Geek, incident responder, agile fanboy, RPG gamer, military doctrine nerd, OpenBSD fan, poor python scripter. Views expressed are my own - not my employer.
Question for @maxb on his awesome talk “Sneaking in Network Security” in #halle at #35c3: Could you elaborate on how you got management and application engineers’ buy-in for the changes described in your talk? What objections did they raise and how did you address them?
Great talk by @sperbsen at #35C3 "How to teach programming to your loved ones" - really hit home how hard it is to teach programming without breaking it into repeatable steps.
(3) yet another great @deepsec talk I'm excited about: "Defense Informs Offense Improves Defense – How to Compromise an ICS Network and How to Defend" by Joe Slowik at https://t.co/dRYm6A7Vf5
Really excited to be participating in my first @deepsec conference here in Vienna! It starts tomorrow. There are some great talks coming - (1) "Leveraging Endpoints to Boost Incident Response Capabilities" by Francisco Galian, Mauro Silva at https://t.co/lUKB8Et5cO and
(2) another great @deepsec talk I'm excited about: "Security as a Community Healthcare: Helping Small Non-Profit Organisations Stay Secure" by at Eva Blum-Dumontet at https://t.co/2eVyhEc6rz and
My new favorite response when someone ask what it feels like to be working at FireEye. There are so many people who know more things than me.... https://t.co/QhuDLfGJCT
Interesting thread from @dotMudge on Democratic thought processes on cyber hygiene in the run-up to the 2016 election, and Republican and possible threat actor interest in him following the election. Worth the read. https://t.co/PRnvTbjqoL
So... I suppose it’s time to share a bit.
I have always worked to try to educate the government so they can make better informed decisions that will benefit all citizens.
1/n https://t.co/rJYC9zaaih
Great article by @jalospinoso at https://t.co/kvI1k7ELnk on fixing the military cyber skills gap with a military medical model. Only open question was the cyber enlisted community. Maybe we need a Nuke Power School for Cyber? 12 months of theory, 12 of lab, high attrition.
Favorite quote from the above link: "Sadly, the Army’s solution to promote outside of the box thinking was…to build another, grander box. Design represents a failure to fundamentally understand big thinking in favor of a 'creativity checklist' to be applied by technicians"
I like structure more than process. That is, I dislike prescriptive processes, but I still like having some structure to be creative in. This thought was inspired by https://t.co/Ngs93yXPzo - it does a great job of highlighting the strange tie between process and risk aversion.
Enjoying the heck out of @a41con this year. Highlights so far: @droethlisberger demonstrating his new tool xnumon for Mac, @unpacker for his research on Lazarus, and @ObiWan666 for his work identifying shipborne IOT vulnerabilities.