jerry,
@jerry@infosec.exchange avatar

For as remarkably devastatingly successful as the vulnerability/attack was, it's fascinating that the attention of our industry is drawn to things like downfall and others.

florenciocano,
@florenciocano@infosec.exchange avatar

@jerry I think some very technical people tend to talk more about technical issues that fascinate them instead of real practical security problems. These people usually also downplay the problems related to governance and management of security that are usually the main reasons for breaches, an not very technical security problems.

asjimene,
@asjimene@infosec.exchange avatar

@jerry I think CPU architecture is magic to just about everyone, so taking advantage of that is always really interesting from a security point of view.

cR0w,
@cR0w@infosec.exchange avatar

@jerry For some of us, things like Downfall offer an opportunity to learn something new and temporarily distract us from the never ending work around things like MOVEit.

mikey,
@mikey@friendsofdesoto.social avatar

@jerry I think it's a matter of "the but for the grace of gawd go I" in a lot of cases.

I just did a table top IR based on a MoveIT because of the sheer horror of what something like that would do. And we don't even use it.

whereisthespai,
@whereisthespai@infosec.exchange avatar

@jerry it’s new and shiny.

jerry,
@jerry@infosec.exchange avatar

Perhaps it's just a problem in the circles I run in.

alex_02,
@alex_02@infosec.exchange avatar

@jerry I think the industry and the media have way to many clowns that want things to be cool and sexy or they try to push some weird "vuln" that if you read the paper is over complicated and mostly a waste of time for most attackers.

spiegelmama,
@spiegelmama@infosec.exchange avatar

@jerry I just checked Dark Reading to see if we fell prey to that, but 32 results for "moveit," all of which will be for the vuln, and 33 for "downfall," with no more than 5 or so that are clearly covering that attack instead of just being dramatic in language. Phew!

infosec_jcp,
@infosec_jcp@infosec.exchange avatar

@jerry

So, quick question, probably stupid, but, does Cloud CISO include OnPrem? /S 😆 🤫 🤦

jerry,
@jerry@infosec.exchange avatar

@infosec_jcp to the extent we have on-prem, yes

infosec_jcp,
@infosec_jcp@infosec.exchange avatar

@jerry

Snaps fingers

⚠️ ☁️ HybridCloud ☁️ ⚠️

😆

Perhaps you should HybridCloudCISO as an acronym?

kuoirad,
@kuoirad@infosec.exchange avatar

@jerry I mean, you do consort with @lerg.

jerry,
@jerry@infosec.exchange avatar

@kuoirad @lerg that’s a good point

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • KamenRider
  • Ask_kbincafe
  • TheResearchGuardian
  • KbinCafe
  • Socialism
  • oklahoma
  • SuperSentai
  • feritale
  • All magazines