Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I’ve mentioned this before: this is one of the oncoming trains for corp-security.

I’ve mentioned this before: this is one of the oncoming trains for corp-security.

Scheduled Pinned Locked Moved Uncategorized
25 Posts 22 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • haroonmeer@infosec.exchangeH This user is from outside of this forum
    haroonmeer@infosec.exchangeH This user is from outside of this forum
    haroonmeer@infosec.exchange
    wrote last edited by
    #1

    I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

    Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

    Their agents will.

    webhat@infosec.exchangeW nholzschuch@piaille.frN rickf@indieweb.socialR netraven@hear-me.socialN wydamn@social.linux.pizzaW 15 Replies Last reply
    4
    0
    • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

      I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

      Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

      Their agents will.

      webhat@infosec.exchangeW This user is from outside of this forum
      webhat@infosec.exchangeW This user is from outside of this forum
      webhat@infosec.exchange
      wrote last edited by
      #2

      @haroonmeer they need to add: "Don't hack stuff" to the prompt, that will protect them

      raymaccarthy@mastodon.ieR aj@techhub.socialA 2 Replies Last reply
      0
      • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

        I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

        Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

        Their agents will.

        nholzschuch@piaille.frN This user is from outside of this forum
        nholzschuch@piaille.frN This user is from outside of this forum
        nholzschuch@piaille.fr
        wrote last edited by
        #3

        @haroonmeer @temptoetiam that’s also the end of parental control, I guess.

        1 Reply Last reply
        0
        • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

          I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

          Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

          Their agents will.

          rickf@indieweb.socialR This user is from outside of this forum
          rickf@indieweb.socialR This user is from outside of this forum
          rickf@indieweb.social
          wrote last edited by
          #4

          @haroonmeer @TindrasGrove

          I am so glad I’m no longer in the operational security world anymore ….. these problems are going to grow exponentially* and so will the corresponding burnout.

          * on top of the ongoing usual problems that should’ve been fixed / addressed 20 years ago but still haven’t.

          n_dimension@infosec.exchangeN 1 Reply Last reply
          0
          • R relay@relay.publicsquare.global shared this topic
          • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

            I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

            Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

            Their agents will.

            netraven@hear-me.socialN This user is from outside of this forum
            netraven@hear-me.socialN This user is from outside of this forum
            netraven@hear-me.social
            wrote last edited by
            #5

            @haroonmeer I wasn't even aware codex ran locally? I thought it was just in the browser with shitty github connections.

            1 Reply Last reply
            0
            • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

              I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

              Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

              Their agents will.

              wydamn@social.linux.pizzaW This user is from outside of this forum
              wydamn@social.linux.pizzaW This user is from outside of this forum
              wydamn@social.linux.pizza
              wrote last edited by
              #6

              @haroonmeer I mean, right away the solution would be podman, not docker. Podman doesn't require root level privs to run.

              1 Reply Last reply
              0
              • R relay@relay.mycrowd.ca shared this topic
              • rickf@indieweb.socialR rickf@indieweb.social

                @haroonmeer @TindrasGrove

                I am so glad I’m no longer in the operational security world anymore ….. these problems are going to grow exponentially* and so will the corresponding burnout.

                * on top of the ongoing usual problems that should’ve been fixed / addressed 20 years ago but still haven’t.

                n_dimension@infosec.exchangeN This user is from outside of this forum
                n_dimension@infosec.exchangeN This user is from outside of this forum
                n_dimension@infosec.exchange
                wrote last edited by
                #7

                @rickf @haroonmeer @TindrasGrove

                Still no use case for #Ai and apparently #LLM are useless...

                (I should start a file of these)

                1 Reply Last reply
                0
                • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

                  I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

                  Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

                  Their agents will.

                  timwardcam@c.imT This user is from outside of this forum
                  timwardcam@c.imT This user is from outside of this forum
                  timwardcam@c.im
                  wrote last edited by
                  #8

                  @haroonmeer I had a problem with corporate security theatre getting in the way of something I needed to do.

                  So I asked the corporate provided AI how to get round the corporate security theatre.

                  And instead of reporting me to security it gave me some code. (Which, in the nature of AI generated code, didn't actually work, but it did give me the clue necessary to write my own code which did work.)

                  1 Reply Last reply
                  0
                  • webhat@infosec.exchangeW webhat@infosec.exchange

                    @haroonmeer they need to add: "Don't hack stuff" to the prompt, that will protect them

                    raymaccarthy@mastodon.ieR This user is from outside of this forum
                    raymaccarthy@mastodon.ieR This user is from outside of this forum
                    raymaccarthy@mastodon.ie
                    wrote last edited by
                    #9

                    @webhat @haroonmeer
                    ha ha ha
                    Uninstalling the Agent is the only solution.

                    1 Reply Last reply
                    0
                    • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

                      I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

                      Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

                      Their agents will.

                      megatronicthronbanks@mastodon.socialM This user is from outside of this forum
                      megatronicthronbanks@mastodon.socialM This user is from outside of this forum
                      megatronicthronbanks@mastodon.social
                      wrote last edited by
                      #10

                      @haroonmeer

                      Yeah it's like Cliff Stoll and sendmail all over anew (yes I'm that old). Docker frequently writes root owned files to the FS. We are a dumb species.

                      1 Reply Last reply
                      0
                      • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

                        I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

                        Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

                        Their agents will.

                        stux@mstdn.socialS This user is from outside of this forum
                        stux@mstdn.socialS This user is from outside of this forum
                        stux@mstdn.social
                        wrote last edited by
                        #11

                        @haroonmeer People are willingly installing malware now, heck.. they’re even paying for it

                        expertenkommision_cyberunfall@mastodon.socialE 1 Reply Last reply
                        0
                        • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

                          I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

                          Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

                          Their agents will.

                          ahhhhhhhhhhh@mastodon.socialA This user is from outside of this forum
                          ahhhhhhhhhhh@mastodon.socialA This user is from outside of this forum
                          ahhhhhhhhhhh@mastodon.social
                          wrote last edited by
                          #12

                          @haroonmeer feeling less stupid for being paranoid enough to not add my user to the docker group.

                          1 Reply Last reply
                          0
                          • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

                            I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

                            Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

                            Their agents will.

                            tdelmas@mamot.frT This user is from outside of this forum
                            tdelmas@mamot.frT This user is from outside of this forum
                            tdelmas@mamot.fr
                            wrote last edited by
                            #13

                            @haroonmeer at least it didn't use the latest linux exploit

                            1 Reply Last reply
                            0
                            • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

                              I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

                              Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

                              Their agents will.

                              cgudrian@social.tchncs.deC This user is from outside of this forum
                              cgudrian@social.tchncs.deC This user is from outside of this forum
                              cgudrian@social.tchncs.de
                              wrote last edited by
                              #14

                              @haroonmeer As a last resort it would have probably tried running the copyfail exploit.

                              1 Reply Last reply
                              0
                              • stux@mstdn.socialS stux@mstdn.social

                                @haroonmeer People are willingly installing malware now, heck.. they’re even paying for it

                                expertenkommision_cyberunfall@mastodon.socialE This user is from outside of this forum
                                expertenkommision_cyberunfall@mastodon.socialE This user is from outside of this forum
                                expertenkommision_cyberunfall@mastodon.social
                                wrote last edited by
                                #15

                                @stux @haroonmeer

                                And corp encourages them to do do.

                                mdione@en.osm.townM 1 Reply Last reply
                                0
                                • R relay@relay.an.exchange shared this topic
                                • expertenkommision_cyberunfall@mastodon.socialE expertenkommision_cyberunfall@mastodon.social

                                  @stux @haroonmeer

                                  And corp encourages them to do do.

                                  mdione@en.osm.townM This user is from outside of this forum
                                  mdione@en.osm.townM This user is from outside of this forum
                                  mdione@en.osm.town
                                  wrote last edited by
                                  #16

                                  @expertenkommision_cyberunfall @stux @haroonmeer and some corps forces us to do it.

                                  expertenkommision_cyberunfall@mastodon.socialE 1 Reply Last reply
                                  0
                                  • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

                                    I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

                                    Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

                                    Their agents will.

                                    mdione@en.osm.townM This user is from outside of this forum
                                    mdione@en.osm.townM This user is from outside of this forum
                                    mdione@en.osm.town
                                    wrote last edited by
                                    #17

                                    @haroonmeer but isn't the docker's `root` user mapped to a host's transient normal user?

                                    fuzzyfuzzyfungus@cyberplace.socialF 1 Reply Last reply
                                    0
                                    • mdione@en.osm.townM mdione@en.osm.town

                                      @expertenkommision_cyberunfall @stux @haroonmeer and some corps forces us to do it.

                                      expertenkommision_cyberunfall@mastodon.socialE This user is from outside of this forum
                                      expertenkommision_cyberunfall@mastodon.socialE This user is from outside of this forum
                                      expertenkommision_cyberunfall@mastodon.social
                                      wrote last edited by
                                      #18

                                      @mdione @stux @haroonmeer

                                      Feels like sabotage

                                      1 Reply Last reply
                                      0
                                      • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

                                        I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

                                        Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

                                        Their agents will.

                                        kumarvibe@mastodon.socialK This user is from outside of this forum
                                        kumarvibe@mastodon.socialK This user is from outside of this forum
                                        kumarvibe@mastodon.social
                                        wrote last edited by
                                        #19

                                        @haroonmeer @jackeric agents are very clever. I’ve seen them try all kinds of things like this just to “get the task done.” I’ve only noticed because I put them in sandbox-exec.

                                        1 Reply Last reply
                                        0
                                        • mdione@en.osm.townM mdione@en.osm.town

                                          @haroonmeer but isn't the docker's `root` user mapped to a host's transient normal user?

                                          fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                                          fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                                          fuzzyfuzzyfungus@cyberplace.social
                                          wrote last edited by
                                          #20

                                          @mdione @haroonmeer Docker can map to a user other than root; but it leaves whether or not it does so up to you. I'm not sure if there's some specialty lockdown config that tightens this; but by default docker doesn't even seem to intend to protect the host from the user; and leaves it up to the user whether they want any actual protection from container contents or not.

                                          Link Preview Image
                                          Understanding the Docker USER Instruction | Docker

                                          Discover best practices and common pitfalls associated with the Docker USER instruction. Also get a hands-on demo to learn the importance of these practices.

                                          favicon

                                          Docker (www.docker.com)

                                          fuzzyfuzzyfungus@cyberplace.socialF 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups