Crash Override

We Need Modern Product Security Certification And We Need It Now

We Need Modern Product Certification and We need It Now
By Mark Curphey
June 6, 2023

Why you should not give a f*ck about security awards

The bull shitake from some security companies is out of control and security awards are a farcical tool they are using to look credible. It needs to stop.
By Mark Curphey
May 10, 2023

Is developer led, the best strategy for the adoption of security tools?

The data from corporate messaging tools may indicate that developer led adoption isn't the best strategy for the widespread adoption of security tools
By Mark Curphey
March 29, 2023

Security Tools Can't Just Be Friction Free. Was SCA the Tipping Point?

Why aren't there more developer tools with security features ?
By Mark Curphey
March 20, 2023

Developers Only Pay Lip Service to Security. Get Over It.

We should accept that developers only pay lip service to security
By Mark Curphey
March 2, 2023

Could sports advertising be a valid model for for open-source security?

How can we help open-source security projects generate sustainable funding without having to become commercial open-source companies? I have an idea.
By Mark Curphey
March 1, 2023

Why security companies and communities come and go

This articles shares observations and anecdotes from my life about what makes companies and communities come and what makes them go.
By Mark Curphey
January 26, 2023

Why supply chain security is so much more than open source code and CVE’s

This article describes why supply chain security is about all of the upstream and downstream dependencies that modern applications rely on and not just open source libraries.
By Mark Curphey
January 10, 2023

CVE / NVD doesn’t work for open source and supply chain security

Part two of my article about what is wrong with CVE/NVD and some ideas about how we could improve it.
By Mark Curphey
December 21, 2022

A Security Tools Crash Is Coming

An explosion of security startups and the economic climate are colliding and going to result in a train wreck. This post dives deeper in this that a recent short post in LinkedIn.
By Mark Curphey
November 21, 2022

What I Learned About Information Security From Academia

In this post I share lessons from my degree in info lessons earned in the real world after I left, told with some colourful real anecdotes
By Mark Curphey
October 11, 2022