SecurityMetrics Podcast | 29
Teaching Data Security to Children
"I have a passion to keep people safe online, especially young ones. I don't expect kids to pick up this book and understand the concepts right away, but I want to empower the adults to teach. "
Teaching data security and internet safety to the next generation can prove to be challenging. From the complex tools to the vast vocabulary, it's no simple thing to learn.
Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) sits down with Curtis Brazzell as they discuss his recent endeavor to better help children learn, and parents teach about data security.
Listen to learn:
- Curtis's cybersecurity ABC book, "M is for Malware"
- How to better teach our young ones how to be safe online
- Helping to teach those just entering the data security field
Get your copy of "M is for Malware" at https://misformalware.com/
Resources:
Download our Guide to PCI Compliance! - https://info.securitymetrics.com/pci-guide
Download our Guide to HIPAA Compliance! - https://info.securitymetrics.com/hipaa-guide
[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.
Teaching Data Security to Children Transcript
Hello, and welcome back to the Security Metrics podcast. I'm Jen Stone. I'm a principal security analyst here at Security Metrics, and I am very excited about our, guest today. Let me tell you a little bit about him and I even I have a prop.
So Stan, if you're listening to it and you're not watching this on YouTube, you're going to have to imagine the prop because I wanna use it a couple of times. But, it still will be good on on audio, so don't stress too much. Alright. Our guest today is Curtis Brazzle. He is the principal security consultant for Pondurance.
And super excited about talking to him because he wrote these books for children. But before I get into that, I'm gonna give you a little bit above a bio on Curtis. He's passionate about the cybersecurity field for nearly twenty five years. I feel that.
Curtis brings both a wide and deep technical skill set while also demonstrating management and team leadership skills to protect organizations against cyber threats. So he and I were just talking before the show about what he actually does there at Ponderance, and he leads their their red team, does penetration testing, that type of thing. So I I think in a lot of ways, we have a lot of really similar interests in cybersecurity and helping, different organizations.
Curtis has a strong desire to always continue learning and comes from a mostly self taught and hands on experience background. He gives back to the community with technical security research and offers general security advice to a less technical audience, which I'm super excited about. Because if you're in cybersecurity, knowing how to use the right words and the right, examples to explain things to people can be really hard.
And he's the author of the popular children's book series, standby for the prop, the cybersecurity ABCs. So I have with me here, m is for for malware. There are two other books in this series so far. So far, I mean, maybe he's I don't know.
We'll ask if he's writing more or not. But, where he introduces security concepts to a younger audience. Now if you don't have children or if you are not younger, don't worry. These are cool.
My, marketing team actually were were the ones who found these books and and found Curtis and were so stoked about him that they're like, you have to talk to him. And then they gave me the book, and I said, you're not getting that back. So this is now on my bookshelf.
Curtis, welcome to the show.
Hey. Thank you so much, Jen, for having me on here. I appreciate it. It's an honor.
Did I get any of that wrong in my in my intro? Is that, No. Awesome.
You nailed it.
Yay.
So, the the marketing team, they they liked your book so much. They said, okay.
We wanna get these books. We wanna maybe put our logo on it and hand it out at conferences, and we were kinda going that path. And then something weird happened with the last year where conferences in person didn't really happen.
So we have a bunch of books, and I've been given permission to do a giveaway.
So I'll give details on the giveaway at the end of the show.
And they're they're super cute. They're super worth having. And and we're we will also give instructions on where to go buy them. One of the fun things about being on the video part of this podcast is we can see what you've got behind. So tell me a little bit about your office there, Curtis, before I get to that.
If you can call this an office anymore.
Yeah. So I fulfill my own books, at least the ones that go to the US.
And so I had, you know, pallets upon pallets of boxes delivered to my home. And I don't have a lot of space here, so I had to to put them all around me. So whenever I'm on a conference call or anything, you can see stacks of boxes until I fulfill all of these things.
Nice.
I'm a little motivated to sell these also just to get them out of my house.
You'd like your space back? Yeah. And and and you used to sell them on Amazon, but don't anymore. And so that's another thing that we'll give the the link where people can go and purchase their own, on our when we post this, it'll be on our website. And, also, we'll talk about it, towards the end of the show.
But first of all Yeah.
What made you write these books? What what made you go, hi.
I think I'm gonna write books for children.
Yeah. No. That's a great question. So, you know, I have three little ones under five, and, you know, as you know, you spend a lot of your evenings reading the same old material over and over again.
Mhmm. And, it just makes you think while you're reading it, especially the the younger children. And when you're doing the ABC books, for example, we have a a variety of ABC books here. And, you know, you can't help but be a little bit of a backseat driver when you're when you're reading those Yeah.
And you're thinking, you know, if I did these, I'd do these slightly differently. Maybe, you're going through the animal ABCs and, you know, they don't have a y, so they use yawn, for example. And that bothered me. I was like, why don't they use yak or something?
You know, like, little things like that. And so it gets me thinking, I would love to write a children's book, not necessarily because I think I could do it better, just because I think it would be a fun experience, you know, but I don't have a lot to contribute knowledge wise. You know, what can I do that hasn't been done before?
And then it just hit me one day. You know?
Cybersecurity is something I'm, you know, the most familiar with.
Mhmm.
If I have an area of expertise at all, it's gotta be cybersecurity.
It's been a passion of mine, like you said, for a long time. I've always thought that concept was a little too complicated in some areas unless you're talking about, like, privacy and things like that.
But then I thought, no. You know, kids are really smart. Sure.
Let's just throw it out there. It'll be fun for the parents too, and so I just kinda started thinking through, you know, if I did an ABC book, first of all, are there even enough letters in the alphabet for every so so I or, you know, or let's flip that and say, are there enough terms to cover every letter in the US alphabet?
And so I just started drafting them out, you know, a through z. Can I come up with enough generic cybersecurity terms that aren't too too big or too overly complicated for a younger audience, but something that would also be fun for the adults? So that's kinda kinda how that originated.
And then what I also like about that idea is that even if you don't explain everything about a term, it at least they've heard it. And so sometimes when I'm talking to people, they've never even heard the word Yubikey, for example.
But if you've got it in the younger audience, you've got some cyber literacy that starts really, really young. Even if they don't know what something is, they do know what the if they've heard the term. And so then they're not trying to learn that there is a term and then what it's what it means and all of these things. So so just being knowing that that a word exists, I think, is a step towards being able to teach people, what it means.
So I think that's, that's definitely value in that. But let's talk about the illustrations, which I love. These are so cute. Yes.
Tell me about, how you chose an illustrator for these.
Yeah. So that was one of the original challenges. Right? I've never created a book. I was going to draw them myself originally, which is hilarious because if you look at my sketch drawings, I mean, they were they would have been boring.
Thank goodness for my wife and kids because, I came up with some pretty cool terms, I thought. But then, you know, I was gonna do, like, b is for buffer overflow, and then I had this, input box that looked like an HTML form field. And then I had characters going past the past the limit. And then I'm like, that's not a very cool illustration at all.
And, but how can I take a a term like buffer overflow and relate it to a real world scenario where, you know, kids can see characters acting out, whatever that represents?
And, I think it was my wife that was like, what about cute monsters or something?
-Nice.
-And, so one of the first things, you know, I was like, well, I can't draw monsters. I'm pretty awful illustrator, at least when I'm trying to come up with something unique.
And I didn't want these to look like anything else. You know? I didn't wanna base there's a million different, you know, illustrated monsters out there for kids. And I hired a bunch to basically do one illustration.
And, I came up with a pretty challenging first couple of, ones. So like, zero zero day was one of the first ones I had people do which was a pretty complicated illustration and then, unauthorized access was the other one. And so if the illustrators could come back and kinda get what I was thinking in my head, because it's really hard to convey a a concept like that into an illustration.
And I tried not to micromanage too much, but I had a pretty good idea of what I wanted each one to represent, because I didn't expect the illustrator to also have a cybersecurity background. That's that's kind of a stretch.
That might be a little unreasonable.
Yeah. Yeah.
But I found this one illustrator, Amanda Matthews. She had she was an award winning illustrator I thought well she's gonna be expensive but you know let's try it let's have her test a couple out and she did amazing I mean and she's the one I ended up ultimately going with long story short she ended up quitting fiber after the first book, and I thought I didn't know if I was gonna make any more books anyways.
But fortunately, you know, we had a relationship with so I was able to go back and and basically beg her to come back and do the other two books. And, she said she had so much fun doing the Malware one, that she did agree to it and that's why we have the three books now.
And tell me the names of the other two books.
So r is for red team, and b is for blue team are the other two books in the series. And I wanted one, so the first one, M is for Mauer, is more generic, because I thought it was the only one I was going to do. So, you know, it covers concepts across all of information security.
Ours for Red Team focuses on just offensive cybersecurity concepts, where b is for blue team focuses on the defensive techniques.
So I thought each one might be a little bit more personalized to each person's career.
Somebody that's in cybersecurity might get a kick out of, oh, you know, I'm a pen tester. I would like the red team one, or I work in a sock. I would like the blue team one.
Or, you know, I do forensics or something like that.
So that that was my goal, was to try to just bring it home and try to tie up, you know, as much of the the field as I could and and three three small bugs.
And and what a fun, like, idea for a gift for someone who is a a, you know, like a colleague who's a pen tester who is on this in the SOC. If anybody knows anything about, cybersecurity is we like our kitschy little things. Every time I walk past other people's desks, all all you see is these little, you know, squishy squishy toys and other things that we picked up at various conferences. And this is definitely it's a fun thing to add.
So, fun thing to add. So, when when you think about back to MS for malware, it covers a lot of ground. And and so how did you and and you thought it was going to be the only one. So how did you settle on the the the topics that that just in the alphabet that's in this book?
Well, that's a good question. So some of them were just I I I came up with them only because it's really hard to come up with certain letters specifically. You know, when you get down to the end of the alphabet and you're talking about x, y, and z, those are extremely hard, letters to try to come up with. And so some of those, like, YubiKey, for example, I try to avoid, brands and and specific products because I kinda wanted this these books to be timeless as as timeless as you can be in security. I know the field changes dramatically and quickly. Sure.
But I I didn't wanna date myself too much.
But YubiKey is one of those things where, you know, it was that or y two k or something. You know, there were there weren't too many.
And and I didn't feel like that really had a place Yeah.
It's over.
The cybersecurity space. Yeah. And it's, like, way it's way behind us, especially for kids. They're like, that's a hundred years ago.
Who was even alive then?
Yeah. That was like before the dinosaurs or something.
Anyway, so so some of those, you know, just having a difficulty finding a term dictated what those letters were going to be. And then other ones, you know, I came up with multiples. I came up with maybe ten letters or ten terms per letter. I had a a Microsoft OneNote that I just wrote down each one that I thought of.
And And I would. I would think about it while I was driving to work. You know, I'd be thinking about it when I went to appointments and things like that. And anytime I thought of something, I would stop and and add it to the list.
And, eventually, I just kinda filtered out the rest of them and chose one. And and often, I would choose one based on what I thought would be easiest to conceptualize visually.
Mhmm.
And and certain ones were great terms, but I thought, you know, that would be really hard to act out in a scene.
Yeah.
You know, how in the world am I gonna take, like, Java deserialization, for example, and turn that into something that that the kids understand.
Right. But, what I like is that Java deserialization actually made the cut.
So Yeah.
And it's one of the only ones that really doesn't, depict what it means in the illustration. I just had fun with it.
But So if you look at that, you know, when Java is the coffee.
I kinda like cereal. So maybe that's why I like just just the serialization, but, you know, also the weird pun. So Yes. That was were there any ones that you that you kinda wanted to put in, but it was just too hard?
Yeah. And those ended up ultimately making the cut in the red and blue team ones because I I was again getting to the point, especially when you do it three times. Right? You get to the point where it's like, man, we're really grasping, for letters here for terms.
And I didn't want, you know, I didn't wanna budge. There were people that were like, hey. You know, why don't you just take the second letter like they do in some alphabet books. You know, they they capitalize on exfiltrate, and they'll do the, you know, the e the x, you know, as the letter x, and they'll make it big and bold.
And I thought, no. I don't wanna I didn't wanna compromise. You know, I was pretty particular about what I wanted. I wanted the I wanted the first letter to make the most sense.
That's that's kinda why I went that route, with those.
Okay. So which which one is your favorite?
Oh, that's a good question. I should have thought about that before it's before this podcast.
Do you have a favorite?
Was it more like your kids were? Of course, you don't have a favorite, but you do, but you just don't say it.
I don't have a favorite. I think, I think my favorite, and it was originally the biggest the biggest pain for me and the biggest headache, again, was why, but this time in the red team book. So why so serial is a is a tool.
You know, I don't I assume a lot of our listeners are familiar with it. It's to exploit Java deserialization vulnerabilities. So it ties back to Java deserialization again, which has always been the hardest concept for me. So now I have to illustrate I come up with a way to conceptualize a tool that exploits Java deserialization.
And I'm like, how in the world am I gonna come up with a graphic?
But I have to pick this term. There's, like, nothing else I can think of. So, I thought about it and thought about it, and and I literally had dreams about it when I was trying to sleep. I, you know, I'd I'd wake up thinking about it in the middle of the night.
And finally, I was watching Star Trek and, just nerding out and watching an episode of Star Trek. And probably instead of doing a deliverable or something, I was supposed to be working on. And and, you know how they materialize and dematerialize, and they're oh my goodness. All the star trek nerds are gonna get upset with me now because it I assume it's called a transporter.
That's okay.
We'll let them be upset.
You know, it basically decompiles or it takes takes apart your atoms and your molecules and then recompiles them on the other side. And I thought that is just like deserialization.
You know? You you serialize data and you deserialize data. And so it hit me. I could have a monster stepping into, one of these transporters where they're getting, you know, dematerialized.
And, you know, Java deserialization is where you're basically manipulating that payload so that it'll come out, you know, and do something different when it's, you know, resealized.
So or you deserialized. And anyway, my point is, after thinking about this forever and almost going crazy and you can see why talking about it, I thought I'll have a little robot in there because the robots are supposed to be the red team and they're kinda playing tricks and trying to to exploit the blue team.
He'll be flipping a switch and and changing the location.
So in the attack, they're making the dragon basically come out at a different location than he anticipated, examples of how something fairly complicated works.
So I think that that maybe, your next book should be using these, stories and and nontechnical things to explain very technical, concepts because they're hard. I decided to give myself a challenge this year.
And so I'm learning how to do JavaScript and, like, all of the the, full stack web developer, taking a course. Right? Online.
This Yeah. It's awesome. It's not fun. I'm not having a good time. It's really, really hard. I have so much respect for developers.
But what I find is when I get stuck, I'll go to YouTube and say, alright. Somebody find me an explanation that is not just telling me this is the term. This is how it works. This is how you use it. I wanna know I I want something that I can hang the ideas on in my head that are not technical. And so I think that's the real value in some of these things that you're putting in your book is how do we take the nontechnical and use them to explain the technical.
I think it helps Right. Settle things in our heads better. And so, maybe you could do, like, the next step up book for, like, middle schoolers just as an idea.
That's that's a good yeah. No. That's a great idea. And, there's a lot of people out there I've noticed that I follow on Twitter and other social media platforms where they, you know, create these awesome infographics.
I'm sure you've seen them go around too where they take, you know, complex topics and they break them down and they make them really understandable. Yeah. And I I think that's really, really neat Yeah. That people do that.
It's, yeah, so much better than, just using technical terms to explain technical terms and because that kind of keeps up the barriers to understanding, when people are trying to just get into cybersecurity. So a lot of the people who listen to this, show are not technical cybersecurity people. And I love that because it it means that we can we have a chance to talk about, technical things to nontechnical people and hopefully be successful on that. But, there are also some Yeah. Some technical people who listen to it as well. So, hopefully, it there's value in what you're doing to people of all stripes.
So, it sounds also like when I when I was reading through the thing, I what I really liked is that the very end of the book, of m is for malware, there's online safety tips. Don't chat with strangers on the Internet. Right? Never provide personal information without approval from a parent or guardian. So, tell me more about why you decided to put that at the end of your book.
Yeah. I put that, I end up adopting that same strategy for for all three books.
And I did that because, you know, there's not a lot of this is for kids, you know, under a certain age.
There's not a lot of space. It's a six by six book. So there's not a lot of space for text. You know, I I wish I could describe every term in detail, and why it's in there and why it's important. There's just not there's not physical space on on the page. So I wanted at least a page at the end. I didn't wanna do a glossary.
I felt like that was a little too tacky for kids to write a board book, but I did wanna do safety tips because that's important to me.
I have a passion for, you know, keeping people safe online, especially young ones, especially as as my own kids are starting to grow up, you know, I want them to be safe online.
So the things, you know, that we all kind of understand as adults that you shouldn't do, you know, be to be safe online and and, you know, that that that includes everything you just mentioned.
I wanted to put that in the book and I wanted to kinda drive that home, you know, for different concepts like cyber bullying and and things like that. You know, look out for things that make you uncomfortable and tell your parent, tell an adult, if if anything makes you uncomfortable that you see online. Because I want that to be a conversation. And and this whole book is about, you know, I don't expect kids to pick this book up and understand the concepts right away by themselves.
I don't expect them to scan the QR code and go out there and and read the glossary. Sure. I wanna empower I wanna empower the adults to teach.
And so they don't have to tell the kids everything that goes into an illustration like I just explained with, you know, the deserialization and the lyso serial tool. I don't I don't expect that, but I do hope it opens up a broader conversation.
Sure.
You know, when you're online, don't give out your data. Be careful if you click on links, things like that. It it really boils down to those those basic messages. Right.
The and, well, I forgot to mention the QR code, which is on the inside of the front cover. So you can scan that and it takes you to a glossary and it and it has not only more information about the term, but how the illustration is representing that term. So you can kind of connect those ideas in your head between the the, the illustration and the concept, itself. And I I think that's great because like you said, you don't wanna put all of that information in the book.
What a turn off that would be to most Right.
Kids to have, what are all of these words on the page that I cannot read and it doesn't make sense what I do?
Right. But when they're ready for more information or if the parent wants more information, they can go and look at the glossary. It gets them a little bit of a step farther into their understanding. And sometimes that's enough to then go seek out more information. There's I love that today, if I don't understand something, I can go, pull out my phone, type it in, find out all of the information in the world about pretty much any topic.
Yeah. Absolutely.
And so often it just starts with, do you have that that curiosity sparked to be able to go and do that? And and so I have a I have some, friends who when they don't know something, they're just like, I just don't know that. And and I'm like, but let's let's find out. What is like, we'll we'll find that out.
Check it out.
Yeah. It's just silly things. We're sitting around the other day talking about this fish called a Chucky mad tom. Why is it called a Chucky mad tom?
I don't know. So then we go down this rabbit hole of what this is some kind of catfish in the south. Right? And so and and and the the idea that we can start with a term that is completely unfamiliar to us and then go down that that rabbit hole of all of this information that is available for us to us for free.
And it's the same thing in the cybersecurity world. If you wanna find the information, if you wanna understand something better, all you need is the curiosity sparked first.
Yeah. Absolutely. And the kids are often the ones that get us thinking. Right? As adults, they ask questions that we wouldn't think of sometimes.
Oh, yeah.
And, you know, if you wanna see a picture or something, that that's my kid now all the time. Like, can I see a real picture of that animal or something?
And it's like, yeah.
Let's do it. And I'll learn something most of the time by looking that up. So Yeah. You're exactly right.
Is that real or is that a made up thing or is that and they wanna know. Right. Yeah. I I used to have a Yep.
A rule when my children my kids are in their twenties. And, in some ways, that's a relief because I used to have a rule where we they were not allowed to ask me physics questions after seven PM because I was done. I was my brain was done. I didn't want Checked out.
Sometimes I'm like, man, maybe I wasn't a very good mom because I should've just let them ask questions. But sometimes you just reach your limit in the day.
Absolutely.
Okay. So, finding you mentioned a minute ago about helping parents keep their kids safe online.
I know there's some other are you familiar with any other places that they can go? Other people's, maybe works that we can point people to? I know we can put it in the notes for sure.
Yeah.
So shortly after I created my book, I was aware, and usually because people reached out. And I did do some some, you know, searching online to see if there were this was done before because this wasn't something I was probably gonna do unless, you know, it was a new and novel.
Marcus Carey came out with a book, I I believe, shortly after called The Three Little Hackers three little hackers just three little hackers. Okay.
I bought that book and I thought it was great. He really focused on the privacy aspect and I don't wanna give too much about a way about the book.
But I do recommend it. I thought it was a good story. Right. And it makes kids think about, you know, being safe online. And again, you know, almost to those points in the back of my book where I talk about, you know, common sense things like, you know, don't give out information to strangers and things like that.
His story plays right into that and that's perfect. You know, Thinking Code is another one that Marcus Carey created.
You know, and I came across several, little ones like, Skate and Me and a really cute looking books that other people had done that were either IT focused or cybersecurity focused in some way. And I love that I'm seeing more and more of that.
You know, this isn't something I feel like, you know, I certainly don't have or, the market cornered and I don't wanna have the market cornered in this. I think the more material, the better. So I encourage people to create content for for children, and I'm excited to see more and more, you know, courses and there's companies getting involved, that are creating content for children Right. Around, security and privacy. That's awesome.
We had Vandana Verma on on the podcast a couple of episodes ago and she, started up a group called Infosec Kids.
And then It's awesome.
There yeah.
There's a lot of, groups that when they start with, like more cybersecurity for women or or other minority communities bringing in people who typically aren't aren't known to be heavily involved with cybersecurity.
They tend to have some type of arm that has to do with children.
So I'm I'm sure there's a lot of resources out there. We'll definitely have links, in the show notes for people who want want to learn more about that.
But like I said at the beginning of this, I'm assuming that a lot of people who are adults are not actually buying these for their kids because I'm putting this on my shelf. And and, and I'm really excited about having this as part of my my library. Do you get that feedback from other adults as well?
Yeah. It's funny, Jen. I do, and thanks for saying that. I I it's funny. I get a lot of feedback around, you know, yeah, these are for my kids.
You know, I bought two copies. These are for my kids and these are for me. I don't want my kids, like, dinging up the corners and things like that.
Or I don't even have kids and I love these books here, you know, things like that. I love I love feedback.
That's one of the most rewarding things about making this book is getting a message about it. And, you know, I really want positive and negative feedback.
So I'm scouring, you know, I'm scouring Twitter for comments about the the book even if they didn't tag me specifically in it. So if you're listening to this and you have the book, I would love some feedback.
No pressure at all. I just wanna make sure everybody enjoys it and specifically when I made the other two books, I wanted to make sure it lived up to the expectation of the original.
But yeah, I do see a lot of people, especially in our profession, you know, they buy them for themselves and they put it on their desk or, you know, they put it in the background of their webcast which I think is really cool.
I reached out to the people at MITRE Uh-huh.
Because I was thinking about using their attack framework in one of the books and unfortunately, it didn't work out that way because I came up with a different letter for a that I thought fit better.
But, I got some really, really encouraging feedback from them that a lot of people that work there, you know, have their books on display proudly on their desk and things like that. And so, you know, I'm like, nobody knows who I am. This is really neat to be able to talk to people. And then, you know, my buddy was watching a Black Hills, webcast that they do.
And in the background of John Strand's office, he has, you know, my three books on display and even gives me a shout out in it. And I thought that is really neat that, you know, these cybersecurity professionals that everybody knows, you know, it's getting into the hands of a lot of people, and I never expected that when I first created this. And I'm humbled by the whole thing and excited by it. I think it's really, really neat.
Those Black Hills people are I I follow I kind of stalk them online because I think they're really cool. They've got a lot of good things going on. And, like you, I love this podcast because I get to talk to interesting people in the in the industry as well. And, you know, come to think about it, if they're if as a listener, if you have somebody that you think would be great on this show, reach out. Let me know. I would love to talk to new people. And I don't I certainly don't know everybody in the industry, but they have a great way of gamifying, incident response.
And and when you can gamify that and it's not a drag, it it really is a great way to improve the security stance of any organization.
And and so in in the community, I I know early on, there was a lot of, kind of make maybe some gatekeeping people keeping other people out of cybersecurity. And I just don't feel that anymore. It feels like a very open and inclusive welcoming community.
And and I do a lot of, mentoring. People often ask me, well, how do I get these broader conversations? How do I network? How do I how do I get to meet these people who I find compelling?
How do I, be more part of the community? And one of the best ways to do it is to start contributing to the community. So like you did. Yep.
You know, you you start putting things out there. People will especially if you're doing it in a positive, supportive way that is trying to better the community, Other people will rally around that and support your efforts.
Yeah. And even the community itself, you know, it, it kinda bothers me to see sides fighting over, you know, fighting each other, like the red team and the blue team. You know, I don't like to see a divide. Sometimes you see almost these Twitter wars, and and I get it.
Some some some red teams think they're, you know, really elite or something because, and some security, you know.
And then and then they almost look down on the blue team or vice versa and I think no we're all here together, we all play a role, we need each other, there's definitely two sides to this and it could be argued there's more sides than that even you know we we need every area of security, everybody plays a part and so that also kind of motivated me to come out with the red team and the blue team books because I wanted to show, you know, from my own background, I I love the red team, I still love the red team, I do, you know, I jump in and do incident response still because I love it so much, and I used to do digital forensics.
So let's take that and put that into these books and then also make the red team, and let's make them balanced. And and I tried in the concepts. If if you look at the red and blue team I I just had fun with it and I played off certain concepts back and forth between the two and I tried to tell a little bit of a story with certain terms.
Right. So you know like, the dragons were the blue team and they were defending a castle or or some you know something like that and then the red team are these robots and they're kind of invasive they're trying to sneak in the castle they're even impersonating you know I is for impersonation in the red team they're dressing up like a dragon to see if they can sneak into the castle and then you'll see that same robot later, dropping a drop box, and b is for drop box or something.
So things like that. I try to put some in some page and then I'll reference them in the other book and that's just for parents that just happened to know. I try to put little Easter eggs on there to make it fun for the parents too.
Well, I'm clearly, I'm gonna have to get your other two books because I love dragons. They're my favorite thing.
And I love that you use them for blue team because that's I'm solidly blue team.
And, Yeah. But even on blue team, you have to know how red team thinks and how red team works or you can't be successful at blue team. And so so knowing what those balances are, I think is is really important. And I'm glad that you talked about that, about the, a little bit of push pull sometimes in the community between different groups.
But, I think some some competition and and challenge of each other is is healthy. But looking down on another group, that doesn't get us anywhere. But, No. Yeah.
I'm I'm, I'm not on Twitter, because I find it to be assessable.
Yeah. Twitter is not the best place to get cybersecurity information.
Oh, it's really I shouldn't have said that, but I hope that isn't too rude. But it it just feels really uncomfortable to be on Twitter. It seems like, it's just people trying to make a point but not listening. And so, yeah, I I find a lot of value in these face to face conversations. And since we don't have conferences happening still, it's hard to get that.
Yeah.
And and that's, I think, one of the value, the the valuable things in going to a conference is not, well, can I get this information anywhere else? Of course, you can. Information is free. I think we talked about that. Right? But going to a conference, you get to talk to people in person about ideas and and thoughts and, these concepts that that it it brings some real, value to having that conversation with with other people who are excited about the same concepts.
Absolutely. Yeah. And you do learn a lot just being there in person, you know, there's something about it.
I know, you know, the kind people at Circle City Con, I'm in Indianapolis, so Circle City Con, you know, is like thirty minutes from my house. So, the kind people at Circle City Con last year were going to allow me to set up a booth for next to nothing and because they believed in the project and they thought it was really neat, you know, what we were doing for the community. And so, I was gonna take that opportunity to set up a booth and and more than anything, just get to see people in person and, I was excited not to have to charge people for shipping. I thought, well, that'd be cool if they walk by, they pay some money, and I get to meet people.
And then the pandemic hit, of course. So that kinda shut down everything. Yeah. So I'm excited to get back out there when, you know, everything opens up again, and then we can safely all get together and go to these conferences again.
Me too. I speak at a lot of right.
Even virtually, I spoke at a lot of conferences this year, but, and it might surprise people to know I get so anxious just before getting you know, the night before I don't sleep and I'm just it's honestly terrifying standing up in front of people and talking. Why do I do it?
Because of these opportunities. Because it it it lets me then talk to people about what I'm excited about. And so it's worth it to me to go through that Yes. Not feeling super great in order to have these per these personal face to face conversations that that happen at conferences. So I'm, so hope that those are gonna open up again, soon because I would love to see people in person.
Well Yeah.
And look at you now. You're an amazing podcast person.
Oh my gosh. I don't know. This is something life takes you in weird directions, and I'm so fortunate that I get to be hosting this podcast and meeting people. So, it's been an absolute delight talking with you, Curtis. Thank you so much for coming on and talking about your book and talking about the things that drive you and and make you excited about cybersecurity.
Tell me the the, URL for people to go on and purchase books from you.
Yeah. So it's cybersecurity, a b c's dot com, which is the longer version.
Mhmm.
It's really just a redirect for m is for malware dot com, which is the original title.
Okay.
I sell it exclusively on my site. So you might see it on places like Amazon. You know, you referenced earlier. I did try to sell it on Amazon.
I did, sell it successfully on Amazon if you call it that. I lost money because I'm not very good with budgeting apparently and miscalculated all of that. So I had to take it off of Amazon so it could be profitable Yeah. And sell it directly on my own site.
So right now, that's the only place you can get it unless I do, you know, sell it in person. I'm hoping to take it to some conferences. I'm hoping to give them out to libraries. I have a lot of copies that are extra that I'm hoping to, either give away to people in the community or, I would love to just start shipping them to random libraries throughout, the US and and so hopefully people can, you know, rent those at their at their local library Nice.
If they want to.
Yeah. Before we go, I wanted to give you the instructions for entering our giveaway for this very cute book. Whether it's for you, for your desk, for one of your kids, for a colleague, I'll bet you know a colleague who would love to have this and I mean it's hard sometimes to find good gifts for nerds.
This is this is definitely one of them. Here's how we're going to do it. Go to YouTube. Even if you're an audio listener, we need you to go to YouTube.
Subscribe and leave a comment about, you know, something you heard on the show that you enjoyed. Something about Curtis's book. People who leave comments will choose five of the people who leave comments and and get the book to you. If you don't win or if you would like to support Curtis, which I think is a great idea, he puts so much time and effort into these books and his own money, Go over to emmas for malware dot com. We'll have the the links in the show notes. Go my book.
Well, terrific. We'll definitely put the all of those links that we've talked about today in the podcast. We'll put them in the show notes. And, again, super happy to have you here. Thank you so much.
Yeah. Thank you, Jen. It's been a pleasure. Thank you. Thanks.
Thanks for watching. To watch more episodes of Security Metrics podcast, click on the box on the left. If you prefer to listen to this podcast, it's available on all your favorite podcast platforms. See you on the slopes.
