Writing ·
Ginger Security
In the spring of 2018 at Rutgers I made Ginger Security — security explained by the Security Ginger — a podcast that ran for seven episodes, each one taking a field of the security industry and explaining it to someone who’d never touched it.
It opens with Cybersecurity 101 and a motto borrowed from Offensive Security — the quieter you become, the more you’re able to hear — then spends an episode on how to actually get acquainted with the industry, which in 2018 mostly meant a guided tour of the right subreddits. Penetration testing got two episodes: the first on the cyber domain, the second arguing that the lock on the server room door is as much a part of the perimeter as the software — an attacker who can walk in doesn’t need an exploit.
The back half is the part I still stand by: vulnerabilities and disclosure — what you’re supposed to do when you find a hole: tell the company, tell the world, or sell it — social engineering as the manipulation everyone unknowingly practices, and reverse engineering as engineering run backwards: start from the finished thing and take it apart until you know how it works at every level.
Every episode was “brought to you by the Rutgers Security Club,” which I spent the outros recruiting for. The course ended; the name didn’t — I still ship under GingerSecurity today.