No employee should have the power to subvert 130 high value accounts in a short time period.
Why isn't there a whitehouse.gov ActivityPub instance that no single admin can censor or subvert?
51–60 of 245 posts
No employee should have the power to subvert 130 high value accounts in a short time period.
Why isn't there a whitehouse.gov ActivityPub instance that no single admin can censor or subvert?
Earlier quoted context omitted.
Dongles are rare here in the US. But I know that bloomberg uses them. I was shocked when I learned that retail banks in Singapore give everyone dongles to log in. In the US that's tyranny Lol
Rare for employees or rare for consumers? Companies can push much higher security onto employees than onto consumers.
Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…
Why are internal employee tools publically accessible? Minimum they should require VPN access, but really go further with Zero Trust.
Security comes in layers. That first layer of requiring a VPN can stop many types of attacks from happening.
Next layer is requiring MFA for VPN access. Then for admin access, require MFA only from approved devices on the domain.
Large banks and the DoD have been doing this for years.
The "fail often and fail fast" crew are always reinventing the wheel after bad experiences. I honestly feel sorry for them.
Earlier quoted context omitted.
I don’t get it. You know your ebay password?
Some password databases involve copy and pasting or autotyping. If you want automatic hostname verification you need a password database integrated with your browser. On mobile many browsers don't support extensions so integrating my password database into the browser would be hard. In short, I do not know my ebay password, but I could have fallen for this phishing attack.
No employee should have the power to subvert 130 high value accounts in a short time period.
Why do we even have 'high value' accounts on a centralized platform? Why isn't there a whitehouse.gov ActivityPub instance that no single admin can censor or subvert?
They should require hardware security devices (dongles). Really Twitter should be ashamed of their poor internal security.
For example if a Twitter user was logged in with a dongle but the attacker had access via social engeneered remote desktop access a dongle still could mean access to private data.
But yes. As far as I know Google and Facebook require them. Also Google sometimes require permission of an other co-worker to access data.
Source (with more details): https://blog.twitter.com/en_us/topics/company/2020/an-update... > The social engineering that occurred on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools. Not all o…
> ultimately Tweeting from 45 for a moment I thought it read `tweeting from 45's`
Hands down the easiest way to make Shaun Cassidy sound like one of the Chipmunks.
Earlier quoted context omitted.
Dongles are rare here in the US. But I know that bloomberg uses them. I was shocked when I learned that retail banks in Singapore give everyone dongles to log in. In the US that's tyranny Lol
I work for a crypto currency company and it was the first time in my career that I was issued a YubiKey (I once had an RSA 2fa token for vpn access). It took some getting used to but now I just keep in on my keychain and I always have it with me. I need it for SSO, git, VPN, and basically all internal services. They aren't sufficient by themselves however, they don't protect from is malicious internal employees.
Do a cursory amount of preparation. Outside of basic measures, you're probably doing more harm to the business than good. The likelihood of internal malicious attackers is very low in the grand scheme of things, and the attack surface is huge.
Most companies are going to be compromised by outside attackers—its there that you should focus your energy. If internal attackers are your biggest threat, you've done a fantastic job.
Earlier quoted context omitted.
Why are internal employee tools publically accessible? Minimum they should require VPN access, but really go further with Zero Trust.
AFIK, in a Zero Trust Architecture a VPN is considered a perimeter and therefore it becomes a vector of attack to access systems of authoritative decision. Many security researchers have already established that the benefits of a VPN especially in the modern distributed world are marginal at best. Basically, yes a VPN makes you a tiny bit safer but it also adds a lot of networking complexity and adds more friction to…
This would be a nightmare for the people managing any nontrivial system. There are good reasons to use something like Active Directory and tie systems and applications to it for easier policy enforcement and management. There are good reasons to avoid this centralization for certain things too. Either extreme would be an exercise in frustration.
Earlier quoted context omitted.
Why do we even have 'high value' accounts on a centralized platform? Why isn't there a whitehouse.gov ActivityPub instance that no single admin can censor or subvert?
We will do that now. We will start the competitive bidding process, and we expect the RFP paperwork to be returned by October, 2021. After that, if there are no injunctions filed because of the bidding process, preliminary design documents will start being created. Preliminary design review will occur August 2022. ...