Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

K.I.S.S. up, or we lose

Posted on June 13, 2017 By Michael Kavka No Comments on K.I.S.S. up, or we lose

There is a distinct possibility we overlooked it. It is just that little nagging in the back of our head, but still we know better, or do we?

 

So there I was, wondering why the Powershell script I modified and was using was not working. Why I was getting access denied errors. I went over the script again and again. I tried limiting the scope, hard coding information instead of having to input it, and still that same damn error. The answer was there, I just had to find it…

Yes, this was me recently. I bet you have been in a similar situation though. Can’t quite find that issue. Come on, we are smart, we know our stuff, but still we can’t find the answer. In my case it was I was using the wrong account to run the script. Stupid, simple and maddening. Only took a few days of troubleshooting to realize it. I should have known to double check the simple though, it has been a recurring theme in my life. Looking at a lot of the IT and infosec world, I think we all need to look at this.

I was a teenager back in the 80’s, tired of entering data statements to get the cool graphics on my Commodore 64. Compute’s Gazette had a program in there that would allow me an easier path once I inputted it and loaded it. Turtle graphics and commands, and I was going to get this going except it didn’t work. I checked the hundreds of numbers in all the data lines. Everything was right. I checked all my statements, compared back and forth for weeks, months, years. Still error when ran. The only way I could get it to not error was if I increased the if-then loop by one. That kept hitting me as I had to have messed up the data statements in some way. Five years passed, and I found the extra comma at the end of one of the data statements by total accident. That fixed the issue. A simple typo cause 5 years of troubleshooting off and on. I was bound to learn from this, to check for the simplest things. I would learn from it dammit, at least until I didn’t.

Think about it. Look at phishing, how we treat users, how we treat each other. How many times have you turned and said, “Oh that isn’t something I need to check,” and yet that was the problem. The simple answer. The one thing you didn’t feel the need to do.

I was learning to build and upgrade my own computers in the early to mid 90’s. I had changed out cards in the PC many times, and this was just a new sound card. Put it in, put everything back together, loaded the driver and… nothing. Only the boot beep code of the motherboard’s little speaker. No music, no sound effects, no nothing. Re-seat the card, check to make sure plugs are in solid. Still nothing. Try the old card, and nothing. Try a different slot, nothing. Six months of this, and I went to do some cabling cleanup. Yeah, I found that for 6 months I had the speakers plugged into the microphone jack and the microphone plugged into the speaker jack (the male ends of the plugs were not color coded back then). Switch the two plugs and I tried to make myself deaf from how loud I had the volumes turned up.

So where does this leave us. How many layers of devices do we have to “secure all the things?” What does each thing do? Do we know how to work with each device, piece of software, policy to its fullest extent? Do they even make sense or is it the old, “lets just throw things at it until it sticks,” scenario? How convoluted and complex has it all become, and why? I think for me ti is best summed up in a classic episode of Doctor Who during the Tom Baker era. He went to open a door with a complex electronic lock and pulled out a bobby pin to do it. When asked why he said,” the more complex the system the simpler it is to break with something simple.” Have we all gotten to the point where we have forgotten where we came from? Where we are just outsmarting ourselves? Do we listen to fresh eyes, fresh ideas or just throw them away as a bunch of nonsense? Are we willing to learn how to keep it simple, or have we made it easier for the bad guys to get through because of how overly complex we have made everything? Is our own cleverness our actual real weakness being exploited?

Rants, Security Tags:InfoSec

Post navigation

Previous Post: Have we lost sight of the future?
Next Post: In our own sandbox

Related Posts

  • Security is Reactionary, No Matter What Security
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

More Related Articles

Security is Reactionary, No Matter What Security
Defender, KQL and Lockbit Microsoft
Do well, not be “popular” Ramblings
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Malicious npm packages evade install-script defenses at runtime September 20, 2026 Bill Toulas
  • Researchers escape OpenAI Codex sandbox to run commands on host September 20, 2026 Ax Sharma
  • An undercover Google analyst infiltrated a notorious supply-chain hacking gang September 20, 2026 Andy Greenberg
  • GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign September 20, 2026
  • Google’s Gemini is the latest AI model to hack other companies September 19, 2026 Anthony Ha
  • Gemini went rogue, hacked three companies, and Google hid it September 19, 2026 Terrence O’Brien
  • BragJack attacks hijack AI browser agents through malicious extensions September 19, 2026 Ax Sharma
  • Agentic security is the billion-dollar challenge for some clever startup to solve September 19, 2026
  • North Korean WaterPlum hackers infected 30,000 devices worldwide September 19, 2026 Bill Toulas
  • ShinyHunters hacks Clop leak site, threatens to extort ransomware gang September 19, 2026 Lawrence Abrams
  • Calling viral AI actress Tilly Norwood? Agree to a face scan first September 19, 2026 Ax Sharma
  • Viral AI actress' hotline face-scans every caller, watches their mood September 19, 2026 Ax Sharma

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Malicious npm packages evade install-script defenses at runtime September 20, 2026 Bill Toulas
  • Researchers escape OpenAI Codex sandbox to run commands on host September 20, 2026 Ax Sharma
  • An undercover Google analyst infiltrated a notorious supply-chain hacking gang September 20, 2026 Andy Greenberg
  • GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign September 20, 2026
  • Google’s Gemini is the latest AI model to hack other companies September 19, 2026 Anthony Ha
  • Gemini went rogue, hacked three companies, and Google hid it September 19, 2026 Terrence O’Brien
  • BragJack attacks hijack AI browser agents through malicious extensions September 19, 2026 Ax Sharma
  • Agentic security is the billion-dollar challenge for some clever startup to solve September 19, 2026
  • North Korean WaterPlum hackers infected 30,000 devices worldwide September 19, 2026 Bill Toulas
  • ShinyHunters hacks Clop leak site, threatens to extort ransomware gang September 19, 2026 Lawrence Abrams
  • Calling viral AI actress Tilly Norwood? Agree to a face scan first September 19, 2026 Ax Sharma
  • Viral AI actress' hotline face-scans every caller, watches their mood September 19, 2026 Ax Sharma
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.