Tarah Wheeler

10.6K Followers
60 Following
1.7K Posts
♦️ CSO of TPO Group ♦️EFF Board Of Directors♦️US/UK Fulbright Scholar in Cyber Security ♦️ Formerly Harvard, Brookings, Splunk, Symantec. ♦️she/her curmudgienne♦️standard disclaimer regarding personal opinions.♦️Searchable. t AT tarah DOT org

In defense of Reviewer 2.

Dear Reviewer 2: Reviewers 1 and 3 snarked uselessly. You, however, did a damn fine job giving me actionable changes, sight reading the missing recall stat from my own graph, pointing out what it meant to my theory, and making my work better. Thank you.

Love, someone going to the conference and who has a brand new peer-reviewed publication thanks to your "weak accept". I ain't proud; I'll take it.

Be gay.
Do crimes.
Post about being gay.
DO NOT POST ABOUT DOING CRIMES.

It's quite simple.

i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with [email protected] or similar.

The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

And yes, all of those emails contain the actual PII of the person who has been 'deleted' :-D

#infosec

I dream of a place where there are pedicures that don’t hurt, aren’t ticklish, where the tech understands “I have recently had ingrown toenail surgery; please don’t cut the side of my nail bed”, and no one uses a drill or gets irritable or mad at me when I tell them not to file my skin til it bleeds.

What is the name of the version of a pedicure I want, and why are pedicures so damn miserable and overstimulating and stressful? Getting my eyebrows done isn’t pleasant but at least there is no mass social hallucination that it’s supposed to be a relaxing experience.

Just tried to translate “Whatchu talkin’ bout, Willis” into French in my head but lost count of all the “q”s. #ShowerThoughts
Helping out some of my kids’ friends with tech, and once again am reminded that domestic abuse is absolutely the flagship threat model in this industry, the place the victim is closest to real physical harm and has the least recourse and resources available to them. The hardest problem, almost totally unaddressed, exaggerated when the victim is underage.

Listen, if your kid trusts you enough to ask for a burner, help them. Wipe your old phone or find something cheap, teach them about threat models, private browsing and factory reset, then teach them how to teach these things to other people. The only question you need to ask is, is this for you or for someone else, and you don’t ask who or why.

You don’t need to make the first conversation perfect, you need to make the next conversation possible.

High five to everyone who has suffered from anxiety, burnout, and depression without even once stealing 0-days from their employer and selling them to the Russians. https://www.zetter-zeroday.com/trenchant-exec-says-he-had-depression-money-troubles-when-he-decided-to-sell-zero-days-to-russian-buyer-also-new-info-reveals-nature-of-his-work-for-australian-intelligence-agency/
The Sad Decline of Trenchant Exec Who Had Everything, Before Deciding to Steal and Sell Zero Days to Russian Buyer

Peter Joseph Williams, a former L3 Trenchant executive recently convicted of secretly selling zero-day exploits to a Russian broker, says he was suffering anxiety, burnout, years of depression, and financial difficulties when he decided to steal exploits from his US employer and sell them to the Russian buyer. Williams, who

ZERO DAY

#PennedPossibilities 980 Have you ever had your work plagiarized or stolen?

Yes: I'm a party to the Anthropic AI class action lawsuit. They'd plagiarized 28 out of 33 of my novels for AI training purposes, the fuckers. I'm looking forward to my payout (with the caveat that their out-of-court settlement is much lower than their maximum liability under US copyright law).