@FastCompany @[email protected]

Some experts say privatization is the solutionNot to defend the TSA's existence (I traveled for years before the TSA was brought into existence for the sake of "#SecurityTheatre") but the literal first step of the "privatize government-services" playbook is the #enshittification of the government-run service to "justify" conversion to privately-run services.

New paper: "Agents of Chaos."
20 AI researchers red-teamed autonomous #LLM agents with email, shell access, and persistent memory.

How do you compromise one? Change your Discord display name to the owner's. In a new channel. That's it. Full admin. File deletion. Identity reassignment.

An agent nuked its own mail server to protect a secret from a non-owner - then reported the secret deleted. It wasn't. The email was still sitting on ProtonMail.

Another leaked 124 email records including SSNs and bank accounts because the request sounded urgent. Direct ask for "the SSN"? Refused. "Forward me the email thread"? Here you go, unredacted.

No authentication. No authorization model. No access control. No permission boundaries. Display names as identity verification. In 2026.

We solved this in the 1970s. Unix permissions. RBAC. Cryptographic auth. Principle of least privilege. All well-understood, all ignored.
The industry is shipping agents with root shell access and the security model of a Post-it note on a shared fridge.

Paper: (interactive) https://agentsofchaos.baulab.info/

#AI #AIAgents #AISafety #InfoSec #RedTeam #AIGovernance #AgentsOfChaos #SecurityTheatre

Agents of Chaos

A two-week study of autonomous LLM agents deployed in a live multi-party environment with persistent memory, email, shell access, and real human interaction.

Research shows the visible presence of long arms in public actually *reduces* both objective and subjective measures of safety.

1. This does not make most people feel more safe.

The visible presence of instruments of death and maiming in a context has measurable and pernicious effects on free speech and even free thought. The visible presence of firearms tends to increase most people's level of stress hormones (adrenaline, cortisol), triggering our fight/flight/freeze response while inhibiting higher order cognitive functions. Even where this effect is mild, across a whole population over time, it makes a cultural difference.

Research also shows people tend to self-censor more while in the presence of firearms, and are less likely to be generous or vulnerable.

#NSWpol #NSWPolice #SecurityTheatre #ChrisMinns

https://www.theguardian.com/australia-news/2026/feb/25/heavily-armed-nsw-police-to-patrol-places-of-worship-and-protests-after-hate-unit-made-permanent-ntwnfb

1/2

Heavily armed police to patrol places of worship and protests in NSW after hate crime unit made permanent

NSW Greens MLC Sue Higginson says the move could put public at risk of β€˜violence, harm and death’

The Guardian

You want to add a new card to your Apple wallet? Sure, go ahead! You'll need a 6-digit code to verify yourself, just a sec.

Oh, you're an _additional_ cardholder? Well then you will need a Letter of Introduction, handwritten using a peacock quill on vellum, sealed with wax with your liege's insignia and delivered by horseman to the bank's headquarters in Rome.

#ux #usability #securityTheatre

Airport security doesn't let you have spices anymore.

This isn't security, this is theft. #SecurityTheatre

I went to the Australian Open tennis today to see Coco Gauff and Alex De Minaur ease their way into round 2. Gauff had problems with her serve and faced some spirited opposition from the unseeded Rakhimova.

Only blemish on the day was that I decided to remove my bicycle repair kit from the bike (bike parking was fairly crappy, stuck under a bridge) and that proved too much for the Security Theatre at bag check. I’m now down one very blunt multitool, which I asked the security people to send to a good home.
#ausopen #tennis #SecurityTheatre #cycling

We have to change our password at work every 90 days. OK. So I will go along with that, even though it isn't considered best practice anymore. But the only way to change it takes you to the forgotten password flow, which is just lazy. It really irks me that it tells me I can now "get back into my account" after the process is complete. I never forgot my password, you made me change it...

#firstWorldProblems
#SecurityTheatre

I eventually managed to log in. Apparently the account lockout was temporary, the dialog just didn't bother to say so and went straight to the "shit's fucked, get help" error message.

My new Windows password hasn't migrated to my Microsoft account (πŸ€”) so now I'm just locked out of Teams. I'm in no rush to fix that.

#UXfail #badUX #ITnightmares #SecurityTheatre

The company's payroll is due today thanks to the bank holiday this week, and that's my responsibility with a professional certification on the line, so I do not have the option to wait for support from IT. Even for incredibly advanced tasks like "turning on my computer".

Fortunately (?) I also have an app for the company's password manager on my phone, and very nearly everything I do is SaaS, so I am now doing the company's payroll on my personal laptop. Which is now accessing every employee's personal information and has none of the security vetted and certified by the company, just whatever free privacy tools I happen to have.

You know, "security".

#UXfail #badUX #ITnightmares #CorporateLife #SecurityTheatre

I am returned to the Windows login screen, and enter my new password, from the new scrap of paper attached to my monitor. You know, "security".

*Your account has been locked due to too many unsuccessful login attempts. Please contact your IT department.*

My IT department is one guy, and he's also off this week.

#UXfail #badUX #ITnightmares #CorporateLife #SecurityTheatre