We can fix it. We have the technology. OK. We need to create the technology. Alright. The policy guys are mucking with the technology. Relax. WE'RE ON IT.
I'm increasingly thinking that every functioning system has two forms: The abstraction that outsiders are led to believe, and the reality that insiders actually and carefully operate.
You don't incrementally learn a system. You eventually unlearn its necessary lies.
OH:
The Keanu Reeves Four-fold Path:
Bill & Ted: Be excellent to one another.
Speed: do not engage bad faith actors on their terms.
The Matrix: Step out of your worldview and listen to those doing the work toward revolution.
John Wick: Destroy those who delight in cruelty.
Active shooter drills are child abuse, in a uniquely awful way. I worry this particular security theatre manufactures the active shooters it’s supposed to be managing.
Kids learn what you teach them. You don’t always know what they learn.
It would take a while to find out.
This video is fantastic *documentation*:
“Hi. You might have this problem. You will think of this solution. It will be wrong. This is what the right solution looks like. I am going to do this right in front of you. Here is how you will test that you’re doing it right.”
If somebody helped you — always feel free to let them know. They may not. Really.
There is no statute of limitations on being thankful. Years, decades, doesn’t matter. Now is always a good time.
Best when you don’t need them for any reason.
Notice the helpers.
Banning kidnapped children from hugging isn't even Nazi shit.
It's Dolores Umbridge shit.
There's a reason she's the most feared and despised character
@jk_rowling
ever created. Kids know Voldemort isn't real.
It’s genuinely exhausting seeing Twitter get raged against for making a very, very hard call, correctly. Stop it, or nobody will ever do anything not aggressively legislated as a requirement.
"Well you see, it's not really kidnapping, their parents shouldn't have..."
You take a baby, you take a toddler, you take a seven year old, you drag him away from his mom, he doesn't know what bullshit you tell yourself to sleep at night. He knows he's being KIDNAPPED.
"Cybersecurity is a game in which you get to make the rules. You are under no obligation to play fair; it's *your* *network*. You *get to cheat*."
This, more than anything else, is what offense knows implicitly but defense is always *gobsmacked to hear*.
YOU GET TO CHEAT.
You are never, ever too “junior” to talk to anyone in Infosec. There’s no bar you must pass, talk you must give, code you must write before you’re qualified to nerd out with someone. Anyone. Really.
Trust me, the “famous” nerds miss the heck out of you.
@SwiftOnSecurity
We’d written this proper HTML filter. Whitelist — not approved,not allowed.
<b starts a bold tag. ✅
<i starts an italic tag. ✅
<div starts a div tag. ✅
<3
isn’t a tag. Tags don’t allow numbers. But I didn’t allow <3 as text.
And that is how I broke every heart on MySpace.
Tech.
@jack
.
Stop it. This wasn't cool, even *when* we were still cool. This is how we *stopped* being cool.
It's like going to a restaurant and having the waiter disagree with your order. Dude, this is not a negotiation.
Amazing time-lapse footage of a day in the life of a pair of pot plants. Plants are so much more active than we usually imagine! We don't notice, though, because they move in slow motion (or, from the plant's point of view, we move in crazy fast motion).
Wait wait wait
Could a country ban Bitcoin mining
And then claim
To have eliminated over half their emissions
Thus meeting all their reduction targets and not needing to do anything more
Would that work
Asking for a global superpower
@SimoneGiertz
It takes a while.
You get more minutes back, every day or so. Less than you'd like, more "or so" than you'd want.
Parts of Simone are making friends with other parts of Simone. Or perhaps, catching up. It's been a while. There's been a lot of...moving.
We can wait.
Also, this guy is choosing very intentionally to experience a painful thing such that others might experience less pain, less panic, less death.
Good man. Role model. Hero.
Citizen of the world I would like to live in.
@SimoneGiertz
That is an amazing and brave photograph. Bracingly honest. This is you. Rebuilding.
Just realize you are the world expert here. You did you. Nobody else did, nobody else could, nobody else will. Some guys showed up with bulldozers, but you're the architect.
Simone 2.0.
You can’t vouch for your own bug. You will always see it as the most beautiful bug that ever did bug. Doesn’t matter if you’re the one who does the thing, or even if you’re right. If it needs a vouch, recuse yourself. It’s ok. It’ll hold up on its own, or not. Learn either way.
no malware
fully password compliant
never clicked a bad link
all required patches applied
secure against literally all known and unknown 0day
best defense, no be there.
Banning a kid from hugging?
He knows he's being KIDNAPPED by people who MEAN HIM HARM.
We're not even dumb enough to do that to prisoners, because prisoners know how to riot.
Ok, so. Microphones are speakers, if you run power in the other direction. Doesn’t sound great, but it does a thing.
LEDs are solar panels, in exactly the same way.
In fact — solar panels are LEDs too. Run em backwards, they glow.
Hacking is mostly ignoring the directions.
Close. AI has plenty of doubt (most models can return probabilities for any prediction, if you configure them to).
The problem is humans, not doubting the AI enough to notice when it doubts itself.
It’s a tool, and it matters how you use it.
The data showed Prozac no more effective than getting a dog. Somebody said this meant Prozac doesn’t really work. No, it means dogs actually work. They want you to live. It’s contagious.
Welcome to why the placebo effect is real, and why it gets stronger the harder we fight it.
I once asked my dad, a Stanford cardiologist, for the single greatest piece of advice he gave his transplant patients. He didn’t skip a beat: “I tell them to get a dog.”
Law is a lot more ex post facto, and he-who-has-the-gold-makes-the-rules, than it would appear.
Medicine is a lot more "just distract the patient till the body fixes itself".
Microprocessor behavior is determined, on other things.
Global PKI is a lot more DNS than it appears.
@owltastic
This happens partially because your contact then has to explain to his manager that he overpaid everyone else.
Yes! Ask for more money. Also, build networks where you can ask people what they’re getting. Heroes are rare, often people will just assume you know you’re bad at this
There is only one Actually Bad Idea.
"You must be perfect. To fail once is to be exiled forever."
I see this concept, this burden, this prediction in people, systems, and sometimes myself. I have never seen it be useful or true, ever. Not once.
You get to fail. How you learn.
@SimoneGiertz
Next week, we're still here.
Next month, we're still here.
Next year, we're still here.
We'll be here, when you're here. Laughing. Hysterically.
I have no idea at what.
Probably a Brian Catapult.
This thread is absolutely a love letter to everything I’ve treasured, being an Infosec nerd. A *lot* of people were kinder than they had to be. I’m proud to say I did everything I knew to return the favor, and not ashamed to admit I didn’t always know how.
But I can document :)
The perfect gift for the ranch-obsessed grad 🎓, customize your own Hidden Valley Ranch bottle for your special graduation occasion! Graduation never tasted this good.
Get yours here TODAY:
#HVRLove
💚
Interesting research on creating synthetic fingerprints that can match a large number of real fingerprints. These would be Master Prints, just like we have Master Keys for locks.
#GAN
The most useful bit of corporate wisdom I ever learned was:
Disagree and commit.
Fight your fights, make your stand, play your play, but once a decision is made, even a “lesser” one, commit.
Your mission is not to fight some forever war.
Only works under good faith.
To be very clear: That complex systems have abstractions isn't a surprise to me.
It's that any system in which you _haven't_ had to unlearn half your assumptions, isn't a system you've learned in the first place.
At least for systems of any complexity.
If you’re thinking of mocking
@elonmusk
for developing tech that might well treat Parkinsons, Epilepsy, Senility/Dementia, even Depression:
Well, you can join Team Cervical Cancer and Team Measles. Targeting is *the* problem in chemical systems, it’s why we evolved nerves.
I support trans people.
Not because I am one. Boring old straight white guy over here.
Not because I have trans friends. I do — watched several transition, at great difficulty, and finally become genuinely comfortable in this harsh world. I wish I could do that, glad they did.
If somebody wants to nerd out with you in the hallway at con, unless you *absolutely* have to be somewhere — they are the most awesome person in the world at that very moment. Doesn’t matter if they’re competent or not. Does matter if they’re curious!
Explore. Yes, you get to.
There’s a culture war going on, and it’s come for tech. Be sympathetic. Nerds aren’t supposed to be bullies, but we sure took everyone’s lunch money. Journalism got defunded, and “user generated content” is not enough.
But don’t forget that tech can be fun and useful. Some do.
And here's the thing. I know this is an administration *built* on the non-obvious benefits of making people angry, *designed* around the sort of performative rage in this very tweet.
I know it demonstrates how powerful they must be, if they can ignore dissent this widespread.
Build things, regularly. Especially things that have nothing to do with security.
Nothing will make your skills go stale faster than *only* breaking stuff. You will stop knowing what things to break, or how they imagine the world works.
This is a problem. We make poor tools.
Uber paid $100K to protect 57M people?
Good.
I think people forget the goal is actually to prevent harm.
Yeah, those hackers could totally have kept the data. But then, their identities were known, and they knew they might face consequences.
Not ideal, welcome to the real.
A small number of high level nerds eventually get high enough in business to wonder
how the hell is anyone still in business
and the answer is
they’re often not, we just hide that with m&a and reorgs and such
“metrics fixation leads to a diversion of resources away from frontline producers toward managers, administrators, and those who gather and manipulate data.”
Power is what you take, minus what others take back.
The idea in democracy is the more you overstep, the greater the alliance forms against you, and so the easier it becomes to restore normal order.
In reality, it only takes the solid support or indifference of a few to win.
The war is against burnout. Don’t forget that. Money does not cure burnout. Be kind to yourself, don’t think working for yourself doesn’t mean your boss can’t be an asshole. You’d assume. You’d be wrong.
Under no circumstances share a hotel room with another consultant.
Heh. Nobody’s as happy as they look. Best I can tell, everyone’s on fire.
Lots of ways to burn.
Protect your curiosity. Seek it in others. You’re not “supposed to already know”...anything. That’s the fun of hacking. Pawing around in the darkness, discovering accidental beauty.
The worst is when you’re trying to solve some obscure ancient and serious problem
And you google
And the only links that come back
Are your own
...
And you didn’t solve it back it in the day either