|
lcamtuf
@
lcamtuf
SF Bay Area
|
|
Furniture making and doomsday preparedness tips.
|
|
|
246
Tweetovi
|
431
Pratim
|
26.396
Osobe koje vas prate
|
| Tweetovi |
|
lcamtuf
@lcamtuf
|
22. sij |
|
This is a pretty good reminder that any invasive heuristics in the browser - be it XSS filters or privacy protections - often cause more problems than they address: arxiv.org/ftp/arxiv/pape…
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
16. sij |
|
Machine learning uprising canceled for today... pic.twitter.com/e8RBHISHyJ
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
30. lis |
|
Walnut dining table that I was meaning to finish this week, but came down with a nasty cold. pic.twitter.com/nGsHSAQr23
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
4. kol |
|
Weekend project: a slightly curved stool. Cherry + curly maple pic.twitter.com/BEP2pqWnOu
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
3. lip |
|
...and so, I suspect that simply being born in the 70s or 80s, and picking up some interest in infosec in the 90s, was a far better predictor of success
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
3. lip |
|
Perhaps tellingly, many similar stories have been written about other companies and associations that operated at the time; off the top of my head: techcrunch.com/2014/03/02/w00…
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
3. lip |
|
Either way, like many of my colleagues from that era, I went on to do many of the same things as the people listed in the article. The company was one of a handful of reputable infosec workplaces back in the day, but I don't think it a magical gateway to success.
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
3. lip |
|
As to "why": don't know. They were a consulting company, I was a young Polish guy on on a visa. Maybe I said something stupid in the interviews. Maybe they didn't want a guy who had a strong accent and couldn't get a clearance.
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
3. lip |
|
I interviewed there in 2002 and didn't get the job; reading the article, I was almost expecting to see "...an event which profoundly affected Zalewski's career and reshaped the industry for years to come."
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
3. lip |
|
Worthwhile read. The company was an important nexus of the infosec industry at the time. But also take it with a grain of salt: some of the connections and claims feel a bit tenuous: wired.com/story/cult-of-…
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
18. tra |
|
I'd strongly encourage folks to read the real thing. The legal decisions and the surrounding political commentary are not going to change anyone's mind, but the now largely public operational details should be very interesting to the folks in our industry.
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
18. tra |
|
Not here for the politics (yeah right), but the first 50 pages of the Mueller report contain a really nice treasure trove of details about the compromise, data exfil, and comms tactics of a state-sponsored adversary.
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
8. tra |
|
@7r4p3z01d @bis0nmakinm00 @Pod_Sec @ErrataRob @danielcincu @chowspecial @tehjh @kees_cook ask and ya shall receive I guess pic.twitter.com/6HnW0e8lUC
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
7. tra |
|
DID YOU JUST CALL MY CLOCK IMPRACTICAL?!
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
7. tra |
|
Aaand done. pic.twitter.com/lZEI53rUbe
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
7. tra |
|
Some progress to report. pic.twitter.com/BBoiOnZZce
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
7. tra |
|
Weekend project: building a clock pic.twitter.com/22BRM7ae0J
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
23. velj |
|
Solving it requires finesse that regulators usually lack. But you know: I am fairly tranquil about my "cyber" risk. I am far more unsettled about the privacy practices in the industry - in part because they remain shielded from view and have not been properly "priced in". (5/5)
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
23. velj |
|
Where we fail as an industry is helping people with unique security or privacy needs. If some facet of your online presence is more valuable than the "society average", we don't have an end-to-end solution for you - and not many companies are seriously investing in that. (4/5)
|
||
|
|
||
|
lcamtuf
@lcamtuf
|
23. velj |
|
To abuse an analogy: when most of us don't mind that our front locks can be picked with a bent paperclip, yet we call for government action after every breach, I can't help but think that we sound a bit like the overeager door lock salesmen of infosec. (3/5)
|
||
|
|
||