Top Banner
Crazy like a Fox #Infosec Ideas that Just Might Work™ @jschauma
20

Crazy Like A Fox - #Infosec Ideas That Just Might Work

Feb 14, 2017

Download

Internet

Jan Schaumann
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Crazy like a Fox #Infosec  Ideas  that  Just  Might  Work™  

@jschauma  

Page 2: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Think differently. Use  an  adverb  to  describe  our  mental  process  correct.  

@jschauma  

Page 3: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Get pwned. Hard.

@jschauma  

Page 4: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Get pwned. Hard.

@jschauma  

(Then  blame  APT.)  

Page 5: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Pay outside consultants to tell you what you already know.

@jschauma  

Page 6: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Pay outside consultants to tell you what you already know.

@jschauma  

If  they  come  up  with  other  ideas,  one  of  you  is  likely  wrong.  Figure  out  who.  

 

Page 7: Crazy Like A Fox - #Infosec Ideas That Just Might Work

mount  -­‐o  noexec,nosuid,nodev  /home  mount  -­‐o  noexec,nosuid,nodev  /tmp  …  

@jschauma  

mount –o ro /

Page 8: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Just because Microsoft does it, doesn’t necessarily mean it’s terrible.

I  <3  Kerberos.   @jschauma  

Page 9: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Forget Network ACLs.

@jschauma  

Page 10: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Forget Network ACLs.

@jschauma  

You’ve  been  pwned  already.  

Page 11: Crazy Like A Fox - #Infosec Ideas That Just Might Work

root ssh for everybody!

@jschauma  

Page 12: Crazy Like A Fox - #Infosec Ideas That Just Might Work

root ssh for everybody! Most  frequently  executed  sudo(8)  commands?  Survey  says:  bash(1),  su(1)  

@jschauma  

Page 13: Crazy Like A Fox - #Infosec Ideas That Just Might Work

No login for you! Come back… never!

Sorry,  not  a  fox.   @jschauma  

Page 14: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Reboot, refresh, repeat.

@jschauma  

What  could  possibly  happen?  

Page 15: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Security  is  everybody’s  responsibility.  

@jschauma  

Page 16: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Embrace “cyber”. It’s  YUGE.  

@jschauma  

Page 17: Crazy Like A Fox - #Infosec Ideas That Just Might Work

@jschauma  

Focus

Page 18: Crazy Like A Fox - #Infosec Ideas That Just Might Work

@jschauma  

Focus

Srsly.     Stop.  

Doing.  Unimportant.  Shit.  

Page 19: Crazy Like A Fox - #Infosec Ideas That Just Might Work

Think differently. •  Get  pwned.  Hard.  (Then  blame  APT.)  •  Pay  consultants  to  tell  you  what  you  already  know.  •  Learn  from  Microso].  (Don’t  reimplement  Kerberos.)  •  mount  –o  ro  /;  mount  –o  nosuid,noexec,nodev  /home  •  Forget  ACLs.  (You’re  already  pwned.)  •  root  ssh  for  everybody!  •  No  logins  whatsoever.  (User  login  =>  reimage.)  •  Auto-­‐reboot  and  auto-­‐update  regularly.  •  Make  security  everybody’s  job.  •  Embrace  “cyber”.  

@jschauma   Focus.

Page 20: Crazy Like A Fox - #Infosec Ideas That Just Might Work

@jschauma  

Think differently.

Focus.

•  Get  pwned.  Hard.  (Then  blame  APT.)  •  Pay  consultants  to  tell  you  what  you  already  know.  •  Learn  from  Microso].  (Don’t  reimplement  Kerberos.)  •  mount  –o  ro  /;  mount  –o  nosuid,noexec,nodev  /home  •  Forget  ACLs.  (You’re  already  pwned.)  •  root  ssh  for  everybody!  •  No  logins  whatsoever.  (User  login  =>  reimage.)  •  Auto-­‐reboot  and  auto-­‐update  regularly.  •  Make  security  everybody’s  job.  •  Embrace  “cyber”.