Infosec Myths, Mistakes, and Misconceptions - Adrian Sanabria - ASW #279
2024-4-3 00:0:0 Author: sites.libsyn.com(查看原文) 阅读量:6 收藏

Apr 2, 2024

Sometimes infosec problems can be summarized succinctly, like "patching is hard". Sometimes a succinct summary sounds convincing, but is based on old data, irrelevant data, or made up data. Adrian Sanabria walks through some of the archeological work he's done to dig up the source of some myths. We talk about some of our favorite (as in most disliked) myths to point out how oversimplified slogans and oversimplified threat models lead to bad advice -- and why bad advice can make users less secure.

Segment resources:

The OWASP Top 10 gets its first update after a year, Metasploit gets its first rewrite (but it's still in Perl), PHP adds support for prepared statements, RSA Conference puts passwords on notice while patching remains hard, and more!

Visit https://www.securityweekly.com/asw for all the latest episodes!

Show Notes: https://securityweekly.com/asw-279


文章来源: http://sites.libsyn.com/18678/infosec-myths-mistakes-and-misconceptions-adrian-sanabria-asw-279
如有侵权请联系:admin#unsafe.sh