bullshitsecurity.bsky.social
@bullshitsecurity.bsky.social
Just your average CS researcher ranting about security theater nonsense
... we may find out that there are better and more reliable ways to build our infrastructure, resulting in the realization that we do not have any need for most "security" tools, which is my point.
November 26, 2024 at 9:04 PM
Its a well tested firewall, unlike the quality garbage you can buy. Thats the main point.

But we can also ask why you database server is on the same network then anything but your front end server (and jump hosts for administration access)

And if we keep asking questions like that ...
November 26, 2024 at 9:02 PM
Why do you need a firewall to control your network access?
Do you open ports on servers without requirement?

Most firewall setups I have seen were as open as the sky, while simple things like vlan did most of the separation.

And if you really need one, iptables would suffice too
November 25, 2024 at 7:20 PM
A "security" product that runs garbage code with thew highest privileges is not actually good for your security? I am shocked! If only we could have known ... oh wait ..
November 24, 2024 at 9:36 PM
Without that Palo Alto firewall behind CVE-2024-0012 you would undeniably be better off. Unless you need that firewall to hide more dumpster fires on the same scale of fuck up as your "security" product.

Use the tools that come with your OS instead of third party security theater
November 24, 2024 at 5:10 PM