Spent some time looking for ideas on how to do a security training (compliance requirement) that didn’t suck. Cribbing from some reddit posts, I think I’m going to give everyone a notecard with something like “Is Bob Bobson a client here”, have them pair up, and do a little phone conversation roleplay where one person is a visher trying to trick the other into revealing the piece of information, while the other person gets practice saying “No.” Seemed like a good way to let the staff dip a toe into thinking like an attacker.
- 0 Posts
- 15 Comments
sirblastalot@ttrpg.networkto
cybersecurity@infosec.pub•Password managers less secure than promised
2·2 days agoYeah to be clear, I do not recommend my method and I don’t think it’s a good allocation of mental resources. I’m just stubborn :P
sirblastalot@ttrpg.networkto
cybersecurity@infosec.pub•Password managers less secure than promised
1·3 days agoFWIW, I use Diceware for password generation; it’s good at making memorable yet still random passphrases.
sirblastalot@ttrpg.networkto
cybersecurity@infosec.pub•Password managers less secure than promised
31·3 days agoThe prospect of putting all my passwords in one big juicy target has always made me nervous. I go to great lengths to just memorize everything, but damn if it doesn’t take a toll.
sirblastalot@ttrpg.networkto
cybersecurity@infosec.pub•Password managers less secure than promised
4·3 days agoPlease tell me you have backups of that flash drive
sirblastalot@ttrpg.networkto
cybersecurity@infosec.pub•Why We Abandoned Matrix: The Dark Truth About User Security and Safety
1·2 months ago“Matrix” is a pretty difficult-to-search name. What is it? Federated IRC?
Pretty normal for us over here
sirblastalot@ttrpg.networkto
cybersecurity@infosec.pub•What are You Working on Wednesday
1·2 months agoHad to invoke our Data Transmission policy’s AI clause for the first time
sirblastalot@ttrpg.networkto
cybersecurity@infosec.pub•What are You Working on Wednesday
1·3 months agoWell, no one else comments in these threads, might as well.
sirblastalot@ttrpg.networkto
cybersecurity@infosec.pub•Study concludes cybersecurity training doesn’t work
1·4 months agoEvery email client I can think of off the top of my head blocks images by default. And I don’t see how that relates to your criticism of the whole idea of anti-phishing training
sirblastalot@ttrpg.networkto
cybersecurity@infosec.pub•Study concludes cybersecurity training doesn’t work
1·4 months agoClicking the link hypothetically confirms to the spammer that yours is a valid and monitored email address, and that you’re a sucker suitable for more targeted phishing.
Of course, it seems like every random user will also happily type their password into any text box that asks for it, too.
sirblastalot@ttrpg.networkto
cybersecurity@infosec.pub•Study concludes cybersecurity training doesn’t work
3·4 months agoOne time I failed a phishing test because I did a message trace and confirmed that it originated from our own internal servers.
sirblastalot@ttrpg.networkto
cybersecurity@infosec.pub•What are You Working on Wednesday
2·4 months agoNuthin, furloughed.
sirblastalot@ttrpg.networkto
cybersecurity@infosec.pub•What are You Working on Wednesday
2·5 months agoInventory management. Can’t secure what you can’t see etc
Depending on your field, your business may already have a cybersecurity department. There’s an endless parade of thankless grunt work to be done like patching (often after hours), following up with users whose machines didn’t patch for whatever reason, and so on. (With your manager’s permission) you may be able to reach out to them and volunteer to help with some of those tasks, as a way to dip a toe into that world and start learning.