I like to tell ppl the hardest thing to do in security is accept risk, but its also the most valuable and where security ppl can really earn their $ #infosec#thoughtops
I have a method for breaking all current prime-factor based encryption but I used my novel nano-dark-matter-AI-warp encryption to post the proof paper on the time flux index and the fact that you can't see it proves my encryption is unbreakable. #qed
Can we all agree that security questions (especially based on personal details that can often be enumerated via OSINT) are a ridiculous security non-feature that adds friction with little practical risk reduction and they should be eliminated?
The occurrence of vulnerabilities is INEVITABLE. Defense is HARD. You can be right 22 million times and wrong ONCE and you "lose" in the eyes of users and media. Oh well. We all know the real game is not 0 vulns but increasing attack cost and improving response capabilities.
Idea for a new twitter feature: filter any post with a GIF below a certain resolution. I'm so tired the same crappy spittake.gif that's been around for 15 years. Get your GIF game into the modern era, people.
The simplest and least effective security strategy is one built on inflexible proclamations and security platitudes that shut down dialogue, preventing reducing risk in a meaningful way. Always listen, evaluate and be ready to adapt and compromise.
@alexstamos The most interesting analysis will be of enforcement actions. This will be the key indicator of the cost/risk of sloppy, underfunded or "interpretive" implementations of GDPR.