home.social

#securityengineering — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securityengineering, aggregated by home.social.

  1. A phrase I really do not like is: "I told you so." Usually, people say it after something has already happened that could have been prevented. After systems have already shown their limitations. The recent Lithuania registry breach reminded me once again how important access infrastructure has become. Especially when digital systems operate around government data, real estate, legal entities, and public trust. But through calm engineering discussion, collaboration, and practical security architecture. Article: https://www.antonmb.com/en/blog/rethinking-access-security-after-the-lithuania-breach #CyberSecurity #Authentication #Authorization #AccessControl #ZeroTrust #SecurityArchitecture #GovTech #SecurityEngineering
  2. A phrase I really do not like is: "I told you so." Usually, people say it after something has already happened that could have been prevented. After systems have already shown their limitations. The recent Lithuania registry breach reminded me once again how important access infrastructure has become. Especially when digital systems operate around government data, real estate, legal entities, and public trust. But through calm engineering discussion, collaboration, and practical security architecture. Article: https://www.antonmb.com/en/blog/rethinking-access-security-after-the-lithuania-breach #CyberSecurity #Authentication #Authorization #AccessControl #ZeroTrust #SecurityArchitecture #GovTech #SecurityEngineering
  3. In modern security operations, the hardest problem isn’t detection — it’s maintaining integrity across distributed systems.
    AI accelerates analysis, but resilience still depends on identity, verification, and the ability to reason under uncertainty.
    Speed matters, but judgment matters more.

    #CyberSecurity #InfoSec #AI #SecurityEngineering #ThreatIntelligence #DistributedSystems #IdentitySecurity #Verification

  4. In modern security operations, the hardest problem isn’t detection — it’s maintaining integrity across distributed systems.
    AI accelerates analysis, but resilience still depends on identity, verification, and the ability to reason under uncertainty.
    Speed matters, but judgment matters more.

    #CyberSecurity #InfoSec #AI #SecurityEngineering #ThreatIntelligence #DistributedSystems #IdentitySecurity #Verification

  5. In modern security operations, the hardest problem isn’t detection — it’s maintaining integrity across distributed systems.
    AI accelerates analysis, but resilience still depends on identity, verification, and the ability to reason under uncertainty.
    Speed matters, but judgment matters more.

    #CyberSecurity #InfoSec #AI #SecurityEngineering #ThreatIntelligence #DistributedSystems #IdentitySecurity #Verification

  6. In modern security operations, the hardest problem isn’t detection — it’s maintaining integrity across distributed systems.
    AI accelerates analysis, but resilience still depends on identity, verification, and the ability to reason under uncertainty.
    Speed matters, but judgment matters more.

    #CyberSecurity #InfoSec #AI #SecurityEngineering #ThreatIntelligence #DistributedSystems #IdentitySecurity #Verification

  7. Are you on the safe side yet? 🛡️

    In an era of sophisticated phishing and data breaches, relying on passwords or SMS codes is like locking your front door but leaving the key under the mat. For a robust level of private security, I’ve integrated Yubico Yubikey into my daily routine as the ultimate hardware root of trust.

    The true value of "Cold" Security

    Hardware authenticators offer unparalleled security. Their physical nature means cryptographic keys are embedded directly, making them impossible to copy, extract, or steal remotely. No physical device, no access. Period.

    My "Strict Security" Setup

    I’ve minimized my attack surface by removing the weakest links:

    1. Phone-Free: I have disabled phone number linkage and SMS authentication wherever possible to eliminate SIM-swapping risks.

    2. Passwordless: Where supported, I use FIDO2/WebAuthn. No password means no password can be phished.

    3. The Backup Rule: I use a minimum of two keys. My primary key is always with me, and a backup key is hidden in a secure, off-site location.

    Hardware-Signed Workflow

    I leverage the full multi-protocol potential of the key:

    - GPG & Git: I use GPG primarily for signing git commits. When I push code, I am physically "touching" the hardware to sign that digital information.

    - PIV/SSH: Secure access to servers without resident private keys on the machine.

    - OTP & Static Passwords: Bridges for legacy services.

    The Vault Strategy

    For passwords and sensitive metadata, I rely on Bitwarden. Access to my vault is strictly locked behind my hardware keys.

    > No, I'm not "that paranoid" ... yet. But I do keep an eye on the compromise of central servers. That’s why I’m planning to implement a fully self-hosted, self-controlled vault solution soon.

    I’d love to hear your thoughts – what are your favorite self-hosted security stacks?

    #CyberSecurity #YubiKey #Bitwarden #Infosec #Privacy #MFA #PGP #SSH #SecurityEngineering #SelfHosted

  8. Are you on the safe side yet? 🛡️

    In an era of sophisticated phishing and data breaches, relying on passwords or SMS codes is like locking your front door but leaving the key under the mat. For a robust level of private security, I’ve integrated Yubico Yubikey into my daily routine as the ultimate hardware root of trust.

    The true value of "Cold" Security

    Hardware authenticators offer unparalleled security. Their physical nature means cryptographic keys are embedded directly, making them impossible to copy, extract, or steal remotely. No physical device, no access. Period.

    My "Strict Security" Setup

    I’ve minimized my attack surface by removing the weakest links:

    1. Phone-Free: I have disabled phone number linkage and SMS authentication wherever possible to eliminate SIM-swapping risks.

    2. Passwordless: Where supported, I use FIDO2/WebAuthn. No password means no password can be phished.

    3. The Backup Rule: I use a minimum of two keys. My primary key is always with me, and a backup key is hidden in a secure, off-site location.

    Hardware-Signed Workflow

    I leverage the full multi-protocol potential of the key:

    - GPG & Git: I use GPG primarily for signing git commits. When I push code, I am physically "touching" the hardware to sign that digital information.

    - PIV/SSH: Secure access to servers without resident private keys on the machine.

    - OTP & Static Passwords: Bridges for legacy services.

    The Vault Strategy

    For passwords and sensitive metadata, I rely on Bitwarden. Access to my vault is strictly locked behind my hardware keys.

    > No, I'm not "that paranoid" ... yet. But I do keep an eye on the compromise of central servers. That’s why I’m planning to implement a fully self-hosted, self-controlled vault solution soon.

    I’d love to hear your thoughts – what are your favorite self-hosted security stacks?

    #CyberSecurity #YubiKey #Bitwarden #Infosec #Privacy #MFA #PGP #SSH #SecurityEngineering #SelfHosted

  9. A kernel bug sat in plain sight for 8 years. AI found it in an hour.

    Wrong takeaway: AI is making attackers faster.

    Better takeaway: our security model assumes too much about patching.

    Assume latent flaws exist.
    Design around containment, isolation, and resilience.

    AI isn’t changing vulnerability physics.
    It’s exposing reality faster.

    More thoughts here:
    LinkedIn: 🔗 linkedin.com/posts/dinesh-mr_7

    #CyberSecurity #Linux #AISecurity #SecurityEngineering

  10. A kernel bug sat in plain sight for 8 years. AI found it in an hour.

    Wrong takeaway: AI is making attackers faster.

    Better takeaway: our security model assumes too much about patching.

    Assume latent flaws exist.
    Design around containment, isolation, and resilience.

    AI isn’t changing vulnerability physics.
    It’s exposing reality faster.

    More thoughts here:
    LinkedIn: 🔗 linkedin.com/posts/dinesh-mr_7

    #CyberSecurity #Linux #AISecurity #SecurityEngineering

  11. Linux Privilege Escalation Cheat Sheet: Techniques and Prevention.

    In this cheat sheet, I break down essential enumeration commands, common escalation paths, and practical techniques every security professional should know.
    denizhalil.com/2025/06/30/linu

    #CyberSecurity #LinuxSecurity #PrivilegeEscalation #Pentesting #RedTeam #BlueTeam #InfoSec #ethicalhacking #SecurityEngineering #itsecurity

  12. Linux Privilege Escalation Cheat Sheet: Techniques and Prevention.

    In this cheat sheet, I break down essential enumeration commands, common escalation paths, and practical techniques every security professional should know.
    denizhalil.com/2025/06/30/linu

    #CyberSecurity #LinuxSecurity #PrivilegeEscalation #Pentesting #RedTeam #BlueTeam #InfoSec #ethicalhacking #SecurityEngineering #itsecurity

  13. UDP Network Monitoring with C++: A Comprehensive Guide

    In this guide, I demonstrate how to build a UDP packet sniffer in C++ using raw sockets, parse packet headers, and extract key data like source/destination IPs and ports.
    denizhalil.com/2025/07/14/udp-

    #CyberSecurity #NetworkMonitoring #PacketSniffer #UDP #Cpp #NetworkSecurity #InfoSec #BlueTeam #RedTeam #InfoSec #securityengineering #denizhalil

  14. UDP Network Monitoring with C++: A Comprehensive Guide

    In this guide, I demonstrate how to build a UDP packet sniffer in C++ using raw sockets, parse packet headers, and extract key data like source/destination IPs and ports.
    denizhalil.com/2025/07/14/udp-

    #CyberSecurity #NetworkMonitoring #PacketSniffer #UDP #Cpp #NetworkSecurity #InfoSec #BlueTeam #RedTeam #InfoSec #securityengineering #denizhalil

  15. UDP Network Monitoring with C++: A Comprehensive Guide

    In this guide, I demonstrate how to build a UDP packet sniffer in C++ using raw sockets, parse packet headers, and extract key data like source/destination IPs and ports.
    denizhalil.com/2025/07/14/udp-

    #CyberSecurity #NetworkMonitoring #PacketSniffer #UDP #Cpp #NetworkSecurity #InfoSec #BlueTeam #RedTeam #InfoSec #securityengineering #denizhalil

  16. BGP, the protocol that decides where internet traffic flows, still operates largely on trust. That creates opportunities for route leaks, hijacks, and outages that don’t require touching the target environment at all. technicalciso.com/bgp-blind-sp #CyberSecurity #NetworkSecurity #BGP #InternetInfrastructure #SecurityEngineering #CyberRisk

  17. BGP, the protocol that decides where internet traffic flows, still operates largely on trust. That creates opportunities for route leaks, hijacks, and outages that don’t require touching the target environment at all. technicalciso.com/bgp-blind-sp #CyberSecurity #NetworkSecurity #BGP #InternetInfrastructure #SecurityEngineering #CyberRisk

  18. BGP, the protocol that decides where internet traffic flows, still operates largely on trust. That creates opportunities for route leaks, hijacks, and outages that don’t require touching the target environment at all. technicalciso.com/bgp-blind-sp #CyberSecurity #NetworkSecurity #BGP #InternetInfrastructure #SecurityEngineering #CyberRisk

  19. Python C2 Server for Red Teaming: A Comprehensive Hands-On Guide

    In this guide, I walk through building a Python-based C2 server, covering its architecture, encrypted communication, and real-world operational workflow.
    denizhalil.com/2025/12/15/pyth

    #CyberSecurity #RedTeam #C2 #commandandcontrol #Python #offensivesecurity #Pentesting #infosec #threatdetection #blueteam #securityengineering #ethicalhacking

  20. Python C2 Server for Red Teaming: A Comprehensive Hands-On Guide

    In this guide, I walk through building a Python-based C2 server, covering its architecture, encrypted communication, and real-world operational workflow.
    denizhalil.com/2025/12/15/pyth

    #CyberSecurity #RedTeam #C2 #commandandcontrol #Python #offensivesecurity #Pentesting #infosec #threatdetection #blueteam #securityengineering #ethicalhacking

  21. Python C2 Server for Red Teaming: A Comprehensive Hands-On Guide

    In this guide, I walk through building a Python-based C2 server, covering its architecture, encrypted communication, and real-world operational workflow.
    denizhalil.com/2025/12/15/pyth

    #CyberSecurity #RedTeam #C2 #commandandcontrol #Python #offensivesecurity #Pentesting #infosec #threatdetection #blueteam #securityengineering #ethicalhacking

  22. SSH Tunneling and Port Forwarding Techniques: A Comprehensive Guide

    In this article, I cover:
    * How SSH tunneling works under the hood
    * Local, remote, and dynamic port forwarding techniques
    * Real-world use cases (databases, internal services, pivoting)
    * Security risks and hardening recommendations

    denizhalil.com/2026/02/02/ssh-

    #CyberSecurity #sshtunneling #portforwarding #NetworkSecurity #Linux #RedTeam #BlueTeam #Pentesting #InfoSec #securityengineering #EthicalHacking #ITSecurity