A Logo

Feel free to include my content in your page via my
RSS feed

Help Irongeek.com pay for
bandwidth and research equipment:

Subscribestar or Patreon

Search Irongeek.com:

Affiliates:
Irongeek Button
Social-engineer-training Button

Help Irongeek.com pay for bandwidth and research equipment:

paypalpixle


Opening Keynote: Words Have Meanings - Dan Tentler (Circle City Con 2017 Videos) (Hacking Illustrated Series InfoSec Tutorial Videos)

Opening Keynote: Words Have Meanings
Dan Tentler

viss
Circle City Con 2017

Getting your point across is important. Clear communications are essential. Why is the information security industry packed full of buzzwords, catchy phrases, logos for bugs and jargon that doesn't make sense? Information Security is not only a difficult line of work to get into, it's difficult to navigate once inside. Every different vendor has their own "language", different compliance regulatory bodies have jargon as well, which isn't congruent, and most of which is entirely made up, or completely false. Nobody can agree on whether certs matter or not. Charlatans and plagiarists sound exactly like 10-year-weathered veterans. Dozens of security organizations routinely confuse "Red Team Assessments" with "Vulnerability Scans" and "Pen Tests". Words seemingly have no meaning anymore. How can we cope? Like many other professions, communication is the foundation. If you can communicate effectively, you can make things happen. Conversely, use the wrong words, or mis-speak a few times, and the industry ceases to take you seriously. This is a massive problem if we as the security community intend on helping the public be safer and more secure together - everywhere from their phones, to their workstations, to their smart homes and embedded devices. How are they supposed to believe us if we don't sound like we know what we're talking about? Or if we perpetually contradict ourselves? Why is SQL injection a problem that's 25 years old? Why can nobody agree on if XSS is important or not? Why are "ping" and "sslv3" critical findings? This presentation will cover some of the pitfalls, landmines, baits, traps, common misconceptions and hazards you can expect to encounter living the infosec life. You will be baited, hunted, attacked, trapped, trolled and victimized. People who have zero experience but can "talk the talk" will put your feet to the fire. You will be called out on contradicting yourself or being a hypocrite. All of this, while you are trying to help. The words you elect to use when communicating about security are directly responsible for your success in making your point. If you are sincerely interested in making a difference, but feel that you just aren't getting through to your audience, this talk is for you.

Dan Tentler is the founder and CEO of The Phobos Group, a boutique information security services company. Previously a co-founder and CTO of Carbon Dynamics, and a security freelancer under the Aten Labs moniker, Dan has found himself in a wide array of different environments, ranging from blue team, to red team, to purple team, to ???evil hacker for a camera crew. When not obtaining shells or explaining against how to get shelled, Dan enjoys FPV racing and crashing drones in new and interesting ways.

Back to Circle City Con 2017 Videos list

Printable version of this article

15 most recent posts on Irongeek.com:


If you would like to republish one of the articles from this site on your webpage or print journal please contact IronGeek.

Copyright 2020, IronGeek
Louisville / Kentuckiana Information Security Enthusiast