Post B5xVFoIWqI62eMl5Mm by icedquinn@blob.cat
(DIR) More posts by icedquinn@blob.cat
(DIR) Post #B5xUuknCgCdBhJ48rQ by david_chisnall@infosec.exchange
1 likes, 1 repeats
Why does our industry keep looking at things, claiming it's doing them, and doing the exact opposite of what the original idea was? A few examples:Alan Kay (who coined the term) defined the key idea of object orientation as late bounding, so we ended up with a load of things that use rigid nominal type systems to tightly couple components, marketed as 'object oriented'.The Agile Manifesto's core idea was 'people over process'. I've lost count of the number of times I've seen places claim they're using 'the agile methodology' because they have sprints, standups, and other processes taken from Agile.The Zero Trust paper said, at its core, 'assume endpoints are compromised, design your systems so that an endpoint compromise doesn't automatically give control over everything', yet almost everything I've seen branding itself as Zero Trust has been of the form 'run some over-privileged thing on the endpoints to increase their attack surface, then if that thing reports that the endpoint isn't compromised allow it to do a load of things it shouldn't be allowed to do'.
(DIR) Post #B5xVFoIWqI62eMl5Mm by icedquinn@blob.cat
1 likes, 0 repeats
@david_chisnall the agile processes wouldn't even be so bad if people stole them properly. that machinery is designed in service of "hire people who are competent, make the expectations of work clear (story cards) and contextual (deming noted its important for people to understand why the customer wants this so they know which corners to cut and optimize around), have a designated bullshit mangler (the scrum master) and then get management out of the room and let them cook"so many places don't even understand the basic concept that the scrum master is supposed to be the dedicated unblocker
(DIR) Post #B5y0rarqK15EZzlyfg by mangeurdenuage@shitposter.world
1 likes, 0 repeats
@david_chisnall The reason why zero trust bs emerged in the first place was because a basic foundation of security which was "don't execute untrusted software" was forgotten/swiped aside. It's moronic, nothing will fix this and grifters will continuously sell fake solutions to that, like hardware drm like sgx or trustzones etc...