Showing posts with label NotTech. Show all posts
Showing posts with label NotTech. Show all posts

Thursday, June 15, 2017

Know Thy Audience: A Guide to Sounding Professional (or not)

      I recently had a discussion with some friends about conduct in and out of the workplace, which led to a larger discussion that how someone speaks in different situations has an impact on the general perception of their knowledge and competency. A couple days after this I thought I'd compile a list of words that shouldn't be used if you want to be taken seriously. I already knew a couple of the words/phrases that were like nails on a chalkboard to me (no matter the situation really), but I wanted to get your input as well. (See tweet here). I originally thought this list could be used for almost any setting, but then thought I should break it down a little further. In a world where memes have broken into every day life by being on the news, in advertisements, and even at work it's sometimes hard for some to make a distinction as to when certain behaviors and phrases are acceptable. It's not only wording that we should worry about either. It's the entirety of your being. Yes you should be happy being yourself and shouldn't bow down to please the entire world. That being said, you should always still remain clean cut, take showers, apply deodorant, wear clean clothes, and not punch people in the face as they walk by.
     We should first break social and professional settings up into different categories. Each of these categories are going to have different sub-levels as well.

  1. Home - This is where you reside or spend time with close friends. Out on the patio grilling and drinking beer, playing video games, or binging on Netflix. You are free to act as asinine as you want with little to no repercussions to your actions. Of course there are rules of conduct at home, just like anywhere else. You don't wear your shoes on the carpet, you need to rinse your dishes, but you can still lounge around in your underwear with your hands down your pants with no judgement or impact to your overall path in life.
  2. General Public -  Obviously a step above the home life. You wear respectable clothing depending on where you're headed. A 5 star restaurant will demand different attire and attitude then waltzing into Walmart at 3a.m., but they are still in view of strangers of different backgrounds and situations. You'll speak with a little more clarity, as inside jokes and rules from home aren't widely known to the rest of the masses.
  3. Professional Event - There are so many different sub-levels of professional events. You may be an industry leader at a very formal suit & tie event, or it could just be a local meetup of peers. At any level there is a certain amount of professionalism and tact that others will associate with you based on your words, how you dress, your demeanor, and actions. I've had soooo many conversations with people and with people in the same room as me that were insanely smart and helpful. How you act could be the difference in them blowing you off or offering you a job, book deal, or other opportunity.
  4. Workplace - Again, so may different sub-levels depending on the industry you work in, your role, and the company you work for. Over the last several jobs I've had there are vastly different rules as to what is and isn't appropriate. Sometimes I've had to cover up my tattoos, in other positions I could have had a face tattoo and bright pink hair with not even a second glance. So many decisions are based on how you read the situation. While I believe the majority of at least the USA is becoming more liberal in regards to judging people based on how they look, how you act and speak is still going to be a reflection of your persona overall. If the same person walked in to talk to an executive, to apply for a job, to sell a widget, or whatever....one time wearing a well fit suit and tie & speaking intelligently and the next time came in wearing last night's clothes and talking like a hoodrat, who makes the better first impression? I don't give two shits if they can accomplish the exact same thing, because perception matters!!
  5. Social Media - Now Social Media is where it can get super fuzzy. There are a million different types of platforms for different reasons. While there are still private groups and direct messages you should always be aware that no matter how private it is, there is always the possibility of what has been written or shared to be shown publicly at any point in time. Whatever is on the internet stays there forever. You can actually break up social media into the 4 categories above. However it still all depends on context. I personally have a fairly open Facebook account, filled with a lot of different infosec people. Additionally I have security groups setup according to levels of trust. While this helps to a certain point, there's nothing stopping someone from taking a screenshot of anything that I might post and sharing it publicly or privately without me knowing. I have a public Twitter account as well, composed of a majority of information security professionals at different levels. I expect everything that I tweet to be seen by my employer, future employer, friends, family, and obviously the NSA. I personally try to keep it a good balance of quality content mixed with my own ranting and raving. However there are industry leaders that may only post on their infosec specialty. They are a higher content to crap ratio and will end up with a higher following and potentially better business and opportunities because of it.
Below is a list compiled from Twitter and Facebook of almost everything I've been sent. I've broken it up into "slang" and "industry annoyances". Either list should be used sparingly unless you're at home, at that point I don't really care what you say or how you say it. Slang is best suited for at home or depending on your end goal or personal situation could be used in the workplace or social media (again, in moderation). The industry annoyances come from the repetitive sales meetings, conference calls, and overall professional bullshit that most of us have to deal with daily. I personally think the terms listed here can have their place (in moderation....repeat much?) in making thoughts and strategy well articulated.


  • Slang

    • AF
    • Amazeballs
    • Bad boy
    • Bae
    • Bigly
    • Boi
    • Boo
    • Buh
    • Cray
    • Dope
    • Ehrmagerd
    • Fam
    • Fleek
    • For realz
    • Gucci
    • Hashtag
    • IKR?!
    • Ktksbai
    • Like a boss
    • Lit
    • Literally can't even
    • Make some noise
    • Mos def
    • Please 1) check yourself before you 2) wreck yourself
    • Rekt
    • Right?!
    • Salty
    • Savage
    • Swag
    • Thic
    • Thot
    • Totes
    • Triggered
    • Turnt
    • Woke (in any form)
    • Yo
    • Yolo


  • Industry Annoyances

    • "50 shades of X" (Play off of 50 Shades of Gray)
    • "Make $noun $adjective again" (Play off of Make America Great Again)
    • "training" as a countable noun
    • Actually
    • All intensive purpose
    • And that being said
    • Any form of "splaining"
    • At the end of the day
    • Basically
    • But do you?
    • Circle back down the drain
    • Cyber
    • For fun and profit
    • Gartner
    • Having said that
    • If you will
    • Irregardless
    • Just so you know
    • Obviously
    • Per se
    • Please advise
    • Simply
    • Sun Tzu quotes
    • To be honest
    • To your point
    • Touch base


A special thanks to @haydnjohson for the insight

Other stuff from my amazingly stylish friend @Cyb3r_Assassin
https://www.wsj.com/articles/why-dressing-for-success-leads-to-success-1456110340
https://www.facebook.com/gqstyle/videos/10154695302463658/?hc_ref=SEARCH

Wednesday, May 25, 2016

Getting your foot into the infosec door

Time and time again I have the discussion with my peers about mentoring and a starting a career in infosec. I’ve been asked my opinion, what I’ve personally done, and what others can do to be successful. Recently there was a panel discussion held on the subject of infosec careers at a Michigan Security group called #MiSec. It covered a large range of information such as mentoring, networking, contributing, and attitude. For a good write up on the session itself you can visit  https://blog.greenjam94.me/path-dark-side/.

It is said that the lazier the tech worker, the harder they work to automate tasks. My goal is to put down my thoughts in this article to point others to for a beginner guide of my recommendations. While it’s only driven by my personal experience and observations, it seems valuable to enough people to warrant it’s own automation.
So a fast primer on how I got here. Like most people I wasn’t born into information security. I’m what you would consider a late bloomer to technology compared to most. I had plans on joining the Marines and when that didn’t pan out for personal reasons I thought to myself “Hey I’m decent with computers, I’ll do that!”. I didn’t have my first tech job until I was almost out of college. I had gone for my 2 year “Helpdesk” degree at a local tech college and honestly had no idea what I had just learned or how to apply any of it to the real world. After 5 years at various helpdesks and another 5 as a network/systems admin I was finally introduced into the world of infosec. I had no idea that it was an entire subculture.

My first toe step into infosec had come from a project that a friend had gotten me involved in. Being an overachiever, I had jumped in right away and started to work on this project. Bi-monthly skype meetings, shared documents, collaborating with people I barely knew. I was loving it! Shortly after that the project owner killed it but I had already started the ball rolling in my mind. I knew that I wanted to be a part of more than just a 8-5 job. I cared immensely for the work I was doing day to day and I wanted to continue and expand upon that to help out as many people as I could. Even being involved in a project that didn’t go anywhere gave me the drive and experience I needed to realize that there was so much more out there that I could be involved in. So that is my first piece of advice. Find or create a project. It doesn’t matter what your skillset is, there *will* be a project out there that needs help. Documentation is needed on 99% or more of the open source projects out there. If you’re good at scripting or programming find a need and fill it. It may help you in your day to day job, or maybe it’s just a fun project that you do on the side. Either way you are spending your time on something useful that could end up helping save time for someone.

My second piece of advice is volunteer and participate at an information security conference and attend local meetups. There are hundreds of them across the US and they almost always need volunteers. Just attending a conference has it’s benefits, but truly immersing yourself will push you further to learn and experience more. Maybe you saw someone give a talk or training on something or overheard an interesting conversation. Many careers have been started by having a simple conversation about a passion over lunch or a beer. Remember those projects that I talked about working on before…...a great ice breaker. Networking is a game changer in our industry. I’m not saying that it’s the silver bullet for everyone. You can network all you want, but unless you are a desirable candidate it won’t matter. Having a willingness and desire to learn, listen, collaborate, and the ability to think for yourself are all ideal traits in such a fast paced industry. Others will want to work with you if you are a positive person that they can rely on and trust. You can also join a team for a capture the flag (CTF) or other competition, attend training, or maybe even create your own event. CTFs are a great way to challenge yourself and build problem solving skills. You can learn by watching and competing with others.

Another item to add to your “to-do” list should be to either find or be a mentor. Mentorship can come in many forms but is not just going to be solutions and information handed to you on a silver platter. If someone is offering to mentor you, they are doing it for free with their extra time, so don’t screw it up. Remember, they don’t owe you anything. Mentoring can be extremely rewarding for both parties and also can occupy a lot of time depending on the level of commitment. Try to find someone in a different company so you can bounce ideas off of each other from different perspectives. You don’t have to have a strict career path to be mentored. With so much information in infosec having a broad understanding of any piece of it will help you down the road.

While a career in information security could be an 8-5 job, to excel in it won’t be. I think it’s safe to say any career can be made into an 8-5 without personal and professional drive and commitment. You are going to get a return on investment only on the work that you put into it.

Tuesday, September 30, 2014

My first year of cons - Knowledge and Squishy Feels

Last year DerbyCon 3.0 was my first hacker con ever, and I just sat down from a long week at DerbyCon 4.0. In this year I've now been to 7 total. I've gone from a lowly attendance goer with no clue of who anyone was and zero self confidence to a conference organizer, blog writer, speaker, and volunteer with 0.1% self confidence. It's been an amazing journey of learning, networking, experience, and fun.

My first DerbyCon got me hooked. I was in somewhat of a volatile and unhealthy relationship at the time (now looking from the outside in) and the only way that I was "allowed" to attend was the fact that Dave Kennedy (founder of DerbyCon) had given me a free ticket to attend. I spent the entire con moving from talk to talk, taking notes, not actually speaking to anyone much (lest I get in trouble). The moment it really hit me that this is where I belong was during the DerbyCake CTF (capture the flag) Challenge. I was working solo into the early morning hours on different challenges, even though I was not even close to being as technical to the other people in the room competing or the organizer Rob Fuller (mubix). The amount of help, comradery, and just good fun that we all had in that room just opened my mind and made me realize what I wanted to do in life. I walked away from that CTF with some amazing knowledge and some great friends. That led into the closing ceremonies where I saw what amazing and giving people they all were. It was a true family!! I could totally be a part of this!!

The person inside of me that had been lost and oppressed was awoken, which sped up the decline of my marriage. Shortly after this I was given the (false sense of a) choice between my career and my marriage. I still believe that I made the right move. Going after a career that means so much to me shouldn't be mutually exclusive to a relationship. If you'd like the long story sometime just let me know. I spent such a long time in a state of depression and anxiety that I had started on some anti-depression and anti-anxiety medication about 4 months prior. The meds helped a lot with my internal struggles. I wouldn't be where I am today without them and the infosec community.

After my husband and I split up (a week following derby) I dove headfirst into the community, working, and learning. An article I wrote transitioned into me submitting my first, second, and third CFPs (call for presenters); being accepted to speak and volunteering for CircleCityCon. CircleCityCon was my fourth con ever. I enjoyed volunteering so much for BsidesNash that I volunteered for that as well and submitted to speak. I had some of the things go through my head that so many others have. "Who wants to hear what I have to say, I don't know anything!!" My friends pushed me to go for it. I had to start somewhere. CircleCityCon needed more help after I volunteered so I became an organizer and plan on doing so again next year.

At my second con, Bsides Columbus, I was still super shy and didn't really talk to many people. Fast forward to BsidesNash I met some amazing people, had Raf Los convince me to ride a mechanical bull, and met some people in person that I had known online for awhile. I thought I was going to just wait until DerbyCon for my next con after that. Which I was ok with. It's way worth it. After all I did get an anonymous donation to send me to training. That was something that just blew my mind. Someone, somehow, figured out I was interested in becoming a pentester and wanted me to realize my dream. Instead of waiting for derby my friend tehExodus decided to start a crowdfund for me so I could go to my first DEFCON. Even though I was starting to get a grip on my place in the community, DEFCON is still something that was a little intimidating. Really just from the stories I had heard; creepy dudes, no family vibe like derby, Vegas craziness. I signed up right away to volunteer for BsidesLV. Volunteering is a great way to meet people, learn the behind the scenes of a con, and contribute back to the community. BsidesLV and DEFCON were both amazing. I had a great time at a lot of different parties, workshops, and CTFs. I didn't have a single issue with creepy dudes, rockstars, or rude people. I am forever thankful for the people and friends that donated to me so I could make the trip.

A close friend of mine told me that the reason that it works so well and we feel so close to each other is that many of us are broken. We are broken in different ways. Whether it be from bad relationships, to medical/physical/psychological/emotional issues, to clinical depression, to a whole range of other brokenness. I guess in summary I just want to point out that we all have a starting point. Sometimes we'll be lifted out of a dark and horrible place into the light among new friends. Other times we just need that nudge in the right direction of where to start. Either way, welcome to our community, I can't wait to see what this next year brings!!

A special thanks goes out to Dave Kennedy (@HackingDave), Rob Fuller (@mubix), Steve Loughran (@z0rlac), Adrian Crenshaw (@irongeek_adc), Josh Louden (@tehEx0dus), Bill Garder (@oncee), Nate Husted (@DrWhomPhD), Jason Samide (@jason_samide), Michael Smith (@drbearsec), Ben Ten (@Ben0xA), Michael Cooley (@irishjack), DerbyCon (@DerbyCon), CircleCityCon (@CircleCityCon), BsidesNash (@BsidesNash), BsidesLV (@BsidesLV), Defcon (@_defcon_) and every other person that has helped me realize that I have potential, helped me through the bad times, and have made me feel welcome.

Wednesday, August 7, 2013

Hello World

Creating this blog to document some of the practices, procedures, and tech solutions that I've put into place working in Healthcare IT and IT in general.

I'm a n00b at a lot of things, especially anything *nix related. But through Twitter, Vimeo, and a load of other online help I'm getting a little smarter. One step at a time. :)

You can follow me on Twitter @Infosystir