HN user

dogman144

3,122 karma
Posts2
Comments984
View on HN

I’ve been in security for a while and I increasingly think understanding what the future looks like under this threat model is about the only security research that really matters fully above the rest (many topics also very important in their own ways).

The state change is just so significant and so under discussed because you learn about it via making an effort in a cybersec career, hitting conferences very years, eventually lucking out with who you met for a beer, and so on.

So how do policy leaders trying to understand this stand a chance at understanding it? How do local PD chiefs understand what they’re bringing in, who I really do believe deserve the benefit of the doubt wrt positive intentions?

There is really no counter-voice to an incredibly capable nationwide surveillance network that’s been around for at least 10-15 years. The EFF doesn’t really count because the EFF complains about these things, SEN Wyden writes a memo, and that seems to be the accepted scope of the work..

Just like man… the bill of rights… it’s a thing! Insane technology.

Was fortunate to talk to a security lead who built the data-driven policing network for a major American city that was an early adopter. ALPR vendors like Flock either heavily augment and/or anchor the tech setups.

What was notable to me is the following, and it’s why I think a career spent on either security researching, or going to law school and suing, these vendors into the ground over 20 years would be the ultimate act of civil service:

1. It’s not just Flock cams. It’s the data eng into these networks - 18 wheeler feed cams, flock cams, retail user nest cams, traffic cams, ISP data sales

2. All in one hub, all searchable by your local PD and also the local PD across state lines who doesn’t like your abortion/marijuana/gun/whatever laws, and relying on:

3. The PD to setup and maintain proper RBAC in a nationwide surveillance network that is 100%, for sure, no doubt about it (wait how did that Texas cop track the abortion into Indiana/Illinois…?), configured for least privilege.

4. Or if the PD doesn’t want flock in town, they reinstall cameras against the ruling (Illinois iirc?) or just say “we have the feeds for the DoT cameras in/out of town and the truckers through town so might as well have control over it, PD!”

Layer the above with the current trend in the US, and 2025 model Nissan uploading stop-by-stop geolocation and telematics to cloud (then, sold into flock? Does even knowing for sure if it does or doesn’t even matter?)

Very bad line of companies. Again all is from primary sources who helped implement it over the years. If you spend enough time at cybersecurity conferences you’ll meet people with these jobs.

Understanding crypto from this type of international context focused on these sorts of issues is where it indisputably makes much sense and is seeing indisputable adoption. Low and slow but end of the day to a very large and growing problem, bitcoin+ adoption or a mass civics readjustment in the US are the solutions. Which is more likely?

So it’s an inefficient tech with a mess of problems and uneven adoption but if you want to send $1-$1mm anywhere in the globe you can. That’s very powerful tech and the implications are about as important as anything else from cryptography hitting public adoption. And all of those have been consequential.. see 30 year fight about e2ee.

If you work in cybersecurity, I’d table many views in this thread and just understand it’s the place to be to cut your teeth in fairly hard security problems and make money along the way. If 1980’s security culture seemed cool with a new BoF everyday and Bill Gates himself calling you a bad word for doing it, and toss in advanced threat actors, a sec career in crypto isn’t too far off of that. Of course company by company variations apply and the above could include explaining EDR to small teams with absurds amounts of funds tied to a private key in a .txt.

That said, much of the feedback in this thread applies to working in it imo, as the other side of keeping these companies and their treasuries not hacked and capitalized is it exposes you to a lot.

That said, I’ve done big tech too, and the nonsense in crypto just has a couple less rungs of management insulation than the rest of tech. The rest of tech lives with the consequences of asinine decisions over 4-5x quarters and in crypto you live with it month to month. Pick your poison on preferred version of nonsensical tech instability.

There’s a twitter comment that covers what I’ve come to think - natural state of crypto is just a more direct instantiation of what’s going on everywhere else, crypto just doesn’t hide it (sort of). Hard not to believe that with tech selling “trade in your IRA!” as if that’s not offering a beer to my 20 yr sober Uncle Bob, in terms of products that are cancerous for “the people.” So I see nothing in crypto that’s not reflected everywhere in tech and civics right now.

The crypto tech or integrations to pay attention to - btc, atomic swaps cross-chain, trading firms, whatever finserv is testing for payment and settlement infra. All of these have deep building, are functional and funded. Wouldn’t bet against it over a career.

Haha very important disclaimer there, because reading your post sounds a lot like a person who works for big ag.

The other reason these laws exist is a long history by Big Ag (Monsanto, Cargill) doing the following, and has been done in the states for a while:

1) gmo/patented seeds in field on the left, community non-big ag seeds on the right field.

2) Cross-pollination occurs because we’re talking crops. Variations on this.

3) Monsanto sues Farmer John and Jane into the ground next season for stealing tech via the crops he’s growing.

Add in a little bit of fear (encryption backdoors for the children, laws to prevent dangerous counterfeit seeds!), and you have monopoly on farming run by big corps.

Also, US corps have a long history of POC’ing underhanded approaches in Africa.

What could be going on here!?

Edit - Man, rereading, “forced to plant [dangerous] saved seeds,” guess it’s Big Ag + tech startups now pushing this. Maybe… those farmers just want to control their “IP” (saved seeds) so they don’t have to buy them from a cartel of seed providers? This is such a well known problem in the states, is this marketing really working in Africa?

Final edit on the soapbox - other reason why this matters is genetic diversity. Crop blight is a thing. There is no way the natural “herd immunity” of a basket of seed variants in a community is outstripped in effectiveness by a growing monoculture of owned hybrid seeds that stay in front of the blights each season. Coffee rust already jumped the Atlantic from Africa to SA. Often feels like I’ve read this sci-fi novel already (there is a good one - Windup Girl).

Not a great post, I’d not follow it if interested in leading teams long term.

A Self-admitted self taught manager learns the good parts about servant leadership via self-learning (nice!) but figures that is all there is instead of - “this is interesting, this seems to work but have gaps, what is there to this?”

If the author did that, they’d discover a massive body of knowledge to include the specific problem they point out - you solve problems for your team, how do they start to solve their own problems?

Servant leadership works if paired with the following, tuned to the capabilities and maturities of the specific employee:

- servant leadership: resource your team, umbrella your team, let the smart people you hired do smart things, or turn so so employees into great ones by resourcing them to learn, getting them mentorship, and “sun is strong than cold wind” sort of thinking.

- Left/right limits and target outcome: consistently inform your team their duty, in exchange for all the above manager work that’s way past the least-effort bar, is to get comfortable solving problems within the bounds of what the solution does and does not need to look like. Force this issue always, and they start solving their own problems at growing speed, and you have a QA check as a manager via documenting those boundaries per project etc

- train your replacement: part serving your team is reaching there’s probably another sociopath on it who wants to lead teams, wants raw power, and so on. Enable that! Teach them how to lead teams in the above fashion. They’ll realize it works. You’ll train someone who can take over the remaining problem solving. This won’t hurt your own job either.

Put it all together you’ll get very loyal productive teams of employees who’ll respect you outside of work in your industry where it matters for networking purposes, and you can live with yourself after the laptop closes as you know you’re treating your fellow man/woman the right way while surving in crazy corporate environments.

In short, bad advice in that article. There’s a whole corpus to leadership beyond what the author figured out in the side and describes here ha.

Edit - ironically the author then argues for arguably similar as the above, but claims it’s something else of their own invention. Engineers should really grok how there are existing bodies of very useful knowledge for all the things that seem easily dismissible as gaps or weak points from tho social sciences. It’d save them a lot of time.

What am I missing? Risk acceptance is what you’re referring to - risk creation and reward creation.

Sec lead might have a pretty darn clear idea of an out of whack creation of risk v reward. CEO disagrees. Risk accept and move on.

When you’re technical and eventually realize there’s a business to survive behind the tech skills, this is the stuff you learn how to do.

People “will know” as you say because it’s all documented and professionally escalated.

Servant leadership works just fine in business (as in a competitive non-church environment) as long you’re aware you you’re serving and who you’re working peer to peer with/against/whatever.

Another term for it somewhat is being a “players coach.”

End state is you will build loyal as heck teams with it, and if you want to take a very cynical business mindset, it produces with the least pain and suffering three very impotent outcomes - your team will produce output, they won’t hate you along the way, and your team will write you (well earned) manager perf reviews. A manager who has a loyal as heck team up and down the stack builds unique odds of corporate survival.

All it takes is a little EQ.

Assuming a 101 security program past the quality bar, there are a number of reason why this can still happen at companies.

Summarized as - security is about risk acceptance, not removal. There’s massive business pressure to risk accept AI. Risk acceptance usually means some sort of supplemental control that’s not the ideal but manages. There are very little of these with AI tools however - small vendors, they’re not really service accounts but IMO best way to monitor them probably is that, integrations are easy, eng companies hate devs losing admin of some kind but if you have that random AI on endpoints becomes very likely.

I’m ignoring a lot of nuance but solid sec program blown open by LLM vendors is going to be common, let alone bad sec programs. Many sec teams I think are just waiting for the other shoe to drop for some evidentiary support while managing heavy pressure to go full bore AI integration until then.

Manipulating this for creative accounting seems to be the root of Michael Burry’s argument, although I’m not fluent enough in his figures to map here. But, commenting that it interesting to see IBM argue a similar case (somewhat), or comments ITT hitting the same known facts, in light of Nvidia’s counterpoints to him.

Why is that the problem for above the legal speed limit drivers?

A slow fleet of Waymo’s will impact your average 5-10 over same as your 20 over, and that’ll collectively impact traffic.

The implicit assumption you and many other in tech share is humans must adapt to the tech protocol, and not the other way around.

After 20 years of growing negative externalities from this general approach, which I see baked into your comment - are we seriously about to let this occur all over again with a new version of tech?

Fool me once, fool me twice… I think we’re at fool me 10 times and do it again in terms of civic trust of tech in its spaces.

Cadillac Desert, Marc Reisner, worth a read!

Salton sea features heavily, and you’ll learn the whole American West is on as fragile a water setup with similar health, civil and economic problems to follow as what this Salton sea example, but imagine it applying LA-wide, central Oregon-wide, Salt Lake valley-wide.

Water issues out west will be a major issue of USA’s next 70 years. Very scary stuff.

I think a lot of tech needs to go through that struggle.

From the perspective of a long career in infosec, what’s occurring now was enabled a longtime ago by broad-based industry consensus. Concerns then, which == awful stuff occurring now, were robustly dismissed by many many many devs with s/strong viewpoints/paychecks.

The only silver lining I can see is we’re taking our medicine now, but there’s a lot more to go through still, on the back of many significant tech capabilities.

For example, Flock was kept out of many cities, but Amazon was not, Flock just signed a data sharing deal with Ring. That’s a no-nonsense, nationwide, warrantless vehicular and pedestrian tracking network mechanism.

Not great, Bob! But RSUs for building it all sure was great.

Reads like they’re doing one of several way to get mobile device IDs, and then x-ref those against anon’d adtech datasets that anchor on the mobile ID.

If your device privacy is a mess, mobile ID links you to all the good and bad things you do on a phone.

Had no idea this was part of the tool options, but backbone cell network makes sense.

Other TTPs I’d read about was variations on geo-fenced adserving to phish a mobile ID basically via user interaction or scroll past the ad. Small enough geofence and do it a few times, one could safely figure out the user being the ID. Googling “RTB surveillance” or “DSP surveillance” are ways into the topic.

Scary stuff! Pair that with this tech has been working for years, and is international. Frames a bit differently every action by a public figure - also at risk via the same threat model.

Also long have wondered what data analysis like this is done on technical forums… ran by a VC firm… with a lot of insider context (product market fit?) in the comments.

My very loose sense on this was developed after a lot of perspective shifts via fortunately living in a lot of different spots in the US.

I think these small orgs are still around, are needed and I wish they were easier to find, but feels like finding them filters through:

- If it’s useful, it involves coastal tech people so to speak, and you can wade through many unknown gates to include “community” that’s actually sponsored marketing: often seems to be small group digital communities on Signal with shared thematic backgrounds of the members. Pair these with meeting people IRL when you can via travel and find time, it’s quite a useful network that’s all built digitally at first.

- If it’s fulfilling but low stakes, and peer-oriented: a lot of this is in infosec still via hacker culture, but overall I think you have to get outside of your economic class and bubble to find it generally, esp if you’re a tech person. In tech and similar careers, every “small group dinner” under the hood feels like 6-7 men making $550tc and trying to hit 650tc, or a group trying to attract those people. Dodgeball league for young professionals or not, career management feels very often in the background. It doesn’t feel authentic, or at least feel safe, because it likely isn’t.

Groups of people still do go fishing together, hiking together, cities sponsor makerspaces, community centers offer wood working classes, small group s get together to dicusss ideas, people have standing brunches… but it’s really hard to find this stuff in authentic contexts if first you’re not looking for it over some time, second you can’t suffer through being into the things you’re into alone, until you find someone doing the same, and third *if you city or area doesn’t have a moat to keep out, or at bay, modern, massively networked economies and what I think it tends to incentivize - the small org is in the cheap but functional community center, that is sponsored by a city that cares about it, that is advertised via the community radio station, that is in a city not under water by angry people at the exploding CoL…

I found 1 city out of 6-7 that still offers the latter input, and it to me feels is the lynchpin.

Still going, and we can call the guy keeping it going by his public records name - Fred Eshelman, pharma wealthy North Carolinian owns the notoriously checkerboarded Elk Mountain in Wy, which if you ever drive I80 past Laramie Wy it’s the big mountain on the south side going west.

owns 6000 acres of checkerboard land that’s effectively 20,000 acres with a notorious ranch manager.

Lost his case in Fed courts in Wyoming and on appeal, trying to do Supreme Court now.

Wyofile has consistently good coverage on this.

Have lived next to 2-3x reservations myself.

If the worst thing you can say to prove a point is “they have fantastic equipment,” well arguably they could be owed some good equipment in exchange for the total culture, socioeconomic collapse. And fantastic equipment tends to produce less waste.

That’s also ignoring we’re talking salmon run numbers and you’re talking excess at the hatchery. There’s no issues at the hatchery, they can sudo user their way into more fish at that stage. What’s at obvious issue is what happens to the fish when they’re out there and growing and then coming back to spawn.

Also interesting how you can laser in on the natives and ignore… all of the dams in WA, Or, Cali and their documented 50 yr+ impact on west coast salmon.

Like I said, have lived next to rezs myself. The coded language from WA, Idaho, MT, WY non-natives tends to be anything but coded.

The counterinsurgency lessonz of note from a doctrinal standpoint have little to do with how you framed it and I recall it. So before we go in on Total War is the Best War, your framing feels convenient vs actually thought out.

How to do counterinsurgency, as I ran into it from the “what works” angle in the formal setting to learn these things.

- the Malaya/British example. Notably Britain doesn’t run Malaya anymore and that country doesn’t exist. This is the direction you’re arguing works fwiw

- COIN and Patraeus (sp), assuming conditions were correct across the board and you could get a unit commander and all related stakeholders to try it. Notably we didn’t “win the insurgency” in Afghanistan

So there are both well established COIN case studies, one heavy and one light, both didn’t work, and no overlap with what you’re arguing.

Well the detesting trawling angle is valid but similar to how you could detect coal mining in West Virginia the mountains/sea bottom is gone either way.

I believe the single most important policy change for fishiers would be to end trawling, second being sort out international regs.

Both very hard, both bad news for kings. But at some point people are going to see the outcomes in their grocery stores and maybe that’ll start change.

Yes, the river system of about 10 others that the US successfully dammed up in the hot passion of 1950’s engineering culture run wild and successfully more or less ended the salmon runs south of British Columbia?

Yes, definitely the fishing patterns from tribes, not the 10-15 concrete dams.

Rich comment, but a an old one.

Global warming is playing out in AK in a way only as observable down south with perhaps the dwindling skiing and the colo river. Wrapping that all up into how you phrased it is pretty darn close to the ol “greedy undisciplined Native” trope.

But sure, blame the tribes, and make sure it’s done extra strongly on the next sport fishing trip in Ak that can’t offer Kings as you’ll be seen as very aware of the issues by your guide.

That should be the takeaway, paired with if you ever make a startup avoid “military grade” marketing as you’ll eventually sell to a vet who thinks it’s quite humorous.

The other takeaway is tech used to target insurgents is now getting American citizen data.