Ryan Lackey
ryan@venona.com
Objective
An opportunity to apply computing, communications, and cryptographic technologies to real-world problems.
Skills
Principal competencies:
- Architecting, deploying, and operating mobile voice/data networks (GSM, UMTS) and developing and deploying premium mobile data and voice applications across
carrier networks
- Formation and management of start-up technical teams, including multinational distributed projects
- Payment systems design,
implementation, and deployment, including anti-fraud measures, regulatory
compliance, and integration with existing networks
- Entrepreneurship
in the Middle East, North Africa, and Central Asia
- Technical defense contracting,
including requirements development, winning contracts, and program management
- Conflict-zone operations, including
logistics, intelligence, communications, security, and finance
- Secure facilities/infrastructure design for high reliability, availability,
and maintainability
- Secure application architecture -- distribution for tamper-resistance,
replication for performance and reliability, multiparty administrative
control
- Designing agoric solutions to non-traditional problems
- Technical sales and sales engineering, particularly in the security
and Internet arenas
- Legal and technical structuring to comply with crypto
export/technology transfer, financial reporting, and taxation regulations
- Security review/penetration testing from open-source publications,
vendor inquiries, or system access
- Re-engineering existing systems and processes for high security, reliability, availability, and maintainability
- Extensive involvement with the next generation of open systems financial
technology, including electronic cash and automated markets
- Implementing reference versions of current research in cryptology and electronic cash
Knowledge and experience working with, implementing, and/or defeating:
Development and Systems Administration: UNIX (Linux (especially Ubuntu/Debian), FreeBSD/OpenBSD, Solaris),
PalmOS, Symbian (S60 and UIQ), iPhone SDK, Windows NT/2000/XP/2003/Vista, J2ME, JavaCard, Multos, Blackberry
Network Architecture and Engineering: TCP/IP networks using UNIX based
network appliances, Cisco, Juniper, and HP equipment, mobile telephony
networks (GSM MSC/BSC/BTS), satellite IP networks
Languages and Platforms: Java, Python, Postscript, Scheme, C, LISP,
Perl, Shell, TCL, Z80 asm, PHP, Facebook Platform, OpenSocial, Flash (Flex,
ActionScript), MySQL
Protocol Details: Electronic cash protocols, DNS, common EGPs and
IGPs, SSL, OpenPGP, SMTP, HTTP,
SSH1 and SSH2, x509, SNMP, NTP, DHCP, OTP, SET
Facilities: 3-phase power systems, large UPSes (battery and rotational),
power generation (petrol, diesel, turbine, solar, wind),
lasers and laser scanners, biometric ID products,
smartcard and magnetic stripe cards and card readers, satellite teleports
Devices: PC hardware, PC104, Unix workstation hardware (Sun,
Digital/Compaq, IBM RS/6000, HP), iButton, IBM 4758, Biometric ID
products (retina, iris, hand geometry,
fingerprint, voice), Compaq Atalla, key and combination locks,
commercial safes and vaults, secure timebases (cesium, gps, wwv,
maser), Wiegand-protocol security systems, wireless networking
(satellite, WaveLAN, 802.11, microwave, laser, FH SS HF, Ricochet,
CDPD), Palm and EPOC handhelds, RFID card systems, security
microcontrollers, Point of Sale systems, magnetic strips, VSAT remote
operations (Tachyon, Linkstar, Hughes, iDirect), VSAT hub operations
(iDirect, SCPC)
Major Algorithms: Radiosity/heat-transfer, SHA-1, MD5, Tiger,
DES (DES, DESX, 3DES), CAST5, Blowfish, RC2, RC4, RC5, AES submissions
(primarily MARS, RC6, Serpent, Twofish), RSA,
Elliptic Curve systems, RSA, DH, ElGamal, Schnorr, Brickell-McCurley
Financial Systems: premium SMS and mobile billing, ACH, ATM networks,
debit and credit card fraud
detection systems, e-gold, realtime trading systems, e-check, electronic
token systems, micropayment schemes, SET, gift/prepaid cards, loyalty card
systems, private wire systems
Experience and Education
-
Social Media Networks, Inc. (Winter 2007 - Present)
-
Worked with an experienced team of advertising industry veterans to
deploy new advertising technologies on social networks. Kept services
running with minimum downtime despite constant functionality upgrades and
a rapidly-evolving application. Improved server
infrastructure, adding application-specific load balancing, reliability
and monitoring improvements, and implemented MySQL sharding and replication
to support data-intensive realtime operations. Evaluated mobile and
mobile payments technologies, vendors, and strategies.
- Blue Iraq (Winter 2004 - Winter 2007)
-
Founded and led a communications company operating in conflict zones and
emerging markets, starting with the satellite and wireless market for
DoD and Contractor customers in Iraq. Bootstrapped operations from a handful
of initial clients and leased facilities. Arranged financing, vendor
relationships, and deployed redundant facilities. Negotiated with the DoD
and Iraqi Government, and expanded operations into other countries in the
Middle East and North Africa. Developed new technology for the satellite
industry, and expanded into the end-user consumer voice market.
- SSI Iraq (Summer 2004 - Winter 2004)
-
Responsible for developing new products, business relationships, and managing
major multi-site clients from initial contact throughout entire relationship,
in the challenging and rapidly changing reconstruction Iraq market. Rebranded
company, and developed a comprehensive marketing and technical plan to go
after the US DoD/western contractor market. Built substantial
relationships with DoD and Contractor customers. Transitioned to an outside
contractor in order to implement this plan with external capitalization.
- metacolo (Winter
2002 - Summer 2004)
- Founder of a distributed global network of technical and business
infrastructure, allowing Internet-based businesses to pick and choose from
16+ jurisdictions around the world for incorporation, financial transaction
processing, and secure servers with reliable network bandwidth. Negotiated
with local business partners, governments, and global technology providers,
managed technology development, and supervised and coordinated infrastructure
roll-out in multiple locations in parallel. Developed operations and marketing
plans, and directed ongoing sales, publicity, and operations. Also
directed consulting efforts, both leading contracts in RFID payments and
cryptographic applications, and managing other contracts for network
implementation, security audits, and application development.
- HavenCo (Summer 1999 -
Winter 2002)
- Founder and CTO of a global colocation company designed to provide the
best secure, reliable, high-performance colocation in a variety of
regulatorily interesting jurisdictions worldwide. Participated in
development of business concept, business plans, and budget from the founding
of the company through the present. Responsible for all
technical aspects of the company, and hired/managed development and
operations staff. Developed and implemented anti-DDoS high-speed global
network architecture, tamper-resistant server computer technology, and
a highly manageable, high density, low marginal administration server
architecture. Additionally, attracted and managed several major press
contacts, including the cover of Wired Magazine and an interview with Slashdot,
which helped raise HavenCo's visibility. Also negotiated aggressive
discount/payment/financing terms with several vendors despite limited
trading history and offshore incorporation.
- Systemics AI (Summer 1998 - Spring 1999)
-
Co-founded an Anguillan operation to develop electronic payment systems
for the Internet. Architecture and initial implementation of an
anonymous privacy-protecting electronic cash system, as well as development
of a schema of electronic cash systems and several novel protocols. Designed
and constructed a datacenter with redundant power, redundant cooling,
firewalling, and multi-site networking in a country where importation of
ordinary equipment is difficult to impossible.
- Venona Secure Solutions (1994 - 1998)
-
Conducted security reviews for a variety of clients, as well as
consulted with a range of startups in the areas of applications and
systems architecture for security as well as regulatory compliance.
Participated in several open source software efforts and attended
conferences to stay current on developments in security and open systems.
Major projects included developing design requirements, specification,
and implementation plans for a major electronic cash project still
underway. including facilities, network infrastructure, and some
of the application software.
- MIT Media Lab Wearable Computing Project (1996)
-
As an undergraduate research student, worked to implement advanced 3-d
imaging technology on a wearable platform. Developed system to
distribute high-computation parts of the application over a heterogeneous
farm of high-end UNIX workstations. Additionally, did general UNIX
systems administration and Linux hacking to adapt Linux to a
wearable embedded computing platform with video I/O and wireless
communications.
- Massachusetts Institute of Technology (Summer 1995 - Fall 1997)
-
Enrolled as an undergraduate/M.Eng. student from 1995 through 1997, beginning
with advanced standing due to prior work. Primarily took courses in advanced
mathematics, computer science, and cryptography. In-depth participation
in MIT Entrepreneur's Club and $50k New Venture competition. Additionally,
worked on developing user documentation and user technical support in
a volunteer computer service organization. Did not complete degree due
to financial pressure; left to move to Anguilla, British West Indies to
participate in a startup venture.
Certifications and Licenses
I am a Certified Information Systems Auditor (CISA), licensed USA and UAE driver with endorsements,
and hold a US passport. I have a DoD CAC and employment/residence visas
for several Middle Eastern countries. Please contact me directly regarding
active DoD security clearance questions.
Interests
I enjoy travel, photography, and contributing to open source software projects. I am comfortable
speaking and writing French, German, and Latin, and have a basic level of
spoken Arabic. I am interested in private space ventures, especially
inexpensive low-earth orbit launch using ram accelerators, and in free
trade zone economics and politics around the world.
I am a member of the American Civil Liberties Union (ACLU), Association
for Computing Machinery (ACM), Amnesty International (AI), Information
Systems Audit and Control Association (ISACA), Alpha Phi Omega service
fraternity (APO), Electronic Frontier Foundation (EFF), MIT Entrepreneurs
Club, International
Association for Cryptologic Research (IACR), European Internet Registry
(RIPE), North American Network Operators Group (NANOG), Middle East Network
Operators Group (MENOG), Internet
Engineering Task Force (IETF), American Motorcyclist Association (AMA),
and the Institute of Electrical and Electronics Engineers (IEEE).
Publications and Presentations
- (partial list)
- 2003-12-11: Bay Area FreeBSD Users Group (BAFUG): Networking with FreeBSD: Routers and more (with Tom Sparks)
- 2003-10-07: San Francisco OpenBSD Users Group (SFOBUG): Tamper-resistant security modules for secure applications
- 2003-08-01: Defcon XI: Behind the Remailers
- 2003-04-15: RSA Security Conference 2003: Dynamic Locations: Secure Mobile Services Discovery and Dynamic Group Membership
- 2002-10-20: ACM UIUC Reflections/Projections 2002: Practicalities of Internet Freedom
- 2002-08-01: Defcon X: Anonymous, Secure, Open Electronic Cash
- 2002-07-13: H2K2:
The Ultimate Co-location Site
- 2002-02-10: RSA Conference 2002: Jurisdictional Arbitrage for Risk Management
- 2002-02-10: RSA Conference 2002: P2P Taxonomy
- 2001-08-15: HAL 2001: In Defense of Privacy: Offshore Datahavens and Hosting Controversial Data
- 2001-07-13: Defcon 9: HavenCo: One Year Later
- 2001-04-02: Jupiter MediaMetrix Plug-In Europe: File Sharing: How the Music Industry Can Work With Users
- 2000-07-29: Defcon 8: Secure Server Hosting
- 2000-08-15: DNSCON 2000: How to Host Applications Securely
- 1999-02-15: Financial Cryptography 1999: Summary of FC99 conference for IEEE Cipher
- 1998-08-02: Digital Commerce Society of Boston Symposium on Electronic Payments: Working around the DigiCash ecash patent monopoly
References available upon request.