Disclosure: I build Vigilance, which does this.
165 karma · joined January 21, 2025
Creator of Vigilance.
vigihq[dot]com phended[dot]com
Disclosure: I build Vigilance, which does this.
I built Vigilance to be a simple alternative to the problem to watch for one thing in any part of the supply chain. What files changed in ability and what that ability is. It compares one version of a file to another and says what inside it gained a new ability. This takes what used to be a diff of files from a few thousand in worst case to a list of under 4 with clear stated intentions and at any point within the supply chain. I built it to reduce noise and make the boots on the ground job of triaging simpler and easier.
It’s a single Go binary, no dependencies, no AI, no CVE database. It can run on edge devices to end user computers, build servers to dev machines and air gapped environments. The free version sends basic telemetry reports up for that state file hash and any powers, no file paths, no names, no user information. This is going to be used for research and improving the product. The paid version is licensed completely offline so no telemetry is sent to us but it operates the exact same way to the user on an unlimited number of machines.
Early adopters get two years free if they supply a logo and/or testimonial for the product.
You can try it on most npm packages in the sandbox at https://vigihq.com/sandbox. The sandbox has a daily cap and I am happy to answer any questions.
AFAIK the most robust data they have on industrial sectors is within the national labs, and even then its considered sparse.
Banking is resourced well enough to absorb that regulation and stand up a compliance team. I bring up ATC because of the consequence. Default passwords are a symptom, not the failure mode.
ATC is already federal, with the FAA running that. 20 years of regulation has not fixed the problems that still plague that industry: outdated equipment, short-staffed, a small niche talent and training pipeline, and people dying as a consequence of those systemic problems. That's even closer to my point. Making something regulated doesn't change the inherent problems inside the industry.
It is a top down initiative that needs to happen in a more meaningful way. It’s adjacent in a similar way to the issue of air traffic controllers. Talent shortage, old equipment, old hats, burn out and the like.
It needs some real backing and effort to make it happen.
OT does not equal IT
NSA doesn’t do IT for the DoD/W, DHS doesn’t do IT for the government, CISA only gives guidance where they can. And IT does not equal OT. The issue comes down to actual skilled people hours to do the work and resource constraints to do so.
I agree that in theory this would not be a stretch if the stars aligned, but these are for the most part, not federal government funded entities nor government controlled even at a state level. They are usually clooged together by 100 years of paper maché. And that’s just water. What about Energy? Data Centers? Pharma? Regulation is way too far behind to just instantly drop a silver bullet.
And 100% agree that we are witnessing repercussions of leadership that did not have much forethought but that ain’t new and goes back quite a ways especially in CI.
What does that audit look like and how frequent does that happen? It’s a security assessment? A quality assessment? A risk assessment?
I’m open to the idea, but I will repeat, I don’t think the problem is well enough understood for a “make the feds do it” type of comment.
I much prefer the non-vendor perspective on this. Andy Krapf, co-chair of the Water ISAC, has a great breakdown about the status quo systemic problems that water faces today.
How do you lockdown something that may have not been taken offline for decades because it will cost downtime or harm. Or something that can’t be locked down without tossing new tech around it that may not be compatible with the protocols etc.
Passing the buck to the Federal Government is not understanding the problem.
Passing the buck to the Federal Government is not understanding the problem.
Which is one of MANY problems OT faces. IT best practices don’t suffice in OT and even when they do, most of these orgs are too resource hamstrung to do anything about all of the fires they have to put out.
Not to mention all of the OT vendors who flooded the market with tools instead of people being taught the boring process driven work.
Water is the most underserved sector for resources and yet it is the most critical for life. Unbelievable that it has gotten to this point and no one is sounding the alarm and doing anything about it.
What I found was pretty brutal. Companies asking for 4 years of agentic AI experience… pardon?
Then it hit me.
Oh they are all making shit up now and have no bar that anyone can hit because they are believing in the hype without understanding the fundamentals.
GREAT. Even as I climb the AI-Native ranks, I apparently am unqualified for any AI-Native job.
We are the virtuous ones that need to make the safest model for humanity, because we care more than “they” do. While at the same time saying that “coding is solved” but they still ship bugs themselves, and creating something that is capable of fucking up someone else’s infrastructure. It’s too far gone y’all.
Also, use cases? I’m a little lost after nailing down all the movement.
Can’t use for commercial purposes. Can’t opt out of training. Data retained.