Ryan

@Lithron

Current: AppSec. S-SDLC. Tester. Coder. Self-doubter. Previous: Tabletop gamer. Speaking for myself and not my employer.

Atlanta area
Vrijeme pridruživanja: ožujak 2009.

Tweetovi

Blokirali ste korisnika/cu @Lithron

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @Lithron

  1. 30. sij

    "Nearly one third of all DNSSEC-supporting domains publish records in ways that prevent validation and thus provides no practical security." - Chung, Rijswijk-Deij, Chandrasekaran, et al.

    Poništi
  2. proslijedio/la je Tweet
    24. sij

    Learning how to let go of things is essential to long term happiness.

    Poništi
  3. 14. sij

    Twitter, I need some advice. I found a bug in a program and the 'exploitable' gdb plugin (from ) claims the issue is likely exploitable. How do I know if/when it is time to request a CVE number be assigned? (technical and policy answers desired)

    Poništi
  4. proslijedio/la je Tweet
    24. pro 2019.

    Please don't start a software security program with blocking gates in the deployment process. Start with training developers on security. Even if you start with small, voluntary training. These devs can become your security champions and help you get where you want to go.

    Poništi
  5. 23. pro 2019.

    "Fuzz ntpd, the network time daemon?" ... "I just don't want to find an 0day" - - Responsible disclosure would be challenging if the bug is found on a live stream😂

    Poništi
  6. 15. pro 2019.

    The rest of the organization tires of donating hours of effort, funds, and planning time. Often the results are invisible or unmeasurable. Eventually they stop, and security and infosec stands alone. In this moment the fatigue must be healed and relationships have to be rebuilt.

    Prikaži ovu nit
    Poništi
  7. 15. pro 2019.

    I find myself watching Henry Rollins. He described 'donor fatigue'. So I looked it up, realizing this phrase should be familiar to anyone in infosec. Too often our political capital is overspent and *that* is what the rest of the business remembers of us.

    Prikaži ovu nit
    Poništi
  8. proslijedio/la je Tweet
    7. pro 2019.

    Every day, you get to choose how you'll impact those you interact with. Be someone who leaves others happy to have encountered you. Trust me, you'll be happy you did.

    Poništi
  9. 18. stu 2019.

    This paper is focused on zero day vulnerabilities. Those stats are frightening if they extend to all vulnerabilities and they likely do.

    Prikaži ovu nit
    Poništi
  10. 18. stu 2019.

    On the topic of how long software vulnerabilities survive in the wild - "exploits have an average life expectancy of 6.9 years" && "only 25 percent of vulnerabilities do not survive to 1.51 years, and only 25 percent live more than 9.5 years"

    Prikaži ovu nit
    Poništi
  11. 29. lis 2019.

    'The harder I expect a target to be the cleaner I try to write the fuzzer such that it's easier to make better' - Learn a bit about custom fuzzer development:

    Poništi
  12. proslijedio/la je Tweet
    27. lis 2019.

    A gentle reminder, There is an Infosec WoW Classic Guild, Horde on Westfall -- Anyone on discord can add: or DM me.

    Poništi
  13. proslijedio/la je Tweet
    23. lis 2019.
    Odgovor korisniku/ci

    The goal of a career in security needs to be actually becoming part of the business by enabling secure methods of achieving business goals. We're not outside the business, guarding. We're inside the business, guiding.

    Poništi
  14. 18. lis 2019.

    Throwback Friday: That time IT emailed to say my Apple laptop was infected with Windows malware. Then demanded I re-install the non-Windows operating system to remove it. Good times.

    Poništi
  15. 10. lis 2019.

    “More firewalls than the devil’s bedroom” - at Hacker Halted. Context of this quote not important.

    Poništi
  16. 10. lis 2019.

    “Dumpster diving was the first thing I outsourced” - at Hacker Halted

    Poništi
  17. 8. lis 2019.

    Hitting a moving target is one set of challenges. Hitting a target that can't be seen and won't exist until after you've fired.. well, that's a whole different level of difficulty.

    Prikaži ovu nit
    Poništi
  18. 8. lis 2019.

    "I was disappointed and frustrated that policymakers all too often failed to deliver clear direction. And lacking a defined mission statement, I frequently didn’t know what I was expected to accomplish" - James Mattis -

    Prikaži ovu nit
    Poništi
  19. 30. ruj 2019.

    The irony of my appsec awareness campaign for devs/qa being killed by management the day before Cyber Security Awareness month begins is not lost on me

    Poništi
  20. 18. ruj 2019.

    Been playing with fuzzing Java libraries lately with . I’m not super knowledgeable about the JVM or Java so mostly I’m learning that, instead of finding potential security issues. Gotta learn the basics before I can tackle bigger problems

    Poništi

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·