Salta al contenuto principale


Which firewall vendor will disclose critical vulnerabilities in time to ruin Christmas for many? and why is it probably Fortinet?
Questa voce è stata modificata (2 giorni fa)
in reply to ❄️☃️Merry Jerry🎄🌲

RE: infosec.exchange/@jerry/115735…

Back when I was important, I saw the common trend of incidents being reported on Fridays or right before holiday breaks. I started asking the reporters (while thanking them) "why did you report it when you did?" and the response was consistent: "I knew this was important and I didn't want it to sit over the weekend/holiday without anyone knowing about it".

I suspect there may be a similar situation with discovered vulnerabilities.


Which firewall vendor will disclose critical vulnerabilities in time to ruin Christmas for many? and why is it probably Fortinet?

in reply to ❄️☃️Merry Jerry🎄🌲

its very nice of them. We hold our breath starting Friday at 3pm, watching the inbox, waiting for the last minute email.

Jokes on them though, we will schedule a call and they have to be included. If its important enough to report Friday afternoon, it is important enough for an incident call.

in reply to ❄️☃️Merry Jerry🎄🌲

My support roles always saw a spike in tickets just before lunchtime, and just before close of business. I always thought people had a list of things to get done before noon, and another list to get done before they leave for the day.
in reply to ❄️☃️Merry Jerry🎄🌲

Traditionally, the federal government would release controversial memos (like you'll be working on a hovering station from now on) late Fridays so you wouldn't pick a fight at the end of the week.
in reply to ❄️☃️Merry Jerry🎄🌲

I had a long discussion with a (MD of psychology) friend years ago about the "last chance" urgency effect on our brains. Essentially the same phenomenon that is believed to cause a squirrel to think "AHHH, RUN NOW" at the worst possible moment when a car is approaching.

I wonder if some of the same basal survival instinct wiring is responsible for this phenomenon. 😛

in reply to K.C. Budd

@phreakmonkey perhaps. though I gather that these people thought they were actually being helpful and not doing it out of self preservation. Maybe that is there at some level, though, and the layers of cognition just build a cover story
in reply to ❄️☃️Merry Jerry🎄🌲

@phreakmonkey Well it seems plausible, and it’s a good answer... They (the reporter/s) get hold of the story, they try to dig deeper, work on verifying… this of course being the workng week. By the end of the week, if they feel it is important enough, they - being known to be so altruistic - don’t want to “sit” on it... or much more likely, they are worried someone else might scoop them.
in reply to ❄️☃️Merry Jerry🎄🌲

I'm voting ASA/Firepower. Because Forti at least forces upgrades these days, Cisco it's been a year so they due for some hard coded creds to appear.
in reply to Pauliehedron ✅

So I'm batting .200, it was Ironport on the Cisco side, and then also Sonicwall Management. But it's only hump day, we still got some time till push to prod day.
in reply to ❄️☃️Merry Jerry🎄🌲

We're getting there! Something this way comes...

infosec.exchange/@BleepingComp…

in reply to Pauliehedron ✅

Son of a biscuit

infosec.exchange/@BleepingComp…

in reply to ❄️☃️Merry Jerry🎄🌲

We have a new contender!

mastodon.social/@cisakevtracke…

in reply to ❄️☃️Merry Jerry🎄🌲

Cloudflare : *stands in the corner looking nervous*

Also Cloudflare : We... We don't count as a firewall, right?

#FuckCloudflare

in reply to ❄️☃️Merry Jerry🎄🌲

PANW hasn't published an advisory since 12 November so I'm leaning that way right now.
in reply to ❄️☃️Merry Jerry🎄🌲

Fortinet has dropped what...20 CVEs in the past few weeks? They must be running out of them 😀
in reply to jonw

don't worry - they've had their best developers working hard to create some new vulnerabilities for people to discover
in reply to ❄️☃️Merry Jerry🎄🌲

what a relief. I usually take all of January off with my time in lieu accrual from the last 2 weeks of the year 😀
in reply to ❄️☃️Merry Jerry🎄🌲

the Grinch is the APT behind all of these. We've been downplaying his capabilities for too long.

Questo sito web utilizza cookie tecnici e di sessione. Proseguendo la navigazione su questo sito, accetti l'utilizzo dei cookie.