Post B94LFQ8W8IQAXY4t3A by gorplop@pleroma.m68k.church
 (DIR) More posts by gorplop@pleroma.m68k.church
 (DIR) Post #B94Jci5RMNssxqcGMy by gorplop@pleroma.m68k.church
       2 likes, 2 repeats
       
       CSO when they find a computer on the domain with Defender offvs the embedded engineer who knows the access control box runs linux 2.6 with open ssh root login, running under some floor tile and the CCTV DVR has unpatched HiSilicon backdoor
       
 (DIR) Post #B94L5GGtxGnD379geW by quad@akko.quad.moe
       0 likes, 0 repeats
       
       @gorplop Our CISO made me remove the OpenBSD ssh bastion I'd used for 3 years and replace it with opening ssh through the firewall.Presumably because he couldn't plug the OpenBSD box into intune, i dunno
       
 (DIR) Post #B94LFQ8W8IQAXY4t3A by gorplop@pleroma.m68k.church
       0 likes, 0 repeats
       
       @quad lol what a moron.
       
 (DIR) Post #B94LFQJVTRDB5dDfBA by quad@akko.quad.moe
       0 likes, 0 repeats
       
       @gorplop when i asked him why, he told me the firewall is better because it has IPS.at this point i've learned that corporate security arguments are like speaking to a brick wall. so sure, i'll remove it as long as he takes the blame if something goes wrong.
       
 (DIR) Post #B94LxEvLBLH6VToEE4 by gorplop@pleroma.m68k.church
       0 likes, 0 repeats
       
       @quad So he decided to swap a known-hardened component with a firewall that allows internal network access by default and then maybe some IPS system will analyze the packets and prevent unauthorized accessI was having some discussion with a friend today about how a lot of corporate CISO types have no idea what they are doing
       
 (DIR) Post #B94LxF72TqdH5lHZSa by quad@akko.quad.moe
       0 likes, 0 repeats
       
       @gorplop knowing how CISOs work I can bet he just read some random recommendation somewhere that "critical infrastructure (such as ssh) should be behind IPS" and went into panic mode because the ssh couldn't have IPS since it went through a VM instead of a firewall.
       
 (DIR) Post #B94MCdNKYQVwgYF3Im by quad@akko.quad.moe
       0 likes, 0 repeats
       
       @gorplop as for why they're like this. I think the pattern is pretty simple.anyone smart enough to make a decent ciso knows that modern infosec is an unsolvable problem (due to budgets, corporate pushback, apathy or all the other factors) and doesn't want to poke it with a ten foot polethe ones at the top get rich by doing research instead, which a ciso then typically misunderstands when they hear it after it's been regurgitated and bent via a series of 12 different corporate sales teams, workshops and conferences
       
 (DIR) Post #B94NPGO1RBLl6b9RGi by quad@akko.quad.moe
       0 likes, 0 repeats
       
       @gorplop Man, I encounter so much dumb shit at work that I wish I could post. But alas, I cannot comment on it.
       
 (DIR) Post #B94QKlSilqRbtqtaOu by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @quad @gorplop Someone on fedi wrote a great blogpost about it but I can't find it right now:basically, if the IPS company's sales team used their marketing budget to buy your CISO a nice dinner, or fly him to a fancy conference, that trumps any technical arguments
       
 (DIR) Post #B94QqF2eqPRMcHiKmW by quad@akko.quad.moe
       0 likes, 0 repeats
       
       @wolf480pl @gorplop That doesn't surprise me one bit. Because any CISO who gains technical knowledge would quit.