Discourse & Analysis
Stop the Silos and the OWASP Flip are worked out with time to prepare. These are the same underlying ideas, showing up live, unscripted, in conversation — proof the thinking is repeatable, not rehearsed.
The Same Root Cause, Three Industries Apart
"Reminds me of two things: the music industry's fight against P2P file-sharing, and blockchain. When Napster's central servers fell, decentralized networks emerged to avoid that single point of failure — and one later countermeasure was poisoning the network's trust from inside, which is basically what CrowdStrike just did here. Blockchain shows P2P doesn't have to be this vulnerable, though — cryptographic consensus means nodes verify each other instead of blindly trusting a peer list. Sality trusted its peer list; that's the exact gap exploited. Is that weakness inherent to decentralization, or a Sality-specific design flaw better-architected P2P networks have already solved?"
In reply to Gina Yacone, on the Sality botnet takedown — September 2026
The Core Principle, Restated Live
"'The system creating a change cannot be its own sole validator' tracks with a write-up I came across of your July talk at AI Engineer World's Fair — it cited LLM self-validation catching only around 50% of vulnerabilities across repeated runs, with a fairly low F1 score. If that's roughly right, self-validation isn't just architecturally risky, it's measurably unreliable. Curious whether 'independently executed tests the generating agent cannot alter' is closer to solved at Snyk specifically, or still mostly aspirational industry-wide."
In reply to Manoj Nair (CTO, Snyk) — September 2026
A Case Study, Reapplied on the Spot
"This maps almost exactly onto something I dug into with the Muleshoe, Texas water attack — Mandiant could only confirm a link between the persona claiming credit and prior Sandworm activity, but explicitly couldn't verify Sandworm was operationally involved in that specific attack. Most public reporting still said 'Russia-linked hackers did this' as settled fact anyway. Same gap you're describing: no confirmable evidence isn't the same as no involvement, and the public narrative usually moves faster than what the primary source actually supports."
In reply to Karla Reffold (Chief Insights Officer, Surefire Cyber) — September 2026
Behavior Over Composition, Independently Reached
"The AI 'ingredient list' idea is a real step forward, but the OpenAI and Anthropic incidents this summer both involved fully-documented, known models behaving unexpectedly once running. A complete ingredient list wouldn't have caught either one — the risk was in what the model did, not what it was. Continuous TPRM probably needs to track behavior over time, not just composition at a point in time."
In reply to Christina Cacioppo (Cofounder & CEO, Vanta) — September 2026