Alex Stamos to Become CSO of Facebook
facebook.com
facebook.com
Here's the Q&A and while I do think the intelligence community actually does some decent work on occasion, the kind of doublespeak displayed by Rogers here is what really gives the IC a bad name and has lead it down bad paths. https://www.youtube.com/watch?v=TjL1WYhLx-M
I'd also very much encourage developers here to watch this presentation which is my personal favorite. Alex talk about some really smart ways to approach application security and why the idea of a traditional firewall is basically dead. Also some interesting stuff re moving away from virtualization towards containerization. https://www.youtube.com/watch?v=-1kZMn1RueI
Edit: Just wanted to add, I really hope he continues contributing talks to the infosec community as they're a great contribution.
Facebook is only worth 100bn because it sells peoples' personal information.
Am I jaded? Not at all. I am a realist. Facebook is primarily a monitoring tool that monetises itself on selling people's personal information.
What does that have to do with the security that Facebook has put in place to protect this info so only they can sell it? These seem like orthogonal discussions. You're arriving at the conclusion that Facebook security sucks because it sells peoples' data. That is an illogical argument.
Really, I wonder how one guy can change how a company can develop secure applications
Why the excitement?
Contrast this to Alex Stamos, who's given many presentations at Defcon/Blackhat, co-founded iSEC, EE/CS background, and it seems a bit of a mentality shift for Facebook.
I'm excited to see what Alex does since his credentials are stronger on the technology front, but the team's shift to a technology focus has been happening for a long time. I view this as another hugely positive step in that direction.
Joe had more of a legal focus, but if you think back to where FB was at the time there were significant problems with privacy/compliance, LERT and other external-facing security issues that made him a good choice. Similarly, Uber is in the position now where they need someone who can handle those aspects of company security and policy more than someone to tighten up the internal pcap analysis system...
I just commented because I wanted people to know that it wasn't like there was no software focus before Joe left--things weren't as binary as that. The software focus shift had been in progress for some time before he stepped down.
And yeah, feels good to talk about FB with no filter. :-)
Congrats to Alex.
0) Highly Technical Past. https://www.blackhat.com/presentations/bh-jp-06/BH-JP-06-Sta... < This is part of the problem space every app dev team has. 1) Great handle on technical realities and where things are going. 2) Great, clear, entertaining speaking style. 3) Articulate social media presence. 4) Doesn't come off as a security asshole.
Most companies realize they should have security at this point. Getting there is another matter. Delivering the culture and attracting the right hires from a incredibly finite talent pool is the difference in the ability to execute.
From what I've seen, his style wins over even the non-security people and he knows the technical better than most "Senior" security people. I suspect he'll have no problems filling his roles at Facebook.
For the record: my guess as to why he left Yahoo? Because he was offered CSO of Facebook.
all i can say is that in very happy. while he did a little real good at yahoo, he was mostly doing two things: promoting his name and adopting everything in sight based on cool factor without regard for hard facts.
life for people that actually know things was hell. life for the frivolous i-just-read-about-some-cool-thing-on-hn was paradise and full of bonuses.
Especially amused by the attempted "read-something-on-HN" snark. Yeah, that's where all the high-profile elite security people are these days. Hanging out on HN with me.
My impression has been that alex wants to tackle problems that are large in scale. Probably less about money and more about doing good for the most people possible.
And I worked with Chris Rolf, who is frighteningly good.
Facebook track people through IP addresses, Facebook logos, partnerships, etc. So they know what you say, what you look at, when, who you talk to etc.
If the wrong people get that data (including espionage, change of management etc), it could get VERY ugly.
It's really beyond me why anyone would sign up for Facebook nowadays. Feels like we need to reboot the Internet honestly.