Irish, 20 years experience in Security, do a bit of everything. Expert in nothing except Powerpoint and fixing broken processes. Tweets/Toots are a mixture of #infosec, #hiking, #ireland and anything that makes me smile.
Posts
Irish, 20 years experience in Security, do a bit of everything. Expert in nothing except Powerpoint and fixing broken processes. Tweets/Toots are a mixture of #infosec, #hiking, #ireland and anything that makes me smile.
Irish, 20 years experience in Security, do a bit of everything. Expert in nothing except Powerpoint and fixing broken processes. Tweets/Toots are a mixture of #infosec, #hiking, #ireland and anything that makes me smile.
Irish, 20 years experience in Security, do a bit of everything. Expert in nothing except Powerpoint and fixing broken processes. Tweets/Toots are a mixture of #infosec, #hiking, #ireland and anything that makes me smile.
Irish, 20 years experience in Security, do a bit of everything. Expert in nothing except Powerpoint and fixing broken processes. Tweets/Toots are a mixture of #infosec, #hiking, #ireland and anything that makes me smile.
Irish, 20 years experience in Security, do a bit of everything. Expert in nothing except Powerpoint and fixing broken processes. Tweets/Toots are a mixture of #infosec, #hiking, #ireland and anything that makes me smile.
Irish, 20 years experience in Security, do a bit of everything. Expert in nothing except Powerpoint and fixing broken processes. Tweets/Toots are a mixture of #infosec, #hiking, #ireland and anything that makes me smile.
- Any incident is stressful, and at this time of year is even worse. I feel really really bad for everyone involved.
- Relying on users to pick a strong master password is not realistic. The #1Password approach appears to make more sense - force a secure default in the face of determined attackers who may ultimately succeed.
- I suspect for many users the "notes" fields are more sensitive than their passwords. Passwords can be changed.
- #LastPass will hopefully reflect on what design decisions drove them not to encrypt URLs, and if they have made any similar risk trade-offs elsewhere.
- Attribution (if possible) matters here for all of our threat models.
- I've seen little discussion of how the breach occurred, although the movement from dev environment->cloud backup is telling. The entire IT industry has walked itself into a cloud security nightmare, with easy-to-make mistakes or compromises having potentially severe consequences for many companies.
- #Bitwarden appears marginally better than LP, but I'm not seeing anything fundamentally better? (see 2). More like out of the frying pan into a small pot.
- I spent some time mucking around with Bitwarden self-hosted. Some of the guides to self-hosting I read were downright dangerous, and certificates were a problem. I'm unconvinced it's a realistic answer for all but a small few.
Irish, 20 years experience in Security, do a bit of everything. Expert in nothing except Powerpoint and fixing broken processes. Tweets/Toots are a mixture of #infosec, #hiking, #ireland and anything that makes me smile.
Irish, 20 years experience in Security, do a bit of everything. Expert in nothing except Powerpoint and fixing broken processes. Tweets/Toots are a mixture of #infosec, #hiking, #ireland and anything that makes me smile.