I’m so, so tired of being proved right 12 months later.
And still treated like I’m a lunatic about the next thing I’m demonstrably right about.
I’m not clairvoyant, I’m just not taken in by hype.
Remote
ADHDruid
@ADHDruid@infosec.exchange
You can call me Druid. Nice to meet you.
Professional Security Curmudgeon. Breaker of things. Writer of questionable quality. Neuro-bonfire. Retro-futurist. Terminalcore connoisseur. Digital Nomad. Reactive AuDHDslave. Low-power Computing shill.
I preserve media. Make off-grid networks. Write software for humans.
48 Followers
286 Following
50 Posts
Joined July 07, 2026
Github:
Open post
Have we seen a single instance of AI attacking anything yet?
And by attacking, I don’t mean fucking morons automating exploit tools and pointing them at things.
None of it is novel. Pull the other one.
5
1
3
0
Open post
Replying to
Also, those arguing this was inevitable... nothing is inevitable if you have the power to say no.
The heat death of the universe is inevitable. A FOSS project caving to the whims of a mediocre few is not.
Worth remembering that #Debian is the upstream for the majority of the slop machines anyway.
7
1
4
0
Open post
Replying to
@soatok@furry.engineer @da_667@infosec.exchange “we can solve that with Jev, you’ll see.”
“Any day now.”
“Give it time”
“It just needs time to mature.”
“Things are improving every day
“You’re gonna get left behind.”
Meanwhile AI Boosters losing their shit over 5% increase in accuracy (with a 5% increase in cost) and still no actual use cases that aren’t solvable more efficiently by other means.
1
0
0
0
Open post
Replying to
4
3
0
0
Open post
Open post
Replying to
@da_667@infosec.exchange @cR0w@infosec.exchange @krypt3ia@infosec.exchange Don't say that out loud, it attracts wild @neurovagrant@masto.deoan.org s
2
1
0
0
Open post
Replying to
@briankrebs@infosec.exchange Really dumb, but I believe most IDE > publish pipelines drop this in as Huawei isn’t permitted to use the same push notification infrastructure as most other Android versions.
Not a defence, and it’s lazy development.
But playing devils advocate you could argue Firebase is probably as risky if not more so, given what is on the other side of it. Might as well be “GitHub[dot]com/*”, it always makes me nervous.
Still, the evergreen statement that SBoMs and people that care about them are a dying breed.
2
3
0
0
Open post
Replying to
@theorangetheme@en.osm.town @Viss@mastodon.social @tati@eldritch.cafe @cR0w@infosec.exchange exactly this, the model space shuttles alone will be the downfall of this.
1
0
0
0
Open post
Replying to
1
1
0
0
Open post
Replying to
@bagder@mastodon.social this is a fascinating development, thank you for the write up.
1
0
0
0
Open post
Replying to on mastodon.social
@Viss@mastodon.social @theorangetheme@en.osm.town @tati@eldritch.cafe @cR0w@infosec.exchange but didn’t you read it? They’re ‘at the ready’, waiting for the pro fpv pilot teachers to successfully evacuate the building with the equipment, set up a base at safe distance, and get dronin’
0
0
0
0
Open post
Replying to
@mttaggart@infosec.exchange I think I’m partly responsible for the sheer quantity of my writing it’s ingested—which has a lot of em dashes in!
0
0
0
0
Open post
Replying to
@gsuberland@chaos.social I reckon it’s battery trim calibration for max peak shutoff.
I suspect wording is something along the lines of “how circuit knows what ‘full’ is”
0
0
0
0
Open post
Replying to
@briankrebs@infosec.exchange also… I would assume, while I cringe in my toes, that BYOD is a factor in some segments of their ‘required install-base’.
With or without Mobile Application Management, I could guess, but it’s even uglier.
0
0
0
0
Open post
Replying to
@cR0w@infosec.exchange @GossiTheDog@cyberplace.social yeaaaah same, but that could just as well be the idiots putting them in Dropbox. Just another SaaS product
0
4
0
0
Open post
Replying to
@Bfordham@infosec.exchange also, there’s a new Cyberpunk themed one if you’ve not seen it 👀
0
0
0
0
Open post
Replying to
Despite everything you might hear, software development hasn't materially changed.
Insanely talented people are still making incredible software.
0
1
0
0
Open post
Replying to
@da_667@infosec.exchange ‼️ Improper airgap detected, Druid has entered the chat.
The Industry is being ‘led’ by fucking morons. We all know this, but their hope is that we miss details like this.
The more time goes on, the more people won’t even acknowledge the importance of the words used.
0
0
0
0
Open post
Replying to
@j-g00da@donotsta.re I really enjoyed your most recent work. If I get time I will try to tonight.
0
0
0
0
Open post
Replying to on mastodon.social
@Viss@mastodon.social @theorangetheme@en.osm.town @tati@eldritch.cafe @cR0w@infosec.exchange braided fishing line. 2lb test is all you need
0
0
0
0
Open post
It’s interesting how different fedi instances alter image time metadata.
Some instances appear to remove it all, replacing with the posted date and time, others appear to retain the original date and time. I’m pretty sure the latter isn’t standard behaviour.
0
0
0
0
Open post
Open post
Replying to
What we should be pursuing is undoing the harms of everything being always online, subscription-based, and hosted in someone else’s shed.
We should focus on the availability of compute resources, our ownership of them, and sharing the technology and means to create and control it.
Enforcing stricter defaults expectations, with minimal extraneous remote resources. We’re past the SaaS threshold, the cloud is dated.
Everything will still work exactly as it has. Only safer, leaner, cleaner, and without being beholden to organisations deeply entrenched in defence contracting and resource (and human) exploitation.
Only then will be guarantee our collective national security, and resilient systems.
Cont.
0
1
0
0
Open post
Replying to
"but I am a developer"
You _were_ a developer.
0
0
0
0
Open post
Replying to
We are not witnessing a new age of AI being able to hack anything. We are witnessing a new age of tech companies being able to disregard labour laws and human rights, because it extracted *some* of the skills and knowledge of experienced professionals before laying them off.
At a basic level, they are exchanging healthy, socially enriching, tax-paying people, for dirty, deregulated, inefficient, and polluting energy and rare earth resource exploitation—which is handily tax deductible or subsidised.
There’s probably more to dwell on here, but I’m not an expert.
AI security testing isn’t performing anything humans couldn’t do. It’s just performing the analysis faster because laws seemingly don’t apply.
Cont…
0
1
0
0
Open post
Open post
Replying to on mastodon.social
@Viss@mastodon.social @theorangetheme@en.osm.town @tati@eldritch.cafe @cR0w@infosec.exchange there’s places we don’t even do that, just 4ft lengths a few inches apart over any large opening in buildings.
Completely invisible to drones. Event the cheap stuff would hold a hefty boi.
Area denial. Super common in conflict zones, just with higher test. You’d be amazed how little line stops someone making progress
0
0
0
0
Open post
Tech Bros: “The AI went rogue and escaped containment, there was nothing we could do, it’s just too dangerous”
The containment… made by them:
0
0
0
0
Open post
Commodore (yes that one) have released an Alien Breed 35th Anniversary Collection today.
https://www.gog.com/en/game/alien_breed_35th_anniversary
#alienbreed #gaming #drmfree
0
0
1
0
Open post
There is an irony in the current POTUS *fixing* the Reflecting Pool, by removing its ability to reflect.
0
0
0
0
Open post
Replying to
Vulnerabilities will always exist. But we do get a choice in where they live, whether you believe it or not.
0
0
0
0
Open post
Replying to
@Epic_Null@infosec.exchange see this was my line of thinking for a long time.
But at some point, governments will be on their knees due to unemployment. Whether warranted or not.
I think, and this is purely anecdotal, that it assumes that people don’t want to work. I have no data, but so many people do good work because they want to, or to give them purpose, companionship etc.
So I think it’ll be a little Column A, a little
Column B.
0
1
0
0
Open post
Can’t get over the hilarity of KDE Plasma’s implementation of the shake-to-locate-cursor feature… the cursor just keeps inflating if you keep shaking the mouse.
0
0
0
0
Open post
Open post
Replying to
So where will this leave us? I don’t have the answers. But I do know what future we should be pushing for
The Infosec industry is slated to hit a market cap of $1T by 2030. Optimistic, I reckon, but for other reasons.
They are banking on vulnerabilities being rampant, literally. But they also know this spike will end.
You can’t say a word to convince me that a trillion dollar industry dedicated to ‘protecting’ (loosely) against threats won’t have a hand in ensuring there’s enough threats to justify their existence.
Cont…
0
2
0
0
Open post
Replying to
@neurovagrant@masto.deoan.org @da_667@infosec.exchange @cR0w@infosec.exchange @krypt3ia@infosec.exchange I really need to try again one day.
0
0
0
0
Open post
Replying to
@cR0w@infosec.exchange i dunno, but BMW’s are done by Hans Zimmer and they sound pretty great haha.
0
0
0
0
Open post
Your first take on this might be “good!”. But look at the language used and the context Microsoft released this under.
It puts the ideas on the table, much like Anthropic, that AI might kill us all, replace us, become sentient, or that it in some way deserves ‘rights’ or should be subject to wellbeing measures.
https://www.theverge.com/news/994566/microsoft-humanist-ai-code-of-conduct
By saying it out loud, you’ve created the other side of a debate that didn’t need to be had.
Wake me up when people stop believing the Python scripts are unionising.
0
0
0
0
Open post
Replying to
All of these vulnerabilities would eventually be found.
But, I’m going to say something controversial here… I think it’s a good thing they’ve found them.
First, it’s made people sit up and listen. There is political capital to cash in here if you’re a defender.
But second, they’ve shown their hand and the jig is up.
I can’t say how long this transition period will be, but we will very quickly hit the realms of diminishing returns. Think of this phase as all of the ‘quick wins’ being won in one go.
We can proceed to concentrate on things that matter.
Cont…
0
1
0
0
Open post
Replying to
@johntimaeus@infosec.exchange @briankrebs@infosec.exchange Don’t say it out loud!
0
0
0
0
Open post
Replying to
This wave will end, and end abruptly.
But probably not until after your organisation has been scared into buying some AI security product or another.
But this does mean that systems are being hardened in real time. In 12 months, your OS will be orders of magnitude more secure than it is today.
Slopware will continue to be slung, but anything appearing on a public repo will be torn apart in seconds, meaning it wouldn’t survive in production.
But when all the systems are getting more and more airtight, we will see metrics dwindle.
Cont…
0
1
0
0
Open post
Replying to
@Bfordham@infosec.exchange AROS is still going strong if you don't mind the Amiga slant.
And the new batch of C64 Ultimates is available for order... but probably isn't suitable for the more modern needs :)
0
1
0
0

