I have another new paper out with the Canadian Global Affairs Institute about the Canadian Armed Forces Cyber Forces, this time specifically about CAFCYBERCOM.
https://www.cgai.ca/th_pp_everything_you_should_know_about_caf_cyber_command
I research and publish on Canadian cyber defence policy, with a focus on CAFCYBERCOM. CGAI/Triple Helix & NAADSN Fellow.
Carleton University PhD(ABD): State behavior, doctrine, and force structures of cyber conflict.
I run Canadian Cyber in Context: cyberincontext.ca
| Bluesky | https://bsky.app/profile/cyberincontext.ca |
| CGAI Fellow | https://www.cgai.ca/Alexander_Rudolph |
| Linktree | https://linktr.ee/alexfrudolph |
| Website | www.cyberincontext.ca |
I have another new paper out with the Canadian Global Affairs Institute about the Canadian Armed Forces Cyber Forces, this time specifically about CAFCYBERCOM.
https://www.cgai.ca/th_pp_everything_you_should_know_about_caf_cyber_command
I have a new oped out with Digital Journal. I argue that in the face of vibecoding and AI's impact on software development, the Canadian government needs a secure-coding. Luckily, @SheHacksPurple already has one: https://www.ourcommons.ca/petitions/en/Petition/Details?Petition=e-7115
The latest Canadian Cyber in Context Canadian Cyber News Rewire is now out. I bring together cyber-related news concerning Canada from the past week. A lot is going on, including a new data centre, Bill C-22, and phishing emails to journalists with IP tracers.
https://www.cyberincontext.ca/p/canadian-cyber-news-rewire-210326
My new article on the history of the Canadian Armed Forces cyber defence program is finally out! Come read the paper that the Canadian Security Intelligence Service was too scared to publish.
Canadian Program for Cyber Security Certification (CPCSC) is going to really disrupt Canadian defence procurement. It is the Canadian CMMC. My friend Andrew, a CMMC and compliance expert, wrote a good introduction for SMEs.
https://www.cyberincontext.ca/p/compliance-is-cash-where-to-begin
The Government of Canada hints at where it is taking sovereign cloud with the latest updates to the RFI.
https://www.cyberincontext.ca/p/canadian-government-provides-next
My latest paper about the Canadian Armed Forces and its efforts to achieve digital transformation and pan-domain capabilities.
The CAF has started its most important force and doctrinal change in decades, and few realize it.
I was invited by @VVX7 to speak in the @PreludeSecurity Discord on June 22 at 7 PM EST.
I'll be giving my talk "Global Affairs? In my Threat Model?" on ways to understand threats in global affairs.
Some of you may remember this talk as "Everyone is wrong about Cyber Warfare (Except me)."
I have since expanded on this talk and will specifically be discussing how to understand the role of global affairs in risk/threat models.
Looking forward to seeing you there! http://discord.gg/fZbfdUQM4A
Ah yes, another high profile bug bounty forcing non-disclosure — even for fixed bugs.
🤦🏻♀️
It’s the bugs they won’t fix that will put users at risk.
All orgs need a vulnerability disclosure program that doesn’t ban Disclosure.
But what do I know.
I just coauthored the standard
#GPT
“But it’s a bug bounty & they are paying so it’s fair to ask for non disclosure”
That’s fine if everything submitted is paid work, like a penetration test.
Oh, only paying selectively & only the first of any duplicates?
That’s labor abuse & the worst gig economy deal out there.
“But pen tests don’t get you all the eyeballs”
Neither do bug bounties - you get a random number of eyeballs willing to sign NDAs.
If orgs actually care about security, they cast as wide a net s as possible to get the best researchers - especially those who won’t sign NDAs.
“This is better than no bug bounty”
No, it isn’t.
It breeds a false sense of security for users & the org itself, while actively excluding the highest skilled researchers who will never sign an NDA for speculative pay or who want to see the bugs FIXED as their motivation.