41 with two kids, all that time spent working should have been spent experiencing the world and having a lot more fun.
I think a combination of getting more senior at work and having kids reduces your choices in how you can spend your time (To be fair it opens up new options as well). It highlights the value of your time and how little you got in return for it when it was abundant.
It's probably worth remembering that there is an open source exemption. If a piece of 'intrusion software' has been published the export controls no longer apply.
Publish your exploits to github before you send them overseas or travel to the conference to announce them.
Why do you dislike Huawei in particular? I could hazard some guesses but most of the reasons I would guess are present in every other manufacturer I can think of. I'm truly interested in why that's a problem for you.
Apparently they signed up Huawei with a contract where they warranted there were no backdoors in the hardware. Guarantees nothing of course but props for the chutzpah to demand such an outrageous clause in the contract.
When talking about the Iraq dossier there were proven falsehoods.
"Without exception, all of the allegations included within the September Dossier have been since proven to be false, as shown by the Iraq Survey Group."
My guess would the third of your options, it feels like a scanning tool artifact.
However, my point was that even given the age of the OWASP Top 10 and its incredible brand recognition among developers globally, the IBM bulk application scans are still finding (At least some of) these issues.
Interesting point about taxonomies of security flaws, similarly taxonomies of security attacks are also hard (Wicked maybe). This may be due to the difficulty of fully defining the world of unexpected or unwanted application behaviour. There is something complex about the space of possible attacks (or flaws) that resists classification at anything other than at such a level of foundational definition to be practically useless in the real world.
I would strongly recommend reading Clay Christensen's book How will you measure your life? He discusses a general approach to working out what you want to do with your life without telling you what he thinks you should do.
This just made me cry on busy London commuter train. Cathartic but awkward. An incredibly moving story that has reminded me to tell the people that matter to me that they matter to me.
The subject of start-ups and regulators has come up a few times recently and there tends to be a view espoused that regulators are intent on legislating away innovation.
My experience of working alongside or for regulators is that they overwhelmingly do not want to write new law unless they absolutely have to. Law is hard to write, hard to schedule and politically difficult to agree.
Generally regulators prefer industry associations or similar creating 'best practices' that the regulators can then rely on for evidence of recklessness or negligence compared to peers in the industry.
This can lead to established players in a market controlling the regulatory framework for innovation but this is solved through either new players engaging with the industry associations or a truly valuable innovative approach forcing legislators hands.
By not engaging with regulators and industry associations to address best practices the only route left is to be valuable and disruptive enough to require new law which is resisted by all those involved until the last moment possible.
It is always worth remembering that no matter how good your relationship with the regulator is their goals are not yours, they would like you as an industry to be successful but they exist to protect society as a whole and when placed in a position between your success and the perception of harm to society they will enforce regulations strongly.
F-D was mostly awful because it was open. There are plenty of private security forums with a much higher signal to noise ratio.
They perform slightly different functions and rely on a higher level of trust than an open mailing list can deliver but the security community is not uniformly awful.
They didn't single Ubuntu out of a crowd, they just only reviewed Ubuntu which is probably due to the brand name recognition in the government departments the advice was aimed at or possibly the experience of the team doing the review.
I have assumed that was what you were referring to and not a different statement?
41 with two kids, all that time spent working should have been spent experiencing the world and having a lot more fun.
I think a combination of getting more senior at work and having kids reduces your choices in how you can spend your time (To be fair it opens up new options as well). It highlights the value of your time and how little you got in return for it when it was abundant.