Skip to content
EN

Back to the catalog

crankysec.com
jsonEnglish

CrankySec

crankysec.com · English

Fuck InfoSec

json

Open the feed

https://crankysec.com/feed/feed.json

Last post
Sep 15, 2026
Posts in 24 h · 7 days · 30 days
0 · 0 · 1
Our last check
Answering
Served from
United States
Text score at discovery
5,466
Format
json

Posts

What our queue read from this feed. Open one to read it here, or go to the site that published it.

  1. Appeal to deez nutz
    Sep 15, 2026 · original
    How are you, friends? It's been a minute, eh? As I've mentioned , we're not dead. In fact, I've been busy as hell doing things I know how to do for the benefit of the almighty shareholder. The funny think is that the "things I know how to do" are not that complicated: if you want to do those things, all you need to do is add some general knowledge and brainpower to the problem at hand, and the solutions start to emerge. Your brain needs the workout. And your brain is excellent at making connections between things, identifying patterns, and coming up with ways to handle information more efficiently. You just need to give a shit and have at least a superficial knowledge of things outside of your immediate surroundings. Let me give you an example: you don't prioritize your patching based on the CVSS score. A lot of people do, but that's because they don't know any better. If you do know bet
  2. You're smarter than this
    Apr 27, 2026 · original
    The whole debacle around Anthropic going all "Oh my god, I cannot believe we are this good !" with their Mythos model has made me realize that a lot of cyberfolk lack a very fundamental skill: skepticism. Everywhere you go, someone is yapping about 271 vulnerabilities in Firefox, and how this is a portent of terrible things to come. These people should shut the fuck up. I will not try to out-beaut this beaut here because I cannot, but let's take a look at this specific 271 vulnerabilities number. On April 21, 2026, Mozilla published a blog by Firefox CTO Bobby Holley, in which he states the following with regards to Mythos: This week’s release of Firefox 150 includes fixes for 271 vulnerabilities identified during this initial evaluation. It sounds really impressive, since he prefaces this with this: We wrote previously about our collaboration with Anthropic to scan Firefox with Opus 4.6
  3. Smash the glass wing
    Apr 15, 2026 · original
    You know shit's getting out of control when your friends and family start asking you about this "new AI hacking thing" they saw on Instagram. I know cyberfolk tend to blow things out of proportion, but, when things like this spill over onto main street, you just know you're in for a wild ride that should be used as a textbook example of the Gell-Mann Amnesia Effect. Anthropic, the AI company equivalent of DJ Khaled in that it keeps suffering from success, gathered a bunch of people who would in no way, shape or form benefit from this attention, gave this group a silly name as people who do vulnerability research are wont to do, and called in the press. The press, of course, started lapping it up, and went on to write pieces about how hard it is for Anthropic to be so good looking, so rich, and have such a big dick that they can't even leave the house. It's a problem. And that's from a co
  4. A New New Hope
    Apr 8, 2026 · original
    What's up, friends? Hope you're all doing all right, because I am not. Working two full-time jobs to keep the lights on ain't easy on the soul. Enough about me, though. Let's talk about the future of this industry of ours. Every single person I talk to says the same thing: it's almost impossible to land a job these days. On top of fake ass job postings on LinkedIn (Why are you reposting this job after getting thousands of applications, bud?), poverty wages, and general fuckery, we have lEaDeRs dead set on replacing you with an LLM. Here's the thing, though: 10-ply lEaDeRs who think ChatGPT can do anything because they are thoroughly mesmerized by the LLM's ability to write a bullshit email or prepare a bullshittier slide deck are going to be very surprised when this bill comes due. You see, spitting out a LinkedIn post is EZ. So easy that it's become a joke . Coding? Sure, it can do some
  5. Let's Delve In
    Mar 21, 2026 · original
    A lot of peeps out there shocked, and I mean SHOCKED!, about this whole Delve thing . If you don't know what I'm talking about, go have a read. If you're lazy, here's a summary: looks like YC graduate compliance company Delve has allegedly defrauded clients. Allegedly. No one's been charged with anything, and no one's been found guilty of anything. So... Allegedly. Their whole business model revolves (revolved? Who knows!) around a platform that helps companies achieve compliance with SOC 2, ISO/IEC 27001, HIPAA, and GDPR through some "AI-powered" platform. Someone from this company mistakenly posted a link to a bunch of reports, and the folks behind the LONG article linked above did some digging. It doesn't look great. It's not THAT surprising either. You see, I was a PCI-DSS QSA for a long time. And I've been certified as a Lead Auditor for ISO/IEC 27001 for the last two editions of th
  6. The Drive By
    Mar 11, 2026 · original
    In the masterpiece movie "Analyze That", there's a scene between mafioso Paul Vitti, and actor Tony Bella, who's playing a character based on the former. It goes like this: Bella: I'm looking for something to do when my character finds out he's being indicted. I was thinking of punching the wall, but I did that when they killed Uncle Lenny, and I did it again when Franny left me. Oh, and I punched a car, a van actually, when Peezee screwed up the big drug deal. So I'd like to find something different, that doesn't involve, you know, punching anything. Vitti: Try kickin' something. Let me know how it works out. Bella: Wait, Paul. That's interesting. Like what? Vitti: I don't know. You could kick a guy in the face. Bella: Who? Vitti: Just some guy! You knock him down, give him a couple quick kicks in the head while he's on the ground. Bella: Why? Vitti: Why not? Because he's there and you'
  7. Molto Bene
    Feb 2, 2026 · original
    Hello, friend! Welcome to the first post of 2026. I know it's been a minute, but life's been wild. Also: I've been doing this for 2 years now? Dang. Anyway. We're still open to business if you have any interesting projects, and a cybersecurity budget. I don't know if that's still a thing, though. Thought I'd ask. Today, however, I want to talk about this craziness that is ClawdBot MoltBot OpenClaw. But first, a brief detour: I am not going to sit here and tell you that I don't use LLMs. I do. What I do think is that a) the societal value they provide does not make up for the resources they consume, b) many of you reading this right now are having a hard time finding gainful employment because someone told some hiring manager that some LLM could do your job, and c) handing the keys to your life to a bot is insane. The reality is that a lot of people do love this shit. And I would go even
  8. It's never simple
    Dec 9, 2025 · original
    How do you do, friends? Hope everything is good, and the holiday season is not making you mad. Anyway, on top of working on the previously mentioned business, I've been doing some cleaning and decluttering my life, digital and otherwise. I think it's good to take some time (I can hear you LOL-ing at "take some time", and you're right) and reassess where your time, money, and energy are going. You'd be surprised. I digress, though. Or, do I? We'll see about that. Indeed, I do have two things to talk about, and they are kinda related. So, let's do that hockey! First of all, I would like to address every single one of you cyber beauts, and offer some unsolicited advice: Do not confuse posturing for knowledge. Really. It happens all the time , and it hurts everyone. Every time some dumbass 10-ply vCISO who can't tell the difference between Java and JavaScript starts yapping about React2Shell
  9. Call us, maybe?
    Oct 31, 2025 · original
    Hi! How are you? It’s been a while, I know! And let me tell you why: I’ve been fucking busy. Some of that is good busy, some of that is bad busy. I’ll tell you more about the former, because fuck the latter. As you may or may not know, I started dumping my thoughts here in February of 2024 with literally zero expectations that anyone would care. I got some bumps from good friends who are better at wordsmithing than I am, but I think the reason people keep indulging me is not because I’m funny or original—which I am —, but because we all experience the same bullshit I describe herein: The contempt for expertise. Calling the bizarre practice of dumbing things down so some idiot executive can pretend to care the “LaNgUaGe oF BuSiNeSs”. That feeling that only the true sociopaths can get ahead. The general lack of respect. It sucks that bitching and complaining is the thing that brought us to
  10. More Hands
    Sep 24, 2025 · original
    I am an idealist. For the longest time, I thought that common sense and logic would always prevail, even if a little bit of convincing was needed. In my clearly stupid mind, I should aways operate under some guiding principles. Things like “don’t overcomplicate things”, “don’t reinvent the wheel”, “say what you mean and mean what you say”, “more hands make light work”, etc. Basically: look for ways to make things better. And that’s the dumbest approach to a corporate job you can possibly have. It is a great way to approach your own stuff, however. Perhaps your own business, your personal life, your relationships, your hobbies, and all that. Just not a corporate job. Not necessarily because “capitalism bad!”, but because there are things at play that you don’t understand. You don’t understand it because you’re not a psychopath. You know it, but you don’t understand it. You’re not hardwire
  11. The Modern Individual Contributor
    Sep 2, 2025 · original
    As of this writing, it is the year 2025. Things have changed since I started doing cybersecurity. Or have they? Maybe I’m the one who’s changed. Maybe the real change was the enemies we made along the way. Be that as it may, some lessons were learned. Here are some tips and tricks on how to be an individual contributor in 2025! Right off the bat, the very first thing you need to accept is that the term “individual contributor” itself carries a reminder of where one is in the hierarchy. It means you’re not in charge of anything that’s not assigned to you. That’s very important, so keep that in mind at all times. You take orders, and you execute those orders. That’s it. Are those orders stupid? Do you know how to get the same results in a much more efficient way? Do you have opinions on how to address the root cause of the problem you’re being ordered to tackle? It. Does. Not. Matter. Keep
  12. Fork that.
    Aug 5, 2025 · original
    Right off the bat, let me state for the record that I have, in fact, used LLMs. I still do. They're good for some inconsequential bullshit you don't want to do like "Write a short bio about you!", or a RACI matrix that would otherwise take 40 hours to produce just so it can sit somewhere being used by no one, or your "goals" as an individual contributor (lol), or any OKR. It's kinda like ordering a couple of Chicago-style hot-dogs, a Double Fatso with Cheese, and fries from Fatso's Last Stand—true beauts, by the way—when you can't be bothered to cook something a little more healthy. It's not good for you, it's not good for the environment, and it's not good for public health. It is convinient, and it's probably good for pharma companies that charge a trillion dollars for insulin, but that's another matter. It's a lot of damage for very little gain. And that's not even touching instances
  13. Be Savvy
    Jul 29, 2025 · original
    I was going to title this something like "The smart person's guide to tech bullshit", but that pretty much would go against one of the points that I'm trying to make: "smarts" is very hard to define. I mean, you can be smart enough to start a business, get funding, grow a customer base, and, by many conventional metrics, be successful. And you can be dumb enough to actively sabotage all that by making stupid business decisions . You have a business dedicated to facilitating confidential communication between people. You make the very, very dumb decision to demand some sort of KYC process in order to "ascertain" that the person signing up is a "woman" (and let's not even get into that ), and, despite the fact that there are several third-parties you can hire to do that for you, you think "how hard can it possibly be?", and you roll your own. And you are so incredibly stupid that you make
  14. When You Wish Upon a Star
    Jul 18, 2025 · original
    I wasn't going to write about this at all. My plan was to sit down to bitch about the scam we call "bounty hunting", but, as usual, I got sidetracked. My day job sometimes involves looking at job descriptions for cybersecurity positions, and friends... it's getting even worse. Just this week I was presented with a job description that a) was 3 pages long, and b) had 46 bullet points. These people want someone to do incident response, cybersecurity architecture, risk assessments, compliance, threat intel, policies and procedures, mentoring, auditing, application security, SDLC security, vulnerability management, cloud security, API security, IAM, security operations, and, of course, AI security. Add to that the usual ridiculous education, certification, and experience requirements. Job descriptions like that are the norm, mind you. But, as you can imagine, filling positions like this one
  15. The Grass Is Always Grayer
    Jun 19, 2025 · original
    A friend of mine once shared with me a saying from where he's from: "If the grass suddenly changed color, a lot of people would starve to death." It's kind of nasty in the sense that this saying is calling everyone some kind of herbivore, presumably a donkey. However, if you can get past that, the underlying message is not that everyone's a donkey. The message is something like "just because the grass changed color, it didn't stop being grass.", and you can extrapolate that to "you need to be able to look past the obvious, have some awareness, and practice critical thinking if you want to be a functional human being." Like, you gotta think about shit. We see this happening every day as cybersecurity professionals. Practices and processes and activities that are performed not because they deliver better security outcomes, but because people assume they do. And they don't. A lot of smart p
  16. Smart Guys
    May 29, 2025 · original
    Where I come from, there's this saying that goes something like "the smart guy's weakness is believing everyone else is dumb." When you believe that you're smarter than everyone else, you make assumptions. When you make assumptions, you're fucked. "No one would do that!" - They would "No one will think of that!" - They will "Why would anyone do this? It makes no sense!" - LOL Those assumptions are, coincidentally, at the core of pretty much every single software, hardware, wetware vulnerability there is. "Why would anyone type ‘ OR ’1’ = ‘1’ ? It makes no sense!" Being a dilettante is a very dangerous thing, and the tech industry is full of those. That, I think, comes from not having experienced reality like many of us have. Assumptions made by a tech bro born and raised with all the privileges in the world are not the same assumptions you and I would make. That's why they come up with t
  17. Pour one out for community
    May 17, 2025 · original
    By now, it should be clear to everyone that the whole " Tragedy of the commons " concept was not intended to be an argument in favor of preserving the commons. It was, instead, a racist line of thought that can be condensed to something like "You barbarians cannot control yourselves. Whereas, I, Garrett Hardin, a person belonging to the most refined and enlightened class, believe that only the most refined and enlightened should be in charge of said commons." In other words, the tragedy of the commons is not about preserving the commons: it's about getting rid of them, and handing them over to powerful people who would be better stewards of it. Which, of course, it's S-Tier bullshit. This argument is a projection. Hardin probably thought "I know I would exploit this common resource to the ground, but I am refined and enlightened, so I know how to suppress these troglodyte impulses. You r
  18. We're all DEVO
    May 5, 2025 · original
    There was a time back in the mid-to-late aughts where it looked like being in cybersecurity (née information security, a.k.a. infosec) was a good way to make a living: it was an interesting field that required a lot of knowledge about a lot of things, most of them cool shit. It was the post-phreaker, post-hacker era, when a lot of the folks who invented the field by accident realized they could make money out of their habit of being nosy. The post-Aleph One era. The post-cDc days. The post-L0pht times. Those days were easy in the sense that things were not this complicated, and we were all mainly figuring things out as we went, with a boost from the prevailing cultural tailwinds of a time when hacks and leaks were deemed serious and an existential threat to businesses big and small. If you knew your stuff, you were a hot commodity. I spent the vast majority of my career doing cybersecuri
  19. There is no "community"
    Apr 14, 2025 · original
    The jumping point of this post is what happened to Chris Krebs, and how the "community" reacted to it. I don't want to dwell on this particular case because a) a lot of people who are smarter and more eloquent than me already did that, and b) it's not surprising at all. What I do want to talk about, though, is the whole "community" thing, and why expecting for-profit businesses to stick to principles is a recipe for disappointment. Let's start with the whole concept of there even being some sort of cybersecurity community: there isn't one. There are many communities that formed around the subject, but to think there's one big fraternal order is just silly. Like everything else in society, there are in-groups and out-groups, and to pretend otherwise is disingenuous. And that's not even a problem, I don't think: some people have more affinity with some people than others. That's just socie
  20. What can possibly go wrong?
    Apr 3, 2025 · original
    I was watching Daniel Stenberg's FOSDEM video about the curl project's approach to security, and that got me thinking a bit about how wild it is that an open source project operating on a shoestring budget can deliver such an ubiquitous piece of software with such quality. And that shit's written in C. Watching the video, it's clear that Stenberg cares deeply about curl. Stenberg and the other folks maintaining curl are thoughtful, careful, knowledgeable, and dedicated to the goal of delivering quality software that runs on probably billions of devices. For free. Software that is used by other software, many of those commercial. In other words: some people make money from the work performed by the curl maintainers. That's not news, and that's true for a whole lot of open source software. It's a labor of love, generally speaking. On the other end of the spectrum, you have this trend of ju

Discovered by the rss-feed-index crawler, which checks each feed at most once a month.

Same record as JSON: https://api.agentalog.com/api/feeds/fd_crankysec_com_2e88da40e2186fca. More from this site: crankysec.com in the Feeds tab.