back
user profile
_tk_
3,918karma·625submissions·November 12, 2019
about
Information Security Officer at Fortune 50 global corporation.
recent activity (625 total)
comment
Ross Anderson's lecture Security Engineering can be found here[1]. I can highly recommend it. [1]: https://www.youtube.com/watch?v=2qNlv435L5g&list=PL88-McA5nK... …
comment
Two things are truly horrifying if this is true. 1. Just how normalized this behavior has become in Silicon Valley upper management circles. 2. That this has not gotten out earlier. Hundreds or thousa…
comment
Phishing campaigns barely do any good if they are well-prepared and accompanied with good communication in a company environment. Employees need to be aware of phishing tests and have to have a way of…
comment
There is nothing comparable to Microsoft Office. 99% of white collar employees globally know/have to know MS Office. Every government uses MS office. Every sector uses MS office. Who doesn’t use …
comment
I guess artists should charge extra for seats where the on-site EMTs can see you.
comment
It has been obvious for some time now, that Microsoft uses security merely as a means to enhance profit. See all the security improvements that an organization gets, when upgrading from E3 to E5. Trus…
comment
Ikigai is one of these concepts, that I suspect to be mostly substituted by western life coach BS, which mostly means common sense application of modern-ish western philosophy to daily life including …
comment
Good job! I’d be interested to know how you’re coming to the conclusion that the amount of affected users is likely higher. From the looks of it, I’d suspect that at least some of the sites you mentio…
comment
They mention they are working on their own QC. In corporate logic, using a third party projection to make a statement about where you are headed seems absolutely legit to me.
comment
Not sure what the protocol is. Delete the post entirely? Let the mods take care of it?
comment
Take a look at FIRST‘s FAQ wrt Supplemental Metrics. It’s so complicated you have to have a degree in CVSS to properly rate a vuln and it’s also highly subjective - which they want it to be. [1]: htt…
comment
Could you elaborate why them being state owned was a contributing factor? We’ve seen countless similar incidents with private MSSPs as well.
comment
I cannot really speak to the "Radio Equipment Directive", but what the author claims or implies with regards to the Cyber Resilience Act is not correct. These Annexes explain the imposed Vul…
comment
All the tooling that's been integrated everywhere is reliant on CVEs and CVSS. All vendors issue their vulns with CVEs, not ZoomVEs. Disruption is not likely unfortunately.
comment
I guess it depends on what field you are talking about. I'd say that the typical scores on CVEs can be helpful indicators, but that's really it. I'd agree with you, that everyone(?) in …
comment
Somewhat off-topic, but what do you feel like are the best techniques to find the artists in Tier 2 and 3? I face a similar conundrum just in a different genre.
comment
Are they though? The paper is lacking evidence for this premise.
comment
Looking things up in other urban areas does not yield this result for me. The grouping could be changed though. I can't click some Dots because there's on overlap with another dot. I like th…
comment
Better than APTXYZ, but it’s still impossible to remember more than three of these.
37 pts