Thoave

@Hogosec

Infosec, privacy, & GRC specialist with a smidge of research to boot. I am happy to retweet when others say brilliant things. My employer doesn't know I exist.

Vrijeme pridruživanja: siječanj 2014.

Tweetovi

Blokirali ste korisnika/cu @Hogosec

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @Hogosec

  1. 6. velj 2019.

    I frequently see DIY website creation solutions used for small business sites that provision accounts and take CC payments without having configured TLS. Not sure which is worse, the business or their customers not knowing any better.

    Poništi
  2. 8. kol 2018.

    Really nice work by and team on wifi threats. Check out Dom's talk if you are at DEFCON.

    Poništi
  3. 6. kol 2018.

    So take your triple A security preso to GRC, privacy, or Auditing conferences and bring the level of security discorse up to a higher level in these organization's own backyard.

    Prikaži ovu nit
    Poništi
  4. 6. kol 2018.

    And do not forget about how important the role that counsel and auditors play in decisions that are being made. They too need to be educated and it should come outside of their internal echo chambers.

    Prikaži ovu nit
    Poništi
  5. 6. kol 2018.

    Technical comprehension limitations aside, business operatives are desperate for ways to reframe the argument to improve security control postures. And there are some who honestly do not understand the stakes. Infosec professionals are all about the debate. Take it there!

    Prikaži ovu nit
    Poništi
  6. 6. kol 2018.

    Sure, it is amazeballs to pontificate with peers and friends and sharing knowledge makes for a stronger community. But at the end of the day, the infosec industry needs to overcome the value proposition issues intrinsic in corporate operational funding debates.

    Prikaži ovu nit
    Poništi
  7. 6. kol 2018.

    There is a huge untapped opportunity for researchers who only target high profile infosec conferences to take that info and educate the people who really need it - members of corporate leadership. No, not CISOs. I am talking about COOs, CIOs, CROs, and their respective underlings

    Prikaži ovu nit
    Poništi
  8. 25. srp 2018.

    This is tangential to the current cert procturing debate, but reminds me that driving the pursuit of a mastery of practical infosec knowledge and execution is what good certs/training programs do. I think exemplifies this. Shot out to as well.

    Prikaži ovu nit
    Poništi
  9. 25. srp 2018.

    Many years ago, told me that it is perfectly ok to have to google commands or tool options that I could not recall in real time, so long as I understood what I was attempting to get the system to do and why.

    Prikaži ovu nit
    Poništi
  10. 22. srp 2018.

    I see infosec as a zero-sum game. Sides are playing against a finite set of resources, so the idea of absolute control is a bit of a fallacy. There is always risk associated with inherent points of failures. Present objective intel to allow for informed risk decisions.

    Poništi
  11. 27. sij 2018.

    I know the cert/collegiate degree debate has simmered down now, but a recent interview dialogue on the topic reminded me that most collegiate infosec majors utilize professional certs as core curriculum. CompTIA, Cisco, ISC2, EC Council... I guess that says it all?

    Poništi
  12. 4. sij 2018.

    Meltdown/Spectre personal hot take free zone here. I am of the 'TL:DR' camp on this one and defer to people much smarter than me to lay it down.

    Poništi
  13. 31. pro 2017.

    Happy New Year to all of my infosec and privacy friends!

    Poništi
  14. 24. pro 2017.

    Nothing frustrates me quite like Google Nearby shoving ads on my phone when walking through the mall by taking advantage of the fact that I use bluetooth peripherals. What happened to this being an opt-in service? Another example of forcing features to program user complacency.

    Poništi
  15. 2. pro 2017.

    Someone asked me what sports team the beanie I was wearing represented. I replied, "Not exactly a sports team, but they kick ass at defensive strategies all the same."

    Poništi
  16. 25. stu 2017.

    I am not an attorney, but why aren't there static classes of users pre-defined per industry? For instance, retail or medical breaches should invoke a class for recompense by default. It seems more effective than offering worthless credit monitoring.

    Poništi
  17. 20. stu 2017.

    I have shown business partners that intrinsic lack of trust in the testing of controls aligned to governance expectations cannot be processed around. Integrity of assessments can be improved to a degree through transparency, otherwise it is a agree to disagree proposition.

    Poništi
  18. proslijedio/la je Tweet
    22. lis 2017.

    An intro to malware reversing from Go vote in his poll and tell him to do more ;)

    Poništi
  19. 15. lis 2017.

    Does the infosec community have a centralized metric as to the current state of industry-wide technical debt, like an IT doomsday clock?

    Poništi
  20. proslijedio/la je Tweet
    14. lis 2017.

    Lots of companies can hire good researchers to do good research. Not many can create good researchers. Speak to me about working

    Poništi

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·