Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

OWASP® Global AppSec US 2021 Virtual - Aakash Shah's 'Why Checking Your Infrastructure-As-Code For Misconfigurations Is Not Enough, How To Secure Your Cloud Native Applications' →

May 06, 2022 by Marc Handelman in OWASP®, Global AppSec US ’21, AppSec Conferences, Education, Security, Infrastructure Security

Our thanks to both the OWASP® Foundation and the OWASP Global AppSec US 2021 Virtual Conference for publishing their well-crafted application security videos on the organization’s’ YouTube channel.

May 06, 2022 /Marc Handelman
OWASP®, Global AppSec US ’21, AppSec Conferences, Education, Security, Infrastructure Security

The True Danger To North America: Unmanaged & Embedded Infrastructural Technical Debt

December 10, 2019 by Marc Handelman in Technical Debt, Infrastructure Security, Information Security

via Alexis C. Madrigal - writing for The Atlantic - comes this prescient piece, targeting technical debt within the United States's physical infrastructure. Quite likely, the single , most dangerous and looming threat to our way of life. Read and watch your FearMeterⓇ redline... Oh, and given the interconnected nature of all this, the same holds true for Canada's, and Estados Unidos Mexicanos' infrastructures...

"A kind of toxic debt is embedded in much of the infrastructure that America built during the 20th century. For decades, corporate executives, as well as city, county, state, and federal officials, not to mention voters, have decided against doing the routine maintenance and deeper upgrades to ensure that electrical systems, roads, bridges, dams, and other infrastructure can function properly under a range of conditions." - via Alexis C. Madrigal - writing for The Atlantic

December 10, 2019 /Marc Handelman
Technical Debt, Infrastructure Security, Information Security

When a Tree Falls in St. Louis, Will the Power Go Out?

May 09, 2019 by Marc Handelman in Physical Power Networks, Forestry, Artificial Intelligence, Machine VIsion, Machine Learning, UAV, ICS/SCADA, ICS, Electrical Engineering, Infrastructure, Infrastructure Security

A superlative bit of combinatorial scholarship coming out of St. Louis University, where Sean Hartling, Vasit Sagan, Paheding Sidike, Maitiniyazi Maimaitijiang and Joshua Carron have lashed-up geospatial sciences, machine learning, UAVs, and no-small level of intellectual virtuosity to study trees, the natural felling thereof, and power outages. Todays' Must Read for you ICS Boffins and Foresty geeks (while not ignoring the AI, ML, UAv and Network Information Security types as well).

"At SLU, geospatial science meets machine learning. In a study recently published in Sensors, Saint Louis University researchers paired satellite imaging data with machine learning techniques to map local tree species and health. The data generated by the project will help inform best practices for managing healthy green spaces as well as trimming programs to avoid power outages following storms." - via Carrie Bebermeyer, Senior Media Relations Specialist at St. Louis University

May 09, 2019 /Marc Handelman
Physical Power Networks, Forestry, Artificial Intelligence, Machine VIsion, Machine Learning, UAV, ICS/SCADA, ICS, Electrical Engineering, Infrastructure, Infrastructure Security

Shmoocon 2019, Adam Everspaugh's 'Un-f*$#ing Cloud Storage Encryption' →

March 10, 2019 by Marc Handelman in Shmoocon 2019, Infrastructure Security, Infrastructure, Information Security, Education, Conferences

Source Credit: Shmoo Con 2019 at Archive.org, also available at 0xdade's YouTube Channel. Enjoy!

March 10, 2019 /Marc Handelman
Shmoocon 2019, Infrastructure Security, Infrastructure, Information Security, Education, Conferences

ZeroNights 2018, Alexandre Gazet's, Fabien (0xf4b) Perigaud's & Joffrey (@_Sn0rkY) Czarny's 'Turning Your BMC Into A Revolving Door'

January 05, 2019 by Marc Handelman in ZeroNights, Information Security, Conferences, Hardware Security, iLO Security, Education, Infrastructure Security

From The Video Description: "Unmonitored and unpatched BMC (remote administration hardware feature for servers) are an almost certain source of chaos. They have the potential to completely undermined the security of complex network infrastructures and data centers. Our on-going effort to analyze HPE iLO systems (4 and 5) resulted in the discovery of many vulnerabilities, the last one having the capacity to fully compromise the iLO chip from the host system itself. This talk will show how a combination of these vulnerabilities can turn an iLO BMC into a revolving door between an administration network and the production network." - via Alexandre Gazet's, Fabien (0xf4b) Perigaud's & Joffrey (@_Sn0rkY) Czarny - 'Turning Your BMC Into A Revolving Door'

H/T

January 05, 2019 /Marc Handelman
ZeroNights, Information Security, Conferences, Hardware Security, iLO Security, Education, Infrastructure Security

Photo Credit: Vincent-Ferron

A New Way In: The Cloudflare IPFS Gambit

October 05, 2018 by Marc Handelman in Must Read, Infrastructure Security, Information Security

Dependent - of course - on your point-of-view - i.e, whether you are on the IPFS Hypermedia File System construct, or not. Intrigued? I was, hence the designation of Lawrence Abrams' superlative reportage as Today's Must Read!

October 05, 2018 /Marc Handelman
Must Read, Infrastructure Security, Information Security

via User Friendly by Illiad!

Infrastructure Security Monday: The Idiocy Chronicles →

August 13, 2018 by Marc Handelman in Sysadmins?, IT Stories, Physical Security, Infrastructure, Infrastructure Security

via Rebecca Hill, writing for El Reg, comes a tale of the need for education (not too mention common sense) in the system adminsitration ranks... Read it - my friends, and weep for the present-that-apparently-never-ends.

August 13, 2018 /Marc Handelman
Sysadmins?, IT Stories, Physical Security, Infrastructure, Infrastructure Security