pull down to refresh

If you use Fortigate, you're probably already aware of this, but you can check to see if your IP was leaked here. Today, some more info was shared via a blogpost here, where you can also check to see if you have a leaked TLS or SSH key (keys are hashed)

I also wanted to share this because there is a sentiment from the blogpost that resonated with me deeply as a security professional in this current age of "build it now, test in prod like a real man".
It is an unfortunate reality that these days, security products often are themselves the source of security vulnerabilities. While I have no empirical evidence for this (and nobody else has the data, have I complained about this before?), I believe that we have entered a situation in recent years where security products turned from "mostly useless, sometimes harmful" to "almost certainly causing more security issues than they prevent". I have more thoughts on this that I may share at another time.
If you are wondering what to do, the solution is neither to patch and fix your Fortinet device nor to buy additional attack surface from one of its equally bad competitors. It is to stop believing that adding more attack surface will increase security.