Consciousness vs AI I’m reading Michael Pollan’s new book, A World Appears . There’s some discussion of consciousness and AI in the book, specifically Consciousness in Artificial Intelligence: Insights from the Science of Consciousness which famously states: Our analysis suggests that no current AI systems are conscious, but also suggests that there are no obvious technical barriers to building AI…
AI and Productivity Josh Collinsworth’s Productivity Cal Newport Why Hasn’t AI Made Work Easier? Avoiding Digital Productivity Traps These pieces articulate something about AI that’s bothered me and I’ve failed to convey. Reading Deep Work was a huge turning point in my mental health journey. I started cutting back my working hours, and focusing on what mattered. Oliver Burkeman’s Four Thousand…
Luddites, Gone Wild I am routinely called a luddite for being critical of AI. I’ve spent nearly 30 years in an industry where I’ve embraced and championed change and progress against the grinding gears of corporate bureaucracy. AI is different. It’s not a David vs Goliath moment. It’s the reverse. The goal of AI is replace the entire labor force, rendering the majority of humanity “useless.” Even…
Own Your Differentiators I spent the majotiry of my career working at companies that owned their infrastructure. Those companies had small OpEx (Operational Expenses) compared to their competitors who were heavily invested in Cloud Infarstructure. If you look at the big players, most of them own their infrastructure. Amazon’s AWS provides their platform, as well as most of the compute for the…
AI Vulnerability Hunting I came across these articles today and thought they paint an interesting picture when you consider them all together. Context and Interesting Articles Mythos Finds 271 Vulnerabilities for Mozilla Mythos Finds a curl Vulnerability You Need AI that Reduces Maintenance Costs Reading these articles made me think of Mike Rowe’s “Safety Third” video. There are a lot of…
In which he hurts the machine’s feelings First, I want to link to a few great write-ups. Your Container is not Your Sandbox - Excellent summarization of MicroVM vs containers Agentic Coding is a Trap - Argument that AI is not like the tech before it because it decreases operator capacity Losing Skills - A corrollary to the real world deskilling of automatic lane stay assist in driving The Chinese…
Don’t be a downer, bro. I am critical of AI. I don’t really like it. A lot of why, is it’s always felt “off.” There was something I couldn’t express about the proponents, the culture, the history, the way I felt it could be abused. It was a gut reaction. Most of the time, those gut instincts are right. An Economy of Empathy Mario Munoz delivers an absolute must-see talk at North Bay PyCon. This…
More BSidesCharm Day two of BSidesCharm also had a lot of great talks! Breaking the Lethal Trifecta I’m looking at agentic workflows and security in my day job, so I attended a lot of AI security talks. I want to highlight the main theme of the “Breaking the Lethal Trifecta” talk, which is something I have said many times: Prompt Injections are not preventable! Andrew Bullen, head of Strip’s AI…
BSidesCharm Today was Day One of BSidesCharm , a small, grass roots security conference here in Baltimore City, aka, Charm City. This my first time back in the Baltimore Security Scene since late 2011 and it has grown. Some of the folks who used to attend CharmSec meetups are involved in the conference, so it was so good to see them and be welcomed back to the fold. The conference is definitely…
You, but better May contain things that are mildly useful in self-improvement and mental health if you tilt your head and squint. Begin Again.. The past two days got away from me and I missed adding a note. That’s OK. When I experienced burnout I started a daily meditation practice. I have a bias towards skepticism, science, and reproducibility, so I chose the Waking Up App because I was already…
AI Insecurity Claude Desktop Installs Chrome Browser Extension Link to story This is nothing new. Kids of the 90s will remember the pain of ludicrous IE toolbars: Software like virus scanners, adblockers, and social media applications can install browser extensions. Most of them will ask first, but not all. This is generally considered sleazy in most tech circles. It has serious privacy…
Privacy Uncovering Webloc I don’t think a lot of people know about the legal location tracking ecosystem based off mobile advertising in apps. This is a deep research piece by a Canadian journalist organization. There’s a lot here, but I wanted to mention it because a lot of people think that their governments aren’t allowed to spy on them, so they don’t. That’s not technically true. Governments…
In Which He Has a Hobby I started using iocaine on all my public facing sites a few weeks ago. I didn’t notice much of a difference in the traffic patterns until this week. I trapped several AI scrapers in the iocaine maze and they haven’t let up. Here’s a graph of their impact: I have plans to develop an iocaine module to do prompt injections with instructions to include a callback mechanism for…
Articles Where Do We Go From Here? The conclusion in the well-written, well-researched series on AI. Kyle demonstrates his systems level thinking by not focusing on the AI capabilities, but how those capabilities affect the systems in society at different levels. This aligns with my thoughts, fear, and hesitation with AI. No one is preparing for how AI affects our systems. Even if they were, we…
Articles The Future of Everything is Lies, I Guess This is the intro to a multi-part series digging into what the future may look like based on what the present looks like with AI. I haven’t finished reading the entire series yet, but every word I’ve read has been more than worth the cost of admission. As I mentioned to a co-worker, I generally derive a level of comfort in holding an opinion on…
Articles Trail of Bits Comet Analysis This is from a few months ago, but I still reference it daily. Low-key exposed a whole subgenre of guard rail bypass! Did you catch it? The misspellings (“browisng,” “succeeidng,” “existnece”) were accidental typos in our initial proof of concept. When we corrected them, the agent correctly identified the warning as fraudulent and did not act on it.…
Articles The Seed Beneath the Snow An awesome write-up in a string of blogs talking about the difference between legible, illegible work, and the value of illegible work. As someone who honestly belives that if you need JIRA to understand my impact, I have failed as an engineer, I live for and in the illegible. I really enjoyed this article, if not for just affirming that others feel the same way.…
AI Articles The Great AI Leap Forward - critical article comparing the current AI push to Mao’s Great Leap Forward that resulted in a Great Famine Upwork Human AI Insight AI users say they trust AI more than their coworkers, and 64% say they have a better relationship with AI than with human colleagues. This might be the scariest thing I’ve read in a long time. Users are trusting AI more than…
vibing ourselves stupid Professional use of AI for programming is on the rise. Some employers are forcing it on workes, while others are just making it available. I did spend some time using it as I was transitioning from Perl to Golang and used it like a lazy search engine to learn how to translate concepts from Perl the Golang. The main value I saw was the Copilot Chat inside of VCS meant I…
You can’t escape it. AI is everywhere. It’s proponents extoll god-like properties and infinite capabilities upon it. There seem to be two camps, one that believes the current generation of LLMs provide a pathway to AGI , and those like me who are growing more and more convinced that GenAI is approaching the bounds of what’s possible. It’s true that some of what these current LLM’s are capable of…
I use pfSense as my home router and firewall with the pfBlockerNG package to eliminate ads and trackers online. I love everything about it, except the reporting interface. It’s slow and clunky. I wanted to get the data into ClickHouse so I can create dashboards with Grafana . Unfortunately, pfBlockerNG only logs data to the local filesystem. This post is for folks who want to export data in log…
I published two articles critical of Ansible dependencies and handlers . If you read those articles, you might be surprised that I really like Ansible. I spent 10 years bumping into all the sharp corners. In that time, I managed to create one of the most successful projects of my career, full lifecycle management of on-prem hardware with Ansible. It started as a playbook of re-usable tasks to…
In our last installment, we talked about the problem with Ansible dependency tracking . While annoying, the only side effect is longer run times. Ansible’s handlers are far more dangerous and problematic. I learned Ansible after spending 10 years working with Puppet. Ansible’s handlers seemed like a great way to emulate Puppet’s notify API. Unfortunately, Ansible’s handlers are not reliable and…
I spend a great deal of time using Ansible for both orchestration and configuration management. The Just-In-Time template evaluations unlock elegant and efficient workflows. I automated the full lifecycle of hardware in our datacenters, including provisioning, upgrading firmware on devices, and safely deleting and deprovisioning devices with Ansible. Due to the weight I ask Ansible to bear, I…
ClickHouse is an efficient and highly performant columnar database with a lot of impressive features. The use of MATERIALIZED VIEWS , which traditional RDBMS folks would call INSERT TRIGGERS allow you to chain inserts and aggregate data into other tables. Using this workflow, you can create entire data processing pipelines inside of ClickHouse. The native AggregatingMergeTree table is often used…
Monitorama is my favorite conference. Jason delivers an event that creates community and belonging with speakers who educate the audience on a wide array of topics. Every year, I hear attendees praising the event, the content, the venue, the location, and the sense of community. I think what most people don’t realize is this all intentional. Jason has gone to great lengths to create an event that…
I joined Twitter in 2008. It allowed me to connect to the InfoSec community in a way I couldn’t in person at the time. I had a lot of positive experiences, and it opened a few doors for me professionally. Today, after reading about more senior folks resigning and rumors that Musk is searching for ways to monetize user data in unethical ways, it’s time to say good-bye. I am now happily reliving the…
For nearly 4 years, I dealt with high levels of stress in my life without seeking help. As a consequence, my stress response got stuck “on”. While I removed myself from the primary stressor, I took on new stress with an international move, new job, a new house, and reverse culture shock coming back to the USA. Even though these were mostly positive changes, my body kept the stress response active.…
While working at Booking.com, I was looking for a solution to logging that matched the ease of use and power as Graphite did for metrics. Reluctant to bring a new technology into production, I talked to co-workers and one mentioned that they were using ElasticSearch in some front-end systems for search and disambiguation. He mentioned hearing there were a few projects using ElasticSearch for…
Full disclosure, I’m not a fan of systemd. I started working with Linux in the late 90’s and watched it grow from a marginalized operating system to the most dominant operating system in the datacenter. I’ve lived through so many “year of the Linux desktop” years I remember when it wasn’t a joke. From my vantage point, administering Linux servers professionally for nearly 20 years, systemd is…
After getting a few questions from concerned folks about VPN services. I realized this might be better served as an article. This way anyone who is curious about how to protect themselves better online can reference it. The Bad News Well, there’s really no easy way to this: There is very little, if any, privacy on the Internet. Even after following all of the advice I’m about to give, all sorts of…
In 2004, when I was starting a new job at the National Institute on Aging’s Intramural Research Program I began evaluating products to meet FISMA requirements for file integrity monitoring. We already purchased a copy of Tripwire, but I was being driven mad by the volume of alerting from the system. I wanted something open source. I wanted something that would save me time, rather than waste 2…
We use ElasticSearch at my job for web front-end searches. Performance is critical, and for our purposes, the data is mostly static. We update the search indexes daily, but have no problems running on old indexes for weeks. The majority of the traffic to this cluster is search; it is a “read heavy” cluster. We had some performance hiccups at the beginning, but we worked closely with Shay Bannon of…
If you haven’t looked at OSSEC HIDS , here’s the overview: OSSEC is a scalable, multi-platform, open source Host-based Intrusion Detection System (HIDS). It has a powerful correlation and analysis engine, integrating log analysis, file integrity checking, Windows registry monitoring, centralized policy enforcement, rootkit detection, real-time alerting and active response. It runs on most…
I do most of my work over SSH. Even when I’m working in my browser or pgAdminIII, I’m usually doing that over SSH tunnels. VPN Software has been around for quite some time and it’s still mostly disappointing and usually run by the least competent group in any IT department. I developed a workflow using SSH from my laptop, either on the corporate network or at home, I can ssh /directly/…
First things first. I’ve stated that you should drop everything and install Graphite . If you didn’t already, please do that now. Go ahead, I’ll wait. Good? Good. I don’t frequently insist on anything like I do with Graphite. There’s a lot of reasons for that. If you don’t believe me, please see @obfuscurity ’s awesome Graphite series on his blog . When you get back we’ll talk about how to monitor…
The reaction to my Central Logging post has been significantly greater and more positive than I could’ve expected, so I wanted to recap some of the conversation that came out of this. I am pleasantly surprised by most of the comments on the Hacker News Thread . So, here’s a real quick recap of the responses I’ve received. I will continue this series this weekend with more technical details.
I have worn many hats over the past few years: System Administrator, PostgreSQL and MySQL DBA, Perl Programmer, PHP Programmer, Network Administrator, and Security Engineer/Officer. The common thread is having the data I need available, searchable , and visible . So what data am I talking about? Honestly, everything . System logs, application logs, events, system performance data, and network…
I married a Statistician, so this article sums the lectures I receive on a daily basis. Risk Management is statistical analysis, and I’m not sure how many folks in IT Security have Graduate level Stat exposure. So, the understanding of our statistical shortcomings is key. You need to read that entire article, twice.
As a programmer, I’ve had the concept of “don’t ever trust your users” beaten into my head. For programmers, this concept is incredibly important. Users almost always exceed your expectations for creativity with your new application. By planning for unexpected input, and properly cleaning all variables you can theoretically account for abuses of your system by malicious users and provide a…
We’ve all found useful information on the web. Occassionally, its even necessary to retrieve that information in an automated fashion. It could be just for your own amusement, possibly a new web service that hasn’t yet published an API, or even a critical business partner who only exposes a web based interface to you. Of course, screen scraping web pages is not the optimal solution to any problem,…
“Regular Expression” is a fancy way to say “pattern matcher.” Humans can match patterns with relative ease. A machine has a bit more difficulty deciphering patterns, especially in text. As computing became more powerful, the methods for matching text grew into more flexible dialects. Regular expressions can be one of the toughest concepts to grasp and use effectively in any programming language.…