Profile avatar
cryptodd.bsky.social
California native, Enterprise Strategy Group analyst, cybersecurity geek, soccer goalkeeping phenom. Crypto = cryptography, Views=mine, Reposts≠endorsement
141 posts 571 followers 1,474 following
Prolific Poster

Come visit us at the Kubernetes SIG Security booth in the #KubeCon Project Pavilion! We’re at booth P-17B 💙☸️💙

New, by me: How Each Pillar of the 1st Amendment is Under Attack In an address to Congress this month, President Trump claimed he had "brought free speech back to America." But barely two months into his second term, the president has waged an unprecedented […] [Original post on infosec.exchange]

Talks from the 0xCON 2024 security conference, which took place last November, are available on YouTube Just three now... hoping for more: www.youtube.com/playlist?lis...

Peter Marks, FDA’s top vaccine regulator, forced out www.statnews.com/2025/03/28/f... via @statnews.com

Here's my take on the @wiz_io acquisition & how #cloudnative security solutions have evolved. This a 🔥 space and this post explores the evolution over the past 10 years. #cloudsecurity #CSPs #cloudnative #devsecops #applicationsecurity #appsec www.techtarget.com/searchsecuri... via @techtargetnews

I spoke to Wired about the 23andMe bankruptcy and how the company would protect your data. Spoiler: It won't.

LOL!

Valuable info for anybody who has used 23andMe. #deleteyourdata

This is hands-down the most insane national security reporting I have ever read — the White House accidentally included Jeffrey Goldberg in a principal's Signal group to coordinate military strikes in Yemen www.theatlantic.com/politics/arc...

Microsoft is going to town on Security Copilot AI Agents. Today's announcement will alleviate a lot of #cybersecurity analyst burdens with agents for vulnerability remediation, DLP investigation, AI infrastructure security - www.theverge.com/news/634598/...

Saying a judge granting a TRO on your obviously unconstitutional attack on a law firm is "treason" is seriously fucked up. In any other time, with any other President, this would be blasted all over the headlines and people would be asking about impeachment/25th Amendment. But... here? Now? Nothing

VERY IMPORTANT to label this as what it is, The Police State Executive Order. it's not an exaggeration. This is the inner wiring of a police state.

Veeam RCE bug lets domain users hack backup servers, patch now

#Trump moves to fire Democratic #FTC commissioners. The move, which critics say is unconstitutional, also potentially threatens numerous agency investigations and enforcement around privacy and cybersecurity. via @derekbjohnson.bsky.social cyberscoop.com/trump-moves-...

This is a great fit! Stimulating Risky Business commentary and better informed portfolio companies.

Today seems to be "Data Loss Prevention" day in cybersecurity land. MIND Security comes out with an announcement and Orion Security comes out of stealth. I'm honored to be quoted in the @darkreading.bsky.social coverage - www.darkreading.com/insider-thre...

There is zero question in my mind this was initially deployed in an attempt to circumvent established network security controls. In cybersecurity, we have a term for when an authorized user knowingly tries to evade security controls. It's "insider threat."

A new MIND #cybersecurity report explains the state of data loss prevention (#DLP) and Insider Risk Prevention! This fresh Enterprise Strategy Group research covers current enterprise DLP key challenges. mind.io/newsroom/min...

You youngsters wouldn't know this. But: phone people for Soc Sec admin are actually *great.* My wife has been dealing w them before/after death of her mother, at 102. Entirely diff from AI-based, phone-tree-maze, outsourced hell of airline/insurance/warranty phone "support." Informed + competent.

Super interesting intersection of data security ( #DSPM) & data management that Bedrock Security solves for. The Metadata Lake enables Security teams to assess and reduce risk sensitive data while IT teams managing data can understand data & track data movement. blog.bedrock.security/news-article...

@kgreifeld.bsky.social There is an imposter account that you need to be aware of - bsky.app/profile/kati...

Concerned about DOGE stealing your personal information? File a FOIA request to find out what they've done with your data. To do that, here's a letter you can fill out, sign, and send. Courtesy of Congressman Jamie Raskin. s3.us-east-1.amazonaws.com/ak-raskin/im...

Interesting Rubrik commentary during earnings call of how integrating Data Security Posture Management (#DSPM) into Rubric Security Cloud drives DSPM adoption.ESG Data Resilience research showed enterprise plan to deploy DSPM over next 12-24 months- It is happening. ir.rubrik.com/news-events/...

I got to testify to the House Select Committee on the Chinese Communist Party last week. One focus area was the threat from TP-Link routers. Having 60% of the US consumer Wi-Fi market flooded with devices that get automatic software updates from the PRC is a risk we can't accept.

Nice @laurelwams.bsky.social article on DOGE accessing citizen data. If DOGE claims to have read-only access, take it with a grain of salt. Read-only access allows someone to copy data to another location, say to train a GenAI model. www.npr.org/2025/03/11/n...

New publication from @gitguardian.com on the problem of secrets sprawl in GitHub. Non-human identities ( #NHI) like secrets are a festering part of the enterprise #cybersecurity attack surface - www.gitguardian.com/state-of-sec... .

Security starts with trust, and trust starts with people. At Seclore, we foster collaboration, curiosity, and shared success—solving complex challenges while building real connections. Ready to join us? Explore careers: bit.ly/3X7frd8 #PeopleFirst #DataSecurity #NowHiring

New Enterprise Strategy Group research delivered by @harmonicsec.bsky.social on the state of #cybersecurity data loss prevention ( #dlp). Underscores problems with alert noise and policy consistency along with new use cases like #GenAI apps. www.harmonic.security/resources/es...

Juicy new #cybersecurity research by Enterprise Strategy Group highlighting state of data loss prevention ( #DLP) and the enterprise desire for change to solve problems like alert noise and new use cases like #GenAI applications. www.harmonic.security/resources/es...

To be crystal clear: 1. Measles is a nasty disease 2. You cannot treat measles with antibiotics or cod liver oil 3. The measles vaccine is very safe and highly effective, as shown by the ELIMINATION OF THE DISEASE IN THE US FOR 25 YEARS 4. RFK Jr. is an ignorant fool

Be careful out there! If someone tries to push you to urgently do something financial, slow down and don't be pressured.

If Donald Trump & Elon Musk have it their way, your Social Security will be privatized and your benefits will be entirely reliant on the stock market. If you want a sense of what that'll be like – take a look at your 401k today.

Can't even secure Twitter's servers -- but sure, give him control over Govt servers in social security, IRS, Justice, Medicaid and Medicare .. and let him 'update' the air traffic control system. I mean, c'mon folks. @wired.com doing the work, again. www.wired.com/story/x-ddos...

Insights into the value of veterans, the US Veterans Administration and the cybersecurity impact of recent cuts.

Kudos to @liccardo.house.gov for a spicy and informative town hall in Mountain View CA today. The Republican reps may be hiding, but Sam is out there listening to his Silicon Valley constituents.

"The Trumpists are no longer at the height of glory. They control the executive branch, Congress, the Supreme Court, and social media. But in American history, the supporters of freedom have always won. They are starting to raise their heads." Raise your head. www.theatlantic.com/internationa...

Response from student leaders at @georgetownlaw.bsky.social: “While we did not expect to be fighting for our basic First Amendment rights, we are prepared to do so—we will not waver, cower, nor hesitate.”

I'm a friend of @techdirt.bsky.social and this piece explains why. If you value journalism and American democratic institutions, think about being a friend of Techdirt - www.techdirt.com/2025/03/04/w...

@rmogull.com will there be a Disaster Recovery Breakfast for RSA Conference 2025? It is normally the highlight of my RSA experience.

This seems bad.

New, by me: U.K. health giant HCRG, which was hacked last month, demanded a U.S.-based cybersecurity journalist who writes at DataBreaches.net "take down" their reporting, citing a U.K. court order. The journalist declined to comply, citing a lack of jurisdiction. techcrunch.com/2025/03/06/h...