Lesley Carhart Profile picture
ICS DFIR @dragosinc, martial artist, marksman, humanist, Lvl14 Neutral Good rogue, USAF Ret. Tweet *very serious* things about infosec. Thoughts mine. They/them
13 subscribers
Nov 9, 2022 5 tweets 3 min read
The hacker / infosec Mastodon servers have really reached critical mass to contain useful community and information. If you haven't tried it out yet, I really recommend it. There's enough intel and news to be viable at this point. This isn't a niche hobby thing anymore.
Nov 5, 2022 4 tweets 1 min read
I’m just the ornery retired military person who swaps stories with you, the military member who is drunk and I have never met, at the bar now. We have a great time. Temporary friends are cool.
Oct 31, 2022 4 tweets 1 min read
There's these threads from people laid off at Twitter and the *comments*.... trolls think they're witty, but they just look incredibly jealous of people who make good money in tech and are employable. They come off as devoid of tech knowledge and miserable with their lot in life. Any of these engineers are just going to get immediately rehired for a deep six-figure salary, and the trolls with the incredibad takes about code reviews won't make that money no matter how much they take out their insecurities about their own shortcomings.
Oct 28, 2022 5 tweets 2 min read
Drop your handles on other social networks so that I can follow back? Thank you, me:
mastodon.social/@hacks4pancakes
infosec.exchange/web/@hacks4pan…
counter.social/@hacks4pancakes
instagram.com/hacks4pancakes/
tisiphone.net
hacks4pancakes on tiktok
Oct 26, 2022 5 tweets 1 min read
Yeah, it’s super bad that click-driven social media is a primary source of information and news for large numbers of Americans, but also incredibly depressing it took China being involved in it (naturally) for anyone to care, way too late. “We can control the relatively unknown monster which driven by ultra wealthy corporations because it’s draped in an American flag” is a weird take.
Oct 25, 2022 6 tweets 1 min read
I have always had wild dreams. However, 14-year-old me would be extremely confused at me fighting creeping fascism daily on the computer alongside Godwin, a bunch of annoyed military veterans, Michael Okuda, a few cDc folks, and somehow also George Takei. “Sometimes you will even talk to these luminaries on the internet. Mostly about nazis, and breakfast foods. That’s what we do on the internet in the future”.
Oct 20, 2022 4 tweets 1 min read
Whatever you think of the move (I ditched Netflix a while ago), you have to wonder what the nasty false positives on this are going to look like. From military members, to college kids, to business travelers… locations are hard. Wouldn’t want to be on the team stuck engineering or enforcing this. Big yikes.
Oct 17, 2022 9 tweets 2 min read
Friends, I was asked, so let's talk about why we use the term "mansplaining".

It is gendered because it's referring to a behavior that is frequently performed by men in a way that causes harm, but because it is deeply tied to toxic masculinity and men's feelings of self-worth. It isn't because women can't be condescending, or that non-binary people can't explain things nobody wants to know about. All of us can do bad stuff! However, there's a specific behavior that is commonly taught to young men in our society that hurts people of any gender.
Oct 16, 2022 4 tweets 1 min read
I’m sorry but, martial arts twitter, but can we please talk about the kinda racist undercurrent in quite a few so-called international associations, that sell themselves as global and unity-focused, But no matter how hard you work and what rank you achieve, you’ll never really be allowed to be an elected official. You’ll never be asked to be in photos, or to social events,

Then you get snide comments in a language they don’t think you speak, if you’re not their nationality?
Oct 13, 2022 8 tweets 2 min read
I beg y’all to stop asking me to work hard and prep talks, decks, etc to *promote your company* that I am not employed or paid by, for free.

It’s almost unabashed how little people value my time.

It’s hurting me financially. I’m losing money doing free work out of kindness. If you would otherwise pay an employee to do what you are asking me to spend hours on, and you’re not like a community event, or school or small non profit, etc, I deserve to at least be compensated for my time. It’s unbelievable what profitable companies ask me to do for free.
Oct 6, 2022 4 tweets 1 min read
All the other infosec 'influencers', it feels:
- impressive pro home gym
- posting workouts at 5am
- luxury car photos
- perfect candid head shots

Me, Pancakes:
- pro thriftin' at the Goodwill
- eating peanut butter by the jar
- accidentally ate a hair
- in my Honda
- lets Tweet (That's a compliment, I am super jealous)
Oct 6, 2022 4 tweets 1 min read
OT incident response requires pretty different skillset, mindset, and tools than IT incident response, and if a cybersecurity company tells you otherwise they are trying to sell you something. I call it ‘OT/IT DFIR divergence’, and it makes it challenging to hire and train folks. A lot of low level DFIR jobs at MSSPs that people use to cut their teeth are very EDR/XDR playbook based, and that stuff barely exists in OT. It’s a whole different world in terms of tools and critical thinking.
Oct 2, 2022 4 tweets 1 min read
I’ll never forgive FTX for ruining fortune cookies, and that’s all I associate with them now 🤷🏻‍♀️🍸 What is this crap, why even?
Sep 27, 2022 4 tweets 1 min read
Okay, things are getting a bit dire. I really need a speaker agent. I’m Chicago-based. Referrals welcome. DM, or hacks4pancakes at gmail. If it costs more than my car, sorry but no thank you. I’m trying but this is very hard.
Sep 27, 2022 9 tweets 2 min read
I try to be a dignified, conscientious adult professional and not SHEIN haul, but then it’s 2AM and I find a jacket made out of graffiti and a broccoli necklace. This is very hard to say no to.
Sep 26, 2022 4 tweets 1 min read
I think this is the most interesting comment on this and the most applicable to the people I mentor. I mentor a lot of people who have been through serious trauma and who have grown up very poor (and both) and I think in some ways there's a combination of trauma and imposter syndrome that keeps people from taking the leap into the career, even if I make it easy.
Sep 18, 2022 4 tweets 1 min read
That parent at the tournament for 9 year olds screaming “murder him!!!” at his child 🤷🏻‍♀️🍸 People put some absolutely *insane* pressure on their kids at a non -ranked tournament where *everyone gets a medal*, is all I’m saying. The older kids who burst into tears because they got second. The parents flailing into matches like they’re a trained coach and can object.
Sep 15, 2022 5 tweets 1 min read
This tweet is for a specific type of person - especially young and hungry ones. I’m talking to the ones who jump in and quietly save things whenever their teammates and seniors drop the ball. Sometimes when not too much is on the line, you have to just let them fail. I’m saying this as a manager. Like, have an open dialogue with your boss and give constructive and courteous feedback to your peers first, but if you are constantly silently saving the day and nobody sees it, they’re probably gonna get promoted and you’re not.
Sep 13, 2022 4 tweets 1 min read
Up at 4am dragging the cleaners that lost my suit on every conceivable social media site for what it’s worth, because they still haven’t replaced it and I still don’t own a suit that fits (because I lost a ton of weight and it was pretty expensive). Just such a miserable situation. It was from a company called Kirrin Finch that makes suits for non gender conforming people, and it was super gender-affirming, too. I got to wear it once and I was so damn excited to get it.
Aug 30, 2022 5 tweets 1 min read
Vague-post, but I was at a con last weekend and caught up with some really remarkable, senior, respected people in infosec of whom a surprising multitude are ready to quit their jobs because of poor management and poor leadership at their organizations. It is really shocking. It is 2022 and we're still promoting techy people into leadership positions who do not have basic EQ, understanding of the aspects of good leaders, or any training in team dynamics. There's still nepotism, shocking disregard for labor law, and lack of formal management training.
Aug 27, 2022 6 tweets 1 min read
I am ready (and only a little hung over) to review all your resumes and help you make your cybersecurity career dreams come true @BlueTeamCon today! Come on in, after the keynote - and let us help you!