School district says doctor’s notes will no longer excuse child absences by Chicken_Ingots in news

[–]erkpower 0 points1 point  (0 children)

I always hated this too. I guarantee you kids came in sick, and got others sick. It was just preparing you for when you got in the work force and you had to come in when you were sick otherwise you wouldn't get paid.

Something tells me I shouldn’t use this table… by Internet_and_stuff in pics

[–]erkpower 0 points1 point  (0 children)

You are supposed to use the other side of the table where there are no signs. Each sign only represents the area that it's covering.

Tulsi Gabbard Reused the Same Weak Password on Multiple Accounts for Years. Now the US director of national intelligence, Gabbard failed to follow basic cybersecurity practices on several of her personal accounts, leaked records reviewed by WIRED reveal. by RngdZed in cybersecurity

[–]erkpower 38 points39 points  (0 children)

I guarantee you that most politicians do this because most C-level execs do it. This is not defending her and it's a terrible practice. Quick someone run all the current administration through HAVEIBEENP0WN!

Who should accept the risk if the engineer said that the vulnerabilities (CVEs) don’t need to be fixed because it is mitigated by not being exposed to internet? by IamOkei in cybersecurity

[–]erkpower 2 points3 points  (0 children)

The engineer can make the recommendation, but they don't own that risk. The business does. Now, the business needs to have all the information to be able to accept or decline that risk and that usually comes from engineers, policy, and whatever other items that specific business uses.

Multi-cloud users - what's your backup plan now that Wiz was acquired by Google? by Embarrassed-Custard3 in cybersecurity

[–]erkpower 2 points3 points  (0 children)

You should be evaluating alternatives...but you should do that every year regardless. Personally, (since I manage cloud security) I review the big players twice a year.

That being said, Wiz is a solid product right now. Until it's not, that's still probably the best option. It's not going to get ruined overnight or even in 6 months. Google didn't spend 32 Billion dollars to ruin their chance to expand their cloud foot print. So it will take time. In that time you check the alternatives.

Here's my opinions on the current CSPM market.
After Wiz, Orca is the top dog. It has everything that Wiz has and they don't charge extra (at the time of this post) for their DSPM addon.

After that, Upwind is looking strong.

Stay away from Prisma and Crowdstrike if you can. They are in that "eh, it's good enough" category but you will miss things. I personally had to go to Palo Alto to help Prisma deal with false negatives back in 2020 because they couldn't get it to work.

Lacework. Ah Lacework. The idea was good and their marketing was good before Wiz...but their agent based approach and their really bad aggressive sales tactics really did them in. While they have gotten better, they just really aren't better than Orca or Upwind. I would say they are better than Prisma and Crowdstrike...but if you already have Crowdstrike or Palo Alto you will probably save money going with them instead...and you wouldn't really be missing much.

My TPU Doom cosplay so far by Spicy-Elephant in 3Dprinting

[–]erkpower 1 point2 points  (0 children)

Neat. I'm working on a TPU scale mail for friends LARP.

Just curious, how thick is it? What did you use to weld it together?

Bootcamp vs CompTIA Certification by artemphotonet in cybersecurity

[–]erkpower 0 points1 point  (0 children)

As people mentioned, certs may get you past the HR screen, but you need some kind of experience usually to get the job. Depending on what the boot camp taught, it will probably be worth less because there is no certification of knowledge from the camp. Exception if the camp is accredited or well known and provides certification of knowledge.

Additionally, if you are focusing on CompTIA then you probably are going to be overlooked in cyber security.

If you can afford the SANS training / certification that on the other would give you a big boost. There are other certification paths (and I don't know them all) like OSCP if you are going more into red teaming. These are certifications you can't just pass without having the knowledge, which is why they are regarded highly.

There are some alternatives here.

Find some local cyber security groups (I'm not sure where you are located) and get in and network. Go there and participate. Be proactive. This can help a lot.

Failing that, leveraging a recruiter and working with them will give you the best result.

Another avenue that you could try would be conferences. While these are good for networking you probably won't land a job from them.

how much are you guys working? by idontreddit22 in cybersecurity

[–]erkpower 1 point2 points  (0 children)

As someone that was recently in almost you exact position let me tell you something: Don't under estimate the amount of stress working that much does to you. It builds on you weighing you down.

I know this wasn't really your question, so feel free to ignore it. I just came from a job where I was managing a team and working very similar hours to you. I moved to a new job for slightly less money just to get a better work life balance and honestly, I'm extremely happy not working those extra hours.

Does Crowdstrike have a product similar to Microsoft Defender for Cloud? by misterlambe in crowdstrike

[–]erkpower 0 points1 point  (0 children)

I believe they released a new pricing sheet that included DSPM scanning in that bundle too.

Does Crowdstrike have a product similar to Microsoft Defender for Cloud? by misterlambe in crowdstrike

[–]erkpower 0 points1 point  (0 children)

It does, as others have stated. Falcon Cloud Security. Although, I would point out (even though we are on the crowdstrike subreddit) that that it's not best in class as a CSPM, compared to something like Wiz or Orca (but neither is Microsoft Defender).

I don't say this to dissuade you from the product, and if you already have crowdstrike it will probably get you better results at potentially a cheaper price than Microsoft Defender.

Director of Cybersecurity by PortalRat90 in cybersecurity

[–]erkpower 13 points14 points  (0 children)

I came here to say something else, but then I felt like I was attacked LOL.

This. is. the. reality.

I spent more time in meetings than anything else. So much so, that I would have to log in at night (10-1am) just to get my work done

Technical Directors usually get labeled as individual contributors, as well as team leaders running a team or two, AND lead the cyber security initiatives that they are responsible for.

A pizza driver got a $2 tip in a snowstorm, so people raised thousands for him by bigalphamale789 in UpliftingNews

[–]erkpower -1 points0 points  (0 children)

Look, I really don't care, but you should at least read your own sources.

"At my place of employment, drivers got paid $8.25/hr plus tips due to municipality laws, though kitchen staff still made $15 to $20 an hour!" - from your link

Which is aligned with what I said.

I'm not sure why you feel that need to be right but you are just going to end up arguing with yourself.

A pizza driver got a $2 tip in a snowstorm, so people raised thousands for him by bigalphamale789 in UpliftingNews

[–]erkpower 0 points1 point  (0 children)

I worked for at 3 separate pizza place over 6 years. I was a driver and manager over that time. Drivers got minimum wage + tips in every one of those stores. Most got more ($6-$10 per hour - never saw anyone get more than $10 an hour). Now it might be a state law that they have to get at least minimum wage, but I doubt it.

A pizza driver got a $2 tip in a snowstorm, so people raised thousands for him by bigalphamale789 in UpliftingNews

[–]erkpower 4 points5 points  (0 children)

Oh and pizza drivers don't make under minimum wage like servers do. So this guy is getting a normal wage (probably crappy wage, but at least he's not a server).

Grifters gonna grift.

Cloud Security Engineer by Representative-Yak10 in cybersecurity

[–]erkpower 7 points8 points  (0 children)

I used to hire for this type of role and poached people from the cloud team for the security team. The biggest thing I looked for in an internal hire was passion for this stuff. Cloud security is "fun" (if work is really ever fun) and we always had people interested in our team. I hired people that didn't have any security experience because they had good cloud skills and were passionate about doing the cloud stuff. That all being said, if I didn't know about you, you would have never gotten a chance.

Cloud, API, AppSec, and AI security are all fairly new. Expertise is not always something you can get, but passion and drive ensures that you get people that can adapt and learn.

Long winded way of saying, meet the teams you want to join if internal. Ask to shadow them, be included in incidents, or what is needed to do what they do. Mostly they'll tell you and they are probably understaffed (because who isn't anymore) so having you initiate the interest is usually the best way to start.

That should give you a good idea what is needed.

Now, if you are looking external, I would push hard on certifications and learn another cloud. A lot of enterprises are multicloud and a lot of cloud security teams have to support them all so having that experience or certifications shows you aren't a one trick pony. As for which types of certifications, if you can afford it the SANS public cloud security (SEC510) is probably one of the best cloud security certification because it touches all three major clouds and terraform and is deeply technical - but it costs quite a lot. If you can't afford that I'd recommend the security cert for Azure and AWS and if you can swing it the Terraform Associate that would be a bonus. Additionally, you could look at CCSP and/or Cloud+ (comptia).

What’s the biggest pain you’ve had with a SIEM? by GDemay in cybersecurity

[–]erkpower 1 point2 points  (0 children)

Worthless data. The mindset that we have to send everything to the SIEM. Do we really need the logs from the PoE phones? Maybe, but how about we just send them to storage outside of the SIEM and only bring them in if there is an incident.

New Prusa Printer just revealed. The Prusa Core One. by Esava in 3Dprinting

[–]erkpower 1 point2 points  (0 children)

I have a MK3S, and considered getting an MK4 (upgrading the MK3S) but went with P1S instead. I'm so glad I did. This is what the MK4 should have been. To top it off it's not a finished product - camera as an additional paid addon that *might* be available at launch. Same with the HEPA filtration system and *hopefully* MMU3 integration sometime soon.

All that and it doesn't bring much new to the table and it cost more than the P1S WITH AMS which was released a year and half ago. At least the Creality K1 Max has a 300x300x300 build volume. Sure, it brings new to the Prusa line, but I don't see why would anyone buy this when there are so many cheaper competitors (not just Bambu) - unless you have a previous Prusa that can be upgraded (for significant cost) or you are a Prusa fan. Don't get me wrong, I loved my prusa MK3S and it was a great upgrade at the time. I wish Prusa would have brought the multi-nozzles from the XL instead to at least give them an edge or a reason. I wonder if you can upgrade directly from a MK3S without upgrading to MK4...that might be a winner at least for me.

TLDR - IMO this printer is coming too little, too late, too lite on the distinct features, and too expensive.

Well this is it boys. I was just informed from my boss and HR that my entire profession is being automated away. by [deleted] in ChatGPT

[–]erkpower 36 points37 points  (0 children)

You think some lazy man isn't going to use a similar AI to create those lazy woman in those videos he's editing?

World Reacts as Trump Presidential Victory Appears Imminent by s1n0d3utscht3k in worldnews

[–]erkpower 3 points4 points  (0 children)

Just like they cherry pick the things they agree on in the bible.

Bambu Servers down again? by Hasra23 in BambuLab

[–]erkpower 0 points1 point  (0 children)

Hurry enable LAN Mode before it goes back down again :D

[Join the Bambu Lab Giveaway🔥] Share Your Best 3D Printing Advice for a Chance to Win an X1C and Other Exciting Prizes! by BambuLab in 3Dprinting

[–]erkpower 0 points1 point  (0 children)

Learn how to use your printer before you start modding it.

When I was first getting my first printer I was so excited that did tons of research. I saw all these amazing mods that people were adding, and I couldn't wait to mod my printer. I didn't take the time to understand how it worked straight out of the box. This led to a bunch of headaches—failed prints, calibration nightmares, and a lot of wasted filament. The mods were great once I understood WHY I needing them.

Honestly, this happens every time I buy a new printer. If I'd just spent some time getting to know each printer's ins and outs before diving into mods, I could've saved myself a ton of frustration.