Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Andrew Kalat

@lerg@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Elder Nerd. Pilot, IT Security Leader, firearms instructor, speaker, author, photographer. Award-Losing Co-host of the Defensive Security and Getting Defensive Podcasts. Mostly posting about Infosec, Aviation, and cats.

711 Followers
80 Following
26 Posts
Joined November 04, 2022
Twitter:
https://twitter.com/Lerg
Defensive Security Podcast:
https://defensivesecurity.org/
Getting Defensive Podcast:
https://gettingdefensive.com/
Youtube Podcast feed::
https://www.youtube.com/@DefensivePodcasts
Open post
Andrew Kalat @lerg@infosec.exchange
· 5mo ago

So, Brian Armstrong, CEO of Coinbase, published a letter on X about his companies future and his planned layoffs.

You can find the full post here: https://x.com/brian_armstrong/status/2051616759145185723?s=20

So many folks, rightly so, have zeroed in on this sentence with serious angst:

"Non-technical teams are now shipping production code..."

I think this is the inevitable outcome of the past 30 years. First cloud, then SaaS, now vibe coding has moved IT ownership to the masses.

I don't think this is great for security, governance, or oversight, but it's AMAZING for CEOs and boards who just want to go fast and break things and "empower their people."

I'm not belittling "the masses." But they aren't technologists, by and large.

And what is being demanded of them by misguided leaders is to run some massively complex SaaS/Cloud/Coding tool that "Looks Easy Enough" but all of the devil is in the details that only hard core technologist would know or care about.

I believe this is why we have seen so many breaches based on misconfigurations and poor secret management and poor API/Token/Oauth management. The people making those design decisions aren't equipped with the skills to understand the consequences of their design choices.

They are marketing people, or sales people, or HR people, or whatever. They have other important skills, but we have forced IT onto them because leadership massively underestimates the complexity, risk, and specialized knowledge required to run it safely.

"I mean, how hard can a surgery robot be? You just push buttons right? Get the front desk guy to do it!"

This is inevitable, but stupid. Good luck to us all.

Brian Armstrong (@brian_armstrong) on X
X (formerly Twitter)

Brian Armstrong (@brian_armstrong) on X

This is an email I sent earlier today to all employees at Coinbase: Team, Today I’ve made the difficult decision to reduce the size of Coinbase by ~14%. I want to walk you through why we're doing this now, what it means for those affected, and how this positions us for the future. Why now Two fo…

121
39
90
6
Open post
Andrew Kalat @lerg@infosec.exchange
· 2mo ago
So. OpenAI was testing an advanced model and it escapes their sandbox and attacked Hugging Face. Lots to unpack. But this statement really rubs me the wrong way: “we are implementing strict controls in infrastructure configuration at the cost of research velocity” Oh noes! Not your precious research velocity. Look, your dog just got out and mauled some poor kid. And you are begrudging going to build a fence and then point out how selfless you are and how much it’ll inconvenience you. Arrogant and obnoxious tone. https://openai.com/index/hugging-face-model-evaluation-security-incident/
openai.com
16
2
9
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 5mo ago

Proof that occasionally @jerry@infosec.exchange and I are in the same room.

45
2
1
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 4mo ago

The next time your employer asks you to go the extra mile or work those extra hours or support “the family” just remember all the layoffs happening right now to people who did all of those things.

21
0
12
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 3mo ago
Replying to
@jerry@infosec.exchange
6
3
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 4mo ago

Stand by for news!

Okay, that's long enough. Now the news!

Today mark's my last day at Salesloft after nearly 5 years. It has been a very eventful time.
- Buyout by Private Equity
- 2 Mergers/Acquisitions
- 4 CEOs
- 7 Rounds of Layoffs
- Death of my mother
- Death of a beloved pet.
- Leadership role through a major security incident.
- Scaled a security team of 2 up to 8 and rebuilt the entire program from the ground up.

I can honestly say I learned a great deal working through all of these events. I had a great team who I will miss working with and who I owe all of our success too. I also saw some terrible leadership decisions and predictably terrible outcomes as a result. Wisdom generating events, as I like to call them.

So what's next? I'm going to take a bit of a break to try to get back to being the person I strive to be. Then I'm going to look for some new interesting adventures. Consulting, fractional work, part time, non-traditional engagements, or even full time work is all on the table. I am looking to find something that excites me again working with quality people. Life is too short to not be inspired by how we spend our precious limited time.

So if you find my particular mix of security skill and snark of use, please reach out!

10
1
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 11mo ago
46
0
25
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 2mo ago
GitHub AI Agent Leaks Data From Private Repo's #defensivesecuritypodcast
2
0
2
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 5mo ago
Replying to
@aburka Nope. I think good managers are force multipliers who do their best work by ensuring their people have the tools, air cover, priorities and time to do their jobs.
8
1
1
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 2mo ago
Did you know the Defensive Security Podcast now had a daily briefing? Jerry is putting out a 5 minute podcast every morning. Look for the "Daily Defsec Brief" in your podcast app of choice, or on our Youtube channel! @DefensivePodcasts@www.youtube.com
youtube.com
2
0
1
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 5mo ago

Executives bragging about coding again and shipping production code with AI because they can misses a huge massive point.

Is this really the BEST use of an executives limited time and mental energy?

Sure, it makes them feel productive and “in touch” but the role of a executive should be strategy, setting direction and priorities, hiring and mentoring their staff, holding teams accountable, and enabling their teams to be successful.

This is ego and shiny toy syndrome talking. It’s a distraction from critical high leverage work only they can do.

If you want to fast, go alone. If you want to go far, go together.

5
0
2
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 5mo ago
Replying to
@aburka I think 7 is a reasonable max for effective leadership who actually has time for their people.
4
3
1
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 5mo ago

I think we need to bring back https://en.wikipedia.org/wiki/Fucked_Company but now for companies that get fucked by their own AI usage.

en.wikipedia.org
4
1
1
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 4mo ago

I’m seeing a lot of companies say that they are measuring AI usage as a performance metric.

The assumption is AI usage == efficiency.

I think this is a poor metric. They should try to measure actual efficiency metrics, not tool use. See exhibit A:
https://arstechnica.com/ai/2026/05/amazon-employees-are-tokenmaxxing-due-to-pressure-to-use-ai-tools/

arstechnica.com
3
2
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 4mo ago
2
0
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 4mo ago

Tikaboo Peak, Legendary Area 51 Viewing Spot, Closed by U.S. Government https://theaviationist.com/2026/05/02/tikaboo-peak-area-51-spot-closed/

Tikaboo Peak, Legendary Area 51 Viewing Spot, Closed by U.S. Government
The Aviationist

Tikaboo Peak, Legendary Area 51 Viewing Spot, Closed by U.S. Government

From 1995 until now, Tikaboo Peak - 26 miles from Groom Lake - offered the closest and best public vantage point with a complete view of Area 51.  A

2
0
2
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 5mo ago
Replying to
@jerry Next stop: UL Listing for professionally built apps.
2
1
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 4mo ago
Russia’s New Two-Seat Su-57 Felon Takes Its First Flight
TWZ

Russia’s New Two-Seat Su-57 Felon Takes Its First Flight

Official imagery confirms that the two-seat Su-57D version of the Russian fighter has begun flight testing. Official imagery confirms that the two-seat Su-57D version of the Russian fighter has begun flight testing.

1
1
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 4mo ago

Y'all got any more of them security patches? | iOS 26.5 has fixes for 50 security issues on iPhone, details here https://9to5mac.com/2026/05/11/ios-26-5-has-fixes-for-50-security-issues-on-iphone-details-here/

iOS 26.5 has fixes for 50+ security issues on iPhone, details here - 9to5Mac
9to5Mac

iOS 26.5 has fixes for 50+ security issues on iPhone, details here - 9to5Mac

In addition to new features, Apple’s latest software updates also include security improvements, with over 50 fixes in iOS 26.5 alone.

1
0
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 5mo ago

3rd Row for Josh Gates Live. Popped for the meet and greet. We’re nerds.

0
0
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 3mo ago
Braves Sportsball for the 4th!
0
0
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 2mo ago
How many infosec vendor sales decks just got updated to say they would have protected Hugging Face?
0
1
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 2mo ago
This is really amazing. And also a good look at how far undersea drone imaging technology has come. https://www.bbc.com/news/articles/cdrvyllxj71o
bbc.com
0
0
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 2mo ago
True story.
0
1
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 3mo ago
Replying to
@free_amproot@infosec.exchange They will now! Brilliant.
0
0
0
0
Open post
Andrew Kalat @lerg@infosec.exchange
· 2mo ago
Replying to
@jerry@infosec.exchange Plant based Flashdance remake is well along I see.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 16:01:04 UTC