Video 3/3 (I feel this one •deeply•, to the bone):
“Developer watching QA test the product”
@python_discussions anyone who uses "simply", "just", "all you need to do is..." Has no idea what another person will need to do to solve an issue... Their experience will not match what others will have to do. I've seen it happen too often for that not to be a rule... #programming #infosec #cybersecurity
In discussing the Biden administration’s new #CyberSecurity Strategy, @arozenshtein makes an important point:
Creating more secure software will increase costs(*). Fair enough, but let’s remember the other side of that equation: Insecure systems and insecure software are costing us billions right now.
* The processes needed to produce secure software have significant other benefits which will offset the cost.
So of the six control categories four of them almost sound like two each. Preventive and deterrent sound like they should be grouped together. Same goes for corrective and recovery.
I’m sure the material will draw a cleaner distinction but I wonder if it’s really there or we’re creating too much. If corrective is to “fix components after an incident occurred,” how is recovery not a form of corrective?
It just feels like we’re creating complexity for the sake of it sometimes. #infosec #cissp
I created an #Expensify account, and Expensify sent me in-app message saying my company uses Expensify, gave me the option to join an existing team as well as the team name, the billing owner’s name and email address. I’m not affiliated with that company. I didn’t click “Join Team” so I don’t know what would happen. I will delete my account b/c they shouldn’t give out that info to a stranger. Would you email that team owner to notify? Inform Expensify?
All the worst fears the pearl-clutching "privacy tech has gone too far" crowd says about the architects of such systems are 100% correct: it is designed to frustrate law enforcement, because of *checks notes* hundreds of years of state repression against poor, labor, peace, indigenous, and black power movements for basic human dignity and fairness. I thought this was obvious? #privacy #history #signal #opensource #encryption #infosec
I like to use computers to solve problems. Problems might include anything from analyzing DNA from genomes to protecting sensitive data from prying eyes.
My other interests include:
- Contra dancing (a U.S. folk dance) #contradance
- Kendo (a martial art)