279 karma · joined February 12, 2020
andrew@plets.ch
This is a wrong assumption, it's not that they aren't customers as they'll deal with hundreds of vendors/partners and will benefit from these changes regardless but national cyber & supporting IT agencies (including the UK) are often providers themselves to both other government agencies and private organizations in the country.
This can be anything from running their SOC functions to specialized consulting services to intelligence sharing so the bill is definitely relevant and the exclusion of the govt. doesn't seem to serve a purpose other than saving the budget to implement/maintain their own rules.
- One location, people who may fall into multiple categories (or none) don't need to check multiple places, users also know that all my communication will be via that page/they don't have to wonder if they're missing something
- As much as some detail doesn't matter to certain audiences, I find being able to give all the detail you want a user to know while maintaining readability to less technical audiences is a skill worth developing because the result is regardless of where your notes end up, the person will understand what's changed and why it matters
- Maintaining multiple versions leads to mistakes, at some point you'll leave out a detail to one audience that matters so letting the user mentally filter what they don't care about takes the onus to get it right 100% of the time off of you. I'll often categorize my changes by the section that had the change to help users with this.
- This is a personal preference and you touched on this one but it's just far less work, I've found it common in tech that people don't want to do things more than once or they'll automate it/look for shortcuts and this is no different. This isn't always a bad thing but getting release notes right means your users stay informed/use new features which is why we build them so I think it's worth putting my energy into doing it properly every time
The post does use cyber industry terminology inconsistently though, noted in another comment, and I fear that's going to make every technologist exit the page before getting the point.
1.95% interview success rate and 400+ users? On effectively a new site?
2."Learn from industry leaders and seasoned FAANG professionals with real-world experience", like who? There are only so many cyber FAANG staff (and their time is very expensive) and not only do you not list backgrounds/who they are, you don't even list who you are on the about page
3. The hands on labs don't seem to exist? There are also plenty of sites you could point to that do this but I suspect you want the users for subscription $
I say all this because cyber is an industry based on trust and there's very little to trust about the site as it is.
Last thing I will add, LLMs in this field are struggling, you need a crazy amount of data to tune it properly and I fear you may end up doing more harm than good by having the model suggest made up things as good answers. I think a good path to solve this problem would be curating the questions for your background field (then hiring others for theirs) and having low-high value answers.
With that said, I find myself agreeing with the mandate, if you're using university resources, they have a responsibility to protect those resources and EDR is table stakes these days.. but they also need to be providing any devices required for the job, allowing BYOD for restricted data makes an already tough environment to secure harder than it needs to be.
I don't know if there's a way out of businesses that don't see the value of IT ignoring these risks (outside of legislation) but I hope we don't end up in a situation where bailouts are common/companies rely on govt intervention.
They may not have had a security email but I’m sure there was some contact this could have been sent to before posting something like this.
Part of me wonders if OP even tried or was mostly just looking to dunk on a company.
There’s often a couple different ways to victory and there’s already enough built out to put plans into action immediately.
So maybe not illegal as much as just a terrible look for the party.
Are you under the impression that MS doesn't spend millions on security? They're currently spending roughly $1b/year. This isn't going to be fixed by "a few pen test"
Google Maps also keeps track of your location, I don't have the exact setting but its under location history. Might be worth checking. You can also turn your phone to only allow location to apps while the app is open.