惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

WeLiveSecurity

The quest for greater tech independence Why geopolitical turmoil is a gift for scammers, and how to stay safe FrostyNeighbor: Fresh mischief and digital shenanigans Eyes wide open: How to mitigate the security and privacy risks of smart glasses Fake call logs, real payments: How CallPhantom tricks Android users Fixing trivial passwords is as easy as 123456 A rigged game: ScarCruft compromises gaming platform in a supply-chain attack This month in security with Tony Anscombe – April 2026 edition The calm before the ransom: What you see is not all there is GopherWhisper: A burrow full of malware New NGate variant hides in a trojanized NFC payment app Ransomware’s back office: What the ransom note won’t say Why that next data breach alert could be a trap Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Why LinkedIn is a hunting ground for threat actors – and how to protect yourself Is it time for internet services to adopt identity verification? Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition A brush with online fraud: What are brushing scams and how do I stay safe? Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing Recruitment red flags: Can you spot a spy posing as a job seeker? How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware Minecraft mods: When ‘hacking’ your game becomes a security risk IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough The case for cybersecurity: Why successful businesses are built on protection Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE Cybersecurity Awareness Month 2025: Knowledge is power This month in security with Tony Anscombe – September 2025 edition
In memoriam: David Harley
2025-11-07 · via WeLiveSecurity

Digital Security

Former colleagues and friends remember the cybersecurity researcher, author, and mentor whose work bridged the human and technical sides of security

07 Nov 2025  •  , 7 min. read

In memoriam: David Harley

The cybersecurity community lost one of its luminaries with the passing of David Harley last week, at the age of 76.

Despite being a self-described late entrant to IT, David went on to forge a long and distinguished career in cybersecurity that stretched from the early days of computer viruses until the age of modern ransomware and included a tenure as ESET Senior Research Fellow until his retirement in 2018.

With an academic background in modern languages, social sciences, and computer science, David understood early that the most dangerous vulnerabilities weren’t always technical, but human. This lesson would echo through much of his later work, particularly in his writings about the psychology of cybercrime. His expertise ranged widely, however, and also encompassed analysis of malware trends and engagement with the standards of antimalware product testing.

A prolific author, editor, and conference speaker, David viewed writing and public speaking as an extension of research and an opportunity to connect with peers and, indeed, anyone else committed to making the internet a safer place for everyone. WeLiveSecurity is proud to preserve part of David's vast body of written work; meanwhile, the various books and scholarly articles that he authored, co-authored, and edited are listed here.

If you ever had the privilege of learning from David, consider paying it forward. David himself was proud to be part of the cybersecurity community and viewed cybersecurity as a public good. (He was also an accomplished singer, songwriter, and guitarist. Listen for yourself here.)

Former colleagues, meanwhile, remember David as a fountain of knowledge and a meticulous wordsmith who left a lasting mark on the field and all those who worked with him.

Says ESET Vice President of Government Affairs Andrew Lee:

"In 1999 I met a man who would become a friend, a colleague, and a collaborator on many projects over the years.

At the time, I was working in a government office, establishing the first fully implemented security and antivirus platform throughout the agency. There was a message board, the alt.comp.virus newsgroup (kind of like a very early social media for geeks), where others involved in the antivirus sphere would discuss. On that forum, at the time working for the NHS as its computer security head, was a man named David Harley. On that board, many conversations would take place, and David would often give his input, which was relevant, informed, and always worth reading. He, among others, helped me tremendously in providing information and advice that helped me do my job.

At a conference called ‘Infosec’ (sadly long defunct), I finally met David, in late 1999, and we hit it off immediately, sharing many more interests than just security. During that first meeting, over pizza, I discussed an idea that I was working on – a paper on Linux malware. I knew David was a good writer, so I asked him for some tips. I have always been good at having ideas, but with severe ADHD (undiagnosed at the time), I was simply unable to get them onto the page in a logical way, I speak far better than I write. David almost immediately offered to help me write the paper, and we eventually presented it at the EICAR conference in 2001, in Copenhagen. I did the presenting, as it was not David's strength at the time. We complemented each other well. We would bounce ideas around, he would send a draft, I would add my contributions, then he would edit it into something usable. Then I'd present our work.

Eventually, I left government and joined ESET – and it's true to say that without David helping me with those early conference papers, I might never have had the chance to meet the ESET folks. David and I kept in touch, regularly meeting up at industry conferences, and eventually, it was a huge pleasure to be able to hire him into ESET, where once again, we worked on many white papers and presentations together. He also wrote books on security, one of which I had the pleasure of contributing to.

We also bonded over music. David was, like me, a huge fan of traditional British folk music, and was himself a very accomplished guitarist, singer, and songwriter. During the pandemic, I helped him clean up, remix, and master some of his earlier work, and it's a shame that more people did not discover his songs, as they are beautiful, well written, and often deeply moving.

David was a quiet man, he was gentle, kind, but also funny and clever. His work was important, and while the industry has moved on, much of the advice he wrote is still relevant and vital today. His reserved nature sometimes hid from others the deep intellect and insight that David held.

In some small part, I hope our work together helped him too; as is often said, two heads are better than one. I will always remember when he met his true 'second head', Jude, in Berlin, and their lasting bond, friendship, and love was something that was obvious to those who met them.

Above all, David was my friend. I will miss him greatly.

My love to Jude, David's daughter, and all who knew and loved him.

Rest in peace my friend.”

Says ESET Research Fellow Bruce P. Burrell:

“I'm not quite sure when I first met David – probably though VIRUS-L/comp.virus in the late 80s or early 90s. I'm not certain about when I met him in person, either, but I'm pretty sure it was in 1995, at the Virus Bulletin conference in Boston. Or maybe in San Francisco at VB 97 (the conference report mentions him, so I know he was there). Whenever it was, by that time it was like meeting an old friend.

Probably a bit before our first face-to-face meeting, the alt.comp.virus newsgroup came into existence, and I had many interactions with David there. Eventually, it became clear that an FAQ was needed for the newsgroup, and a triumvirate of David, George Wenzel, and I started putting one together. More accurately, David did almost all of the putting, while George and I contributed a bit or two; I also did a wee bit of wordsmithing. Emphasis on ‘wee’: David's writing skills were superlative, so it was mostly just sanity-checking.

At around this time also, David and I were involved with wordsmithing the AVIEN Malware Defense Guide for the Enterprise – indeed, while a group effort, I suspect that he wrote most of that, too.

Note also that, while the gentlest and kindest of people, he had a wickedly clever wit – just browse the titles and headers of his writings.

I overnighted at his flat in London in the summer of 1998, and later that year, at VB 98, I met the regular occupant of that room – his adorable eight-to-ten-year-old(?) daughter Katie. I believe that she followed her father into computer security; whether or not she's still in that field, he had every reason to be proud of her.

Over the years, we'd been in regular contact – but when I joined ESET, we soon formed another trio of wordsmiths – David, Nick FitzGerald, and myself. It was a great pleasure – and learning experience – to work with these two on a daily basis, instead of the occasional one-off emails and the all-too-rare conference or ‘I just happen to be in town’ meetings. I was fortunate to be able to work with him closely for several years, until his retirement. Not an early retirement, but certainly earlier than I'd have liked it to be!

Post-retirement, we stayed in touch, but in retrospect, not nearly enough. I shall miss you tremendously.”

Says ESET Senior Research Fellow Righard Zwienenberg:

“I am truly saddened to hear this news. Having known David for over three decades, I was fortunate to share many memorable moments with him, on stage during presentations and through our mutual love of music. We had some nice sessions together with David on guitar and myself on drums. He will be deeply missed by me.

David was a 'walking Wikipedia'. Whenever you sent him an abstract or a full paper to edit, he always returned it with hints to more material, references to supporting material, etc. Many people know that for all his brilliance as a writer and editor, he was ‘clumsy’ as a presenter. Often losing track, having his notes in the wrong order so he was talking about slides yet to come but not the current one, laughing about his own mistakes ... Everybody who really knew him will remember, ‘Oh dear …’, which was his typical way of apologizing on stage while presenting and yet again losing track. Yet, due to his vast knowledge on the topic he was presenting or ready-when-needed history when the Q&A time was there, he always attracted a large crowd …

May his memory live on through the music and moments we shared.”

We offer our heartfelt condolences to David's family and friends.

Here’s where you can learn more about the life and work of David Harley:


Let us keep you
up to date

Sign up for our newsletters