@shortridge@hachyderm.io
@shortridge@hachyderm.io avatar

shortridge

@shortridge@hachyderm.io

Senior Director @Fastly | author of Security Chaos Engineering: Sustaining Resilience in Software & Systems (O'Reilly)

resilience + complex systems | bringing software security out of the dark ages

&void; | daedric prince of chaos | previously @swagitda_

“In the information society, nobody thinks. We expected to banish paper, but we actually banished thought."

This profile is from a federated server and may be incomplete. Browse more on the original instance.

aka_pugs, to random
@aka_pugs@mastodon.social avatar

How did I not know about this? HUGE collection of old computer brochures & ads, including a lot of . https://www.1000bit.it/ad/bro/brochures.asp?id=83

shortridge,
@shortridge@hachyderm.io avatar

@aka_pugs 🥵 well now I know my weekend plans, what a treasure trove

shortridge, to Cybersecurity
@shortridge@hachyderm.io avatar

this Galentine’s / Palentine’s/ Valentine’s Day, do you want to learn the secret to everlasting love?

my secret is writing a book ✨ because a book or creative project will never let you down or cheat on you or leave you or get tired of you rambling about your special interests for hours and hours, in fact that is the whole point and if you create for yourself, you can be beautiful weirdos together, forever 💞

https://www.securitychaoseng.com/

A video of me frolicking around NYC in Valentine's regalia with my beloved book. My first outfit is a hot pink skort suit that is kind of like if Barbie misunderstood what a business dress code meant, especially given I paired it with impossibly towering crystal emblazoned platform heels. My second outfit is a fluffy lilac turtleneck, as cozy and warm as it sounds, and my pants are a ludicrously bright shade of pink. There are many scenes, such as tossing the book in a park and hugging it with playful glee. Spinning with the book up in the air rom-com style on a cobblestone street. Caressing the book in front of a store festooned with floral garlands. Shopping with my book trying on something that can only be described as a minidress sequined with mermaid lore. Rambling to my book in a garden; it “nods” in agreement. More spinny on the street. A hot girl walk with ranunculi and the book. Doing yoga in my apartment wearing a Geek Squad shirt and NASA pajama pants, starting in star pose then descend into skandasana while keeping the book on my head, much to my own surprise. Even more spinny! Reposing in front of my fireplace in a silky black robe nuzzling my book as the flames flicker on my pale skin and its glossy cover. Finally stop spinny but now dizzy. For the final shot, I'm in Barbie's First Board Meeting outfit again in a romantic neighborhood bar reading my book fondly before giving it a final kiss and showing it off for the camera. You're welcome, femmes and thems.

bynkii, to random
@bynkii@mastodon.social avatar

I will say this until it is no longer true:

If a non-admin user clicking on a link or opening up an infected word file damages anything on your network your security is shit.

Periodt.

shortridge,
@shortridge@hachyderm.io avatar

@bynkii @saraislet I haven’t seen any real data on this, but if we assume the avg corp worker receives ~100 biz-related emails per day during the work week, that’s approx 26k per year. Let’s assume 50% have links.

If they click on 1 malicious email link in a year, that’s a ~0.008% “fail” rate to them.

Even if they click on 100 malicious links, that’s only ~0.8%.

It’s entirely rational to click the damn links; spending even 1 min on scrutinizing each email adds up to 217 hours per year!

shortridge,
@shortridge@hachyderm.io avatar

@tilde @bynkii @hazelweakly exaaaactly why a platform eng approach is desperately needed in more cybersecurity orgs.

the status quo approach is convenience for the security team for the high price of everyone else’s inconvenience.

attention is finite and precious. we can’t expect humans to do their full time job (ie critical function) and be continually “secure aware”. It’s unhealthy to be that hypervigilant.

Security teams should make the safe way the convenient way for their users.

shortridge, to security
@shortridge@hachyderm.io avatar

dear plausibly sentient citizens of the milky way,

I published a cliff notes / cheat sheet / tl;dr guide for you on what the hot topixxx of software and chaos engineering (SCE) mean: https://kellyshortridge.com/blog/posts/security-chaos-engineering-sustaining-software-systems-resilience-cliff-notes/

it’s basically the chapter summaries of my paywalled book repurposed as a public, bite-sized guide for you to devour, absorb, then change-make (or sound smart online, in meetings, at parties, to your cat, etc)

let’s keep trying to modernize together xx

shortridge,
@shortridge@hachyderm.io avatar

@perfect5th same, Geralt schooled me on temporal autocorrelation the other day, v embarrassing

shortridge,
@shortridge@hachyderm.io avatar

@dbsmasher love 2 see it ✨

shortridge,
@shortridge@hachyderm.io avatar

@dbsmasher oh please don’t stop there, knowing my creations are giving you life is a reward (and also have you written about your part in that macro shift??)

shortridge,
@shortridge@hachyderm.io avatar

@dbsmasher omg I’ve read that post, didn’t realize that was you! legendary

shortridge, to random
@shortridge@hachyderm.io avatar

I just received a notification that an order of $item is out for delivery…

…an order I placed November 17…

…in 2022…

🤨

shortridge,
@shortridge@hachyderm.io avatar

@Kensan oddly it wasn’t a crowdfunding project. it was… a shower cap. a bougie one, admittedly, but still, a shower cap. and just one.

whereistanya, to random
@whereistanya@hachyderm.io avatar

Doing tech support for a family friend.

Login to icloud on your iphone with an appleid which is a gmail address and then into your windows account on your laptop and that's also a gmail address but ofc with a different password, and Chrome on your iPhone and Chrome on your laptop talk to each other in ways you don't expect, but anyway your iPhone opens Safari half the time and Windows will convince you to use Edge if it kills you both so good luck finding where you opened gmail GODSPEED.

shortridge,
@shortridge@hachyderm.io avatar

@whereistanya extremely relatable for my current situation rn, especially the apologizing on behalf of the entire software / tech community

shortridge, to random
@shortridge@hachyderm.io avatar

not me trying to connect to the Airbnb wifi over and over until realizing they decided to end the “sentence” containing the password with a period. right next to it. like “password.” but the password is just “password” and if you hear about some new sorcerer recluse in the woods near you soon you know who it is

shortridge,
@shortridge@hachyderm.io avatar

@antondollmaier in this case the quotes weren’t included, so it was more like:

The password is P@ssw0rd.

but quotes would make it even more confusing, yes

shortridge, to random
@shortridge@hachyderm.io avatar

in case there are other nerds out there who haven’t yet read this classic, behold “the case of the 500-mile email” https://www.ibiblio.org/harris/500milemail.html

I adore the “absurd computer-borne mysteries” genre and kindly ask for more content from the annals of y’all’s careers

shortridge,
@shortridge@hachyderm.io avatar

@joelanman love it, v worthy addition to the genre

shortridge,
@shortridge@hachyderm.io avatar

@bob_zim this is an exquisite tragicomystery, thank you for sharing it, I’m in awe

shortridge,
@shortridge@hachyderm.io avatar

@MichaelTBacon I lowkey love the persistence of the person sending the pirates Shrek video, incredible story all around, thank you

shortridge,
@shortridge@hachyderm.io avatar

@rjohnston wait so when they say “flush the cash” they don’t mean sticking it in the dish washer on heavy rinse???

shortridge, to Cybersecurity
@shortridge@hachyderm.io avatar

tbh I’m getting frustrated hearing “everyone does this” from engineers at high-growth tech companies when I talk about modern security / stuff.

but then the “mature corp” majority often haven’t even heard of some of the basic concepts/practices, let alone are trying to adopt them…

it’s why I often leverage the “two Americas” analogy to describe the state of cybersecurity today. These things really aren’t “obvious” to many and pretending they are widens the gap.

shortridge,
@shortridge@hachyderm.io avatar

@fool I mean, fair. It frustrates me as much as when MatureCorp CISO says “this is impossible” as if there aren’t companies doing it.

Trying to bridge the two worlds is imo worth it but by Ithelia is it vexing sometimes

shortridge, to gaming
@shortridge@hachyderm.io avatar

Monday morning read: The untold history of Barbie Fashion Designer, the first mass-market ‘game for girls’ https://www.polygon.com/23776996/barbie-fashion-designer-retro-game-untold-story-history

lots of 90s game dev lore gems in it; feels incredible they pulled it off tbh

and, was it lowkey the first mainstream 3D printing game, too??

shortridge,
@shortridge@hachyderm.io avatar

@kaflurbaleen wait what is this feminist hacker Barbie, I’m immediately intrigued

shortridge, to random
@shortridge@hachyderm.io avatar

I submitted a poem to a magazine many months ago and just got my rejection.

I expected it because their acceptance rate is like 0.5% but I am so glad I at least put myself and my work out there.

Getting comfortable with rejection and not letting it sink you is an invaluable skill. Not trying something is an implicit rejection, anyway.

How else can we explore all the treasures life offers us, if we don’t challenge ourselves in new ways?

This is your sign to try the thing that scares you ✨

shortridge, to Software
@shortridge@hachyderm.io avatar

software engineers: what’s something you feel your security team is doing right in your org?

and security engineers: what’s something you feel your devs teams are doing right in your org?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • GTA5RPClips
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • osvaldo12
  • Youngstown
  • ngwrru68w68
  • slotface
  • everett
  • rosin
  • thenastyranch
  • kavyap
  • tacticalgear
  • megavids
  • modclub
  • normalnudes
  • cubers
  • ethstaker
  • mdbf
  • Durango
  • khanakhh
  • tester
  • provamag3
  • cisconetworking
  • Leos
  • anitta
  • lostlight
  • All magazines