Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. @puniko I hate how much of the infosec industry consists of just checking checkboxes rather than actually understanding what you're securing or why

@puniko I hate how much of the infosec industry consists of just checking checkboxes rather than actually understanding what you're securing or why

Scheduled Pinned Locked Moved Uncategorized
4 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • quad@akko.quad.moeQ This user is from outside of this forum
    quad@akko.quad.moeQ This user is from outside of this forum
    quad@akko.quad.moe
    wrote last edited by
    #1
    @puniko I hate how much of the infosec industry consists of just checking checkboxes rather than actually understanding what you're securing or why
    serafine@void.lgbtS 1 Reply Last reply
    0
    • quad@akko.quad.moeQ quad@akko.quad.moe
      @puniko I hate how much of the infosec industry consists of just checking checkboxes rather than actually understanding what you're securing or why
      serafine@void.lgbtS This user is from outside of this forum
      serafine@void.lgbtS This user is from outside of this forum
      serafine@void.lgbt
      wrote last edited by
      #2
      @quad @puniko "Just copy those settings into your xyz config and now you have a secure system" god I hate those types of videos/blogs ... ppl just clicking and using stuff without understanding what it does
      quad@akko.quad.moeQ 1 Reply Last reply
      0
      • serafine@void.lgbtS serafine@void.lgbt
        @quad @puniko "Just copy those settings into your xyz config and now you have a secure system" god I hate those types of videos/blogs ... ppl just clicking and using stuff without understanding what it does
        quad@akko.quad.moeQ This user is from outside of this forum
        quad@akko.quad.moeQ This user is from outside of this forum
        quad@akko.quad.moe
        wrote last edited by
        #3
        @serafine @puniko I was thinking more about the fact that infosec people just read whatever the news says and then do it in the most half-assed way possible.

        For example they might set up logging on absolutely everything and have a flood of crap, because that's what they heard at a conference or whatever.

        But it's the opposite of what you should actually do, you should log everything you need to detect something, and then make sure you can actually respond to the thing you need to.

        But nah, just enable monitoring on 5 bajillion things and now you have a control panel with 200 flashing red lights 24/7, 90% of which are false positives and you don't have the people or knowledge to filter out the 10% you need to care about and then action on it.
        serafine@void.lgbtS 1 Reply Last reply
        0
        • quad@akko.quad.moeQ quad@akko.quad.moe
          @serafine @puniko I was thinking more about the fact that infosec people just read whatever the news says and then do it in the most half-assed way possible.

          For example they might set up logging on absolutely everything and have a flood of crap, because that's what they heard at a conference or whatever.

          But it's the opposite of what you should actually do, you should log everything you need to detect something, and then make sure you can actually respond to the thing you need to.

          But nah, just enable monitoring on 5 bajillion things and now you have a control panel with 200 flashing red lights 24/7, 90% of which are false positives and you don't have the people or knowledge to filter out the 10% you need to care about and then action on it.
          serafine@void.lgbtS This user is from outside of this forum
          serafine@void.lgbtS This user is from outside of this forum
          serafine@void.lgbt
          wrote last edited by
          #4
          @quad @puniko yea, fair
          1 Reply Last reply
          1
          0
          • R relay@relay.mycrowd.ca shared this topic
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • World
          • Users
          • Groups