HN user

rattus

3 karma

rattus.org

[ my public key: https://keybase.io/rattus; my proof: https://keybase.io/rattus/sigs/oFiw4HdZKY9uMO46O_MSOMWHsthAyEQCbmeKnKwJBWs ]

Posts0
Comments12
View on HN
No posts found.

Vilification of discovery scans in 2012. Weird.

Yes. Appstack is totally the way to go if you're an app pen guy. Shocking.

Portscanning not too useful in a whitebox pen assessment, sure.

Don't do it at all because blackhats "don't do that"? Not really. Just make sure instrumentation and response exists for both of these cases.

Pen guys don't want to perform an assessment of the environment to gauge targets but instead just break out the same kit for each engage? Sounds fine if it works for them and leaves more things to discover to the next crew that wanders through.

Sounds like more "pentesting isn't compliance" drum beating, which is both good and bad.

If you're asking social engineering questions, you're already pretty well equipped for poker.

My picks in this realm were Hold'Em Poker for Advanced Players by David Sklansky and Mason Malmuth (which seems to be out of fashion now as it dictates a pretty tight game) and also Mike Caro's Poker Tells book is quite good about the most common types of tell behavior you will see at tables and tourneys. It's up to you to determine if they're real or if someone is putting on a show.

I wish I could learn all over again :)

Silent Circle appears to be for people who both

1) Want military-grade(ish) hardened coms

and also

2) Aren't willing to set it up themselves, but trust a service provider to do it for them

I read their docs a bit ago and don't really get it. I didn't really get Whisper Systems offering either as it appeared to have a broken trust model on a variety of levels.

If I cared about this kind of thing, and I really don't, I'd likely want to own all parts of the transport system and have the only available threat surface be the encryption algorithm as much as possible http://www.voip-info.org/wiki/view/Asterisk+encryption

Might it all be pointless without massive amounts of traffic padding based on this attack? I wouldn't know. http://link.springer.com/article/10.1007%2Fs10207-010-0111-4...

He demonstrated a proof of concept, collected data, and went to journalists. Cherry picking irc logs for things for possible uses of the data is weak because they have a weak case.

Arguing about methods of responsible disclosure, a very dead horse that has been beaten to dust, seems like a waste of time and not really relevant.

This is just the endgame of the chilling effect of arresting and hounding researchers which has been going strong ever since 2001 http://news.cnet.com/2100-1001-270082.html

Many others have read the published books and incorporated the same in their processes.

I had a series of interviews that was all logic questions with a trick that you had to decode to successfully answer it.

It's cute, and everyone gets to feel really proud of themselves if they can solve an applied prisoners dilemma for the answer everyone in the room is looking for, but it's not relevant to the performance of any position that I was being considered.

I'm involved in a lot of interviews and I think the problem is getting worse. Taking all of your questions from a certification exam, constructing a bubble sort, or talking about why manhole covers are circles might be satisfying to a bad interviewer, but does no one a service IMHO.

I'd suggest diving deep into past work experience and ask them to show you something that they have done well so that you can understand the utility that they provide. Very few people that I encounter do this and then try to pound round pegs into square holes.