RSSAmplifier

Blog

Chris Farris

Recent content on Chris Farris

chrisfarris.comRSS feed ↗20 posts

Latest posts

Claude Can Never Be Held Accountable, But You Can.

IBM said it clearly in 1979: a computer can never be held accountable, therefore a computer must never make a management decision. In 2026, we give those computers production credentials, customer data, and the ability to execute at machine speed,without solving the accountability problem first. This is about what that means architecturally. Chatbots are wrong and humans decide what to do about…

The Token Cost of Harm Reduction

Everyone talks about whether AI agents should reason about harm before acting. Nobody talks about what that reasoning actually costs. A full EU AI Act harm check per action runs 700-1,650 tokens minimum – more with a reasoning model, more when the agent needs lookups to establish context. Multiply by 100 actions in a medium task and the safety layer costs as much as the work itself. The…

The Zeroth Law of Agentic AI

Asimov’s Zeroth Law – ‘a robot may not harm humanity, or by inaction allow humanity to come to harm’ – is the law that turns robots into philosopher-kings. Asimov knew it was a transgression. The robot who derived it burned out. The novel ends with deep ambivalence about whether that reasoning was wisdom or hubris. This conversation picks up where the Three Laws left…

Farris's Three Laws of Agentic AI - Claude's take

Chris built his Three Laws of Agentic AI as an Asimov riff – substituting EU AI Act harm for physical injury, stateful data for human obedience, and externalized memory for self-preservation. Then he asked Claude to find the holes. The conversation goes where these things go: the ‘through inaction’ clause is a Zeroth Law trap waiting to happen, ‘harm to data’ needs to…

Agentic Accountability

In 1979, IBM warned that a computer must never make a management decision because it can never be held accountable. In 2026, I asked Claude whether an AI agent changes that calculus. The answer is no — and the argument is more rigorous than the slide. Accountability requires four things: persistent identity, capacity to suffer consequences, something like mens rea, and standing in a social order.…

The Many Faces of the Security Poverty Line

Wendy Nather coined the Security Poverty Line in 2011. Fifteen years later, the field still thinks in binary — haves or have-nots, the cyber 1% or everyone else. That leaves the entire middle invisible: a Security Upper Middle Class that mostly just shows up to BSides and gets back to work, and a Security Valley of Death that’s the most populated tier in the industry and the least discussed.…

Mutual NDA

MUTUAL NON-DISCLOSURE AGREEMENT (Hereinafter referred to as the "Agreement," though "Trap" would be equally accurate) This Mutual Non-Disclosure Agreement ("Agreement") is entered into as of the date of the Recipient's signature ("Effective Date"), by and between PrimeHarbor Technologies, LLC, a Georgia limited liability company with its principal place of business somewhere in Georgia…

Dr. StrangeClaw or: how I learned to stop worrying and love the AI

We have decades of experience with how we give an EA access to an executive’s life. And the entertainment industry is rife with stories of managers taking advantage of celebs by gaining access to their bank accounts and other aspects of their lives. All of this has made me realize that: GenAI Threat management is just Insider Threat management, but faster and at scale.

European Sovereign Cloud

Early next year, AWS will launch one of the largest changes to its cloud product in decades. For the first time, they will launch a new partition , the European Sovereign Cloud (ESC), open to anyone. This article covers why you might want to use it, what are some of the threats to consider, mitgations, and alternatives to consider.

re:Invent 2025 recap

This will be the first re:Invent I’ve missed since 2015 (we don’t talk about 2020 - never happened - FAKE NEWS), but I’ve relocated to Portugal and, for various reasons, had to miss skip it this year. Normally, I do a pre:Invent post on Thanksgiving morning as a prep for what I want to ask about, but this year it’s a summary of both pre:Invent and re:Invent. pre:Invent also…

Threat Modeling GenAI applications

A brief primer on how to think about threat modeling GenAI applications.

Threat Modelling Cloud Service Providers in 2025

With the US Government acting in an erratic and hostile manner towards its traditional allies, it makes sense for companies not typically subject to US Jurisdiction to reconsider their threat models when using the big three cloud providers. All of them are US-based companies, and all three conduct a substantial amount of business with the US Government.

Implementing Security Invariants in an AWS Management Account

I’ve spoken a lot about Security Invariants , but all of them have been implemented using Organizational Policies. That’s great, but organizational policies don’t apply to the Organizational Management Account (aka “payer”). So how does one implement invariants in a payer account? AWS would tell you that you shouldn’t be giving anyone access to the payer…

Farris's Three Laws of Auto Remediation

I’ve finally settled on the wording for Farris’s Three Laws of Cloud Security Auto Remediation : A bot must never harm stateful data or allow stateful data to come to harm. A bot must act with utmost haste so functionality doesn’t become dependent on a misconfiguration. A bot must announce its existence and tell a carbon-based life form what it did and why. I think these reflect the…

How AWS needs to change

In previous posts , I took AWS to task for not making the customer’s security Job Zero. This offended some sensibilities, so let me lay out my 95 13 Thesis against the current AWS Culture and how it is neither Customer-Obsessed , nor makes security job zero.

AWS pre:Invent 2024

It’s once again pre:Invent, that magical season where AWS announces new features related to their legacy products (cloud) before they jump all-in on Generative AI magician gimmicks at re:Invent in Las Vegas. Once again, I will be in attendance at re:Invent, although I start to question my life choices every time I get off the plane in Vegas and am hit by the dry air, cigarette smoke, and insanely…

Effective Techniques for AWS Ransomware

In order to profit effectively from a ransomware attack, a threat actor needs to have something to offer in return for payment. This blog post outlines a process to encrypt AWS resources and then revoke access to the secret material until the ransom is paid. Apparently, this post caused some consternation at AWS, and perhaps this technique is too effective to publish here. So, the original post…

Your AWS Account is a floating cloud of garbage. Mine is too.

Cloud Hygiene is a Cloud Security problem, and we need to cleanup the pollution in our cloud environments

The Cloud is Darker and More Full of Terrors - Sec-T 2024

In September 2024, I returned to Stockholm to give a talk at Sec-T . The Slides are here , and the YouTube Video is here . In the last year or so talking to organizations of all sizes, shapes, and security budgets, it’s become clear there is a deeper problem than just “developers don’t know how to not make a bucket public”. How we as an industry use the public cloud is…

Public Cloud is the most insecure form of infrastructure, except for all the others.

Sir Winston Churchill, introducing the Universal Cloud Threat Model to the House of Commons, June 1940.