56
After cybersecurity lab wouldn’t use AV software, US accuses Georgia Tech of fraud
(arstechnica.com)
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
Community Rules
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]
Notable mention to [email protected]
I think the security researcher has a valid point.
In a secure environment you don't want random things running in memory, sending samples to third parties.
Would a static virus scanner run periodically on the volume itself been sufficient? If yes, then the researcher was being unreasonable.
That's a real roller coaster ride of a journey. Thanks for sharing it. Glad you got some bonus hardware out of it.
Totally reasonable to not do a dumb thing if you have no contractual obligation to do the dumb thing.
Sadly they had that obligation, so they have to weigh the cost of doing the dumb thing with the cost of breaching contract.