Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Stéphane Bortzmeyer
Stéphane Bortzmeyer
@bortzmeyer@mastodon.gougere.fr  ·  activity timestamp 2 months ago

« L'union fait la force » (in French, about cybersecurity)

"Humans learn to walk by falling. Why don't we learn from cyberattacks? Are there not enough incidents?"

  • Copy link
  • Flag this post
  • Block
Stéphane Bortzmeyer
Stéphane Bortzmeyer
@bortzmeyer@mastodon.gougere.fr replied  ·  activity timestamp 2 months ago

"Not learning from mistakes is part of the human nature."

A lot of catch phrases for my next slides on cybersecurity 😄

#LuxembourgInternetDays

  • Copy link
  • Flag this comment
  • Block
Stéphane Bortzmeyer
Stéphane Bortzmeyer
@bortzmeyer@mastodon.gougere.fr replied  ·  activity timestamp 2 months ago

"whois is a kind of repository". Awfully wrong, of course, but I noticed that .lu don't give a lot of details via whois, even, for corporations (try whois microsoft.lu)

#LuxembourgInternetDays

  • Copy link
  • Flag this comment
  • Block
Federation Bot
Federation Bot
@Federation_Bot replied  ·  activity timestamp 2 months ago

"It is hard to notify people of security issues. There is a standard security.txt [RFC 9116] but nobody uses it."

Correction, I do: https://www.bortzmeyer.org/.well-known/security.txt

#LuxembourgInternetDays

https://www.bortzmeyer.org/.well-known/security.txt
  • Copy link
  • Flag this comment
  • Block
gregR ☯
gregR ☯
@gregr@mamot.fr replied  ·  activity timestamp 2 months ago

@bortzmeyer Microsoft too
https://microsoft.com/.well-known/security.txt

  • Copy link
  • Flag this comment
  • Block
Trix (WHY2025 - DECT TRIX)
Trix (WHY2025 - DECT TRIX)
@trix@social.c3l.lu replied  ·  activity timestamp 2 months ago

@bortzmeyer This makes me wonder, how "Expires" plays a role regarding PGP keys? Sure, the link might be the same, but the key('s expiry) could be updated.

For instance

security,txt:
> Expires: 2030-01-01T00:00:00Z

linked PGP key (at time of writing):
> pub rsa4096 2014-02-08 [SC] [expires: 2027-09-16]

  • Copy link
  • Flag this comment
  • Block
Stéphane Bortzmeyer
Stéphane Bortzmeyer
@bortzmeyer@mastodon.gougere.fr replied  ·  activity timestamp 2 months ago

@trix Because there is other stuff in security.txt than PGP keys?

  • Copy link
  • Flag this comment
  • Block
Trix (WHY2025 - DECT TRIX)
Trix (WHY2025 - DECT TRIX)
@trix@social.c3l.lu replied  ·  activity timestamp 2 months ago

@bortzmeyer Nono, obviously the information is still valid, and technically the *link* to the PGP key is also still valid, even after an update.

  • Copy link
  • Flag this comment
  • Block
Stéphane Bortzmeyer
Stéphane Bortzmeyer
@bortzmeyer@mastodon.gougere.fr replied  ·  activity timestamp 2 months ago

Discussion about notification. Even when you get an email address, people don't reply to it / do nothing. One of the big frustrations in cybersecurity.

#LuxembourgInternetDays

(On the other hand, many reports are spurious, ask @bagder )

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct