Don Mallory
banner
singleusermode.bsky.social
Don Mallory
@singleusermode.bsky.social
Infosec | darkroom photog |
and stuff.
Next time you see me, ask me about the plant on the monitor.
July 7, 2025 at 2:32 PM
I'd ship you maple syrup, but Canada Post is on strike. :-P
November 29, 2024 at 12:34 AM
Apparently you can subscribe to other people's block lists like this one joabaldwin.com/scrapers. It seems to reduce the noise a little.
Bluesky
joabaldwin.com
November 20, 2024 at 4:21 AM
I see your cats, and raise you a sleepy dog cuddling her stuffed bunny with her tongue sticking out.
November 15, 2024 at 3:26 AM
That includes architecting it with security at the beginning instead of assuming that someone will tack somewhere on later to deal with underdeveloped shortcomings.
January 3, 2024 at 6:15 PM
Agreed, tech changes without consideration of the impact to services around them will be what kills allowlists as a solution. It comes back to my original statement, the vendor or tech creator should be responsible for both understanding what they built, and what is required to support it.
January 3, 2024 at 6:13 PM
The trick is, where do you place the allowlist for optimal success and you have to be willing or have tooling to assess _everything_ that deviates from allowed activity.
January 3, 2024 at 5:27 AM
Sure we can, we've been doing allowlisting for years, it's just that most orgs feel it's too complicated and if we don't take the time to understand what we are allowing, our model will be too permissive. Vendors that create solutions could also create the allowlists for the expected platform.
January 3, 2024 at 5:24 AM