5 ms·
CNAPPs and CSPMs are extremely common tools in cybersecurity. This is my concern. If you're in cyber and don't have knowledge of these things you're either in s
by ryanSrich 2y ago
CNAPPs and CSPMs are extremely common tools in cybersecurity. This is my concern. If you're in cyber and don't have knowledge of these things you're either in something insanely niche, in research of some sort, or lack critical knowledge that you should have. There's a big responsibility as a security practitioner to stay up to date on new tools and techniques. CNAPP and CSPM is not some new thing that was invented last year. It's been around for a decade.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- arachnids 2y agoYou might want to google the person you’re arguing with
- brailsafe 2y agoOne of those beautiful HN moments where just clicking the profile link would have helped them shift from such an authoritative tone.
- csomar 2y agoCSPM solutions are what corporate buys when they don't want to invest in security. It is rubber-stamping and ass covering. From my experience most people involved with such platforms are rather technical sales people than actual security experts.
- philsnow 2y agoI’ve never heard or seen either of those terms before reading this thread. What you’re calling “CNAPP” I’ve been calling “endpoint security”. I’ve been building internal “CSPM” tooling since 2014 with like raw cloud api calls feeding into graphviz, CI-like tests in a terraform repo, transforming the state of a set of cloud accounts into a form I can shove into z3 and ask questions about, that kind of thing, but never heard it called that. I suppose if your company prefers to build over buy, you won’t be exposed to the kind of knowledge and vocabulary that buyers in the space use to orient themselves.
- wglb 2y ago> . If you're in cyber and don't have knowledge of these things you're either in something insanely niche, in research of some sort, or lack critical knowledge that you should have Here are some things that counter this: https://users.ece.cmu.edu/~adrian/731-sp04/readings/Ptacek-Newsham-ids98.pdf https://users.ece.cmu.edu/~adrian/731-sp04/readings/Ptacek-N...: A paper that rocked the security industry at the time. Tptacek also was cofounder of Matasano, now part of NCC; also cofounder of Latacora. More info: https://sockpuppet.org/me/ https://sockpuppet.org/me/ Also the co-author of https://cryptopals.com/ https://cryptopals.com/, https://microcorruption.com/login https://microcorruption.com/login. The author of https://www.latacora.com/blog/2018/04/03/cryptographic-right-answers/ https://www.latacora.com/blog/2018/04/03/cryptographic-right..., https://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/, https://sockpuppet.org/stuff/dnssec-qa.html https://sockpuppet.org/stuff/dnssec-qa.html, These are about what I call hard-core security, hardly insanely niche, and hardly lacking critical knowledge.