Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General
  • Gatekeeping and Treatment of Others Rants

Frost Piss.. er First Post of 2018

Posted on January 5, 2018 By Michael Kavka No Comments on Frost Piss.. er First Post of 2018

From the frozen sections of the Northern U.S. welcome to 2018! I hope everyone had a good holiday and is refreshed. If not, step outside in the cold, you’ll at least be somewhat refreshed.

Spectre/Meltdown. There I have mentioned it. With so many fantastic write-ups and posts out there, you don’t need another one so lets move on.

One of the things I have been noticing is a lack of forethought. We (and our bosses especially) are so caught up in the reactionary phase of things, that we tend to not think things through. A new vuln comes out, chicken little starts screaming, and we all get over stressed. This happens whether there is a POC, it is found in the wild, or neither. In a products community forum recently, it was asked about the current hullabaloo, why worry about the endpoints since there is nothing in the wild. I responded with the same statement I am making here. Why be reactive when you can be proactive.

Now I know, we have pent test, vuln scans, SEIM and blah blah blah that makes us proactive. Does it really though? How often are we reacting to something from one of our tools? Yes, you can claim putting the tool in place is being proactive. How long though between finding something with the tools, and mitigation? Days? Weeks? Months? How often could being a little faster on the response to some proactive tool stop a piece of malware coming in?

While this is a big deal, there is another one. That is in the planning stages for, well, anything. Take acquisitions for example. Are you doing an audit on their security posture? What about their AD? How messed up is that? When will it get cleaned up? How are they granting access and putting people in security groups? How will this translate to your company’s policies? What happens when you try to merge them into your AD/File Share structure? Is their share structure just going to be changed to your domain, or are you copying the data over only? These are important questions and affect your company’s security posture.

It is a new year, and really time to start thinking anew. After all, you can’t fill up an already full tea cup, and you can’t learn unless you empty your preconceived notions.

General, Rants Tags:Meltdown, Security, Spectre

Post navigation

Previous Post: As we move to a new year
Next Post: We are headed for a Spectre of a Meltdown

Related Posts

  • New Year, New Post, from the start General
  • Do well, not be “popular” Ramblings
  • Ransomware, Are You Ready? General
  • Gatekeeping and Treatment of Others Rants
  • The one about banking passwords… Rants
  • Solarwinds Sunburst: Haven’t We Been Here Before? Ramblings

More Related Articles

New Year, New Post, from the start General
Do well, not be “popular” Ramblings
Ransomware, Are You Ready? General
Gatekeeping and Treatment of Others Rants
The one about banking passwords… Rants
Solarwinds Sunburst: Haven’t We Been Here Before? Ramblings

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP

RSS Taggart Institute Intel Feed

  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General
  • Gatekeeping and Treatment of Others Rants

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.