Bob Lord @boblord.bsky.social · 6hNear misses reveal where the system is fragile. Tracking them can improve software safety before attackers find the same weaknesses. Organizations that embody a secure-by-design philosophy treat near misses as learning opportunities, not lucky escapes. 041
Bob Lord @boblord.bsky.social · 6hNear misses: Near misses are safety incidents that almost happened, but didn't. In aviation and medicine, near misses are treated as early warnings and investigated thoroughly. In software, they are rarely tracked. When a defect is found internally, it is usually fixed quietly and forgotten. 1101
Bob Lord @boblord.bsky.social · 09/10/2026Most of it isn't disclosure: CVEs that are complete, with the CWE naming the root cause. SDLC self-attestations. A memory safety roadmap. None of that is a roadmap for attackers, and all of it benefits defenders more than adversaries. 050
Bob Lord @boblord.bsky.social · 09/10/2026Embrace Radical Transparency: Radical transparency means publishing information that may feel uncomfortable today — but enables continuous improvement tomorrow. It shifts manufacturers from secrecy to shared learning / accountability and it exposes recurring flaws that would otherwise stay private. 173
Bob Lord @boblord.bsky.social · 08/10/2026Replacing "organizations" with "maker" or "operator" forces clarity of thought, sometimes with surprisingly helpful results. 030
Bob Lord @boblord.bsky.social · 08/10/2026This is one of my favorite cards, and I see people getting tripped up by it almost daily. It's fascinating to notice how people speak and write, and how often they seem to be talking about one, and then all of a sudden they're talking about the other. 140
Bob Lord @boblord.bsky.social · 08/10/2026In software the words hide the parties. "Organizations" and "industry" can mean manufacturers, operators, or both. That ambiguity pulls attention toward what the operator should do about a defect and away from what the manufacturer should do to eliminate it. Operators have work to do.This is not it. 130
Bob Lord @boblord.bsky.social · 08/10/2026Manufacturers vs. Operators: We never confuse an automaker with the driver. Drivers have real duties: maintenance, speed limits, seat belts. Designing out a defect is not one of them, and when a defect injures the driver, the automaker answers for it. 183
Bob Lord @boblord.bsky.social · 07/10/2026That residual risk compounds across sectors, borders, and time — threatening national security, economic stability, and public trust. Pushing the cost of insecure design onto the most vulnerable actors is the result of multiple, interlinking incentives. 030
Bob Lord @boblord.bsky.social · 07/10/2026But when SMBs can't manage that risk, it doesn't disappear. It spills over into disrupted supply chains, breached data, financial losses, and public-sector emergency response. 130
Bob Lord @boblord.bsky.social · 07/10/2026Passing the Buck: With 99% of US businesses classified as small or mid-sized, expecting them to absorb the full cost of insecure software is not a plan. 132
Bob Lord @boblord.bsky.social · 06/10/2026Every broken pattern from 40 years of software — insecure by default, costs externalized to customers, no manufacturer accountability — is already visible in AI systems. Understanding why human-created software is unsafe today is the prerequisite for not making the same mistakes with AI. 082
Bob Lord @boblord.bsky.social · 06/10/2026AI is Software: AI systems are software products, subject to the same incentive structures, market pressures, and liability gaps that produced today's unsafe software ecosystem — and they should follow the same Secure by Design Principles. The newness of AI does not reset the clock on those forces. 2115
Bob Lord @boblord.bsky.social · 05/10/2026The lesson: Manufacturers won't make safer products until society demands them. 051
Bob Lord @boblord.bsky.social · 05/10/2026Post-WWII automakers prioritized style and speed over safety. Nader's book sparked public outrage and helped drive the National Traffic and Motor Vehicle Safety Act of 1966, which created the first mandatory federal safety standards for cars and the agency that became NHTSA. 140
Bob Lord @boblord.bsky.social · 05/10/2026Unsafe at Any Speed: In 1965, Ralph Nader published Unsafe at Any Speed, arguing that car accidents were caused not just by human error — but by the design of the car itself. 1102
Bob Lord @boblord.bsky.social · 05/10/2026The software industry could learn a lot from other safety-critical sectors, like planes, trains, automobiles, food, medicine, ... 130
Bob Lord @boblord.bsky.social · 04/10/2026Great reporting! Maybe there are problems letting corporations decide the language we use, especially when their profits depend on controlling the narrative. Also: medium.com/@boblord/zer...medium.com“Zero-Day” Is Not a Definition, It’s a DeflectionIntroduction 000
Bob Lord @boblord.bsky.social · 04/10/2026Attacker-centric terms like "arbitrary code execution" describe what the attacker achieved. Software-centric alternatives like "improper input neutralization" describe what the manufacturer failed to prevent. 072
Bob Lord @boblord.bsky.social · 04/10/2026Language Matters: The words we use influence how people think. Shifting language shifts mindsets. "Vulnerability" sounds like weather: unpredictable, nobody's fault. "Product defect" names something a manufacturer built and could have prevented. Keep it only where it's a term of art, like CVE. 2126
Bob Lord @boblord.bsky.social · 03/10/2026While we don't know how to make perfectly secure software, we know how to make software much, much more secure. 💪🔐 100
Bob Lord @boblord.bsky.social · 03/10/2026When the same defect classes recur year after year, the problem isn't that defenders are failing to deploy updates fast enough. It's that manufacturers face no consequence for shipping the defect in the first place. Deploying updates should be the last resort, not the primary defense. 150
Bob Lord @boblord.bsky.social · 03/10/2026The 2026 Verizon DBIR found median enterprise remediation time rose to 43 days, up from 32, with only 26% of known-exploited vulnerabilities remediated. 130
Bob Lord @boblord.bsky.social · 03/10/2026Myth: "Orgs just need to patch faster" Reality: Deploying a software security update is a response to someone else's defect. It's not a strategy, it's a tax. 2142
Bob Lord @boblord.bsky.social · 03/10/2026I’d like to put in a request for a month where I don’t need to be aware. Thank you for your attention to this matter. 020
Bob Lord @boblord.bsky.social · 03/10/2026Yeah, that's not a thing. Instead, the bad guys will ask for your password, and you will give it to them. Or Tom Cruise will call you asking for money for his unexpected hospital stay. And you will wire money to Nigeria to help him out. Poor guy. 010
Bob Lord @boblord.bsky.social · 02/10/2026Welcome to Cybersecurity Awareness Month! Ah, I can already smell the hacklore in the air! Mixed in with some really great suggestions we're sure to find a bunch of zombie advice that is long past its expiration date. Be sure to check out www.hacklore.org for more information! 🧟🧟♂️ 182
Reposted by Bob LordDavid Lynch's Worlds @davidlynchsworlds.bsky.social · 30/09/2026September 30 / October 1 #TwinPeaks 29420
Bob Lord @boblord.bsky.social · 02/10/2026Compare the Lucky 13 to MITRE's Top 25 Most Dangerous Software Weaknesses. 050
Bob Lord @boblord.bsky.social · 02/10/2026These are defects (like XSS, SQLi) that keep appearing year after year. Their recurrence is not a technical mystery; it is a business and incentive failure. The presence of an unforgivable vulnerability signals that customer safety was not treated as a non-negotiable requirement. 150
Bob Lord @boblord.bsky.social · 02/10/2026In 2007, MITRE published "Unforgivable Vulnerabilities," listing 13 recurring classes of coding error (known as the "Lucky 13") for which effective mitigations had been available. 193
Bob Lord @boblord.bsky.social · 01/10/2026Yet we tolerate phrases like "humans are the weakest link" in 2026. People need to read more Sidney Dekker! ✈️ 130
Bob Lord @boblord.bsky.social · 01/10/2026When a system fails because of an innocent mistake, it was designed that way. It is brittle by design. Human error should be treated as the immediate cause of an incident, never its conclusion. 160
Bob Lord @boblord.bsky.social · 01/10/2026Human error is inevitable. Secure-by-design systems are built to account for that. When a security failure is blamed on "human error" the real question is: why did the system make the unsafe choice easy and the safe choice hard? 2122
Reposted by Bob LordDeth Veggie @dethveggie.bsky.social · 25/09/2026HAPPY DOLLY PARTON DAY, ERRBODY! 18027
Reposted by Bob LordFirewalls Don't Stop Dragons @firewalldragons.bsky.social · 25/09/2026Monday is the BIG DAY… My 500TH PODCAST!!! 🐉🎙️ 🎉 #FDSD500 Returning for his 5th “podcentennial” appearance - he was here for 100, 200, 300 & 400 - is Bruce Schneier! We’re having a fun debate about AI. 🤖 Don’t miss it! And tell your friends! 📣 firewallsdontstopdragons.com/podcast/firewallsdontstopdragons.comPodcast - Firewalls Don't Stop DragonsI have a weekly podcast called Firewalls Don't Stop Dragons which has over 500 episodes! The show is a mix of cybersecurity news and interviews of prominent people in the industry. But like the book, ... 012
Bob Lord @boblord.bsky.social · 22/09/2026Six-year-old girl from China sets new Rubik's Cube world record (Why is there still no emoji for a Rubik's Cube‽) www.bbc.com/news/videos/...bbc.comSix-year-old girl from China breaks Rubik's Cube world recordLian Yunzhi broke the women's world record twice in three days at World Cube Association competitions. 150
Reposted by Bob LordProf Peter Hotez MD PhD DSc(hon) @peterhotezmdphd.bsky.social · 21/09/2026 22261132
Reposted by Bob LordA Whole Damn Town! @im.a.whole.damn.town · 19/09/2026Twin Peaks: FBI Special Agent Dale Cooper, driving while talking to his tape recorder. 15913