51 Followers
99 Following
138 Posts

Allegedly a cybersecurity professional.

Linux container primitives, eBPF and attestation, secure architecture, threading the needle.

Follow my main for computational occultism

Less professional main@[email protected]
PronounsHe/Him
Not that literally anybody has to do what I say and not that any kind of social statement online can avoid that kind of performative tone policing. Infiniscroll social media is poison.

Thing is, my whole life has been an inevitablism of people telling me to stop being obstructionist and get with the program. I’m now validated that people were projecting how they think someone bearing warnings should also bear intent.

Don’t look at how people treat LLMs for your signs of adequate social understanding, look at whether they talk to other PEOPLE like chatbots. Are there people who suddenly seem terse because they don’t think they need you (or anyone) on side or not?

Don’t just judge from afar, interact and find out. Whatever you think of this tech, if you think the future doesn’t involve people then ask yourself what business, what cybersecurity is even *for*.

I don’t care much whether you reach the same conclusions as me so much as you actually take responsibility for your interactions rather than blaming norms formed from misaligned incentives.

Personally I’m loving the age of LLMs in tech.

It’s made all y’all bullshitters and overconfident sociopaths REALLY fuckin obvious.

Allow us to block Copilot-generated issues (and PRs) from our own repositories on #github

https://github.com/orgs/community/discussions/159749

Allow us to block Copilot-generated issues (and PRs) from our own repositories · community · Discussion #159749

Select Topic Area Product Feedback Feature Area Issues Body I find the following two news items on the front page: https://github.blog/changelog/2025-05-19-creating-issues-with-copilot-on-github-co...

GitHub
Hello #dc4420 people I am bad at socialising.

I'm working on a project to try to mitigate some of these risks and I affectionately call it the "loaded footguns" project.

All this risk that Google put paying customers through that frankly just boggles my mind. It's like they made it bad on purpose to drive you toward something but that other something just doesn't exist...

All I want is to be able to configure blocks and rules in an API. I would happily write the terraform provider myself.

I feel like Google left space for a product upsell here and then the project got cancelled.

Want to quarantine emails, block senders or create content compliance rules? Is there an API for that? No, go fuck yourself.

You have to click around in their *awful* inconsistent web interface, so obviously you can't do any configuration review.

We nearly had a fuckup the other day because the compound conditionals on the content compliance rules have to be selected from a drop-down and ANY looks a whole lot like AND and nobody could review the change before it went out.

Periodically I have to use Google Admin to deal with phishing reports and hot damn is it actively combusting refuse.

I tell people about the "rough edges" and they honestly don't believe me.

Here's a fun one - if you view a message in the investigate tool, and you want to inspect an attachment, it will warn you that the attachment may be dangerous but because it's a javascript button you can't right click and "save as", it will literally just yolo open the potentially malicious pdf in your browser.

How do you get around this? Go search for the same fucking email in Google Vault and export it.

I’ll be at BSides LDN tomorrow, hmu!