Category Archives: Security

MD Tesla Kills One in “Veered” Crash

Police are investigating.

The single-vehicle crash happened shortly before 3:30 p.m. on the northbound side of the parkway at Fort Meade Road. According to preliminary information, the Tesla veered off the parkway and crashed into a stone bridge under Fort Meade Road.

Firefighters were at the scene working to extinguish the fire. More than half an hour after the crash, they were seen spraying a still-smoking vehicle with water. A large grassy area around the crash site was visibly charred.

Fighting AI Speed is Like Trying to Outswim Loch Ness Monster

Marcus Hutchins published a highly credentialed anti-hype AI risk piece. His conclusions read right to me. Credential Guard, LAPS, segmentation, automatic quarantine, credential rotation are the basics. The basics hold. None of it needs a model. All of it predates the marketing.

That being said I have to protest how he gets there. He argues against “machine speed” using the same mistake that the claim is built on.

Look at how he accepts CrowdStrike’s 29-minute average and 27-second fastest breakout as “solid numbers” and then rejects the 89% AI-enabled figure beside them. Well, that is the same Falcon telemetry, same press release, same selection bias, same, same. He takes what helps him, and leaves the rest, which is what every vendor does with that report. The end he arrives at seems ok, but his means are not.

His core claim, that attackers are not adopting generative AI, is a good example. It all rests on this:

It’s a rare vantage point, but having spent over a decade as a threat intelligence analyst, I’ve gotten to analyze the inner workings of plenty of threat actors’ infrastructure.

Probably true. And also completely unverifiable, which is his complaint about others. The prohibitionist drinks beer? A CISO cannot weigh Hutchins’ visibility against CrowdStrike’s because neither of them is open to inspection. That is how we lose science and end up in mythology, marketing fills the void. It has to be plausible, like a narwhal tooth invents the unicorn. The rebuttal however has to be provable with instruments that may be hard or impossible to get.

Then he prices the AISI Mythos evaluation at $8,000 to $42,000 per successful compromise and says a crew could hire humans for less. Mythos Preview is gated to roughly forty approved organisations, but it seems no crew can buy it at any price.

The actual available commodity baseline is what matters, which is why I have been publishing it since April. AISLE reproduced the showcase Mythos finding on eight of eight open-weight models, one at eleven cents per million tokens. I built Lyrik on Wirken and matched two flagship bugs from the Mythos system card for seventy five cents. Hutchins prices a model no attacker can buy, and then skips past the numbers that would answer his own question.

He says AI attacks are “extremely rare” and every one “makes headlines,” as if that could be proven, then names only PromptLock, a university project. That’s it?

I can think of two other cases. Anthropic’s GTG-1002 report of November 2025 claimed a Chinese state actor ran Claude Code against roughly thirty targets at 80 to 90 percent autonomy. Anthropic detected it, attributed it, wrote it up, and nobody corroborated. That is self-citation, should be panned as such, which Hutchins skips.

The second case has no lab in the loop. OALABS published full session logs in June of an amateur in Addis Ababa who used Opus 4.5 and Codex to breach at least fourteen companies by typing “recon this” and framing every prompt as an authorized red team. Three generations behind the frontier, a consumer subscription, a novice, fourteen networks. That is the machine-speed case as it actually exists, and it fits neither the vendor story nor the “attackers aren’t adopting” story. Hutchins leaves it out, and it would change his whole story.

His pre-AI window is a year too long too. He dates attacker access to generative AI at ChatGPT, 30 November 2022, and shows breakout times falling before it. GitHub Copilot went to public preview 29 June 2021. The GPT-3 API dropped its waitlist 18 November 2021. The trend is observable, and the date he gave it isn’t right.

I guess I remember it because it was late to me, given that in 2012 I gave a BSidesLV talk titled Big Data’s Fourth V: Or Why We’ll Never Find the Loch Ness Monster. Back then all the emerging intelligence technology was seeing only three Vs (volume, variety and velocity). The fourth, I started arguing, was vulnerability, the data itself as the attack vector. I called it Loch Ness to make a warning. An industry that cannot verify inputs will manufacture FUD, like a monster it can never confirm and never dismiss, sustained by the people who sell trinkets aroud the myth. That means when someone talks about machine speed, ask yourself if they are describing the current Nessie swim speed sighting.

Hutchins says the monster is a log, nothing to worry about. He uses the same photograph as the people who say it is a monster to make his point. I say neither can produce the data lake that would settle the question. The ranges, the telemetry, the model access belong to parties whose revenue depends on the sighting staying unresolved. The basics work because they presuppose the risks and do not depend on the answers.

The reason we keep having this argument is that everyone who could end it earns more by leaving it open.

DHH Nazism Funded by 1Password VP Who Wrote “Honest Security”

Jason Meller wrote a security rulebook. I read it. He is in direct violation of it.

As CEO of Kolide, Meller published honest.security and reduced it to five tenets on December 8, 2020. The first: “The values your organization stands behind should be well-represented in your security program.” That’s politics at work. The third holds that trust is demonstrated through informed consent and transparency. The fifth holds that people make rational decisions about risk when they are educated and honestly motivated. Then 1Password, whose 2021 round was joined personally by Shopify’s Tobi Lütke and Harley Finkelstein, the executives who platformed Nazi merchandise and seated David Heinemeier Hansson (DHH) on their board, bought Kolide in February 2024, made Meller VP of Product, and still publishes the document as the guiding principles of its Device Trust product.

Houston, we have a problem.

DHH published his infamous Nazi screed called “As I remember London” on September 15, 2025. The post mourns a London no longer full of “native” British and approves a right-wing Tommy Robinson march promoting white supremacy.

Meller answered the criticism of DHH on September 26, 2025 with a photo of a child in a dance costume, back turned to the camera, at the edge of a lifeless/closed private pool. With that he boasted he became a multi-millionaire thanks to Rails, DHH, and the company DHH keeps: “Let’s ignore the noise and keep building.”

Source: Twitter

He posted that as a director of the Rails Foundation, which DHH chairs. 1Password had taken a board seat in 2024 and Meller filled it with such questionable “values”. Again, this was the guy who wrote a rulebook saying work is political, where trust is earned.

Fast forward to July 12, 2026, DHH published The will to power will return.” He tries to gin up a “loss” narrative to evoke FUD, claiming the West has lost its will, weak men have made hard times, a hero generation will end the managed decline, and the last such Crisis ended in total war, so do not bet against another. That title is Nietzsche’s phrase fraudulently repackaged by his antisemitic sister Elisabeth Förster-Nietzsche: she made a posthumous compilation cut from his notebooks into a racist doctrine of strength over weakness, which was adopted by the Nazis. It has been treated by scholars as hers rather than the philosopher’s since the Colli-Montinari edition. This isn’t obscure history. Hitler ran PR at her Weimar archive in 1934, photographed at the door taking her hands, and photographed inside contemplating the bust of her brother.

Elisabeth Förster-Nietzsche happily welcomes Hitler at the door of the Nietzsche-Archiv, Weimar, 1934, offering him a warm smile and both hands. Source: Germanisches Nationalmuseum, Deutsches Kunstarchiv, http://www.gnm.de/museum/abteilungen-anlaufstellen/deutsches-kunstarchiv/

Days later DHH published the word remigration, Martin Sellner’s Potsdam term for forced deportation of settled populations, documented here at the time, because it’s Nazi propaganda worth identifying as such.

On July 21, 2026, DHH doubled-down on all this Nazism with “Wolves, sheep, and gypsies.” He describes Romani people in Copenhagen parks beside a wolf population and states the remedy for one is shooting and the remedy for the other is deportation. Make no mistake. DHH pushes the dehumanization of an ethnic group in preparation for its removal on force of death. It is the rhetoric that preceded the Porajmos. DHH then complained publicly when Claude refused to translate his Nazi propaganda into Italian.

On August 31, 2026, DHH named 1Password a Distinguished Corporate Patron of his Omacom Foundation, $100,000 a year for three years, in a quid pro quo he described the same afternoon as proof open source need not be a “commune.”

Source: Twitter

“Commune” is the Nazi dog-whistle of being anti-communist, the antisemitic project from the start: it’s how the NSDAP fused Jews and the labor movement into being their “one” enemy of “Jewish Bolshevism”. Rosenberg’s 1936 Nuremberg speech made the equation explicit. Seven weeks after the will-to-power essay, DHH spoke of a commune as his enemy on the day he took 1Password’s money.

1Password is the first corporate patron he does not own, and the independence ends there. Lütke, on 1Password’s cap table since 2021, pledged $1 million on August 21. His portfolio company followed in ten days. The quid was the default install slot 1Password had held since Omakub. DHH thanked Meller by name for leading it.

Meller had already explained the bond the evening before: DHH pitched him one-on-one for two hours, and he switched to Mac for Rails and DHH seventeen years ago and is switching platforms again for him now.

Source: Twitter

Then he called DHH’s past year a masterclass in “force of will”. Nine days before the deportation post, DHH’s own headline had announced the return of the “will to power”, the phrase identified above. Meller’s words echo the DHH Nazi title, seven weeks on.

Jason Meller, VP of Product at 1Password, August 30, 2026. “Force of will” repeats the title DHH gave his July 12 essay, nine days before the Romani post. The 1935 film title was Triumph of the Will.

On August 31 Meller produced the metric that became the company’s defense: Omarchy is the third largest Linux distribution among active 1Password users and first on weekends. DHH called it crazy. A fan called it his cocaine energy. You know, weekend stuff.

Source: Twitter

When employees and customers objected, this data point was cited. CEO David Faugno told staff the money goes to a foundation and not a person (e.g. to a NSDAP not to Hitler himself), that 1Password rejects DHH’s exclusionary views without offering proof, and that Omarchy is a top Linux platform for its users. Cofounder Roustem Karimov, in a Slack message obtained by The Verge, accused objecting staff of trying to setup a moral monopoly and ostracizing colleagues by rejecting Nazism.

Now back to those tenets.

Tenet one. Values the organization stands behind, represented in the security program. The CEO says the company rejects DHH’s views, yet show us where. The VP of Product funds them, celebrates them, and sits on a board DHH chairs. One of those is the value the organization stands behind. The money identifies which.

Tenet three. Trust through informed consent and transparency. The pledge was announced by DHH, on DHH’s platform, with the objections handled afterward in private Slack. Employees learned of the affiliation the way everyone else did. Consent was never sought. Transparency arrived through a leak.

Tenet five. People make rational decisions when educated and honestly motivated. The employees and customers who objected read the two posts and decided. Meller’s word for that decision in 2025 was noise. Karimov’s word in 2026 was moral monopoly. The doctrine says respect the informed decision. The practice says discredit it.

Meller’s method is the same on both dates. He never engages the text. He recodes the objection as noise or as shots taken, then answers with a number: his net worth in 2025, weekend install counts in 2026. Honest Security was written against exactly that move. Its whole argument is that a security team which answers human objections with telemetry has already lost.

Every director of the Rails Foundation, every patron of Omacom, and every executive at 1Password now owns Nazi propaganda.

But Meller is different from everyone, because that guy owns them twice. He brokered the money and he wrote a standard that says Meller can’t be trusted.