the guide of security jerk

7
@CreativeConnard The Guide of Security Jerk Code of conduct is for bastards RMLL Sec 2016 – Rump session

Upload: clement-oudot

Post on 22-Jan-2018

543 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: The guide of Security Jerk

@CreativeConnard

The Guideof Security

Jerk

Code of conduct is for bastards

RMLL Sec 2016 – Rump session

Page 2: The guide of Security Jerk

@CreativeConnard

Previous edition

Le Guide du Connard du Logiciel Libre

https://2015.rmll.info/le-guide-du-connard-du-logiciel-libre

Page 3: The guide of Security Jerk

~ 3 ~@CreativeConnard

HOW TObe a security jerk

~ Developer ~

~ Sysadmin ~

~ End user ~

Page 4: The guide of Security Jerk

~ 4 ~@CreativeConnard

Developer

Store passwords in base64 (or in base32 for 32bits systems)※Require specific lib versions and discourage any upgrade※

Invent your own cryptographic algorithm※

Page 5: The guide of Security Jerk

~ 5 ~@CreativeConnard

Sysadmin

export TLS_REQCERT=never (aka Malware In The Middle)※Write your own Config Management (SSH for kids)※

Always run processes as root and disable SELINUX※

Page 6: The guide of Security Jerk

~ 6 ~@CreativeConnard

End user

Don’t trust One Time Password as is it always changing※Click everywhere, IT is a game※

Use pastebin as password manager※

Page 7: The guide of Security Jerk

~ 7 ~@CreativeConnard

@CreativeConnard

Links for bastards

@DonJon_Legacyhttp://donjonlegacy.com/