Comment on God ****** dammit, here we go again

tym@lemmy.world ⁨1⁩ ⁨week⁩ ago

As someone who consults in the IT Security space, It’s bad out there. Contractors and BYOD companies are downright sheepish in asking their outsourced employees to do anything security-related to their devices. The biggest attack vector is allowed unfettered remote access (and therefore the whole company)

I still can’t get over how quickly companies-at-large have abandoned VPN Servers (removing network trust from the list of options as well)

I’m down to managed browsers via IdP, and I just can’t wait for the objections to that as well. People out here offering their faces to leopards. Certificate-based MFA on all the things IMO - passwords shouldnt matter (but six digit MFA codes aren’t immune to fake landing pages and siphoned MFA tokens that don’t expire)

source
Sort:hotnewtop