Katie Moussouris (she/her)🥜👋🏼<p>100th post, as fine a time as any to do the traditional <a href="https://infosec.exchange/tags/introduction" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>introduction</span></a> before nobody on <a href="https://infosec.exchange/tags/mastodon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mastodon</span></a> does them anymore.<br>I’m a <a href="https://infosec.exchange/tags/hacker" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacker</span></a> , a parent, a founder & CEO, government advisory board member, cat food servant, defender and participant in democracy, & an arm wrestling and karaoke enthusiast — not necessarily at the same time, but not opposed to trying it all at once either.<br>Carpe brachium karaoke as they say. 💪🏼🎤<br>Here we go. Get a snack & some water, this is long. 🍪 🥛 <br>My professional passions include <a href="https://infosec.exchange/tags/SystemDynamics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SystemDynamics</span></a> & <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> with my <a href="https://infosec.exchange/tags/focus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>focus</span></a> on helping organizations & governments develop healthy sustainable <a href="https://infosec.exchange/tags/VulnerabilityDisclosure" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VulnerabilityDisclosure</span></a> programs that may end up growing into a <a href="https://infosec.exchange/tags/BugBounty" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BugBounty</span></a> program, or helping existing programs mature & evolve.<br>🌺🏝️ 🌺🏝️ 🌺🏝️ 🌺🏝️<br>🌺I founded & run <a href="https://www.Lutasecurity.com" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="">Lutasecurity.com</span><span class="invisible"></span></a> & we employ dozens of people, mostly in the US, to help some of our customers manage their <a href="https://infosec.exchange/tags/VDPs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VDPs</span></a> and <a href="https://infosec.exchange/tags/BugBounties" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BugBounties</span></a> as internally-placed personnel.<br>📜Services: <a href="https://www.lutasecurity.com/services" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="">lutasecurity.com/services</span><span class="invisible"></span></a><br>💻Hiring: <a href="https://www.lutasecurity.com/careers" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="">lutasecurity.com/careers</span><span class="invisible"></span></a><br>💵Referral bounties: <a href="https://www.lutasecurity.com/referralbounty" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">lutasecurity.com/referralbount</span><span class="invisible">y</span></a><br>🌺🏝️ 🌺🏝️ 🌺🏝️ 🌺🏝️<br>👩🏻💻💰🛡️ 👩🏻💻💰🛡️ 👩🏻💻💰🛡️<br>I helped launch <a href="https://infosec.exchange/tags/HackThePentagon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HackThePentagon</span></a> in 2016, which was the first bug bounty of the US government & the first time it was legal to hack the USG. <br>👩🏻💻💰🛡️ 👩🏻💻💰🛡️ 👩🏻💻💰🛡️<br>This was after I created Microsoft’s first bug bounty programs in 2013, paying out the most at the time for brand new exploitation techniques, which would later lead to me directly helping the US renegotiate the <a href="https://infosec.exchange/tags/Wassenaar" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Wassenaar</span></a> Arrangement to clarify “intrusion software” and “intrusion software technology” export control exemptions to more easily allow for hassle-free exchange of 0day & malware samples across borders for vulnerability disclosure & incident response.<br>🛠️💻 🛠️💻 🛠️💻 🛠️💻<br>I also started two vulnerability research programs, Symantec Vulnerability Research & Microsoft Vulnerability Research. The latter was also the first formal major vendor multiparty <a href="https://infosec.exchange/tags/SupplyChain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SupplyChain</span></a> vulnerability coordination & disclosure program.<br>🛠️💻 🛠️💻 🛠️💻 🛠️💻<br>I now serve on 3 Federal advisory boards in cyber.<br>⚖️NIST ISPAB: <a href="https://csrc.nist.gov/Projects/ispab/members" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">csrc.nist.gov/Projects/ispab/m</span><span class="invisible">embers</span></a><br>💱Commerce ISTAC: <a href="https://tac.bis.doc.gov/index.php/documents/members-listing/422-istac-website-listing/file" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">tac.bis.doc.gov/index.php/docu</span><span class="invisible">ments/members-listing/422-istac-website-listing/file</span></a><br>🚨DHS CSRB: <a href="https://www.dhs.gov/news/2022/02/03/dhs-launches-first-ever-cyber-safety-review-board" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">dhs.gov/news/2022/02/03/dhs-la</span><span class="invisible">unches-first-ever-cyber-safety-review-board</span></a><br>🎙️Fun fact: Despite mainstream media lip service about getting diverse voices on TV, and my extensive direct experience in US domestic & foreign cyber policy & norm-setting, I have *never* been invited to be on broadcast news to talk about it. Not one time. But there are the same dudes with none of my experience showing up on TV all the time.<br>📺 Email Press@Lutasecurity.com if you can change that.<br>📺📺📺📺📺📺📺📺<br>⚖️💸 ⚖️💸 ⚖️💸 ⚖️💸<br>👩🏻⚖️ Speaking of gender equity, I was the lead plaintiff in the attempted class action gender pay and promotion discrimination lawsuit against Microsoft. <br>💵💪🏼 <a href="https://www.theverge.com/22331972/pay-equity-now-pledge-katie-moussouris-microsoft-lawsuit" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">theverge.com/22331972/pay-equi</span><span class="invisible">ty-now-pledge-katie-moussouris-microsoft-lawsuit</span></a><br>When it failed to get class certified due to some legal gotchas, NOT because of lack of data and evidence, I decided to drop my case and founded <a href="https://www.payequitynowfoundation.org/blog" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">payequitynowfoundation.org/blo</span><span class="invisible">g</span></a> & created <br><a href="https://www.manglonalab.org/" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="">manglonalab.org/</span><span class="invisible"></span></a> to fight for <a href="https://infosec.exchange/tags/PayEquity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PayEquity</span></a> in our lifetime.<br>⚖️💸 ⚖️💸 ⚖️💸 ⚖️💸<br>🌸Another fun fact: I’m asked about the gender stuff way more often than any of my professional work or national security work. I view this as The Lady Tax & I’m all paid up thanks. <br>🙅🏻♀️Don’t ask me about how to attract more diverse candidates, don’t ask me to mentor your mentee, and don’t ask me for any more free labor. Don’t ask any historically marginalized people to do free labor, especially to solve your diversity puzzle.<br>👏🏼I highly recommend <a href="https://blacktechpipeline.com/" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="">blacktechpipeline.com/</span><span class="invisible"></span></a> if you are serious about not just hiring but welcoming more black workers into your company. There are specialty recruiters out there for you to pay, so don’t ask every woman or person of color you know to help you with that unless they are being paid to do it.<br>👏🏼💰👏🏼💰👏🏼💰👏🏼💰<br>🧩 Miscellaneous bits if you’ve made it this far is that I studied molecular biology, biochemistry & mathematics but dropped out to become a systems administrator, a professional Linux developer, then a hacker for hire. <br>🔐 I still hack by accident (because hacksidents happen), and nobody should have to be the coauthor/coeditor of the International Standards on how to do Vulnerability Disclosure to get an organization’s attention.<br>👩🏻🏫 ISO standards overview: <a href="https://m.youtube.com/watch?v=-L3DNZtK8lc" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">m.youtube.com/watch?v=-L3DNZtK</span><span class="invisible">8lc</span></a></p><p>📲 Clubhouse hack: <a href="https://www.wired.com/story/clubhouse-bug-lurkers-ghost/" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">wired.com/story/clubhouse-bug-</span><span class="invisible">lurkers-ghost/</span></a><br>🔐🔐🔐🔐🔐🔐🔐<br>💸💸💸💸💸💸💸<br>🙄 Despite my entire career being technical, when my company tried for venture capital funding to build something cool, we were met with sexism & lack of imagination & I was hilariously asked more than once if I had a technical cofounder. <br>It’s cool, joke’s on them. We’re <a href="https://infosec.exchange/tags/profitable" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>profitable</span></a> and growing.<br>🤨<a href="https://www.vice.com/en/article/xgyvza/this-hacker-is-trying-to-close-the-gender-pay-gap-in-cybersecurity" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">vice.com/en/article/xgyvza/thi</span><span class="invisible">s-hacker-is-trying-to-close-the-gender-pay-gap-in-cybersecurity</span></a><br>💸💸💸💸💸💸💸<br>🏛️🏛️🏛️🏛️🏛️🏛️🏛️<br>I participate in Democracy with more than voting. Anyone with the bandwidth should look into doing it too.<br>1. Google “find my Legislative district”<br>2. Go to your State website & search by your address<br>3. Look up your Legislative District’s (LD) website to find out how to join<br>4. Attend monthly LD meetings<br>5. Run for Delegate per LD or be appointed like me when not enough people do 1-4<br>🏛️🏛️🏛️🏛️🏛️🏛️🏛️<br>👋🏼✌🏼👋🏼✌🏼👋🏼✌🏼👋🏼✌🏼<br>🛑Ending abruptly is on brand for me as a neuroatypical person, so I’ll leave you with this thought:<br>🐈 I named my 17 year old cat Scapy (rhymes with happy) after the Python tool of the same name. Because he is dumb & fuzzy.<br>😸If you get that joke, you pretty much get me.<br>🤙🏽🤙🏽🤙🏽🤙🏽🤙🏽🤙🏽🤙🏽🤙🏽<br>✌🏼Be kind, drink water, touch grass, save the planet, save Democracy, pet cute animals. ✌🏼</p>