kuzushi (@kuzushi) 's Twitter Profile
kuzushi

@kuzushi

founder of @cactuscon · staff at @hackgdl - ex @bishopfox · @spiderlabs · @MVPAward

Hacking - Machine Learning - AppSec - Not a super villian

ID: 17723751

linkhttps://linktr.ee/andrew.wilson calendar_today29-11-2008 00:15:35

9,9K Tweet

807 Followers

349 Following

kuzushi (@kuzushi) 's Twitter Profile Photo

To continue the thread with Justin Gardner, I documented the first part of my 'theory on optimizing hacking'. Before you can do anything else, we have to align on outcomes. It was fun to write up: sensecurity.io/probability-of…

kuzushi (@kuzushi) 's Twitter Profile Photo

You can't fault consumers for being 'checkbox seekers' when the reality is 95.4% of our industry is built around passing blame via compliance.

kuzushi (@kuzushi) 's Twitter Profile Photo

In 2005, CardSystems Solutions was breached and lost 40 million credit cards. They are one of the only cases where the credit card providers revoked their ability to process cards. Their penalty for all of this? Nothing. They sold the business for 47 million dollars.

kuzushi (@kuzushi) 's Twitter Profile Photo

"Analysis of major breach incidents reveals a concerning pattern regarding compliance status at the time of security incidents. Many organizations that experienced significant breaches had recently passed PCI DSS compliance assessments, raising critical

kuzushi (@kuzushi) 's Twitter Profile Photo

Arguing that doing something is better than nothing is actually quite fair-- but it is also always true. It would be better if you walk 10k steps a day. It wouldn't be good if you lost your business over not doing it because a bank said so.

kuzushi (@kuzushi) 's Twitter Profile Photo

I think I am just bitter that they tried to force me to fill out some stupid form and pay them money to inform them that I am not required by their own standards to do anything else.

kuzushi (@kuzushi) 's Twitter Profile Photo

I'd like to clarify my previous tweet. It isn't that I disbelieve that security controls work, I am just really nervous that we built a billion dollar industry on "just trust me bro" validation it works.

kuzushi (@kuzushi) 's Twitter Profile Photo

Guy cuts people off to get off the plane first, then brags about being married to a trust-fund baby. I wish I could make this stuff up.