<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Random Thoughts on Education &amp; Learning from @markofu</title>
	<atom:link href="http://www.securityninja.co.uk/application-security/random-thoughts-on-education-learning-from-markofu/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securityninja.co.uk/application-security/random-thoughts-on-education-learning-from-markofu/</link>
	<description>Security research, news and guidance</description>
	<lastBuildDate>Thu, 09 May 2013 14:59:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Penetration Testers are Cool?? &#124; The IT Geek Chronicles</title>
		<link>http://www.securityninja.co.uk/application-security/random-thoughts-on-education-learning-from-markofu/comment-page-1/#comment-12290</link>
		<dc:creator>Penetration Testers are Cool?? &#124; The IT Geek Chronicles</dc:creator>
		<pubDate>Thu, 01 Nov 2012 20:54:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.securityninja.co.uk/?p=2386#comment-12290</guid>
		<description>[...] before Christmas @markofu was interviewed on @securityninja&#8217;s blog in a post called &#8220;Random Thoughts on Education &amp; Learning&#8220;, I posted a comment asking for advice about how to &#8220;break into security&#8221; [...]</description>
		<content:encoded><![CDATA[<p>[...] before Christmas @markofu was interviewed on @securityninja&#8217;s blog in a post called &#8220;Random Thoughts on Education &amp; Learning&#8220;, I posted a comment asking for advice about how to &#8220;break into security&#8221; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: markofu</title>
		<link>http://www.securityninja.co.uk/application-security/random-thoughts-on-education-learning-from-markofu/comment-page-1/#comment-11678</link>
		<dc:creator>markofu</dc:creator>
		<pubDate>Thu, 22 Dec 2011 21:00:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.securityninja.co.uk/?p=2386#comment-11678</guid>
		<description>No worries Adam, hopefully it helps.

Feel free to ping me on Twitter etc. 

Cheers...m</description>
		<content:encoded><![CDATA[<p>No worries Adam, hopefully it helps.</p>
<p>Feel free to ping me on Twitter etc. </p>
<p>Cheers&#8230;m</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam Maxwell</title>
		<link>http://www.securityninja.co.uk/application-security/random-thoughts-on-education-learning-from-markofu/comment-page-1/#comment-11676</link>
		<dc:creator>Adam Maxwell</dc:creator>
		<pubDate>Thu, 22 Dec 2011 19:55:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.securityninja.co.uk/?p=2386#comment-11676</guid>
		<description>Mark, thank you for taking the time to reply.

With regards to Twitter, I agree following too many people means you miss things, currently I&#039;m only following people that either tweet things of interest to me or seem to have a good &quot;reputation&quot; on Twitter.

The challenges for Pen Testing is something on my list to try, and I will no doubt blog about my success and failures, I&#039;m a patience person so I&#039;m in no rush to have hundreds of hits (and the content isn&#039;t there yet either). My blog is more like my own personal diary of how my &quot;skills&quot; are developing, if people read it all the better.

There aren&#039;t any &quot;local&quot; security groups near me, but I intend to go to Defcon and possibly OWASP in London next year. I hadn&#039;t heard of the InfoSec Mentor programme but I will have a look now.

I was actually having a look at the Offensive Computing courses, might see if I can convince work to pay for it.. :)

Thanks for the reading book lists, some of those are on my list. I&#039;ve been making a list of areas of InfoSec that I need to work on and then adding books to my list as I go.

Again thank you for taking the time to response to my comments.

Adam</description>
		<content:encoded><![CDATA[<p>Mark, thank you for taking the time to reply.</p>
<p>With regards to Twitter, I agree following too many people means you miss things, currently I&#8217;m only following people that either tweet things of interest to me or seem to have a good &#8220;reputation&#8221; on Twitter.</p>
<p>The challenges for Pen Testing is something on my list to try, and I will no doubt blog about my success and failures, I&#8217;m a patience person so I&#8217;m in no rush to have hundreds of hits (and the content isn&#8217;t there yet either). My blog is more like my own personal diary of how my &#8220;skills&#8221; are developing, if people read it all the better.</p>
<p>There aren&#8217;t any &#8220;local&#8221; security groups near me, but I intend to go to Defcon and possibly OWASP in London next year. I hadn&#8217;t heard of the InfoSec Mentor programme but I will have a look now.</p>
<p>I was actually having a look at the Offensive Computing courses, might see if I can convince work to pay for it.. <img src='http://www.securityninja.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Thanks for the reading book lists, some of those are on my list. I&#8217;ve been making a list of areas of InfoSec that I need to work on and then adding books to my list as I go.</p>
<p>Again thank you for taking the time to response to my comments.</p>
<p>Adam</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: markofu</title>
		<link>http://www.securityninja.co.uk/application-security/random-thoughts-on-education-learning-from-markofu/comment-page-1/#comment-11675</link>
		<dc:creator>markofu</dc:creator>
		<pubDate>Thu, 22 Dec 2011 19:32:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.securityninja.co.uk/?p=2386#comment-11675</guid>
		<description>1. I have a twitter account and I&#039;ve followed people that tweet about InfoSec but I can&#039;t find any lists of who I should be following, and once I&#039;ve found people, how do you get them to follow you?

&gt;&gt; I&#039;ve never really worried about who follows me and who doesn&#039;t, at the start maybe a little but I really don&#039;t care. I don&#039;t think I&#039;ve ever asked anyone to follow me but I have had folk DM me, then unfollow so I couldn&#039;t DM them back :) 

I don&#039;t like following too many people because I find that I miss so much from the people that I do want to follow. There are lists out there but again they&#039;re subjective to the creator and many are full of &quot;thought leaders&quot; and &quot;evangelists&quot;, which IMHO isn&#039;t a good thing and they&#039;re not the people you want to follow. A lot of the time you get real &quot;gems&quot; out of really clever people who don&#039;t have that many followers, nor do they care about having many.

On Twitter, you can comment on what others tweet as most folk are decent and will reply, engaging in a conversation Say enough interesting things and you&#039;ll be followed. Similarly tweet links with your own comments &amp; hashtags. This will most likely generate RTs etc.

I personally don&#039;t follow people lists - it&#039;s generally friends, friends of friends or folk who I feel are industry leaders and if any of that lot retweet something interesting, I&#039;ll trial following the person who was retweeted. 

Although I may not follow someone, I&#039;ll always reply to a tweet to me, something a lot of so-called &quot;security thought leaders&quot; don&#039;t do. Why? No idea, maybe their ego gets in the way? On the other hand, some sh!t-hot folk (who you imagine are incredibly busy) will go out of their way to help.

2.  I have a blog, which although isn&#039;t 100% security related will feature articles about Security, but then what? For example I was looking for a Pen Testers process flow diagram, Google was  no help so I made my own, but who/how do I get it checked to see if it&#039;s right before I blog about it?

&gt;&gt; I think you&#039;re doing the right things but driving traffic to your site is difficult, especially when the people you want to read it are usually busy and many are trying to do the same thing as you whilst others are choosy over what they&#039;ll read.

Have you thought about doing some of the challenges for pen tests or forensics on the web? You could the contests and post your solution on the blog after the challenge close date? That&#039;ll generate traffic to your blog and usually get folk offering constructive criticism.

For me, I did a combination of the study route, was lucky enough to meet Brian Honan and got invited to be part of Iriss Cert, created HackEire, presented at local security meetings and posted links to what I did (as well as being fairly chatty on Twitter).

I&#039;d recommend looking around where you live to see if there are any Security groups - Owasp, 2600, DefCon or even on the net, have you thought about applying to InfoSec Mentors as a mentee?

I think everyone&#039;s different and you figure out along the way what works for you.

3. Courses - Are they worth it (I know hands on experience is best)? If so which one? SSCP, CEH, Security+

&gt;&gt; As I said on the blog, I&#039;m a huge fan of SANS/GIAC and the &#039;red aprons&#039;, however, I do appreciate that they&#039;re expensive :) I&#039;d also look at the Offensive Computing courses, I&#039;ve heard nothing but good about OCSP and OCSE (they are cheaper). I&#039;d like to try them myself but if I do another course, it&#039;ll most likely lead to a divorce!!

I don&#039;t know enough about the others to comment though I&#039;ve heard very mixed reports about the middle one.

4. Books - I&#039;m reading 3 at the moment, but is there a book list somewhere? Or is it a personal choice?

&gt;&gt; On the HackEire blog about HackEire 2011, I posted some books that would&#039;ve been useful for the CTF - http://www.hackeire.net/2011/11/hackeire-2011-ramblings-part-1.html.

Personally though, it&#039;s a personal choice and if you want some guidance, you can&#039;t go wrong with Bejtlich&#039;s list - http://www.bejtlich.net/reading.html.</description>
		<content:encoded><![CDATA[<p>1. I have a twitter account and I&#8217;ve followed people that tweet about InfoSec but I can&#8217;t find any lists of who I should be following, and once I&#8217;ve found people, how do you get them to follow you?</p>
<p>&gt;&gt; I&#8217;ve never really worried about who follows me and who doesn&#8217;t, at the start maybe a little but I really don&#8217;t care. I don&#8217;t think I&#8217;ve ever asked anyone to follow me but I have had folk DM me, then unfollow so I couldn&#8217;t DM them back <img src='http://www.securityninja.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  </p>
<p>I don&#8217;t like following too many people because I find that I miss so much from the people that I do want to follow. There are lists out there but again they&#8217;re subjective to the creator and many are full of &#8220;thought leaders&#8221; and &#8220;evangelists&#8221;, which IMHO isn&#8217;t a good thing and they&#8217;re not the people you want to follow. A lot of the time you get real &#8220;gems&#8221; out of really clever people who don&#8217;t have that many followers, nor do they care about having many.</p>
<p>On Twitter, you can comment on what others tweet as most folk are decent and will reply, engaging in a conversation Say enough interesting things and you&#8217;ll be followed. Similarly tweet links with your own comments &amp; hashtags. This will most likely generate RTs etc.</p>
<p>I personally don&#8217;t follow people lists &#8211; it&#8217;s generally friends, friends of friends or folk who I feel are industry leaders and if any of that lot retweet something interesting, I&#8217;ll trial following the person who was retweeted. </p>
<p>Although I may not follow someone, I&#8217;ll always reply to a tweet to me, something a lot of so-called &#8220;security thought leaders&#8221; don&#8217;t do. Why? No idea, maybe their ego gets in the way? On the other hand, some sh!t-hot folk (who you imagine are incredibly busy) will go out of their way to help.</p>
<p>2.  I have a blog, which although isn&#8217;t 100% security related will feature articles about Security, but then what? For example I was looking for a Pen Testers process flow diagram, Google was  no help so I made my own, but who/how do I get it checked to see if it&#8217;s right before I blog about it?</p>
<p>&gt;&gt; I think you&#8217;re doing the right things but driving traffic to your site is difficult, especially when the people you want to read it are usually busy and many are trying to do the same thing as you whilst others are choosy over what they&#8217;ll read.</p>
<p>Have you thought about doing some of the challenges for pen tests or forensics on the web? You could the contests and post your solution on the blog after the challenge close date? That&#8217;ll generate traffic to your blog and usually get folk offering constructive criticism.</p>
<p>For me, I did a combination of the study route, was lucky enough to meet Brian Honan and got invited to be part of Iriss Cert, created HackEire, presented at local security meetings and posted links to what I did (as well as being fairly chatty on Twitter).</p>
<p>I&#8217;d recommend looking around where you live to see if there are any Security groups &#8211; Owasp, 2600, DefCon or even on the net, have you thought about applying to InfoSec Mentors as a mentee?</p>
<p>I think everyone&#8217;s different and you figure out along the way what works for you.</p>
<p>3. Courses &#8211; Are they worth it (I know hands on experience is best)? If so which one? SSCP, CEH, Security+</p>
<p>&gt;&gt; As I said on the blog, I&#8217;m a huge fan of SANS/GIAC and the &#8216;red aprons&#8217;, however, I do appreciate that they&#8217;re expensive <img src='http://www.securityninja.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I&#8217;d also look at the Offensive Computing courses, I&#8217;ve heard nothing but good about OCSP and OCSE (they are cheaper). I&#8217;d like to try them myself but if I do another course, it&#8217;ll most likely lead to a divorce!!</p>
<p>I don&#8217;t know enough about the others to comment though I&#8217;ve heard very mixed reports about the middle one.</p>
<p>4. Books &#8211; I&#8217;m reading 3 at the moment, but is there a book list somewhere? Or is it a personal choice?</p>
<p>&gt;&gt; On the HackEire blog about HackEire 2011, I posted some books that would&#8217;ve been useful for the CTF &#8211; <a href="http://www.hackeire.net/2011/11/hackeire-2011-ramblings-part-1.html" rel="nofollow">http://www.hackeire.net/2011/11/hackeire-2011-ramblings-part-1.html</a>.</p>
<p>Personally though, it&#8217;s a personal choice and if you want some guidance, you can&#8217;t go wrong with Bejtlich&#8217;s list &#8211; <a href="http://www.bejtlich.net/reading.html" rel="nofollow">http://www.bejtlich.net/reading.html</a>.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
