Layer 2 person spoofing
and impostor syndrome
% sudo ifconfig en0 ether 78:4f:43:69:1b:10 \
&& ifconfig en0 | head -3
en0: flags=8863 mtu 1500
ether 78:4f:43:69:1b:10
inet netmask 0xfffffc00 broadcast
@benjammingh for BsidesNZ
Who's this clown? (1/2) 2
• Security Engineer at Stripe.
• Infrastructure security at Etsy.
• Opera5ons engineer at Puppet.
• Two 5me sponsor of Wrong Island Con.
https://
Who's this whingeing pom? (2/2)
• Knows how to pronounce "router".
• Is delighted to be back here enjoying the 300/400ms latency on
• Has had his Instagramme stuck giving him NZ ads for the past 3
months. (if you know how to fix this, please help me!)
is heaps be)er than
is also be)er than both
But first!
A trigger warning
This talk is about
vulnerability |vʌln(ə)rəˈbɪlɪ4|
noun (plural vulnerabili*es) [mass noun]
the quality or state of being exposed to the possibility of being
a5acked or harmed, either physically or emo:onally: conserva:on
authori:es have realized the vulnerability of the local popula:on
the quality or state of being exposed
to the possibility of being a5acked
or harmed, either physically or
So if you're looking for 0-day, you
may be in the wrong room.
Impostor syndrome!
Impostor syndrome is when high-
achieving individuals are marked by
an inability to internalise their
accomplishments & a persistent fear
of being exposed as a "fraud"
— clinical psychologists Dr. Pauline R. Clance & Suzanne A. Imes
"Am I even qualified to give this
— Me, earlier today, proving that I probably am.
"But everyone has this, no?"
Actually liking things to be 2dy
@benjammingh for BsidesNZ 16
Slide 17
Slide 17 text
"I am going to be discovered and
— Me, then.
It makes it real hard to do good work
Which then just perpetuates itself
Which leads to burnout...
Reality vs. Percep0on of others
From https://
(Best (worst) stock photo ever?)
Impostor syndrome can be a sign
that you're about to learn awesome
It can be a sign you have a lot of
knowledge to share too!
Straw poll
How many people have you heard of ge3ng
fired due to knowing nothing?
How many people have you heard of having
impostor syndrome?
So why do our brains make this
trade off?
Did I men)on I work in security?
Infosec problems (including but not limited to)
• Has a&ackers. Coders have bugs, ops people have well the world.
There are real humans a&acking you trying to break your shit.*
• There is very clear win/lose stakes.
• Especially in the con scene, a lot of posturing.
• DefCon sCll exists (;
* Assume blue team here, I know...
...which leads to
• people not showing their vulnerabili3es (not that kind).
• people not admi:ng they don't know something out of fear.
• people burning out and leaving the industry.
• Infosec not being the most diverse and inclusive industry.
"well don't think of yourself as an
imposter, think of yourself as not a
— Sco& Roberts
"One of the best things I've done for
myself lately: created a doc where I
"For passphrases, make them
something posi2ve and encouraging,
so every 2me you have to type them
in, you feel a li:le be:er about the
— paraphrased from an Anonymous Canadian
Aside: cogni,ve dissonance
What can you do as an organisa0on?
Acknowledge it!
It's okay to say what's okay
From The Recurse Center
Obligatory reference to blameless
postmortems as I'm contractually
bound to by Etsy
Praise others, because they may feel
this too.
Tip for praise: Don't personalize. For
the same reason you wouldn't say
"You're a dumbass," don't just say
"You're a genius."
— @candor
Blameless praise! from Slack's great article on giving feedback
Stop the nerd snipe, even if it's good
Your culture o*en affects people in
seemingly invisible ways
Just don't go too far (;
Dunning–Kruger effect
Let's hope I'm on track for 2me!
• be understand to people, this is hard.
• be kind to yourself, even if you're a jerk like me.
• seek help if you can (friends, therapists, coworkers)
This affects people differently
• Confidence sadly o.en comes with privilege.
• As does arrogance.
Mess of links that will be useful when I tweet the URL to this
• Impostor Syndrome in DFIR - Sco5 Roberts fantas9c piece on
the topic.
• Allowed To Apply - blog on telling yourself you can do this.
• How to get a promo9on
• Blue Hackers - site on mental health in the tech community and
how to help.
If this sounds like an environment
you'd like to work in, come talk to
me about
Jobs at Stripe
• My blog post on the subject
• Fax: +1 (415) 484-7239
• Twidder: @benjammingh
• SpeakerDeck:
@benjammingh for BsidesNZ 60