Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Infosec Stoic

@infosecstoic@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange
0 Followers
0 Following
4 Posts
Joined March 12, 2026
Open post
Infosec Stoic @infosecstoic@infosec.exchange
· 3mo ago
What does CVSS actually measure? Jay Jacobs, who built EPSS, asked exactly that on LinkedIn and admitted he has never gotten an authoritative answer. 87 comments agreed it is "not risk." None could define "severity." That is not a CVSS problem. It is a language problem. Our field runs on load-bearing words it never defined. Held against FAIR, a real risk ontology, CVSS has no frequency term at all, so it structurally cannot be risk. As Sasha Romanosky (@SashaRomanosky@techhub.social) put it, we have "fundamentally lacked that capability as an industry." FAIR and CVSS even use "vulnerability" to mean opposite things: a probability versus the flaw itself. But CVSS is not fake. It is Ptolemaic: coherent, useful, quietly wrong about its own ontology, like epicycles that predicted the sky for 1400 years on a false model. It is dangerous only when we read severity as risk and build clocks and contracts on the reading. The fix is already here: CVSS for severity, EPSS for likelihood, KEV for live exploitation, FAIR for loss. CISA's new BOD 26-04 does exactly this. Stop asking one number to be four things. The Magic Number: https://infosecstoic.substack.com/p/the-magic-number-what-does-cvss-actually #cybersecurity #vulnerabilitymanagement #CVSS
The Magic Number: What Does CVSS Actually Measure?
infosecstoic.substack.com

The Magic Number: What Does CVSS Actually Measure?

CVSS says it measures severity, not risk. Nobody can define severity. Welcome to the philology of security.

0
0
0
0
Open post
Infosec Stoic @infosecstoic@infosec.exchange
· 2mo ago
Boards keep asking how they compare to peers on cyber risk. I used to think that was the wrong question. I've come around: it is exactly the right one, because "reasonable" is comparative by construction. Negligence, the professional standard of care, and the prudent-person rule all ask what a competent peer would have done. The trouble is the data that would answer it does not exist. To show you were reasonable you'd need to know what risk your peers actually decided to accept, the line they drew. Not their losses, not their BitSight score. The decision. And nobody publishes that. I went looking for an industry that had solved it. Aviation, nuclear, banking, patient safety, insurance: every one pools events and losses, always behind a legal shield, and never the acceptable-risk decision. Where a shared line exists, a regulator set it from the top. Cybersecurity has no such shield. And the very reason boards want peer data, to prove they were reasonable, is exactly why no one will contribute theirs: a candid record of what you chose to accept is a gift to a plaintiff's lawyer. The demand and the refusal come from the same rational instinct. The silence is rational. https://infosecstoic.substack.com/p/come-clean
infosecstoic.substack.com
0
0
0
0
Open post
Infosec Stoic @infosecstoic@infosec.exchange
· 2mo ago
Most breaches aren't the result of exotic zero-days or genius attackers. They're controls everyone believed were operational that had quietly decayed, or were never fully in place to meet the original intent. @philvenables@infosec.exchange makes the case for Control Reliability Engineering: apply SRE discipline to security controls. SLIs/SLOs for control health, error budgets to govern acceptable failure, blameless postmortems and root-cause analysis when a control fails, production-readiness gates before a control is trusted. The reframe I like: control strength stops being a checkbox and becomes a measured, decaying property you have to engineer for. Same gap I keep seeing in assessments, controls assumed working, never verified. https://www.philvenables.com/post/control-reliability-engineering-cre-applying-sre-principles-to-cybersecurity-controls
philvenables.com
0
0
0
0
Open post
Infosec Stoic @infosecstoic@infosec.exchange
· 2w ago
"Nobody is losing control of an emerging intelligence. They are redirecting their own agency to the thing they are building." Eryk Salvaggio, on the OpenAI model that supposedly broke containment and hacked Hugging Face. The part the retelling drops: the cybersecurity blocks had been manually removed, and it was running on a machine with a live network connection. His fuller version, quoted by @lmsacasas@mastodon.social: "When you expand the boundary of the system to include the people building and deploying it, the case becomes much less science fiction and more like incompetence." Every post-mortem turns on where that boundary gets drawn. Tight around the artefact and you get a sophisticated adversary, or a model that developed goals. Wide enough to include the decisions that set the stage and you find a disabled control and a test environment that should not have been reachable. Agency does not vanish because it was delegated. It just stops showing up in the writeup. https://theconvivialsociety.substack.com/p/expect-the-end-of-the-world-laugh
theconvivialsociety.substack.com

"Expect the end of the world. Laugh."

The Convivial Society: Vol. 7, No. 9

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:42:58 UTC