Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2025 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

Lack of Vision

May 3, 2018 By Michael Kavka Leave a Comment

I have noticed something about our field. The lack of vision we have. We get comfortable with our knowledge, and are afraid of being wrong. We blind ourselves which makes us susceptible to attacks.

via GIPHY

Unfortunately this feeling can eventually lead us to feeling like this when things go wrong:

via GIPHY

I am not saying there is anything wrong with being confident in what one knows. I am talking about blinding ourselves. We have been seeing some old techniques and tactics come back into play again. We aren’t watching for these because they were eradicated years ago perhaps, or never were much of a threat. Instead they are being used as one part of an attack. We also get caught up in not only attribution, but a blame game. It is “X” companies fault. The legacy system needed only works on “Y” OS so it is the OS companies fault. I see this all the time. Watch twitter enough and you will see it too. The thing is we are all to blame. We have our hatred of X company because of reasons. We prefer Y because it seems more secure. We discount the simple answer immediately until we wind up taking the long way around and come back to it after eliminating the more complex and sexier looking possibilities.

There are reasons for so many things. For instance legacy and the countries infrastructure. I saw a talk at Cyphercon on the basics of ICS threat hunting. Lesley Carhart gave some basic information on the world of ICS so we could understand things better. There are reasons that upgrading systems are so slow in that world. Very good reasons, such as making sure your power is not interrupted. All the majority of us see is, legacy bad, change it now, instead of learning why legacy is needed.

The world of the theoretical is lovely, but it is not always achievable. We have to learn that. We have to take off the blinders and understand that we may be wrong, that the old ways may come back in a vicious circle. We need to realize that we do not know so much, and that it is okay not to know. What is not okay is to have tunnel vision.

Filed Under: Rants, Security

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

RSS Taggart Institute Intel Feed

  • Are You Protecting Yourself from Deepfakes? Take This Quick Quiz. October 27, 2025 Shanan Winters
  • Losing the Swing States October 27, 2025 Richard Fontaine
  • UN Cybercrime Treaty wins dozens of signatories, to go with its many critics October 27, 2025 Simon Sharwood
  • Uncovering Qilin attack methods exposed through multiple cases October 27, 2025 Takahiro Takeda
  • ISC Stormcast For Monday, October 27th, 2025 https://isc.sans.edu/podcastdetail/9672, (Mon, Oct 27th) October 27, 2025
  • Shaq's new ride gets jaq'ed in haq attaq October 26, 2025 Brandon Vigliarolo
  • The Kavanaugh stop, 50 days later October 26, 2025 Chris Geidner
  • Kaitai Struct WebIDE, (Sun, Oct 26th) October 26, 2025
  • Hackers steal Discord accounts with RedTiger-based infostealer October 26, 2025 Bill Toulas
  • [REVIVE-SA-2025-002] Revive Adserver Vulnerability October 26, 2025

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP