🔒 Guest lectured again. Had to be remote because COVID. The professor has a habit of getting a shot when I have a funny line on the slides.

Last time I was doing code/bug examples and my slide said “what could go wrong?”

This one is talking about rules of engagement and responsible disclosure.

“I DONT WANT TO GO TO JAIL”

🔒 23andMe wants us to accept new terms that change their “Dispute Resolution and Arbitration” process. I wonder what might have spurred that change?

🔒 A Mental Model for Cybersecurity Operating Modes

A person in risk & security can generally be thought of as acting like one of the following:

  • Engineer
  • Analyst
  • Influencer

Interestingly (and helpfully), this is independent of official title. You’ve probably met engineers whose main operating mode is as the advocate, or leaders who act more like high-level analysts, or ops or risk analysts who focus on building capabilities.

Like all models, this has limitations, but it is useful. It can help you think about what’s missing, where strengths are, what structure should look like, etc.

H/T to David Ames who introduced me to this concept, though with a different name for the third role.

🔒 The presenter is handing out Security Buzzword Bingo cards for this next keynote. 😆

🔒 Spouse: “So, is the…shell4k doing better?” 😆

Note: the previous big deal vulnerability was Log4j or Log4Shell, the newer less-big deal was Spring4shell.

Week in Review 2021-12-10....err 2021-12-16

I started writing this on Friday the 10th, but am just now posting, because…

🔒 The Log4j issue is really bad. Security and engineering teams are scrambling to protect against attacks. The best teams started last week or weekend, but many organizations waited until Monday or later to get going. The vulnerability is once again hitting the hard problems of inventory management, 3rd-party software component management, and vendor management. I don’t think I’ve seen something this bad in 20 years of being a security practitioner. The vulnerability is easy to exploit, has the worst kind of impact (it runs the attacker’s code), and is present in many common technologies. In addition, there have been several follow-on problems identified, such as additional attacks, or weaknesses in the fixes for the attack! If you’d like a laugh instead of cry, check log4j memes.

⚽️ After a really great start to the Premiere League (where they were recently top of the table) and Champions League (where they are reigning champions), Chelsea are leaking goals and struggling at this point in the seasons. 3-3 vs. Zenit in the CL means they take 2nd spot (below Juventus), but are on to the round of 16 and matched up with Lille. They got a little lucky in the Leeds PL game to win 3-2, but tied 1-1 in what should have been an easy win at home against Everton.

🛩 I recently had my 2nd business travel since “the beforetimes”. I tested when I got back and am luckily safe. I welcomed my new team members (direct and indirect reports) and honed 2022 strategy with the leaders on my team. It was good getting people together, but still feels a little strange getting back to it! In other work news, I also got the promotion I had been hoping for, bringing me to only 1 to 2 levels below my internal customers and working peers 😆. (Outside my team, I primarily work with SVPs and VPs, and am now an AVP.) Joking aside, I am thankful for the support of my leaders, who have shown trust in me and helped find funding and assistance for the important initiatives I’ve been pushing.

📚 My spouse and I registered for a new library. To be honest, we mostly did it to have another library in Libby/Overdive, but it turns out the library is lovely, too. There’s no public funding in the town for a library and kids had to pay high fees to get access to a library in one of the neighboring towns. So, one family donated the land, funds for the building, and funds for the initial collection of materials. The library stays afloat with donations and a modest yearly fee for patrons. We were charmed by the library, especially their themed puzzle 🧩 collection that you can borrow like books!

🌟🎄 I’m looking forward to a break, soon. We’ll be hosting my spouse’s side of the family, again. All (who can be) are vaccinated (and boosted) and we will be testing before we get together. We have folks with compromised immune systems and/or who are too young to be vaccinated, but we are being safe for each other. We’re very much looking forward to time together, as there has been so little of that in the last two years.

🔒 Know any java developers or cybersecurity folks? Check in on them, maybe bring them some soup or something.

Sunday Quote 📚

Have you tried this method? 🔒