Seceng
Seceng
@seceng.bsky.social
Security engineer, back to tech role after leadership role. Previously head of engineering in a large US corp and security startups and academic research (PhD). Sharing thoughts and opinions on engineering leadership and security.
Yes indeed! It will definitely help
March 4, 2025 at 1:09 PM
Btw, yes IBM provides also a tool for containers that search for key materials but when I tried to run it on my pc with the filesystem functionality it did not do very well. I still consider it very much a research tool rather than something to rely upon.
February 4, 2025 at 3:07 PM
However, when it comes to infrastructure the situation is worse, even though the problem there is larger. There exist a lot of tools to do ciphers discovery (e.g., network-based tools for SSH/TLS) but none of them to the best of my knowledge actually provides you with the cbom.
February 4, 2025 at 3:05 PM