CRob
1.1K posts

CRob
@SecurityCRob
Security-ologist that herds cats trying to secure free software
The Interwebs Katılım Ağustos 2015
215 Takip Edilen471 Takipçiler

@HackingDave Thank you for everything you have done to help improve our community @HackingDave
English

I'll share something personal, when we ended Derby - it was crushing for me because we had started something different that helped so many people.
It was a vehicle for people to start their careers, get exposure, remove elitism statuses and bring everyone together. So many prominent and brilliant folks in security have publicly as well as privately said DerbyCon started their career in security and changed their life forever. Truth is, they did and we just happened to be a vehicle for that.
Derby donated more to charity than any other conference every single year still to this date. We made zero money off of it other than we would take the team out to a nice dinner after the conference was over to celebrate. Literally everything went into the con and into helping others.
When we decided to end it...I was upset, sad and frankly a bit broken as many of us were. I went to a dark spot.
The truth is I wasn't upset at the people that attacked the con.. it was that I wasn't strong enough to continue to get beaten and battered everyday when minor things would turn into explosions. I took the weight of the world on my shoulders versus reaching out to my friends that would also share that load and be stronger together.
We were a continued target and everyone was waiting for anything they could leverage to go after me and for various reasons and purposes that I still don't truly understand.
At the end of the day, hurt people hurt people.
It's not that I'm not at fault. I am... We didn't handle every situation perfect, but we sure as hell tried to. We learned from those and we got better each time.
I personally shouldn't have responded back so passionately versus trying to understand their perspective.. Truthfully, when you believe in something so much and are helping so many people - when that's attacked - defensiveness comes into play and I was wrong on how I responded out of emotion.
The truth is, the con was one of the safest conferences out there with record low of incidents. It's not that we didn't have incidents as any con with 5K+ people does... but it was always handled with the upmost best way that we possibly could and learned and got better each time.
A lot of the barrage came from a controversial member of the team.. At the end of the day - the role of that individual was less and less each year and my loyalty to friends is not something I regret. I'll always continue to help friends and try to make them a better person even if I might disagree with their views or how they act. Sometimes though it requires that person to change and you can only help them so much before you move on.
For awhile, I felt like I couldn't impact people the way that I could with Derby and felt like I was missing a piece of me and just growing companies.
That changed, because I found that I could help more people in different ways. Continue the Derby legacy without throwing a conference, and without having to deal with the population on social media that tear down other people for their own benefit or self gratification.
At the end of the day, those negative folks that are so prominent in this industry on tearing others down, helped focus me on a different mission that will change more lives than I could have hoped for.
Thank you to those folks. Those personal attacks against my family, children, friends, my character, my reputation, my well-being ... it only helped me be more motivated to make an even larger impact to others. It made me realize these folks lashing out are hurt people themselves.. I should understand them better and try to help them as well as others.
I don't have any motives other than changing lives for the better because I'm so thankful for what I was able to build and the people I get to work with everyday. It's the community and industry that helped the success I have today. I'll always give back to that and not ask for a thing in return.
If you want to know why I am the way I am, I shared a life changing event that happened to me at war where I almost died that gave me a different perspective and outlook on life. It's the first time I ever shared it and I don't even know why I did...I never had before but I felt that I needed to there:
youtube.com/watch?v=SuvbfY…
There you have it. Felt like getting that off my chest since I haven't talked about any of this other than to close friends.

YouTube
English

@HackingDave #Derbycon was magical. The 2 times I had to present there are some of my most treasured speaking experiences. I loved the community there, i loved the helping and teaching, I loved the HyattLou. I have yet to find a conference that has a vibe close to matching it! #TrevorForget
English

<Tap, tap> Is this thing still on? I’m speaking at #OpenSSFDay on May 10th hosted by @openssf@social.lfx.dev in Vancouver. Join me at the event: events.linuxfoundation.org/openssf-day-no… #HONKgoestheGoose

English
CRob retweetledi

Data Fortify is a new systemic mitigation for memory corruption vulnerabilities. Tune in to Chips & Salsa e53 as @jerry_Intel and @SecurityCRob talk to Intel’s @hasarfaty about how Data Fortify helps eliminate classes of attack. youtu.be/iXFJBUgM4sM

YouTube

English

Want to dive into secrets management and do some hunting? try this github.com/OWASP/wrongsec… #secretsmanagement #secrets #hunting #p0wnableapp #OWASP #WrongSecrets
English
CRob retweetledi

Thank you to @SecurityCRob for this fun Q&A we've just posted @openatintel! He shared his optimistic take on the state of #opensource #security, & his work with @theopenssf. Enjoy! Listen to the audio for the full experience. 🎙️🎶 #IamIntel intel.com/content/www/us…
English
CRob retweetledi

@jerry_Intel and @SecurityCRob are back for episode 31 of Chips & Salsa with @YaakovCohen88, @Schtrudel, and @yossioren discussing #HammerScope, a method of observing DRAM power consumption using #Rowhammer. intel.ly/3UghesV #IntelSecurity

English
CRob retweetledi

Our FLOSS Weekly interview with Linux kernel maintainer @gregkh "Secrets of the Linux Kernel" is already up @TWiT! We talked emailing patches, drivers, trust in open source software, and more. Greg is such a nice guy and made this a really fun episode! twit.tv/shows/floss-we…
English
CRob retweetledi

Tune in to the latest episode of Chips & Salsa as @SecurityCRob and I talk to Intel's Scott Constable about a new tool to find potential disclosure gadgets in the Linux Kernel. Read Scotts blog and our results. intel.ly/3tePCbG

English
CRob retweetledi

It's Patch Tuesday! Tune in as @jerry_Intel and @SecurityCRob discuss the November 2022 security advisories in episode 30 of Chips & Salsa: intel.ly/3AlOYxh. #PatchTuesday #IntelSecurity

English

I am speaking at INFORMATION SECURITY SUMMIT 2022. Please check out my talk if you're attending the event! @NEOSecSummit - via #Whova event app

English
CRob retweetledi

Community provides the "critical infrastructure" of #opensource security, says @SecurityCRob
intel.ly/3fP2p10
English
CRob retweetledi

2 New Concise Guides Now Available from the OpenSSF Best Practices for Open Source Developers Working Group 🙌
- Developing More Secure Software
- Evaluating Open Source Software
hubs.la/Q01mncD40 #OSSummit #OSS #Developers #DevSecOps #Security
English

@JudyoBrienKelly @RedHatSecurity @theopenssf Thanks for all of your assistance in bringing these guides out to the community!
English

@WhyHiAnnabelle I am sad I did not get to spend time with one of my favourite oss-peeps
English
CRob retweetledi
CRob retweetledi

"The future is open," says @SecurityCRob of @Intel + @theopenSSF "We work on open standards, tools & processes. "Join us and help us solve these immense problems" #ossummit
English
CRob retweetledi

As #OSS evolved, so has the threat landscape explains @SecurityCRob @intel Trust is built from the foundation, up & down the stack and supply chain #OSSSummit #trust #security

English