Avatar

SapphironZA

SapphironZA@sh.itjust.works
Joined
0 posts • 109 comments
Direct message

Yep, at this point the “security” companies can do with imitating malware development practices.

permalink
report
parent
reply

That’s because cloudstrike likely has significantly worse leadership compared to your company.

They have a massive business development budget though.

permalink
report
parent
reply

It’s likely not an intern’s fault. Likely a C suite not authorizing the testing infrastructures requested by the developers and sysops people.

permalink
report
parent
reply

Way too many. It’s not the 90’s or early 2000s anymore.

permalink
report
parent
reply

It’s outside the primary failure domain.

permalink
report
parent
reply

Because the windows OS is inherently insecure with lots of permission elevation opportunities.

permalink
report
parent
reply

We also backup our bitlocker keys with our RMM solution for this very reason.

permalink
report
parent
reply

What amazes me is that so many big companies still use windows in critical core infrastructure.

Windows endpoints is one thing, but anyone using windows servers and MSSQL for mission critical application stacks need to be hit with the modernization hammer.

And then on top of that, they do not have a test rollout of any changes in a test environment, before rolling it out in the production stack.

Good luck to all the engineers in the trenches, having to fix the mistakes of their leadership.

permalink
report
reply

Valve is an excellent example of a sustainable tech company. It’s not on the growth at any cost, boom and bust cycle

permalink
report
reply

Very true. But work your butt off to make sure you have better options next time. Us in the rest of the world can only look in from outside and try to avoid the damage.

permalink
report
parent
reply