Professional: DFIR / Incident Management lead
Volunteer: Search & Rescue specialist, CERT trainer, Parrot handler
Amateur: Cello & Guitar
(was: 0xMatt on twitter)
| Twitter: | 0xMatt |
| Website: | foofus.com |
| Keybase: | amuse |

Professional: DFIR / Incident Management lead
Volunteer: Search & Rescue specialist, CERT trainer, Parrot handler
Amateur: Cello & Guitar
(was: 0xMatt on twitter)
| Twitter: | 0xMatt |
| Website: | foofus.com |
| Keybase: | amuse |
Given the big PyPI, Node and Github supply chain attacks in the last month or two I am *very* curious:
Orgs who have walked far down the SBOM path - are you feeling pretty good about that right now? Is it genuinely helping you respond to supply chain attacks?
While I'm throwing out unimportant musings: What's up with real estate agents putting "Drone shot" photos from 100 feet above a house showing the great view from up there?
Unless there's a patio 100' up I can sit on, that's a blatant misrepresentation of the situation.
One of my biggest worries today is that decreasing job security and declining volunteerism are going to multiply one another in ways that severely undercut the fabric of our country. An early indicator: The diminishment of volunteer firefighting.
https://www.nfpa.org/news-blogs-and-articles/nfpa-journal/2026/02/11/volunteer-fire-service-crisis
This trend is understandable. Who can afford to spend the time volunteering when the cost of living fast outpaces wage growth, and when job stability is low?
Confused that you have strong DKIM/DMARC rules & configured SPF, yet people are still spoofing your CEO's mail in fraud attempts? This may be because you included Salesforce, Mailchimp, or other SaaS in your SPF.
Abusers can use free/fraudulent accounts there to spam "as" you.