June 24, 2012
It Ain't Me Babe (InfoSec Awareness Edition)
Hidee ho, neighbors! Let's fire up the cathode rays on ye olde youtubez and sing-song sing-along once more, to the tune of Bob Dylan's It Ain't Me Babe. It's only appropriate to bring Dylan back, since we haven't (ab)used him since the BSides track The Cons They Are a Changin' almost a year ago.
This song's content is a bit more introductory, unlike some of the advanced topics we covered in We Didn't Start the (Fire)Wall and We Didn't Start the (Next Gen Fire)Wall.
Get ready to sing like you can't, Dylan style, with ShpanTazer'd lyrics, of course...
Securely yours,
gAli G AKA @Shpantzer
It Ain't Me Babe
This particular version is sung by Joan Baez, who explains that it's an 'anti-marriage' 'protest song.' You learn something new every day! Feel free to sing it like Dylan, though, it's more annoying to your cubicle neighbors that way...
http://www.youtube.com/watch?v=nADCKIT_Kbw
Go away from my Windows
Leave at your own chosen speed
I'm not the one you want babe
I'm not the one you'll bleed
You say you're looking for someone
Whose password's weak but thinks it's strong
To click you and install you
Whether you are right or wrong
Someone to open each and every .jar
But it ain't me babe
NO, NO, NO
It aint' me babe
It ain't me you're phishing for, babe
Go lightly on the ledge babe Go lightly on the ground
I'm not the one you want babe
I'll only let you down
You say you're looking for someone
Who'll never call the feds
Someone to choose your fake AV
Someone to buy your meds
Someone who will pay for all your scams
But it ain't me babe
NO, NO, NO
It ain't me babe
It ain't me you're phishing for, babe
Go melt back in the net, babe
Everything I have you want to pwn
There's nothing in here to exfil
And anyway I'm not alone
You say you're looking for someone
To click your links each time you spear
To not update Reader and Flash
And to help finance your beer
A sucker for your fraud and nothing more
But it ain't me babe...
Labels:
Dylan,
parody,
Phishing,
Ridiculosity,
Security Awareness,
Thermite
May 01, 2012
Sympathy for the Devil: Public Relations Re-Examined
Sympathy for the Devil: Public Relations Re-examined
AKA Carnival Barkers meet Infosec LARPers
Mood music... http://www.youtube.com/watch?v=vBecM3CQVD8
Pleased to meet you
Hope you guess my name!
But what's puzzling you
Is the nature of my game...
I stuck around San Francisco
When I saw it was a time for a change
Bombed RSA with buzz words
Liquid Matrix screamed in vain
I paid the analysts
gave awards to finalists
When the FUD it raged
And my pitches main-staged
Pleased to meet you
Hope you guess my name, oh yeah
Ah, what's puzzling you
Is the nature of my game, oh yeah
(woo woo, woo woo)
I watched with horror
While your antivirus corps
Fought for three decades
For the gods they made
(woo woo, woo woo)…
Just as every cop is a criminal
And all the sinners saints
As heads is tails
Just call me Lucifer
'Cause I'm in need of some restraint
(who who, who who)…
So if you meet me
Have some courtesy
Have some sympathy and some taste
Use all your well-learned politesse
Or I'll lay your soul to waste...
Public relations types, they're not LITERALLY the devil, right? PR/Marketing/Sales is so maligned, hated, despised, ridiculed and loathed by many security professionals that the mere thought of those words brings to mind FUD, willful technical ignorance (if not maligned neglect) and just general ridiculosity of the third kind.
That said, I wanted to shed some light on these dark arts (...) in a series of blog posts, in order to understand how the sausage is made and find points in the security marketing/pr/sales kill chain where we can make any improvements.
We all use security products and services but can’t stand the whole song-and-dance, so let’s look behind the curtains and delve into the way this works from soup to nuts. (Does that sentence have three analogies or whatever-you-call-those-things?)
Rather than my usual, oh-so-satisfying approach of lambasting PR from my comfy chair, devoid of any context and meaning, this time I reached out to Jennifer Leggio, aka @mediaphyter, who has been involved in ‘the community’ for years. Jennifer also happens to be Vice President of Corporate Communications for Sourcefire (http://blog.sourcefire.com, @Sourcefire), so she has experience working with a 'legit' vendor that's been around for a while and isn't known for relying on FUD for 99% of its revenue stream. Sourcefire, as you may know, is a purveyor of fine squishy pink Snorty pigs and, of course, some cool network security products!
"ASTERISK": I've never had a business relationship with Sourcefire so no is the answer to your questions regarding pay-for-play on my blog).
Basically, PR is more than writing crappy press releases before RSA... PR is part of a larger process that involves product marketing, business development, reporting to Wall Street, signaling to the M&A market and other hidden forces.
Here’s what I learned in a bit of informal QnA:
Q. What’s a typical “day in the life” of a PR professional supporting a company like Sourcefire?
A. It depends on the day. As a PR professional, you need to be ready at a moment’s notice to flip between proactive and reactive modes. Some days we’re knee deep in content development for strategic campaigns, which could or could not include bugging reporters and analysts, and other days we’re mapping along to competitive or market movement. Flexibility is paramount.
Q. What are the top three misconceptions of PR in the practitioner community?
A. Hmm, only three? OK, here goes...
1. All we care about is FUD (fear, uncertainty, doubt), or we create the FUD, or generally, we are only harbingers of FUD. That is lazy PR. The good ones are more proactive than reactive. The great ones help shape what the market is thinking about.
2. Not *every* PR person wants to put a researcher in an ironed button-down shirt and tie and give them a corporate pitch to deliver. Sometimes you don’t mold clay, you figure out how the clay unmolded (aka a gritty, brilliant researcher) is already a beautiful piece of art and work with it. Let us.
3. That one of us represents all of us. Some are more social. Some flit from conference to conference. Some you don’t even know, but they could be most talented because they are working rather than self-marketing. At the core of it, remember we are not identical creatures. It’s a wonderful thing.
Q. How can vendors make better use of l33t PR skillz?
A. I cannot say this enough. I’d type it in all caps if it wasn’t an Internet faux pas. Bottom line? PR needs to be part of your overall business strategy. Beyond PR, corporate communications from PR to social to analyst relations and, even in some cases, investor relations, can have a direct impact on your bottom line and financial perception. So stop treating PR as an afterthought, a noise creator, a buzz generator. Think smarter. If your PR agency or internal PR team is not helping sales sell, creating stories that field marketing can use to push deals into the pipe or sales can use to push deals through the pipe, then your PR team is not doing its job. Sometimes it’s because the right chips aren’t in place. Sometimes, it’s because they aren’t enabled to do so. Sometimes, the internal folks get it but they just have a bad network of agencies who think that the “cold calling buzz machine” and handshakes at conferences is all you need to drive business. However, if you let PR “in” and you have the right team in place, it’s pay dirt. I’m lucky that Sourcefire really gets this. Now, the pressure is on me and my team to perform. And I wouldn’t have it any other way.
Q. Let’s reverse-engineer a PR end-product, like a pre-RSA announcement of a product or service. How does that work? Starting with the announcement, walk it back to the source for us. Who’s involved, etc.
A. Oh, this is a long one. Announcement planning generally starts months and months ahead of the news cycle. And, if you’re smart, you’re engaging with industry analysts according to roadmap schedules versus announcement schedules (because, of course, they are your allies for selling, strategy awareness, though a lot of people forget that). It’s complex. For fun, let’s say Company A is announcing Widget B at Security Conference Extraordinaire on January 1.
The internal PR team should have weeks ahead, if possible, notified all external agencies of the coming dates so that local plans driven by sales priorities could be developed. Internal PR then needs to conspire cross-functionally with product marketing, and together they must skip in lock-step with other teams for message and story development, content development, many other things that would bore the people reading this, and then they break off to focus on external communications, web development, collateral, field communications, channel communications, and so on.
Stuff (press releases, blog posts, pitches, social media plans of attack, etc.) is developed. Outreach to press usually begins 2-3 weeks ahead of launch, but for huge overcrowded or more bloated events, longer might be necessary (Note: there is a small but distinct window of opportunity between “too early” and “too late” on most influencer event calendars. If you know them, as you should, you know in your gut when this is). You book meetings. WIN! No? Yes, now you have to properly prepare all spokespeople, which for an event, is many. Briefing docs and research is conducted. Sometimes, regional spokesperson training. Preso development (though I do not believe in PPT for press meetings, but that’s another conversation...). For journos not attending the event, embargoed pre-briefings the week before. For the event folks, on-site “hell fire” coordination to ensure everyone is in the same place at the same time. After the event, you relax. No? No! Then you’re chasing them for coverage, trying to make them remember your story amid a bevy of crap (because, of course, *our* stuff is *never* crap).
Complete this sentence:
PR is... an artform. Really. Stop laughing, technical folks. (Editor's note: I'm not laughing. I would be, except that I've consulted to a couple of niche security vendors and one of the hardest things I've ever done in 11 years of infosec consulting is write a not-horrible pre-RSA press release, announcing a partnership between my tiny client's startup security company and a major multi-billion dollar infosec gorilla... That's despite six years as a co-editor on the SANS Newsbites between 2002 and 2008. Doing this well is not easy...)
PR is not... merely cold calling influencers. More than ever, PR professionals must be business strategists who see the bigger picture, understand the map from air cover to the bottom line, and know how to build sustainable relationships beyond the low-hanging coverage fruit.
PR does this right... So many variables. However, if you find the perfect mix of strong leadership, good spokespeople, great products, good external and internal PR teams, your achievement of desired results is endless.
PR needs to do this better... This is not a “what can you do for me?” field. Maybe it was, and quite honestly, maybe it is outside of enterprise tech. But, in computer security, if your only reason for reaching out to influencers to help your agenda and you never give back, prepare for failure.
-----
I learned something new about PR today, how about you?
I'd like to thank @mediaphyter and the Academy of Self-Promotion Pictures for the opportunity to give the true PR professionals a break and to help them help us... We can learn a lot from PR pros so I'll be bringing more PR, Marketing and Sales professionals to my tiny little soapbox on this corner of the internet, torationalize away their horrible behavior better understand their role in the security ecosystem ;-)
We now return to our regularly scheduled infosec snark programming.
AKA Carnival Barkers meet Infosec LARPers
Mood music... http://www.youtube.com/watch?v=vBecM3CQVD8
Pleased to meet you
Hope you guess my name!
But what's puzzling you
Is the nature of my game...
I stuck around San Francisco
When I saw it was a time for a change
Bombed RSA with buzz words
Liquid Matrix screamed in vain
I paid the analysts
gave awards to finalists
When the FUD it raged
And my pitches main-staged
Pleased to meet you
Hope you guess my name, oh yeah
Ah, what's puzzling you
Is the nature of my game, oh yeah
(woo woo, woo woo)
I watched with horror
While your antivirus corps
Fought for three decades
For the gods they made
(woo woo, woo woo)…
Just as every cop is a criminal
And all the sinners saints
As heads is tails
Just call me Lucifer
'Cause I'm in need of some restraint
(who who, who who)…
So if you meet me
Have some courtesy
Have some sympathy and some taste
Use all your well-learned politesse
Or I'll lay your soul to waste...
Public relations types, they're not LITERALLY the devil, right? PR/Marketing/Sales is so maligned, hated, despised, ridiculed and loathed by many security professionals that the mere thought of those words brings to mind FUD, willful technical ignorance (if not maligned neglect) and just general ridiculosity of the third kind.
That said, I wanted to shed some light on these dark arts (...) in a series of blog posts, in order to understand how the sausage is made and find points in the security marketing/pr/sales kill chain where we can make any improvements.
We all use security products and services but can’t stand the whole song-and-dance, so let’s look behind the curtains and delve into the way this works from soup to nuts. (Does that sentence have three analogies or whatever-you-call-those-things?)
Rather than my usual, oh-so-satisfying approach of lambasting PR from my comfy chair, devoid of any context and meaning, this time I reached out to Jennifer Leggio, aka @mediaphyter, who has been involved in ‘the community’ for years. Jennifer also happens to be Vice President of Corporate Communications for Sourcefire (http://blog.sourcefire.com, @Sourcefire), so she has experience working with a 'legit' vendor that's been around for a while and isn't known for relying on FUD for 99% of its revenue stream. Sourcefire, as you may know, is a purveyor of fine squishy pink Snorty pigs and, of course, some cool network security products!
"ASTERISK": I've never had a business relationship with Sourcefire so no is the answer to your questions regarding pay-for-play on my blog).
Basically, PR is more than writing crappy press releases before RSA... PR is part of a larger process that involves product marketing, business development, reporting to Wall Street, signaling to the M&A market and other hidden forces.
Here’s what I learned in a bit of informal QnA:
Q. What’s a typical “day in the life” of a PR professional supporting a company like Sourcefire?
A. It depends on the day. As a PR professional, you need to be ready at a moment’s notice to flip between proactive and reactive modes. Some days we’re knee deep in content development for strategic campaigns, which could or could not include bugging reporters and analysts, and other days we’re mapping along to competitive or market movement. Flexibility is paramount.
Q. What are the top three misconceptions of PR in the practitioner community?
A. Hmm, only three? OK, here goes...
1. All we care about is FUD (fear, uncertainty, doubt), or we create the FUD, or generally, we are only harbingers of FUD. That is lazy PR. The good ones are more proactive than reactive. The great ones help shape what the market is thinking about.
2. Not *every* PR person wants to put a researcher in an ironed button-down shirt and tie and give them a corporate pitch to deliver. Sometimes you don’t mold clay, you figure out how the clay unmolded (aka a gritty, brilliant researcher) is already a beautiful piece of art and work with it. Let us.
3. That one of us represents all of us. Some are more social. Some flit from conference to conference. Some you don’t even know, but they could be most talented because they are working rather than self-marketing. At the core of it, remember we are not identical creatures. It’s a wonderful thing.
Q. How can vendors make better use of l33t PR skillz?
A. I cannot say this enough. I’d type it in all caps if it wasn’t an Internet faux pas. Bottom line? PR needs to be part of your overall business strategy. Beyond PR, corporate communications from PR to social to analyst relations and, even in some cases, investor relations, can have a direct impact on your bottom line and financial perception. So stop treating PR as an afterthought, a noise creator, a buzz generator. Think smarter. If your PR agency or internal PR team is not helping sales sell, creating stories that field marketing can use to push deals into the pipe or sales can use to push deals through the pipe, then your PR team is not doing its job. Sometimes it’s because the right chips aren’t in place. Sometimes, it’s because they aren’t enabled to do so. Sometimes, the internal folks get it but they just have a bad network of agencies who think that the “cold calling buzz machine” and handshakes at conferences is all you need to drive business. However, if you let PR “in” and you have the right team in place, it’s pay dirt. I’m lucky that Sourcefire really gets this. Now, the pressure is on me and my team to perform. And I wouldn’t have it any other way.
Q. Let’s reverse-engineer a PR end-product, like a pre-RSA announcement of a product or service. How does that work? Starting with the announcement, walk it back to the source for us. Who’s involved, etc.
A. Oh, this is a long one. Announcement planning generally starts months and months ahead of the news cycle. And, if you’re smart, you’re engaging with industry analysts according to roadmap schedules versus announcement schedules (because, of course, they are your allies for selling, strategy awareness, though a lot of people forget that). It’s complex. For fun, let’s say Company A is announcing Widget B at Security Conference Extraordinaire on January 1.
The internal PR team should have weeks ahead, if possible, notified all external agencies of the coming dates so that local plans driven by sales priorities could be developed. Internal PR then needs to conspire cross-functionally with product marketing, and together they must skip in lock-step with other teams for message and story development, content development, many other things that would bore the people reading this, and then they break off to focus on external communications, web development, collateral, field communications, channel communications, and so on.
Stuff (press releases, blog posts, pitches, social media plans of attack, etc.) is developed. Outreach to press usually begins 2-3 weeks ahead of launch, but for huge overcrowded or more bloated events, longer might be necessary (Note: there is a small but distinct window of opportunity between “too early” and “too late” on most influencer event calendars. If you know them, as you should, you know in your gut when this is). You book meetings. WIN! No? Yes, now you have to properly prepare all spokespeople, which for an event, is many. Briefing docs and research is conducted. Sometimes, regional spokesperson training. Preso development (though I do not believe in PPT for press meetings, but that’s another conversation...). For journos not attending the event, embargoed pre-briefings the week before. For the event folks, on-site “hell fire” coordination to ensure everyone is in the same place at the same time. After the event, you relax. No? No! Then you’re chasing them for coverage, trying to make them remember your story amid a bevy of crap (because, of course, *our* stuff is *never* crap).
Complete this sentence:
PR is... an artform. Really. Stop laughing, technical folks. (Editor's note: I'm not laughing. I would be, except that I've consulted to a couple of niche security vendors and one of the hardest things I've ever done in 11 years of infosec consulting is write a not-horrible pre-RSA press release, announcing a partnership between my tiny client's startup security company and a major multi-billion dollar infosec gorilla... That's despite six years as a co-editor on the SANS Newsbites between 2002 and 2008. Doing this well is not easy...)
PR is not... merely cold calling influencers. More than ever, PR professionals must be business strategists who see the bigger picture, understand the map from air cover to the bottom line, and know how to build sustainable relationships beyond the low-hanging coverage fruit.
PR does this right... So many variables. However, if you find the perfect mix of strong leadership, good spokespeople, great products, good external and internal PR teams, your achievement of desired results is endless.
PR needs to do this better... This is not a “what can you do for me?” field. Maybe it was, and quite honestly, maybe it is outside of enterprise tech. But, in computer security, if your only reason for reaching out to influencers to help your agenda and you never give back, prepare for failure.
-----
I learned something new about PR today, how about you?
I'd like to thank @mediaphyter and the Academy of Self-Promotion Pictures for the opportunity to give the true PR professionals a break and to help them help us... We can learn a lot from PR pros so I'll be bringing more PR, Marketing and Sales professionals to my tiny little soapbox on this corner of the internet, to
We now return to our regularly scheduled infosec snark programming.
March 31, 2012
I Am a Sensitive Hacker...
Well hello there, boys and girls! I've been meaning to ask you: Do you know someone in infosec who's so super cool that s/he thinks they're better than, well, everybody else? Do they remind you of the Sensitive Artist type from King Missile's classic hipster-bashing song from the 90s? http://www.youtube.com/watch?v=O-kHB2fWUS8
If you don't know this gem, please familiarize yourself with it, then follow along and cringe with me, as you knowingly snicker under your breath at the ones you find annoyingly in love with themselves.
We all know someone like this. Maybe they're going through a phase, or maybe they were just born this way. ...And maybe if they get a link to this post sent from a bunch of people, they'll get the hint.
Think of it as a public service...
XO XO,
Gossip Gal
-------------------
Sensitive Hacker
I am a sensitive hacker
I am a sensitive hacker
I am a sensitive hacker
I am a sensitive hacker
I am a sensitive hacker,
Nobody understands me because I am so l33t
In my work, I make allusions to sploits nobody else has developed, classes of vulnerabilities nobody else has ever heard of and 0days nobody else has seen
I can’t help it, because I am so much more intelligent and hyper-specialized than everyone who surrounds me.
I stopped using Windows when I was six months old, because registry surgery was so boring and stupid, and I started using openBSD, and going to DefCon and CCC.
I don’t go to mainstream cons anymore, because my fanbois are too legion.
And I don’t submit papers to CFPs anymore, because all the reviewers are haters, cuz they’re jealous of my skillz, and I can’t deal with jealous haters, because they don’t understand me.
I stay at home, writing tools that are beneath me, and working on my new framework, which no one understands.
I am sensitive
I am sensitive
I am a sensitive hacker
I am a sensitive hacker...
SENSITIVE!!!
March 20, 2012
We Didn't Start the (NextGen) Fire(wall)
Oops, I did it again...
:-o
Another sing-song, sing-along through infosec history, this time with more cowbell!
Same spoof on Billy Joel's We Didn't Start the Fire, different infosec terms and references.
Enjoy...
Gal Shpantzer
PS A guide to pronunciation for the sake of the song's rhyming and timing:
Roesch like mesh.
RIAA like diarrhea (I'm not sorry, they deserve it... http://shpantzer.blogspot.com/2009/09/send-in-clowns-riaas-embarrassing.html )
M-P-A-A like Em Pee Ey Ey
SCADA like Skay-duh
NIPC like NipSee
Here we goooooooo..... mi mi mi mi mi..... la la la LA la la laaaaaa....
Diffie-Helman, Token Ring, Private Cloud, Google and Bing
Forrester, hypervisor, Christmas Tree attacks
Marcus Ranum, DEC SEAL; Scarfo loses, no appeal
Multics, lethal ping, Trustworthy Computing
Stephen Northcutt, IDS, wirespeed analysis
Magic Quadrant, APT, Flash and Reader (Adobe)
We didn’t start the firewall...
It was always burning
Since the URL’s been turning
We didn't start the fire
No we didn't light it
But we tried to fight it
Straw-hat glasses, geotags, BIOS firmware blackbags
Hardware hacking, side channel, Communist Bloc
Wireless to Zigbee mesh, Alan Turing, Marty Roesch
Evening Iguana, Rock Around the Clock
EINSTEIN, A-Team, Sharks with friggin LASER beams
Bruce Schneier, MBR, Twitter Facebook, SQUIRREL!!!
Android, VDI, @Hrbrmstr, SQLi
TSA, CSA, RIAA/M-P-A-A
We didn’t start the firewall...
Joshua Corman, PCI, No Child will be Left Behind
SCADA, Office Space, Common Criteria
Enigma, Firewall, Comodo CA Falls
Night Dragon, NetFlix, SB 1386
NIPC, Farmville, Arpanet, ‘bola Monkey, MafiaBoy
MapReduce, Hadoop, TwoFish is a no-go
Duqu, BSD, AOL sends out CDs
Zombie botnets, Psycho, Nudie Scans at SFO
We didn’t start the firewall...
Gartner’s “IDS Is Dead,” joyride on the NO-OP Sled
Remote screen emulation, Van Eck emanations
Wall Street speculators lie, Nortel’s decade compromised
TrueCrypt, Next-Gen, Firewalls are back again
UseNet, XSS, browser pwn on the WordPress
RSA: Blown away! What else do I have to say?
We didn’t start the firewall…
Trojan horse, Chuvakin, Zero-Client endpoint Zen
TCP, NFC, Peer to Peer, RFC
Sneakers, Matrix, BGP, thank you Sir Tim Berners-Lee
Ayatollahs in Iran, US in Afghanistan
SecurID, seeds exposed, DIB is getting hosed
Foreign debts, homeless Vets, WEP cracked in minutes
Angelina in Hackers, I Can Haz D Cheezburgers
Linux flavor holy war, I can’t take it anymore!
March 15, 2012
We Didn't Start the Fire(wall)
Well, hello there, boys and girls, it's time for another sing-song, sing-along!
Previously, we
Today, we point our favorite secure (ahem) browser to http://www.youtube.com/watch?v=eFTLKWw542g (open in another tab), support the original artist by watching the official video with a 30 second commercial, then follow along with our very own mangled, er, um, I mean ShpanTazered (TM) version of this Billy Joel classic!
The original song was difficult to follow, with so many vague references to historical events and figures. I left some of the original references in there, just to be confusing, but switched up the rest for an infosec audience (who else reads this ridiculous blog...)
Security types will certainly be more familiar with Operation Bot Roast than Santayana (who's THAT?) and with the infamous and historically significant Paris Hilton Sidekick hack than with any 'trouble in the Suez' nonsense (where's that again...?)
We usually look at the world through the hazy filters of geek rock star practitioners and analysts, malware outbreaks, advances in hacking tools, networking breakthroughs and disruptive technologies. Not actual rock stars and you know, shooting wars, and whatever else people pay attention to... We're special little infosec snowflakes! Cuz I said so.
It's been a long, wild ride, intertubes, so have a drink of water, warm up your vocal chords, strap in and try to sing this techie tongue-twister to the Billy beat!
Good luck,
gAli G AKA Gal Shpantzer
We Didn't Start the Fire(wall)
Hacktivism, PGP, Red China, Entropy
BlackBerry, Neuromancer, PageRank SEO
Dan Kaminsky, Richard Nixon, Studebaker, Max Vision
Red Pill, Blue Pill, CISSP
RADIUS, Logic Bomb, Pain Ray, Johnny Long
Gene Schultz, The King And I, when do we stop SQLi ?
Robert Morris, Vaccine, England's got the same queen
DVD Jon, Liberace, Operation Bot Roast
We didn't start the firewall
It was always burning
Since the URL’s been turning
We didn't start the fire
No we didn't light it
But we tried to fight it
Pirate Party, Rybolov, Nimda and CSRF
Blaster LoveBug, John The Ripper, Communist Bloc
SRI, BBN, PDF bugs round the bend,
D-N-S Fails, Synchronize the Clocks
Stuxnet, LASER Beam, BSides’ got a winning team
Hoffacino, Xerox PARC, Kristin Paget, Bletchley Park
Lycos, LulzSec, Altavista, Cuckoo’s Egg
Freedom Frisk, Howard Schmidt, Paris Hilton’s Sidekick
We didn't start the firewall
It was always burning
Since the URL’s been turning
We didn't start the fire
No we didn't light it
But we tried to fight it
Cyber Storm, AirCrack, Mickey Mantle, ENIAC
Mitnick, System High, It’s the year of PKI
Keyloggers, Stacheldracht, Operation ShadyRAT
BitLocker, SecuTwits, Sony-BMG Rootkit
SE Linux, @Beaker, EFF, Mafia
SIPRNET, Lamo, Ripco is a no-go
U2, WikiLeaks, IANA and IRC
Securosis, RAND Corp, Hacker’s Manifesto
We didn't start the firewall
It was always burning
Since the URL's been turning
We didn't start the fire
No we didn't light it
But we tried to fight it
Zimmerman, LANMan, Stranger in a Strange LAN
Webcam, KLM, APT invasion
(David) Bell-Lapadula, Foursquare check-in mania
Vint Cerf, Trojans, GPUs make BitCoins
JavaScript, Active X, British Politician sex
RSA: Blown away! What else do I have to say?!?
We didn't start the firewall
It was always burning
Since the URLs been turning
We didn't start the firewall
No we didn't light it
But we tried to fight it
451, brute forcing, Kerberos is back again
Pick locks, teraflops, Captain Crunch, DevOps
Begin, Reagan, Cross Domain, hackers bringing Titan Rain
Ayatollas in Iran, US in Afghanistan
9/11, Sally Ride, Biba Model, suicide
Foreign debts, homeless vets, AIDE, Crack, iOS
Got collisions in the SHA, China's under martial law
BYOD, browser wars, I can't take it anymore!
We didn't start the firewall
It was always burning
Since the URL’s been turning
We didn't start the fire
No we didn't light it
But we tried to fight it
Subscribe to:
Posts (Atom)

