Eric Grosse (@n2vi) 's Twitter Profile
Eric Grosse

@n2vi

infosec, pilot, husband/father/grandad.

ID: 42266519

linkhttp://n2vi.com calendar_today24-05-2009 19:30:53

177 Tweet

974 Followers

174 Following

Niels Provos (@nielsprovos) 's Twitter Profile Photo

Interested in joining a world-class security team Stripe? I am hiring for many interesting security roles. Do you bring low ego/high empathy? Do you have great engineering taste? Do you know how to build scalable systems and the value of simplicity? bit.ly/ZfNa1

Interested in joining a world-class security team <a href="/Stripe/">Stripe</a>? I am hiring for many interesting security roles. Do you bring low ego/high empathy? Do you have great engineering taste? Do you know how to build scalable systems and the value of simplicity? 

bit.ly/ZfNa1
Communications of the ACM (@cacmmag) 's Twitter Profile Photo

"Implementing Insider Defenses," by Eric Grosse Eric Grosse, Fred Schneider Cornell University, and Lynette Millett National Academies, on #benefits and #challenges of involving people in cyber #defense bit.ly/32OWZJL. And video on Department of Defense 🇺🇸, private sector practices bit.ly/3xAxHNM

"Implementing Insider Defenses," by Eric Grosse <a href="/n2vi/">Eric Grosse</a>, Fred Schneider <a href="/Cornell/">Cornell University</a>, and Lynette Millett <a href="/theNASEM/">National Academies</a>, on #benefits and #challenges of involving people in cyber #defense bit.ly/32OWZJL. And video on <a href="/DeptofDefense/">Department of Defense 🇺🇸</a>, private sector practices bit.ly/3xAxHNM
Eric Grosse (@n2vi) 's Twitter Profile Photo

Thanks @[email protected] -- Follow me there for arstechnica.com/information-te… and earlier articles about FIDO. In January I ranted in n2vi.com/Auth.pdf about some related issues, in an effort to help OMB strengthen federal agencies' logins.

Institute for Security and Technology (@ist_org) 's Twitter Profile Photo

IST continues the design development for CATALINK, an additive 21st century nuclear crisis communication solution that can be used in the lead up to, during, or after a crisis.

IST continues the design development for CATALINK, an additive 21st century nuclear crisis communication solution that can be used in the lead up to, during, or after a crisis.
Eric Grosse (@n2vi) 's Twitter Profile Photo

Kudos to Yubico for this program and for their partnership with Hideez to equip Ukraine. #YubiKey is the single best thing ordinary folks can adopt to protect accounts they care about.

Eric Grosse (@n2vi) 's Twitter Profile Photo

At dispute is whether, after data was deleted, to classify as breach + extortion + ransom payment or as vulnerability demonstration + pressuring a vendor to fix their security + bug bounty. It can be argued either way. 2/9

Eric Grosse (@n2vi) 's Twitter Profile Photo

It would be good if Congress created crisp and workable definitions, but they haven't despite trying. Alternatively, it would be ok for a series of court decisions over time to create law by setting civil fines against companies. 3/9

Eric Grosse (@n2vi) 's Twitter Profile Photo

To jump to felony conviction of an individual is unfair. To selectively prosecute only one person for actions within existing prevailing norms is deeply unfair. 4/9

Eric Grosse (@n2vi) 's Twitter Profile Photo

Years ago in that role at Google, I argued for always going public whether breach or bug. The temporary pain was outweighed by the long-term trust it built with customers. This was not a popular or universally-accepted position. 5/9

Eric Grosse (@n2vi) 's Twitter Profile Photo

But I was in the privileged position of a fantastic security team with fantastic support from management. Many CISOs are not so lucky. Infosec is hard, rules are murky, resources are limited, and facts are uncertain or late. 6/9

Eric Grosse (@n2vi) 's Twitter Profile Photo

Federal prosecution here is foolish as well. The enemy isn't Joe Sullivan, the enemy is GRU and CCP and NK and ransomware gangs. Start putting your allies in jail and you'll have fewer allies. 7/9

Eric Grosse (@n2vi) 's Twitter Profile Photo

Various agencies of the federal government have done a lot of bad things in infosec over the years. For me, this prosecution is the last straw. 8/9