(and yeah, I have an M4 and 3 Turkish knockoff M4s (1 great out of the box, one I fixed up, one which doesn't love to eject but I can probably fix), and the 2 x 1301s I own are better.)
39,339 karma · joined July 8, 2008
Chief Security Officer for Evertas Insurance -- the world's first cryptoasset insurance carrier. https://evertas.com/
Previously, CEO and Co-Founder of CryptoSeal (YC S11), which was sold to CloudFlare on 2 June 2014. CISO/Board Member of Tezos Foundation 2018-2020.
Previous startup founder (HavenCo, a couple ecash projects, distributed colo, and DoD/Iraq contracting, new thing), too. Deeply interested in computer security, infrastructure, security, conflict zones, and making the world a better place.
Aside from living on a Caribbean island during crypto export controlled 1990s, I've lived on a tiny artificial platform in the North Sea, plus more reasonable places like London, Amsterdam, Iraq, Afghanistan, Kuwait, and spent 6 months diving in Thailand.
"I, the greengrocer XY, live here and I know what I must do. I behave in the manner expected of me. I can be depended upon and am beyond reproach. I am obedient and therefore I have the right to be left in peace."
Email: ryan@venona.com (etc) Twitter: @octal https://twitter.com/octal LinkedIn: http://www.linkedin.com/in/ryanlackey
Top color: aaaaaa
(and yeah, I have an M4 and 3 Turkish knockoff M4s (1 great out of the box, one I fixed up, one which doesn't love to eject but I can probably fix), and the 2 x 1301s I own are better.)
Looked like 5-10g (maybe up to 20g?) of explosive, NOT battery. I think you could fit the whole package inside an AA battery, along with an AAAA battery, so you could do something crazy there, or just replace a rechargeable battery pack with something of smaller battery capacity containing the explosive, some electronics, etc. Or just use spare volume inside the case and hope no one does gross physical inspection.
Assuming the Berlin patents have expired, a visible light or "night vision" near IR camera made from commodity sensors and on-device stitching is about $100-200 BOM which could be a $500 premium cat toy (and thus actually affordable as a tactical tool for users other than funded US/EU police). I've been finding gear for community safety guys in South Africa and it is amazing how much can get done with cheap consumer gear now.
Museum of Computing was extra amazing because some of the volunteers had worked on the hardware on display (and I'd worked on stuff 20 years after that), so we were able to talk about the actual hardware/OSes.
Just being a citizenship bar, even if it did nothing else, really complicates hiring in tech -- what you often end up doing is having as much work as possible done uncleared/commercially and then thrown over the wall to cleared people who can implement it with the client. Works well in infosec with mostly systems integrated with commercial stuff; doesn't work with jet engines or missiles as well
Clearances being handed out like relative candy to 18-28 year olds in the military (so, for someone like Manning, approximately zero information responsive to requests (as minor records excluded, and the 7-10 year lookback isn't relevant when you have far fewer adult years), extreme reluctance to suspend or revoke a clearance when granted), and ineffective reporting of incidents.
The hassle of holding a clearance to some extent depends on the issuing agency/level (DOD Secret is relatively non-hassle; law enforcement ones are more lifestyle focused on paper at lower levels; substantial travel restrictions for levels/programs come in above Secret too).
There is also the difference between official restrictions and reality -- given OPM hack and general government incompetence, it's safe to assume your info becomes public or at least known to adversaries, so even after a clearance expires, it would probably be unwise to travel to some countries for a much longer period. Also exposes your family/other contacts to hassle from both USG investigators and potential foreign adversaries.
Then hacker conferences like defcon have their own volunteer staff of various kinds. These usually are doing crowd control and information, but occasionally get involved in attendee drunken or stupid incidents, usually with lesser consequences to attendees.
Some high profile attendees (NSA head, John McAfee, etc) have their own personal security; goons/volunteers then worked as a buffer between those people and attendees. (I did this for a McAfee event at BSides which was super fun because his armed security were also high on methamphetamine and erratic)
(Obviously doing crowd control, providing information, and front line emergency response is absolutely fine, although tbh even that they should probably have guard cards in most jurisdictions for liability reasons. If someone is violently disruptive, as a private citizen go for it, but unauthorized speaking on stage is pretty far from that. Would be hilarious if dude makes more money from that than he was stiffed by his employer.)
(Also lol I did the 2013 glitter nail polish talk w Eric Michaud. I feel old now.)
CIA has the main seals defeat capability in USG.
Another aspect are all the cartel-like programs of banks overall (and the banking regulators) to keep even well-capitalized fintechs from offering these services directly. For e.g. Mercury they could probably be entirely fine without the high debit card fees.
There are a bunch of things where I'd rather wait 8-24h at home, even in pain, than go to an overloaded emergency room.
For me, I'm definitely putting more effort into things I'm relatively skilled in (both inherent, and due to prior work/historical advantage/access/etc.). Also stuff with the highest return on effort for the amount of effort I'm reasonably likely to put into it (so, something which requires 100 hours to get any result is still possibly ok, but something which requires 4000 hours/yr for 10 years to get any result is much less interesting; something which requires 4000h/yr for 10 years but with incremental rewards, maybe.
Also helps when interests are clustered -- I like hardware, and security, and infrastructure, and crypto, and finance, and satellites, and communications, and military/next gen drone stuff, and interesting legal and jurisdictional arbitrage, and there's a lot of crossover among those, more so than adding other interests outside of that galaxy like art.
Keeping enough spare time/other capacity to take advantage of opportunities as they come up is good, too. e.g. I'm interested in semiconductor fab stuff, but not at a deep professional level doing anything in it, but when I get a chance to work on (security, infra) in that context, I jump on it.
HDHP plus great price transparency (especially pre service, where one can potentially cross-shop providers, vs. being in a facility and given only one option) would be good for cost reduction; if you can't surface and measure the costs, you won't have any incentive to lower them.
I personally have a fairly mediocre $230/mo blue cross plan in Puerto Rico which largely only covers care within Puerto Rico (and which I've never actually used for anything), and rely on medical tourism where I pay 100% out of pocket, and until Amazon bought them, OneMedical for cheap clinic care which I also paid 100% out of pocket. I previously had a WA state HDHP for $100-200/mo pre-ACA which was great but ACA killed those/insurers left the state.