A dozen years of paid break-ins. I would like to report that they were hard. Mostly someone had left a credential somewhere reasonable and it reached somewhere unreasonable, and I walked. Compromise is a reachability problem. The exploit is the part that gets the conference talk.

I still find the paths. The difference is that I’m now in the room when the system gets designed, which is cheaper for everyone. Mostly that means the boundaries around identity, tenants, and the agents we now give credentials to on purpose. Co-founder at Adversis and Puck, which answers what an attacker can actually reach from here, a question I used to answer more slowly and at a day rate. There is a book. No Starch is publishing it, which means it will have a robot on the cover.

Nothing new here

Every bad compromise I’ve walked through had the same plot. No zero-day. Something, a token, a service account, a browser extension, an integration, could reach more than anyone remembered granting, and the attacker found that out first.

The distance between what a thing is supposed to touch and what it can touch is most of my job now. Agents make it more interesting: the thing holding the credential now reads untrusted text and decides what to do next.

The agent on the desktop is the new browser, minus thirty years of hardening lessons, and it ships with prompt injection unsolved. The parts I find myself poking at: whether grammar-constrained encoding and decoding can make an agent’s output boring enough to trust, what intent-based access control looks like when the intent arrives as prose, and what happens once both sides automate. Red teams already drive fleets of agents. The defense worth building is the one that rolls out to the whole fleet at the first tripwire, before the second host is touched.

The other thing I keep noticing is that the industry can’t measure much of anything, and that most of what it sells doesn’t survive contact with the research. The short list of papers that convinced me is on the resources page.

Tools

All the tools →

Writing

More →

Now

Fractional CISO for a handful of companies through Adversis. AI security assessments for a few more. Building Puck, which is mostly about answering “are we affected?” from the endpoints instead of from a meeting.

Email noah at this domain. Haikus get read first. Everything else gets read eventually.

Elsewhere

GitHub (@thesubtlety, and @noahpotti) · LinkedIn · Adversis · Puck Security