Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Mike Williamson

@sleepycat@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Digital Transformation = Agile + APIs + AppSec

Security Architecture, Programming.

284 Followers
434 Following
32 Posts
Joined November 13, 2022
blog:
https://mikewilliamson.dev
github:
https://github.com/sleepycat
Code: Worktree.ca:
https://worktree.ca/sleepycat/
Open post
Mike Williamson @sleepycat@infosec.exchange
· 2mo ago
"The less busy work you have the less appealing these Al tools are." -- Kelsey Hightower https://bsky.app/profile/kelseyhightower.com/post/3mptigbdzjk2k
bsky.app
9
0
2
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 6mo ago

Inside the complacency and decisions that eroded trust in #Azure — from a former Azure Core engineer.

https://isolveproblems.substack.com/p/how-microsoft-vaporized-a-trillion

infosec.exchange
5
0
4
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 2mo ago
"The nature of a #vulnpocalypse is that you’re going to be drowning in the deluge of the vulnerabilities – if you weren’t, it wouldn’t be a vulnpocalypse! Given that background, you need to step back and ask “how do we get out of this situation?” And the answer is that you make foundational investments in systemic prevention of entire classes of vulnerabilities, even at the expense of having marginally high latency to fixing individual vulnerabilities." https://alexgaynor.net/2026/jul/15/you-cant-bugfix-your-way-out-of-the-vulnpocalypse/
alexgaynor.net

You can't bug fix your way out of the vulnpocalypse · Alex Gaynor

1
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 2mo ago
A list of #OSS style licences that restrict software from being included in #AI training sets https://github.com/non-ai-licenses/non-ai-licenses
GitHub

GitHub - non-ai-licenses/non-ai-licenses: This repository contains software licenses that restrict software from being used in AI training datasets or AI technologies.

This repository contains software licenses that restrict software from being used in AI training datasets or AI technologies. - non-ai-licenses/non-ai-licenses

1
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 20mo ago

"The PBO said that in the four departments it studied, IT services provided by outside contractors cost taxpayers between 22 and 25.7 per cent more than they would have if the services had been provided in-house."

#gcdigital #contracting

https://www.ctvnews.ca/politics/article/federal-it-contracting-cost-more-than-in-house-services-pbo-report/

infosec.exchange
30
3
26
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 6mo ago

The #WebAssembly #ComponentModel
https://component-model.bytecodealliance.org/introduction.html

infosec.exchange
3
1
3
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 8mo ago

In #TBS policy there are a number of places where they mention cloud service models as a progression from IaaS > PaaS > SaaS.

It's like commodity SaaS software is end state all initiatives should be aiming for... as though there is nothing unique about running a country that might require software.

#FaaS is furthest up the stack for custom development.
#SaaS is for commodity software.

#gcdigital

infosec.exchange
3
0
1
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 8mo ago

My latest attempt at explaining that mandate specific stuff will require custom development, not just procurement.

The weirdly consistent refusal I see (at all levels) in the Canadian government to engage in software development (or even employ programmers) means there are certain things can't/won't get done.

Does this make a clear case for custom dev? How would you argue that point?

3
1
6
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 7mo ago

"The $126M-funded object storage company systematically dismantled its community edition over 18 months, and the fallout is still spreading"

"If your risk model assumes that #CNCF membership means long-term stability, #MinIO is your counterexample."

https://news.reading.sh/2026/02/14/how-minio-went-from-open-source-darling-to-cautionary-tale/

infosec.exchange
2
0
1
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 8mo ago

@joriki@infosec.exchange Big 👍 to Mazzucato's work. That book is new for me. I'll dig in!

2
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 6mo ago

Love to see the innovation in the GraphQL space: #Shopify reworked #graphql execution from depth first to breadth for performance gains.

"Almost every GraphQL implementation uses this depth-first pattern, including the canonical graphql-ruby gem that we have used since 2015, and the official graphql-js spec implementation that it follows. In our experience running this execution model with Ruby, we’ve found that it scales poorly."

https://shopify.engineering/faster-breadth-first-graphql-execution

infosec.exchange
1
0
1
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 6mo ago

Rise 8 Livestream with Jennifer Pahlka & Bryon Kroger

https://www.youtube.com/watch?v=2Tciq0Ga3uY

1
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 6mo ago

"The invisible #Unicode characters were devised decades ago and then largely forgotten. That is, until 2024, when hackers began using the characters to conceal malicious prompts fed to AI engines. While the text was invisible to humans and text scanners, #LLMs had little trouble reading them and following the malicious instructions they conveyed."

https://arstechnica.com/security/2026/03/supply-chain-attack-using-invisible-code-hits-github-and-other-repositories/

infosec.exchange
1
0
1
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 6mo ago

"2025’s exploited vendors followed the same pattern we observed last year, with big tech experiencing the most zero-day exploitation and security vendors following directly behind.
...
#Cisco and #Fortinet remain commonly targeted networking and security vendors, while #Ivanti and #VMware continue to see exploitation that reflects the high value threat actors place on VPNs and virtualization platforms."

https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review

infosec.exchange
1
0
1
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 7mo ago

Austrailia's early 2000s experiment with a #SharedServices organization is super interesting.

Super impressed that they actually checked that their #centralization effort was delivering on it's claims.... and it wasn't.

The original business case was "fundamentally flawed" and has "resulted in a total cost to the State of $473 million" instead of the expected savings of $68 million/year.

* 91 per cent of sampled agencies comment that service delivery has deteriorated upon transitioning to shared
services.
* Over 80 per cent of the sampled agencies reported that processing timeframes have worsened
* rolling-in to the DTFSSC has had a detrimental impact on the operations of the majority of rolled-in agencies

"The Authority concludes that the current structure of the DTFSSC is problematic. It is a monopoly provider, with a mandated client base and a lack of meaningful service level agreements. This means that there are minimal incentives for DTFSSC to improve service delivery and few ways in which client agencies can hold DTFSSC accountable"

#gcdigital

https://www.erawa.com.au/sites/default/files/Final%20Report%20-%20Inquiry%20into%20the%20Benefits%20and%20Costs%20Associated%20with%20the%20Provision%20of%20Shared%20Corporate%20Services%20in%20the%20Public%20Sector%20-%2010%20June%202011.PDF

infosec.exchange
1
1
3
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 7mo ago

#Exploitation in the era of #formalverification A peek at a new frontier with adacore/Spark

https://av.tib.eu/media/62268

infosec.exchange
1
0
1
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 8mo ago
Replying to
"This is the second part of our two-blog series, where we explore various #initialaccess vectors into #Kubernetes environments, analyze the associated attack angles, and clarify the relevant risks. " #wiz #securityhttps://www.wiz.io/blog/kubernetes-data-plane
Kubernetes Initial Access Vectors Part 2: Data Plane | Wiz Blog
wiz.io

Kubernetes Initial Access Vectors Part 2: Data Plane | Wiz Blog

Learn about Kubernetes data plane access, including applications running on the cluster, container images, and execution-as-a-service workload types.

0
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 6mo ago
Replying to
Sovereign by Design: Strategic Options for Canadian #AI #Sovereignty "Canada still has options to strengthen our capacity, reduce foreign leverage, build partnerships, and modernize our institutions. However, the time to act is short." #gcdigital #munkSchoolhttps://aicompetitiveness.ca/
aicompetitiveness.ca
0
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 3mo ago
Replying to
If you want to a #typescript version of #Breadthfirst #GraphQLhttps://github.com/gmac/graphql-breadth-js
GitHub

GitHub - gmac/graphql-breadth-js: A reference implementation of breadth-first GraphQL execution for JavaScript

A reference implementation of breadth-first GraphQL execution for JavaScript - gmac/graphql-breadth-js

0
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 7mo ago

" #eBPF was built to strengthen #Linux visibility and control. It succeeded, but that same capability has created new terrain for attackers. What began as an #observability framework has evolved into a critical security surface, one that defenders can no longer afford to ignore."

https://linuxsecurity.com/features/ebpf-abuse-linux-kernel-visibility-gap

infosec.exchange
0
0
2
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 7mo ago

The original #lakehouse paper:

Lakehouse: A New Generation of Open Platforms that Unify
#Data Warehousing and Advanced Analytics

https://www.cidrdb.org/cidr2021/papers/cidr2021_paper17.pdf

infosec.exchange
0
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 6mo ago

Capability based budgeting: "The point is that the capability—not the org chart or a system boundary—is the unit of planning and delivery."

#gcdigital

https://www.niskanencenter.org/federal-it-budgeting-capability/

infosec.exchange
0
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 6mo ago

#Grafast 1.0 is finally out. This is a reworking of the #graphql execution model to be breadth-first, batched, plan-based. It looks great.

https://grafast.org/news/2026-03-24-v1-released

infosec.exchange
0
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 6mo ago

Exploring #wasm lately and finding #wasmcloud kinda fascinating.

They're orchestrating wasm modules on #Kubernetes with #nats as the control plane. A really interesting project that just hit 2.0.

https://wasmcloud.com/blog/wasmcloud-v2-is-here/

infosec.exchange
0
0
1
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 6mo ago

VM-Class Secure, Millisecond-Fast Cloud-Native Apps With #Hyperlight + #Nanvix

https://www.youtube.com/watch?v=uA8WitzWeN4

0
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 2mo ago
US #DoW suspends the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements: "We will not defeat our adversaries with compliance checklists; we will defeat them by rapidly fielding superior capabilities produced by an expanded, resilient American industrial base." #CMMChttps://federalnewsnetwork.com/wp-content/uploads/2026/07/CIO-CMMC-Reform-Memo_26-P-1023.pdf
federalnewsnetwork.com
0
1
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 2mo ago
Is there a #systems term for the state where an organization is spending the majority of it's time on second or third order consequences of it's systems instead of pursuing it's original purpose? I think most programmers would describe this as spending your time "firefighting" but it doesn't really capture the idea.
0
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 2mo ago
Love this line. The article is about design, but this rings true for privacy, security, compliance, enterprise architecture, governance and so many more "They have learned the language of strategy without the discomfort of owning outcomes. They can talk about user needs, business goals, systems thinking, and product quality, but struggle when asked to make a call. They want influence, but not the exposure that comes with it." #gcdigitalhttps://www.smashingmagazine.com/2026/07/bull-and-bear-case-digital-design-age-ai/
smashingmagazine.com
0
0
0
0
Open post
Mike Williamson @sleepycat@infosec.exchange
· 2mo ago
Nice bit of storytelling about the history of #TLS and the CA forum. https://youtu.be/-9KiLFr8_hI?si=Rdf27a96oBwk_fh2
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:43:55 UTC