Back on the World Wide Interweb
I'd like to thank Rimuhosting, MySQL, Apache, PHP, Ubuntu, Wordpress and Google for getting me back on the tubes.
The first post. It is a thank-you note to a stack.
The thoughts of Andrew Becherer on software, life and Tacoma.
ARCHIVE 45 posts recovered
SPAN 2007-04-08 to 2008-07-29
SOURCE web.archive.org
STATUS andrew.becherer.org stopped
serving this in 2008, and has
not served it since
This was a WordPress blog at andrew.becherer.org/blog/. It ran for fifteen months and then stopped. The domain is still listed in its author's LinkedIn profile, in the websites field, where it has pointed at nothing for eighteen years.
Forty-six archived URLs survive in the Internet Archive. Forty-five of them are posts. The forty-sixth snapshot caught the site mid-migration and preserved a Drupal error page reading Site off-line, which is its own kind of document and is not counted here.
The title is a Java joke.
What follows is the blog, and then what happened after the blog. Everything in quotation marks on this page was written or said by its author. Nothing has been tidied, including the typos.
I'd like to thank Rimuhosting, MySQL, Apache, PHP, Ubuntu, Wordpress and Google for getting me back on the tubes.
The first post. It is a thank-you note to a stack.
In theory I am a client/server developer (Java & .Net) but in practice I am a jack of all trades.
He found unannounced public WiFi on the Sounder commuter trains before the transit agency had documented it anywhere. He worked out the SSID naming scheme, and he told readers which part of the train to sit in.
Everyone should come out and get your geek on this Saturday afternoon at the Tacoma Linux Users Group.
Two months later the agency published a page confirming the service. He posted again to say so. Notice the undocumented thing, characterise it precisely, publish the finding, then follow up when the official version arrives. That is the whole method, in 2007, on a blog mostly about restaurants.
Day 1 was vegetarian restaurants. Day 2 was things I have always meant to do. Day 3 was stores for computer geeks.
In a Slashdot thread on young jailed computer criminals user sm62704 coined the term cyberglar. Oh my God, that is horrible. On the upside the feds might like it. Cyber, cyber, cyber, cyber.
That is the entire post.
Dear Santa, All I want for Christmas is the HTC Touch Pro running the Google Android operating system. Thank you.
Also the entire post. Posted in June.
The last post. There was no farewell and no explanation. A man wrote about his city for fifteen months and then had other things to do.
Unedited, as recovered. This table is the most honest biography on this page.
Tacoma . . . . . . . . . . 24 Blogging . . . . . . . . . 10 Uncategorized . . . . . . 5 Linux . . . . . . . . . . 4 Wireless . . . . . . . . . 4 Network Security . . . . . 4 Taclug . . . . . . . . . . 3 Navel Gazing . . . . . . . 3 UWT . . . . . . . . . . . 3 Art . . . . . . . . . . . 2 Lists . . . . . . . . . . 2 .Net . . . . . . . . . . . 1 Java . . . . . . . . . . . 1 Programming Languages . . 1 ideas . . . . . . . . . . 1
Twenty-four posts about a mid-sized city in Washington. Four about network security. He was, at the time, simultaneously finishing a computing degree at night, working full time at a bank, sitting on the board of the Tacoma Linux Users Group, presiding over a student ACM chapter, advising a student security group, and acting as liaison between his university's technology institute and the regional open-source groups.
The blog stopped. The writing did not. It moved onto other people's platforms, which is where it has stayed, and those platforms decay at their own pace.
From here each entry carries what kind of evidence it rests on. Two labels do most of the work. PUBLIC‑CITED means a stranger can pull the artifact and check it. SELF‑ASSERTED means he is the source. Not doubtful: sourced to him, and said so.
My primary emphasis is placed upon helping software developers build safe, reliable code.
Seven years. iSEC Partners was acquired by NCC Group in 2010, five years in, and continued to trade under its own name, so the brief NCC-titled stretch at the end is a change of letterhead inside one tenure rather than a separate job.
A named co-author of three. The byline is alphabetical by surname. His section is the Linux pseudorandom number generator under Xen, and it is 8.2 minutes of the 61. The slides are the artifact that survives best:
Computers are deterministic, cannot generate random numbers with math.
Don't use these for online poker
He builds the attack completely. Fingerprint the victim instance, pull the machine image, extract the seed file that ships identical to every user, model the interrupt timings, then:
Simulate ssh-keygen. Test against fingerprint. If fail, permutate PRNG. Goto 6.
And then, having spent the whole section building it, the next slide says:
Is this a practical attack? Maybe. Or maybe not.
Dangerous enough to fix.
Followed by three mitigations. That refusal to oversell a finished attack is the most durable thing in this entire archive, and it never changes.
A white paper and a deck, both still on Black Hat's own media server. The paper opens:
As originally implemented Hadoop security was completely ineffective.
The objection is never that a primitive is weak. It is always about how many machines the design assumes:
The secret key must be shared between the Name Nodes and all of the Data Nodes — SHARED WITH ALL OF THE DATA NODES!!! That is a lot of nodes.
Alice had access the Hadoop cluster. Bob had access the Hadoop cluster. Alice and Bob had to trust each other completely. If Mallory got access to the cluster Alice and Bob both died in a fire.
(The missing "to" is his. Quoted as printed.) One slide is headed Tokens: Gotta Catch 'em All. And the conclusion, again, declines the easy verdict:
The new Hadoop security model requires additional time and effort before it will meet the requirements of many large enterprises.
Not "Hadoop is insecure." A scoped claim about large enterprises.
The title is the posture. It was recovered from a third party's conference recordings on the Internet Archive, which is the only reason anyone knows the talk happened.
During last night's meeting I brought up an excellent paper that was recently brought to my attention, Privilege Separation in HTML5 Applications by Devdatta Akhawe, Prateek Saxena, and Dawn Song at the University of California, Berkeley.
He attended, and then posted to recommend somebody else's paper to the room. Five years into a consulting career, still doing the user-group thing. It is not a speaking credit and is not listed as one.
Datadog's first security hire. The tenure spanned the company's Series B through its IPO.
The published research stops here. The output for this stretch is not a paper. It is a security program at a company that went from Series B to public.
Human based defense is dead. Staris is reinventing application security for an increasingly AI driven world. The future promised by generations of security automation is finally achievable. We use generative agents to eliminate the undifferentiated manual toil that has limited the scope and effectiveness of security assessment.
A complete thesis with a date on it, sitting in a profile field where nobody looks. "Undifferentiated manual toil" is his phrase.
Mythos? I'm a practitioner, not a pundit. I have to prepare for this. If you do too, the real question is… how long until Mythos capabilities go commodity?
Today the burglar class with these capabilities are state actors and well-capitalized criminals. People with budgets, org charts, and dental plans. In future it is anyone with a mid-range GPU and an afternoon.
State actors don't get new capabilities from Mythos. They get margin.
Eighteen years after cyberglar, the same instinct: the interesting question is never the scary one, it is the one about who gets the thing next and how cheaply.
I joined Socket because the supply chain is where the fight is right now, and Socket is doing some of the hardest, most important work in this space.
Every CISO I talk to is trying to figure out how to give their developers the open source ecosystem and the AI tooling they need without inheriting somebody else's malicious package.
And from his own description of the role:
I own the internal security, IT, and trust programs: engineering security, infrastructure, compliance, and risk. I also show up as a peer to the CISOs and security teams that depend on Socket to secure their software supply chain.
Which is the most concrete definition of the job anywhere in the record, and note the second sentence: at a security vendor he treats the buyer-side CISO community as part of the job.
Every archive is partly a record of what did not survive. This one more than most, because its author published into other institutions' channels for eighteen years and those channels do not keep things for you.
Created 2011-03-06. Zero public repositories. The account is real, the name on it is his, and it is empty.
Twelve other consultants at that firm had one. He did not, across seven years and two Black Hat papers under his byline. Neither paper appears in the firm's own publications repository either.
He says he co-authored it. No copy survives in any public archive. Forty search channels and sixty thousand archived pages of the relevant standards body produce no title, no date, and no document number. The search has been logged in full so that nobody has to run it again.
No Substack, no newsletter, no blog. The Bluesky account has eleven posts in three years. The durable independent surface he had in 2007 he stopped maintaining, and nothing replaced it.
Which is, in the end, why this page exists.
He has written this paragraph three times, nineteen years apart, for three different rooms.
The thoughts of Andrew Becherer on software, life and Tacoma.
I've been a software developer, application security engineer, a Chief Security Officer and a founder. I am a husband & dad. Formerly Datadog, Iterable, NCC & iSEC Partners. Living the dream in America's Pacific Northwest.
Andrew Becherer is a security executive working to bring about a secure, trustworthy and fast Internet.
The 2007 one is the only one that mentions a city. The 2023 one is the only one that leads with the sequence rather than the current title. The 2026 one is a mission statement.
A sociology degree, then two years of national service. In his own descriptions of those roles:
I worked in a team of 10 performing 6 to 8 week service projects across the Southeastern United States.
I recruited both volunteer tutors and adult learners.
Between those two he helped win a fifty thousand dollar grant for a mobile computer lab, and converted eleven hundred feet of railroad trestle into a segment of the Palmetto Trail. Then a regional bank, where the security career actually starts, in card-industry compliance. Then a second degree, in computing, at night.
His 2008 About page carried a quotation. It is worth reproducing because of what a man chooses to put at the top of his own homepage, and it is worth attributing correctly, which the internet generally does not:
More people are killed every year by pigs than by sharks, which shows you how good we are at evaluating risk. Bruce Schneier. Not Andrew Becherer. Displayed on his site in 2008.