Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
fathermarz
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Show HN: Vigilance – Catch software supply chain attacks anywhere in the SDLC
(vigihq.com)
1 points
by
fathermarz
11h ago
|
0 comments
2.
▲
by
fathermarz
7d ago
In my experience, it depends on the community. Where I live most people are retired so there is tons of interest and a really well ran community program called Elder College. I would look into similar programs near you!
3.
▲
by
fathermarz
8d ago
This is very accurate. I teach seniors about how to use AI responsibly and they are always mind blown, and I keep it very high level. The amount of Chat”GTP” users there are out there that have no idea who the main vendors are. Most of them
4.
▲
by
fathermarz
9d ago
This is amazingly awesome. Very intriguing and what a great idea in the first place. One of the most important pieces of modern software IMO.
5.
▲
Vigilance – Catch supply chain attacks without the noise or the work
(vigihq.com)
1 points
by
fathermarz
23d ago
|
1 comments
6.
▲
by
fathermarz
23d ago
I’ve worked in software supply-chain security for six years doing binary analysis on firmware, industrial controls systems, and commodity IT closed/open source software. What I learned is that in hopes to secure the software supply cha
7.
▲
Show HN: Vigilance – catch supply-chain attacks by diffing what a file can do
(vigihq.com)
2 points
by
fathermarz
24d ago
|
0 comments
8.
▲
by
fathermarz
1mo ago
I think that now we are starting to see the hype go bye-bye and the real use cases are starting to emerge. However, the systems that come out must be constructed with care aligned with our world has been constructed (reality) and not how th
9.
▲
Claude, GPT and the Minnesota attackers all used known bugs and weak logins
(cabreza.substack.com)
1 points
by
fathermarz
1mo ago
|
0 comments
10.
▲
by
fathermarz
1mo ago
I believe the comment was to say you can not create a join for data that does not exist. Access to financial records is trivial, but there is likely no such comparable record that one can query on for water/industrial. Maybe metrics
11.
▲
by
fathermarz
1mo ago
> Top down regulation drives the systematic change, just like it did with the banking sector. Banking is resourced well enough to absorb that regulation and stand up a compliance team. I bring up ATC because of the consequence. Default p
12.
▲
by
fathermarz
2mo ago
Yes there are pieces of what you are saying that make sense theoretically. But what I mean by a silver bullet, is it is a systemic change that needs to happen in a bigger swing than just “regulate”. It is a top down initiative that needs to
13.
▲
by
fathermarz
2mo ago
Ouch. You just caused a major outage for <insert critical system>. Either you costed your company millions of dollars or you killed someone. OT does not equal IT
14.
▲
by
fathermarz
2mo ago
National Security has always been a federal government responsibility yes. But what does that fundamentally mean for boots on the ground? NSA doesn’t do IT for the DoD/W, DHS doesn’t do IT for the government, CISA only gives guidance w
15.
▲
by
fathermarz
2mo ago
What’s the penalty you would impose on a rural water system that has under 10 employees that services thousands of people for water and/or wastewater? What does that audit look like and how frequent does that happen? It’s a security as
16.
▲
by
fathermarz
2mo ago
https://www.linkedin.com/pulse/end-complacency-i-can-hope-an... I much prefer the non-vendor perspective on this. Andy Krapf, co-chair of the Water ISAC, has a great breakdown about the status quo systemic problems tha
17.
▲
by
fathermarz
2mo ago
Well I think it speaks to the age of the equipment they are speaking of in the industrial sector. How do you lockdown something that may have not been taken offline for decades because it will cost downtime or harm. Or something that can’t
18.
▲
by
fathermarz
2mo ago
I will repeat a comment from below. There are over 150k water utilities alone in the US. Passing the buck to the Federal Government is not understanding the problem.
19.
▲
by
fathermarz
2mo ago
What industry? Very relevant.
20.
▲
by
fathermarz
2mo ago
There are over 150k water utilities alone in the US. Passing the buck to the Federal Government is not understanding the problem.
21.
▲
by
fathermarz
2mo ago
“Run your security patches” is easier said than done in the case of OT and it’s actually an issue that is further upstream than this. Policies, procedures, culture, and resources to execute. None of which are technical.
22.
▲
by
fathermarz
2mo ago
What policies do y’all have in place for this? Is there a program in place or the beginnings of one at least?
23.
▲
by
fathermarz
2mo ago
Not IT malpractice and this where the industry diverges. IT folks usually don’t work on or understand these systems. Which is one of MANY problems OT faces. IT best practices don’t suffice in OT and even when they do, most of these orgs are
24.
▲
by
fathermarz
2mo ago
I really dislike the mention of AI in this article. Does it help expedite things? Maybe. Is it making attacks more sophisticated? The evidence and guidance tell us that these actors are simply logging to these Internet connected systems wit
25.
▲
by
fathermarz
2mo ago
Recently poked around the job market to see what I qualify for in this day and age. Working as a solo builder in my org I would say that I have done enough in the last 18 months to consider myself “with it”. What I found was pretty brutal.
26.
▲
by
fathermarz
2mo ago
Good to know thanks for the clarification
27.
▲
by
fathermarz
2mo ago
I know web designers that are getting good ol’ local business requests that are now one shotting the sites they used to spend a considerable amount of time on. So I think that’s something. But I couldn’t give you percentages
28.
▲
by
fathermarz
2mo ago
And in 5,000 years, they will say. “They must have worshipped this star to create such a monument around it, showing how connected to the stars this ancient civilization was”
29.
▲
by
fathermarz
2mo ago
The most upsetting part to me, is that these labs are in pure cognitive dissonance mode while virtue signalling. We are the virtuous ones that need to make the safest model for humanity, because we care more than “they” do. While at the sam
30.
▲
by
fathermarz
2mo ago
The website on mobile is constantly jumping around so I literally can’t read the copy before the height changes and goes below the fold. Also, use cases? I’m a little lost after nailing down all the movement.
More ›