443 karma · joined October 14, 2015
http://www.zerohedge.com/news/2016-06-15/nato-says-it-might-...
And look who gets blamed for the DNC leak:
http://www.zerohedge.com/news/2016-07-25/fbi-launches-probe-...
Good fences make good neighbors.
That goes for all parties involved.
Given that the DNC emails provide enough rope to hang themselves, Russia would be stupid to NOT do this.
If it comes down to: Trump - friendship with Russia, Clinton - war with Russia, I know which way I'd vote.
242-FZ: It requires data on Russian citizens be kept in databases within the borders of Russia, and that first-write and first-update happen in Russia.
The other laws involved required retention of internet access logs for 6 months.
There are many boutique companies that are excellent, but don't have a fair share at the market.
Companies that are 'all things to all men' tend to have quality issues over time... like the big security giants of the last decade. Eventually people get tired of it and look for specialists. That's where this will help.
Many go to them, they see awesome resumes. They also see very large costs. The the customer finds he doesn't get the A-team, but the F-Team, due to 'unprecedented demand'.
This is about making the process transparent.
For baby steps I would advise starting with nessus, and metasploit then targeting virtual machines that you build on your own home network.
Pen-tests should be good reality checks to ensure the system is working, and that it is sufficient to withstand current attacks.
Sometimes companies are very smug and need the reality check. Boards are starting to request them to ensure the confidence is warranted.
I've also seen pen tests used as a tool to GET funding. Fail one big time due to known vulnerabilities just to show how messed up things really are...then get a budget to fix them.
We are taking the feedback system seriously and are slowly testing it out. An easily gamed system is useless for everyone.
2 Way NDA (also called Mutual NDA):Let's have an open honest conversation, and as you signed MY NDA, written in neither party's favor then: I CANNOT tell anyone about YOUR secrets, and you CANNOT tell anyone about my secrets. It enables honest dialogs.
TLDR>> 1 Way NDA's suck
Also on the pen test side, we wont't say vendor C put in a $10k bid, you should put one in at $9k. It just means we value trust and privacy, as everyone in the security field should. Testers would also sign an NDA when they take a job, so that they won't leak things they learned in confidence.