New blog: Free Threat Modeling Training for Displaced Federal Workers
US Government employees (and former employees) are going through a lot of chaos. Many of our colleagues, collaborators, and friends are out of work — suddenly and unexpectedly.
At Shostack + Associates, we can’t fix that. But we can offer something concrete.
In times of uncertainty, we focus on what we know, and what we know is threat modeling and how to teach it. It’s what we do best, and it’s how we can help.
(1/4) full post, links: https://is.gd/nYz3y2
My #PyConUS session is later today, let's find out together if your requirements.txt is haunted? 👻
Join the haunt in Ballroom BC at 1:45PM, don't be scared!
Apple Weather: expect thunderstorms soon.
Also Apple Weather: hey, I betcha need a wind map now, right?
How are these things still so bad.
Allan’s corollary to Clarke’s 3rd law:
Debugging any sufficiently advanced technology involves magic.
I published a new small project called "whichprovides" that's an abstraction over many package manager ecosystems, mostly for generating Package URLs to include in SBOMs: