Elektrine lite

← Feed

Haroon Meer

haroonmeer@infosec.exchange

<p>Security Geek at Thinkst. We build <a href="https://canary.tools" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">canary.tools</span><span class="invisible"></span></a> (he/him)</p>

Posts

  • View post

    RE: https://mastodon.social/@campuscodi/117054483452378870 You should absolutely watch this talk. 1) It is totally ok to not have a strong opinion 5 secs after it&#39;s done; 2) It&#39;s kinda great that the agents first created #hack &amp; it all went wrong from there; 3) http://canarytokens.org remains free - you should absolutely deploy tokens¹ __ ¹ not a gratuitous ad - tokens/deception are the only defensive measure the talk mentions.

  • View post

    I don’t know how Mandanis grocery stores will work out, but it _is_ kinda wild seeing the All-in/VCs clutching their pearls about unsustainable business models being made to look workable in the short term..

  • View post

    Chris Nolan (indirectly) weighs in on the raising vs bootstrapping debate: “You’re encouraged in a big movie to rapidly hire an enormous number of people... Then you have to feed that beast.” “If I can work a little cheaper than ppl expect.. they’ll let me do my thing”

  • View post

    An odd side effect of decades in infosec, is having visited Las Vegas more times than normal people would expect.

  • View post

    That no actual friend, or board of directors is able to tell Musk (in a week when both Tesla and SpaceX stock is crashing) that maybe he should park the culture-warrior, Gad-Saad BS.. is a strong reason to be careful investing in his companies.. Many mad-kings started sane..

  • View post

    There are many well-discussed upsides/downsides to building a company. One that&#39;s seldom discussed is the unexpected joy from something like a customer writing a ~2000 word &quot;love letter&quot; to the company. Hit me right in the feels. 10/10. Will recommend. https://infosec.exchange/@haroonmeer/116941632029750478

  • View post

    A writeup of @ThinkstCanary@mastodon.sdf.org (&amp; our other tools) 🤯🥲💚 &quot;this is my love letter to a company&quot; &quot;something rare in this industry: it made me feel good about detection again&quot; &quot;gave me back .. signal over noise, and something close to joy in the process.&quot; https://www.linkedin.com/pulse/little-bird-told-me-catching-intruders-thinkst-canary-kyle-goode-pdzcc/

  • View post

    Everyone is talking about the effect of Kimi on OpenAI and Anthropic, but imagine if you were a Space Exploration company that recently IPO&#39;d at a hugely inflated valuation based on your future AI/model dominance 🤯

  • View post

    The main problem that Docusign seems to have solved, was getting people over “wet signatures”. Technologists often slam Slack/Docusign/companies like this, but they’ve been life changing for me/us.

  • View post

    I think one of the most subtly damaging notions that was popularized over the past decade, was that of “imposter syndrome”. Lots of people quote “imposter syndrome” and “dunning-kruger” - but we’d be better off if we spotted our occurrences of the latter more the former.

  • View post

    People often spout lines about how better products don&#39;t win, &quot;X&quot; actually wins.. I&#39;ve seldom found this to be true.. Build better products..

  • View post

    If you built a company in the past decade you probably received advice from the Eric Ries classic: “The Lean Startup”. His new book, “Incorruptible” is more important. We’ve been told constantly how choices we made at @ThinkstCanary@mastodon.sdf.org are unique/non-repeatable. He shows otherwise. If you are building a cyber-startup, you should read this book. You will always be told that it’s too early to think about building a company that aims to do good (until you are told it’s too late)....

  • View post

    Niels Provos posting smart security stuff, Dave Aitel knows stuff he can’t share, Halvar exploring the current space, and people arguing loudly about disclosure ethics.. This could totally be 2002..

  • View post

    I’ve avoided saying it for a bit, but in a world where everyone can find/exploit everything easily - what you need more than ever, is knowing when serious attackers are exploring your “internals”. It’s where @ThinkstCanary shines.. __ ¹ for values of [everyone|internal]

  • View post

    Can we at least agree that anyone who did an ICO or tried to convince us that NFTs were a thing, shouldn’t be trusted with “crypto” market advice.

  • View post

    It sounds childish, but the weirdest part of how we seem to be marching towards wars &amp;amp; global uncertainty, is how unnecessary it seems 🤷‍♂️ (“Evil” sounds too judgmental, but) this seems like the stage we’ll later recall as “the banality of evil”

  • View post

    When we first showed up at BlackHat as unknown S Africans, we were kinda shellshocked (&amp;amp; awestruck) by it all. FX was one of the first people to pull us in &amp;amp; hung out with us. We kept in touch but not nearly as much as I should have. He will be missed. https://blog.recurity-labs.com/2026-03-02/Farewell_Felix

  • View post

    A common startup meme has been how shipping velocity trumps all. With people on the fringes “shipping” thousands of lines of code per day, it’s now “obvious” that startups should be adopting this new paradigm and just —yolo’ing it… Except maybe… not. Apple and google have long had (near)infinite dollars to hire ppl to generate thousands of lines of code per day… but great products are much more than just code velocity.. Run the idea maze.. build beautiful things.. org tempo matters, not klo...

  • View post

    Only just caught up with this older episode of “Inside the Network” with Michelle Zatlyn. Cloudflare impressively manages to keep shipping cool stuff despite their size, and she shares a bunch of down-to-earth, startup advice (even for non cyber-sec startups). https://pca.st/episode/9af0baa8-8907-4405-a362-22a7267c4186

  • View post

    RSAC was more subdued this year. Although the floor was plastered in AI, AI protection &amp;amp; Agentic*, everyone knows its a placeholder while we figure things out.. So it&amp;#39;s more performative than normal: Vendors act like they have the solutions &amp;amp; attendees act like they believe it

  • View post

    Important, business-critical need.. A sticker vendor aware of Apples corner radius..

  • View post

    A quick thought on RSAC (while flying home). On why the show floor keeps making promises it cant keep (and why Dave Aitel actually had a valid point¹). https://blog.thinkst.com/2026/03/rsac-infosec-themes-and-crumby-products.html __ ¹ All those years ago

  • View post

    We’ve always had a problem with least privilege, but users needed to be owned for it to visibly hurt the enterprise. Kevin didn’t know what to do with the extra creds, but his agent will. Maybe the first run of the “paperclip” problem will be agents wiping shares to save us..

  • View post

    For decades(?) we laughed at the hacker-news commenters who felt they could build Dropbox in a weekend. We knew that engineer was confusing the ability to write a POC with an actual enterprise-ready solution. AI now lets everyone be that engineer.