• 1 Post
  • 172 Comments
Joined 1 year ago
cake
Cake day: July 1st, 2023

help-circle













  • If the accounts were logged into from geographically similar locations at normal volumes then it wouldn’t look too out of the ordinary.

    The part that would probably look suspicious would be the increase in traffic from data exfiltration. However, that would probably be a low priority alert for most engineering orgs.

    Even less likely when you have a bot network that is performing normal logins with limited data exfiltration over the course of multiple months to normalize any sort of monitoring and analytics. Rendering such alerting inert, since the data would appear normal.

    Setting up monitoring and analysis for user accounts and where they’re logging from and suspicious activity isn’t exactly easy. It’s so difficult that most companies tend to just defer to large players like Google and Microsoft to do this for them. And even if they had this setup which I imagine they already did it was defeated.







  • You’re right, we should all stop talking about and discussing problems and risks. And silently stare at each other tille someone else comes up with a solution.

    Step 1 in fixing a problem is to recognize and get awareness for it.

    Step 2 is garnering interest from the people who are qualified to actually make realistic proposals

    Step 3 is collaborating on ideas to figure out what will or won’t be effective, and to create new ideas by returning to step 2.

    Step 4 is to circle back to step 1, but for actions and implementations. Repeat ad nauseum.

    **We’re Still in Step 1. ** Complaining that we aren’t getting to the next step quick enough without providing assistance to get there is incredibly meta to this process 🤔