J Wolfgang Goerlich

I’m the unflinchingly optimistic graybeard, wandering in this cyber dystopia. InfoSec, cybersecurity, futurist, strategist, chaotic good. The views expressed are my own. Sometimes humorously.
jwgoerlich.com

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-26

@krypt3ia Oh I won’t! I. Won’t.

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-26

I know, I know. Different companies naming threat actor groups different things is confusing. I get it.

(But real talk, how fun is it that the Iranians are named kittens? Beware the Nemesis Kitten!)

J Wolfgang Goerlich boosted:
Amitai Schleierschmonz@schmonz.com
2025-06-26
Did you know I'm looking for my next employer? Here's what's on offer:

1. Technical breadth and depth
2. Proven delivery experience
3. Thoughtful communication and teaching
4. Bridge-building across roles, silos
5. Team culture and developer happiness
6. Respected industry voice
J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-26

@neurovagrant is there anything legit or valid on a .top domain these days? It’s wild.

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-26
J Wolfgang Goerlich boosted:
2025-06-26

@jwgoerlich Oh sure, let’s cut costs by just training people. Because that’s always worked so well instead of, like, logging.

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-25

Invisible until it breaks: The risk of cutting costs and undervaluing cybersecurity

fastcompany.com/91352486/invis

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-25

@heiglandreas she gets it! I don’t think the customer service people understand the purpose of the steps we security people have them doing. It takes stepping outside of the script to see the flaws.

J Wolfgang Goerlich boosted:
Tom Headtomhead
2025-06-25

@jwgoerlich

“It is I, Mr. Smith. Please let me in.”
“Sorry, I can’t let you in. I don’t know you, Mr. Smith. Oh, there is no picture of you on file. Do you have a recent photo?”
<hands over photo>
“Thank you, I will add this to your file, Mr. Smith. Ah yes, now I recognize you! You are the person in the photo!”

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-25

Them: "In order to make this change, I need to verify you. I'll do this with a one-time text."

Me: Sure.

Them: "We have no phone number on file."

Me: ...

Them: "Not to worry. I'll update your account. What number would you like to use?"

#CustomerService > #Security

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-24

@krypt3ia Fingers crossed. If I can help in any way, you know how to find me.

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-21

@cesarpose Putting aside the joke about the transcription, yep, it’s a feature gone wrong.

openai.com/index/sycophancy-in

J Wolfgang Goerlich boosted:
2025-06-20

This weekend is going to be awesome! 💫😍

Hosting Girls Who Hack and Spawn-Camp day camps 🥳

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-20

Really, AI is sycophantic? Well huh. I hadn’t noticed.

Auto-caption reading: I've been Wolfgang Godlike for Cisco.
J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-19

“Trust the lack of process.”

— Motivational things I say unironically

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-17

@adamshostack 🤔 true, true.

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-17

Don’t do the thing to do the thing. Do the thing so you can do the next thing.

Consider threat modeling. The goal isn’t a thing, a diagram. The goal is insight and understanding.

Taking short-cuts (cough, AI) short-circuits learning.

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-13

Everyone who tries this prompt gets cool cozy desk photos. Picture books and sticky notes and memorabilia related to them. Me? I get an excited Wolf and a confused GPT. Maybe I broke the model.

Based on our conversation history, generate an image that shows what it feels like chatting with me on any given day.
J Wolfgang Goerlich boosted:
2025-06-12

Apropos of everything, I’m so glad I got my trans kid out of Texas.

J Wolfgang Goerlichjwgoerlich@infosec.exchange
2025-06-12

DevSecOps. Where we're going, we don't need roadmaps.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst