Skip to content
DevMeme
3868 of 7590
Security Post #4211 · source on Telegram

The Sisyphean Task of Cybersecurity Advice

Description

This image is a screenshot of a tweet from user Vlad Styran (@arunninghacker) that captures the cyclical frustration of cybersecurity professionals. The tweet lists several security best practices that were once widely recommended to the public, followed by the unintended negative consequences that undermined them. First, it notes that users were told to look for the browser padlock, but Letsencrypt's free SSL certificates enabled phishers to get them easily. Second, users were told not to click pop-ups, but GDPR regulations then forced websites to present cookie consent pop-ups. Third, automatic updates were encouraged, but this became a vector for major supply-chain attacks like those on Medoc and Solarwinds. The tweet concludes with the ominous, unfinished thought: 'And then we asked them to enable logging...'. For experienced engineers, this is a deeply resonant and cynical take on the security landscape. It highlights how well-intentioned advice can be rendered useless by evolving threats, compliance requirements, or the weaponization of infrastructure, with the final line being a pointed reference to the then-recent and catastrophic Log4j/Log4Shell vulnerability, which was triggered by logging user-controlled data

Comments

8
Anonymous ★ Top Pick The first rule of cybersecurity club is: Don't talk about cybersecurity club. The second rule is: Every piece of advice you give will eventually be weaponized into a CVE
  1. Anonymous ★ Top Pick

    The first rule of cybersecurity club is: Don't talk about cybersecurity club. The second rule is: Every piece of advice you give will eventually be weaponized into a CVE

  2. Anonymous

    Defense in depth 2023: phisher-issued HTTPS, GDPR-mandated clickbait, auto-updated backdoor, logs purged for privacy - yet the board still feels safer because the deck says “zero trust” in corporate font

  3. Anonymous

    Security best practices are like abstraction layers - each one solves the previous problem while introducing two new ones, except now they're your compliance team's favorite and you can't refactor them out

  4. Anonymous

    Security best practices have a great track record: each one works perfectly until attackers read the same checklist

  5. Anonymous

    This is the security equivalent of 'the road to hell is paved with good intentions' - we've essentially created a perfect storm where every security improvement becomes the next attack vector. Let's Encrypt democratized SSL, which is fantastic until you realize phishers now have the same green padlock as your bank. GDPR tried to protect privacy but trained an entire generation to blindly click 'Accept All Cookies' just to make the banner go away. And automatic updates? Well, when nation-state actors compromise your update server (looking at you, SolarWinds and MeDoc/NotPetya), suddenly that 'security feature' becomes the perfect delivery mechanism for malware to 18,000+ organizations. The ellipsis after 'enable logging' is chef's kiss - because we all know the punchline: comprehensive logging means attackers now have a detailed roadmap of your infrastructure, or your logs become the next compliance nightmare when they inevitably get breached. It's almost as if security is a complex, nuanced field that can't be reduced to simple rules... but hey, at least we have our checklists

  6. Anonymous

    We asked for logging, then Legal asked for anonymization, Finance asked for 7-day retention, and the attacker politely waited eight

  7. Anonymous

    Security best practices: the observer effect where mandating logs just logs your next breach

  8. Anonymous

    Enterprise security today: we taught users padlock=good, popups=bad, auto‑update=good; then Let’s Encrypt, GDPR banners, and SolarWinds said “plot twist” - now we beg for logging so at least the blast radius has a map

Use J and K for navigation