IBM said it clearly in 1979: a computer can never be held accountable, therefore a computer must never make a management decision. In 2026, we give those computers production credentials, customer data, and the ability to execute at machine speed,without solving the accountability problem first. This is about what that means architecturally. Chatbots are wrong and humans decide what to do about…
Everyone talks about whether AI agents should reason about harm before acting. Nobody talks about what that reasoning actually costs. A full EU AI Act harm check per action runs 700-1,650 tokens minimum – more with a reasoning model, more when the agent needs lookups to establish context. Multiply by 100 actions in a medium task and the safety layer costs as much as the work itself. The…
Asimov’s Zeroth Law – ‘a robot may not harm humanity, or by inaction allow humanity to come to harm’ – is the law that turns robots into philosopher-kings. Asimov knew it was a transgression. The robot who derived it burned out. The novel ends with deep ambivalence about whether that reasoning was wisdom or hubris. This conversation picks up where the Three Laws left…
Chris built his Three Laws of Agentic AI as an Asimov riff – substituting EU AI Act harm for physical injury, stateful data for human obedience, and externalized memory for self-preservation. Then he asked Claude to find the holes. The conversation goes where these things go: the ‘through inaction’ clause is a Zeroth Law trap waiting to happen, ‘harm to data’ needs to…
In 1979, IBM warned that a computer must never make a management decision because it can never be held accountable. In 2026, I asked Claude whether an AI agent changes that calculus. The answer is no — and the argument is more rigorous than the slide. Accountability requires four things: persistent identity, capacity to suffer consequences, something like mens rea, and standing in a social order.…
Wendy Nather coined the Security Poverty Line in 2011. Fifteen years later, the field still thinks in binary — haves or have-nots, the cyber 1% or everyone else. That leaves the entire middle invisible: a Security Upper Middle Class that mostly just shows up to BSides and gets back to work, and a Security Valley of Death that’s the most populated tier in the industry and the least discussed.…
MUTUAL NON-DISCLOSURE AGREEMENT (Hereinafter referred to as the "Agreement," though "Trap" would be equally accurate) This Mutual Non-Disclosure Agreement ("Agreement") is entered into as of the date of the Recipient's signature ("Effective Date"), by and between PrimeHarbor Technologies, LLC, a Georgia limited liability company with its principal place of business somewhere in Georgia…
We have decades of experience with how we give an EA access to an executive’s life. And the entertainment industry is rife with stories of managers taking advantage of celebs by gaining access to their bank accounts and other aspects of their lives. All of this has made me realize that: GenAI Threat management is just Insider Threat management, but faster and at scale.
Early next year, AWS will launch one of the largest changes to its cloud product in decades. For the first time, they will launch a new partition , the European Sovereign Cloud (ESC), open to anyone. This article covers why you might want to use it, what are some of the threats to consider, mitgations, and alternatives to consider.
This will be the first re:Invent I’ve missed since 2015 (we don’t talk about 2020 - never happened - FAKE NEWS), but I’ve relocated to Portugal and, for various reasons, had to miss skip it this year. Normally, I do a pre:Invent post on Thanksgiving morning as a prep for what I want to ask about, but this year it’s a summary of both pre:Invent and re:Invent. pre:Invent also…
With the US Government acting in an erratic and hostile manner towards its traditional allies, it makes sense for companies not typically subject to US Jurisdiction to reconsider their threat models when using the big three cloud providers. All of them are US-based companies, and all three conduct a substantial amount of business with the US Government.
I’ve spoken a lot about Security Invariants , but all of them have been implemented using Organizational Policies. That’s great, but organizational policies don’t apply to the Organizational Management Account (aka “payer”). So how does one implement invariants in a payer account? AWS would tell you that you shouldn’t be giving anyone access to the payer…
I’ve finally settled on the wording for Farris’s Three Laws of Cloud Security Auto Remediation : A bot must never harm stateful data or allow stateful data to come to harm. A bot must act with utmost haste so functionality doesn’t become dependent on a misconfiguration. A bot must announce its existence and tell a carbon-based life form what it did and why. I think these reflect the…
In previous posts , I took AWS to task for not making the customer’s security Job Zero. This offended some sensibilities, so let me lay out my 95 13 Thesis against the current AWS Culture and how it is neither Customer-Obsessed , nor makes security job zero.
It’s once again pre:Invent, that magical season where AWS announces new features related to their legacy products (cloud) before they jump all-in on Generative AI magician gimmicks at re:Invent in Las Vegas. Once again, I will be in attendance at re:Invent, although I start to question my life choices every time I get off the plane in Vegas and am hit by the dry air, cigarette smoke, and insanely…
In order to profit effectively from a ransomware attack, a threat actor needs to have something to offer in return for payment. This blog post outlines a process to encrypt AWS resources and then revoke access to the secret material until the ransom is paid. Apparently, this post caused some consternation at AWS, and perhaps this technique is too effective to publish here. So, the original post…
In September 2024, I returned to Stockholm to give a talk at Sec-T . The Slides are here , and the YouTube Video is here . In the last year or so talking to organizations of all sizes, shapes, and security budgets, it’s become clear there is a deeper problem than just “developers don’t know how to not make a bucket public”. How we as an industry use the public cloud is…