@jerry@infosec.exchange

Cloud CISO
Podcast: https://defensivesecurity.org
Blog: https://infosec.engineering
Twitter: https://infosec.exchange/@maliciouslink
https://Infosec.Exchange Admin
#infosec #security #cybersecurity #risk #fedi22
…and for fucks sake, be nice to each other. We are only here for a brief time. Make it enjoyable.

To help support the costs associated with running this instance, please consider donating. You can set up recurring donations here:

Patreon: https://www.patreon.com/infosecexchange

Ko-Fi: https://ko-fi.com/infosecexchange

Liberapay: https://liberapay.com/Infosec.exchange/

You can also support with a one-time donation using PayPal to "[email protected]".

This profile is from a federated server and may be incomplete. Browse more on the original instance.

adiblind97, to random

hey everyone, its been a wile sense i posted here

jerry,
@jerry@infosec.exchange avatar

@adiblind97 welcome back!

vidmo, to random
@vidmo@infosec.exchange avatar

Uh @jerry I went to my own profile page and got this... just letting you know

jerry,
@jerry@infosec.exchange avatar

@vidmo I saw it too. I think Hetzner is having some network issues between the various servers.

SwiftOnSecurity, to random
@SwiftOnSecurity@infosec.exchange avatar

Truly impressive the enormity of the dipshits pushing their business acumen and mastery of capital suddenly finding out businesses have to generate money and they haven’t been fucking doing it this whole time and yet still expect us to peel their grapes for their presence.

jerry,
@jerry@infosec.exchange avatar

@SwiftOnSecurity as if grifting that hard doesn’t take a lot of work and talent.

jerry, to random
@jerry@infosec.exchange avatar

A few more pirates from the parade

image/jpeg
image/jpeg
image/jpeg

jerry, to random
@jerry@infosec.exchange avatar

Finally, some pirates at the pirate parade

image/jpeg
image/jpeg
image/jpeg

jerry, to random
@jerry@infosec.exchange avatar

I do like the pedal powered mobile bar that was in the parade

jerry, to random
@jerry@infosec.exchange avatar

No pirate parade would be complete without an old military jeep with a machine gun, right?

jerry,
@jerry@infosec.exchange avatar

@xabean I would say the attendance was pretty diverse. Families tend to stand together likely giving that appearance

jerry,
@jerry@infosec.exchange avatar

@xabean that said, this is Florida so…

jerry,
@jerry@infosec.exchange avatar
jerry,
@jerry@infosec.exchange avatar

@perigrin @xabean is know as the Redneck Riviera for a reason

jerry, to random
@jerry@infosec.exchange avatar

An initial few pics from the pirate parade in #pcb

image/jpeg
image/jpeg

jerry, to random
@jerry@infosec.exchange avatar

The Israel/Hamas situation is really bringing out the best in people on the fediverse today. RIP my reports.

jerry,
@jerry@infosec.exchange avatar

@davep yeah, any criticism or moderation actions are basically reduced to antisemitism or Islamophobia, depending on whose I take action on.

jerry,
@jerry@infosec.exchange avatar

@spmatich @davep that’s what I’ve been doing for going on 7 years now. It’s just disappointing to see, I suppose.

jerry, to random
@jerry@infosec.exchange avatar

My oldest son got invited to work grounds at the post season Atlanta Braves home games. So that’s pretty cool for him.

jerry, to random
@jerry@infosec.exchange avatar

A few more pics from last night’s fireworks

image/jpeg
image/jpeg

jerry,
@jerry@infosec.exchange avatar

@chirpbirb that was my Nikon with a 70-200 lens

jerry,
@jerry@infosec.exchange avatar

@IMcPwn that are from a tripod - 5 second exposures

jerry,
@jerry@infosec.exchange avatar

@deach here’s what I did:

Before the fireworks, I set my camera on a tripod

I used a remote shutter release

I am shooting on manual, auto ISO

I dropped the exposure down 3 EV to keep the camera from overexposing the fireworks by jacking up the iso too high

I set the camera to f5.6 and 5 second shutter speed

I focused as best I could before the fireworks started then flipped to manual focus so it would stay

Then I just snapped one after the other.

Note, even then some came out as a smoky mess

jerry, to random
@jerry@infosec.exchange avatar

I get to watch a pirate pARRade this evening. Look for pics later. Or block/mute if you don’t like pirate parades.

Also, I get to try my firework photography again this evening. I think I understand some things I need to do better. Last night was my first attempt.

jerry, to random
@jerry@infosec.exchange avatar

#FeetOfInfosec #OnlyFeet
This is perhaps the last good beach day of the year.

jerry,
@jerry@infosec.exchange avatar

@IoanSaid it’s a long running joke. I’ve been threatening to sell feet pics to help pay the bills for Infosec.exchange.

jerry,
@jerry@infosec.exchange avatar

@urda NSF anything 😂

BiaSciLab, to random
@BiaSciLab@infosec.exchange avatar

Stop by the @GirlsWhoHack booth at Coney Island Maker Faire!
Learn to pick locks, grab a t-shirt or some stickers!
We also have our cool soldering kit and soldering irons from @adafruit !

jerry,
@jerry@infosec.exchange avatar

@BiaSciLab @GirlsWhoHack a maker faire at Coney Island? That sounds awesome!

73ms, to random
@73ms@infosec.exchange avatar

has a surprisingly low limit for how many lists you can create, seems to be set at 50. Is that something configurable?

jerry,
@jerry@infosec.exchange avatar

@73ms that’s a good question. I will ask the developers

cirriustech, to random
@cirriustech@infosec.exchange avatar

Deleted X a few weeks ago. Deleted Bluesky too. Keeping IEX and LinkedIn. Reducing usage of FB which I only use with wife and current/former workmates.
Net reduction in SM usage. So will or should be posting less often. Unlikely to be able to achieve goal of going to more (any) conferences or events.
So, around but less so.

Stepping down as a mod here too.

jerry,
@jerry@infosec.exchange avatar

@cirriustech I wish you well, sir

admin, to random
@admin@mastodon.ai8w.ddns.net avatar

@smitty @jerry @stux

Any of you getting connection requests from a "VIVIT" (or something similar) whose BIO states it's a bot created to connect with admins of servers? Seems sus to me.

Please let me know.

Edited to correct spelling and punctuation.

jerry,
@jerry@infosec.exchange avatar

@admin @smitty @stux I noticed some calls to suspend that domain on the fediblock hashtag yesterday. Otherwise, I’ve not seen it

jerry,
@jerry@infosec.exchange avatar
WowSuchCyber, to random
@WowSuchCyber@toot.zof.sh avatar

@jerry Hi! Sorry to interrupt but I don't "know" a lot of person I could ask those questions:
What do you think is essential in a CISO for a large org?
What are the biggest organisational challenges?
What is the most pressing thing the board is expected from you?

jerry,
@jerry@infosec.exchange avatar

@WowSuchCyber hi. I am working on a response. That’s a great question

jerry,
@jerry@infosec.exchange avatar

@WowSuchCyber

What do you think is essential in a CISO for a large org?
Experience with or at least knowing how to get things done in a large organization. Large companies tend to have complex organizational structures and responsibilities are often split in unique ways between areas of the business and “corporate”. Being able to navigate that and do what needs to be done is vital.
Another problem is situational awareness - things tend to be so distributed and many different systems and tools being used, that it’s tough to know where you are at.
Also, we security people disparage “compliance” a lot. Once a security leader is responsible for the security of 2 million systems managed by a hundred different teams, spanning thousands of “IT” workers, you quickly realize that “compliance” is about the only thing you can do to have any hope of maintaining your environment.
> What are the biggest organisational challenges?
The highly federated nature of security and IT in large orgs. Senior leadership is usually making super high level decisions at a macro scale and those decisions on staffing, funding, and whatnot can have impacts on the security posture, and it’s not always apparent.
> What is the most pressing thing the board is expected from you?
At a high level, keeping our business, customer and employee data safe, and keeping us out of the news, while being as cost efficient as possible. They want to know see that we are embracing new technologies to drive efficiency and continue to improve our security posture. They want to ensure that we are supporting the business’ objectives - and not just being completely risk averse, but rather partnering with the business to advise on how to do what they want to do safely.
They also want to know that we are on top of all the latest news that they see on CNBC and good morning America about the latest named vulnerabilities and threats like ransomware.

jerry, to random
@jerry@infosec.exchange avatar

#PCB had fireworks tonight for the pirate festival. This is from a bit over a mile away with a 70-200 and 2x teleconverter.

image/jpeg
image/jpeg
image/jpeg

jerry,
@jerry@infosec.exchange avatar

@mansr that was 5 seconds

jerry, to random
@jerry@infosec.exchange avatar

The lessons of today: do not roll your own encryption and do not host your own dns

jerry,
@jerry@infosec.exchange avatar

@gangrif ddos mitigation is nearly impossible for “normies”

jerry,
@jerry@infosec.exchange avatar

@LovesTha yes. Almost preferable

jerry, to random
@jerry@infosec.exchange avatar

I made some changes to the Infosec.exchange CDN by moving the cache to more countries and using much faster nvme storage at the edge. It should be a good bit faster and a lot more expensive, so I have to stay on top of purging old media. Let’s see how that goes.

jerry,
@jerry@infosec.exchange avatar

@Viss I am not sure if bunny has an api that would let me do that. It’s a good idea.

jerry,
@jerry@infosec.exchange avatar

@jahanson its bunny.net’s cdn.

jerry,
@jerry@infosec.exchange avatar

@darkuncle @Viss that is true. I did check and bunny has a full set of APIs and pretty excellent documentation

ArenaCops, to random
@ArenaCops@infosec.exchange avatar

How much of Marjorie Taylor Greene's net worth of $41 milliion is of Russian Kremlin origin?
Has/have there been a thorough investigation(s) by expert tax investigators?

https://caknowledge.com/marjorie-taylor-greene-net-worth/

jerry,
@jerry@infosec.exchange avatar

@ArenaCops I am embarrassed to have her represent my district in congress. Perhaps I am more embarrassed by my neighbors who apparently vote for her.

jerry,
@jerry@infosec.exchange avatar

@ArenaCops my voice matters for senate and President. The vast majority of the people in the area I live in literally believes her stories about Jewish space lasers and fret over the democrats deploying the Gazpacho police.

giffengrabber, to random
@giffengrabber@infosec.exchange avatar

How can I get in touch with the moderation team here on infosec.exchange?

ping @jerry

jerry,
@jerry@infosec.exchange avatar

@giffengrabber send me a PM is the easiest way

Kugg, to random
@Kugg@infosec.exchange avatar

I have a bluesky account. I still have not found anyone I know there. Do I use a migration tool or whats the plan?

jerry,
@jerry@infosec.exchange avatar

@Kugg I have yet to sort out bsky.

infosec_exchange_chennai_guy, to random
jerry,
@jerry@infosec.exchange avatar
mhannemann, to random
@mhannemann@infosec.exchange avatar

Dude. Seriously?

jerry,
@jerry@infosec.exchange avatar

@mhannemann there is a reason the politicians are generally very old

jerry, to random
@jerry@infosec.exchange avatar

Fascinating. Only 28% of accounts that signed up to Infosec.exchange in August (<2 months ago) are still active.

jerry,
@jerry@infosec.exchange avatar

@SpaceLifeForm its based on logins over the past 30 days. An account that hasn’t logged in during the past 30 days goes into an inactive state (that has no implications other that for the purposes of counting active accounts)

jerry,
@jerry@infosec.exchange avatar

@SpaceLifeForm I am guessing about 75%

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • KamenRider
  • TheResearchGuardian
  • KbinCafe
  • Socialism
  • oklahoma
  • SuperSentai
  • feritale
  • All magazines