Anzeige

Crazy incentives and how they drive security into no man's land

23. Mar 2023
Anzeige

Más contenido relacionado

Anzeige

Crazy incentives and how they drive security into no man's land

  1. Crazy incentives and how they drive security into no man's land Christian Folini Keynote 2023
  2. Streaming in China Source: @RealSexyCyborg (Naomi Wu) Streaming in China
  3. Hello Insomni’Hack! I am Christian Folini Find me at @ChrFolini / @folini@infosec.exchange Swiss Security Engineer OWASP CRS Co-Lead Wearer of Many Helmets
  4. “ In general, incentives are anything that persuade a person to alter their behaviour. (Wikipedia)
  5. “ In general, incentives are anything that persuade a person to alter their behaviour. ... Higher incentives amount to greater levels of effort and therefore, higher levels of performance.
  6. Elon scrambling for money
  7. Nessus Reports
  8. More Nessus Madness
  9. Inflated Numbers
  10. Even Bigger Numbers Source: https://techjury.net/
  11. The Infamous Norse Dashboard A Kibana Example
  12. Typical ModSecurity Dashboard Element
  13. Survivorship Bias Source: Wikipedia: Survivorship Bias
  14. Bug Bounty Hunters Source: https://pexels.com
  15. Bug Bounty Hunters Penetration Testers
  16. Large Baskets with Many, Many Eggs
  17. Crisis Communication
  18. Ransomware Source: Wikipedia: AIDS DOS Trojan 1989
  19. Ransomware and Cyber Insurance
  20. Commercial WAF Detection Rates Source: https://fraktal.fi (Tuomo Makkonnen, 2020)
  21. Unce upon a time, there was a boy ...
  22. The boy was a shepherd
  23. His little herd also included a ram
  24. He took them through a forest
  25. In the forest, there was a wolf
  26. The boy screamed and called the hunters
  27. The hunters came and wanted to kill the wolf
  28. But as it turned out, it was all a false positive!
  29. The alternative: a false negative!
  30. The alternative: a false negative!
  31. The alternative: a false negative!
  32. Commercial WAF Detection Rates Source: https://fraktal.fi (Tuomo Makkonnen, 2020)
  33. Summary Let’s wrap this up!
  34. Level 1 An overly relaxed attitude, ignorance, negligence and carelessness lead to bad incentives for users. Tricking them into weak decisions undermining security. Two Levels of Bad Incentives Level 2 Deliberately following or setting crazy incentives for immediate gain; consciously prioritizing financial benefit over security of users and their data.
  35. It’s your job to raise the alarm when incentives and security don’t align!
  36. Contact christian.folini@netnea.com @ChrFolini @folini@infosec.exchange
Anzeige