- Cybersecurity News and Career Updates
Quick recap. The Cloud Security Office Hours meeting was an open forum for participants to discuss current topics in cybersecurity. Neil Carpenter began by sharing updates on his job search after his startup closed, noting positive responses from his network and ongoing interviews. The group then discussed a major data breach involving 150 million driver's licenses, expressing concerns about identity theft and the security practices of organizations. They also touched on the recent move of Anton Chuvakin and Sunil James to Cisco, seeing it as a significant development. Other topics included advice on dealing with recruiters, the use of password managers like 1Password, and the general state of cybersecurity, with many participants noting that most breaches result from basic security failures rather than sophisticated attacks. The conversation ended with well-wishes for Neil's job interviews.
Show 4 discussion topics
Cybersecurity News and Career Updates
The meeting was an open office hours session where participants discussed various topics including cybersecurity news and career updates. Neil shared that his startup is closing down and he is currently job searching, with several opportunities including potential consulting work and interviews with Wiz. The group discussed a significant data breach where 153-165 million US driver's licenses were compromised and sold on the dark web, with participants debating the implications and potential uses of this stolen data for identity fraud and financial crimes. Jay shared news about Dr. Anton Chevakin, a former Gartner analyst and Google security leader, who announced the end of Google's cloud security podcast and his move to Cisco, along with his former boss Sunil joining as well.
Driver's License and Banking Security
The group discussed security concerns around driver's license verification and banking security, with Rev sharing a concerning Reddit story about someone's bank account being taken over after their driver's license passed validation. Juninho and Neil shared experiences about seeing security gaps in customer organizations, highlighting that many compromises are caused by simple issues like missing multi-factor authentication rather than sophisticated attacks. Jay emphasized that security failures are primarily due to people and organization factors rather than lacking tools, noting that budget constraints and prioritization issues prevent many organizations from implementing necessary security measures.
Data Security and Recruitment Challenges
The group discussed challenges with data security and privacy, including recent data breaches and the increasing complexity of regulations around age and ID verification. Matt and others shared personal experiences with credit monitoring and security incidents, highlighting the growing prevalence of cyber threats. The conversation then shifted to recruitment practices, with participants discussing how to identify legitimate recruiters and potential security concerns related to fake job applicants, including the use of AI and filters. No specific decisions or action items were outlined, but the discussion provided insights into current security challenges and recruitment strategies.
Recruitment and Identity Protection Challenges
The group discussed challenges with recruitment practices, particularly focusing on untrustworthy recruiters who use spray-and-pray approaches by cold outreach to large groups of candidates. Neil advised seeking referrals for reliable recruiters and looking for specialists in cybersecurity, while warning against recruiters who pitch jobs without first understanding candidates' interests and background. The conversation also covered identity protection measures, with Jay recommending SAP's identity and credit protection benefits, and Shawn sharing his experience using 1Password's Watchtower feature to monitor dark web breaches across multiple unique email addresses. --- **Attendees:** Shawn Nunley (Organizer), Edmond Chinjo (External), Brian Smith (External), Thomas Braddy (UPS SOC) (External), Bryan Green (External), Brian Smith (External), Paola Burneo (External), Nicholas (External), Mariam (External), Eddie Liao (External), Alhaji Bah | Wiz (External), Kaye (External), james lewis (External), Don McQueen (External), Jay Thoden van Velzen (SAP) (External), Maryjo (External), Shraddha Pandya (External), Raul Reyes (External), rev darragh (External), Sam Mekailek (External), Jim Rotan (SAP) (External), Ryan Simon (External), Ryan Brio (External), Ashraf Mirza (External), Bret Friedrich (External), Frederick Fernando (External), Jeremiah (External), Junninho Thomas (External), Kate (External), piyush (External), Alex Robbins (External), Anish Adhikari (External), Temba's Notetaker (Otter.ai) (External), Carlson's Notetaker (Otter.ai) (External), Rev Darragh (External), Temba's Notetaker (Otter.ai) (External), Steve Luengo (External), Jordan's Notetaker (Otter.ai) (External), read.ai meeting notes (External), Alex Cohen (ArmorPoint) (External), Pio Salipot (External), Upvest Session Brief (External), Matt Alvarez (External), Kevin Kake (External), Ken (External), Patrick Fields (External), Nick C (External), Neil Carpenter (External)
