Tag

Learn

Processing experience into insight - retrospectives, lessons

Personal

My "office" setup

As WFH was going from novel to normal, the thought occurred to me that "virtual semiotics" was quickly going to become a thing... The equivalent of the how to dress, where to sit, how to speak type advice executives get taught, but for a world which is virtual by default.

By Casey Ellis · 28 Mar 2021
Policy

NIST: Vulnerability Disclosure as a Requirement for Every Organization

What is the NIST Cybersecurity  Framework? The NIST Cybersecurity Framework is a set of policies meant to help the private sector in strengthening their cybersecurity r

By Casey Ellis · 08 Mar 2021
Policy

Responsible Disclosure Programs with Katie Moussouris & Casey Ellis | 401 Access Denied Ep. 22

Katie Moussouris, Founder & CEO of Luta Security and Casey Ellis, Founder & CTO of Bugcrowd join Joe and Mike to talk all things responsibility disclosure – the good, the bad, and the ugly.

By Casey Ellis · 26 Feb 2021
Policy

Establishing asset ownership in vulnerability reporting

The thing I see people get wrong most frequently in vulnerability reporting is being able to answer the question of ownership and "where to report my findings." Here are some practical tips for establishing ownership and thereby identifying the appropriate coordinator to contact.

By Casey Ellis · 22 Feb 2021
Policy

Modes of Public Vulnerability Disclosure

A proposed taxonomy... Discovery, Documentation, Distribution.

By Casey Ellis · 20 Feb 2021
Security

A thought re vulnerability research clustering

The fact that insecure software pipelines are exploitable feels a little like the idea that bugs exist in old F/OSS code, or that a chip design might not be 100% perfect. It's almost QED - but in the defensive realm, people weren't looking there.

By Casey Ellis · 10 Feb 2021
Security

Help! My Social Media has been hacked!

I know you do security stuff with computers and my Twitter/Facebook/Instagram/etc has been hacked! It's posting all kinds of strange stuff that isn't from me. What do I do to stop this???

By Casey Ellis · 11 Jan 2021
Personal

Outrage is cheap

Outrage is cheap and of fleeting value. Introspection and change are expensive, precious, and resilient... and very easy to miss if everything is the other guy’s fault.

By Casey Ellis · 09 Jan 2021
Personal

2020 Lernings for Make Benefit Glorious Year of 2021

My family and I are straight-up blessed with how we've fared this year, and I'm incredibly thankful for the myriad of people and things - but whichever way you cut it, 2020 was a dense and challenging year and not one I’d rush to repeat.

By Casey Ellis · 31 Dec 2020
Security

Van Buren v. United States — Oral Argument

The Supreme Court heard oral argument in Van Buren v. United States, a case concerning a statute of the Computer Fraud and Abuse Act (CFAA) and violations of terms of service agreements.

By Casey Ellis · 01 Dec 2020
Policy

DEF CON endorsed by POTUS!

Great news everyone: After years of steady work and deliberate improvement of relationships and trust between the hacker community and government officials, we've made it to the apex of the American org chart!

By Casey Ellis · 14 Nov 2020