Because I'm all about the "good enough."

Thursday, January 31, 2013

Training for RSAC.

Yes, I'm getting ready for the RSA Conference next month in San Francisco. RSA is a particularly brutal week for those in my line of work; thus far I'm meeting with 23 vendors, most of them in 30-minute sessions, and that's not counting the time I'll be walking the exhibit hall, trying to meet with more. I have three panels and one talk to give during the week. We won't mention all the vendor events in the evenings, both public and private, the side conferences taking place, or the fun gatherings like the Security Bloggers' Meetup.

In order to get ready for this challenge, I've been doing the following exercises, which you may want to try as well:

  • Walk three miles in heels; drink two cocktails and then walk another mile without spraining an ankle.
  • Stand for two hours in one spot, holding a tiny napkin full of mini-quiches and seared tuna canapés in one hand, a glass of Pinot Noir in the other, and handing out business cards with the other other hand.
  • Go to a public restroom and practice removing stains from the aforementioned wine and canapés from a white shirt.
  • Do wind sprints through a hallway full of high school students to practice the art of the two-minute break between one-on-one meetings.
  • Speed-read through books on calculus, knitting, quantum mechanics, teleology, bread baking, and constitutional law to get ready for reams of vendor brochures and white papers.
  • Practice lip-reading in a dark room by the light of strobes and lasers. 
  • Memorize 80 names per day out of the phone book.
  • Practice listening earnestly to comedian monologues without cracking a smile or giggling.

    and finally ...
  • Go geocaching in Costco to practice finding the one vendor at RSA that is not claiming to do 'big data' or 'analytics.'
 See you there.






Saturday, December 29, 2012

Levelling up in the real world.

Here's a great post from Victor Wong on What They Don't Tell You About Promotions.

All of his points are so, so true -- and I thought I'd add some more from my own experiences and perspective. There are a lot of misconceptions out there about what entitles you to a promotion, so let me get those out of the way first:

What does not get you promoted:
  • Being the oldest person on your team. (Really, some people seem to believe this.) It's not about how old you are; management or senior positions are not about babysitting other people.
  • Being in your position the longest. Your position does not expire after a certain date, and you don't level up just by doing your job.
  • Doing your job the best of everyone else on the team. It's not about how well you do what's expected of you; it's about what you do above and beyond your job description.
  • Needing the money. Sorry, but that is not a sufficient reason for your boss to actually give you more money, much less move you to another position. You have to prove that you're worth it.
  • Working the hardest on your team. Again, it's not about fulfilling your current responsibilities. If you are working much harder than others, your boss might be looking at you and thinking, "This person doesn't know when to stop." Or your boss might decide, "We really need this person to keep the group afloat, so we're not going to change her job." It might even be, "This person has to work harder to do the same job as everyone else -- he's not as competent."
  • Taking a course or two to prepare for your next level. Courses are nice, but there's no guarantee that you can actually execute on what you've learned. You need to prove that you can do the next higher job by actually doing it. Think of a promotion as an acknowledgment of what you've already been doing rather than a change into a brand-new set of responsibilities that you haven't done yet.

Here are some other things that will keep you from getting promoted:
  • Not playing well with others. If you upset people inside or outside the team, it creates extra work for your boss, who has to smooth things over. When you create extra work for your boss, you are totally not getting rewarded for it. 
  • Taking a negative view of things. If you complain about other people, your workload, or talk about customers as if they're idiots, you're not going to level up. Nobody likes a pill.
  • Having no helpful ideas of your own. Your boss wants a problem-solver who can be trusted to do it the right way without creating other problems (see above). Just reporting on problems isn't enough.
  • Not seeing the big picture. If you are thinking only about your current job or your current team, you're not thinking big enough. You need to prove that you can approach things from your boss's perspective (or that of your boss's boss). Even better, you should be coming up with ideas that they haven't (but that they like).
  • Not doing the job your boss wants you to do. You may be the most brilliant person in the world who is going to change the whole industry; you may think you have the right answers (and in some cases that might even be true). But people who haven't managed teams have no idea how annoying it is to have an employee who won't just do his fricking job because he thinks he knows better. If you don't agree with your boss on how to do things, go find another boss. You'll be doing everyone a favor.

And finally, here's one that not a lot of people think about:

Being irreplaceable. Yes, being irreplaceable will keep you from being promoted. If you are so key to operations that you can't take a vacation or sick day without things falling apart, you are not going to get moved to a different position so that things can fall apart full-time. If you are already a manager, your job is to make sure your team has the skills and empowerment to take care of anything that comes up in your absence. A succession plan is vitally important in every organization. Your own boss will feel much better knowing that you have a stable and successful team, and knowing that you're not endangering operations by indulging your ego's need to feel special.

When you are looking out for the welfare of your organization instead of focusing on what you can get for yourself, that's when you'll be given the chance to do more and own more. 


Tuesday, November 20, 2012

Sure, I'll be your unicorn.

I was fascinated to read about the cancellation of the British Ruby conference due to the arguments that the speaker lineup lacked diversity.  Other people have their own opinions on why we have this problem and what we should do about it.  I've spent a lot of my career as a hiring manager, trying to walk the fine line between encouraging diversity and slipping into tokenism; I've also had to be as impartial as possible in selecting conference talks (full disclosure: I'm on the RSA 2013 committee).

As someone who has a chromosome allocation that has traditionally been in short supply in IT, I'm used to being the only one of my kind in the room. If that makes me a unicorn from time to time, there's not much I can do about it, short of leaving the room, and that kind of defeats the purpose of my being there in the first place, which is simply to learn from and contribute to whatever is going on. If I've been exceptionalised, it wasn't such that I could detect it, but I don't know what discussions are ever held behind the scenes.

But here's the thing, the most important thing: What we see every day is what we expect.

Our brains are hardwired that way, so that we spend less processing time trying to re-analyze and make predictions about stuff that we've experienced before. It goes on without our realizing it, and you can sometimes tell it's happening when you find yourself paying more attention to something than you usually do; it means that something is different from what your brain was used to. We expect humans to be walking on two legs, and so we notice anyone we see on crutches or in wheelchairs. We are used to women with hair on their heads, so a woman with visible hair loss receives a lot of attention (as I did in the middle of chemo when I visited my kids' school playground). This is natural.

So if we want to hack our brains, we have to be conscious about it, and put some effort into changing our subconscious expectations of the way things ought to be. This is why I applaud conference organizers such as Chuck Hardy who work on soliciting paper submissions (and more than one B-Sides conference does this too; I've volunteered to be a speaker mentor for London 2013). Reaching out to anyone who is different from yourself -- and helping them along if necessary so that nobody can complain about quality -- is what we need to do to change our experience, and therefore our expectations, of who is seen onstage.

I don't know whether I've ever been invited to speak simply on account of being female, but if it happens, I'm okay with it. Haters gonna hate, and they probably won't change their minds on why I was selected just because I gave a pretty good talk. But at least I have a chance with the rest of the audience: to change their experience regardless of whether I'm a quality presenter (we're all used to seeing bad male speakers, aren't we? Why shouldn't I be allowed the same opportunity to fail?).

So if you want me as your unicorn, I'll take one for the team. If it means opening up the door a little wider in the future for other people who look different, then I still think it's worth doing.



Saturday, August 18, 2012

Pre-rejected CFP submissions.

Here are some of my planned conference submissions that I thankfully abandoned early in the process:

"Increasing Security Awareness Using Wall-to-Wall Counseling"
Most security awareness training is less effective than it could be.  Introducing a physical reminder component boosted our compliance levels up to 450% (but did necessitate a new carpet from time to time). 

"Zero-Day Exploits For CP/M"
There are critical risks to data integrity for every enterprise using WordStar.  Help us get the word out about these frightening vulnerabilities that have been around for DECADES.

"A Meta-Discussion on Meta-Talks at Security Conferences"
A disturbing trend in security conferences is meta-talks that have nothing to do with, like, pwning stuff.  Burnout, sexism, career advice, economics, recruiting, food, exercise and other presentations, usually on what's wrong with the security industry, are replacing actual knowledge transfer involving shell scripts, cookie abuse and lockpicking. Our whole community is in danger of extreme navel-gazing.  This presentation aims to point out the meta-risks of meta-talks.

"On a New Certification For Security Professionals"
We can't possibly take ourselves, or each other, seriously in the security industry without certifications.  The current ones are not fine-grained enough to depict the exquisite subtleties of arcane knowledge that make us so proud to be in this business.  In this presentation, we will propose a new certification model with 25 levels and over 18,000 separate certifications to remedy this granularity problem.  (And all of them start with the letter C!)

"Musical Ports"
After many years of research, we have discovered a new weapon in the battle against intruders:  musical ports, in which services migrate every few seconds to new port numbers so that they can't be found and exploited.  This is done to the system administrator's choice of music (or you can leave it on the default setting, which uses streaming dancehall reggae).  Every so often, when the music stops, one service that can't find an open port is arbitrarily terminated.  The end effect is a much more secure infrastructure.

"The Original Internet Privacy Threat: Your Mom"
You think you can still fight for your privacy?  Privacy is deader than you know.  Your mom built the Internet, punk, and not only has she been monitoring all your activity, she's got Google alerts on you and has a network of other moms planted where you least expect them. She thinks it's really cute how you change pseudonyms every so often, by the way. And since you're reading this, she'd like to remind you to take out the garbage and brush your teeth.

"It's Probably Okay, Don't Worry About It"
Security isn't the problem that people think it is.  Chill, folks.  It's just ones and zeroes.  You're just getting everyone upset with all this bogeyman talk about APTs and insider threats and whatnot.  Relax, open up the firewall to let it breathe, and embrace the Internet.


Thursday, August 16, 2012

Actually, you're both right.

I normally don't like to write about gender issues.  It's not that I don't have opinions on them; it's just that it would be like taking a public stand on other controversial topics that may (or should) not have anything to do with my profession.

But it seems that the pot has come to a rolling boil these days over sexism and other kinds of harassment, and since I think I understand both sides of the arguments, I thought I'd just come out and say that everyone is (mostly) right.

I think the fundamental problem is that there is a continuum of acceptable conduct and/or speech that at some point crosses over into unacceptable.  The problem is that the dividing line is very blurry, and people who are most in danger of crossing it resent attempts to define it too closely or to move the goalposts without notice.  In fact, it's pretty hard to define it completely without writing a huge book on it.

Harassment is bad, no matter who does it or to whom.  Harassment should be defined as well as is possible and should not be tolerated. 

I can understand how someone can write in his usual style -- blunt, verbose, with a touch of condescension -- and not mean it to be any different just because the current target is a woman as opposed to a man.  I can also see how a woman can take it as an inappropriate attack.  They're both right.  In a case where someone is treating a woman exactly the way he would treat a man, it's not sexism on his part.  At the same time, if that treatment happens to match sexist acts that the woman has experienced, to her it's certainly more of the same.  There is no getting around the mismatch, and it can't always be remedied.  

So when harassment or sexism is contextual -- something is a normal behavior when doing it to a man, but not to a woman, for example -- then I can see how it can be very confusing to someone who doesn't innately experience the difference.  People can wind up perplexed rather than informed.  It can look like one team has a secret rulebook and there might always be a rule or two that could be violated without warning.

The key here is "without warning."  Feedback, like salad, is best when it's fresh.  (I don't know where that analogy came from.  Work with me here.)  Feedback needs to be immediate and unambiguous, which means that it can't always be subtle or polite.  When it comes to unwanted actions of any kind, people have to speak up right then and there.  Women need to be able to yell, push, or punch someone in the nose if all other tactics fail.

A long time ago, in a club in a country far, far away, some drunken guy grabbed me around the waist in what presumably was an attempt to dance with me.  I shoved him away.  The international language of "no" was clear, and I didn't have to do it twice.  Were his feelings hurt?  Probably.  Did I overreact?  We could sit here debating that for hours.  But the fact is, it worked without any need for escalation.  He could have had harmless intentions, other women could have found it charming, and at the same time I still felt it was an unwanted and obnoxious act.  Short of putting the decision to Schrödinger's cat, we're always going to have two states here.  And if we're all going to get along, we have to recognize that and build bridges to deal with both of them.

There are some forms of harassment that we can all agree on:  using threatening language, launching  attacks that do damage, calling someone names.  And most of the time, those types of harassment are clearly intentional.  As a community, we can and should work together to fight that kind, because it's a shared standard.  Where a reasonable person could claim that something is not intentional, however, we need to recognize that and respond in a way that gives feedback, not accusations or punishment.  We can also recognize that this feedback may not be well received, but we can work to make sure it's understood.  And anyone who agrees with the feedback can and should speak up to support it -- not to make it worse, not to escalate it, but to strengthen it.

What we don't want is to wind up in extremes:  where both sides feel attacked, albeit for different reasons.  We don't want women, men, ethnic minorities, people of size, people of age*, or anyone else to be wary of attending a conference for fear of intentional harassment.  We also don't want people attending conferences to be scared of unintentionally offending someone through the mismatch described above.  We want people to be able to write what they think is normal language, and get a second chance if they mess up once.  In all of these cases, though, if you keep getting the same feedback for the same actions or language, maybe you'd better take the lesson to heart, whether you understand/agree with it or not.



* Hello.




Wednesday, August 15, 2012

The OTHER problem with passwords.

There are some sites that I use very rarely, and I can never remember what I used for a password there.  But it doesn't matter, because honestly, the reset procedure is less onerous than trying a few passwords and risking getting locked out.  So I just don't bother: I put in a crazy strong password, forget about it, and when I come back to the site I just ask for a reset.  In many cases there aren't even security questions to answer; I just get a new password mailed to my address of record.  In the case of one site where they wanted me to change the password every 90 days, I did this dance every 90 days.

Yes, yes, I know, password manager.  But most of the public doesn't use one. And site designers know it.  Any site feature that makes it harder for a non-technical user to do a password reset causes that user to email or call the support desk, and every use of the support desk (as in actual humans) costs money.  So organizations are motivated to prioritize ease of use over security, if they feel their target audience won't be able to use more advanced features without support.  The end result is that the password reset process to an address of record is the easiest way to get into an account.

And of course attackers know this too: this is why many publicized breaches today started with the password reset.  If it's a simple enough process, getting into an account is no longer "something you know;" it's "something you have," as in control of the email address.  If you've broken into the address of record, you can collect password resets from as many sites as you can find without having to do any more homework. 

The next level up in attacking an account is to add a new email address of record that you control, which often requires social engineering of the support desk.  But support people are incentivized to help the helpless, which tends to make the process easier.  And as Mat Honan found out, the types of security verification data that support desks use can often be found out with a little Google action (and in his case, the clever use of an Apple process loophole).  This is why I've never liked the use of the last four SSN digits as an identifier; they're even more widely used than the whole SSN these days, and they're used for everything, including utility and phone service accounts. It's arguably less secure than a site-specific PIN.

Make no mistake: designing identity and access management while balancing cost and security is hard.  You can't control the biggest factor, which is the level of expertise for your users (particularly if they're all external to your organization).  With each of these breaches, we're learning more about what works and what doesn't in these designs.  But there's still a lot of risk out there.


 

Monday, August 13, 2012

CFP Karaoke.

I have to thank Wim Remes for coming up with the idea of CFP Karaoke:  you come up with a talk title, and someone else has to do the rest of the work.  Here are some of the gems he came up with on Twitter; feel free to take one and run with it.

@wimremes: "Two and a half clouds : how to keep winning on tiger blood as a service"
@wimremes: "Infosec and the God complex : we're better than we are and worse than we realize."
@wimremes:  "Exploit sales for the masses : do you want a patch with that?"
@wimremes: "Cutting through the infosec BS : is there an evangelist in the house?"
@wimremes: "Eeny, meeny, miny, mo, your QSA says it's secure but I say no."