Writes "Starting Up Security" @ scrty.io, tweets horror stories @badthingsdaily

Joined March 2009
59 Photos and videos
Ryan McGeehan retweeted
I strongly believe there are entire companies right now under heavy AI psychosis and its impossible to have rational conversations about it with them. I can't name any specific people because they include personal friends I deeply respect, but I worry about how this plays out. I lived through the great MTBF vs MTTR (mean-time-between-failure vs. mean-time-to-recovery) reckoning of infrastructure during the transition to cloud and cloud automation. All those arguments are rearing their ugly heads again but now its... the whole software development industry (maybe the whole world, really). It's frightening, because the psychosis folks operate under an almost absolute "MTTR is all you need" mentality: "its fine to ship bugs because the agents will fix them so quickly and at a scale humans can't do!" We learned in infrastructure that MTTR is great but you can't yeet resilient systems entirely. The main issue is I don't even know how to bring this up to people I know personally, because bringing this topic up leads to immediately dismissals like "no no, it has full test coverage" or "bug reports are going down" or something, which just don't paint the whole picture. We already learned this lesson once in infrastructure: you can automate yourself into a very resilient catastrophe machine. Systems can appear healthy by local metrics while globally becoming incomprehensible. Bug reports can go down while latent risk explodes. Test coverage can rise while semantic understanding falls. Changes happens so fast that nobody notices the underlying architecture decaying. I worry.
512
1,901
15,329
1,586,326
8 Oct 2025
I wish all security pros practiced a scenario-first mindset. Explanations based on risk scenarios before jumping to best practices, gaps, controls, compliance etc. I wrote an essay to coach on this: "Writing a risk scenario" medium.com/starting-up-secur…
2
1
5
537
17 Jul 2025
I wrote about that moment every security team faces when someone asks if they can work from China for a while, and then everyone freaks out. magoo.medium.com/the-working…
1
1
15
1,661
18 Nov 2024
Ramping up on bluesky 🦋: bsky.app/profile/mag00.bsky.…

1
509
2 Oct 2024
My "Starting Up Security" writing correlates to my caffeine intake which has dropped off over the last few years. Today I got tricked into an actual coffee, so drafts are open. Taking any requests, just DM ☕️
4
769
Ryan McGeehan retweeted
“Detection is a problem I describe as deceptively tractable.” @Magoo on 🔍 Prioritizing Detection Engineering Proposed implementation order: 1. Get logging in order, focusing on query-ability and minimum viable logs. 2. Spend time on hardening before formalizing detection. 3. Introduce high-quality detections and alerts, starting with a reference alert and focusing on invariants. 4. Address management challenges before scaling detection efforts. 5. Fully embrace an engineering approach to detection, with the ability to throttle or accelerate work as needed. medium.com/starting-up-secur…
2
17
1,588
17 Sep 2024
Malware (!!??!!) may have been the factor in an attack that blew up hundreds of Hezbollah Operatives pagers in an attack.
1
1
682
17 Sep 2024
I will be really surprised if these were not sabotaged before delivery somehow.
1
3
337
17 Sep 2024
335
14 Aug 2024
Should CVE-2024-38063 be more widely discussed? It's a zero click IPv6 RCE (????). Am I just not reading this right? Normally there's a of panic about ITW exploitation, exposed hosts, and wormability for a vuln like this. I gotta be missing something. msrc.microsoft.com/update-gu…

7
3
32
8,607
Ryan McGeehan retweeted
1/ Thrilled to announce we’ve raised $150mm Series C at a $2.45bn post valuation led by @sequoia alongside our existing investors @ycombinator, @CrowdStrike, @craft_ventures, @Atlassian, @Workday, and @HubSpot and new friends @GoldmanSachs and @jpmorgan. The terms on this round are exactly as we aim Vanta experiences to be: straightforward and clean.
82
48
828
281,161
30 May 2024
A good read on work imbalances in security orgs, a topic I have touched on often over the years. Adding some things to the discussion from my experiences working with teams. A short 🧵 /1 x.com/ramimacisabird/status/…

Asymmetric workloads are the double edged ⚔️ of force multipliers Security can add asymmetric costs on our orgs, just as our orgs can incur outsized costs on us I talk about this problem, with examples and tips for mitigating, over with @clintgibler tldrsec.com/p/dont-security-…
1
4
5
2,161
30 May 2024
In this essay, I suggest a model for security work that tries to wrap around and reduce toil from ops, incidents, and surprises from the business. This is just another way of looking at the overall work created by a security org, becoming efficient. medium.com/starting-up-secur…
1
1
2
572
30 May 2024
Offensive work, detection engineering, and compliance are especially common sources of painful imbalances. Easy to argue to include others too. My written commentary has mostly been on negative imbalances, but they can be framed positively too.
1
268