GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    hanno (hanno@mastodon.social)'s status on Friday, 19-Jul-2024 21:23:30 JST hanno hanno

    Let's cut the bullshit and spell out a few things. The IT security industry is about as trustworthy as the food supplement and vitamin industry, but somehow they escaped the same reputation. Their products are overwhelmingly based on flawed ideas, and the quality of their software is exceptionally bad. And while not everyone will agree with the harshness of my words, I'll say this: Essentially everyone in IT security who knows anything in principle knows this.

    In conversation about 11 months ago from mastodon.social permalink
    • Embed this notice
      Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Saturday, 20-Jul-2024 03:19:43 JST Jake Hildreth (acorn) :blacker_heart_outline: Jake Hildreth (acorn) :blacker_heart_outline:
      in reply to
      • Bálint Szilakszi
      • Ash_Crow
      • MarvinFreeman
      • LinuxUserGD

      @MarvinFreeman @Ash_Crow @HugeGameArtGD @szbalint @hanno It’s not packaged with or pushed by MS; it’s just the best EDR.

      In conversation about 11 months ago permalink
    • Embed this notice
      Ash_Crow (ash_crow@mastodon.social)'s status on Saturday, 20-Jul-2024 03:19:44 JST Ash_Crow Ash_Crow
      in reply to
      • Bálint Szilakszi
      • LinuxUserGD

      @HugeGameArtGD @szbalint @hanno it's still caused by a third party software. Had they broken their Linux updater instead of the Windows one, we would get kernel error screens.

      In conversation about 11 months ago permalink
    • Embed this notice
      MarvinFreeman (marvinfreeman@mastodon.online)'s status on Saturday, 20-Jul-2024 03:19:44 JST MarvinFreeman MarvinFreeman
      in reply to
      • Bálint Szilakszi
      • Ash_Crow
      • LinuxUserGD

      @Ash_Crow @HugeGameArtGD @szbalint @hanno Serious question: Why is #cloudstrike deployed almost everywhere with windows? Is it pushed by MS? Or recommended? Or packaged with MS products?

      In conversation about 11 months ago permalink
    • Embed this notice
      LinuxUserGD (hugegameartgd@mastodon.gamedev.place)'s status on Saturday, 20-Jul-2024 03:19:45 JST LinuxUserGD LinuxUserGD
      in reply to
      • Bálint Szilakszi

      @szbalint @hanno Seems to be technically right because the BSOD is a Microsoft Windows outage

      In conversation about 11 months ago permalink
    • Embed this notice
      Bálint Szilakszi (szbalint@x0r.be)'s status on Saturday, 20-Jul-2024 03:19:46 JST Bálint Szilakszi Bálint Szilakszi
      in reply to

      @hanno not if major news orgs don’t even get the company name right:

      In conversation about 11 months ago permalink

      Attachments


      1. https://cdn.x0r.be/media_attachments/files/112/813/133/384/518/937/original/189f762f8ae8ca81.jpeg
    • Embed this notice
      hanno (hanno@mastodon.social)'s status on Saturday, 20-Jul-2024 03:19:47 JST hanno hanno
      in reply to

      Honestly, if we could get that one basic message out, that if their IT security is based on more complexity, not less, that they're doing it wrong, maybe we could start putting crap companies like crowdstrike or citrix out of business.

      In conversation about 11 months ago permalink
    • Embed this notice
      hanno (hanno@mastodon.social)'s status on Saturday, 20-Jul-2024 03:19:47 JST hanno hanno
      in reply to

      I'm mentioning citrix specifically because it really boggles my mind how they can be still in business. In case you don't remember, there were countless gov entities, hospitals, and what not, hacked in 2020, due to a really epic fuckup by citrix. It was a flaw they knew about, and hadn't provided a fix, only an unreliable workaround that sometimes didn't work.

      In conversation about 11 months ago permalink
    • Embed this notice
      hanno (hanno@mastodon.social)'s status on Saturday, 20-Jul-2024 03:19:47 JST hanno hanno
      in reply to

      Actually, the value of Citrix rose after that: https://www.marketscreener.com/quote/stock/CITRIX-SYSTEMS-INC-4863/ These things have no consequences for these companies, it's a completely broken market. I'm reading news that crowdstrike's value dropped, I have doubts that this will be permanent.

      In conversation about 11 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.marketscreener.com
        Citrix Systems, Inc. Stock (CTXS) - Quote Nasdaq- MarketScreener
        Citrix Systems, Inc. (CTXS.NASDAQ): Stock quote, stock chart, quotes, analysis, advice, financials and news for Stock Citrix Systems, Inc. | Nasdaq: CTXS | Nasdaq
    • Embed this notice
      hanno (hanno@mastodon.social)'s status on Saturday, 20-Jul-2024 03:19:48 JST hanno hanno
      in reply to

      Their products are flawed not just because they're badly implemented - which they are - but because they are based on a stupid idea. The idea that you improve your IT security by adding more complexity. Doing the opposite is the right approach. But you can't sell that as a product. (You can still sell it, but it's not something you just plug into your network and get security magically.)

      In conversation about 11 months ago permalink
      Blaise Pabón - controlpl4n3 repeated this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.