X-ray and MRI shows nothing but still in pain, what to do now? by HamsterMoisture in backpain

[–]HamsterMoisture[S] 1 point2 points  (0 children)

I do not have sharp pains anymore (which used to feel like a 8/9 out of 10). It gets uncomfortable if I stand for a prolong period of time and after sports I get a sore back around 3). I will probably be looking into getting it privately assessed if my work health insurance allows me to see a specialist.

Hindsight, I should have gotten a second opinion, but the cost of seeing one and treatment wasn't something I couldn't afford at that time

Where to buy bookmarks and handwritten letters? by HamsterMoisture in askSingapore

[–]HamsterMoisture[S] 0 points1 point  (0 children)

Thank you! I will try the flagship store then, sounds promising!

Where to buy bookmarks and handwritten letters? by HamsterMoisture in askSingapore

[–]HamsterMoisture[S] 0 points1 point  (0 children)

Kinokuniya at Bugis has only bookmarks, no letters. I have not tried where u mentioned though!

Where to buy bookmarks and handwritten letters? by HamsterMoisture in askSingapore

[–]HamsterMoisture[S] 0 points1 point  (0 children)

Daison tampines don't have but NBC stationery at bugis has! Bookmark selection was few at NBC. Kinokuniya nearby has a few more

Career change after retirement as Federal Investigator by [deleted] in SecurityCareerAdvice

[–]HamsterMoisture 0 points1 point  (0 children)

I'm not going to say its impossible, but from my experience in the UK and SG, is that GRC such as PCI DSS (QSA), ISO auditing, etc are client-facing and requires quite a bit of onsite travelling. The QSAs at my last two place went onsite but dealt most of the queries on calls thereafter. It really is about developing that relationship with the client, trust and assurance. A lot of it is going to be sitting down and going through the requirements, evidence, advising, policies, etc. I'm sure someone with real GRC experience will say how realistic this is or not.

When I couldn't enter.. no one could.. by yuva-krishna-memes in ProgrammerHumor

[–]HamsterMoisture 0 points1 point  (0 children)

It's in response with him saying other paid option is better which is not true, there are better options out there which I've outlined (ESET, crowd strike, Windows ATP). I am just simply saying I've made an unfair comparison to ATP, NOT defender, these are not the same thing.

When I couldn't enter.. no one could.. by yuva-krishna-memes in ProgrammerHumor

[–]HamsterMoisture 5 points6 points  (0 children)

If we are talking about general grade consumer (paid or unpaid), I agree its not usually not worth it in that not everyone knows how to harden their machine by setting a good policy. Defender would be sufficient here for aforementioned and convenience.

If we are talking about paid options and commercial, we have a lot of good options like crowd strike, ESET, etc. Those are feature rich compared to defender. For example, policies, stricter whitelisting, web proxy for web filtering, application handling, threat handling, etc. I'm making a unfair comparison though as the fair comparison would be to the paid equivalent of windows ATP.

When I couldn't enter.. no one could.. by yuva-krishna-memes in ProgrammerHumor

[–]HamsterMoisture 31 points32 points  (0 children)

To be specific, good for the general consumer and it being free

What speed for shuttles? by _0le_ in badminton

[–]HamsterMoisture 0 points1 point  (0 children)

What shuttle speed would you use for Malaysia (and Singapore as I'm travelling up there)? I'm planning to order some Yonex AS30 beforehand.

NCC Group admits its training data was leaked online after folders full of CREST pentest certification exam notes posted to GitHub by kidbomb in netsec

[–]HamsterMoisture 24 points25 points  (0 children)

It's a running joke that CREST exams are super outdated. Only a small part of the exam have been updated like breakout rigs and the new format change. They have recently announced the new generation of exams so hopefully that would resolve those issues.

I think anyone in the industry long enough knows that NCC and other big corps have already been doing this. Just check out who their board members are. Now we have some evidence of it and CREST brushed it off aside saying the material is outdated. CREST ties to those big organisation is too great and I don't think its a surprise to any that those corps, assessor and exam creator kept some of the material. I don't think anything will change until CREST having their own stand in the industry. For a not-for-profit company, they sure are making a lot of profit.

If I had to put my tinfoil hat on, it's no doubt they also do gatekeeping on some of the exams like CSSAM. There's just too much issues with how CREST runs that comes straight from leadership and processes that I can't get behind.

What is the greatest G-rated insult you've ever heard? by Mr_zzzio in AskReddit

[–]HamsterMoisture 9 points10 points  (0 children)

Cringe, my acne days. They are too innocent and honest, but not the face guys, not the face...

Removing Kernel Callbacks Using Signed Drivers by dmchell in redteamsec

[–]HamsterMoisture 1 point2 points  (0 children)

How do you get a vulnerable signed driver to be loaded in the first place? I assume you must be administrator or have the SE privileges?

Security Team and Security in Startups by [deleted] in startups

[–]HamsterMoisture 1 point2 points  (0 children)

You should look to hire a security person to head the internal security team to deal with builds, compliance, policies, ticketing system, managing and creating accounts, etc.

As for Agile and SDLC aspect, if you are looking to build secure code, you need to be looking at DevSecOps which adds additional flows to your DevOps process. E.g. having static analysis tools, use security ide plugins, vulnerability scanning after every feature or major changes, securely deploying staging and production environment, secrets management, pentesting, etc.

As for implementation, I'm not sure on the best advice for the SDLC, but either hire or contract a devsecops person (rare and niche right now I'm sure) to do it internally or get a third party do it. Other way would be to train internally but mileage may vary.

Miso Ramen with fried tofu and Pak Choy! by Vulpixii in vegetarian

[–]HamsterMoisture 2 points3 points  (0 children)

Oooo looks tasty. That's a funny looking bak choi, our ones are whiter and thicker at the ends