I have had several people request my slide deck from Hack3rCon^4. Because of bandwidth and email issues, I have uploaded it and my notes here. Dropbox
The video of my presentation can be found on IronGeek's site.
Have fun and don't forget to speak with your elected officials often!
*****Note: I got a couple of things wrong in my presentation.
1) The coauthor of the 2nd Amendment that I was referring to is George Mason. Some really good quotes on the 2nd Amendment can be found here and here. Before discussing what the founders "intended," read what they actually said!
2) I eluded to the 17th Amendment as a joke but got the timeframe wrong. The 17th amendment forced States to hold direct elections for Senators in 1913. Prior to this, some States still allowed Senators to be appointed by those State's governors. This intent of the 17th Amendment was to stop the corruption of Senators at the State level. This worked! However, Senators are now corrupted at the national level.
Saturday, October 19, 2013
Friday, October 11, 2013
My EPIC week of FAIL! and better things to come
So, this week was a hum-dinger! I tackled some tasks at work that, well, didn't work. I finally started some high priority home projects that, well, FAILED! I decided that self deprecation is about the only thing I can get right this week so here it is...
WORK
Q: What happens when you spend hours creating a powerpoint presentation and import it into Captivate (like I have done many times before)?
A: It crashes your computer of course.
Q: What happens when you restore files from the midnight backup?
A: It does not restore the the last 6 hours of work of course.
Q: What else happens?
A: You also have to do another 5 hour FTP of Rachel-Pi.
Q: What happens when you change your password and forget what it is?
A: You continue an all day loop of forgetting and reseting your password.
HOME
Q: What happens when you root for the Jets while putting DD-WRT on that shiny new router?
A: You accidentally rip the power cord out of the back, bricking the router.
Q: What happens when you perform a "hard" reset (like I have had to do many times before)?
A: You listen to things go pop, watch the blue smoke escape, cry as the power light goes black, and cover your nose from the acrid odor.
Q: What happens when you root your old Android phone in order to get ready to play at SkyDogCon?
A: You remember that you stopped using the phone because it won't hold a charge longer than 1 hour!
Q: What happens when you decide to give up on all things electronic and you take the trash to the curb?
A: The Herbie cart slips out of your hand and trash spills all over the yard!
On the plus side, I will be starting a new blog series that will include learning a new tool, reviewing it, and interviewing the author. Many brilliant people have responded favorably to my interview requests and I will begin with Armitage and Raphael Mudge.
Oh, last but not least, I have been accepted to speak at SkyDog! This week was not a total FAIL.
I think I will sleep until Monday now.
WORK
Q: What happens when you spend hours creating a powerpoint presentation and import it into Captivate (like I have done many times before)?
A: It crashes your computer of course.
Q: What happens when you restore files from the midnight backup?
A: It does not restore the the last 6 hours of work of course.
Q: What else happens?
A: You also have to do another 5 hour FTP of Rachel-Pi.
Q: What happens when you change your password and forget what it is?
A: You continue an all day loop of forgetting and reseting your password.
HOME
Q: What happens when you root for the Jets while putting DD-WRT on that shiny new router?
A: You accidentally rip the power cord out of the back, bricking the router.
Q: What happens when you perform a "hard" reset (like I have had to do many times before)?
A: You listen to things go pop, watch the blue smoke escape, cry as the power light goes black, and cover your nose from the acrid odor.
Q: What happens when you root your old Android phone in order to get ready to play at SkyDogCon?
A: You remember that you stopped using the phone because it won't hold a charge longer than 1 hour!
Q: What happens when you decide to give up on all things electronic and you take the trash to the curb?
A: The Herbie cart slips out of your hand and trash spills all over the yard!
On the plus side, I will be starting a new blog series that will include learning a new tool, reviewing it, and interviewing the author. Many brilliant people have responded favorably to my interview requests and I will begin with Armitage and Raphael Mudge.
Oh, last but not least, I have been accepted to speak at SkyDog! This week was not a total FAIL.
I think I will sleep until Monday now.
Tuesday, October 8, 2013
What are you doing in May? I'm going to another BSides!
BSides is one of the greatest ideas I have seen in a while. Its stated goal is to be a "community-driven framework for building events for and by information security community members." That leads me to the next BSides I will be attending. On May 17, 2014, the Ezell Center at Lipscomb University will play host to BSides Nashville.
Looking at the list of organizers/volunteers, I can tell you this should be a quality event. This coupled with the location and the keynote speaker already slated to present is money baby!
I had the opportunity to hear Brett Wahlin, the CISO of HP, speak (you still haven't accepted my invite on LinkedIn by the way). He came to the University of Kentucky HealthCare and helped to educate our IT staff on the importance of protecting the confidentiality, integrity, and availability of our strategic asset, data, without resorting to FUD. This is something very few people can accomplish. FUD usually creeps into the conversation in some way.
Looks like I will need to start a new research project so I can have something new for the CFP (happening now by the way). See you there!
Make sure you check out the websites and follow them on Twitter for updates.
BSides Nashville website: http://www.bsidesnash.org
Security BSides website: http://www.securitybsides.com/w/page/67993467/BSidesNash2014
Twitter handle: @bsidesnash
Twitter tag: #BsidesNash
As always, feel free to comment.
Looking at the list of organizers/volunteers, I can tell you this should be a quality event. This coupled with the location and the keynote speaker already slated to present is money baby!
I had the opportunity to hear Brett Wahlin, the CISO of HP, speak (you still haven't accepted my invite on LinkedIn by the way). He came to the University of Kentucky HealthCare and helped to educate our IT staff on the importance of protecting the confidentiality, integrity, and availability of our strategic asset, data, without resorting to FUD. This is something very few people can accomplish. FUD usually creeps into the conversation in some way.
Looks like I will need to start a new research project so I can have something new for the CFP (happening now by the way). See you there!
Make sure you check out the websites and follow them on Twitter for updates.
BSides Nashville website: http://www.bsidesnash.org
Security BSides website: http://www.securitybsides.com/w/page/67993467/BSidesNash2014
Twitter handle: @bsidesnash
Twitter tag: #BsidesNash
As always, feel free to comment.
Saturday, October 5, 2013
Louisville Metro InfoSec Conference
A small conference, in a big city. This year I attended the Louisville Metro InfoSec Conference. This is my third time to attend and will not be my last. The quality of presentations is always great and the small number of attendees give the con an intimate feel. This year, the highlights for me were the second keynote speech by David Kennedy (Burn it Down! Rebuilding and Information Security Program), the presentation by Adrian Crenshaw (Information Security in University Campus and Open Environments), and the lock pick area run by Kyle Stone.
What can I say about Dave's speech. As usual, it was very entertaining. Start with a gut check, add a liberal dose of humor, and end with 5 key steps that will help any organization improve their business. Yes, I did say, improve your business. After all, no one wants to start a business to meet compliance. They want to make money. Watch Dave's presentation for more information.
Adrian had a very interesting presentation. He helped the audience understand how an average college co-ed could wreak havoc on the open networks at universities. After all, most university administrators actually believe that creativity is stifled if you even attempt to secure your environment. He also highlighted the means by which IT and InfoSec can counter these "hackers." The presentation is heavy with links to tools but I recommend it since the tools are worth it.
Finally, the lock pick village was the break I needed from the typical con burnout. There are few things better than picking up a couple of small pieces of metal and opening those wafer locks!
As always, the videos can be found on www.irongeek.com.
What can I say about Dave's speech. As usual, it was very entertaining. Start with a gut check, add a liberal dose of humor, and end with 5 key steps that will help any organization improve their business. Yes, I did say, improve your business. After all, no one wants to start a business to meet compliance. They want to make money. Watch Dave's presentation for more information.
Adrian had a very interesting presentation. He helped the audience understand how an average college co-ed could wreak havoc on the open networks at universities. After all, most university administrators actually believe that creativity is stifled if you even attempt to secure your environment. He also highlighted the means by which IT and InfoSec can counter these "hackers." The presentation is heavy with links to tools but I recommend it since the tools are worth it.
Finally, the lock pick village was the break I needed from the typical con burnout. There are few things better than picking up a couple of small pieces of metal and opening those wafer locks!
As always, the videos can be found on www.irongeek.com.
Monday, September 30, 2013
DerbyCon 3.0 is over, CPEs logged, It's a wrap!
I have just logged my CPEs so it must be over. Another DerbyCon has come and gone. Friends were reunited for a flash and life will be returning to normal soon. I always write something about the cons I attend and this is no different. Well, maybe it is a little different.
You see, this year's DerbyCon was completely different for me. After helping Adrian Crenshaw (Irongeek) with video at BSides Las Vegas, I offered my services again. This time, my reasons were less selfish. (After all, I was late to the game for BSides and couldn't get a ticket unless I volunteered). This time, my purpose was to give back. The crew of DerbyCon have each helped me in some way or another in the past 3 years so I felt the call. They are not aware of how they have helped so here it is:
1. DerbyCon has put me in touch with a new crop of people who have similar experiences in IT/Security burnout.
2. I have been able to talk to industry leaders and determine my future Information Security roadmap/career.
3. The quality of my work has increased due to me having a core of colleagues that I can bounce ideas off of.
4. I just enjoy talking to people again...
I tried not to bore you guys with a recap of the briefings I sat through. After all, you can just check those out at the irongeek.com website. Thanks for taking time to read my blog and, as always, feel free to comment.
And again, thanks for putting on a great "family" style conference. See you next year (I'll be the guy in the Staff t-shirt and the hip toy).
Wednesday, September 25, 2013
DerbyCon 3.0 - All in the Family
Welcome to DerbyCon 3.0 – “All in The Family”.
It is that time of the year again. Every September (for the past 3 years anyway) InfoSec professionals, hackers, and the 3l33t descend on Louisville, KY for a week of technical training, presentations, and more importantly hallway con. I am looking forward to catching up with friends and making new ones. If you are going, feel free to hit me up. You can contact me on Twitter at @cowboysfaninky or email at bwmgwm1@gmail.com. I can't wait to see you there!
Goals: It is hard to hit the target if you can't see it
Pick up just about any self help guide or management book and you will read about the virtues of written goals. I have had great personal success over the years by writing down, and working from, goal sheets that include short-, medium- and long-term goals. Because of this success, I have decided to do the same with my bucket list. After perusing the interwebs, I decided to use a website called wishberg.com. This website allows the user to create a bucket list with a Pentrest feel to it. Feel free to check out the site and my bucket list. You can find my bucket list at http://www.wishberg.com/bwmgwm/wish.
As always, feel free to leave a comment.
Subscribe to:
Posts (Atom)



