# information-security

Published articles for information-security.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## My Career Pivot: From IT recruiter to information security

DevFeed: [My Career Pivot: From IT recruiter to information security](<https://devfeed.tech/articles/my-career-pivot-from-it-recruiter-to-information-security-32387.md>)

Original publisher: [Read original article](<https://medium.com/@SkyscannerEng/my-career-pivot-from-it-recruiter-to-information-security-cf955ca39d24?source=rss-401f3b3c958f------2>)

Author: Skyscanner Engineering

Published: 2022-06-24T08:08:19Z

Content type: article

Language: en

Sources: [Stories by Skyscanner Engineering on Medium](<https://devfeed.tech/sources/stories-by-skyscanner-engineering-on-medium.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [career](<https://devfeed.tech/tags/career.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [female-engineers](<https://devfeed.tech/tags/female-engineers.md>), [information-security](<https://devfeed.tech/tags/information-security.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [women-in-tech](<https://devfeed.tech/tags/women-in-tech.md>)

### AI overview

This profile follows Maria Sepulveda's career transition from customer service and IT recruitment into information security. As a Senior Security Engineer at Skyscanner, she discusses her role, career development, and responsibility for leading the recertification of the company's PCI DSS compliance.

### Source excerpt

Senior Security Engineer Maria Sepulveda As we celebrate International Women in Engineering Day this week, we're profiling female-identifying engineers across our business. Maria Sepulveda is a Senior Security Engineer at Skyscanner. An expert within information security, Maria led the recertification of Skyscanner's PCI DSS (Payment Card Industry data Security Standard) compliance. Maria took an unconventional path to information security, starting her career in customer service and IT recruitment. Here, she discusses her journey, imposter syndrome and what her role looks like today. Maria, as a Senior Security Engineer, what does your role involve? Well, I only recently joined Skyscanner so a typical day for me today might look different to a typical day in a couple of months time! Having said that, I have already been given responsibility to lead the recertification of our PCI-DSS compliance. It's great that I can be trusted so early on in my Skyscanner journey. My day typically starts with following up on tasks that are due in the coming week. During the day I meet with people and various teams to understand what they do. I'll also attend internal events, often to better understand the Skyscanner culture and the way things work here -- as well as to make connections. Focus Time in the afternoon allows me to re-read my notes and absorb information I obtained during the day. The day might end with a recap of the day with my team, allowing me to ask questions I haven't already asked or just generally talk about how the day went. What was your career journey to this point? I took an unconventional path into information security. Originally from Australia, I worked in customer service roles and IT recruitment. I arrived in London and found a job working at an in-house recruitment team for an online betting company. I knew that I wanted to move into a more tech-focussed role but still interfacing with the business. My colleague who was recruiting for the security team

## A Vulnerable System

DevFeed: [A Vulnerable System](<https://devfeed.tech/articles/a-vulnerable-system-36655.md>)

Original publisher: [Read original article](<https://shostack.org/blog/a-vulnerable-system/>)

Author: Adam

Published: 2021-09-13T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Computing](<https://devfeed.tech/topics/computing.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [book](<https://devfeed.tech/tags/book.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [history](<https://devfeed.tech/tags/history.md>), [information-security](<https://devfeed.tech/tags/information-security.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

A review of Andrew J. Stewart's book A Vulnerable System, which traces the history of computer security and examines why the field's recurring problems, guiding mantras, and narrow debates remain relevant today.

### Source excerpt

Andrew Stewart has an excellent new book, A Vulnerable System.

## Apple Guidance on Intimate Partner Surveillance

DevFeed: [Apple Guidance on Intimate Partner Surveillance](<https://devfeed.tech/articles/apple-guidance-on-intimate-partner-surveillance-36671.md>)

Original publisher: [Read original article](<https://shostack.org/blog/apple-guidance-on-intimate-partner-surveillance/>)

Author: Adam

Published: 2021-05-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [apple](<https://devfeed.tech/tags/apple.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [information-security](<https://devfeed.tech/tags/information-security.md>), [safety](<https://devfeed.tech/tags/safety.md>), [surveillance](<https://devfeed.tech/tags/surveillance.md>)

### AI overview

The article examines Apple's "Device and Data Access when Personal Safety is At Risk" guidance for reviewing and changing access to devices, accounts, shared information, and location. It connects intimate partner surveillance with information-security challenges and argues for a cybersecurity public health discipline that complements traditional information security.

### Source excerpt

Apple has released 'Device and Data Access when Personal Safety is At Risk' and I wanted to explore it a bit.

## CyberSecurity Hall of Fame

DevFeed: [CyberSecurity Hall of Fame](<https://devfeed.tech/articles/cybersecurity-hall-of-fame-36752.md>)

Original publisher: [Read original article](<https://shostack.org/blog/cybersecurity-hall-of-fame/>)

Author: Adam

Published: 2018-08-06T00:00:00Z

Content type: news

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Computer science](<https://devfeed.tech/topics/computer-science.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [computer-science](<https://devfeed.tech/tags/computer-science.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [des](<https://devfeed.tech/tags/des.md>), [information-security](<https://devfeed.tech/tags/information-security.md>), [news](<https://devfeed.tech/tags/news.md>), [people](<https://devfeed.tech/tags/people.md>)

### AI overview

The article congratulates the 2016 CyberSecurity Hall of Fame inductees, highlighting seven figures associated with information security, computer science, cryptography, and related fields.

### Source excerpt

[no description provided]

## Just Culture and Information Security

DevFeed: [Just Culture and Information Security](<https://devfeed.tech/articles/just-culture-and-information-security-36859.md>)

Original publisher: [Read original article](<https://shostack.org/blog/just-culture-and-information-security/>)

Author: Adam

Published: 2018-05-09T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Availability](<https://devfeed.tech/topics/availability.md>)

Tags: [information-security](<https://devfeed.tech/tags/information-security.md>), [password](<https://devfeed.tech/tags/password.md>), [password-manager](<https://devfeed.tech/tags/password-manager.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [patterns](<https://devfeed.tech/tags/patterns.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article reflects on just culture in information security after Twitter disclosed that plain-text passwords had been stored in log files without evidence of access or a known breach. It revisits criticism of password-management systems with centralized storage, arguing that locally distributed storage may avoid more catastrophic failure modes while acknowledging tradeoffs in monitoring, response, upgrades, and availability.

### Source excerpt

[no description provided]

## Voter Records, SSN and Commercial Authentication

DevFeed: [Voter Records, SSN and Commercial Authentication](<https://devfeed.tech/articles/voter-records-ssn-and-commercial-authentication-37107.md>)

Original publisher: [Read original article](<https://shostack.org/blog/voter-records-ssn-and-commercial-authentication/>)

Author: Adam

Published: 2017-07-05T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [data](<https://devfeed.tech/tags/data.md>), [identity](<https://devfeed.tech/tags/identity.md>), [information-security](<https://devfeed.tech/tags/information-security.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article examines the information-security implications of a request for voter data, including dates of birth and the last four digits of Social Security numbers. It questions whether exposing those details undermines their use as an authentication factor and discusses uncertainty about the applicable law.

### Source excerpt

[no description provided]

## Information Security and Privacy News Quiz Materials for Twitter Hackweek

DevFeed: [Information Security and Privacy News Quiz Materials for Twitter Hackweek](<https://devfeed.tech/articles/wait-wait-don-t-pwn-me-30139.md>)

Original publisher: [Read original article](<http://www.netmeister.org/blog/waitwait.html>)

Published: 2014-01-11T19:50:55Z

Content type: article

Language: en

Sources: [Signs of Triviality](<https://devfeed.tech/sources/signs-of-triviality.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [X (Twitter)](<https://devfeed.tech/topics/twitter.md>)

Tags: [information](<https://devfeed.tech/tags/information.md>), [information-security](<https://devfeed.tech/tags/information-security.md>), [news](<https://devfeed.tech/tags/news.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security-and-privacy](<https://devfeed.tech/tags/security-and-privacy.md>), [twitter](<https://devfeed.tech/tags/twitter.md>)

### AI overview

Materials, stories, and links for a variation of the NPR News Quiz focused on information security and privacy news, created for Twitter's quarterly Hackweek.

### Source excerpt

For this quarter's Hackweek at Twitter, I put together a variation of the NPR News Quiz with a focus on information security and privacy news. These are the materials, stories, and links.