CISO at @sardineai. Treasurer of @OWASP Board of Directors. (he/him) qatta' mIghtaHghach.

Phoenix, AZ
Joined July 2009
This conference is amazing!
Tickets to the Layer 8 Conference go on sale tomorrow at noon EST! GA: $50 (includes lunch!) Or, you can buy a $60 ticket, the extra $10 goes to your choice of @HackersHealth, @TOOOL Boston or @InnocentOrg. We will also have Improv Workshops! Buy early!!
1
1
1
Bil Corry retweeted
@ngalongc, @EdOverflow, and I are starting a new security blog. In our first write-up, we will discuss the impact of "SameSite by default" and how it affects web app sec. Feel free to request future topics you would like us to cover. blog.reconless.com/samesite-…
11
209
9
407
Bil Corry retweeted
Great slide deck! This talk provides a data driven analysis of how accounts get compromised. Then it provides an in-depth overview of the defense we found effective at Google to protect users from account compromise. elie.net/talk/account-protec… @elie
1
2
11
Replying to @mdennedy
The upside, if you run for office and your motive is purely in the public interest, quid pro quo doesn’t exist. You can drive your Trump truck right through that hole to riches!
1
Replying to @realhamed
“Show a return or onward ticket” Irony: EU doesn’t want British immigrants.
1
Agreed. I’ve noticed that certs seem more important on the US East coast, perhaps due to more government contract jobs. I don’t have any certs either. For me, it’s not the effort/cost for the cert, it’s the ongoing costs and “earning” CEUs.
3
Yes, burnout and gatekeeping. Personally, I remove cert and education requirements from job listings and instead allow equivalent experience. That said, I do recognize that biased hiring practices means that some candidates show up with numerous certs to signal their expertise.
1
3
Not sure who needs to hear this, but have your kids skip taking the SAT/ACT and instead direct them to a university that doesn’t require meaningless gatekeeping tests. Community colleges are one choice, or there are more than 1k universities to choose: fairtest.org/university/opti…
As other research has found with the SAT, a new study shows the ACT is useless as a predictor - in this case, of college completion: is.gd/3t3YqM. There's simply no excuse for these tests, & forcing non-college-applicant HS kids to take them is even more outrageous
1
Bil Corry retweeted
Remarkable. Electronic patient records systems used by thousands of doctors were programmed to automatically suggest opioids at treatment, thanks to a secret deal between the software maker and a drug company. @emmarcourt reports. bloomberg.com/news/articles/… via @technology
146
2,829
835
2,994
Julia Stiles as the school newspaper’s cyberpunk editor-in-chief on a 1994 episode of ‘Ghostwriter.’ I will never get tired of this clip.
667
7,334
1,935
44,130
0
Bil Corry retweeted
How to detect if something tampers with your CSP:
Replying to @randomdross @we1x @ndm
You could include a script that gets blocked by your CSP. If the header is removed, it will execute and inform you.
1
3
Replying to @AskLyft
Thanks, but it’s already resolved.
1
I had a @lyft ride that was quoted at $29, but I was charged $64. Turned out the driver didn’t end the ride for over an hour after dropping me off. Lyft refunded the overage, but it’s a first for me. Guess I’ll pay closer attention from now on.
2
Replying to @LeaKissner
Personally, I wish the audience is released at the end of the talk and anyone wanting to stay for Q&A can.
Replying to @randomdross
Similar thought about this:
1
Travel hack, using the Do Not Disturb hanger as a peep hole cover. More generally, why don’t hotels have peep hole covers? Wasn’t the $55 million awarded to Erin Andrews warning enough?
1
Bil Corry retweeted
Y’all! Have you registered for our webinar?! Tuesday is Privacy Day and I’m so excited and honored to be on the panel with @deb_infosec and @mdennedy 🎉 bit.ly/2NvcfUM #infosec #privacy #WomenInSTEM
2
10
2
12
Sounds awesome, wish I could attend. Needs the tag line: “If you have to ask, guaranteed you will not like the answer.”
3
Replying to @iMeluny
<sarcasm> But they offer continuing education credits, they must be informative?
1
1