| pronouns | he/him |
| pronouns | he/him |
Good morning, friends ☕ ☕ 🐕 🐕 💞 💞
The "Zero Day Clock" is a Masterclass in Bad Data Science.
I've heard this clock mentioned multiple times at #RSAC this week. It predicts an "exponential collapse" of the time-to-exploit (TTE) toward zero. It makes for a scary keynote slide, but the math is fundamentally broken.
The model suffers from:
Right-Censoring: It ignores that slow exploits for 2025 haven't happened yet, artificially forcing the "average" to zero.
Selection Bias: It only tracks the fastest 1.5% of vulnerabilities and ignores the "long tail."
Administrative Lag: It mistakes the growing NVD backlog for "attacker velocity."
We don’t need hyperbolic "scare-ware" statistics to justify our urgency. Defense is hard enough without distorting the data.
I’ve written a full technical audit on why this methodology fails a basic statistical peer review:
Technical Breakdown: https://gist.github.com/jgamblin/91f7843b62069616c951f32957c921cd
#RSAC #RSAC2026 #Infosec #CyberSecurity #DataScience #VulnerabilityManagement
"It's none of my business," the woman said, "but..."
The witch did not roll her eyes.
"...I heard you gave the baker's gal fangs, and claws."
"She asked."
"You've made her a monster!"
"Adding doesn't make you a monster. Removing does."
"Removing what?"
"Someone's right to be who they are."
“Two Iranian semiofficial news agencies close to the paramilitary Revolutionary Guard claimed that there had been no negotiations — direct or indirect — with Washington as described by Trump. The Fars and Tasnim news agencies instead portrayed the American president as backing down due to Iran’s threats.”
- AP
A sad state of affairs when I put more trust in Iranian news agencies than I do the President of the United States…