11 Followers
67 Following
40 Posts
MeDuncan IRL | Father | AppSec Engineer | Photographer | He/Him | My opinions are a)dumb and b)my own and not representative of anyone but me

Great talks tonight @dallas_hackers.
Two things as takeaways tonight:

1. I actually worked to operationalize LINDDUN for Privacy by Design. Its actually working out cheaper to do at design time than tack it on later. Hard with legacy apps, but still better to model it first and prioritize. AND, ITS A COMPLIANCE REQUIREMENT.

2. AppSec requires you to meet the devs where they are at. Part of the failure here though is a credibility issue. SAST or DAST tools are rife with false positives and require a ton of tuning. Without a triage process thats a failing strategy because developers don’t trust you, and triage takes a long time which slows deployment. IAST, interactive application security testing, is much higher fidelity, use that instead.

#NeverForget

#JohnMastodon
#JohnMastodonDay
#Fediverse

Never forget the name John… Mastodon.

@wirefall I’m not going to be able to run the coding room at DHA this month. Had a positive Covid test yesterday, and want to try and keep everybody safe.
Truth
@wrv Seriously great talk on fuzzing video. Love it! Keep coming to @dallas_hackers , please
I am filled with glorious purpose.

@shortidge I’m now rethinking all of my life decisions, so thanks for that….

https://kellyshortridge.com/blog/posts/what-does-the-word-security-mean/

When we say "security", what do we mean?

This essay is a semantic safari of the word ‘security’. What do we mean when we say it and what should it mean in the context of cyber?

Sensemaking by Shortridge
He was.
Should have taken the metro…
Anyone headed to #ThreatModCon in my extremely limited online social circle?