this post was submitted on 26 Aug 2024
56 points (100.0% liked)

Cybersecurity

5540 readers
71 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 12 points 1 month ago (2 children)

I think the security researcher has a valid point.

In a secure environment you don't want random things running in memory, sending samples to third parties.

Would a static virus scanner run periodically on the volume itself been sufficient? If yes, then the researcher was being unreasonable.

[–] [email protected] 4 points 1 month ago

Totally reasonable to not do a dumb thing if you have no contractual obligation to do the dumb thing.

Sadly they had that obligation, so they have to weigh the cost of doing the dumb thing with the cost of breaching contract.