Do We Need Penetration Testing and Vulnerability Scanning? - Adrian Sanabria, Josh Bre... - PSW

  Рет қаралды 775

Security Weekly - A CRA Resource

Security Weekly - A CRA Resource

19 күн бұрын

This may be controversial, however, we've been privately discussing how organizations benefit from penetration testing and vulnerability scanning. Do you still need these services as a critical part of your security program? Can't you just patch stuff that is missing patches? Tune in for a lively debate!
Visit www.securityweekly.com/psw for all the latest episodes!
Show Notes: securityweekly.com/psw-833

Пікірлер: 2
@db257c
@db257c 16 күн бұрын
The comments about how, "you should never have vulnerable docker containers," makes me laugh. I would challenge you to do the work the next couple times the, "Friday afternoon, pin it till Monday," situation happens and make that statement again. Realistic mode would be with a php container. As soon as you get into language depencency chains (npm, composer, pip, etc), "Just update it," immediately becomes a painfully naive statement. PHP is hard mode because you also have c extensions to deal with and it's a *very* common language, even if it's no longer in Vogue. I agree with you that the work needs to be done. And I agree that it shouldn't be, "pinned till Monday and then forgotten," or more likely, "pinned till Monday, then Monday morning business decides some other random thing is suddenly a huge priority." Which is something you can easily deflect if you have the gumption, experience, and political clout to tell business to pound sand on security issues when neccesary. But it's rare to find ops teams that curate that. And this is ignoring the common situation of, "We have a centralized 'devops' team (which isn't how it's supposed to work but is very common) and disparate dev teams, none of whom talk to each other or coordinate tools/technology/languages/etc." "Just patch the container," turns into, "Learn a whole new language, dependency chain, and sometimes application to do work business won't otherwise prioritize. And also chase dev and qa around for verification." I'm not going to get into the xz situation, but running bleeding edge versions of dependencies patches all the time also has a crop of issues unrelated to just, "The app broke." I'm sure you didn't mean it that way, but the statement, "You shouldn't have out of date or vulnerable containers in your environment ever," comes off as very, "Decree from the security ivory tower," that is tolerated to an extent and ignored/actively undermined in extreme cases.
@securitypodcaster
@securitypodcaster 4 күн бұрын
Thanks for your comments! Everyone's organization and dev environments are different, as is your risk profile and tolerance. Certainly you will have vulnerabilities in your containers, and so many tools and processes exist to help organizations with this problem. However, at the end of the day it comes down to the risks you are willing to take, what actually protects the business, and the resources you have at your disposal.
Hack all the things, patch all the things - PSW #833
1:50:38
Security Weekly - A CRA Resource
Рет қаралды 271
Trump’s Second Term: Last Week Tonight with John Oliver (HBO)
29:15
LastWeekTonight
Рет қаралды 7 МЛН
LOVE LETTER - POPPY PLAYTIME CHAPTER 3 | GH'S ANIMATION
00:15
Мы никогда не были так напуганы!
00:15
Аришнев
Рет қаралды 6 МЛН
Survival skills: A great idea with duct tape #survival #lifehacks #camping
00:27
I switched to Linux 30 days ago... How did it go?
28:46
Craft Computing
Рет қаралды 182 М.
Understanding Ransomware Threats to ESXi: Essential Insights
53:39
HTMX Sucks
31:45
ThePrimeTime
Рет қаралды 115 М.
MoveIT, Entrust, Fed Reserve, ISPs, Volt Typhoon & More - SWN #395
29:09
Security Weekly - A CRA Resource
Рет қаралды 279
Hacker Heroes - Joe Grand - PSW Vault
1:43:58
Security Weekly - A CRA Resource
Рет қаралды 261
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 1,2 МЛН
Is Skynet watching you already?
1:04:00
David Bombal
Рет қаралды 1 МЛН
How To Avoid Being Phished - SWN Vault
46:06
Security Weekly - A CRA Resource
Рет қаралды 159
🚀  TDD, Where Did It All Go Wrong (Ian Cooper)
1:03:55
DevTernity Conference
Рет қаралды 553 М.
ИГРОВОВЫЙ НОУТ ASUS ЗА 57 тысяч
25:33
Ремонтяш
Рет қаралды 352 М.
Опять съемные крышки в смартфонах? #cmf
0:50
WATERPROOF RATED IP-69🌧️#oppo #oppof27pro#oppoindia
0:10
Fivestar Mobile
Рет қаралды 18 МЛН