Profile avatar
coffeefueled.org
My book's great, go buy it: https://sbbooks.store/cybercircuit "...sartorially he’s what you’d get if The Doctor decided to park the Tardis and spend some time in cyber security." - Andrew Peck
119 posts 412 followers 543 following
Prolific Poster
Active Commenter

Heard about the NCSC paper on forgivable and unforgivable vulnerabilities? Join our walk and talk on the fuss with the brand new Boring On podcast, available on YouTube and most podcast platforms. youtu.be/vu3MUXDZkP4?...

Delighted and excited to announce that on the 15th of March I will be up in Lancaster to speak at LUHack's Hackademia 2025 event at Lancaster University. It's a talk that I think has been needed for a long time in the cyber security industry, "Stop Buying New Sh!t". #SiliconSnakeOil #MoneyPits

There are lots of things I've done and achieved that I'm quite proud of, but in this moment I'd struggle to name one that's given more of a feeling of triumph than successfully fixing the vacuum cleaner the night before we were going to take it to the repair cafe.

Scammers getting really lazy. Just had a phone call with a bad text-to-voice message. "I'm a recruiter from Indeed UK. We are interested in your resume but unable to contact you. Please write to us via WhatsApp." Ignoring other issues, phoning me to say you can't contact me is an odd move.

Oh I see. *Now* intellectual property matters. https://cointelegraph.com/news/microsoft-openai-probe-deepseek-improper-data-mining-bloomberg

Saw the crows on the walk around the lake today and said hello, then a heron spotted waiting to annoy the anglers.

www.forbes.com/sites/abigai...

On today's walk around the lake, after initial hesitation all three crows came down to collect monkey nuts. Progress is slow but steady.

Just had to buy a new batch of ISBNs for Security Blend Books with the upcoming publications (securityblendbooks.com). Ended up going with 100 rather than 10 because it's only just over twice as much, and 10 would leave no spares. So I guess I need to get more manuscripts in to review.

I wish this story was a joke. Not because the vulnerabilities they're talking about don't exist, but they're talking about the weakness of the BLE connection. The range of BLE is up to 100 metres. This is not a plausible threat. www.independent.co.uk/tech/sex-toy...

Giving away 100 copies of my book (book version) for 2025. The code will work for the first 100, or the end of January 1st 2025. https://securityblendbooks.com/discount/HAPPYNEWYEAR?redirect=%2Fproducts%2Fthe-cyber-circuit-1

Secret (sort of) project finished just in time for Christmas.

I have replaced my Fold with a separate phone and tablet. So I guess my weekend is going to be fine tuning the themes on both to match my laptop.

Today, the UK government announced a proposal to change copyright law - for the benefit of AI companies - that would cause huge, irreversible harm to creators. More info below, but most importantly here's what you can do (wherever you live): 1. Email your MP. Template letter in 🧵 👇 1/10

For a talk I'm working on, I need pictures of infosec and cyber security cats. Being herded is ideal, but general pictures and permission to use them in the talk is great (credit will be given unless requested otherwise).

People who will get snotty about someone anthropomorphising pets will talk about how an LLM 'decided' or 'thought' or 'said' things like it's a sapient entity instead of a fundamentally limited mathematical model.

My new toy making espressos available at the touch of a button may have been a mistake.

Anyone else noticing as the shine is wearing off the AI bubble, we're back to quantum computing making huge strides? The cycle of hype continues.

This is your official permission to go and build things and make them happen not because they'll make you a billionaire, but because they make you smile. Unrelated, meet my new haiku-writing professional networking badge.

The idea that the intelligence quotient is the only one that should matter leads nowhere good (others are emotional, social, and adversity). Sadly, we've ended up going that way, seemingly driven by men with big bank accounts and the most fragile egos.

Unjustifiable pleased with myself after unearthing the Badgers during unpacking and making a thing.

Asking an LLM to do maths is like asking a calculator to run spellchecker. It isn't what they're for, and they won't make a good job of it. LLMs have their uses. That's not one of them, nor should it be.

I have a couple of Badger 2040 e-ink badges and want to find a purpose for them. They've been sitting in a draw for *cough* years, still in their original packaging. I did think cocktail recipes, but with the industry's toxic relationship with alcohol I'm thinking maybe not. All ideas appreciated.

Apparently Musk wants to 'summon MPs to the US over their threats against him'. Those 'threats' are asking him to give evidence about disinformation spread via Twitter. I can't even imagine what it must be like to have an ego that fragile. There's no big plan, no 4D chess, just knee-jerk response.

When can we admit that the cyber security industry is very loosely, rarely, and only by coincidence related to securing anything? Is it too soon still?

Expedition to IKEA has faced difficulties but is near completion. Supplies are low but spirits high as door colours have been settled with a minimum of casualties. If I don't check in for a few days, send search party.

LinkedIn has finally found my weakness, and it's logic puzzles.

Speaking at Aviation Cyber Security on Wednesday about the weakest link, and this question's going to come up a lot. Should you always strengthen your weakest link? cybersenate.com/aviation-cyb...

Book signing today, and thinking I should have brought more along! Running a little low.