Skip to content
← home

tag

#security

106 posts

The technical heart: vulnerability research, disclosure, threat analysis, the craft of finding and fixing

Security

7 Years and counting…

In 2012, Bugcrowd set out to create a radical cybersecurity advantage and level the playing field between attackers and defenders. As one of the

16 May 2019 · 1 min read
Security

My moves during the RSAC/BSides SF circus

Quick post re where I’ll be speaking and attending while the infosec/cyberz are in town for RSA Conference and B-Sides: ps

02 Mar 2019 · 1 min read
Security

Managing smart device risk: A "how-to" for the average human.

I’m going to provide a practical, ubiquitous, and risk/benefit focussed version of the advice in the tweet, aimed at the average Internet citizen who wants to take advantage of these technologies, while understanding how they can minimize the risks that come with their use.

20 Jan 2019 · 5 min read
Security

Making noise

“We had a problem with a few needles, and as an industry decided that the best thing to do was to drop a haystack

31 Aug 2018 · 1 min read
Security

What's in a name? Defining "hacker" in 2018

If you do a Google Image Search against the word hacker, you’ll get images of scary-looking balaclava-clad cybercriminals hunched over a

25 Jun 2018 · 2 min read
vulnerability-disclosure

Thoughts on the vault7 CIA/Wikileaks disclosures

Wikileaks’ release of thousands of confidential CIA documents today is yet another demonstration of our just how vulnerable the cybersecurity domain is. Unless we

07 Mar 2017 · 2 min read
Security

My cybersecurity predictions for 2017

If 2016 did anything for cybersecurity, it was to prove that truth can end up wayyyyyyy stranger than fiction (where fiction, of course, are

19 Dec 2016 · 1 min read
Security

Solve 99% of Your Infosec Problems with this One Weird Trick!

99% of good infosec is equivalent to remembering to wash your hands after you use the bathroom. As an industry, we should be working to make that easier.

31 May 2016 · 1 min read
Security

Pain of staying the same > Pain of change = Change

Cybersecurity has long been a challenge lead from the top down, but as heat increases in the consumer market and hacking becomes dinner-table conversation at non-geek dinner-tables, I wonder...

21 Mar 2016 · 1 min read
vulnerability-disclosure

On the U.S. Government and bug bounties

My favorite thing about going to conferences is establishing the underlying trends behind the questions I’m asked. We’re only half-way through

06 Mar 2016 · 3 min read
Security

3 years, 20,000 Security Researchers & 200 Clients later...

2012 was the year that almost every industry, banking, education, government, big tech and even security, was hacked. Many, if not all of these

08 Oct 2015 · 3 min read
vulnerability-disclosure

disclose.io — Driving safety, simplicity, and standardization in vulnerability disclosure.

disclose.io is a collaborative and vendor-agnostic project to standardize best practices around safe harbour for good-faith security research. The project expands

22 Jul 2014 · 1 min read