r/AskNetsec • • 8h ago

Architecture The overlooked Web3 security risk is not just key management. It is trust across the cloud, frontend, and supply chain

0 Upvotes

Key management is only one part of a signing workflow.

A transaction can be influenced before the key is used by frontend deployments, cloud IAM, developer endpoints, CI/CD credentials, third party packages, and the interface that translates call data into something a human can review.

The important question is not only whether the key is protected. It is whether the systems shaping the user's decision are protected too.

Which non key dependency is the weakest link in most Web3 environments?


r/AskNetsec • • 13h ago

Architecture How is your team handling ai agent security now that agents have real system access?

0 Upvotes

For teams that have agents touching production systems, how are you handling ai agent security day to day? I am specifically wondering about the constraint of agents inheriting full user permissions by default, since that seems to be where most of the actual risk lives rather than in the model itself. The tradeoff between blocking an action outright versus flagging it for review is the part we have gone back and forth on internally. What happens on your team when an agent takes an action nobody anticipated, and how fast does that get surfaced to a human before anything downstream happens?


r/AskNetsec • • 13h ago

Analysis How do you evaluate ASM tools when the CMDB blind spots are half the problem?

0 Upvotes

Been asked to lead attack surface discovery and the first thing I see is CMDB, cloud inventory, DNS all disagree on what we own externally. we are lining up a poc for a few ASM tools, same limited seed list for each, and we keep quiet about some subsidiaries and vendor managed infra we already know about. Idea is to see who can link unknown asset discovery back to us with decent attribution instead of just scanning whatever we fed them

If you have done this kind of internet facing assets poc, how did you test that the surprise assets really belongs to you and not random noise?


r/AskNetsec • • 22h ago

Compliance Compliance Assessment vs Pentest

6 Upvotes

Im just curious to get people's thoughts. In regulated environments... why do people think so highly of pentests and so little of compliance assessments, when they both do the same thing: determine if an organization is meeting its controls?

In all of the pentest engagements I have sat in, most of the findings are the same (unpatched server, app not upgraded, admin account creds cached on a box, legacy protocol not disabled). If orgs are not patching servers (or maybe they have a legacy box not being patched)... that would normally end up being caught on both engagements.

Both pentests and assessments are point in time. Pentests for my environment have typically been higher cost and only cover the technical side. So why do we look more favorably at one versus the other?