eliasp, to firefox
@eliasp@mastodon.social avatar

Security Agent doing endpoint-security-things.

No! This URL isn't dangerous!
No! You didn't block this, I could continue to use this URL in just fine!
No! You're not supposed to fiddle around in the memory space of my Firefox process and thereby fucking up its security!

Most of this corporate malware just serves as a "we are doing security" puppet.
In most cases, it's just an annoyance, increased attack surface and performance hog!

Screenshot of TrendMicro Security Agent, showing a tabular view with a single list entry: Date/Time: 2024-02-20 (Tue) 19:59 URL: https://github.com/1Password/onepassword-operator Risk Level: Dangerous Description: Verified fraud page or threat source Process: C:\Program Files\Mozilla Firefox\firefox.exe Action: Block

slink, to infosec
@slink@fosstodon.org avatar

Does anybody know of a good overview of cases where #antivirus and other #EndpointSecurity has failed and/or been the problem rather than the solution? #infosec

josh, to security

This is a genuine request for input from the community.

A member of upper-middle management for a midsized internet technology company recently explicitly stated that they didn't want to install the company's management agent on their device. "I think for leadership, that sort of thing should be optional" was the quote.

This person is intelligent and capable, and is otherwise someone I would respect as a fellow member of the same circles and business.

This is so against axioms that I hold almost self-evident, that I realized I don't even have good arguments. I can endlessly find corners of the internet where this would be akin to "Pi is exactly 3!" at a Mathematics convention, but is there ever generally a time or company's infrastructure configuration where simply ignoring or allowing to be optional endpoint security wouldn't just be blatantly stupid?

Besides being aghast and expressing sharp chastisement, how does someone go about even beginning to describe why this cavalier attitude is so abhorrent?

Is there some situation where it's actually a kosher methodology or mindset?

I think I might just be so thrown off guard by the concept that I just can't think of even an obvious answer to start with here.

sophos, to random

We’re excited to announce a new partnership with Boise State University that provides the university with access to our leading and creates new opportunities for students and benefits for organizations across the state.

Organizations in smaller, local communities are not immune to and other . At the same time, the worldwide cybersecurity skills gap puts organizations of all shapes and sizes at risk.

The Institute for Pervasive Cybersecurity’s Cyberdome addresses both of these challenges, as it delivers security to organizations across Idaho, including in rural areas, and offers hands-on cybersecurity training. Learn more: https://bit.ly/48U6p7E

sophos, to random

Vulnerable endpoints are a cybercriminal's delight. Ransomware accounts for two-thirds of incidents reported to our threat response team and 36% of these attacks stem from vulnerabilities on endpoint devices.

Basic steps can rectify failings, Daniel Thomas reports in SC Media. Regularly scheduled patch management for all network endpoints can provide base-level peace of mind, while puts up an additional barrier of defense. At the same time, services like XDR provide round-the-clock vigilance. Learn more: https://bit.ly/3PXT7OV

glyph, to random
@glyph@mastodon.social avatar

In just over 45 minutes, I'll be talking about secrets management — in Python and beyond — with @talkpython , and there should be a livestream here: https://www.youtube.com/watch?v=Gey87cZXF3Q

tasket,

@glyph @talkpython

"It all terminates at your computer, if your computer is not secure..."

Indeed,

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • rosin
  • modclub
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • khanakhh
  • osvaldo12
  • tacticalgear
  • Youngstown
  • everett
  • slotface
  • kavyap
  • anitta
  • thenastyranch
  • mdbf
  • tester
  • GTA5RPClips
  • provamag3
  • Leos
  • Durango
  • ethstaker
  • cisconetworking
  • normalnudes
  • megavids
  • cubers
  • lostlight
  • All magazines