Hilton Head Rugby recently closed out our men’s XV 2024/2025 season. We had some wins, had some losses, had to deal with both hurricanes and ice storm related weather issues during it, ending the season with a playoff berth in our union. Along the way we’ve got the foundations of a great women’s XV team coming together, had a very successful first season of youth flag rugby…
This weekend I spent a few moments playing with some of the new generative ai engines that have recently been in the news so much lately. It’s interesting, and of course there is a ton of power there, much of it yet to be unlocked. For someone like me who’s been a big fan of procedurally generated content, from nethack to some approaches I’ve taken in testing and…
Almost a year ago since I wrote about my DNS filtering setup . I’ve enjoyed using that setup, but the interface into Cloudflare for teams wasn’t that friendly, and was clearly geared much more towards enterprise managemnt than end use. So over the last few weeks I decided to do a little redesign of my dns filtering system. I’ve heard great things about NextDNS , and so far it has…
Seasonal change has a way of making me feel reflective, and the transition from Summer to Autumn usually does it more than the others. This year it’s only amplified as I approach my forth decade. While I didn’t grow up on a farm, we were surrounded by fields. Whether it was the appearance of hay bales, the smell of peanuts being turned over to dry or the blizzards of cotton coming into…
These days I don’t get much time to write code. In a lot of ways Outlook and Zoom have become my most used Integrated development Environments, and my emacs sessions are much more likely to involve markdown for a slidedeck than code for a module. But, like I’ve talked about here before I still look at both my practical coding skills and theoretical computational science knowledge as…
Today I am thankful for the process, and the markers along the way. The last few months I have been working towards getting healthier. I realize that it is not something that is never going to end, but it is nice to celebrate doing the things that I’ve never done before. Today that thing was being part of an organized 5k, the ubiqitious Thanksgiving morning Turkey Trot, and the 40 degree…
Previously I talked about using command line tools for efficiency in Command Line Leadership . Since then I’ve changed my flow a bit. LaTex is a fantastic system, and Beamer is great but the templates didn’t have the right look. They were a bit too “academic” in feel. I’ve moved to using RevealJS instead. The included css has a bit more modern feel and is easier to…
Originally posted to LeadDev , duplicated here for archival purposes because Cool URIs don’t change . It is unlikely that any other activity will have nearly the same amount of leverage as bringing a junior engineer up to speed so that they can successfully contribute. This is often more easily said than done. While team leads should be accountable for ensuring that this happens, many…
The current state of the web is poor… at best. Ads and tracking are out of control and have moved from just being a minor annoyance to being a real detriment to my user experience, whether in a browser or an app. Worse the tools to filter these things are getting worse. They’re woefully underpowered for mobile and on desktops it seems that the filtering tools that they did have is…
Earlier this month I had the pleasure of being a guest on The Data Standard podcast. Catherine and I had a great conversation about data engineering vs application engineering and how they’re much more alike than different.
Being proficient with various *nix-style tools for working with plain text is a well known way to “level up” engineering skills. Efficiently using your editor of choice ( vim or emacs ), along with common command line tools like grep , awk , and less common ones like xxd and jq can lead to massive time savings. What a lot of people may not realize is that understanding how to use these…
I see fascinating levels of learned helplessness in so much software engineering articles/posts these days. Folks tripping over themselves to cede every bit of decision making to other parts of their businesses and make themselves into replaceable cogs. Deathly afraid to have to put their reputation behind a decision, more enamored with the quiet comfort of a scrum where they seldom have to worry…
Folks, if you’re not getting a good slate of talent it’s your fault. It is not hard for you as a hiring manager to send a note with a link to a job posting out to candidates that could be a good fit. Just because many recruiters/agencies take least effort path doesn’t mean you have to. $50/mo for the ability direct messages to a diverse talent market on a platform like LinkedIn should be either 1)…
We live in an era of scale. Most things in software have to be large to be interesting. We’ve seen the explosion of microservices, pipelines, and all sorts of other things. Those things can be great. But I cannot help but feel that growth in the number and complexity of the tools we use lead to many of us being too separated from the problems we’re trying to solve. Software, especially…
Earlier this month Luma was acquired by Newell (Fortune #208). Our team will be joining First Alert, Newell’s security and safety division, to build connected products under the OneLink brand. I’m excited that all of the engineers and product managers on my team will be coming along to Newell to make sure that our fleet of Lumas continue to be well taken care of. We announced the first…
This was the first time I was able to go to the Consumer Electronics Show, and it was an experience. Being able to see all the new products up close as they’re being announced to the world was awesome. There are some neat things out there, and the partnership conversations that happen inside of a single week are unbelievable. We’re on the right track with Luma. The connected home is…
Wow. Today we unveiled Luma, the project I’ve been working on for most of the last year. We’re going to completely change the way that people feel about their WiFi. We’re building on the mesh concepts that have been used in some enterprise and industrial uses, and bringing them into homes. And since our founding team all have a long history in cybersecurity they’ll be no…
While lacking the sex appeal of memory corruption based attacks, phishing remains a problem for many end users. Defenses against phishing have not advanced significantly in years. Mostly in boils down to more attempts to phish your own people. In this presentation I explored new approaches to detection using perceptual hashing.
While many of my colleagues were away at Blackhat, Defcon, and Bsides Las Vegas I decided to spend a day exploring through an Android app. I became interested in this particular app due to it being the “official” app of a popular web service that included some functionality not exposed to end users through the API that they’ve provided and this annoyed me, as I was reasonably sure that some…
While many of my colleagues were away at Blackhat, Defcon, and Bsides Las Vegas I decided to spend a day exploring through an Android app. I became interested in this particular app due to it being the “official” app of a popular web service that included some functionality not exposed to end users through the API that they’ve provided. I was reasonably sure that some spammers on this web service…
Over the last 24 or so hours theres been a lot of commentary on Twitter reitterating their policy that developers should not implement full twitter clients. This should have come as a suprise to no one, but seems to have kicked off a lot of ire in the dev community, nearly all of it misplaced, Yes, Twitter gained a lot in its early days from having a warm relationship with developers, and yes its…
Last night ruby stole back a few of those hours that it has saved me over the years, and made me feel like I was going just a little crazy in the process of doing it. So in the interest of documenting my failures and maybe saving you a few moments here’s a braindump of the events. I’ve been working on an implementation of a countsketch data structure for a stream consumption project I’ve been…
That old quote from Twain about the lie getting halfway around the world before the truth puts its pants on. Turns out the same thing happens even if the truth has a couple years head start. This week yours truly was mentioned in not only a foxnews.com entertainment article , but also perezhilton . Truly odd times. Anyways, just to clarify, I said as much as 20-25% of searches on…
The security community echo chamber was rocking hard over the weekend with news of an online backup/sharing service, Dropbox, changing its Terms of Service to grant them “worldwide, non-exclusive, royalty-free, sublicenseable rights to…” do basically anything they want with your content. From Dropbox’s point of view, this is the sort of thing that they claim they need to have in order to provide…
I still believe that the presentations and panels being selected for most information security events are much too far removed from the “roots” of the art. Often times to the extent that there is a full slate of presentations where most sessions turn out to be less glorified keynotes with little more than feelings, whether warm fuzzies or cold pricklies, to take home with them. This is a negative…
The question sounds crazy, especially for someone who’s spent a fair amount of the last year working on making spam and other malicious message detection on social networks better. But we do a disservice to tools geared for protection when we don’t think long term about the consequences of them. Does better spam detection on say twitter for example reduce the total amount of spam that…
The Facebook data team released some interesting data a few days ago focusing on the connectedness of their social graph, taking six degrees of Kevin Bacon and looking at how many connections away from each other any two people on the network are. From their research it seems like more than 90% of people on the network are seperated by only four degrees, meaning that any person A has a friend that…
Last week I had the opportunity to attend the first public planning/brainstorming session for the DHS seeded Open Information Security Foundation and their next generation IDS project. Lots of good discussion, with the first couple hours focusing on the foundation itself, and the rest of the day was spent discussing various features that would be required by the IDS and roughly prioritising them…
Following up my last post on fuzzing an unknown proprietary protocol, we’ve now got a collection of packet captures to start ripping through to get some semblance of a fuzzer going to send packets to our target. Theres a few routes we can go, something as simple as flipping bits and putting garbage data into the stream all the way up to building a network model. I’m not big on either of the…
Thanks to the near constant stream of “the sky is falling, these protocols aren’t secure” presentations at security conferences around the globe, everyone is familiar with mainstream ICS protocols, Ethernet IP, DNP3, and of course Modbus, amongst others. And of course it is important to make sure that these protocols are implemented correctly to assure that the devices supporting them function…
To a lot of you, this is post isn’t going to tell you anything you don’t already know, but for others I think it needs to be said again. MAC and IP addresses are easily changeable and are useless for authentication. Far too often when we’re on site we see security measures that rely heavily on them, and its something that we need to move away from in control systems. We need to decouple…
Code signing is a security feature that has been around for quite some time, and has been proven in many other areas, but is uncommon to find it in any control system component and very rare to find in control devices where firmware uploading is an important feature. Without a doubt the technology is useful, and provides a high level of assurance that the code running on the device is the code…
Dale Peterson and I demonstrate how using commonly available tools an attacker can learn how firmware is loaded into two different Programmable Logic Controller (PLC) Ethernet cards, write his own malicious firmware, and load that malicious firmware into the field device Ethernet cards.
This phrase was hammered into my head during an uncharacteristically interesting AI class during college (I later dropped the class, my hats off to those of you who enjoy writing search algorithms all day, I’ll never compete with you for a job), and it’s something that I remind myself of constantly when doing assessments. Much of the work of attacking systems is doing the dumb thing first, a…
This paper and accompanying presentation was first presented at Blackhat USA 2007 and DEFCON 15 (OX0F). Ben Feinstein and I explore the browser as an increasingly ubiquitous target for attacks.