Hacker News new | ask | show | jobs
by imwillofficial 1781 days ago
One of their missions is infrastructure security of nationally important assets. Usually this is military stuff. But think power grids, etc… NSA ironically puts out some good security stuff. Their “manageable network plan” pdf is a must read for anyone hacking to wrangle a new environment, even if it isn’t followed by the owners of said environment.

I’ve been recommending it to various localities after my security assessments for years now. https://apps.nsa.gov/iaarchive/library/ia-guidance/security-...

1 comments

I get a "cannot find requested file" page when trying to get the actual file. The IAD library stopped being updated in 2018 and the link has apparently bitrotted. Cryptome still has a copy, FWIW [0].

Having said that, the last thing I tried implementing from the NSA was a simple systemd service to disable ptrace [1]. The provided service definition had at least three errors, and the instructions themselves were incomplete. Not exactly a confidence builder, but I'll take a look at this one so thank you.

[0] https://cryptome.org/2016/01/nsa-16-0114.pdf

[1] https://media.defense.gov/2019/Jul/16/2002158062/-1/-1/0/CSI...

Thanks for the update!