Tag

Security

The technical heart: vulnerability research, disclosure, threat analysis, the craft of finding and fixing

vulnerability-disclosure

Thoughts on the vault7 CIA/Wikileaks disclosures

Wikileaks’ release of thousands of confidential CIA documents today is yet another demonstration of our just how vulnerable the cybersecurity domain is. Unless we do a be

By Casey Ellis · 07 Mar 2017
Security

My cybersecurity predictions for 2017

If 2016 did anything for cybersecurity, it was to prove that truth can end up wayyyyyyy stranger than fiction (where fiction, of course, are end of year prediction pieces

By Casey Ellis · 19 Dec 2016
Security

Solve 99% of Your Infosec Problems with this One Weird Trick!

99% of good infosec is equivalent to remembering to wash your hands after you use the bathroom. As an industry, we should be working to make that easier.

By Casey Ellis · 31 May 2016
Security

Pain of staying the same > Pain of change = Change

Cybersecurity has long been a challenge lead from the top down, but as heat increases in the consumer market and hacking becomes dinner-table conversation at non-geek dinner-tables, I wonder...

By Casey Ellis · 21 Mar 2016
vulnerability-disclosure

On the U.S. Government and bug bounties

My favorite thing about going to conferences is establishing the underlying trends behind the questions I’m asked. We’re only half-way through RSAC/BSides week, and alrea

By Casey Ellis · 06 Mar 2016
Security

3 years, 20,000 Security Researchers & 200 Clients later...

2012 was the year that almost every industry, banking, education, government, big tech and even security, was hacked. Many, if not all of these companies were doing “all”

By Casey Ellis · 08 Oct 2015
vulnerability-disclosure

disclose.io — Driving safety, simplicity, and standardization in vulnerability disclosure.

disclose.io is a collaborative and vendor-agnostic project to standardize best practices around safe harbour for good-faith security research. The project expands on th

By Casey Ellis · 22 Jul 2014
Security

Bugcrowd — the Premier Crowdsourced Cybersecurity platform.

Bugcrowd is the premiere crowdsourced security platform. More enterprise organizations trust Bugcrowd’s Crowdcontrol platform to manage their bug bounty, vulnerability di

By Casey Ellis · 31 Aug 2012
Security

Sms Scams – What Can Be done?

First things first… If you receive a spam SMS you should forward the message to the Australian Media and Communications Authority Spam SMS service on 0429 999 888. I rec

By Casey Ellis · 26 Jun 2012
Security

Sms Scams — What Can Be done?

First things first… If you receive a spam SMS you should forward the message to the Australian Media and Communications Authority Spam SMS service on 0429 999 888. I re

By Casey Ellis · 16 Jun 2012
Security

mysqlcheck.com – in Ur mysql, Checking ur… mysql.

Check out this website by Mark Wickendam. Let it be said first up that I think this site is awesome. I lol’d hard, visited it again, lol’d hard again, and so on. As o

By Casey Ellis · 11 Jun 2012