Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Thank you for proposing to cure the lack of competence with the lack of freedom, but the easier source of target identity is the August 2022 breach of LastPass


Insider Threat is real, can't discount that at all. What I can tell you as someone who participates in OSINT competitions and has engaged in red team activities, Linkedin is always the first stop when shopping for info.

Edit: Also wanted to mention 3 out of 4 incidents I am involved in is related to insider threat.


We can't discount the insider threat at all, but it's very easy to discount such shallow measures. Also, this wasn't a competition, and even there "the first stop" tells us nothing about its effectiveness (maybe the next 5 steps take 5 mins longer, but are even more accurate, so the benefit of the ban would still not exist)




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: