Fix It One Level Deeper

- 2 mins read

The Concept

Recently I read a great article called Try to Fix It One Level Deeper by Alex Kladov, in which he discusses a unique (to me) approach to squashing software bugs. Instead of just fixing the bug at hand, Alex encourages the reader, and his team to dig one level deeper. Really determine why the bug exists at all. Is this parameter really being mishandled? Or should we even be asking for this parameter?

2024.08.27.News You Should Know

- 4 mins read

Series: News You Should Know

Hardware Backdoor Discovered in RFID Cards Used in Hotels and Offices Worldwide (thehackernews.com) - Hardware backdoor means even with appropriate controls, threat actors can still attack hotel and office doors around the globe. The FM11RF08S backdoor enables any entity with knowledge of it to compromise all user-defined keys on these cards, even when fully diversified, simply by accessing the card for a few minutes.

Alerting

- 2 mins read

So You Want To Build A SOC

Or How To Lose Your Mind In 10 Weeks

A number of companies I’ve worked for have security tools in place, but they’re almost always half-configured, half-utilized, and no one has a good idea what’s missing or what should be there. Luckily, there’s a solution, or at least a tool that can help us move towards a solution.

Troubleshooting

- 5 mins read

Troubleshooting

A Quick Primer

The Back Story

A friend called and requested some assistance with her electrical. She had moved into a new (to her) house recently and she feared the electrical had gotten the landlord/flipper special. Spoiler turns out she was right, at least to a point. And now one of the circuits in the kitchen was no longer working. I don’t know if you’ve ever tried to cook in the dark but its not a pleasant experience.

Thoughts for a New Leader

- 8 mins read

Series: Management

What follows is a list of thoughts crafted in an airport terminal in San Jose, California hours after completing my first attendance at the RSA Conference. This also happens to be the anniversary of my first year as a people leader in the security engineering space. (I had previously mentored and led soldiers in the US Army and in various other civilian industries including Optical Lens Manufacturing and Operational Incident Response.)

RSA Day 3

- 7 mins read

Series: RSAC 2024

(Posting this a day late as I was crazy exhausted yesterday after walking nearly ten miles! I literally laid down in the room at 22:30 and woke up at 04:30 still in my clothes, lights on, etc…. I think I was effectively conferenced out, and that was only Day 3!)

RSA Day 2

- 7 mins read

Series: RSAC 2024

Today was a great opportunity to see what RSA was all about. We walked over early to get badges and get checked in. The conference provided us with a decent swag pack, an RSA branded bag, water bottle (something I hadn’t been able to find at any of the airports along the way), a notebook, a pen, a shirt, and for newbies, a “First Timer” pin.

Today was a travel day to RSA 2024. It started off simple enough, boarding at my municipal airport, then a puddle jumper to the nearest metro-airport, Atlanta.

Luckily, as if there wasn’t enough anxiety around Boeing aircraft, our initial plan was inoperable and a secondary plane had to be found delaying our flight. Considering Boeing’s in the business of killing whistleblowers this week, and they make roughly 90% in Delta’s fleet (Atlanta is Delta’s home turf) it didn’t look like I was going to make it west on a non-Boeing flight.

Hello_World

- 1 min read

Hello World

Welcome to my little slice of internet freedom.

I hope to start moving a number of my writings here and making this a comfortable place for musings, software configuration guides, security issues and the like.

After all the fight I had to get Hugo, Alpine, Proxmox, Nginx, and LetsEncrypt configure, this better be worth the trouble. Then again, is anything ever really? If anything I learned a hundred ways to not do things and thats got to be worth something.