Brutkey

Claudius Link
@realn2s@infosec.exchange

SW craftsperson & technology enthusiast, emphasis on security #SpielerischeSicherheit.

Co-organiser of Open Security Conference
@OSCo@infosec.exchange

Private here. Working in the intersection of
#informationSecurity, #ITSecurity, #OTSecurity, #SecureDevelopment, #ProductSecurity with a dose of #CriticalInfrastructure mixed in.

also at
https://bookwyrm.social/user/realn2s

(working for
@SMAsolar@techhub.social)
Opinions are my own, not my employer’s
#BLM #nonazis #NoAfD


Notes
44163
Following
0
Followers
0
Pronouns
he/him
Language
de,en
39c3
#6076

Claudius Link
@realn2s@infosec.exchange

I'm just reading the AI Con: How to Fight Big Tech's Hype and Create the Future We Want
by
@emilymbender@dair-community.social and @alex@dair-community.social

I can highly recommend it. It should be a required read for anyone doing something with AI (voluntarily or otherwise)

Claudius Link
@realn2s@infosec.exchange

I seem remember a #Mapping (Software Development) related #Event in Austria. I believe it was an #OpenSpace. I missed it several years and now can't remember how it was called.

Can someone tell me the name?

#BoostWelcome

Claudius Link
@realn2s@infosec.exchange

TIL about the #CarnotEfficiency

A formular which calculates the maximal efficiency of a heat-based engine. It describes the maximum ratio of work which can be produced by a heat base "engine".

Heat-base engine sound strange and theoretical but coal, gas-based power plants as well as nuclear power plants are heat engines.

The efficiency of heat-base engines depends on the difference between the hot and the cold temperastur. A smaller difference reduces the efficiency.

This mean that with the raising temperatures through
#ClimateChange make al heat base power plants less efficient.

https://en.wikipedia.org/wiki/Carnot%27s_theorem_(thermodynamics)

This another strong argument the fossile energy needs to be ended

Claudius Link
@realn2s@infosec.exchange

【Are you interested in a different kind of security conference?】


Then take a look at the Open Security Conference (
@OSCo@infosec.exchange). #osco25 takes place from October 2 to 5 in Rückersbach (Germany near Frankfurt) and registration is still open at https://opensecurityconference.org/.
(this is an English version of the original German thread
https://infosec.exchange/@realn2s/114936419689473030)Why?


The Open Security Conference aims to be diverse and inclusive. This also includes different levels of knowledge and experience.
It is therefore not only for security experts or for people who have (already) worked in the security sector for a long time,
but also for people who are interested in security or want to get into the field.

The
#OpenSpace format not only enables expert presentations,
but also non-expert topics or questions as session topics. Sessions are not resticted to presentations, they can be interactive, collaborative, workshops or basically anything else.

Since topics do not have to be submitted months in advance,
but the agenda is created jointly by the participants, hot topics can also be covered.

The conference is non-commercial, i.e. the total costs are shared between the participants (including the organizers).
The costs include accommodation and meals in the conference hotel.

And yes, there are also sponsors who cover part of the costs.
But not everything is different.


There are great keynotes e.g. by
@bkastl@mastodon.social ("History repeating itself") and Mireia Cano ("Building an AppSec Program from Scratch").

#CyberSecurity #Security #InfoSec #AppSec #ProductSecurity #OTsecurity

Claudius Link
@realn2s@infosec.exchange

Habt ihr Interesse an einer etwas anderen Sicherheitskonferenz?
#BoostWelcome

Dann schaut euch mal die
#osco25 an. Sie findet vom 2-5 Oktober in Rückersbach statt und die Registrierung ist noch offen
https://opensecurityconference.org/【Warum?】


Die
@OSCo@infosec.exchange hat das Ziel divers und inklusiv zu sein. Das schließt auch unterschiedliche Wissens- und Erfahrungsstände mit ein. Sie ist also nicht nur für Sicherheitsexpert*innen oder für Menschen die schon lange im Sicherheitsbereich arbeiten.

Das
#OpenSpace Format ermöglicht nicht nur Expert*inne-Präsentationen, sondern es können "Halbwissen"-Themen* oder auch einfach Fragen behandelt werden. Da Vorträge nicht Monate im Voraus eingereicht werden müssen sondern die Agenda von den Teilnehmenden gemeinsam erstellt wird, können auch brandaktuelle Themen behandelt werden.

Die Konferenz ist nicht-komerziell, sprich die Gesamtkosten werden zwischen den Teilnehmenden (inklusive Organisator*innen) aufgeteilt. Die Konsten enthalten die Übernachtung und Verpflegung im Tagungshotel.
Und ja, es gibt auch Sponsoren die Teile der Kosten übernehmen.

Es ist aber nicht alles anders. Es gibt auch Keynotes z.B. von
@bkastl@mastodon.social ("History repeating itself") und Mireia Cano ("Building an AppSec Program from Scratch")

Wenn es euch interessiert registriert euch unter
https://register.opensecurityconference.org/

#Cybersicherhet #CyberSecurity

Claudius Link
@realn2s@infosec.exchange

I'm just in a process training. One topic is Weighted Shortest Job First (#WSJF). For some reason if got a bad feeling about the use of WSJF. It feels like adding several unknown values (guesstimates) and dividing by some more unknowns, leading to an arbitrary result with questionalble value which isn't free.

The official devicition is

Cost of Delay / Job Size

where

Cost of Delay = User-Business Value + Time Criticality + Risk Reduction and/or Opportunity Enablement.

IMHO Agile is all about theat we generally don't know the Job Size, and are regularly wrong (biased) about the (User) Buisness Value.

The samme applies to Risk Reduction and Opportunity Enablement. If there isn't a fixed external dealine also the Time Criticality is pretty arbitray (reading pure opinion or politics)

Anyone has experience with it?
#SAFe #Agile

Claudius Link
@realn2s@infosec.exchange

A related #quote which comes to my mind in situations like this

“There's no sense in being precise when you don't even know what you're talking about”
― John von Neumann

Claudius Link
@realn2s@infosec.exchange

I'm just in a process training. One topic is Weighted Shortest Job First (#WSJF). For some reason if got a bad feeling about the use of WSJF. It feels like adding several unknown values (guesstimates) and dividing by some more unknowns, leading to an arbitrary result with questionalble value which isn't free.

The official devicition is

Cost of Delay / Job Size

where

Cost of Delay = User-Business Value + Time Criticality + Risk Reduction and/or Opportunity Enablement.

IMHO Agile is all about theat we generally don't know the Job Size, and are regularly wrong (biased) about the (User) Buisness Value.

The samme applies to Risk Reduction and Opportunity Enablement. If there isn't a fixed external dealine also the Time Criticality is pretty arbitray (reading pure opinion or politics)

Anyone has experience with it?
#SAFe #Agile

Claudius Link
@realn2s@infosec.exchange

In "eigener" Sache (#BoostWelcome)

Meine Partnerin mag nicht mehr alleine von Unternehmen zu Unternehmen ziehen. Sie sucht ein Team, das Lust hat, mit ihr gemeinsam spannende Projekte zu gestalten und Rahmenbedingungen für gute Lösungen zu schaffen.

Als Sozialpädagogin ist sie über Jahrzehnte immer mehr in die Agile und Organisationsentwicklung gerutscht. Durch diesen Werdegang bring sie andere und diverse Perspektiven ein, die eine enorme Bereicherung bringen können.

Was sie mitbringet
Langjährige Erfahrung als Coach und Organisationsentwicklerin
Erfahrung internen und externen Beratungs- und Coachingrollen,
Führungserfahrung
technische Affinität
Flexibilität gepaart mit Pragmatismus

Was sie sich wünscht, sind Aufgaben wie:
Design und Moderation von Veranstaltungen
Organisations- und Teamentwicklung
Digitalisierung von Prozessen
Gestaltung von Kommunikations-Strukturen und -abläufen
Beratung und Begleitung bei Konflikten
Teamentwicklung
Coaching
Krisenintervention & schwierige Gespräche


Teilzeit oder Vollzeit, remote oder hybrid idealerweise von
#Kassel mit der Bahn und öffentlichen Verkehrsmitteln erreichbar 😃😃

Hier im Fediverse ist sie unter
@SNeunes@infosec.exchange zu Hause und freut sich über Angebote, Ideen oder Tips.

#FediHire #GetFediHired

Claudius Link
@realn2s@infosec.exchange

Completely switching the genre

Someone I can't leave out ist Leo Moracchioli.
Who does fantastic and funny
#metal covers of songs, alone or with other artists.

Some favorites:
* Sultans of Swing
https://youtu.be/x0RV0kgdqJU
* Adele - Hello
https://youtu.be/LtQUJMBH8uE
* Hot in Here
https://youtu.be/tdTtWfzZqHA
* Ed Sheeran - Bad Habits
https://youtu.be/Oc-yGEQPviA
* Land of Confusion
https://youtu.be/PHvJdHV8iVA
* Flashdance - Maniac
https://youtu.be/be-1mCM8QYs
* What Is Love?
https://youtu.be/DKo9ok2829M (#PriscilaSerrano voice 😲😲​)

and last but not least a cover of a parody children song What Does the Fox Say?
https://youtu.be/aeV2aervI1Y

One more thing: the fan made video to the Pink - Get The Party Started cover
https://youtu.be/9GR9862LqMk

#LeoMoracchioli #Covers #Music

Claudius Link
@realn2s@infosec.exchange

Not strictly speaking a cover band but initially street musicians. Outside Germany (or even the Cologne area) an insider tip ;-)

#AnnenMayKantereit

The voice!!!

* Tom's Diner
https://youtu.be/5r3B7yz6J68
* Can't Get You out of My Head
https://youtu.be/RacxNskxySo

and one of their own (in German)
Ich geh heut nicht mehr tanzen
(I'm not going dancing today)
https://youtu.be/MKyj6lYHfT8

#Music #Covers

Claudius Link
@realn2s@infosec.exchange

Next Pink Martini

An orchestral version with a touch of the 1920th but hard to pinpoint :-)

* I Lost Myself
https://www.youtube.com/watch?v=sPHYdUIISv0
* Amado Mio
https://www.youtube.com/watch?v=sCbzWiJLVhk

#PinkMartini #Covers #Music