More posts
All →
"Monitoring the Situation" - The Internet of Birbs
Two pale-blue speckled eggs on the sunroom bookshelf turned into three cameras, an Unraid NAS, two AI models, and a journal that writes itself every morning. None of it had to be useful — it just had to be possible. Because joy.
AI isn't the problem — asymmetry is
AI isn't the security problem — it widens the asymmetry between vulnerability discovery and remediation, putting attack capability in many more hands.
Mythos feels a lot like Snowden
Mythos is to vulnerability awareness what Snowden was to surveillance: the moment the zeitgeist finally caught up to what insiders already knew.
Security-focussed test/fix is basically “sparkling QA”
A short reaction to Firefox's claim that AI-found defects are finite: security-focused test-and-fix is basically QA wearing a fancier hat.
Spicy Takes from my Aikido Security Podcast
Nine takes from my RSAC conversation with Mackenzie Jackson on Aikido's Secure Disclosure podcast — on bug bounty, AI slop, hack-back, vibe coding, and why the internet still working is a minor miracle.
We don't have a slop problem.
The real security problem isn't AI slop — it's that vulnerability research and the broader industry can't prioritize what actually matters in the noise.
Build the tooling. Don't be the tooling.
The AI move in vulnerability research isn't prompting from scratch every run — it's using AI to build deterministic scanners, fuzzers, and analysis pipelines.
Offense Scales with Compute. Defense Scales with Committees.
Why AI is widening the attacker-defender gap faster than anything we've built to close it — and what that actually means for the next decade of security.
Why Security Teams Gaslight Hackers: Disclosure Reality
The cybersecurity industry has a dirty secret: security teams are systematically dismissing legitimate vulnerability reports from ethical hackers. In a recent episode of Hackers on the
The Compliance Reckoning
AI makes security verification cheap, putting two decades of checkbox compliance, paper pentests, and audit theater under sudden economic pressure.
Bug Bounties in the Age of AI
As AI accelerates the offense-defense asymmetry, bug bounties and vulnerability disclosure remain essential. Casey Ellis on the future of bug bounties, the evolving threat landscape, and how disclose.io and the SRLDF protect the researchers keeping us safe.
The FCC Just Banned Every Foreign-Made Router
The FCC added every foreign-made consumer router to the Covered List — a March 2026 supply-chain action that goes far beyond previous adversary-nation bans.