spanicker / ip-blindness

119 stars 19 forks source link

Attack forensics conundrum #2

Closed gitcnd closed 4 years ago

gitcnd commented 4 years ago

Law, insurance, and best practice demand ubiquitous post-intrusion forensic data in almost all large organisations.

Alleged privacy introduced by ip-blindness will either destroy their audit efficacy (if, against their policies, they disabled their logging), or it would only be temporary and would be reversible after-the-fact.