@shortridge@hachyderm.io
@shortridge@hachyderm.io avatar

shortridge

@shortridge@hachyderm.io

Senior Director @Fastly | author of Security Chaos Engineering: Sustaining Resilience in Software & Systems (O'Reilly)

resilience + complex systems | bringing software security out of the dark ages

&void; | daedric prince of chaos | previously @swagitda_

β€œIn the information society, nobody thinks. We expected to banish paper, but we actually banished thought."

This profile is from a federated server and may be incomplete. Browse more on the original instance.

shortridge, to Cybersecurity
@shortridge@hachyderm.io avatar

my new post covers how to get started with chaos experiments without having to larp as sysadmin, disrupt your users, or piss off your execs ✨ https://www.fastly.com/blog/chaotic-good-resilience-stress-tests-at-the-edge

it includes a js code example that verifies super basic #cybersecurity assumptions about your org’s website, like:

πŸͺ my site requires cookies or auth headers
βš”οΈ my site does not allow cross-origin requests

so, it’s a great starter experiment to get familiar with the practice β€” and it clones requests to avoid fucking with prod ✨

wingo, to random

graphviz is a tool to convert graphs to unintelligible spaghetti

shortridge,
@shortridge@hachyderm.io avatar

@wingo literally why @rpetrich and I created Deciduous https://github.com/rpetrich/deciduous

I will never get all those hours of dot wrangling back, but we hope we can spare others of a similar fate (at least in the decision tree context)

shortridge, to random
@shortridge@hachyderm.io avatar

a confession: I’ve battled mourning doves for months, ever since I bought a bird feeder for my garden and they kept draining it in less than a day.

they are allegedly stupid creatures, but that’s just what they want us to think.

I am plausibly an expert in cyber defense, having written a book and academic papers, lectured at federal agencies and F500s alike β€” yet the doves thwart my every mitigation.

I planned to write a blog post once I won, but my hope for victory further desiccates daily…

shortridge,
@shortridge@hachyderm.io avatar

@mikeloukides that might work when there is actual ground, but I, living in NYC, have only a humble rooftop that I’d rather not be smeared in dove shit.

So, the doves hanging around all day is still a non-starter.

But, the focus of my battle is a Bird Buddy. I did buy a squirrel buster feeder which indeed prohibits them from feeding, but I am extremely stubborn so wanted to thwart their ambitions to feed from the Bird Buddy; that way, the finches, cardinals, and sparrows could finally feed.

shortridge, to random
@shortridge@hachyderm.io avatar

tired: too many browser tabs

wired: the system is struggling to absorb and regenerate from anthropogenic stresses

shortridge,
@shortridge@hachyderm.io avatar

@th how does it feel to possess such power

shortridge, to random
@shortridge@hachyderm.io avatar

anyone know the best place around Moscone to get a chai latte?

shortridge, to security
@shortridge@hachyderm.io avatar

went down to the hotel lobby to retrieve my dinner delivery in a yoga outfit + snuggly cardigan + face mask.

some men with lanyards exited the elevator as I re-entered; they turned back to look at me and one said (very loudly, very pointedly staring at me) to the other, β€œI was like, did you hire me a hooker?”

if you are a man attending , please shut that kind of shit down when your peers do it. let’s not let insecurity rule our industry.

shortridge,
@shortridge@hachyderm.io avatar

@afterdark I definitely read that as a security conference dedicated to @bea’s glorious contributions, and I am here for it

shortridge, to Cybersecurity
@shortridge@hachyderm.io avatar

The 2024 Verizon Data Breach Investigations Report (#DBIR) is out this morning, and I make sense of it in my new post: https://kellyshortridge.com/blog/posts/shortridge-makes-sense-of-verizon-dbir-2024/

I focused on what felt like the most notable points, from #ransomware to MOVEit to web app pwnage to #GenAI and more.

I have insights, quibbles, and hot takes as always β€” but the fact remains it’s our best source of empirical data on cyberattack impacts. If you’re a #cybersecurity vendor, please consider contributing data to it.

shortridge, to Bulgaria
@shortridge@hachyderm.io avatar

To my #EU friends, followers, and future allies: I’m keynoting #CraftConf in exactly one month (May 30).

I will bring #cybersecurity heresy β€” and custom #ChaosKitty stickers β€” with me to Budapest.

You still have spacetime to buy tickets and bask in software craftship: https://craft-conf.com/2024/talk/disputation-on-the-power-and-efficacy-of-cybersecurity

Let me know if you’ll be attending, speaking, or otherwise proximate xx

shortridge, to random
@shortridge@hachyderm.io avatar

Me: β€œI’m lowkey bullish on inexact supercomputing.”

Them: β€œIntel’s been doing that since the 90s!”

(historical context for the joke: https://en.wikipedia.org/wiki/Pentium_FDIV_bug)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • β€’
  • anitta
  • thenastyranch
  • magazineikmin
  • Youngstown
  • khanakhh
  • InstantRegret
  • tester
  • slotface
  • osvaldo12
  • mdbf
  • rosin
  • kavyap
  • ngwrru68w68
  • everett
  • JUstTest
  • DreamBathrooms
  • ethstaker
  • cisconetworking
  • Leos
  • tacticalgear
  • modclub
  • GTA5RPClips
  • Durango
  • megavids
  • provamag3
  • normalnudes
  • cubers
  • lostlight
  • All magazines