Sign in

Ryan Basden

@ryanbasden.com
89 followers 110 following 122 posts

Writer @ ryanbasden.com // Hacker @ empiricsecurity.com #1 photography account about hacking. Previously: @bishopfox.bsky.social Red Team @risk3sixty Pentesting Practice Lead

PostsRepliesMedia
Ryan Basden @ryanbasden.com · 12/09/2026
Listening to non-technical people get frustrated about LLM output is like listening to my in-laws insist that their iPhone switched to Korean all by itself.
000
Ryan Basden @ryanbasden.com · 04/09/2026
Many non-technical people are blindly trusting LLM output the same way older generations blindly trusted "the Google" and cable news.
000
Ryan Basden @ryanbasden.com · 28/08/2026
Despite being a "verified defender" with Daybreak, OpenAI still rejected me when I appealed a warning they sent for generating a simple shellcode loader for research. I verified my identity and the legitimacy of my consulting LLC that I've run for two years now, and apparently that doesn't matter?
000
Ryan Basden @ryanbasden.com · 26/08/2026
Don't make me coin "slopreneur"
000
Ryan Basden @ryanbasden.com · 18/08/2026
Ginny is my new role model. www.youtube.com/watch?v=3QYx...
youtube.com
Ninja Warrior at 74: The Simple Routine Behind Her Insane Strength ft. Ginny MacColl
YouTube video by Sierra Clark
000
Ryan Basden @ryanbasden.com · 04/08/2026
Staking out how I do and do not use LLMs for good. Just in case anyone was wondering if I'm interested in handing over my humanity for expediency. ryanbasden.com/ai.html
ryanbasden.com
AI - Ryan Basden
Where Ryan Basden uses large language models, where he refuses to, and the tools he’s built to keep the line clear.
000
Ryan Basden @ryanbasden.com · 01/08/2026
“Hey, I could tell by your face that you were kind of frustrated on that call” Bro my facial expressions are humanitarian aid compared to what I was actually thinking
000
Reposted by Ryan Basden
nico_n_art (looking for work) @nico-n-art.bsky.social · 19/07/2026
If you want you can also support me on Ko-fi, I will try to post there more often. I just posted a work in progress of the illustration I've been working on this week. It's pretty metal and I'm sure you will love it! ko-fi.com/post/WIP-Le-...
Detail of a black and white pixel art illustration showing part of a face and an eye looking upward
051
Ryan Basden @ryanbasden.com · 30/05/2026
Claude when I stop typing in the chat field and hit Ctrl-G to open Vim
static.klipy.com
Dramatic Man Looks Up in Pain
ALT: Dramatic Man Looks Up in Pain
000
Ryan Basden @ryanbasden.com · 26/05/2026
Going to start using "load-bearing" instead of "cool" and "sick" in regular conversation
000
Ryan Basden @ryanbasden.com · 25/05/2026
LLMs don't have to be able to replace red teams. AI companies just have to convince enough of the market that they can.
000
Ryan Basden @ryanbasden.com · 28/04/2026
Claude API issues are the new us-east-1 outages.
000
Ryan Basden @ryanbasden.com · 17/04/2026
You're at the top of my shortlist for the inevitable moment I need some spooky design work!
110
Ryan Basden @ryanbasden.com · 17/04/2026
Link to the hospital's site for those interested: turtlehospital.org
turtlehospital.org
The Turtle Hospital. Rescue, Rehab, Release. – The Turtle Hospital. Rescue, Rehab, Release.
000
Ryan Basden @ryanbasden.com · 17/04/2026
Went to a turtle hospital in Key West today. They drown if they eat plastics that ruin their buoyancy. They develop tumors as we contaminate the water. They get hit by boats/jet skis and become permanently paralyzed. Sometimes it's hard to keep caring about security.
100
Ryan Basden @ryanbasden.com · 28/03/2026
jk, this is my preworkout tub, you really thought I went to RSAC?
000
Ryan Basden @ryanbasden.com · 28/03/2026
Marketing designs at RSAC were wild this year
100
Ryan Basden @ryanbasden.com · 23/03/2026
Sometimes I wonder if I could ever go back to just being a good people manager. I miss leading and developing teams, but I will never miss the mountain of billable work that usually comes with consulting.
000
Ryan Basden @ryanbasden.com · 20/03/2026
The industry will keep moving. Being self-directed is the only way to stay ahead of it. If you want a longer version of this with some "old man yells at cloud", check out my personal blog: ryanbasden.com/blog/infosec...
ryanbasden.com
Infosec Training Is Weird Now - Ryan Basden
Enshittification comes for us all.
011
Ryan Basden @ryanbasden.com · 20/03/2026
The practical answer, I think, is to treat your own development as your own responsibility. Build a home lab. Develop a methodology you actually own. Use open-source tooling to sharpen your own workflow rather than renting access to someone else's.
110
Ryan Basden @ryanbasden.com · 20/03/2026
I don't think any of this is a reason to panic, but it is a reason to be clear-eyed about what these platforms are actually for. Your professional development isn't their primary concern. It's a selling point. There's a difference.
100
Ryan Basden @ryanbasden.com · 20/03/2026
The people who buy tools and the people who use them have different interests. That gap is what's being exploited here.
100
Ryan Basden @ryanbasden.com · 20/03/2026
The AI pivot is the latest version of the same pattern. "Autonomous pentesting" tools being sold not to practitioners but to the companies that hire them, or used to.
100
Ryan Basden @ryanbasden.com · 20/03/2026
So the subscription tiers appeared. The premium learning paths. The certification ecosystems and leaderboards. All of it designed to keep people engaged and paying, with employment dangled as the reason it's worth it. None of that is unique to infosec. It's just how this goes.
100
Ryan Basden @ryanbasden.com · 20/03/2026
Then came the venture capital, which is when things got predictable. Running infrastructure for hundreds of thousands of users isn't cheap, and the platforms that took outside funding took on the same mandate every VC-backed company takes on: grow revenue, find an exit.
110
Ryan Basden @ryanbasden.com · 20/03/2026
The problem is that making something accessible doesn't automatically make it meaningful. The skill set that used to come with years of context and technical background got packaged into modules. Certifications multiplied. Resume parsers got fed. The signal got fuzzy.
100
Ryan Basden @ryanbasden.com · 20/03/2026
HackTheBox and TryHackMe came along and did something genuinely useful: they made the educational content more accessible and far cheaper by separating it from the credential. A polished platform, lots of free material, and a lower barrier to entry for people who wanted to learn.
100
Ryan Basden @ryanbasden.com · 20/03/2026
But the moment a credential becomes a line item on a job description, the market starts trying to produce it more cheaply.
100
Ryan Basden @ryanbasden.com · 20/03/2026
Then it showed up in job postings, and everything that followed from that was probably inevitable. OffSec realized they had something valuable and built a whole certification ecosystem around it. Which, fair enough, that's what companies do.
100
Ryan Basden @ryanbasden.com · 20/03/2026
It was slow and messy but it worked. The OSCP was the first credential that felt like it actually meant something. 24 hours in a lab, machines to compromise, points to earn, and a report to write with whatever energy you had left. It was hard to get and people respected it.
100
Ryan Basden @ryanbasden.com · 20/03/2026
When I started learning to hack around 2009, there wasn't much in the way of structured training. You learned in forums and IRC channels. I learned Nmap by reading the documentation, SQL injection after already understanding SQL, and Linux by setting up file shares for friends.
100
Ryan Basden @ryanbasden.com · 20/03/2026
Not to mention how strange the infosec training landscape has gotten over the last decade or so. Not strange in a catastrophic way, just strange in the way that happens when an industry matures faster than anyone planned for.
100
Ryan Basden @ryanbasden.com · 20/03/2026
The whole TryHackMe/NoScope thing got me thinking about what training was like when I was a young lad and the changes I've seen in how people learn. 🧵
110
Ryan Basden @ryanbasden.com · 17/03/2026
Fork this repo. github.com/rexrodeo/ame...
github.com
GitHub - rybaz/american-healthcare-conundrum: Investigative data journalism: quantifying fixable waste in US healthcare, one issue at a time. Open-source analysis of CMS, OECD, and federal datasets. $...
Investigative data journalism: quantifying fixable waste in US healthcare, one issue at a time. Open-source analysis of CMS, OECD, and federal datasets. $98.6B in savings identified so far. - rybaz...
001
Ryan Basden @ryanbasden.com · 17/03/2026
...and a consultant willing to say it out loud even when it's unpopular. empiricsecurity.substack.com/p/how-to-ens...
empiricsecurity.substack.com
How to Ensure Your Purple Team Fails Miserably
Your ultimate guide to guaranteeing one of security's most beneficial exercises does nothing for you.
000
Ryan Basden @ryanbasden.com · 17/03/2026
Neither of those incentives points toward honesty about current capability gaps. A purple team that actually works requires something most organizations aren't prepared for: a realistic assessment of where their detection program is...
110
Ryan Basden @ryanbasden.com · 17/03/2026
The structural problem is that both sides are unconsciously optimizing for theater. Clients want to know they're already resilient enough and consultants want profitable contracts.
100
Ryan Basden @ryanbasden.com · 17/03/2026
Teams spending months building the perfect automated platform while real attackers were just opening PowerShell.
100
Ryan Basden @ryanbasden.com · 17/03/2026
The consulting-side ones are more frustrating to write, because I've lived them. Sales teams pitching "purple team" as a red team ride-along. Practitioners skipping the scoping questions that might have made the deal smaller, or killed it entirely.
100
Ryan Basden @ryanbasden.com · 17/03/2026
The client-side ones are what you'd expect: teams using the engagement as an EDR benchmark rather than testing their actual detection capability, no threat intelligence informing what techniques to run, and reports that went to SharePoint instead of a ticketing system.
100
Ryan Basden @ryanbasden.com · 17/03/2026
Purple team exercises are my favorite work when they go well. Few things burn me out harder than when they're set up to fail and I have to run them anyway. I wrote up the specific failure modes I've seen repeatedly, on both the client side and the consulting side. 🧵
101
Ryan Basden @ryanbasden.com · 02/03/2026
I really love breaking into buildings, but when clients have asked me about the specific threat model, I haven't had a great answer. Here's my attempt at figuring it out. empiricsecurity.substack.com/p/oceans-ele...
empiricsecurity.substack.com
Ocean's Eleven Heists In a Louvre Four World
Are physical security assessments a fun novelty? Or are fewer businesses taking them as seriously as they should?
000
Ryan Basden @ryanbasden.com · 01/03/2026
Oh, this? Yeah, I only use AI on the command line. I’m a bit of a power user. ChatGPT? I’ve heard of it, but Claude just sort of gets me, you know? Plus it understands my Vim commands, so the mental load is almost nonexistent. Vim? Yeah, hard to explain, you might be better off with the web UI.
000
Ryan Basden @ryanbasden.com · 21/02/2026
- Key Steps to Ensuring Your Purple Team Fails Miserably - Guerrilla Metric Reporting Warfare for Technical Teams - The Only Difference Between Felons and Professionals is Getting Caught - There's Always a Bigger Phish: Internal Messaging as Forbidden Fruit
000
Ryan Basden @ryanbasden.com · 21/02/2026
Spicy blog drafts I've had in the hopper for a long time: - How to Fool Your PCI Auditor and Get That Bag - Continuous Pentesting or Just Continuous Vulnerability Management? - Your Executives Make Phishing Easier For Me and My Friends - A Song of Supply Chains and Drive-By 0-days
110
Ryan Basden @ryanbasden.com · 14/02/2026
If @bsky.app could add TOTP as an MFA option instead of emailing me a code that is not only case sensitive but doesn't use a font that clearly differentiates between uppercase O and the number 0, that would be fantastic.
000
Ryan Basden @ryanbasden.com · 13/02/2026
stop being so conscientious and considerate, this is infosec
110
Reposted by Ryan Basden
Empiric Security @empiricsecurity.bsky.social · 12/02/2026
We’ve all seen it: the "compliance-first" mindset that checks every box while leaving the front door wide open, but out of scope. If you’re tired of the theatre and actually want to move the needle, give this a read. empiricsecurity.substack.com/p/how-shadow...
empiricsecurity.substack.com
How Shadow Incentives Harm Real Security
Despite the millions upon millions of dollars thrown at penetration testing ever year, big data breaches are still as common as ever.
021
Ryan Basden @ryanbasden.com · 14/01/2026
One more stressful event away from making disappearing into the woods part of my personality
000
Ryan Basden @ryanbasden.com · 09/01/2026
Have you guys checked out your Kroger 2025 Wrapped yet
000