BLUE
Profile banner
JD
Jason Danner
@jpdanner.com
Analytical chemist & techie Reluctant American & proud Kiwi Chief Beer Officer @ Aerorock Director of HOPS @ Usable Balance @jpdanner from Tweeter He/him Friendliest asshole you'll ever meet
408 followers459 following485 posts
Reposted by Jason Danner
Jjjengar.bsky.social

0
JDjpdanner.com

Some takeaways & thanks @karit.nz#OWASPNZ

1
JDjpdanner.com

We should always use MFA & SSO if you can. @karit.nz#OWASPNZ

1
JDjpdanner.com

Self service password resets can also be attacked @karit.nz#OWASPNZ

1
JDjpdanner.com

Don't treat corporate enrolled devices as a second factor @karit.nz#OWASPNZ

1
JDjpdanner.com

Uh... Also we need to make sure these apply to all cloud apps. Very easy to forget admin apps. @karit.nz#OWASPNZ

1
JDjpdanner.com

What if we have a CAP that disables MFA from the office IP? Well the guest network is probably also on that IP... @karit.nz#OWASPNZ

1
JDjpdanner.com

We can change the "user agent" to bypass a targeted CAP @karit.nz#OWASPNZ

1
JDjpdanner.com

Let's create a CAP @karit.nz#OWASPNZ

1
JDjpdanner.com

Nitty gritty of CAPs @karit.nz#OWASPNZ

1
Profile banner
JD
Jason Danner
@jpdanner.com
Analytical chemist & techie Reluctant American & proud Kiwi Chief Beer Officer @ Aerorock Director of HOPS @ Usable Balance @jpdanner from Tweeter He/him Friendliest asshole you'll ever meet
408 followers459 following485 posts