Serious Discussion How Does One improve Security ?

General Security Discussions
57 Replies 5,953 Views
Guys, please stay on topic. This thread is for discussing "How does one improve security'.
I shared some insights and some links about disclosed vulnerabilities that would help other better understand the threat vectors. Each one of the replies I made is one way or another related to the core of this topic.

Edit:


Correcting misinformation and dismantling unverified claims (on the topic of cyber security) is precisely on-topic.
 

This completely nukes the fallacy of "up-to-date"

The Januscapel Vulnerability was introduced in the Linux kernel in August 2010, and it was not patched until 2026 (16 years!)

For a decade and a half, Linux system administrators who religiously kept their servers "up-to-date" were still completely vulnerable to this zero-day exploit. An updated OS only protects against known threats; it does nothing to stop a 16-year-old architectural flaw.
 
Guys, this thread is for posting Methods to Improve Security.

@Divine_Barakah has demo'ed another way, and that is to learn from attack dissections by security researchers. Some call it Open Source Intelligence. (OSINT). Members of MT frequently post these as Security News in the forum. Sometimes, the dissections reveal methods where we can block some of the attacks. For example for ClickFix attacks, we can use Group Policy to forbid use of the Run Box ( accessed by Winkey + R )
 
I found one way to improve my security is to list out all the security configurations that I make - AV and it's settings, Hard Configurator settings, all hardening steps into a document and upload it to AI, and then ask it to criticize the security, identify the security gaps and attack vectors I've missed, and suggest compensating controls that addresses the security gaps.
I have subscribed to Anthropic Claude. And asked for critique, twice. And both times the AI suggested different things. So remember to ask it at least twice.
 
I firmly believe in having a non-default-security set up. Having a plain Win 11 out of box and a popular AV without configuration is asking for trouble. Hackers come prepared for that sort of set up.

And the most vulnerable stage of a box is during the setup stage, when defenses are not all in place. Have a written down hardening check list, divide it into offline do-able and online to-do's, do it up to the point of needing to go online. Do a drive image, then continue. That way if something bad happens or something feels weird while online in the middle of setup, you can quickly revert and do it again. And when it does all go as planned, save a drive image too.

'Feels weird' is hard to pin down. When you have the UAC slider all the way to the top, and an expected UAC doesn't show up. That sort of defines weird. That was in the past. A recent one was that I was doing an dnf update (online update of Fedora Linux) and suddenly I get a bunch of red lines appear indicating a disruption. Network errors are not weird, but later my perfectly entered password that I have muscle memory of refuses to authenticate, a few times, I decided at the time that I'd let it slide. Watch me regret it. There is the pre-online drive image. Lets see if I have to 'start' over.
 
Last edited:
Need more explanation;
I cannot recall the exact CVE, but for example it was vulnerability on a router, and the attacker can remotely activate a flaw, and run code.

And don't think Windows is immune from these sort of things, Windows take input from the network in many instances. For example your Windows Spotlight randomly receives 'photos' ( a glob of something). and if there's a flaw in the graphics processing, it could get hit. For one, the firewall does not expose a control over it.
 
Last edited:
I cannot recall the exact CVE, but for example it was vulnerability on a router, and the attacker can remotely activate a flaw, and run code.

And don't think Windows is immune from these sort of things, Windows take input from the network in many instances. For example your Windows Spotlight randomly receives 'photos' ( a glob of something). and if there's a flaw in the graphics processing, it could get hit. For one, the firewall does not expose a control over it.
This is true but is an extremely rare scenario.
Such vulnerabilities are usually pateched regularly.
It takes a significant amount of effort and time to explore is there are still one or two unpatched and trying to exploit.
Only psychopathic hackers might try to use for hacking average Joe machine; it is for high-caliber targets.
 
Only psychopathic hackers might try to use for hacking average Joe machine; i
As I am fond of reminding people, hackers comes with various motivations and skill levels. An exploit might be floating around in the underground and one might just take it and modify it. Not all hackers are accomplished cybercriminals. The apprentice hacker will target anyone within reach. And with the proliferation of distro's like Kali and Parrot, anyone who takes interest can pick up the fundamental skills. Hell, even I, a sworn defender, have a Kali distro in my backups.
 
Last edited:
it is for high-caliber targets.
i also want to dispel that notion. Remember a few days ago someone at MT posted news of a IoT camera vulnerability. Who would you think takes advantage of those kinds of vulnerabilities, amateur hackers of course. They are just plain nosy and want to see your 15 yr old daughter !
 
Remember a few days ago someone at MT posted news of a IoT camera vulnerability.
This is called the "attack surface area"; I have the narrowest possible, only very basic hardware and very essential software and features to run the few apps I use.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top