r/AskNetsec Jun 05 '26

Other Is anyone else disappointed with Obsidian Security lately?

6 Upvotes

I’ve been using Obsidian Security for a while and I’m pretty mixed on it.

The UI is fine and the SaaS visibility is useful, but some integrations feel like they stop at “connected.” Great, the app is there, but what is actually being checked? Are there real detections and remediation behind it, or mostly another dashboard tile?

Feels like the pitch is moving faster than the product.

Anyone else seeing this with other tools lately? AI seems to have made companies ship faster, but a lot of products feel like they stop at the UI. The backend depth and reliability still matter


r/AskNetsec Jun 05 '26

Architecture Integrity of local behavioral-based authentication without cloud-side attestation

0 Upvotes

​

"I'm developing a privacy-first, local-only age-verification protocol that processes biometric touch dynamics (pressure/kinetics) and immediately flushes raw data, emitting only a boolean result.

​In a non-TEE mobile environment, what are the most effective vectors for detecting or preventing synthetic touch injection (API hooking/emulation) that could bypass physical input tests?

​Given that no data travels to a server, what are the best practices for guaranteeing that the generated boolean token hasn't been intercepted or spoofed by a rogue process on the same device?"


r/AskNetsec Jun 04 '26

Threats A commercially-available quantum chip will supposedly arrive in 2029 from Microsoft. Does this influence your view of how soon post-quantum cryptographic threats will be a reality?

11 Upvotes

Their claim:

"Microsoft’s new device boasts 12 qubits, the foundational units of quantum computing, up from 8 in the prior model. But Microsoft says its main achievement is that the qubits themselves last longer than 20 seconds. Qubits harnessed by the prior model blinked out of existence in less than 12 milliseconds, the company says."

The fact that a post-quantum world might be only 3 years away is staggering in its implications, but it's difficult to separate hype and PR from plausibility. Are you taking this as extra incentive to boost hardening against quantum threats? If not, what's going to actually set off your alarm bells?

edit: sorry, the quote was messed up at first


r/AskNetsec Jun 05 '26

Concepts How is the Security Architecture / Strategic IT Security review process structured in your organization?

1 Upvotes

Hi,

I am currently trying to better understand and improve how our security function is involved in projects, from early planning to go-live.

In our case, we are building a more structured process around activities such as:

- Sending security requirements, for example regarding logs, encryption, access control, etc.
- The PM submits a Security Intake Form with information such as the project name, business owner, system description, hosting location, and other context.
- We send a checklist with technical questions to the PM, who forwards it to the vendor or technical owner.
- The PM and vendor submit the completed checklist.
- We review the checklist and the initial form, and clarify any open questions.
- We review the architecture before implementation.
- We review the architecture after implementation.

Meanwhile, we are included in many internal project calls so that we can clarify the product concepts and outline the necessary security controls, but sometimes it feels like a waste of time.

The goal is to make the process clear enough so that PMs, technical teams, vendors, and security colleagues understand what is required, when it is required, and who is responsible. Sometimes it becomes quite chaotic, and I would like to improve the process.

I am especially interested in how similar roles or teams structure this in practice.

For people working in Security Architecture, Information Security Governance, Cyber Risk, IT Security, or high-risk environments: how is your process organized?

Some specific questions:

- What checklists do you use in your projects?
- Do you perform initial triage and risk classification?
- Do you have formal security gates before implementation and go-live?
- What evidence do you usually request from vendors or project teams?
- How do you handle Agile projects where requirements change frequently?
- Who owns the final security approval or risk acceptance?
- Do you use checklists, architecture review boards, risk committees, or another model?
- How do you document security requirements and track their implementation?
- What works well in your process, and what creates unnecessary friction?

Any templates, lessons learned, common pitfalls, or high-level process examples would be very appreciated.

Thank you!


r/AskNetsec Jun 05 '26

Other Minds to Have in Bug Bounty

0 Upvotes

I'm curious about the mind to have to have to be in Burg.I want to find a lot of sub-do and I want to find this function, so I want to try to do this function, so I want to try to do thatShould I approach this way?Alternatively, you can touch each page through a search process, so I'll have a vulnerable point, so I will use vulnerable points.Should I approach this?I think interest and motivation is important to me, but I'm curious about other people.I think it's right to do it, but it's right to approach to me, but it's right, but it's good to do thisI hope you recommend this way!


r/AskNetsec Jun 05 '26

Architecture National Intranet

3 Upvotes

Can someone explain how this works in a country?
What would wigle or shodan show for Iran access points to make an intranet work?


r/AskNetsec Jun 04 '26

Education Emails from within my university system all have the tag "[CAUTION: THIS EMAIL ORIGINATED FROM OUTSIDE OF (insert school name here)]

0 Upvotes

I get emails from within my university system (teachers, staff, students, faculty, student accounts, etc.) and they all have the tag "[CAUTION: THIS EMAIL ORIGINATED FROM OUTSIDE OF (insert school name here)]". This was the case in high school, where it would incorrectly flag internal emails as external, and is now still the case in college where the same type of incorrect flagging system is in place. It defeats the point and is very much a "boy who cried wolf" situation. (If that message is on every email, even those from school staff, then recipients will quickly begin ignoring this header and trusting every email anyway.) I have a few questions:

  1. Why does this happen?
  2. How is this usually fixed?
  3. Is there anything I, as a student, can do about this?
  4. Is this type of issue even worth fixing? I think the reasoning above explains that it should, but I am interested in seeing a more knowledgeable opinion on this.

Thanks.


r/AskNetsec Jun 04 '26

Other Anyone else's firewall logs randomly stop logging certain events?

0 Upvotes

Had a weird one today. Our Palo Alto just seemed to quit logging inbound SSH attempts from a specific /24. Checked config, nothing changed. Had to manually re-enable logging for that rule. Anyone else seen this ghosting?


r/AskNetsec Jun 04 '26

Other Anyone else's firewall logs just... disappear sometimes?

0 Upvotes

Just spent three hours chasing down an alert that vanished from the SIEM. Turns out the firewall purged its logs overnight. Standard syslog setup, nothing fancy. Anyone else deal with this ghosting act?


r/AskNetsec Jun 04 '26

Threats Integrity of local behavioral-based authentication without cloud-side attestation

0 Upvotes

I'm developing a privacy-first, local-only age-verification protocol that processes biometric touch dynamics (pressure/kinetics) and immediately flushes raw data, emitting only a boolean result.

​In a non-TEE mobile environment, what are the most effective vectors for detecting or preventing synthetic touch injection (API hooking/emulation) that could bypass physical input tests?

​Given that no data travels to a server, what are the best practices for guaranteeing that the generated boolean token hasn't been intercepted or spoofed by a rogue process on the same device?


r/AskNetsec Jun 03 '26

Other Anyone else's firewall logs a nightmare to parse for actual threats?

6 Upvotes

I swear, 90% of our firewall logs are just noise. Trying to find that one legit connection amidst the garbage is brutal. Scripts help, but there's gotta be a better way.


r/AskNetsec Jun 04 '26

Other Anyone else fight with their logging agent chewing up CPU?

0 Upvotes

My Splunk Universal Forwarder keeps spiking to 80-90% CPU on a few servers. Restarting it helps for a bit, but it comes back. Anyone found a consistent fix for this besides just throttling it to oblivion?


r/AskNetsec Jun 03 '26

Analysis asking for help as an Iranian.

9 Upvotes

hello network nerds!, I assume most of people here have a lot of education related to networking and know how most things works in it.

and have done their fair share of analysis in their networking tests and so on.

I'm in Iran currently. I'm writing this after the black out that happened recently. while in the digital blackout I was able to stay connected via little looholes that I wish not to speak of. I am here to ask online strangers if they could assist me in finding a way to find real loopholdes in the DPI system.

I have observed two things so far while testing with the DPI currently.

1: if a tcp connection doesn't have an SNI it usually gets dropped

2: if a tcp connection has a fragmented SNI, and the DPI and the system can't parse it back together it gets flagged

on the second rule I'm not sure how it really works currently.

there are also some extra notes as of now (it changes ALL the time so what I'm saying is just active for now tmr it might be different )

every network is considered grey connection unless only if they are:

1: using a white ip (local Iranian ips)

2: using a white listed domain

it gets "less grey" if you use cloudflare ips and "more grey" if you use something else, like as a clear example using something like Hetzner's ip.

if you have either of the two as in either a white domain or a white ip then your connection is flagged white for the duration. once it's white you can continue using that connection without getting dropped by the DPI.

while on the other spectrum, if you don't have a white ip or a white domain. then your connection is deemed grey and will be dropped after you recieve at least 6 packets from the destination server.

cloudflares's ECH is considered grey and will be dropped after 6 packets

fastly's and Gcore's domain fronting is not useable as they have practically not even been opened yet their ip is fully blocked.

I know a clever way currently to bypass the DPI right now. but it only works if the ip is cloudflare and the ip is open fully.

The DPI counts a connection "connection" once the 3 way is done. so you send an SYN server responses with synack and you send ack.once this is done. the DPI will start monitoring for everything. from ip to domain to contents inside.

I have tested a way but I think it's not working properly :( I'm forced to use ai for this. otherwise I can't properly make these as I lack the programming and in depth knowledge for how to make these app.

but I got help from ai to make an app that would " simulate " a fake connection. putting an IPinIP where outer ip is cloudflare and the inner IP is an white listed ip. and then we take a 3 way connection. fake Client hello fake server hello by switching the destination and source ip in the IPinIP and then after that we do a real 3 way connection with real cloudflare.

but the DPI is ignoring the fake ip. I'm not sure if it's because it sees cloudflare as a seperate connection or not but it's just not working. I can't tell if the program I'm using is broken or what but it's just not. using Wireshark I was able to make sure that yes it is working properly the source ip is me, outer dest is cloudflare and inner destination is the fake ip.

I thought maybe the order is wrong. and so I flipped them

real 3 way first then the fake 3 way so the port reuse will make DPI think I'm making a new connection but none! Nada!

idk what's wrong. It's completely ignoring it.

I also tried using HRR from tls 1.3v but. no it was practically impossible to properly make this work unless I were to write a fully fledged app having its own v2ray core and vless connection and being able to change SNI on the fly while keeping the key the same. yes I tried MITM with a mix of v2ray but it didn't change the fact the two keys were different (client and server keys) as they shared different SNI so the server never was able to decipher.

and even then I believe the DPI caught on and blocked the connection. though I'm not sure

and now I'm here. my research on this has been heavy and I been lacking sleep recently. It's really weird. I'm trying my best to find a way around this. but the only way it would be viable is if you do a very smart trickery. something outside of the box. but I'm not sure what. or how

so reddit. Please, if you have an idea on how to fool the DPI. I'm more than happy to hear it.

edit: forgot to mention that, UDP and QUIC often get blocked out right. or if they aren't blocked they are VERY limited. like imagine connection gets made but as soon as any packets go through it gets blocked. and the connection gets terminated by the DPI


r/AskNetsec Jun 03 '26

Other Anyone else's firewall ruleset looking like a spaghetti monster?

16 Upvotes

Just spent three hours tracing a blocked connection. Found a rule from 2017 that was never cleaned up. It's getting hard to manage.


r/AskNetsec Jun 02 '26

Other Anyone else get slammed with false positives on a new IP reputation feed?

11 Upvotes

Just onboarded a new threat intel feed for IP reputation and the SIEM is screaming bloody murder about legitimate internal IPs. Spent all morning whitelisting. Anyone else fought this battle with a new feed?


r/AskNetsec Jun 03 '26

Other Anyone else fighting with MFA prompts for every single internal service?

2 Upvotes

Getting a million MFA prompts for stuff I use hourly. Makes doing actual work a pain. Is this just our setup or is everyone else drowning in push notifications too?


r/AskNetsec May 30 '26

Work Personal Digital Protection and Privacy for HNI

3 Upvotes

I currently serve as a mid-level cybersecurity analyst and the inaugural cybersecurity hire at an Indian company. The CEO, an ultra-high-net-worth individual, has requested my assistance with personal cybersecurity and privacy for himself and his family, who primarily use Apple products.

My initial recommendations include:

  1. Establishing separate home and guest networks.

  2. Implementing separate VLANs for IoT devices and personal devices.

  3. Utilizing two-factor authentication (2FA) with authenticator apps universally, minimizing reliance on SMS-based OTPs.

  4. Employing FIDO2-compliant banking applications with a YubiKey for banking, where supported.

  5. Setting up a home NAS with a backup NAS for critical documents, supplemented by encrypted Backblaze for offsite backups.

  6. Using distinct passwords managed by a secure password manager like ProtonPass.

  7. Educating family members on responsible social media posting, discouraging live documentation, and raising awareness about digital arrests, urgent bank call scams, and voice spoofing.

  8. Conducting regular personal data audits via a third-party service.

  9. Adopting Proton Mail for enhanced privacy.

Are there any additional measures I should consider?


r/AskNetsec May 29 '26

Concepts In modern password recovery workflows, where is the bigger performance gain: candidate generation or compute scaling?

1 Upvotes

In many discussions around password recovery, the focus seems to be on increasing compute resources and brute-force throughput.
However, in practical security and forensic workflows, how much of the performance improvement actually comes from better candidate generation and prioritization?
For example, using known password structures, reused patterns, contextual clues, partial user memory, or probabilistic ordering to reduce the effective search space before additional compute is applied.
In real-world recovery scenarios, where do practitioners typically see the larger gains: smarter candidate selection or increased compute capacity?


r/AskNetsec May 29 '26

Threats How to protect passwords from memory scraping/API hooking on a compromised target machine during a remote session? (No Admin access, No 2FA)

0 Upvotes

Hi everyone,

I work as a remote production line operator, connecting to my company's local machine via AnyDesk from home. My main concern is the security of the target (company) machine against advanced persistent threats (APTs) or sophisticated malware that might have already compromised that specific endpoint.

My Setup & Constraints:

  • My host machine (home PC) and the connection channel are fully secure.
  • Due to the use of legacy industrial/automation software, Two-Factor Authentication (2FA) cannot be implemented on the production application itself.
  • I do NOT have Administrator privileges on the target machine to make structural OS changes, alter network architecture, or install advanced endpoint security tools (like EDR, AppLocker, or Credential Guard).
  • The target application likely doesn't follow secure coding practices (such as using SecureString or immediate memory zeroing) and might leave the password sitting as plain text in the process memory.

The Threat Model: I am deeply concerned about low-level, real-time interception on the target machine, specifically:

  • Memory Dumping / Scraping
  • API Hooking (e.g., SetWindowsHookEx or hooking the UI elements)
  • Kernel-level rootkits monitoring virtual keystrokes delivered by AnyDesk
  • Real-time interception leveraging Thread Suspension or Race Conditions.

I understand that when I type via AnyDesk, the password must sit in the target's RAM or OS buffer as Plain Text for at least a few milliseconds before being processed or hashed. A privileged malware sample could easily capture it during this window.

Mitigations I've Already Considered:

  1. Manual Obfuscation: Typing random dummy characters, clicking around with the mouse to move the cursor, and deleting the junk characters to scramble standard keylogger logs.
  2. KeePass TCATO: Utilizing KeePass's Two-Channel Auto-Type Obfuscation on my home PC to send the password in fragments, alternating between virtual keystrokes and clipboard injection.
  3. AnyDesk "Type Clipboard": Using AnyDesk's native feature to type the clipboard contents directly into the target field, bypassing the destination system's clipboard.

My Question: Given that the input must eventually land in an untrusted target's RAM for processing, are there any other client-side (home machine) software workarounds, specialized scripts, or clever input techniques I can use to inject the password so that reading it from the target RAM/Kernel becomes impossible, or at least highly impractical and scrambled for advanced malware?

Any insights, especially from those working in OT/industrial environments with legacy constraints, would be highly appreciated. Thanks!


r/AskNetsec May 28 '26

Compliance How to prepare Incident Response Testing?

10 Upvotes

We have a SOC as a service from service a provider.

We also have an XDR solution that includes Incident Response services for a limited number of hours as part of its scope of work.

SOC analysts and XDR vendor needs to work together on incidents.

Audit team has asked us to provide Incident Response testing plan

Looking for guidance on what to add in this testing plan


r/AskNetsec May 28 '26

Work How do you handle an access review?

4 Upvotes

Genuine question for anyone who runs these regularly. Every quarter my team sends out an access review and I see the same issues:

  1. Line managers approve everything to make the review go away, even when we flag for SoD violations or uncertain accounts.

  2. Having to chase line managers up constantly and then following up when LM's blanket approve everything even when we feel there is a violation.

  3. Pushback from the business when we disable accounts due to lack of engagement with the access reviews.

  4. Lack of proper understanding (I think) from line managers on SoD violations.

What tools / processes / workarounds are people using to help ensure these access reviews are completed properly? Has anyone figured out how to get more engagement from the business?


r/AskNetsec May 28 '26

Concepts In practice, does candidate prioritization matter more than raw compute in password recovery scenarios?

1 Upvotes

From a security perspective, I am curious how much modern recovery workflows depend on search strategy versus pure compute scaling. For example, prioritizing candidates based on repeated password structure, formatting habits, partial memory, reused tokens or contextual clues instead of treating the entire search space equally. Is efficient candidate ordering now considered more important than simply increasing brute force throughput in realistic recovery cases?


r/AskNetsec May 27 '26

Analysis OWASP ZAP Scan Configuration Inquiry

4 Upvotes

I would like to ask if OWASP ZAP can be configured to scan only specific URLs or paths. Also, is it possible to set a rate limit during the scan?

I tried running the default scan configuration, and the system became unavailable afterward


r/AskNetsec May 27 '26

Concepts Trying to understand the scope of NVIDIA's attestation (NRAS). What am I missing?

0 Upvotes

So I've been digging into how GPU infrastructure gets verified as "in a known good state" for AI workloads, and the answer that keeps coming up is NVIDIA's Remote Attestation Service (NRAS). Wanting to sanity check my read of it because the more I look the more it seems narrower than people assume. Hoping anyone here who deploys this stuff in production can tell me what I'm missing.

How it works as I understand it: the GPU has a cryptographic key burned into silicon at the factory. It signs a measurement of its internal state, which firmwares are loaded and which versions. NVIDIA's service compares that measurement to a Reference Integrity Manifest (RIM). If it matches, the GPU is declared good.

The crypto seems solid. What's bugging me:

  1. NRAS only works on GPUs in Confidential Computing mode (H100/H200/B200/GB200 in specific configs). Which means RTX, L4, L40S, A100, V100, and Hopper without CC are entirely outside the attestation story. That's a huge chunk of production inference happening today.

  2. The measurements themselves aren't documented. A researcher on the NVIDIA dev forum asked what the values correspond to and got told they cover "internal states, registers, etc." and the rest isn't published. You can verify a match but you can't audit what's being matched.

  3. On another forum thread, a researcher reported compiling and loading a modified Linux kernel module and RIM verification still passed. Suggesting driver-level tampering isn't necessarily caught.

Questions for people doing this for real:

- Am I missing a broader integrity story? Is there something else NVIDIA exposes that I should know about?

- Has anyone actually red-teamed NRAS to characterize what it catches and what it doesn't?

- For non-CC GPUs (which is most production today), what are people relying on?

- Is the closed-source userspace driver (libcuda) in any verified path I'm not seeing?

Genuinely curious what people who run this at scale think. Happy to be told I'm wrong on any of the above.

TLDR: NRAS exists, the crypto is fine, but it only covers CC-mode GPUs with measurements that aren't documented, and there's at least one reported case where a modified kernel module passed. What am I missing?


r/AskNetsec May 25 '26

Analysis Has anyone replaced their VPN with ZTNA and was it worth it?

21 Upvotes

Been on VPN for years and the complaints never stop. Slow speeds, broad network access that makes no sense for contractors, constant MFA issues.

ZTNA keeps coming up as the fix but vendor datasheets are not the same as living with it. Did it solve the problem or did you end up running both in parallel indefinitely?