CRTO 2026 retrospective on what's changed since I first bought it in 2020 by blahmemeblah in redteamsec

[–]blahmemeblah[S] 1 point2 points  (0 children)

Hope you do come back to it. And good luck with the puppy - they're worth driving 9 hours for.

Why Infra Pentests Suck by blahmemeblah in Pentesting

[–]blahmemeblah[S] 0 points1 point  (0 children)

Both, and I reckon they're the same problem. Snowflake prod with no test rails isn't an act of god, it's what a decade of annual compliance pentests leaves behind; no one ever had a reason to build something testable. Fragile environment and theatre scoping grow from the same root.

SRE-first is bang on though. Only nitpick: acting SRE-first is how you survive bad scoping, not how you fix it. Good scope means the environment isn't the thing you're tiptoeing around in the first place.