I recently read the book Decisive by Chip Heath and Dan Heath. This is one of the better growth books I've read lately, because it nicely combines scientific truths with actionable guidelines. Most growth books are either purely motivational, repeating shallow inspirational mantras with small tweaks, or they present solid logic that explains how things could be better, just without much hints on how one can put this logic into practical use. This book, on the other hand, explains well-substantiated pitfalls in our decision-making logic and also offers simple mental hacks to help us overcome those pitfalls. I also liked that each chapter concludes with a single-page summary that makes it easy to recap what was taught and the conclusions of each chapter. I find this immensely useful because I'm the type of person who reads very little each day, and not every day, so reading a single chapter can sometimes take me weeks.
The rest of this post lists my key takeaways from this book.
Continue reading "Book review: "Decisive""
I recently read a good essay by Alex Gantman titled: “A Corporate Anthropologist’s Guide to Product Security”. It's a year old, but I did not notice it before, and in any event, its contents are not time-sensitive at all. If you're responsible for deploying SDLC in any real production environment, then you are likely to find much truth in this essay.
Continue reading "Recommended: A Corporate Anthropologist’s Guide to Product Security"
Every company that has both development teams and security teams also enjoys a healthy amount of tension between them. Specifics of the emotions involved may vary, but quite often security guys see developers as: not caring enough about security, focusing on short-term gains in features rather than on long-term robustness, and all-in-all, despite best intentions, still not “seeing the light”. Developers, in turn, often see their security-practicing friends as people with overly intense focus on security, which blinds them to all other needs of the product. They sometimes see those security preachers as people who maintain an overly simplistic view of the product design, and particularly of the cost and side-effects of the many changes they request for the sacred sake of security.
People of both camps are to a certain extent right, and to a certain extent exaggerating and not giving the other side enough credit. And yet, it doesn't even matter where the truth lies, nor if there is truth at all. What matters is that there are two groups that are both essential for product success, and which should work towards a common goal: a product that has many appealing properties, including security.
The rest of this post presents tips for proper collaboration between security and development teams, specifically where it comes to setting and implementing security requirements. Due to my default affiliation with the security camp, the actions I prescribe are targeted primarily at the security people, but I hope that both developers and security practitioners can benefit from the high level perspective that I try to convey in the following five tips.
Continue reading "Getting security requirements implemented"
A few months ago I read an interesting post, which I felt compelled to write about. The post titled “Australian Court determines that an Artificial Intelligence system can be an inventor for the purposes of patent law” tells exactly what its title denotes. The case in question comes from the drugs industry, which has always been an avid user of the patent system, but one can easily see how the verdict can be applied to many (if not all) patent areas as well.
The article reads:
“In Australia, a first instance decision by Justice Beach of the Federal Court has provided some guidance: pursuant to Thaler v Commissioner of Patents (2021) FCA 879, an AI system can be the named inventor for an Australian patent application, with a person or corporation listed as the applicant for that patent, or a grantee of the patent.”
Worldwide, this is the first court decision determining that an AI system can be an inventor for the purposes of patent law.”
“The UK Intellectual Property Office (UKIPO), European Patent Office (EPO), and US Patent and Trademark Office (USPTO) each determined that an inventor must be a natural person.”
An appeal process is still ongoing, but this judgment still serves as an important milestone in the anticipated future of artificial intelligence, which bears enough resemblance to traditional human intelligence to demand similar treatment, first as art, and now also as the subject of patents.
I must admit that when I first read this article it seemed to me as a joke, and even a funny one at that. However, as I kept thinking about it, it made more and more sense. The purpose of this post is to take you through my thought process.
Just note that I am not a lawyer, not a patent attorney, and only express an opinion as someone who's nowhere close to being authoritative on the subject.
Continue reading "Patents invented by Machine Learning"
I recently got a US patent application granted by the US Patent and Trademark Office. The patent bears the title “System, Device, and Method of Managing Trustworthiness of Electronic Devices”.
Continue reading "My new patent on device trustworthiness measurement"
On July 12th, I was interviewed on Security challenges of organizations deploying IoT. The recorded (and transcribed) video interview can be found here. For those who prefer a written abstract, here is the outline of what I said in reply to a short set of questions about the security challenges with IoT deployment, and the approach followed at Pelion to overcome them.
Continue reading "An interview on security challenges of organizations deploying IoT"
I recently participated in a discussion about the role of machine-generated text in the spread of fake news.
The context of this discussion was the work titled: How Language Models Could Change Disinformation. The progress made by the industry in the area of algorithmic text generation has led to concerns that such systems could be used to generate automated disinformation at scale. This report examines the capabilities of GPT-3 — an AI system that writes text, to analyze its potential use for promoting disinformation (i.e., fake news).
The report reads:
In light of this breakthrough, we consider a simple but important question: can automation generate content for disinformation campaigns? If GPT-3 can write seemingly credible news stories, perhaps it can write compelling fake
news stories; if it can draft op-eds, perhaps it can draft misleading tweets.
Following is my take on this.
Continue reading "Machine generated content helping spread fake news"
On May 12th, the Biden administration issued an Executive Order that was written to improve the overall security posture of software products that the government buys from the private sector. Recent events, such as the SolarWinds hack, contributed to the realization that such a move is necessary.
This Executive Order is a big deal. Of course, nothing will change overnight, but given the size and complexity of the software industry, as well as the overall culture behind software security (the culture of: “If the customer doesn’t see it — don’t spend money on it”), an Executive Order can probably yield the closest thing to immediate improvement that we could reasonably wish for. The US Government is a very large customer, and all major vendors will elect to comply with its requirements rather than cross it all off their addressable markets.
A lot has been written on how important it is for the government to use its buying power (if not its regulatory power) to drive vendors into shipping more secure products. Product security suffers from what could best be described as a market failure condition, which would call for such regulatory intervention.
To not overly repeat the mainstream media, I would like to focus on one unique aspect of the current Executive Order, and on how it can ignite a new trend that will change product and network security for the better. I’ll discuss true machine-readable security documentation.
Continue reading "One blessing of the Cybersecurity Executive Order"
I've been listening to the Risky Business security podcast for several years now, and mark it as among my favorite security podcasts, if not my favorite one. There are a few good security podcasts out there, but this is the one I listen to most rigorously, i.e., without missing an episode. Here is what makes this security podcast stand out.
Continue reading "Recommended Podcast: Risky Business"
The book Essentialism: The Disciplined Pursuit of Less, by Greg McKeown, carries a very important message: you shall not seek to do more, but rather to do less things, but do the ‘right’ ones. When people succeed in life (even moderate success), they are encouraged to do more and hence de-focus. In general, our society promotes the concept of doing more and more, which makes it hard for us to just say ‘no’ to additional commitments, even if those commitments invoke activities are not within our priorities. As Greg McKeown nicely puts it: if you don’t prioritize your life, someone else will.
Continue reading "Book review: "Essentialism: The Disciplined Pursuit of Less""