Tarah M. Wheeler Profile picture
CEO @RedQueenDyn♦️ @tarah@infosec.exchange on Mastodon ♦️Sr Flw @CFR_org♦️💍@deviantollam♦️she/her♦️t@tarah.org IG/tarahwheeler LI/tarah
#BlueChecksLose Profile picture 1 subscribed
Nov 10, 2022 5 tweets 1 min read
I run a security company which, among other things, handles compliance. Self-certification by itself is not something "individual engineers" can do on behalf of a company. Arguably an employee can claim to self-certify all they wish, but only an officer can actually do so. An employee would (arguably) not face any consequences from self-certifying their code because they’re not able to act on behalf of the company in terms of compliance.
Oct 5, 2022 15 tweets 10 min read
I and @AlderdiceLord are incredibly pleased to announce the publication of our @USUKFulbright collaboration: "Cyber Collateral: WannaCry & the impact of cyberattacks on the mental health of critical infrastructure defenders."

ccw.ox.ac.uk/blog/2022/10/5… This work assessing the mental health of incident responders in nation-state attacks came from many interviews over Jan-April 2021 of WannaCry responders, technical experts, journalists, & people at @NHSuk.

We found responders do not receive the mental health support they need. Image
Jun 24, 2022 8 tweets 3 min read
After today's devastating news, you might be installing Signal for the first time. Please, expire your old messages automatically (from 4 weeks to as little as 30 seconds!) in case someone unlocks your phone without your consent. Here's how.

1) tap someone's face in Chats.

1/4 Tap on their face/avatar again at the top of your message history.

2/4
Jun 22, 2022 12 tweets 7 min read
For much of the last two years, I've been the @BrookingsInst contributing cybersecurity editor. As I move on from this role with gratitude, I want to take a moment to celebrate some of what I and my intrepid #TechStream editors @EliasGroll & @chrismeserole have published. This mattered. The first piece I wrote called out the dangers in hyperbolic overstatement in what constituted cyberwar. Protip: if not a single human is harmed as a direct result of the attack, it's not cyberwar. brookings.edu/techstream/the…
Jan 19, 2022 7 tweets 5 min read
I need to find something from 1833 in the @nytimes about Ada Lovelace (then, Ada Byron). Can you help me? 🧵 @nytimes Just read “In Byron’s Wake” by @mirandajseymour. Seymour cites an awful comment about Ada Lovelace made in The New York Times that she was “a very coarse and vulgar young woman” after she ran off with the neighbor kid WHEN SHE WAS SIXTEEN YEARS OLD.
Jun 24, 2021 11 tweets 10 min read
🧵After @nhannahjones was announced as the incoming Knight Chair in Race & Investigative Journalism at @UNC, she found that the 5-yr contract the U had offered her didn’t come with tenure bc wealthy interests had strongly lobbied to not grant it to her.

cnn.com/2021/06/23/us/… @nhannahjones @UNC This was a break with tradition. This post, intended to attract pro journalists (possibly what in many places would be called a Professor of Practice, someone *very* well known for doing the thing they teach) was downgraded to a contract like any adjunct instructor.
Mar 1, 2021 6 tweets 2 min read
For any app that asks for your Contacts list: unless you contact each & every person in your list & ask their permission to share their birthday, phone #, real location, all emails, & any notes you have on them w the app you want to install, do not click Allow. It is unethical. I’ve had some questions on what I mean by “location”. When I go look at given friend’s contact info in my Contacts, I see info she does not want shared with the world, including standard fields like Notes or Birthday, as well as her real physical home instead of mailing address.
Jan 11, 2021 5 tweets 3 min read
This is a bug. Trump’s bio site on Dept of State shows “term ended” b\c Yoast SEO Plugin is adding a Zulu time variable. Verify by viewing page source, refresh, & watch Zulu time value change. Pence’s bio also affected. C also unrelated @neilpatel blog. state.gov/biographies/do… ImageImageImage @neilpatel I could be wrong, but I think this is just prep work for the turnover that was either made public due to a variable misconfiguration or at absolute max, someone just added the prep text for the turnover today and didn’t see that it would be public immediately.
Feb 15, 2020 23 tweets 23 min read
I’m concerned about several of the claims made in this blog post from @Voatz.

They claim to be “staffed by cybersecurity experts”. Let’s take a look at that. 1/

blog.voatz.com/?p=1259 @Voatz I’m very open on LinkedIn; I connect with anyone there. I’m connected to thousands, perhaps tens of thousands of people there now. I’d go find the exact number but I find myself not much caring about it.

Until today, when it gives me the chance to see Voatz staff numbers.

2/