@tilde@infosec.town
@tilde@infosec.town avatar

tilde

@tilde@infosec.town

๐ŸŒธ "High-end nondescript." ๐ŸŒธ

#Nonbinary ๐Ÿณ๏ธโ€โšง๏ธ #Trans ๐ŸŒˆ #Queer ๐Ÿง  #Disabled ๐Ÿ• #Jewish ๐ŸŒน #Socialist ๐Ÿด๐Ÿšฉ #AntiFascist ๐Ÿ™ #Urbanist.

๐Ÿต Limitless green tea & matcha; elaborately-prepared coffee in moderation. โ˜•
๐ŸฅŸ Dumplings & soup, therefore: xiao long bao. ๐Ÿฑ
๐ŸŽฒ Immersive and site specific theater, storytelling & roleplaying. (Most recently: Pathfinder, Quest)
๐ŸŒธ Cherry blossom season. (Even if in the SF Bay area, they're mostly plums.). ๐ŸŒบ Wildflowers of all kinds. ๐Ÿชป
๐Ÿงฑ Gently dissociating with elaborate Lego sets and podcasts or audiobooks. ๐ŸŽง
๐Ÿ•๏ธ Hiking, sailing, being among trees. โ›ต (And so can you! semperexplorandum.com)

๐Ÿ’ป #Technologist ๐Ÿ“ฃ #Activist & โ˜” #ProductManager in ๐Ÿคซ #Privacy, ๐Ÿ”’ #Security, &.๐Ÿ‘๏ธ #TrustAndSafety. ๐Ÿ›ก๏ธ
๐Ÿซฐ๐Ÿป Current gig: Head of Product for Red Queen Dynamics. redqueendynamics.com
โŒ› Previously: Tall Poppy, https://mastodon.social/@brave, Committee to Protect Journalists, https://mastodon.social/@torproject, https://mozilla.social/@mozilla. tildelowengrimm.com/#experience
๐Ÿงญ Volunteering: Explorers Guild, Cornell Clinic to End Tech Abuse, Call of the Sea, Techies for Reproductive Justice.

๐Ÿคณ๐Ÿป Avatar alt text: a white person with high cheekbones and dark eyes looks squarely at the camera. Asymmetric purple and indigo curls fall on one side of their head.
๐Ÿ•น๏ธ Header image alt text: magenta and blue lighting falls over a collection of retro electronics: an original Game Boy, a Commodore, an IBM-style mechanical keyboard and more.
๐Ÿ“ท Header/banner image is "vintage gray game console and joystick" by Lorenzo Herrera, used under the Unsplash license. unsplash.com/photos/p0j-mE6mGo4

๐Ÿ“ Unceded Ohlone land in the Confederated Villages of Lisjanโ€™s territory. Pay your Shuumi Land Tax to support rematriating stolen land. sogoreate-landtrust.org/shuumi-land-tax/

This profile is from a federated server and may be incomplete. Browse more on the original instance.

tilde, to random
@tilde@infosec.town avatar

What the heck is "default opt-in"? Is this corporate consent-subversion talk for "opt-out"? Just say "opt-out". mastodon.social/

RE: mastodon.social/users/arstechnica/statuses/112457773374003138

tilde, to random
@tilde@infosec.town avatar

For being a pet story, this story is weirdly relatable? mas.to/

RE: mas.to/users/kissane/statuses/112442637073844205

tilde, to random
@tilde@infosec.town avatar

Reading Scatter, Adapt, and Remember back to back with Four Lost Cities, @annaleen comes off as something of a luxury travel writer whose destinations just happen not to exist any more. It's as if they started with an obsessive need to understand how cities and societies fall apartโ€ฆ and so naturally went on a wold tour of climate scientists, historians, and archeological sites. The books are just kinda an inevitable side effect which occur naturally when a science (fact & fiction) writer and journalist tracks down a thought which they simply cannot get out of their head any other way.

tilde,
@tilde@infosec.town avatar

@annaleen In my mind, you embarked on journeys to places which no longer exist (or haven't happened yet). The actual physical locations you had to visit in order to find those are just airport lounges and bus stations on the way there.

tilde, to random
@tilde@infosec.town avatar

Michelle Yeoh can do literally any role she wants. But if she brings anything like the same energy that she brought in Discovery, I think she'll be an absolute superstar in a Blade Runner show. variety.com/2024/tv/news/michelle-yeoh-blade-runner-2049-sequel-series-amazon-1235993492/

lzg, to random
@lzg@mastodon.social avatar

aaahhhh! the awards for Tech Trivia turned out amazing! Designed by Hannah Diaz. I'll see some of you there tomorrow evening!

tilde,
@tilde@infosec.town avatar

@lzg My dyslexic first glance gave me "Tech Trauma" awards, and my brain had zero reason to question why you might be announcing those.

tilde, to random
@tilde@infosec.town avatar

"We abolished the inheritance of political power; why, then, should we not abolish the inheritance of economic power, too?"

insidestory.org.au/the-case-for-banning-billionaires/

tilde, to random
@tilde@infosec.town avatar

You either die an insider threat or live to become an outside agitator

tilde, to random
@tilde@infosec.town avatar

A solid argument that the term "antisemitism" has had its time, and we make life easier and more straightforward by using terms like "anti-Jewish hate".

Original on Twitter: twitter.com/sim_kern/status/1786500008742687217
Thread compiled off-site for those without an account any more (good work): threadreaderapp.com/thread/1786500008742687217.html

And some bonus reading on the history of the term: academic.oup.com/ahr/article/123/4/1139/5114731

tilde,
@tilde@infosec.town avatar

Nonetheless: Jews and Judaism and Israel are not the same thing. Criticism of the actions of the state of Israel is not antisemitic, it is not anti-Jewish, and is not inherently hateful. However, not all people who live in Israel and not all Israelis support or are complicit in the Israeli government's ongoing attempted genocide of the Palestinian people. Just as it is hard to blame individual Americans for the actions of the US military or individual British people for their transphobic government, it is unfair to blame individual Israelis for the actions taken by the IDF under Netanyahu. Criticizing Israel's reprehensible actions is not a criticism of every Israeli person, and is absolutely not a criticism of Jews or or an act of hatred towards Judaism.

tilde,
@tilde@infosec.town avatar

The Palestinian people deserve freedom. That starts at the most basic: freedom from violence. Israel's ongoing campaign is not constrained to the military goal of defeating Hamas or of preventing future attacks like the horrific slaughter of October 7th. The IDF's conduct includes consistent and brazen violations of international law and norms โ€” conduct which looks very much like an attempt to exterminate the Palestinian people. ๐Ÿ‡ต๐Ÿ‡ธ

tilde, to random
@tilde@infosec.town avatar

In the 90s โ€” so the story goes โ€” the APA noticed that they were basically only diagnosing boys with ADHD, so they checked, and, yep, girls get it too, it just looks different because โœจreasonsโœจ. So they invented the inattentive subtype for ADHD to make sure girls got diagnosed too. And anyway it is so strangely validating not only to finally have a formal ADHD Diagnosis, but also to specifically have Girl ADHDโ„ข, because yes, obviously, correct.

tilde,
@tilde@infosec.town avatar

ADHDโ„ข โ€” now for girls!ยฎ is obviously substantially more expensive than regular ADHDโ„ข (you know, the standard normal one, for boys).

tilde, to random
@tilde@infosec.town avatar

My security friends keep asking me what it is that we actually do at Red Queen Dynamics. I just sent this pretty-concise explanation privately. I think it's a reasonably good summary for folks who aren't elbow-deep in this every day of the week.

Security and compliance are difficult. It's hard to understand because it's so convoluted, it's hard to know if you're doing the right thing, and often compliance especially is a big short-term push to get the thing done. We're trying to be an executive functioning prosthesis for this, taking away a bunch of the garbage work like unending spreadsheet checklists, and also the mental overhead of not knowing the right thing to do.

So we made a little app which contains all (most of) our knowledge about security and also maps that to a bajillion compliance frameworks like NIST's cybersecurity for SMB, the defense industrial base's CMMC, and the CIS controls, as well as a bunch of the underwriting checklists for cybersecurity insurance providers. We know that password managers, automatic updates, and phishing-resistant auth are important. Our clients know that they need (ex) CMMC self-attestation and cyber insurance. And we've built this kinda deduplicated knowledge graph of all of that.

We send a question or two a week to everyone in an organization. And those questions are mostly written by me and are human-readable. We ask some calibration questions to know who's who at the org and then send the right people the right questions to get a more-or-less comprehensive human-level understanding of the org's security/compliance posture.

Most people at the org just do this two-minute task a week, and the app compiles all that info, digesting it for their technical leaders or their MSP or whatever. It spits out insights for them like "You said you wanted to get cyber insurance, and here are the three things you can do to get guaranteed good rates and expedited processing." (with the knowledge that they are actually complying with the terms of the policy!), or "You said you wanted to be CMMC compliant, and you still need to make this technical change to get there.", or "You've reached compliance with CIS v8 IGA, would you like to print of a serious-looking PDF self-attestation document to show someone?", or "You said your business has a high ransomware risk, but your backups aren't really ready for that. Here's what to ask your MSP for." or whatnot.

In a nutshell, we've built something which takes like 60-80% of the general-purpose security/compliance expertise of someone like me or @Tarah (or the people who ask me this question), and we make it available to small businesses who absolutely could not afford a couple of hours of our consulting rates. And! We encourage small, consistent, incremental long-term improvement rather than rushed/hurried compliance cram-sessions.

And (mandatory self-promotion ๐Ÿ˜ฌ) you can sign up today at signup.dynah.net/ or learn more at redqueendynamics.com

BlackAzizAnansi, to random
@BlackAzizAnansi@mas.to avatar

Legal question: If a private college calls out cops to get rid of protesters and the major intervenes and tells the cops to stand down, would the school have a cause of action against the city if something happens?

tilde,
@tilde@infosec.town avatar

@BlackAzizAnansi Cops don't have a duty to intervene.

tilde, to random
@tilde@infosec.town avatar

The greatest power fantasy of D&D is that getting a full night of rest will leave you fully healed and refreshed.

tilde,
@tilde@infosec.town avatar

Obviously, there are other incredible dreams in this game like:

  1. Having clear, concrete goals on which you can directly act.
  2. Being able to help people and take actions which leave the world better off.
  3. Making new friends as an adult.
  4. Learning a new skill, language, craft, or musical instrument.
  5. The opportunity to grow in power until you eventually attack and dethrone god.
  6. The world is only sometimes in peril; those world-threatening problems can be solved; and some people with power are actually willing to help solve them.
  7. Having "downtime" between your exhausting and nerve-wracking adventures.
AlSweigart, to random
@AlSweigart@mastodon.social avatar

deleted_by_author

  • Loading...
  • tilde,
    @tilde@infosec.town avatar

    @AlSweigart A typewriter and a twelve gauge is a very specific gender, IMO.

    tilde,
    @tilde@infosec.town avatar

    @AlSweigart Hemmingwaycore Jack-London-pilled. Completely self-sufficient and independent as long as you don't account for any of the influences of our shared culture or the support of an organized society.

    foone, to random
    @foone@digipres.club avatar

    for complicated tumblr reasons involving dreaming of classified CIA visual novels, I mocked up a Powerpoint 4.0 slide for government agents trying to seduce transfems.

    I thought I'd share it here for retro nostalgia and trans shitposting reasons

    tilde,
    @tilde@infosec.town avatar

    @foone @phildini I have a deep and powerful need to see the rest of this presentation.

    tilde, to random
    @tilde@infosec.town avatar

    In addition to the one very polite (though sometimes loud) bird who lives inside the house, there are simply too many extremely loud birds who live in the garden and are on birdie-Tinder at the top of their tiny lungs at a truly unreasonable hour. Send help.

    tilde, to random
    @tilde@infosec.town avatar

    I have to agree with Brennan/Gurdy on this: of the many honeyed confections, baklava is king. (And by far the best baklava I've had in the SF Bay Area is from Baklava Story on Harrison Street in SF.)

    charliejane, to random
    @charliejane@wandering.shop avatar

    I love Discovery (as recently stated), but Lower Decks is the only Trek I rewatch over and over, and it's my happy place as a viewer. These characters are so rich and complex and they deserve much more time to develop.

    tilde,
    @tilde@infosec.town avatar

    @charliejane Lower Decks is an incredible magic trick. It's simultaneously a joke whose punchline is "Star Trek, amirite?", and some of the most distilled trekiest trek that ever trekked? I love it. And it's also absolutely one of my comfort watches over and over and over. ๐Ÿ’œ

    hazelweakly, to random
    @hazelweakly@hachyderm.io avatar

    Dude bros will really spend millions of dollars on analytics programs rather than go to therapy or actually talk to anyone to figure out how they feel about shit

    Introducing an innovative framework for: product discovery, market research, customer focus groups, developer experience, product led growth, business intelligence, and more.

    I call it "TALK"

    T: TALK TO YOUR FUCKIN PEOPLE
    A: ALL OF THEM, SERIOUSLY, JUST DO IT
    L: LEGITIMATELY, THIS ACTUALLY WORKS
    K: K? THAT WASN'T SO HARD NOW WAS IT

    tilde,
    @tilde@infosec.town avatar

    @hazelweakly I feel this in my heckin' bones.

    robb, to random
    @robb@social.lol avatar
    tilde,
    @tilde@infosec.town avatar

    @robb Ooh, exciting! And what a fun way to learn about @prami, nice!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • โ€ข
  • provamag3
  • GTA5RPClips
  • magazineikmin
  • tacticalgear
  • khanakhh
  • InstantRegret
  • Youngstown
  • mdbf
  • slotface
  • thenastyranch
  • everett
  • osvaldo12
  • kavyap
  • rosin
  • megavids
  • DreamBathrooms
  • Durango
  • normalnudes
  • ngwrru68w68
  • vwfavf
  • ethstaker
  • modclub
  • cubers
  • cisconetworking
  • Leos
  • anitta
  • tester
  • JUstTest
  • All magazines