smart folks on HN and elsewhere who can provide use cases and data ... to say nothing of vendors who will argue from either side depending on what they are selling.

hth, adric

Speaking vaguely on purpose without sources (apologies), the folks who were concerned about weapons targeting a few decades back had no expectation that any part of the greater metropolitan Atlanta area would survive a nuclear strike.

The historical maps are still around and might be FOIA'able from US gov or others. shiver The doctrine and culture around MAD is, even a few decades on, really quite frightening.

The content is available after it is decrypted in a browser on a single host. If the streams are inspectable by network defenses they can be inspected at much more feasible scale allowing one device to protect 10,000s of hosts from the same malware-laden ad. The alternative is to try and deliver protection to 10,000 browsers, and somehow keep them synchronized which is just so much harder and expensive. Or you could make the host operating system, apps, and the browser resistant to exploitation...

It's not that encrypting secrets is bad (and sessions are secrets). It's that encrypting everything without looking at what you gain and lose is poor engineering and it all seems to be politicized somehow (camps, factions, dogma..) with HTTPS-only being pushed as the answer to one security problem (confidentiality vs active eavesdroppers) at the expense of existing solutions to other problems, including integrity (please don't compromise my hosts), availability (I cannot use recent browsers to admin my equipment because they ban self-signed certs but trust 100+ CAs) and non-repudiation (where did the malware come from?).

... speaking as someone who studies malware analysis.

Cheers, adric

Yes, especially when they seem to affect their applications.

Automatic updates are easy (mostly). Healthy software and vulnerability management that doesn't damage productivity needlessly can be a lot of work. What do you test?

The classic simplified use case for this is Java runtimes: Your organization needs: a) A specific Java version to run a critical application b) Not to have workstations compromised though weak Java versions.

As a technology and security professional in this space your objective is to meet both of these goals. As the application developer you may have totally different goals (release date, market share, sales, renewals) and may not have these on your map at all...

Okay, so looking over the post they didn't feel like CVSS 2 was giving a clear indication of risk, and CVSS 3 isn't done yet and lacks perfection. That's sensible enough, I suppose.

I hope they took more than a glance at what some other vendors are doing (EG Microsoft) before adding to what can already be a confusing collection of incompatible qualitative ratings :/

As noted by other commenters here a vague description of the category and some idea of the global risk, with a spot for you to add local risk seems a good tool here that serves both attack and defense with some balance. Oh, wait, we have that already in CVSS!

edit: spell acronyms right!

I scanned this before coffee this morning and in short I'm not sure anyone else should read it in its present state.

Although the author poses some interesting ideas the piece feels long and muddled and I'm not at all sure who the audience is or what the call to action might be. Voice is unclear as some paragraphs are personal statements ("I") and others are observations about culture and economics.

It might be more powerful if it was drastically shorter and simpler ... or maybe if it was three times longer with more references and a stronger set of recommendations. I really can't say.