6 ms·
Open Security Training: open license training material for computer security
- JDW1023 6y agohttps://twitter.com/XenoKovah/status/1336054258140139521 https://twitter.com/XenoKovah/status/1336054258140139521 The founder of OST(OpenSecurityTraining) recently tweet that he's going to work full time on OST.
- jacobwilliamroy 6y agoCool. He says he's going to do it full time for 10+ years so... Who's funding him? Where is he getting his money supply?
- deleted 6y ago[deleted]
- enjoyyourlife 6y agoCompanies pay him to give in person classes and create customized training material
- jacobwilliamroy 6y agoWhich ones? Is he funded for the next ten years? Did he take out a loan for 10+ years of expenses?
- deleted 6y ago[deleted]
- lilSebastian 6y agoWouldn't it make sense to ask him rather than post these questions here?
- jacobwilliamroy 6y agoI don't use twitter
- lilSebastian 6y agoThere's an info@ email address listed on the website
- White_Wolf 6y agoIsn't that a bit too private to ask from a random person to a random person? Even if he would ask for donations to keep it going, disclosing other revenue streams is a bit much to ask for someone not involved in the project.
- jacobwilliamroy 6y agoI'm only curious. I don't actually care if I ever find out. Never hurts to ask.
- tertius 6y agoTrying to understand revenue of a business (i.e. what this guy is doing) is a cornerstone of HN. I'm surprised by the blowback your're getting. Maybe it's your tone. Maybe start with: "I've always wondered how the economics of this work, how would he survive? How can someone replicate this model?"
- jacobwilliamroy 6y agoThey're getting suspicious, I guess. Here's what I know about funding these sorts of activities: Greenpeace started out selling shirts and buttons and things which had a pretty quick turnaround. Then they began signing up middle and upper class people to donate $10+/mo regularly. At present greenpeace has at least a million such monthly donors of $10/mo or more. As the years wore on and they became famous, wealthy people began willing their estates to Greenpeace. It was all driven by their media and communications machine: iconic images of men and women in orange jumpsuits riding zodiacs into a hail of soviet whaler bullets and harpoons just to protect endangered whales. Of course this was pre-internet so their media was distributed by mail and telex. Greenpeace has probably spent millions on postage alone by now. I feel comfortable sharing this knowledge because just knowing this is not enough to actually make a difference in the grand scheme of things. Even if OST gets funded, without a good lawyer this Xeno Kovah person could easily have it all stolen out from under his nose in an instant. Or the other members of his organization could turn on him and purge him. Or his board could just choose to ignore his vision and completely change the direction and shape of OST. More money, more problems. All the money in the world won't make a difference if you don't have any skills managing such a large sum. And it's hard to find mentorship for such things because usually, consistently, your mentor will decide that you are dead weight and THE MENTOR should be in charge of the whole enterprise, not you. It takes much more than just money to succeed. So I feel completely comfortable discussing fundraising techniques.
- tertius 6y agoAh, so those who responded to you were correct in their assessment? Be honest about it before you start asking questions to trap the person you're asking. It goes a long way.
- OpenSecTraining 6y agohttps://twitter.com/XenoKovah/status/1336325340524789763 https://twitter.com/XenoKovah/status/1336325340524789763
- fsociety 6y agoAmazing! Xeno if you are reading this, would happily contribute a small amount of cash monthly for this :)
- cheschire 6y agoI wish computer security training included courses on avoiding or destroying the bureaucracy that seems to inevitably form around cybersecurity dogma. COVID was a lightning rod and channeled a lot of technological advances through that would’ve been otherwise halted by the cyber hand wringers who seem to have infiltrated all approval processes.
- ThrowItAway2Day 6y agoI agree that it's unfortunate that security and bureaucracy go hand-in-hand. As security becomes more a priority, the annoying overhead grows with it. However, I think this is just the nature of security. It's a cumbersome task. Think of any organization that security is very important to, especially where it is life and death. Military, government, criminal gangs, VIPs/executives. All have large bureaucracies to maintain and enforce security. I think the adversaries any of these groups face are so persistent and capable that the only answer is bureaucracy. Training the person can only go so far. Individuals alone are too susceptible to minor slips in operational security. If a small company that isn't targeted by advanced persistent threats has such a bureaucracy, it's overkill.
- cheschire 6y agoThere's a difference between defense in depth and bureaucracy. One recent example I saw was prioritizing the re-evaluation of a system that is low impact and limited access over the remediation of issues on a widely accessible system, only because the low impact evaluation was going to be out of tolerance sooner and therefore look bad on report cards.
- tptacek 6y agoIt drives me nuts that people think the right way to teach cryptography and "cryptanalysis" (I'd say: cryptographic vuln research) is stuff like differential and linear cryptanalysis, or, for that matter, index calculus. Practically nobody is going to use that stuff; it's just the stuff that's been in textbooks for 20 years, and so people assume they need to teach it. How far into this do you get before you learn how CBC bitflips work? Trick question! It's never covered. The cryptanalysis slides are from 2013, sure, but CBC padding oracles were already passé by then. It just makes me feel like people aren't taking the subject seriously. Which is how a lot of this courseware reads to me! A recitation of random facts.
- mikevm 6y agoWhich resource(s) would you recommend for someone who wants to learn crypto?
- indigochill 6y agoDisclaimer: I have zero professional crypto experience. That said, my hypothetical crypto curriculum looks like this: 1. Cryptopals challenges as a guide to what to learn and pay attention to (which I suspect tptacek would probably recommend as well since he had a hand in making it :P) 2. Serious Cryptography as an introduction to core concepts 3. Applied Cryptography for encyclopedic reference
- tptacek 6y agoNot a fan of Applied Cryptography: https://sockpuppet.org/blog/2013/07/22/applied-practical-cryptography/ https://sockpuppet.org/blog/2013/07/22/applied-practical-cry...
- JshWright 6y agoIf you learn well in a self directed "hands on" fashion, https://cryptopals.com/ https://cryptopals.com/ is a good place to start. (Co-created by the person you're responding to)
- 6y ago
- vips7L 6y agoThis is how I learned x86 assembly! It was such a fun course to take.
- caniszczyk 6y agoThe OpenSSF released a bunch of free courses on security: https://openssf.org/press-release/2020/10/29/open-source-security-foundation-announces-education-courses-and-participation-initiatives-to-advance-its-commitment-to-securing-the-worlds-software-infrastructure/ https://openssf.org/press-release/2020/10/29/open-source-sec...
- dwheeler 6y agoThere's a set of 3 free courses on secure software development fundamentals developed by the Linux Foundation Open Source Security Foundation (OpenSSF). Just go here: https://www.edx.org/professional-certificate/linuxfoundationx-secure-software-development-fundamentals https://www.edx.org/professional-certificate/linuxfoundation... For a fee you can also take tests to earn certificates. Full disclosure: I developed these courses (with lots of gratefully-accepted feedback). But I hope you'll like them anyway :-).
- gnunez 6y agoAny opinions on "The Handbook of Applied Cryptography". Is this information still relevant? https://cacr.uwaterloo.ca/hac/ https://cacr.uwaterloo.ca/hac/