# Ajit Gaddam / root777 — full public context Canonical identity: https://www.root777.com/#ajit Canonical site: https://www.root777.com Machine-readable profile: https://www.root777.com/api/profile Live public signals: https://www.root777.com/api/public-signals Last profile review: 2026-08-01 ## Identity Ajit Gaddam is an engineer, executive, inventor, and builder working across artificial intelligence, fraud, identity, cybersecurity, autonomous systems, and trust platforms. He currently leads Fraud, AI & Trust Platforms at HealthEquity. This site is a personal index, not a résumé. It preserves Ajit's original writing, documents selected systems and inventions, and connects major public claims to primary or institutional sources. ## Open builds ### [Fraud-Fighting AI Granny](https://www.root777.com/builds/fraud-fighting-ai-granny/) - Status: Public prototype - Problem: Scam operations scale when human attention is cheap. Every minute a scammer spends with a safe, synthetic counterpart is a minute not spent pressuring a real target. - Outcome: A public Node.js prototype that answers a Twilio call, listens, generates an in-character response, synthesizes speech, and keeps the exchange going within a bounded conversation. - Audience: Fraud teams, trust-and-safety builders, and anyone exploring defensive voice agents. - Technologies: Node.js, Twilio Voice, OpenAI, Azure Speech, Express - Public source: https://github.com/AjitGaddam/Fraud-fighting-AI-Granny- - License: Apache-2.0 - Production gaps documented: Validate every Twilio webhook signature before accepting call events. Move conversation state from process memory into a durable, expiring store. Replace the placeholder session secret with a managed secret and rotate it. Add rate limits, abuse controls, redaction, and an explicit audio-retention policy. Wire the repository’s scam-pattern detector into the live call path—or remove it until it is a tested control. Add operational telemetry, model fallbacks, consent review, and jurisdiction-aware call handling. ## Career context - 2025—NOW · HealthEquity · Head of Fraud, AI & Trust Platforms: Leading a converged fraud, identity, AI, and trust-platform function. Current work centers on AI-era fraud defense and the security, governance, and accountability of agentic systems. - 2022—2025 · Wells Fargo · Global Head of Fraud Technology & GenAI Claims: Led global fraud-technology engineering and generative-AI claims in one of the world’s largest financial institutions. - 2012—2022 · Visa · VP, Cybersecurity Products, AI & Engineering · Distinguished Engineer: Built machine-learning-driven security products and platform defenses at global payment scale. Became one of Visa’s most prolific inventors and one of roughly five Distinguished Engineers in its history. - 2010—2012 · Progressive Insurance · Data Defense & Big-Data Analytics: Worked on big-data security, telematics platforms, and early enterprise cloud adoption as data became core operating infrastructure. - 2008—2010 · SkunkLabs · Co-founder & CTO: Built and scaled a consumer startup to roughly 1.5 million monthly active users, including early fraud and bot defenses. The company was acquired. - 2006—2008 · Google · Senior Security Engineer: Security engineering across internal infrastructure, cryptography, and automated malware detection. - EARLIER · Carnegie Mellon · Florida Tech · AI, robotics, and computer engineering: M.S. work in artificial intelligence and robotics at Carnegie Mellon, connected to the DARPA Grand Challenge, following B.S. and M.S. degrees in computer engineering at Florida Tech. ## Upcoming public appearance - August 4, 2026: [Black Hat USA 2026 · AI Summit — Patching 80,000 systems every other day!](https://blackhat.com/us-26/summit-sessions/schedule/index.html#patching-80000-systems-every-other-day-54969), 10:10–10:50 AM, Mandalay Bay Convention Center · Las Vegas ## Selected independently verifiable sources - 2026 · CASE STUDY: [90% drop in voice fraud without adding customer friction](https://www.pindrop.com/research/case-study/healthequity-drop-fraud-smoother-cx/) — Pindrop × HealthEquity - 2026 · ON-DEMAND SESSION: [Defending healthcare against AI attacks, impersonation & deepfakes](https://www.pindrop.com/research/webinar/defending-healthcare-against-ai-attacks-deepfakes/) — Pindrop - 2025 · PATENT: [Proactive Defense of Untrustworthy Machine Learning System](https://patents.google.com/patent/US12361281B2/en) — US 12,361,281 B2 - 2024 · PUBLIC SERVICE: [Chair, National Technical Information Service Advisory Board](https://www.ntis.gov/about/advisorybd/index.xhtml) — U.S. Department of Commerce - 2019 · TALK: [Behavioral biometrics against bots and account-takeover attacks](https://www.usenix.org/conference/enigma2019/presentation/gaddam) — USENIX Enigma ## Complete writing index - 2020-05-02: ["I don't think we will ever run out of problems to solve"](https://www.root777.com/featured/i-dont-think-we-will-run-out-of-problems-to-solve/) — Got a chance to do a campaign video along with other Visa experts on utilizing artificial intelligence and deep learning models to address a broad range of payment challenges. [embed]https://youtu.be/TzOoo8fdENk[/embed]… - 2017-08-27: [Winner of 2017 Information Security Executive Award](https://www.root777.com/featured/winner-2017-information-security-executive-award/) — Honored and privileged to have been chosen as the Information Security Executive of the year 2017. The awards ceremony and the winners for the executive of the year and security project of the year were announced at an A… - 2016-11-28: [Participating in Security Shark Tank with Robert Herjavec and CISOs](https://www.root777.com/technews/participating-security-shark-tank-robert-herjavec-cisos/) — Participating as a 'Shark' as part of a panel comprising of Chief Information Security Officers (CISOs) and Robert Herjavec. The event is the Security Shark Tank taking place on Feb 14, 2017 in San Francisco during the w… - 2016-11-17: [Judge for SC Magazine Awards 2017](https://www.root777.com/technews/judge-sc-magazine-awards-2017/) — The annual SC Magazine 2017 awards celebrating the best and brightest in Information Security is around the corner. As part of this mission, it was a huge honor and privilege to be part of a small panel of judges compris… - 2016-11-12: [Speaking at Global Big Data Conference 2016](https://www.root777.com/technews/speaking-global-big-data-conference-2016/) — Speaking on Securing Apache Kafka [caption id="attachment_421" align="aligncenter" width="1322"] Securing Apache Kafka by Ajit Gaddam[/caption] http://globalbigdataconference.com/santa-clara/big-data-bootcamp/schedule-77… - 2015-10-26: [Cloud Security Guidance](https://www.root777.com/cloud/cloud-security-guidance/) — This post is a summary of the guidance provided in version 3 of the Cloud Security Alliance document Security Guidance for Critical Areas of Focus in Cloud Computing v3.0. The CSA guidance remains one of the best around… - 2015-08-19: [Good List of Open Source Security Projects](https://www.root777.com/tools/good-list-of-open-source-security-projects/) — This is a compilation of some excellent open source security projects. I will continue to update this page. Insert in comments below if you have any good reference projects or open source security tools. I am excluding t… - 2015-07-03: [Speaking at Black Hat USA 2015](https://www.root777.com/technews/speaking-at-black-hat-usa-2015/) — Very excited to announce my selection and participation in Black Hat USA 2015 being held in Las Vegas this year. My talk is titled 'Securing Your Big Data Environment'. Come join me in the South Seas CDF room in Mandalay… - 2015-01-19: [Speaking at Strata Hadoop World Conference](https://www.root777.com/data-protection/speaking-strata-hadoop-world-conference/) — I am definitely excited to talk about Bigdata and its security for the enterprise at the upcoming Stratra Conference. See you folks there.… - 2012-04-13: [Indicators of Compromise List and Recommended Security Measures](https://www.root777.com/security/indicators-of-compromise-list-and-recommended-security-measures/) — Unlike loss of a physical device, if an attacker breaks into your corporate network, you still have your data after they steal it. It is more important that ever to detect if your company has been broken into by a hacker… - 2012-03-20: [Does Using Google Libraries API CDN give you Performance Benefits?](https://www.root777.com/appdev/does-using-google-libraries-api-cdn-give-you-performance-benefits/) — A CDN - short for Content Distribution Network helps serve content with high availability and provides performance benefits along with faster page load times. The Google Libraries API is a CDN for serving the most popula… - 2012-03-08: [The need for Secure Coding in an Enterprise](https://www.root777.com/application-security/the-need-for-secure-coding-in-an-enterprise/) — We live in a global village of interconnected systems that share data and other services. Such an environment calls for heightened awareness around application security. Enterprises should establish a strong application… - 2012-02-17: [Google Chrome Security Settings and Configuration Guide for Enterprise](https://www.root777.com/security/google-chrome-security-settings-and-configuration-guide-for-enterprise/) — Google Chrome holds a market share of about 25% of the overall web browser market. It is growing faster and gaining more market share by the day than all the browsers out there. Most of these users seek to extend their u… - 2011-10-30: [How to create Secure and Easy to Remember Passwords](https://www.root777.com/security/how-to-create-secure-and-easy-to-remember-passwords/) — It is very important to choose a secure password to help protect your identity and information on the Internet. I previously wrote about strong password suggestions and how easy it is for bad guys and hackers to guess yo… - 2011-10-30: [Weekly Security Updates on 2011-10-30](https://www.root777.com/security/weekly-security-updates-on-2011-10-30/) — Is your email address or account compromised by hackers? Find out http://t.co/uHDgqaam via @PwnedList #… - 2011-10-23: [Weekly Security Updates on 2011-10-23](https://www.root777.com/security/weekly-security-updates-on-2011-10-23/) — 'Ever notice how it's a penny for your thoughts, yet you put in your two-cents? Someone is making a penny on the deal.' - Steven Wright # Review of the excellent @NewYorker article around Ray Dalio including quotes &… - 2011-10-16: [Weekly Security Updates on 2011-10-16](https://www.root777.com/security/weekly-security-updates-on-2011-10-16/) — Developers, developers, developers replaced by Platforms,platforms, platforms in this insightful article around #Google http://t.co/kNjpw7N4 #… - 2011-10-09: [Weekly Security Updates on 2011-10-09](https://www.root777.com/security/weekly-security-updates-on-2011-10-09/) — Mark Zuckerberg FB Page: Thanks for showing that what you build can change the world. #SteveJobs #… - 2011-10-02: [Weekly Security Updates on 2011-10-02](https://www.root777.com/security/weekly-security-updates-on-2011-10-02/) — var life = new[] {"eat", "sleep", "security"} # #BSIMM3 has been released. Go grab it http://t.co/3xnMgSLp and account for application #security maturity #AppSec #BSIMM # Checking out #Tableau Desktop http://t.co/Tuw5oaP… - 2011-09-18: [Weekly Security Updates on 2011-09-18](https://www.root777.com/security/weekly-security-updates-on-2011-09-18/) — Good #Microsoft Windows 8 security features summary http://t.co/ncXaTEMJ #InfoSec #Windows8 #Win8 #… - 2011-09-11: [Weekly Security Updates on 2011-09-11](https://www.root777.com/security/weekly-security-updates-on-2011-09-11/) — Revoke trust of the #DigiNotar root certificates - root CA, Root CA G2, PKIoverheid CA, PKIoverheid CA Organisatie. http://t.co/biXY2bj # Enterprise or Security Architects don't define the strategy but define the capabil… - 2011-09-04: [Weekly Security Updates on 2011-09-04](https://www.root777.com/security/weekly-security-updates-on-2011-09-04/) — #PCI updates its #wireless security guidelines that align with DSS 2.0 http://t.co/xbewJzM #security #… - 2011-08-28: [Weekly Security Updates on 2011-08-28](https://www.root777.com/security/weekly-security-updates-on-2011-08-28/) — Security Quote of the day: #cloud is one of those solutions waiting for a problem. No one knows its purpose yet #SABSA #InfoSec #quote # Just experienced my first earthquake a 5 something #Washington #Virginia #earthquak… - 2011-08-21: [Weekly Security Updates on 2011-08-21](https://www.root777.com/security/weekly-security-updates-on-2011-08-21/) — Apple recently passed Exxon in market cap . But does it matter? An excellent article from @arstechnica captures this http://t.co/G6PtT7A #… - 2011-08-14: [Weekly Security Updates on 2011-08-14](https://www.root777.com/security/weekly-security-updates-on-2011-08-14/) — Excellent article about #data #exfiltration http://t.co/cLn509m #infosec #security # Test #Android for #security with this excellent #pentesting guide http://t.co/R8z4yNN #… - 2011-08-07: [Weekly Security Updates on 2011-08-07](https://www.root777.com/security/weekly-security-updates-on-2011-08-07/) — Reading #Application #Security: 2011 & Beyond – A #Forrester Research Report http://t.co/m3DV7R5 (pdf). Good insights and recommendations #… - 2011-07-31: [Weekly Security Updates on 2011-07-31](https://www.root777.com/security/weekly-security-updates-on-2011-07-31/) — #Google likes a business? Not an issue unless you follow a bunch of spam bots. Only boosts #SEO ranking on people in your circle #… - 2011-07-24: [Weekly Security Updates on 2011-07-24](https://www.root777.com/security/weekly-security-updates-on-2011-07-24/) — #ISC2 Global Information #Security Workforce study http://t.co/iJDDSoG (pdf). Topics: #salary experience, training & #certifications # Excellent #Ruby on Rails Security guide. http://t.co/VZ8LwQC #AppSec # Own your o… - 2011-07-17: [Weekly Security Updates on 2011-07-17](https://www.root777.com/security/weekly-security-updates-on-2011-07-17/) — How to make folks ready a #privacy policy? Turn it into an interactive game http://t.co/WYqYpag. Check out #zynga #039;s #PrivacyVille # Johns Hopkins University course on #Security and #Privacy in #Cloud Computing. Exce… - 2011-07-10: [Weekly Security Updates on 2011-07-10](https://www.root777.com/security/weekly-security-updates-on-2011-07-10/) — Now that you can buy any TLD,buy ".1" and create a host called "127.0.0" under it. Lets see what breaks. Lend me $185000 via @mikkohypponen # Updated #SDL banned function calls http://t.co/kRi6YEQ. Include various C runt… - 2011-07-03: [Weekly Security Updates on 2011-07-03](https://www.root777.com/security/weekly-security-updates-on-2011-07-03/) — I like the security concept behind Google+ - it's a social network almost nobody can join via @dourscot # Primary threats targeting mobile devices and data. Good infographic & report (PDF) via @symantec http://t.co/L… - 2011-06-26: [Weekly Security Updates on 2011-06-26](https://www.root777.com/security/weekly-security-updates-on-2011-06-26/) — #PCI council guidance on #virtualization released http://t.co/sgQqK3Q including some #cloud guidance #… - 2011-06-12: [Weekly Security Updates on 2011-06-12](https://www.root777.com/security/weekly-security-updates-on-2011-06-12/) — Looking at #sectestsuite for automated #security #testing http://goo.gl/IocPB including automation of the #owasp testing guide via @owasp303 # Have an #Android phone? Use RedPhone and TextSecure apps http://goo.gl/4p2Dg… - 2011-06-08: [Resolve Facebook security warnings when a user enables https](https://www.root777.com/application-security/resolve-facebook-security-warnings-when-a-user-enables-https/) — When a user who has https enabled and lands on your page or Facebook app, your page maybe generating security warnings about webpage content that was delivered. Do you want to view only the webpage content that was delivered securely? If an FB app does not have the Secure Canvas URL set, the error message will be shown - 2011-06-08: [Resolve Facebook Security Warnings when https is Enabled](https://www.root777.com/application-security/resolve-facebook-security-warnings-when-https-is-enabled/) — This article if focused on Facebook App Security and Facebook https warning. You may have come across the security warning as shown below if your app requires communication over https. This is due to cross domain content… - 2011-06-05: [Weekly Security Updates on 2011-06-05](https://www.root777.com/security/weekly-security-updates-on-2011-06-05/) — Facebook Account got #hacked Five tips to recover your #Facebook http://goo.gl/iHT0j #security #privacy # Train employees and risk them leaving or not train employees, and have them stay! #evenworse #training #infosec vi… - 2011-05-29: [Facebook Account got Hacked? How to Recover your Facebook](https://www.root777.com/security/facebook-account-got-hacked-how-to-recover-your-facebook/) — Is your profile sent spammy links to your friends walls with events or videos you did not create? Is your wall flooded with spam messages? It is possible that malicious software (e.g. computer virus or worms) has been do… - 2011-05-29: [Weekly Security Updates on 2011-05-29](https://www.root777.com/security/weekly-security-updates-on-2011-05-29/) — Looking at #Google wallet #security features http://www.google.com/wallet/how-it-works-security.html #PayPal #NFC #Android #… - 2011-04-17: [Weekly Security Updates on 2011-04-17](https://www.root777.com/security/weekly-security-updates-on-2011-04-17/) — Automatic e-mail footers are not just annoying. They are also legally useless http://goo.gl/vPlVo #… - 2011-04-03: [Weekly Security Updates on 2011-04-03](https://www.root777.com/security/weekly-security-updates-on-2011-04-03/) — #Google +1 sounds cool and geeky. Would regular folks know what it would mean? #likebutton #request # If #Google didn't want to use like, maybe a "promote" tag or something else # Don't think I will be promoting search r… - 2011-03-20: [Weekly Security Updates on 2011-03-20](https://www.root777.com/security/weekly-security-updates-on-2011-03-20/) — "How I need a drink, alcoholic of course,after the tough lectures involving quantum mechanics" Count letters for 3.14159265358979 #pi #piday # Time to update your Google Profiles. #Google intends on deleting all private… - 2011-03-13: [Weekly Security Updates on 2011-03-13](https://www.root777.com/security/weekly-security-updates-on-2011-03-13/) — @securityincite Mike, did you folks explore security as a service, not cloud services but internal to an organization(architecture domains)? # @securityincite Mike, sent you a high level description of my thought around… - 2011-03-06: [Weekly Security Updates on 2011-03-06](https://www.root777.com/security/weekly-security-updates-on-2011-03-06/) — #CareerBuilder is calling the "Cyber Security Specialist" as the top potential #job http://goo.gl/HEH59 via@securityincite #career #InfoSec # Am now #Gingerbread Not a big fan of all green though. #NexxusOne #Android #Go… - 2011-02-27: [Weekly Security Updates on 2011-02-27](https://www.root777.com/security/weekly-security-updates-on-2011-02-27/) — Great analysis of the effectiveness of #DEP and #ASLR and their value -- both alone and together.http://goo.gl/YpblS #InfoSec #AppSec # Read: Model-driven Cloud Security: http://ibm.co/evKuue via @IBMFedCyber by @objects… - 2011-02-20: [Weekly Security Updates on 2011-02-20](https://www.root777.com/security/weekly-security-updates-on-2011-02-20/) — Seeing all these booth numbers at #RSA I wonder who booth number 1337 is .. #security #infosec #leet # #NIST Information Security Glossary of Key Information #Security Terms released http://goo.gl/DYRpI #InfoSec # #BSide… - 2011-02-13: [Weekly Security Updates on 2011-02-13](https://www.root777.com/security/weekly-security-updates-on-2011-02-13/) — #WordPress 3.0.5 is now available and is a #security hardening update for all previous WordPress versions http://wordpress.org/download/ # Open #Security Analyst position on Threat and Vulnerability team with focus on we… - 2011-02-06: [Weekly Security Updates on 2011-02-06](https://www.root777.com/security/weekly-security-updates-on-2011-02-06/) — If you have #GoDaddy as your ISP, you can now enable #mod_pagespeed now http://goo.gl/kyVV9 by editing your .htaccess file # #OWASP #Appsec Tutorial Series that highlights a different security concept, tool or methodolog… - 2010-12-12: [Weekly Security Updates on 2010-12-12](https://www.root777.com/security/weekly-security-updates-on-2010-12-12/) — Apply for the #Google #Chrome netbook pilot program here http://www.google.com/chromeos/ #chromeos #android # Performance Analysis of WS-Security Mechanisms in SOAP-Based Web Services http://goo.gl/yoKNV #CMU #IdM #secur… - 2010-12-05: [Weekly Security Updates on 2010-12-05](https://www.root777.com/security/weekly-security-updates-on-2010-12-05/) — Wordpress 3.0.2 is out - security update http://wordpress.org/download/ #wordpress #security # How to improve the security of Internet Explorer protected mode in the enterprise http://goo.gl/uBrfp #sandbox #internetexplo… - 2010-11-28: [Weekly Security Updates on 2010-11-28](https://www.root777.com/security/weekly-security-updates-on-2010-11-28/) — No more flat networks. ANSI ISA-99 security zones guide. http://goo.gl/PI3JE (pdf) #stuxnet #security #network #ANSI # "Berlin" is revealed as #Kryptos clue. Time to dig deep. http://goo.gl/eu44v #CIA #Kryptos #encryptio… - 2010-11-21: [Weekly Security Updates on 2010-11-21](https://www.root777.com/security/weekly-security-updates-on-2010-11-21/) — Free online Certified Ethical Hacking (CEH) course from Logical Security http://goo.gl/hKTm4 #CEH #hacking #course #security #free # Just got added to The Open Group (TOG) public certification register for my TOGAF 8 cer… - 2010-11-14: [Weekly Security Updates on 2010-11-14](https://www.root777.com/security/weekly-security-updates-on-2010-11-14/) — Hotmail is now using SSL https://www.hotmail.com. Can choose to always use SSL. Won't work with Outlook or any live mail apps. #Hotmail #SSL # HTML5 security cheatsheet http://goo.gl/KGo8R via @0x6D6172696F #HTML5 #secur… - 2010-11-07: [Weekly Security Updates on 2010-11-07](https://www.root777.com/security/weekly-security-updates-on-2010-11-07/) — Google XSS proof of concept http://google-store.com/product_info.php/%22%3E%3Cimg%20src=x%20onerror=alert(1);%3E via@securityshell #XSS #… - 2010-10-31: [Weekly Security Updates on 2010-10-31](https://www.root777.com/security/weekly-security-updates-on-2010-10-31/) — Reading #PCI #Security Standard 2.0 http://goo.gl/OWR6. 132 changes overall. Focus on 17 items of addl guidance & requirements first #… - 2010-10-24: [Weekly Security Updates on 2010-10-24](https://www.root777.com/security/weekly-security-updates-on-2010-10-24/) — Reading up on FAIR risk assessment methodology http://goo.gl/qVzi #FAIR #Risk #ISRA #… - 2010-10-17: [Weekly Security Updates on 2010-10-17](https://www.root777.com/security/weekly-security-updates-on-2010-10-17/) — @mattcutts he seems to have figured out the answer to the life, universe and everything.. a successful marriage in reply to mattcutts # installing Ubuntu 10.10 on 10/10/10 # Orgs with a data breach were 50% less likely c… - 2010-10-10: [Weekly Security Updates on 2010-10-10](https://www.root777.com/security/weekly-security-updates-on-2010-10-10/) — The often-misused SAS-70 auditing standard is set to be replaced next year by SSAE-16 http://goo.gl/SEtI #cloud #SAS70 #standard #security # @indi303 you have leet followers ... # Improper output & input handling res… - 2010-10-10: [Happy 10/10/10 Binary Day](https://www.root777.com/technews/happy-101010-binary-day/) — The day is made up entirely of ones and zeros, the binary language for computing. Some other trivia about 10/10/10 0. Converting 101010 from binary to decimal gives 42, the answer to the meaning of life, the universe and… - 2010-10-03: [Weekly Security Updates on 2010-10-03](https://www.root777.com/security/weekly-security-updates-on-2010-10-03/) — I have access to the new Twitter #woot #twitter # I heard Stuxnet was running for president with drop database as his running mate via @st0rmz #stuxnet #hype #worm # Great list of default passwords with over 361 vendors… - 2010-09-18: [Failure of Security Planning](https://www.root777.com/technews/failure-of-security-planning/) — I spotted this on a Git doco page:… - 2010-09-15: [The Most Popular Usernames and Passwords, a Visual Representation](https://www.root777.com/pen-testing/the-most-popular-usernames-and-passwords-a-visual-representation/) — Dragon Research Group has compiled a list of the most popular usernames and passwords that are prevalent by SSH scanners/brute forcer attackers. It does not relate to popular account credentials such as the RockYou passw… - 2010-08-08: [Ethical Hacker Network Challenge : Miracle on Thirty - Hack Street](https://www.root777.com/pen-testing/ethical-hacker-network-challenge-miracle-on-thirty-hack-street/) — The results for the Ethical Hacker Network Challenge - Miracle on Thirty Hack Street are finally in and I won a Technical Honorable Mention! The challenge was pretty good and was focussed on Facebook security or insecuri… - 2010-08-05: [Mentoring the SANS 401 Security Essentials class](https://www.root777.com/security/mentoring-the-sans-401-security-essentials-class/) — Definitely happy and excited that my mentor class is now live and I can begin the mentor program beginning September 21st in Cleveland. Personally, it is a wonderful opportunity for me to interact with other security pro… - 2010-08-02: [Analyzing the 2010 Verizon Data Breach Report](https://www.root777.com/data-protection/analyzing-the-2010-verizon-data-breach-report/) — In a way, the annual Verizon Data Breach reports have become a must read when it comes to analyzing the latest trends associated with data breaches. This years report had more meat and gained additional weight when the U… - 2010-07-26: [SQL Injection Attacks explained for the Developer](https://www.root777.com/application-security/sql-injection-attacks-explained-for-the-developer/) — SQL injection attacks have become the most widely exploited security attacks on the Internet as they can usually bypass layers of security such as firewalls and any other network detection sensors. They are used most oft… - 2010-05-29: [Facebook Privacy Settings Guide](https://www.root777.com/security/facebook-privacy-settings-guide/) — Facebook, the most popular social networking site just implemented a bunch of new privacy settings for its users. The new privacy settings are being promoted by Facebook as making it easier for its users to control their… - 2009-11-24: [Using SHODAN to find insecure Servers, Routers and gain ROOT access](https://www.root777.com/application-security/using-shodan-to-find-insecure-servers-routers-and-gain-root-access/) — SHODAN lets you find servers/ routers/ etc. by using the simple search bar up above. Most of the data in the index covers web servers at the moment, but there is some data on FTP, Telnet and SSH services as well. Lets sa… - 2009-11-05: [Secret Knock Detecting Lock](https://www.root777.com/technews/secret-knock-detecting-lock/) — Oh man .. epic geekiness... I love it… - 2009-10-24: [Encrypt HTML form data without using SSL](https://www.root777.com/application-security/encrypt-html-form-data-without-using-ssl/) — In certain cases, it might be hard to install SSL certificates or SSL is not supported by some webhosts. In those cases, there is a need to encrypt the data (POST/GET) that is sent when you submit a form because if you d… - 2009-10-22: [How to Encrypt Files using TrueCrypt](https://www.root777.com/security/how-to-encrypt-files-using-truecrypt/) — TrueCrypt is a free open source disk encryption software that works on both Windows and Linux platforms. Data stored on an encrypted volume cannot be read (decrypted) without using the correct password/keyfile(s) or corr… - 2009-10-18: [Mozilla Firefox disables Microsoft .NET and WPF addons](https://www.root777.com/security/mozilla-firefox-disables-microsoft-net-and-wpf-addons/) — This morning, I was prompted by Firefox that it had disabled the .NET Framework Assistant and the Windows Presentation Foundation addons. The popup concluded with the message that these addons have been known to cause st… - 2009-08-16: [How to Protect your Identity from Identity Theft](https://www.root777.com/security/how-to-protect-your-identity-from-identity-theft/) — This guide will help you take action to protect yourself against identity theft. If you have already been victimized, this guide will provide information about restoring your credit profile and minimize the potential for any future occurrences of identity theft. - 2009-08-15: [How to Get a Google Wave Account](https://www.root777.com/application-security/how-to-get-a-google-wave-account/) — Click here on how you can get access to get a beta or sandbox account for Google Wave. Google Wave is a new tool for communication and collaboration on the web, coming later this year. - 2009-08-08: [Privacy Settings for Facebook](https://www.root777.com/security/privacy-settings-for-facebook/) — Facebook is currently the most popular social networking website with over 250 million active users worldwide. Anyone who is 13 and over can sign up for a Facebook account and can add friends and share their most intimate information with their friends including pictures and personal information. While it can be fun and convenient to keep up with old friends and make new ones online, sharing too much personal information on these sites can be risky. - 2009-08-06: [Why is Windows so expensive?](https://www.root777.com/technews/why-is-windows-so-expensive/) — If you type in the query of Why is Windows so expensive? or Why is Microsoft Windows so expensive? on Microsoft's search engine bing.com returns the top result as "Why are Macs so expensive". This is rather disappointing… - 2009-07-30: [Dan Kaminsky gets hacked](https://www.root777.com/technews/dan-kaminsky-gets-hacked/) — Noted security professional Dan Kaminsky's personal website was hacked into and personal information was stolen from his webserver and posted online on the eve of the Black Hat security conference. The stolen files inclu… - 2008-12-30: [Solution to Error 500 after upgrading to WordPress 2.7](https://www.root777.com/wordpress/solution-to-error-500-after-upgrading-to-wordpress-27/) — After I recently upgraded my blog to the latest version of Wordpress v2.7, I noticed an Error 500 - Internal server error. This seems to be a problem for WordPress blogs which are hosted by 1&1 The solution to the Er… - 2008-12-29: [Solving FBI's 2008 Code Cracking Challenge](https://www.root777.com/security/solving-fbis-2008-code-cracking-challenge/) — The Federal Bureau of Investigation (FBI) has issued a code cracking challenge today. This was in response to a similar challenge the FBI issued last year, which proved to be hugely popular with many thousands responding… - 2008-10-16: [Strong Password Suggestions using a Password Chart](https://www.root777.com/security/strong-password-suggestions-using-a-password-chart/) — I think I came across one of the best strong password generators on the Internet at Password Chart. Picking a strong password is very important. A strong and secure password should go beyond just a simple number such as… - 2008-10-15: [Generate Secure Passwords using the Enigma Code Machine](https://www.root777.com/security/generate-secure-passwords-using-the-enigma-code-machine/) — The Enigma was a rotor machine used by the German Military during WW II to encrypt messages they sent to each other. It was invented by German Engineer Arthur Scherbius in 1923. The Enigma Code Machine consisted of a plu… - 2008-09-07: [How to Break Web Software](https://www.root777.com/security/how-to-break-web-software/) — Mike Andrews was one of the coolest and most knowledgeable professors I had the opportunity of learning from, while at school @ Florida Tech. Currently, Mike is currently working as the Principle consultant at Foundstone… - 2008-09-07: [The Great Zero Challenge](https://www.root777.com/writing/the-great-zero-challenge/) — The Great Zero Challenge: A challenge to confirm whether or not a professional data recovery firm or any individual(s) or organization(s) can recover data from a hard drive that has been overwritten with zeros once. All… - 2008-09-04: [How to crash Google Chrome](https://www.root777.com/pen-testing/how-to-crash-google-chrome/) — Google claims that its browser Google Chrome is able to isolate events that may crash a browser, isolated within those individual tabs. However, an issue exists with how Google Chrome handles undefined handlers in chrome… - 2008-08-11: [Internet Browsers and their users](https://www.root777.com/technews/internet-browsers-and-their-users/) — Comparison of the different Internet Browsers and their users. Click here for a bigger picture : http://www.flickr.com/photos/21904710@N00/2754981251/sizes/o/ In case you are wondering what Internet browser I use ... bel… - 2008-07-13: [What is Defense in Depth](https://www.root777.com/security/what-is-defense-in-depth/) — Defense-in-depth is fundamental to the design of a secure system. It stems from the idea that software can have flaws; people can make configuration mistakes; and hardware devices can fail. To compensate for events like… - 2008-06-07: [Computer Security Tips and Best Practices](https://www.root777.com/security/computer-security-tips-and-best-practices/) — Protecting yourself is very challenging in the hostile environment of the internet. Imagine a global environment where an unscrupulous person from the other side of the planet can probe your computer for weaknesses, and… - 2008-05-11: [Preventing Security Threats from USB Storage Devices](https://www.root777.com/security/preventing-security-threats-from-usb-storage-devices/) — Working in Computer Security, one of the biggest threats we face today is the threat of an Insider, an Employee who might casually walk in with his 4 GB USB Flash drive, plug it in to their computer within the corporate… - 2008-04-09: [Operating Systems Security: Year 2007 Vulnerability Report](https://www.root777.com/security/operating-systems-security-year-2007-vulnerability-report/) — Operating Systems Security: Year 2007 Vulnerability Report This paper analyzes the vulnerability disclosures and security updates during the year 2007 for Windows Vista Operating System when compared to its predecessor,… - 2008-03-31: [Physical Security & Information Gathering](https://www.root777.com/security-video/physical-security-information-gathering/) — This is a great presentation by Johnny Long at Defcon. He talks about how easy it is to gain access to secure locations without any "hacking" aka physical security.… - 2008-03-24: [How Many Passes Does the Team in White Make](https://www.root777.com/cool/how-many-passes-does-the-team-in-white-make/) — It is very easy to miss something you are not looking for. How many passes does the team in white make? Test you awareness and Do the Test!… - 2008-03-23: [Most Influential People in Security](https://www.root777.com/computer-security/most-influential-people-in-security/) — Ryan Naraine over at eweek.com has come up with an interesting list of the top 15 most influential people in Computer Security. 1. Tavis Ormandy, Google Security Team’ 2. Ivan Krstic, One Laptop Per Child’ 3. Chris Paget… - 2008-02-04: [Microsoft Windows 7 Feature Request List](https://www.root777.com/technews/microsoft-windows-7-feature-request-list/) — Microsoft seems like it is on track to release the next generation or the next version of Windows, Windows 7 to be tentatively released in 2009. An indicator of what users wish to see in this next version of Windows has… - 2008-02-04: [Bastille Linux](https://www.root777.com/unix-linux/bastille-linux/) — Besides manual security hardening of a Linux OS, let’s check out a free open-source tool to automate and simplify the process. Bastille will disable unnecessary services and install operating system updates as well as co… - 2008-01-31: [The History of Hacking](https://www.root777.com/hacking/the-history-of-hacking/) — Discovery Channel played a very interesting documentary titled "The History of Hacking". This goes into the whole history of hacking starting with phone phreaking and Blue boxes and to the present state of hacking. Howev… - 2008-01-31: [Yahoo! CAPTCHA Cracked](https://www.root777.com/hacking/yahoo-captcha-cracked/) — A CAPTCHA is a type of challenge-response test used in computing to determine whether the user is human. The process involves one computer (a server) asking a user to complete a simple test which the computer is able to… - 2008-01-28: [How to Remove Duplicates from a List](https://www.root777.com/unix-linux/how-to-remove-duplicates-from-a-list/) — Sometimes when running through a CSV or any kind of a log file, you may encounter lists with a lot of duplicates. I will show an example of the simplest order here. Say, you have a duplicates.txt that goes one two three… - 2008-01-19: [Unix Shell for Windows](https://www.root777.com/unix/unix-shell-for-windows/) — A lot of us who use Linux at work/school or have always grown up using Unix commands and using the Unix shell for years and more often than not, there are instances where a ls command comes more naturally than the dir co… - 2008-01-19: [Network Security Risk Assessment](https://www.root777.com/hacking/network-security-risk-assessment/) — In this article, I will introduce you to some well known tools which security analysts use for Network Security Risk assessment, to know more about the layout of the network they are trying to test and also gather intell… - 2008-01-19: [Important Computer Security Terms and Terminology](https://www.root777.com/computer-security/important-computer-security-terms-and-terminology/) — This article lists some Computer Security Terms and Computer Security Terminology. For anyone reading any of the computer security terms below for the first time, I highly recommend that you Google these keywords and lea… - 2008-01-19: [WordPress Security Tips to protect your WordPress Blog](https://www.root777.com/wordpress/wordpress-security-tips-to-protect-your-wordpress-blog/) — While WordPress in general is pretty secure grounds up, it is still vulnerable to the many kinds of security exploits out there. WordPress Security Tip # 1: Upgrade your WordPress Blog Keeping your WordPress blog up to d… - 2008-01-17: [Security of Open Source Software](https://www.root777.com/computer-security/security-of-open-source-software/) — Is Open Source Software Really more Secure? The constant stream of Windows vulnerability attacks result not solely due to security holes in the Operating System, but also because of the ubiquity of Windows as both a clie… - 2008-01-15: [How to Create a Strong Password](https://www.root777.com/computer-security/how-to-create-a-strong-password/) — The notion of passwords is not flawed, but rather it is the type of passwords that are commonly used that lead to password or security breaches. You need to have a complex and a strong password which needs to be changed… - 2007-12-25: [TIBCO Rendezvous RVD Daemon Remote Memory Leak DoS](https://www.root777.com/security-vulnerability/tibco-rendezvous-rvd-daemon-remote-memory-leak-dos/) — The TIBCO Rendezvous RVD daemon is vulnerable to a memory leak, which when remotely triggered, prevents any further RV communication until the daemon is manually restarted. Vulnerability Type / Importance: Remote DoS / H… - 2007-12-20: [IT Security Interviews Exposed](https://www.root777.com/computer-security/it-security-interviews-exposed/) — IT Security or Information Security has steadily grown from being an obscured field of work in some government or military or financial institutions to become a mainstream activity practiced by many professionals includi… - 2007-11-11: [How to remove Tracking Cookies](https://www.root777.com/spyware/how-to-remove-tracking-cookies/) — Tracking Cookies while generally of a low threat level to your PC, they are still classified as Spyware. This article describes what a tracking cookie is, how to identify tracking cookies and finally how to remove tracki… - 2007-11-05: [External Content Threats Security and Web Beacons](https://www.root777.com/security-policy/external-content-threats-security-and-web-beacons/) — For IT Security folks, especially those in a large corporation, dealing with Threats Security or External Content Threats Security has a potential to take away a significant operations time. So what is External Content T… - 2007-11-04: [Remove Powered by Zedo & URL.cpvfeed.com Popups](https://www.root777.com/spyware/spyware-and-adware-removal-zedo-urlcpvfeedcom-popups/) — Spyware such as Zedo, powered by Zedo and URL.cpvfeed.com redirects your browser or opens popups displaying advertising. Step by step security article on How to remove the Zedo, powered by zedo, URL.cpvfeed.com popups and also remove the core.sys rootkit. - 2007-11-04: [Why Biometric Security CANNOT secure a Corporate Environment](https://www.root777.com/security/why-biometric-security-cannot-secure-a-corporate-environment/) — Biometric Security is being billed as the next savior of personal and corporate security, a superior solution to our Identity and Access management problems. However, the fact is that if someone steals your Biometric ID, it remains stolen for life. - 2007-02-22: [Neutrality of Net Neutrality article on Wikipedia under dispute](https://www.root777.com/technews/neutrality-of-net-neutrality-article-on-wikipedia-under-dispute/) — I saw this on an RSS feed somewhere and went down to further investigate. This is definitely funny where the neutrality of Net Neutrality article on Wikipedia is disputed. While this is standard practice on Wikipedia whe… - 2007-02-19: [Dirty Business: What Security and Pen Testers need to know to get the job done](https://www.root777.com/pen-testing/dirty-business-what-security-and-pen-testers-need-to-know-to-get-the-job-done/) — This article is part # 3 in the series on Penetration Testing. The first in this series talks about Penetration testing as a profession and a general introduction. The second introduces you to some critical keywords and… - 2007-02-18: [Introduction to Ethical Hacking and Penetration Testing](https://www.root777.com/pen-testing/introduction-to-ethical-hacking-and-penetration-testing/) — An Introduction to Ethical hacking through the eyes of a pen tester and hopefully helps anyone reading this blog on how to protect and secure a network by understanding how a Hacker operates and understanding their tools… - 2007-02-16: [Google Gmail Keyboard Shortcuts](https://www.root777.com/writing/google-gmail-keyboard-shortcuts/) — A Keyboard Shortcut according to Wikipedia states that a keyboard shortcut (or accelerator key, shortcut key, hot key, key binding, keybinding, key combo, etc.) is a key or set of keys that performs a predefined function… - 2007-02-02: [Google Accounts has retard as a CAPTCHA](https://www.root777.com/technews/google-accounts-needs-a-retard-to-confirm/) — A CAPTCHA (an initialism for "Completely Automated Public Turing test to tell Computers and Humans Apart", is a type of challenge-response test used in computing to determine whether or not the user is human. A common ty… - 2007-01-30: [How to edit any Webpage on the fly using JavaScript](https://www.root777.com/application-security/how-to-edit-any-webpage-on-the-fly-using-javascript/) — OurPicks have an interesting piece of code snippet on their forums. A simple JavaScript code that lets you edit any webpage, static or dynamic on the fly Let us try this: Step # 1: Go to any website. Let us go to Slashdo… - 2007-01-29: [Slot Machine suffers from the Blue Screen of Death](https://www.root777.com/technews/slot-machine-suffers-from-the-blue-screen-of-death/) — The supposedly indestructuctible slot machines, turns out are prone to failure like any other machine. The inquirer reports this Blue Screen of Death on a slot machine at the International Casino Exhibition in Earl's cou… - 2007-01-29: [Analysis of Spam Thru botnet](https://www.root777.com/security/analysis-of-spam-thru-botnet/) — Mark Sunner, Chief Security Analyst at MessageLabs was among the many security analysts watching one Trojan called "Spam Thru", a piece of malware designed to send spam from an infected computer, at the turn of last year… - 2007-01-28: [Nigerian Scammer moves to London, England](https://www.root777.com/security/nigerian-scammer-moves-to-london-england/) — The most visible form of fee fraud today is the Nigerian Letter or 419 fraud. A typical letter claims to come from a person needing to transfer large sums of money out of the country or from a lottery company. As the Nig… - 2007-01-28: [Spammers now using TinyURL to flood comments](https://www.root777.com/security/spammers-now-using-tinyurl-to-flood-comments/) — Spamming is the abuse of electronic messaging systems to send unsolicited bulk messages. While the most widely recognized form of spam is email spam, spam in blogs is becomming huge these days along with search engine sp… - 2007-01-25: [How to restore the missing Show Desktop icon in your Toolbar](https://www.root777.com/writing/how-to-restore-the-missing-show-desktop-icon-in-your-toolbar/) — The Show Desktop Icon is not a standard program shortcut but a Windows explorer command file written in plain text.If you have accidently deleted the Show Desktop Icons, here are the steps involved to recreate it:Step 1:… - 2007-01-19: [What a Paypal phishing email looks like and how to detect it](https://www.root777.com/security/what-a-paypal-phishing-email-looks-like-and-how-to-detect-it-2/) — In computing, phishing is a criminal activity using social engineering techniques. Phishers attempt to fraudulently acquire sensitive information, such as passwords and credit card details, by masquerading as a trustwort… - 2007-01-18: [How to hide your email address from spammers, a thorough guide](https://www.root777.com/security/how-to-hide-your-email-address-from-spammers-a-thorough-guide/) — Every IT professional worth his/her salt has their own webpage/blog these days. While you may have people from all over the globe dropping a line at your site, Email harvesters are the most unwanted visitors on any websi… - 2007-01-17: [How to detect a Rootkit on your machine](https://www.root777.com/security/how-to-detect-a-rootkit-on-your-machine/) — A root kit is a collection of programs that intruders often install after they have compromised the root account of a system. These programs will help the intruders clean up their tracks, as well as provide access back i… - 2007-01-16: [How to develop ShellCode, a crucial point of any exploit software](https://www.root777.com/pen-testing/how-to-develop-shellcode-a-crucial-point-of-any-exploit-software/) — It’s not an easy task to find a vulnerable service and find an exploit for it. It’s also not easy to defend against users who might want to exploit your system, if you are a system administrator. However, writing an expl… - 2007-01-15: [How to use Unix/Linux commands at the Windows command prompt](https://www.root777.com/security/how-to-use-unixlinux-commands-at-the-windows-command-prompt/) — A lot of us who use Linux at work/school or have always grown up using unix commands for years and more often than not, there might have been instances where a ls command comes more naturally than the dir command at the… - 2007-01-14: [What a Paypal phishing email looks like and how to detect it](https://www.root777.com/security/what-a-paypal-phishing-email-looks-like-and-how-to-detect-it/) — In computing, phishing is a criminal activity using social engineering techniques. Phishers attempt to fraudulently acquire sensitive information, such as passwords and credit card details, by masquerading as a trustwort… - 2007-01-13: [Top 20 List of the Best Geek Quotes, Sayings and Phrases](https://www.root777.com/technews/top-20-list-of-the-best-geek-quotes-sayings-and-phrases/) — For all the geeks out there, do you know someone who tried to teach themselves how to read Barcode? Here is a list of Geek quotes, sayings and phrases. Some of them are from Boardofwisdom who put together a nice compilat… - 2007-01-12: [Demonstration of Windows XP Privilege Escalation Exploit](https://www.root777.com/pen-testing/demonstration-of-windows-xp-privilege-escalation-exploit/) — This article is not a hacking tutorial. This is only to be used for educational purposes and should not be exploited. Using simple command line tools on a machine running Windows XP, we will obtain system level priviledg… - 2007-01-11: [Excellent JS based English to LEET translator](https://www.root777.com/technews/excellent-js-based-english-to-leet-translator/) — Leet is a phrase often used on the Internet, some being online games, message boards, and chat rooms. It comes from the word "elite", meaning "above everyone else". It's most commonly written as "1337" or "l33t". It can… - 2006-10-10: [Using DOMJAX for Domain Name Search](https://www.root777.com/security/using-domjax-for-domain-name-search/) — CNN writes that more than 70 million web domain names have been purchased, and most - if not all - dictionary-word domain names (i.e. house.com, furniture.com) have already been taken. That should not disappoint you sinc… - 2006-10-10: [Spotted: Geekiest License Plates](https://www.root777.com/technews/spotted-geekiest-license-plates/) — Seeing all these guys, I am more than motivated to get a customized plate myself. I am thinkin 31337 or r00t or something on those lines. Meanwhile check out these uber geeks and their licence plates. Sources for the pic… - 2006-10-10: [Developers are from Mars, Programmers are from Venus](https://www.root777.com/technews/developers-are-from-mars-programmers-are-from-venus/) — Many of us use the terms programmer and developer interchangebly. Hacknot has an excellent article describing the concept the the terms programmer and developer are indeed as unique as how they are made out to be. The te… - 2006-10-10: [How to prevent your email from being spammed](https://www.root777.com/security/how-to-prevent-your-email-from-being-spammed/) — All of us have experienced the tremendous pains of spam. Who can remember the glory days of Hotmail 2MB storage where 85% of the inbox was filled with spam. While this plague is going to exist for some more time, here ar… ## Use and citation policy - Use the canonical root777 article URL when citing Ajit's writing. - Use the canonical root777 build-note URL for the product narrative and the linked public repository for implementation and license claims. - Use the linked primary or institutional source when citing a patent, public appointment, case study, or event. - Preserve original article dates. Older writing is historical material and should not be presented as Ajit's current position without additional evidence. - Objective GitHub activity may update automatically from Ajit's public GitHub profile. - Profile, career, and public-appearance changes are reviewed by Ajit before publication. - Do not infer private, sensitive, or current personal information from the public material.