Showing posts with label tech. Show all posts
Showing posts with label tech. Show all posts

Saturday, February 27, 2021

Learning Python

 I stumbled across what appears to be a great resource for learning Python. It's been over a decade since I've known I need to learn Python. During that time I have taken a Coursera course and written a few scripts here and there, but I still do most of my Python programming by Googling and searching Stack Overflow. That works okay for occasional use, but I have recently found the need to make Python my daily driver. So I went in search of some solutions in the fall. 


I started by looking for something that I could use on my phone. Python Programming: Ultimate guide looked promising, but my enthusiasm for their app waned as I an into some technical difficulties. I should go back and revisit that, though. 

Eventually I found Python Morsels, and I think this is what I need in my life right now. I did the free month-long trial in the fall and I just signed up for a year. The site is created and maintained by Trey Hunner, a Python trainer for teams. I'm still fairly new on my journey there, and he just introduced a new "flexible mode," but the basic structure seems pretty well established. He gives an assignment, reference hints, automated verification, and follow-up discussions of the solutions. I highly recommend it.

The new "flexible mode" sets up a profile that can be made public. Mine's not that interesting, but I expect it will become more so over this next year!


3/11/21 Edit: I just noticed that Trey is a contributor to EditorConfig and his name is on a bunch of the plugins.

Thursday, February 28, 2019

How to Cut Through Vendor Claims & Marketing Hype When Evaluating New Security Tools


I have a new post on the Threat Stack blog.

Check out my other recent Threat Stack posts!

Friday, May 18, 2018

SLDC, SOC 2, and Other Four Letter Words


I have a new post on the Threat Stack blog based on my presentation last week at SOURCE Boston!

Talk description:
Except for any authors of trojans that may have stumbled in accidentally, we all want to write secure applications. In spite of our sincere desires, vulnerable code gets shipped. Why? What do we do to fix it? What can we do to prevent it from happening? The answers exist in the realm of the software development life cycle, or SDLC. Various compliance vehicles (such as SOC2) exist to help us formulate an effective SDLC, but any security expert knows that checking a box does not typically yield the desired results. This talk describes the SDLC used by the agent team at Threat Stack, while also bringing in outside experiences to supplement. It also goes over pitfalls observed and lessons learned. You might not use the same tools or produce the same product, but the talk focuses on principles to make the resulting product more secure.

Check out my other recent Threat Stack posts!

Monday, February 26, 2018

Heading to SOURCE Mesa/Phoenix

This week I'm heading to SOURCE Mesa/Phoenix. While there I will present my talk: SDLC, SOC2, and other four letter words. I'll post the slides for the talk later, but you can read the abstract now:
Except for any authors of trojans that may have stumbled in accidentally, we all want to write secure applications. In spite of our sincere desires, vulnerable code gets shipped. Why? What do we do to fix it? What can we do to prevent it from happening? The answers exist in the realm of the software development life cycle, or SDLC. Various compliance vehicles (such as SOC2) exist to help us formulate an effective SDLC, but any security expert knows that checking a box does not typically yield the desired results. This talk describes the SDLC used by the agent team at Threat Stack, while also bringing in outside experiences to supplement. It also goes over pitfalls observed and lessons learned. You might not use the same tools or produce the same product, but the talk focuses on principles to make the resulting product more secure.
I'm slotted to present on day two, March 1st, at 1:10 pm. So right after lunch. Rob Cheyne interviewed me ahead of the conference to preview my talk, and you can find that on YouTube:


Sorry about the audio. I definitely have some lessons learned there for myself about getting the right equipment and prepping for the discussion a bit better.

I'll be there for both days of the main conference. I look forward to meeting new folks and learning new things!

Monday, May 1, 2017

Eyes on the Ground: Why You Need Security Agents


I have a new post on the Threat Stack blog based on my presentation last week at SOURCE Boston!

Talk description from SOURCE agenda:
Whether you build, buy, borrow, or steal it, you need a security agent on your endpoints. We can already hear your cries of "agent fatigue" and we sympathize. Any agent, no matter how lightweight, has costs associated with running it. Minimize those costs and get an agent, because you need the information that only an agent can harvest from the endpoint. We talk about various types of security agents, including their respective strengths and weaknesses. We explore how agents can interact and interfere with each other, and provide some tips for evaluating agents. We cover open-source, custom-built, and vendor perspectives, from cloud to IoT. We need information to do our jobs, and we need agents on our digital assets to provide that information. 

I exported the keynote slides to slideshare.

Check out my other recent Threat Stack posts!

Monday, April 10, 2017

Welcome SOURCE visitors!

Maybe you've stumbled onto this blog after hearing of me through SOURCE Conference Boston. Welcome! While this blog has links to my professional blog posts, they actually live on my company's blog.


Things that make it onto this blog tend to be things that do not fit elsewhere. That includes the notes for religious talks I give as part of my volunteer position in the LDS (Mormon) church, among other things. Feel free to ask me about them!

Friday, February 12, 2016

My Bit9 posts are dead, long live my Bit9 posts!



Bit9 recently renamed itself to Carbon Black. It looks like they won't be carrying over the Bit9 blog posts to the Carbon Black blog. Makes sense, but it's still kind of a bummer. Good thing we have the WaybackMachine! Nothing dies on the internet, folks:

You can even go and see my old blog profile at Bit9.

Friday, November 13, 2015