@chetwisniewski@securitycafe.ca avatar

chetwisniewski

@chetwisniewski@securitycafe.ca

Director, Global Field CTO at Sophos, frequent speaker and press go to. Said opinions are mine, not the company.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

Followers in Vancouver who don't follow the media closely, there will be a loud fly over by the Snowbirds at 1900. Don't panic, protect your pet's ears if needed!

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

Before my Canadian followers watch the Vancouver Canucks take it to the Edmonton Oilers at Rogers Arena, you can tune into CTV News and Global BC to hear my thoughts on the British Columbia PSC breach and where it might likely lead us. Expect to be on at 5 and 6 on both networks.

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

Commentary not included in 5pm news apparently, although info I shared was used in the stories. Always a gamble, maybe the hour long news at 6.

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar
Viss, to random
@Viss@mastodon.social avatar

"our security is so bad that when we get hit we have to divert ambulances"

i dont want this to come off as "victim blaming" but if the head of security in that circumstance didnt have " have to divert ambulances" in their threat model as the person in charge of a healthcare org - they should be the next one in the hotseat in court getting grilled by the prosecution.

$5 says its related to "for profit healthcare"

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@Viss If only someone had told them about this new type of attack they might have prepared a response plan.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

As usual, RSA was exhausting, but I did win by not entering the conference centre. Met with so many amazing journalists and old friends that it was certainly worth the trouble. Thank you to everyone who spared some time to spend with me.

jaseg, to linux
@jaseg@chaos.social avatar

So my just catastrophically self-destructed. I was using arch with the yubikey full-disk encryption package, when the machine hung and crashed during a system update. The machine crashed exactly after the old initramfs files were cleaned up, and before the new ones were written to disk. Since the yubkikey fde thing stores the seed ("challenge") for the luks key in the initramfs, all copies of the seed are gone now, and the data on that disk is unrecoverable.

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@jaseg That is a terrible design. Thanks for the warning, will avoid

NanoRaptor, to random
@NanoRaptor@bitbang.social avatar

Commodore 128DD

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@NanoRaptor i had one of these and was so excited for the software that was yet to come... And never arrived.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

OK, I think we are close to final on the new logo for my podcast with @0xBennyV

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@0xBennyV OK, I think I now have the episode logo also nailed down. Only need to do 700 more steps and we are ready to record!

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

Dear BC United. Running TV ads saying you have a plan to end BC's public safety crisis is not the same as having an actual plan. If you can't address the toxic drug crisis, which you have promised to make worse, you are simply full of hot air.

pluralistic, to random
@pluralistic@mamot.fr avatar
chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@pluralistic Welcome to our home. Wish you weren't sold out! Wanted to see your reading.

mjg59, to random
@mjg59@nondeterministic.computer avatar

I'll be at Bsides SF this weekend, if anyone wants to say hi

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@mjg59 Sadly not able to make BSides this year, but if you are around all week would be nice to say hi, I arrive Monday afternoon.

ChrisShort, to random
@ChrisShort@hachyderm.io avatar

Suggested Read: Organizations patch CISA KEV list bugs 3.5 times faster than others researchers find https://therecord.media/kev-list-vulnerabilities-patched-significantly-faster

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@ChrisShort This is interesting and supports that although not perfect, CISA's efforts are making a difference. One of the larger problems is those who need to hear their messages aren't listening (small/mid-market). This is a good start, now we need to push harder for smaller orgs to take heed.

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@ChrisShort This is also part of CISA's push. Stay tuned...

potus, to random

As president, I will always defend free speech.

And I will also be just as strong in standing up for the rule of law.

That’s not a choice for me as president to make.

That’s my responsibility to you the American people, and my obligation to the Constitution.

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@potus That's strange, I heard you want to ban TikTok.

privacylawyer, to random
@privacylawyer@twit.social avatar

This decision is going to be significant for all lawyers who work in cyber incident response and breach coaching. The IPC's decision that forensic reports are NOT privileged was upheld as correct by the ON Divisional Court. LifeLabs LP v. ON IPC https://canlii.ca/t/k4bqw

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@privacylawyer This will dovetail with other terrible practices already being practiced. When helping with incident response we are frequently asked to not produce a report and to only verbally explain any findings, including not recording the details ourselves. This is very bad.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

My piece from Global BC on the London Drugs cyber attack is now on their site: https://globalnews.ca/news/10459821/london-drugs-closed-tuesday-western-canada-cybersecurity-breach/

kevin, to random
@kevin@elephant.crime.group avatar

So have script kiddies in cybersecurity been replaced by prompt kiddies yet? Mostly unknowledgeable people using ChatGPT to write exploit scripts?

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@kevin All AI content is derivative, by definition, so most of it should be easily detected as nonsense... emphasis on should.

coffeegeek, to Espresso
@coffeegeek@flipboard.social avatar

Right now is one of the best times ever to buy a Breville espresso machine, as the entire Barista lineup, and the Bambino Plus, are all 20% off, factory authorized. Here's what's available, and thoughts on each machine.

cc @espresso

https://coffeegeek.com/blog/deals/brevilles-biggest-sale-on-espresso-machines/

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@coffeegeek Ut oh, error establishing database connection... :(

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@coffeegeek All better. Must have been Masto-DDoS

slashdot, to random
@slashdot@mastodon.cloud avatar

Dave

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@slashdot I'm sorry Dave.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

Well, Global BC is keeping me busy today, just filmed another piece for the 5 and 6pm news here in BC on the London Drugs "cyberincident". Tune in to watch me squirm and explain ransomware.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

For my followers in Western Canada I will be on CBC Radio's The Calgary Eyeopener Apr 30 at 8:10AM MDT (7:10 PDT) and on Global BC Morning News (TV) at 6:10AM PDT talking about the London Drugs cybersecurity incident.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

Hey hockey fans! It's not just Stanley Cup fever season, don't forget the Professional Women's Hockey League (PWHL) is still playing as well. TOR vs. NYC on now on CBC, SportsNet, and YouTube

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

It may be a poor time to point this out, but the Leafs could use to take a few pages from PWHL Toronto's playbook.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • Durango
  • magazineikmin
  • InstantRegret
  • hgfsjryuu7
  • vwfavf
  • Youngstown
  • slotface
  • thenastyranch
  • ngwrru68w68
  • rosin
  • kavyap
  • PowerRangers
  • DreamBathrooms
  • cisconetworking
  • khanakhh
  • mdbf
  • tacticalgear
  • ethstaker
  • modclub
  • osvaldo12
  • everett
  • tester
  • cubers
  • GTA5RPClips
  • normalnudes
  • Leos
  • provamag3
  • All magazines