4/

I've been thinking about #uncertainty from risk POV, & Doug Hubbard's concepts of calibrated estimators. My team does weekly calibrations for #estimating uncertainty. Listening to Choi-Greene talk about AI's certainty - confidently wrong, sometimes - I couldn't help but think that having calibrated, specific uncertainty on events, plans, projects, #technology would become MORE valuable in the future.

@bsidesseattle #BSidesSeattle #BSidesSEA #2026 #cybersecurity #infosec #cyber #security

3/

@bsidesseattle #BSidesSeattle #BSidesSEA #2026 #cybersecurity #infosec #cyber #security

Last year #BSidesSeattle, #llm / #genai / #agentic AI looked like hype that might blow over. This year acceptance, realistic / grounded direct topics.

Emily Choi-Greene's applying AI to Threat Modeling was a great kick off session. Best part was genAI's confidence - & the value of uncertainty.

#BSidesSeattle #BSidesSEA 2026 thoughts:

2/

Brian Myers' talk "Waking Up to AI: An Adventure in Governance" was fabulous. I heard him @ #BsidesPDX Oct on #British #Library #ransomware, so knew it'd be good.

The realistic, slow walk through for companies caught off guard by #AI and #LLMs - and the supply chain issues it brings up - reinforced the idea that weaknesses and strengths can be amplified by AI; leaving me wondering where are the brakes (so we can go fast).

#infosec #cyber #security

Excellent #BSidesSeattle #BSidesSEA 2026. Unpacking a few thoughts:

1/

Super enjoyed "The Security Policy Rollout Survival Guide" by Maya Kaczorowski. Great talk! Wish it had been a 1 hour. She may mean something else but this is my take home:
1) who set the policy is who should enforce
2) a pilot project is actually a #decision, not #research. Treat it as such
These may not be #hot #new #information to others, but it really resonated with me. Thank you Maya! Great talk.

@bsidesseattle

Interesting. #Microsoft just forced #BSidesSEA to enforce ID verification with tickets 3 days before the event.

Refunds are available if you believe this could affect you by the fash or just bullshit.

#BSides

Y'all
I had such an amazing experience at #BSidesSeattle this year.
That area's tech scene feels so alive.

I wrote up some of my thoughts on the event.

https://blog.gitguardian.com/bsides-seattle-2025/

#BSidesSEA

BSides Seattle 2025: Rebuilding Trust in Systems In The Age Of NHIs

The BSides Seattle 2025 speakers showed how security and IAM fail under stress and why usable security must consider human limits and machine-scale risk.

GitGuardian Blog - Take Control of Your Secrets Security

"Learn the difference between 'helping' and being 'helpy'"

~ @wendynather at #BSidesSEA - this is very useful. Just pointing out that an article does not make a specific point you'd like to see is "helpy". Pointing out that many people already knew what an article states also does little for the world. Being actually helpful looks different & is more work. 1/2

#BSidesSeattle #BSidesSEA

A pain in the SaaS: Scalable Detection in the Age of Data Sprawl
Alan Braithwaite

#BSidesSeattle #BSidesSEA

What Your Exposed APIs Are Leaking
Tristan Kalos

#BSidesSeattle #BSidesSEA

Unpacking Session ID Security: Entropy, Encoding, and Math (Oh My!)
Jake Karnes