@chetwisniewski@securitycafe.ca avatar

chetwisniewski

@chetwisniewski@securitycafe.ca

Director, Global Field CTO at Sophos, frequent speaker and press go to. Said opinions are mine, not the company.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

privacylawyer, to random
@privacylawyer@twit.social avatar

This decision is going to be significant for all lawyers who work in cyber incident response and breach coaching. The IPC's decision that forensic reports are NOT privileged was upheld as correct by the ON Divisional Court. LifeLabs LP v. ON IPC https://canlii.ca/t/k4bqw

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@privacylawyer This will dovetail with other terrible practices already being practiced. When helping with incident response we are frequently asked to not produce a report and to only verbally explain any findings, including not recording the details ourselves. This is very bad.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

My piece from Global BC on the London Drugs cyber attack is now on their site: https://globalnews.ca/news/10459821/london-drugs-closed-tuesday-western-canada-cybersecurity-breach/

kevin, to random
@kevin@elephant.crime.group avatar

So have script kiddies in cybersecurity been replaced by prompt kiddies yet? Mostly unknowledgeable people using ChatGPT to write exploit scripts?

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@kevin All AI content is derivative, by definition, so most of it should be easily detected as nonsense... emphasis on should.

coffeegeek, to Espresso
@coffeegeek@flipboard.social avatar

Right now is one of the best times ever to buy a Breville espresso machine, as the entire Barista lineup, and the Bambino Plus, are all 20% off, factory authorized. Here's what's available, and thoughts on each machine.

cc @espresso

https://coffeegeek.com/blog/deals/brevilles-biggest-sale-on-espresso-machines/

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@coffeegeek Ut oh, error establishing database connection... :(

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@coffeegeek All better. Must have been Masto-DDoS

slashdot, to random
@slashdot@mastodon.cloud avatar

Dave

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@slashdot I'm sorry Dave.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

Well, Global BC is keeping me busy today, just filmed another piece for the 5 and 6pm news here in BC on the London Drugs "cyberincident". Tune in to watch me squirm and explain ransomware.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

For my followers in Western Canada I will be on CBC Radio's The Calgary Eyeopener Apr 30 at 8:10AM MDT (7:10 PDT) and on Global BC Morning News (TV) at 6:10AM PDT talking about the London Drugs cybersecurity incident.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

Hey hockey fans! It's not just Stanley Cup fever season, don't forget the Professional Women's Hockey League (PWHL) is still playing as well. TOR vs. NYC on now on CBC, SportsNet, and YouTube

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

It may be a poor time to point this out, but the Leafs could use to take a few pages from PWHL Toronto's playbook.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

Anyone know any artists who are interested in creating a logo for a new podcast? I would like to hire someone to create a logo and then make it CC licensed when finished for my new podcast I'm working on with @0xBennyV

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

With this wave of unrepentant mediocre garbage overwhelming the internet due to SEO and generative AI models it feels like enshitification might be here to stay.

I'm feeling some optimism today. We seem to be entering an age of authenticity. We are rejecting mass produced junk and much of the drive toward social media, TikTok, and their ilk seem to be a way of seeking real people and real things. Of course influencers are no more real than ChatGPT, but I think is on the rise.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

I said something yesterday at the Vancouver Cloud Summit that I will repeat here:

"Logs are cheaper than lawyers".

When deploying to the cloud, especially "cloud native" applications you must ensure you are collecting logs for analysis, threat hunting, and forensics. Platforms have logging off and often charge for it. Turn them on, protect them and USE THEM.

GottaLaff, to Canada
@GottaLaff@mastodon.social avatar

So we just made our usual reservations for our next trip up to BC, , but something was different this time.

We didn't have to make them for a return trip to California.

Shit's getting real. 🇨🇦

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@GottaLaff I moved from Michigan to BC just over 20 years ago. If there is anything you would like to know or need help with, don't hesitate to reach out.

franksting, to random
@franksting@theblower.au avatar

I agree with Roman Mars, this is the greatest record of all time. https://tidal.com/track/77632987

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@franksting what is it? Link requires a login.

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@franksting oh, that's a good favourite, I think I have it on LP.

franksting, to random
@franksting@theblower.au avatar
chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@franksting not exactly covered, only 50 from what I hear, but more than enough to be scary in April. El niño is not our friend

jvagle, to random
@jvagle@mastodon.lawprofs.org avatar

Wired, June 1997

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@jvagle on-line. Been awhile since I've seen that. Even America was Online.

mattblaze, to random
@mattblaze@federate.social avatar

I just found out X/Twitter unilaterally "verified" my old and dormant account there ("because you're an influential user"), now making me look like I'm an idiot who's voluntarily paying Musk eight bucks or whatever it is a month.

A free gift of defamation.

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@mattblaze I wonder what their criteria is? Clearly they're desperate to bring back their "influencers." I had a verified check before and was a "prominent figure" by whatever that subjective quality is. Mine has not got it back (yet), but I only had 14k followers.

I'm not going back, but I am curious what devious plan is being attempted.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

Please tech companies, keep adding AI to your services as a "premium" paid for feature that allows me to avoid it and also not have to pay you. Win-Win.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

May everyone in Taiwan find themselves shelter and safety during this frightening natural disaster. Please share legitimate charities who may help and steer people away from opportunistic fraudsters.

chetwisniewski, to infosec
@chetwisniewski@securitycafe.ca avatar

I'm very excited to guest lecture tomorrow to a class of University of British Columbia's students on the pros and cons of multifactor authentication technologies. Always fun to engage with students and learn from their perspectives.

charlie.savage.nyt, to random

Test to see if this shows up on Mastodon

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@charlie.savage.nyt It does indeed.

chetwisniewski, to random
@chetwisniewski@securitycafe.ca avatar

As a former President of the Vancouver SecSIG and ISC2 chapter I declare myself President Emeritus.

JoeUchill, to random
@JoeUchill@mastodon.social avatar

I've been thinking about something recently and, I dunno, maybe I'll make it into a talk.

My sense is that a lot of the infosec research done by the private sector and individual researchers is unavailable to policy researchers.

That's not to say it's technically unavailable. I just don't get the sense that information outside the research databases (JSTOR, ProQuest, etc.) is in the line of sight of someone doing academic research.

chetwisniewski,
@chetwisniewski@securitycafe.ca avatar

@JoeUchill This is an incredibly interesting and difficult problem. It has taken me 25 years of getting to know people and the "leaders" who drive their research to sort the wheat from the chaff. Good people are pressured to publish garbage, while others publish amazing work for the worst orgs. Keep us in the loop, would love to help if I have anything to offer.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • tacticalgear
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • Durango
  • cubers
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • ngwrru68w68
  • kavyap
  • GTA5RPClips
  • provamag3
  • ethstaker
  • InstantRegret
  • Leos
  • normalnudes
  • everett
  • khanakhh
  • osvaldo12
  • cisconetworking
  • modclub
  • anitta
  • tester
  • megavids
  • lostlight
  • All magazines