Andrew 🌻 Brandt 🐇
Words published here do not necessarily reflect views of my employer or any other organization I am affiliated with.
Research and analysis about malware, network forensics, and the intersection of crime with anything that electrons or photons flow through.
Board member of World Cyber Health, the parent organization behind Malware Village and the NO-HAVOC project.
Docent of obsolete technology at @mediaarchaeologylab@post.lurk.org
Executive director, Elect More Hackers: electmorehackers.com
"By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges." -- Cory Doctorow
I have an all-hands-on-deck call to action today.
At what point do we stop owning the things we buy, and just rent everything?
That's the #enshittification problem that the #RightToRepair movement is trying to address.
In Colorado, where we finally (just 3 months ago!) saw the nascent first awakening of a new right to repair law come in to effect, that infant could end up smothered in its crib this week, as the Colorado senate considers a bill that would roll back the right to repair for any device considered "critical infrastructure" - and yes, it is that vague in its wording.
If you care about whether we get to control and use (to whatever purpose we see fit) the things we buy -- including commercial servers, firewalls, routers, or other electronic gear -- then please consider signing on to this petition urging the Colorado legislature to reject the fearmongering and bad-faith arguments of the tech industry, who are making a desperate attempt to protect the long term revenue stream of support contracts.
Don't get angry; Get active. We can win this one with reasoned arguments. Please ask the Colorado legislature to not give in to FUD, and embrace Coloradans' resiliency and willingness to fight the good fight.
Sign the petition here:
https://pirg.org/colorado/take-action/tell-your-senator-protect-colorados-right-to-repair-law/
Two #Boulder residents have filed a lawsuit against the city of Boulder to challenge the city's agreement to run 31 #Flock cameras.
The lawsuit was filed almost at the same time as a new task force, convened by the city manager, had its inaugural meeting.
I am one of the members of this new task force, charged with producing a report on how the city can be more responsible in the way they adopt and use emerging technology. Other members include the CEO of an AI startup, IT specialists and professors from the university, legal experts, and other community members with related technology expertise.
The task force will meet every 6 weeks for the next year. I will provide updates as the group performs its work. The next meeting is July 15th.
https://coloradosun.com/2026/05/28/lawsuit-boulder-police-flock-cameras/
https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/
Google just XKCD 927ed their threat actor nomenclature, just because.
Surely this will speed up response time, because whenever I think about the country of Iran, I always immediately think of the word "ION" 🙄
It's like the result of someone's Rorschach test was used to justify the release of a new naming convention.
Shot...chaser
🚨 Current update on the Colorado bill (SB26-090) that would rescind "right to repair" for "critical infrastructure" 🚨
Please share widely.
The bill is currently scheduled for "third reading (final passage)" in the Colorado senate for Monday, April 13, first thing in the morning. If you have delayed until now doing something, this is your moment to act. You do not need to be a Colorado, or even a US resident, to speak up!
https://leg.colorado.gov/agenda/floor/202604132
Paul Roberts (secure-resilient.org) is putting together a list of people willing to be signatories to a letter opposing this bill. Please reach out to him if you want to sign on to that letter.
Wayne Seltzer, who runs the Boulder U-fix-it Clinic, shared a link to this petition/letter to legislators: https://actionnetwork.org/letters/support-your-right-to-repair-in-colorado
Danny Katz of CO PIRG is running a petition drive to send messages to the legislature. Petition link: https://pirg.org/colorado/take-action/tell-your-senator-protect-colorados-right-to-repair-law/
Finally, and this is important, rep. Brianna Titone (the author of the original 2024 right to repair bill) informed me that some of the advocates for right to repair who have been writing to legislators have been threatening or offensive in their language they used in their messages. This is unhelpful and will not persuade lawmakers to change their minds, so please try to encourage others to remember that these legislators -- who are on the fence -- can be persuaded, and are not (necessarily) inherently evil or corrupt, and just lack understanding.Talk/write to them with that frame of mind.
Thank you!
https://leg.colorado.gov/bills/SB26-090
#COpolitics #Boulder #legislation #RightToRepair #SB26090 #Colorado #CriticalInfrastructure #activism #engagement #TechPollicy #policy #ElectMoreHackers #InfoSec #malware #cybersecurity
Watch out for the people cosplaying temu surveillance Elvis Costello. https://www.eff.org/deeplinks/2026/06/move-fast-surveil-things
RE: @threatresearch@infosec.exchange
Current update on SB26-090 (Colorado's misguided "wrong to repair" bill):
After spending a bunch of the senate session on Tuesday in debate over a bunch of amendments, the bill is tentatively on the calendar for tomorrow, again, to have its third reading in the senate.
Please keep up the pressure - Coloradans and the rest of the country rely on being able to fix broken things in order to protect them from cyberattack. The repair is not the problem here.
https://leg.colorado.gov/agenda/floor/202604162
https://leg.colorado.gov/bills/sb26-090
#COpolitics #Boulder #legislation #RightToRepair #SB26090 #Colorado #CriticalInfrastructure #activism #engagement #TechPollicy #policy #ElectMoreHackers #InfoSec #malware #cybersecurity
#Boulder Daily Camera, October 27, 1897: a list of political parties competing on the November ballot.
Note the iconography used for the political parties, and the number of different parties represented on the ballot: ten.
The Democratic party symbol is a strutting rooster (!) and the Republican symbol is an eagle clutching olive branches but standing on top of a shield laying on the ground. Truly bizarre.
RE: @bsidesboulder@infosec.exchange
GET TICKET NOW!
Happy Electronic Warfare Remembrance Day to all the Russian APTs who celebrate
https://vpk.name/en/851572_electronic-warfare-specialists-day-in-russia.html
RE: @threatresearch@infosec.exchange
The SB26-090 hearing is underway. Live stream is https://sg001-harmony.sliq.net/00327/Harmony/en/PowerBrowser/PowerBrowserV2/20260427/33/18751
@cR0w@infosec.exchange Thank you for your service!

