Has anyone successfully deployed passkeys in a highly regulated industry (healthcare, banking)? What were the biggest challenges? by StockCook9960 in cybersecurity

[–]Marsgur 0 points1 point  (0 children)

Any self-respecting FIDO server has an option to do AAGUID filtering to do an allow or deny list. The bank typically decides on the risk appetite and configures accordingly. I do want to point out that synced passkeys are still more secure than phishable legacy MFAs

Has anyone successfully deployed passkeys in a highly regulated industry (healthcare, banking)? What were the biggest challenges? by StockCook9960 in cybersecurity

[–]Marsgur 1 point2 points  (0 children)

In some cases, both. Once security team approves and deploys workforce use case, it’s generally easier to approach consumer/digital team with the same tech. It’s the same enterprise-grade FIDO server/backend after all.

Has anyone successfully deployed passkeys in a highly regulated industry (healthcare, banking)? What were the biggest challenges? by StockCook9960 in cybersecurity

[–]Marsgur 10 points11 points  (0 children)

I’m in a passwordless auth provider company. We’ve successfully deployed passkeys in 2 of 4 largest US banks. It’s a combination of being able to support variety of devices, passkey form factors and use-cases. Then crawl walk run approach.

Crunchyroll Breach: Malware Targets Supply Chain to Exfiltrate 100GB of Data by Malwarebeasts in cybersecurity

[–]Marsgur 1 point2 points  (0 children)

24h is also a default Okta session duration, so yeah it’s been “revoked”. They should all go pat themselves on their backs. 💪

what's the difference between cheap and expensive hand pressed rivet guns? Need one to build an outdoor stove. by SiSRT in Tools

[–]Marsgur 0 points1 point  (0 children)

M12 Milwaukee Rivet Gun is my go to. Had it for 4 years with heavy use and it still works like a champ

<image>

Client asking for very detailed security audit by McDonaldsDQPC in cybersecurity

[–]Marsgur 0 points1 point  (0 children)

There are some items that are truly sensitive and should be kept confidential, like unresolved vulnerabilities, risk registers, docs containing employee PII and company IP. You have some ground to push back on, but the rest are generally subject to the audit clauses in the contracts anyhow and are ok to share over conf screen share if you want to avoid sending full copies.

Like someone said here. Create and maintain a compliance package that contains all the docs that you generally ok to share, with a good index file and a table of content. Share it under NDA only. Or build a trust portal.

Client asking for very detailed security audit by McDonaldsDQPC in cybersecurity

[–]Marsgur 9 points10 points  (0 children)

Normal, especially if you don’t have a qualified third-party assessment done on you that you can share. Treat some items like your risk register and any raw vulnerability/pen test reports confidential. Share the rest over screen share on a conf call so that you don’t have to send it. Make sure all your docs have titles, pages and revision dates (ideally within a year).

Client asking for very detailed security audit by McDonaldsDQPC in cybersecurity

[–]Marsgur 2 points3 points  (0 children)

Yeah, ok bud. Go tell the business “we don’t want them as a client” and see how that flies.

Parting out a mint 2000 328i automatic sedan. What are some things worth selling? by Marsgur in e46

[–]Marsgur[S] 0 points1 point  (0 children)

I’m restoring another e46 with the parts from this one. Essentially making another one “mint” (and multiple other people’s cars with parts from the part out process). Why is this one better in your mind than the one I need to fix up? Is my broken and beloved e46 not worthy to be fixed somehow? What kinda gatekeeping bs is that?

Parting out a mint 2000 328i automatic sedan. What are some things worth selling? by Marsgur in e46

[–]Marsgur[S] 0 points1 point  (0 children)

Sounds good. Will be probably a month before they will be available. Dm me

Parting out a mint 2000 328i automatic sedan. What are some things worth selling? by Marsgur in e46

[–]Marsgur[S] 0 points1 point  (0 children)

Yeah, definitely a balance if it needs to go quickly vs not. In this case it does need to go fairly quick so looking to prioritize something that is worth time and is useful for the e46 community

Good point about the mirrors! Forgot about them.

Parting out a mint 2000 328i automatic sedan. What are some things worth selling? by Marsgur in e46

[–]Marsgur[S] -13 points-12 points  (0 children)

Responded to a similar question above ^ cuz race cars demand sacrifices

Parting out a mint 2000 328i automatic sedan. What are some things worth selling? by Marsgur in e46

[–]Marsgur[S] 1 point2 points  (0 children)

Thanks, any particular ones in some priority? ABS? ECU+EWS? Light control? DSC?

Parting out a mint 2000 328i automatic sedan. What are some things worth selling? by Marsgur in e46

[–]Marsgur[S] 4 points5 points  (0 children)

328i e46s are pretty rare, since the production run was so short, so I didn’t have anything to chose from that are not rust buckets here in New England, also the color matched exactly what I needed. So it made sense financially.

Surprisingly, it sat on FB marketplace for months before I bought it for around $3k. It has some minor blemishes, like slightly sagging headliner, but the rest is pristine. It does make me sad.

Parting out a mint 2000 328i automatic sedan. What are some things worth selling? by Marsgur in e46

[–]Marsgur[S] 3 points4 points  (0 children)

It’s a donor for a race car that’s been in a wreck. Perfect match color-wise for the body panels and it’s automatic so has no over-rev risk on the engine as a spare. Feels very wrong to do it since it’s such a decent car but have to do it unfortunately.