![Keith Profile](https://pbs.twimg.com/profile_images/1263501106614693890/ViyqLBp9_x96.jpg)
Keith
@kwm
Followers
3K
Following
5K
Statuses
3K
Award-winning husband and dad. Co-founder @redcanary. Tweets are my own, unless otherwise noted.
Denver, CO, US
Joined March 2007
RT @ryanaraine: Dave Aitel, writing on DailyDave: "This is probably my new favorite podcast, with an uncensored take on current infosec e…
0
8
0
RT @ryanaraine: Quick ear-check with the listeners: What's the ideal length of your favorite podcast?
0
6
0
@ac1dgoddess Inventory matters, for the same reason it matters if you replace nmap with ~100 other dual-use tools. Usage (provenance in particular) should inform threat detection. nmap + known nmap source = meh nmap / nmap-like activity + unknown nmap source = threat
1
1
2
@FrankMcG @BlueTeamCon Source of ongoing debate 🙃 Chase each platform, cross-post galore, but engage poorly everywhere? Optimize for impressions? Engagement? Attempt to grok audience sentiment? 👈 Hardest—moves come in waves, big externalities at play. But again, it's fragmentation vs. migration.
0
0
1
@jeremiahg An assumption on my part, which I realize is dangerous, is that liability is absolutely coming. That said, if I understand your argument, it's that liability would have been a more useful place to start, instead of starting with control mandates. I can get behind that.
1
0
0
@jeremiahg I guess the point I'm trying to make is that "doing something" here *does* depend on "doing something else, too." Have to start somewhere. Getting any leverage over an unregulated industry where we have an acute problem is better than nothing.
0
0
0
@jeremiahg A good q for all the infosec nihilists out there: What's the alternative? Literally do nothing (status quo)? Ban sale of consumer Internet devices (lol)? Something else entirely? Honest question: What gets us "iOS updates" effectiveness, for devices at 20x lower cost/margin?
1
0
0
@jeremiahg The consumer router as a test case: Companies yeet millions (🤷) of these into homes, to be abused with impunity. The most basic monitoring + periodic updates doesn't make the problem go away, but is orders of magnitude better than doing literally nothing at all (status quo).
0
0
0
@ImposeCost Interesting observation. I think younger me was more likely to "focus" on weaknesses. Today, I don't focus on them, but I do pay much more attention to their nature + impact. Some weaknesses are just that (ultimately, opportunities). Some are purely toxic traits (bye bye).
1
0
3