back
user profile

_tk_

3,918karma·625submissions·November 12, 2019
about
Information Security Officer at Fortune 50 global corporation.
recent activity (625 total)
comment
I work in a team of 100+ cyber professionals, and consume the typical infosec content that’s out there. None of the authors that I know, or any of my peers argue in this presumed way. Additionally, as…
5y ago·view thread
comment
If there’s a business need, you can secure a wooden box on the sidewalk in a way, that it is almost impossible to break in. It will be very costly, but if profit or IP depends on it, one can find a wa…
5y ago·view thread
comment
There are other stakeholders involved in a transaction like this, most importantly banks. Payments, especially large ones, are heavily regulated. You cannot hack a finance department and issue a mone…
5y ago·view thread
comment
Could you elaborate on where you see the hardening taking place? Colonial had a threat actor in their network and by paying the ransom, they supposedly left without doing any more damage. I don’t thin…
5y ago·view thread
comment
Disclaimer: I work as a CISO in a large corporation. The interesting bit in this article is not necessarily the sum of the ransom, but that Colonial decided to pay quasi-immediately. It seems as if t…
5y ago·view thread
comment
I can’t speak for Thomas- but generally you’d want to invest your money in a vuln that is rather static. Web applications with attack surfaces that are constantly changing are not a good fit for a sop…
5y ago·view thread
comment
I feel the same way about this issue (the chat and the photo) and the response by Troy just feels... abysmal. He starts out by saying: "The photo, however, is the one most consistent with others …
5y ago·view thread
comment
Can someone elaborate what the satirical part of this article is? I’m not sure I understand. Or in other words: I agree with this version very much.
5y ago·view thread
comment
Correct. This is an argument made from a corporate network perspective.
6y ago·view thread
comment
To maybe give some perspective _why_ security people say that security by obscurity is bad - and especially serving ssh via port 64323: Typically you want to know who is connecting to what server via …
6y ago·view thread
comment
With the numbers shown "the entire internet" is really more than exaggerated and thus the title seems pretty clickbait-y.
6y ago·view thread