Comments
Attacking Developers Using 'Shadow Containers'
Newest First  |  Oldest First  |  Threaded View
alphaa10
50%
50%
alphaa10,
User Rank: Strategist
2/1/2018 | 10:20:15 AM
Interviews Need Editing
Potential interest in every video segment. However, every interview needs editing-- video or audio-- because, without editing, it becomes a prisoner of its own format, laden with vague questions, obscure, hard to follow answers, and general tedium. With all due respect, the current video interview format rarely meets expectations.

A tighter delivery of information is accomplished with prerecorded video of text and graphics (where appropriate). Data professionals have learned to take in information at a much higher rate, and the exclusively text/graphics approach is likely to make the information flow "denser" or faster. As a prepared presentation, the information also can be more clearly focused and organized.

Another suggestion is to have the interviewer come from a background in the area under discussion. Unfocused questions like, "What are you fondest memories of the Black Hats of years past?" are innocently but agonizingly general, and serve only to open segments, as if trying to make conversation. DR should explore the utility of having veterans of the field as interviewers, with a general script to keep the line of questions integrated.

Potentially, of course, video interviews open something really fascinating, but we rarely find somebody with a good story just waiting to be interviewed, try as we might to prime interviewees with advance questions.

Let's face it-- in most situations, people have a tendency to make video resemble an exercise in filling a time slot. Truthfully, this is the first and last time I plan to watch a DR Black Hat video in the current format-- I simply don't have the time. In return for your having invested so much effort in production, not to mention actual interview time, you would serve your own cause by spendnig additional time editing the result.

You cannot afford to omit more intensive post-production, because only quality gathers an audience. Our time, like yours, is valuable-- please, make our investment even more engaging. That said, the UBM effort shows promise-- few other publishers take the trouble to cover these areas with such [potential) depth and detail.


Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2016-10739
PUBLISHED: 2019-01-21
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possib...
CVE-2019-6499
PUBLISHED: 2019-01-21
Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could potentially be exploited by malicious users to compromise the affected system.
CVE-2019-6500
PUBLISHED: 2019-01-21
In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial /h2hdocumentation//%2e%2e/ substring.
CVE-2019-6498
PUBLISHED: 2019-01-21
GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.
CVE-2019-6497
PUBLISHED: 2019-01-20
Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter.