Your threat model is wrong
Several subjects have come up with the past week that all come down to the same thing: your threat model is wrong. Instead of addressing the the threat that exists, you've morphed the threat into something else that you'd rather deal with, or which is easier to understand.Phishing
An example is this question that misunderstands the threat of "phishing":
Should failing multiple phishing tests be grounds for firing? I ran into a guy at a recent conference, said his employer fired people for repeatedly falling for (simulated) phishing attacks. I talked to experts, who weren't wild about this disincentive. https://t.co/eRYPZ9qkzB pic.twitter.com/Q1aqCmkrWL— briankrebs (@briankrebs) May 29, 2019
Recently, my university sent me an email for mandatory Title IX training, not digitally signed, with an external link to the training, that requested my university login Continue reading
CEO Nikesh Arora pledged to integrated Twistlock container security and PureSec severless security...
The latest flaw allows a witty attacker to target API endpoints behind the docker cp command that...
It’s unclear what impact, if any, the outcome of the legal challenge will have on Huawei's...
The vendor has reportedly reached deals to buy container security startup Twistlock for between...


