Kits (2)
Discussions

At yesterday’s chat night we this article on threat modeling and tried sketching our own threat model. https://arstechnica.com/information-technology/2017/07/how-i-learned-to-stop-worrying-mostly-and-love-my-threat-model/ We started with a handful of threats that we wanted to be well prepared for: hackers, a disgruntled ex, mice… Then for each we got specific about how each of them could hurt us. Were we concerned about survival, property, health… preserving the cotton candy in the walls… For each combination of threat and asset, we talked about options for protecting that asset from that threat. And occasionally decided that some of those risks could just be accepted without protection. = Threats (source of problems) = hackersdisgruntled ex – newbie hackerhurricanewildfirehousefiremousefloodwater heater damage = Assets (what could actually go wrong) = moneydebit cardcredit cardidentity – name, ssn, address – use to file for unemploymentaccess to food/waterpossessions in apartment: carpet, furniture, suppliesaccess to shelteraccess to toiletimmune healthlifecotton candy in walls = Protection (how to mitigate threats to assets) = Say no when purse company asks if ordering purse for someone in Texas.Be careful who you piss off.Up-to-date contact infoLifeLock– gave alert of info used for other state unemployment– alerts on any usage of information– invasive! credit card company blocked cardno upload to lifelock.– but locked out of account– and they keep warning via email anyway– alternative: credit karma shows what loans you have openHomeTitleLock – like LifeLock but for homechange passwords quarterlyemail account reminds password change every 3 months2fa on all financial accounts – any accountcredit card notifies via text on each usagestash of pemmicanfire extinguisherplan to bug out and related equipmentred cross contact infocar bug out kitbug out kit buried in front yardBB gunsanitize house with BAK benzyle chloratesandbagspumpdon’t play in flood waterboatflood evac plan to higher elevationflood panwater sensor in water heater flood panmaintenance/plumber contact infoshop vacfans to dehumidify


Load more...

At yesterday’s chat night we this article on threat modeling and tried sketching our own threat model. https://arstechnica.com/information-technology/2017/07/how-i-learned-to-stop-worrying-mostly-and-love-my-threat-model/ We started with a handful of threats that we wanted to be well prepared for: hackers, a disgruntled ex, mice… Then for each we got specific about how each of them could hurt us. Were we concerned about survival, property, health… preserving the cotton candy in the walls… For each combination of threat and asset, we talked about options for protecting that asset from that threat. And occasionally decided that some of those risks could just be accepted without protection. = Threats (source of problems) = hackersdisgruntled ex – newbie hackerhurricanewildfirehousefiremousefloodwater heater damage = Assets (what could actually go wrong) = moneydebit cardcredit cardidentity – name, ssn, address – use to file for unemploymentaccess to food/waterpossessions in apartment: carpet, furniture, suppliesaccess to shelteraccess to toiletimmune healthlifecotton candy in walls = Protection (how to mitigate threats to assets) = Say no when purse company asks if ordering purse for someone in Texas.Be careful who you piss off.Up-to-date contact infoLifeLock– gave alert of info used for other state unemployment– alerts on any usage of information– invasive! credit card company blocked cardno upload to lifelock.– but locked out of account– and they keep warning via email anyway– alternative: credit karma shows what loans you have openHomeTitleLock – like LifeLock but for homechange passwords quarterlyemail account reminds password change every 3 months2fa on all financial accounts – any accountcredit card notifies via text on each usagestash of pemmicanfire extinguisherplan to bug out and related equipmentred cross contact infocar bug out kitbug out kit buried in front yardBB gunsanitize house with BAK benzyle chloratesandbagspumpdon’t play in flood waterboatflood evac plan to higher elevationflood panwater sensor in water heater flood panmaintenance/plumber contact infoshop vacfans to dehumidify


Load more...