Keith Crawford

753 Followers
449 Following
552 Posts

Cybersecurity GRC specialist focused on building sustainable, high-trust security programs that protect business-critical functions and drive growth.

A monument to mercy & Father.


Interests/Hobbies: Disaster Relief Volunteer, Weather Geek, Kayaking.
 
{Views are my own}



Hashtags: #lrtweetup #sectwits #GRC #arkansas #arwx

Links:https://tsudo.carrd.co/
Location:Southern U.S. 🇺🇸
Homepage:https://forwardslashsecurity.com

The best hat I’ve seen yet

#BsidesLV

The most important & disturbing talk I’ll hear this week.

We as an industry/community have to reckon with sexual predators & extortionists that are drawn to cybersecurity.

Excellent talk stating the significant problem.

Find this video later.

https://bsideslv.org/talks#TMTNLQ

#bsideslv

See his slides and more links in speaker notes

https://tinyurl.com/dwayne-bslv

I'm A Machine And You Should Trust Me - BSidesLV

Generic Presentation I'm A Machine And You Should Trust Me: The Future Of Non-Human Identity https://tinyurl.com/dwayne-bslv

Google Docs

At a #BSidesLV talk on non-human identity, referenced GitGuardian’s State of Secrets Sprawl 2025 Report:
🔐 23.8M secrets leaked on GitHub in 2024 (+25%)
🤖 Most are tied to non-human IDs—API keys, service accts
📉 70% of 2022 secrets still active

https://blog.gitguardian.com/the-state-of-secrets-sprawl-2025/

#passwordscon

credit: @mcdwayne

Let me know if you want it trimmed even further for character count or tone.

The State of Secrets Sprawl 2025

GitGuardian's 2025 report reveals 70% of leaked secrets remain active two years later. Discover the alarming state of secrets sprawl & protect your organization.

GitGuardian Blog - Take Control of Your Secrets Security
@rallias sorry, the app froze when I posted. But the dupes have been deleted
So ready for Day 1 of Hacker Summer Camp #bsideslv
@mcdwayne Looking forward to it
@Viss oh I certainly don’t disagree that compliance does not equals security or that it isn’t a common approach

@Viss that’s a whole other discussion.

Compliance when done well is structure and demonstrating trust.

Bad controls however are the root of all evil.

It could be argued that the cybersecurity orgs don’t prioritize thinking.
Just reacting.
Another meeting.
Another Slack thread.
Another alert.
Nearly conditioned to see, react, discuss, then do.
No pause. No reflect. No design.

Make thinking great again.