Profile avatar
infosecgreybeard.bsky.social
Grumpy old InfoSec beard. Whether it's physical security or grumbling about firewalls and governance, I ramble about it all.
445 posts 239 followers 176 following
Regular Contributor
Active Commenter

A quick British English lesson for the non Brits on here. My wife just said to an overseas call centre worker as she was placed on hold again "Thank you, you've been brilliant so far"! Translation "You've been barely adequate and I have extremely low expectations for the rest of the call"

It's interesting to hear people say that welfare spending should be cut to boost defense spending. But these people are missing the point. Welfare spending is defence spending. A fair, healthy society is far more resilient to propaganda and sabotage.

Worth a watch: Head of Signal, Meredith Whittaker, on so-called "agentic AI" and the difference between how it's described in the marketing and what access and control it would actually require to work as advertised.

The Hot Fajita chillis are cropping well. Sweet, juicy and blow your head off!

If a cloud provider uses a shared system across its data centres, then it's not resilient and can only be considered a single data centre.

The same can also be said about company output, as well as public news.

Companies: We're a multi-cloud organisation! Reality: Prod based entirely in AWS and they use Google Workplace

I love tech start-ups. They're so proud of their unique approach, excellent skills, fantastic product and amazing people. Which, it turns out, is just like every other tech start-up. And is a strong indicator that they're massively wrong about their own capabilities!

It's going to be a warm one today, and hotter tomorrow. Take care everyone, close your windows and curtains or blinds and try to keep at least some parts of your home cool. (Bonus points if you recognise the image!)

It was a bit warm in London today.

This morning I opened the fridge to be met by a horrible smell. I searched the entire fridge for whatever had rotted so badly that it was emitting the terrible stench before realising it was the French camembert we'd bought t coupe of days ago. Luckily, I had a new French fridge freshener at hand.

Billionaires make bad politicians. Musk and Trump think business smarts translate to government, but politics isn’t about winning at all costs. It’s compromise, not control. And history shows: when entrepreneurs enter politics, chaos usually follows. Full story by ‘Slicker’ in the latest issue.

Both Microsoft and Samsung are advertising AI assistants at the moment, but all the adverts don't actually provide a valid use case for business. It's almost as though they're solutions looking for a problem..... 🤣🤣🤣

I can't see a Nutella product without thinking of this story: www.derrydaily.net/2016/01/15/d...

Controversial as it may sound, I've never found a long term financially successful company who runs Macs, Google Workplace, Slack and Okta. Failing to.put commercial realities before personal preference is never a positive sign.

What product can you find that AI has randomly been deployed into today?

What happened in LA was page 1 of the Dictator's Playbook. Removing gun ownership is page 2. The constitution was ignored on page 1 and it will be ignored again on page 2.

I wholly approve of Martha's Tuesday vibes.

The British Army is running an advent where a soldier proudly tells his friend that he's trained in "Cyber defense". The trouble is that no one has heard of this qualification in the private sector and have no idea what it's worth or enables the holder to be able to do.

It never fails to amaze me that so little progress has been made on minimising desktop OSes to the point that they become wrappers around applications, in the same way that containers have done for server applications. Especially as this was hypothesised in the 1990s.

Replicating data != Backup Replicating data is done for resilience whereas backup are more about integrity. Unfortunately, many people in technology seem to have forgotten that.

Most companies aren't following the rules around DPOs. I've seen DPOs who aren't independent, who don't report to the C-suite, DPOs who don't know anything about the role and it's requirements and who aren't training staff. DPOs are vitally important to InfoSec so make sure you support your DPO.

Risk is the chance that a threat actor with sufficient capability will come across a vulnerability and act on it, causing a loss. If you can minimise vulnerabilities, make them hard to act on, minimise threat actor access to them or minimise losses you minimise the risk.

Call me old and grumpy, but instead of golf days, track experiences and meals, why don't security vendors spend the money on product development, supporting the 3rd party vetting process and giving great support?

Since when did InfoSec Europe become a giant bunk off work day? It seems that half of my LinkedIn feed is people looking embarrassed to be photographed with various sales people on their stands.