People who cheat & steal harm the rest of us through their actions. These “bad apples” who act in their own self-interest above the common interest tend to rely on secrecy and obfuscation in order to commit their misdeeds.
One can have privacy without secrecy. This is the model being tested in cryptocurrency now.
If you’re interested in learning about some avant-garde technical work, check out the work done by various groups to advance the concept of Decentralized Autonomous Organizations (DAOs).
It would be really cool to establish HackerDAO. I’ve given it a lot of thought, but ultimately I don’t think that it is an ‘idea whose time has come’ for the majority of folks who follow me. These ideas take time to percolate, and DAOs are still a very niche idea at present.
Creating art which is then roundly enjoyed by others has helped me with perfectionism.
Intellectually, I know that ‘perfect is the enemy of good’.
Unfortunately, my standards for my own work are often far too high to encourage incremental progress & learning in public.
2/8
Part of the reason why I feel that way is because the security community is so frequently negatively judging. As this is the community I joined from a young age, it has molded my behavior to be far too constrained & limited — in direct opposition to the hacker ethos.
Have you ever wanted to drop out of infosec and become your own defensive consultant? Learn from us and our mistakes.
Some things @0xBanana and I learned running our first startup, a boutique cybersecurity consultancy 2018-2020.
A thread🧵
1/
Having lots of enterprise contacts will only get you so far.
Lg corps who have interesting infosec problems to solve typically won't hire a small consultancy unless they have a decent assurance the risk of doing so is low, and the value which will be gained will be high.
2/
Small to mid-size corps have much, much less interesting infosec problems to solve.
In this category, orgs who happen to have a budget with which to hire infosec mostly need product-focused security engineering support, and some nascent devsecops capability.
3/
“When presented with such warrant […] Australian companies, system administrators etc. must comply, and actively help the police to modify, add, copy, or delete the data of a person under investigation”
Despite all of the “intractable” problems we seem to have, for at least half of these, money gathered in service of our country and Her people, allocated carefully, is the solution.
Republicans refuse to participate in increasing taxation while claiming to be the party of limited government as justification. Excuse me, that ship sailed long ago.
For neocons, or whatever the GOP even are anymore, a small government is no longer a priority.
2/
The main priority of the GOP leadership (and a few Dem leadership as well), based solely on their actions, appears to be the acquisition & maintenance of power for power’s sake. In politics, money drives the machine, so they’ll do whatever is needed to keep it coming in.
3/