For Good Measure Remember the Recall

Sherlock’s statement is most often quoted to imply that uncommon
scenarios can all be explained away by reason and logic. This is missing
the point. The quote’s power is in the elimination of the impossible
before engaging in such reasoning. The present authors seek to expose
a similar misapplication of methodology as it exists throughout information
security and offer a framework by which to elevate the common Watson.


Managing an open source program at scale

Open source software is fundamental to building a modern tech company. This panel discussion will feature companies widely recognized for running high-quality open source programs. Attendees will gain insight into the tooling, processes, and team structures these companies have built to manage open source programs that keep communities engaged at scale.
Jeff McAffer, Microsoft
Surupa Biswas, Facebook
Andrew Spyker, Netflix
Moderated by GitHub

Anti-Spam by Design: Building a Company of Spam-Fighters

Spam fighting isn’t just about writing policies, training classifiers, and combating attacks. Leveraging the “secure by design” principal in the context of spam helps create better products with built-in features for preventing and managing large-scale attacks. In this talk, we’ll share how Facebook spam-fighters extended their efforts to align incentives and include other product teams within the company in the effort to fight abuse.

Red Teams – Starting Up Security – Medium

You’ve spent money on security products that escalate nothing. You have a 24/7 SOC that hardly pays attention to their tools, or knows how to use them. You have intelligence feeds but have no idea what consumes them. Logs are inaccessible, slow to query, or non-existent. Defenders have stopped hunting and lost a sense of purpose.

That means it’s time for a Red Team to come in and fuck shit up.


Stop Buying Bad Security Prescriptions – Medium

I’ve been working in information security for about two decades — spanning attack and defense, across the public and private sectors — and the most consistent truth I’ve found is that people overwhelmingly misunderstand how information security works. Even worse, the common misconceptions are such an endemic problem that they’ve fueled a $75 billion industry, comprised largely of snake oil solutions that range from ineffective to outright harmful. That’s left us in a place where the vast majority of the tech sector is throwing their money away on security that just doesn’t work, while ignoring the basic practices and processes that actually do produce secure systems … but it doesn’t have to be this way.