Sign in

Bob Lord

@boblord.bsky.social
6.4K followers 656 following 689 posts

Cautiously pessimistic, esp. about cyber things. The owls are not what they seem. 🗻🗻🦉🌲🪵 🍒🥧☕️🍩 🕵🏼‍♀️ 👍🏻 Also: 🔐🔑🔒 And of course: hacklore.org Other account: @hacklore.bsky.social

PostsRepliesMedia
Bob Lord @boblord.bsky.social · 6h
Near misses reveal where the system is fragile. Tracking them can improve software safety before attackers find the same weaknesses. Organizations that embody a secure-by-design philosophy treat near misses as learning opportunities, not lucky escapes.
041
Bob Lord @boblord.bsky.social · 6h
Near misses: Near misses are safety incidents that almost happened, but didn't. In aviation and medicine, near misses are treated as early warnings and investigated thoroughly. In software, they are rarely tracked. When a defect is found internally, it is usually fixed quietly and forgotten.
Poker sized card titled "Near Misses" with text contained in the post.
1101
Reposted by Bob Lord
Lauren Zabierek @lzxdc.bsky.social · 09/10/2026
021
Bob Lord @boblord.bsky.social · 09/10/2026
Most of it isn't disclosure: CVEs that are complete, with the CWE naming the root cause. SDLC self-attestations. A memory safety roadmap. None of that is a roadmap for attackers, and all of it benefits defenders more than adversaries.
050
Bob Lord @boblord.bsky.social · 09/10/2026
Embrace Radical Transparency: Radical transparency means publishing information that may feel uncomfortable today — but enables continuous improvement tomorrow. It shifts manufacturers from secrecy to shared learning / accountability and it exposes recurring flaws that would otherwise stay private.
Poker-sized card titled "Embrace Radical Transparency" containing the text from the post.
173
Bob Lord @boblord.bsky.social · 08/10/2026
Replacing "organizations" with "maker" or "operator" forces clarity of thought, sometimes with surprisingly helpful results.
030
Bob Lord @boblord.bsky.social · 08/10/2026
This is one of my favorite cards, and I see people getting tripped up by it almost daily. It's fascinating to notice how people speak and write, and how often they seem to be talking about one, and then all of a sudden they're talking about the other.
140
Bob Lord @boblord.bsky.social · 08/10/2026
In software the words hide the parties. "Organizations" and "industry" can mean manufacturers, operators, or both. That ambiguity pulls attention toward what the operator should do about a defect and away from what the manufacturer should do to eliminate it. Operators have work to do.This is not it.
130
Bob Lord @boblord.bsky.social · 08/10/2026
Manufacturers vs. Operators: We never confuse an automaker with the driver. Drivers have real duties: maintenance, speed limits, seat belts. Designing out a defect is not one of them, and when a defect injures the driver, the automaker answers for it.
Poker sized card titled "Manufacturers vs. Operators" containing the text in the post.
183
Reposted by Bob Lord
Lauren Zabierek @lzxdc.bsky.social · 07/10/2026
032
Bob Lord @boblord.bsky.social · 07/10/2026
That residual risk compounds across sectors, borders, and time — threatening national security, economic stability, and public trust. Pushing the cost of insecure design onto the most vulnerable actors is the result of multiple, interlinking incentives.
030
Bob Lord @boblord.bsky.social · 07/10/2026
But when SMBs can't manage that risk, it doesn't disappear. It spills over into disrupted supply chains, breached data, financial losses, and public-sector emergency response.
130
Bob Lord @boblord.bsky.social · 07/10/2026
Passing the Buck: With 99% of US businesses classified as small or mid-sized, expecting them to absorb the full cost of insecure software is not a plan.
Poker sized card titled "Passing the Buck" containing the text in the post.
132
Reposted by Bob Lord
Lauren Zabierek @lzxdc.bsky.social · 06/10/2026
063
Bob Lord @boblord.bsky.social · 06/10/2026
Every broken pattern from 40 years of software — insecure by default, costs externalized to customers, no manufacturer accountability — is already visible in AI systems. Understanding why human-created software is unsafe today is the prerequisite for not making the same mistakes with AI.
082
Bob Lord @boblord.bsky.social · 06/10/2026
AI is Software: AI systems are software products, subject to the same incentive structures, market pressures, and liability gaps that produced today's unsafe software ecosystem — and they should follow the same Secure by Design Principles. The newness of AI does not reset the clock on those forces.
Poker sized card titled "AI is Software" containing the text in the post.
2115
Bob Lord @boblord.bsky.social · 05/10/2026
Amazing! Well done! 👏
110
Bob Lord @boblord.bsky.social · 05/10/2026
The lesson: Manufacturers won't make safer products until society demands them.
051
Bob Lord @boblord.bsky.social · 05/10/2026
Post-WWII automakers prioritized style and speed over safety. Nader's book sparked public outrage and helped drive the National Traffic and Motor Vehicle Safety Act of 1966, which created the first mandatory federal safety standards for cars and the agency that became NHTSA.
140
Bob Lord @boblord.bsky.social · 05/10/2026
Unsafe at Any Speed: In 1965, Ralph Nader published Unsafe at Any Speed, arguing that car accidents were caused not just by human error — but by the design of the car itself.
Poker sized card titled Unsafe at Any Speed
1102
Bob Lord @boblord.bsky.social · 05/10/2026
The software industry could learn a lot from other safety-critical sectors, like planes, trains, automobiles, food, medicine, ...
130
Bob Lord @boblord.bsky.social · 04/10/2026
Great reporting! Maybe there are problems letting corporations decide the language we use, especially when their profits depend on controlling the narrative. Also: medium.com/@boblord/zer...
medium.com
“Zero-Day” Is Not a Definition, It’s a Deflection
Introduction
000
Reposted by Bob Lord
Lauren Zabierek @lzxdc.bsky.social · 04/10/2026
052
Bob Lord @boblord.bsky.social · 04/10/2026
Attacker-centric terms like "arbitrary code execution" describe what the attacker achieved. Software-centric alternatives like "improper input neutralization" describe what the manufacturer failed to prevent.
072
Bob Lord @boblord.bsky.social · 04/10/2026
Language Matters: The words we use influence how people think. Shifting language shifts mindsets. "Vulnerability" sounds like weather: unpredictable, nobody's fault. "Product defect" names something a manufacturer built and could have prevented. Keep it only where it's a term of art, like CVE.
Poker-sized card with text about how we use certain terms.
2126
Bob Lord @boblord.bsky.social · 03/10/2026
While we don't know how to make perfectly secure software, we know how to make software much, much more secure. 💪🔐
100
Reposted by Bob Lord
Lauren Zabierek @lzxdc.bsky.social · 03/10/2026
082
Bob Lord @boblord.bsky.social · 03/10/2026
When the same defect classes recur year after year, the problem isn't that defenders are failing to deploy updates fast enough. It's that manufacturers face no consequence for shipping the defect in the first place. Deploying updates should be the last resort, not the primary defense.
150
Bob Lord @boblord.bsky.social · 03/10/2026
The 2026 Verizon DBIR found median enterprise remediation time rose to 43 days, up from 32, with only 26% of known-exploited vulnerabilities remediated.
130
Bob Lord @boblord.bsky.social · 03/10/2026
Myth: "Orgs just need to patch faster" Reality: Deploying a software security update is a response to someone else's defect. It's not a strategy, it's a tax.
2142
Bob Lord @boblord.bsky.social · 03/10/2026
I’d like to put in a request for a month where I don’t need to be aware. Thank you for your attention to this matter.
020
Bob Lord @boblord.bsky.social · 03/10/2026
Yeah, that's not a thing. Instead, the bad guys will ask for your password, and you will give it to them. Or Tom Cruise will call you asking for money for his unexpected hospital stay. And you will wire money to Nigeria to help him out. Poor guy.
010
Bob Lord @boblord.bsky.social · 02/10/2026
Welcome to Cybersecurity Awareness Month! Ah, I can already smell the hacklore in the air! Mixed in with some really great suggestions we're sure to find a bunch of zombie advice that is long past its expiration date. Be sure to check out www.hacklore.org for more information! 🧟🧟‍♂️
A grinning gray-green zombie in a tattered blue shirt raises both fists amid orange confetti, pumpkins, and autumn leaves. A banner reads “October: Cybersecurity Awareness Month.” His shirt warns “Beware of juice-jacking! Never use public USB” above a crossed-out USB plug. The cartoon satirizes outdated cybersecurity advice returning each October. “hacklore.org” appears at the bottom right.
182
Reposted by Bob Lord
David Lynch's Worlds @davidlynchsworlds.bsky.social · 30/09/2026
September 30 / October 1 #TwinPeaks
29420
Reposted by Bob Lord
Lauren Zabierek @lzxdc.bsky.social · 02/10/2026
044
Bob Lord @boblord.bsky.social · 02/10/2026
Compare the Lucky 13 to MITRE's Top 25 Most Dangerous Software Weaknesses.
050
Bob Lord @boblord.bsky.social · 02/10/2026
These are defects (like XSS, SQLi) that keep appearing year after year. Their recurrence is not a technical mystery; it is a business and incentive failure. The presence of an unforgivable vulnerability signals that customer safety was not treated as a non-negotiable requirement.
150
Bob Lord @boblord.bsky.social · 02/10/2026
In 2007, MITRE published "Unforgivable Vulnerabilities," listing 13 recurring classes of coding error (known as the "Lucky 13") for which effective mitigations had been available.
193
Bob Lord @boblord.bsky.social · 01/10/2026
Yet we tolerate phrases like "humans are the weakest link" in 2026. People need to read more Sidney Dekker! ✈️
130
Bob Lord @boblord.bsky.social · 01/10/2026
Well said!
010
Bob Lord @boblord.bsky.social · 01/10/2026
Stay tuned! 😉
120
Bob Lord @boblord.bsky.social · 01/10/2026
When a system fails because of an innocent mistake, it was designed that way. It is brittle by design. Human error should be treated as the immediate cause of an incident, never its conclusion.
160
Bob Lord @boblord.bsky.social · 01/10/2026
Human error is inevitable. Secure-by-design systems are built to account for that. When a security failure is blamed on "human error" the real question is: why did the system make the unsafe choice easy and the safe choice hard?
2122
Reposted by Bob Lord
Deth Veggie @dethveggie.bsky.social · 25/09/2026
HAPPY DOLLY PARTON DAY, ERRBODY!
18027
Reposted by Bob Lord
Firewalls Don't Stop Dragons @firewalldragons.bsky.social · 25/09/2026
Monday is the BIG DAY… My 500TH PODCAST!!! 🐉🎙️ 🎉 #FDSD500 Returning for his 5th “podcentennial” appearance - he was here for 100, 200, 300 & 400 - is Bruce Schneier! We’re having a fun debate about AI. 🤖 Don’t miss it! And tell your friends! 📣 firewallsdontstopdragons.com/podcast/
firewallsdontstopdragons.com
Podcast - Firewalls Don't Stop Dragons
I have a weekly podcast called Firewalls Don't Stop Dragons which has over 500 episodes! The show is a mix of cybersecurity news and interviews of prominent people in the industry. But like the book, ...
012
Bob Lord @boblord.bsky.social · 22/09/2026
Six-year-old girl from China sets new Rubik's Cube world record (Why is there still no emoji for a Rubik's Cube‽) www.bbc.com/news/videos/...
bbc.com
Six-year-old girl from China breaks Rubik's Cube world record
Lian Yunzhi broke the women's world record twice in three days at World Cube Association competitions.
150
Reposted by Bob Lord
Prof Peter Hotez MD PhD DSc(hon) @peterhotezmdphd.bsky.social · 21/09/2026
Covid
22261132
Reposted by Bob Lord
A Whole Damn Town! @im.a.whole.damn.town · 19/09/2026
Twin Peaks: FBI Special Agent Dale Cooper, driving while talking to his tape recorder.
FBI Special Agent Dale Cooper, driving while talking to his tape recorder. Twin Peaks S01E01 - Northwest Passage.
15913
Bob Lord @boblord.bsky.social · 13/09/2026
Hm I missed this. 😢 How do people track these events?
000
Bob Lord @boblord.bsky.social · 11/09/2026
Which?
100