fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

9.8K
active users

#spof

0 posts0 participants0 posts today
Replied in thread

@bert_hubert : nog enkele "puntjes":

• Elke medewerker die op een cloud- in plaats van een locaal account moet inloggen, wordt een SPOF (Single Point Of Failure) voor informatiebeveiliging (voorbeeld: security.nl/posting/859906/Spe).

• Microsoft's Authenticator app beschermt niet tegen steeds meer phishingsites ("evil proxies"): techcommunity.microsoft.com/t5

• SOC's (Security Operations Centres) kunnen bij het vuilnis en je bent afhankelijk van de cloudprovider voor jouw logs (security.nl/posting/862564/Mic).

www.security.nlSpeculatie over Politie-hack - Security.NL
#Cloud#SPOF#2FAFail
Continued thread

First up is this lecture by Mike Menzel who led the "System Engineering" efforts of the James Webb Telescope. #jwst

Infosec and CS in general loves to focus on failures, but I think we should focus more on successes. And the JWST is a extremely impressive success.

In this lecture he gives a overview of how they made it a success, even with so many things that could go wrong.

I mean the JWST had 344 "single points of failure"!? And yet it worked, perfectly, above expectation even.

Just go watch it, but do it when you have time to digest it, it's long.

It's currently at 845 views and 20 👍, which is criminally low for content this great. Let's try make it trend shall we?

youtube.com/watch?v=ceAEhkfRhT

YouTubeMike Menzel '81: Science & Systems Design of NASA's James Webb Space TelescopeTitle: Science & Systems Design of NASA's James Webb Space TelescopeBio: Michael Menzel has 39 years of experience in the aerospace, working 23 years in indu...

@feld @kravietz @PlaneSailingGames @GossiTheDog @vpz

ok, now I got to understand that the Keychain is an encrypted data structure stored somewhere (it could be Apple's key-value store). Reading this story I gather that a whole thing is encrypted with a symmetric wrapping key. This wrapping key can be either obtained by the syncing identity or derived from the recovery code.
So devices exchange the key exchange key among themselves during pairing? Could recovery code be seen as a #SPOF?

@koehntopp Klar, wird besser wenn es einen zentralen Key-Storage gibt und der, neben der ordentlichen Absicherung, über ein vernünftiges Backup/Restore-Konzept verfügt (Google Authenticator? 😂)…

Und wehe das Ding ist tot. Dann erschlägt einen der geballte Risikoklumpen! #SPOF

Replied in thread

@DaniEhm @hacks4pancakes

Like #journalists who are, slowly, migrating over here to #web3, governments need a longer and longer cycle to go through the approval and getting the correct #intern with management support and backing to empower said #intern is the key. I.T.'s a culture thing and iF it's not a turnkey solution a lot of government stuff just doesn't bother, imo.

Solutions for exist for clients that can side post the same to both networks exist which will help make the transition but even THAT requires #management buy in just do even do THAT so... I.T.'s an independent #leadership & #vision gap right now.

Helping management understand why this is important ( #SPOF#SinglePointOfFailure™ , #OligarchManipulationPlatform, #MLTL, etc ) requires them to have an understanding the fall of centralized one stop choke point platforms like #Meta #Instagram #WhatsApp #DelistedTWTR etc by taking back the Machine Learning Manipulation Timelines™ #MLMTL™ and get back to a chronological non-ML-TL #CNMLTL™.

The #fediverse is about to hit 11 million users soon. Most social media presence just redirects people to their web site anyways. 🤷‍♂️🤷‍♀️🤷🤷‍♂️🤷‍♀️🤷

Oddly a Non-ML-TL use to be Twitter as an option. 🧐

Just my 2¢. 👀👀