Elektrine lite

← Feed

@tychotithonus@infosec.exchange

Post #4374421

2026-08-04 11:37 UTC

We are living through the AI-accelerated death of security through obscurity. Which is forcing us to learn what turns out to have always been the true definition of obscurity: every possible variant of obscurity, whether deliberate or accidental. Every gap between our theoretical or practical understanding of a security model ... and its underlying reality. The maximum worst-case impact of every scrap of potential technical debt ... now has a looming balloon payment. Only the "assume everything is broken" model -- designing, monitoring, and prepping for incidents accordingly, and demolishing anything (technical, cultural, organizational) that blocks risk reduction -- seems likely to prove the only long-term mitigation strategy. The "undue diligence" (in my long-time catchphrase) is becoming due ... and coming due.

Replies (2)

  • Posited corollary: @wendynather@infosec.exchange's "security poverty line" has always had a companion threshold: a "security realism poverty line", the divide between organizations that have the political will to mercilessly and constantly reduce the gap between what they think is true (or want to be true, or have budgeted to be true) and what is actually true ... and those that don't, whether due to budget or competence or competing incentives. And the AI-accelerated death of security through all-cause obscurity (described above) is magnifying the gap on either side of that line. Sinclair's "It is difficult to get a man to understand something when his salary depends on his not understanding it" ... is an existential security threat that will now more rapidly metastasize if left unchecked.

    Open ##4374420

  • @fuzztech@infosec.exchange 2026-08-04 14:07

    @tychotithonus@infosec.exchange Could not agree more.

    Open ##4389659