diff --git a/assets/portraits/security-pros/card_001.png b/assets/portraits/security-pros/card_001.png deleted file mode 100644 index a984533..0000000 Binary files a/assets/portraits/security-pros/card_001.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_002.png b/assets/portraits/security-pros/card_002.png deleted file mode 100644 index 33e3bf0..0000000 Binary files a/assets/portraits/security-pros/card_002.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_003.png b/assets/portraits/security-pros/card_003.png deleted file mode 100644 index 99951f1..0000000 Binary files a/assets/portraits/security-pros/card_003.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_004.png b/assets/portraits/security-pros/card_004.png deleted file mode 100644 index 43e7367..0000000 Binary files a/assets/portraits/security-pros/card_004.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_005.png b/assets/portraits/security-pros/card_005.png deleted file mode 100644 index f470845..0000000 Binary files a/assets/portraits/security-pros/card_005.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_006.png b/assets/portraits/security-pros/card_006.png deleted file mode 100644 index 7ddc4c6..0000000 Binary files a/assets/portraits/security-pros/card_006.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_007.png b/assets/portraits/security-pros/card_007.png deleted file mode 100644 index d790e1f..0000000 Binary files a/assets/portraits/security-pros/card_007.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_008.png b/assets/portraits/security-pros/card_008.png deleted file mode 100644 index d9ab256..0000000 Binary files a/assets/portraits/security-pros/card_008.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_009.png b/assets/portraits/security-pros/card_009.png deleted file mode 100644 index debf88d..0000000 Binary files a/assets/portraits/security-pros/card_009.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_010.png b/assets/portraits/security-pros/card_010.png deleted file mode 100644 index 795a602..0000000 Binary files a/assets/portraits/security-pros/card_010.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_011.png b/assets/portraits/security-pros/card_011.png deleted file mode 100644 index e2787a2..0000000 Binary files a/assets/portraits/security-pros/card_011.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_012.png b/assets/portraits/security-pros/card_012.png deleted file mode 100644 index 22054c3..0000000 Binary files a/assets/portraits/security-pros/card_012.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_013.png b/assets/portraits/security-pros/card_013.png deleted file mode 100644 index 76ce6dc..0000000 Binary files a/assets/portraits/security-pros/card_013.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_014.png b/assets/portraits/security-pros/card_014.png deleted file mode 100644 index 2770667..0000000 Binary files a/assets/portraits/security-pros/card_014.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_015.png b/assets/portraits/security-pros/card_015.png deleted file mode 100644 index 584188f..0000000 Binary files a/assets/portraits/security-pros/card_015.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_016.png b/assets/portraits/security-pros/card_016.png deleted file mode 100644 index bca299f..0000000 Binary files a/assets/portraits/security-pros/card_016.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_017.png b/assets/portraits/security-pros/card_017.png deleted file mode 100644 index 5d282fd..0000000 Binary files a/assets/portraits/security-pros/card_017.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_018.png b/assets/portraits/security-pros/card_018.png deleted file mode 100644 index dbc2054..0000000 Binary files a/assets/portraits/security-pros/card_018.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_019.png b/assets/portraits/security-pros/card_019.png deleted file mode 100644 index 4a15018..0000000 Binary files a/assets/portraits/security-pros/card_019.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_020.png b/assets/portraits/security-pros/card_020.png deleted file mode 100644 index 8c946de..0000000 Binary files a/assets/portraits/security-pros/card_020.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_021.png b/assets/portraits/security-pros/card_021.png deleted file mode 100644 index 2735548..0000000 Binary files a/assets/portraits/security-pros/card_021.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_022.png b/assets/portraits/security-pros/card_022.png deleted file mode 100644 index 7b5ffa0..0000000 Binary files a/assets/portraits/security-pros/card_022.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_023.png b/assets/portraits/security-pros/card_023.png deleted file mode 100644 index d8867a9..0000000 Binary files a/assets/portraits/security-pros/card_023.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_024.png b/assets/portraits/security-pros/card_024.png deleted file mode 100644 index c2edea6..0000000 Binary files a/assets/portraits/security-pros/card_024.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_025.png b/assets/portraits/security-pros/card_025.png deleted file mode 100644 index 5d858e1..0000000 Binary files a/assets/portraits/security-pros/card_025.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_026.png b/assets/portraits/security-pros/card_026.png deleted file mode 100644 index 02d3847..0000000 Binary files a/assets/portraits/security-pros/card_026.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_027.png b/assets/portraits/security-pros/card_027.png deleted file mode 100644 index 1ced391..0000000 Binary files a/assets/portraits/security-pros/card_027.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_028.png b/assets/portraits/security-pros/card_028.png deleted file mode 100644 index 73c6a6f..0000000 Binary files a/assets/portraits/security-pros/card_028.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_029.png b/assets/portraits/security-pros/card_029.png deleted file mode 100644 index 63011ec..0000000 Binary files a/assets/portraits/security-pros/card_029.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_030.png b/assets/portraits/security-pros/card_030.png deleted file mode 100644 index e076d03..0000000 Binary files a/assets/portraits/security-pros/card_030.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_031.png b/assets/portraits/security-pros/card_031.png deleted file mode 100644 index b798931..0000000 Binary files a/assets/portraits/security-pros/card_031.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_032.png b/assets/portraits/security-pros/card_032.png deleted file mode 100644 index ed0648a..0000000 Binary files a/assets/portraits/security-pros/card_032.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_033.png b/assets/portraits/security-pros/card_033.png deleted file mode 100644 index c28a487..0000000 Binary files a/assets/portraits/security-pros/card_033.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_034.png b/assets/portraits/security-pros/card_034.png deleted file mode 100644 index 2a92e9c..0000000 Binary files a/assets/portraits/security-pros/card_034.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_035.png b/assets/portraits/security-pros/card_035.png deleted file mode 100644 index eaf43ec..0000000 Binary files a/assets/portraits/security-pros/card_035.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_036.png b/assets/portraits/security-pros/card_036.png deleted file mode 100644 index d0b980e..0000000 Binary files a/assets/portraits/security-pros/card_036.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_037.png b/assets/portraits/security-pros/card_037.png deleted file mode 100644 index d93595f..0000000 Binary files a/assets/portraits/security-pros/card_037.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_038.png b/assets/portraits/security-pros/card_038.png deleted file mode 100644 index 32d741c..0000000 Binary files a/assets/portraits/security-pros/card_038.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_039.png b/assets/portraits/security-pros/card_039.png deleted file mode 100644 index 99709be..0000000 Binary files a/assets/portraits/security-pros/card_039.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_040.png b/assets/portraits/security-pros/card_040.png deleted file mode 100644 index 8395c29..0000000 Binary files a/assets/portraits/security-pros/card_040.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_041.png b/assets/portraits/security-pros/card_041.png deleted file mode 100644 index f19528a..0000000 Binary files a/assets/portraits/security-pros/card_041.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_042.png b/assets/portraits/security-pros/card_042.png deleted file mode 100644 index 47a8fa2..0000000 Binary files a/assets/portraits/security-pros/card_042.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_043.png b/assets/portraits/security-pros/card_043.png deleted file mode 100644 index b4ddc87..0000000 Binary files a/assets/portraits/security-pros/card_043.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_044.png b/assets/portraits/security-pros/card_044.png deleted file mode 100644 index 4586780..0000000 Binary files a/assets/portraits/security-pros/card_044.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_045.png b/assets/portraits/security-pros/card_045.png deleted file mode 100644 index 54611ab..0000000 Binary files a/assets/portraits/security-pros/card_045.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_046.png b/assets/portraits/security-pros/card_046.png deleted file mode 100644 index b778eb1..0000000 Binary files a/assets/portraits/security-pros/card_046.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_047.png b/assets/portraits/security-pros/card_047.png deleted file mode 100644 index 093ccf8..0000000 Binary files a/assets/portraits/security-pros/card_047.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_048.png b/assets/portraits/security-pros/card_048.png deleted file mode 100644 index d804524..0000000 Binary files a/assets/portraits/security-pros/card_048.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_049.png b/assets/portraits/security-pros/card_049.png deleted file mode 100644 index bb4eb64..0000000 Binary files a/assets/portraits/security-pros/card_049.png and /dev/null differ diff --git a/assets/portraits/security-pros/card_050.png b/assets/portraits/security-pros/card_050.png deleted file mode 100644 index d872803..0000000 Binary files a/assets/portraits/security-pros/card_050.png and /dev/null differ diff --git a/public/cards/security/001-whitfield-diffie-back.png b/public/cards/security/001-whitfield-diffie-back.png deleted file mode 100644 index 915e9f9..0000000 Binary files a/public/cards/security/001-whitfield-diffie-back.png and /dev/null differ diff --git a/public/cards/security/001-whitfield-diffie-front.png b/public/cards/security/001-whitfield-diffie-front.png deleted file mode 100644 index a94cd2a..0000000 Binary files a/public/cards/security/001-whitfield-diffie-front.png and /dev/null differ diff --git a/public/cards/security/002-martin-hellman-back.png b/public/cards/security/002-martin-hellman-back.png deleted file mode 100644 index 13e8958..0000000 Binary files a/public/cards/security/002-martin-hellman-back.png and /dev/null differ diff --git a/public/cards/security/002-martin-hellman-front.png b/public/cards/security/002-martin-hellman-front.png deleted file mode 100644 index 4c44c51..0000000 Binary files a/public/cards/security/002-martin-hellman-front.png and /dev/null differ diff --git a/public/cards/security/003-ron-rivest-back.png b/public/cards/security/003-ron-rivest-back.png deleted file mode 100644 index 065bb24..0000000 Binary files a/public/cards/security/003-ron-rivest-back.png and /dev/null differ diff --git a/public/cards/security/003-ron-rivest-front.png b/public/cards/security/003-ron-rivest-front.png deleted file mode 100644 index 9e84ffd..0000000 Binary files a/public/cards/security/003-ron-rivest-front.png and /dev/null differ diff --git a/public/cards/security/004-adi-shamir-back.png b/public/cards/security/004-adi-shamir-back.png deleted file mode 100644 index 5a55fd0..0000000 Binary files a/public/cards/security/004-adi-shamir-back.png and /dev/null differ diff --git a/public/cards/security/004-adi-shamir-front.png b/public/cards/security/004-adi-shamir-front.png deleted file mode 100644 index 19d8ce3..0000000 Binary files a/public/cards/security/004-adi-shamir-front.png and /dev/null differ diff --git a/public/cards/security/005-leonard-adleman-back.png b/public/cards/security/005-leonard-adleman-back.png deleted file mode 100644 index ee6ecde..0000000 Binary files a/public/cards/security/005-leonard-adleman-back.png and /dev/null differ diff --git a/public/cards/security/005-leonard-adleman-front.png b/public/cards/security/005-leonard-adleman-front.png deleted file mode 100644 index 1e72d2f..0000000 Binary files a/public/cards/security/005-leonard-adleman-front.png and /dev/null differ diff --git a/public/cards/security/006-phil-zimmermann-back.png b/public/cards/security/006-phil-zimmermann-back.png deleted file mode 100644 index 013dcb2..0000000 Binary files a/public/cards/security/006-phil-zimmermann-back.png and /dev/null differ diff --git a/public/cards/security/006-phil-zimmermann-front.png b/public/cards/security/006-phil-zimmermann-front.png deleted file mode 100644 index 88e40f7..0000000 Binary files a/public/cards/security/006-phil-zimmermann-front.png and /dev/null differ diff --git a/public/cards/security/007-bruce-schneier-back.png b/public/cards/security/007-bruce-schneier-back.png deleted file mode 100644 index 0aa4626..0000000 Binary files a/public/cards/security/007-bruce-schneier-back.png and /dev/null differ diff --git a/public/cards/security/007-bruce-schneier-front.png b/public/cards/security/007-bruce-schneier-front.png deleted file mode 100644 index 09ee26d..0000000 Binary files a/public/cards/security/007-bruce-schneier-front.png and /dev/null differ diff --git a/public/cards/security/008-paul-kocher-back.png b/public/cards/security/008-paul-kocher-back.png deleted file mode 100644 index f59ff81..0000000 Binary files a/public/cards/security/008-paul-kocher-back.png and /dev/null differ diff --git a/public/cards/security/008-paul-kocher-front.png b/public/cards/security/008-paul-kocher-front.png deleted file mode 100644 index 1ad6909..0000000 Binary files a/public/cards/security/008-paul-kocher-front.png and /dev/null differ diff --git a/public/cards/security/009-dorothy-denning-back.png b/public/cards/security/009-dorothy-denning-back.png deleted file mode 100644 index 316ee33..0000000 Binary files a/public/cards/security/009-dorothy-denning-back.png and /dev/null differ diff --git a/public/cards/security/009-dorothy-denning-front.png b/public/cards/security/009-dorothy-denning-front.png deleted file mode 100644 index 7cc90d9..0000000 Binary files a/public/cards/security/009-dorothy-denning-front.png and /dev/null differ diff --git a/public/cards/security/010-gene-spafford-back.png b/public/cards/security/010-gene-spafford-back.png deleted file mode 100644 index 0e7499e..0000000 Binary files a/public/cards/security/010-gene-spafford-back.png and /dev/null differ diff --git a/public/cards/security/010-gene-spafford-front.png b/public/cards/security/010-gene-spafford-front.png deleted file mode 100644 index 53deabb..0000000 Binary files a/public/cards/security/010-gene-spafford-front.png and /dev/null differ diff --git a/public/cards/security/011-ross-anderson-back.png b/public/cards/security/011-ross-anderson-back.png deleted file mode 100644 index 5b828bd..0000000 Binary files a/public/cards/security/011-ross-anderson-back.png and /dev/null differ diff --git a/public/cards/security/011-ross-anderson-front.png b/public/cards/security/011-ross-anderson-front.png deleted file mode 100644 index 3e2d83e..0000000 Binary files a/public/cards/security/011-ross-anderson-front.png and /dev/null differ diff --git a/public/cards/security/012-matt-blaze-back.png b/public/cards/security/012-matt-blaze-back.png deleted file mode 100644 index f62ff8a..0000000 Binary files a/public/cards/security/012-matt-blaze-back.png and /dev/null differ diff --git a/public/cards/security/012-matt-blaze-front.png b/public/cards/security/012-matt-blaze-front.png deleted file mode 100644 index 7a04bb5..0000000 Binary files a/public/cards/security/012-matt-blaze-front.png and /dev/null differ diff --git a/public/cards/security/013-radia-perlman-back.png b/public/cards/security/013-radia-perlman-back.png deleted file mode 100644 index 1ec4b05..0000000 Binary files a/public/cards/security/013-radia-perlman-back.png and /dev/null differ diff --git a/public/cards/security/013-radia-perlman-front.png b/public/cards/security/013-radia-perlman-front.png deleted file mode 100644 index 52e33b4..0000000 Binary files a/public/cards/security/013-radia-perlman-front.png and /dev/null differ diff --git a/public/cards/security/014-steven-bellovin-back.png b/public/cards/security/014-steven-bellovin-back.png deleted file mode 100644 index 1b0a1bf..0000000 Binary files a/public/cards/security/014-steven-bellovin-back.png and /dev/null differ diff --git a/public/cards/security/014-steven-bellovin-front.png b/public/cards/security/014-steven-bellovin-front.png deleted file mode 100644 index a6c48d4..0000000 Binary files a/public/cards/security/014-steven-bellovin-front.png and /dev/null differ diff --git a/public/cards/security/015-william-cheswick-back.png b/public/cards/security/015-william-cheswick-back.png deleted file mode 100644 index 1b2d5b6..0000000 Binary files a/public/cards/security/015-william-cheswick-back.png and /dev/null differ diff --git a/public/cards/security/015-william-cheswick-front.png b/public/cards/security/015-william-cheswick-front.png deleted file mode 100644 index f96a23e..0000000 Binary files a/public/cards/security/015-william-cheswick-front.png and /dev/null differ diff --git a/public/cards/security/016-marcus-ranum-back.png b/public/cards/security/016-marcus-ranum-back.png deleted file mode 100644 index ce73574..0000000 Binary files a/public/cards/security/016-marcus-ranum-back.png and /dev/null differ diff --git a/public/cards/security/016-marcus-ranum-front.png b/public/cards/security/016-marcus-ranum-front.png deleted file mode 100644 index c877732..0000000 Binary files a/public/cards/security/016-marcus-ranum-front.png and /dev/null differ diff --git a/public/cards/security/017-wietse-venema-back.png b/public/cards/security/017-wietse-venema-back.png deleted file mode 100644 index e667238..0000000 Binary files a/public/cards/security/017-wietse-venema-back.png and /dev/null differ diff --git a/public/cards/security/017-wietse-venema-front.png b/public/cards/security/017-wietse-venema-front.png deleted file mode 100644 index b40d480..0000000 Binary files a/public/cards/security/017-wietse-venema-front.png and /dev/null differ diff --git a/public/cards/security/018-dan-farmer-back.png b/public/cards/security/018-dan-farmer-back.png deleted file mode 100644 index 5cb3d65..0000000 Binary files a/public/cards/security/018-dan-farmer-back.png and /dev/null differ diff --git a/public/cards/security/018-dan-farmer-front.png b/public/cards/security/018-dan-farmer-front.png deleted file mode 100644 index 473abf7..0000000 Binary files a/public/cards/security/018-dan-farmer-front.png and /dev/null differ diff --git a/public/cards/security/019-gordon-lyon-back.png b/public/cards/security/019-gordon-lyon-back.png deleted file mode 100644 index cd2b3f9..0000000 Binary files a/public/cards/security/019-gordon-lyon-back.png and /dev/null differ diff --git a/public/cards/security/019-gordon-lyon-front.png b/public/cards/security/019-gordon-lyon-front.png deleted file mode 100644 index 9ec0efb..0000000 Binary files a/public/cards/security/019-gordon-lyon-front.png and /dev/null differ diff --git a/public/cards/security/020-martin-roesch-back.png b/public/cards/security/020-martin-roesch-back.png deleted file mode 100644 index 02d4a65..0000000 Binary files a/public/cards/security/020-martin-roesch-back.png and /dev/null differ diff --git a/public/cards/security/020-martin-roesch-front.png b/public/cards/security/020-martin-roesch-front.png deleted file mode 100644 index 8c832f0..0000000 Binary files a/public/cards/security/020-martin-roesch-front.png and /dev/null differ diff --git a/public/cards/security/021-gerald-combs-back.png b/public/cards/security/021-gerald-combs-back.png deleted file mode 100644 index b8cc12d..0000000 Binary files a/public/cards/security/021-gerald-combs-back.png and /dev/null differ diff --git a/public/cards/security/021-gerald-combs-front.png b/public/cards/security/021-gerald-combs-front.png deleted file mode 100644 index e1a455e..0000000 Binary files a/public/cards/security/021-gerald-combs-front.png and /dev/null differ diff --git a/public/cards/security/022-renaud-deraison-back.png b/public/cards/security/022-renaud-deraison-back.png deleted file mode 100644 index 0217894..0000000 Binary files a/public/cards/security/022-renaud-deraison-back.png and /dev/null differ diff --git a/public/cards/security/022-renaud-deraison-front.png b/public/cards/security/022-renaud-deraison-front.png deleted file mode 100644 index ce87913..0000000 Binary files a/public/cards/security/022-renaud-deraison-front.png and /dev/null differ diff --git a/public/cards/security/023-paul-vixie-back.png b/public/cards/security/023-paul-vixie-back.png deleted file mode 100644 index e6c6456..0000000 Binary files a/public/cards/security/023-paul-vixie-back.png and /dev/null differ diff --git a/public/cards/security/023-paul-vixie-front.png b/public/cards/security/023-paul-vixie-front.png deleted file mode 100644 index 821a620..0000000 Binary files a/public/cards/security/023-paul-vixie-front.png and /dev/null differ diff --git a/public/cards/security/024-niels-provos-back.png b/public/cards/security/024-niels-provos-back.png deleted file mode 100644 index f89601b..0000000 Binary files a/public/cards/security/024-niels-provos-back.png and /dev/null differ diff --git a/public/cards/security/024-niels-provos-front.png b/public/cards/security/024-niels-provos-front.png deleted file mode 100644 index cf9a1aa..0000000 Binary files a/public/cards/security/024-niels-provos-front.png and /dev/null differ diff --git a/public/cards/security/025-jeremiah-grossman-back.png b/public/cards/security/025-jeremiah-grossman-back.png deleted file mode 100644 index d047bb6..0000000 Binary files a/public/cards/security/025-jeremiah-grossman-back.png and /dev/null differ diff --git a/public/cards/security/025-jeremiah-grossman-front.png b/public/cards/security/025-jeremiah-grossman-front.png deleted file mode 100644 index ad6925a..0000000 Binary files a/public/cards/security/025-jeremiah-grossman-front.png and /dev/null differ diff --git a/public/cards/security/026-robert-hansen-back.png b/public/cards/security/026-robert-hansen-back.png deleted file mode 100644 index 0f23d79..0000000 Binary files a/public/cards/security/026-robert-hansen-back.png and /dev/null differ diff --git a/public/cards/security/026-robert-hansen-front.png b/public/cards/security/026-robert-hansen-front.png deleted file mode 100644 index cb5823c..0000000 Binary files a/public/cards/security/026-robert-hansen-front.png and /dev/null differ diff --git a/public/cards/security/027-mark-curphey-back.png b/public/cards/security/027-mark-curphey-back.png deleted file mode 100644 index bb236cb..0000000 Binary files a/public/cards/security/027-mark-curphey-back.png and /dev/null differ diff --git a/public/cards/security/027-mark-curphey-front.png b/public/cards/security/027-mark-curphey-front.png deleted file mode 100644 index 11ec5d1..0000000 Binary files a/public/cards/security/027-mark-curphey-front.png and /dev/null differ diff --git a/public/cards/security/028-jeff-williams-back.png b/public/cards/security/028-jeff-williams-back.png deleted file mode 100644 index f432ca9..0000000 Binary files a/public/cards/security/028-jeff-williams-back.png and /dev/null differ diff --git a/public/cards/security/028-jeff-williams-front.png b/public/cards/security/028-jeff-williams-front.png deleted file mode 100644 index d5c7f86..0000000 Binary files a/public/cards/security/028-jeff-williams-front.png and /dev/null differ diff --git a/public/cards/security/029-gary-mcgraw-back.png b/public/cards/security/029-gary-mcgraw-back.png deleted file mode 100644 index c7086da..0000000 Binary files a/public/cards/security/029-gary-mcgraw-back.png and /dev/null differ diff --git a/public/cards/security/029-gary-mcgraw-front.png b/public/cards/security/029-gary-mcgraw-front.png deleted file mode 100644 index 0605914..0000000 Binary files a/public/cards/security/029-gary-mcgraw-front.png and /dev/null differ diff --git a/public/cards/security/030-michael-howard-back.png b/public/cards/security/030-michael-howard-back.png deleted file mode 100644 index 05e5226..0000000 Binary files a/public/cards/security/030-michael-howard-back.png and /dev/null differ diff --git a/public/cards/security/030-michael-howard-front.png b/public/cards/security/030-michael-howard-front.png deleted file mode 100644 index 8ecbb8d..0000000 Binary files a/public/cards/security/030-michael-howard-front.png and /dev/null differ diff --git a/public/cards/security/031-adam-shostack-back.png b/public/cards/security/031-adam-shostack-back.png deleted file mode 100644 index 2fba100..0000000 Binary files a/public/cards/security/031-adam-shostack-back.png and /dev/null differ diff --git a/public/cards/security/031-adam-shostack-front.png b/public/cards/security/031-adam-shostack-front.png deleted file mode 100644 index 2120988..0000000 Binary files a/public/cards/security/031-adam-shostack-front.png and /dev/null differ diff --git a/public/cards/security/032-ivan-ristic-back.png b/public/cards/security/032-ivan-ristic-back.png deleted file mode 100644 index 33dd533..0000000 Binary files a/public/cards/security/032-ivan-ristic-back.png and /dev/null differ diff --git a/public/cards/security/032-ivan-ristic-front.png b/public/cards/security/032-ivan-ristic-front.png deleted file mode 100644 index 8b9f45d..0000000 Binary files a/public/cards/security/032-ivan-ristic-front.png and /dev/null differ diff --git a/public/cards/security/033-mark-dowd-back.png b/public/cards/security/033-mark-dowd-back.png deleted file mode 100644 index f231912..0000000 Binary files a/public/cards/security/033-mark-dowd-back.png and /dev/null differ diff --git a/public/cards/security/033-mark-dowd-front.png b/public/cards/security/033-mark-dowd-front.png deleted file mode 100644 index 8700220..0000000 Binary files a/public/cards/security/033-mark-dowd-front.png and /dev/null differ diff --git a/public/cards/security/034-halvar-flake-back.png b/public/cards/security/034-halvar-flake-back.png deleted file mode 100644 index 6a0d853..0000000 Binary files a/public/cards/security/034-halvar-flake-back.png and /dev/null differ diff --git a/public/cards/security/034-halvar-flake-front.png b/public/cards/security/034-halvar-flake-front.png deleted file mode 100644 index 86064ce..0000000 Binary files a/public/cards/security/034-halvar-flake-front.png and /dev/null differ diff --git a/public/cards/security/035-alex-sotirov-back.png b/public/cards/security/035-alex-sotirov-back.png deleted file mode 100644 index fd1cb3f..0000000 Binary files a/public/cards/security/035-alex-sotirov-back.png and /dev/null differ diff --git a/public/cards/security/035-alex-sotirov-front.png b/public/cards/security/035-alex-sotirov-front.png deleted file mode 100644 index 94dba9a..0000000 Binary files a/public/cards/security/035-alex-sotirov-front.png and /dev/null differ diff --git a/public/cards/security/036-thomas-ptacek-back.png b/public/cards/security/036-thomas-ptacek-back.png deleted file mode 100644 index 8112421..0000000 Binary files a/public/cards/security/036-thomas-ptacek-back.png and /dev/null differ diff --git a/public/cards/security/036-thomas-ptacek-front.png b/public/cards/security/036-thomas-ptacek-front.png deleted file mode 100644 index d1bed8f..0000000 Binary files a/public/cards/security/036-thomas-ptacek-front.png and /dev/null differ diff --git a/public/cards/security/037-matthew-green-back.png b/public/cards/security/037-matthew-green-back.png deleted file mode 100644 index 605ad9a..0000000 Binary files a/public/cards/security/037-matthew-green-back.png and /dev/null differ diff --git a/public/cards/security/037-matthew-green-front.png b/public/cards/security/037-matthew-green-front.png deleted file mode 100644 index a7a100c..0000000 Binary files a/public/cards/security/037-matthew-green-front.png and /dev/null differ diff --git a/public/cards/security/038-j-alex-halderman-back.png b/public/cards/security/038-j-alex-halderman-back.png deleted file mode 100644 index 68721d7..0000000 Binary files a/public/cards/security/038-j-alex-halderman-back.png and /dev/null differ diff --git a/public/cards/security/038-j-alex-halderman-front.png b/public/cards/security/038-j-alex-halderman-front.png deleted file mode 100644 index 9074d70..0000000 Binary files a/public/cards/security/038-j-alex-halderman-front.png and /dev/null differ diff --git a/public/cards/security/039-nadia-heninger-back.png b/public/cards/security/039-nadia-heninger-back.png deleted file mode 100644 index fb9eaa0..0000000 Binary files a/public/cards/security/039-nadia-heninger-back.png and /dev/null differ diff --git a/public/cards/security/039-nadia-heninger-front.png b/public/cards/security/039-nadia-heninger-front.png deleted file mode 100644 index 8a47094..0000000 Binary files a/public/cards/security/039-nadia-heninger-front.png and /dev/null differ diff --git a/public/cards/security/040-troy-hunt-back.png b/public/cards/security/040-troy-hunt-back.png deleted file mode 100644 index d24a191..0000000 Binary files a/public/cards/security/040-troy-hunt-back.png and /dev/null differ diff --git a/public/cards/security/040-troy-hunt-front.png b/public/cards/security/040-troy-hunt-front.png deleted file mode 100644 index 5572fad..0000000 Binary files a/public/cards/security/040-troy-hunt-front.png and /dev/null differ diff --git a/public/cards/security/041-window-snyder-back.png b/public/cards/security/041-window-snyder-back.png deleted file mode 100644 index 984b62d..0000000 Binary files a/public/cards/security/041-window-snyder-back.png and /dev/null differ diff --git a/public/cards/security/041-window-snyder-front.png b/public/cards/security/041-window-snyder-front.png deleted file mode 100644 index 9d4d275..0000000 Binary files a/public/cards/security/041-window-snyder-front.png and /dev/null differ diff --git a/public/cards/security/042-heather-adkins-back.png b/public/cards/security/042-heather-adkins-back.png deleted file mode 100644 index 7a13a8b..0000000 Binary files a/public/cards/security/042-heather-adkins-back.png and /dev/null differ diff --git a/public/cards/security/042-heather-adkins-front.png b/public/cards/security/042-heather-adkins-front.png deleted file mode 100644 index 1a6b554..0000000 Binary files a/public/cards/security/042-heather-adkins-front.png and /dev/null differ diff --git a/public/cards/security/043-parisa-tabriz-back.png b/public/cards/security/043-parisa-tabriz-back.png deleted file mode 100644 index 1f8a070..0000000 Binary files a/public/cards/security/043-parisa-tabriz-back.png and /dev/null differ diff --git a/public/cards/security/043-parisa-tabriz-front.png b/public/cards/security/043-parisa-tabriz-front.png deleted file mode 100644 index 950dff9..0000000 Binary files a/public/cards/security/043-parisa-tabriz-front.png and /dev/null differ diff --git a/public/cards/security/044-alex-stamos-back.png b/public/cards/security/044-alex-stamos-back.png deleted file mode 100644 index 7357be2..0000000 Binary files a/public/cards/security/044-alex-stamos-back.png and /dev/null differ diff --git a/public/cards/security/044-alex-stamos-front.png b/public/cards/security/044-alex-stamos-front.png deleted file mode 100644 index 2b3c68e..0000000 Binary files a/public/cards/security/044-alex-stamos-front.png and /dev/null differ diff --git a/public/cards/security/045-dan-geer-back.png b/public/cards/security/045-dan-geer-back.png deleted file mode 100644 index 9afe5c4..0000000 Binary files a/public/cards/security/045-dan-geer-back.png and /dev/null differ diff --git a/public/cards/security/045-dan-geer-front.png b/public/cards/security/045-dan-geer-front.png deleted file mode 100644 index 98f7dd9..0000000 Binary files a/public/cards/security/045-dan-geer-front.png and /dev/null differ diff --git a/public/cards/security/046-kevin-mandia-back.png b/public/cards/security/046-kevin-mandia-back.png deleted file mode 100644 index 0d7eadf..0000000 Binary files a/public/cards/security/046-kevin-mandia-back.png and /dev/null differ diff --git a/public/cards/security/046-kevin-mandia-front.png b/public/cards/security/046-kevin-mandia-front.png deleted file mode 100644 index e4e68ae..0000000 Binary files a/public/cards/security/046-kevin-mandia-front.png and /dev/null differ diff --git a/public/cards/security/047-mikko-hypponen-back.png b/public/cards/security/047-mikko-hypponen-back.png deleted file mode 100644 index 49aefc2..0000000 Binary files a/public/cards/security/047-mikko-hypponen-back.png and /dev/null differ diff --git a/public/cards/security/047-mikko-hypponen-front.png b/public/cards/security/047-mikko-hypponen-front.png deleted file mode 100644 index d2aa740..0000000 Binary files a/public/cards/security/047-mikko-hypponen-front.png and /dev/null differ diff --git a/public/cards/security/048-robert-m-lee-back.png b/public/cards/security/048-robert-m-lee-back.png deleted file mode 100644 index cb39e91..0000000 Binary files a/public/cards/security/048-robert-m-lee-back.png and /dev/null differ diff --git a/public/cards/security/048-robert-m-lee-front.png b/public/cards/security/048-robert-m-lee-front.png deleted file mode 100644 index 71b9c74..0000000 Binary files a/public/cards/security/048-robert-m-lee-front.png and /dev/null differ diff --git a/public/cards/security/049-lesley-carhart-back.png b/public/cards/security/049-lesley-carhart-back.png deleted file mode 100644 index 39ae333..0000000 Binary files a/public/cards/security/049-lesley-carhart-back.png and /dev/null differ diff --git a/public/cards/security/049-lesley-carhart-front.png b/public/cards/security/049-lesley-carhart-front.png deleted file mode 100644 index 62a29c6..0000000 Binary files a/public/cards/security/049-lesley-carhart-front.png and /dev/null differ diff --git a/public/cards/security/050-katie-nickels-back.png b/public/cards/security/050-katie-nickels-back.png deleted file mode 100644 index 8fea037..0000000 Binary files a/public/cards/security/050-katie-nickels-back.png and /dev/null differ diff --git a/public/cards/security/050-katie-nickels-front.png b/public/cards/security/050-katie-nickels-front.png deleted file mode 100644 index 118e8db..0000000 Binary files a/public/cards/security/050-katie-nickels-front.png and /dev/null differ diff --git a/src/app/security-professionals/[slug]/page.tsx b/src/app/security-professionals/[slug]/page.tsx index f6ef4dd..edee9ba 100644 --- a/src/app/security-professionals/[slug]/page.tsx +++ b/src/app/security-professionals/[slug]/page.tsx @@ -6,8 +6,10 @@ import { site } from '@/data/site'; type Params = { params: Promise<{ slug: string }> }; +// Only illustrated cards get a page — an entry with no face has nothing to show, +// and listing it here would prerender 404s. export function generateStaticParams() { - return pros.map((p) => ({ slug: p.slug })); + return pros.filter((p) => p.front).map((p) => ({ slug: p.slug })); } export async function generateMetadata({ params }: Params): Promise { @@ -37,8 +39,8 @@ export default async function ProPage({ params }: Params) { const prev = i > 0 ? pros[i - 1] : undefined; const next = i < pros.length - 1 ? pros[i + 1] : undefined; - // Art is published for the whole set, but keep the page honest if a face is - // ever missing rather than rendering a broken image. + // A card page exists only once its art does. While the set is unillustrated this + // is every slug, which is intended — better a 404 than a page with no card on it. if (!p.front || !p.back) notFound(); const jsonLd = { diff --git a/src/data/security.ts b/src/data/security.ts index 0911938..4eed104 100644 --- a/src/data/security.ts +++ b/src/data/security.ts @@ -1,6 +1,13 @@ -// Security Professionals — Series Three. IN PROGRESS: copy is written, art is not started. -// Hand-curated (not auto-generated). `front`/`back` will be written by the publish step -// once portraits exist — do not hand-edit those two fields. +// Security Professionals — Series Three. Copy is final; ART IS WITHDRAWN. +// Hand-curated (not auto-generated). `front`/`back` are written by the publish step — +// do not hand-edit those two fields. +// +// 2026-09-08: the first art pass was generated from text prompts alone, so every portrait +// was an invented face rather than a likeness of the real person. For a set that presents +// itself as documented history that is a fabrication, so all 50 faces were withdrawn and +// the source portraits deleted. The replacement pass conditions generation on a real, +// freely-licensed reference photo and credits the photographer; anyone with no such photo +// gets no face at all rather than an invented one. // // The brief for this set is deliberately narrower than Series Two. Hacking Legends // documents the people who broke things; this one documents the people whose job was to @@ -53,8 +60,6 @@ export const pros: Pro[] = [ 'With Martin Hellman, published “New Directions in Cryptography” in 1976 and showed that two parties who had never met could agree on a secret over a wire anyone could read. It broke a problem the field had considered permanent, and every TLS handshake since is a descendant. Shared the 2015 Turing Award for it, and spent decades afterwards arguing the civil-liberties side of the crypto policy fights.', note: 'The paper that made secure commerce on a public network conceivable at all.', status: 'locked', - front: '/cards/security/001-whitfield-diffie-front.png', - back: '/cards/security/001-whitfield-diffie-back.png', sources: [ { label: 'Whitfield Diffie', url: 'https://en.wikipedia.org/wiki/Whitfield_Diffie' }, { label: 'New Directions in Cryptography (1976)', url: 'https://ee.stanford.edu/~hellman/publications/24.pdf' }, @@ -80,8 +85,6 @@ export const pros: Pro[] = [ 'Co-author of the 1976 paper and Stanford professor who then refused to let the NSA classify academic cryptography out of existence, publishing and teaching through explicit pressure to stop. Also co-authored the early analysis of DES key length that argued, correctly and years early, that 56 bits was not enough. Shared the 2015 Turing Award with Diffie.', note: 'Won the maths, then won the argument about who is allowed to do the maths.', status: 'locked', - front: '/cards/security/002-martin-hellman-front.png', - back: '/cards/security/002-martin-hellman-back.png', sources: [ { label: 'Martin Hellman', url: 'https://en.wikipedia.org/wiki/Martin_Hellman' }, { label: 'ACM A.M. Turing Award 2015', url: 'https://amturing.acm.org/award_winners/hellman_4055781.cfm' }, @@ -106,8 +109,6 @@ export const pros: Pro[] = [ 'Co-invented the RSA cryptosystem at MIT in 1977 with Shamir and Adleman, turning public-key cryptography from a proposal into something you could ship. Went on to design MD2, MD4, MD5, RC4, RC5 and RC6, co-author the standard algorithms textbook, and spend his later career on verifiable election systems. Turing Award, 2002.', note: 'Half the acronyms in a 1990s protocol stack trace back to one office at MIT.', status: 'locked', - front: '/cards/security/003-ron-rivest-front.png', - back: '/cards/security/003-ron-rivest-back.png', sources: [ { label: 'Ron Rivest', url: 'https://en.wikipedia.org/wiki/Ron_Rivest' }, { label: 'ACM A.M. Turing Award 2002', url: 'https://amturing.acm.org/award_winners/rivest_1403005.cfm' }, @@ -132,8 +133,6 @@ export const pros: Pro[] = [ 'Co-invented RSA, then invented Shamir secret sharing, then co-developed differential cryptanalysis with Eli Biham — the technique that turned out to be the one the DES designers had quietly hardened against seventeen years earlier. Also a co-author of the cube attack and a long line of side-channel work. Turing Award, 2002.', note: 'Builds the lock and breaks the lock, usually in the same decade.', status: 'locked', - front: '/cards/security/004-adi-shamir-front.png', - back: '/cards/security/004-adi-shamir-back.png', sources: [ { label: 'Adi Shamir', url: 'https://en.wikipedia.org/wiki/Adi_Shamir' }, { label: 'Differential cryptanalysis', url: 'https://en.wikipedia.org/wiki/Differential_cryptanalysis' }, @@ -158,8 +157,6 @@ export const pros: Pro[] = [ 'The third name on the RSA paper, whose role was to keep breaking the schemes Rivest and Shamir proposed until one survived. Later coined the term “computer virus” for Fred Cohen’s 1983 experiments, and founded DNA computing with a molecular solution to the Hamiltonian path problem. Turing Award, 2002.', note: 'The designated attacker on the RSA team. The set needs more of those.', status: 'locked', - front: '/cards/security/005-leonard-adleman-front.png', - back: '/cards/security/005-leonard-adleman-back.png', sources: [ { label: 'Leonard Adleman', url: 'https://en.wikipedia.org/wiki/Leonard_Adleman' }, { label: 'ACM A.M. Turing Award 2002', url: 'https://amturing.acm.org/award_winners/adleman_7308544.cfm' }, @@ -184,8 +181,6 @@ export const pros: Pro[] = [ 'Released Pretty Good Privacy as free software in 1991, and it escaped onto the internet worldwide. The US government opened a three-year criminal investigation into him for munitions export, dropped it in 1996 without charges, and the crypto-export regime never recovered. He later co-founded Silent Circle and worked on ZRTP for encrypted voice.', note: 'The card for everyone who has ever typed a passphrase to read their own mail.', status: 'locked', - front: '/cards/security/006-phil-zimmermann-front.png', - back: '/cards/security/006-phil-zimmermann-back.png', sources: [ { label: 'Phil Zimmermann', url: 'https://en.wikipedia.org/wiki/Phil_Zimmermann' }, { label: 'Pretty Good Privacy', url: 'https://en.wikipedia.org/wiki/Pretty_Good_Privacy' }, @@ -210,8 +205,6 @@ export const pros: Pro[] = [ 'Wrote Applied Cryptography in 1994, the book that taught a generation of engineers how ciphers actually work, then designed Blowfish and co-designed Twofish. Spent the two decades after arguing the harder point: that security is a systems and incentives problem, not a maths problem. Coined “security theatre”, has written the Crypto-Gram newsletter since 1998, and helped report on the Snowden documents.', note: 'More people entered this field because of one book than any other single cause.', status: 'locked', - front: '/cards/security/007-bruce-schneier-front.png', - back: '/cards/security/007-bruce-schneier-back.png', sources: [ { label: 'Bruce Schneier', url: 'https://en.wikipedia.org/wiki/Bruce_Schneier' }, { label: 'Schneier on Security', url: 'https://www.schneier.com/' }, @@ -236,8 +229,6 @@ export const pros: Pro[] = [ 'Published the timing-attack paper in 1996 and differential power analysis in 1999, establishing that a correct implementation of a correct algorithm can still leak its key through how long it takes or how much current it draws. Co-authored the SSL 3.0 specification, founded Cryptography Research, and in 2018 was one of the co-discoverers of Spectre.', note: 'Twice made the whole industry re-audit hardware it had already shipped.', status: 'locked', - front: '/cards/security/008-paul-kocher-front.png', - back: '/cards/security/008-paul-kocher-back.png', sources: [ { label: 'Paul Kocher', url: 'https://en.wikipedia.org/wiki/Paul_Kocher' }, { label: 'Spectre (security vulnerability)', url: 'https://en.wikipedia.org/wiki/Spectre_(security_vulnerability)' }, @@ -263,8 +254,6 @@ export const pros: Pro[] = [ 'Published “An Intrusion-Detection Model” in 1987, the paper that framed detection as statistical deviation from a profile of normal behaviour and gave the entire monitoring industry its foundation. Also wrote Cryptography and Data Security, worked on database security and lattice-based information flow, and was one of the few academics engaging seriously with both sides of the Clipper chip debate.', note: 'Every alert queue in every SOC is downstream of one 1987 paper.', status: 'locked', - front: '/cards/security/009-dorothy-denning-front.png', - back: '/cards/security/009-dorothy-denning-back.png', sources: [ { label: 'Dorothy E. Denning', url: 'https://en.wikipedia.org/wiki/Dorothy_E._Denning' }, { label: 'An Intrusion-Detection Model (1987)', url: 'https://www.cs.colostate.edu/~cs656/reading/ieee-se-13-2.pdf' }, @@ -290,8 +279,6 @@ export const pros: Pro[] = [ 'Produced one of the first detailed technical analyses of the 1988 Morris worm while the internet was still smoking, co-wrote Practical UNIX and Internet Security with Simson Garfinkel, co-created Tripwire, and founded Purdue’s COAST lab and then CERIAS — for years the largest academic security centre in the US. Has advised more federal panels than most people have attended.', note: 'Trained a large fraction of the people on the rest of these cards.', status: 'locked', - front: '/cards/security/010-gene-spafford-front.png', - back: '/cards/security/010-gene-spafford-back.png', sources: [ { label: 'Gene Spafford', url: 'https://en.wikipedia.org/wiki/Gene_Spafford' }, { label: 'CERIAS, Purdue University', url: 'https://www.cerias.purdue.edu/' }, @@ -316,8 +303,6 @@ export const pros: Pro[] = [ 'Cambridge professor who wrote Security Engineering, the closest thing the field has to a canonical text, and gave away earlier editions free online. Founded the security-economics research programme with the observation that systems fail because the people who could fix them are not the people who bear the loss. Spent years demonstrating that bank chip-and-PIN systems were weaker than the banks told courts they were. Died in 2024.', note: 'If you only read one book on this list, it is this one.', status: 'locked', - front: '/cards/security/011-ross-anderson-front.png', - back: '/cards/security/011-ross-anderson-back.png', sources: [ { label: 'Ross J. Anderson', url: 'https://en.wikipedia.org/wiki/Ross_J._Anderson' }, { label: 'Security Engineering, third edition', url: 'https://www.cl.cam.ac.uk/~rja14/book.html' }, @@ -342,8 +327,6 @@ export const pros: Pro[] = [ 'Found the protocol flaw in the NSA’s Clipper chip escrow scheme in 1994 and published it, which did more to end mandated key escrow than any amount of lobbying. Later led state-commissioned source reviews of US voting systems, published work on the vulnerabilities of master-keyed physical locks and wiretap systems, and became a law-school professor arguing the same points to a different audience.', note: 'Has broken the government’s preferred backdoor design once already.', status: 'locked', - front: '/cards/security/012-matt-blaze-front.png', - back: '/cards/security/012-matt-blaze-back.png', sources: [ { label: 'Matt Blaze', url: 'https://en.wikipedia.org/wiki/Matt_Blaze' }, { label: 'Protocol Failure in the Escrowed Encryption Standard (1994)', url: 'https://www.mattblaze.org/papers/eesproto.pdf' }, @@ -368,8 +351,6 @@ export const pros: Pro[] = [ 'Invented the spanning-tree protocol that made large bridged Ethernets possible, and did the early work on routing protocols designed to keep functioning when a participating node is actively hostile rather than merely broken. Co-wrote Network Security: Private Communication in a Public World, and designed the “ephemerizer” approach to making data reliably expire.', note: 'Designed for the assumption that some of the network is lying to you.', status: 'locked', - front: '/cards/security/013-radia-perlman-front.png', - back: '/cards/security/013-radia-perlman-back.png', sources: [ { label: 'Radia Perlman', url: 'https://en.wikipedia.org/wiki/Radia_Perlman' }, { label: 'Internet Hall of Fame profile', url: 'https://www.internethalloffame.org/inductee/radia-perlman/' }, @@ -394,8 +375,6 @@ export const pros: Pro[] = [ 'Wrote the 1989 paper cataloguing the security problems in TCP/IP — sequence-number prediction, source routing, DNS spoofing — years before anyone was exploiting them at scale. Co-authored Firewalls and Internet Security with Cheswick, co-invented encrypted key exchange, was a Usenet co-creator, and served as chief technologist at the FTC and on the Privacy and Civil Liberties Oversight Board.', note: 'Published the attack list first and spent thirty years watching it come true.', status: 'locked', - front: '/cards/security/014-steven-bellovin-front.png', - back: '/cards/security/014-steven-bellovin-back.png', sources: [ { label: 'Steven M. Bellovin', url: 'https://en.wikipedia.org/wiki/Steven_M._Bellovin' }, { label: 'Security Problems in the TCP/IP Protocol Suite (1989)', url: 'https://www.cs.columbia.edu/~smb/papers/ipext.pdf' }, @@ -421,8 +400,6 @@ export const pros: Pro[] = [ 'Co-wrote the 1994 book that taught the industry what a firewall was and how to reason about a perimeter. “An Evening with Berferd” documented him feeding a live intruder a fake environment for months and writing down everything, which is the honeypot genre’s founding text. Later ran the Internet Mapping Project at Bell Labs.', note: 'Invented the practice of watching the attacker instead of just shutting the door.', status: 'locked', - front: '/cards/security/015-william-cheswick-front.png', - back: '/cards/security/015-william-cheswick-back.png', sources: [ { label: 'William Cheswick', url: 'https://en.wikipedia.org/wiki/William_Cheswick' }, { label: 'An Evening with Berferd (1992)', url: 'https://www.cheswick.com/ches/papers/berferd.pdf' }, @@ -447,8 +424,6 @@ export const pros: Pro[] = [ 'Built DEC SEAL, generally credited as the first commercial firewall product, then the TIS Firewall Toolkit and Gauntlet — the code most early internet perimeters were actually made of. Ran whitehouse.gov’s first email server. Has spent the decades since publicly arguing that most of what the industry sells does not work, which has aged better than the products did.', note: 'The perimeter, as an idea people could buy, is largely his fault and his credit.', status: 'locked', - front: '/cards/security/016-marcus-ranum-front.png', - back: '/cards/security/016-marcus-ranum-back.png', sources: [ { label: 'Marcus J. Ranum', url: 'https://en.wikipedia.org/wiki/Marcus_J._Ranum' }, { label: 'Firewall (computing) — history', url: 'https://en.wikipedia.org/wiki/Firewall_(computing)' }, @@ -473,8 +448,6 @@ export const pros: Pro[] = [ 'Wrote TCP Wrapper, which for years was the access control on a very large share of Unix hosts on the internet, and Postfix, a mail server written from the start around privilege separation. Co-wrote SATAN with Dan Farmer and later the Coroner’s Toolkit and Forensic Discovery, giving incident responders their first real open tooling.', note: 'Shipped the defence, then shipped the tools to work out how it was beaten.', status: 'locked', - front: '/cards/security/017-wietse-venema-front.png', - back: '/cards/security/017-wietse-venema-back.png', sources: [ { label: 'Wietse Venema', url: 'https://en.wikipedia.org/wiki/Wietse_Venema' }, { label: 'Postfix', url: 'https://www.postfix.org/' }, @@ -499,8 +472,6 @@ export const pros: Pro[] = [ 'Wrote COPS as a student, then in 1995 released SATAN with Wietse Venema — a scanner that audited a network the way an attacker would, published openly so defenders could run it first. The press predicted the end of the internet; SGI fired him over it; the security scanner became a permanent product category. Later co-wrote Forensic Discovery.', note: 'The original argument that defenders should get the attacker’s tools too.', status: 'locked', - front: '/cards/security/018-dan-farmer-front.png', - back: '/cards/security/018-dan-farmer-back.png', sources: [ { label: 'Dan Farmer', url: 'https://en.wikipedia.org/wiki/Dan_Farmer' }, { label: 'SATAN', url: 'https://en.wikipedia.org/wiki/Security_Administrator_Tool_for_Analyzing_Networks' }, @@ -526,8 +497,6 @@ export const pros: Pro[] = [ 'Released Nmap in Phrack in 1997 and has maintained it ever since, adding OS fingerprinting, service detection and the NSE scripting engine. Runs seclists.org, hosting the Bugtraq and Full Disclosure archives that are the field’s institutional memory, and fought MPAA and studio takedown attempts over the tool. Nmap is the first command most defenders learn.', note: 'Twenty-eight years of one maintainer. The reliability is the achievement.', status: 'locked', - front: '/cards/security/019-gordon-lyon-front.png', - back: '/cards/security/019-gordon-lyon-back.png', sources: [ { label: 'Gordon Lyon', url: 'https://en.wikipedia.org/wiki/Gordon_Lyon' }, { label: 'Nmap', url: 'https://nmap.org/' }, @@ -552,8 +521,6 @@ export const pros: Pro[] = [ 'Wrote Snort in 1998 as a lightweight packet sniffer, and it became the intrusion detection system that put IDS within reach of organisations that could never have bought one. Founded Sourcefire around it, which Cisco acquired in 2013. The Snort rule syntax outlived the product and is still how a large part of the industry writes network detections.', note: 'A weekend tool that became the de facto standard for network detection.', status: 'locked', - front: '/cards/security/020-martin-roesch-front.png', - back: '/cards/security/020-martin-roesch-back.png', sources: [ { label: 'Martin Roesch', url: 'https://en.wikipedia.org/wiki/Martin_Roesch' }, { label: 'Snort', url: 'https://www.snort.org/' }, @@ -578,8 +545,6 @@ export const pros: Pro[] = [ 'Started Ethereal in 1998 because commercial protocol analysers cost more than his employer would spend, renamed it Wireshark in 2006 after a trademark problem, and has shepherded it ever since through thousands of contributed protocol dissectors. It is the default answer to “what is actually on the wire” for network engineers and incident responders alike.', note: 'The tool you reach for when nobody can agree on what the traffic is doing.', status: 'locked', - front: '/cards/security/021-gerald-combs-front.png', - back: '/cards/security/021-gerald-combs-back.png', sources: [ { label: 'Wireshark', url: 'https://en.wikipedia.org/wiki/Wireshark' }, { label: 'Wireshark project', url: 'https://www.wireshark.org/about.html' }, @@ -604,8 +569,6 @@ export const pros: Pro[] = [ 'Released Nessus in 1998 as a free scanner with its own plugin language, at a point when the alternative was an expensive appliance. Co-founded Tenable Network Security around it in 2002 and took the product closed-source in 2005, a decision the community argued about for years. Vulnerability management as a routine operational practice largely grew out of that codebase.', note: 'The scan report that lands in an admin’s inbox every Monday started here.', status: 'locked', - front: '/cards/security/022-renaud-deraison-front.png', - back: '/cards/security/022-renaud-deraison-back.png', sources: [ { label: 'Nessus (software)', url: 'https://en.wikipedia.org/wiki/Nessus_(software)' }, { label: 'Tenable leadership', url: 'https://www.tenable.com/about-tenable/leadership' }, @@ -630,8 +593,6 @@ export const pros: Pro[] = [ 'Maintained BIND for years and wrote or co-wrote a long run of DNS RFCs, then built the response-policy zone mechanism that lets defenders block malicious domains at the resolver. Founded the first anti-spam DNSBL, ran the Internet Software Consortium, operates F-root, and co-founded Farsight Security around passive DNS. Internet Hall of Fame, 2014.', note: 'Ran the plumbing, then built the filters when the plumbing got abused.', status: 'locked', - front: '/cards/security/023-paul-vixie-front.png', - back: '/cards/security/023-paul-vixie-back.png', sources: [ { label: 'Paul Vixie', url: 'https://en.wikipedia.org/wiki/Paul_Vixie' }, { label: 'Internet Hall of Fame profile', url: 'https://www.internethalloffame.org/inductee/paul-vixie/' }, @@ -656,8 +617,6 @@ export const pros: Pro[] = [ 'Wrote honeyd, co-designed the bcrypt password hash with David Mazières, and created systrace and privilege separation work in OpenSSH. At Google he led the Safe Browsing malware research that put interstitial warnings in front of drive-by download sites, and co-authored the papers that measured how large that problem actually was.', note: 'bcrypt alone has protected more passwords than most companies have users.', status: 'locked', - front: '/cards/security/024-niels-provos-front.png', - back: '/cards/security/024-niels-provos-back.png', sources: [ { label: 'Niels Provos', url: 'https://en.wikipedia.org/wiki/Niels_Provos' }, { label: 'A Future-Adaptable Password Scheme (bcrypt, 1999)', url: 'https://www.usenix.org/legacy/events/usenix99/provos/provos.pdf' }, @@ -682,8 +641,6 @@ export const pros: Pro[] = [ 'Was an information security officer at Yahoo before founding WhiteHat Security in 2001, where continuous scanning of thousands of production sites produced the first credible public statistics on how long real web vulnerabilities actually stay open. Co-founded the Web Application Security Consortium, and co-authored XSS Attacks: Cross Site Scripting Exploits and Defense in 2007 — the book that turned cross-site scripting from a curiosity into a class of bug developers were expected to know.', note: 'The XSS book is still the reference. Web appsec became a discipline on his watch.', status: 'locked', - front: '/cards/security/025-jeremiah-grossman-front.png', - back: '/cards/security/025-jeremiah-grossman-back.png', sources: [ { label: 'XSS Attacks: Cross Site Scripting Exploits and Defense', url: 'https://books.google.com/books/about/XSS_Attacks.html?id=FKN5uL57tyAC' }, { label: 'Jeremiah Grossman’s blog', url: 'https://blog.jeremiahgrossman.com/' }, @@ -710,8 +667,6 @@ export const pros: Pro[] = [ 'Ran ha.ckers.org and published the XSS cheat sheet, which for years was the reference list of filter-evasion payloads that every web application firewall was tested against. Co-authored XSS Attacks with Grossman, released Slowloris to demonstrate that a single machine could hold a web server’s connections open indefinitely, and co-wrote Detecting Malice on behavioural detection.', note: 'The cheat sheet did more for input validation than any standards document.', status: 'locked', - front: '/cards/security/026-robert-hansen-front.png', - back: '/cards/security/026-robert-hansen-back.png', sources: [ { label: 'XSS Attacks: Cross Site Scripting Exploits and Defense', url: 'https://books.google.com/books/about/XSS_Attacks.html?id=FKN5uL57tyAC' }, { label: 'Slowloris (computer security)', url: 'https://en.wikipedia.org/wiki/Slowloris_(cyber_attack)' }, @@ -736,8 +691,6 @@ export const pros: Pro[] = [ 'Started the Open Web Application Security Project in September 2001 as a mailing list and a few documents, and it became the vendor-neutral body that produced the Top Ten, the ASVS, ZAP and the testing guides that appsec teams still work from. Later founded SourceClear on software composition analysis and has kept publicly pushing OWASP to stay relevant to modern supply-chain risk.', note: 'Built the commons the whole application security industry now cites.', status: 'locked', - front: '/cards/security/027-mark-curphey-front.png', - back: '/cards/security/027-mark-curphey-back.png', sources: [ { label: 'OWASP', url: 'https://en.wikipedia.org/wiki/OWASP' }, { label: 'Mark Curphey — OWASP Foundation', url: 'https://owasp.org/www-board-candidates/2022/mark_curphey_2022' }, @@ -762,8 +715,6 @@ export const pros: Pro[] = [ 'Wrote the first OWASP Top Ten and served as the volunteer chair of OWASP from 2003 to 2011, the years in which it went from a mailing list to the reference that PCI DSS and a long line of other standards cite by name. Co-founded Aspect Security and then Contrast Security, arguing for instrumentation inside the running application rather than scanning it from outside.', note: 'One list, and suddenly every auditor knew what SQL injection was.', status: 'locked', - front: '/cards/security/028-jeff-williams-front.png', - back: '/cards/security/028-jeff-williams-back.png', sources: [ { label: 'OWASP', url: 'https://en.wikipedia.org/wiki/OWASP' }, { label: 'OWASP Top Ten project', url: 'https://owasp.org/www-project-top-ten/' }, @@ -788,8 +739,6 @@ export const pros: Pro[] = [ 'Wrote Building Secure Software, Exploiting Software and Software Security, making the case that you cannot test defects out of a system you designed insecurely. Co-created BSIMM, which measures what security programmes actually do rather than what a standard says they should, and has run a long-standing interview series documenting the field’s own history.', note: 'Moved the argument from “scan it later” to “design it right”.', status: 'locked', - front: '/cards/security/029-gary-mcgraw-front.png', - back: '/cards/security/029-gary-mcgraw-back.png', sources: [ { label: 'Gary McGraw', url: 'https://en.wikipedia.org/wiki/Gary_McGraw' }, { label: 'BSIMM', url: 'https://www.bsimm.com/' }, @@ -814,8 +763,6 @@ export const pros: Pro[] = [ 'Co-wrote Writing Secure Code, which Bill Gates ordered Windows engineers to read during the 2002 Trustworthy Computing halt, and helped build the Security Development Lifecycle that came out of it — threat modelling, banned APIs, fuzzing and a final security review before ship. The SDL became the template most large software organisations copied.', note: 'Turned “be careful” into a checklist an entire company could be held to.', status: 'locked', - front: '/cards/security/030-michael-howard-front.png', - back: '/cards/security/030-michael-howard-back.png', sources: [ { label: 'Microsoft Security Development Lifecycle', url: 'https://en.wikipedia.org/wiki/Microsoft_Security_Development_Lifecycle' }, { label: 'Writing Secure Code, second edition', url: 'https://www.microsoftpressstore.com/store/writing-secure-code-9780735617223' }, @@ -840,8 +787,6 @@ export const pros: Pro[] = [ 'Drove threat modelling into shippable practice at Microsoft, including the Elevation of Privilege card game that got non-security engineers doing it voluntarily, then wrote Threat Modeling: Designing for Security and later Threats: What Every Engineer Should Learn. Served on the CVE editorial board and co-wrote The New School of Information Security on learning from breach data.', note: 'Four questions — what are we building, what can go wrong, what do we do, did we do a good job.', status: 'locked', - front: '/cards/security/031-adam-shostack-front.png', - back: '/cards/security/031-adam-shostack-back.png', sources: [ { label: 'Adam Shostack’s site', url: 'https://shostack.org/about/adam' }, { label: 'Elevation of Privilege threat modelling game', url: 'https://shostack.org/games/elevation-of-privilege' }, @@ -866,8 +811,6 @@ export const pros: Pro[] = [ 'Wrote ModSecurity, the open-source web application firewall that became the reference implementation and the base of the OWASP Core Rule Set. Then built SSL Labs, whose A-to-F grade for a server’s TLS configuration turned an obscure ops detail into something executives asked about, and wrote Bulletproof TLS and PKI as the manual for fixing the grade.', note: 'Made bad TLS visible and embarrassing, which fixed more of it than any RFC.', status: 'locked', - front: '/cards/security/032-ivan-ristic-front.png', - back: '/cards/security/032-ivan-ristic-back.png', sources: [ { label: 'Ivan Ristić', url: 'https://en.wikipedia.org/wiki/Ivan_Risti%C4%87' }, { label: 'Qualys SSL Labs', url: 'https://www.ssllabs.com/' }, @@ -892,8 +835,6 @@ export const pros: Pro[] = [ 'Co-wrote The Art of Software Security Assessment with John McDonald and Justin Schuh, still the most thorough published treatment of how to find memory-safety and logic flaws by reading code. Found deep bugs in Sendmail, OpenSSH and Flash while at ISS X-Force and IBM, and founded Azimuth Security. His work is why a generation of auditors know what to look for in a parser.', note: 'The book that turned code review from a chore into a craft.', status: 'locked', - front: '/cards/security/033-mark-dowd-front.png', - back: '/cards/security/033-mark-dowd-back.png', sources: [ { label: 'The Art of Software Security Assessment', url: 'https://www.informit.com/store/art-of-software-security-assessment-identifying-and-9780321444424' }, { label: 'Azimuth Security', url: 'https://www.azimuthsecurity.com/' }, @@ -919,8 +860,6 @@ export const pros: Pro[] = [ 'Built the graph-based binary diffing that made it routine to extract the vulnerability out of a vendor patch, founded zynamics around BinDiff and VxClass, and sold it to Google in 2011. Later worked in Project Zero and wrote the “weird machines” framing that treats exploitation as programming an unintended state machine inside the target.', note: 'Turned Patch Tuesday into a reliable source of exploit intelligence.', status: 'locked', - front: '/cards/security/034-halvar-flake-front.png', - back: '/cards/security/034-halvar-flake-back.png', sources: [ { label: 'BinDiff', url: 'https://www.zynamics.com/bindiff.html' }, { label: 'Thomas Dullien’s research blog', url: 'https://addxorrol.blogspot.com/' }, @@ -945,8 +884,6 @@ export const pros: Pro[] = [ 'Co-authored “Bypassing Browser Memory Protections”, the 2008 paper that showed how attackers were routing around DEP and ASLR, then at 25C3 the same year demonstrated a working rogue certificate authority built on MD5 collisions — which pushed the CA industry off MD5 for good. Co-founded Trail of Bits.', note: 'Demonstrated the theoretical break against a live CA, which is the only kind that moves anyone.', status: 'locked', - front: '/cards/security/035-alex-sotirov-front.png', - back: '/cards/security/035-alex-sotirov-back.png', sources: [ { label: 'MD5 considered harmful today (2008)', url: 'https://www.win.tue.nl/hashclash/rogue-ca/' }, { label: 'Bypassing Browser Memory Protections (2008)', url: 'https://www.blackhat.com/presentations/bh-usa-08/Sotirov_Dowd/bh08-sotirov-dowd.pdf' }, @@ -971,8 +908,6 @@ export const pros: Pro[] = [ 'Co-wrote the 1998 paper with Timothy Newsham showing that a network IDS which reassembles traffic differently from the host it protects can be walked straight past — the work that forced every vendor to rethink normalisation. Co-founded Matasano and later Latacora, and wrote the Cryptopals challenges that taught a generation how crypto actually breaks.', note: 'One paper made every IDS vendor rewrite their TCP stack.', status: 'locked', - front: '/cards/security/036-thomas-ptacek-front.png', - back: '/cards/security/036-thomas-ptacek-back.png', sources: [ { label: 'Insertion, Evasion, and Denial of Service (1998)', url: 'https://insecure.org/stf/secnet_ids/secnet_ids.html' }, { label: 'The Cryptopals crypto challenges', url: 'https://cryptopals.com/' }, @@ -997,8 +932,6 @@ export const pros: Pro[] = [ 'Johns Hopkins cryptographer who co-led the Open Crypto Audit Project’s review of TrueCrypt, contributed to the analysis of Dual_EC_DRBG and the RSA BSAFE backdoor, and worked on the attacks behind Logjam and DROWN. His blog is the standard place the rest of the industry goes to find out how badly a new crypto story is being reported.', note: 'Does the audit, then does the translation so the rest of us can follow it.', status: 'locked', - front: '/cards/security/037-matthew-green-front.png', - back: '/cards/security/037-matthew-green-back.png', sources: [ { label: 'Matthew D. Green', url: 'https://en.wikipedia.org/wiki/Matthew_D._Green' }, { label: 'A Few Thoughts on Cryptographic Engineering', url: 'https://blog.cryptographyengineering.com/' }, @@ -1023,8 +956,6 @@ export const pros: Pro[] = [ 'Co-authored the cold boot attack paper showing DRAM retains keys after power off, then spent a career demonstrating — in court and in front of legislatures — that deployed voting machines could be reprogrammed. Co-founded the Internet Security Research Group behind Let’s Encrypt, and co-authored the ZMap internet-wide scanner and the Logjam and FREAK results.', note: 'Let’s Encrypt alone changed the default state of the web from plaintext to TLS.', status: 'locked', - front: '/cards/security/038-j-alex-halderman-front.png', - back: '/cards/security/038-j-alex-halderman-back.png', sources: [ { label: 'J. Alex Halderman', url: 'https://en.wikipedia.org/wiki/J._Alex_Halderman' }, { label: 'Lest We Remember: Cold Boot Attacks on Encryption Keys', url: 'https://citp.princeton.edu/our-work/memory/' }, @@ -1049,8 +980,6 @@ export const pros: Pro[] = [ 'Co-authored “Mining Your Ps and Qs”, which scanned the whole IPv4 internet and found that a meaningful share of TLS and SSH keys shared factors because embedded devices generated them without entropy — and then factored them. Followed it with Logjam, DROWN and FREAK, a body of work whose method is: measure what is actually deployed, then break the weak part.', note: 'Proved the crypto was fine and the random number generators were not.', status: 'locked', - front: '/cards/security/039-nadia-heninger-front.png', - back: '/cards/security/039-nadia-heninger-back.png', sources: [ { label: 'Nadia Heninger', url: 'https://en.wikipedia.org/wiki/Nadia_Heninger' }, { label: 'Mining Your Ps and Qs (USENIX Security 2012)', url: 'https://factorable.net/paper.html' }, @@ -1075,8 +1004,6 @@ export const pros: Pro[] = [ 'Built Have I Been Pwned in 2013 as a way for ordinary people to find out whether their account was in a dump, and it became infrastructure: browsers, password managers and the NIST-endorsed practice of checking passwords against known-breached lists all query it, using a k-anonymity scheme that never sends the password. Runs it as a public good rather than a product.', note: 'One person’s side project ended up inside the login flow of half the web.', status: 'locked', - front: '/cards/security/040-troy-hunt-front.png', - back: '/cards/security/040-troy-hunt-back.png', sources: [ { label: 'Troy Hunt', url: 'https://en.wikipedia.org/wiki/Troy_Hunt' }, { label: 'Have I Been Pwned', url: 'https://haveibeenpwned.com/' }, @@ -1101,8 +1028,6 @@ export const pros: Pro[] = [ 'Was security lead and signoff for Windows XP Service Pack 2 and Windows Server 2003, co-wrote the Threat Modeling book that came out of that era, then ran security at Mozilla for Firefox, at Apple on privacy and security strategy, at Fastly and Square, and became Intel’s first chief software security officer. Founded Thistle Technologies in 2020 to bring update infrastructure to embedded devices.', note: 'Has been the person accountable for a shipping product’s security more times than anyone.', status: 'locked', - front: '/cards/security/041-window-snyder-front.png', - back: '/cards/security/041-window-snyder-back.png', sources: [ { label: 'Window Snyder', url: 'https://en.wikipedia.org/wiki/Window_Snyder' }, { label: 'Thistle Technologies', url: 'https://thistle.tech/' }, @@ -1127,8 +1052,6 @@ export const pros: Pro[] = [ 'A founding member of Google’s security team who built and ran its incident response function, including the response to the 2009 Operation Aurora intrusion that Google chose to disclose publicly — a decision that reset industry norms on breach transparency. Co-authored Building Secure and Reliable Systems, and has served on US federal cybersecurity advisory bodies.', note: 'Ran the response that made public disclosure of a state intrusion normal.', status: 'locked', - front: '/cards/security/042-heather-adkins-front.png', - back: '/cards/security/042-heather-adkins-back.png', sources: [ { label: 'Building Secure and Reliable Systems', url: 'https://sre.google/books/building-secure-reliable-systems/' }, { label: 'Operation Aurora', url: 'https://en.wikipedia.org/wiki/Operation_Aurora' }, @@ -1153,8 +1076,6 @@ export const pros: Pro[] = [ 'Joined Google as a penetration tester, printed “Security Princess” on her business card, and rose to run Chrome. Led the multi-year project to mark plain HTTP as “Not secure” in the world’s most-used browser, which more than anything else moved the web to encryption by default, and pushed Project Zero’s 90-day disclosure deadline as an industry-wide forcing function.', note: 'Changed one string in a browser UI and moved the whole web to TLS.', status: 'locked', - front: '/cards/security/043-parisa-tabriz-front.png', - back: '/cards/security/043-parisa-tabriz-back.png', sources: [ { label: 'Parisa Tabriz', url: 'https://en.wikipedia.org/wiki/Parisa_Tabriz' }, { label: 'Chromium: marking HTTP as not secure', url: 'https://blog.chromium.org/2018/02/a-secure-web-is-here-to-stay.html' }, @@ -1179,8 +1100,6 @@ export const pros: Pro[] = [ 'Was CISO at Yahoo, where he objected to a government email-scanning programme, then CSO at Facebook through the investigation into foreign influence operations, leaving in 2018 over how much the company would disclose. Publicly challenged the NSA director on encryption backdoors, founded the Stanford Internet Observatory, and co-founded iSEC Partners and later Krebs Stamos Group.', note: 'The card about what the job costs when you do it honestly.', status: 'locked', - front: '/cards/security/044-alex-stamos-front.png', - back: '/cards/security/044-alex-stamos-back.png', sources: [ { label: 'Alex Stamos', url: 'https://en.wikipedia.org/wiki/Alex_Stamos' }, { label: 'Stanford Internet Observatory', url: 'https://cyber.fsi.stanford.edu/io' }, @@ -1205,8 +1124,6 @@ export const pros: Pro[] = [ 'Co-authored the 2003 CCIA report arguing that monoculture in operating systems was itself a national security risk, and was fired by @stake, then a Microsoft consultancy, the day it was published. Went on to serve as chief information security officer of In-Q-Tel and to give a run of Black Hat and USENIX keynotes that are still the most quoted long-form arguments about security policy the field has produced.', note: 'Paid for the paper with his job, and the paper was right.', status: 'locked', - front: '/cards/security/045-dan-geer-front.png', - back: '/cards/security/045-dan-geer-back.png', sources: [ { label: 'Dan Geer', url: 'https://en.wikipedia.org/wiki/Dan_Geer' }, { label: 'CyberInsecurity: The Cost of Monopoly (2003)', url: 'https://www.schneier.com/essays/archives/2003/09/cyberinsecurity_the.html' }, @@ -1231,8 +1148,6 @@ export const pros: Pro[] = [ 'Founded Mandiant in 2004 and built breach response into a business that governments and Fortune 100 boards call at 2am. In 2013 the company published APT1, a report attributing years of intrusions to a specific People’s Liberation Army unit with building photographs and operator handles — the moment public, named attribution became something private companies did.', note: 'Made attribution a commercial deliverable instead of a classified one.', status: 'locked', - front: '/cards/security/046-kevin-mandia-front.png', - back: '/cards/security/046-kevin-mandia-back.png', sources: [ { label: 'Mandiant', url: 'https://en.wikipedia.org/wiki/Mandiant' }, { label: 'APT1: Exposing One of China’s Cyber Espionage Units (2013)', url: 'https://www.mandiant.com/resources/reports/apt1-exposing-one-chinas-cyber-espionage-units' }, @@ -1257,8 +1172,6 @@ export const pros: Pro[] = [ 'Has been analysing malware at F-Secure since 1991, through the DOS virus era, Sasser and Blaster, Stuxnet and modern ransomware. Tracked down and interviewed the Pakistani brothers who wrote Brain, the first PC virus, twenty years after the fact. Formulated Hyppönen’s law — if it is smart, it is vulnerable — and is the researcher most often trusted to explain a live incident to the public.', note: 'The continuity card. One person watched the entire history of malware happen.', status: 'locked', - front: '/cards/security/047-mikko-hypponen-front.png', - back: '/cards/security/047-mikko-hypponen-back.png', sources: [ { label: 'Mikko Hyppönen', url: 'https://en.wikipedia.org/wiki/Mikko_Hypp%C3%B6nen' }, { label: 'Brain (computer virus)', url: 'https://en.wikipedia.org/wiki/Brain_(computer_virus)' }, @@ -1283,8 +1196,6 @@ export const pros: Pro[] = [ 'A former US Air Force cyber warfare officer who co-authored the analysis of the 2015 Ukrainian power grid attack and the later CRASHOVERRIDE and TRISIS malware, then founded Dragos to do industrial control system defence as a specialism rather than an IT afterthought. Co-wrote the SANS ICS courses that most OT defenders come through.', note: 'The set’s reminder that some networks fail into a physical consequence.', status: 'locked', - front: '/cards/security/048-robert-m-lee-front.png', - back: '/cards/security/048-robert-m-lee-back.png', sources: [ { label: 'Robert M. Lee — Dragos', url: 'https://www.dragos.com/leadership/robert-m-lee/' }, { label: 'Analysis of the Cyber Attack on the Ukrainian Power Grid (SANS/E-ISAC, 2016)', url: 'https://www.nerc.com/pa/CI/ESISAC/Documents/E-ISAC_SANS_Ukraine_DUC_18Mar2016.pdf' }, @@ -1310,8 +1221,6 @@ export const pros: Pro[] = [ 'Led incident response at Motorola Solutions and then at Dragos, running investigations inside live industrial networks where you cannot simply reimage the plant. Writes long-running public guidance on breaking into and surviving the profession, founded PancakesCon, and holds the SANS Lifetime Achievement Award for that work as much as the casework.', note: 'The mentorship is the contribution. Half a conference floor learned from those posts.', status: 'locked', - front: '/cards/security/049-lesley-carhart-front.png', - back: '/cards/security/049-lesley-carhart-back.png', sources: [ { label: 'Lesley Carhart', url: 'https://en.wikipedia.org/wiki/Lesley_Carhart' }, { label: 'Lesley Carhart’s blog', url: 'https://tisiphone.net/about/' }, @@ -1336,8 +1245,6 @@ export const pros: Pro[] = [ 'Was the threat intelligence lead for MITRE ATT&CK during the years it became the shared vocabulary defenders use to describe adversary behaviour, then went to Red Canary as director of intelligence. Teaches the SANS cyber threat intelligence course and spends most of her public work on the unglamorous question of how an intelligence report turns into a detection someone actually deploys.', note: 'ATT&CK gave the blue team a language. This is the card for the person who taught it.', status: 'locked', - front: '/cards/security/050-katie-nickels-front.png', - back: '/cards/security/050-katie-nickels-back.png', sources: [ { label: 'MITRE ATT&CK', url: 'https://attack.mitre.org/' }, { label: 'Katie Nickels — SANS Institute', url: 'https://www.sans.org/profiles/katie-nickels/' },