A dozen years of paid break-ins, and I’d like to say they were all challenging. Mostly, someone had left a credential somewhere sensible that could reach somewhere it shouldn’t, and we followed it. Compromise is usually a reachability problem. The exploit is the part that gets the conference talk.

I still find attack paths. The difference is that I’m now in the room while the system is designed, which is cheaper for everyone. The boundaries are the same ones: identity, tenants, and now the agents we hand credentials to on purpose.

I co-founded Adversis and Puck. Puck answers, from here, what an attacker can actually reach. There is also a book. No Starch is publishing it, so presumably there will be a robot on the cover.

Nothing new here

Every serious compromise I’ve walked through has had roughly the same plot. Usually no zero-day. A token, service account, extension, or forgotten permission could reach more than anyone remembered granting, and the attacker found out first.

The distance between what something is meant to touch and what it can touch is most of the job.

Agents make that more interesting. The thing holding the credential now also reads untrusted text and decides what to do next. The desktop agent is the new browser, except we’re skipping thirty years of hardening and shipping it with prompt injection unresolved.

Currently exploring problems like whether constrained encoding and decoding can make agent output boring enough to trust, what intent-based access control means when the intent arrives as prose, and what happens when both sides automate. Red teams already run fleets of agents. The defense worth building reaches the whole fleet at the first tripwire.

The other recurring problem is measurement. The industry can measure less than it pretends to. The papers that changed my mind are on the resources page.

Tools

All the tools →

Writing

More →

Now

Fractional CISO for a handful of companies through Adversis. AI security assessments for a few more. Building Puck, which is mostly about answering “are we affected?” from the endpoints instead of from a meeting.

Email noah at this domain. Haikus get read first. Everything else gets read eventually.

Elsewhere

GitHub (@thesubtlety, and @noahpotti) · LinkedIn · Adversis · Puck Security