jerry

joined 2 years ago
MODERATOR OF
[–] jerry 1 points 3 months ago (1 children)

Apologies. It should be fixed and stay fixed now. Docker gets about 37 updates per week and for some reason that particular container won’t restart on its own, so I’ve created a script to restart it automatically.

[–] jerry 2 points 3 months ago

I’ve worked in all levels of management, including C-level at a Fortune 500 company, and I can tell you that from the perspective of the C level, the tools are a given. If the employees have complaints about the tools, the perception is that either the mid to lower level management or the employees are not competent and need to be replaced with ones that are able to deliver on the promise of the tools.

(I say this without judgement - most of the time it’s BS, some of the time it’s true)

[–] jerry 2 points 4 months ago

What do yall think a CISO of today needs to know/understand?

[–] jerry 2 points 4 months ago

I am trying to figure that out

[–] jerry 2 points 4 months ago (3 children)

I will sort it out

[–] jerry 1 points 4 months ago (6 children)
[–] jerry 3 points 4 months ago

Thank you so much for your support. It is always good to hear from people that appreciate the podcast and orchid pics. I don’t get a lot of feedback so it’s nice to hear.

[–] jerry 13 points 4 months ago (4 children)

Heya, I’m the admin for infosec.pub, along with a bunch of other fediverse instances including infosec.exchange. I’ve been on the fediverse for a long time - infosec.exchange turns 8 next month, for example.

With each event that disenfranchises people (twitter bought by Musk, Reddit API, etc), I’ve seen a big surge in new instances. My observation is that many people get into running multi-user instances without really understanding what it takes, time-wise, emotionally, and financially.

Some of the software, like lemmy, but also kbin, calckey, and others, get pushed into the spotlight before they’re really in a reasonable spot to support the incoming community. Lemmy is relatively well functioning and complete, but only around a core set of use cases, whereas some of the others were just nowhere near ready.

I don’t know of anything on the lemmy roadmap to add account portability.

In any event, I’m here for the long term, though I do have to keep reminding our user base that this service is free to use, but not free to run, and therefore donations are much appreciated though not mandatory.

[–] jerry 4 points 5 months ago

good luck! I was an amazing day when I got my CISO position. It was an even better day when I left it :)

[–] jerry 2 points 5 months ago

Thanks. I’ve added to my list to fix

[–] jerry 2 points 5 months ago (9 children)

ok. I set up threativore and added you as a moderator. I doubt it's as sophisticated as what reddit had to offer. The instructions are here: https://github.com/db0/threativore/blob/main/README_manual.md

[–] jerry 6 points 5 months ago (1 children)

OK - old.infosec.pub is now up and running

115
Please don’t enable 2FA (self.infosecpub)
submitted 2 years ago by jerry to c/infosecpub
 

2FA in lemmy doesn’t work reliably yet. Please don’t enable it or you will almost certainly get locked out.

Note: it makes me sad to post this.

37
Blocking sh.itjust.works (self.infosecpub)
submitted 2 years ago by jerry to c/infosecpub
 

Hi all. I am going to implement a block for sh.itjust.works. I am going to need years of therapy from all the nasty crap coming from that instance.

 

Hi all. I’ve disabled new community creation and federation until there is a fix for the latest vulnerability

65
Vulnerability fixed (self.infosecpub)
submitted 2 years ago by jerry to c/infosecpub
 

As some have pointed out, there was a serious xss vulnerability in lemmy disclosed yesterday. The Lemmy team released a fix a bit ago and I've since patched infosec.pub.

138
submitted 2 years ago by jerry to c/infosecpub
 

Lemmy and kbin have been... exciting to set up and debug.

There is a new version of lemmy in RC right now that should fix most of the issues we've been seeing, or at least give error messages that indicate what is going on.

view more: ‹ prev next ›