Ryan Lackey
ryan@venona.com

Objective

An opportunity to apply computing, communications, and cryptographic technologies to real-world problems.

Skills

Principal competencies:
Knowledge and experience working with, implementing, and/or defeating:

Development and Systems Administration: UNIX (Linux (especially Ubuntu/Debian), FreeBSD/OpenBSD, Solaris), PalmOS, Symbian (S60 and UIQ), iPhone SDK, Windows NT/2000/XP/2003/Vista, J2ME, JavaCard, Multos, Blackberry
Network Architecture and Engineering: TCP/IP networks using UNIX based network appliances, Cisco, Juniper, and HP equipment, mobile telephony networks (GSM MSC/BSC/BTS), satellite IP networks
Languages and Platforms: Java, Python, Postscript, Scheme, C, LISP, Perl, Shell, TCL, Z80 asm, PHP, Facebook Platform, OpenSocial, Flash (Flex, ActionScript), MySQL
Protocol Details: Electronic cash protocols, DNS, common EGPs and IGPs, SSL, OpenPGP, SMTP, HTTP, SSH1 and SSH2, x509, SNMP, NTP, DHCP, OTP, SET
Facilities: 3-phase power systems, large UPSes (battery and rotational), power generation (petrol, diesel, turbine, solar, wind), lasers and laser scanners, biometric ID products, smartcard and magnetic stripe cards and card readers, satellite teleports
Devices: PC hardware, PC104, Unix workstation hardware (Sun, Digital/Compaq, IBM RS/6000, HP), iButton, IBM 4758, Biometric ID products (retina, iris, hand geometry, fingerprint, voice), Compaq Atalla, key and combination locks, commercial safes and vaults, secure timebases (cesium, gps, wwv, maser), Wiegand-protocol security systems, wireless networking (satellite, WaveLAN, 802.11, microwave, laser, FH SS HF, Ricochet, CDPD), Palm and EPOC handhelds, RFID card systems, security microcontrollers, Point of Sale systems, magnetic strips, VSAT remote operations (Tachyon, Linkstar, Hughes, iDirect), VSAT hub operations (iDirect, SCPC)
Major Algorithms: Radiosity/heat-transfer, SHA-1, MD5, Tiger, DES (DES, DESX, 3DES), CAST5, Blowfish, RC2, RC4, RC5, AES submissions (primarily MARS, RC6, Serpent, Twofish), RSA, Elliptic Curve systems, RSA, DH, ElGamal, Schnorr, Brickell-McCurley
Financial Systems: premium SMS and mobile billing, ACH, ATM networks, debit and credit card fraud detection systems, e-gold, realtime trading systems, e-check, electronic token systems, micropayment schemes, SET, gift/prepaid cards, loyalty card systems, private wire systems

Experience and Education
Social Media Networks, Inc. (Winter 2007 - Present)
Worked with an experienced team of advertising industry veterans to deploy new advertising technologies on social networks. Kept services running with minimum downtime despite constant functionality upgrades and a rapidly-evolving application. Improved server infrastructure, adding application-specific load balancing, reliability and monitoring improvements, and implemented MySQL sharding and replication to support data-intensive realtime operations. Evaluated mobile and mobile payments technologies, vendors, and strategies.
Blue Iraq (Winter 2004 - Winter 2007)
Founded and led a communications company operating in conflict zones and emerging markets, starting with the satellite and wireless market for DoD and Contractor customers in Iraq. Bootstrapped operations from a handful of initial clients and leased facilities. Arranged financing, vendor relationships, and deployed redundant facilities. Negotiated with the DoD and Iraqi Government, and expanded operations into other countries in the Middle East and North Africa. Developed new technology for the satellite industry, and expanded into the end-user consumer voice market.
SSI Iraq (Summer 2004 - Winter 2004)
Responsible for developing new products, business relationships, and managing major multi-site clients from initial contact throughout entire relationship, in the challenging and rapidly changing reconstruction Iraq market. Rebranded company, and developed a comprehensive marketing and technical plan to go after the US DoD/western contractor market. Built substantial relationships with DoD and Contractor customers. Transitioned to an outside contractor in order to implement this plan with external capitalization.
metacolo (Winter 2002 - Summer 2004)
Founder of a distributed global network of technical and business infrastructure, allowing Internet-based businesses to pick and choose from 16+ jurisdictions around the world for incorporation, financial transaction processing, and secure servers with reliable network bandwidth. Negotiated with local business partners, governments, and global technology providers, managed technology development, and supervised and coordinated infrastructure roll-out in multiple locations in parallel. Developed operations and marketing plans, and directed ongoing sales, publicity, and operations. Also directed consulting efforts, both leading contracts in RFID payments and cryptographic applications, and managing other contracts for network implementation, security audits, and application development.
HavenCo (Summer 1999 - Winter 2002)
Founder and CTO of a global colocation company designed to provide the best secure, reliable, high-performance colocation in a variety of regulatorily interesting jurisdictions worldwide. Participated in development of business concept, business plans, and budget from the founding of the company through the present. Responsible for all technical aspects of the company, and hired/managed development and operations staff. Developed and implemented anti-DDoS high-speed global network architecture, tamper-resistant server computer technology, and a highly manageable, high density, low marginal administration server architecture. Additionally, attracted and managed several major press contacts, including the cover of Wired Magazine and an interview with Slashdot, which helped raise HavenCo's visibility. Also negotiated aggressive discount/payment/financing terms with several vendors despite limited trading history and offshore incorporation.
Systemics AI (Summer 1998 - Spring 1999)
Co-founded an Anguillan operation to develop electronic payment systems for the Internet. Architecture and initial implementation of an anonymous privacy-protecting electronic cash system, as well as development of a schema of electronic cash systems and several novel protocols. Designed and constructed a datacenter with redundant power, redundant cooling, firewalling, and multi-site networking in a country where importation of ordinary equipment is difficult to impossible.
Venona Secure Solutions (1994 - 1998)
Conducted security reviews for a variety of clients, as well as consulted with a range of startups in the areas of applications and systems architecture for security as well as regulatory compliance. Participated in several open source software efforts and attended conferences to stay current on developments in security and open systems. Major projects included developing design requirements, specification, and implementation plans for a major electronic cash project still underway. including facilities, network infrastructure, and some of the application software.
MIT Media Lab Wearable Computing Project (1996)
As an undergraduate research student, worked to implement advanced 3-d imaging technology on a wearable platform. Developed system to distribute high-computation parts of the application over a heterogeneous farm of high-end UNIX workstations. Additionally, did general UNIX systems administration and Linux hacking to adapt Linux to a wearable embedded computing platform with video I/O and wireless communications.
Massachusetts Institute of Technology (Summer 1995 - Fall 1997)
Enrolled as an undergraduate/M.Eng. student from 1995 through 1997, beginning with advanced standing due to prior work. Primarily took courses in advanced mathematics, computer science, and cryptography. In-depth participation in MIT Entrepreneur's Club and $50k New Venture competition. Additionally, worked on developing user documentation and user technical support in a volunteer computer service organization. Did not complete degree due to financial pressure; left to move to Anguilla, British West Indies to participate in a startup venture.
Certifications and Licenses

I am a Certified Information Systems Auditor (CISA), licensed USA and UAE driver with endorsements, and hold a US passport. I have a DoD CAC and employment/residence visas for several Middle Eastern countries. Please contact me directly regarding active DoD security clearance questions.

Interests

I enjoy travel, photography, and contributing to open source software projects. I am comfortable speaking and writing French, German, and Latin, and have a basic level of spoken Arabic. I am interested in private space ventures, especially inexpensive low-earth orbit launch using ram accelerators, and in free trade zone economics and politics around the world.

I am a member of the American Civil Liberties Union (ACLU), Association for Computing Machinery (ACM), Amnesty International (AI), Information Systems Audit and Control Association (ISACA), Alpha Phi Omega service fraternity (APO), Electronic Frontier Foundation (EFF), MIT Entrepreneurs Club, International Association for Cryptologic Research (IACR), European Internet Registry (RIPE), North American Network Operators Group (NANOG), Middle East Network Operators Group (MENOG), Internet Engineering Task Force (IETF), American Motorcyclist Association (AMA), and the Institute of Electrical and Electronics Engineers (IEEE).

Publications and Presentations
(partial list)
2003-12-11: Bay Area FreeBSD Users Group (BAFUG): Networking with FreeBSD: Routers and more (with Tom Sparks)
2003-10-07: San Francisco OpenBSD Users Group (SFOBUG): Tamper-resistant security modules for secure applications
2003-08-01: Defcon XI: Behind the Remailers
2003-04-15: RSA Security Conference 2003: Dynamic Locations: Secure Mobile Services Discovery and Dynamic Group Membership
2002-10-20: ACM UIUC Reflections/Projections 2002: Practicalities of Internet Freedom
2002-08-01: Defcon X: Anonymous, Secure, Open Electronic Cash
2002-07-13: H2K2: The Ultimate Co-location Site
2002-02-10: RSA Conference 2002: Jurisdictional Arbitrage for Risk Management
2002-02-10: RSA Conference 2002: P2P Taxonomy
2001-08-15: HAL 2001: In Defense of Privacy: Offshore Datahavens and Hosting Controversial Data
2001-07-13: Defcon 9: HavenCo: One Year Later
2001-04-02: Jupiter MediaMetrix Plug-In Europe: File Sharing: How the Music Industry Can Work With Users
2000-07-29: Defcon 8: Secure Server Hosting
2000-08-15: DNSCON 2000: How to Host Applications Securely
1999-02-15: Financial Cryptography 1999: Summary of FC99 conference for IEEE Cipher
1998-08-02: Digital Commerce Society of Boston Symposium on Electronic Payments: Working around the DigiCash ecash patent monopoly

References available upon request.