Profile_bird

Hey there! spinkham is using Twitter.

Twitter is a free service that lets you keep in touch with people through the exchange of quick, frequent answers to one simple question: What's happening? Join today to start receiving spinkham's tweets.

Already using Twitter
from your phone? Click here.

spinkham

  1. Errata Security calls BS on Brazil power hack, and Wired Threat Level Confirms it. Both good reads. http://is.gd/4RKy6 http://is.gd/4RKyN
  2. @jeremiahg Depends on the nature of the site and the experience of the tester. Neither does a good job without a good operator
  3. Paranoia: Not being willing to give ISSA website your credit card information It's a job hazard I suppose...
  4. Previously mentioned DNSSEC meeting time: Tuesday, 27 October: 5:00 pm PDT, 8:00 pm EDT, 12:00 midnight, UTC. Slides available now.
  5. Interesting DNSSEC workshop tonight w/ dial-in, webcast & slides available. Looks like good news on deployment timeline http://is.gd/4EgcF
  6. Now THIS I would pay to see... http://is.gd/4mQxW
  7. @jeremiahg WAFs are not analogous to simple IP firewalls, they are more like IPSs. A complex potential failure point needs to prove itself.
  8. Amusing. Bitorrent drives largest increase in IPv6 adoption yet. Behold the power of P2P. http://is.gd/354xD
  9. http://is.gd/32PT7 The man signs our laws and runs our military and we're afraid of his power to tell kids to stay in school and work hard?
  10. rvm is sweet, recommended for 1.9 or jruby transition. Best way is to use RVM to install all but system ruby versions http://is.gd/2IgyN
  11. @hdmoore There's also http://rvm.beginrescueend.com/ and (vim/emacs/textmate) when you tire of the IDEs. Fairly new but works a treat so far
  12. @hdmoore I recommend netbeans, also has great ruby support.
  13. Free SSL certs from StartCom already valid in Firefox, valid in IE tomorrow. That's 90-95% market share. Game changer. http://is.gd/2s2eU
  14. In HK, eating squid ink and bacon bread. Saw it in a store, had to try. Surprisingly good
  15. This is what is wrong with the security industry: "Security Researcher" is a cool title, "Software Quality Specialist" is not.
  16. Flash updates! Get your flash updates here! http://tr.im/uPKE Now with less p0wn4g3, but I'm sure there's plenty of fun in there still...
  17. So far Dowd and Kaminsky have the goods though. http://tr.im/uKF6 http://tr.im/uKG3 Definately 2 of the most creative men in the business.
  18. RT @buckybit: Every year the presentations at #blackhat and #defcon are a live horror-film festival for security paranoids.
  19. As a researcher I <3 new attacks but as an auditor it's the XSS attack from 1997 or poor authentication & authorization that usually fails
  20. How typical low-tech attacks were used to gain access to many confidential twitter documents: No fancy 0 day needed. http://is.gd/1Jbrf