Skip to main content

Posts

Showing posts from 2016

What's the point of (InfoSec) Certifications?

Quite recently, my GSE was up for renewal. I'm currently in the middle of transporting my family to another continent and I've slightly more responsibilities work-wise in 2016 versus 2012. However, given the effort and study that it took to get the cert the first time (and to a lesser degree the expense), I figured it was a no-brainer to renew. For me, I've always been a huge fan of the GSE and considered it the epitome of InfoSec certifications, much like the CCIE for (Cisco) networking. Personally, I learn better by "doing" and consider it as the evidence that someone knows their stuff so the "2-day lab" element in the GSE was a both a huge goal and challenge that I was excited about. I talked about the value of "doing" when trying to learn about yourself previously here with the infamous Security Ninja and here on my own blog so there's no point in repeating myself. When I did the GSE, I absolutely loved the hands-on lab mo

Being the Bug in Bug Bounty :: Fail & Tell

Late in December 2015, I sent the email below to all of "Engineering" across Riot Games. I want to share this externally because it's core to the security culture that we want to build in Riot, i.e. one of accountability and responsibility, where we aren't afraid to talk about our screw-ups. ############################################################ Hey Folks, So as most of you know, I'm a bit of a perfectionist with high standards :) Well recently, I screwed up and didn't come close to meeting my own expectations. What did I do? Well, when testing (locally) Netflix's Security Monkey in 2014, I copied over some aws-related scripts I was using and found useful to a local directory on  my work laptop, where my Github repo was stored. I also mistakenly copied over a flask configuration file ( config-deploy.py ) from the local version of Security Monkey that I was testing at the time. To compound this mistake, prior to committing file

Reading List

At BruCon last year, one of the audience came up afterwards and started asking about the books that I read. He was fascinated by some of the books that I'd mentioned in my talk (massive surprise to me) so I promised to publish a list on my blog. Granted it has taken me around 7 months but I've started to compile such a list on Good Reads, now I just have to find out who it was :-/