tag
#hot-takes
Short-form takes — quick reactions and sharp one-liners.
Systems, not bugs
The folk doing really cutting-edge vulnerability research right now: if you peel the paint off how they're doing it, it'
Security is an afterthought, and that's economics
There are some black pill truths around security (the "nothing's ever going to change" kind) that need to be reconciled.
I can just do stuff
Personally, I'm hacking on stuff again. With AI in the toolkit it feels kind of like the early 2000s in some ways:
The law matters less than the legal team
I'm not a lawyer, and if I was, I'm not your lawyer. With anti-hacking laws there's a
The hackers weren't lying
A lot of what's actually happening right now is people realizing that, no, the hackers weren't lying this whole time.
Fixing everything is a fool's errand
Vulnerability management is a bit of a fool's errand if your goal is to make sure that everything's fixed. We&
Root is the product
For those of us on offense, root (full control of the target) is the product. If we're just doing pure offense, that&
We think like that because we're like that
People in security greatly overestimate the ability and the propensity for people to think like bad guys in the way that we do. We
You don't kill a bug by finding it
I've never really believed that you just kill a bug by finding it. This is the guy who started Bugcrowd, so I
A convict colony thing
Australia has always punched above its weight from an offensive security standpoint. I think it's a convict colony thing that just shows
You get to choose your hard
Being known for what you're against is easy. Being known for what you're for is hard. You get to choose
It's con season
It's con season — Black Hat, DEF CON, and the summer security-conference circuit are nearly here. The best research of the year