The Truth, Whole Truth and Nothing b/t Truth of Cybersec

Louis Deweaver (Cyber Security Consultant · MMA)

Blacks in Cyber Village @ DEF CON 33 · Day 1 · Blacks in Cyber Village

Overview

In "The Truth, Whole Truth and Nothing b/t Truth of Cybersec," Dr. Lewis Deweaver, a seasoned cybersecurity consultant and academic, delivers a provocative and unfiltered critique of the contemporary cybersecurity industry. Dr. Deweaver challenges prevalent narratives, exposing what he terms "snake oil" solutions from a vast majority of vendors, the ineffectiveness of many industry certifications, and the fundamental flaws in current security approaches that prioritize detection and response over genuine prevention. His talk serves as a stark wake-up call, urging cybersecurity professionals to question marketing hype, demand verifiable results, and reclaim control over their security posture.

Watch on YouTube

Visual summary for The Truth, Whole Truth and Nothing b/t Truth of Cybersec by Louis Deweaver
Visual summary for The Truth, Whole Truth and Nothing b/t Truth of Cybersec by Louis Deweaver

Key moments

  1. 0:00 Speaker's controversial introduction and talk overview
  2. 2:10 Bold claim: 98% of cyber vendors sell snake oil
  3. 3:30 Industry focus: detection/response over prevention
  4. 5:00 Why breaches make stock prices soar
  5. 6:15 Vendors' deceptive practices and product failures
  6. 6:45 Controversial take: cybersecurity certifications are useless
  7. 7:50 Personal commitment: Helping people find better jobs
  8. 8:20 Education's importance: personal story about degrees

The Truth, Whole Truth and Nothing b/t Truth of Cybersec

Speakers: Louis Deweaver, Cyber Security Consultant, MMA

Conference: Blacks in Cyber Village

YouTube: https://www.youtube.com/watch?v=mU9djJSqdBQ

Overview

In "The Truth, Whole Truth and Nothing b/t Truth of Cybersec," Dr. Lewis Deweaver, a seasoned cybersecurity consultant and academic, delivers a provocative and unfiltered critique of the contemporary cybersecurity industry. Dr. Deweaver challenges prevalent narratives, exposing what he terms "snake oil" solutions from a vast majority of vendors, the ineffectiveness of many industry certifications, and the fundamental flaws in current security approaches that prioritize detection and response over genuine prevention. His talk serves as a stark wake-up call, urging cybersecurity professionals to question marketing hype, demand verifiable results, and reclaim control over their security posture.

Dr. Deweaver's presentation is particularly significant because it confronts uncomfortable realities often obscured by aggressive marketing and entrenched industry practices. He meticulously details how even leading cybersecurity vendors, trusted by major corporations, are themselves vulnerable to basic attacks, with their own credentials frequently compromised and available on the dark web. The talk resonates deeply by advocating for a return to foundational cybersecurity principles, emphasizing practical skills, robust policy enforcement, and a skeptical approach to vendor claims, thereby empowering individuals and organizations to build more resilient defenses.

The core message of this talk is a challenge to the status quo: the cybersecurity industry, fueled by private equity and a "breach economy," has become a self-serving ecosystem where prevention is neglected in favor of profitable remediation. Dr. Deweaver's insights are crucial for anyone navigating the complex landscape of cybersecurity tools, training, and career paths, offering a refreshing, no-nonsense perspective on what truly constitutes effective security in an era of pervasive threats and misleading information.

Background

▶ Watch: Speaker's controversial introduction and talk overview (0:00)

The cybersecurity landscape, as Dr. Deweaver describes it, is a chaotic and overcrowded market, particularly evident at major conferences like Black Hat, which he notes are "flooded with vendors." A critical observation is the massive influx of private equity (PE) funds into the sector over the last decade. However, this investment is disproportionately directed towards detection and response solutions, with a noticeable lack of funding for prevention. This imbalance, he argues, creates a perverse incentive structure where breaches, rather than their absence, drive industry growth and profitability.

The market is dominated by a few major players—Microsoft, Palo Alto, CrowdStrike, and Fortinet—who collectively own over 50% of the industry. This concentration, Deweaver contends, stifles innovation and allows these giants to dictate market trends, often to the detriment of effective security. He highlights the irony that many of these top-tier companies, despite selling "the best cyber security vendors that this industry has to offer," have themselves experienced significant breaches, including Microsoft and CrowdStrike. He cites examples like Equifax and Marriott, whose stock prices soared post-breach, illustrating a "buy the breach" phenomenon where financial markets reward, rather than punish, companies after major security incidents. This demonstrates a deep disconnect between perceived security and actual resilience.

Dr. Deweaver also strongly criticizes the prevailing emphasis on certifications within the industry. Drawing from his own experience of being denied a teaching position despite outperforming other candidates, simply for lacking a degree at the time, he argues that certifications are often "useless" and do not reflect practical ability. He points out that hackers, who routinely compromise systems, rarely possess these credentials, underscoring the disconnect between theoretical knowledge (tested by multiple-choice exams) and real-world skills. He advocates for a focus on hands-on experience, lab work, and continuous learning, urging professionals to prioritize genuine capability over paper qualifications.

Furthermore, he challenges the "us versus them" narrative often propagated by vendors, where the industry frames itself as fighting external threats. Instead, Dr. Deweaver asserts, "it's them against us," implying that many vulnerabilities are introduced or exacerbated by the very vendors purporting to offer solutions. He contends that compromising a single vendor can now grant access to an entire company, a far cry from the "back in the day" approach of hacking "one computer after the next." This shift highlights the increased supply chain risk inherent in relying heavily on third-party security products.

Key Findings

▶ Watch: Industry focus: detection/response over prevention (3:30)

Dr. Deweaver presents several stark and often controversial findings that challenge conventional wisdom in the cybersecurity industry:

  • Pervasive "Snake Oil": A staggering 98% of cybersecurity vendors, particularly those exhibiting at major conferences like Black Hat, are selling "snake oil." Their products, he claims, do not work as advertised, and their demonstrations are often misleading, using "perfect" data that doesn't reflect real-world performance.
  • Certifications are Useless: While not entirely dismissing education, Dr. Deweaver asserts that many industry certifications (e.g., CISSP) are "useless" as a measure of practical skill. He points out that hackers do not possess these credentials, yet they are highly effective. He advises against pursuing jobs that demand certifications without valuing practical experience, and champions hands-on learning over rote memorization for exams.
  • Top Vendors Are Compromised: Many of the industry's leading cybersecurity vendors, including "Falcon" (implied CrowdStrike), Cisco, Microsoft, and Fortinet, have significant internal security vulnerabilities. Their own systems and customer data are frequently compromised, with credentials found in stealer logs on the dark web. For example, he cites "Falcon" with over 1,000 stealer logs and 935 employee leaks, Cisco.com having stealer logs directly on its login server, and Microsoft with over 5,000 stealer logs affecting Office and admin accounts. Fortinet.com customers' SSO credentials are also found on the dark web.
  • Gardner's Magic Quadrant is Corrupt: The widely referenced Gardner's Magic Quadrant is dismissed as "useless" and "bought and paid for years ago." Dr. Deweaver alleges that companies must pay to achieve higher rankings, rendering its recommendations biased and untrustworthy.
  • Prevention Doesn't Pay, Breaches Do: The prevailing business model in cybersecurity is structured to profit from breaches, not their prevention. Vendors make money from detection and response and subsequent remediation, creating a financial incentive for vulnerabilities to persist rather than be eliminated.
  • Ineffective Phishing Training: Current phishing training methods are deemed "useless" and counterproductive. By allowing phishing emails to reach employee inboxes for testing, companies open themselves to risk and demoralize employees. The focus should instead be on preventing these emails from ever reaching the inbox.
  • AI in Cybersecurity is Dangerous and Unregulated: Dr. Deweaver views the rapid advancement of AI in cybersecurity as dangerous and unregulated. He states that bad actors are already far ahead in using AI, and attempts to "fight AI with AI" are futile because the defensive AI can easily be compromised and turned against its users.
  • Trust is a Vulnerability: The concept of inherent trust within networks is fundamentally flawed. Dr. Deweaver, whose dissertation was on Zero Trust, advocates for its widespread adoption, arguing that trust is a human emotion that has no place in secure network design.
  • 90% of Cybersecurity is Policy: Effective cybersecurity, according to Dr. Deweaver, is 90% about policy enforcement. Strong, well-enforced policies, coupled with the elimination of "weakest links" (e.g., accessing company files from personal, potentially infected, devices), are far more impactful than expensive tools.

Technical Deep Dive

▶ Watch: Vendors' deceptive practices and product failures (6:15)

Dr. Deweaver's technical deep dive focuses on exposing the systemic vulnerabilities introduced by cybersecurity vendors and advocating for a return to fundamental security principles. A central theme is the widespread compromise of credentials via stealer log malware. He asserts that this malware, whose sole purpose is to exfiltrate credentials, is so prevalent that "probably 90% of the population is" infected. This is particularly dangerous when employees access company resources from personal, compromised machines, effectively bypassing other security layers.

He provides concrete examples of major vendor vulnerabilities:

  • "Falcon" (widely understood to be CrowdStrike): Cited for having over 1,000 stealer logs and 935 employee "provincial leaks," with 34 mentions on the dark web. A critical concern is their demand for kernel-level access, which grants them "complete access to your computer... down to your processor." Deweaver warns that such deep access should prompt immediate removal of the solution.
  • Cisco: Cisco.com, the company's own portal, reportedly has stealer logs on its server, meaning user credentials are being "sold on the Russian market" every time someone logs in. This is attributed to "stealthy" malware that evades detection.
  • Microsoft: Microsoft is implicated with "over 5,000+" stealer logs affecting Office, Microsoft accounts, and admin accounts. This means credentials for a vast number of users are likely stolen. He points out that if MFA is in place but legacy authentication is not disabled, attackers can often bypass MFA by logging in via outlook.office.microsoft.com.
  • Fortinet: Their website, Fortinet.com, is said to expose SSO (Single Sign-On) credentials for all their customers on the dark web, meaning internal network access linked through SSO is compromised.

Dr. Deweaver stresses that the industry's focus on detection and response is a misdirection. True prevention, he argues, involves monitoring true East-West traffic (internal network communication), packets, and net flows. He claims many vendors fail to adequately monitor this critical internal traffic because breaches, not prevention, are their revenue driver.

Regarding email security, he criticizes phishing training as ineffective. Instead, he advocates for solutions that prevent phishing emails from reaching the inbox in the first place. This proactive approach, he suggests, is often cheaper and more effective than reactive training and punitive measures against employees.

He introduces Shodan as a powerful tool for discovering exposed systems, recounting finding 38 ransomware-infected machines with screenshots openly available online. For foundational email security, he recommends MX Toolbox to verify MX records and implement a DMARC policy, which can prevent domain spoofing and phishing. These basic configurations are often overlooked but provide significant protection.

Policy, according to Deweaver, constitutes "90% of cyber security." He emphasizes the importance of making and enforcing policies, such as prohibiting access to company files from personal, potentially compromised computers. This directly addresses the threat of stealer logs, as removing this attack vector eliminates a major source of credential theft.

Finally, he discusses Lumu as an example of a "good" vendor. Lumu, created by ex-military and ex-vendor personnel, monitors only metadata and net flows across the network, including switches. It's non-intrusive, doesn't slow down machines, and maps observed traffic patterns against the MITRE ATT&CK framework to identify adversarial behaviors. Crucially, Lumu involves human confirmation before blocking actions, preventing false positives, especially for actions like file encryption, even when performed with legitimate but compromised credentials. This aligns with his advocacy for Zero Trust, which he describes as removing inherent trust from network interactions, a concept explored in his doctoral dissertation. He concludes by cautioning against the current state of AI in cybersecurity, deeming it unregulated and dangerous, with bad actors already having a significant advantage.

Demo / Proof of Concept

▶ Watch: Controversial take: cybersecurity certifications are useless (6:45)

While Dr. Deweaver's talk did not include a live, on-stage technical demonstration in the traditional sense, he effectively presented compelling "proofs of concept" through his personal research methods and direct confrontations with vendors. He vividly describes his approach to validating his claims, which serves as an implicit demonstration of how these vulnerabilities can be uncovered.

His methods include:

  • Vendor Booth Confrontations: He recounts deliberately visiting vendor booths at conferences and challenging their representatives with evidence of their own company's compromised security. For instance, he would ask if they were using their own product, given evidence of their stealer logs, forcing them into a no-win situation.
  • Dark Web Intelligence: Dr. Deweaver extensively uses dark web searches to identify compromised credentials and stealer logs associated with major cybersecurity companies and even individuals. He dramatically illustrates this by revealing an FBI agent's compromised personal credentials, obtained via her .gov email address, during her own cybersecurity talk. This highlights the pervasive nature of credential theft and the lack of awareness even among security professionals.
  • Open-Source Intelligence (OSINT) Tools: He mentions using tools like Shodan to quickly identify vulnerable systems globally, providing an example of finding 38 ransomware-infected machines with their screens publicly exposed on the internet. He also recommends MX Toolbox for basic domain security checks, such as verifying MX records and DMARC policies, which are critical for preventing email spoofing and phishing.
  • Practical Hacking Background: Dr. Deweaver shares personal anecdotes of his early "hacking" days, from photocopying money and manipulating vending machine codes to using GitHub for code manipulation and leveraging YouTube videos to learn various hacking tools. This background underscores his hands-on, practical understanding of how systems are exploited, lending credibility to his critique of theoretical-only security approaches.

These examples, woven throughout his presentation, serve as powerful, real-world illustrations of the industry's failings and the accessibility of information for uncovering vulnerabilities, effectively acting as a continuous, impactful "proof of concept" for his arguments.

Defensive Implications

▶ Watch: Education's importance: personal story about degrees (8:20)

The defensive implications arising from Dr. Deweaver's talk are profound, urging a fundamental shift in how organizations and individuals approach cybersecurity:

  • Rigorous Vendor Vetting: Organizations must drastically improve their vendor vetting processes. This goes beyond marketing brochures and Gartner reports. Demand Proof of Concepts (POCs) performed within your actual environment, not in a controlled vendor lab. Actively investigate a vendor's own security posture, including searching for their credentials in stealer logs or on the dark web, as Dr. Deweaver does. If a vendor requires kernel-level access, understand the profound risks and consider alternative solutions.
  • Prioritize Prevention Over Reaction: Shift budget and focus from solely detection and response to robust prevention. This means investing in foundational security controls that stop attacks before they occur, rather than just cleaning up after a breach.
  • Back to Basics Network Hygiene: Re-emphasize fundamental network monitoring. Ensure comprehensive visibility into East-West traffic, analyze packets and net flows. Many current vendor solutions fail to provide this critical internal visibility, leaving organizations blind to lateral movement.
  • Strengthen Policy and Enforcement: Recognize that "90% of cyber security is policy." Develop clear, enforceable security policies. Crucially, eliminate "weakest links" by prohibiting access to company data or systems from personal devices, which are highly susceptible to stealer log malware. Regularly review and update these policies.
  • Rethink Cybersecurity Training and Education: Organizations should invest in practical, hands-on training for their security teams, paying for attendance at conferences like Blacks in Cyber, bootcamps, and virtual labs. De-emphasize certifications as the sole measure of competence and prioritize real-world skills. For employees, replace ineffective phishing training with proactive solutions that prevent malicious emails from ever reaching the inbox.
  • Embrace Zero Trust Architecture: Move away from implicit trust within networks. Implement Zero Trust principles where every access request, regardless of origin, is authenticated, authorized, and continuously validated. This removes the inherent vulnerability of trusting users or devices simply because they are inside the network perimeter.
  • Be Skeptical of AI Solutions: Approach AI-driven security solutions with extreme caution. Given the unregulated nature of AI and the head start bad actors have, relying solely on AI to fight AI is a dangerous proposition. Focus on understanding the underlying mechanisms and potential for compromise.
  • Empower Security Professionals: CSOs and leadership must empower their teams, listen to their concerns, and provide the resources needed for continuous learning and skill development. Failure to do so leads to demoralization, skill stagnation, and ultimately, increased vulnerability.
  • Utilize Free and Open-Source Tools: Encourage the use of powerful, free tools like Shodan for external threat intelligence, MX Toolbox for domain security validation, and community resources like GitHub for code and vulnerable virtual machines for practical skill development.

Key Takeaways

  • Vendor Skepticism is Critical: A vast majority of cybersecurity vendors sell ineffective "snake oil," with even top-tier companies demonstrating severe internal security flaws and compromised credentials (e.g., stealer logs on Cisco.com, Microsoft, Fortinet).
  • Practical Skills Outweigh Certifications: Industry certifications are often poor indicators of real-world ability; hands-on experience, lab work, and continuous learning are far more valuable for effective cybersecurity.
  • Prevention, Not Just Detection, is Paramount: The industry's profit model incentivizes detection and response over true prevention. Organizations must shift focus to proactive measures, including robust network monitoring (East-West traffic) and preventing threats like phishing emails from reaching end-users.
  • Policy is Your Strongest Defense: Effective cybersecurity is 90% about strong, enforced policies, such as eliminating access to company data from personal, potentially compromised devices, which directly combats widespread credential theft.
  • Embrace Zero Trust and Reject Implicit Trust: Trust is a vulnerability. Implementing a Zero Trust architecture, where no entity is inherently trusted, is essential for modern network security.
  • Empower Your Team and Invest in Training: Organizations must actively support their cybersecurity professionals with paid training, conferences, and mentorship, as their expertise is the most critical defense, not vendor tools alone.

About the Speaker(s)

Dr. Lewis Deweaver is a highly experienced and often controversial figure in the cybersecurity industry, serving as a Cyber Security Consultant with MMA. With over 20 years of experience, a Doctorate in Computer Science, and multiple degrees in cybersecurity, Dr. Deweaver is known for his critical and unfiltered perspective on security certifications, tools, and vendor claims. He identifies himself as a husband, father, brother, keynote speaker, ethical hacker, and veteran, having "done everything" in the field. Dr. Deweaver is deeply committed to empowering cybersecurity professionals, actively helping over 200 individuals find new jobs and offering free training and mentorship to those seeking to advance their skills and careers, particularly challenging the notion that certifications are essential. His passion stems from a desire to expose uncomfortable truths and foster a more informed and capable cybersecurity community.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Deweaver is delivering a practitioner gut-check talk to an audience that genuinely needs it — Blacks in Cyber is a community-building and career-development space, not DEF CON main stage. In that lane, a blunt, experienced voice calling out vendor theater, stealer-log exposure on vendor infrastructure, and the certification treadmill has real value. The problem is the talk never fully commits to its own evidence: the specific claims (1,000+ stealer logs on Falcon, Cisco login server exposure, Fortinet SSO on dark web) are serious allegations that deserved sourcing, methodology, and reproducible steps — and without that scaffolding, the talk reads more like a compelling sermon than a…

Heather Calloway (CISO) — SOLID

Deweaver is firing at real targets — vendor capture, the breach economy, certification theater — and the audience at Blacks in Cyber is exactly right for this message. But the talk operates almost entirely at the level of grievance and observation, without giving security leaders the decision framework they need to actually act on what he's describing.

→ Top-rated talks at Blacks in Cyber Village @ DEF CON 33

All talks from Blacks in Cyber Village @ DEF CON 33