can someone who knows about cybersecurity please help me?
I am currently microblogging on Mastodon: @jd7h@fosstodon.org.
2026 2025 2024 2023 2022 2021 2020 2019 2018 2017 2016 2015 2014
I was wondering if there will be a difference in popularity of talks on Twitter during and after the #34C3 conference. Turns out the difference between last year's top 10 is significant! For #33C3's list, see https://gist.github.com/jd7h/810cb22b2ae8044845a2a08b310e6104
I've turned off image loading in my browser for a scraping job, but now I'm seriously considering leaving things this way.
The top 10 of #34C3 talks has been updated to include tweets from the last days of congress. https://gist.github.com/jd7h/30de3cc1c48a1cf1affd2e2b0bbe4a67
Replying to @alicegoldfuss
I like to understand patterns in systems and the system of myself is no different.
Like last year, I made a top 10 of #34C3 talks, based on the number of tweets that refer to them. Here's the list based on tweets from the first few days of conference: https://gist.github.com/jd7h/30de3cc1c48a1cf1affd2e2b0bbe4a67
Absolutely loving the traveling library of @hacklibrary at #34C3. Great selection of books: from Terry Pratchett and science fiction classics to the yoga sutras, books on political science and cryptography. #deadtreelovers
In Tibet, distances were traditionally measured by the number of cups of tea needed for each journey.
In that case, the distance to #34C3 should be measured in the number of caffeinated drinks needed for the journey. ;) https://twitter.com/qikipedia/status/946383989845217281
"Please implement your own crypto. Just don't use it for anything." Seems like a decent message @dsp6s
My favorite Christmas song of 2017 is @PTXOfficial's Mary Did You Know. https://www.youtube.com/watch?v=I5PyLwNZvhQ
So how is everyone's Christmas Day so far? :D
Replying to @jd7h
Well done, Twitter. A perfect placement of a tweet from @EffinBirds!
Rereading the Harry Potter books this Christmas and I just noticed spare time at Hogwarts is comprised of boardgames, sports, books and visiting people for tea. No music, movies, tv-series or video games.
Netflix's #BrightMovie Is A Terrible Movie. Please Don't Watch It. via @Forbes by @ScottMendelson http://www.forbes.com/sites/scottmendelson/2017/12/22/netflixs-bright-is-a-terrible-movie-please-dont-watch-it/
TIL the word "mockbuster". https://twitter.com/ScottMendelson/status/944221011280580612
Thread with a happy ending https://twitter.com/mzbat/status/943158113137577984
YES because there are NEVER enough Jo March influences in my life. https://twitter.com/goodreads/status/943186697721991168
In January, I will be starting my new job as a PhD candidate at @UTwente on the topic of natural language generation.
Charlie and the “Zero day” factory https://twitter.com/levibroderick/status/941397359086280704
We used predictive keyboards trained on all seven books to ghostwrite this spellbinding new Harry Potter chapter http://botnik.org/content/harry-potter.html
This is why we need natural language generation. There will never be enough Harry Potter chapters. #nlg https://twitter.com/botnikstudios/status/940627812259696643
Here's this week's newsletter. :) http://mailchi.mp/fe7d8af82fe0/on-killer-robots-korra-and-appreciating-comics
Grim Fandango Remastered is *FREE* on @gogcom right now. If you haven't played it yet, holy hell you really should https://www.gog.com/
I have an internet connection again (YAY FIBRE) so this week's newsletter goes out tomorrow. Sign up here: http://eepurl.com/c-Q53D
A list of common SSIDs. Apparently, HOGWARTS is very popular. https://www.wigle.net/stats#ssidstats
When in doubt, FLOUNCE https://twitter.com/emilyscartoons/status/917127129598394368
Yes, we're having a black friday sale :) $5 Shodan Membership instead of $49 and it will run from Friday through Monday
Played Zork (1980) w/ @mrngm over the weekend, after we heard a reference to the game in an episode of The Big Bang Theory. Text-based adventure games ftw!
Interesting part of the book ART & FEAR about a pottery class and how focusing on quantity sometimes leads to better quality: https://www.amazon.com/exec/obidos/ASIN/0961454733/wwwaustinkleo-20/ref=nosim/
CUT PACKETS INTO PIECES
THIS IS MY DEFAULT PORT
FRAGMENTATION
NO STREAMING
DON’T GIVE A PING IF THE SIZE IS EXCEEDING
Replying to @veelasha_m
@veelasha_m @tarah My training and certification exams were paid by my employer.
My talk proposal about Markov Chains was rejected, so that means the talks at #34C3 will be EVEN MORE AWESOME than the one I had in mind, right? ;)
In last week's newsletter, I wrote about gritty comics, hand-drawn presentation slides and a vintage video game! Read it here:
http://mailchi.mp/42805a756327/back-to-vintage-video-games-comic-books-and-hand-drawn-slides ft. @b0rk @heikala_art
Posting this so others are reminded it is okay to fail. CFP to 34c3 declined. Can't win them all. Just try, try again!
Had lots of fun talking to the @Radboud_Uni and @TUe_MCS students today. Slides (with links to career advice and infosec challenges) are available here: https://judithvanstegeren.com/assets/1711-incident-response-toolkit-sio-slides.pdf
Awww yiss, my first newsletter is scheduled. *Excited
This week, I talk about bad-ass women in space (and where to find them) and christmas songs to dance to. Sign up here: http://eepurl.com/c-Q53D
@mrngm for your email footer? https://twitter.com/effinbirds/status/929061377356042246
Apparently, newsletters are the new Twitter. Join my quasi-weekly supercerebral non-sensical FUN newsletter here: https://eepurl.com/c-Q53D
If you regularly want beautiful art in your timeline, be sure to follow @heikala_art! https://twitter.com/heikala_art/status/894759933358383105
My next research project in 4 comic panels. #nlg #textgeneration https://twitter.com/WholesomeMeme/status/928623469335646208
File disclosure vulnerability in OpenOffice. "The vulnerability is mitigated by the need for the attacker (...) to trick the user into saving the document and sending it back." Srsly, this got a CVE-ID? http://www.openoffice.org/security/cves/CVE-2017-3157.html
The Twitter app on my Mac still hasn’t updated to let me write 280, and I’d be perfectly happy if it never did.
Only just realised I need to update my Python3 Twitter bots! https://twitter.com/nmeans/status/928643615072706562
Next week, I'm giving a presentation on incident response for computer science students of @Radboud_Uni and @TUeindhoven. Here's a sneak peek. #DFIR
"Assume you will be breached. Invest in detection and response agility". Words of wisdom from @malwareunicorn at Blomberg's #TheYearAhead
This is fascinating @mcdemarco's http://www.mcdemarco.net/blog/2017/10/27/history-of-choice-mapping/
Surveys the various methods over time by which authors have constructed choice maps for crafting interactive text -- all of it applicable to historical text making
PhD position in automated formal analysis of security protocols, http://www.cs.ru.nl/J.deRuiter/vacancy.html
Application deadlline: 12 Nov 2017
Anyone with a Dutch library membership can get the book "I, robot" for free this November, thanks to @NederlandLeest. Cool!
I laughed so hard at this commercial. #blessed
https://www.youtube.com/watch?v=bh19YxASA-4
This is what #STEM is all about! Meet the pioneering Women of @NASA in LEGO form! 👩🚀🌛 #LEGOIdeas #LEGOWomenOfNASA
Introduction to haiku. I hope to find a good saijiki (dictionary with seasonal words) in Dutch or English one day.
https://www.youtube.com/watch?v=VJHCGPp4G4k
Criteria voor het bepalen van nieuwswaarde. Handig voor wetenschappers die aan media outreach willen doen! #scicomm NL
Trying to improve my understanding of The Media as a technical/scientific expert with this interesting reading material. #scicomm
Replying to @jd7h
With special thanks to @ionicasmeets for recommending this book in Het Exacte Verhaal.
“Like a government diverting money from defense to education, humans diverted energy from biceps to neurons.” -Yuval Noah Harari (Sapiens)
Replying to @joelcox
@joelcox Verder bevatten de factsheets van @ncsc_nl veel best practices op technisch en organisatorisch gebied, zie https://www.ncsc.nl/actueel/factsheets
Replying to @joelcox
@joelcox Arnoud Engelfriet kan veel juridische zaken vaak helder uitleggen. Zie @iusmentis en https://blog.iusmentis.com/tag/gdpr/
Replying to @joelcox
@joelcox GDPR heeft veel facetten dus dit is een brede vraag. Op welk vlak? Organisatorisch/technisch? Ligt er ook aan wat MKB nu al heeft ingericht.
Happy #AdaLovelaceDay ! A worldwide celebration of women in science, technology, engineering and maths #womeninSTEM
Life advice for people in tech... ermmm, I mean everyone. https://jvns.ca/blog/answer-questions-well/
The #34C3 CfP ends on Sunday. Now is the time to make your entry: https://events.ccc.de/2017/09/19/34c3-call-for-participation-and-submission-guidelines/ Remember: There is no reason to be shy :)
Read this and then determine what YOU want out of your smart phone or social media. https://www.theguardian.com/technology/2017/oct/05/smartphone-addiction-silicon-valley-dystopia
Replying to @ohmaipie
@ohmaipie Love your inktober drawings! You inspired me to make one of my own. ^^ Looking forward to seeing the rest of your creations on twitter.
@jakeparker Can you tell me the name of the font you used in the official inktober prompt list? Thanks.
Replying to @ohmaipie
@ohmaipie What media did you use? Black ink and paint brush or something else?
This article has some fun suggestions for coming up with new blog post ideas: https://thenextweb.com/contributors/2017/09/29/13-ways-come-fresh-content-ideas/#.tnw_DWy1jgM0
Yay, my first #hacktoberfest pull request was merged! This is a good post for easy pull request ideas: http://vaibhavsagar.com/blog/2017/07/31/easy-pull-requests/index.html
The Open Movie DataBase (OMDB) is no longer open: you can't access the API without paying $1 per month. *sadface
Oh noes, now the White Walkers have puppies too! #GoT https://twitter.com/cutebabyanimals/status/914665967300485120
Investigating Security Incidents with Passive DNS, by @xme https://isc.sans.edu/forums/diary/Investigating+Security+Incidents+with+Passive+DNS/22886
Want to join #hacktoberfest but not sure where to start? Read @b0rk's article: https://jvns.ca/blog/2017/08/06/contributing-to-open-source/
#youcandoit #opensource
Support open source this October and earn stickers or a T-shirt from @digitalocean and @github https://hacktoberfest.digitalocean.com/ #hacktoberfest #FOSS
Just blogged: Roger (python tool) monitors changes in HTTP status codes #OSINT https://judithvanstegeren.com/blog/2017/roger-osint-python-tool-for-monitoring-http-status-codes.html
Here is a fun exercise to learn Python and Scapy: extract the picture from the following PCAP https://tuftsdev.github.io/DefenseAgainstTheDarkArts/labs/secret.pcap
We need more exercise material like this. https://twitter.com/0xmchow/status/915228533554925570
So please, oh please, we beg, we pray
Go throw your TV set away
And in its place you can install
A lovely bookshelf on the wall… ROALD DAHL
Today is a very special day: I just opened my 42nd git repository! HUZZAH!
Twitter forensics from the 2017 German election, nice research bij F-Secure #OSINT https://labsblog.f-secure.com/2017/09/25/twitter-forensics-from-the-2017-german-election/
Yay, I submitted my proposal for a talk on fun with Markov Chains for the #34C3 CFP! And now we wait... *fingers crossed
Did you know that "netsh wlan show profile" shows every network your computer has ever connected to? And "key=clear" shows the *passwords*?
I think you accidentally a word. https://twitter.com/qikipedia/status/913629411722846209
Here's a thought, Twitterverse: Before you respond to an inflammatory tweet, consider whether you're being used/trolled. Breathe. Ignore.
A Jane Austen-themed game from the maker of Second Life! This appeals to my inner historian. https://www.theguardian.com/books/2017/sep/28/ever-jane-reader-i-clicked-on-him-i-test-drive-the-virtual-jane-austen-role-playing-game
The easy way to analyze huge amounts of PCAP data http://i5c.us/2fB1G50
Replying to @ASmallFiction
@ASmallFiction Brevity is the soul of wit.
Replying to @annejanbrouwer
@annejanbrouwer @mrngm @whvholst @McAfee Good idea!
Sent from my iPhone
"I plead with you to make science fiction into science fact, and make the impossible possible" - Bolden #IAC2017
The Matrix, 2001: A Space Oddysey, Planet of the Apes, Alien and Jurassic Park are all science fiction movies. https://twitter.com/spacekate/status/912983848782147585
Replying to @rsinha
@rsinha @angealbertini The rest of the code is scraping the CCC Fahrplan and some dataset cleaning.
Replying to @rsinha
@rsinha @angealbertini An implementation of Markov chains is already open sourced as one of my github projects: https://github.com/jd7h/andrey
Hey, at least PowerShell commands will fit in Twitter now.
Interesting article about the consequences of instilling a fixed mind-set vs a growth mind-set in children.
https://www.scientificamerican.com/article/the-secret-to-raising-smart-kids1/
Push for gender equality in tech? Some men say it's gone too far. http://nyti.ms/2hmZjDn
Next week: Is vaccination bad for society? We interview several strains of polio that say it's gone too far https://twitter.com/nytimes/status/911651916584759296
Replying to @okoeroo
@okoeroo Oh yes, especially when you insert "blockchain" or "cloud".
If you're getting 401 errors from the Twitter streaming API, check your system time. Twitter won't push tweets if your clock is wrong.
I'm falling in love with NLTK's part of speech tagger. I use it to get random adjectives and nouns from a corpus and play with them.
I'm using Markov chains to generate talk abstracts for the #34C3 CFP. Some of the outputs are hilarious and/or quite believable.
Replying to @jd7h
"Most robots out there are things you won't need to specify the behavior of iptables in terms of bigstep semantics."
Replying to @jd7h
"Who is flagged as a dreaming machine opens a security update to fix the EU's vulnerabilities."
Replying to @jd7h
"How large and pervasive the impact on an ARM microcontroller that has an unfortunate reputation of evoking a raw dystopia..."
Replying to @jd7h
"A lightning talk attempts to gain an open virtual machine learning to remotely install persistent code, incentivized by scientists."
Replying to @jd7h
"This talk discusses the world's largest platform for various IPv6 in space agencies fixed by our solar system to accommodate our research."
"Hold the newsreader's nose squarely, waiter, or friendly milk will countermand my trousers." https://www.youtube.com/watch?v=ZFD01r6ersw #language #linguistics
Just watched Hidden Figures, about the women of colour that computed for the NASA in the 60s: a beautiful, important and inspiring movie.
Replying to @strangelykatie
@strangelykatie Looking forward to more chapters! Also we need moar tea dragons.
If you like webcomics, pastels and tea, be sure to read The Tea Dragon Society by @strangelykatie at http://teadragonsociety.com
Replying to @qikipedia
@qikipedia What about 'Henry', 'Edward' and 'George'?
A Botched Black Bag Job Reveals the Long Arm of Chinese Intelligence. Physical security is information security. https://worldview.stratfor.com/article/botched-black-bag-job-reveals-long-arm-chinese-intelligence
Event Blog: 34C3: Call for Participation and Submission Guidelines https://events.ccc.de/2017/09/19/34c3-call-for-participation-and-submission-guidelines/ #CCC
Timeline for the #34C3 Call For Participation:
Sep 19: CFP open
Oct 15: CFP closed
Nov 19: Notification of acceptance
Dec 27: Conference! https://twitter.com/ccc/status/910264840240889856
Event Blog: 34C3: Call for Participation and Submission Guidelines https://events.ccc.de/2017/09/19/34c3-call-for-participation-and-submission-guidelines/ #CCC
Replying to @ilthea
@ilthea Good luck! I just passed mine. :D Maybe this article in which I describe my learning method can help you: https://judithvanstegeren.com/blog/2016/how-I-prepared-for-my-GIAC-GPEN-exam.html
"Click publish because you have something to say, not because you have to say something."
Replying to @CinisSec
@CinisSec @cyberdomein "Humor" is natuurlijk breed te interpreteren :p
Just blogged: Digesting difficult books with @RyanHoliday's reading method.
https://judithvanstegeren.com/blog/2017/digesting-difficult-books-with-holidays-method-for-reading.html
Best geek test evah and awww yish I scored 48%. http://www.innergeek.us/geek-test.html (via @SecBert)
Replying to @hacks4pancakes
@hacks4pancakes @MalwareJake @sansforensics Thanks for the tip (and the stories) ;)
Replying to @jd7h
@jd7h There is an open @DFRWS challenge currently running ...
This looks like a REALLY cool digital forensics challenge! You can participate until feb 2018. More details here: http://www.dfrws.org/dfrws-forensic-challenge https://twitter.com/Fr333k/status/905441246969286656
Replying to @WriteSpeakCode
@WriteSpeakCode @sailorhg @b0rk @codecartoons "@freeradblog" seems to be a dead link -- is there a typo in there somewhere?
Looking for challenges, puzzles, wargames, and permanent CTFs to practice the skills I learned in the SANS Digital Forensics course. Ideas?
@MalwareJake @hacks4pancakes @sansforensics Any ideas? #DFIR https://twitter.com/jd7h/status/905409028683157504
Replying to @ickyphuz
@0xhanz Do these have /forensics/ challenges? Not really looking for 'break this' challenges, but more 'find evidence of activity X'.
Looking for challenges, puzzles, wargames, and permanent CTFs to practice the skills I learned in the SANS Digital Forensics course. Ideas?
Replying to @jd7h
@jd7h There is an open @DFRWS challenge currently running ...
Replying to @jd7h
This website has some great digital forensics puzzles, by the way. I also like the way they choose a winner. http://forensicscontest.com/puzzles
Replying to @jd7h
This is the back of the cover of "Wonder Women" by Sam Maggs and Sophia Foster-Dimino.
Yay, I just passed my GCFA exam (forensics and incident reponse) with a score of 87%, thanks to training from @MalwareJake and lots of prep.
We are entering a new age of automation, unlike anything that's come before. https://www.youtube.com/watch?v=WSKi8HfcxEk
Spoons address the problem of conveying liquid from bowl to mouth (...). How is your idea like a spoon? https://medium.com/civic-tech-thoughts-from-joshdata/so-you-want-to-reform-democracy-7f3b1ef10597
Check out @Kiva loans- small loans to people around the world helping them to generate further income for themselves and their families
I've been using @Kiva for years (even as a student) and I absolutely love it. If you're not yet giving to charity, be sure to check it out. https://twitter.com/LydiaBenedetta/status/900049176469405697
Replying to @mboelen
@mboelen This is the timeline for last year. I'm planning to send in two proposals for #34C3. I've teamed up with some friends for feedback exchange.
Timeline for the #33C3 Call For Participation:
Sep 1: CFP open
Sep 30: CFP closed
Nov 14: Tweets with "Yay, my talk was accepted!"
For those who are considering sending in a talk proposal to the CFP for #34C3: https://twitter.com/jd7h/status/903595778291245058
Timeline for the #33C3 Call For Participation:
Sep 1: CFP open
Sep 30: CFP closed
Nov 14: Tweets with "Yay, my talk was accepted!"
This page by @lara_hogan is SO cool: "Eating a donut is an integral part of my career celebration process." http://larahogan.me/donuts/
Productivity in terrible times: "Know that the tufted titmouse has never even heard of the electoral college." https://superyesmore.com/productivity-in-terrible-times-709d4b3127d845e2d090bf94f0b93263
So... my nonverbal "algorithm assembly instructions" might actually grow into a larger project – a webcomic? A book? Some rough prototypes:
StarCraft is a high speed time machine! ...Unfortunately, it only goes one way: to the future!
Puzzle for Saturday-afternoon: write a one-liner in bash to find out which words have the highest amount of i's and j's. https://twitter.com/mrngm/status/901486012731457536
BTW you get bonus points if you turn this into a bash scripting contest with your significant other. https://twitter.com/jd7h/status/901489852411256833
Replying to @mrngm
@mrngm cat [yourwordlisthere] | awk '{print split($0,a,/i|j/)-1 "\t" $0}' | sort -n
Zaterdagmiddagprogrammeerpuzzel: welke NL woorden hebben het hoogst aantal i en/of j letters?
Puzzle for Saturday-afternoon: write a one-liner in bash to find out which words have the highest amount of i's and j's. https://twitter.com/mrngm/status/901486012731457536
Aww yisss, putting some extra effort in my GIAC GFCA exam index really paid off! I feel so ready for the exam now. ^^ #DFIR #SANS #GIAC
@WriteSpeakCode Are the talks recorded? I couldn't participate in the conf but would love to see some of the talks. :)
Just finished my GIAC Certified Forensics Analyst exam index -- I ended up with over 350 entries. Time for the last practice exam! #dfir
“Follow the campsite rule and leave tech better than you found it.” #wsc2017conf
You say I cannot write
A poem right and true
To Twitterlimits tight
But I say Hold my beer!
Composing without fear
There's nothing I can't d
This person wins the #SE pretext game today https://m.imgur.com/gallery/USjnb
Replying to @btwsl
@btwsl You were a crying infant, once. You might have a crying infant, someday. #dwi
Home decoration style advice for ladies, 1896. https://www.gutenberg.org/files/26368/26368-h/26368-h.htm#CHAPTER_XIII #downtonabbey
@computistic @sailorhg And if you want to learn by implementing crypto and then breaking it, there are the cryptopals challenges. https://www.cryptopals.com
My talk at @SHA2017Camp is online, fastest of all venues! "An academic's view to incident response" https://www.youtube.com/watch?v=4vSmr2H_u_Y #sha2017
Replying to @sailorhg
@sailorhg How many pins did you make for the first run?
Yay, I finished my crawler/scraper/tokenizer project today at #sha2017! I'll upload the code to https://github.com/jd7h/adjutant after refactoring.
A SEO Expert walks into a bar bars tavern alehouse pub public house alcohol beer liquor whiskey
I just realised I really need a 3D printer before moving to a new apartment. https://twitter.com/nickf4rr/status/891579698643382272
Picard management tip: Conducting an experiment with an unknown outcome is time well spent, even if the result disappoints you.
Replying to @jms_dot_py
@jms_dot_py @OSMOSISCon Thanks! I've been to some infosec conferences but OSINT talks are not something I encounter a lot. Any infosec confs you can recommend?
@jms_dot_py Are you aware of any OSINT-focused conferences that are interesting for techies specifically?
Machine Learning for security monitoring leaves analysts with more time to take action. http://www.darkreading.com/analytics/machine-learning-in-security-4-factors-to-consider/d/d-id/1328704
Love exploring words, language and concepts? Addicted to browsing a thesaurus? Try this website: https://wordassociations.net/en/words-associated-with/security
So I made this drawing after reading Daring Greatly by @BreneBrown. I might release it as a colouring page with Meteoriet Design later.
Begone with your old-fashioned 30-day password expiration notices and special character constraints! https://www.troyhunt.com/passwords-evolved-authentication-guidance-for-the-modern-era/
'Coding like a girl' (by @sailorhg) is worth reading. I make some of the mistakes mentioned in here too. https://medium.com/@sailorhg/coding-like-a-girl-595b90791cce
How NOT to make a fantasy book cover, the 12-step guide. https://thoughtsonfantasy.com/2017/07/18/how-to-make-a-cliched-high-fantasy-cover/
This philosophical essay about work and leisure should be titled "The 4-hour workday". http://www.zpub.com/notes/idle.html
I have surpassed my GoodReads challenge of 32 books by reading 33 books this year. Now what am I going to do with the rest of 2017?
@Android Is it possible to get the monthly security bulletins as an xml/csv file?
Replying to @erwinkooi
@jd7h And remember that "promotion" does not mean up the mgmt ladder. Promotion is a shift to a job where you can learn new things.
Replying to @nmeans
@nmeans I have yet to see serendipity as a performance metric.
Now I find it strange that sometimes creativity and innovation are used as a performance metric. https://twitter.com/robdew/status/889958904804855809
Just blogged: Things I learned after 18 months of working. https://judithvanstegeren.com/blog/2017/things-i-learned-after-18-months-of-working.html
I found out there's a #SHA2017 lecture on state machines/type theory and now I'm doing a little dance in my chair. https://program.sha2017.org/events/342.html
How to build a racist classifier without even trying: https://gist.github.com/rspeer/ef750e7e407e04894cb3b78a82d66aed
Threat indicator of the day: "Mini cats", ie. little kittens dumping hashes and plain text credentials from memory. #threat #IOC
The "Break, learn, break, cry, break" routine. Nice blog by @roguelynn. http://www.roguelynn.com/words/Im-faking-it/
The user's going to pick dancing pigs over security every time. -Bruce Schneier
You can never remove all risk, but you can protect yourself as much as possible and mitigate risk to an acceptable degree. -Kevin Mitnick
The secret to strong security in computer software: less reliance on secrets. -Whitfield Diffie
Introducing the Humble Book Bundle: Cybersecurity by Wiley! Pay what you want for tech ebooks and support charity!
https://www.humblebundle.com/books/cybersecurity-wiley?utm_source=Twitter&utm_medium=Link&utm_campaign=Cybersecurity_Tech_Books_Announce
This Bundle contains the security classics. Nice range of topics: social engineering, physical security, crypto, forensics and reversing. https://twitter.com/humble/status/887009268003725317
Just try to bust yourself gently of the fantasy that publication will heal you. It can't. It won't. But writing can. -Anne Lamott
I've been inking a drawing and ZOMG I HAVEN'T BLINKED IN FOUR HOURS
Replying to @btwsl
@btwsl None, because "we" are too busy meditating?
"Python2 is for those that live in the past, Python3 is for those that live in the future."
DARPA used formal verification to make their Little Bird drone much more secure ("hacker-proof"). https://www.quantamagazine.org/formal-verification-creates-hacker-proof-code-20160920/
Book recommendations for Jon Snow: "Are you my mother?", "The Crow", and "All my friends are dead." https://www.goodreads.com/blog/show/966-what-would-jon-snow-read-book-recs-for-your-favorite-game-of-thrones-ch
If Gutenberg’s revolution was Pandora 2.0 and the Industrial Revolution 3.0, then the information age is Pandora 4.0. -Stephen Fry
Only one day left to the conclusion of the challenge https://h1702ctf.com/ #h1702 Happy last minute hacking!
I'm really looking forward to the writeups! I might learn a thing or two about mobile reversing. https://twitter.com/hacker0x01/status/885948291032199170
If you ever need to write a company newsletter, don't forget to look at this page: http://dilbert.com/search_results?terms=newsletter
Every writer you know writes really terrible first drafts, but they keep their butt in the chair. -Anne Lamott
OH: "The code for this project looks like a bunch of drunk monkey got together to write code on typewriters."
You are Not an Impostor by Nickolas Means (@nmeans) https://www.youtube.com/watch?v=l_Vqp1dPuPo
Social-engineering-as-a-Service to get victims to give up their PIN codes. https://motherboard.vice.com/en_us/article/3knz98/dark-web-site-robocalls-to-steal-credit-card-pins
Even if a security-minded programmer erases all passwords from memory, they might still be floating around in RAM because of the OS.
"Work hard, but don't rush." Career advice from George Monbiot. http://www.monbiot.com/career-advice/
It's OK to:
- ask for help
- not know everything https://twitter.com/gilest/status/735131901900521472
Replying to @electricdusk
@dsp6s In the Hague there are plenty of spots where you can buy milk tea!
"Threat intelligence sharing: what you don’t know can hurt you" by @McAfee describes the challenges of sharing CTI.
https://www.mcafee.com/us/resources/reports/rp-quarterly-threats-mar-2017.pdf
What can developers learn from being on call? by @b0rk - https://jvns.ca/blog/2017/06/18/operate-your-software/
Replying to @AnneliesvN
@AnneliesvN I'll return soon enough, for the party of the year! ;)
I will improve my machine learning skills with the Stanford Machine Learning course on Coursera, starting today! https://www.coursera.org/learn/machine-learning/
Here we go! We are just oiling the last gear wheels and soon we will open the DECT registration!
It's open! https://poc.sha2017.org/ https://twitter.com/sha2017poc/status/882340969932345344
Duck typing in security: Does it look like a duck? Does it walk like a duck? Does it hack like a duck?
Reserve an out-of-band communications channel for your Incident Responders, as business comms might have been compromised as well.
"Do not react too quickly to an incident by pulling the plug. We need to move towards intelligence-driven incident response."
By popular demand, my Twitter mass-backup-and-unfollow Python script can be found here: https://gist.github.com/jd7h/02094c6e1a79b1ee069635a452d7b0e7
Incident response to the rescue! Now for sale in my RedBubble shop. :)
https://www.redbubble.com/people/meteorietdesign/works/26156559-incident-reponse-to-the-rescue
I made this shirt design for all those awesome infosec Incident Responders out there. They are, after all, superheroes. Who you gonna call?