I've seen things you people wouldn't believe...Aging Indian managers who think that 'TLS' is something that we have to implement ourselves...I've watched Jeetcoders write entire configuration schemes which just amount to pushing every secret in the application to version control.All of these... Moments... Will be lost...Like shit on the street...Time to buy a farm...
speaking of indians and being retarded around TLS>indian becomes new CISO>demands we implement TLS termination...EVERYWHERE>we already use it for security on product and the HQ office because that's the only place with enough compute + storage to deal with it>he also demands admin access to the arkime instance>head of SOC tries to get CEO to override him>CEO is retarded and tells him to give him access>three months later saar's account gets popped and our MSSP notes that arkime was accessed over the course of 17 hours>XDR didn't kick in because CISO had accessed the instance so many times from India that the attacker looked like him and the ML algo thought it was legit...because the attacker was in India>the only thing that saved us was the bad guy running a really loud privesc on one of our appsec serversI'm legitimately rethinking my career choice right now
In previous job, discovered a product owner generating "random" nonce thusly:> date | base64After I raised the issue, I got an angry 5:00PM call from the guy>saar it is random every time I run it I get a different stringI directed him to some materials on cryptographic randomness and never heard from him again.