Sign in

Lauren Zabierek

@lzxdc.bsky.social
96 followers 134 following 22 posts

substack.com/@lzxdc

PostsRepliesMedia
Lauren Zabierek @lzxdc.bsky.social · 21h
011
Reposted by Lauren Zabierek
Bob Lord @boblord.bsky.social · 07/10/2026
Passing the Buck: With 99% of US businesses classified as small or mid-sized, expecting them to absorb the full cost of insecure software is not a plan.
Poker sized card titled "Passing the Buck" containing the text in the post.
132
Lauren Zabierek @lzxdc.bsky.social · 07/10/2026
032
Reposted by Lauren Zabierek
Bob Lord @boblord.bsky.social · 06/10/2026
AI is Software: AI systems are software products, subject to the same incentive structures, market pressures, and liability gaps that produced today's unsafe software ecosystem — and they should follow the same Secure by Design Principles. The newness of AI does not reset the clock on those forces.
Poker sized card titled "AI is Software" containing the text in the post.
2115
Lauren Zabierek @lzxdc.bsky.social · 06/10/2026
063
Reposted by Lauren Zabierek
Bob Lord @boblord.bsky.social · 05/10/2026
Unsafe at Any Speed: In 1965, Ralph Nader published Unsafe at Any Speed, arguing that car accidents were caused not just by human error — but by the design of the car itself.
Poker sized card titled Unsafe at Any Speed
1102
Lauren Zabierek @lzxdc.bsky.social · 05/10/2026
010
Reposted by Lauren Zabierek
Bob Lord @boblord.bsky.social · 04/10/2026
Language Matters: The words we use influence how people think. Shifting language shifts mindsets. "Vulnerability" sounds like weather: unpredictable, nobody's fault. "Product defect" names something a manufacturer built and could have prevented. Keep it only where it's a term of art, like CVE.
Poker-sized card with text about how we use certain terms.
2126
Lauren Zabierek @lzxdc.bsky.social · 04/10/2026
052
Reposted by Lauren Zabierek
Bob Lord @boblord.bsky.social · 03/10/2026
Myth: "Orgs just need to patch faster" Reality: Deploying a software security update is a response to someone else's defect. It's not a strategy, it's a tax.
2142
Lauren Zabierek @lzxdc.bsky.social · 03/10/2026
082
Reposted by Lauren Zabierek
Bob Lord @boblord.bsky.social · 02/10/2026
In 2007, MITRE published "Unforgivable Vulnerabilities," listing 13 recurring classes of coding error (known as the "Lucky 13") for which effective mitigations had been available.
193
Lauren Zabierek @lzxdc.bsky.social · 02/10/2026
044
Reposted by Lauren Zabierek
Bob Lord @boblord.bsky.social · 01/10/2026
Human error is inevitable. Secure-by-design systems are built to account for that. When a security failure is blamed on "human error" the real question is: why did the system make the unsafe choice easy and the safe choice hard?
2122
Lauren Zabierek @lzxdc.bsky.social · 01/10/2026
A class of defect is a category of product defect that recurs across products, codebases, and time - such as buffer overflows, SQL injection, or use-after-free errors. Many are predictable and preventable defects that should be eliminated at the root.
A class of defect is a category of product defect that recurs across products, codebases, and time - such as buffer overflows, SQL injection, or use-after-free errors.
Many are predictable and preventable defects that should be eliminated at the root.
Eliminating a class of defect means making it structurally impossible, not just fixing individual instances. This is a core goal of secure-by-design software.
When a product ships with the same class of defect it shipped with last year, it signals that the fix was applied to the symptom, not the cause.
011
Reposted by Lauren Zabierek
JoshCorman @joshcorman.bsky.social · 10/03/2026
DON’T miss: Provoking & Most Taylor Swift at #RSAC debate w/ me & @lzxdc.bsky.social TUE 3/24 1:15 #UnDisruptable27 #SecureBy #VoltTyphoon
121
Lauren Zabierek @lzxdc.bsky.social · 23/02/2026
You know how national security is largely framed as protection from external threats & our policies (and $) focus on defense, military equipment, surveillance, border control, & adv tech–essentially to keep things out? Despite that, many don’t feel safe or secure from a lot of other threats?
100
Lauren Zabierek @lzxdc.bsky.social · 08/12/2025
open.substack.com/pub/lzxdc/p/...
open.substack.com
What the New National Security Strategy Refuses to See (Its People)
Redefining National Security and the Blind Spots of the 2025 National Security Strategy
000
Reposted by Lauren Zabierek
Girls Who Code @girlswhocode.bsky.social · 13/02/2025
Today, we’re announcing our next bold step: Five by Five, a five-year strategic plan to reach 5 million women and nonbinary individuals by 2030. Five by Five is more than a number — it’s a mission to shape the leaders who will use tech for good. www.girlswhocode.com/strategic-plan
0177
Lauren Zabierek @lzxdc.bsky.social · 28/01/2025
If you read Juliette Kayyem’s book The Devil Never Sleeps: Learning to Live in An Age of Disasters, or if you watch her on CNN, you know that she has this unique ability to cut through the noise to help us understand the “what”, the “so what,” and the “what now” in a pragmatic and practical way.
120
Reposted by Lauren Zabierek
Paul Barrett ❌👑 @paulthedogman.bsky.social · 27/01/2025
I've written a piece for Tech Policy Press called, "Some Facts About Fact-Checking: Defending the Imperfect Search for Truth in an Era of Institutionalized Lying." It sounds wonky, but it's from the heart, people. Please give it a read (and a boost). Thanks. www.techpolicy.press/some-facts-a...
techpolicy.press
Some Facts About Fact-Checking: Defending the Imperfect Search for Truth in an Era of Institutionalized Lying | TechPolicy.Press
Fact-checking ensures a distinction between facts and falsehoods and that everything is not up for grabs because powerful people say so, writes Paul Barrett.
34425