darthfrosty

63 Followers
82 Following
206 Posts
25+ year technologist and Agile InfoSec leader. Purple teams for a safer Internet! I appreciate contrarians with thought-provoking points passionately argued. he/him

I'm not writing an entire blog post about how stupid a US TikTok ban would be because this is all that needs to be said:

If the Chinese government is in your threat model, don’t install TikTok on your device. Otherwise, your actual problem is surveillance capitalism.

Wait wait wait wait

Let me get this straight...

LinkedIn wants to generate crappy AI content and then invite me to fix it, for free, under some guise of flattery calling out my "expertise"

Really?

@SinclairLewis @NE_Purple_Mom I’ve been taking cues from my spouse. She’s seeing the effects on the front lines as a substitute teacher and active member of our PTA. Even she’s beginning to doubt. Some things I’ve seen aren’t necessarily a money problem, in my view. In some cases it feels like a talent problem. More money to attract better talent, perhaps, but within administration positions, rather than the teacher ranks—my honest experience is that they’re all super committed and professional. This comms issue with the “encryption event” is an example, but comms were an issue during the various George Floyd-period sit ins, walk-outs, and protests too. My spouse’s experience with HR felt similarly unprofessional too. While that could be a symptom of overload, none of that helps in recruiting good talent.

Having been in the middle of a breach response effort before, I’m confident IT is struggling to keep up with the 100x load. They should be able count on their PR people not to make that situation worse. Recent evidence leads me to question whether the talent, leadership and professionalism is there to make that true though.

As a public institution, this is where elections matter too. School board hires the superintendent. Superintendent sets the org structure and mission for it that makes our schools capable of creating an environment ready to teach and fertile for learning. MPS isn’t succeeding there. This new opportunity to hire a superintendent is the community’s opportunity to influence the Board and maybe change that.

@davep update… it totally landed! I had to explain the concept of Blockbuster, and my kid had to sing the chorus to really get it, but he thought it was hillarious!

@NE_Purple_Mom I’m an InfoSec professional, and I reached out to @ian. We are exploring an idea of doing a town hall forum/panel discussion for the community to talk through some of Ian’s good recommendations and maybe reach a different audience. I’ve got some others from my professional network possibly interested in participating too. I’m a little ambivalent about wading into this, but I think our professional community could help parents, staff, and alumnae/i regain a little sense of control.

#MPS #ransomware #Medusa #identitytheft

@SinclairLewis @NE_Purple_Mom my spouse and I have this debate actively. Behavior issues and distractions make for a poor learning environment, and the administration is inept on so many levels. This “encryption event” is just another example. We’re parents in #MPS , and my spouse is both a former and current MPS employee. We’ve presumed to try to be part of the solution to public schools degradation by sticking with them, but we too are now wondering whether we’re unwittingly trading our kids’ futures for self-indulgent thinking.
@SinclairLewis my husband, full sarcasm voice: “I’m beginning to think this district is run by a bunch of incompetent people.”
YA THINK?!
How is this supposed to help with our enrollment and teacher/staff hiring problem??????

@jeridansky

Boosting and adding more hashtags:

Birdsite thread with important information on the recent Minneapolis Public Schools data breach. It boils down to that if you've had a child at MPS or been employed by MPS since 1995, you better pay attention. And change your passwords. And set up two factor authentication. And monitor all your accounts for identity theft.

https://nitter.net/IanColdwater/status/1633586154988552193

#MNastodon #MSP #MPS #Minnesota #TwinCities #TwinCitiesMN #Minneapolis

https://sfba.social/@jeridansky/109996999882566128

Ian Coldwater 📦💥 (@IanColdwater)

The Minneapolis Public Schools data breach is really bad. Much worse than we've been told. This affects current & former staff, students, & parents. The district hasn't been forthcoming, so here's a 🧵 w/ facts about what's going on & concrete steps to take to protect ourselves.

Nitter

@jbhall56 my first question was, would this make someone more susceptible to telephony-based MFA spoofing/spamming attacks?

I kind of think we need to stop amplifying the propaganda that it’s okay as long as no credit card data was stolen. I want to know if EFT routing/account numbers or debit card numbers were stolen. That has immediate, personal bank account emptying implications that impact peoples’ ability to conduct their lives. At this point credit card replacement is a cost of doing business for multi-billion dollar lenders. When they’ve had opportunities to improve security of payments (requiring PINs on EMV, for example), they opted for more fluidity in user experience instead of better security.

/end-rant

@davep although I’ve just realized they’re too young to know what a video store is!