Andrew ๐ŸŒป Brandt ๐Ÿ‡

3.3K Followers
788 Following
5.6K Posts

Words published here do not necessarily reflect views of my employer or any other organization I am affiliated with.

Research and analysis about malware, network forensics, and the intersection of crime with anything that electrons or photons flow through.

Board member of World Cyber Health, the parent organization behind Malware Village and the NO-HAVOC project.

Docent of obsolete technology at @mediaarchaeologylab

Executive director, Elect More Hackers: electmorehackers.com

"By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges." -- Cory Doctorow

Backup tooter@threatresearch.bsky.social
Threat levelmostly harmless

I am at the Colorado capitol today to testify against a new bill, SB26-090, that would carve out a broad and unnecessary exemption to our groundbreaking right to repair law that would effectively remove the right to repair for large categories of technologies.

The bill is going to be heard in committee today "upon adjournment" of the senate. If you have the ability to testify online or in writing against this bill, I would encourage you to do so as soon as possible.

Background: https://www.ifixit.com/News/116447/a-new-colorado-bill-could-blow-a-hole-in-the-nations-strongest-right-to-repair-lawhe-nations-strongest-right-to-repair-law

Testimony signup link: https://sites.coleg.gov/public-testimony/sign-up-to-testify/step-1

Current day status board: https://www.leg.state.co.us/public/display.nsf/index.html

Bill details: https://leg.colorado.gov/bills/SB26-090

A New Colorado Bill Could Blow a Hole in the Nationโ€™s Strongest Right to Repair Law

A bill could hollow out the strongest electronics Right to Repair law in the country, using the overbroad term โ€œcritical infrastructure.โ€

iFixit

DEF CON 34โ€™s theme is โ€˜Agencyโ€™. Weโ€™re focusing on self-determination in our use of tech. Charting our own course and helping others do the same.

Letโ€™s start moving our valuable attention to tech that supports our agency. Letโ€™s find the places we can help and choose to act.

Read more at: https://defcon.org/html/defcon-34/dc-34-theme.html

Visual style guide and homework assignments coming soon!

#defcon #defcon34 #agency

@defcon Agency obviously includes the right to repair. The right to repair must include the right to interoperate and build new clients. Looking at Slack, discord, and so many others.
heads up users of github

@Viss For folks looking for the right knob: https://github.com/settings/copilot, Allow GitHub to use my data for AI model training" -> Disabled

#savedyouaclick

Watching the premiere episode of @huntress' new webcast, _declassified, and John Hammond is talking to master scam-baiter Jim Browning about a hidden-camera video he's showing of a job interview of a prospective scam call center worker. The interviewer and interviewee use a kind of coded language to talk about the interviewee's experience in phone-based scams. Truly remarkable insider video I've never seen before. #scam #spam #cybercrime
Watching the premiere episode of @huntress' new webcast, _declassified, and John Hammond is talking to master scam-baiter Jim Browning about a hidden-camera video he's showing of a job interview of a prospective scam call center worker. The interviewer and interviewee use a kind of coded language to talk about the interviewee's experience in phone-based scams. Truly remarkable insider video I've never seen before. #scam #spam #cybercrime

The latest episode of 'Where Warlocks Stay up Late" dropped yesterday. Featuring yours truly. The interview goes pretty deep from growing up in Maine, working at Lotus, stories about L0pht you may not have heard before to getting fired from @stake. Probably the most personal interview I have ever given.

https://www.youtube.com/watch?v=j6jhAugNqvE

#l0pht #spacerogue #warlocks

holy fucking shit so this is the worst "ai psychosis" story I have read in a while but also is it "ai psychosis" as much as it is "an AI is literally feeding you that you're in the middle of a piece of conspiracy fiction"? https://bsky.app/profile/ckunzelman.bsky.social/post/3mgazir4wu22x

https://techcrunch.com/2026/03/04/father-sues-google-claiming-gemini-chatbot-drove-son-into-fatal-delusion/

cmrn knzlmn (@ckunzelman.bsky.social)

This is bad, and part of what makes it so bad is that this is clearly pulling from *genre* understandings of reality, which the statistical linguistic machine seemingly cannot distinguish from other text included in the training data. Truly an ideology machine where every episode of CSI is true. [contains quote post or other embedded content]

Bluesky Social

When your company suffers a security breach, the instinct is to say as little as possible. Your legal team wants to limit liability. Your communications team wants to control the narrative. The result is vague, unhelpful disclosures that end up doing exactly the opposite of what they're intended to do.

In a new article published this week on Law.com, EPSD Advisory Board member Melanie Ensign, privacy attorney Michelle Finneran Dennedy and I make the case that vague breach communications don't protect you. They alienate your customers, freeze your pipeline, hand narrative control to third parties, and leave you facing litigation with an already hostile audience.

The lawsuits are coming regardless. What you control is whether you face them with customer trust intact or in tatters.

Read the full article ($): https://www.law.com/corpcounsel/2026/03/01/beyond-liability-how-vague-breach-communications-harm-your-business-and-legal-position/

Beyond Liability: How Vague Breach Communications Harm Your Business (And Legal Position)

The lawsuits are coming regardless. Vague communications ensure youโ€™ll face them with an alienated customer base and evidence that they prioritize legal cover over helping victims protect themselves. Thatโ€™s a costly combination for any brand.

Corporate Counsel