5 ms·
A cybersecurity company was hacked — what an irony
by x1unix 11mo ago
A cybersecurity company was hacked — what an irony
- vasco 11mo agoNot so much irony as it's a great vector to get inside an org. Security / monitoring agents that you deploy everywhere and don't suspect when you see they exfiltrate data, since you're expecting the telemetry anyway.
- x3n0ph3n3 11mo agoEvery time some security compliance goon comes by telling me to install an agent on all of our servers to meet some security compliance requirement, I remind them that they are asking me to install a backdoor on our servers and handing the keys to a 3rd party.
- natebc 11mo agoThe Crowdstrike Falcon Sensor agent (with a kernel module) establishes TLS connections to several random AWS endpoints. I really have no idea how security people think this is a good thing aside from checkbox compliance but man-o-man do they love it.
- neffy 11mo agoWell honestly, this security person thinks its a terrible idea - but needless to say the people selling those systems disagree - and for non-technical management, it ticks the compliance box and they get back to their jobs.
- goalieca 11mo agoThey are also telling you how to cover-your-ass once a breach happens.
- ExoticPearTree 11mo agoYou will not be faulted for anything if the security company gets hacked and you get hacked through it. Probably a lot of sleepless nights to fix your infra, but that's it.
- x3n0ph3n3 11mo agoTell that to my customers.
- ExoticPearTree 11mo agoYour lawyers and your PR department will do that, emphasizing very strongly that you did nothing wrong and their security is your utmost priority.
- 1oooqooq 11mo agomost of those companies nowadays are just insurance policies for CISO, who are just insurance policies for the CEO/CTO.