Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
flakeloaf
Feb 26, 2003

Still better than android clock

eonwe posted:

The study materials I found to be useful were the following:

Sybex Official Study Guide 9th Edition
LearnZapp
CISSP Exam Cram (8 hour video) - https://www.youtube.com/@InsideCloudAndSecurity
Think Like A Manager video - https://www.youtube.com/@GwenBettwyTSI

I read a lot of study plans on r/CISSP and after taking the exam I sort of felt like they're focusing on the wrong things mostly. They were doing very technical deep dives and writing all these bizarre questions, but mostly it felt like the exam was a test of whether you had a basic understanding of all the technologies, understood why you would use one technology as opposed to another technology, and whether you were capable of reading a question and finding the question they are actually asking.
Also understanding that if there are 4 answers on a question all 4 might be right, but one might be more right.

The book is good because it covers everything, LearnZapp is good not because the questions are anything like the ones on the exam but because they'll point out what technologies you don't understand, the 8 hour video is good to have some 'mind map' stuff, and the Gwen Bettwy channel is good for getting into the mindset of how ISC2 actually asks their questions.

Mile wide, inch deep. I really should use that test voucher at some point... if it still even works?

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

Everyone must be in the office two days a week for collaboration but don't all show up at once because there isn't room for everyone

flakeloaf
Feb 26, 2003

Still better than android clock

The song they used to teach us how to count had a drum score that was impossible to count

Generic Monk posted:

This is me, also my boss will immediately notice if cameras aren’t on and call you complaining after the meeting.

My old section got a new manager who put in a rule like that. Three of us quit.

flakeloaf
Feb 26, 2003

Still better than android clock

Very Public Network

flakeloaf
Feb 26, 2003

Still better than android clock

Can't stop a sea can full of cars but we have big plans for a device the size of a wallet, and those plans involve making it illegal to have a thing it was already illegal to have in circumstances that make it seem like you're using it to steal cars

flakeloaf
Feb 26, 2003

Still better than android clock

There isn't. A canadian bank, I want to say RBC, caught hell for that same thing like a decade ago.

E: okay there is: in theory they could hash all 16000 variations of that sequence and check them all against your password hash, but they almost definitely are not doing this

flakeloaf fucked around with this message at 22:18 on Feb 16, 2024

flakeloaf
Feb 26, 2003

Still better than android clock

I got it wrong too - there are 4 letters on 7 - so it'd be 4^6 * 5 = 20480

flakeloaf
Feb 26, 2003

Still better than android clock

There are far nobler uses for that tech

flakeloaf
Feb 26, 2003

Still better than android clock

the honourable minister of innovation, everyone

flakeloaf
Feb 26, 2003

Still better than android clock

Bitwarden the product may be fine.

Bitwarden the company is wearing goat horns for having left open a known vulnerability with autofill (already a dodgy feature) for four years
https://www.itpro.com/security/cyber-security/370288/bitwarden-to-release-fix-for-four-year-old-vulnerability

flakeloaf
Feb 26, 2003

Still better than android clock

Compliance is my whole thing but I use my powers for good, to dig through the morass of things that say no, to get my boss to a yes without using silver bullets.

It's entertaining even if it can be mind numbing at times.

flakeloaf
Feb 26, 2003

Still better than android clock

Subjunctive posted:

No, they don’t. You might not be reading very reliable things.

They did a decade or so ago (one of our demos used an SDR to de-anonymize phones by doing exactly that) but I haven't checked on it recently. If you're organized enough to do that, though, you can just set up an imsi catcher. Walmart is probably not doing that, and anyone who is isn't interested in you.

e: an article on probe requests https://blog.spacehuhn.com/probe-request

flakeloaf fucked around with this message at 15:25 on Mar 3, 2024

flakeloaf
Feb 26, 2003

Still better than android clock

Subjunctive posted:

are you talking about connecting to unadvertised SSIDs? I don’t recall anything in the WiFi scanning protocol that has an SSID outbound from the scanning device

I imagine that's how it worked, yeah; the phone was sending out probe requests for its familiar but un-advertised networks and my device (with the manual I didn't read, about the spec I also did not read) picked 'em up so I could see things like MARRIOTT 346 from among the consenting few who'd left their phones on.

Not to alarm you or anything mekyabetsu , these are not things ordinary users need to concern themselves with. Anyone doing this knows what they're doing is wrong.

flakeloaf
Feb 26, 2003

Still better than android clock

Yup, the instructor talked about himself and the other jobs he'd had most of the time, between intonations that the exam was too broad to get into in class and that we should read the book and memorize every page on an "inch-deep / mile wide" level, and I decided the money the training budget had burned on this bullshit wasn't worth the corresponding misery of dragging my unmanaged adhd rear end through that kind of studying

flakeloaf
Feb 26, 2003

Still better than android clock

I've hit the point now where I need to let the network guy be the network guy, because giving in to the temptation to play his position for him sends me on increasingly deeper dives into man pages and configuration manuals and endless tech bulletins all describing the care and feeding of equipment I will only be touching if something has gone catastrophically wrong, which is a lot of work for a yea/nay call on a suggested upgrade or whatever.

So yeah, nothing wrong with specializing. If you can be a great network person, be a great network person, and build a bit of mutual trust and respect with your itsec person so they can do itsec policy wonk poo poo.

flakeloaf
Feb 26, 2003

Still better than android clock

It also anagrams to A GOTHIC JENNA, so I choose to blame Wednesday Addams.

flakeloaf
Feb 26, 2003

Still better than android clock

Subjunctive posted:

is that you, Bruce?

Prove it isn't

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock



There, now we have zero trust in them. Well done lads

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply