RSS Amplifier

Blog

Breanne Boland

Appsec engineer, SRE, writer, UX, endless questions mostly

breanneboland.comSource feed ↗10 posts

Dormant Last read · last published · next check
Read 4 days ago and current, but nothing has been published for 17 months.

Latest posts

Threat Modeling Meets Model Training: Web App Security Skills for AI for BSides 2025

This is the blog post component for my talk at BSidesCharm, BSidesSF, and BSides Dublin. Video to come. AI enthusiasts and those who create LLMs sometimes create a sense of exoticism around LLMs and AI: it s so different, it s so innovative, it s a completely different paradigm of computing. Well: yes and no. Yes, there are Continue reading Threat Modeling Meets Model Training: Web App Security…

BSides SF 2023 talks!

I contributed two talks to BSides SF 2023. The first, with Amy Martin: No Adversaries: Getting Users on Your Side for Tough Transformations. The second: New Apps, Good Snacks: Effective Threat Modeling for New Territory, featuring a dizzying array of kawaii food art, which I got from Mount Pleasant Designs on Etsy. Decks for both Continue reading BSides SF 2023 talks! The post BSides SF 2023…

BSides SF 2023: New Apps, Good Snacks: Effective Threat Modeling for New Territory

This is the blog post version of my other BSides SF 2023 talk. Yes, I m tired. Video to come. Slides are here. Threat modeling is all about approaching a new product, system, or situation and evaluating it with fresh eyes. Dev and product teams get immersed enough in what they re building that excitement and familiarity Continue reading BSides SF 2023: New Apps, Good Snacks: Effective Threat…

BSides SF 2023: No Adversaries: Getting Users on Your Side for Tough Transformations

This is the blog post version of my talk with Amy Martin, Project Manager, SF Digital Services, on April 22, 2023, at BSides San Francisco. Video to come. Slides are here. Every security initiative has two sides. One is purely technical: we need to prevent abusive emails from getting into company inboxes with a product, Continue reading BSides SF 2023: No Adversaries: Getting Users on Your Side…

Diana Initiative 2022: How to Become a Security Partner (and Why You Should)

In which I give you lots and lots of links around being a security partner The post Diana Initiative 2022: How to Become a Security Partner (and Why You Should) appeared first on Breanne Boland .

BSides SF 2022: Read the Fantastic Manual

This is the blog version of my BSides SF 2022 talk, Read the Fantastic Manual: Writing Security Docs People Will Actually Read . I ll embed video here when it s available. If you came here from my conference talk: hello! I m glad you re here. Let s talk documents. Every company needs them, and security in particular needs to Continue reading BSides SF 2022: Read the Fantastic Manual The post…

Hello, AWP 2022!

If you re here, it might be because we talked and I gave you one of my shiny business cards. Here are some useful resources for knowing more about what I m doing. The posts on this blog are typically about my work as an SRE and then as a security engineer. Read on if you want, Continue reading Hello, AWP 2022! The post Hello, AWP 2022! appeared first on Breanne Boland .

PancakesCon 3: CLI Server Surveillance and Writing Your First Novel

This is the blog component of my PancakesCon 3 talk on 16 January 2022. Video to come. My monthly writing newsletter lives here. Part one: CLI Server Surveillance This part of the talk concentrates on CLI tools that enable OSINT: Open Source INTelligence gathering. This is when you use publicly available information to learn more Continue reading PancakesCon 3: CLI Server Surveillance and Writing…

Diana Initiative 2021: The System Call Is Coming from Inside the House

In which we compare internet security issues with a bevvy of scary things in the interest of people better remembering how to find and fix them. The post Diana Initiative 2021: The System Call Is Coming from Inside the House appeared first on Breanne Boland .

Day of Shecurity 2021: Intro to Command Line Awesomeness!

Updated: now with video! First, the important stuff: here s the repo with a big old markdown file of commands and how to use them. It also includes my talk slides, which duplicate the markdown (just with a prettier theme, in the way of these things). Second: I went to the Lookout Security Bootcamp in 2017, Continue reading Day of Shecurity 2021: Intro to Command Line Awesomeness! The post Day of…