@krypt3ia Oh I won’t! I. Won’t.
I’m the unflinchingly optimistic graybeard, wandering in this cyber dystopia. InfoSec, cybersecurity, futurist, strategist, chaotic good. The views expressed are my own. Sometimes humorously.
https://jwgoerlich.com
@krypt3ia Oh I won’t! I. Won’t.
I know, I know. Different companies naming threat actor groups different things is confusing. I get it.
(But real talk, how fun is it that the Iranians are named kittens? Beware the Nemesis Kitten!)
@neurovagrant is there anything legit or valid on a .top domain these days? It’s wild.
@scottwilson @wendynather 🤦♂️
@jwgoerlich Oh sure, let’s cut costs by just training people. Because that’s always worked so well instead of, like, logging.
Invisible until it breaks: The risk of cutting costs and undervaluing cybersecurity
@heiglandreas she gets it! I don’t think the customer service people understand the purpose of the steps we security people have them doing. It takes stepping outside of the script to see the flaws.
“It is I, Mr. Smith. Please let me in.”
“Sorry, I can’t let you in. I don’t know you, Mr. Smith. Oh, there is no picture of you on file. Do you have a recent photo?”
<hands over photo>
“Thank you, I will add this to your file, Mr. Smith. Ah yes, now I recognize you! You are the person in the photo!”
Them: "In order to make this change, I need to verify you. I'll do this with a one-time text."
Me: Sure.
Them: "We have no phone number on file."
Me: ...
Them: "Not to worry. I'll update your account. What number would you like to use?"
@krypt3ia Fingers crossed. If I can help in any way, you know how to find me.
@cesarpose Putting aside the joke about the transcription, yep, it’s a feature gone wrong.
This weekend is going to be awesome! 💫😍
Hosting Girls Who Hack and Spawn-Camp day camps 🥳
Really, AI is sycophantic? Well huh. I hadn’t noticed.
“Trust the lack of process.”
— Motivational things I say unironically
@adamshostack 🤔 true, true.
Don’t do the thing to do the thing. Do the thing so you can do the next thing.
Consider threat modeling. The goal isn’t a thing, a diagram. The goal is insight and understanding.
Taking short-cuts (cough, AI) short-circuits learning.
Everyone who tries this prompt gets cool cozy desk photos. Picture books and sticky notes and memorabilia related to them. Me? I get an excited Wolf and a confused GPT. Maybe I broke the model.
Apropos of everything, I’m so glad I got my trans kid out of Texas.
DevSecOps. Where we're going, we don't need roadmaps.