4 ms·
A cybersecurity company was hacked — what an irony
by x1unix 1y ago
A cybersecurity company was hacked — what an irony
- vasco 1y agoNot so much irony as it's a great vector to get inside an org. Security / monitoring agents that you deploy everywhere and don't suspect when you see they exfiltrate data, since you're expecting the telemetry anyway.
- x3n0ph3n3 1y agoEvery time some security compliance goon comes by telling me to install an agent on all of our servers to meet some security compliance requirement, I remind them that they are asking me to install a backdoor on our servers and handing the keys to a 3rd party.
- natebc 1y agoThe Crowdstrike Falcon Sensor agent (with a kernel module) establishes TLS connections to several random AWS endpoints. I really have no idea how security people think this is a good thing aside from checkbox compliance but man-o-man do they love it.
- neffy 1y agoWell honestly, this security person thinks its a terrible idea - but needless to say the people selling those systems disagree - and for non-technical management, it ticks the compliance box and they get back to their jobs.
- goalieca 1y agoThey are also telling you how to cover-your-ass once a breach happens.
- ExoticPearTree 1y agoYou will not be faulted for anything if the security company gets hacked and you get hacked through it. Probably a lot of sleepless nights to fix your infra, but that's it.
- x3n0ph3n3 1y agoTell that to my customers.
- ExoticPearTree 1y agoYour lawyers and your PR department will do that, emphasizing very strongly that you did nothing wrong and their security is your utmost priority.
- 1oooqooq 1y agomost of those companies nowadays are just insurance policies for CISO, who are just insurance policies for the CEO/CTO.