Gary Belvin πŸ”’

164 Followers
382 Following
85 Posts
CISO, Cryptographer, Consultant, Board Member.
Let's make evil expensive
RolePrincipal
CompanyGDB Security LLC
Websitehttps://gdbelvin.com/
CityBoston
Keybasekeybase.io/gdbelvin
LinkedInhttps://www.linkedin.com/in/gdbelvin/

Absolutely loving this by Sarah Wynn-Williams. I thought I’d like it for the horror stories about the #facebook management but the writing and pacing is great!

I saw her speaking briefly at a thing with @pluralistic at The Barbican in London where she couldn’t say much because of a non disparagement clause in her Facebook contract!

If you want to know why spaces like this are so important read the book! Her description of #davos suddenly makes the world make a terrible kind of sense

Hey, @thedarktangent! I totally enjoyed Graeme Dymond's custom #Blackhat2025 #Lego set! #blackhat #lego
Photographer Eric J. Smith captured a whale sneaking up on oblivious whale watchers.
Use Signal. We promise, no AI clutter, and no surveillance ads, whatever the rest of the industry does. <3

I am a former FBI Computer Scientist that worked in the Philadelphia Division of the FBI, and was promoted to Cyber Division Headquarters; during my time I worked on numerous criminal and national security matters, and had the fortunate opportunity to see the direct impact my job had in making America safer and saving lives. Since leaving the FBI, I've worked as a Privacy and Security engineer for companies such as Twitter and Google. I am also an Eagle Scout who continues to live by the code and ethics set since I was a young child.

I am writing to share how horrified I am with regards to the existential threats that my friends and former colleagues face right now. The acting director of the FBI was ordered to provide a list of all employees who worked on any January 6th matter; this includes not just Special Agents, but Intelligence Analysts, Computer Forensics Examiners, Computer Scientists, and more. These cases were lawfully investigated, supported by Judges, followed due process, and in many cases resulted in convictions by jury. These employees were doing their job, and are now threatened for following the oath we all swore. I fear not only for their safety, but also the safety of our country as these employees not only investigated these matters, but numerous others that have immediate impact on national security and saving lives, just like my career had done. Our foreign adversaries are using this as an opportunity, right now, to attack our country. Please use your voice to support the FBI and its employees immediately.

While everyone's else is "thanking" Trump for saving TikTok let's thank @jerry for his service.

Oh, and while Trump is a clown, Jerry is not.

Jimmy Carter is forever an A-List president.

A short thread 🧡

1/

It’s been recently reported that North Koreans are getting quite successful at passing IT interviews for remote roles in fluent English and then immediately installing malware.

In our remote-first, AI-enabled world, this is producing all kinds of creative and strange behavior, some of which I’ve seen first-hand as a CISO.

Protecting yourself is simple:

  • Get multiple forms of ID.
  • Verify those IDs against an official source.
  • Make sure the human matches the ID.
  • Enroll multiple factors (MFA) from the validated IDs.

For more details, check out NIST 800-53A, or get in touch

https://medium.com/@gdbelvin/how-to-not-hire-a-north-korean-spy-5349dc21eca3

How to not hire a North Korean spy - Gary Belvin - Medium

It’s been recently reported that North Koreans are getting quite successful at passing IT interviews for remote roles in fluent English and then immediately installing malware. As a CISO, this is…

Medium

This is a thoughtful piece; what Chris didn't see were some of the failure modes of Hixie's hubris when it came to inventing new elements in HTML5 (see also: "what we need is WASM and WebGPU" pipe dreams). But it's spot-on about how Google has turned away from the web, particularly on mobile, and empowered the Android team to facilitate a cozy anti-web duopoly:

https://cdibona.substack.com/p/my-eulogy-for-the-open-web-and-old

My Eulogy for the Open Web and Old Google

Why did the web grow the way it did?

Chris’s Substack

Probably the same people who believe in all the phony GOP election fraud claims also don't have any faith left in the FBI. Still, I'm glad to see this. One of the more timely alerts from the feds.

https://www.ic3.gov/Media/Y2024/PSA240912

Just So You Know: False Claims of Hacked Voter Information Likely Intended to Sow Distrust of U.S. Elections