<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>The Security Shit Show</title><link>https://youtube.com/c/SecurityShitShow</link><description><![CDATA[Information security is mostly a shit show, so we made the Security Shit Show.<br /><br />This is the place where shit gets real. No filter. Straight talk about shit that ain’t right in the information security industry (or life in general). <br /><br />Three industry experts share their daily experiences and pick a topic to discuss each week. The Security Shit Show is LIVE on Thursday nights and the fans are ENCOURAGED to participate. If it’s not fun, it’s definitely good therapy!<br /><br />This is not a commercial podcast, meaning we won't be hocking product or taking sponsors. We suppose this could change sometime in the future, but probably not.]]></description><atom:link href="https://www.spreaker.com/show/4388802/episodes/feed" rel="self" type="application/rss+xml"/><language>en</language><category>Technology</category><copyright>Copyright The InfoSec Mission</copyright><image><url>https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cff8fc06d2c768cbc5934b90509bbe8c.jpg</url><title>The Security Shit Show</title><link>https://youtube.com/c/SecurityShitShow</link></image><lastBuildDate>Mon, 09 Feb 2026 18:51:31 +0000</lastBuildDate><itunes:author>The InfoSec Mission</itunes:author><itunes:owner><itunes:name>The InfoSec Mission</itunes:name><itunes:email>feeds@spreaker.com</itunes:email></itunes:owner><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cff8fc06d2c768cbc5934b90509bbe8c.jpg"/><itunes:subtitle>Information security is mostly a shit show, so we made the Security Shit Show.&#13;
&#13;
This is the place where shit gets real. No filter. Straight talk about shit that ain’t right in the information security industry (or life in general). &#13;
&#13;
Three...</itunes:subtitle><itunes:summary><![CDATA[Information security is mostly a shit show, so we made the Security Shit Show.<br /><br />This is the place where shit gets real. No filter. Straight talk about shit that ain’t right in the information security industry (or life in general). <br /><br />Three industry experts share their daily experiences and pick a topic to discuss each week. The Security Shit Show is LIVE on Thursday nights and the fans are ENCOURAGED to participate. If it’s not fun, it’s definitely good therapy!<br /><br />This is not a commercial podcast, meaning we won't be hocking product or taking sponsors. We suppose this could change sometime in the future, but probably not.]]></itunes:summary><itunes:category text="Technology"/><itunes:explicit>true</itunes:explicit><podcast:guid>eb0b0712-16a7-59d2-9db8-f1f02bd27775</podcast:guid><itunes:type>episodic</itunes:type><item><title>Episode #97 Head in the Clouds</title><link>https://www.spreaker.com/episode/episode-97-head-in-the-clouds--50480847</link><description><![CDATA["Why going to the cloud means more work for security not less, shared responsiblity is 100% your problem <br />- Am I going to treat this like a green field, or the next dumpster to throw the data, systems, and stuff we can’t deal with in real life? <br />- What are my expectations? (planning, timing, longevity, migration, business, etc.)<br />- Will we use it as an enclave to simply separate developers from anything else, or vice-versa, OR will we take a stance and work with ALL the teams to build it out successfully?<br />- DOES my cloud governance align with the rest of my business and technology policies and goals?<br />- AM I willing to implement the recommendations that most cloud providers offer TO make things safer and more secure?<br />- Can I manage the audit and compliance of a new world, and HOW will I integrate it?<br />- Speaking of integration, WILL my business and technology actually function IN/WITH the cloud?<br />- The cloud is MUCH more than someone else’s computers OR a spare data centre, but it still has to live somewhere, so WHERE does it live, and HOW do you get to it?<br />- Where’s YOUR staff, how do they talk with the cloud, what controls, management, etc.<br />- How much control will I have over my data in YOUR cloud?<br />- Who’s got access TO my little slice of the cloud, hardware, system, bare metal, data, etc.<br />- How do I (OR who’s going to) monitor YOUR cloud infrastructure, and MY systems for access, etc.<br />    - And if it’s on your side, do I get to see the logs<br />    - What’s the charges FOR monitoring<br />    - SLA’s etc?<br />-  Who’s managing the encryption for my data, if it’s YOU then where’s my key’s if it’s me what help etc.<br />- I don’t want to catch cooties from YOUR other clients, how to you maintain separation/segmentation?<br />- What options exist to backup my data, my configs, and what happens if YOUR systems go down?<br />- What areas of the technology, services, systems, and environments fall into shared responsibilities?<br />    - Who has to deal with what when it goes wrong<br />    - Who get’s to point fingers, and who has to fix things (AND what timeframe, etc.)<br />- ALL my data belongs to YOU… what happens about uptime, distribution, redundancy, AND company stability.<br />    - Technology roadmap in here too<br />    - What dependencies, partnerships, and vendors do THEY rely upon?<br />- Let’s talk security, compliance, regulatory stance, etc. What do you have, AND how do you maintain it?<br />- When we fall OUT of love, what happens, how do I migrate, what options are out there (and costs, etc.)"]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/50480847</guid><pubDate>Mon, 11 Jul 2022 14:30:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/50480847/episode_97_head_in_the_clouds.mp3" length="91265280" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>"Why going to the cloud means more work for security not less, shared responsiblity is 100% your problem &#13;
- Am I going to treat this like a green field, or the next dumpster to throw the data, systems, and stuff we can’t deal with in real life? &#13;
-...</itunes:subtitle><itunes:summary><![CDATA["Why going to the cloud means more work for security not less, shared responsiblity is 100% your problem <br />- Am I going to treat this like a green field, or the next dumpster to throw the data, systems, and stuff we can’t deal with in real life? <br />- What are my expectations? (planning, timing, longevity, migration, business, etc.)<br />- Will we use it as an enclave to simply separate developers from anything else, or vice-versa, OR will we take a stance and work with ALL the teams to build it out successfully?<br />- DOES my cloud governance align with the rest of my business and technology policies and goals?<br />- AM I willing to implement the recommendations that most cloud providers offer TO make things safer and more secure?<br />- Can I manage the audit and compliance of a new world, and HOW will I integrate it?<br />- Speaking of integration, WILL my business and technology actually function IN/WITH the cloud?<br />- The cloud is MUCH more than someone else’s computers OR a spare data centre, but it still has to live somewhere, so WHERE does it live, and HOW do you get to it?<br />- Where’s YOUR staff, how do they talk with the cloud, what controls, management, etc.<br />- How much control will I have over my data in YOUR cloud?<br />- Who’s got access TO my little slice of the cloud, hardware, system, bare metal, data, etc.<br />- How do I (OR who’s going to) monitor YOUR cloud infrastructure, and MY systems for access, etc.<br />    - And if it’s on your side, do I get to see the logs<br />    - What’s the charges FOR monitoring<br />    - SLA’s etc?<br />-  Who’s managing the encryption for my data, if it’s YOU then where’s my key’s if it’s me what help etc.<br />- I don’t want to catch cooties from YOUR other clients, how to you maintain separation/segmentation?<br />- What options exist to backup my data, my configs, and what happens if YOUR systems go down?<br />- What areas of the technology, services, systems, and environments fall into shared responsibilities?<br />    - Who has to deal with what when it goes wrong<br />    - Who get’s to point fingers, and who has to fix things (AND what timeframe, etc.)<br />- ALL my data belongs to YOU… what happens about uptime, distribution, redundancy, AND company stability.<br />    - Technology roadmap in here too<br />    - What dependencies, partnerships, and vendors do THEY rely upon?<br />- Let’s talk security, compliance, regulatory stance, etc. What do you have, AND how do you maintain it?<br />- When we fall OUT of love, what happens, how do I migrate, what options are out there (and costs, etc.)"]]></itunes:summary><itunes:duration>5705</itunes:duration><itunes:keywords>chris,chrisroberts,cloud,cloutier,cybersecurity,evan,evanfrancen,francen,infosec,podcast,roberts,ryan,ryancloutier,security,securityshitshow,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cff8fc06d2c768cbc5934b90509bbe8c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode #96 Dude where is my data</title><link>https://www.spreaker.com/episode/episode-96-dude-where-is-my-data--50476013</link><description><![CDATA[Information security tells us that the job it is all about protecting data, protecting the confidentiality, integrity, and availability of the data ultimately to protect the human(s) the data is about.  <br /><br />On average each human creates 146,880 MB of data per day for a staggering total of 1.145 trillion MB a day or 2.5 Quintillion bytes WHOA that’s a lot of data, where is all this data coming from and more importantly where is it going, who has it and how is it being used?<br />How do I know my data is safe? <br />How do I know I can trust that it is accurate?<br />How do I know where my data is, has been, and is going?<br />How will my data be used to manipulate and or harm me?<br />DUDE Where is my data? And what are you doing with it?]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/50476013</guid><pubDate>Thu, 07 Jul 2022 16:30:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/50476013/episode_96_dude_where_is_my_data_1.mp3" length="104160575" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Information security tells us that the job it is all about protecting data, protecting the confidentiality, integrity, and availability of the data ultimately to protect the human(s) the data is about.  &#13;
&#13;
On average each human creates 146,880 MB of...</itunes:subtitle><itunes:summary><![CDATA[Information security tells us that the job it is all about protecting data, protecting the confidentiality, integrity, and availability of the data ultimately to protect the human(s) the data is about.  <br /><br />On average each human creates 146,880 MB of data per day for a staggering total of 1.145 trillion MB a day or 2.5 Quintillion bytes WHOA that’s a lot of data, where is all this data coming from and more importantly where is it going, who has it and how is it being used?<br />How do I know my data is safe? <br />How do I know I can trust that it is accurate?<br />How do I know where my data is, has been, and is going?<br />How will my data be used to manipulate and or harm me?<br />DUDE Where is my data? And what are you doing with it?]]></itunes:summary><itunes:duration>6510</itunes:duration><itunes:keywords>chris,chrisroberts,cloutier,data,evan,evanfrancen,francen,informationsecurity,infosec,podcast,privacy,roberts,ryan,ryancloutier,security,securityshitshow,shit,show,talk,truth</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cff8fc06d2c768cbc5934b90509bbe8c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode #95 So, what is it that you'd say you do here_</title><link>https://www.spreaker.com/episode/episode-95-so-what-is-it-that-you-d-say-you-do-here--50384142</link><description><![CDATA["Lots of us say that information security is EVERYONE'S responsibility. While this is sort of true, we use this as a copout more than anything else. The truth is, everyone has information security responsibilities but information security is NOT everyone's responsibility. <br /><br />See what we did there?<br /><br />Everyone has information security responsibilities. So, let's start at the top and work our way down. The Board of Directors, the CEO, other C-Levels, etc. <br /><br />Hey, CISO, what is it that you'd say you do here? <br />The quality of your answer might say everything we need to know. You either know or you don't. <br />If you know, share the answer with us (simpler, shorter answers are usually an indication of mastery, just sayin'). <br />If you don't know, that's OK, BUT ONLY IF you don't pretend you do and you seek out the answer.<br /><br />Now that we got that squared away, MAYBE we can figure out what everyone else's responsibilities are. If we don't get this right, how the hell are we going to hold anyone accountable. If we can't hold anyone accountable, how the hell are we going to get any better?"]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/50384142</guid><pubDate>Tue, 05 Jul 2022 17:55:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/50384142/episode_95_so_what_is_it_that_you_d_say_you_do_here.mp3" length="125520379" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>"Lots of us say that information security is EVERYONE'S responsibility. While this is sort of true, we use this as a copout more than anything else. The truth is, everyone has information security responsibilities but information security is NOT...</itunes:subtitle><itunes:summary><![CDATA["Lots of us say that information security is EVERYONE'S responsibility. While this is sort of true, we use this as a copout more than anything else. The truth is, everyone has information security responsibilities but information security is NOT everyone's responsibility. <br /><br />See what we did there?<br /><br />Everyone has information security responsibilities. So, let's start at the top and work our way down. The Board of Directors, the CEO, other C-Levels, etc. <br /><br />Hey, CISO, what is it that you'd say you do here? <br />The quality of your answer might say everything we need to know. You either know or you don't. <br />If you know, share the answer with us (simpler, shorter answers are usually an indication of mastery, just sayin'). <br />If you don't know, that's OK, BUT ONLY IF you don't pretend you do and you seek out the answer.<br /><br />Now that we got that squared away, MAYBE we can figure out what everyone else's responsibilities are. If we don't get this right, how the hell are we going to hold anyone accountable. If we can't hold anyone accountable, how the hell are we going to get any better?"]]></itunes:summary><itunes:duration>7845</itunes:duration><itunes:keywords>chrisroberts,ciso,cybersecurity,evanfrancen,informationsecurity,infosec,live,officespace,podcast,responsibilities,ryancloutier,security,securityshitshow,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cff8fc06d2c768cbc5934b90509bbe8c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode #94 Top 10 Let's talk Baselines</title><link>https://www.spreaker.com/episode/episode-94-top-10-let-s-talk-baselines--50382445</link><description><![CDATA[Let's talk intelligence, machine learning, quantum and ALL the various future technologies and things we should be asking OURSELVES and OTHERS (our vendors, partners, suppliers, etc.) As we go forth into this brave new world...]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/50382445</guid><pubDate>Fri, 01 Jul 2022 19:30:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/50382445/episode_94_top_10_let_s_talk_baselines.mp3" length="86880470" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Let's talk intelligence, machine learning, quantum and ALL the various future technologies and things we should be asking OURSELVES and OTHERS (our vendors, partners, suppliers, etc.) As we go forth into this brave new world...</itunes:subtitle><itunes:summary><![CDATA[Let's talk intelligence, machine learning, quantum and ALL the various future technologies and things we should be asking OURSELVES and OTHERS (our vendors, partners, suppliers, etc.) As we go forth into this brave new world...]]></itunes:summary><itunes:duration>5430</itunes:duration><itunes:keywords>ai,baseline,chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,ml,podcast,ryancloutier,security,shit,show,truth</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cff8fc06d2c768cbc5934b90509bbe8c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode #93 All this quantum talk has me entangled</title><link>https://www.spreaker.com/episode/episode-93-all-this-quantum-talk-has-me-entangled--50380167</link><description><![CDATA[Every day we inch closer to a new computing reality, the arrival of commercially stable quantum computing, we hear about this new disruptive technology, that when unleashed will break the worlds strongest encryption in nanoseconds, that is a very scary proposition for any info-sec professional.<br /><br />There is work being done today to make quantum resistant encryption or so we hope. It is already difficult enough to secure and keep up with the systems that make up our modern world. Systems that are overly complex and running trillions and trillions of lines of code just using 1’s and 0’s, systems we already fail to protect every day, in part due to the complexity of them.<br /><br />If you think current technology is complex and at times confusing, you haven’t seen anything yet, quantum introduces a whole new level of complexity and way of thinking about what is happening, and why.<br /><br />What does this mean for us in the information security industry, will future system admins need PHD’s in quantum physics and discreet mathematics? Will we all need to get our CQISSP? Can we secure quantum? How will our world change? What new things we will be able to do? How will quantum be abused and misused by criminals and nation states.<br />So may questions so little answers, tune in for a fun discussion on the impact of quantum computing and what the grey hairs have to say about it.<br /><br />All this and more on the Security Shit Show with Evan Francen, Chris Roberts, and Ryan Cloutier<br /><br />Thursdays' at 10pm central / 9pm mountain]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/50380167</guid><pubDate>Wed, 29 Jun 2022 21:10:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/50380167/episode_93_all_this_quantum_talk_has_me_entangled.mp3" length="110480535" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Every day we inch closer to a new computing reality, the arrival of commercially stable quantum computing, we hear about this new disruptive technology, that when unleashed will break the worlds strongest encryption in nanoseconds, that is a very...</itunes:subtitle><itunes:summary><![CDATA[Every day we inch closer to a new computing reality, the arrival of commercially stable quantum computing, we hear about this new disruptive technology, that when unleashed will break the worlds strongest encryption in nanoseconds, that is a very scary proposition for any info-sec professional.<br /><br />There is work being done today to make quantum resistant encryption or so we hope. It is already difficult enough to secure and keep up with the systems that make up our modern world. Systems that are overly complex and running trillions and trillions of lines of code just using 1’s and 0’s, systems we already fail to protect every day, in part due to the complexity of them.<br /><br />If you think current technology is complex and at times confusing, you haven’t seen anything yet, quantum introduces a whole new level of complexity and way of thinking about what is happening, and why.<br /><br />What does this mean for us in the information security industry, will future system admins need PHD’s in quantum physics and discreet mathematics? Will we all need to get our CQISSP? Can we secure quantum? How will our world change? What new things we will be able to do? How will quantum be abused and misused by criminals and nation states.<br />So may questions so little answers, tune in for a fun discussion on the impact of quantum computing and what the grey hairs have to say about it.<br /><br />All this and more on the Security Shit Show with Evan Francen, Chris Roberts, and Ryan Cloutier<br /><br />Thursdays' at 10pm central / 9pm mountain]]></itunes:summary><itunes:duration>6905</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,information,informationsecurity,infosec,podcast,quantum,ryancloutier,security,shit,show,talk</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cff8fc06d2c768cbc5934b90509bbe8c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode #92  Math's Don't Lie, Humans Do.</title><link>https://www.spreaker.com/episode/episode-92-math-s-don-t-lie-humans-do--50373244</link><description><![CDATA[Don't overthink this, human. Just take my word for it. Math is beautiful, math is your friend, and math is trustworthy. Math DOES NOT lie. Math can be used to figure out bank balances, areas of shapes, rates of acceleration, even the angle of the sun in Asunción Paraguay at 11:42am (local time) on May 7th, 2022. The list of useful things math can do is endless. You, human, you're a different story. You are also beautiful, and you might be my friend, but you are not trustworthy. Humans have emotions. Humans have bias. Worst of all, humans LIE! What do we do when the math doesn't match up with the story you've told? You mention risk, math (whom I trust) tells me one thing, but you tell me something different. Why?]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/50373244</guid><pubDate>Mon, 27 Jun 2022 21:30:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/50373244/episode_92_math_s_don_t_lie_humans_do_security_shit_show.mp3" length="119440326" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Don't overthink this, human. Just take my word for it. Math is beautiful, math is your friend, and math is trustworthy. Math DOES NOT lie. Math can be used to figure out bank balances, areas of shapes, rates of acceleration, even the angle of the sun...</itunes:subtitle><itunes:summary><![CDATA[Don't overthink this, human. Just take my word for it. Math is beautiful, math is your friend, and math is trustworthy. Math DOES NOT lie. Math can be used to figure out bank balances, areas of shapes, rates of acceleration, even the angle of the sun in Asunción Paraguay at 11:42am (local time) on May 7th, 2022. The list of useful things math can do is endless. You, human, you're a different story. You are also beautiful, and you might be my friend, but you are not trustworthy. Humans have emotions. Humans have bias. Worst of all, humans LIE! What do we do when the math doesn't match up with the story you've told? You mention risk, math (whom I trust) tells me one thing, but you tell me something different. Why?]]></itunes:summary><itunes:duration>7465</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,math,podcast,ryancloutier,security,shit,show,talk,truth,verdad</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cff8fc06d2c768cbc5934b90509bbe8c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode #91 It takes a village to raise a geek</title><link>https://www.spreaker.com/episode/episode-91-it-takes-a-village-to-raise-a-geek--50371082</link><description><![CDATA[I'm fortunate, I am surrounded by good people whom are NOT like me, they bring different experiences, lives, thoughts, deeds, and viewpoints to all of life's interactions. That pool of good people continues to ebb and flow, often going weeks, months, and years between conversations. Some are thankfully more regular, and like clockwork we sit, talk, share ideas and breath a sigh of relief that all IS good in the world, at least at the very table we're occupying...<br /><br />The key is to raising the geek right? Don't shelter them. Don't surround them with kin, and DO put them in a world that will challenge them, force them to reconsider their views, open their eyes, and look beyond what is presented simply with first sight.<br /><br />Why this?<br /><br />Because sometimes we loose sight of what is important, what keeps us grounded, and that the world around us IS different, and that IS a good thing, it's something that we should NOT label, not poke at, ridicule, attempt to redirect with humor, or discount.. OR something we should NOT let others do either.<br /><br />That village? It's family. My Family.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/50371082</guid><pubDate>Sun, 26 Jun 2022 20:10:20 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/50371082/episode_91_it_takes_a_village_to_raise_a_geek.mp3" length="55920562" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>I'm fortunate, I am surrounded by good people whom are NOT like me, they bring different experiences, lives, thoughts, deeds, and viewpoints to all of life's interactions. That pool of good people continues to ebb and flow, often going weeks, months,...</itunes:subtitle><itunes:summary><![CDATA[I'm fortunate, I am surrounded by good people whom are NOT like me, they bring different experiences, lives, thoughts, deeds, and viewpoints to all of life's interactions. That pool of good people continues to ebb and flow, often going weeks, months, and years between conversations. Some are thankfully more regular, and like clockwork we sit, talk, share ideas and breath a sigh of relief that all IS good in the world, at least at the very table we're occupying...<br /><br />The key is to raising the geek right? Don't shelter them. Don't surround them with kin, and DO put them in a world that will challenge them, force them to reconsider their views, open their eyes, and look beyond what is presented simply with first sight.<br /><br />Why this?<br /><br />Because sometimes we loose sight of what is important, what keeps us grounded, and that the world around us IS different, and that IS a good thing, it's something that we should NOT label, not poke at, ridicule, attempt to redirect with humor, or discount.. OR something we should NOT let others do either.<br /><br />That village? It's family. My Family.]]></itunes:summary><itunes:duration>3495</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,geek,information,infosec,podcast,real,ryancloutier,security,shit,show,truth</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cff8fc06d2c768cbc5934b90509bbe8c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode #90 Keeping up with change</title><link>https://www.spreaker.com/episode/episode-90-keeping-up-with-change--50370362</link><description><![CDATA[When I sit back and think about it so much has changed in the last 24 months almost every part of our life’s is in some way much different now then it was before, and in others it is very much the same old story, so how do we keep up with all this change while keeping our sanity intact.<br /><br />Even in the last couple of weeks the cybersecurity landscape has changed significantly. The world has gone from “not going to happen to me”, or “we are doing enough to be compliant” to I need all the security and I need it now. The rules have changed, the risk has changed, the pace has changed. We have changed as a society and as an industry. Many of us have new opportunities, new roles, and new responsibilities, and for those of us who care there is too much to do, to much to take on to meet our goals and God forbid find time to take care of ourselves to prevent burn out and dropping to many of the wrong things disappointing ourselves and those we care about.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/50370362</guid><pubDate>Sun, 26 Jun 2022 18:05:50 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/50370362/episode_90_keeping_up_with_change.mp3" length="96480575" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>When I sit back and think about it so much has changed in the last 24 months almost every part of our life’s is in some way much different now then it was before, and in others it is very much the same old story, so how do we keep up with all this...</itunes:subtitle><itunes:summary><![CDATA[When I sit back and think about it so much has changed in the last 24 months almost every part of our life’s is in some way much different now then it was before, and in others it is very much the same old story, so how do we keep up with all this change while keeping our sanity intact.<br /><br />Even in the last couple of weeks the cybersecurity landscape has changed significantly. The world has gone from “not going to happen to me”, or “we are doing enough to be compliant” to I need all the security and I need it now. The rules have changed, the risk has changed, the pace has changed. We have changed as a society and as an industry. Many of us have new opportunities, new roles, and new responsibilities, and for those of us who care there is too much to do, to much to take on to meet our goals and God forbid find time to take care of ourselves to prevent burn out and dropping to many of the wrong things disappointing ourselves and those we care about.]]></itunes:summary><itunes:duration>6030</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,data,dog,evanfrancen,information,infosec,mexico,ryancloutier,security,shit,show,tiger</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cff8fc06d2c768cbc5934b90509bbe8c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Seventy-Six - What the hell were they thinking?</title><link>https://www.spreaker.com/episode/episode-seventy-six-what-the-hell-were-they-thinking--48220968</link><description><![CDATA[We’ve talked a little in the past about inner voices, and how some folks don’t have one (which I still find fascinating, and would offer up one of mine if you aren’t fortunate enough to have a traveling companion in your noggin); however, this conversation takes it a little further. <br /><br />I’d like to unpack both some historic “what the heck” moments, as well as look at some of the current issues we see with folks opening their mouths before engaging their brain…. <br /><br />OR <br /><br />Is it that people still have an entitled mentality and think they can get away with it and simply apologize IF caught/found out/called out? We see the same behavior in our industry across numerous areas, from individuals grooming others, to put-downs, elitism, and denial…. (not the river) all of them COULD be mitigated if folks just paused, looked around, evaluated the situation, and then thought about things before inserting one or both feet in their mouth. Let’s talk about why this happens, and why we still don’t seem to be able to tackle it.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/48220968</guid><pubDate>Mon, 10 Jan 2022 15:30:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/48220968/episode_76_what_the_hell_were_they_thinking.mp3" length="111520418" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>We’ve talked a little in the past about inner voices, and how some folks don’t have one (which I still find fascinating, and would offer up one of mine if you aren’t fortunate enough to have a traveling companion in your noggin); however, this...</itunes:subtitle><itunes:summary><![CDATA[We’ve talked a little in the past about inner voices, and how some folks don’t have one (which I still find fascinating, and would offer up one of mine if you aren’t fortunate enough to have a traveling companion in your noggin); however, this conversation takes it a little further. <br /><br />I’d like to unpack both some historic “what the heck” moments, as well as look at some of the current issues we see with folks opening their mouths before engaging their brain…. <br /><br />OR <br /><br />Is it that people still have an entitled mentality and think they can get away with it and simply apologize IF caught/found out/called out? We see the same behavior in our industry across numerous areas, from individuals grooming others, to put-downs, elitism, and denial…. (not the river) all of them COULD be mitigated if folks just paused, looked around, evaluated the situation, and then thought about things before inserting one or both feet in their mouth. Let’s talk about why this happens, and why we still don’t seem to be able to tackle it.]]></itunes:summary><itunes:duration>6970</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,podcast,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5306c202592ad8daf64c6fe96fd7f9d9.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Seventy-Five - Security Shit Show New Year Special</title><link>https://www.spreaker.com/episode/episode-seventy-five-security-shit-show-new-year-special--48124475</link><description><![CDATA[HAPPY NEW YEAR!<br /><br />Join us as we wrap up and do a recap of 2021 what a year it has been lots to unpack here. <br /><br />We will also be laying down our predictions for 2022, will Evan ever put on pants? Will Chris migrate his soul to the cloud? Will Ryan shut the Fark up? So many things to predict!<br /><br />Who will be the biggest breach?<br />Will we finally see something other than "password" as the #1 bad password?<br />How many critical vulnerabilities will be from the 90's in 2022?<br /><br />All this and more on the Security Shit Show New Year Special.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/48124475</guid><pubDate>Sat, 01 Jan 2022 06:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/48124475/episode_75_security_shit_show_new_year_special.mp3" length="96240666" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>HAPPY NEW YEAR!

Join us as we wrap up and do a recap of 2021 what a year it has been lots to unpack here. 

We will also be laying down our predictions for 2022, will Evan ever put on pants? Will Chris migrate his soul to the cloud? Will Ryan shut...</itunes:subtitle><itunes:summary><![CDATA[HAPPY NEW YEAR!<br /><br />Join us as we wrap up and do a recap of 2021 what a year it has been lots to unpack here. <br /><br />We will also be laying down our predictions for 2022, will Evan ever put on pants? Will Chris migrate his soul to the cloud? Will Ryan shut the Fark up? So many things to predict!<br /><br />Who will be the biggest breach?<br />Will we finally see something other than "password" as the #1 bad password?<br />How many critical vulnerabilities will be from the 90's in 2022?<br /><br />All this and more on the Security Shit Show New Year Special.]]></itunes:summary><itunes:duration>6016</itunes:duration><itunes:keywords>2021,2022,chrisroberts,colonialpipeline,cybersecurity,evanfrancen,fun,happynewyear,humor,informationsecurity,infosec,newyear,ryancloutier,securityshitshow,solarwinds,truth</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/ccfee0b209baec600353209cde1f1411.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Seventy-Four - The Security Shit Show Christmas Special</title><link>https://www.spreaker.com/episode/episode-seventy-four-the-security-shit-show-christmas-special--48123816</link><description><![CDATA[Merry Christmas to all!! <br /><br />The Security Shit Show crew wants to take a moment to show our appreciation for all of you! This Christmas special is just a small token of our appreciation for you. Tune in for what is sure to be some holiday joy filled antics. <br /><br />No topic, no agenda just some good friends, good beverages, laughs and love. Come join us and be in your ugliest Christmas sweater, we may be bringing you on the show live to share your holiday joy with the listeners.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/48123816</guid><pubDate>Fri, 31 Dec 2021 21:06:53 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/48123816/episode_74_the_security_shit_show_christmas_special.mp3" length="89040483" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Merry Christmas to all!! 

The Security Shit Show crew wants to take a moment to show our appreciation for all of you! This Christmas special is just a small token of our appreciation for you. Tune in for what is sure to be some holiday joy filled...</itunes:subtitle><itunes:summary><![CDATA[Merry Christmas to all!! <br /><br />The Security Shit Show crew wants to take a moment to show our appreciation for all of you! This Christmas special is just a small token of our appreciation for you. Tune in for what is sure to be some holiday joy filled antics. <br /><br />No topic, no agenda just some good friends, good beverages, laughs and love. Come join us and be in your ugliest Christmas sweater, we may be bringing you on the show live to share your holiday joy with the listeners.]]></itunes:summary><itunes:duration>5565</itunes:duration><itunes:keywords>chrisroberts,christmas,cybersecurity,evanfrancen,humor,informationsecurity,infosec,merrychristmas,podcast,ryancloutier,securityshitshow,truth</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/93c592700d926fb3727da9f0f9856583.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Seventy-Three - Simple is NOT Easy</title><link>https://www.spreaker.com/episode/episode-seventy-three-simple-is-not-easy--47996394</link><description><![CDATA[Humans are creatures of energy conservation; it is baked into our DNA as part of our natural survival instincts, this natural tendency is what lead us to invent tools to help us get more done with less effort.<br /><br />We are always looking for ways to make things easier on ourselves, usually with little to no regard for the long-term impact of such a convenience. This is true in every part of the human experience but it's magnified 100 times in the world of information and cyber security. <br /><br />The reason that “Easy button” marketing works is because we all want an easier path to the win, the problem is hard work is not easy, no magic button or set of technology can eliminate hard work. it can evolve it, move it, reduce it, but all we are doing is shuffling the hard work to some other place or person.<br /><br />For example, when we go to the grocery store it is easy to pick up our produce, meat, our prepackaged and prepared meals and put it in our cart. Very rarely do we stop to think of all the people involved, and the very hard work they put in to get that food on the shelf. Growing food is hard work, running the logistics to get that food from the farm to the store is hard work even with the help of machines and computers.<br /><br />Information and cyber security are no different, it takes a ton of hard work to do it right, we preach that the enemy of good information security is complexity, so then simple is its ally, easy right?<br />Simple is not easy simple is a ton of hard work, it is asking tough questions, digging for answers, it is building understanding, communication, documentation, trial, and error. <br /><br />Now knowing that humans prefer to limit the amount of hard work they do, to conserve energy incase they need to run away from a saber tooth tiger, or some other primal drivers, how do we shift this paradigm?<br /><br />We do not ask enough of the right questions; we are in a hurry to find a solution that will make it easier on us to accomplish our goals, we need to do a better job of connecting on that primal level and showing that doing the hard work saves energy and resources in the long run.<br /><br />For me this begins with speaking simply to the business, avoiding technical terms as much as possible, showing that I am as invested in helping them to conserve energy as they are, working hard to understand the business driver and value behind the ask, helping them to identify existing solutions that meet their needs, without needing to add another magic button to the environment, that will most certainly not be magic or easy. Helping them to understand the impact later to convenience now.<br /><br />Most business leaders will not want to create a situation in the future where the business is unable to function because someone wanted one less step in their day.<br /><br />All this and more on the Security Shit Show Thursday at 2100 Mountain/2200 Central]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47996394</guid><pubDate>Mon, 20 Dec 2021 14:40:17 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47996394/episode_73_simple_is_not_easy.mp3" length="75919491" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Humans are creatures of energy conservation; it is baked into our DNA as part of our natural survival instincts, this natural tendency is what lead us to invent tools to help us get more done with less effort.

We are always looking for ways to make...</itunes:subtitle><itunes:summary><![CDATA[Humans are creatures of energy conservation; it is baked into our DNA as part of our natural survival instincts, this natural tendency is what lead us to invent tools to help us get more done with less effort.<br /><br />We are always looking for ways to make things easier on ourselves, usually with little to no regard for the long-term impact of such a convenience. This is true in every part of the human experience but it's magnified 100 times in the world of information and cyber security. <br /><br />The reason that “Easy button” marketing works is because we all want an easier path to the win, the problem is hard work is not easy, no magic button or set of technology can eliminate hard work. it can evolve it, move it, reduce it, but all we are doing is shuffling the hard work to some other place or person.<br /><br />For example, when we go to the grocery store it is easy to pick up our produce, meat, our prepackaged and prepared meals and put it in our cart. Very rarely do we stop to think of all the people involved, and the very hard work they put in to get that food on the shelf. Growing food is hard work, running the logistics to get that food from the farm to the store is hard work even with the help of machines and computers.<br /><br />Information and cyber security are no different, it takes a ton of hard work to do it right, we preach that the enemy of good information security is complexity, so then simple is its ally, easy right?<br />Simple is not easy simple is a ton of hard work, it is asking tough questions, digging for answers, it is building understanding, communication, documentation, trial, and error. <br /><br />Now knowing that humans prefer to limit the amount of hard work they do, to conserve energy incase they need to run away from a saber tooth tiger, or some other primal drivers, how do we shift this paradigm?<br /><br />We do not ask enough of the right questions; we are in a hurry to find a solution that will make it easier on us to accomplish our goals, we need to do a better job of connecting on that primal level and showing that doing the hard work saves energy and resources in the long run.<br /><br />For me this begins with speaking simply to the business, avoiding technical terms as much as possible, showing that I am as invested in helping them to conserve energy as they are, working hard to understand the business driver and value behind the ask, helping them to identify existing solutions that meet their needs, without needing to add another magic button to the environment, that will most certainly not be magic or easy. Helping them to understand the impact later to convenience now.<br /><br />Most business leaders will not want to create a situation in the future where the business is unable to function because someone wanted one less step in their day.<br /><br />All this and more on the Security Shit Show Thursday at 2100 Mountain/2200 Central]]></itunes:summary><itunes:duration>4745</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,live,podcast,ryancloutier,securityshitshow,simple</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f7bf80a504a6927d516c4bfbc7f71171.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Seventy-Two - Tell me lies, tell me sweet little lies...</title><link>https://www.spreaker.com/episode/episode-seventy-two-tell-me-lies-tell-me-sweet-little-lies--47996258</link><description><![CDATA[Let's try this again.<br /><br />Read the title of the episode. Are you singing the song in your head right now?<br />You know, the hit song by Fleetwood Mac? Here, I'll help you out.<br /><br />     If I could turn the page<br />     In time then I'd rearrange just a day or two<br />     Close my, close my, close my eyes<br />     But I couldn't find a way<br />     So I'll settle for one day to believe in you<br />     Tell me, tell me, tell me lies<br /><br />Haha, now you got it!<br /><br />What the hell does this have to do with information security? <br />Well, nothing really, if we're just talking about the song. The theme for this episode of the Security Shit Show is just "LIES", not the song Little Lies, but when I started writing this introduction, I squirreled. <br /><br />OK, let's get to it...<br /><br />Lies are everywhere in our industry. Hell, they're everywhere in general! We ARE the Security Shit Show, so we'll keep it to information security (I think).<br /><br />Lies are told and believed so often in the information security industry, we start to question what reality we're living in! In case you missed it, Chris wrote a LinkedIn post earlier this week:<br /><a href="https://www.linkedin.com/posts/sidrag.." rel="noopener">https://www.linkedin.com/posts/sidrag..</a>.<br /><br />At the end of his post, he posed a question (with a poll). <br />Which LIE is the worst we tell everyone?<br />     Option 1: We CAN protect you!<br />     Option 2: Endpoint will solve it ALL!<br />     Option 3: Just install “x” technology<br />     Option 4: “Other” leave No.x below :)<br /><br />Interesting, eh? Got me thinking...<br /><br />     Why do we lie so much in this industry?<br />     Is it OK to lie in certain circumstances?<br />     Is it OK to lie if everyone else is?<br />     Is one lie worse than another?<br />     Do people even realize they're lying?<br />     Do we just accept the lies?<br />     What about lies of omission, clearly they aren't as bad as lies of commission, right?<br />     Am I a liar? Are you?<br /><br />The truth is...<br />            (watch the show to find out)! <br /><br />We're going to tear this one up and you'll enjoy the fireworks! If not, drinks are on Chris.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47996258</guid><pubDate>Mon, 20 Dec 2021 14:35:17 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47996258/episode_72_tell_me_lies_tell_me_sweet_little_lies.mp3" length="140961463" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Let's try this again.

Read the title of the episode. Are you singing the song in your head right now?
You know, the hit song by Fleetwood Mac? Here, I'll help you out.

     If I could turn the page
     In time then I'd rearrange just a day or two...</itunes:subtitle><itunes:summary><![CDATA[Let's try this again.<br /><br />Read the title of the episode. Are you singing the song in your head right now?<br />You know, the hit song by Fleetwood Mac? Here, I'll help you out.<br /><br />     If I could turn the page<br />     In time then I'd rearrange just a day or two<br />     Close my, close my, close my eyes<br />     But I couldn't find a way<br />     So I'll settle for one day to believe in you<br />     Tell me, tell me, tell me lies<br /><br />Haha, now you got it!<br /><br />What the hell does this have to do with information security? <br />Well, nothing really, if we're just talking about the song. The theme for this episode of the Security Shit Show is just "LIES", not the song Little Lies, but when I started writing this introduction, I squirreled. <br /><br />OK, let's get to it...<br /><br />Lies are everywhere in our industry. Hell, they're everywhere in general! We ARE the Security Shit Show, so we'll keep it to information security (I think).<br /><br />Lies are told and believed so often in the information security industry, we start to question what reality we're living in! In case you missed it, Chris wrote a LinkedIn post earlier this week:<br /><a href="https://www.linkedin.com/posts/sidrag.." rel="noopener">https://www.linkedin.com/posts/sidrag..</a>.<br /><br />At the end of his post, he posed a question (with a poll). <br />Which LIE is the worst we tell everyone?<br />     Option 1: We CAN protect you!<br />     Option 2: Endpoint will solve it ALL!<br />     Option 3: Just install “x” technology<br />     Option 4: “Other” leave No.x below :)<br /><br />Interesting, eh? Got me thinking...<br /><br />     Why do we lie so much in this industry?<br />     Is it OK to lie in certain circumstances?<br />     Is it OK to lie if everyone else is?<br />     Is one lie worse than another?<br />     Do people even realize they're lying?<br />     Do we just accept the lies?<br />     What about lies of omission, clearly they aren't as bad as lies of commission, right?<br />     Am I a liar? Are you?<br /><br />The truth is...<br />            (watch the show to find out)! <br /><br />We're going to tear this one up and you'll enjoy the fireworks! If not, drinks are on Chris.]]></itunes:summary><itunes:duration>8811</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,lies,podcast,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/70aee699bb08a87e6cbec9aceab2a1cf.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>POSTPONED - Episode #72 Tell me lies, tell me sweet little lies...</title><link>https://www.spreaker.com/episode/postponed-episode-72-tell-me-lies-tell-me-sweet-little-lies--47996046</link><description><![CDATA[The original show (outlined below) is DEFERRED to next week. One of the show hosts was unavailable for this one.<br /><br />Are you singing the song in your head right now?<br />You know, the hit song by Fleetwood Mac? Here, I'll help you out.<br /><br />     If I could turn the page<br />     In time then I'd rearrange just a day or two<br />     Close my, close my, close my eyes<br />     But I couldn't find a way<br />     So I'll settle for one day to believe in you<br />     Tell me, tell me, tell me lies<br /><br />Haha, now you got it!<br /><br />What the hell does this have to do with information security? <br />Well, nothing really, if we're just talking about the song. The theme for this episode of the Security Shit Show is just "LIES", not the song Little Lies, but when I started writing this introduction, I squirreled. <br /><br />OK, let's get to it...<br /><br />Lies are everywhere in our industry. Hell, they're everywhere in general! We ARE the Security Shit Show, so we'll keep it to information security (I think).<br /><br />Lies are told and believed so often in the information security industry, we start to question what reality we're living in! In case you missed it, Chris wrote a LinkedIn post earlier this week:<br /><a href="https://www.linkedin.com/posts/sidragon1_oh-the-lies-we-tell-having-just-landed-activity-6871732134323765248-VokQ" rel="noopener">https://www.linkedin.com/posts/sidragon1_oh-the-lies-we-tell-having-just-landed-activity-6871732134323765248-VokQ</a><br /><br />At the end of his post, he posed a question (with a poll). <br />Which LIE is the worst we tell everyone?<br />     Option 1: We CAN protect you!<br />     Option 2: Endpoint will solve it ALL!<br />     Option 3: Just install “x” technology<br />     Option 4: “Other” leave No.x below :)<br /><br />Interesting, eh? Got me thinking...<br /><br />     Why do we lie so much in this industry?<br />     Is it OK to lie in certain circumstances?<br />     Is it OK to lie if everyone else is?<br />     Is one lie worse than another?<br />     Do people even realize they're lying?<br />     Do we just accept the lies?<br />     What about lies of omission, clearly they aren't as bad as lies of commission, right?<br />     Am I a liar? Are you?<br /><br />The truth is...<br />            (watch the show to find out)! <br /><br />We're going to tear this one up and you'll enjoy the fireworks! If not, drinks are on Chris.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47996046</guid><pubDate>Mon, 20 Dec 2021 14:28:04 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47996046/postponed_episode_72_tell_me_lies_tell_me_sweet_little_lies.mp3" length="26560601" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The original show (outlined below) is DEFERRED to next week. One of the show hosts was unavailable for this one.

Are you singing the song in your head right now?
You know, the hit song by Fleetwood Mac? Here, I'll help you out.

     If I could turn...</itunes:subtitle><itunes:summary><![CDATA[The original show (outlined below) is DEFERRED to next week. One of the show hosts was unavailable for this one.<br /><br />Are you singing the song in your head right now?<br />You know, the hit song by Fleetwood Mac? Here, I'll help you out.<br /><br />     If I could turn the page<br />     In time then I'd rearrange just a day or two<br />     Close my, close my, close my eyes<br />     But I couldn't find a way<br />     So I'll settle for one day to believe in you<br />     Tell me, tell me, tell me lies<br /><br />Haha, now you got it!<br /><br />What the hell does this have to do with information security? <br />Well, nothing really, if we're just talking about the song. The theme for this episode of the Security Shit Show is just "LIES", not the song Little Lies, but when I started writing this introduction, I squirreled. <br /><br />OK, let's get to it...<br /><br />Lies are everywhere in our industry. Hell, they're everywhere in general! We ARE the Security Shit Show, so we'll keep it to information security (I think).<br /><br />Lies are told and believed so often in the information security industry, we start to question what reality we're living in! In case you missed it, Chris wrote a LinkedIn post earlier this week:<br /><a href="https://www.linkedin.com/posts/sidragon1_oh-the-lies-we-tell-having-just-landed-activity-6871732134323765248-VokQ" rel="noopener">https://www.linkedin.com/posts/sidragon1_oh-the-lies-we-tell-having-just-landed-activity-6871732134323765248-VokQ</a><br /><br />At the end of his post, he posed a question (with a poll). <br />Which LIE is the worst we tell everyone?<br />     Option 1: We CAN protect you!<br />     Option 2: Endpoint will solve it ALL!<br />     Option 3: Just install “x” technology<br />     Option 4: “Other” leave No.x below :)<br /><br />Interesting, eh? Got me thinking...<br /><br />     Why do we lie so much in this industry?<br />     Is it OK to lie in certain circumstances?<br />     Is it OK to lie if everyone else is?<br />     Is one lie worse than another?<br />     Do people even realize they're lying?<br />     Do we just accept the lies?<br />     What about lies of omission, clearly they aren't as bad as lies of commission, right?<br />     Am I a liar? Are you?<br /><br />The truth is...<br />            (watch the show to find out)! <br /><br />We're going to tear this one up and you'll enjoy the fireworks! If not, drinks are on Chris.]]></itunes:summary><itunes:duration>1660</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,podcast,postponed,ryancloutier,securityshitshow,short</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5ae751edbff1d424c28e9663cd83ecc3.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Seventy-One - You talkin' to me_ You talkin' to me_ You talkin' to me_</title><link>https://www.spreaker.com/episode/episode-seventy-one-you-talkin-to-me-you-talkin-to-me-you-talkin-to-me--47995896</link><description><![CDATA[Every time I encounter an ego in our industry, I immediately think they are channeling their inner Robert Denerio. Or when I run into a vendor who is in the protection racket, buy my tool or else. I remember We are here to protect people not to provide “protection”<br /><br />Why do we feel the need to act like gangsters and thugs, bullying our way around, scaring the people we are supposed to be protecting. Our industry is rife with extortion tactics and borderline criminal business practices all in the name of helping, but the only thing we seem to be helping is our pockets to get fatter. When your sales strategy is a quote from Vito Corleone “I’m gonna make him an offer he can’t refuse.” Something is wrong.<br /><br />You say you want to help, yet your help is behind a registration wall, your “help” comes with a constant barrage of unsolicited emails telling me how if I just buy more of your shit, I can stop the cybercriminals. Forget the fact your own security is probably in shambles and your marketing email is how your customer is going to get infected.<br /><br />If you need to behave like a quote from a gangster, I suggest you quote Tony Montana<br /><br />“All I have in this world is my balls and my word, and I don’t break them for no one.”<br /><br />Remember this sage wisdom from Mario Puzo “The lawyer with the briefcase can steal more money than the man with the gun.”<br /><br />“Listen to me very carefully. There are three ways of doing things around here: the right way, the wrong way, and the way that I do it. You understand?” – Ace Rothstein<br /><br /> If we are going to keep acting like the criminals, we are trying to stop then we should have gangster names so at least there is some authenticity to our actions.<br /><br />Join Spotted Dick Roberts, Mind Fuck Francen and Pretty Face Cloutier for a lively discussion tonight on the Security Shit Show.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47995896</guid><pubDate>Mon, 20 Dec 2021 14:24:42 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47995896/episode_71_you_talkin_to_me_you_talkin_to_me_you_talkin_to_me.mp3" length="103759334" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Every time I encounter an ego in our industry, I immediately think they are channeling their inner Robert Denerio. Or when I run into a vendor who is in the protection racket, buy my tool or else. I remember We are here to protect people not to...</itunes:subtitle><itunes:summary><![CDATA[Every time I encounter an ego in our industry, I immediately think they are channeling their inner Robert Denerio. Or when I run into a vendor who is in the protection racket, buy my tool or else. I remember We are here to protect people not to provide “protection”<br /><br />Why do we feel the need to act like gangsters and thugs, bullying our way around, scaring the people we are supposed to be protecting. Our industry is rife with extortion tactics and borderline criminal business practices all in the name of helping, but the only thing we seem to be helping is our pockets to get fatter. When your sales strategy is a quote from Vito Corleone “I’m gonna make him an offer he can’t refuse.” Something is wrong.<br /><br />You say you want to help, yet your help is behind a registration wall, your “help” comes with a constant barrage of unsolicited emails telling me how if I just buy more of your shit, I can stop the cybercriminals. Forget the fact your own security is probably in shambles and your marketing email is how your customer is going to get infected.<br /><br />If you need to behave like a quote from a gangster, I suggest you quote Tony Montana<br /><br />“All I have in this world is my balls and my word, and I don’t break them for no one.”<br /><br />Remember this sage wisdom from Mario Puzo “The lawyer with the briefcase can steal more money than the man with the gun.”<br /><br />“Listen to me very carefully. There are three ways of doing things around here: the right way, the wrong way, and the way that I do it. You understand?” – Ace Rothstein<br /><br /> If we are going to keep acting like the criminals, we are trying to stop then we should have gangster names so at least there is some authenticity to our actions.<br /><br />Join Spotted Dick Roberts, Mind Fuck Francen and Pretty Face Cloutier for a lively discussion tonight on the Security Shit Show.]]></itunes:summary><itunes:duration>6485</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,gangsters,informationsecurity,infosec,podcast,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c91533ac68e32383d4505d6f78726a13.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Seventy - Can I put that on my tab please</title><link>https://www.spreaker.com/episode/episode-seventy-can-i-put-that-on-my-tab-please--47995717</link><description><![CDATA[Remember those days?<br />Remember the scene?<br />Remember when that was semi-acceptable?<br /><br />Yea… long time ago, in a country pub a LONG ways away.<br /><br />You might still have the luxury OF doing that in your favorite restaurant, bar, pub, or location…. Heck when you go to a hotel or entertainment location you can put things on the tab, HOWEVER in those cases they’ve already charged you for the room, and they DO have your credit card on file.<br /><br />Yet we think it’s ok to run up a tab with people in this industry?<br /><br />We think it’s ok to have folks do work for us, then invoice us, and THEN maybe pay in 30 days?<br /><br />We think it’s ok to get services for free while WE invoice our clients ahead of time?<br /><br />We think it’s ok to take advantage of people’s kindness and then when it comes time to pay we throw roadblocks, request, and all sorts of ridiculous demands (can you send a canceled check, proof of a bank account, a letter from the financial institution, can you copy 4 people from accounting, and BTW one is on holiday for the next 2 weeks, etc.)<br /><br />This is something that’s affecting me at a personal level, and I don’t think folks realize, understand, or simply want to acknowledge that we ALL have bills to pay, we ALL have folks depending upon us, and we ALL value our time, services, and work efforts to a point where you don’t get to take advantage of them for a month or two before paying at least something FOR those services.<br /><br />Not only that, when was the last time you called out a plumber, electrician, or other professional trade, and when presented with the invoice explained that you’ll pay in 30 days IF they provide you with 3 references, their first born and a blood sample? They’d rip out your new shiny HVAC unit and walk off in disgust, same with any contractor coming into your home, they have expenses, costs, systems to purchase and don’t need your numpty ass defaulting on things. It’s risk management 101 and we ALL have to deal with it.<br /><br />SO, next time someone send in an RFP, SOW, LOI, or document asking for some of the funds up front realize it’s because they’re also human, they rely upon income, and YOU are a risk to them. Treat them like a human and don’t be an ass about paying up front for a portion of the work effort, after all BOTH parties are risking something. <br /><br />Yes, you can get something for nothing, and yes many of us want to (and often DO) help, often putting mission before money, but that doesn’t put food on the table… that invoice you have DOES… remember that please.<br /><br />And no, you can’t put it on your tab….]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47995717</guid><pubDate>Mon, 20 Dec 2021 14:20:07 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47995717/episode_70_can_i_put_that_on_my_tab_please.mp3" length="125760287" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Remember those days?
Remember the scene?
Remember when that was semi-acceptable?

Yea… long time ago, in a country pub a LONG ways away.

You might still have the luxury OF doing that in your favorite restaurant, bar, pub, or location…. Heck when you...</itunes:subtitle><itunes:summary><![CDATA[Remember those days?<br />Remember the scene?<br />Remember when that was semi-acceptable?<br /><br />Yea… long time ago, in a country pub a LONG ways away.<br /><br />You might still have the luxury OF doing that in your favorite restaurant, bar, pub, or location…. Heck when you go to a hotel or entertainment location you can put things on the tab, HOWEVER in those cases they’ve already charged you for the room, and they DO have your credit card on file.<br /><br />Yet we think it’s ok to run up a tab with people in this industry?<br /><br />We think it’s ok to have folks do work for us, then invoice us, and THEN maybe pay in 30 days?<br /><br />We think it’s ok to get services for free while WE invoice our clients ahead of time?<br /><br />We think it’s ok to take advantage of people’s kindness and then when it comes time to pay we throw roadblocks, request, and all sorts of ridiculous demands (can you send a canceled check, proof of a bank account, a letter from the financial institution, can you copy 4 people from accounting, and BTW one is on holiday for the next 2 weeks, etc.)<br /><br />This is something that’s affecting me at a personal level, and I don’t think folks realize, understand, or simply want to acknowledge that we ALL have bills to pay, we ALL have folks depending upon us, and we ALL value our time, services, and work efforts to a point where you don’t get to take advantage of them for a month or two before paying at least something FOR those services.<br /><br />Not only that, when was the last time you called out a plumber, electrician, or other professional trade, and when presented with the invoice explained that you’ll pay in 30 days IF they provide you with 3 references, their first born and a blood sample? They’d rip out your new shiny HVAC unit and walk off in disgust, same with any contractor coming into your home, they have expenses, costs, systems to purchase and don’t need your numpty ass defaulting on things. It’s risk management 101 and we ALL have to deal with it.<br /><br />SO, next time someone send in an RFP, SOW, LOI, or document asking for some of the funds up front realize it’s because they’re also human, they rely upon income, and YOU are a risk to them. Treat them like a human and don’t be an ass about paying up front for a portion of the work effort, after all BOTH parties are risking something. <br /><br />Yes, you can get something for nothing, and yes many of us want to (and often DO) help, often putting mission before money, but that doesn’t put food on the table… that invoice you have DOES… remember that please.<br /><br />And no, you can’t put it on your tab….]]></itunes:summary><itunes:duration>7860</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,money,podcast,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a597d39b0b8fd32d05b92fb70acb3938.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Sixty-Nine - The Show MUST Go On</title><link>https://www.spreaker.com/episode/episode-sixty-nine-the-show-must-go-on--47995549</link><description><![CDATA[The show MUST go on. The show ALWAYS goes on. <br /><br />The show goes on regardless of your wishes and regardless of your participation.<br /><br />Do you remember signing up for the show?<br />You did. Maybe you didn't know you signed up, maybe you don't remember signing up, or maybe you didn't know what you were signing up for, but you DID sign up.<br /><br />Welcome to the show!<br /><br />Now that you're in the show. Get out there and show 'em what you got!<br />The show is AMAZING and you'll do fine. Keep you head up, play your part, and keep your mouth shut. <br /><br />Play your role and you'll be fine. The show has its stars, but you're probably not one of them. The stars are only stars in the show. This is all for show.<br /><br />Some days we put on a great show, some days not so much. No matter, you still get paid (probably) and you'll be paid well (probably).<br /><br />What about those days you don't want to perform?<br />What about those days when you want to quit the show?<br /><br />Go ahead and quit, but the show MUST go on.<br /><br />What about those times when the entire show goes to shit?<br />When does the show end?<br /><br />The show does NOT end. The show MUST go on!<br /><br />Even when people know it's all for show, we keep on playing. Don't you get it yet? THE SHOW MUST GO ON!<br /><br />This is certain to be a great conversation between myself (Evan), Chris, and Ryan. Rachel will do her best to keep us in line. Join us LIVE @ 10pm and tell how the show looks to you.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47995549</guid><pubDate>Mon, 20 Dec 2021 14:14:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47995549/episode_69_the_show_must_go_on.mp3" length="119201254" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The show MUST go on. The show ALWAYS goes on. 

The show goes on regardless of your wishes and regardless of your participation.

Do you remember signing up for the show?
You did. Maybe you didn't know you signed up, maybe you don't remember signing...</itunes:subtitle><itunes:summary><![CDATA[The show MUST go on. The show ALWAYS goes on. <br /><br />The show goes on regardless of your wishes and regardless of your participation.<br /><br />Do you remember signing up for the show?<br />You did. Maybe you didn't know you signed up, maybe you don't remember signing up, or maybe you didn't know what you were signing up for, but you DID sign up.<br /><br />Welcome to the show!<br /><br />Now that you're in the show. Get out there and show 'em what you got!<br />The show is AMAZING and you'll do fine. Keep you head up, play your part, and keep your mouth shut. <br /><br />Play your role and you'll be fine. The show has its stars, but you're probably not one of them. The stars are only stars in the show. This is all for show.<br /><br />Some days we put on a great show, some days not so much. No matter, you still get paid (probably) and you'll be paid well (probably).<br /><br />What about those days you don't want to perform?<br />What about those days when you want to quit the show?<br /><br />Go ahead and quit, but the show MUST go on.<br /><br />What about those times when the entire show goes to shit?<br />When does the show end?<br /><br />The show does NOT end. The show MUST go on!<br /><br />Even when people know it's all for show, we keep on playing. Don't you get it yet? THE SHOW MUST GO ON!<br /><br />This is certain to be a great conversation between myself (Evan), Chris, and Ryan. Rachel will do her best to keep us in line. Join us LIVE @ 10pm and tell how the show looks to you.]]></itunes:summary><itunes:duration>7451</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,podcast,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/21eab49ed6e7fe1eba36d4726803ba54.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Sixty-Eight - What are you talking about, Confusing communication, causing calamity.</title><link>https://www.spreaker.com/episode/episode-sixty-eight-what-are-you-talking-about-confusing-communication-causing-calamity--47995357</link><description><![CDATA[Words matter, your choice of words can have a profound impact on the outcome, we love to speak OUR language the language of tech and engineering. Our language is complex and full of unique terms, it is a beautiful language that no one outside of tech understands.<br /><br />We must ask ourselves why we would speak tech talk to non-technical people. This is like trying to speak Sanskrit to a person who doesn’t speak Sanskrit. We need subtitles or translators because our language is not helping to get the message across to our users. We bitch and moan they are not doing what we told them to do and that’s why we got breached, but we are failing to realize we told them in a language that to them sounds like Charlie Browns parents.<br /><br />Our language is full of $50 dollar words, acronyms, negative and aggressive words, complex words that require a novels worth of information to put into context.<br /><br />If we hope to fix what is broken, to do more with less, to increase security, to reduce risk and make an ethical sale or two along the way, then we need to find a way to communicate that resonates with every person. Simple and understandable, easy to connect with and internalize, relatable and personal these are the corner stones of effective communication.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47995357</guid><pubDate>Mon, 20 Dec 2021 14:08:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47995357/episode_68_what_are_you_talking_about_confusing_communication_causing_calamity.mp3" length="127840470" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Words matter, your choice of words can have a profound impact on the outcome, we love to speak OUR language the language of tech and engineering. Our language is complex and full of unique terms, it is a beautiful language that no one outside of tech...</itunes:subtitle><itunes:summary><![CDATA[Words matter, your choice of words can have a profound impact on the outcome, we love to speak OUR language the language of tech and engineering. Our language is complex and full of unique terms, it is a beautiful language that no one outside of tech understands.<br /><br />We must ask ourselves why we would speak tech talk to non-technical people. This is like trying to speak Sanskrit to a person who doesn’t speak Sanskrit. We need subtitles or translators because our language is not helping to get the message across to our users. We bitch and moan they are not doing what we told them to do and that’s why we got breached, but we are failing to realize we told them in a language that to them sounds like Charlie Browns parents.<br /><br />Our language is full of $50 dollar words, acronyms, negative and aggressive words, complex words that require a novels worth of information to put into context.<br /><br />If we hope to fix what is broken, to do more with less, to increase security, to reduce risk and make an ethical sale or two along the way, then we need to find a way to communicate that resonates with every person. Simple and understandable, easy to connect with and internalize, relatable and personal these are the corner stones of effective communication.]]></itunes:summary><itunes:duration>7990</itunes:duration><itunes:keywords>chrisroberts,communication,cybersecurity,evanfrancen,informationsecurity,infosec,podcast,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/04f22b4507ab93a2075e13168466ae3f.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Sixty-Seven - Control the message, control reality</title><link>https://www.spreaker.com/episode/episode-sixty-seven-control-the-message-control-reality--47995040</link><description><![CDATA[A true story with four realities (or versions of reality).<br /><br />1. The public version. <br />2. The employee version. <br />3. The management version. <br />4. The Security Analyst’s version.<br /><br />To the public, -ORGANIZATION- seems to be doing a great job. -ORGANIZATION- has a noble mission and appears to be serving the mission well. They don’t think about information security at -ORGANIZATION- because it doesn’t come up in conversation. All they care about is that -ORGANIZATION- is fulfilling their mission, and they seem to be treating the public OK.<br /><br />To the employee, -ORGANIZATION- is doing OK. Sure, there are plenty of challenges, and politics sometimes gets in the way, but employee's like what they do. As long as employees do their job well, they’ll be fine. Information security isn’t a concern because the employees don’t really know what it is. Just stay focused on the job, keep your head down, and you'll be OK.<br /><br />To management, -ORGANIZATION- has a mission, but personal missions far outweigh the -ORGANIZATION- one! The personal mission is to keep this job and get some kudos along the way. In order to keep the job, they have to play the game. The game is politics, and sometimes politics are cutthroat. Management spends more time defending itself and attacking each other than they do on accomplishing anything. As long as the public and the employees see management as great (or good) leaders, they’ll be safe. Problem is, they suck at the job. Focus #1 is "MY JOB" (at all costs). They love the job because it comes with a lot of perks. Information security is a pain in the ass and management doesn't have time to learn about it. Who cares anyway?<br /><br />To the Security Analyst, -ORGANIZATION- has a mission and information security is (and must be) part of the mission. There are so many risks to deal with and there's not enough support. The Security Analyst is a team of one and has no support from management. People keep clicking on links, people keep choosing crappy passwords, management wants new blinkly lights, and the Security Analyst can’t cope anymore. The Security Analyst is not paid well (by industry standards), but they're here because they care. The Security Analyst doesn't want people to get hurt, and they believe in the mission, but they need help!<br /><br />The true reality? Most of three realities are bullshit. To some extent, the public has been deceived, employees are misled, management is shitty, and the Security Analyst needs some support.<br /><br />The Security Analyst works at -ORGANIZATION- for the right reasons. <br /><br />The Security Analyst loves people and wants to protect -ORGANIZATION-. <br /><br />The Security Analyst wants to protect -ORGANIZATION-'s employees, customers, and the public.<br /><br />The Security Analyst doesn't want to make a name for themselves, but desperately wants to do the right thing. <br /><br />The Security Analyst has tried again and again to get their message through to the alternate realities, but the results are very disappointing. <br /><br />The Security Analyst feels it's their moral responsibility to do something. <br /><br />To this end, the Security Analyst sends a VERY respectable email to the -TOP MANAGER-'s executive assistant. The email is respectful, informative, fact-driven, and was NOT threatening in any way. The sole purpose of the email is to get help and to help (the public, employees, and management).<br /><br />The next day...<br /><br />The Security Analyst is called into a meeting, and here's what the Security Analyst is told:<br /> - "The Board and most people don't give a shit about Security and it's not our job to educate them."<br /> - "Our job is only to deal with internal concerns and stay in our lane."<br /> - You "didn't follow the chain of command and need to be mindful of the bigger picture and their concerns, and realize that (your) focus isn't theirs."<br /><br />This story is REAL. It just happened last week. Let's talk about this and the alternate realities we live in. What the hell do we do about this?<br /><br />Join myself, Ryan, Chris, and Rachel LIVE and give your thoughts...]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47995040</guid><pubDate>Mon, 20 Dec 2021 13:43:08 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47995040/episode_67_control_the_message_control_reality.mp3" length="97120470" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>A true story with four realities (or versions of reality).

1. The public version. 
2. The employee version. 
3. The management version. 
4. The Security Analyst’s version.

To the public, -ORGANIZATION- seems to be doing a great job. -ORGANIZATION-...</itunes:subtitle><itunes:summary><![CDATA[A true story with four realities (or versions of reality).<br /><br />1. The public version. <br />2. The employee version. <br />3. The management version. <br />4. The Security Analyst’s version.<br /><br />To the public, -ORGANIZATION- seems to be doing a great job. -ORGANIZATION- has a noble mission and appears to be serving the mission well. They don’t think about information security at -ORGANIZATION- because it doesn’t come up in conversation. All they care about is that -ORGANIZATION- is fulfilling their mission, and they seem to be treating the public OK.<br /><br />To the employee, -ORGANIZATION- is doing OK. Sure, there are plenty of challenges, and politics sometimes gets in the way, but employee's like what they do. As long as employees do their job well, they’ll be fine. Information security isn’t a concern because the employees don’t really know what it is. Just stay focused on the job, keep your head down, and you'll be OK.<br /><br />To management, -ORGANIZATION- has a mission, but personal missions far outweigh the -ORGANIZATION- one! The personal mission is to keep this job and get some kudos along the way. In order to keep the job, they have to play the game. The game is politics, and sometimes politics are cutthroat. Management spends more time defending itself and attacking each other than they do on accomplishing anything. As long as the public and the employees see management as great (or good) leaders, they’ll be safe. Problem is, they suck at the job. Focus #1 is "MY JOB" (at all costs). They love the job because it comes with a lot of perks. Information security is a pain in the ass and management doesn't have time to learn about it. Who cares anyway?<br /><br />To the Security Analyst, -ORGANIZATION- has a mission and information security is (and must be) part of the mission. There are so many risks to deal with and there's not enough support. The Security Analyst is a team of one and has no support from management. People keep clicking on links, people keep choosing crappy passwords, management wants new blinkly lights, and the Security Analyst can’t cope anymore. The Security Analyst is not paid well (by industry standards), but they're here because they care. The Security Analyst doesn't want people to get hurt, and they believe in the mission, but they need help!<br /><br />The true reality? Most of three realities are bullshit. To some extent, the public has been deceived, employees are misled, management is shitty, and the Security Analyst needs some support.<br /><br />The Security Analyst works at -ORGANIZATION- for the right reasons. <br /><br />The Security Analyst loves people and wants to protect -ORGANIZATION-. <br /><br />The Security Analyst wants to protect -ORGANIZATION-'s employees, customers, and the public.<br /><br />The Security Analyst doesn't want to make a name for themselves, but desperately wants to do the right thing. <br /><br />The Security Analyst has tried again and again to get their message through to the alternate realities, but the results are very disappointing. <br /><br />The Security Analyst feels it's their moral responsibility to do something. <br /><br />To this end, the Security Analyst sends a VERY respectable email to the -TOP MANAGER-'s executive assistant. The email is respectful, informative, fact-driven, and was NOT threatening in any way. The sole purpose of the email is to get help and to help (the public, employees, and management).<br /><br />The next day...<br /><br />The Security Analyst is called into a meeting, and here's what the Security Analyst is told:<br /> - "The Board and most people don't give a shit about Security and it's not our job to educate them."<br /> - "Our job is only to deal with internal concerns and stay in our lane."<br /> - You "didn't follow the chain of command and need to be mindful of the bigger picture and their concerns, and realize that (your) focus isn't theirs."<br /><br />This story is REAL. It just...]]></itunes:summary><itunes:duration>6070</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,podcast,reality,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/3218aea13bf7b7f2b9de418e0aef515a.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Sixty-Six - O No Bro, don't be that guy</title><link>https://www.spreaker.com/episode/episode-sixty-six-o-no-bro-don-t-be-that-guy--47987742</link><description><![CDATA[Repeat After Me:<br /><br />I am NOT a neanderthal<br />(Even if I look like one)<br /> <br />I do NOT walk around with a permanent hard on<br />(IF you do, then you’re taking too many blue pills)<br /> <br />I do NOT need to treat every interaction with a female in InfoSec/IT/Cyber/Tech as an opportunity to peacock, and prove my manliness by dry humping the server rack.<br /> <br />I will NOT step away from chivalry, HOWEVER, I will not use it as a shield to hide bad behavior OR ulterior motives.<br /> <br />IF I don’t tell Chris that he looks pretty, then there is NO place to do the same to anyone else.<br />(And if you DO tell me I’m pretty you STILL don’t get a hallway pass to do the same to others…)<br /> <br />IF I cannot walk shoulder TO shoulder with my female counterparts, then I do NOT deserve a place in this industry<br />(…and I’m on shaky ground elsewhere in society!)<br /> <br />A meeting is NOT a date<br /> <br />A LACK of wedding ring is NOT an invitation to drool and act the fool<br /> <br />A wedding ring is NOT a challenge<br /> <br />I will NOT mansplain, and IF I’m going to argue, then I AM going to go and look at the awesome flowchart from Kim Goodwin<br /> <br />Done? Need to repeat it? Tattoo it on a body part?<br /> <br />SO:<br /> <br />If ANY of this is jogging a memory then y’all might want to go find that second voice and listen to it BEFORE engaging in a conversation with the opposite sex.<br /> <br />If YOU are offended by this, then go look in a mirror and ask WHY<br /> <br />If YOU laughed at this, then I hope it’s a laugh of clarity, and not of ignorance.<br /> <br />If YOU know anyone that NEEDS to read this, forward TO them, blame me, it’s simpler and I’ve been blamed for worse.<br /> <br />IF you are a narcissist you’ve likely recognized yourself and simply don’t care… for you I have tasers.<br />(Although you’d probably enjoy that too…)<br /> <br />If your regional, religious, back-arsed belief system has put “you” as superior, then please go boil your head, and GTFO of our industry, you have NO place here, none of us want you.<br /> <br />‘Enough said for now, a HUGE thanks to both Christy F. and Sky Kennedy for the inspiration!<br /> <br />Feel free to print, forward, blame, but FFS get the word out that this shit has got to stop.<br /> <br />‘all for now<br /> <br />Chris<br /><br />Join us tonight on the Security Shit Show 2200 Central 2100 Mountain <br /><br />#respect #infosec #cyber #inspiration #society #technology #culture #change #womenincyber]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47987742</guid><pubDate>Sun, 19 Dec 2021 20:27:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47987742/episode_66_o_no_bro_don_t_be_that_guy.mp3" length="116960575" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Repeat After Me:

I am NOT a neanderthal
(Even if I look like one)
 
I do NOT walk around with a permanent hard on
(IF you do, then you’re taking too many blue pills)
 
I do NOT need to treat every interaction with a female in InfoSec/IT/Cyber/Tech as...</itunes:subtitle><itunes:summary><![CDATA[Repeat After Me:<br /><br />I am NOT a neanderthal<br />(Even if I look like one)<br /> <br />I do NOT walk around with a permanent hard on<br />(IF you do, then you’re taking too many blue pills)<br /> <br />I do NOT need to treat every interaction with a female in InfoSec/IT/Cyber/Tech as an opportunity to peacock, and prove my manliness by dry humping the server rack.<br /> <br />I will NOT step away from chivalry, HOWEVER, I will not use it as a shield to hide bad behavior OR ulterior motives.<br /> <br />IF I don’t tell Chris that he looks pretty, then there is NO place to do the same to anyone else.<br />(And if you DO tell me I’m pretty you STILL don’t get a hallway pass to do the same to others…)<br /> <br />IF I cannot walk shoulder TO shoulder with my female counterparts, then I do NOT deserve a place in this industry<br />(…and I’m on shaky ground elsewhere in society!)<br /> <br />A meeting is NOT a date<br /> <br />A LACK of wedding ring is NOT an invitation to drool and act the fool<br /> <br />A wedding ring is NOT a challenge<br /> <br />I will NOT mansplain, and IF I’m going to argue, then I AM going to go and look at the awesome flowchart from Kim Goodwin<br /> <br />Done? Need to repeat it? Tattoo it on a body part?<br /> <br />SO:<br /> <br />If ANY of this is jogging a memory then y’all might want to go find that second voice and listen to it BEFORE engaging in a conversation with the opposite sex.<br /> <br />If YOU are offended by this, then go look in a mirror and ask WHY<br /> <br />If YOU laughed at this, then I hope it’s a laugh of clarity, and not of ignorance.<br /> <br />If YOU know anyone that NEEDS to read this, forward TO them, blame me, it’s simpler and I’ve been blamed for worse.<br /> <br />IF you are a narcissist you’ve likely recognized yourself and simply don’t care… for you I have tasers.<br />(Although you’d probably enjoy that too…)<br /> <br />If your regional, religious, back-arsed belief system has put “you” as superior, then please go boil your head, and GTFO of our industry, you have NO place here, none of us want you.<br /> <br />‘Enough said for now, a HUGE thanks to both Christy F. and Sky Kennedy for the inspiration!<br /> <br />Feel free to print, forward, blame, but FFS get the word out that this shit has got to stop.<br /> <br />‘all for now<br /> <br />Chris<br /><br />Join us tonight on the Security Shit Show 2200 Central 2100 Mountain <br /><br />#respect #infosec #cyber #inspiration #society #technology #culture #change #womenincyber]]></itunes:summary><itunes:duration>7310</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,live,podcast,respect,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b2c10f154b32fc49cbbe9657137dbe4a.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Sixty-Five - Hope Restored Lessons From GrrCON</title><link>https://www.spreaker.com/episode/episode-sixty-five-hope-restored-lessons-from-grrcon--47986896</link><description><![CDATA[Hope in one hand and shit in the other! this is what I was told as a child about hope, this is because hope is commonly associated with expectations, and expectations lead to disappointment.<br /><br /> It was not until later that I learned hope could also mean a want or desire for something to happen, that hope is about anticipation for positive outcomes.<br /><br />Then I remembered I work in information security, an industry that at times appears to be a hopeless wasteland of soul sucking, ungrateful people, never-ending greed, over inflated egos, blaming and shaming and awful behavior. An industry were the vendors treat their customers like victims, while peddling rebranded anti-virus and packet inspection as next gen and don’t get me going on the “Rock stars” of the industry are high on their own farts.<br /><br />Work in this industry long enough and you will start to lose hope, lost hope that anything will change, that we can get ahead of the criminals, that we can do the right thing, that we will become diverse and inclusive, that we will help and protect those we serve, that the next generation will know how a computer and network actually works.  <br /><br />Feeling hopeless makes it hard to get up each day and keep fighting this fight, hopelessness is hard on mental health, passion and drive start to suffer and apathy starts to set in. It was in this spiral of negative feelings about our industry and its future that I found myself, when I arrived at my very first GrrCON.  <br /><br />What unfolded over the next few days, surprised, renewed, refreshed, inspired, encouraged, empowered, energized and left me with a restored since of hope.<br /><br />After spending an amazing time hanging with and learning from some of the kindest, nicest, humblest, smartest people in infosec. I could see we have a chance to do better, to be better and there are some of us in this industry who are in it for all the right reasons. From the amazing folks at ILF to the thoughtful sessions, the openness to share knowledge, and humbleness of some of the biggest names in the game. Every person I met from the newest in the industry to the dusty old dinosaurs (holding up a mirror) every single person was eager to help, excited to grow and learn from one another regardless of experience level.<br /><br />We need to take what makes the attendees of GrrCON so special, put it in a bottle and sell it as a service.<br /><br />All this and more tonight on the Security Shit Show with Chris, Evan and Ryan.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47986896</guid><pubDate>Sun, 19 Dec 2021 20:14:27 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47986896/episode_65_hope_restored_lessons_from_grrcon.mp3" length="125440549" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Hope in one hand and shit in the other! this is what I was told as a child about hope, this is because hope is commonly associated with expectations, and expectations lead to disappointment.

 It was not until later that I learned hope could also mean...</itunes:subtitle><itunes:summary><![CDATA[Hope in one hand and shit in the other! this is what I was told as a child about hope, this is because hope is commonly associated with expectations, and expectations lead to disappointment.<br /><br /> It was not until later that I learned hope could also mean a want or desire for something to happen, that hope is about anticipation for positive outcomes.<br /><br />Then I remembered I work in information security, an industry that at times appears to be a hopeless wasteland of soul sucking, ungrateful people, never-ending greed, over inflated egos, blaming and shaming and awful behavior. An industry were the vendors treat their customers like victims, while peddling rebranded anti-virus and packet inspection as next gen and don’t get me going on the “Rock stars” of the industry are high on their own farts.<br /><br />Work in this industry long enough and you will start to lose hope, lost hope that anything will change, that we can get ahead of the criminals, that we can do the right thing, that we will become diverse and inclusive, that we will help and protect those we serve, that the next generation will know how a computer and network actually works.  <br /><br />Feeling hopeless makes it hard to get up each day and keep fighting this fight, hopelessness is hard on mental health, passion and drive start to suffer and apathy starts to set in. It was in this spiral of negative feelings about our industry and its future that I found myself, when I arrived at my very first GrrCON.  <br /><br />What unfolded over the next few days, surprised, renewed, refreshed, inspired, encouraged, empowered, energized and left me with a restored since of hope.<br /><br />After spending an amazing time hanging with and learning from some of the kindest, nicest, humblest, smartest people in infosec. I could see we have a chance to do better, to be better and there are some of us in this industry who are in it for all the right reasons. From the amazing folks at ILF to the thoughtful sessions, the openness to share knowledge, and humbleness of some of the biggest names in the game. Every person I met from the newest in the industry to the dusty old dinosaurs (holding up a mirror) every single person was eager to help, excited to grow and learn from one another regardless of experience level.<br /><br />We need to take what makes the attendees of GrrCON so special, put it in a bottle and sell it as a service.<br /><br />All this and more tonight on the Security Shit Show with Chris, Evan and Ryan.]]></itunes:summary><itunes:duration>7840</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,grrcon,hope,informationsecurity,infosec,live,podcast,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/2a8f110b0b9af3c4bf5a2ee91dec48da.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Sixty-Three - If I Were King of the World</title><link>https://www.spreaker.com/episode/episode-sixty-three-if-i-were-king-of-the-world--47986567</link><description><![CDATA[In the early 1970s (1971 to be exact), a group of wise men (Three Dog Night) were quoted as saying:<br /><br />And if I were the king of the world<br />Tell you what I'd do<br />I'd throw away the cars and the bars and the war<br />Make sweet love to you<br /><br />Wise, right?<br /><br />Wait a second! What is I/you like cars and bars? Some people must like wars too because we keep having them.<br /><br />OK, all that aside for now. What if I were king of the world? What would I do?<br /><br />In terms of information security:<br />Would I fire CEOs for not doing the basics?<br />Would I flog the vendor for making crappy stuff?<br />Would I define what's negligent and what's not, then throw people in jail?<br />Would I fire the CISOs who continue to take shortcuts?<br />Would I break up the monopolies that dominate technology?<br />Would I, would I, would I...<br /><br />This should be a good discussion where we can dream a little bit. How would we right the world and how would you? Join me (Evan), Ryan, Chris, and Rachel (leading the online stuff) for an entertaining (and hopefully helpful) show LIVE on these Youtubes!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47986567</guid><pubDate>Sun, 19 Dec 2021 17:47:25 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47986567/episode_63_if_i_were_king_of_the_world.mp3" length="96240666" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>In the early 1970s (1971 to be exact), a group of wise men (Three Dog Night) were quoted as saying:

And if I were the king of the world
Tell you what I'd do
I'd throw away the cars and the bars and the war
Make sweet love to you

Wise, right?

Wait a...</itunes:subtitle><itunes:summary><![CDATA[In the early 1970s (1971 to be exact), a group of wise men (Three Dog Night) were quoted as saying:<br /><br />And if I were the king of the world<br />Tell you what I'd do<br />I'd throw away the cars and the bars and the war<br />Make sweet love to you<br /><br />Wise, right?<br /><br />Wait a second! What is I/you like cars and bars? Some people must like wars too because we keep having them.<br /><br />OK, all that aside for now. What if I were king of the world? What would I do?<br /><br />In terms of information security:<br />Would I fire CEOs for not doing the basics?<br />Would I flog the vendor for making crappy stuff?<br />Would I define what's negligent and what's not, then throw people in jail?<br />Would I fire the CISOs who continue to take shortcuts?<br />Would I break up the monopolies that dominate technology?<br />Would I, would I, would I...<br /><br />This should be a good discussion where we can dream a little bit. How would we right the world and how would you? Join me (Evan), Ryan, Chris, and Rachel (leading the online stuff) for an entertaining (and hopefully helpful) show LIVE on these Youtubes!]]></itunes:summary><itunes:duration>6016</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,live,podcast,rant,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a09785cf168ab6a2447f6f678413faa5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Sixty-Two - Over the hill...</title><link>https://www.spreaker.com/episode/episode-sixty-two-over-the-hill--47965304</link><description><![CDATA[Over the hill and through the woods we go to…<br />Where are we going, I can’t recall, I may be going senile.<br /><br />To grow old is one of life’s blessings, but it is not all roses, one day you wake up and find you have injured yourself while sleeping. Maybe today is the day you discover you have knees, and they are very unhappy with the way you have treated them over the years. Or maybe this is the day you realize that you can't keep up with all the new things and changes happen around you daily.<br /><br />Sometimes, as I reflect on growing older, and the older I grow the more I seem to reflect, not because I am fearful of the aging process, or that I am worried about my final outcome (hint I love Jesus). I reflect because I ask myself what I have done to set the next generation up for success?<br /><br />What can (or should) I be doing with the time I have left to help others?<br /><br />In my career I have watched the birth and growth on an entire industry. I have seen how the technology we made has had a profound and lasting impact on what it means to be a human, and how you interact with the world. Those who come after us do not have this same luxury, they are lacking the wisdom earned through these gray hairs.<br /><br />Each year that goes by, it becomes clear(er) that I have forgotten more than I (or they) know. With age and experience came a price that must be paid. I don’t know all the latest and greatest things happening, new tech, new vulnerabilities, new exploits. Who does? The good news is, it doesn't matter as much as how you deal with them. How you deal with them hasn't changed much in the last 30 years.<br /><br />Experienced professionals have stories to tell, advice to give, and lessons they learned the hard way. They have so much to share!<br /><br />Are we doing enough to mentor those coming up in the industry? Hopefully before our minds leave us, spending our waning days rocking in a chair reminiscing about the good old days. You remember yelling at people in your house, “Hey I am on the internet, hang up the phone”, or that one time we waited 4 hours for a .jpeg to download?<br /><br />Those were days when you knew what was on your network and could explain what it was doing. "Googling it" wasn't an option.<br /><br />I find myself pondering this question as I grow older, I ask myself about the legacy we're leaving for the next generation. Believe it or not, they ARE looking to us for guidance and leadership.<br /><br />What lessons have we learned, technical and non-technical, that we want to pass on? There's a story, purpose, and lesson behind every scar.<br /><br />In an industry that is as competitive as ours, based on secrecy, are we doing enough to equip the young'uns with the hard-earned knowledge that no book or class can teach? There's something about being in the heat of the batter. If we don't share our knowledge, then the same mistakes will be made over and over again.<br /><br />Maybe this is why we're still trying to get people to backup their data?<br /><br />I enjoy growing old because I value the experience I've gained and the scars I've earned.  There are the joyous moments and there are the painful ones too. Like the title of one my favorite western films, "the good the bad and the ugly".<br /><br />Although I may feel like a lost shoe on the side of the highway, we should wonder, where it came from, how in the F did it get here and does it still serve a purpose.<br /><br />I used to wonder why all the old people seemed to be cranky and fed up with the world, and each day this worldview makes more and more sense.<br /><br />Join us tonight for a discussion on aging, the impact it has on us as humans and security professionals and most importantly, what are we doing to pass on the experience we have to the next generation.<br /><br /><a href="https://www.youtube.com/watch?v=a2__8xIIa2A" rel="noopener">https://www.youtube.com/watch?v=a2__8xIIa2A</a><br /><br />Evan, Chris and Ryan]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47965304</guid><pubDate>Fri, 17 Dec 2021 17:38:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47965304/episode_62_over_the_hill.mp3" length="139761502" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Over the hill and through the woods we go to…
Where are we going, I can’t recall, I may be going senile.

To grow old is one of life’s blessings, but it is not all roses, one day you wake up and find you have injured yourself while sleeping. Maybe...</itunes:subtitle><itunes:summary><![CDATA[Over the hill and through the woods we go to…<br />Where are we going, I can’t recall, I may be going senile.<br /><br />To grow old is one of life’s blessings, but it is not all roses, one day you wake up and find you have injured yourself while sleeping. Maybe today is the day you discover you have knees, and they are very unhappy with the way you have treated them over the years. Or maybe this is the day you realize that you can't keep up with all the new things and changes happen around you daily.<br /><br />Sometimes, as I reflect on growing older, and the older I grow the more I seem to reflect, not because I am fearful of the aging process, or that I am worried about my final outcome (hint I love Jesus). I reflect because I ask myself what I have done to set the next generation up for success?<br /><br />What can (or should) I be doing with the time I have left to help others?<br /><br />In my career I have watched the birth and growth on an entire industry. I have seen how the technology we made has had a profound and lasting impact on what it means to be a human, and how you interact with the world. Those who come after us do not have this same luxury, they are lacking the wisdom earned through these gray hairs.<br /><br />Each year that goes by, it becomes clear(er) that I have forgotten more than I (or they) know. With age and experience came a price that must be paid. I don’t know all the latest and greatest things happening, new tech, new vulnerabilities, new exploits. Who does? The good news is, it doesn't matter as much as how you deal with them. How you deal with them hasn't changed much in the last 30 years.<br /><br />Experienced professionals have stories to tell, advice to give, and lessons they learned the hard way. They have so much to share!<br /><br />Are we doing enough to mentor those coming up in the industry? Hopefully before our minds leave us, spending our waning days rocking in a chair reminiscing about the good old days. You remember yelling at people in your house, “Hey I am on the internet, hang up the phone”, or that one time we waited 4 hours for a .jpeg to download?<br /><br />Those were days when you knew what was on your network and could explain what it was doing. "Googling it" wasn't an option.<br /><br />I find myself pondering this question as I grow older, I ask myself about the legacy we're leaving for the next generation. Believe it or not, they ARE looking to us for guidance and leadership.<br /><br />What lessons have we learned, technical and non-technical, that we want to pass on? There's a story, purpose, and lesson behind every scar.<br /><br />In an industry that is as competitive as ours, based on secrecy, are we doing enough to equip the young'uns with the hard-earned knowledge that no book or class can teach? There's something about being in the heat of the batter. If we don't share our knowledge, then the same mistakes will be made over and over again.<br /><br />Maybe this is why we're still trying to get people to backup their data?<br /><br />I enjoy growing old because I value the experience I've gained and the scars I've earned.  There are the joyous moments and there are the painful ones too. Like the title of one my favorite western films, "the good the bad and the ugly".<br /><br />Although I may feel like a lost shoe on the side of the highway, we should wonder, where it came from, how in the F did it get here and does it still serve a purpose.<br /><br />I used to wonder why all the old people seemed to be cranky and fed up with the world, and each day this worldview makes more and more sense.<br /><br />Join us tonight for a discussion on aging, the impact it has on us as humans and security professionals and most importantly, what are we doing to pass on the experience we have to the next generation.<br /><br /><a href="https://www.youtube.com/watch?v=a2__8xIIa2A" rel="noopener">https://www.youtube.com/watch?v=a2__8xIIa2A</a><br /><br />Evan, Chris and Ryan]]></itunes:summary><itunes:duration>8736</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,podcast,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/0b1e14d5f766631da571ad3c08b12ff9.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Sixty-One - Say Something Nice...</title><link>https://www.spreaker.com/episode/episode-sixty-one-say-something-nice--47912744</link><description><![CDATA[I remember my Mother teaching me “if you don’t have anything nice to say, then don’t say anything at all” and there’s a LOT of merit in that statement for various situations.... However, when it comes to our industry, and some of the companies, folks, and players INSIDE of it I must admit I’ve broken that rule on several occasions.<br /> <br />Which brings me to the rather splendid Osthoff Resort, sandwiched between Milwaukee and Green Bay, Wisconsin.<br /> <br />I’m here...<br /> <br />Surrounded by a posse of FBI agents, InfraGard folks, and businesses...<br /><br /><br />THANKFULLY I’m not alone in this pickle. I’ve got Evan Francen and Ryan Cloutier, CISSP with me to even out the odds a little.<br /> <br />And we’ve just spent the day (I’m up on stage in a couple of hours to complete the trifecta of apocalyptic horsemen) beating the living snot out of the entire industry, LOTS of folks, companies, and agencies that are in it.<br /> <br />Which means we should probably end the day thinking/saying something nice. IF nothing else we need to give folks some hope (and ourselves some redeeming qualities beyond just binging the alcohol.)<br /> <br />SO, this evening the #shitshow IS going to be live FROM the FBI/InfraGard stage and IF we can, we’re going to find some good things to talk about. There might be some pauses, some moments of silence as we work out what IS good....<br /> <br />Come along, hang out, join in (we’re doing audience participation on this one)<br /> <br />AND let’s see if there ARE some good things inside InfoSec (aside from the availability of alcohol, tea, and caffeinated beverages)<br /><br />Shout out to InfraGard for allowing us in!<br />AND to the Federal Bureau of Investigation (FBI) for being nice enough to not arrest us on sight again....]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47912744</guid><pubDate>Tue, 14 Dec 2021 16:35:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47912744/episode_61_say_something_nice.mp3" length="115520287" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>I remember my Mother teaching me “if you don’t have anything nice to say, then don’t say anything at all” and there’s a LOT of merit in that statement for various situations.... However, when it comes to our industry, and some of the companies, folks,...</itunes:subtitle><itunes:summary><![CDATA[I remember my Mother teaching me “if you don’t have anything nice to say, then don’t say anything at all” and there’s a LOT of merit in that statement for various situations.... However, when it comes to our industry, and some of the companies, folks, and players INSIDE of it I must admit I’ve broken that rule on several occasions.<br /> <br />Which brings me to the rather splendid Osthoff Resort, sandwiched between Milwaukee and Green Bay, Wisconsin.<br /> <br />I’m here...<br /> <br />Surrounded by a posse of FBI agents, InfraGard folks, and businesses...<br /><br /><br />THANKFULLY I’m not alone in this pickle. I’ve got Evan Francen and Ryan Cloutier, CISSP with me to even out the odds a little.<br /> <br />And we’ve just spent the day (I’m up on stage in a couple of hours to complete the trifecta of apocalyptic horsemen) beating the living snot out of the entire industry, LOTS of folks, companies, and agencies that are in it.<br /> <br />Which means we should probably end the day thinking/saying something nice. IF nothing else we need to give folks some hope (and ourselves some redeeming qualities beyond just binging the alcohol.)<br /> <br />SO, this evening the #shitshow IS going to be live FROM the FBI/InfraGard stage and IF we can, we’re going to find some good things to talk about. There might be some pauses, some moments of silence as we work out what IS good....<br /> <br />Come along, hang out, join in (we’re doing audience participation on this one)<br /> <br />AND let’s see if there ARE some good things inside InfoSec (aside from the availability of alcohol, tea, and caffeinated beverages)<br /><br />Shout out to InfraGard for allowing us in!<br />AND to the Federal Bureau of Investigation (FBI) for being nice enough to not arrest us on sight again....]]></itunes:summary><itunes:duration>7220</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,fbi,informationsecurity,infosec,live,podcast,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/32f063be28e3b45e80ac86acd982b1b1.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Sixty - Are you driving (your computer) with a gun pointed at your head</title><link>https://www.spreaker.com/episode/episode-sixty-are-you-driving-your-computer-with-a-gun-pointed-at-your-head--47909800</link><description><![CDATA[You know about the massive Takata airbag recall story, right? <br /><br />No?! Maybe?<br /><br />Well, we've got one helluva story to tell you. Takata was (keyword "was") a Japanese company founded in 1933 that started making airbags in 1988. At one time the company owned 20% of the market, and things were good. At least we thought things were good...<br /><br /> - Honda knew about more than 100 injuries and 13 deaths related to Takata airbags, starting in about 1998.<br /> - In the Spring of 2013, recalls were issued. Not small recalls either, like 3.6 million cars.<br /> - In June 2014, Takata admitted that their Mexican subsidiary mishandled "the manufacture of explosive propellants" used in their airbags.<br /> - Later in June 2014, BMW, Chrysler, Ford, Honda, Mazda, Nissan, and Toyota all announced recalls. The reason? Takata airbags "could rupture and send debris flying inside the vehicle".<br /><br />Let's stop for a second... What do you call something that uses an explosive propellant to launch a projectile (or "debris")?<br /><br />It's called a gun.<br /><br />In July 2014, a pregnant Malaysian woman was killed. A metal fragment sliced into her neck. (she was going 18 MPH).<br />-----INSERT MANY STORIES HERE-----<br />Late last year, Janett Perez, a U.S. citizen in Mexico was killed when a Takata airbag shot a metallic fragment into her neck too. Another car accidentally backed into her.<br /><br />Today, millions of Takata ticking timebombs are still on the road.<br /><br />More than 30 car manufacturers have been affected, and the NHTSA ordered an (ongoing) US-wide recall of more than 42 million cars (the largest automotive recall in U.S. history). Worldwide, the estimated size of the recall is roughly 100 million cars.<br /><br />So what does this have to do with information security? Lots actually! The parallels include consumer ignorance, manufacturer negligence, regulatory ineffectiveness, and more. As we integrate technology more and more into our physical world, the parallels become even more frightening.<br /><br />Let's have a truthful (and downright scary) talk about this shit tonight!<br /> <br />Join us LIVE @10pm CDT, August 26th.<br /><br />Evan, Ryan, and Chris are sure to have one helluva discussion about this!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47909800</guid><pubDate>Tue, 14 Dec 2021 04:00:58 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47909800/episode_60_are_you_driving_your_computer_with_a_gun_pointed_at_your_head.mp3" length="141600522" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>You know about the massive Takata airbag recall story, right? 

No?! Maybe?

Well, we've got one helluva story to tell you. Takata was (keyword "was") a Japanese company founded in 1933 that started making airbags in 1988. At one time the company...</itunes:subtitle><itunes:summary><![CDATA[You know about the massive Takata airbag recall story, right? <br /><br />No?! Maybe?<br /><br />Well, we've got one helluva story to tell you. Takata was (keyword "was") a Japanese company founded in 1933 that started making airbags in 1988. At one time the company owned 20% of the market, and things were good. At least we thought things were good...<br /><br /> - Honda knew about more than 100 injuries and 13 deaths related to Takata airbags, starting in about 1998.<br /> - In the Spring of 2013, recalls were issued. Not small recalls either, like 3.6 million cars.<br /> - In June 2014, Takata admitted that their Mexican subsidiary mishandled "the manufacture of explosive propellants" used in their airbags.<br /> - Later in June 2014, BMW, Chrysler, Ford, Honda, Mazda, Nissan, and Toyota all announced recalls. The reason? Takata airbags "could rupture and send debris flying inside the vehicle".<br /><br />Let's stop for a second... What do you call something that uses an explosive propellant to launch a projectile (or "debris")?<br /><br />It's called a gun.<br /><br />In July 2014, a pregnant Malaysian woman was killed. A metal fragment sliced into her neck. (she was going 18 MPH).<br />-----INSERT MANY STORIES HERE-----<br />Late last year, Janett Perez, a U.S. citizen in Mexico was killed when a Takata airbag shot a metallic fragment into her neck too. Another car accidentally backed into her.<br /><br />Today, millions of Takata ticking timebombs are still on the road.<br /><br />More than 30 car manufacturers have been affected, and the NHTSA ordered an (ongoing) US-wide recall of more than 42 million cars (the largest automotive recall in U.S. history). Worldwide, the estimated size of the recall is roughly 100 million cars.<br /><br />So what does this have to do with information security? Lots actually! The parallels include consumer ignorance, manufacturer negligence, regulatory ineffectiveness, and more. As we integrate technology more and more into our physical world, the parallels become even more frightening.<br /><br />Let's have a truthful (and downright scary) talk about this shit tonight!<br /> <br />Join us LIVE @10pm CDT, August 26th.<br /><br />Evan, Ryan, and Chris are sure to have one helluva discussion about this!]]></itunes:summary><itunes:duration>8850</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,live,podcast,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/2833ad03429bc24b36b278e0072c85af.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Fifty-Nine - The times they are a-changing but are we? (Part 2)</title><link>https://www.spreaker.com/episode/episode-fifty-nine-the-times-they-are-a-changing-but-are-we-part-2--47869481</link><description><![CDATA[Last week we took some time away to do some of the things we love, Chris went to DefCon to taste whiskey with folks, Evan took his beard and bike to Sturgis to make memories, one of his most favorite things to do and I took some time to visit with my wife and dog.<br /> <br />As I was reflecting on all the things that had happened in just a weeks’ time, it dawned on me we are at the beginning of a new era as a society and as an industry and even as I type this my news feed is full of new discoveries, new legislation, new science and change on a global scale that at times is hard to comprehend. <br /><br />The scope and scale of work in front of us is daunting, old thinking and old methods must go, we must get creative, we must innovate, we must simplify. <br /><br />What used to work is no longer working, what used to be acceptable is no longer acceptable, what used to be enough is no longer enough. We now must embrace these changes head on and take a whole new approach to a new world, especially in our industry.<br /><br />Tonight, we will discuss some of the changes that have happened that affect our industry, pontificate on what we need to change to adapt and adjust to this new world.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47869481</guid><pubDate>Fri, 10 Dec 2021 16:09:33 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47869481/episode_59_the_times_they_are_a_changing_but_are_we.mp3" length="118560522" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Last week we took some time away to do some of the things we love, Chris went to DefCon to taste whiskey with folks, Evan took his beard and bike to Sturgis to make memories, one of his most favorite things to do and I took some time to visit with my...</itunes:subtitle><itunes:summary><![CDATA[Last week we took some time away to do some of the things we love, Chris went to DefCon to taste whiskey with folks, Evan took his beard and bike to Sturgis to make memories, one of his most favorite things to do and I took some time to visit with my wife and dog.<br /> <br />As I was reflecting on all the things that had happened in just a weeks’ time, it dawned on me we are at the beginning of a new era as a society and as an industry and even as I type this my news feed is full of new discoveries, new legislation, new science and change on a global scale that at times is hard to comprehend. <br /><br />The scope and scale of work in front of us is daunting, old thinking and old methods must go, we must get creative, we must innovate, we must simplify. <br /><br />What used to work is no longer working, what used to be acceptable is no longer acceptable, what used to be enough is no longer enough. We now must embrace these changes head on and take a whole new approach to a new world, especially in our industry.<br /><br />Tonight, we will discuss some of the changes that have happened that affect our industry, pontificate on what we need to change to adapt and adjust to this new world.]]></itunes:summary><itunes:duration>7410</itunes:duration><itunes:keywords>balance,chrisroberts,cybersecurity,health,informationsecurity,infosec,missionbeforemoney,ryancloutier,securityshitshow</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/779cffc1dcda0b9672ce16f67a725296.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Fifty-Eight - The times they are a-changing but are we?</title><link>https://www.spreaker.com/episode/episode-fifty-eight-the-times-they-are-a-changing-but-are-we--47750194</link><description><![CDATA[Last week we took some time away to do some of the things we love, Chris went to DefCon to taste whiskey with folks, Evan took his beard and bike to Sturgis to make memories, one of his most favorite things to do and I took some time to visit with my wife and dog.<br /> <br />As I was reflecting on all the things that had happened in just a weeks’ time, it dawned on me we are at the beginning of a new era as a society and as an industry and even as I type this my news feed is full of new discoveries, new legislation, new science and change on a global scale that at times is hard to comprehend. <br /><br />The scope and scale of work in front of us is daunting, old thinking and old methods must go, we must get creative, we must innovate, we must simplify. <br /><br />What used to work is no longer working, what used to be acceptable is no longer acceptable, what used to be enough is no longer enough. We now must embrace these changes head on and take a whole new approach to a new world, especially in our industry.<br /><br />Tonight, we will discuss some of the changes that have happened that affect our industry, pontificate on what we need to change to adapt and adjust to this new world.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47750194</guid><pubDate>Thu, 02 Dec 2021 16:45:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47750194/episode_58_the_times_they_are_a_changing_but_are_we.mp3" length="118161789" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Last week we took some time away to do some of the things we love, Chris went to DefCon to taste whiskey with folks, Evan took his beard and bike to Sturgis to make memories, one of his most favorite things to do and I took some time to visit with my...</itunes:subtitle><itunes:summary><![CDATA[Last week we took some time away to do some of the things we love, Chris went to DefCon to taste whiskey with folks, Evan took his beard and bike to Sturgis to make memories, one of his most favorite things to do and I took some time to visit with my wife and dog.<br /> <br />As I was reflecting on all the things that had happened in just a weeks’ time, it dawned on me we are at the beginning of a new era as a society and as an industry and even as I type this my news feed is full of new discoveries, new legislation, new science and change on a global scale that at times is hard to comprehend. <br /><br />The scope and scale of work in front of us is daunting, old thinking and old methods must go, we must get creative, we must innovate, we must simplify. <br /><br />What used to work is no longer working, what used to be acceptable is no longer acceptable, what used to be enough is no longer enough. We now must embrace these changes head on and take a whole new approach to a new world, especially in our industry.<br /><br />Tonight, we will discuss some of the changes that have happened that affect our industry, pontificate on what we need to change to adapt and adjust to this new world.]]></itunes:summary><itunes:duration>7386</itunes:duration><itunes:keywords>chrisroberts,cybersecurity,evanfrancen,informationsecurity,infosec,podcast,ryancloutier,securityshitshow,truth</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/779cffc1dcda0b9672ce16f67a725296.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Fifty-Seven - Hey CISO, You Can't Win</title><link>https://www.spreaker.com/episode/episode-fifty-seven-hey-ciso-you-can-t-win--47749756</link><description><![CDATA[DAY ONE<br />CONGRATULATIONS! You've made it to the top. You're the CHIEF!<br />CHIEF INFORMATION SECURITY OFFICER, the CISO. <br />Sounds pretty damn good! It's feels pretty damn good too! <br />I AM THE CISO!!! YAY ME!!!<br /><br />SOMEWHERE BETWEEN DAY TWO AND NINETY<br />I'm (still) grateful to be the CISO. I get paid to make a difference, and it's great to be in a position where I can!<br />It's a lot of work though. Like ALOT or work. It didn't seem so hard from the outside. Maybe I'm just not doing it right. Or, you know what? I'm still adjusting. Yep, that's it! Still adjusting.<br />This will be great!<br />Now that I think about it, it's sort of lonely here at the top too. <br />Oh well, whatever. Remember, I'm adjusting and I'M CISO!<br /><br />SOMEWHERE BETWEEN DAY NINETY AND WHAT SEEMS LIKE ETERNITY<br />Wow. Now I realize that it's lonely at the top, AND the wind blows the strongest at the top of the mountain!<br />Between the unrealistic expectations of the "business", lack of collaboration with other executives (namely the CEO), preaching the same shit everyday, the politics, and very limited resources, I'm starting to miss the good old days.<br />WAIT?! What am I saying?! I'm the damn CISO! I'm the the top dog, and this is awesome!<br />Now I need to figure out how to tell my wife I'm going to be late again tonight...<br /><br />IF YOU'VE BEEN PAYING ATTENTION...<br />You may have noticed that you're playing a game that you CANNOT win. You are being held accountable for things you're not empowered to control. Everybody looks at you when you know they should be looking at themselves.<br /><br />That damn head of research and his damned grants! There's no way in hell I'm going to get him to use MFA on the data repository.<br /><br />Bill in sales is a real turd too! Just because he brings in millions of dollars of business, it shouldn't exempt him from following the rules! He's putting the business at risk!!!<br /><br />Crap, and what about Sally, the head of the London office? She keeps playing the politics card with me and I don't have the same kind of pull she does.<br /><br />My budget keeps getting cut, I feel like I'm losing the respect of my peers, and I always feel like I should be leading my team better. Speaking of my "team", I'm running at 40% staffing level right now! THIS IS HARD! <br /><br />To top it all off, I'm not sleeping very well, my wife is distant (and usually pissed at me), and I have no time to take the new boat out.<br /><br />THAT'S IT!!! I CAN'T WIN!!!<br />Oh this sucks! Now what? I've got two kids in college, a big house payment, this nice car I've got to pay for, and this fricken boat I never get to use!<br />I can't quit! What will happen with everything I worked so hard for?<br /><br />Shit. <br /><br />I'll just go with the flow and try not to make waves anymore. That "change" I was so excited about at the beginning? Yeah, screw it. I'll just play the game to lose.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47749756</guid><pubDate>Thu, 02 Dec 2021 07:27:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47749756/episode_57_hey_ciso_you_can_t_win.mp3" length="102880784" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>DAY ONE
CONGRATULATIONS! You've made it to the top. You're the CHIEF!
CHIEF INFORMATION SECURITY OFFICER, the CISO. 
Sounds pretty damn good! It's feels pretty damn good too! 
I AM THE CISO!!! YAY ME!!!

SOMEWHERE BETWEEN DAY TWO AND NINETY
I'm...</itunes:subtitle><itunes:summary><![CDATA[DAY ONE<br />CONGRATULATIONS! You've made it to the top. You're the CHIEF!<br />CHIEF INFORMATION SECURITY OFFICER, the CISO. <br />Sounds pretty damn good! It's feels pretty damn good too! <br />I AM THE CISO!!! YAY ME!!!<br /><br />SOMEWHERE BETWEEN DAY TWO AND NINETY<br />I'm (still) grateful to be the CISO. I get paid to make a difference, and it's great to be in a position where I can!<br />It's a lot of work though. Like ALOT or work. It didn't seem so hard from the outside. Maybe I'm just not doing it right. Or, you know what? I'm still adjusting. Yep, that's it! Still adjusting.<br />This will be great!<br />Now that I think about it, it's sort of lonely here at the top too. <br />Oh well, whatever. Remember, I'm adjusting and I'M CISO!<br /><br />SOMEWHERE BETWEEN DAY NINETY AND WHAT SEEMS LIKE ETERNITY<br />Wow. Now I realize that it's lonely at the top, AND the wind blows the strongest at the top of the mountain!<br />Between the unrealistic expectations of the "business", lack of collaboration with other executives (namely the CEO), preaching the same shit everyday, the politics, and very limited resources, I'm starting to miss the good old days.<br />WAIT?! What am I saying?! I'm the damn CISO! I'm the the top dog, and this is awesome!<br />Now I need to figure out how to tell my wife I'm going to be late again tonight...<br /><br />IF YOU'VE BEEN PAYING ATTENTION...<br />You may have noticed that you're playing a game that you CANNOT win. You are being held accountable for things you're not empowered to control. Everybody looks at you when you know they should be looking at themselves.<br /><br />That damn head of research and his damned grants! There's no way in hell I'm going to get him to use MFA on the data repository.<br /><br />Bill in sales is a real turd too! Just because he brings in millions of dollars of business, it shouldn't exempt him from following the rules! He's putting the business at risk!!!<br /><br />Crap, and what about Sally, the head of the London office? She keeps playing the politics card with me and I don't have the same kind of pull she does.<br /><br />My budget keeps getting cut, I feel like I'm losing the respect of my peers, and I always feel like I should be leading my team better. Speaking of my "team", I'm running at 40% staffing level right now! THIS IS HARD! <br /><br />To top it all off, I'm not sleeping very well, my wife is distant (and usually pissed at me), and I have no time to take the new boat out.<br /><br />THAT'S IT!!! I CAN'T WIN!!!<br />Oh this sucks! Now what? I've got two kids in college, a big house payment, this nice car I've got to pay for, and this fricken boat I never get to use!<br />I can't quit! What will happen with everything I worked so hard for?<br /><br />Shit. <br /><br />I'll just go with the flow and try not to make waves anymore. That "change" I was so excited about at the beginning? Yeah, screw it. I'll just play the game to lose.]]></itunes:summary><itunes:duration>6431</itunes:duration><itunes:keywords>broken,chrisroberts,ciso,cybersecurity,evanfrancen,informationsecurity,infosec,ryancloutier,securityshitshow,truth</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/870ade35877fa47fa5b46a5e4bf42ed8.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Fifty-Six - You Got Breached, Congratulations</title><link>https://www.spreaker.com/episode/episode-fifty-six-you-got-breached-congratulations--47171477</link><description><![CDATA[You Got Breached.<br /><br />Congratulations.<br />You’re NOT a special snowflake<br />You can’t go round pouting<br />You don’t need to find anyone to blame<br />No, the Russians probably didn’t do it<br />No, I don’t need tagging in the post<br />Yes, likely you DO need to change some things<br />No, you probably couldn’t have stopped it<br />Yes, you could have likely detected it sooner<br />Yes, you could probably have remediated it faster<br />No, don’t you DARE blame the users!<br />No, your annual training for 30 mins isn’t effective (it sucks)<br />Yes, you can recover from it (hopefully)<br />No, it won’t kill you JUST yet, wait a few more years though…<br />More budget? Stop wining and spend what you have wisely<br />Yes, it means you have to roll up your sleeves<br />Yes, interns or apprentices can help remediate this<br />Yes, get off your ass, it got pwned, get over it<br />No, you’re still NOT a special snowflake.<br /><br />Congratulations.<br />You’re JUST like all the other breaches<br />You can sit down and plan<br />You should go look in the mirror<br />You likely did it to yourself, we’ll get to that.<br />Yes, you can reach out for help and advice<br />NO, you don’t need to buy everyone’s cyber-crap<br />NO, everyone’s cyber-crap isn’t going to stop it either<br />YES, it would be good to know what you actually have<br />YES, it would be great to know WHERE your data IS<br />Yep, IF you can track it back, it probably starts on a users machine<br />Yes, ongoing education HELPS (doesn’t fix, but helps)<br />Yes, you can recover from it (get the basics in order)<br />Yes, we are working on hacking the chips in humans, fun eh?<br />Nope, don’t expect more money, so work smarter<br />Yes, it means you can now get your house in order, good!<br />Yes, you can probably justify headcount but save $$ and get folk TO train<br />Yea, it sucks, sorry, but it’s the way of the new world.<br />And no, you’re not special, you CAN however be a good example.<br /><br />Get the basics sorted out BEFORE your ass is delivered TO you on a silver platter<br /><br />* Assets, what do you have?<br />* Assets, where are they?<br />* Who’s got access to them, and why?<br />* What DO they do, what is their purpose?<br />* What’s on them?<br />* Which ones do you need to care about?<br /><br />Got it? Good, now go get a cuppa tea or coffee and go deal with it…. I’m going to go make breakfast.<br /><br />‘all for now<br /><br />Chris]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47171477</guid><pubDate>Wed, 27 Oct 2021 00:43:46 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47171477/episode_56_you_got_breached_congratulations.mp3" length="81439478" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>You Got Breached.&#13;
&#13;
Congratulations.&#13;
You’re NOT a special snowflake&#13;
You can’t go round pouting&#13;
You don’t need to find anyone to blame&#13;
No, the Russians probably didn’t do it&#13;
No, I don’t need tagging in the post&#13;
Yes, likely you DO need to change...</itunes:subtitle><itunes:summary><![CDATA[You Got Breached.<br /><br />Congratulations.<br />You’re NOT a special snowflake<br />You can’t go round pouting<br />You don’t need to find anyone to blame<br />No, the Russians probably didn’t do it<br />No, I don’t need tagging in the post<br />Yes, likely you DO need to change some things<br />No, you probably couldn’t have stopped it<br />Yes, you could have likely detected it sooner<br />Yes, you could probably have remediated it faster<br />No, don’t you DARE blame the users!<br />No, your annual training for 30 mins isn’t effective (it sucks)<br />Yes, you can recover from it (hopefully)<br />No, it won’t kill you JUST yet, wait a few more years though…<br />More budget? Stop wining and spend what you have wisely<br />Yes, it means you have to roll up your sleeves<br />Yes, interns or apprentices can help remediate this<br />Yes, get off your ass, it got pwned, get over it<br />No, you’re still NOT a special snowflake.<br /><br />Congratulations.<br />You’re JUST like all the other breaches<br />You can sit down and plan<br />You should go look in the mirror<br />You likely did it to yourself, we’ll get to that.<br />Yes, you can reach out for help and advice<br />NO, you don’t need to buy everyone’s cyber-crap<br />NO, everyone’s cyber-crap isn’t going to stop it either<br />YES, it would be good to know what you actually have<br />YES, it would be great to know WHERE your data IS<br />Yep, IF you can track it back, it probably starts on a users machine<br />Yes, ongoing education HELPS (doesn’t fix, but helps)<br />Yes, you can recover from it (get the basics in order)<br />Yes, we are working on hacking the chips in humans, fun eh?<br />Nope, don’t expect more money, so work smarter<br />Yes, it means you can now get your house in order, good!<br />Yes, you can probably justify headcount but save $$ and get folk TO train<br />Yea, it sucks, sorry, but it’s the way of the new world.<br />And no, you’re not special, you CAN however be a good example.<br /><br />Get the basics sorted out BEFORE your ass is delivered TO you on a silver platter<br /><br />* Assets, what do you have?<br />* Assets, where are they?<br />* Who’s got access to them, and why?<br />* What DO they do, what is their purpose?<br />* What’s on them?<br />* Which ones do you need to care about?<br /><br />Got it? Good, now go get a cuppa tea or coffee and go deal with it…. I’m going to go make breakfast.<br /><br />‘all for now<br /><br />Chris]]></itunes:summary><itunes:duration>5090</itunes:duration><itunes:keywords>breach,chris,cloutier,cyber,cybersecurity,evan,francen,infosec,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/57417f6c7012b421fe5f44740fe1603f.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Fifty-Five - To code scan or not to code scan that is the question</title><link>https://www.spreaker.com/episode/episode-fifty-five-to-code-scan-or-not-to-code-scan-that-is-the-question--47148178</link><description><![CDATA[You'll have to listen to find out.  Actually, we forgot to write the show notes for this episode. Cut us some slack though, this is the Security Shit Show!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47148178</guid><pubDate>Mon, 25 Oct 2021 18:51:42 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47148178/episode_55_to_code_scan_or_not_to_code_scan_that_is_the_question.mp3" length="72720431" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>You'll have to listen to find out.  Actually, we forgot to write the show notes for this episode. Cut us some slack though, this is the Security Shit Show!</itunes:subtitle><itunes:summary><![CDATA[You'll have to listen to find out.  Actually, we forgot to write the show notes for this episode. Cut us some slack though, this is the Security Shit Show!]]></itunes:summary><itunes:duration>4545</itunes:duration><itunes:keywords>chris,cloutier,code,cybersecurity,evan,francen,infosec,roberts,ryan,security,shit,show,vulnerability</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/7bc200cc21fec3202c3b3f525e234ff4.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Fifty-Four - It's Just Urine</title><link>https://www.spreaker.com/episode/episode-fifty-four-it-s-just-urine--47146318</link><description><![CDATA[We all piss. We drink shit (not literally), the shit finds it's way to the kidney (I only have one left), and eventually to the prostrate (if you're genetically male), and out through the wanker.<br /><br />Pretty standard stuff. At the end, you get urine (hopefully). That's it.<br /><br />So, why the !%@$# pissing contest?! What's there to contest?<br />Is your pee yellower?<br />Is your stream stronger?<br />Did you hit the bowl this time?<br /><br />Why are you so *!@& proud of yourself?<br /><br />The fact of the matter is, we engage in pissing contests way too much in this industry, and it's a COMPLETE waste of time. They serve nothing but the selfish, destructive ego.<br /><br />Let's go through two examples from this week, and see where it goes from there.<br />In example #1, it's the classic establish dominance right out of the gate maneuver, "Well, let me give you a scenario...". <br />Example #2 was straight up intimidation of a colleague with less experience and confidence. The pissing contestant went with the "Well, let me stop you right there..." move.<br /><br />At the end of both examples, we DID make new friends, but not until we established that we don't give two shits about ego. Let's solve some damn problems!<br /><br />I'm sure we'll come up with some more good examples during the show!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/47146318</guid><pubDate>Mon, 25 Oct 2021 16:12:59 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/47146318/episode_54_it_s_just_urine.mp3" length="136720431" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>We all piss. We drink shit (not literally), the shit finds it's way to the kidney (I only have one left), and eventually to the prostrate (if you're genetically male), and out through the wanker.&#13;
&#13;
Pretty standard stuff. At the end, you get urine...</itunes:subtitle><itunes:summary><![CDATA[We all piss. We drink shit (not literally), the shit finds it's way to the kidney (I only have one left), and eventually to the prostrate (if you're genetically male), and out through the wanker.<br /><br />Pretty standard stuff. At the end, you get urine (hopefully). That's it.<br /><br />So, why the !%@$# pissing contest?! What's there to contest?<br />Is your pee yellower?<br />Is your stream stronger?<br />Did you hit the bowl this time?<br /><br />Why are you so *!@& proud of yourself?<br /><br />The fact of the matter is, we engage in pissing contests way too much in this industry, and it's a COMPLETE waste of time. They serve nothing but the selfish, destructive ego.<br /><br />Let's go through two examples from this week, and see where it goes from there.<br />In example #1, it's the classic establish dominance right out of the gate maneuver, "Well, let me give you a scenario...". <br />Example #2 was straight up intimidation of a colleague with less experience and confidence. The pissing contestant went with the "Well, let me stop you right there..." move.<br /><br />At the end of both examples, we DID make new friends, but not until we established that we don't give two shits about ego. Let's solve some damn problems!<br /><br />I'm sure we'll come up with some more good examples during the show!]]></itunes:summary><itunes:duration>8545</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,ego,evan,francen,infosec,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/d40c27c050a617fc43f94817ccec5495.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Fifty-Three - Let's Play 20 Questions (for vendors)</title><link>https://www.spreaker.com/episode/episode-fifty-three-let-s-play-20-questions-for-vendors--46397541</link><description><![CDATA[Vendor Questions!<br /> <br />On tonight’s YouTube #shitshow we’re going to discuss what to ask the vendors as the line up to take your annual budget....<br /> <br />Think of this as OUR version of 20 questions.<br /> <br />Join Ryan Cloutier, CISSP, Evan Francen, Rachel Arnold, and I, as we work through things to contemplate, cogitate, consider, AND use as you sort for that elusive needle IN the thicket we call the “right” InfoSec vendor in the ever increasingly convoluted and complex landscape.<br /> <br />Somewhere in among the twenty questions we WILL likely have the following:<br /> <br />- Where’s my data?<br />- What IS the airspeed velocity of a swallow?<br />- How do YOU train your staff?<br />- What IS the meaning of life?<br />- Explain how YOU use 2FA/MFA<br />- Do you feel lucky?<br />- What’s a polymorphic trojan, AND why is there one in your code?<br />- Is it safe?<br />- What’s your plan for the end of the world?<br />- Who ya gonna call (when it breaks)<br />- Define protection?<br />- Where’s your decoder ring for the acronyms?<br />- Who’s accountable when it breaks?<br />- Etc.<br /> <br />Join us THIS evening (Thursday 21:00 mountain time) as we (try) to piece together 20 USEFUL questions you can ask the next vendor that makes it past the front receptionist AND their trap doors…<br /> <br />BONUS: How to, and where to hide the body If the vendor in question prefixes each response with “That’s a really good question Chris, let me…”<br /> <br />SIGN-UP NOW! And receive spam for life free* (Postage not included)<br /> <br />CLICK THE LIKE!! And we’ll track the click AND enter you into a free draw to win stickers!<br />(This one we can do, we HAZ stickers, DM me if you want some!!)]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/46397541</guid><pubDate>Thu, 09 Sep 2021 13:45:18 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/46397541/episode_53_let_s_play_20_questions_for_vendors.mp3" length="127763148" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Vendor Questions!
 
On tonight’s YouTube #shitshow we’re going to discuss what to ask the vendors as the line up to take your annual budget....
 
Think of this as OUR version of 20 questions.
 
Join Ryan Cloutier, CISSP, Evan Francen, Rachel Arnold,...</itunes:subtitle><itunes:summary><![CDATA[Vendor Questions!<br /> <br />On tonight’s YouTube #shitshow we’re going to discuss what to ask the vendors as the line up to take your annual budget....<br /> <br />Think of this as OUR version of 20 questions.<br /> <br />Join Ryan Cloutier, CISSP, Evan Francen, Rachel Arnold, and I, as we work through things to contemplate, cogitate, consider, AND use as you sort for that elusive needle IN the thicket we call the “right” InfoSec vendor in the ever increasingly convoluted and complex landscape.<br /> <br />Somewhere in among the twenty questions we WILL likely have the following:<br /> <br />- Where’s my data?<br />- What IS the airspeed velocity of a swallow?<br />- How do YOU train your staff?<br />- What IS the meaning of life?<br />- Explain how YOU use 2FA/MFA<br />- Do you feel lucky?<br />- What’s a polymorphic trojan, AND why is there one in your code?<br />- Is it safe?<br />- What’s your plan for the end of the world?<br />- Who ya gonna call (when it breaks)<br />- Define protection?<br />- Where’s your decoder ring for the acronyms?<br />- Who’s accountable when it breaks?<br />- Etc.<br /> <br />Join us THIS evening (Thursday 21:00 mountain time) as we (try) to piece together 20 USEFUL questions you can ask the next vendor that makes it past the front receptionist AND their trap doors…<br /> <br />BONUS: How to, and where to hide the body If the vendor in question prefixes each response with “That’s a really good question Chris, let me…”<br /> <br />SIGN-UP NOW! And receive spam for life free* (Postage not included)<br /> <br />CLICK THE LIKE!! And we’ll track the click AND enter you into a free draw to win stickers!<br />(This one we can do, we HAZ stickers, DM me if you want some!!)]]></itunes:summary><itunes:duration>7986</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,information,infosec,risk,roberts,ryan,security,shit,show,vendors</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/ec0d04102a7a2380dbcc13a84f446b5d.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Fifty-Two - The Addiction is Real</title><link>https://www.spreaker.com/episode/episode-fifty-two-the-addiction-is-real--46397345</link><description><![CDATA[Picture by Nerea Sesma Perez<br /><br />Looking back at the history of modern technology, it's incredible how far we've come in such a short period of time. Parents remember life without a cell phone, while kids were born with them as part of their DNA (practically).<br /><br />Parents struggle to keep up, kids can't wait for the next thing.<br /><br />Social Media:<br />5.22 billion unique mobile device users.<br />4.20 billion social media users.<br />+1.0% (population growth), +1.8% (mobile user growth), +7.3% (Internet user growth), and +13.2% (active social media user growth) - All annual.<br />2.32 billion active monthly Facebook users.<br />2.5 hours per day spent on social networks and messaging (on average).<br />Most popular social platforms (in order): Facebook, YouTube, WhatsApp, FB Messenger, Instagram, Weixin/WeChat, TikTok, QQ, Douyin, Sina Weibo, Telegram, Snapchat, Kuaishou, Pinterest, Reddit, Twitter, and Quora.<br /><br />Devices:<br />Average number of connected devices per household in 2020 (worldwide): 10<br />The smart home market will grow by $54 billion by 2022.<br />IoT data volume is expected to grow to nearly 79.4 zettabytes by 2025.<br />Worldwide network device ownership will be 3.6 per person in 2023.<br /><br />All this comes with a price. What is the price and how will we pay for it? We've adopted technology so fast, MUCH faster than our ability to use it responsibly and MUCH faster than our ability to secure it.<br /><br />Where are we? How did we get here? Are we OK with where we're at, or are we heading for disaster?<br /><br />Good luck taking the phone out of your kids hands! Look down at your own.<br /><br />This will be a great Shit Show! <br />Join myself (Evan), Chris, and Ryan LIVE at 2200CST right here.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/46397345</guid><pubDate>Mon, 06 Sep 2021 12:25:07 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/46397345/episode_52_the_addition_is_real.mp3" length="117844140" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Picture by Nerea Sesma Perez

Looking back at the history of modern technology, it's incredible how far we've come in such a short period of time. Parents remember life without a cell phone, while kids were born with them as part of their DNA...</itunes:subtitle><itunes:summary><![CDATA[Picture by Nerea Sesma Perez<br /><br />Looking back at the history of modern technology, it's incredible how far we've come in such a short period of time. Parents remember life without a cell phone, while kids were born with them as part of their DNA (practically).<br /><br />Parents struggle to keep up, kids can't wait for the next thing.<br /><br />Social Media:<br />5.22 billion unique mobile device users.<br />4.20 billion social media users.<br />+1.0% (population growth), +1.8% (mobile user growth), +7.3% (Internet user growth), and +13.2% (active social media user growth) - All annual.<br />2.32 billion active monthly Facebook users.<br />2.5 hours per day spent on social networks and messaging (on average).<br />Most popular social platforms (in order): Facebook, YouTube, WhatsApp, FB Messenger, Instagram, Weixin/WeChat, TikTok, QQ, Douyin, Sina Weibo, Telegram, Snapchat, Kuaishou, Pinterest, Reddit, Twitter, and Quora.<br /><br />Devices:<br />Average number of connected devices per household in 2020 (worldwide): 10<br />The smart home market will grow by $54 billion by 2022.<br />IoT data volume is expected to grow to nearly 79.4 zettabytes by 2025.<br />Worldwide network device ownership will be 3.6 per person in 2023.<br /><br />All this comes with a price. What is the price and how will we pay for it? We've adopted technology so fast, MUCH faster than our ability to use it responsibly and MUCH faster than our ability to secure it.<br /><br />Where are we? How did we get here? Are we OK with where we're at, or are we heading for disaster?<br /><br />Good luck taking the phone out of your kids hands! Look down at your own.<br /><br />This will be a great Shit Show! <br />Join myself (Evan), Chris, and Ryan LIVE at 2200CST right here.]]></itunes:summary><itunes:duration>7366</itunes:duration><itunes:keywords>addiction,chris,cloutier,evan,francen,information,infosec,media,privacy,roberts,ryan,security,shit,show,social</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c75edd1ab54aeac0fc13021c9e461212.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Fifty-One - Honey! The Neighbors are Watching us Again!</title><link>https://www.spreaker.com/episode/episode-fifty-one-honey-the-neighbors-are-watching-us-again--45905084</link><description><![CDATA[At least in years past we could at least spot the neighbors as they tried to hide behind the shrubs in the garden, the curtains in the house, or ducked down below the fence line that separated each of our little slices of the American Dream....<br /><br />These days; however, things are a little more subtle (if the neighbors have been paying attention to the InfoSec world for more than 5 minutes...)<br /><br />Long gone are the days of just borrowing the neighbors wireless to launch an attack against the NSA through their cable provider (although it IS fun to see the black suburban roll up occasionally to their doorstep when you’re feeling mischievous..)<br /><br />Today’s targets for neighborhood “watching” vary across an entire spectrum of fun and games...<br /><br />I still feel slightly guilty about the 50-gallon barrel of lube my neighbors have, but “Hey Siri...” we just have to have some fun....<br /><br />I DO enjoy making their microwave go off in the middle of the night, although they've replaced it a few times now, and the electrician doesn’t use Google Maps anymore to find them... amazing just how far away those WEMO plugs can be controlled from.<br /><br />Now, thankfully Xfinity allows themselves to provide “free” WiFi to anyone with account credentials, so it IS still possible to get directly TO their router (you’d think folks would update the things.... but no) and given I’ve got around 1,335,000 Xfinity account ID/Passwords I’m set for a LONG time before I must leave my own fingerprints...<br /><br />Oh, speaking of fingerprints, confession time... one of the neighbors has a RING doorbell, oh how we laughed when we changed out the screws during install and just last week got the doorbell to short circuit and burn ½ the place down... shame the fire alarms didn’t work, someone should REALLY unblock NEST’s fire alarms from the firewall and allow them to do their job. The video of the owners yelling “Hey Google FFS call the fire brigade” will be posted on YouTube later (thanks Arlo for the default account credentials...)<br /><br />Oh, while we’re on the subject of the recently deceased, I guess playing Poltergeist on the other neighbors Roku device and having it display on all their nice Samsung IoT enabled TV’s is probably a mean thing to do... although it does make for entertainment as we might have also hooked up their Phillips Hue to pulse at the same frequency as the TV... I guess that’s why they seem a little nervous these days.<br /><br />Oh, and we won’t mention the fun we had with the Tesla and some bright spark in the neighborhood thinking they could geofence the car into opening/closing the garage as they came home... Watching the garage door rapidly open and close AS the car tried to get in watching Grandma eat dinner with her falsies...<br /><br />Speaking of that, I need to go mess with dear old Grandma’s IoT toothbrush, I think tonight we’ll set it for “killer mode” and see if it can chase her round the bathroom again...<br /><br />We haven’t even gotten to the fun part watching the cute couple across the road react as their adult toys came to life in the middle of a webinar and started to inch across the desk... now THAT was fun to record… got to LOVE Bluetooth enabled things.<br /><br />You get the idea; the neighborhood is SO much more fun these days....<br /><br />Join us tonight as we talk though the evolution of the nosey neighbor :)]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/45905084</guid><pubDate>Mon, 02 Aug 2021 11:58:34 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/45905084/episode51_073021.mp3" length="138324053" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>At least in years past we could at least spot the neighbors as they tried to hide behind the shrubs in the garden, the curtains in the house, or ducked down below the fence line that separated each of our little slices of the American Dream....

These...</itunes:subtitle><itunes:summary><![CDATA[At least in years past we could at least spot the neighbors as they tried to hide behind the shrubs in the garden, the curtains in the house, or ducked down below the fence line that separated each of our little slices of the American Dream....<br /><br />These days; however, things are a little more subtle (if the neighbors have been paying attention to the InfoSec world for more than 5 minutes...)<br /><br />Long gone are the days of just borrowing the neighbors wireless to launch an attack against the NSA through their cable provider (although it IS fun to see the black suburban roll up occasionally to their doorstep when you’re feeling mischievous..)<br /><br />Today’s targets for neighborhood “watching” vary across an entire spectrum of fun and games...<br /><br />I still feel slightly guilty about the 50-gallon barrel of lube my neighbors have, but “Hey Siri...” we just have to have some fun....<br /><br />I DO enjoy making their microwave go off in the middle of the night, although they've replaced it a few times now, and the electrician doesn’t use Google Maps anymore to find them... amazing just how far away those WEMO plugs can be controlled from.<br /><br />Now, thankfully Xfinity allows themselves to provide “free” WiFi to anyone with account credentials, so it IS still possible to get directly TO their router (you’d think folks would update the things.... but no) and given I’ve got around 1,335,000 Xfinity account ID/Passwords I’m set for a LONG time before I must leave my own fingerprints...<br /><br />Oh, speaking of fingerprints, confession time... one of the neighbors has a RING doorbell, oh how we laughed when we changed out the screws during install and just last week got the doorbell to short circuit and burn ½ the place down... shame the fire alarms didn’t work, someone should REALLY unblock NEST’s fire alarms from the firewall and allow them to do their job. The video of the owners yelling “Hey Google FFS call the fire brigade” will be posted on YouTube later (thanks Arlo for the default account credentials...)<br /><br />Oh, while we’re on the subject of the recently deceased, I guess playing Poltergeist on the other neighbors Roku device and having it display on all their nice Samsung IoT enabled TV’s is probably a mean thing to do... although it does make for entertainment as we might have also hooked up their Phillips Hue to pulse at the same frequency as the TV... I guess that’s why they seem a little nervous these days.<br /><br />Oh, and we won’t mention the fun we had with the Tesla and some bright spark in the neighborhood thinking they could geofence the car into opening/closing the garage as they came home... Watching the garage door rapidly open and close AS the car tried to get in watching Grandma eat dinner with her falsies...<br /><br />Speaking of that, I need to go mess with dear old Grandma’s IoT toothbrush, I think tonight we’ll set it for “killer mode” and see if it can chase her round the bathroom again...<br /><br />We haven’t even gotten to the fun part watching the cute couple across the road react as their adult toys came to life in the middle of a webinar and started to inch across the desk... now THAT was fun to record… got to LOVE Bluetooth enabled things.<br /><br />You get the idea; the neighborhood is SO much more fun these days....<br /><br />Join us tonight as we talk though the evolution of the nosey neighbor :)]]></itunes:summary><itunes:duration>8646</itunes:duration><itunes:keywords>chris,cloutier,evan,francen,funny,hacker,informationsecurity,infosec,iot,privacy,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/27f7b107e39fe61fc72aa172279a2426.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Fifty - Shit Show in the Woods</title><link>https://www.spreaker.com/episode/episode-fifty-shit-show-in-the-woods--45487698</link><description><![CDATA[For the first time, the Security Shit Show hits the road for an in person event. Chris, Evan, and Ryan are heading down to the woods of Nebraska for the weekend. The first night we're there, we do the show.<br /><br />We're not really sure what to expect, but we're pretty sure there will be some information security stuff, some shit, and some whiskey.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/45487698</guid><pubDate>Tue, 29 Jun 2021 13:00:15 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/45487698/episode50_062921.mp3" length="118003801" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>For the first time, the Security Shit Show hits the road for an in person event. Chris, Evan, and Ryan are heading down to the woods of Nebraska for the weekend. The first night we're there, we do the show.

We're not really sure what to expect, but...</itunes:subtitle><itunes:summary><![CDATA[For the first time, the Security Shit Show hits the road for an in person event. Chris, Evan, and Ryan are heading down to the woods of Nebraska for the weekend. The first night we're there, we do the show.<br /><br />We're not really sure what to expect, but we're pretty sure there will be some information security stuff, some shit, and some whiskey.]]></itunes:summary><itunes:duration>7376</itunes:duration><itunes:keywords>accountability,chris,cloutier,cybersecurity,evan,francen,infosec,live,privacy,respect,roberts,ryan,security,shit,show,woods</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/af89a5200e1ce804f9284fff38eb9504.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Forty-Nine - Sorry to disturb you...</title><link>https://www.spreaker.com/episode/episode-forty-nine-sorry-to-disturb-you--45472984</link><description><![CDATA[Sorry to Disturb You...<br />·      But your front doors open...<br />·      Your flies are undone...<br />·      I found your kid wandering on the street...<br />·      But I think you dropped your wallet...<br /><br />All things many of us have said, done, acted upon OR been the recipient of over our years, and all of them taken in the spirit of the manner delivered, graciously, often with relief and a huge thanks to whomever delivered the news.<br /><br />HOWEVER, in the digital realm...<br />·      I do say, you appear to have an open port on the Internet...<br />·      Um, your application has a hole in it...<br />·      We found your data lost and confused....<br />·      I think you might have a hole in your cloud...<br />SOME of us have tried to have these conversations with companies, individuals, and entities out in the digital realm and have been met with a variety of responses ranging from thanks AND relief, to accusation, lawyers, silence, or the FED’s arriving on the doorstep etc.<br /><br />Somehow, in the physical realm when point out your mistakes, flaws and general numptiness you are happy to receive the feedback, yet in the digital realm when we do the same it’s as if we called your baby “robust with a face only a mother could love.”<br /><br />What gives? How DO we give you YOUR data BACK in the digital realm without all this grief?<br /><br />I mean, it’s NOT as if you realized it was gone, OR that chocolate fireguard you were sold would have slowed us down anyhow IF we did want it!<br /><br />Things to ponder on and discuss this coming Thursday on the Shit Show with Evan, Ryan, and Chris<br />‘all for now<br />Chris]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/45472984</guid><pubDate>Mon, 28 Jun 2021 13:25:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/45472984/episode49_062721.mp3" length="126899975" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Sorry to Disturb You...
·      But your front doors open...
·      Your flies are undone...
·      I found your kid wandering on the street...
·      But I think you dropped your wallet...

All things many of us have said, done, acted upon OR been the...</itunes:subtitle><itunes:summary><![CDATA[Sorry to Disturb You...<br />·      But your front doors open...<br />·      Your flies are undone...<br />·      I found your kid wandering on the street...<br />·      But I think you dropped your wallet...<br /><br />All things many of us have said, done, acted upon OR been the recipient of over our years, and all of them taken in the spirit of the manner delivered, graciously, often with relief and a huge thanks to whomever delivered the news.<br /><br />HOWEVER, in the digital realm...<br />·      I do say, you appear to have an open port on the Internet...<br />·      Um, your application has a hole in it...<br />·      We found your data lost and confused....<br />·      I think you might have a hole in your cloud...<br />SOME of us have tried to have these conversations with companies, individuals, and entities out in the digital realm and have been met with a variety of responses ranging from thanks AND relief, to accusation, lawyers, silence, or the FED’s arriving on the doorstep etc.<br /><br />Somehow, in the physical realm when point out your mistakes, flaws and general numptiness you are happy to receive the feedback, yet in the digital realm when we do the same it’s as if we called your baby “robust with a face only a mother could love.”<br /><br />What gives? How DO we give you YOUR data BACK in the digital realm without all this grief?<br /><br />I mean, it’s NOT as if you realized it was gone, OR that chocolate fireguard you were sold would have slowed us down anyhow IF we did want it!<br /><br />Things to ponder on and discuss this coming Thursday on the Shit Show with Evan, Ryan, and Chris<br />‘all for now<br />Chris]]></itunes:summary><itunes:duration>7932</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,infosec,privacy,roberts,ryan,security,shit,show,talk</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/14ae5507509227a3f19c2aaca2c71e47.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Forty-Eight - Jeopardy v2 (Take #2)</title><link>https://www.spreaker.com/episode/episode-forty-eight-jeopardy-v2-take-2--45436679</link><description><![CDATA[Well we are going to try this again Episode #47 went a different direction, so tonight we are going to to try Jeopardy again<br />It's time to play some Security Shit Show Jeopardy again. Hell yeah!<br /><br />I will be your host Ryan Trebek <br /><br />One game, one Cham Peon. Like v1, we'll pick three contestants from our live audience to play our version of Jeopardy. Winner gets some bragging rights and a Security Shit Show T-shirt (that I'll forget to send you).<br /><br />YOU THINK YOU'VE GOT WHAT IT TAKES?! <br />COME PROVE IT!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/45436679</guid><pubDate>Sat, 26 Jun 2021 07:55:17 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/45436679/episode48_062521.mp3" length="139271236" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Well we are going to try this again Episode #47 went a different direction, so tonight we are going to to try Jeopardy again
It's time to play some Security Shit Show Jeopardy again. Hell yeah!

I will be your host Ryan Trebek 

One game, one Cham...</itunes:subtitle><itunes:summary><![CDATA[Well we are going to try this again Episode #47 went a different direction, so tonight we are going to to try Jeopardy again<br />It's time to play some Security Shit Show Jeopardy again. Hell yeah!<br /><br />I will be your host Ryan Trebek <br /><br />One game, one Cham Peon. Like v1, we'll pick three contestants from our live audience to play our version of Jeopardy. Winner gets some bragging rights and a Security Shit Show T-shirt (that I'll forget to send you).<br /><br />YOU THINK YOU'VE GOT WHAT IT TAKES?! <br />COME PROVE IT!]]></itunes:summary><itunes:duration>8705</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,fun,game,information,infosec,jeopardy,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/50e672c84cb90572f1fb6a8e20f809b8.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Forty-Seven - Episode #47 - Jeopardy v2 (and other interesting things...)</title><link>https://www.spreaker.com/episode/episode-forty-seven-episode-47-jeopardy-v2-and-other-interesting-things--45436620</link><description><![CDATA[Originally we were planning to play another round of Security Shit Show Jeopardy, but things went weird off the bat. <br /><br />We just talked about stuff, really. Got honest about things. Hell, this is the Security Shit Show! What did you expect?!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/45436620</guid><pubDate>Fri, 25 Jun 2021 06:47:09 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/45436620/episode47_062421.mp3" length="139364023" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Originally we were planning to play another round of Security Shit Show Jeopardy, but things went weird off the bat. 

We just talked about stuff, really. Got honest about things. Hell, this is the Security Shit Show! What did you expect?!</itunes:subtitle><itunes:summary><![CDATA[Originally we were planning to play another round of Security Shit Show Jeopardy, but things went weird off the bat. <br /><br />We just talked about stuff, really. Got honest about things. Hell, this is the Security Shit Show! What did you expect?!]]></itunes:summary><itunes:duration>8711</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,information,infosec,life,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/0bbfd5ded98676d1ee5680701976ce40.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Forty-Six - Lawnmower Man</title><link>https://www.spreaker.com/episode/episode-forty-six-lawnmower-man--44785195</link><description><![CDATA[My Retirement Plan…<br /><br />Is to head to New Zealand…<br /><br />Somewhere nice and remote…<br /><br />With good power (or a wind farm, etc.)<br /><br />Good internet (terrestrial and Satellite)<br /><br />AND a nice AS/400 to live in<br /><br />If I have my way, and I think well get there before I go too much more senile given the work being done on untangling some of the innerworkings of the brain, I should be at a point where not only can my current intelligent system recognize when I want a cuppa tea, but it can also figure out why, and likely decide what options to present me etc. Already it knows where I’m at, IF I’m thinking of him, and what settings to set the screen to based on several factors that my brain apparently is telling it without letting me know.<br /><br />If I can help push the boundaries of what we’re working on I’ve every confidence that a digital version of me will be coursing around the Interwebs before I’m pushing up daisies. Which brings a WHOLE heap of questions.<br /><br />What makes us human?<br /><br />Are we just quarks and binding energy?<br /><br />Is there really something else to this?<br /><br />Can we be broken down into pulses?<br /><br />Where ARE the limits (or are there any?)<br /><br />Just one retirement plan, what else is there out there? Let’s discuss this and where else humanity IS heading as it does handstands on the edge of the existence cliff…<br /><br />So, as nicely as I can say it, screw y’all, I’m going to hang out in my self sustaining AS/400 and watch things unfold AND if it looks really dodgy I’m going to work out a way to simply fire my digital self into space as a set of waves and see what the hell happens…<br /><br />Lawnmower man, here we come!<br /><br />‘all for now<br />Chris]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/44785195</guid><pubDate>Thu, 13 May 2021 20:28:36 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/44785195/episode46_051221.mp3" length="128244281" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>My Retirement Plan…

Is to head to New Zealand…

Somewhere nice and remote…

With good power (or a wind farm, etc.)

Good internet (terrestrial and Satellite)

AND a nice AS/400 to live in

If I have my way, and I think well get there before I go too...</itunes:subtitle><itunes:summary><![CDATA[My Retirement Plan…<br /><br />Is to head to New Zealand…<br /><br />Somewhere nice and remote…<br /><br />With good power (or a wind farm, etc.)<br /><br />Good internet (terrestrial and Satellite)<br /><br />AND a nice AS/400 to live in<br /><br />If I have my way, and I think well get there before I go too much more senile given the work being done on untangling some of the innerworkings of the brain, I should be at a point where not only can my current intelligent system recognize when I want a cuppa tea, but it can also figure out why, and likely decide what options to present me etc. Already it knows where I’m at, IF I’m thinking of him, and what settings to set the screen to based on several factors that my brain apparently is telling it without letting me know.<br /><br />If I can help push the boundaries of what we’re working on I’ve every confidence that a digital version of me will be coursing around the Interwebs before I’m pushing up daisies. Which brings a WHOLE heap of questions.<br /><br />What makes us human?<br /><br />Are we just quarks and binding energy?<br /><br />Is there really something else to this?<br /><br />Can we be broken down into pulses?<br /><br />Where ARE the limits (or are there any?)<br /><br />Just one retirement plan, what else is there out there? Let’s discuss this and where else humanity IS heading as it does handstands on the edge of the existence cliff…<br /><br />So, as nicely as I can say it, screw y’all, I’m going to hang out in my self sustaining AS/400 and watch things unfold AND if it looks really dodgy I’m going to work out a way to simply fire my digital self into space as a set of waves and see what the hell happens…<br /><br />Lawnmower man, here we come!<br /><br />‘all for now<br />Chris]]></itunes:summary><itunes:duration>8016</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,information,infosec,privacy,roberts,ryan,security,shit,show,talk</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/0623fd25bdefa42fbcef1210e6577a5d.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Forty-Five - Dolla Dolla Bill Y'all</title><link>https://www.spreaker.com/episode/episode-forty-five-dolla-dolla-bill-y-all--44688906</link><description><![CDATA[Money!! it makes the world go round, we need it, we want it, and when it comes to money for our security program we fight for it, but are we spending it wisely?<br /><br /> - Will it have the impact on our security program we hopped it would?<br /> - Did we spend too much or not enough?<br /> - How much money is enough?<br /> - What the hell should I be spending it on that will make the biggest impact?<br /><br />Is it wiser to invest in your people and the fundamentals or to invest in state-of-the-art laser cats with predictive AI powers? What is the right level of budget for your organization and how will you show improvements to the organizational security posture against the spend on the security program.<br /><br />Vendors love money, and the love of money is the root of all evil.<br /><br /> - How do you know if your vendor is predatory?<br /> - Does the product or service do what they claim?<br /> - Will you need to increase headcount to accommodate the tool or service?<br /> - Could you get a better deal on this tool or service?<br /> - Do I even need this tool in my portfolio or is there an existing tool that I can leverage better?<br /><br />All this and more, on the Security Shit Show Join Chris Roberts, Evan Francen and myself for what should be a a very lively discussion. <br /><br />On YouTube Thursday night at 9pm MTN 10 PM central time <br /><br /> - Ryan Cloutier]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/44688906</guid><pubDate>Wed, 12 May 2021 20:08:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/44688906/episode45_050721.mp3" length="313006591" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Money!! it makes the world go round, we need it, we want it, and when it comes to money for our security program we fight for it, but are we spending it wisely?

 - Will it have the impact on our security program we hopped it would?
 - Did we spend...</itunes:subtitle><itunes:summary><![CDATA[Money!! it makes the world go round, we need it, we want it, and when it comes to money for our security program we fight for it, but are we spending it wisely?<br /><br /> - Will it have the impact on our security program we hopped it would?<br /> - Did we spend too much or not enough?<br /> - How much money is enough?<br /> - What the hell should I be spending it on that will make the biggest impact?<br /><br />Is it wiser to invest in your people and the fundamentals or to invest in state-of-the-art laser cats with predictive AI powers? What is the right level of budget for your organization and how will you show improvements to the organizational security posture against the spend on the security program.<br /><br />Vendors love money, and the love of money is the root of all evil.<br /><br /> - How do you know if your vendor is predatory?<br /> - Does the product or service do what they claim?<br /> - Will you need to increase headcount to accommodate the tool or service?<br /> - Could you get a better deal on this tool or service?<br /> - Do I even need this tool in my portfolio or is there an existing tool that I can leverage better?<br /><br />All this and more, on the Security Shit Show Join Chris Roberts, Evan Francen and myself for what should be a a very lively discussion. <br /><br />On YouTube Thursday night at 9pm MTN 10 PM central time <br /><br /> - Ryan Cloutier]]></itunes:summary><itunes:duration>7826</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,information,infosec,money,roberts,ryan,security,shit,show,waste</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bfce314c8c281fe54101fd6bb1e9abc2.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Forty-Four - Am I Crazy?</title><link>https://www.spreaker.com/episode/episode-forty-four-am-i-crazy--44689603</link><description><![CDATA[What the hell is going on?! It feels like the world has lost it's mind. Everywhere I look (out there), it's chaos.<br /><br />Hypocrisy running rampant.<br /><br />Virtue signaling is a "thing", gotta score those popularity points.<br /><br />Cancel culture? This is a thing now, maybe, maybe not?<br /><br />Politicians preach nonsense, openly lying and manipulating.<br /><br />Big societal problems left unsolved, with no (unbiased) solutions.<br /><br />Black kids shot (accidental or not, the result is the same) on the streets.<br /><br />Cities burning, and we're burning them.<br /><br />People hurting (deeply), and we're not helping them.<br /><br />Vaccinate! Wait, maybe not. If you do, maybe you'll die?<br /><br />Accountability, what the hell is that?<br /><br />On, and on.<br /><br />The bath water is dirty. Who cares about the baby.<br />People spew shit out of their mouths that doesn't make any sense. Nobody speaks up. Worse yet, yahoos sell their souls to support bullshit, because it's better to be in the "in" crowd. Who the hell is the "in" crowd anyway?<br /><br />This shit IS NOT computing. <br /><br />Not in this brain anyway. Everyone's lost their minds! Not "everyone" everyone, but everyone out there.<br /><br />WAIT A SECOND. <br />It clicks. Didn't my Dad say something about this once?  <br /><br />Son, if everyone's an asshole, you're the asshole.<br />So, does this mean, if everyone's crazy, I'm the one who's crazy?!<br /><br />Dammit! Now, I have some reflection to do. The journey down the rabbit hole begins...<br /><br />What does this have to do with information security?<br />Simple.<br /><br />Everything. <br /><br />The hypocrites, the virtue signalers, the cancellers, the politicians, the "illegals", the Blacks, the Whites, the Hispanics, the people who live in our cities, the people who live in our suburbs, the people who are hurting, the people who vaccinate, the people who don't vaccinate, the Liberals, the Conservatives, and everyone in between, is ALSO my co-worker, my relative, my partner, my customer, my friend, my employee, and my fellow human being.<br /><br />I may run in my circles, just like you run in yours, but my job is to protect EVERYONE, regardless of who you are, where you come from, what you believe, or what you're struggling with. Knowing that information security isn't about information or security as much as it is about people, makes people my focus. Not just the people I like and agree with.<br /><br />This is deep, but sometimes we have to dig deep to find out who we really are and what we're really doing here.<br /><br />Looking forward to talking this shit out with my AWESOME friends, Ryan Cloutier and Chris Roberts! Catch us this week LIVE at 10pm/2200 CDT on the YouTube. <br /><br />(and yes, I am crazy, but a functional crazy)<br /><br />Sorry maybe, but this is me.<br />-Evan]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/44689603</guid><pubDate>Fri, 07 May 2021 21:31:27 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/44689603/episode44_050721.mp3" length="132405064" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>What the hell is going on?! It feels like the world has lost it's mind. Everywhere I look (out there), it's chaos.

Hypocrisy running rampant.

Virtue signaling is a "thing", gotta score those popularity points.

Cancel culture? This is a thing now,...</itunes:subtitle><itunes:summary><![CDATA[What the hell is going on?! It feels like the world has lost it's mind. Everywhere I look (out there), it's chaos.<br /><br />Hypocrisy running rampant.<br /><br />Virtue signaling is a "thing", gotta score those popularity points.<br /><br />Cancel culture? This is a thing now, maybe, maybe not?<br /><br />Politicians preach nonsense, openly lying and manipulating.<br /><br />Big societal problems left unsolved, with no (unbiased) solutions.<br /><br />Black kids shot (accidental or not, the result is the same) on the streets.<br /><br />Cities burning, and we're burning them.<br /><br />People hurting (deeply), and we're not helping them.<br /><br />Vaccinate! Wait, maybe not. If you do, maybe you'll die?<br /><br />Accountability, what the hell is that?<br /><br />On, and on.<br /><br />The bath water is dirty. Who cares about the baby.<br />People spew shit out of their mouths that doesn't make any sense. Nobody speaks up. Worse yet, yahoos sell their souls to support bullshit, because it's better to be in the "in" crowd. Who the hell is the "in" crowd anyway?<br /><br />This shit IS NOT computing. <br /><br />Not in this brain anyway. Everyone's lost their minds! Not "everyone" everyone, but everyone out there.<br /><br />WAIT A SECOND. <br />It clicks. Didn't my Dad say something about this once?  <br /><br />Son, if everyone's an asshole, you're the asshole.<br />So, does this mean, if everyone's crazy, I'm the one who's crazy?!<br /><br />Dammit! Now, I have some reflection to do. The journey down the rabbit hole begins...<br /><br />What does this have to do with information security?<br />Simple.<br /><br />Everything. <br /><br />The hypocrites, the virtue signalers, the cancellers, the politicians, the "illegals", the Blacks, the Whites, the Hispanics, the people who live in our cities, the people who live in our suburbs, the people who are hurting, the people who vaccinate, the people who don't vaccinate, the Liberals, the Conservatives, and everyone in between, is ALSO my co-worker, my relative, my partner, my customer, my friend, my employee, and my fellow human being.<br /><br />I may run in my circles, just like you run in yours, but my job is to protect EVERYONE, regardless of who you are, where you come from, what you believe, or what you're struggling with. Knowing that information security isn't about information or security as much as it is about people, makes people my focus. Not just the people I like and agree with.<br /><br />This is deep, but sometimes we have to dig deep to find out who we really are and what we're really doing here.<br /><br />Looking forward to talking this shit out with my AWESOME friends, Ryan Cloutier and Chris Roberts! Catch us this week LIVE at 10pm/2200 CDT on the YouTube. <br /><br />(and yes, I am crazy, but a functional crazy)<br /><br />Sorry maybe, but this is me.<br />-Evan]]></itunes:summary><itunes:duration>8276</itunes:duration><itunes:keywords>chris,cloutier,crazy,cybersecurity,evan,francen,information,infosec,roberts,ryan,security,shit,show,social</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/0741985fa0c83beacc2f02ec96d26020.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Forty-Three - Killed My Grandma (updated)...</title><link>https://www.spreaker.com/episode/episode-forty-three-killed-my-grandma-updated--44359939</link><description><![CDATA[NOTE: #ShitShow​ topic NOT my Grandma in Real Life before anyone gets worried!<br /><br />Annually, there are anywhere from 22,000 to 250,000 cases of death in the medical field that really should NOT have happened.<br /><br />Firstly, I’m glad the medical field has as many problems as we do in counting how many people they harmed. InfoSec has no REAL idea as to the implications of our actions beyond “Hey, Look! More data’s out there…” At least in the medical field there’s bodies to count.<br /><br />The question then is how do you categorize death? IF they were sick before they came TO hospital does that count as malpractice, or “accelerated natural causes”? You get the idea, it’s apparently rather subjective…<br /><br />These two fields are coming together on something akin to a collision course of a planet sized scale.<br /><br />Technology In/on/around the body (smart pills, nanotechnology, biotechnology, telemedicine, etc.) are all making serious inroads into “us” the human. Analog humans ARE becoming part OF the digital realm.<br /><br />We need a LOT more forethought before medical malpractice adds another tick box marked “CAUSE OF DEATH… Kernel Panic”<br /><br />So, join Ryan Cloutier, CISSP Evan Francen and the crew tonight on the Shit Show to discuss…]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/44359939</guid><pubDate>Fri, 16 Apr 2021 15:12:38 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/44359939/episode43_041621.mp3" length="139844320" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>NOTE: #ShitShow​ topic NOT my Grandma in Real Life before anyone gets worried!

Annually, there are anywhere from 22,000 to 250,000 cases of death in the medical field that really should NOT have happened.

Firstly, I’m glad the medical field has as...</itunes:subtitle><itunes:summary><![CDATA[NOTE: #ShitShow​ topic NOT my Grandma in Real Life before anyone gets worried!<br /><br />Annually, there are anywhere from 22,000 to 250,000 cases of death in the medical field that really should NOT have happened.<br /><br />Firstly, I’m glad the medical field has as many problems as we do in counting how many people they harmed. InfoSec has no REAL idea as to the implications of our actions beyond “Hey, Look! More data’s out there…” At least in the medical field there’s bodies to count.<br /><br />The question then is how do you categorize death? IF they were sick before they came TO hospital does that count as malpractice, or “accelerated natural causes”? You get the idea, it’s apparently rather subjective…<br /><br />These two fields are coming together on something akin to a collision course of a planet sized scale.<br /><br />Technology In/on/around the body (smart pills, nanotechnology, biotechnology, telemedicine, etc.) are all making serious inroads into “us” the human. Analog humans ARE becoming part OF the digital realm.<br /><br />We need a LOT more forethought before medical malpractice adds another tick box marked “CAUSE OF DEATH… Kernel Panic”<br /><br />So, join Ryan Cloutier, CISSP Evan Francen and the crew tonight on the Shit Show to discuss…]]></itunes:summary><itunes:duration>8741</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,grandma,infosec,roberts,ryan,security,shit,show,sidragon</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/8ded178a532c3b41f06c9ecd03f66ad4.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Forty-One - Security Shit Show Jeopardy!</title><link>https://www.spreaker.com/episode/episode-forty-one-security-shit-show-jeopardy--44100208</link><description><![CDATA[Security Shit Show and Jeopardy<br /><br />Yep, this shit's happening! <br />For the first time, we're going to host the Jeopardy game show, Security Shit Show style. <br /><br />The topics?<br />Come on. You think we plan that far ahead? <br />We don't know yet. <br />It's the Security Shit Show! <br />We'll figure it out when the time is right.<br /><br />Participants?<br />You and us.<br />We'll pull folks from the live stream chat.<br />Then we'll find out how much shit they know about some shit. <br />The champ stays, chumps go back and sit down.<br /><br />Any other questions?<br />Save 'em for the show.<br />If we like your question, we'll answer it. <br />If we don't, we'll probably ignore it.<br /><br />I'm the game show host (Evan), while Chris and Ryan will heckle you. <br />Tune in, this will be a good time! (or it could suck, but that's unlikely).]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/44100208</guid><pubDate>Mon, 29 Mar 2021 16:52:50 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/44100208/episode41_032921.mp3" length="126162650" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Security Shit Show and Jeopardy

Yep, this shit's happening! 
For the first time, we're going to host the Jeopardy game show, Security Shit Show style. 

The topics?
Come on. You think we plan that far ahead? 
We don't know yet. 
It's the Security...</itunes:subtitle><itunes:summary><![CDATA[Security Shit Show and Jeopardy<br /><br />Yep, this shit's happening! <br />For the first time, we're going to host the Jeopardy game show, Security Shit Show style. <br /><br />The topics?<br />Come on. You think we plan that far ahead? <br />We don't know yet. <br />It's the Security Shit Show! <br />We'll figure it out when the time is right.<br /><br />Participants?<br />You and us.<br />We'll pull folks from the live stream chat.<br />Then we'll find out how much shit they know about some shit. <br />The champ stays, chumps go back and sit down.<br /><br />Any other questions?<br />Save 'em for the show.<br />If we like your question, we'll answer it. <br />If we don't, we'll probably ignore it.<br /><br />I'm the game show host (Evan), while Chris and Ryan will heckle you. <br />Tune in, this will be a good time! (or it could suck, but that's unlikely).]]></itunes:summary><itunes:duration>7886</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,information,infosec,jeopardy,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/99307e0b69d27379c9b761bdf3207bba.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Forty - Simplify, then add lightness…</title><link>https://www.spreaker.com/episode/episode-forty-simplify-then-add-lightness--44019004</link><description><![CDATA[The late Colin Chapman, founder of Lotus eschewed the pursuit of horsepower in favor of lightness combined with better handling across his road and race vehicles.<br /><br />That courage to buck the trend resulted in numerous accolades on both sides of the Atlantic.<br /><br />It is that ethos our industry should once again embrace.<br /><br />Simplify:<br />The interfaces, the barriers to entry, the integration, deployment and overall management of the plethora of technology we eagerly buy, deploy, and then complain about.<br /><br />Lightness:<br />Adding power is great if you are going in a straight line, however, leave the power alone, remove the complexity, and unnecessary features (the rule of 90%) and reduce the amount of time you have to fettle over the technology.<br /><br />How well do your tools integrate?<br />How much unnecessary overlap do you have?<br />How much of that tool do you REALLY use?<br />How many hands does it take to run?<br />Do you maintain it?<br />Etc.<br /><br />Start measuring vendors, technologies and PEOPLE by how well they help you simplify, then that should add some lightness across the board.<br /><br />Join Evan Francen, Ryan Cloutier, Rachel Arnold and I as we unpack this tonight on the Shit Show…<br /><br />‘all for now<br />Chris]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/44019004</guid><pubDate>Tue, 23 Mar 2021 17:11:30 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/44019004/episode40_032321.mp3" length="124962883" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The late Colin Chapman, founder of Lotus eschewed the pursuit of horsepower in favor of lightness combined with better handling across his road and race vehicles.

That courage to buck the trend resulted in numerous accolades on both sides of the...</itunes:subtitle><itunes:summary><![CDATA[The late Colin Chapman, founder of Lotus eschewed the pursuit of horsepower in favor of lightness combined with better handling across his road and race vehicles.<br /><br />That courage to buck the trend resulted in numerous accolades on both sides of the Atlantic.<br /><br />It is that ethos our industry should once again embrace.<br /><br />Simplify:<br />The interfaces, the barriers to entry, the integration, deployment and overall management of the plethora of technology we eagerly buy, deploy, and then complain about.<br /><br />Lightness:<br />Adding power is great if you are going in a straight line, however, leave the power alone, remove the complexity, and unnecessary features (the rule of 90%) and reduce the amount of time you have to fettle over the technology.<br /><br />How well do your tools integrate?<br />How much unnecessary overlap do you have?<br />How much of that tool do you REALLY use?<br />How many hands does it take to run?<br />Do you maintain it?<br />Etc.<br /><br />Start measuring vendors, technologies and PEOPLE by how well they help you simplify, then that should add some lightness across the board.<br /><br />Join Evan Francen, Ryan Cloutier, Rachel Arnold and I as we unpack this tonight on the Shit Show…<br /><br />‘all for now<br />Chris]]></itunes:summary><itunes:duration>7811</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,entertainment,evan,francen,roberts,ryan,security,shit,show,simplify</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/0f7322013f60da3d23c42c3e11e2f020.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Thirty-Nine - The Tool Fool - Part 2</title><link>https://www.spreaker.com/episode/episode-thirty-nine-the-tool-fool-part-2--43898878</link><description><![CDATA[THIS IS PART TWO - CONTINUATION FROM EPISODE 38<br /><br />A fool is a person who acts unwisely or imprudently. A Tool Fool is someone who unwisely or imprudently loves tools. They don’t necessarily love the tools they have; they just love tools. The more tools, the better.<br /><br />Don’t be offended. We’re all fools from time to time. When it comes to our information security, we do the best we know how. We don’t intentionally act the fool, but when it comes to our tools, too many of us ARE the fool.<br /><br />Don’t be the Tool Fool!<br /><br />Here’s are 10 things about the Tool Fool:<br />1. Brags about their tools, but they don’t know how to use them.<br />2. Brags about a big budget, but they can’t justify it.<br />3. Thinks “tool first” instead of a “needs first”.<br />4. Thinks tools fix process.<br />5. Thinks tools makes problems easier to solve.<br />6. Likes easy but confuses “easy” with “simple”.<br />7. Has tools they don’t know they have.<br />8. Advocates for tools because fools like company.<br />9. Oblivious to they’re most significant risks.<br />10. Knows how to use some of their tools but won’t to use them well*.<br /><br />The Tool Fool costs the organization more than they know. Tool Fools waste money on tools they don’t need, don’t understand, and/or can’t use. The Tool Fool can convince themselves that their tools will keep them secure when the opposite is true. Worst yet, the Tool Fool’s work has convinced management of the same.<br /><br />The Tool Fool has a false sense of security. The Tool Fool makes security worse.<br /><br />The Tool Fool is the topic for this Thursday’s (3/4) Security Shit Show with Chris, Evan, and Ryan. Be sure to catch the show LIVE on YouTube at 10pm/2200 CST!<br /><br />*This is relevant to a dialog between Senator Wyden (D-OR) and witnesses (Kevin Mandia, Sudhakar Ramakrishna, Brad Smith, and George Kurtz) in the recent open hearing, “Hearing on the Hack of U.S. Networks by a Foreign Adversary” before the U.S. Senate Intelligence Committee (2/23). This particular exchange happens at 1:22:08 in the recording here: <a href="https://www.intelligence.senate.gov/hearings/open-hearing-hearing-hack-us-networks-foreign-adversary" rel="noopener">https://www.intelligence.senate.gov/hearings/open-hearing-hearing-hack-us-networks-foreign-adversary</a>, and has been transcribed here: <a href="https://evanfrancen.com/unsecurity-episode-121-show-notes/" rel="noopener">https://evanfrancen.com/unsecurity-episode-121-show-notes/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/43898878</guid><pubDate>Thu, 18 Mar 2021 17:15:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43898878/episode39_031821.mp3" length="133923928" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>THIS IS PART TWO - CONTINUATION FROM EPISODE 38

A fool is a person who acts unwisely or imprudently. A Tool Fool is someone who unwisely or imprudently loves tools. They don’t necessarily love the tools they have; they just love tools. The more...</itunes:subtitle><itunes:summary><![CDATA[THIS IS PART TWO - CONTINUATION FROM EPISODE 38<br /><br />A fool is a person who acts unwisely or imprudently. A Tool Fool is someone who unwisely or imprudently loves tools. They don’t necessarily love the tools they have; they just love tools. The more tools, the better.<br /><br />Don’t be offended. We’re all fools from time to time. When it comes to our information security, we do the best we know how. We don’t intentionally act the fool, but when it comes to our tools, too many of us ARE the fool.<br /><br />Don’t be the Tool Fool!<br /><br />Here’s are 10 things about the Tool Fool:<br />1. Brags about their tools, but they don’t know how to use them.<br />2. Brags about a big budget, but they can’t justify it.<br />3. Thinks “tool first” instead of a “needs first”.<br />4. Thinks tools fix process.<br />5. Thinks tools makes problems easier to solve.<br />6. Likes easy but confuses “easy” with “simple”.<br />7. Has tools they don’t know they have.<br />8. Advocates for tools because fools like company.<br />9. Oblivious to they’re most significant risks.<br />10. Knows how to use some of their tools but won’t to use them well*.<br /><br />The Tool Fool costs the organization more than they know. Tool Fools waste money on tools they don’t need, don’t understand, and/or can’t use. The Tool Fool can convince themselves that their tools will keep them secure when the opposite is true. Worst yet, the Tool Fool’s work has convinced management of the same.<br /><br />The Tool Fool has a false sense of security. The Tool Fool makes security worse.<br /><br />The Tool Fool is the topic for this Thursday’s (3/4) Security Shit Show with Chris, Evan, and Ryan. Be sure to catch the show LIVE on YouTube at 10pm/2200 CST!<br /><br />*This is relevant to a dialog between Senator Wyden (D-OR) and witnesses (Kevin Mandia, Sudhakar Ramakrishna, Brad Smith, and George Kurtz) in the recent open hearing, “Hearing on the Hack of U.S. Networks by a Foreign Adversary” before the U.S. Senate Intelligence Committee (2/23). This particular exchange happens at 1:22:08 in the recording here: <a href="https://www.intelligence.senate.gov/hearings/open-hearing-hearing-hack-us-networks-foreign-adversary" rel="noopener">https://www.intelligence.senate.gov/hearings/open-hearing-hearing-hack-us-networks-foreign-adversary</a>, and has been transcribed here: <a href="https://evanfrancen.com/unsecurity-episode-121-show-notes/" rel="noopener">https://evanfrancen.com/unsecurity-episode-121-show-notes/</a>]]></itunes:summary><itunes:duration>8371</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,foolish,francen,information,roberts,ryan,security,shit,show,tools</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6db747e4e699a2cd8ff70e48568a7630.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Thirty-Eight - The Tool Fool</title><link>https://www.spreaker.com/episode/episode-thirty-eight-the-tool-fool--43898213</link><description><![CDATA[A fool is a person who acts unwisely or imprudently. A Tool Fool is someone who unwisely or imprudently loves tools. They don’t necessarily love the tools they have; they just love tools. The more tools, the better.<br /><br />Don’t be offended. We’re all fools from time to time. When it comes to our information security, we do the best we know how. We don’t intentionally act the fool, but when it comes to our tools, too many of us ARE the fool.<br /><br />Don’t be the Tool Fool!<br /><br />Here’s are 10 things about the Tool Fool:<br />1. Brags about their tools, but they don’t know how to use them.<br />2. Brags about a big budget, but they can’t justify it.<br />3. Thinks “tool first” instead of a “needs first”.<br />4. Thinks tools fix process.<br />5. Thinks tools makes problems easier to solve.<br />6. Likes easy but confuses “easy” with “simple”.<br />7. Has tools they don’t know they have.<br />8. Advocates for tools because fools like company.<br />9. Oblivious to they’re most significant risks.<br />10. Knows how to use some of their tools but won’t to use them well*.<br /><br />The Tool Fool costs the organization more than they know. Tool Fools waste money on tools they don’t need, don’t understand, and/or can’t use. The Tool Fool can convince themselves that their tools will keep them secure when the opposite is true. Worst yet, the Tool Fool’s work has convinced management of the same.<br /><br />The Tool Fool has a false sense of security. The Tool Fool makes security worse.<br /><br />The Tool Fool is the topic for this Thursday’s (3/4) Security Shit Show with Chris, Evan, and Ryan. Be sure to catch the show LIVE on YouTube at 10pm/2200 CST!<br /><br />*This is relevant to a dialog between Senator Wyden (D-OR) and witnesses (Kevin Mandia, Sudhakar Ramakrishna, Brad Smith, and George Kurtz) in the recent open hearing, “Hearing on the Hack of U.S. Networks by a Foreign Adversary” before the U.S. Senate Intelligence Committee (2/23). This particular exchange happens at 1:22:08 in the recording here: <a href="https://www.intelligence.senate.gov/hearings/open-hearing-hearing-hack-us-networks-foreign-adversary" rel="noopener">https://www.intelligence.senate.gov/hearings/open-hearing-hearing-hack-us-networks-foreign-adversary</a>, and has been transcribed here: <a href="https://evanfrancen.com/unsecurity-episode-121-show-notes/" rel="noopener">https://evanfrancen.com/unsecurity-episode-121-show-notes/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/43898213</guid><pubDate>Mon, 15 Mar 2021 15:33:20 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43898213/episode38_031521.mp3" length="59524268" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>A fool is a person who acts unwisely or imprudently. A Tool Fool is someone who unwisely or imprudently loves tools. They don’t necessarily love the tools they have; they just love tools. The more tools, the better.

Don’t be offended. We’re all fools...</itunes:subtitle><itunes:summary><![CDATA[A fool is a person who acts unwisely or imprudently. A Tool Fool is someone who unwisely or imprudently loves tools. They don’t necessarily love the tools they have; they just love tools. The more tools, the better.<br /><br />Don’t be offended. We’re all fools from time to time. When it comes to our information security, we do the best we know how. We don’t intentionally act the fool, but when it comes to our tools, too many of us ARE the fool.<br /><br />Don’t be the Tool Fool!<br /><br />Here’s are 10 things about the Tool Fool:<br />1. Brags about their tools, but they don’t know how to use them.<br />2. Brags about a big budget, but they can’t justify it.<br />3. Thinks “tool first” instead of a “needs first”.<br />4. Thinks tools fix process.<br />5. Thinks tools makes problems easier to solve.<br />6. Likes easy but confuses “easy” with “simple”.<br />7. Has tools they don’t know they have.<br />8. Advocates for tools because fools like company.<br />9. Oblivious to they’re most significant risks.<br />10. Knows how to use some of their tools but won’t to use them well*.<br /><br />The Tool Fool costs the organization more than they know. Tool Fools waste money on tools they don’t need, don’t understand, and/or can’t use. The Tool Fool can convince themselves that their tools will keep them secure when the opposite is true. Worst yet, the Tool Fool’s work has convinced management of the same.<br /><br />The Tool Fool has a false sense of security. The Tool Fool makes security worse.<br /><br />The Tool Fool is the topic for this Thursday’s (3/4) Security Shit Show with Chris, Evan, and Ryan. Be sure to catch the show LIVE on YouTube at 10pm/2200 CST!<br /><br />*This is relevant to a dialog between Senator Wyden (D-OR) and witnesses (Kevin Mandia, Sudhakar Ramakrishna, Brad Smith, and George Kurtz) in the recent open hearing, “Hearing on the Hack of U.S. Networks by a Foreign Adversary” before the U.S. Senate Intelligence Committee (2/23). This particular exchange happens at 1:22:08 in the recording here: <a href="https://www.intelligence.senate.gov/hearings/open-hearing-hearing-hack-us-networks-foreign-adversary" rel="noopener">https://www.intelligence.senate.gov/hearings/open-hearing-hearing-hack-us-networks-foreign-adversary</a>, and has been transcribed here: <a href="https://evanfrancen.com/unsecurity-episode-121-show-notes/" rel="noopener">https://evanfrancen.com/unsecurity-episode-121-show-notes/</a>]]></itunes:summary><itunes:duration>3721</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,foolish,francen,information,roberts,ryan,security,shit,show,tools</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6db747e4e699a2cd8ff70e48568a7630.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Thirty-Seven - It's Time...</title><link>https://www.spreaker.com/episode/episode-thirty-seven-it-s-time--43710280</link><description><![CDATA[That resource we want more of, or less of, the one we want to slow down, speed up, thank, curse, monitor, measure, ignore and obey. All often within the span of the same day. <br /><br />The very resource we so often run our lives by, yet waste at every turn. It too, like our digital world is a more abstract concept than the tactile analog world we live in. It too can be captured and tamed for fleeting moments in devices, yet like it’s digital cousin we think we control it, but we are nothing more than custodians of the memories it leaves behind.<br /><br />We are not good with time; we’ve had 6,000 years or so to get used to the idea of its passing and the consequences.  We used to track it by the moon, nowadays we are ruled by atoms that are accurate to a millisecond every decade.<br />So, why should we care?<br /><br /><br />We waste so much of it.<br />We allow others to dictate our use of it<br />Our very existence is tyrannized by it<br /><br /> <br />We have watched the convergence of our digital world and that of time, and realized the very objects meant to save us are doing nothing more than sucking more and more time from us.<br /><br />Like our digital world we need to be better custodians of time (not that it really cares as it marches on no matter what we do) but for our own sanity, stand up, be accountable to time itself.<br /><br />Join us for a conversation around time….]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/43710280</guid><pubDate>Tue, 02 Mar 2021 22:44:55 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43710280/episode37_030221.mp3" length="127764046" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>That resource we want more of, or less of, the one we want to slow down, speed up, thank, curse, monitor, measure, ignore and obey. All often within the span of the same day. 

The very resource we so often run our lives by, yet waste at every turn....</itunes:subtitle><itunes:summary><![CDATA[That resource we want more of, or less of, the one we want to slow down, speed up, thank, curse, monitor, measure, ignore and obey. All often within the span of the same day. <br /><br />The very resource we so often run our lives by, yet waste at every turn. It too, like our digital world is a more abstract concept than the tactile analog world we live in. It too can be captured and tamed for fleeting moments in devices, yet like it’s digital cousin we think we control it, but we are nothing more than custodians of the memories it leaves behind.<br /><br />We are not good with time; we’ve had 6,000 years or so to get used to the idea of its passing and the consequences.  We used to track it by the moon, nowadays we are ruled by atoms that are accurate to a millisecond every decade.<br />So, why should we care?<br /><br /><br />We waste so much of it.<br />We allow others to dictate our use of it<br />Our very existence is tyrannized by it<br /><br /> <br />We have watched the convergence of our digital world and that of time, and realized the very objects meant to save us are doing nothing more than sucking more and more time from us.<br /><br />Like our digital world we need to be better custodians of time (not that it really cares as it marches on no matter what we do) but for our own sanity, stand up, be accountable to time itself.<br /><br />Join us for a conversation around time….]]></itunes:summary><itunes:duration>7986</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,information,infosec,roberts,ryan,security,shit,show,time</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9f4456f83b538f1475e6edfc173356ea.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Thirty-Six - Timmy is in the well... Nope, that's sodium hydroxide!</title><link>https://www.spreaker.com/episode/episode-thirty-six-timmy-is-in-the-well-nope-that-s-sodium-hydroxide--43614997</link><description><![CDATA[This week we saw an attack against a city water system, in an attempt to poison the drinking water.<br /><br />Many of us have been warning about this for years.<br /><br />How did this happen? <br />It must have been the work of sophisticated nation state attackers, it has to be hard to hack a water treatment plant because you know, people could die if that happened. The people in charge must take extra precautions, and have really good security practices in place to keep our drinking water safe. They must have been unable to prevent or avoid this attack.<br /><br />These are all things that we hope would be true, unfortunately the reality of what actually happened is far more disturbing.   <br /><br />(Channeling my inner security Yoda) Sophisticated this attack was not, difficult to pull off was it not,  prevented could have been, security basics lacking they were, practice good they did not.<br /><br />What happened was a multitude of failures in requiring and implementing the most basic and foundational of security controls. <br /><br />We have reached a point in our technology journey as a society, that we need to pause for one moment and take stock of the giant mess we have created. <br /><br />We need to figure out what minimum safety standards are needed for critical infrastructure. <br /><br />We need to ask ourselves should the things that can kill us be connected to the internet in the first place?<br /><br />Knowing that the security posture of the affected water treatment plant, borders on gross and willful negligence, what should the legal and criminal consequences be for those who made these shit decisions in the first place.<br /><br />It's 2021 and computers can kill you, so let's act accordingly.  <br /><br />We will be discussing this and more tonight on the Security Shit Show, join us for what is guarantied to be a lively discussion, and you never know Chris may do some show and tell as well.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/43614997</guid><pubDate>Wed, 24 Feb 2021 16:45:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43614997/episode36_021721.mp3" length="95123941" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>This week we saw an attack against a city water system, in an attempt to poison the drinking water.

Many of us have been warning about this for years.

How did this happen? 
It must have been the work of sophisticated nation state attackers, it has...</itunes:subtitle><itunes:summary><![CDATA[This week we saw an attack against a city water system, in an attempt to poison the drinking water.<br /><br />Many of us have been warning about this for years.<br /><br />How did this happen? <br />It must have been the work of sophisticated nation state attackers, it has to be hard to hack a water treatment plant because you know, people could die if that happened. The people in charge must take extra precautions, and have really good security practices in place to keep our drinking water safe. They must have been unable to prevent or avoid this attack.<br /><br />These are all things that we hope would be true, unfortunately the reality of what actually happened is far more disturbing.   <br /><br />(Channeling my inner security Yoda) Sophisticated this attack was not, difficult to pull off was it not,  prevented could have been, security basics lacking they were, practice good they did not.<br /><br />What happened was a multitude of failures in requiring and implementing the most basic and foundational of security controls. <br /><br />We have reached a point in our technology journey as a society, that we need to pause for one moment and take stock of the giant mess we have created. <br /><br />We need to figure out what minimum safety standards are needed for critical infrastructure. <br /><br />We need to ask ourselves should the things that can kill us be connected to the internet in the first place?<br /><br />Knowing that the security posture of the affected water treatment plant, borders on gross and willful negligence, what should the legal and criminal consequences be for those who made these shit decisions in the first place.<br /><br />It's 2021 and computers can kill you, so let's act accordingly.  <br /><br />We will be discussing this and more tonight on the Security Shit Show, join us for what is guarantied to be a lively discussion, and you never know Chris may do some show and tell as well.]]></itunes:summary><itunes:duration>5946</itunes:duration><itunes:keywords>chris,cloutier,critical,cybersecurity,evan,francen,information,infosec,infrastructure,oldsmar,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/1b5ba5b4f9450f650a4ab1c2658d7cb5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Thirty-Five - The root of all information security industry problems</title><link>https://www.spreaker.com/episode/episode-thirty-five-the-root-of-all-information-security-industry-problems--43479185</link><description><![CDATA[Here's a question for you:<br />What is at the root of all information security industry problems?<br /><br />Oh shit! Talk about an ambiguous question. Yes, but who said ambiguous questions are bad?<br /><br />Alright, let's break this down then.<br /><br />First, the question assumes there are "problems". Are there? We think so, but...<br /><br /> - ~942,000 people in the U.S. are gainfully employed in this industry, and most of us are getting paid pretty well. Good paying jobs doesn't seem like a problem to me.<br /> - Worldwide, the cybersecurity market is valued at $173B. Seems the people selling shit are doing alright, no problem here.<br /> - Global "cybercrime" losses for 2020 were estimated to be $945B. The crooks DEFINITELY aren't experiencing any problems either!<br /><br />So, where are the problems then?<br /><br />Simple, look for the people who suffer, the victims. <br /><br />They're the ones who get the short end of the stick. They feel the brunt (or symptoms) of the problems. They lose money, they lose businesses, they lose income, they lose peace of mind, they lose time, they lose productivity, they lose their privacy, they lose their innocence (especially kids), and they lose life.<br /><br />So, yeah. There are problems! <br /><br />One group clearly takes advantage of the other. We'll call them "Profiteers" and "Victims". There's one more group. There's a group of us who are trying to protect Victims from the Profiteers. We stand in the void.<br /><br /> - Profiteers: Cybersecurity practitioners who don't serve the (potential) victims, companies hocking products that don't serve the (potential) victims, and the crooks who steal outright.<br /> - Us: Practitioners who stand in between, serving (potential) victims.<br /> - Victims: Governments, companies, non-profits, schools, everyday people (grandparents, parents, kids, etc.) <br /><br />OK, so we've got problems. The masses become victims and feel the result(s) of the problems, the symptoms. Oh shit! The rabbit hole goes deeper.<br /><br />We'll stop here, before things get too out of hand. <br /><br />We need to save some shit for the Shit Show. Chris, Ryan, and I will take it from here. Maybe we'll get far enough down the rabbit hole, and deep enough into the shit to find some semblance of the "root of all information security industry problems".<br /><br />Regardless of how far we make it, it should be entertaining!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/43479185</guid><pubDate>Mon, 15 Feb 2021 20:13:23 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43479185/episode35_021521.mp3" length="138243954" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Here's a question for you:
What is at the root of all information security industry problems?

Oh shit! Talk about an ambiguous question. Yes, but who said ambiguous questions are bad?

Alright, let's break this down then.

First, the question assumes...</itunes:subtitle><itunes:summary><![CDATA[Here's a question for you:<br />What is at the root of all information security industry problems?<br /><br />Oh shit! Talk about an ambiguous question. Yes, but who said ambiguous questions are bad?<br /><br />Alright, let's break this down then.<br /><br />First, the question assumes there are "problems". Are there? We think so, but...<br /><br /> - ~942,000 people in the U.S. are gainfully employed in this industry, and most of us are getting paid pretty well. Good paying jobs doesn't seem like a problem to me.<br /> - Worldwide, the cybersecurity market is valued at $173B. Seems the people selling shit are doing alright, no problem here.<br /> - Global "cybercrime" losses for 2020 were estimated to be $945B. The crooks DEFINITELY aren't experiencing any problems either!<br /><br />So, where are the problems then?<br /><br />Simple, look for the people who suffer, the victims. <br /><br />They're the ones who get the short end of the stick. They feel the brunt (or symptoms) of the problems. They lose money, they lose businesses, they lose income, they lose peace of mind, they lose time, they lose productivity, they lose their privacy, they lose their innocence (especially kids), and they lose life.<br /><br />So, yeah. There are problems! <br /><br />One group clearly takes advantage of the other. We'll call them "Profiteers" and "Victims". There's one more group. There's a group of us who are trying to protect Victims from the Profiteers. We stand in the void.<br /><br /> - Profiteers: Cybersecurity practitioners who don't serve the (potential) victims, companies hocking products that don't serve the (potential) victims, and the crooks who steal outright.<br /> - Us: Practitioners who stand in between, serving (potential) victims.<br /> - Victims: Governments, companies, non-profits, schools, everyday people (grandparents, parents, kids, etc.) <br /><br />OK, so we've got problems. The masses become victims and feel the result(s) of the problems, the symptoms. Oh shit! The rabbit hole goes deeper.<br /><br />We'll stop here, before things get too out of hand. <br /><br />We need to save some shit for the Shit Show. Chris, Ryan, and I will take it from here. Maybe we'll get far enough down the rabbit hole, and deep enough into the shit to find some semblance of the "root of all information security industry problems".<br /><br />Regardless of how far we make it, it should be entertaining!]]></itunes:summary><itunes:duration>8641</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,information,infosec,people,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/1200ed8a540e63a55c1400e277c0348d.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Thirty-Four - From the Sublime to the Ridiculous</title><link>https://www.spreaker.com/episode/episode-thirty-four-from-the-sublime-to-the-ridiculous--43272904</link><description><![CDATA[There’s been a lot of hand wringing these last few weeks as ALL sorts of folks have woken up to, realized, or started to question their online presence. Their digital world has crumbled around them as they’ve realized not only don’t they own anything they commit to the keyboard, but whatever they do is, controlled by someone else.<br /><br />Congratulations you are no longer the master (or mistress) of your own destiny, welcome to the digital world, please get in a queue like a good subservient population and tow the line or else.<br /><br />No?<br /><br />Then please leave. Leave the digital world behind, after all WE still have all that you were while you WERE here…<br /><br />But, you can’t can you?<br /><br />Someone somewhere HAS a digital record of you, it’s out of your control, welcome back peasant.<br /><br />What IF you could be YOU on a digital medium? How DO you secure AND use it, yet ensure that nobody keeps nicking it? (Stealing for the colonials here)<br /><br />THIS is the topic of this evenings Security Shit show with Rachel, Ryan, Evan and I<br /><br />IS it possible?<br /><br />Does it mandate lead lined boxes?<br /><br />Will there be volcano’s?<br /><br />IS Cerberus with us?<br /><br />Will hiding it under the mattress work?<br /><br />OR are we screwed and should simply give it all up as a bad job?]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/43272904</guid><pubDate>Wed, 03 Feb 2021 20:45:26 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43272904/episode34_020321.mp3" length="114403980" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>There’s been a lot of hand wringing these last few weeks as ALL sorts of folks have woken up to, realized, or started to question their online presence. Their digital world has crumbled around them as they’ve realized not only don’t they own anything...</itunes:subtitle><itunes:summary><![CDATA[There’s been a lot of hand wringing these last few weeks as ALL sorts of folks have woken up to, realized, or started to question their online presence. Their digital world has crumbled around them as they’ve realized not only don’t they own anything they commit to the keyboard, but whatever they do is, controlled by someone else.<br /><br />Congratulations you are no longer the master (or mistress) of your own destiny, welcome to the digital world, please get in a queue like a good subservient population and tow the line or else.<br /><br />No?<br /><br />Then please leave. Leave the digital world behind, after all WE still have all that you were while you WERE here…<br /><br />But, you can’t can you?<br /><br />Someone somewhere HAS a digital record of you, it’s out of your control, welcome back peasant.<br /><br />What IF you could be YOU on a digital medium? How DO you secure AND use it, yet ensure that nobody keeps nicking it? (Stealing for the colonials here)<br /><br />THIS is the topic of this evenings Security Shit show with Rachel, Ryan, Evan and I<br /><br />IS it possible?<br /><br />Does it mandate lead lined boxes?<br /><br />Will there be volcano’s?<br /><br />IS Cerberus with us?<br /><br />Will hiding it under the mattress work?<br /><br />OR are we screwed and should simply give it all up as a bad job?]]></itunes:summary><itunes:duration>7151</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,industry,information,infosec,privacy,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/1ec7ebf36305a3cd7e98b1c6780e34a7.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Thirty-Three - End Cyber Risk. Selling the Pipe Dream.</title><link>https://www.spreaker.com/episode/episode-thirty-three-end-cyber-risk-selling-the-pipe-dream--43165861</link><description><![CDATA[Recently a well known cybersecurity company made a very bold claim that they can end cyber risk!<br />This begs the question can you end cyber risk? what would it take to end all cyber risk? Is it even possible to end cyber risk? what if you put the phone in the chipper shredder, throw the laptop into a crucible and melt it to bits, will that help? How deep does the digital rabbit hole go? is there any escape from cyber risk?  <br /><br />Can you go off grid or will the grid follow you? if you do go off grid does that impact how much you care about your digital life? does being off grid affect your cyber risk exposure?<br /><br />Or is it all just a pipe dream? are vendors selling pipe dreams and not solutions? or are they just smoking some funny stuff that makes them think this behavior is ok.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/43165861</guid><pubDate>Thu, 28 Jan 2021 15:07:54 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43165861/episode33_012821.mp3" length="140324137" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Recently a well known cybersecurity company made a very bold claim that they can end cyber risk!
This begs the question can you end cyber risk? what would it take to end all cyber risk? Is it even possible to end cyber risk? what if you put the phone...</itunes:subtitle><itunes:summary><![CDATA[Recently a well known cybersecurity company made a very bold claim that they can end cyber risk!<br />This begs the question can you end cyber risk? what would it take to end all cyber risk? Is it even possible to end cyber risk? what if you put the phone in the chipper shredder, throw the laptop into a crucible and melt it to bits, will that help? How deep does the digital rabbit hole go? is there any escape from cyber risk?  <br /><br />Can you go off grid or will the grid follow you? if you do go off grid does that impact how much you care about your digital life? does being off grid affect your cyber risk exposure?<br /><br />Or is it all just a pipe dream? are vendors selling pipe dreams and not solutions? or are they just smoking some funny stuff that makes them think this behavior is ok.]]></itunes:summary><itunes:duration>8771</itunes:duration><itunes:keywords>advertising,chris,cloutier,dream,evan,false,francen,information,infosec,marketing,pipe,risk,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c084d6180484164681fe0b8b0d936afc.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Thirty-Two - Where's the Plunger?!</title><link>https://www.spreaker.com/episode/episode-thirty-two-where-s-the-plunger--43051961</link><description><![CDATA[We're back after three weeks off! <br />Seems the world didn't right itself while we were away. <br />BUMMER or BUGGER (for Chris)!<br /><br />2020's gone. YAY! <br />2021's here. YAY (maybe)?!<br /><br />The calendar flipped, but the script didn't. 2020 was a f*cked up year for sure. Like seriously f*cked up! There was no shortage of breaches, sh*tty security stuff, panic, fear, loathing, division, etc., etc., etc.<br /><br />The new year brings hope, right? Hope for a fresh start. When the calendar flipped to 2021, there was a collective sigh of relief. <br /><br />Yes, 2020 is behind us! There's hope! We can see light at the end of the tunnel! Hope is GOOD!<br /><br />Then reality hits (again).<br /><br />The sh*t from 2020 didn't go away. It's like 2020s sh*t is still in the toilet bowl and the f*cking toilet is clogged. Will 2021 be a year we find the plunger or a year we eat a sh*tload of bad Mexican food while we ignore the clog? We don't want 2021s sh*t to pile on top of 2020s sh*t, do we?!<br /><br />We've stumbled out of the gate (in 2021). If we don't do something soon, 2021s sh*t is gonna be bad.  We can't let 2021 become 2020 with more sh*t. The smell is terrible and it's unhealth as... Well, sh*t!<br /><br />Can we flip the script? Sooner or later, we're gonna have to! Hell, isn't flipping the script something that motivates us in this industry? <br /><br />This will be a good episode for sure! We're HAPPY to be back!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/43051961</guid><pubDate>Thu, 21 Jan 2021 22:27:52 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43051961/episode32_012121.mp3" length="119604228" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>We're back after three weeks off! 
Seems the world didn't right itself while we were away. 
BUMMER or BUGGER (for Chris)!

2020's gone. YAY! 
2021's here. YAY (maybe)?!

The calendar flipped, but the script didn't. 2020 was a f*cked up year for sure....</itunes:subtitle><itunes:summary><![CDATA[We're back after three weeks off! <br />Seems the world didn't right itself while we were away. <br />BUMMER or BUGGER (for Chris)!<br /><br />2020's gone. YAY! <br />2021's here. YAY (maybe)?!<br /><br />The calendar flipped, but the script didn't. 2020 was a f*cked up year for sure. Like seriously f*cked up! There was no shortage of breaches, sh*tty security stuff, panic, fear, loathing, division, etc., etc., etc.<br /><br />The new year brings hope, right? Hope for a fresh start. When the calendar flipped to 2021, there was a collective sigh of relief. <br /><br />Yes, 2020 is behind us! There's hope! We can see light at the end of the tunnel! Hope is GOOD!<br /><br />Then reality hits (again).<br /><br />The sh*t from 2020 didn't go away. It's like 2020s sh*t is still in the toilet bowl and the f*cking toilet is clogged. Will 2021 be a year we find the plunger or a year we eat a sh*tload of bad Mexican food while we ignore the clog? We don't want 2021s sh*t to pile on top of 2020s sh*t, do we?!<br /><br />We've stumbled out of the gate (in 2021). If we don't do something soon, 2021s sh*t is gonna be bad.  We can't let 2021 become 2020 with more sh*t. The smell is terrible and it's unhealth as... Well, sh*t!<br /><br />Can we flip the script? Sooner or later, we're gonna have to! Hell, isn't flipping the script something that motivates us in this industry? <br /><br />This will be a good episode for sure! We're HAPPY to be back!]]></itunes:summary><itunes:duration>7476</itunes:duration><itunes:keywords>2020,2021,chris,cloutier,covid,cybersecurity,evan,francen,infosec,podcast,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/be02bf609cb656af87085e129b556461.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Thirty-One - IF</title><link>https://www.spreaker.com/episode/episode-thirty-one-if--42593692</link><description><![CDATA[Written at the turn of penultimate century, and published around 1910, Kipling’s “If” is a force that speaks as wisely today as at the time of writing.<br /><br />Breaking it down to a few simple guides, we can learn the following:<br /><br />- Keep a clear head while others around are losing theirs.<br />- Be mindful of our thoughts AND actions.<br />- Never ever give up.<br />- Reach FOR the stars, but keep your feet firmly planted.<br /><br />Now, given the last few weeks of fun and games in our industry have put the icing on an already challenging year, the words above should probably be printed and stuck TO our monitors.<br /><br />Here’s how I see those guides:<br />- WE need us to show people that we can handle a crisis; THEIR digital lives are in our hands.<br /><br />- WE need to ALL cooperate, collaborate AND work through our issues as one.<br /><br />- The world sucks reach out and do a buddy check, you never know how necessary it is sometimes.<br /><br />- We DO hold the keys to the digital realm; NEVER forget that without everyone else, we would NEVER succeed.<br /><br />We’re going to dig into this a little more Thursday night on the Security Shit Show, join Rachel Arnold, Evan Francen, Ryan Cloutier, CISSP, and I at 2100 mountain on YouTube.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/42593692</guid><pubDate>Mon, 21 Dec 2020 11:17:48 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/42593692/episode31_122120.mp3" length="132804215" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Written at the turn of penultimate century, and published around 1910, Kipling’s “If” is a force that speaks as wisely today as at the time of writing.

Breaking it down to a few simple guides, we can learn the following:

- Keep a clear head while...</itunes:subtitle><itunes:summary><![CDATA[Written at the turn of penultimate century, and published around 1910, Kipling’s “If” is a force that speaks as wisely today as at the time of writing.<br /><br />Breaking it down to a few simple guides, we can learn the following:<br /><br />- Keep a clear head while others around are losing theirs.<br />- Be mindful of our thoughts AND actions.<br />- Never ever give up.<br />- Reach FOR the stars, but keep your feet firmly planted.<br /><br />Now, given the last few weeks of fun and games in our industry have put the icing on an already challenging year, the words above should probably be printed and stuck TO our monitors.<br /><br />Here’s how I see those guides:<br />- WE need us to show people that we can handle a crisis; THEIR digital lives are in our hands.<br /><br />- WE need to ALL cooperate, collaborate AND work through our issues as one.<br /><br />- The world sucks reach out and do a buddy check, you never know how necessary it is sometimes.<br /><br />- We DO hold the keys to the digital realm; NEVER forget that without everyone else, we would NEVER succeed.<br /><br />We’re going to dig into this a little more Thursday night on the Security Shit Show, join Rachel Arnold, Evan Francen, Ryan Cloutier, CISSP, and I at 2100 mountain on YouTube.]]></itunes:summary><itunes:duration>8301</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,information,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/7e986021db7cc688518e19183c8fce87.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Thirty - Shit, It's One of Us!</title><link>https://www.spreaker.com/episode/episode-thirty-shit-it-s-one-of-us--42508613</link><description><![CDATA[Another day, another breach in the news, what's new? well..., this time the victim is one of the worlds leading information/cybersecurity providers.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/42508613</guid><pubDate>Tue, 15 Dec 2020 23:29:40 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/42508613/episode30_121520.mp3" length="117844202" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Another day, another breach in the news, what's new? well..., this time the victim is one of the worlds leading information/cybersecurity providers.</itunes:subtitle><itunes:summary><![CDATA[Another day, another breach in the news, what's new? well..., this time the victim is one of the worlds leading information/cybersecurity providers.]]></itunes:summary><itunes:duration>7366</itunes:duration><itunes:keywords>breach,chris,cloutier,cybersecurity,data,evan,fireeye,francen,information,roberts,ryan,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5ddc39e74c38acf710667056a2b3784e.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Twenty-Nine - 'Tis the Season to be Ripped Off</title><link>https://www.spreaker.com/episode/episode-twenty-nine-tis-the-season-to-be-ripped-off--42399828</link><description><![CDATA[The tech, the calls, and clicks of folly<br />Fa-la-la-la-la, la-la-la-la<br />‘Tis the season to rob Holly<br />Fa-la-la-la-la, la-la-la-la<br />Don, he shops online in peril <br />Fa-la-la, la-la-la, la-la-la<br />Scammers have him over a barrel<br />Fa-la-la-la-la, la-la-la-la<br /><br />This is the audio recording of the Security Shit Show, which runs live every Thursday night at 10om CST on YouTube (<a href="https://www.youtube.com/c/SecurityShitShow)" rel="noopener">https://www.youtube.com/c/SecurityShitShow)</a>.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/42399828</guid><pubDate>Wed, 09 Dec 2020 17:49:52 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/42399828/episode29_120920.mp3" length="115044294" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The tech, the calls, and clicks of folly
Fa-la-la-la-la, la-la-la-la
‘Tis the season to rob Holly
Fa-la-la-la-la, la-la-la-la
Don, he shops online in peril 
Fa-la-la, la-la-la, la-la-la
Scammers have him over a barrel
Fa-la-la-la-la, la-la-la-la

This...</itunes:subtitle><itunes:summary><![CDATA[The tech, the calls, and clicks of folly<br />Fa-la-la-la-la, la-la-la-la<br />‘Tis the season to rob Holly<br />Fa-la-la-la-la, la-la-la-la<br />Don, he shops online in peril <br />Fa-la-la, la-la-la, la-la-la<br />Scammers have him over a barrel<br />Fa-la-la-la-la, la-la-la-la<br /><br />This is the audio recording of the Security Shit Show, which runs live every Thursday night at 10om CST on YouTube (<a href="https://www.youtube.com/c/SecurityShitShow)" rel="noopener">https://www.youtube.com/c/SecurityShitShow)</a>.]]></itunes:summary><itunes:duration>7191</itunes:duration><itunes:keywords>chris,cloutier,cybersecurity,evan,francen,information,infosec,roberts,ryan,scams,security,shot,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/daa4f9987aeadeb8c1a91b9158d617d0.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Twenty-Eight - Compliance (and the Paqui One Chip Challenge)</title><link>https://www.spreaker.com/episode/episode-twenty-eight-compliance-and-the-paqui-one-chip-challenge--42143259</link><description><![CDATA[HOT CHIPS!!!<br /><br />We're gonna take the Paqui Chip Challenge this week. Chris will NOT be cheating and Evan has his chip in hand. Ryan? We think he ordered his, but we forgot to check.<br /><br />Whatever. It's the SHIT SHOW!<br /><br />Here's what we're gonna talk about:<br />Compliance… <br /><br />We’ve taken something that should be simple….<br /><br />AND<br /><br />Turned it into something so SO damn convoluted that once again we’ve have to create an entire branch of our industry to JUST decipher it<br /><br />We need to simplify this, so HOW do we do it?]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/42143259</guid><pubDate>Tue, 24 Nov 2020 16:13:57 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/42143259/episode28_112420.mp3" length="72964163" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>HOT CHIPS!!!

We're gonna take the Paqui Chip Challenge this week. Chris will NOT be cheating and Evan has his chip in hand. Ryan? We think he ordered his, but we forgot to check.

Whatever. It's the SHIT SHOW!

Here's what we're gonna talk about:...</itunes:subtitle><itunes:summary><![CDATA[HOT CHIPS!!!<br /><br />We're gonna take the Paqui Chip Challenge this week. Chris will NOT be cheating and Evan has his chip in hand. Ryan? We think he ordered his, but we forgot to check.<br /><br />Whatever. It's the SHIT SHOW!<br /><br />Here's what we're gonna talk about:<br />Compliance… <br /><br />We’ve taken something that should be simple….<br /><br />AND<br /><br />Turned it into something so SO damn convoluted that once again we’ve have to create an entire branch of our industry to JUST decipher it<br /><br />We need to simplify this, so HOW do we do it?]]></itunes:summary><itunes:duration>4561</itunes:duration><itunes:keywords>compliance,cybersecurity,hipaa,information,infosec,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/67e569ca0327faa5d0ab336a49d3697a.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Twenty-Seven - O Shit, am I on FIRE?</title><link>https://www.spreaker.com/episode/episode-twenty-seven-o-shit-am-i-on-fire--42039566</link><description><![CDATA[What is that smell?...  Is that smoke I see?...  Why am I hot?<br /><br />OH SHIT, I'm ON FIRE!<br /><br />Work in InfoSec long enough and you will see a fire or two, Oh hell let's be honest, work in InfoSec long enough and you will be the cause of a fire or two. It could be your flagship application leaking vast amounts of data, it could be the secretary clicking on a link, a misconfiguration, a failed patch, your most critical 3rd party has a data breach, and ransomware event all in one, then there is the tomfoolery of China, Russia, North Korea just to name a few.<br /><br /> At some point, we have all gotten the "Shits on fire" call at some ungodly hour of the night, and this is assuming we were sleeping, instead of sitting up chewing our fingernails waiting for the phone to ring with a fire on the other end that we then have to deal with. This constant barrage of fires, day in and day out, takes a toll just like in a real fire-you get burnt.<br /><br />Then we have the political fires when someone is trying to burn us down, we have to deal with this on top of the security fires, and this only further contributes to the personal burning, (no not that kind of personal burning, get your mind out of the gutter) I am referring to the burning of our energy and passion, the kind of burning that if not managed leads to burn out. The old saying goes "be careful not to burn the candle at both ends for too long" this is because you will eventually burn out, but along the way, you will burn up first.   <br /><br />Oh and don't forget, your doorbell, cell phone charger, smart oven, furnace, lightbulbs are all trying to burn down your house.<br /><br />So what can be done? What is the digital equivalent of a fire extinguisher, smoke detector, or sprinkler? How do you tell when you or a colleague is getting burned up or is already burned out? What do you do when your doorbell is trying to kill you with FIRE! <br /><br />All this and SPICY Chips (or Crisps as Chris would say) on the Shit Show.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/42039566</guid><pubDate>Wed, 18 Nov 2020 16:15:47 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/42039566/episode27_111820.mp3" length="120083628" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>What is that smell?...  Is that smoke I see?...  Why am I hot?

OH SHIT, I'm ON FIRE!

Work in InfoSec long enough and you will see a fire or two, Oh hell let's be honest, work in InfoSec long enough and you will be the cause of a fire or two. It...</itunes:subtitle><itunes:summary><![CDATA[What is that smell?...  Is that smoke I see?...  Why am I hot?<br /><br />OH SHIT, I'm ON FIRE!<br /><br />Work in InfoSec long enough and you will see a fire or two, Oh hell let's be honest, work in InfoSec long enough and you will be the cause of a fire or two. It could be your flagship application leaking vast amounts of data, it could be the secretary clicking on a link, a misconfiguration, a failed patch, your most critical 3rd party has a data breach, and ransomware event all in one, then there is the tomfoolery of China, Russia, North Korea just to name a few.<br /><br /> At some point, we have all gotten the "Shits on fire" call at some ungodly hour of the night, and this is assuming we were sleeping, instead of sitting up chewing our fingernails waiting for the phone to ring with a fire on the other end that we then have to deal with. This constant barrage of fires, day in and day out, takes a toll just like in a real fire-you get burnt.<br /><br />Then we have the political fires when someone is trying to burn us down, we have to deal with this on top of the security fires, and this only further contributes to the personal burning, (no not that kind of personal burning, get your mind out of the gutter) I am referring to the burning of our energy and passion, the kind of burning that if not managed leads to burn out. The old saying goes "be careful not to burn the candle at both ends for too long" this is because you will eventually burn out, but along the way, you will burn up first.   <br /><br />Oh and don't forget, your doorbell, cell phone charger, smart oven, furnace, lightbulbs are all trying to burn down your house.<br /><br />So what can be done? What is the digital equivalent of a fire extinguisher, smoke detector, or sprinkler? How do you tell when you or a colleague is getting burned up or is already burned out? What do you do when your doorbell is trying to kill you with FIRE! <br /><br />All this and SPICY Chips (or Crisps as Chris would say) on the Shit Show.]]></itunes:summary><itunes:duration>7506</itunes:duration><itunes:keywords>burnout,cloutier,cybersecurity,francen,information,infosec,iot,roberts,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9f5fb9540e2c72d7b52e91a159936a28.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Twenty-Six - Seven Ways Security Can Improve Your Sex Life</title><link>https://www.spreaker.com/episode/episode-twenty-six-seven-ways-security-can-improve-your-sex-life--41875763</link><description><![CDATA[Who doesn't want the best sex life possible? Hmm. Maybe not someone we'd want to know.<br /><br />Believe it or not, some of us are convinced that good/better security can lead to a good/better sex life. Thought-provoking? We think so.<br /><br />Chris, Evan, and Ryan are going to dissect this theory and give you (at least) seven ways better information security can lead to a better sex life. If you're interested (in a better sex life), you'd better tune in!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/41875763</guid><pubDate>Mon, 09 Nov 2020 12:00:15 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/41875763/episode26_110920.mp3" length="116643406" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Who doesn't want the best sex life possible? Hmm. Maybe not someone we'd want to know.

Believe it or not, some of us are convinced that good/better security can lead to a good/better sex life. Thought-provoking? We think so.

Chris, Evan, and Ryan...</itunes:subtitle><itunes:summary><![CDATA[Who doesn't want the best sex life possible? Hmm. Maybe not someone we'd want to know.<br /><br />Believe it or not, some of us are convinced that good/better security can lead to a good/better sex life. Thought-provoking? We think so.<br /><br />Chris, Evan, and Ryan are going to dissect this theory and give you (at least) seven ways better information security can lead to a better sex life. If you're interested (in a better sex life), you'd better tune in!]]></itunes:summary><itunes:duration>7291</itunes:duration><itunes:keywords>cybersecurity,infosec,security,sex,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c65348c70a54d1932032a680ba5be727.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Twenty-Five - Kiss and Make Up?</title><link>https://www.spreaker.com/episode/episode-twenty-five-kiss-and-make-up--41771658</link><description><![CDATA[So, les face it, the decisions for the next president is probably already made despite everyone still running round the country stumping for more votes and hoping for a last minute turnout. We’ve seen record numbers of folks at the polls and the USPS folks have carried (successfully) more and more mail in ballots than we’ve seen in many years gone past.<br /><br />Which means the dye is cast, we just have to wait to hear who’s won the next 4 years in the hot seat.<br /><br />Which means the time for healing is upon us, or at least we should be planning for it.<br /><br />OR CAN we?<br /><br />Every 4 years it seems as if we up the ante in this fight for power, mud is slung, words are exchanged, wounds opened and then it’s over. We’re meant to move on, and try to get back to working together as ONE country as opposed to two divided ideologies or 50 individual states. To me this is like lawyers at the end of a trial who’ve insulted each other and their clients for days on end, they just shake hands and move on, while some of us STILL want to throw that Molotov cocktail across the courtroom.<br /><br />HOW does this nation repair itself, how do families, communities and people come together, CAN WE?<br /><br />How does one side not gloat? How does the other not lament what could/should have been? AND how DOES a house divided against itself actually work??<br /><br />LOTS to talk about this evening, join us for a lengthy discussion on these topics and more.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/41771658</guid><pubDate>Wed, 04 Nov 2020 19:23:49 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/41771658/episode25_110320.mp3" length="138484699" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>So, les face it, the decisions for the next president is probably already made despite everyone still running round the country stumping for more votes and hoping for a last minute turnout. We’ve seen record numbers of folks at the polls and the USPS...</itunes:subtitle><itunes:summary><![CDATA[So, les face it, the decisions for the next president is probably already made despite everyone still running round the country stumping for more votes and hoping for a last minute turnout. We’ve seen record numbers of folks at the polls and the USPS folks have carried (successfully) more and more mail in ballots than we’ve seen in many years gone past.<br /><br />Which means the dye is cast, we just have to wait to hear who’s won the next 4 years in the hot seat.<br /><br />Which means the time for healing is upon us, or at least we should be planning for it.<br /><br />OR CAN we?<br /><br />Every 4 years it seems as if we up the ante in this fight for power, mud is slung, words are exchanged, wounds opened and then it’s over. We’re meant to move on, and try to get back to working together as ONE country as opposed to two divided ideologies or 50 individual states. To me this is like lawyers at the end of a trial who’ve insulted each other and their clients for days on end, they just shake hands and move on, while some of us STILL want to throw that Molotov cocktail across the courtroom.<br /><br />HOW does this nation repair itself, how do families, communities and people come together, CAN WE?<br /><br />How does one side not gloat? How does the other not lament what could/should have been? AND how DOES a house divided against itself actually work??<br /><br />LOTS to talk about this evening, join us for a lengthy discussion on these topics and more.]]></itunes:summary><itunes:duration>8656</itunes:duration><itunes:keywords>cybersecurity,disinformation,infosec,politics,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/1b62573300abd30a8706ae73fd3d624c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Twenty-Four - Is My Vote Secure?</title><link>https://www.spreaker.com/episode/episode-twenty-four-is-my-vote-secure--41649352</link><description><![CDATA[Will my vote count this year? <br />What is the safest way to vote?<br />So many options, so many questions, and a shitload of confusion. <br /><br />As the last few weeks of this unprecedented year have unfolded the focus has been shifting to the upcoming election and the challenges the pandemic has created for our democratic process, specifically how in the actual F are we going to vote this year. some of the questions we have been pondering are:<br /><br />If I vote by mail will it arrive and be counted?<br />Is 1234 actually an admin password for voting machines?<br />Are the Russians and Iranians or "others" setting up fake ballot boxes?<br />I want to wait in line for 19 hours to vote in person how safe is the voting machine?<br />Should I vote from my phone, is that safer than mail or in-person?<br />Will my vote be thrown out on a technicality?<br />Who is counting the votes and are they trustworthy?<br />How safe is my polling location?<br />How can I identify real poling security from someone pretending to be? <br />The list of questions goes on and on, it is enough to make your head spin your stomach hurt and your confidence in our democratic process to be shaken to its core.<br /><br />What can you do? who has the answers we seek? how can you ensure your vote is secure and counted?<br /><br />But don't worry yet, all hope is not lost there are things that can be done, and lots we can learn to improve in the future, we will be discussing this and more on this episode of the ShitShow.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/41649352</guid><pubDate>Mon, 26 Oct 2020 19:06:18 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/41649352/episode24_102620.mp3" length="123124699" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Will my vote count this year? 
What is the safest way to vote?
So many options, so many questions, and a shitload of confusion. 

As the last few weeks of this unprecedented year have unfolded the focus has been shifting to the upcoming election and...</itunes:subtitle><itunes:summary><![CDATA[Will my vote count this year? <br />What is the safest way to vote?<br />So many options, so many questions, and a shitload of confusion. <br /><br />As the last few weeks of this unprecedented year have unfolded the focus has been shifting to the upcoming election and the challenges the pandemic has created for our democratic process, specifically how in the actual F are we going to vote this year. some of the questions we have been pondering are:<br /><br />If I vote by mail will it arrive and be counted?<br />Is 1234 actually an admin password for voting machines?<br />Are the Russians and Iranians or "others" setting up fake ballot boxes?<br />I want to wait in line for 19 hours to vote in person how safe is the voting machine?<br />Should I vote from my phone, is that safer than mail or in-person?<br />Will my vote be thrown out on a technicality?<br />Who is counting the votes and are they trustworthy?<br />How safe is my polling location?<br />How can I identify real poling security from someone pretending to be? <br />The list of questions goes on and on, it is enough to make your head spin your stomach hurt and your confidence in our democratic process to be shaken to its core.<br /><br />What can you do? who has the answers we seek? how can you ensure your vote is secure and counted?<br /><br />But don't worry yet, all hope is not lost there are things that can be done, and lots we can learn to improve in the future, we will be discussing this and more on this episode of the ShitShow.]]></itunes:summary><itunes:duration>7696</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/872597e3ff35d4da7ac00127b7c166d6.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Twenty-Three - Disunited States of America (Election Disinformation)</title><link>https://www.spreaker.com/episode/episode-twenty-three-disunited-states-of-america-election-disinformation--41533942</link><description><![CDATA[The "United" States of America has never been more disunited and divided, at least not in my lifetime. There's a hypothesis claiming a reason for our division is the disinformation that floods our inboxes, televisions, newsfeeds, and social media accounts every second of every day.<br /><br />Is this true? Is disinformation dividing us? What is disinformation anyway? Is there someone or something behind it all?<br /><br />Let’s break this down into component parts using as much logic and reason as we can muster.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/41533942</guid><pubDate>Mon, 19 Oct 2020 13:10:44 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/41533942/episode23_101920.mp3" length="129524072" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The "United" States of America has never been more disunited and divided, at least not in my lifetime. There's a hypothesis claiming a reason for our division is the disinformation that floods our inboxes, televisions, newsfeeds, and social media...</itunes:subtitle><itunes:summary><![CDATA[The "United" States of America has never been more disunited and divided, at least not in my lifetime. There's a hypothesis claiming a reason for our division is the disinformation that floods our inboxes, televisions, newsfeeds, and social media accounts every second of every day.<br /><br />Is this true? Is disinformation dividing us? What is disinformation anyway? Is there someone or something behind it all?<br /><br />Let’s break this down into component parts using as much logic and reason as we can muster.]]></itunes:summary><itunes:duration>8096</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/53e1ec9220e9b9c94d8f6259489a464c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Twenty-Two - Shit, We’re Breaking Down</title><link>https://www.spreaker.com/episode/episode-twenty-two-shit-we-re-breaking-down--41419065</link><description><![CDATA[We, the pioneers, the forefathers, the originators of this bloody industry that we’re dissecting every week are breaking down. We’re past our sell by date, our warranty’s expired, and bugger all chance of getting one of those extended ones…heck we’re almost at a point where we can get Medicaid AND free bus rides.<br /><br />We can’t be more than 20 yards from a toilet, our bodies are breaking…I just learned what the hell gout was (the painful way) and I’m fairly certain that my loving daughter (who called me old and moldy) IS buying me a walking cane for my birthday.<br /><br />HOW do we pass the baton, what can we do to bring the next generation through with LESS mistakes than we made, how do we champion others AND will you please keep those bloody kids OFF my lawn!?!<br /><br />This evening is going to be both groans and moans about falling apart AND a debate about what do we do with the younger generation, those that have to take over AND hopefully do a better job than we did.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/41419065</guid><pubDate>Mon, 12 Oct 2020 10:35:29 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/41419065/episode22_101220.mp3" length="118976454" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>We, the pioneers, the forefathers, the originators of this bloody industry that we’re dissecting every week are breaking down. We’re past our sell by date, our warranty’s expired, and bugger all chance of getting one of those extended ones…heck we’re...</itunes:subtitle><itunes:summary><![CDATA[We, the pioneers, the forefathers, the originators of this bloody industry that we’re dissecting every week are breaking down. We’re past our sell by date, our warranty’s expired, and bugger all chance of getting one of those extended ones…heck we’re almost at a point where we can get Medicaid AND free bus rides.<br /><br />We can’t be more than 20 yards from a toilet, our bodies are breaking…I just learned what the hell gout was (the painful way) and I’m fairly certain that my loving daughter (who called me old and moldy) IS buying me a walking cane for my birthday.<br /><br />HOW do we pass the baton, what can we do to bring the next generation through with LESS mistakes than we made, how do we champion others AND will you please keep those bloody kids OFF my lawn!?!<br /><br />This evening is going to be both groans and moans about falling apart AND a debate about what do we do with the younger generation, those that have to take over AND hopefully do a better job than we did.]]></itunes:summary><itunes:duration>7436</itunes:duration><itunes:keywords>cloutier,cybersecurity,francen,information,infosec,mentorship,roberts,security,shit,shitshow,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/087112a963c8aacde9b3c6628a43c467.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Twenty-One - Shitty Co-Workers</title><link>https://www.spreaker.com/episode/episode-twenty-one-shitty-co-workers--41345423</link><description><![CDATA[We have all had to deal with Shitty co-workers in our careers <br />You know the co-worker who just never seems to want to help, or worse yet actively gets in the way of work getting done, the Co-worker who works harder at avoiding the work than doing the work, the one with the constant bad attitude and excuses.<br /><br />With COVID and remote work the Shitty Co-workers are getting worse and some of us who used to be good co-workers stuck in isolation are now turning into the shitty ones.<br /><br />Our Co-workers get paid by the same company as us, they should be focused on the same business objectives as us, yet it seems as if they are working for someone else for some other purpose. <br /><br />When it comes to information security not only is this behavior annoying, it is irresponsible and dangerous and could lead to someone's death.<br /><br />What makes a Shitty Co-worker? <br /><br />Lack of commitment to the team<br />Constant negative attitude <br />Not focusing on the issues at hand<br />Creating unnecessary political hurdles <br />Avoiding responsibility or accountability <br />Blaming others<br />Creating road blocks <br />Causing delays and confusion <br />Refusing to learn or grow<br />Never seems to be their issue to deal with<br />Generally being a shit person<br />Are you the shitty Co-worker? are you turning shitty from isolation? how can you help your shitty Co-workers to be less shitty?, all that and more tonight on the Security Shit Show<br /><br />Thursday nights at 9 PM Mountain 10 PM Central <br /><br /><a href="https://www.youtube.com/watch?v=150wT..." rel="noopener">https://www.youtube.com/watch?v=150wT...</a><br /><br />Evan, Chris and Ryan the Shit Show Crew]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/41345423</guid><pubDate>Thu, 08 Oct 2020 09:33:50 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/41345423/episode21_100620.mp3" length="126857074" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>We have all had to deal with Shitty co-workers in our careers 
You know the co-worker who just never seems to want to help, or worse yet actively gets in the way of work getting done, the Co-worker who works harder at avoiding the work than doing the...</itunes:subtitle><itunes:summary><![CDATA[We have all had to deal with Shitty co-workers in our careers <br />You know the co-worker who just never seems to want to help, or worse yet actively gets in the way of work getting done, the Co-worker who works harder at avoiding the work than doing the work, the one with the constant bad attitude and excuses.<br /><br />With COVID and remote work the Shitty Co-workers are getting worse and some of us who used to be good co-workers stuck in isolation are now turning into the shitty ones.<br /><br />Our Co-workers get paid by the same company as us, they should be focused on the same business objectives as us, yet it seems as if they are working for someone else for some other purpose. <br /><br />When it comes to information security not only is this behavior annoying, it is irresponsible and dangerous and could lead to someone's death.<br /><br />What makes a Shitty Co-worker? <br /><br />Lack of commitment to the team<br />Constant negative attitude <br />Not focusing on the issues at hand<br />Creating unnecessary political hurdles <br />Avoiding responsibility or accountability <br />Blaming others<br />Creating road blocks <br />Causing delays and confusion <br />Refusing to learn or grow<br />Never seems to be their issue to deal with<br />Generally being a shit person<br />Are you the shitty Co-worker? are you turning shitty from isolation? how can you help your shitty Co-workers to be less shitty?, all that and more tonight on the Security Shit Show<br /><br />Thursday nights at 9 PM Mountain 10 PM Central <br /><br /><a href="https://www.youtube.com/watch?v=150wT..." rel="noopener">https://www.youtube.com/watch?v=150wT...</a><br /><br />Evan, Chris and Ryan the Shit Show Crew]]></itunes:summary><itunes:duration>7929</itunes:duration><itunes:keywords>coworkers,cybersecurity,infosec,security,shitshow,work</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/013f2057a5dfb95571966074c30e9c64.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Twenty - Somebody's Got To Pay (for this)!</title><link>https://www.spreaker.com/episode/episode-twenty-somebody-s-got-to-pay-for-this--41210326</link><description><![CDATA[The issue is accountability, or (maybe) lack of accountability, in our industry.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/41210326</guid><pubDate>Thu, 01 Oct 2020 11:56:32 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/41210326/episode20_092920.mp3" length="119364320" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>The issue is accountability, or (maybe) lack of accountability, in our industry.</itunes:subtitle><itunes:summary><![CDATA[The issue is accountability, or (maybe) lack of accountability, in our industry.]]></itunes:summary><itunes:duration>7461</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/90411b11c7c53dfa387797f9b7af4fd1.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Nineteen - How Did We Get Here?</title><link>https://www.spreaker.com/episode/episode-nineteen-how-did-we-get-here--41107035</link><description><![CDATA[Sometimes in order to keep moving forward, not only must you take one step at a time, but you must be willing to look back occasionally and evaluate your past, no matter how painful it is. Looking back lets you know whether or not you are headed in the right direction.” (G.K Adams)<br /><br />Having just worked with the Semperis crew on delivering a lecture the other day on the historical tie-ins between how we ALL approach technology today and the influences ON those decisions from almost 12,000 years of documented history affect us it’s something I want to explore further.<br /><br />So, this evening’s Shit Show we'll dig a little deeper with Evan Francen, Ryan Cloutier, CISSP and Rachel Arnold<br /><br />We’ll go back to Jericho in 9600 BCE and work our way forward to see how we might better learn from some of the pitfalls that our ancestors found instead of simply continuing to jump into the bloody things each time they are presented.<br /><br />For those of you who are brain diggers OR simply want to know why we continue to do the same daft things I encourage you to join in, for the rest, grab the popcorn and watch as we try to untangle the brain and humans in general.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/41107035</guid><pubDate>Thu, 24 Sep 2020 20:45:34 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/41107035/episode19_092420.mp3" length="132724803" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Sometimes in order to keep moving forward, not only must you take one step at a time, but you must be willing to look back occasionally and evaluate your past, no matter how painful it is. Looking back lets you know whether or not you are headed in...</itunes:subtitle><itunes:summary><![CDATA[Sometimes in order to keep moving forward, not only must you take one step at a time, but you must be willing to look back occasionally and evaluate your past, no matter how painful it is. Looking back lets you know whether or not you are headed in the right direction.” (G.K Adams)<br /><br />Having just worked with the Semperis crew on delivering a lecture the other day on the historical tie-ins between how we ALL approach technology today and the influences ON those decisions from almost 12,000 years of documented history affect us it’s something I want to explore further.<br /><br />So, this evening’s Shit Show we'll dig a little deeper with Evan Francen, Ryan Cloutier, CISSP and Rachel Arnold<br /><br />We’ll go back to Jericho in 9600 BCE and work our way forward to see how we might better learn from some of the pitfalls that our ancestors found instead of simply continuing to jump into the bloody things each time they are presented.<br /><br />For those of you who are brain diggers OR simply want to know why we continue to do the same daft things I encourage you to join in, for the rest, grab the popcorn and watch as we try to untangle the brain and humans in general.]]></itunes:summary><itunes:duration>8296</itunes:duration><itunes:keywords>cybersecurity,data,history,information,infosec,security,shit,shitshow,show,war</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/281235095543e667e9102d921f62b6f0.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Eighteen - Hands Up! Give Me All Your Money</title><link>https://www.spreaker.com/episode/episode-eighteen-hands-up-give-me-all-your-money--40923862</link><description><![CDATA[A good hard talk about ransomware in our industry.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/40923862</guid><pubDate>Wed, 16 Sep 2020 01:53:37 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/40923862/episode18_091520.mp3" length="125364124" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>A good hard talk about ransomware in our industry.</itunes:subtitle><itunes:summary><![CDATA[A good hard talk about ransomware in our industry.]]></itunes:summary><itunes:duration>7836</itunes:duration><itunes:keywords>cybersecurity,information,infosec,ransomware,security,shit,shitshow,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/47bc66d12ccc263ab5f2914b48145140.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Seventeen - Negativity is Bullshit</title><link>https://www.spreaker.com/episode/episode-seventeen-negativity-is-bullshit--40775367</link><description><![CDATA[Full description here: <a href="https://blog.securityshitshow.com/2020/09/episode-17-negativity-is-bullshit.html" rel="noopener">https://blog.securityshitshow.com/2020/09/episode-17-negativity-is-bullshit.html</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/40775367</guid><pubDate>Tue, 08 Sep 2020 15:48:34 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/40775367/episode17_090820.mp3" length="130919220" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Full description here: https://blog.securityshitshow.com/2020/09/episode-17-negativity-is-bullshit.html</itunes:subtitle><itunes:summary><![CDATA[Full description here: <a href="https://blog.securityshitshow.com/2020/09/episode-17-negativity-is-bullshit.html" rel="noopener">https://blog.securityshitshow.com/2020/09/episode-17-negativity-is-bullshit.html</a>]]></itunes:summary><itunes:duration>8183</itunes:duration><itunes:keywords>bullshit,cybersecurity,information,infosec,negativity,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/3bd00030fcc1459b7355d147c468b9f6.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Sixteen- Fried Brains Anyone?</title><link>https://www.spreaker.com/episode/episode-sixteen-fried-brains-anyone--40600393</link><description><![CDATA[This evening on the Security Shit Show we’re going to open the Pandora’s box labeled 5G and see what’s what with the technology, implementations, countries involved AND all the conspiracy theories surrounding it.<br /><br />With the ever-guiding lights provided by Evan Francen, Ryan Cloutier, CISSP and Rachel Arnold we’ll see what we can come up with to dispel the rumors of brain frying, Covid-19 inducing, plant and bird killing technology.<br /><br />We’ll address some of the actual challenges WITH 5G, thanks to some great conversations the other week with Paul Ferrillo and Dr. Rob Spalding, Brig Gen, USAF (Ret)<br /><br />We might even go down the rabbit hole of Body Area Networks, and how we can induce communication within the body… and NO that’s not a 5G thing, but it’s a reality we’re working on…<br /><br />I’m sure our colleagues in China will come up in conversation given the bun fight between the US and that area of the world… we WILL address the technology giant that IS the Far East and what we can (or can’t) do about it.<br /><br />Grab a drink and join us this evening for an engaging conversation about how we’re screwed and should accept the simple fact technology’s won and we’re merely prawns in the digital age (or is it pawns?)]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/40600393</guid><pubDate>Mon, 31 Aug 2020 07:56:10 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/40600393/episode16_083120.mp3" length="117524046" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>This evening on the Security Shit Show we’re going to open the Pandora’s box labeled 5G and see what’s what with the technology, implementations, countries involved AND all the conspiracy theories surrounding it.

With the ever-guiding lights provided...</itunes:subtitle><itunes:summary><![CDATA[This evening on the Security Shit Show we’re going to open the Pandora’s box labeled 5G and see what’s what with the technology, implementations, countries involved AND all the conspiracy theories surrounding it.<br /><br />With the ever-guiding lights provided by Evan Francen, Ryan Cloutier, CISSP and Rachel Arnold we’ll see what we can come up with to dispel the rumors of brain frying, Covid-19 inducing, plant and bird killing technology.<br /><br />We’ll address some of the actual challenges WITH 5G, thanks to some great conversations the other week with Paul Ferrillo and Dr. Rob Spalding, Brig Gen, USAF (Ret)<br /><br />We might even go down the rabbit hole of Body Area Networks, and how we can induce communication within the body… and NO that’s not a 5G thing, but it’s a reality we’re working on…<br /><br />I’m sure our colleagues in China will come up in conversation given the bun fight between the US and that area of the world… we WILL address the technology giant that IS the Far East and what we can (or can’t) do about it.<br /><br />Grab a drink and join us this evening for an engaging conversation about how we’re screwed and should accept the simple fact technology’s won and we’re merely prawns in the digital age (or is it pawns?)]]></itunes:summary><itunes:duration>7346</itunes:duration><itunes:keywords>5g,conspiracy,cybersecurity,infosec,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5cb4b062918355a63c5f850a7464607f.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Fifteen - SHHHHH They are listening</title><link>https://www.spreaker.com/episode/episode-fifteen-shhhhh-they-are-listening--40474880</link><description><![CDATA[Think you're having a private conversation, think again your TV, toaster, thermostat, smart speakers and phones are all listening to you all the time. You're most embarrassing and mundane moments are being listened to by quality control agents all around the globe.<br /><br />Cyber criminals are combing through your chat logs, so they can craft the perfect phishing attack. Smart cameras and webcams are allowing predators access to your home and children. <br /><br />Nation states are listening so they can learn how best to sway your thinking and manipulate you.<br /><br />Why does this matter to you, 3rd party companies are monetizing your personal information and nation-states are weaponizing it against you and your children, grandchildren, nieces, and nephews.<br /><br />Business are having confidential conversations around these spying devices potentially allowing trade secrets and sensitive information to leak.<br /><br />We are sharing sensitive medical information with our doctors via iPads, laptops and smartphones, are you sure that the only person who knows about your embarrassing social disease is your doctor? <br /><br />Have you ever looked at the chat log to see what has been heard by these devices?<br /><br />Do you know you can prevent this, that you can control how much of your life you expose to these in-home spying devices?<br /> <br />Tune in for a lively and honest discussion about who is listening and what you can do, to do to limit or prevent your most private conversations from becoming public. Thursday night at 10pm central.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/40474880</guid><pubDate>Mon, 24 Aug 2020 18:36:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/40474880/episode15_082420.mp3" length="123684346" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Think you're having a private conversation, think again your TV, toaster, thermostat, smart speakers and phones are all listening to you all the time. You're most embarrassing and mundane moments are being listened to by quality control agents all...</itunes:subtitle><itunes:summary><![CDATA[Think you're having a private conversation, think again your TV, toaster, thermostat, smart speakers and phones are all listening to you all the time. You're most embarrassing and mundane moments are being listened to by quality control agents all around the globe.<br /><br />Cyber criminals are combing through your chat logs, so they can craft the perfect phishing attack. Smart cameras and webcams are allowing predators access to your home and children. <br /><br />Nation states are listening so they can learn how best to sway your thinking and manipulate you.<br /><br />Why does this matter to you, 3rd party companies are monetizing your personal information and nation-states are weaponizing it against you and your children, grandchildren, nieces, and nephews.<br /><br />Business are having confidential conversations around these spying devices potentially allowing trade secrets and sensitive information to leak.<br /><br />We are sharing sensitive medical information with our doctors via iPads, laptops and smartphones, are you sure that the only person who knows about your embarrassing social disease is your doctor? <br /><br />Have you ever looked at the chat log to see what has been heard by these devices?<br /><br />Do you know you can prevent this, that you can control how much of your life you expose to these in-home spying devices?<br /> <br />Tune in for a lively and honest discussion about who is listening and what you can do, to do to limit or prevent your most private conversations from becoming public. Thursday night at 10pm central.]]></itunes:summary><itunes:duration>7731</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/27801c5c6a035addf967664ba013d650.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Fourteen - Shut Up Brain! I’m Fine.</title><link>https://www.spreaker.com/episode/episode-fourteen-shut-up-brain-i-m-fine--40386157</link><description><![CDATA[Really? Who’s got all their shit together all the time? Simple. Nobody does.<br /><br />NOTE: Mental health is a topic that hits home with all three of us on the Shit Show, so this is gonna get personal.<br /><br />Let’s get real. Mental health is a real and significant issue. We convince ourselves of the lie, nobody cares and you’re alone. This is bullshit. People do care and you are NOT alone! Some facts:<br />• 19.1% of U.S. adults experienced mental illness in 2018 (47.6 million people). This represents 1 in 5 adults.<br />• 4.6% of U.S. adults experienced serious mental illness in 2018 (11.4 million people). This represents 1 in 25 adults.<br />• 16.5% of U.S. youth aged 6-17 experienced a mental health disorder in 2016 (7.7 million people)<br />• 3.7% of U.S. adults experienced a co-occurring substance use disorder and mental illness in 2018 (9.2 million people)<br /><br />It’s not a race or sexual-preference thing. The annual prevalence of mental illness among U.S. adults, by demographic group:<br />• Non-Hispanic Asian: 14.7%<br />• Non-Hispanic white: 20.4%<br />• Non-Hispanic black or African-American: 16.2%<br />• Non-Hispanic American Indian or Alaska Native: 22.1%<br />• Non-Hispanic mixed/multiracial: 26.8%<br />• Hispanic or Latino: 16.9%<br />• Lesbian, Gay or Bisexual: 37.4%:<br /><br />It’s a fucking human thing! Sadly, too many of us believe the lie and don’t get help. We must fight the stigma and make help more accessible to those who need it.<br />• 11.3% of U.S. adults with mental illness had no insurance coverage in 2018<br />• 13.4% of U.S. adults with serious mental illness had no insurance coverage in 2018<br />• 60% of U.S. counties do not have a single practicing psychiatrist<br /><br />It’s OK to talk about mental health issues openly and it’s OK to face our mental challenges head on. It’s NOT OK to keep this shit under wraps and it’s NOT OK to face your mental challenges alone. The ultimate end for some who are suffering is suicide.<br />• Suicide is the 2nd leading cause of death among people aged 10-34 in the U.S.<br />• Suicide is the 10th leading cause of death in the U.S.<br />• The overall suicide rate in the U.S. has increased by 31% since 2001<br />• 46% of people who die by suicide had a diagnosed mental health condition<br />• 90% of people who die by suicide had shown symptoms of a mental health condition, according to interviews with family, friends and medical professionals (also known as psychological autopsy)<br />• Lesbian, gay and bisexual youth are 4x more likely to attempt suicide than straight youth<br />• 75% of people who die by suicide are male<br />• Transgender adults are nearly 12x more likely to attempt suicide than the general population<br />• Annual prevalence of serious thoughts of suicide, by U.S. demographic group:<br />o 4.3% of all adults<br />o 11.0% of young adults aged 18-25<br />o 17.2% of high school students<br />o 47.7% of lesbian, gay, and bisexual high school students<br /><br />Sadly, these numbers are likely worse now. All these statistics are pre-2020, pre-COVID, pre-riots, etc. Take these facts, sprinkle in the stress of working in our (information security) industry (marginalized, understaffed, misunderstood, etc.), and we have a potential recipe for disaster, at least for some of us.<br /><br />This might not be an uplifting topic to discuss on the Shit Show, but it’s one we won’t back down from. We give a shit about people and we give a shit about you, so we’ll openly discuss all this tonight!<br /><br />Be sure to tune in tonight (8/13) at 10pm CDT for our live show. If can’t catch us live, go watch the recording afterwards.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/40386157</guid><pubDate>Tue, 18 Aug 2020 16:20:55 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/40386157/episode14_081820.mp3" length="129215618" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Really? Who’s got all their shit together all the time? Simple. Nobody does.

NOTE: Mental health is a topic that hits home with all three of us on the Shit Show, so this is gonna get personal.

Let’s get real. Mental health is a real and significant...</itunes:subtitle><itunes:summary><![CDATA[Really? Who’s got all their shit together all the time? Simple. Nobody does.<br /><br />NOTE: Mental health is a topic that hits home with all three of us on the Shit Show, so this is gonna get personal.<br /><br />Let’s get real. Mental health is a real and significant issue. We convince ourselves of the lie, nobody cares and you’re alone. This is bullshit. People do care and you are NOT alone! Some facts:<br />• 19.1% of U.S. adults experienced mental illness in 2018 (47.6 million people). This represents 1 in 5 adults.<br />• 4.6% of U.S. adults experienced serious mental illness in 2018 (11.4 million people). This represents 1 in 25 adults.<br />• 16.5% of U.S. youth aged 6-17 experienced a mental health disorder in 2016 (7.7 million people)<br />• 3.7% of U.S. adults experienced a co-occurring substance use disorder and mental illness in 2018 (9.2 million people)<br /><br />It’s not a race or sexual-preference thing. The annual prevalence of mental illness among U.S. adults, by demographic group:<br />• Non-Hispanic Asian: 14.7%<br />• Non-Hispanic white: 20.4%<br />• Non-Hispanic black or African-American: 16.2%<br />• Non-Hispanic American Indian or Alaska Native: 22.1%<br />• Non-Hispanic mixed/multiracial: 26.8%<br />• Hispanic or Latino: 16.9%<br />• Lesbian, Gay or Bisexual: 37.4%:<br /><br />It’s a fucking human thing! Sadly, too many of us believe the lie and don’t get help. We must fight the stigma and make help more accessible to those who need it.<br />• 11.3% of U.S. adults with mental illness had no insurance coverage in 2018<br />• 13.4% of U.S. adults with serious mental illness had no insurance coverage in 2018<br />• 60% of U.S. counties do not have a single practicing psychiatrist<br /><br />It’s OK to talk about mental health issues openly and it’s OK to face our mental challenges head on. It’s NOT OK to keep this shit under wraps and it’s NOT OK to face your mental challenges alone. The ultimate end for some who are suffering is suicide.<br />• Suicide is the 2nd leading cause of death among people aged 10-34 in the U.S.<br />• Suicide is the 10th leading cause of death in the U.S.<br />• The overall suicide rate in the U.S. has increased by 31% since 2001<br />• 46% of people who die by suicide had a diagnosed mental health condition<br />• 90% of people who die by suicide had shown symptoms of a mental health condition, according to interviews with family, friends and medical professionals (also known as psychological autopsy)<br />• Lesbian, gay and bisexual youth are 4x more likely to attempt suicide than straight youth<br />• 75% of people who die by suicide are male<br />• Transgender adults are nearly 12x more likely to attempt suicide than the general population<br />• Annual prevalence of serious thoughts of suicide, by U.S. demographic group:<br />o 4.3% of all adults<br />o 11.0% of young adults aged 18-25<br />o 17.2% of high school students<br />o 47.7% of lesbian, gay, and bisexual high school students<br /><br />Sadly, these numbers are likely worse now. All these statistics are pre-2020, pre-COVID, pre-riots, etc. Take these facts, sprinkle in the stress of working in our (information security) industry (marginalized, understaffed, misunderstood, etc.), and we have a potential recipe for disaster, at least for some of us.<br /><br />This might not be an uplifting topic to discuss on the Shit Show, but it’s one we won’t back down from. We give a shit about people and we give a shit about you, so we’ll openly discuss all this tonight!<br /><br />Be sure to tune in tonight (8/13) at 10pm CDT for our live show. If can’t catch us live, go watch the recording afterwards.]]></itunes:summary><itunes:duration>8076</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/7f866c80a31676741dd73b1d2c0c0258.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Thirteen - What if I Told You?</title><link>https://www.spreaker.com/episode/episode-thirteen-what-if-i-told-you--40310091</link><description><![CDATA[Your mother was a hamster, and your father smelt of elderberries….<br /><br />Until recently, if I wanted to insult you I HAD to do it to your face, or from the parapet of the nearest castle and hope that you didn’t punch my lights out OR lay siege to my domain.<br /><br />However…<br /><br />These days, anyone with a phone, computer or Internet access can quickly become an armchair critic, troll or anonymous heckler in the digital crowd.<br /><br />To the point where it moves from annoying TO personal and threatening etc.<br />And, as a society, as an industry and as humans we’re ill prepared to deal with this issue. It’s NOT going away, and it affects many of us, so what DO we do about it?]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/40310091</guid><pubDate>Thu, 13 Aug 2020 17:53:12 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/40310091/episode13_081320.mp3" length="124803641" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Your mother was a hamster, and your father smelt of elderberries….

Until recently, if I wanted to insult you I HAD to do it to your face, or from the parapet of the nearest castle and hope that you didn’t punch my lights out OR lay siege to my...</itunes:subtitle><itunes:summary><![CDATA[Your mother was a hamster, and your father smelt of elderberries….<br /><br />Until recently, if I wanted to insult you I HAD to do it to your face, or from the parapet of the nearest castle and hope that you didn’t punch my lights out OR lay siege to my domain.<br /><br />However…<br /><br />These days, anyone with a phone, computer or Internet access can quickly become an armchair critic, troll or anonymous heckler in the digital crowd.<br /><br />To the point where it moves from annoying TO personal and threatening etc.<br />And, as a society, as an industry and as humans we’re ill prepared to deal with this issue. It’s NOT going away, and it affects many of us, so what DO we do about it?]]></itunes:summary><itunes:duration>7801</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/690d77202c33db71b75c79028515d27a.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Twelve - Scammy Shit</title><link>https://www.spreaker.com/episode/episode-twelve-scammy-shit--40122990</link><description><![CDATA[Scams, scams, everywhere are scams and misinformation.<br />In the digital world, it is more important than ever to be able to recognize scams and misinformation. The cybercriminals continue to evolve their tactics, they are playing a longer game these days, making it harder to detect when scams are afoot. scams come in so many flavors, pet scams, romance scams, business scams, COVID scams, charity scams, product scams, and the list goes on and on.<br /><br /> Scams include counterfeit goods and services not to mention the psychological warfare being waged against the world via social media and traditional media. if we continue to allow this to go unchecked we will find ourselves in a world we never wanted and can not escape. if we are going to live digital-first lives we must adopt the necessary skills to do so safely and step one is the ability to identify scams and misinformation.<br /><br />tonight we will talk about what is a scam, how do you identify it, what are the right questions to ask, who do you tell if you think you're being scammed, how do you recover if you have been scammed. what do we as an industry need to do to help build better detection and protection against scams and misinformation?]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/40122990</guid><pubDate>Mon, 03 Aug 2020 10:49:18 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/40122990/episode12_080320.mp3" length="114110155" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Scams, scams, everywhere are scams and misinformation.
In the digital world, it is more important than ever to be able to recognize scams and misinformation. The cybercriminals continue to evolve their tactics, they are playing a longer game these...</itunes:subtitle><itunes:summary><![CDATA[Scams, scams, everywhere are scams and misinformation.<br />In the digital world, it is more important than ever to be able to recognize scams and misinformation. The cybercriminals continue to evolve their tactics, they are playing a longer game these days, making it harder to detect when scams are afoot. scams come in so many flavors, pet scams, romance scams, business scams, COVID scams, charity scams, product scams, and the list goes on and on.<br /><br /> Scams include counterfeit goods and services not to mention the psychological warfare being waged against the world via social media and traditional media. if we continue to allow this to go unchecked we will find ourselves in a world we never wanted and can not escape. if we are going to live digital-first lives we must adopt the necessary skills to do so safely and step one is the ability to identify scams and misinformation.<br /><br />tonight we will talk about what is a scam, how do you identify it, what are the right questions to ask, who do you tell if you think you're being scammed, how do you recover if you have been scammed. what do we as an industry need to do to help build better detection and protection against scams and misinformation?]]></itunes:summary><itunes:duration>7132</itunes:duration><itunes:keywords>cybersecurity,infosec,scam,scams,security,shit,show</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/d2feb66186527623ba16dc63e926dd78.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Eleven - Why?</title><link>https://www.spreaker.com/episode/episode-eleven-why--40039097</link><description><![CDATA[Why do we do this shit, why do you do this shit, and why do they do this shit?<br /><br />We’re all busy as hell. We rush off to do shit, in a rush to get shit done. The shit we do is critical and we’re all important to… Wait!<br /><br />Why?<br /><br />Why am I busy as hell? Why am I rushing off to do shit? Why is it so important I get shit done? Why is what I do critical to anyone?<br /><br />I just assume I know. I get caught up in the whirlwind of shit like most people do. If I get too deep in the shit, I easily forget why I chose to be here in the first place. Did I just assume I knew my purpose without taking the time to reflect on it?<br /><br />This is deeper than I thought.<br /><br />Why did I want to get into this industry? Why am I here?<br /><br />Reflection time. <br /><br />OK, I think I got my shit figured out.<br /><br />What about you? Do you think you’ve got your shit figured out too? Is it safe for me to assume you do?<br /><br />What about them, you know, the business people, the everyday people, and the people who don’t do what we do? Think they got their shit figured out too?<br /><br />Does any of this matter?<br /><br />Hell yes, it all matters! If I don’t have my shit figured out, I have no purpose. If you don’t have your shit figured out, you don’t have purpose either. If my shit and your shit align, we can do good shit together. If they don’t align, we can’t. I’m in this shit, you’re in this shit, and they’re in this shit too. We’re all in this shit together. Some of us are aligned (with our purpose) and some of us aren’t. If and where we’re in alignment, meaning our purposes can serve each other’s purposes, we’re allies. Where there isn’t alignment, we’re adversaries.<br /><br />Simple. Alignment = Ally. Miss-Alignment = Adversary.<br /><br />Find your purpose first, then look for common ground in others. Don’t assume, validate. Assuming I know my purpose or your purpose or their purpose without validation leads to aimless bullshit. Lord knows, we have too much aimless bullshit already.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/40039097</guid><pubDate>Wed, 29 Jul 2020 18:20:53 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/40039097/episode11_072820a.mp3" length="138325038" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Why do we do this shit, why do you do this shit, and why do they do this shit?

We’re all busy as hell. We rush off to do shit, in a rush to get shit done. The shit we do is critical and we’re all important to… Wait!

Why?

Why am I busy as hell? Why...</itunes:subtitle><itunes:summary><![CDATA[Why do we do this shit, why do you do this shit, and why do they do this shit?<br /><br />We’re all busy as hell. We rush off to do shit, in a rush to get shit done. The shit we do is critical and we’re all important to… Wait!<br /><br />Why?<br /><br />Why am I busy as hell? Why am I rushing off to do shit? Why is it so important I get shit done? Why is what I do critical to anyone?<br /><br />I just assume I know. I get caught up in the whirlwind of shit like most people do. If I get too deep in the shit, I easily forget why I chose to be here in the first place. Did I just assume I knew my purpose without taking the time to reflect on it?<br /><br />This is deeper than I thought.<br /><br />Why did I want to get into this industry? Why am I here?<br /><br />Reflection time. <br /><br />OK, I think I got my shit figured out.<br /><br />What about you? Do you think you’ve got your shit figured out too? Is it safe for me to assume you do?<br /><br />What about them, you know, the business people, the everyday people, and the people who don’t do what we do? Think they got their shit figured out too?<br /><br />Does any of this matter?<br /><br />Hell yes, it all matters! If I don’t have my shit figured out, I have no purpose. If you don’t have your shit figured out, you don’t have purpose either. If my shit and your shit align, we can do good shit together. If they don’t align, we can’t. I’m in this shit, you’re in this shit, and they’re in this shit too. We’re all in this shit together. Some of us are aligned (with our purpose) and some of us aren’t. If and where we’re in alignment, meaning our purposes can serve each other’s purposes, we’re allies. Where there isn’t alignment, we’re adversaries.<br /><br />Simple. Alignment = Ally. Miss-Alignment = Adversary.<br /><br />Find your purpose first, then look for common ground in others. Don’t assume, validate. Assuming I know my purpose or your purpose or their purpose without validation leads to aimless bullshit. Lord knows, we have too much aimless bullshit already.]]></itunes:summary><itunes:duration>8646</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/2e41f77f8167b069f13d3387786ca999.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Ten - We Want You...</title><link>https://www.spreaker.com/episode/episode-ten-we-want-you--39916684</link><description><![CDATA[On tonight’s Security Shit Show, Ryan Cloutier, CISSP Evan Francen and I are going to tackle the wonderful world of job descriptions, recruiting and the disaster that appears to be getting people INTO the industry!<br /><br />As a guide, the below should help frame the conversations!<br /><br />Job descriptions (AND their meanings)<br />1) To be part of the team (you’re the first!)<br />2) To lead from the front (you’re the bullet shield)<br />3) To be THE voice (and get blamed)<br />4) To bridge DevSecOps (You’re buying coffee and donuts)<br />5) Drug free workplace (no coffee, tea, alcohol, weed, glue, or gluten)<br />6) To have the following (The tick-list from hell)<br />a) Degree (you know because that ALWAYS helps…)<br />b) CISSP (yea, it’s only an intern role, but we to keep up appearances)<br />c) 5 years of experience (ALL entry level people have that, right?!?)<br />d) CEH (we googled this, it sounded cool)<br />e) Knowledge of networking (WTF is the difference between 5, 5e, 6, etc.)<br />f) Experience with WiFi (A, B, G, F, E, 2.4, 2.5, 5 and many other numbers)<br />g) Fluent in acronym soup<br />h) Fluent in geek, an undergraduate in business, psychology, and PPTX<br /><br />You get the idea; we’re going to dismantle this shit tonight!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/39916684</guid><pubDate>Thu, 23 Jul 2020 11:39:09 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/39916684/episode10_072220.mp3" length="255809921" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>On tonight’s Security Shit Show, Ryan Cloutier, CISSP Evan Francen and I are going to tackle the wonderful world of job descriptions, recruiting and the disaster that appears to be getting people INTO the industry!

As a guide, the below should help...</itunes:subtitle><itunes:summary><![CDATA[On tonight’s Security Shit Show, Ryan Cloutier, CISSP Evan Francen and I are going to tackle the wonderful world of job descriptions, recruiting and the disaster that appears to be getting people INTO the industry!<br /><br />As a guide, the below should help frame the conversations!<br /><br />Job descriptions (AND their meanings)<br />1) To be part of the team (you’re the first!)<br />2) To lead from the front (you’re the bullet shield)<br />3) To be THE voice (and get blamed)<br />4) To bridge DevSecOps (You’re buying coffee and donuts)<br />5) Drug free workplace (no coffee, tea, alcohol, weed, glue, or gluten)<br />6) To have the following (The tick-list from hell)<br />a) Degree (you know because that ALWAYS helps…)<br />b) CISSP (yea, it’s only an intern role, but we to keep up appearances)<br />c) 5 years of experience (ALL entry level people have that, right?!?)<br />d) CEH (we googled this, it sounded cool)<br />e) Knowledge of networking (WTF is the difference between 5, 5e, 6, etc.)<br />f) Experience with WiFi (A, B, G, F, E, 2.4, 2.5, 5 and many other numbers)<br />g) Fluent in acronym soup<br />h) Fluent in geek, an undergraduate in business, psychology, and PPTX<br /><br />You get the idea; we’re going to dismantle this shit tonight!]]></itunes:summary><itunes:duration>6396</itunes:duration><itunes:keywords>broken,cybersecurity,hiring,infosec,jobs,real,security,shit,show,truth</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/e5f763eabe820220bf6c02bc2d8fa7d4.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Nine - Your shits broken! We want a recall!</title><link>https://www.spreaker.com/episode/episode-nine-your-shits-broken-we-want-a-recall--39342277</link><description><![CDATA[This shit again…<br /><br />Key pieces of technology that we rely on are broken and we have no recourse with the manufacture. Why is IT the only industry that when shit breaks, no one seems to be accountable or care to fix their faulty products, the majority of home routers are broken. In this time of COVID the security of our home routers is critical for our business, institutions, governments, and personal safety. It is a sad truth that I am not shocked when I hear this year’s newest home routers are all running out of date OS’s, out of date code with gaping holes and vulnerabilities.<br /><br />If this was a car, stove, toy, building material, TV etc. putting us at risk, we would have recourse with the consumer protection agency, with the manufacture through a recall but because it is the Blackbox of mystery known as IT there is nothing we can do to hold the vendor accountable for putting us at risk. So, how do we change this? How do we, the consumer, take back the power to hold the manufacturers accountable for fixing and/or recalling their products when the products are putting the world at risk?]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/39342277</guid><pubDate>Mon, 13 Jul 2020 10:32:45 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/39342277/episode9_071320.mp3" length="291165124" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>This shit again…

Key pieces of technology that we rely on are broken and we have no recourse with the manufacture. Why is IT the only industry that when shit breaks, no one seems to be accountable or care to fix their faulty products, the majority of...</itunes:subtitle><itunes:summary><![CDATA[This shit again…<br /><br />Key pieces of technology that we rely on are broken and we have no recourse with the manufacture. Why is IT the only industry that when shit breaks, no one seems to be accountable or care to fix their faulty products, the majority of home routers are broken. In this time of COVID the security of our home routers is critical for our business, institutions, governments, and personal safety. It is a sad truth that I am not shocked when I hear this year’s newest home routers are all running out of date OS’s, out of date code with gaping holes and vulnerabilities.<br /><br />If this was a car, stove, toy, building material, TV etc. putting us at risk, we would have recourse with the consumer protection agency, with the manufacture through a recall but because it is the Blackbox of mystery known as IT there is nothing we can do to hold the vendor accountable for putting us at risk. So, how do we change this? How do we, the consumer, take back the power to hold the manufacturers accountable for fixing and/or recalling their products when the products are putting the world at risk?]]></itunes:summary><itunes:duration>7280</itunes:duration><itunes:keywords>broken,cybersecurity,infosec,real,security,shit,show,truth</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cdb6596dd22860f714d69cc5e21fc8e6.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Eight - Mirror, Mirror On The Wall</title><link>https://www.spreaker.com/episode/episode-eight-mirror-mirror-on-the-wall--36333698</link><description><![CDATA[HINT: You're probably NOT the fairest of them all (and neither am I).<br /><br />The dreaded (by some) topic of information security roles and responsibilities. <br /><br />When people don't know their role, or they’re not held accountable for it, what happens? Too often, nothing happens. Information security falters, breaches happen, people suffer, and everybody is left pointing fingers at everybody else.<br /><br />The facts:<br />• NOBODY is more responsible for your information security than you are.<br />• NOBODY should give a shit about your excuses.<br />• SOMEBODY suffers when you don't understand (or define) your role and play it as well as you can.<br />• A CISO can only do what he/she is EMPOWERED to do. Does burying them within IT, empower them?<br /><br />So much shit to talk about in this episode, and there's sure to be some sparks flying (and maybe a disagreement or two).<br /><br />Questions we'll cover (and more):<br />• Who the hell is responsible? You? Me? Them?<br />• At your organization, who's ultimately responsible for information security?<br />• At home, who's ultimately responsible for information security?<br />• Who's to blame when shit goes wrong?<br />• Where's accountability in all this?<br />• Worried about the Russians, the Iranians, the hackers taking all your shit? Whose problem is that and what are you going to do?<br />• You've got the CISO job! Yay! Are you empowered to do your shit? Why/why not?<br />So many angles to take on this and lots to discuss! Join us tonight (7/2) @ 10PM CDT to get the Shit Show Crew's take!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/36333698</guid><pubDate>Mon, 06 Jul 2020 11:45:43 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/36333698/episode8_070620.mp3" length="258010519" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>HINT: You're probably NOT the fairest of them all (and neither am I).

The dreaded (by some) topic of information security roles and responsibilities. 

When people don't know their role, or they’re not held accountable for it, what happens? Too...</itunes:subtitle><itunes:summary><![CDATA[HINT: You're probably NOT the fairest of them all (and neither am I).<br /><br />The dreaded (by some) topic of information security roles and responsibilities. <br /><br />When people don't know their role, or they’re not held accountable for it, what happens? Too often, nothing happens. Information security falters, breaches happen, people suffer, and everybody is left pointing fingers at everybody else.<br /><br />The facts:<br />• NOBODY is more responsible for your information security than you are.<br />• NOBODY should give a shit about your excuses.<br />• SOMEBODY suffers when you don't understand (or define) your role and play it as well as you can.<br />• A CISO can only do what he/she is EMPOWERED to do. Does burying them within IT, empower them?<br /><br />So much shit to talk about in this episode, and there's sure to be some sparks flying (and maybe a disagreement or two).<br /><br />Questions we'll cover (and more):<br />• Who the hell is responsible? You? Me? Them?<br />• At your organization, who's ultimately responsible for information security?<br />• At home, who's ultimately responsible for information security?<br />• Who's to blame when shit goes wrong?<br />• Where's accountability in all this?<br />• Worried about the Russians, the Iranians, the hackers taking all your shit? Whose problem is that and what are you going to do?<br />• You've got the CISO job! Yay! Are you empowered to do your shit? Why/why not?<br />So many angles to take on this and lots to discuss! Join us tonight (7/2) @ 10PM CDT to get the Shit Show Crew's take!]]></itunes:summary><itunes:duration>6451</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c5d981dcd561d7e6df59167d111f2bbb.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Seven - IS it Navajo? Klingon? Esperanto? or heavens help us is it Qwghlmian?</title><link>https://www.spreaker.com/episode/episode-seven-is-it-navajo-klingon-esperanto-or-heavens-help-us-is-it-qwghlmian--34443739</link><description><![CDATA[No…it’s geek.<br /><br />Seriously, what the hell is it with our industries ability to make words up, spew out acronyms and do our level best to flummox and alienate anyone NOT like us? WE have a communication problem and yet we keep on inventing more and more obscure words and phrases to describe what we’re doing.<br /><br />So this week we’re going to unpack that shit.<br /><br />We’re going to get out the translators AND break down some of the stupidity that is geek speak and translate it TO plain and simple English that everyone can understand.<br /><br />We’re NOT dumbing it down, because that implies the non technical folks “won’t understand” but we WILL demystify, deconstruct and break down some of the language barriers<br /><br />Oh, and along the way we’re going to help us build a compendium that I’m in the middle of doing!<br /><br />Join us OR die in a sea of acronyms that rivals that of the Military!!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/34443739</guid><pubDate>Mon, 29 Jun 2020 13:34:33 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/34443739/episode7_062920.mp3" length="210025662" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>No…it’s geek.

Seriously, what the hell is it with our industries ability to make words up, spew out acronyms and do our level best to flummox and alienate anyone NOT like us? WE have a communication problem and yet we keep on inventing more and more...</itunes:subtitle><itunes:summary><![CDATA[No…it’s geek.<br /><br />Seriously, what the hell is it with our industries ability to make words up, spew out acronyms and do our level best to flummox and alienate anyone NOT like us? WE have a communication problem and yet we keep on inventing more and more obscure words and phrases to describe what we’re doing.<br /><br />So this week we’re going to unpack that shit.<br /><br />We’re going to get out the translators AND break down some of the stupidity that is geek speak and translate it TO plain and simple English that everyone can understand.<br /><br />We’re NOT dumbing it down, because that implies the non technical folks “won’t understand” but we WILL demystify, deconstruct and break down some of the language barriers<br /><br />Oh, and along the way we’re going to help us build a compendium that I’m in the middle of doing!<br /><br />Join us OR die in a sea of acronyms that rivals that of the Military!!]]></itunes:summary><itunes:duration>5251</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bd30717762fbafd0684ab581963a36a7.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Six - Analog Human, Digital World</title><link>https://www.spreaker.com/episode/episode-six-analog-human-digital-world--32417485</link><description><![CDATA[Ryan picked a doozy of a topic tonight. Great discussion between Chris, Evan, and Ryan about the challenges we're facing in the super fast adoption of technology in all facets of our lives.<br /><br />There are mental challenges, safety challenges, and of course, information security challenges. When you come to think of it, mental health, safety, and information security may not be separable anymore in our society.<br /><br />These are very difficult challenges to solve and it's going to take all of us working together, even Oprah Winfrey (inside joke)!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/32417485</guid><pubDate>Mon, 22 Jun 2020 11:41:40 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/32417485/episode6_062220.mp3" length="290495662" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Ryan picked a doozy of a topic tonight. Great discussion between Chris, Evan, and Ryan about the challenges we're facing in the super fast adoption of technology in all facets of our lives.&#13;
&#13;
There are mental challenges, safety challenges, and of...</itunes:subtitle><itunes:summary><![CDATA[Ryan picked a doozy of a topic tonight. Great discussion between Chris, Evan, and Ryan about the challenges we're facing in the super fast adoption of technology in all facets of our lives.<br /><br />There are mental challenges, safety challenges, and of course, information security challenges. When you come to think of it, mental health, safety, and information security may not be separable anymore in our society.<br /><br />These are very difficult challenges to solve and it's going to take all of us working together, even Oprah Winfrey (inside joke)!]]></itunes:summary><itunes:duration>7263</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b293f5180b5b8f27dce51f56fd32a349.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Five - Killer Robots? Oh Shit.</title><link>https://www.spreaker.com/episode/episode-five-killer-robots-oh-shit--30768632</link><description><![CDATA[Shout out to a helpful (and maybe even loyal) viewer Robert Hodges for calling our attention to a neat article titled “Should 'Killer Robots' Be Banned?”.<br /><br />Do killer robots sound like a good idea to you? Think about it...<br /><br />Certainly, Chris, Evan, and Ryan will have a few things to say about the topic.<br /><br />Turned out to be a great discussion with Chris playing the devil's advocate. He certainly held his own!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/30768632</guid><pubDate>Mon, 15 Jun 2020 10:24:54 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/30768632/episode5_061520.mp3" length="266725583" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Shout out to a helpful (and maybe even loyal) viewer Robert Hodges for calling our attention to a neat article titled “Should 'Killer Robots' Be Banned?”.

Do killer robots sound like a good idea to you? Think about it...

Certainly, Chris, Evan, and...</itunes:subtitle><itunes:summary><![CDATA[Shout out to a helpful (and maybe even loyal) viewer Robert Hodges for calling our attention to a neat article titled “Should 'Killer Robots' Be Banned?”.<br /><br />Do killer robots sound like a good idea to you? Think about it...<br /><br />Certainly, Chris, Evan, and Ryan will have a few things to say about the topic.<br /><br />Turned out to be a great discussion with Chris playing the devil's advocate. He certainly held his own!]]></itunes:summary><itunes:duration>6669</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/70b8143e92505d8bdd4955c51fedc365.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Four - Moral and Ethical Shit in a Shitty World</title><link>https://www.spreaker.com/episode/episode-four-moral-and-ethical-shit-in-a-shitty-world--29535053</link><description><![CDATA[It’s Chris’ go this week and he’s a little (maybe a lot) torqued about all the shit going on in the world right now. Our topic this week is ethics and morals. So far, we’ve affectionately given the episode name “Moral and Ethical Shit in a Shitty World”.<br /><br />Some deep talk about some touchy shit.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/29535053</guid><pubDate>Mon, 08 Jun 2020 09:36:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/29535053/episode4_060420.mp3" length="253408419" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>It’s Chris’ go this week and he’s a little (maybe a lot) torqued about all the shit going on in the world right now. Our topic this week is ethics and morals. So far, we’ve affectionately given the episode name “Moral and Ethical Shit in a Shitty...</itunes:subtitle><itunes:summary><![CDATA[It’s Chris’ go this week and he’s a little (maybe a lot) torqued about all the shit going on in the world right now. Our topic this week is ethics and morals. So far, we’ve affectionately given the episode name “Moral and Ethical Shit in a Shitty World”.<br /><br />Some deep talk about some touchy shit.]]></itunes:summary><itunes:duration>6336</itunes:duration><itunes:keywords>cybersecurity,ethics,hacking,informationsecurity,infosec,morals,security,shit</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/d970946a3bab4709c188c13975c99109.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Three - Ego in Our Industry</title><link>https://www.spreaker.com/episode/episode-three-ego-in-our-industry--28810289</link><description><![CDATA[Seriously. We got the live feed figured out now. Yay us!<br /><br />Fantastic discussion this week about the role ego plays in our industry; the good, the bad, and the ugly. We got real in the discussion of how an over-inflated ego can wreck somebody's day/week/month and dug in a little bit about the under-inflated ego. Even veterans with decades of experience struggle with these things from time to time.<br /><br />What do you do when you're confronted with an egotist? What if you're the egotist? We unpacked a lot here, and hopefully you'll find some good nuggets of wisdom for yourself. Despite the title for this episode ("Ego? Fuck Your Ego!"), we kept it pretty much on the level. No call outs (the assholes), but definitely some shout outs (respect-worthy, awesome, humble folks in our industry). and our viewers <br /><br />Enjoy! Subscribe to the show and catch us live every Thursday night at 2200 CDT (that's 10pm for those who don't speak the 24hr. clock natively).]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/28810289</guid><pubDate>Mon, 01 Jun 2020 13:34:48 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/28810289/episode3_060120.mp3" length="193596702" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Seriously. We got the live feed figured out now. Yay us!

Fantastic discussion this week about the role ego plays in our industry; the good, the bad, and the ugly. We got real in the discussion of how an over-inflated ego can wreck somebody's...</itunes:subtitle><itunes:summary><![CDATA[Seriously. We got the live feed figured out now. Yay us!<br /><br />Fantastic discussion this week about the role ego plays in our industry; the good, the bad, and the ugly. We got real in the discussion of how an over-inflated ego can wreck somebody's day/week/month and dug in a little bit about the under-inflated ego. Even veterans with decades of experience struggle with these things from time to time.<br /><br />What do you do when you're confronted with an egotist? What if you're the egotist? We unpacked a lot here, and hopefully you'll find some good nuggets of wisdom for yourself. Despite the title for this episode ("Ego? Fuck Your Ego!"), we kept it pretty much on the level. No call outs (the assholes), but definitely some shout outs (respect-worthy, awesome, humble folks in our industry). and our viewers <br /><br />Enjoy! Subscribe to the show and catch us live every Thursday night at 2200 CDT (that's 10pm for those who don't speak the 24hr. clock natively).]]></itunes:summary><itunes:duration>4840</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/29dd06b2d5ed736a40bf670d8a72236b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode Two - Silver Bullet Easy Button Bullshit</title><link>https://www.spreaker.com/episode/episode-two-silver-bullet-easy-button-bullshit--28210106</link><description><![CDATA[Chris, Ryan, and Evan talk about some of the seriously shitty marketing that goes on in the information security industry. Not all marketing is bullshit, but way too much of it is. The shitty marketers need to be called to the carpet because their tactics end up hurting people.<br /><br />How do you spot the silver bullets and easy buttons when they're bullshit? We do out best to cover this.<br /><br />We also discuss the propensity for people to look for silver bullets and easy buttons. Maybe they do it because they're lazy, overworked, lack skill, or some combination of these things. Either way, stop looking for silver bullets and easy buttons, because most of them are bullshit.<br /><br />We're still getting our feet under us. Cut us a little slack, it's only our second episode! This one runs long, so either find the time (1:42) or start/stop your way through it.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/28210106</guid><pubDate>Mon, 25 May 2020 13:00:15 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/28210106/episode2_052420.mp3" length="246812355" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>Chris, Ryan, and Evan talk about some of the seriously shitty marketing that goes on in the information security industry. Not all marketing is bullshit, but way too much of it is. The shitty marketers need to be called to the carpet because their...</itunes:subtitle><itunes:summary><![CDATA[Chris, Ryan, and Evan talk about some of the seriously shitty marketing that goes on in the information security industry. Not all marketing is bullshit, but way too much of it is. The shitty marketers need to be called to the carpet because their tactics end up hurting people.<br /><br />How do you spot the silver bullets and easy buttons when they're bullshit? We do out best to cover this.<br /><br />We also discuss the propensity for people to look for silver bullets and easy buttons. Maybe they do it because they're lazy, overworked, lack skill, or some combination of these things. Either way, stop looking for silver bullets and easy buttons, because most of them are bullshit.<br /><br />We're still getting our feet under us. Cut us a little slack, it's only our second episode! This one runs long, so either find the time (1:42) or start/stop your way through it.]]></itunes:summary><itunes:duration>6171</itunes:duration><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9f7372706fe4d80d56e92b7c74a4270f.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Episode One - The Start of This Shit</title><link>https://www.spreaker.com/episode/episode-one-the-start-of-this-shit--27559220</link><description><![CDATA[This was our first show... <br /><br />What the hell were you expecting?!<br /><br />The Security Shit Show crew started the show shootin' the shit, before we caught Chris putting on a hoodie (historic moment).<br /><br />Topics tonight in the midst of all the great dialog:<br /> - Lack of marketing accountability in our industry. Wild ass claims are made about product capabilities and nobody seems to care about accountability. <br /> - Everyday people are taken advantage of and we must do better.<br /> - Lots of great ideas from the crew and audience, including innovations in education, legislative changes, leveraging existing laws (maybe), bridging the education gap between generations, an information security score clearinghouse, etc.<br /><br />Lot's of great banter and only a few (mostly appropriate) swear words.<br /><br />If the first Security Shit Show was this good, what's coming is going to be effing AWESOME!]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/27559220</guid><pubDate>Sun, 17 May 2020 07:40:07 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/27559220/episode1_051720.mp3" length="186012733" type="audio/mpeg"/><itunes:author>The InfoSec Mission</itunes:author><itunes:subtitle>This was our first show... 

What the hell were you expecting?!

The Security Shit Show crew started the show shootin' the shit, before we caught Chris putting on a hoodie (historic moment).

Topics tonight in the midst of all the great dialog:
 -...</itunes:subtitle><itunes:summary><![CDATA[This was our first show... <br /><br />What the hell were you expecting?!<br /><br />The Security Shit Show crew started the show shootin' the shit, before we caught Chris putting on a hoodie (historic moment).<br /><br />Topics tonight in the midst of all the great dialog:<br /> - Lack of marketing accountability in our industry. Wild ass claims are made about product capabilities and nobody seems to care about accountability. <br /> - Everyday people are taken advantage of and we must do better.<br /> - Lots of great ideas from the crew and audience, including innovations in education, legislative changes, leveraging existing laws (maybe), bridging the education gap between generations, an information security score clearinghouse, etc.<br /><br />Lot's of great banter and only a few (mostly appropriate) swear words.<br /><br />If the first Security Shit Show was this good, what's coming is going to be effing AWESOME!]]></itunes:summary><itunes:duration>4651</itunes:duration><itunes:keywords>cybersecurity,infosec</itunes:keywords><itunes:explicit>true</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/31a1370476be926362073a6c1e67f69d.jpg"/><itunes:episodeType>full</itunes:episodeType></item></channel></rss>
