top of page
Search
The Best Security Controls Don't Feel Like Security
Security succeeds when it changes the environment, not the developer. For years, vulnerability management has followed a familiar pattern. A security scanner identifies an issue, a security engineer reviews the finding, a ticket is created, and eventually that ticket finds its way into a developer's backlog. If the issue isn't addressed quickly enough, we often conclude that the problem is prioritization, security culture, or a lack of developer awareness. I don't think that'
Jeremy Druin
Jul 184 min read
The Five Home Security Decisions That Matter Most
One of the most common cybersecurity questions I receive has nothing to do with corporate networks, cloud security, or penetration testing. Instead, it usually sounds something like this: "What should I do to protect my family online?" Friends, family members, and neighbors often assume the answer involves expensive software, complicated network equipment, or a deep understanding of cybersecurity. The reality is much simpler. Most successful cyberattacks do not succeed becaus
Jeremy Druin
Jun 273 min read
The Security Decision Nobody Can Make Correctly
In recent years, several high-profile intrusions have reportedly begun with a remarkably simple attack path: convincing a help desk employee to reset account credentials. What appears at first glance to be a failure of identity verification is often a much more interesting problem involving trust, uncertainty, and decision-making. The resulting breaches disrupted operations across organizations and became some of the most widely discussed examples of social engineering. The i
Jeremy Druin
Jun 155 min read
What Do Phone Phreaking and AI Prompt Injection Have in Common?
Phone phreaking, command injection, SQL injection, cross-site scripting, and prompt injection are generally treated as distinct classes of security vulnerabilities. The technologies involved span more than fifty years of computing history and operate in completely different environments. At first glance, they appear unrelated. A closer examination reveals a common architectural characteristic. In each case, untrusted users are able to communicate with a system's control plane
Jeremy Druin
Jun 34 min read
bottom of page
