The Infosec Diplomat, Absurdist Polymath. AI philosopher. Reality-Auditor. Hacker, Author @oreilly. Privacy, ethics, chaotic good

Joined July 2008
3,768 Photos and videos
Pinned Tweet
Data leeks are a major problem in #infosec
16
36
186
Hey, Max, look how cute my human is!
292
Risk from defunding #cybersecurity advice agencies (I’m not talking about the surveillance ones) is a threat to nearly everyone on the planet because global security #supplychain is volatile, at best @NCSC @ACSC @ASDGovAu @cybercentre_ca @ownyouronline @ncsc_nz @CISACyber #finalcyberstand
How I imagine @CISAgov @CISACyber for the past year
1
1
3
368
How I imagine @CISAgov @CISACyber for the past year
5
684
April C Wright retweeted
Replying to @imecge @ProtonMail
This tip for sending messages securely, I caveat, is for some of the truly, most paranoid people… Spy shit. This sounds like the same trope we all know (nothing is safe), but here’s the “intel agency real pro tip”: The reason steganography has been so popular for hundreds of years is that “hiding in plain sight” is sometimes better than looking like an outlier to an algorithm or to a human. I pose a paranoid challenge: Who do you think the police or AI are going to investigate harder from CCTV: 1) the person with the anti-surveillance mask, a hat with an LED, and anti-night vision reflective clothing? Or 2) the soccer mom with a stroller (which is actually full of ordinance and messages)? Not everything needs to be AES-900000 encrypted. Consider the dreidel and other low tech devices for communication and sharing secrets and ideas This likely does not apply to you or anyone you know today, but it’s worth noting for the record: Outliers get attention And I looove me some @ProtonPrivacy - I know exactly what encryption means for individuals and society. I believe in you! #Privacy is like, my whole thing. I’m just sayin’. “Spy shit” exists because nothing is infallible When you can’t trust *gestures vaguely at the entire world* anymore, we do what we have to do to communicate
1
2
298
April C Wright retweeted
Replying to @imecge @ProtonMail
You can use one of these services to share a secret separate from an encrypted string with someone How it works (either order) Send encrypted message via email or whatev Send the secret via a pastebin-like link The encrypted text and secret aren’t connected, unless you or your recipient’s end nodes is compromised onetimesecret.com Privnote.com privatebin.info If you will be sharing secrets regularly with this entity, use a password manager. They can basically all do this now. Pro tips (for the truly paranoid): Send the message and pastebin-like link with the secret more than a few minutes apart. This helps potentially limit correlation via an ISP compromise or similar (AI could otherwise easily think “this person send a link and an encrypted string immediately after, so they’re probably related!”) Use different VPNs / separate no-log VPN IPs to send both messages What NOT to do: Do not send a photo of the written secret (AI can read handwriting) Do not allow the pastebin link to be accessed by an end user more than once
3
1
4
347
It’s been 14 years and I STILL want to get off Mr Bones Wild Ride. But the ride never ends, does it… C’est la rollercoaster of life
On this day 14 years ago, an anonymous 4chan user posted a RollerCoaster Tycoon 2 thread showing a 30,696-foot coaster that took four in-game years to finish, complete with riders screaming “I want to get off Mr. Bones Wild Ride” and a looping exit where “the ride never ends.”
5
532
Anyone who says ADHD isn’t real is a liar …3 hours Enter a 1yo @LastWeekTonight about AI (10min remain) During which, I published a blog better explaining AI slop, analyzed cannibalism on the WALL-E Axiom… A 30 minute alleged “comedy” turned into hyperfocus / deep analysis, content generation for the greater good, and a dark understanding of earlier Pixar architectsecurity.org/2026/0…

1
275
And finally, the original story which made me question whether @LastWeekTonight fully understands “slop” vs “art” vs “disinformation”. Or just simplified it for the audience into a fun four letter word. youtube.com/watch?v=TWpg1Rmz…
189
Today we continue our #eli5AI series by explaining AI "slop" vs "AI art" What's the difference? Isn't all Ai output the same? In summary: No. architectsecurity.org/2026/0… (ELi5ai= explain it like i am 5: AI)
1
126
I spend like 30% of most days trying to actually make AI hallucinate on purpose Important and wonderful, but deeply weird work Sometimes it’s fun:
2
3
197
It’s important to use generative AI for stuff other than “writing less passive aggressive emails”
1
1
178
Enjoy #AndyWarhol but he’s a pangolin #generativeAiNonsense
1
132
#MFA is still broken, despite #Yubikey, #passkeys, QR codes for logins Perhaps especially via QR codes… Multiple login factor authentication in many ways has set forward security, but set back 10 years for usability/UX architectsecurity.org/2026/0… #infosec #cybersecurity @Yubico @1Password @dashlane @Apple #extensibility
2
1
412
Even I don’t want to scan a QR code with a 2nd device to login But let’s say I have Yubikey permanently inserted into USB (many ppl do), and my cat walks across the keyboard? Paw hits the port during a login prompt? The cat he has authenticated. This is a problem for security
130
I’ve invented 2 new #infosec paradigms I do not say this lightly MCD is published github.com/enc1pher/MCD_Maxi… When I came up with the “InfoSec color wheel”, I didn’t consider Ego My “universal trust architecture” (uta) seeks to strip ego from the workforce github.com/enc1pher/Universa…
2
2
244
Work in posting progress: github.com/enc1pher/Universa…

1
1
162