user avatar
Heather Adkins - Ꜻ - Spes consilium non est
@argvee
VP Security @Google, Co-Author "Building Secure and Reliable Systems" @r00t0wns, Medieval Historian
California
Joined July 2008
Posts
  • user avatar
    The cybersecurity industry shouldn’t exist. We built the internet wrong, and we can solve most of our cybersecurity problems at their root by rearchitecting technology platforms to be safe-by-default instead of buying security products.
    What's your unpopular cybersecurity opinion that gets a reaction like this?
  • user avatar
    Google’s Project Shield is being urgently expanded to govt websites at high-risk of DDoS attacks amid the war in Ukraine. 150+ websites in Ukraine are already using it. Details for how to sign up here: g.co/projectshield
  • user avatar
    I’m going to conjecture that for every hour of IR done by security staff at Twitter today, they have spent three hours advocating for the controls they wish they had but couldn’t get. </conjecture> This is why you don’t laugh when your colleagues have tough days.
  • user avatar
    Unpopular opinion: If your hobby is now responsible for running the modern world, it’s no longer just a hobby.
  • user avatar
  • user avatar
    Unpopular opinion: CISOs need to have some technical acumen to properly (1) hire the right leaders who have technical roles; (2) ask the right questions about their IT security; 3) avoid outsourcing solutions to a Kaleidoscope of useless vendors; (4) understand adversaries.
    What are your thoughts on a CISO not being technical? It’s ok if your answer is “it depends,” but if so, what does it depend on? For example, what if your CISO has never deployed a server in the cloud or can’t build a script or has never configured a rule on a firewall.
  • user avatar
    This week’s xz back door is a reminder that every open source author that works on code your org relies on, is a potential insider threat. You’ll never meet them and cannot vet them. We haven’t been solving for this.
  • user avatar
    Mr President, that's not how hacking works.
  • user avatar
    Had some fantastic conversations this week about uplifting cyber security for everyone to solve systemic issues. Sauntered through @Dulles_Airport airport on a cloud until I ran into this. Sigh. So far to go.
  • user avatar
    Today, 19 years ago, I walked past a row of lava lamps, a giant red couch, and a grand piano in the Google lobby, assembled my Linux desktop, and got straight to work. That began my journey as a Googler. Everyday since has been an honor defending our users and customers.
  • user avatar
    There are a lot of incredibly smart, hard-working women in infosec today that are solving hard problems and making your world appreciably safer, and they aren’t famous on Twitter. That’s it. That’s the tweet.
  • user avatar
    I’ll never forget @dakami called in 2008 to tell me about a DNS bug; that call gave birth to playbooks we still use at Google. I’ll never forget when I first met him, he dropped everything he was carrying onto the floor to give me a big hug. RIP Dan. You will be missed.
  • user avatar
    18 years ago today, I walked into Google HQ for my first day on the job. Every day since has been an adventure, with amazing colleagues and an inspiring mission. Thank you to everyone I’ve met along the way for making the adventure an absolute joy.
  • user avatar
    20 years ago today, surrounded by lava lamps I assembled my workstation and got to work @Google. Everyday since has been a real honor to defend billions of people online! One thing has remained constant: amazing co-workers! Can’t wait to see what adventures we find next!