I'm angry this morning. Truly angry with myself.

I don't come from money. Growing up, we weren't poor, but near the bottom of the 80's middle class. I always dreamed of being in a better financial position than my parents, but swore I wouldn't forget where I came from.

1/
My first child (of 3) came when I was 17. Married at 21, I lived through nearly two decades of overdrawn bank accounts, maxed out credit cards, collection calls and threats of lawsuits.

Ultimately, we were fortunate. Never had a night where I couldn't scrounge

2/
something together for dinner. I have my family to thank for much of that.

So why I am I giving you this walk through Alyssa's past? Well because now in my 40's I'm in a position that I dreamed of as a child. Financially, while not rich by today's standards, I am in

3/
a very good place and live quite well in that respect.

However, I've been catching myself lately saying things or making judgements that sound very much like I've done exactly what I swore as a kid I wouldn't, forgotten where I came from. And that is not OK with me.

4/
So I'm gonna do what I always do, be mindful of it, try to listen and improve. But I also want to say I'm sorry to anyone who I've impacted with my poor perspectives.

I am sure I've said things where people were like "Well yeah easy for you to say, you've got money".

5/
You're right, and I'm sorry for that. I'm sorry for losing sight of what I went through and the fact that many others experience those challenges and much worse.

So I'm putting this in a tweet thread because I want to reach as many of the people that have noticed me doing

6/
this and offer you my most sincerest of apologies and again to say, I want to and will try to #DoBetterBeBetter. Words matter, words are a reflection of our underlying attitudes and biases. I need to be more aware of mine and more compassionate to others. I will do this!

7/
That said, please enjoy your weekend. If you're celebrating the holiday, I hope it's a Merry one for you. Know that I love you all deeply and I do truly care about you.

/FIN

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Alyssa Miller 👑 Duchess of Hackington

Alyssa Miller 👑 Duchess of Hackington Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @AlyssaM_InfoSec

24 Dec
Christmas more than NYE for me is the time I look back.

I remember so clearly the day I took the red pill. While I knew it'd change my life, many of the changes came in ways I'd have never imagined. So many good things happened this year for me as a result of that day.

1/
I have learned to be authentic in ways I never was before.

That authenticity has allowed me to connect with people in ways I never did before.

Those connections have enabled me to climb mountains in my career and personal life faster than ever before.

2/
Summiting those mountains has given me confidence like never before.

Each climb has brought new amazing people into my life who I love and rely on for support in ways I never could before.

Sure, lots of crappy things happened to me since taking the red pill too.

3/
Read 4 tweets
13 Dec
I certainly believe while we have moved past the tip of the iceberg, we're nowhere done with #log4j and it's issues. EVERYONE is now looking at this package and finding new variants and even new vulns. Don't expect to sleep anytime soon my dear #infosec fam.

1/
That said, remember there are likely malicious actors out there looking for the next thing already. With log4j burnt and orgs rapidly applying mitigations and fixes, what next? Where do we find the next widely used package with significant vulnerabilities like this?

2/
With that in mind, please drop the adversarial bullshit. I've seen devs abdicating all responsibility for the maintainers. I've seen security folks hating on devs. The mistakes made that led to this vuln. are laughably easy (to us as #infosec professionals).

3/
Read 8 tweets
12 Dec
Hey #infosec peeps, many of us are tired, frustrated, and exasperated by #Log4Shell.

That said, how about we not blast developers en-masse or even within OSS or even within the Log4j project. Let's remember we have culpability here as well.

1/
We did nothing with a warning that was given to us in 2016 at BlackHat. Not one detection rule or scanner policy was created.

Despite extensive OSS security research done by orgs and academia, we failed to find this vuln in probably the single most popular Java package.

2/
How many of us are scrambling now because basic security controls (WAF's, Outbound connectivity lockdowns, etc.) that could have limited/prevented exploit of this vulnerability don't exist in our environments?

3/
Read 6 tweets
2 Dec
Thursday morning, back home after a few days of board meetings and I have some thoughts to share on being effective in board presentations. Tech and security leaders still seem to struggle in these settings so here goes:

As always, it's a 🧵

1/
1. Research your board members. Find out in advance who you'll be presenting to and look up their background. Talk to your peers who've chatted with the board before, see what intel you can get from them on the dynamics of those discussions. Prep accordingly.

2/
2. Read the room. Important with any presentation but particularly so in the board room. If they're looking at their phones, you lost them. It maybe that you got to technical. Change things up, change your tone, elevate the message and grab their attention again.

3/
Read 8 tweets
1 Dec
The number of potentially qualified people that I see self-eliminating from open #infosecjobs saddens me. The thing is when you're looking at job descriptions, there are two ways you can look at them.

In typical Alyssa fashion, a 🧵 follows:

1/
Some people will read through the requirements from an implicit mindset of identifying the reasons not to apply. They look for any requirements that suggest they're not qualified and when they find too many of them (for some that means even one), they choose not to apply.

2/
The other method, and the mindset I wish more job seekers would take, is to look at a job description with the focus of finding the reasons to apply. What requirements are things you're good at or could be good at. What responsibilities are areas of interest for you.

3/
Read 6 tweets
21 Nov
FORTY SEVEN

Forty-seven trans people have been violently killed so far in 2021. While this number represents an increasing trend, let's talk about what that number doesn't tell us.

#TDOR #tdor2021

1/
* These are violent crimes, meaning someone else took their lives. This number does not reflect those that took their own lives as a result of unmanageable pressures of discrimination, abandonment, homelessness, forced conversion therapy, etc.

2/
* This number only includes those situations where Law Enforcement documents the victim as transgender. It does not include those killed where police and families hid the gender identity of the victim. This is a common occurrence and skews the numbers heavily.

3/
Read 12 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(