The point of the blog post is that this method is useful for attackers (as a so-called lolbin - trusted binary used in a malicious way).
I work with 500 idiots. Willingly and cluelessly are interchangeable.
Take their computer away.
Management frowned at this suggestion.
Seems to be the goal of most "cybersecurity" types.
I thought their goal was collecting vendor certifications.
Ouch dude
It's a burn but it's accurate. Had three consultancies in (high end well known ones) and and two in house certified to their eyeballs professional cyber security experts in charge. All they did was tick a fuck load of boxes, run some scans, spend a lot of money and make it really hard for people.
Yet I managed to find a fully remote RCE and exploit it in 30 minutes after they did all this.
The industry is a fucking scam.
Confirming this experience, it is Security Theatre all the way down.
Sounds like it's time to make your own certification. :D
Not nicely put, but not wrong. I had half an heart attack when that feature was rolled out, and the danger was split only between myself and a colleague. I can't even trust myself to not screw up. I needed another permanencied invocation of the principle of hope.
Well said, this is why working solo can be beneficial: only one idiot to look out for. :)
That’s the idiot that can do the most damage!
Can confirm.
The industry is only going to keep making more idiots if they treat developers like this.
It kept producing more idiots when we didn't treat them like this and this is easier so fuck it.