This Uber verdict really is going to destroy CISO positions. If one can brief legal, obtain approval by the CEO, & still be hung out to dry for response actions that a hundred other firms have likely taken with far less structural cover, then there can't be enough $$ to sign on
JD Work
20K posts
Former intel, now academic @NDU_CIC, @TheKrulakCenter, @SIWPSColumbia @ColumbiaSIPA, @CyberStatecraft, @ElliottSchoolGW, @PAISWarwick. Apolitical, views=own
Joined March 2017
- TFW you are passing through a border police checkpoint and the screen is merely showing โexploit.batโ. @ANSSI_FR may wish to look at network at CDG airport.
- Unconfirmed reports from ransomware continuing criminal enterprise that a major technology sector victim has executed reciprocal intrusion, encrypting threat actor's own infrastructure. Not the first private sector CCO if true, just rare example where adversary acknowledges
- A lot of cyber intel shops are in wartime ops tempo for the first time. Remember mandatory rest cycles. Keep in mind battlefield rhythms in combatants time zone, & across their reachback teams. Rotate folks that are up, & make sure formal handoff briefs happen. It gets worse yet
- The disclosure of SALT TYPHOON intrusions against US warranted access functions in telecom infrastructure is precisely the fulfillment of warning against mandated backdoors for merely administrative execution. We have known for over 15 years that this is a priority domestic
- The proper response to the execution of an American held hostage should be the immediate & unceasing lethal persistent targeting of those involved, & the leadership of the organization that claimed credit. At all levels, in any place. This is not some negotiated tally of
- I have been begging, tears in my eyes, for years that intelligence professionals need must remember that they are by mandate apolitical, as the objective sensing & sensemaking function of government. Those that abandoned this standard in recent years, & who are now publicly
- The uninitiated reacting to Linux mailing list exchanges, for the first time realizing that one of the most complex things ever built by human hands that drives their phone, entertainment, car, banking, medical care, food & retail, power, & water exists because one man
- Replying to @HostileSpectrumThe number of replies in this thread that fail to recognize the unprecedented nature of criminal charges for a dispute over the extent of incident disclosure, imposed retroactively, is precisely why future CISO candidates will be watching reactions to this case & walk away
- If a single corrupted driver can BSOD Windows this badly, there is likely some very interesting attack surface just below the rotten wood here. The amount of offensive cap dev investment surging into weaponizing this potential over this weekend alone is likely to be surprising.
- Replying to @mr_james_cBulterian jihad consequences. Mentat capacity becomes bottleneck to complex financial instruments. Otherwise calculating variables across interstellar distances and at generational time scales of an ossified feudalist empire becomes impossible.
- Thought experiment: If political speech is so harmful as to spur demands for censorship under EU DSA, then threat actors in response to these claims execute extrajudicial network attack to disrupt political speech in what is clearly a form of electoral interference & violation of




