Content
Strategic insights on blockchain, AI, security, leadership, and career in an age of disruption.

AI Voice Phishing: Why Your Defenses Face the Wrong Direction
AI voice-cloning has fundamentally reversed phishing attacks—now criminals call employees impersonating trusted leaders, exploiting help desk processes instead of technical vulnerabilities.
Recent Essays

AI Homogenization: Why Differentiation Matters Now
As AI tools commoditize professional work, differentiation shifts from speed to unique perspective. Discover how to stand out when everyone has access to the same models.

Crypto Security Failures: It's Always the People
40% of crypto hacks exploit stolen private keys, not broken cryptography. The real security gap isn't the math—it's the humans and processes protecting it.

AI Agents & Hidden Web Instructions: Security Risk
Autonomous AI agents can be manipulated by hidden webpage instructions to make unauthorized payments. Learn how indirect prompt injection threatens enterprise automation.

Who Keeps the Interest? The Real Stablecoin Battle
Stablecoin competition isn't about technology—it's about who controls float income. Learn why Open USD's consortium model threatens Circle's $653M quarterly advantage.
#security
142 posts

Security Longreads — Issue #16
Dive into Security Longreads Issue #16, featuring in-depth analyses of recent security breaches, social engineering threats, and innovative exploits. Stay informed and ahead with these essential reads.

On 10 Weeks of Security Longreads
Discover the journey of creating the "Security Longreads" newsletter, exploring the challenges of curating in-depth security articles for both technical and mainstream audiences over the past 10 weeks.

Security Longreads — Issue
Dive into "Security Longreads," your weekly guide to must-read articles on information security and intriguing topics for security professionals. Explore digital vulnerabilities and offbeat insights today!

Updated for 2014: Online Classes for the Information Security Professional
Explore the latest online courses for information security professionals, featuring 11 top picks across computer security, in-depth topics, and InfoSec-related areas to enhance your cybersecurity skills.

Are Airline Kiosks The Next Fraud Vector?
Explore how airline kiosks might become the next target for credit card fraud, drawing parallels to the infamous Target breach. Learn about potential vulnerabilities and the implications for travelers.

4 Coursera Classes for the InfoSec Professional
Discover key Coursera classes for info security pros, including cryptography and risk management, along with unique offerings like equine nutrition, to broaden your skills and perspectives.
Why I Use Toto
If you scroll to the bottom of the page, the footer says "powered by toto." Toto is a minimalist blogging engine that runs on Ruby and is fully compatible with the Heroku platform.
Interviewing Security Professionals
I was reading a recent 37signals post about why they don't hire programmers based on puzzles or parlor tricks, and it got me wondering what strange tricks I played on the security professionals interviewing with me.
Write Down Your Passwords
The usual protocol when it comes to passwords is to create one that is hard to guess but easy to remember, because you shouldn't write it down. Yet I was still surprised to see a product specifically designed to write your passwords in.
Non Profit Wanted
Looking for a non-profit focused on helping other non-profits and charities with their information security issues, if you know of one.
A Refrigerator Has Never Been Hacked
Today's WSJ had an ad from the US Postal Service touting the security of a printed document over e-mail and the internet. Beyond the security of the printed letter, mail is great out-of-band communication with your customer.
Hacking Made Easier
NPR, along with a number of other media outlets, has been talking about new user-friendly hacking tools that let the average user be an elite hacker. I'm not an advocate for creating hacking tools, but I'd like to know what an attacker is going to use.