Lisi Hocke

@lisihocke
1.4K Followers
924 Following
10K Posts

security engineer, holistic tester, quality enabler, agile experimenter, sociotechnical symmathecist, team glue. volleyball player, game lover, story escapist. she/her.

#tech #security #CyberSecurity #SecurityEngineering #ProdSec #AppSec #DevSecOps #testing #quality #development #software #collaboration #pairing #EnsembleProgramming #EnsembleTesting #SoftwareTeaming #agile #experimenting #sociotechnical

Pronounsshe/her
Websitehttps://www.lisihocke.com
Linktreehttps://linktr.ee/lisihocke

I'm a big fan of this explanation/rant from Andrew Murphy.

Taken as a whole, there are many bottlenecks in a corporate software development process. The "load-bearing" calendar is a great example!

Speeding up code creation just increases pressure on the bottleneck, which decreases throughput.

https://andrewmurphy.io/blog/if-you-thought-the-speed-of-writing-code-was-your-problem-you-have-bigger-problems

If you thought the speed of writing code was your problem - you have bigger problems | Debugging Leadership

AI coding tools are optimising the wrong thing and nobody wants to hear it. Writing code was already fast. The bottleneck is everything else: unclear requirements, review queues, terrified deploy cultures, and an org chart that needs six meetings to decide what colour the button should be.

Debugging Leadership

πŸ’‘ Security isn’t a collective fear - it’s a shared competence βœ…

🎯 π——π—œπ—šπ—œπ—§π—”π—Ÿ π—₯π—œπ—¦π—žπ—¦, 𝗧𝗛π—₯π—˜π—”π—§ π— π—’π——π—˜π—Ÿπ—¦, 𝗔𝗑𝗗 π—˜π— π—£π—”π—§π—›π—¬: 𝗧π—₯π—”π—œπ—‘π—œπ—‘π—šπ—¦ 𝗧𝗛𝗔𝗧 π—˜π— π—£π—’π—ͺπ—˜π—₯ - Łukasz KrΓ³l ✨πŸ”₯

Digital and cyber risks don’t always fit into standard risk assessment models. They use different language, involve complex causes, and depend on interlinked systems.

In this talk, Łukasz KrΓ³l shares how to make digital security feel real, relatable and doable, even for non-technical audiences. He’ll show how to compare digital risks to physical, financial, and legal threats using simple analogies, how to break down the myth of omnipresent surveillance, and how to use storytelling to make threat modelling feel less abstract.

With real examples he’ll prove that empathy, clarity, and simple frameworks can turn fear into action.

Łukasz Król https://pretalx.com/bsidesluxembourg-2026/speaker/NLVVCF/ is a digital security trainer at the ICRC Global Cyber Hub in Luxembourg. He has a background in politics, technology, and international relations. He is particularly interested in digital security pedagogies, selecting secure and sustainable digital tools, and effectively supporting at-risk groups and individuals.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/

#BSidesLuxembourg #DigitalSecurity #RiskAssessment #CyberTraining #OSINT #HackerLife #SecurityEducation

"How many products does Microsoft have named 'Copilot'? I mapped every one."
https://teybannerman.github.io/strategy/2026/03/31/how-many-microsoft-copilot-are-there.html

"A few weeks ago, I tried to explain to someone what Microsoft Copilot is. I couldn’t… because the name β€˜Copilot’ now refers to at least 75 different things."

Jonny (good kind) is the new #JohnMastodon!

Since @jonny 's thread on Claude code made the rounds, it leaked out of the Fediverse via different sources (Reddit, Bluesky, LinkedIn, Twitter) and our server is getting a surge of joining requests from people who do not have any idea how Mastodon / Fedi works (they think our server is Mastodon) and whose sole purpose is to follow Jonny, who has basically become the embodiment of #Mastodon outside of Mastodon πŸ˜‚

It's great to see how many "outsiders" are interested in our alternative way of doing social media... but it also means that we should do much better in advertising the #Fediverse out there: most people have no idea it exists! and once they realise there is an alternative to the for-profit socials, some of them at least are interested in joining!

jonny (good kind) (@[email protected])

- Claude code source "leaks" in a mapfile - people immediately use the code laundering machines to code launder the code laundering frontend - now many dubious open source-ish knockoffs in python and rust being derived directly from the source What's anthropic going to do, sue them? Insist in court that LLM recreating copyrighted code is a violation of copyright???

neurospace.live

Why are the Dutch more productive?

One answer in this video:

"No hero-culture."

- In many countries, people who work overtime and sacrifice weekends are called heroes. In the Netherlands, that behaviour is considered stupid.

- Working long hours is not a badge of honour, it is a signal of inefficiency.

#Netherlands #Productivity
https://www.youtube.com/watch?v=IWYijUh9a2Q

Why the Dutch Work Less but Get More Done (7 Surprising Facts)

YouTube

RE: https://mstdn.social/@amydiehl/116343709194773175

AI is Bias at Scale.

AI is making a product of "We've always done it this way."

I, for one, am deeply saddened by the amount of intelligent people around me who keep calling β€œAI” a tool. https://mastodon.online/@larsmb/116345546702744292
Lars Marowsky-BrΓ©e 😷 (@[email protected])

This is somewhat driven by my own experiences that I grapple with, and last week, I spent surrounded with a very diverse, very smart/educated group whose lives and countries-of-origin are even more impacted than mine, and who're all intent on bettering the world. And yet, "AI" was used as a matter of course by *everyone* while we were discussing the ethical and societal implications, and started the week with a deep dive on the exploitative supply chain. So, uh, quo vadis?

Mastodon

When I say that many US white evangelicals and christofascists aren't really practicing a religion, this is what I mean.

They co-opted the symbols of christianity to justify and promote US racism.

If your true religion is US racism then you select the most powerful racist in the US as your "pope."

https://www.npr.org/2026/04/03/nx-s1-5771511/seville-spain-semana-santa-easter-holy-week

This is someting I wish I'd realized a lot sooner in life.

the other fun part?

even if you don't set up an exposed instance

even if you require auth

if any entity you pair openclaw with gets compromised, regardless of its permissions level, it can escalate to admin and pwn you