HN user

balgan

34 karma

[ my public key: https://keybase.io/balgan; my proof: https://keybase.io/balgan/sigs/g7YMuvjuHPbvh29aA46CJusNwLIxHrCPLlvDkft2i8Y ]

Posts34
Comments28
View on HN
rgb.day 5mo ago

Show HN: Guess My RGB – Daily game to test your color visualization skills

balgan
1pts0
www.balgan.world 4y ago

Observations on current state and future of metaverse

balgan
1pts0
www.balgan.world 5y ago

A cybersecurity view of Covid vaccine vendor chain

balgan
1pts0
blog.binaryedge.io 7y ago

Slides published on how to turn bluekeep into RCE – 800k+ machines exposed

balgan
1pts0
pastebin.com 7y ago

List of cybersecurity tools with blackfriday/cybermonday deals

balgan
4pts0
www.securityrating.io 8y ago

Security rating of domains

balgan
6pts0
www.securityrating.io 8y ago

Securityrating.io security rate of domains

balgan
8pts0
medium.com 8y ago

Security bug bounties: A broken system

balgan
2pts0
blog.binaryedge.io 9y ago

How are users choosing their passwords on the internet?

balgan
8pts0
www.securityrating.io 9y ago

Securityrating.io

balgan
3pts0
www.securityrating.io 9y ago

Securityrating.io

balgan
1pts0
securityrating.io 9y ago

Securityrating.io

balgan
2pts0
securityrating.io 9y ago

Check your IP Address security rating

balgan
3pts0
blog.binaryedge.io 9y ago

Check security rating of your ip address

balgan
9pts0
blog.binaryedge.io 9y ago

Wannacry is just the beginning

balgan
3pts0
www.binaryedge.io 9y ago

Show HN: Check if your ip has been infected with Doublepulsar

balgan
1pts0
blog.binaryedge.io 9y ago

Doublepulsar NSA implant detected in thousands of machines

balgan
2pts0
medium.com 9y ago

A guide to friends and family of a startup founder

balgan
1pts0
blog.binaryedge.io 9y ago

Lots of database technologies attacked by ransomware – updated compendium

balgan
6pts0
blog.binaryedge.io 9y ago

The compendium of database ransomware

balgan
6pts0
blog.binaryedge.io 9y ago

We scanned 36 ports across the internet and wrote about it

balgan
11pts0
ise.binaryedge.io 9y ago

Internet Security Report 2016

balgan
8pts0
blog.binaryedge.io 10y ago

Game of Torrents and Data leaks

balgan
6pts1
blog.binaryedge.io 10y ago

Security of a country: Portugal

balgan
5pts1
cyberfables.io 10y ago

Cyberfables – A mobile app to teach people about security using story telling

balgan
5pts0
blog.binaryedge.io 10y ago

Security of a state: Switzerland

balgan
8pts0
blog.binaryedge.io 10y ago

Data, technologies and security – part 2 – Data exposed and Redis hacked

balgan
6pts0
blog.binaryedge.io 10y ago

SSH – A brief analysis of the internet

balgan
9pts0
blog.binaryedge.io 10y ago

Patreon Leak Analysis

balgan
9pts0
blog.binaryedge.io 10y ago

VNC, image analysis and data science – part 1

balgan
11pts2

Hey

Yes the group will continue to meet and I believe more will come out overtime as we start to better define how we as private entities can help the gov.

Ransomware and attacks on critical infra were the big ones - Joshua our CEO wrote a bit about it here https://www.coalitioninc.com/blog/coalition-meets-with-presi...

- our baseline is internal. We are with our customers end to end. From selling the policy to scanning them, notifying them and we have our own incident response team which means that we learn a lot with every claim. So when we add a vulnerability in critical state in Control you can assume it came from learnings of losses combined with our cybersecurity expertise.

The great thing about insurance is that we don't just get to create baselines our policyholders must adhere to, we also get to enforce them. A perfect example of this is anyone that has a policy with us must have RDP behind VPN/ whitelisted only to specific IPs. I spent years trying for free to convince orgs to do this and was ignored, here we convince all our policyholders to do it and everyday more and more companies as we onboard them.

For backups, not only do they need to have it, they need to be tested, kept offline and encrypted - this doesnt apply to all its split by revenue bands/industry/mix of other logic.

IoT devices - they get notified in Control if we find any on the internet and told to not have them directly exposed

Director of Engineering - Security from Coalition here (we participated in the event) - We committed to building more free security tools for all organisations to protect themselves. We’ve already made Coalition Control our Attack Surface discovery and monitoring platform free (https://control.coalitioninc.com) and we will continue to add more features and more tools for free there. If there are any questions,I am happy to answer them!

There are multiple parts to the underwriting process (full disclosure I run the team that does data collection and security at Coalition where the op you're replying to works). Part of the data we collect is used for risk selection (do we want you on our book?) and then other piece is used for pricing and thats where technologies, providers and a lot of other things come in! Lmk if u have any questions!

Hi, person responsible for the teams that do this at Coalition! Anytime you get a quote from us, we scan all your domains, subdomains and ip addresses. We hit the main ports that might have services running we know are dangerous and your quote might come back contingent on certain actions, for example: if you have Admin panels exposed to the internet we will require that you put them behind a VPN. We give you a PDF that describes all our findings and how we did the association with your org. If you become a policyholder we offer perimeter scanning and notify you when we find weird stuff and make security experts available at no cost to help you fix things! You can read more about it here https://www.coalitioninc.com/blog/analyzing-policyholders-te... though what we do at underwriting time has substantially evolved since. Ask me anything here or on twitter @balgan

Hi!

1 - Its scanning 200 ports

2 - Indeed atm we just provide an overall view, we intend to improve this tool further. We had too many people requesting us custom scans when Doublepulsar came out.

3 - True, please submit an issue on the github so a discussion about this can be started. We like having an open formula that people can change/comment on.

4 - Scans are from last 2 months and will keep changing accordingly. It queries our database rather than doing an active scan!

- For IPv6 rather than scanning the entire space, we are currently passively collecting addresses from multiple sources and scan specific addresses

- We wouldn't use shodan as we developed our own custom scanners and methodologies of scanning to increase data quality which is extremely important for our customers (cyberinsurers, SoCs, cyberrating companies). We also do some specific things with data which you can check on http://blog.binaryedge.io/2016/11/18/bsides-lisbon-2015/

We will add this information, but essentially we and other partners have seen a high quantity of torrents infected with malware. We intend to fine tune this in the future to differentiate the torrents depending on category!