Category Archives: Security

No Tab Pete Punches Down: Hitler’s 1942 Pivot and Hegseth’s Domestic Agenda

Germany’s war was lost by December 1941. And yet, Hitler refused to stop killing, sending millions to death. Who and how? That’s the lesson.

The Wehrmacht stalled at Moscow, the United States entered, and the economic arithmetic that Adam Tooze later laid out in The Wages of Destruction was clearly settled. The “myth” of Rommel is a perfect example. Montgomery broke him by November 1942 and he was flown out of Tunisia in March 1943 with Torch closing from the west. The arrogant, impatient Nazi general was outsmarted and outclassed, losing badly. For two more years he was used a propaganda asset, until the regime demanded he commit suicide and staged his state funeral as killed by enemy wounds.

What followed for three and a half years was a regime that could no longer win a battle against an army, so it instead punched down like a bully who fixated on people who could not fight back. Sound familiar?

Europe-wide extermination was on the table by December 9, 1931, when the Münchener Post printed the Nazi party’s leaked plan for the Jews and its own word for the end state, Endlösung. The Nazis answered by destroying the paper and sending its reporters to Dachau. Historians who date the “decision” to autumn 1941, at the peak of “perceived victory” propaganda, are dating the moment the regime believed it could carry out what it had already published.

The rapid scaling of it came with the reality of imminent defeat.

Wannsee in January 1942 was the genocide organization moment, which today extremist right-wing Germans call “remigration”; a term the AfD party hopes MAGAs them into power. By 1943 trains ran full to Sobibor and Treblinka while the Wehrmacht lacked rolling stock for the front. In March 1944 Hitler occupied Hungary, his own ally, to “remigrate” (AfD term for it) 437,000 Jews to Auschwitz in eight weeks. When Hungarian leader Horthy tried to surrender to the Soviets in October, Hitler had his son kidnapped, deposed him, installed the Arrow Cross, the Hungarian fascists the Germans put in to keep mass murder going, who shot thousands into the Danube and marched tens of thousands toward Austria.

The front was begging, pleading for help yet every one of Hitler’s preferred operations consumed trains, guards, fuel and administrative capacity to punch down on the helpless instead of fight the war. The Reich fought the defenseless, because the defenseless were the only target Nazis could reliably hit.

The Nazi pattern is to claim victim status, declaring themselves unfairly hated, and use that to become more and more hated as a means to take power. Aggression is the whole doctrine, spray at targets until empty, then turn on whoever is nearby and weakest when the magazine runs dry.

Blundell says he just walked Thompson’s 1941 “Who Goes Nazi?” through Bavaria. My reading is that he has cast the cabinet well: Vance the humiliated intellectual, Miller the same without charm, Hegseth the spoiled son in costume. But then Blundell flubs Thompson’s famous line, that nice people never go Nazi. BRZZZZT. Wrong. Her real test was a code, that anything inside that says no becomes the enemy of Nazis. The Dutch clerks who shipped mountains of gold to Hitler and their registries to murder 75% of their neighbors who were Jews were all… nice by Nazi standards. Dachau was opened in 1933 specially to dispose of anyone declared rude: union men, journalists, priests.

Bullies clear the room of the rude, the refusers, then cite the polite survivors as consent. Hegseth purging generals with tabs is that exact same mechanism running now. Pete’s purged Pentagon has performed the first two Nazi platform procedures in Iran: no fire discipline, “max lethality”, and a depleted magazine.

The third procedure is on the domestic side, and it was prepared before the Iran war. It was clearly Nazi doctrine as well, in preparation for the punching down that comes next.

In 2025 the administration sent 7,000 troops into American cities over the objections of their governors, put active duty Marines into Los Angeles during the immigration crackdown, and told the generals at Quantico that American cities were the training ground.

A federal court entered judgment that the Los Angeles deployment of 4,000 Guard and 700 Marines violated the Posse Comitatus Act: troops making arrests, running traffic, controlling crowds. The targets were immigrants and protesters in cities the President lost.

I grew up studying Posse Comitatus as a bipartisan, but especially right-wing extremist, bright line. America was said to never, ever cross it, because that would be tyranny time. The other bright line was said to be construction of massive camps, like the permitting of “processing” (data center) facilities. Yet Trump has killed both those canaries so fast it’s like the shock of a Nepalese glacial tsunami hitting Americans right about now.

The obvious hurdle is the November election. Trump said on May 12 he would not rule out troops at polling places. Hegseth, asked in April whether he would follow an order to seize ballots, called the question a “gotcha hypothetical”.

It’s not a hard question, yet no tab Pete struggled to answer. Federal law since 1865 bars armed federal forces at the polls except to repel armed enemies of the United States, an exception no president invoked even during two world wars.

On August 18 Senator Slotkin asked Hegseth and General Caine for one written sentence: no troops at the polls, no seizure of election material. Caine signed. He wrote that the Joint Force has no plans to send federal military personnel or federalized Guard to polling places, no plans to seize ballots or machines, and that he has neither received nor anticipates any unlawful order.

Hegseth has not answered. Because he’s no tab.

The generals who earned the tabs he never attempted call him No Tab Pete for a reason. The nickname is about a course he did not take. And it’s about to mean something far worse, basdd on a sentence he will not sign.

MD Tesla Kills One in “Veered” Crash

Police are investigating.

The single-vehicle crash happened shortly before 3:30 p.m. on the northbound side of the parkway at Fort Meade Road. According to preliminary information, the Tesla veered off the parkway and crashed into a stone bridge under Fort Meade Road.

Firefighters were at the scene working to extinguish the fire. More than half an hour after the crash, they were seen spraying a still-smoking vehicle with water. A large grassy area around the crash site was visibly charred.

Fighting AI Speed is Like Trying to Outswim Loch Ness Monster

Marcus Hutchins published a highly credentialed anti-hype AI risk piece. His conclusions read right to me. Credential Guard, LAPS, segmentation, automatic quarantine, credential rotation are the basics. The basics hold. None of it needs a model. All of it predates the marketing.

That being said I have to protest how he gets there. He argues against “machine speed” using the same mistake that the claim is built on.

Look at how he accepts CrowdStrike’s 29-minute average and 27-second fastest breakout as “solid numbers” and then rejects the 89% AI-enabled figure beside them. Well, that is the same Falcon telemetry, same press release, same selection bias, same, same. He takes what helps him, and leaves the rest, which is what every vendor does with that report. The end he arrives at seems ok, but his means are not.

His core claim, that attackers are not adopting generative AI, is a good example. It all rests on this:

It’s a rare vantage point, but having spent over a decade as a threat intelligence analyst, I’ve gotten to analyze the inner workings of plenty of threat actors’ infrastructure.

Probably true. And also completely unverifiable, which is his complaint about others. The prohibitionist drinks beer? A CISO cannot weigh Hutchins’ visibility against CrowdStrike’s because neither of them is open to inspection. That is how we lose science and end up in mythology, marketing fills the void. It has to be plausible, like a narwhal tooth invents the unicorn. The rebuttal however has to be provable with instruments that may be hard or impossible to get.

Then he prices the AISI Mythos evaluation at $8,000 to $42,000 per successful compromise and says a crew could hire humans for less. Mythos Preview is gated to roughly forty approved organisations, but it seems no crew can buy it at any price.

The actual available commodity baseline is what matters, which is why I have been publishing it since April. AISLE reproduced the showcase Mythos finding on eight of eight open-weight models, one at eleven cents per million tokens. I built Lyrik on Wirken and matched two flagship bugs from the Mythos system card for seventy five cents. Hutchins prices a model no attacker can buy, and then skips past the numbers that would answer his own question.

He says AI attacks are “extremely rare” and every one “makes headlines,” as if that could be proven, then names only PromptLock, a university project. That’s it?

I can think of two other cases. Anthropic’s GTG-1002 report of November 2025 claimed a Chinese state actor ran Claude Code against roughly thirty targets at 80 to 90 percent autonomy. Anthropic detected it, attributed it, wrote it up, and nobody corroborated. That is self-citation, should be panned as such, which Hutchins skips.

The second case has no lab in the loop. OALABS published full session logs in June of an amateur in Addis Ababa who used Opus 4.5 and Codex to breach at least fourteen companies by typing “recon this” and framing every prompt as an authorized red team. Three generations behind the frontier, a consumer subscription, a novice, fourteen networks. That is the machine-speed case as it actually exists, and it fits neither the vendor story nor the “attackers aren’t adopting” story. Hutchins leaves it out, and it would change his whole story.

His pre-AI window is a year too long too. He dates attacker access to generative AI at ChatGPT, 30 November 2022, and shows breakout times falling before it. GitHub Copilot went to public preview 29 June 2021. The GPT-3 API dropped its waitlist 18 November 2021. The trend is observable, and the date he gave it isn’t right.

I guess I remember it because it was late to me, given that in 2012 I gave a BSidesLV talk titled Big Data’s Fourth V: Or Why We’ll Never Find the Loch Ness Monster. Back then all the emerging intelligence technology was seeing only three Vs (volume, variety and velocity). The fourth, I started arguing, was vulnerability, the data itself as the attack vector. I called it Loch Ness to make a warning. An industry that cannot verify inputs will manufacture FUD, like a monster it can never confirm and never dismiss, sustained by the people who sell trinkets aroud the myth. That means when someone talks about machine speed, ask yourself if they are describing the current Nessie swim speed sighting.

Hutchins says the monster is a log, nothing to worry about. He uses the same photograph as the people who say it is a monster to make his point. I say neither can produce the data lake that would settle the question. The ranges, the telemetry, the model access belong to parties whose revenue depends on the sighting staying unresolved. The basics work because they presuppose the risks and do not depend on the answers.

The reason we keep having this argument is that everyone who could end it earns more by leaving it open.