public static final KITTEN: the recovered weblog of Andrew Becherer

The thoughts of Andrew Becherer on software, life and Tacoma.

ARCHIVE  45 posts recovered
SPAN     2007-04-08 to 2008-07-29
SOURCE   web.archive.org
STATUS   andrew.becherer.org stopped
         serving this in 2008, and has
         not served it since

About this restoration

This was a WordPress blog at andrew.becherer.org/blog/. It ran for fifteen months and then stopped. The domain is still listed in its author's LinkedIn profile, in the websites field, where it has pointed at nothing for eighteen years.

Forty-six archived URLs survive in the Internet Archive. Forty-five of them are posts. The forty-sixth snapshot caught the site mid-migration and preserved a Drupal error page reading Site off-line, which is its own kind of document and is not counted here.

The title is a Java joke.

What follows is the blog, and then what happened after the blog. Everything in quotation marks on this page was written or said by its author. Nothing has been tidied, including the typos.


The blog, 2007 to 2008

Back on the World Wide Interweb

2007-04-08 · Filed under: Blogging

I'd like to thank Rimuhosting, MySQL, Apache, PHP, Ubuntu, Wordpress and Google for getting me back on the tubes.

The first post. It is a thank-you note to a stack.

New Job!

2007-07-06 · Filed under: .Net · Java · Navel Gazing · Programming Languages

In theory I am a client/server developer (Java & .Net) but in practice I am a jack of all trades.

SoundTransit Sounder WiFi

2007-08-17 · Filed under: Tacoma · Wireless

He found unannounced public WiFi on the Sounder commuter trains before the transit agency had documented it anywhere. He worked out the SSID naming scheme, and he told readers which part of the train to sit in.

Tacoma Linux Users Group

2007-09-11 · Filed under: Tacoma

Everyone should come out and get your geek on this Saturday afternoon at the Tacoma Linux Users Group.

Sounder WiFi Follow Up

2007-10-22 · Filed under: Tacoma · Wireless

Two months later the agency published a page confirming the service. He posted again to say so. Notice the undocumented thing, characterise it precisely, publish the finding, then follow up when the official version arrives. That is the whole method, in 2007, on a blog mostly about restaurants.

Tacoma Week of Lists, Day 4: The Places I Drink Beer

2008-03-27 · Filed under: Tacoma

Day 1 was vegetarian restaurants. Day 2 was things I have always meant to do. Day 3 was stores for computer geeks.

Worst New Computer Crime Term Ever

2008-05-06 · Filed under: Network Security

In a Slashdot thread on young jailed computer criminals user sm62704 coined the term cyberglar. Oh my God, that is horrible. On the upside the feds might like it. Cyber, cyber, cyber, cyber.

That is the entire post.

Dear Santa…

2008-06-04 · Filed under: Linux · Lists

Dear Santa, All I want for Christmas is the HTC Touch Pro running the Google Android operating system. Thank you.

Also the entire post. Posted in June.

Metropolitan Apartments Phase 2 Delayed FOREVER!

2008-07-29 · Filed under: Tacoma

The last post. There was no farewell and no explanation. A man wrote about his city for fifteen months and then had other things to do.


Categories

Unedited, as recovered. This table is the most honest biography on this page.

Tacoma . . . . . . . . . . 24
Blogging . . . . . . . . . 10
Uncategorized  . . . . . .  5
Linux  . . . . . . . . . .  4
Wireless . . . . . . . . .  4
Network Security . . . . .  4
Taclug . . . . . . . . . .  3
Navel Gazing . . . . . . .  3
UWT  . . . . . . . . . . .  3
Art  . . . . . . . . . . .  2
Lists  . . . . . . . . . .  2
.Net . . . . . . . . . . .  1
Java . . . . . . . . . . .  1
Programming Languages  . .  1
ideas  . . . . . . . . . .  1

Twenty-four posts about a mid-sized city in Washington. Four about network security. He was, at the time, simultaneously finishing a computing degree at night, working full time at a bank, sitting on the board of the Tacoma Linux Users Group, presiding over a student ACM chapter, advising a student security group, and acting as liaison between his university's technology institute and the regional open-source groups.


Posts written somewhere else, 2008 to 2026

The blog stopped. The writing did not. It moved onto other people's platforms, which is where it has stayed, and those platforms decay at their own pace.

From here each entry carries what kind of evidence it rests on. Two labels do most of the work. PUBLIC‑CITED means a stranger can pull the artifact and check it. SELF‑ASSERTED means he is the source. Not doubtful: sourced to him, and said so.

SELF-ASSERTED

Security Consultant, then Senior, then Principal, then Technical Vice President

2008-05 to 2015-05 · Posted to: iSEC Partners, Seattle · a LinkedIn role description

My primary emphasis is placed upon helping software developers build safe, reliable code.

Seven years. iSEC Partners was acquired by NCC Group in 2010, five years in, and continued to trade under its own name, so the brief NCC-titled stretch at the end is a change of letterhead inside one tenure rather than a separate job.

PUBLIC-CITED

Cloud Computing Models and Vulnerabilities: Raining on the Trendy New Parade

2009-07 · Posted to: Black Hat USA, Las Vegas · with Alex Stamos and Nathan Wilcox

A named co-author of three. The byline is alphabetical by surname. His section is the Linux pseudorandom number generator under Xen, and it is 8.2 minutes of the 61. The slides are the artifact that survives best:

Computers are deterministic, cannot generate random numbers with math.
Don't use these for online poker

He builds the attack completely. Fingerprint the victim instance, pull the machine image, extract the seed file that ships identical to every user, model the interrupt timings, then:

Simulate ssh-keygen. Test against fingerprint. If fail, permutate PRNG. Goto 6.

And then, having spent the whole section building it, the next slide says:

Is this a practical attack? Maybe. Or maybe not.
Dangerous enough to fix.

Followed by three mitigations. That refusal to oversell a finished attack is the most durable thing in this entire archive, and it never changes.

PUBLIC-CITED

Hadoop Security Design? Just Add Kerberos? Really?

2010-07 · Posted to: Black Hat USA, Las Vegas · sole author

A white paper and a deck, both still on Black Hat's own media server. The paper opens:

As originally implemented Hadoop security was completely ineffective.

The objection is never that a primitive is weak. It is always about how many machines the design assumes:

The secret key must be shared between the Name Nodes and all of the Data Nodes — SHARED WITH ALL OF THE DATA NODES!!! That is a lot of nodes.
Alice had access the Hadoop cluster. Bob had access the Hadoop cluster. Alice and Bob had to trust each other completely. If Mallory got access to the cluster Alice and Bob both died in a fire.

(The missing "to" is his. Quoted as printed.) One slide is headed Tokens: Gotta Catch 'em All. And the conclusion, again, declines the easy verdict:

The new Hadoop security model requires additional time and effort before it will meet the requirements of many large enterprises.

Not "Hadoop is insecure." A scoped claim about large enterprises.

PUBLIC-CITED

Hack this Site or Learn How Anyway

2010-04 · Posted to: LinuxFest Northwest, Bellingham · video survives

The title is the posture. It was recovered from a third party's conference recordings on the Internet Archive, which is the only reason anyone knows the talk happened.

PUBLIC-CITED

A paper I brought up at last night's meeting

2013-04-12 · Posted to: the OWASP Seattle mailing list

During last night's meeting I brought up an excellent paper that was recently brought to my attention, Privilege Separation in HTML5 Applications by Devdatta Akhawe, Prateek Saxena, and Dawn Song at the University of California, Berkeley.

He attended, and then posted to recommend somebody else's paper to the room. Five years into a consulting career, still doing the user-group thing. It is not a speaking credit and is not listed as one.

SELF-ASSERTED

Chief Security Officer, Datadog

2015-10 to 2019-10 · Posted to: nothing that survives publicly

Datadog's first security hire. The tenure spanned the company's Series B through its IPO.

The published research stops here. The output for this stretch is not a paper. It is a security program at a company that went from Series B to public.

SELF-ASSERTED

Human based defense is dead.

2023-07 to 2024-05 · Posted to: Staris AI · a LinkedIn role description

Human based defense is dead. Staris is reinventing application security for an increasingly AI driven world. The future promised by generations of security automation is finally achievable. We use generative agents to eliminate the undifferentiated manual toil that has limited the scope and effectiveness of security assessment.

A complete thesis with a date on it, sitting in a profile field where nobody looks. "Undifferentiated manual toil" is his phrase.

PUBLIC-CITED

Mythos? I'm a practitioner, not a pundit.

2026-04-16 · Posted to: LinkedIn

Mythos? I'm a practitioner, not a pundit. I have to prepare for this. If you do too, the real question is… how long until Mythos capabilities go commodity?
Today the burglar class with these capabilities are state actors and well-capitalized criminals. People with budgets, org charts, and dental plans. In future it is anyone with a mid-range GPU and an afternoon.
State actors don't get new capabilities from Mythos. They get margin.

Eighteen years after cyberglar, the same instinct: the interesting question is never the scary one, it is the one about who gets the thing next and how cheaply.

PUBLIC-CITED

The supply chain is where the fight is.

2026-05 · Posted to: Socket · first CISO

I joined Socket because the supply chain is where the fight is right now, and Socket is doing some of the hardest, most important work in this space.
Every CISO I talk to is trying to figure out how to give their developers the open source ecosystem and the AI tooling they need without inheriting somebody else's malicious package.

And from his own description of the role:

I own the internal security, IT, and trust programs: engineering security, infrastructure, compliance, and risk. I also show up as a peer to the CISOs and security teams that depend on Socket to secure their software supply chain.

Which is the most concrete definition of the job anywhere in the record, and note the second sentence: at a security vendor he treats the buyer-side CISO community as part of the job.


The drafts folder

Every archive is partly a record of what did not survive. This one more than most, because its author published into other institutions' channels for eighteen years and those channels do not keep things for you.

NOT FOUND

github.com/abecherer

Created 2011-03-06. Zero public repositories. The account is real, the name on it is his, and it is empty.

NOT FOUND

An author page at his own employer

Twelve other consultants at that firm had one. He did not, across seven years and two Black Hat papers under his byline. Neither paper appears in the firm's own publications repository either.

LOST TO TIME

A white paper on securing the development lifecycle for embedded devices

He says he co-authored it. No copy survives in any public archive. Forty search channels and sixty thousand archived pages of the relevant standards body produce no title, no date, and no document number. The search has been logged in full so that nobody has to run it again.

NOT FOUND

Any personal website after 2008

No Substack, no newsletter, no blog. The Bluesky account has eleven posts in three years. The durable independent surface he had in 2007 he stopped maintaining, and nothing replaced it.

Which is, in the end, why this page exists.


About the author

He has written this paragraph three times, nineteen years apart, for three different rooms.

2007 · the blog tagline

The thoughts of Andrew Becherer on software, life and Tacoma.

2023 · Bluesky

I've been a software developer, application security engineer, a Chief Security Officer and a founder. I am a husband & dad. Formerly Datadog, Iterable, NCC & iSEC Partners. Living the dream in America's Pacific Northwest.

2026 · LinkedIn

Andrew Becherer is a security executive working to bring about a secure, trustworthy and fast Internet.

The 2007 one is the only one that mentions a city. The 2023 one is the only one that leads with the sequence rather than the current title. The 2026 one is a mission statement.

Before all of it

A sociology degree, then two years of national service. In his own descriptions of those roles:

I worked in a team of 10 performing 6 to 8 week service projects across the Southeastern United States.
I recruited both volunteer tutors and adult learners.

Between those two he helped win a fifty thousand dollar grant for a mobile computer lab, and converted eleven hundred feet of railroad trestle into a segment of the Palmetto Trail. Then a regional bank, where the security career actually starts, in card-industry compliance. Then a second degree, in computing, at night.

The epigraph

His 2008 About page carried a quotation. It is worth reproducing because of what a man chooses to put at the top of his own homepage, and it is worth attributing correctly, which the internet generally does not:

More people are killed every year by pigs than by sharks, which shows you how good we are at evaluating risk. Bruce Schneier. Not Andrew Becherer. Displayed on his site in 2008.