Off-Topic Friday
from shellsharks@infosec.pub to cybersecurity@infosec.pub on 22 May 16:47
https://infosec.pub/post/46836348

Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

#cybersecurity

threaded - newest

M33@piefed.world on 22 May 17:36 collapse

Half off topic : how do you deal with infosec information overload ?

Repetitive headlines from multiple sources, considering most of them you must follow anyway…

moonpiedumplings@programming.dev on 22 May 17:48 collapse

99% of cybersecurity news is what I call “cyberslop” and probably actively harmful to consume.

The vast majority of it is either so trivial that somebody else handled it, and you don’t need to do anything. Like they often overhype a malware that doesn’t do any novel techniques to get onto your systems and has already been added to the antivirus database anyways.

Or it’s so grand in scale that you can’t do anything, like nation states doing nation state things. Interesting yes, but it’s ultimately a waste of my time to consume because it’s not actionable.

Only a tiny fraction of news is actually actionable. It’s usually stuff like cve’s or zero days and the like. I just only really pay attention to those and ignore everything else.

Better, is probably to subscribe to an actual vulnerability feed so you don’t have to go through the news cycle.

M33@piefed.world on 22 May 18:30 collapse

Even looking at CVE causes so much fatigue.

Actually I ended up deploying opencve with very few alerts for high cvss score only for critical assets like domain controllers, firewall and vpn gateway.

Even that can’t be the only trusted and exhaustive source, because of sometimes you miss vulnerability that affect your product but is not directly assigned to it.

(-‸ლ)

moonpiedumplings@programming.dev on 22 May 19:07 next collapse

Automatically patch is another solution.

Of course it’s difficult on the tech side. You can do something like failover/high availability, and then auto update one and it fails over if something breaks.

moonpiedumplings@programming.dev on 22 May 19:08 collapse

How many devices and of how many types do you manage with how many people?