Leadership

Anything you can do, we can do worse!

‘On July 21, OpenAI disclosed that several of their models had broken out of an isolated test environment by exploiting a previously unknown (“zero-day”) vulnerability.’

But wait, it appears if one AI LAB having terrible security practices isn’t enough, we have another one now saying, after the Open AI incident, they have actually reviewed their logs, and they are terrible at security too!

Read more “Anything you can do, we can do worse!”
Research

Email and Domain Security

Ok, this is a topic I’ve looked at for years, my views have been built up based on a range of things from the theory, the reality of what I find/see and the incidents I respond to and hear about.

I’ve used Claude largely for this because it’s meant as a quick snapshot in time and a high level thematic view. SPF, DMARC, MTA-STS and DNSSEC (and DNS/Domain management in general) are complex topics and there’s lots of nuance in things.

That said, who wants to see what ‘scanning’ 1 million domains looks like? Let’s take a look at what Claude has come up with:

Read more “Email and Domain Security”