Darren Meyer (@darrenpmeyer) 's Twitter Profile
Darren Meyer

@darrenpmeyer

#InfoSec professional with a heavy focus on #AppSec (currently product and posture consulting). #Blinkenlights and #coffee for fun

ID: 468928589

calendar_today20-01-2012 02:02:39

2,2K Tweet

623 Followers

274 Following

Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

Headed off to #PyConUS, for a little Booth (222 if you want to stop by and maybe win an RGB saber), and a lot of hanging out with fellow Python devs!

Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

Man, there’s a lot of people trying to make the concept of a supply chain dependency really complicated for no reason. Do you depend on it for your stuff to work? Did you get it from outside your org? Congrats, that’s a dependency and it’s in your supply chain.

Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

I had to make this today. I see way too many security people who ought to know better trying to fit facts to theories instead of theories to facts. An adversary doesn’t care about anything except that you have something they want, and whether there’s a path for them to get it.

I had to make this today. I see way too many security people who ought to know better trying to fit facts to theories instead of theories to facts. An adversary doesn’t care about anything except that you have something they want, and whether there’s a path for them to get it.
Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

🍨 If you have a wheat allergy, then it doesn't matter that your cookies-n-cream ice cream doesn't have wheat as a *direct* ingredient, because it's still found *transitively* in the cookie crumble. This applies to software dependencies too! Check it out endorlabs.com/learn/demystif…

Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

In or around Vrije University in Amsterdam? Don’t miss the 20. Juni OWASP Meetup! Two great speakers talking about software dependency management, and of course there will be pizza. Details and free registration: meetup.com/owasp-chapter-…

In or around Vrije University in Amsterdam? Don’t miss the 20. Juni OWASP Meetup! Two great speakers talking about software dependency management, and of course there will be pizza. 

Details and free registration: meetup.com/owasp-chapter-…
Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

We AppSec people have to challenge our nature regularly. We tend to be detail-oriented, but there isn't time to give every issue that treatment. So we have to challenge our nature by developing repeatable, automated processes that are "right enough, most of the time".

Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

The CocoaPods vulns that were just disclosed are a big deal. I sincerely hope that they weren’t widely uncovered by adversaries, but we won’t know for sure for a bit. But if you use CocoaPods, you need to figure out what to do. endorlabs.com/learn/new-coco…

Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

I’m seeing a lot of the take that the #CrowdStrike outage is a lesson not to rely on #Windows. That’s the wrong lesson. Sure, Windows itself has plenty to complain about, but the issue is *monocultures*; maybe don’t have one stack be 100% of your critical infrastructure

Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

Does your #SCA respect your time? We built ours from the ground up with the goal of saving time for #AppSec and Developer teams, instead of wasting precious resources chasing noise. Don’t take my word for it; read Jellyfish’s story: endorlabs.com/learn/jellyfis…

Does your #SCA respect your time? We built ours from the ground up with the goal of saving time for #AppSec and Developer teams, instead of wasting precious resources chasing noise.

Don’t take my word for it; read Jellyfish’s story: endorlabs.com/learn/jellyfis…
Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

It's pretty easy to get sort of consumed by #infosec. But #Burnout is real, and I've seen too many good people get hurt by it. A little #selfcare is important too. Take this as your reminder to drink some water, go for a walk, do something fun and silly with people you care about

Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

Thanks to ringofsteel.org for providing their invaluable expertise — and combat-ready sabers — for the @endorlabs NYC lightsaber training event! Great to work with you, and I’m hoping we get to do so again!

Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

It’s not often you get a chance to lay hands on a prop replica of a lightsaber that actually uses the original parts list!

It’s not often you get a chance to lay hands on a prop replica of a lightsaber that actually uses the original parts list!
Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

If I say "do developer education" and you think "have developers sit in an online class", then please re-think what _education_ means for most professional workers. There's a place for classes, but they're a tiny portion of education, and IMO are wasted if you don't do the rest

Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

We made the #Cyber60 List, again! 🎉 Always appreciate recognition of our ability to solve real problems in #AppSec from orgs like FORTUNE and @LightspeedVP Get the report PDF with the full list direct from Lightspeed at lsvp.com/cyber60-2024-2… #SCA #FortuneCyber60

We made the #Cyber60 List, again! 🎉  Always appreciate recognition of our ability to solve real problems in #AppSec from orgs like <a href="/FortuneMagazine/">FORTUNE</a> and @LightspeedVP

Get the report PDF with the full list direct from Lightspeed at lsvp.com/cyber60-2024-2… 

#SCA #FortuneCyber60
Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

Your SCA tool *completely ignores* transitive dependencies? In 2024? And you're charging a bunch of money for this? I have concerns. Protip: if your expensive tool has a feature doesn't outperform a free, open-source alternative in one important way... stop selling that feature.

Darren Meyer (@darrenpmeyer) 's Twitter Profile Photo

The job of a security org isn't necessarily to "reduce risk". It's to make sure that the org stays within its acceptable risk tolerance, and do that as cost-effectively as you can. In most orgs, reducing risk. But that's tactics in service of the objective.