Sapere Aude - Dare to be wise
Updated August 25, 2026Have the courage to use your own understanding.
Have the courage to use your own understanding.
I cannot guarantee that you will never get hacked. But if you are looking to get hacked then I have some fantastic advice for you. Follow these 5 simple steps and there will be dozens of attackers pretending to be you in no time.
An oft-repeated mantra about building dependencies from source is misguided at best and fear-mongering at worst, and now companies are springing up to capitalize on that fear. Who can you trust?
We're often told not to put all our eggs in one basket. But information isn't eggs, and the basket might be the safest place for it.
LLMs are churning out "junior" developers faster than ever before. Fewer and fewer people understand the code that is shipping to production. Here are a handful of techniques to add guardrails to your environment before someone --dangerously-skip-permissions their way into a production incident.
The cybersecurity industry's product-centric model creates a market equilibrium that actively disincentivizes platform-level fixes, which would deliver far greater security improvement per dollar.
With the rise of the red team in cybersecurity, we also became more and more familiar with the term "blue team." In the context of cybersecurity, this term is typically reserved for folks who serve the incident response function. If the red team breaks into the organization, surely the blue team is the specific people responsible for responding to the break in, right? Well... I'm not so sure.
I cannot guarantee that you will run a successful team, but I can absolutely give you advice on how to fail. Should you choose to heed my advice, your red team will surely fail in stellar fashion.
We're faced with a neverending stream of decisions every day in an effort to secure our environments. Some decisions offer much higher leverage than others, and those are the ones you should focus on first, especially in a small organization.
Offensive security people seem to spend a lot of time debating simulation vs emulation. Hot take: It doesn't matter.