Lawfare Daily: What Can Be Done to Improve Cloud Security with Maia Hamin, Trey Herr, and Marc Rogers
Discussing cloud security
On today's Lawfare Daily, Stephanie Pell spoke to Maia Hamin, Trey Herr, and @cjunky.bsky.social about the Cyber Safety Review Board’s report on the 2023 Microsoft online intrusion, the lagging state of cloud security policy, and more.
20.06.2024 13:47 — 👍 4 🔁 2 💬 2 📌 0
Cloud Un-Cover: CSRB Tells It Like It Is But What Comes Next Is on Us
Lagging policy upholds a status quo in which cloud vendor’s design decisions about how their systems work (and work together) are almost entirely opaque.
Maia Hamin, Trey Herr, and @cjunky.bsky.social discuss a CSRB report on the 2023 intrusion into Microsoft’s cloud infrastructure, and what it reveals about the current state of cloud security policy.
28.05.2024 14:55 — 👍 1 🔁 1 💬 0 📌 0
It is important that we talk about government boundaries and ensure our rights are protected. However must make sure this conversation is bi-partisan, balanced and constructive. We must also make sure we don’t tear down our national defenses in the process. 5/5
14.12.2023 22:02 — 👍 6 🔁 0 💬 0 📌 0
We have no “cyber 9-1-1” in this country. There is no one to call when you face a cybersecurity attack if you don’t have the money for private incident response. Volunteering to protect our fellow citizens is a national institution in this great country. 4/5
14.12.2023 22:02 — 👍 7 🔁 0 💬 0 📌 0
Skilled cybersecurity workers volunteering to support these institutions makes a huge difference even if some feel the work we do is already available elsewhere. The simple fact is many organizations sit below the cybersecurity poverty line and need support. 3/5
14.12.2023 22:02 — 👍 5 🔁 0 💬 0 📌 0
The CTI League did not engage in censorship, it focused on protecting the health sector. Despite testimony to congress that it’s ridiculous hospitals need help the hard truth is they do. At least one major hospital per week is hot by a ransomware incident. Incidents at hospitals cost lives. 2/5
14.12.2023 22:01 — 👍 4 🔁 0 💬 0 📌 0
Statement by Marc Rogers on the CTI League | CTI League
Yesterday I provided testimony to Congress about the CTI League and addressed the allegations that it is somehow part of a government censorship apparatus. ...
I have released a statement about our work in the CTI League. Yesterday I provided this and additional material as testimony to congress. Today we have made our github public and opened up all our files.
cti-league.com/statement-by... Details are in this statement. 1/5
14.12.2023 22:00 — 👍 8 🔁 3 💬 1 📌 1
Maximum advertising value for Diablo from dystopian atmosphere.
08.06.2023 19:04 — 👍 7 🔁 2 💬 0 📌 0
IMHO both are great experiences, but I much preferred the German one. Will have to do it again next year.
27.05.2023 17:57 — 👍 0 🔁 0 💬 0 📌 0
Yeah my experience is one every 2 weeks but ive seen super active people get more. One week I got 6. YMMV :)
24.05.2023 13:54 — 👍 1 🔁 0 💬 0 📌 0
All the lovely people who posted a photo of their copy of my book. I’m humbled. 🥰
13.05.2023 07:28 — 👍 14 🔁 2 💬 3 📌 0
Random number generation the manual way. @ Deutschen Spionagemuseum
21.05.2023 13:49 — 👍 7 🔁 2 💬 0 📌 0
Last message from Lukas at the #offensivecon closing ceremony: Taking sides is hard but has to be done. We should all be mindful of how war affects our communities and have each others backs during these difficult times.
20.05.2023 17:18 — 👍 2 🔁 0 💬 0 📌 0
16.05.2023 21:13 — 👍 4 🔁 1 💬 1 📌 0
I wouldn’t know about most important but i’m definitely happy that significant issues like this, and others such as voting are getting attention at DEF CON. Its great to see the community given a chance to become part of the solution.
08.05.2023 17:03 — 👍 0 🔁 0 💬 1 📌 0
Federation of content is hard. Im looking forward to seeing how it works here.I hope theres a way to allow niche safe spaces while lifting up voices you wouldn’t normally hear. Given that its not possible to federate everything, everywhere, all at once it doesn’t feel like just an algorithm problem
07.05.2023 15:26 — 👍 0 🔁 0 💬 0 📌 0
The parallels between Mastodon and Bluesky aren’t lost on me. I still maintain am account on Mastodon and enjoy engagement there. But it lacks the open discovery of new content from communities you don’t normally engage with that old twitter was great for. Its safer but undeniably more balkanised
07.05.2023 15:21 — 👍 0 🔁 0 💬 0 📌 0
Im both excited and nervous for this. Allowing communities to have their own federated spaces is a great concept. However we need to avoid balkanisation and the creation of toxic echo chambers.
07.05.2023 02:21 — 👍 3 🔁 0 💬 0 📌 0
The key to making the US cyber strategy work: boots on the ground
Prioritizing work with academic institutions, localities and skilled volunteers is the best way of advancing America's cybersecurity needs.
I wrote an article with Sarah Powazek from Berkeley’s CLTC on how we need state and local resources to defend against cyberattacks. We have one of the most forward leaning National Cybersecurity Strategies, now we need to get boots on the ground to defend our schools, hospitals and businesses.
04.05.2023 22:10 — 👍 3 🔁 0 💬 0 📌 0
To summon @kimzetter.bsky.social I think have to whisper the names of specific threat actors in the right order.
03.05.2023 18:10 — 👍 2 🔁 0 💬 1 📌 0
Landed in San Jose CA.
02.05.2023 19:14 — 👍 43 🔁 10 💬 0 📌 2
SolarWinds: The Untold Story of the Boldest Supply-Chain Hack | WIRED
Probably one of the best pieces of reporting on the Solarwinds supply-chain attack. Excellent piece by Kim Zetter.
Highly recommended reading.
03.05.2023 01:48 — 👍 12 🔁 6 💬 1 📌 0
New to Bluesky? Check this out.
02.05.2023 16:32 — 👍 0 🔁 0 💬 0 📌 0
Aka @c_c_krebs over there
Work: Senior Advisor for Privacy and Cybersecurity, Office of Senator Ron Wyden.
AI, Mobile and IoT security, future automotive, viticulture and sim racing. Former Chair of GSMA Fraud and Security Group.
not social-ing much, on a spiral staircase, crafty, bon vivant, explorer, erbsenzähler, glitter distribution vector, BSidesLV COO, InfoSec exec, she/her
Romanian antihacker from another planet. #threatintel #yara #chess #taekwondo black belt
Motto: "One reboot a day keeps the implant away"
CEO & Co-Founder. Entrepreneur, hacker, executive, and general trouble maker/seeker/solver.
Board member @BSidesLV. Keynote speaker. Views are my own.
Technologist, entrepreneur, and hacker | CEO @ OODA | Founder @DevSec | Past Founder of FusionX & Terrorism Research Center. Black Hat board member.
Trying to make the Internet more secure…
This space left intentionally blank.
DARPA/Google/Stripe/L0pht/Twitter/…/DARPA/[redacted]
https://en.wikipedia.org/wiki/Peiter_Zatko
Philosopher-Strategist-Protector… more later
DFIR by day, DFIR by night.
Former vet tech.
Violinist, Salty, Tired, Meme Enthusiast.
Brains are inversely proportionate to common sense - me, Nicole Schwartz. Formerly known as AmazonV. she/her
@DianaInitiative @dcskytalks
Security Hobo, Itinerant Technologist, Policy Anti-Wonk, Former Senior Fellow at The Atlantic Council, Teller of Tales for Darknet Diaries #91 (and other venues). All opines are my own. RS/Fav/Follow≠Endorsement.
Data -> Information -> Knowledge -> Wisdom