HNHacker News
TopNewBestAskShowJobs

fathermarz

165 karma · joined January 21, 2025

Dad & Husband | Security Evangelist | Educator

Creator of Vigilance.

vigihq[dot]com phended[dot]com

submissionscomments
fathermarz··on Entering and Breaking the Avast Antivirus Sandbox Part 2
I have lost faith in signature AV and CVE feeds for that matter. Attackers test against scanners until they come back clean and avoid known fingerprints. The only way I see to catch things now is behaviour diffing through static analysis.

Disclosure: I build Vigilance, which does this.

fathermarz··on Lazydraw: Terminal ASCII editor for drawing diagrams and sketches
This is the least vibe-coded looking thing I have seen in weeks on HN. Not sure if you looked at the repo or if you’re just fatigued from all the slop. Commits look simple and the README is short and purposeful.
fathermarz··on Muse – Meta’s personal AI agent
In my experience, it depends on the community. Where I live most people are retired so there is tons of interest and a really well ran community program called Elder College. I would look into similar programs near you!
fathermarz··on Muse – Meta’s personal AI agent
This is very accurate. I teach seniors about how to use AI responsibly and they are always mind blown, and I keep it very high level. The amount of Chat”GTP” users there are out there that have no idea who the main vendors are. Most of them also think that Google is just a “search” company.
fathermarz··on Show HN: Stuxnet – A reconstructed source code of the infamous cyber-weapon
This is amazingly awesome. Very intriguing and what a great idea in the first place. One of the most important pieces of modern software IMO.
fathermarz··on Vigilance – Catch supply chain attacks without the noise or the work
I’ve worked in software supply-chain security for six years doing binary analysis on firmware, industrial controls systems, and commodity IT closed/open source software. What I learned is that in hopes to secure the software supply chain we have ran a very similar playbook and mostly over engineered the problem, with SBOMs and VEX documents and expected the industry to comply. But what was discovered was that every SBOM looks different depending on who produced it and at what step in the chain, and it didn’t make anything more secure because it was nothing but an ingredients list and in some cases a CVE dump attached. This is not helpful for anyone who actually triages software.

I built Vigilance to be a simple alternative to the problem to watch for one thing in any part of the supply chain. What files changed in ability and what that ability is. It compares one version of a file to another and says what inside it gained a new ability. This takes what used to be a diff of files from a few thousand in worst case to a list of under 4 with clear stated intentions and at any point within the supply chain. I built it to reduce noise and make the boots on the ground job of triaging simpler and easier.

It’s a single Go binary, no dependencies, no AI, no CVE database. It can run on edge devices to end user computers, build servers to dev machines and air gapped environments. The free version sends basic telemetry reports up for that state file hash and any powers, no file paths, no names, no user information. This is going to be used for research and improving the product. The paid version is licensed completely offline so no telemetry is sent to us but it operates the exact same way to the user on an unlimited number of machines.

Early adopters get two years free if they supply a logo and/or testimonial for the product.

You can try it on most npm packages in the sandbox at https://vigihq.com/sandbox. The sandbox has a daily cap and I am happy to answer any questions.

fathermarz··on Why Normal People Aren't Using AI Agents
I think that now we are starting to see the hype go bye-bye and the real use cases are starting to emerge. However, the systems that come out must be constructed with care aligned with our world has been constructed (reality) and not how the AI Labs believe it should be (theory).
fathermarz··on CISA Alert: Water Sector PLC Targeting
I believe the comment was to say you can not create a join for data that does not exist. Access to financial records is trivial, but there is likely no such comparable record that one can query on for water/industrial. Maybe metrics like water quality for some of them, but not the other security data exists other than shodan/censys (weak and out of context) which could take months per site to collect.

AFAIK the most robust data they have on industrial sectors is within the national labs, and even then its considered sparse.

fathermarz··on CISA Alert: Water Sector PLC Targeting
> Top down regulation drives the systematic change, just like it did with the banking sector.

Banking is resourced well enough to absorb that regulation and stand up a compliance team. I bring up ATC because of the consequence. Default passwords are a symptom, not the failure mode.

ATC is already federal, with the FAA running that. 20 years of regulation has not fixed the problems that still plague that industry: outdated equipment, short-staffed, a small niche talent and training pipeline, and people dying as a consequence of those systemic problems. That's even closer to my point. Making something regulated doesn't change the inherent problems inside the industry.

fathermarz··on CISA Alert: Water Sector PLC Targeting
Yes there are pieces of what you are saying that make sense theoretically. But what I mean by a silver bullet, is it is a systemic change that needs to happen in a bigger swing than just “regulate”.

It is a top down initiative that needs to happen in a more meaningful way. It’s adjacent in a similar way to the issue of air traffic controllers. Talent shortage, old equipment, old hats, burn out and the like.

It needs some real backing and effort to make it happen.

fathermarz··on CISA Alert: Water Sector PLC Targeting
Ouch. You just caused a major outage for <insert critical system>. Either you costed your company millions of dollars or you killed someone.

OT does not equal IT

fathermarz··on CISA Alert: Water Sector PLC Targeting
National Security has always been a federal government responsibility yes. But what does that fundamentally mean for boots on the ground?

NSA doesn’t do IT for the DoD/W, DHS doesn’t do IT for the government, CISA only gives guidance where they can. And IT does not equal OT. The issue comes down to actual skilled people hours to do the work and resource constraints to do so.

I agree that in theory this would not be a stretch if the stars aligned, but these are for the most part, not federal government funded entities nor government controlled even at a state level. They are usually clooged together by 100 years of paper maché. And that’s just water. What about Energy? Data Centers? Pharma? Regulation is way too far behind to just instantly drop a silver bullet.

And 100% agree that we are witnessing repercussions of leadership that did not have much forethought but that ain’t new and goes back quite a ways especially in CI.

fathermarz··on CISA Alert: Water Sector PLC Targeting
What’s the penalty you would impose on a rural water system that has under 10 employees that services thousands of people for water and/or wastewater?

What does that audit look like and how frequent does that happen? It’s a security assessment? A quality assessment? A risk assessment?

I’m open to the idea, but I will repeat, I don’t think the problem is well enough understood for a “make the feds do it” type of comment.

fathermarz··on CISA Alert: Water Sector PLC Targeting
https://www.linkedin.com/pulse/end-complacency-i-can-hope-an...

I much prefer the non-vendor perspective on this. Andy Krapf, co-chair of the Water ISAC, has a great breakdown about the status quo systemic problems that water faces today.

fathermarz··on CISA Alert: Water Sector PLC Targeting
Well I think it speaks to the age of the equipment they are speaking of in the industrial sector.

How do you lockdown something that may have not been taken offline for decades because it will cost downtime or harm. Or something that can’t be locked down without tossing new tech around it that may not be compatible with the protocols etc.

fathermarz··on CISA Alert: Water Sector PLC Targeting
I will repeat a comment from below. There are over 150k water utilities alone in the US.

Passing the buck to the Federal Government is not understanding the problem.

fathermarz··on CISA Alert: Water Sector PLC Targeting
What industry? Very relevant.
fathermarz··on CISA Alert: Water Sector PLC Targeting
There are over 150k water utilities alone in the US.

Passing the buck to the Federal Government is not understanding the problem.

fathermarz··on CISA Alert: Water Sector PLC Targeting
“Run your security patches” is easier said than done in the case of OT and it’s actually an issue that is further upstream than this. Policies, procedures, culture, and resources to execute. None of which are technical.
fathermarz··on CISA Alert: Water Sector PLC Targeting
What policies do y’all have in place for this? Is there a program in place or the beginnings of one at least?
fathermarz··on CISA Alert: Water Sector PLC Targeting
Not IT malpractice and this where the industry diverges. IT folks usually don’t work on or understand these systems.

Which is one of MANY problems OT faces. IT best practices don’t suffice in OT and even when they do, most of these orgs are too resource hamstrung to do anything about all of the fires they have to put out.

Not to mention all of the OT vendors who flooded the market with tools instead of people being taught the boring process driven work.

fathermarz··on Coordinated cyberattack disrupts water utilities in 30 Minnesota communities
I really dislike the mention of AI in this article. Does it help expedite things? Maybe. Is it making attacks more sophisticated? The evidence and guidance tell us that these actors are simply logging to these Internet connected systems with default creds _most_ of the time.

Water is the most underserved sector for resources and yet it is the most critical for life. Unbelievable that it has gotten to this point and no one is sounding the alarm and doing anything about it.

fathermarz··on What is happening to jobs? Separating AI hype from reality
Recently poked around the job market to see what I qualify for in this day and age. Working as a solo builder in my org I would say that I have done enough in the last 18 months to consider myself “with it”.

What I found was pretty brutal. Companies asking for 4 years of agentic AI experience… pardon?

Then it hit me.

Oh they are all making shit up now and have no bar that anyone can hit because they are believing in the hype without understanding the fundamentals.

GREAT. Even as I climb the AI-Native ranks, I apparently am unqualified for any AI-Native job.

fathermarz··on The Kimi K3 Moment
Good to know thanks for the clarification
fathermarz··on Who's making money from using/exploiting AI?
I know web designers that are getting good ol’ local business requests that are now one shotting the sites they used to spend a considerable amount of time on. So I think that’s something. But I couldn’t give you percentages
fathermarz··on Charles Ross spent 50 yrs building Star Axis naked-eye observatory in New Mexico
And in 5,000 years, they will say. “They must have worshipped this star to create such a monument around it, showing how connected to the stars this ancient civilization was”
fathermarz··on OpenAI’s accidental attack against Hugging Face is science fiction that happened
The most upsetting part to me, is that these labs are in pure cognitive dissonance mode while virtue signalling.

We are the virtuous ones that need to make the safest model for humanity, because we care more than “they” do. While at the same time saying that “coding is solved” but they still ship bugs themselves, and creating something that is capable of fucking up someone else’s infrastructure. It’s too far gone y’all.

fathermarz··on Show HN: ShipMD.app – Moving things in folders, move things in the real world
The website on mobile is constantly jumping around so I literally can’t read the copy before the height changes and goes below the fold.

Also, use cases? I’m a little lost after nailing down all the movement.

fathermarz··on The Kimi K3 Moment
> Service Misuse. You acknowledge that without the written consent of us and/or the relevant rights holders, (i)you have no authority to use Kimi and the content generated by Kimi in any commercial manner; (ii)you may not use our Services to develop products or services that compete with us.

https://www.kimi.com/user/agreement/modelUse

fathermarz··on The Kimi K3 Moment
Terms of use are very broad and not friendly for most things.

Can’t use for commercial purposes. Can’t opt out of training. Data retained.

Page 1 of 5Next →