Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Subjunctive
Sep 12, 2006

✨sparkle and shine✨

(Amir is a guy at Google—I think?—who is involved in the WebPKI root programs and is asking tough questions in Entrust’s root program compliance incident reports.)

https://open.substack.com/pub/webpki/p/entrust-considered-harmful-part-1

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

digitalist posted:

We share this understanding.

We have been posting for 20 years and advocating for a healthier posting ecosystem, but we consider this an exceptional circumstance and have decided not to delete our posts.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

chin up everything sucks posted:

Last day at my current job, 2 weeks before my new job is going to start.... Got a phonecall with an offer for the job I really wanted, better pay, benefits, better work.... Everything. loving taking it. ISSO here I go.

yeah baby get paid

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

This is a courtesy notice that if your company has Entrust-issued TLS certificates in load-bearing capacities, you would do well to figure out how you would move to either or both of a) another CA, or b) 90-day cert validity periods .

Thank you. You may return to burning effigies of the Palo Alto product manager of your choice.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Rust Martialis posted:

Anyone got a summary I can put in front of my CISO boss's eyes

Expecting one from the head of Mozilla’s root program in the next day or two, maybe today.

Amir’s above is pretty good though incomplete.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Rust Martialis posted:

Anyone got a summary I can put in front of my CISO boss's eyes

https://wiki.mozilla.org/CA/Entrust_Issues just dropped

waiting for Bruce Morton to release a diss track response

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

dragon64 posted:

Glad we have two Entrust threads now

is that you, Bruce?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

only $20K for that? I guess inflation hasn’t hit that market yet

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

The Infosec Thread: Yes, time to move to a mountain and raise goats

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I mean, the stock is down 3.3% on the day, which is pretty much within its normal volatility window from looking at the last month

it’s not being dumped in panic

…yet?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


Very polite of them to try to blank out Ms No Reply’s email address.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

we are in a liminal ownage space

teach the controversy

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Diva Cupcake posted:

The someone is refuting Zscaler’s Trust Center response.

https://twitter.com/pancak3lullz/status/1788576614051135669?s=46

is the thesis of this tweet that whatever that command line is from doesn’t run in a test environment?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Diva Cupcake posted:

I think they’re just saying “nuh uh” without any actual proof.

https://trust.zscaler.com/zscaler.net/posts/18686

Which side? I don’t know how you would prove that your stuff wasn’t breached, I guess publish an independent audit of everything over many months?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Accipiter posted:

I have a lot more details on the Zscaler situation than what's currently flying around the web, and yeah... this doesn't look good.

I don't want to spew the info here because I don't want to step on ZS's collective dick, but the info I have says that the breach appears to definitely impact production systems. There's also an IAM bypass method at work.

I will also say that a certain VP of engineering needs to use way better passwords.

yessss :sicko:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

(step on the dick! step on the dick!)

👠🍆💥

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

ShoeFly posted:

I'm waiting for the day that Cisco starts screwing with Splunk and fucks our whole business.

We’re migrating off Splunk now, just signed our final contract with them. Just like with DataDog, they didn’t think we’d really do it…

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Rust Martialis posted:

Splunk told me they consider themselves price-comparable to Sentinel. Comments?

I wasn't part of the assessment, but we're bringing it in-house so the ops cost is pretty different I'm sure.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply