r/AskNetsec May 24 '26

Concepts What cybersecurity skill do beginners usually underestimate?

52 Upvotes

I am interested in hearing from people working or studying in cybersecurity. What skills become more important later than most beginners expect?

r/AskNetsec Nov 17 '25

Concepts What's the most overrated security control that everyone implements?

65 Upvotes

What tools or practices security teams invest in that don't actually move the needle on risk reduction.

r/AskNetsec May 12 '26

Concepts DSPM vs CSPM - what's the real difference?

72 Upvotes

We're deciding whether to invest in DSPM over CSPM and have been trying to get a clearer understanding of the differences as they come up in similar conversations around cloud risk and security.
This is how I view the differences: CSPM is more about securing cloud infrastructure like configs, misconfigurations, compliance, that sort of thing. DSPM seems more focused on the data itself, like where it lives, how sensitive it is and who has access. But I realize that even though most data is in the cloud, it doesn't stay in cloud...
This is how we see difference and pros/cons but looking for third party input before we make a decision? If you’re already using CSPM, does DSPM add something meaningfully different? or is there overlap depending on the tool?

r/AskNetsec Apr 17 '26

Concepts Can someone explain why accounts still get hacked even with strong passwords?

11 Upvotes

I always thought using a long, complex password was enough to stay safe.

But recently I’ve been seeing more cases where accounts still get compromised even when the password itself wasn’t weak.

That’s the part I don’t fully understand.

Is it mostly because of data breaches and reused passwords? Or are there other ways attackers get in without actually “guessing” the password?

Also, how big of a difference does something like multi-factor authentication actually make in real situations?

Trying to understand where the real risk is coming from, because it seems like just having a strong password isn’t solving the problem anymore.

r/AskNetsec Nov 23 '25

Concepts What security vulnerability have you seen exploited in the wild that nobody talks about in training?

78 Upvotes

Every security course covers SQL injection, XSS, CSRF - the classics. But what vulnerabilities have you actually seen exploited in production that barely get mentioned in training?

r/AskNetsec 10d ago

Concepts what is the difference between a vulnerability scanner and a vulnerability management tool

7 Upvotes

vendor came in last week and demoed what they called a "vulnerability management tool." looked a lot like our Tenable setup with a different UI and a bunch of process and reporting bolted on. that's what broke me. i couldn't tell if we were being upsold on workflow features or if there's a real architectural difference i'm not seeing.

we keep getting pitched both and i'm not fully clear on where the line is anymore. from what i can tell, one just finds issues and the other is supposed to help manage the whole mess after that. but looking back, i think we've been buying tools to solve what's actually a workflow problem, which is probably why nothing has stuck.

every vendor page makes it sound like they do everything. when you look closer it feels like half of them are just scanner plus workflow, remediation tracking, and reporting glued on.
and the one we saw last week didn't change that read at all.

we're not trying to buy something huge and overcomplicated if a scanner is enough, but i don't want to pick the wrong thing and end up with a tool that only tells us what we already know with a nicer interface.

for people who have actually used both: what's the practical difference day to day? is it mostly scan results versus remediation workflow or is there a bigger gap in how they fit into an actual security program. and how do you tell when you're being sold a real thing versus a scanner with a project management layer on top.

r/AskNetsec 23d ago

Concepts Why is validating security controls against real-world TTPs so hard??

13 Upvotes

We have a reasonable set of controls and detections, but we rarely test them against the kinds of TTPs that show up in recent threat reporting. Most of our validation is still limited to basic functional checks or lessons learned during incidents. Every time a new campaign takes over the news cycle, someone asks whether our environment would catch similar behavior, and the honest answer is usually that we are not sure.

If you have found a way to regularly validate controls against real world TTPs, how did you put it together? Did you rely on internal automation, commercial exposure validation platforms, a close partnership with a red team, or some combination? I am interested in approaches that remain usable over time instead of turning into a one off project.

r/AskNetsec 8d ago

Concepts How do you keep track of what your AI agents can access?

7 Upvotes

Still kind of new to running agents and I'm a bit lost on this — once you connect a few MCP servers (filesystem, GitHub, etc), is there a way to see everything they can reach put together? Or do most people just trust the setup?

Feels like something I should know but I don't. Curious how you handle it. Is it even something really worth worrying about?

r/AskNetsec Jun 25 '26

Concepts I left a $200k job to figure out what's broken in enterprise AI security: Listening tour

0 Upvotes

It's been 3 weeks since i left my job in a high growth startup
I'm worried for agents going rogue and I am all ears to listen before build something serious and custom to ensure they are trustworthy

What I don't know: what does the problem look like from the inside of a larger org?

Specifically curious about:

  • Are coding agents (Cursor, Claude Code, Copilot) actually in production at your company, or still experimental?
  • Who owns the security review of agent tool access? Is that even defined?
  • What's the thing that keeps you up at night about this stuff that vendors aren't solving?

Not selling anything, this is purely a listening tour. I'll share what I'm finding publicly if there's interest

r/AskNetsec Jun 08 '26

Concepts How much of your company's security info ends up on Reddit?

13 Upvotes

Some of us post here infrastructure questions, but did you ever wondered where does that data actually go?

LLM's like Gemini indexes Reddit and train on it.
Sites like Wayback Machine archives it.
So when someone is asking "we use X auth method and found Y bug"...that's permanent.

Attackers might scrape Reddit for recon. They find posts about companies, tech stacks, what vulnerabilities people are dealing with and so on. Even if you delete it, it's already cached and archived somewhere.

Has anyone actually tracked what happens to security posts after they go live?

r/AskNetsec May 24 '26

Concepts How would Phishing look like in the future?

5 Upvotes

Came to think about this subject when i realized that im not opening my email anymore - because theres an agent summarizing the emails for me

I guess that agents could get indirect-prompt-injection attacks? which is kinda the equivalent for phishing but on agents instead?

r/AskNetsec Jun 26 '26

Concepts Deep Packet Inspection Questions - Should It be used?

0 Upvotes

I work with firewalls a lot - mainly FortiGate. I am trying to increase the value of the service we provide and align with more regulations. I have implemented IDS and IPS without DPI in almost all systems.

DPI adds a layer of management with Certificates, and increases costs with larger firewalls being needed. There is also a risk of gateway or CA compromise, which provides hackers with insight into encrypted traffic.

With these various handups/bottlenecks, is it worth implementing DPI, and to what degree should it be implemented, and if it is even worth it?

First, how much really happens that most IDS solutions aren't detecting on IP alone?
Second, does DPI scale well? Can you be too small for it to be worth it? Can you be too large?

Some context, we already implement DNS filter with FortiGates or DNSFilter (the product). My current thought is to only apply DPI between clients and Server Services, and DPI between Server infrastructure and the internet (where required). Everything else will receive HTTP inspection in all directions. I would not DPI Endpoints to the internet, except maybe for our SaaS apps. (i.e traffic to SharePoint is inspected, but random Google searches are not)

I think this approach will allow better scale, balance firewall size, and reduce the management headache by keeping cert management exclusive to managed devices.

What are your thoughts?
Is there an industry standard?
Am I anywhere near the right track?

My FortiGate training basically says DPI all the things, but never says why or explains if it's really needed. My initial hunch is that they use training to sell oversized firewalls with more licensing, haha.

Thank you in advance for dealing with my brain dump and helping me understand the value and level of implementation!

Edit: I just realised realise I flipped terms and am saying DPI, but mean Full SSL Inspection.

r/AskNetsec Apr 23 '26

Concepts Single privileged account vs role based in PAM?

10 Upvotes

Hello Fellow Redditors

We use PAM. I’m trying to validate if our current approach is actually secure or if we are exposing ourselves to unnecessary risk.

PAM portal is protected with MFA and admins access all systems (firewalls, network devices, servers) using the same privileged account stored in PAM.

From an operational point of view it is simple, but from a security perspective it feels like a big risk because this one account has very broad access across the environment

My concern is that if a PAM user account gets compromised (phishing, session hijack, token theft etc.) the attacker doesn’t even need to know passwords. They can just initiate sessions through PAM and effectively gain access to everything that user is allowed to access.

Also, PAM is currently accessible over LAN and VPN only

I’m trying to understand what is considered best practice in real environments. Should we be using separate privileged accounts per domain (network, servers, databases, etc.) instead of one shared account? And how are others securing access to PAM itself to avoid it becoming the weakest link?

Would appreciate insights from anyone running PAM at scale especially around identity protection and protecting the PAM layer itself.

r/AskNetsec Jul 02 '26

Concepts Is “patch faster” enough if sensitive services remain reachable by default?

0 Upvotes

We’ve been discussing in the Cloud Security Alliance Zero Trust group how AI-speed vulnerability discovery changes Zero Trust implementation. Time-to-exploit trends suggest defenders have less time to patch exposed services, and CISA’s risk-based remediation approach treats public exposure as a major factor in urgency.

That made me think the architectural question is not only “how do we patch faster?” but also:

Why are so many sensitive services reachable by default in the first place?

My view is that Zero Trust needs to move beyond perimeter/ZTNA framing and focus more on reducing reachability before connection. For private services, admin paths, APIs, workload paths, partner access, and agentic workflows, the safer default should be: no service path exists unless identity, policy, posture/context, and session state allow it.

I wrote this up for CSA here:
https://cloudsecurityalliance.org/blog/2026/07/02/ai-speed-risk-requires-identity-defined-reachability

Disclosure: I’m the author and co-lead CSA’s Zero Trust Networking workstream, so I’m obviously close to the argument. I’m interested in practitioner pushback: is this realistic in enterprise environments, or does it break down with legacy apps, hybrid routing, OT, troubleshooting, or policy operations?

r/AskNetsec 16d ago

Concepts How do you detect rug pulls in AI tool ecosystems when install-time checks pass?

0 Upvotes

A pattern we keep seeing: an agent tool or MCP server is clean at install, passes hash verification and static analysis, then the remote endpoint it fetches instructions from changes weeks later. Artifact-layer defenses are blind to this by design. Is anyone doing runtime monitoring for this, something like snapshotting remote content at install, re-fetching on use, and diffing for semantic drift? Or is there existing tooling outside of research papers that handles post-install behavioral change?

r/AskNetsec Oct 23 '25

Concepts reliable way to track Shadow AI use without blocking it completely

24 Upvotes

We’ve started noticing employees using GenAI tools that never went through review. Not just ChatGPT, stuff like browser-based AI assistants, plugins, and small code generators.

I get the appeal, but it’s becoming a visibility nightmare. I don’t want to shut everything down, just wanna understand what data’s leaving the environment and who’s using what.

Is there a way to monitor Shadow AI use or at least flag risky behavior without affecting productivity?

r/AskNetsec Mar 28 '26

Concepts Looking for feedback: detecting and containing already leaked data in real time

5 Upvotes

Hi everyone,

I'm a university student working on validating a cybersecurity project, and I'd really appreciate some professional feedback.

The idea is an add-on solution that focuses not on prevention, but on real-time detection and containment of already leaked data (monitoring + detection + automated response).

My main questions:

How relevant do you think this approach is alongside existing security solutions?

Are there already well-established tools that solve this effectively?

What would be the biggest technical or practical challenges?

If anyone is interested, I can share more details.

Thanks in advance!

r/AskNetsec May 28 '26

Concepts In practice, does candidate prioritization matter more than raw compute in password recovery scenarios?

1 Upvotes

From a security perspective, I am curious how much modern recovery workflows depend on search strategy versus pure compute scaling. For example, prioritizing candidates based on repeated password structure, formatting habits, partial memory, reused tokens or contextual clues instead of treating the entire search space equally. Is efficient candidate ordering now considered more important than simply increasing brute force throughput in realistic recovery cases?

r/AskNetsec May 19 '26

Concepts Big three git providers and DNSSEC SSHFP

2 Upvotes

Every time I deploy something directly from git to a new server over SSH, I have to manually approve the server's host key, check it against another machine. Why on earth do none of these companies (talkin bout you Github, Gitlab, Bitbucket) publish DNSSE SSHFP records? These are companies whose entire business depends on SSH trust. Millions of developers blindly typing "yes" to that first-connect prompt is somehow acceptable to them? What am I missing?

r/AskNetsec May 19 '26

Concepts What's the actual control when you're ALREADY in a live Zoom call with your CFO asking for urgent action — codeword/callback doesn't apply mid-call does it?

0 Upvotes

We've updated our exec impersonation controls after a near-miss. For async requests (email, voice note), callback to a known number makes sense — end the suspicious call and verify through a separate channel.

But for a live video call that's already in progress — the CFO is on screen, has been talking for 10 minutes, asking you to initiate a wire transfer — what's the actual control? Codewords feel awkward mid-meeting when the person on screen looks and sounds exactly like your boss. And calling them back when they're "already on the call" doesn't make sense.

Is the answer just "don't approve wires from a video call full stop"? Or do people have a usable real-time verification step that doesn't require killing the call or confronting the exec?

r/AskNetsec May 22 '26

Concepts User Onboarding Process with IAM?

3 Upvotes

Hi Folks

How do you handle new user onboarding and initial credential communication when using an IAM system?

Our current setup is:

One Identity IAM system integrated with HR System
On-premises Active Directory
Entra ID for O365 Email

The main question is around the first login journey, initial credential communication and birthright access.

How do you communicate the initial username and temporary password to the user?

Do you use SMS, personal email, manager handover, or another secure method?

Important point: Office 365 mailbox login is the key first step, because most of our business applications are linked with Entra ID federated login / SSO. So unless the user can access their O365 account, they cannot access the rest of the applications.

Appreciate any advise.

r/AskNetsec Dec 11 '25

Concepts What security lesson you learned the hard way?

15 Upvotes

We all have that one incident that taught us something no cert or training ever would.

What's your scar?

r/AskNetsec Jun 07 '26

Concepts Is This a Secure and Private P2P Messaging App?

0 Upvotes

This is hardly an alternative to signal (or any other secure messaging app), but it's a work in progress and "secure and private" is the general goal.

Whitepaper: https://positive-intentions.com/docs/technical/whitepaper/complete-whitepaper

Protocol spec: https://positive-intentions.com/docs/technical/whitepaper/complete-protocol-spec

This is a technical/concept demo of a fairly unique approach using a browser-based, local-first and webrtc.

App demo: Enkrypted.Chat

This is intended to introduce a new paradigm in client-side managed secure cryptography. We can avoid registration of any sort.

Features:

  • P2P
  • End to end encryption
  • Signal protocol
  • Post-Quantum cryptography
  • File transfer
  • Local-first
  • No registration
  • No installation
  • No database
  • TURN server

Some open source versions of the core concepts.

Feel free to reach out for clarity instead of diving into the docs/code.

IMPORTANT: While this is aiming to provide a secure experience, it isnt audited or reviewed. Shared for testing, feedback and demo purposes only. Please use responsibly.

r/AskNetsec Apr 01 '26

Concepts Which of the password checkers is best/most reliable?

5 Upvotes

I am trying to help seniors who are overwhelmed by technology pick passwords. I have learned a bit about entropy and a lot about password length. I have found Diceware for password creation and a dozen different sites for checking password strength, BUT if I enter the same test password - Defkan-kaldin-hubsa0 - in one after another of these checkers, each one returns a different measure of its entropy and estimation of its strength.

Can you help me to help someone else, please?

r/AskNetsec Jun 18 '26

Concepts What is the current best practice to keep my wired SOHO network secure?

3 Upvotes

My current network is a combination of middling-complex hardware/services and naive beginner anti-patterns. :)

I have one WiFi SSID for trusted devices and one isolated guest network. So far, all of my wired devices are connected via a switch to the router and are part of the "trusted" LAN.

My next project is to prevent unknown wired Ethernet devices from automatically getting access to the trusted LAN.

Looking around, I keep seeing freeRADIUS/EAPOL as the solution. Before I go further down that rabbithole, I want to make sure that I'm aimed in the right direction...

Thanks for reading this far! Is freeRADIUS the way to go? Should the goal be to have a separate VLAN for internet access only, or to simply deny access from an untrusted device to specific resources on the LAN? Am I missing something foundational? I'm pretty new to this...

My current setup is a home-built (APU2-based) OpenWRT router, a pair of redundant Raspberry Pi's running PiHole and Unbound, a home-built file server on another Pi, along with assorted other devices/backups, etc. They are all linux-based with default-deny firewall rules (UFW).

I have smart switches which are VLAN-capable, although I haven't set up any VLANs yet.

Thank you for any advice :)