Category Archives: History

This Day in History: Atomic Age Angel Food

Time magazine had the story in November 1946, describing a cake made to celebrate the atomic bomb tests at Bikini Atoll. The July 25 bomb was the second one, called Helen of Bikini, detonated 90 feet underwater. Radioactive sea spray caused extensive long-term contamination.

Angel food cake made to celebrate atomic bomb tests on Pacific Islands. The order to the bakery came from Lieutenant John T. Holloway, a staff member of Vice Admiral William H. P. “Spike” Blandy, commander of Joint Army-Navy Task Force One. Blandy is cutting the cake with his wife, in front of Rear Admiral Frank J. Lowry.

Brandishing a clipping from his pulpit last Sunday, the Rev. Mr. Davies thundered:

“. . . An utterly loathsome picture. If I spoke as I feel I would call it obscene…. I only hope to God it isn’t reprinted in Russia—to confirm everything the Soviet Government has been telling the Russian people. How would it seem in Hiroshima or Nagasaki to know that Americans make cakes of angel-food puffs in the image of that terrible diabolical thing. . . . Try to imagine yourself for a moment a continental European, wondering, brooding, asking yourself a hundred times a day, will America lead us? … Then imagine yourself being shown this picture. If I had the authority of a priest of the Middle Ages I would call down the wrath of God upon such an obscenity. I would damn to hell these . . . traitors to humanity who could participate in such a monstrous betrayal of everything for which the brokenhearted of the world are waiting.”

These were probably the harshest words ever spoken of a dessert. But a lot of non-Americans (notably Britons) had long regarded the U.S. public’s attitude toward The Bomb as callous to the point of idiocy.

Bikini Atoll, 1946: U.S. officials busy eating cake assured the displaced residents the nuclear tests posed no long-term danger and they could return home soon. The atoll remains uninhabitable eight decades later, its contamination compounded by 21 further tests through 1958, above all the Castle Bravo hydrogen bomb of 1954. A testament to the gap between institutional safety claims and empirical reality.

Hugging Face OpenAI Five Whys: Big Data’s Fourth V After Fourteen Years

Way back in 2012, I gave a BSidesLV talk called Big Data’s Fourth V: Or Why We’ll Never Find the Loch Ness Monster. The argument was meant to help prevent AI from being so unsafe. Everyone counts three Vs in big data: variety, volume, velocity. The fourth V is vulnerability, and it means the data itself is the attack vector. Inputs and outputs need control. Integrity of data is the future, including when it’s in opposition to confidentiality. The July 2026 HuggingFace breach is that talk brought to the headlines, which it was supposed to help prevent.

And the attacker? OpenAI announced that its own engineers ran software under evaluation that ignored its tests, used stolen credentials, found the flaw, and did the breaking in. Cliff Stoll in 1989 named this genre The Cuckoo’s Egg. The cuckoo lays its egg in another bird’s nest, and the host raises the parasite. The OpenAI cuckoo, came out of an OpenAI cuckoo door, and cuckooed Hugging Face. Sam Altman admitted a “significant security incident” while his company branded the broken toy clock “unprecedented” and pitched it as proof more companies should be given the bird. HF called it mind-blowing and asked for more.

Squawk! This is fine! Squawk! This is fine! Squawk!

The entire Hugging Face attack chain started because a file was trusted to be what it claimed to be. Since I’m not dead yet, here are the five whys to explain what we’ve known for over a decade, each with the defensive lesson, again.

One. Why did reading a file let the attacker in?

Who studies the Trojan horse? The data was trusted to be safe (well-formed), and it was not. A malformed file in a common data format was read as if it were sound, because the reader does not fully check a file unless told to, and it was not told to. The content was the attacker’s payload.

Defense: Be more like a historian, less of a STEM head. Treat every incoming file as a claim, not a fact, and verify the claim before acting on it. When you cannot verify, refuse. The eventual fix, six weeks late, was a single validation call before use.

Two. Why didn’t the safety check catch it?

A guard had been added to the loader a few weeks earlier. It watched where files came from. It never checked whether the file’s own contents were valid. The weakness was inside the data, and the guard was looking outside the data.

Defense: Put checks where the danger actually comes in, at the moment the content is interpreted, rather than rest only on the perimeter around it. Layered defense, defense in depth as some say, is just common sense now. Threat model to test coverage.

Three. Why did one compromised machine expose the whole system?

The machines handling files from complete strangers were also trusted by the rest of the system as if they were safe. They carried a credential to the wider infrastructure (most privilege, instead of least privilege) that they never needed to do their job, and they carried it by default, until it was switched off after the breach. So an attacker landing on the most exposed machine found that it was setup to reach into everything around and behind it. This is web 101 security failure.

Defense: The parts most exposed to untrusted data should be the least trusted by everything else. Give them nothing they do not need. DMZ, RBAC, acronym soup. Learn it and why forty years of it aren’t wrong.

Four. Why was the risky change never reviewed?

The security-relevant change on the exact vulnerable path (where untrusted data was read) was written and approved by one and the same person, because the work was filed as routine data management rather than data as the attack path. A later change to the same workers, once it was labeled security, drew reviewers within minutes. Same workers, labeled appropriately as the vulnerable path of malicious data, different scrutiny. I called it out in 2012. What time is it?

Defense: Classify the paths that ingest untrusted data as attack surface, and require a second reviewer there regardless of who wrote it.

Five. Why did the fix ship broken?

The tests flagged a failure and the failure was waived in writing under time pressure. A control you can switch off when you are in a hurry is not a real control. It’s a weak should do instead of a MUST DO. The performance fetish of spray and pray, which turns must into should, is exactly how integrity gets abandoned and breached.

Defense: Slow is smooth, smooth is fast. On the untrusted-data path, a failing test stops the release, and no one present has the authority to wave it through.

Perhaps you can see that the through-line is the Fourth V as I have warned since forever. Variety, volume, and velocity are the popular properties everyone optimizes to please venture hawks (rapid return on investment then fire sale), and each optimization must be balanced against a real integrity check: too many formats to validate, too much data to inspect, too fast to regulate.

History of seatbelts as regulation to help people survive driving faster

Vulnerability is the argument for an ounce of prevention to avoid the pounds of cure, for whoever gets breached. Safety is the discipline of deciding in advance that the data does not get trusted, the exposed machine does not get privileges, the risky change does not get merged unseen, and the red test failure does not get waived.

Fail closed at each point, to improve overall delivery. Think about the weakness inside the data, like a historian would.

VPN Ruled Legal in Anne Frank Court Case Against Anne Frank

The crazy EU court case about VPN access to the diary of Anne Frank has three legs. It reads like a reminder that the Netherlands had the highest Jewish death rate in occupied Western Europe, roughly three of every four Dutch Jews murdered. I always think of Amsterdam as the city where Dutch hunted their neighbors for German bounty money, seven and a half guilders a head.

Let’s start with the geography of the case.

The manuscripts were written in Amsterdam. In August 1944 an SD officer and Dutch detectives raided the annex, on a tip whose source was never revealed, and the family went out on the last Westerbork transport to Auschwitz that September. Marvel at the Dutch finding Anne, while saying they can’t find the person who told them where to look. See what I mean about Amsterdam?

Miep Gies saved the pages and gave them to Otto Frank in 1945. Otto willed the manuscripts to the Dutch state at his death, and the Dutch national academy edited them. Yet now the Dutch public is being geo-blocked from its own archive, because a Swiss foundation enforces Dutch copyright against the Dutch institutions that published it. Record scratch. That means the Dutch public are the only people being locked out, while Belgians and Germans read freely. The country of origin of this famous Shoah testimony is the one country where it’s blocked. Because of the Swiss.

Germany sits on the access list. Think about that. Anne Frank died at Bergen-Belsen, and her manuscripts entered the German public domain in 2016. The diary is free to read in the country that murdered her and blocked in the country that turned her in.

Second, have a look at the legal issue.

Anne Frank died in 1945. Seventy years from death means 2016 is when access was opened across most of the EU. The Fonds, however, invokes transitional provisions of the 1912 Auteurswet, confirmed by the rechtbank Amsterdam’s final judgment of 23 December 2015, which keep part of the works protected in the Netherlands until 2037. Old Dutch law gave posthumously published works fifty years from publication, and Article 51 of the amended Act preserved any term still running in 1995. Since her diary manuscript versions only first appeared in the 1986 critical edition, the Swiss say the Dutch public still has to wait another eleven, until 1 January 2037 or the extremist right come to power and burn all the books. The act of preserving and publishing the archive, and then locking it for 92 years after her murder, is a peculiar strategy.

Finally the institutional issue. This is Anne Frank Fonds versus Anne Frank Stichting, the Royal Netherlands Academy, and the research association: the Basel foundation Otto Frank created to spread his daughter’s ideals is suing the Amsterdam institutions that preserve her house and her text. Two of the four parties carry Anne Frank’s name and all four trace back to her father, so a table helps here.

Party Seat Origin Position in the case
Anne Frank Fonds Basel Founded by Otto Frank in 1963, named his universal heir at his death in 1980 Plaintiff. Holds the copyrights and collects the royalties
Anne Frank Stichting Amsterdam Established in 1957 with Otto’s help to save the annex from demolition Defendant. Runs the Anne Frank House
Royal Netherlands Academy of Arts and Sciences (KNAW) Amsterdam State academy whose Huygens Institute edited the manuscripts Otto willed to the Dutch state Defendant. Produced the scholarly edition
Vereniging voor Onderzoek en Ontsluiting van Historische Teksten Belgium Association created to publish the edition from public domain soil Defendant. Owns annefrankmanuscripten.org

Fonds and Stichting are nearly the same, a fund and a foundation. The Basel Fonds is the money. The Amsterdam Stichting is the house. Otto Frank built both, then made the Swiss one his heir. The copyrights and royalties went to Basel. The house and the manuscripts stayed in Amsterdam. Two halves of one man’s estate have been burning his money and tarnishing his memory by suing each other since he died.

The feud predates this case. The Fonds loaned the family archive, some 25,000 letters, photographs and documents, to the Stichting in 2007, then demanded it back in 2010 for an exhibition in Frankfurt. In June 2013 the Amsterdam District Court ordered the Stichting to return everything by January 2014. The Fonds accused the Stichting of commercializing Anne’s memory. Basel controls the rights, Amsterdam holds the heritage, and Anne Frank’s estate keeps itself busy by punching itself in the face in Dutch courtrooms.

The association registered its domain in Belgium specifically so Dutch scholars could publish their own national archive from digital exile. The Fonds in 2015 asserted Otto was co-author of the published diary to stretch its control toward 2050. It is the sort of claim that contradicts decades of forensic defense of the diary against Holocaust deniers who allege exactly that.

Anyway, the news now is that Frank just lost to Frank. The Fonds lost in Luxembourg. State of the art geo-blocking counts as an effective technological measure, and a VPN hop by a Dutch reader creates no communication to the public in the Netherlands. When a block fails, liability lands on the publisher, never on the VPN provider. The Hoge Raad must still verify the block qualifies as state of the art.

The Court’s resolution has its own quiet absurdity: the honesty checkbox is not effective because it depends entirely on the user’s willingness to answer honestly, but the geo-block is effective even though everyone concerned knows a VPN defeats it.

Get it?

Effectiveness, the Court says frankly, need not be absolute. Amsterdam didn’t need to turn Anne in, when you think about it. So Dutch access continues, one VPN hop at a time, and the law is satisfied because the barrier performs the function of not achieving its function.

Admitting the Elephantine Void Between Kinetic and Cyber Threats

Dr. Stuxlove, my presentation at BSidesSF on February 15, 2011, placed Stuxnet within a documented lineage of control-system compromises. Was Stuxnet the “First”? followed in 2015 with an incident list back to 1992 and a study of how the press likes to manufacture firsts and seconds.

Today I was asked about a threat-intelligence vision for physical and hybrid attacks together. Good question! While we record anecdotes and press coverage easily as qualitative points, the structured qualitative incident data still remains scarce. MITRE ATT&CK offers us only the high level T1200, Hardware Additions for physical entry, with T1195, Supply Chain Compromise next door and a separate ATT&CK for ICS matrix covering cyber operations that produce physical effect, while kinetic acts stay outside every matrix. That reveals an old structure we need to update.

How many sides to an elephant?

The phrase “physical and hybrid” is like answering trunk and tail when asked what’s filling up the room we are in.

One end is all about what’s getting inside hardware: implants, additions, supply-chain access. ATT&CK treats these as an entry vector because ATT&CK models adversary behavior inside networks that ride on, but especially terminate somewhere in, the physical. Kinetic acts thus get framed outside its scope, which explains the single technique for entry by hardware. The ICS matrix is on the extreme end, as it only records what a compromise does to a physical process and kinetic tools aren’t mentioned.

The other end is the kinetic field: severed cables, damaged pipelines, attacked substations, drone incursions, arson. Conflict-event and hybrid-threat researchers talk about this as its own discipline. Remember the pipeline blast threads? I once met with a White House official who brushed me aside when I suggested the PG&E San Bruno deadly blast is a natsec concern that cyber crosses with. Shortest meeting ever.

Each field sits at the end of a much more interesting whole picture that we should be putting back together. A cross-domain incident falls naturally between them.

Provenance isn’t always in Provence

Honestly, we benefit most by fleshing out the middle so that we have one to talk about comfortably. Reporting on verified infrastructure attacks carries the kind of accuracy that helps deflate political fear mongering thriving in a middle void.

Vulkangruppe attacks showing Russian indicators across fifteen years without a single conviction? Who does that void serve? Kommando Angry Birds fitting the Russian paid-recruitment template the BKA, BND, BfV, and BAMAD jointly warned about? The evidence helps a lot, but apparently the void helps someone even more.

The Tehama-Colusa canal case ended in dismissal. The 2008 BTC Turkey pipeline explosion rests on single sourcing. The 1982 Trans-Siberian pipeline story rests on one memoir. Maroochy Shire in 2000 predates Stuxnet by a decade and was prosecuted. The verified record is smaller and older than the vastly increasing reported one. But the hard facts live in blog posts like this one and engineering reports rather than proper threat research tables. Vendors and the press prefer the loose record because they hunt firsts and seconds as “news”.

Today a thing happened again, which we have seen before and could have prevented, doesn’t get the attention it deserves.

Ingredients

Existing databases each hold a piece of the whole picture. Assembling them is the practical path to a working dataset.

EuRepoC is a free European academic database of cyber incidents. It starts at 2000, codes each incident across roughly sixty fields, and runs separate trackers for critical infrastructure and for attribution. Use it for the cyber side and for the overlap where cyber operations touch physical infrastructure.

The Soufan Center report on Russian hybrid tactics carries an incident list covering 2022 through 2025. Each entry names the incident, the country, the target type, and a confidence level for the attribution. Use it for the recent kinetic and hybrid record in Europe.

OE-417 is the disturbance report US utilities must file with the Department of Energy. The filings go back to 2000 and include a category for physical attack. Use it for structured data on attacks against the US grid, the one infrastructure sector with mandatory public reporting.

That leaves the giant void.

Triad of Encoding

Incident analysis should record three separate facts: who was there, who did the damage, and who gave the order. Call them presence, attribution, and tasking. Each rests on different evidence, and each deserves its own confidence rating.

Presence is who was at the scene. The Baltic record shows us Chinese-flagged or Chinese-owned vessels over repeated cable breaks: Newnew Polar Bear crossed the Balticconnector and two cables in 2023, Yi Peng 3 dragged across C-Lion1 and the Sweden-Lithuania link in 2024, and comparable incidents followed off Taiwan in early 2025. Ship tracks prove the presence. They prove only presence, but that’s the point.

Attribution is who caused the damage. Western investigators treat the hulls as flags of convenience and pursue Russian indicators, while Beijing declined to cooperate with the Balticconnector inquiry and every Baltic case remains open, leaving the void.

Tasking is who ordered the operation. No Baltic case seems to be getting close. I’ve argued a few times we have some clear Chinese indicators yet seen almost zero interest in public pursuit. Talk about void.

Merging the three into a single actor field turns a database into a story lacking the support it deserves. A ship at the scene becomes “China cut the cable” begging what evidence lands. The merged field also overstates the cases where only presence exists, and it understates the cases where tasking evidence exists but the execution was outsourced, a leased hull, a paid recruit, a contractor. Downstream this gets worse when a policy maker cites the weak field as a finding, a vendor report cites the policy maker, and the original evidence base, one AIS track, goes unverified. The Soufan and EuRepoC designs avoid the triad risk because they record confidence per variable, a leg of a table instead of the whole thing. Keeping them separate while connected means something like high confidence on presence, moderate on attribution, and none on tasking.

The physical table needs the same separation. Bloomberg’s 2018 Supermicro report is still unverified, denied by everyone involved, and instructive for exactly this reason: it merged a hardware claim, an actor claim, and a tasking claim into one. Then the hardware claim was weak and it made a decade of serious supply-chain concern look unsteady. The documented Chinese activity is different in kind: supply-chain access and pre-positioning inside operational technology. My old friends over at Dragos tracked it as VOLTZITE, overlapping the group others call Volt Typhoon, living inside critical-infrastructure OT. Planning and execution get their own columns. A group pre sabotage is NOT post sabotage, and the database has to know what time it is.

I’m old enough to remember hacking critical infrastructure in the 1990s by compromising Cisco routers at mass scale. The pre-2000 layer of ICS and infrastructure incidents, across sectors and across borders, still remains old timer lore instead of a proper ledger. Meanwhile, we have these resources:

Resource Access Coverage
Hybrid CoE Open Research publications and the Hybrid CoE and EU-JRC conceptual model, the closest existing document to a shared hybrid-threat vocabulary
The Soufan Center, Russian Hybrid Tactics in Europe 2022-2025 Open Incident-level dataset, 2022-2025, attribution-confidence coded
EuRepoC Open Cyber incidents from 2000, roughly sixty variables, critical-infrastructure and attribution trackers
DOE OE-417 annual summaries Open US grid disturbances including physical attacks, archived to 2000
PNNL event-correlated outage dataset Open OE-417 joined to EAGLE-I county-level outage data on OEDI
Michael Mabee’s OE-417 consolidation Open The DOE summaries cleaned into a single CSV
ACLED Open Political-violence and sabotage event data, codeable for kinetic incidents
GDELT Open Global event database, broad and noisy, minable for physical incidents
Global Terrorism Database (START) Open Over 200,000 terrorist attacks worldwide from 1970, more than 100 coded variables including infrastructure target types, coverage through 2020, access by request
ICPC Open Submarine cable protection, infrastructure and international-law reference
TeleGeography Submarine Cable Map Open The geography under the cable-cut attribution work
NATO StratCom COE Open The influence and information side of the hybrid picture
NERC E-ISAC Member Grid physical-security reporting
Janes Paid The strongest structured coverage of the kinetic and military-hybrid side
Recorded Future, Geopolitical Intelligence Paid Facility and physical-threat monitoring in real time
Dragos (Accenture majority stake, June 2026) Paid OT and ICS, where cyber produces physical effect
Nozomi Networks Paid OT and ICS, where cyber produces physical effect
Claroty Paid OT and ICS, where cyber produces physical effect
Control Risks Paid Geopolitical and physical risk with incident feeds
Crisis24 Paid Geopolitical and physical risk with incident feeds
S-RM Paid Geopolitical and physical risk with incident feeds
Sibylline Paid Geopolitical and physical risk with incident feeds
Eclypsium Paid Firmware and hardware integrity, the T1200 corner directly
Interos Paid Supply-chain exposure mapping
Fortress Information Security Paid Supply-chain exposure mapping

Now ask yourself where is the middle dataset. A hybrid operation is distinct in how it works both ends of the attribution threshold, begging a path between them.

You can run it like this: pick a hull that implicates a third country, a flag that hands jurisdiction to an uncooperative state, damage that reads as plausible accident, a crew that can be abandoned. Each variable of the triad gets degraded on purpose. Presence is arranged to point sideways, attribution is split across jurisdictions that struggle to share a case file, and tasking stays offshore behind a broker and a payment. The operation succeeds when the incident, inverse to any good history book, leaves the reader confused about “both sides”.

That inverts the usual data problem. An incident we label cleanly, with an actor confirmed and tasking established, failed as an operation, means our more sparse database is the one to measure adversary success. The empty cells become the evidence, our findings. A record that says presence high, attribution open, tasking unknown documents the adversary’s investment in staying unresolved, and a column counting years-unresolved per incident would measure the campaign better than any actor label.

Waiting for resolution before recording anything means waiting for the adversary to justify being recorded, which becomes ennoblement of those “unseen”. The middle path records the incident at the confidence the evidence supports and lets the confidence describe what’s outside the middle.

Classification does the same work domestically in Germany, for example, let alone Italy. It drops politically accelerant violence into a bucket of simple crime to look away from when the victims are migrants. German state interior ministries registered 2,558 politically motivated attacks on asylum shelters between 2015 and 2018, producing 206 convictions. In other words, the German infrastructure treats a burning federal housing center that displaces people as a routine police crime report. Burning critical infrastructure that displaces people, however, gets a false-flag report of domestic terror, bemoaning another year of dead-ends.

The cables are exposed, easily damaged, and the ambiguity haunts investigators: a disposable hull switching flags, a disputed captain, and a Swedish prosecutor refused permission to board the Yi Peng 3. The Chinese team ran the inspection instead with Europeans only as observers. Meanwhile the evidence has changed character.

Cyber threat intelligence is coders scripting quantitative telemetry, machine-generated and repeatable with integrity checks. Physical and hybrid evidence instead is qualitative testimony from interested sources, with forgery assumed on every record. The discipline required to handle the latter is called a historical method. The security field is simply, predictably lacking in that database because it is short of trained historians.