CISO at @sardineai. Treasurer of @OWASP Board of Directors. (he/him) qatta' mIghtaHghach.

Phoenix, AZ
Joined July 2009
Replying to @HelenNegre
And here’s how that strategy turns out IRL. jdsupra.com/legalnews/ftc-da…
1
Why would a church need a police force vs just using a security contractor? Reportable crimes can now be sent to their own police force, who in turn can decline to press charges due to lack of evidence. No more church scandals! npr.org/2019/06/20/734591147…
Why hotel safes are bad: a short video.
18
311
22
701
0
W3C is looking for feedback on their latest accessibility draft of "Inaccessibility of CAPTCHA" lists.w3.org/Archives/Public…
Related, I saw the first five minutes of The Great Muppet Caper at a drive-in. The double feature started with E.T., which we watched, but when the Muppets opened with the hot air balloon and singing, my dad was done and drove off. That’s why I don’t live in Hollywood. #scarred
1
2
If your company is collecting sensitive personal information, you better have a documented information security program.
FTC Data Security Settlement with Auto Dealer Software Provider Goes Further than Ever Before : no reasonable security to personal information belonging to its customers and employees ; and lack of an information security program jdsupra.com/legalnews/ftc-da…
Replying to @iMeluny
Awesome, thanks!
1
Bil Corry retweeted
RT @whitequark: you’ve heard of “he uses 2048-bit RSA, so hit him with this $5 wrench until he tells us the key” but did you know it works on microchips too eprint.iacr.org/2018/717.pdf
1
12
16
Replying to @iMeluny
Are the dives safe for newly certified divers?
1
You can learn scripting or you can target roles that don’t need it (there are lots). Some security roles require little-to-no technical skills at all. Don’t believe the gatekeeping bullshit on Twitter. Anyone interested in security can find a way in then pivot as they learn more.
1
1