CISO at @sardineai. Treasurer of @OWASP Board of Directors. (he/him) qatta' mIghtaHghach.

Phoenix, AZ
Joined July 2009
@ADP I thought it was well-known at this point, but can you ask your CISO to read this article then put in a feature request to remove forced password rotation outside of evidence of compromise? Kthx! ftc.gov/news-events/blogs/te…
Replying to @mkonda
Let me guess, their contract did not offer a warranty. It's (not?) surprising how many security contracts disclaim suitability and performance of their product/service. I always insist they either warrant their product or allow immediate termination if it fails.
1
Replying to @frgx
I’m reminded of the time that I created an endorsement of “Babysitting” for @jeremiahg. I’m pleased to see it’s still there #lulz
2
Bil Corry retweeted
Are you looking for a career in cybersecurity or interested in advancing your career, we invite you to join OWASP at our February 2022 Career Fair! Learn more and REGISTER TODAY owaspcareerfair.vfairs.com/ #cybersecurity #devsecops #infosec
16
34
Replying to @jasonhuck @m8urnett
Or maybe the class action lawsuit will change their mind.
1
1
Replying to @m8urnett
Did you get a notification from Google about the need to upgrade? I checked and I don't have anything from them yet. Crazy that all of their paid plans are "Business" when clearly there are thousands of people using the legacy free tier for personal use.
1
1
Replying to @m8urnett @hillbrad
I saw that a class-action lawsuit is being considered. androidpolice.com/google-gsu…
1
Replying to @billamend
I loved Marathon. There's an open-source version if you're into it. alephone.lhowon.org/
Bil Corry retweeted
Is it one of the best (if not the best) article I read about K8S networking ? Yes it is !!! learnk8s.io/kubernetes-netwo… by @learnk8s
1
36
118
Super random, but TIL that railroad workers don't pay into Social Security, they have their own retirement program called RRB. en.wikipedia.org/wiki/Railro…
I show this “juice jacking” video as part of my security awareness training. Then laugh and tell my audience that NO ONE calls it juice jacking. da.lacounty.gov/community/fr…
1
I'm teaching a course based on my "Security Engineering" book for masters students and final-year undergrads. The first two videos are now online, and open to all: lightbluetouchpaper.org/2022…
7
124
11
309
Don't rely on obfuscation to protect you. The show thought it was fraud. No, the guy memorized all of the prices. Never assume people won't take the time to figure out your system. Obfuscation only works against the lazy. youtube.com/watch?v=HdFKZtZo…
1
Replying to @jasonhuck
It wasn’t great. But the worst lazy cash grab this year is Transylvania 4. It’s essentially an overly-long Saturday morning cartoon.
Most people hang up on scammers, but this guy befriended him. cbsnews.com/news/how-a-scam-…
Apparently I'm in expert in bicycles. 🤔
2
Whippersnapper
1
1