4 ms·
If I’ve learned anything in decades of working in infosec, it’s to never underestimate the ingenuity of a determined attacker. Read through any modern multi st
by ipython 7y ago
If I’ve learned anything in decades of working in infosec, it’s to never underestimate the ingenuity of a determined attacker.
Read through any modern multi stage remote exploit. The amount of engineering required to pull these stunts off - reliably no less - is truly staggering, and yet attackers continue to innovate and develop new techniques and even more complex exploits.
And you overestimate the competency of the defenders: sysadmin? What small business has a dedicated sysadmin? It’s not like we are talking about running a global hosted chat service like slack here. (Oh wait...)
BTW Persistence for the key in memory is trivial: create a shared memory segment and store the key there, with a ttl.