21/05/2021
NorthSec
Or maybe we're just all idiots?
You are notan idiot
Ange Albertini
- Reverse engineering since 1989, Author of Corkami, File format expert.
- PoC or GTFO, Pwnie Award of Crypto 2017.
Professionally
- 13 years of malware analysis
- 3 years of Infosec Engineer at Google
About the author
my license plate is a CPU architecture.
my phone case is a PDF doc,
my resume is a Super NES/Megadrive rom.
My own views
and opinions.
2
This talk
- You might see me as successful (Google, Pwnie…)
- I kept seeing myself as an idiot - until very recently.
- Yet I’m still the same.
Why until now? Why not now?
Choose your flavour:
- the slides are quite generic, the recording is more personal.
THE CURRENT SLIDE IS AN
A CORKAMI ORIGINAL PRODUCTION
HONEST TALK TRAILER
idiot?
3
Yet another
“success” speech ?
This talk is not about showing off my success.
Focusing on the basics.
Not necessary limited to Infosec.
Totally experimental. Unpopular opinions?
I'm obviously biased. I'm here to share & learn.
4
So many reasons to over-worry...
...and forget about yourself.
Infosec...
5
...or your friends.
- very repetitive tasks.
- uncertainty is exhausting.
- profiteers, abusers.
InfoSec is boring exhausting/harmful!
6
Infosec people are always wrong
- We’re the ones preventing projects to launch.
- We’re easily misunderstood.
We’re supposed to just have to “follow the manual”
like any other engineers.
- we discuss hypothetical attacks that never happened yet.
- we publish research that helps to create more attacks.
7
Earlier this week...
8
InfoSec and metrics
Security doesn't have easy metrics.
So defense is very political.
9
The pandemic certainly didn’t help...
10
But we’re a lot more than our work
- All your efforts in infosec are not worth it
if you burn out or commit suicide.
11
First mistakes...
12
You are not an idiot if… = Yanaii
It is normal and ok to… = Iinaot
There are different kinds of personality
It is normal and ok to be different!
13
Some people can’t learn without practice,
or without a genuine motivation.
Everybody is a genius. But if you judge a fish by its ability to climb a tree, it will
live its whole life believing that it is stupid. - Albert Einstein
Fake
Quote
You just can’t learn things magically
14
YANAII...
Story time
Find your own!
Story time 15
School usually provides a unique form of learning.
- We were all born “hackers”...
...then rules are enforced.
And now our work is full
of experimental failure.
School taught us that failure is not an option
16
Once studies are over...
17
Story time
You think your diploma was mostly useless
YANAII...
(basically job #0)
18
...is here to stay.
...just means that you are self conscious!
...is better than the Dunning-Kruger effect!
...can be bypassed: just help someone!
The impostor syndrome..
19
How good you think you are
How good you are
Impostor syndrome
(conscientious expert)
Dunning-Kruger effect
(shameless ignorant)
Some people are never satisfied...
- Arrogance
- Dunning Kruger effect
- Gatekeeping
20
YANAII...
Let me interrupt your expertise with my confidence.
No need to “reinvent the wheel”?
- why not ?
- just be honest and don’t present the idea as new.
- we still use cars, bikes, tools and bread.
21
-
Infosec
for
newbies
Just a different style
can make things click.
And a different style can reach different users!
We all had a bad teacher about something we love,
or a great teacher for a topic we usually hate.
We often forget that...
https://www.getdigital.de/Hacken-Open-Air-Shirt.html?her=BB
https://en.wikipedia.org/wiki/The_Manga_Guides
Story time 22
IINAOT feel stuck in a loop.
As opposed to school,which was creating differences every year.
Consistency is actually a good thing.
Take one small step after another...
23
Others can't always share your perspective.
- No, not even your closest friends/colleagues!
time
critics
Progress
"Weird" "New"
You want to try something different.
24
Story time
YANAII...
Don’t burn yourself trying to be perfect!
25
Focus on yourself first!
Take breaks too!
26
27
You got it wrong so far!
YANAII...
Some people will take
the worst decisions...
Even against their own interests
or their friends’/family’s
Fears/traditions/ideologies
are sadly taken into account.
no matter how stupid they are:
sexism, racism, religion…
28
This is not an excuse to...
29
Attitude
It’s OK to be different,
but everyone has their limit
Story time 30
Be wary of bad habits.
“Respect” is not “authority”.
Try swapping roles!
31
Your past is no excuse!
It’s ok to be insecure. Not to be a jerk.
Story time 32
Nothing comes easy
- anything takes a long time to master.
- if you can still count how much you’ve tried,
it’s probably not much.
“The art of like twirling or doing tricks with a pen in a very appealing nice looking way.
Make it look like it's easy even though it takes like hours and hours and hours of practice.”
- LiveOverFlow
33
33
“How can I…”
Face it: if after [long enough], you never tried,
Then you were probably never actually interested ;)
And if you still hate it after X tries,
then be honest and move on ;)
Story time 34
You’re always doing it wrong?
No matter what, that person is never satisfied…
What if...you actually did nothing wrong?
And you’re just being manipulated…?
What if...
35
Ever heard of gaslighting?
Based on a play from 1938 - and a classic movie, now freely available.
36
37
Honey moon
Silence
Killer face
Asserting power
Faking
Any of these rings a bell ?
38
They make other people feel guilty, in the name of professional conscience, family ties, friendship, love, etc.
They unload their responsibilities onto others or dismiss their own responsibilities. / They do not clearly communicate their requests, needs, feelings or opinions.
They often respond vaguely. / They lie / They are self-centred. / They cite all kinds of logical reasons to disguise their requests.
They change their opinions, behaviours, or feelings depending on the person or situation. / They make veiled threats or openly resort to blackmail.
They make others believe that they must be perfect, never change their minds, always know everything, and immediately respond to requests and questions.
They cast into doubt the qualities, skills and personalities of other people—they criticize without appearing to do so, devalue and judge.
They have their messages communicated by other people or via intermediaries (telephone instead of face-to-face, written notes).
They create suspicion and stir up ill feeling; they divide to conquer, driving a wedge between people, which can lead to relationship break-ups.
They know how to make themselves into victims to gain sympathy (e.g. exaggerated illness, « difficult » surroundings, overloaded at work).
They ignore requests (even if they claim to be taking care of them). / They use flattery to seduce us, give gifts or suddenly start waiting on us hand and foot.
They use the moral principles of others (e.g. notions of humanity, charity, racism, « good » or « bad » mother) to satisfy their needs.
They abruptly change topic in mid-conversation. / They avoid or get out of discussions and meetings. / They cannot take criticism, and deny facts.
They make false statements to discover the truth, twist and interpret facts to suit themselves. / They can be jealous, even if they are parents or spouses.
They do not take into account the rights, needs and desires of others. / They make us do things that we would probably not have done of our own free will.
They often wait until the last minute to ask, order or have others do something. / They rely on the ignorance of others while vaunting their own superiority.
Their words appear logical and consistent, while their attitudes, actions or lifestyle are totally opposite.
They generate a state of discomfort or of not being free (trap). / They are excellent at meeting their own goals, but at the expense of others.
They are constantly the focus of conversation among people who know them, even if they are not present.
by Isabelle Nazare-Aga
30 characteristics of manipulators
Manipulators...
...can be anyone.
...can change over time (very nice before, slowly worsening).
...may be painful to acknowledge as such
(huge denial to overcome the sadness).
39
What can you do against a manipulator?
Keep your distance! Preserve yourself!
A therapy may be impossible to undergo:
- authorities can easily be fooled.
- Proofs may be hard to find.
40
41
Beware of those eager to “help”
- to “help”, but only according to their own terms (nodding, speaking…)
- ignoring your needs, but satisfy their expectations.
”…but I want to fight back!”
You might lose yourself in an unfair and endless fight.
Better be free than burning yourself out in vain.
Your second life begins when you realize you have only one.
42
“Never argue with an idiot. They will drag you down
to their level and beat you with experience.”
- Mark Twain
But why should we care?
We all worry about these… only because we can.
A question of time and priority.
So maybe, we’re still somehow idiots...
43
44
Stop giving a fxck.
There’s no end to your tunnel.
You’re the light.
Story time
Learn to de-prioritize!
45
You’re considering to commit suicide
But maybe (and more than you think):
- people care about you.
- they will be in pain.
46
Story time
YANAII...
Conclusion
47
Yes, maybe we’re all idiots
But why should you care ?
48
Hopefully you went
through similar experiences.
You may not be the only idiot.
49
Thank you!
Take care of yourself
50
Special thanks to:
Doegox , BarbieAuglend, Sally.

More Related Content

PDF
Infosec & failures
PDF
Beyond your studies
PDF
10 Ways to Turn Your Learners into Zombies
ODT
Easy tips for your tweets by bill stankiewicz,
PDF
authoring a hero's journey: finding meaning through story
PPT
Ten ways to turn your learners into zombies
PPT
Writing better e learning
PDF
The great-life-swindle
Infosec & failures
Beyond your studies
10 Ways to Turn Your Learners into Zombies
Easy tips for your tweets by bill stankiewicz,
authoring a hero's journey: finding meaning through story
Ten ways to turn your learners into zombies
Writing better e learning
The great-life-swindle

What's hot (8)

DOCX
Caesar
PDF
Design for dreams not needs: who do you want your customers to become?
PDF
Super fast product creation
PDF
Make du Jour with EdTEchTeam
ODP
Dangerous Ideas Intro Quotes
PDF
E11 writing prompts 2018 2019
KEY
Oct 09 - BJ Epstein - YHBT
PDF
Leveraging for Legacy and Cultivating New Literacies: Region One Texas "Using...
Caesar
Design for dreams not needs: who do you want your customers to become?
Super fast product creation
Make du Jour with EdTEchTeam
Dangerous Ideas Intro Quotes
E11 writing prompts 2018 2019
Oct 09 - BJ Epstein - YHBT
Leveraging for Legacy and Cultivating New Literacies: Region One Texas "Using...
Ad

Similar to You are *not* an idiot (20)

PDF
A question of time - Troopers 2024 Keynote
PPT
Social understanding in autism
PPTX
Baudrillard Make Up Day PPT
PPTX
Susan C - Coming Out of the Hoarding Closet
DOC
How not to be a dick Как Не быть хуем и засранцем
DOCX
13 The Believing Game and How to Make Conflicting Opini.docx
PDF
THE OMNIPOTENT CODES by Ayas Ganguly (Un-Cut Edition)
DOCX
PROS AND CONS OF 53 CONTROVERSIAL ISSUESEDUCATION1. College .docx
PPTX
Truth or myth 4
PDF
The Infamous 9 (Nine) by Ayas Ganguly.pdf
PPTX
how to be a mentor
PDF
Creativity
PPTX
Literary conflict
PPTX
Literary Conflict
PPTX
joi ito and wikipedia
PDF
Ideas For Writing A Persuasive Essay
PDF
10 toxic people you should avoid at all costs
PDF
Posthumanism and the Affective Turn: Epistemic Injustice, Emergent Listening ...
PDF
10 Ways to Turn Your Learners Into Zombies
PPTX
The perfect storm of narcissism and social media
A question of time - Troopers 2024 Keynote
Social understanding in autism
Baudrillard Make Up Day PPT
Susan C - Coming Out of the Hoarding Closet
How not to be a dick Как Не быть хуем и засранцем
13 The Believing Game and How to Make Conflicting Opini.docx
THE OMNIPOTENT CODES by Ayas Ganguly (Un-Cut Edition)
PROS AND CONS OF 53 CONTROVERSIAL ISSUESEDUCATION1. College .docx
Truth or myth 4
The Infamous 9 (Nine) by Ayas Ganguly.pdf
how to be a mentor
Creativity
Literary conflict
Literary Conflict
joi ito and wikipedia
Ideas For Writing A Persuasive Essay
10 toxic people you should avoid at all costs
Posthumanism and the Affective Turn: Epistemic Injustice, Emergent Listening ...
10 Ways to Turn Your Learners Into Zombies
The perfect storm of narcissism and social media
Ad

More from Ange Albertini (20)

PDF
Overview of file type identifiers (HackLu)
PDF
Technical challenges with file formats
PDF
Relations between archive formats
PDF
Abusing archive file formats
PDF
TimeCryption
PDF
Improving file formats
PDF
KILL MD5
PDF
No more dumb hex!
PDF
An introduction to inkscape
PDF
The challenges of file formats
PDF
Exploiting hash collisions
PDF
Connecting communities
PDF
TASBot - the perfectionist
PDF
Caring for file formats
PDF
Hacks in video games
PDF
Trusting files (and their formats)
PDF
Let's write a PDF file
PDF
PDF: myths vs facts
PDF
An overview of potential leaks via PDF
PDF
Advanced Pdf Tricks
Overview of file type identifiers (HackLu)
Technical challenges with file formats
Relations between archive formats
Abusing archive file formats
TimeCryption
Improving file formats
KILL MD5
No more dumb hex!
An introduction to inkscape
The challenges of file formats
Exploiting hash collisions
Connecting communities
TASBot - the perfectionist
Caring for file formats
Hacks in video games
Trusting files (and their formats)
Let's write a PDF file
PDF: myths vs facts
An overview of potential leaks via PDF
Advanced Pdf Tricks

Recently uploaded (20)

PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
Zenith AI: Advanced Artificial Intelligence
PDF
Developing a website for English-speaking practice to English as a foreign la...
PDF
Credit Without Borders: AI and Financial Inclusion in Bangladesh
PDF
Abstractive summarization using multilingual text-to-text transfer transforme...
PDF
A proposed approach for plagiarism detection in Myanmar Unicode text
PDF
STKI Israel Market Study 2025 version august
PPTX
Final SEM Unit 1 for mit wpu at pune .pptx
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
CloudStack 4.21: First Look Webinar slides
PDF
Getting started with AI Agents and Multi-Agent Systems
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PDF
Two-dimensional Klein-Gordon and Sine-Gordon numerical solutions based on dee...
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
sbt 2.0: go big (Scala Days 2025 edition)
PDF
UiPath Agentic Automation session 1: RPA to Agents
PPTX
Chapter 5: Probability Theory and Statistics
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
PDF
The influence of sentiment analysis in enhancing early warning system model f...
Hindi spoken digit analysis for native and non-native speakers
Zenith AI: Advanced Artificial Intelligence
Developing a website for English-speaking practice to English as a foreign la...
Credit Without Borders: AI and Financial Inclusion in Bangladesh
Abstractive summarization using multilingual text-to-text transfer transforme...
A proposed approach for plagiarism detection in Myanmar Unicode text
STKI Israel Market Study 2025 version august
Final SEM Unit 1 for mit wpu at pune .pptx
Enhancing emotion recognition model for a student engagement use case through...
CloudStack 4.21: First Look Webinar slides
Getting started with AI Agents and Multi-Agent Systems
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
Two-dimensional Klein-Gordon and Sine-Gordon numerical solutions based on dee...
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
sbt 2.0: go big (Scala Days 2025 edition)
UiPath Agentic Automation session 1: RPA to Agents
Chapter 5: Probability Theory and Statistics
1 - Historical Antecedents, Social Consideration.pdf
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
The influence of sentiment analysis in enhancing early warning system model f...

You are *not* an idiot

  • 1. 21/05/2021 NorthSec Or maybe we're just all idiots? You are notan idiot Ange Albertini
  • 2. - Reverse engineering since 1989, Author of Corkami, File format expert. - PoC or GTFO, Pwnie Award of Crypto 2017. Professionally - 13 years of malware analysis - 3 years of Infosec Engineer at Google About the author my license plate is a CPU architecture. my phone case is a PDF doc, my resume is a Super NES/Megadrive rom. My own views and opinions. 2
  • 3. This talk - You might see me as successful (Google, Pwnie…) - I kept seeing myself as an idiot - until very recently. - Yet I’m still the same. Why until now? Why not now? Choose your flavour: - the slides are quite generic, the recording is more personal. THE CURRENT SLIDE IS AN A CORKAMI ORIGINAL PRODUCTION HONEST TALK TRAILER idiot? 3
  • 4. Yet another “success” speech ? This talk is not about showing off my success. Focusing on the basics. Not necessary limited to Infosec. Totally experimental. Unpopular opinions? I'm obviously biased. I'm here to share & learn. 4
  • 5. So many reasons to over-worry... ...and forget about yourself. Infosec... 5 ...or your friends.
  • 6. - very repetitive tasks. - uncertainty is exhausting. - profiteers, abusers. InfoSec is boring exhausting/harmful! 6
  • 7. Infosec people are always wrong - We’re the ones preventing projects to launch. - We’re easily misunderstood. We’re supposed to just have to “follow the manual” like any other engineers. - we discuss hypothetical attacks that never happened yet. - we publish research that helps to create more attacks. 7
  • 9. InfoSec and metrics Security doesn't have easy metrics. So defense is very political. 9
  • 10. The pandemic certainly didn’t help... 10
  • 11. But we’re a lot more than our work - All your efforts in infosec are not worth it if you burn out or commit suicide. 11
  • 12. First mistakes... 12 You are not an idiot if… = Yanaii It is normal and ok to… = Iinaot
  • 13. There are different kinds of personality It is normal and ok to be different! 13
  • 14. Some people can’t learn without practice, or without a genuine motivation. Everybody is a genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is stupid. - Albert Einstein Fake Quote You just can’t learn things magically 14 YANAII... Story time
  • 15. Find your own! Story time 15 School usually provides a unique form of learning.
  • 16. - We were all born “hackers”... ...then rules are enforced. And now our work is full of experimental failure. School taught us that failure is not an option 16
  • 17. Once studies are over... 17
  • 18. Story time You think your diploma was mostly useless YANAII... (basically job #0) 18
  • 19. ...is here to stay. ...just means that you are self conscious! ...is better than the Dunning-Kruger effect! ...can be bypassed: just help someone! The impostor syndrome.. 19 How good you think you are How good you are Impostor syndrome (conscientious expert) Dunning-Kruger effect (shameless ignorant)
  • 20. Some people are never satisfied... - Arrogance - Dunning Kruger effect - Gatekeeping 20 YANAII... Let me interrupt your expertise with my confidence.
  • 21. No need to “reinvent the wheel”? - why not ? - just be honest and don’t present the idea as new. - we still use cars, bikes, tools and bread. 21
  • 22. - Infosec for newbies Just a different style can make things click. And a different style can reach different users! We all had a bad teacher about something we love, or a great teacher for a topic we usually hate. We often forget that... https://www.getdigital.de/Hacken-Open-Air-Shirt.html?her=BB https://en.wikipedia.org/wiki/The_Manga_Guides Story time 22
  • 23. IINAOT feel stuck in a loop. As opposed to school,which was creating differences every year. Consistency is actually a good thing. Take one small step after another... 23
  • 24. Others can't always share your perspective. - No, not even your closest friends/colleagues! time critics Progress "Weird" "New" You want to try something different. 24 Story time YANAII...
  • 25. Don’t burn yourself trying to be perfect! 25
  • 26. Focus on yourself first! Take breaks too! 26
  • 27. 27 You got it wrong so far! YANAII...
  • 28. Some people will take the worst decisions... Even against their own interests or their friends’/family’s Fears/traditions/ideologies are sadly taken into account. no matter how stupid they are: sexism, racism, religion… 28
  • 29. This is not an excuse to... 29
  • 30. Attitude It’s OK to be different, but everyone has their limit Story time 30
  • 31. Be wary of bad habits. “Respect” is not “authority”. Try swapping roles! 31
  • 32. Your past is no excuse! It’s ok to be insecure. Not to be a jerk. Story time 32
  • 33. Nothing comes easy - anything takes a long time to master. - if you can still count how much you’ve tried, it’s probably not much. “The art of like twirling or doing tricks with a pen in a very appealing nice looking way. Make it look like it's easy even though it takes like hours and hours and hours of practice.” - LiveOverFlow 33 33
  • 34. “How can I…” Face it: if after [long enough], you never tried, Then you were probably never actually interested ;) And if you still hate it after X tries, then be honest and move on ;) Story time 34
  • 35. You’re always doing it wrong? No matter what, that person is never satisfied… What if...you actually did nothing wrong? And you’re just being manipulated…? What if... 35
  • 36. Ever heard of gaslighting? Based on a play from 1938 - and a classic movie, now freely available. 36
  • 38. Any of these rings a bell ? 38 They make other people feel guilty, in the name of professional conscience, family ties, friendship, love, etc. They unload their responsibilities onto others or dismiss their own responsibilities. / They do not clearly communicate their requests, needs, feelings or opinions. They often respond vaguely. / They lie / They are self-centred. / They cite all kinds of logical reasons to disguise their requests. They change their opinions, behaviours, or feelings depending on the person or situation. / They make veiled threats or openly resort to blackmail. They make others believe that they must be perfect, never change their minds, always know everything, and immediately respond to requests and questions. They cast into doubt the qualities, skills and personalities of other people—they criticize without appearing to do so, devalue and judge. They have their messages communicated by other people or via intermediaries (telephone instead of face-to-face, written notes). They create suspicion and stir up ill feeling; they divide to conquer, driving a wedge between people, which can lead to relationship break-ups. They know how to make themselves into victims to gain sympathy (e.g. exaggerated illness, « difficult » surroundings, overloaded at work). They ignore requests (even if they claim to be taking care of them). / They use flattery to seduce us, give gifts or suddenly start waiting on us hand and foot. They use the moral principles of others (e.g. notions of humanity, charity, racism, « good » or « bad » mother) to satisfy their needs. They abruptly change topic in mid-conversation. / They avoid or get out of discussions and meetings. / They cannot take criticism, and deny facts. They make false statements to discover the truth, twist and interpret facts to suit themselves. / They can be jealous, even if they are parents or spouses. They do not take into account the rights, needs and desires of others. / They make us do things that we would probably not have done of our own free will. They often wait until the last minute to ask, order or have others do something. / They rely on the ignorance of others while vaunting their own superiority. Their words appear logical and consistent, while their attitudes, actions or lifestyle are totally opposite. They generate a state of discomfort or of not being free (trap). / They are excellent at meeting their own goals, but at the expense of others. They are constantly the focus of conversation among people who know them, even if they are not present. by Isabelle Nazare-Aga 30 characteristics of manipulators
  • 39. Manipulators... ...can be anyone. ...can change over time (very nice before, slowly worsening). ...may be painful to acknowledge as such (huge denial to overcome the sadness). 39
  • 40. What can you do against a manipulator? Keep your distance! Preserve yourself! A therapy may be impossible to undergo: - authorities can easily be fooled. - Proofs may be hard to find. 40
  • 41. 41 Beware of those eager to “help” - to “help”, but only according to their own terms (nodding, speaking…) - ignoring your needs, but satisfy their expectations.
  • 42. ”…but I want to fight back!” You might lose yourself in an unfair and endless fight. Better be free than burning yourself out in vain. Your second life begins when you realize you have only one. 42 “Never argue with an idiot. They will drag you down to their level and beat you with experience.” - Mark Twain
  • 43. But why should we care? We all worry about these… only because we can. A question of time and priority. So maybe, we’re still somehow idiots... 43
  • 44. 44 Stop giving a fxck. There’s no end to your tunnel. You’re the light. Story time
  • 46. You’re considering to commit suicide But maybe (and more than you think): - people care about you. - they will be in pain. 46 Story time YANAII...
  • 48. Yes, maybe we’re all idiots But why should you care ? 48
  • 49. Hopefully you went through similar experiences. You may not be the only idiot. 49
  • 50. Thank you! Take care of yourself 50 Special thanks to: Doegox , BarbieAuglend, Sally.