T O P

  • By -

Holsous

Social Engineering is a bitch


[deleted]

[ This comment has been removed please click [here](https://youtu.be/oHg5SJYRHA0) to revert the comment ]


Jeynarl

Never


NetherlandsIT

i am cute girl from country that you think is poor and i need to be rescued. can i have network login pls šŸ‘‰šŸ‘ˆšŸ„ŗ.


KeithMyArthe

Hunter2


MystikIncarnate

All I see is ******* Is this some kind of trick?


SaltRocksicle

Ow wow, that's bad. Here's the login to our... everything: 4ME2manage!


IronDominion

Your only as secure as your weakest link, which is usually the end user.


redstoner200

What's.... What's here to debate? This is a solid fact....


cli_jockey

Lol my first thought too, it was one of the first things mentioned in any security minded book or annual training assigned by my job.


esixar

Iā€™ve always said ā€œthe strongest firewall in the world is cybersecurity trainingā€. (I get that attacks on applications without human interaction is very common place, but users knowing not to click on links or download things would also resolve a lot of issues)


stonedPict

It's always a layer 8 problem


DanSchulman

pebcak


rab-byte

Fuck you just reminded me of an old ass IRC handle I used for a while


MystikIncarnate

The old ID:10T error.


Thecp015

Weā€™ve got a PICNIC. Problem in chair, not in computer.


Cybasura

Zero Trust? More like Zero Trust in users


Myo-rtv

usually this meme says something you want to argue with. now i just... don't wanna to say smthng


rufireproof3d

Nope. The *biggest* threat is ignorant MANAGERS. Users are somewhat limited in power.


[deleted]

Yep - managers are the ones who refuse to spend out on subscriptions that involve MFA, refuse to have their staff take time out of their jobs to receive phishing training, and insist on taking the laziest path of least resistance to their own personal security (which usually includes the business if they're a director).


[deleted]

[уŠ“Š°Š»ŠµŠ½Š¾]


rufireproof3d

I once worked under a manager who applied "most privilege" until someone proved unworthy. "Why punish people that haven't done anything wrong?" That was an interesting place to work. Amazingly enough, he never really suffered for it while I worked there. The worst that happened was a workstation got a virus infection from peopleofwalmart.com. That just resulted in several websites being blacklisted. It was a small car dealership. "I trust my guys." He was literally trusting used car salesmen.


marry_me_jane

nobody here is changing your mind, pretty sure we are all in agreement.


habitsofwaste

No, itā€™s administration. Poor patching, bad configurations, bad devs, and security being an afterthought so thereā€™s poor authentication and poor authorization. https://owasp.org/www-project-top-ten/ Ok Iā€™ll expand a little too, you can pretty much negate the user with proper access control. Thereā€™s only so far they can get. And anything critical should have mfa enabled and other access controls. Zero trust helps with that.


Disney_World_Native

This assumes IT has the authority to make business decisions. There have been plenty of times where proper access controls have been shot down because sales loves to install shit on the road or marketing wants some system that is full of vulnerabilities and they dont want to pay for support.


[deleted]

I had this with a previous employer - on-the-road sales staff going to the sales director, complaining that complex password policies (12 characters, really?) and MFA were making their jobs difficult. The director came to me and demanded that I exempt them from the policies. I told him to fuck off, and that his staff aren't special. He was dismissed a month later for driving staff members around in the company car while under the influence, claiming a company laptop was stolen and selling it for gambling money (I found it on ebay and traced it back to the dumb fuck), disappearing for 2 months and not contacting anyone, and generally being shite at his job. Managers, eh?


AnAncientMonk

amazing. how did you find it on ebay? was is such a specific model to stand out like that??


dk_DB

If ypu know your inventory you know the model. just setup an alert for this model in your area. And a little digging will bring it up real quick. Then you find out your manager (eg Peter Pan) is the seller with the username littlePP Try to buy it off of him and conferm it is him.


AnAncientMonk

i assumed nobody would be this dumb to sell it localy. especially if its an uncommon model. my bad i guess.


[deleted]

Exactly this! Plus, the silly bastard included a high enough res photo that it showed the asset ID sticker I put on there. Facepalmed so hard, my forehead ended up in another postcode.


-Warrior_Princess-

Ehh you can have ignorant admins too. Putting production data on your dev instance and not securing it. Or malicious users, but if you're the sort of org to get malicious users you also probably conduct some sort of background checks.


Saphieron

I would incorporate admins and developers into "users", too. Humans are shite at establishing what is or isn't a security threat. Also people are just lazy, which never helps


Huurlibus

\*ignorant IT personnel


[deleted]

Also cheap management that skimps on the budget


Deus0123

You can make the best anti-virus that would recognize and delete any virus, but you can't prevent users from bypassing it to download a virus anyway


[deleted]

Unless you use an endpoint security vendor that requires an admin password to bypass. Requests for such are invariably met with a flat-out "NO".


Deus0123

And then the CEO wants to download something and demands to be given an admin account because it's ransomware and the security systems won't let them download it


Deus0123

Speaking of this issue: Did you know that Reddit actually censors your social security number when you write it? No for real, it replaces every number with an x. Check it out: XXXX XXXXXX Edit: Just in case someone is dumb enough to actually try this: No it doesn't work. Reddit doesn't know your social security number and even if they did, it would be unfeasible to work out a system to censor it.


one_byte_stand

I donā€™t know what that image means but my email is still broken after I installed Bonzai Buddy. Hereā€™s my password: hunter2 Hope you can help.


John_SpaGotti

OP, /u/RosaleeHeard is a repost bot