security team handed us 600 vulns to fix. half werent even reachable from internet
Posted by relived_greats12@reddit | sysadmin | View on Reddit | 115 comments
Infosec ran their quarterly scan and dropped 600 vulnerabilities on us. 200 marked critical. Leadership wants remediation timeline by Friday.
Spent two days triaging with DevOps. Most criticals were libraries we import but never actually call. Internal APIs behind VPN flagged as publicly exposed. Staging environments with test data treated same as production.
Best one was a critical vuln in a Lambda that runs once a month. Scanner sees vulnerable package but has no idea if the code even executes or if anyone hits that endpoint.
Asked security how to prioritize. They said fix criticals first. Cool, but which ones are actually exploitable versus sitting in unused code? Scanner can't tell the difference.
Devs are ignoring security findings now because we've cried wolf too many times. Then we miss actual issues buried under the noise.
We spent half our sprint on vulnerabilities that didn't matter. Meanwhile an actual exploit attempt last month took 8 hours to detect because buried under 300 false positives.
Security team is mad we're not moving fast enough. We're mad they can't tell us what actually needs fixing versus theoretical risk.
Has anyone solved this or do security and engineering just hate each other everywhere?
115 Comments
Retro_Relics@reddit
MrSanford@reddit
TopHat84@reddit
MrSanford@reddit
TopHat84@reddit
Retro_Relics@reddit
bitslammer@reddit
ddesla2@reddit
bitslammer@reddit
ddesla2@reddit
Retro_Relics@reddit
bitslammer@reddit
merlyndavis@reddit
Humpaaa@reddit
domestic_omnom@reddit
vCentered@reddit
jstuart-tech@reddit
domestic_omnom@reddit
Acceptable_Potato949@reddit
domestic_omnom@reddit
Acceptable_Potato949@reddit
domestic_omnom@reddit
Acceptable_Potato949@reddit
jstuart-tech@reddit
magictiger@reddit
reegz@reddit
Humpaaa@reddit
RobbieRigel@reddit
themastermatt@reddit
Humpaaa@reddit
themastermatt@reddit
jaydizzleforshizzle@reddit
Rhyobit@reddit
jaydizzleforshizzle@reddit
somerandomguy101@reddit
Pup5432@reddit
Diplomatic_Gunboats@reddit
jaydizzleforshizzle@reddit
Inquisitor_ForHire@reddit
themastermatt@reddit
missed_sla@reddit
themastermatt@reddit
merlyndavis@reddit
themastermatt@reddit
merlyndavis@reddit
themastermatt@reddit
Humpaaa@reddit
DeliveryStandard4824@reddit
Khue@reddit
aenae@reddit
TheCTRL@reddit
nethack47@reddit
1z1z2x2x3c3c4v4v@reddit
Turbulent-Pea-8826@reddit
ddesla2@reddit
Turbulent-Pea-8826@reddit
somerandomguy101@reddit
whtbrd@reddit
VA_Network_Nerd@reddit
thegreatcerebral@reddit
rrmcco04@reddit
lightmatter501@reddit
Tx_Drewdad@reddit
calladc@reddit
PlannedObsolescence_@reddit
laz10@reddit
Ihaveasmallwang@reddit
CAMx264x@reddit
syberghost@reddit
Nonaveragemonkey@reddit
johnfkngzoidberg@reddit
Small_Golf_8330@reddit
EuphoricAbigail@reddit
Klop152@reddit
klipz77@reddit
broknbottle@reddit
bageloid@reddit
danekan@reddit
bitslammer@reddit
reegz@reddit
bitslammer@reddit
chaosmonkey@reddit
bitslammer@reddit
disbound@reddit
danfirst@reddit
brixton_@reddit
New-fone_Who-Dis@reddit
Noobmode@reddit
Own-Trainer-6996@reddit
Noobmode@reddit
Zerafiall@reddit
GoogleDrummer@reddit
HopingillWin@reddit
Own-Trainer-6996@reddit
jobohomeskillet@reddit
Ihaveasmallwang@reddit
danekan@reddit
Longjumping_Gap_9325@reddit
Heavy_Dirt_3453@reddit
delti90@reddit
jxd1234@reddit
CluelessPentester@reddit
Either-Cheesecake-81@reddit
blavelmumplings@reddit
LBishop28@reddit
feldrim@reddit
sw4gyJ0hnson@reddit
Mountain-eagle-xray@reddit
sociablezealot@reddit
UnkleRinkus@reddit
TickleMyBurger@reddit
Tcrownclown@reddit
TuxAndrew@reddit
maziarczykk@reddit
enforce1@reddit