noplasticshower · @noplasticshower
410 followers · 10792 posts · Server zirk.us

@SinclairSpeccy I once gave a talk on at bell labs. Dennis was in the front row. That talk included a "C is bad" chant as a silly hook (with audience participation). Dennis nodded his permission to proceed. The talk was really fun and was a harbinger of early static analysis tools.

#swsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
546 followers · 1354 posts · Server sigmoid.social

#swsec #infosec #mlsec

Last updated 1 year ago

noplasticshower · @noplasticshower
371 followers · 8659 posts · Server zirk.us

@briankrebs I have been working on the ML stuff seriously again for four years after a 20 year hiatus to do . See berryvilleiml.com

Happy to chat anytime, esp on the porch by the river.

#swsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
535 followers · 1248 posts · Server sigmoid.social

Only one more talk to go. Four in a row is a bit taxing.

#swsec #mlsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
535 followers · 1242 posts · Server sigmoid.social

Today's talk at secappdev was all about the flaw

You do ARA aka threat modelling, right?

#swsec #appsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
530 followers · 1235 posts · Server sigmoid.social

Secappdev talks and .

#swsec #appsec #mlsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
527 followers · 1207 posts · Server sigmoid.social

Listening to the very last Silver Bullet episode from December 2018. This episode featured my work.

Have a listen

apothecaryshed.files.wordpress

#swsec #appsec

Last updated 1 year ago

noplasticshower · @noplasticshower
353 followers · 6925 posts · Server zirk.us

@SheHacksPurple Jim routh and I published a clear ROI with numbers from Aetna for a initiative based on cost to build and repair software. We did not break out the satellite number by itself, but that part played some role.

In my experience, a champions/satellite program only makes sense after a number of other activities are in place.

#swsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
515 followers · 1040 posts · Server sigmoid.social

I have real questions about this. We had a DARPA project on this idea after the one where we invented SAST, and it was a mess. We were using AOP.

This is very vague and I am highly skeptical.

securityweek.com/mobb-raises-5

#swsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
509 followers · 914 posts · Server sigmoid.social

A link to the RECORDED for webinar I did yesterday with @adamshostack is now available behind a registration wall.

iriusrisk.com/impact-machine-l

#ml #threatmodeling #swsec #mlsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
509 followers · 901 posts · Server sigmoid.social

Webinar (requires registration) in 20 minutes. Feel free to join in as @adamshostack and I discuss Threat Modelling, Machine Learning, and Security.

Will Adam be replaced?

iriusrisk.com/impact-machine-l

#appsec #swsec #ml #mlsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
509 followers · 893 posts · Server sigmoid.social

Doing a webinar on risk analysis and tomorrow. Chances are we will talk as well.

Register now.

sigmoid.social/@cigitalgem/110

#swsec #ml #mlsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
509 followers · 893 posts · Server sigmoid.social

@Riedl Same here. But I am not going to sign.

FWIW, today reminds me of the very early days of circa 1998.

#mlsec #swsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
509 followers · 881 posts · Server sigmoid.social

Crock of shit alert!

Don't build security mechanisms out of broken stuff. We already learned this in . Now we're at it with

techcrunch.com/2023/03/28/micr

#swsec #mlsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
505 followers · 822 posts · Server sigmoid.social

@nsaphrayes!

I used to say the exact same thing about software. Or wait. I still say the same thing about software.

ML tech is software.

is

#mlsec #swsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
505 followers · 822 posts · Server sigmoid.social

@adamshostack ok. You made me look. I am officially ok with "attack fractals"

#swsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
487 followers · 651 posts · Server sigmoid.social

I just asked chatGPT to outline a 20 slide talk I am supposed to deliver for the NSF next week. It did a very literal job. But not bad.

Comparing and

#swsec #mlsec

Last updated 1 year ago

Gary McGraw · @cigitalgem
485 followers · 641 posts · Server sigmoid.social
Gary McGraw · @cigitalgem
485 followers · 640 posts · Server sigmoid.social

Wrote a thing on software security training with Matias madou yesterday. Data driven guidance.

#swsec

Last updated 1 year ago

seniorfrosk · @seniorfrosk
37 followers · 78 posts · Server snabelen.no

Grading final exams, and I learn to my astonishment that @cigitalgem has his own Common Criteria evaluation scheme

#swsec

Last updated 1 year ago