I *rarely* call out journalists. But this is an exception.

Hey @dannyjpalmer, this article you wrote is everything that is wrong in infosec.

zdnet.com/article/why-do…

ding ding schools in session!

1/?
First of all your headline is deliberately inflammatory.

but more critically, you miss the really interesting angle... how is it that these users are setup to fail?

2/?
The fourth estate is supposed to be elevating the discussion. You sir have let us down here. I don't know you... but I feel like you phone it in on this one.

The article should enlighten. At a few points you come close but don't drive home.

3/?
But most damning in my eyes is that the advice you give isn't actually helpful! MFA to stop client side attacks? Do you realize that I have never _once_ been stopped by MFA during a pen test? No competent attacker ever is... and you know why? Phishing.
4/?
The very defense that you tell folks to use is HOW attackers defeat MFA.

So in the interest of trying to make the world better, here's what you should have mentioned.

5/?
Phishing attacks work because attackers need user creds. Over the decades, IT/security has effectively forced attackers to the desktops.

We routinely monitor servers and network devices. We do a poor job on the endpoints. Attackers know this and go where visibility is lowest
6/?
Defenders *must* accept this reality. Logging on the endpoints is now a requirement. Testing to see how attackers can get on a desktop regardless of initial entry vector is key. Phishing, drive by download, malicious insider... it no longer matters.
7/?
Defenders must architect networks so lateral movement is *observable*. pVLANs, host firewalls, etc. All allow us to do that. Many options can be done with just host native tooling. No need for fancy EDR/XDR.
8/?
Also, let's make a shift on what is protected. Build your detections around safeguarding the most important thing. Hint: the device isn't that important to the attacker. It's a launching point to the data which is THE thing.
9/?
So please, please, I beg you. (I mean all of us in infosec in any shape)

STOP BLAIMING USERS.

10/?
If you're not convinced about this, consider this. In no other industry do we continue to blame the user as we do in IT/infosec.

In an industrial facility, if someone gets hurt, OSHA (or similar) reviews things. What allowed that worker to get hurt?

11/?
If you've made it this far.... thanks. Demand better of everyone. Including me... ranting like this doesn't help much... it made me feel a bit better. And I HOPE it gives you a glimpse into how things can be different.

This status quo sucks. We have to shift thinking.
fin.
OMG! Major shoutout to @pathetiq who's comment on this article made me go down this ranty tweet path.
Sooo... coming back to this.

Has the video been swapped? I get an interview with Maya Horowitz, not Troy Hunt who's quoted in the article.

Can someone verify this? I'd like to see if I'm doing something wrong.

FWIW: I quite liked the interview... but it doesn't match the text

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Mick Douglas

Mick Douglas Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @bettersafetynet

30 Mar
I don't normally repost stuff from reddit or other sites, but this is *important*

arstechnica.com/tech-policy/20…

A thread of things to know why US citizens should care deeply about this.

1/?
Many (most?) folks in the US know that the internet was developed by the US by DARPA.

What few do know is that year over year, the US has been slipping in terms of broadband... by every measurable metric.

I'll cover them one at time so you can understand how bad it is
2/?
The US does *not* have the fastest internet speed. We're ranked 11th in the world!

decisiondata.org/news/analysis-…

3/?
Read 12 tweets
19 Aug 20
I hate that I'm going to have this little thread. Buckle up.

Yesterday I made a passing reference to the fact that I take meds for treating my ADHD.

(I hope you know how rarely I cuss)

Fuck you to those who sent me hate DMs. Seriously. You are horrible people.

1/?
I know I shouldn't feed trolls, but this has to be said.

While not perfect, I am a *damn good* tech, biz owner, instructor, and hacker.

You reducing my accomplishments -- while having so very few of your own -- is telling.

2/?
I've opened a boutique infosec consultancy. I am a certified SANS instructor. A member of the IANS faculty... and someone who's not done yet. I've got plans.

For you to say that this is all thanks to a "pill that makes me not be a retard" is about as ugly as it gets.

3/?
Read 17 tweets
6 Apr 20
Clue #3 - a
iVBORw0KGgoAAAANSUhEUgAAAG8AAAB/CAYAAADhE5z7AAAABGdBTUEAALGPC/xhBQAAACBjSFJN
AAB6JgAAgIQAAPoAAACA6AAAdTAAAOpgAAA6mAAAF3CculE8AAAACXBIWXMAACToAAAk6AGCYwUc
AAAABmJLR0QAAAAAAAD5Q7t/AAAAJXRFWHRkYXRlOmNyZWF0ZQAyMDIwLTA0LTA2VDE1OjAzOjMx
Clue #3 - b
KzAwOjAw9YrnxQAAACV0RVh0ZGF0ZTptb2RpZnkAMjAyMC0wNC0wNlQxNTowMzozMSswMDowMITX
X3kAAAUTSURBVHhe7Z0LUuMwEESTHAI4F+QUFMehOASfa/G7RFbjtdgsJUutuDPxJP2qBuTEliU1
gWlJJOtdYiVCslmv16taXF9fr97e3sbTl4O1q9TeS4iMlZqvvKurq9XX19d4tAxMvO/v7/Hossi/
Clue #3 - c
LDfD1waXOkhLBxJPLBOJFxiJFxiJFxhYvKVlm6JDvPv7ewm4QMw0zIrkA3evr682WeOG3bPUlv34
/Pwcz44D0q8M5W+e+UB7ZQpfaAmLjLw/yjYDI/ECI/ECI/ECQxPv5uZmLAkvKOKZcI+Pj+OR8GIQ
b7vdrpKhHRb5DomPj4/V3d3dUGGLl5eXyVXwU6zal9pxrDgGrjMRrRkEex6BNcNSuu5YgdA9w2I/
Read 9 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!