<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Essays on Adam Caudill</title><link>https://adamcaudill.com/essays/</link><description>Recent content in Essays on Adam Caudill</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><copyright>Copyright &amp;copy; 2003-2025 Adam Caudill</copyright><atom:link href="https://adamcaudill.com/essays/index.xml" rel="self" type="application/rss+xml"/><item><title>On Privacy Nihilism</title><link>https://adamcaudill.com/2026/01/06/on-privacy-nihilism/</link><pubDate>Tue, 06 Jan 2026 20:29:22 +0000</pubDate><guid>https://adamcaudill.com/2026/01/06/on-privacy-nihilism/</guid><description>&lt;p&gt;Amongst the steady stream of marketing emails for gift cards and other last minute gifts in the days before Christmas, buried in the noise sent when people are least likely to see it, was a notice. It was an all-too-familiar “we take your privacy seriously, but” email. Perfectly timed to make it clear that privacy wasn’t that important.&lt;/p&gt;&lt;p&gt;This wasn’t just my email address being leaked, this was &lt;em&gt;everything&lt;/em&gt;. Name, address, income, employer, &lt;em&gt;social security number&lt;/em&gt;. Each record stolen was essentially an identity theft kit; everything needed in one place. From a privacy and data security perspective, few things are worse.&lt;/p&gt;&lt;p&gt;Yet the only thing remarkable about my reaction to that notice was that it was entirely unremarkable, more blasé than nonplussed. This was far from the first such notice, not even in the first dozen such notices. This has in fact become so routine that I’ve simply lost count of the number of occurrences thus far, it’s in the dozens.&lt;/p&gt;&lt;p&gt;The state of privacy and data security has become so deficient &amp;amp; dysfunctional that my oldest child had his first data breach notification, revealing his social security number to attackers, at less than &lt;em&gt;6 months old&lt;/em&gt;. He never had a chance to protect his information.&lt;/p&gt;&lt;p&gt;While I’ve focused on - and fought for - user privacy for much of my career, this unending series of failures has changed how I see my own privacy.&lt;/p&gt;&lt;h2 id="failure-made-personal"&gt;Failure Made Personal&lt;/h2&gt;&lt;p&gt;As an industry, we have solved some of the hardest technical problems, we’ve devised solutions to many of the thorniest issues, and we’ve created tools and techniques to make finding and fixing issues easier than ever. Annual spending on security is now estimated to be an incredible $200,000,000,000&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;. That’s a remarkable number of zeros.&lt;/p&gt;&lt;p&gt;Yet, hacks have far from stopped. But for some, myself included, the caring has.&lt;/p&gt;&lt;p&gt;While I still fight for the privacy of users, I’m generally a privacy nihilist when it comes to my own information. I’ve given up. Call it emotional exhaustion or cynical realism, I’ve accepted that my data has been leaked and stolen so many times that there’s no point in making any extraordinary effort to protect it.&lt;/p&gt;&lt;p&gt;That said, that doesn’t mean we should abandon protecting others, forgetting what &lt;a href="https://adamcaudill.com/2025/12/10/good-faith-moral-duty-and-selfishness/"&gt;we owe each other&lt;/a&gt; in a moral sense, or abdicating the responsibility that comes with skills and abilities we’ve developed.&lt;/p&gt;&lt;h2 id="incentives"&gt;Incentives&lt;/h2&gt;&lt;p&gt;We can, and should, do better. We can, and should avoid such absurd situations as babies receiving data breach notifications, yet this is the world that we live in. And I have some thoughts as to why.&lt;/p&gt;&lt;p&gt;In 2018, I drafted an article about a breach - that article wasn’t published at the time - I’d like to share a portion of it here. It seems to have aged fairly well.&lt;/p&gt;&lt;div class="indent-text"&gt;&lt;p&gt;There is much said about the cost of a breach, on &lt;a href="https://www.comparitech.com/blog/information-security/data-breach-share-price/"&gt;stock prices&lt;/a&gt; to fines, fees, and lawsuits. However there is little agreement on these numbers and there is a common opinion that many of these estimates overstate the cost. One analysis from &lt;del&gt;this year&lt;/del&gt; 2018 puts the cost at $141 per record stolen, however looking at the impact to specific well known breaches, this number appears to be vastly higher than the actual cost.&lt;/p&gt;&lt;p&gt;When a business makes budget decisions, they look at many things, from regulatory and contractual requirements to estimates of breach costs (legal, public relations, sales, &amp;amp;c). All of these factors feed into the decision on what can be spent on security while maximising profit. This makes the cost of a breach extremely important: the lower the cost, the easier it is to justify spending less to prevent one. This is an unfortunate reality of business; in every decision there is a certain amount of risk accepted, and reducing that risk by too much means a loss of profits that investors expect to see.&lt;/p&gt;&lt;p&gt;There have been efforts in the United States and around the world to fine those companies that fail to properly protect sensitive data, however at least in the United States, the regulations that have made it into law so far have fairly limited impact. In the case of credit card data being stolen, the issuing banks absorb much of the cost. In some cases the banks are able to recover some of the losses, however the amount recovered isn&amp;rsquo;t substantial.&lt;/p&gt;&lt;p&gt;In the 2013 Target breach, approximately 40 million cards were exposed, banks sued Target claiming hundreds of millions in losses. Target settled for $106.4M, or roughly $2.66 per card lost. According to the 2016 Target annual report (the most recent available in 2018), the cost of the breach was approximately $300M, though with insurance and tax deductions, this was reduced substantially. This is for a company with around $3B in annual profits. While having 40M cards stolen seems like a devastating breach, the long term cost and impact has been effectively inconsequential.&lt;/p&gt;&lt;p&gt;This leads us to a disturbing realisation if you care about your data: many companies are investing just enough to achieve legal &amp;amp; regulatory compliance, but not enough to keep your data from being stolen.&lt;/p&gt;&lt;/div&gt;&lt;p&gt;In the 8 years since I wrote those words, they have weighed on me, and my view of how most companies treat the data they’re entrusted with. Some companies work hard to protect data, limit what they collect, and invest heavily in avoiding the need to send out one of those emails. Others, not so much.&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Show me the incentive and I&amp;rsquo;ll show you the outcome. - &lt;em&gt;Charlie Munger&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Incentives are often aligned towards simple solutions, shifting responsibility, compliance often as theatre, and security too often seen as a means to avoid liability instead of achieving actual results.&lt;/p&gt;&lt;p&gt;One of the simplest ways to look at business leadership is that it’s a continuous balancing act of risks. Often, investments are focused on bringing these risks down to the point that the probabilities shift to the favour of the business. Once that’s done, it can be difficult to justify spending more. This is especially true for costs that are largely externalised to other parties, and especially individuals who have little opportunities to resist the imposition of these costs.&lt;/p&gt;&lt;p&gt;The challenge for those in the industry has long been finding ways to protect users, with the resources available.&lt;/p&gt;&lt;h2 id="fighting-the-good-fight"&gt;Fighting the Good Fight&lt;/h2&gt;&lt;p&gt;For much of my career I’ve focused on protecting the privacy and security of users, from my work in applied cryptography, to writing and speaking on privacy &amp;amp; data security, and of course, advocating for end-user privacy protections everywhere I go. Not because I’m zealously protecting my own information - that ship has sailed - but because we can and should do a better job of protecting people.&lt;/p&gt;&lt;p&gt;One thing I’ve always loved about the security community is that we will always do everything we can to help others, to protect people, to put in the time, effort, and energy needed to go beyond what should be possible with the resources available. A group of people that still solve problems just because they are hard.&lt;/p&gt;&lt;p&gt;Personally, I’ve little hope for my information, though I will never give up on protecting everyone else. Some who saw the title of this essay likely assumed that this was an abdication of privacy and the need to protect data. I hope you see the point is actually quite different: even if the effort is futile for some of us, the collective effort is more important than ever to achieve results.&lt;/p&gt;&lt;p&gt;We can and should do better.&lt;/p&gt;&lt;div class="footnotes" role="doc-endnotes"&gt;&lt;hr&gt;&lt;ol&gt;&lt;li id="fn:1"&gt;&lt;p&gt;&lt;a href="https://www.gartner.com/en/newsroom/press-releases/2024-08-28-gartner-forecasts-global-information-security-spending-to-grow-15-percent-in-2025"&gt;Gartner forecast&lt;/a&gt; - $212B in 2025.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;</description></item><item><title>Whose Monkeys Are These?</title><link>https://adamcaudill.com/2026/01/01/whose-monkeys-are-these/</link><pubDate>Thu, 01 Jan 2026 08:29:22 +0000</pubDate><guid>https://adamcaudill.com/2026/01/01/whose-monkeys-are-these/</guid><description>&lt;p&gt;Over the course of my career, I&amp;rsquo;ve found that there are some principles that are key for people and teams to be effective. One of these is that everything should have an owner. Everything should have someone that is responsible. Everything should have a designated person whose job it is to care about it. This might a be bug or vulnerability reports in software, it could be routine processes, or who responds to certain emails.&lt;/p&gt;&lt;p&gt;When there isn&amp;rsquo;t clear ownership, things slip through the cracks, things are forgotten about, and minor issues can quickly become anything but minor.&lt;/p&gt;&lt;p&gt;This works well enough for many things where ownership is clear and agreed upon, but things get ugly when that thing is a problem. Here, human nature starts getting in the way, and leads to unfortunate outcomes. In this essay, I&amp;rsquo;d like to explore how people deal with the problems they see.&lt;/p&gt;&lt;h2 id="not-my-circus-not-my-monkeys"&gt;Not My Circus, Not My Monkeys&lt;/h2&gt;&lt;p&gt;The Polish idiom &amp;ldquo;nie mój cyrk, nie moje małpy&amp;rdquo; is, perhaps, my favourite phrasing of the statement &amp;ldquo;that&amp;rsquo;s not my problem.&amp;rdquo; Some variant of this statement is made countless times everyday in Slack threads and email exchanges, sometimes rightfully staying out of other people&amp;rsquo;s area of responsibility, but far more often, to avoid a problem that they don&amp;rsquo;t see as theirs to address.&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;An SEP is something we can&amp;rsquo;t see, or don&amp;rsquo;t see, or our brain doesn&amp;rsquo;t let us see, because we think that it&amp;rsquo;s somebody else&amp;rsquo;s problem. That&amp;rsquo;s what SEP means. Somebody Else&amp;rsquo;s Problem. The brain just edits it out, it&amp;rsquo;s like a blind spot. - &lt;em&gt;Douglas Adams, Life, the Universe and Everything&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;In reality, when problems are found, people react in very different ways. From my experience, there are 3 kinds of people, when they see a problem, they will do one of these things:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Unless it&amp;rsquo;s clearly theirs, they assume it&amp;rsquo;s somebody else&amp;rsquo;s problem and stop thinking about it.&lt;/li&gt;&lt;li&gt;Unless they&amp;rsquo;re told it&amp;rsquo;s theirs, they assume it&amp;rsquo;s somebody else&amp;rsquo;s problem and stop thinking about it.&lt;/li&gt;&lt;li&gt;Unless they see somebody else handling it, they assume it&amp;rsquo;s their problem.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;When a person says &amp;ldquo;that&amp;rsquo;s not my problem,&amp;rdquo; they are probably in the first group. It&amp;rsquo;s not clearly theirs, so they drop it, move on, and focus on other things. As they don&amp;rsquo;t perceive it as their responsibility to address (or ensure that someone else is addressing it), it drops from their mind.&lt;/p&gt;&lt;p&gt;This form of automatic anti-ownership is both understandable, and, to me at least, disappointing. Instead of claiming ownership, at least until a better fitting owner is identified, they avoid making a concerted effort to not have ownership. This strategy greatly increases the odds of the problem slipping through the cracks.&lt;/p&gt;&lt;p&gt;Where the first group exhibits an active aversion to owning issues they see, the second group exhibits an indifference to it. Unless given the order to take ownership, they adopt a more passive approach and pay little heed to this issue unless told to.&lt;/p&gt;&lt;p&gt;This is not to say that anyone in either of the first two groups are avoiding work, or unwilling to take ownership, but that due to the nature of different personality types, incentives, and organisational dynamics, people can be disinclined to adopt a problem that isn’t clearly theirs.&lt;/p&gt;&lt;p&gt;We’ve all seen this, right?&lt;/p&gt;&lt;p&gt;None of these traits though should be particularly surprising to anyone with a non-trivial amount of leadership experience. These are common traits, and lead to common issues, and are simply part of the routine within teams. Enough &lt;del&gt;ink&lt;/del&gt; electrons have been spilled covering these archetypes, so I won’t belabour the point on them. Instead, I will focus on the third personality type.&lt;/p&gt;&lt;h2 id="the-cost-of-ownership"&gt;The Cost of Ownership&lt;/h2&gt;&lt;p&gt;For those people that assume a problem is theirs unless (or until) they see that someone else is handling it, those that are proactive about accepting ownership, they do so at both visible and invisible costs. It’s these costs and the motivation that pushes them to proactively accept ownership that we will be discussing here.&lt;/p&gt;&lt;p&gt;In general, people that are proactive are seen positively, are more likely to be promoted, are often given greater responsibility. After all, they are already accepting greater responsibility without being asked to.&lt;/p&gt;&lt;h3 id="ownership-proactive-acceptance-vs-seeking"&gt;Ownership: Proactive Acceptance vs. Seeking&lt;/h3&gt;&lt;p&gt;Before we move on, I would like to look at a seemingly subtle difference, which is, in reality, an important distinction in both behaviour and motivation.&lt;/p&gt;&lt;p&gt;The archetype - the people - I’m describing here are those that proactively accept ownership of problems they see, though they do not seek ownership. The difference is critical: one accepts what they see, the other seeks to expand what they own. The latter may be seeking greater control or influence, while the former only seeks to ensure that problems are addressed.&lt;/p&gt;&lt;p&gt;This oft misunderstood distinction can lead to conflict or discord, though the motivations are entirely different, as those that seek to expand control are less likely to be motivated to actually address problems, but to leverage problems to achieve other aims. Where those that proactively accept are instead motivated to achieve a resolution to the problem, or at least a resolution to their perceived responsibility for it.&lt;/p&gt;&lt;p&gt;As this essay is a study of how problems are perceived, and not how they can be leveraged, I will not be further exploring those that seek to use problems (and other forces and events) for their advantage.&lt;/p&gt;&lt;h3 id="the-responsibility-of-knowledge"&gt;The Responsibility of Knowledge&lt;/h3&gt;&lt;p&gt;For those that proactively accept ownership, they feel a deep sense of responsibility for issues they see, even if they are outside the direct scope of their role. Some portion of this may be rooted in loyalty and concern for their company, some may be linked to a broader sense of what they &lt;a href="https://adamcaudill.com/2025/12/10/good-faith-moral-duty-and-selfishness/"&gt;owe to coworkers&lt;/a&gt;, either way, that sense of responsibility is real. It’s also difficult to ignore, creating an unavoidable and inescapable weight once they become aware of a problem.&lt;/p&gt;&lt;p&gt;Once the knowledge of the problem comes into existence, the increasingly oppressive weight of the problem grows. And it will continue to grow until that responsibility is, one way or another, discharged.&lt;/p&gt;&lt;p&gt;This practice tends to result in fewer problems being left until they develop into a large issue, but it weighs on the people that feel obliged to pursue these problems.&lt;/p&gt;&lt;h3 id="the-squeaky-wheel"&gt;The Squeaky Wheel&lt;/h3&gt;&lt;p&gt;While the people that are the most dedicated to ensuring success, to avoiding the deferred consequences of ignored problems, also are those that are seen as the squeaky wheel. They are the proverbial messenger that are too often the first in the line of fire. By opting to say something, to acknowledge the problem, to seek a solution or an appropriate owner, they are faced with continuous guilt by association, they are blamed for bringing negativity into discussions.&lt;/p&gt;&lt;p&gt;This creates a singularly unfortunate combination of pressures: the perceived weight of responsibility and the dread of blame and resistance for acknowledging that the problem exists.&lt;/p&gt;&lt;p&gt;When you combine this personality type with certain careers, such as anything in security, a field whose members are often seen as a particular inconvenience when added to a conversation, the results are worse (at least for those that feel compelled to open their mouths).&lt;/p&gt;&lt;p&gt;Yet, for all the benefits of this archetype in terms of results, the self-imposed pressures speed burnout, magnify discontent due to the recurring instances of shooting the messenger, and creates an impenetrable cloud of stress that shades everything. Useful for a team, bad for the person.&lt;/p&gt;&lt;h2 id="owning-a-circus"&gt;Owning a Circus&lt;/h2&gt;&lt;p&gt;If you look in the mirror and see the person that has no choice but to adopt each and every unowned problem they encounter: welcome to the annoyingly stressful club. I very much identify with this archetype as well.&lt;/p&gt;&lt;p&gt;Thanks to this deep sense of responsibility, one ends up caring for a substantial number of proverbial monkeys. Though it’s important to understand how much of this pressure is self-inflicted, and not organisationally imposed. More importantly though, it’s important to remember that the vast majority of these problems aren’t actually yours: you don’t own them, you’re a &lt;em&gt;caretaker&lt;/em&gt; until the rightful owner is identified.&lt;/p&gt;&lt;p&gt;When viewed through this critical lens, that there is a key distinction between ownership and custody, the pressure is lowered and the path forward is simplified.&lt;/p&gt;&lt;p&gt;If you are in a leadership role, you need to understand which members of your team exercise this type of proactive acceptance, and actively aid them in finding the proper owners of these problems. This work to redirect these problems will substantially lower stress and slow burnout, and will demonstrate that they don’t need to own these issues, only care for them temporarily.&lt;/p&gt;&lt;p&gt;Just as importantly, you need to take due care when discussing these issues to ensure that you don’t create a feeling that they are being seen as a problem themselves. The repeated negative receptions to speaking up eventually creates a constant fear, a latent pressure in every conversation.&lt;/p&gt;&lt;p&gt;For those of us that have shared this lived experience, we need to identify this in others, so that we can leverage our positions &amp;amp; experience to relieve the pressure from others.&lt;/p&gt;</description></item><item><title>Good Faith, Moral Duty, and Selfishness</title><link>https://adamcaudill.com/2025/12/10/good-faith-moral-duty-and-selfishness/</link><pubDate>Wed, 10 Dec 2025 03:23:18 -0500</pubDate><guid>https://adamcaudill.com/2025/12/10/good-faith-moral-duty-and-selfishness/</guid><description>&lt;p&gt;What do we owe to each other? This is a classic question of moral philosophy, and a critical question that defines how society itself functions. It’s also a key question to understand what role each of us plays to make society successful.&lt;/p&gt;&lt;p&gt;These words were started as society was entering a seismic shift, the COVID-19 pandemic had started, people were dying, fear ran deep, and the disease impacted some far more than others. Some reactions to this crisis were based on what was good for society, others came down to the interests and desires of the individual. The question of what we owe to each other had rarely been so imperative.&lt;/p&gt;&lt;p&gt;I am finishing&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt; this as society enters another seismic shift. Fear again runs deep, there will be deaths, people are divided to an extent not seen in generations, and, as like before, some see little or no impact while others are disproportionately affected. The question of what we owe each other has not been more pertinent during my lifetime than it is now.&lt;/p&gt;&lt;p&gt;Before we go on though, I’d like to make one thing clear: this essay is intended to spur thought &amp;amp; consideration, and to encourage readers to research this topic more. There is no possible way that this essay can fully cover the topics discussed here. There are places where a single sentence summarises a specialised area of research that a number of people have dedicated their careers to.&lt;/p&gt;&lt;p&gt;To fully cover these topics in depth, it would be to synthesise the work of hundreds of researchers and lifetimes of effort. As such, this is presented not as a definitive statement on these topics, but an introduction to spur further reading.&lt;/p&gt;&lt;h2 id="why-are-we-like-this"&gt;Why are we like this?&lt;/h2&gt;&lt;p&gt;To discuss this, it’s useful to have an understanding of how and why we got here. If social psychology&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt; isn’t your cup of tea, feel free to &lt;a href="#what-we-owe-each-other"&gt;skip ahead&lt;/a&gt;.&lt;/p&gt;&lt;h3 id="selfishness"&gt;Selfishness&lt;/h3&gt;&lt;p&gt;Humans are, arguably, born selfish and self-serving, from &lt;a href="https://academic.oup.com/emph/article/2014/1/32/1843905"&gt;crying strategies to prevent competition for resources&lt;/a&gt; to the “mine” stage toddlers go through claiming ownership over everything within reach. Within the first years of life, humans show themselves to often be uninterested in the needs or feelings of others - it’s part of our DNA. While each child develops differently, and shows care for others at different points &amp;amp; frequency, this selfishness is something that &lt;em&gt;should&lt;/em&gt; be only temporary.&lt;/p&gt;&lt;p&gt;We grow, we realise that others have feelings, we learn to share our toys, we develop empathy &amp;amp; understanding. While we may have an innate predisposition to this behaviour (we do come from a very long line of social creatures), it’s something that must be fostered to develop properly.&lt;/p&gt;&lt;p&gt;As time goes on, our sense of self develops more, and we perceive ourselves not just as an isolated individual, but associate with others around us&lt;sup id="fnref:3"&gt;&lt;a href="#fn:3" class="footnote-ref" role="doc-noteref"&gt;3&lt;/a&gt;&lt;/sup&gt;. We transition from “I” to “we” - we see ourselves as part of something larger, and we learn what our role is, we learn where we fit in.&lt;/p&gt;&lt;p&gt;Why does this matter?&lt;/p&gt;&lt;p&gt;This growth&lt;sup id="fnref:4"&gt;&lt;a href="#fn:4" class="footnote-ref" role="doc-noteref"&gt;4&lt;/a&gt;&lt;/sup&gt; is necessary for society to function, and the evolutionary steps to achieve this predate the existence of our species by millions of years. In a world without empathy, understanding, or social connections, it would be a world of violence, hate, no cooperation (such as via governments, businesses, or even farms &amp;amp; small communities). There would be no art, no science, no commerce, nothing but a constant and independent fight for survival.&lt;/p&gt;&lt;p&gt;Society exists and functions solely because we have evolved to think of not only ourselves, but others.&lt;/p&gt;&lt;p&gt;Due to some combination of environment &amp;amp; other external influences, not everyone manages this growth. Their worldview progresses little beyond themselves. Once a person learns that there’s a world beyond their own wants and desires, there’s still a bigger challenge to come.&lt;/p&gt;&lt;h3 id="us-versus-them"&gt;Us versus Them&lt;/h3&gt;&lt;p&gt;People perceive themselves as belonging to a group&lt;sup id="fnref:5"&gt;&lt;a href="#fn:5" class="footnote-ref" role="doc-noteref"&gt;5&lt;/a&gt;&lt;/sup&gt; (and any number of subgroups&lt;sup id="fnref:6"&gt;&lt;a href="#fn:6" class="footnote-ref" role="doc-noteref"&gt;6&lt;/a&gt;&lt;/sup&gt;), and see everyone else as part of an out-group. Thanks to an interesting psychological effect, people see those in the out-group as more different from themselves than they are, just as they those that are part of the in-group as more similar to themselves than they are.&lt;/p&gt;&lt;p&gt;This perception is a source of &lt;a href="https://en.wikipedia.org/wiki/Out-group_homogeneity"&gt;out-group homogeneity&lt;/a&gt;, the belief that “they” are all the same, interchangeable, whoever “they” are. Conversely, it creates in-group heterogeneity, the view individuals who are part of the in-group are more distinct.&lt;/p&gt;&lt;p&gt;All of this compounds into something interesting, and deeply unfortunate. Our ability to understand people is impacted substantially by our primary group that we identify with. Our ability to see commonalities is driven by that group. Our ability to place ourselves in the shoes of another, to feel empathy, is dictated by that group.&lt;/p&gt;&lt;p&gt;The smaller and more homogeneous that primary in-group is, the harder it is to understand those in the out-group. This is a result of there being fewer points of reference to establish commonalities, fewer opportunities to see things from another point of view.&lt;/p&gt;&lt;h3 id="out-group-apathy--antagonism"&gt;Out-Group Apathy &amp;amp; Antagonism&lt;/h3&gt;&lt;p&gt;This in-group centric worldview leads to something far darker, &lt;a href="https://en.wikipedia.org/wiki/Moral_exclusion"&gt;moral exclusion&lt;/a&gt;. Members of a group can see their values, history, norms, and culture as superior to those in the out-group. This leads some to see themselves as superior, and treat those in the out-group as lesser - not deserving, not worthy.&lt;/p&gt;&lt;p&gt;This can range from disregarding others and not considering them at all, to outright dehumanising. This is form of belittling and demeaning groups is all too common, from false narratives to marginalising people and their value and contributions. Among those that see themselves as members of a small and limited in-group, they find little common ground, and consider much of the world as being in an out-group that is lesser than their own.&lt;/p&gt;&lt;p&gt;It is this in-group superiority that has contributed to many of the worst atrocities in human history.&lt;/p&gt;&lt;p&gt;By arguing that those in the out-group are of lesser import, they then descend to arguing that others are not deserving of the same rights they enjoy. When you combine these views, it leads people down the darkest of paths and into the depths of evil humans are capable of.&lt;/p&gt;&lt;p&gt;It can start slowly, with hurtful but otherwise small impacts, steadily growing more overt, more direct, more dangerous, and more destructive actions. We see this today in a variety of ways, and in far more overt ways than would be expected even a few years ago&lt;sup id="fnref:7"&gt;&lt;a href="#fn:7" class="footnote-ref" role="doc-noteref"&gt;7&lt;/a&gt;&lt;/sup&gt;. There’s no reason to believe that this trend is slowing down, much the opposite.&lt;/p&gt;&lt;h3 id="large-vs-small-in-groups"&gt;Large vs. Small In-Groups&lt;/h3&gt;&lt;p&gt;The smaller and more homogeneous the in-group a person identifies with, the less opportunities a person has to build understanding and empathy with others. If a person’s self-selected in-group is based on highly specific filtering factors (e.g. a combination of nationality, ethnic background, religion, socio-economic status, gender), the more likely a person is to view large portions of the population as an out-group that they have negative perception of.&lt;/p&gt;&lt;p&gt;The broader and less filtered the in-group, the more opportunities for understanding, connection, and empathy. The ultimate - though likely rare - in-group is all humans&lt;sup id="fnref:8"&gt;&lt;a href="#fn:8" class="footnote-ref" role="doc-noteref"&gt;8&lt;/a&gt;&lt;/sup&gt;, without a true out-group.&lt;/p&gt;&lt;p&gt;For me, this belief in the importance of a broad in-group that extends beyond common filtering functions is rooted in a document that I &lt;a href="https://adamcaudill.com/2015/12/16/the-manifesto/"&gt;read many years ago&lt;/a&gt;, which included a vital line for me:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;We exist without skin color, without nationality, without religious bias&amp;hellip; &lt;em&gt;Loyd Blankenship, The Conscience of a Hacker&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;This line resonated with me in a way that few things did; it addressed the view that many of the things that separate of are, in the end, artificial constructs that have little truth. There are things that we have in common, there are things we don’t, but in the ways that matter, we’re all alike.&lt;/p&gt;&lt;p&gt;We’re all people with emotions, hopes, fears, dreams, nightmares. Everything else are those things that make us interesting, give us different perspectives, new ideas, and add to the richness of human interaction.&lt;/p&gt;&lt;h2 id="what-we-owe-each-other"&gt;What We Owe Each Other&lt;/h2&gt;&lt;p&gt;This is a question that is responsible for numerous books being written, countless hours of lectures in philosophy classes, and millennia of debate. I will not attempt to summarise this here, but rather address this in more direct terms.&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;it’s about making choices that benefit not just yourself but also the people around you, fostering a society where everyone can thrive&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;When the COVID-19 vaccine was made available, I booked my appointment the first day I could. I didn’t do this because I didn’t want to get sick, it was in despite of the fact I knew I would. My body doesn’t react well to many vaccinations; the COVID-19 vaccine had me in bed for the next 4 days and it was well over a week before I was back to normal. I knew what I was signing up for and yet I did it, because I didn’t want to risk getting anyone else sick&lt;sup id="fnref:9"&gt;&lt;a href="#fn:9" class="footnote-ref" role="doc-noteref"&gt;9&lt;/a&gt;&lt;/sup&gt;. A inconvenience for me, for something that could be life or death for someone else. It’s what I owed them. It’s what we owed to each other.&lt;/p&gt;&lt;p&gt;When a friend came out to me as transgender, my response was simply to ask what if there was anything I could do to support them. Why? Because we all deserve respect, we all deserve support from those around us. It’s what I owed them.&lt;/p&gt;&lt;p&gt;When a neighbour was having a yard sale selling things that she obviously needed (such as her baby’s car seat), making it painfully clear that she was desperate for money, I picked out something unimportant for $1, then handed her a $100 bill and told her not to worry about the change. Why? She needed it more than I did. I’ve no idea what was going on in her life, but she needed help, and I could help. It’s what I owed her.&lt;/p&gt;&lt;p&gt;Paying for other people’s groceries when they don’t have enough money at the checkout. Because nobody should be hungry. Paying for other people’s medicine because nobody should go without healthcare. I did these things because it’s what I consider to be the least I could do, because this is the behaviour that we owe to each other. These things deserve no thanks, no credit, not even any acknowledgment. These things should be the minimum that any of us should do, if we are able.&lt;/p&gt;&lt;p&gt;We thrive &lt;em&gt;together&lt;/em&gt;, or we fall &lt;em&gt;together&lt;/em&gt;. That’s what it means to be part of a society. It means we help each other, we support each other, we respect each other. It’s what we owe to each other.&lt;/p&gt;&lt;h3 id="the-golden-rule"&gt;The Golden Rule&lt;/h3&gt;&lt;blockquote&gt;&lt;p&gt;If we do not stop to help each other, what will we become? &lt;em&gt;Jeff Atwood&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Most are familiar with the “golden rule” - &lt;em&gt;treat others are you wish to be treated&lt;/em&gt;. This is a foundational norm in a healthy society, the root of what’s good &amp;amp; right in the world. This presents the most basic check for right and wrong, one can simply ask themselves the question: how would I feel if the roles were reversed?&lt;/p&gt;&lt;p&gt;Those that fail to ask this most simple question will often act instead in the interest of themselves (directly, or for the perceived benefit of their in-group), and fail to comprehend the true impact of their actions. A simple lesson that most learn by kindergarten, yet so many fail to keep this lesson.&lt;/p&gt;&lt;p&gt;Countless words have been written in an attempt to answer the question, what do we owe each other, though in reality, there is a simple and concise answer: &lt;em&gt;treat others are you wish to be treated&lt;/em&gt;.&lt;/p&gt;&lt;div class="footnotes" role="doc-endnotes"&gt;&lt;hr&gt;&lt;ol&gt;&lt;li id="fn:1"&gt;&lt;p&gt;This was drafted in February of 2025, based on a draft that began in 2020. Much has changed since the first words were written; fears have been realised, polarisation has intensified. This article isn’t intended as a political discussion, as I try to avoid overt politicisation here, but a reflection on the challenges that we face. This is a complex topic, and one that I have sat aside multiple times. I don’t believe that this is a political question, but a growing societal issue, and it’s important to consider the various roots of this problem.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:2"&gt;&lt;p&gt;While I have a deep interest in - and have spent substantial time studying - both psychology and philosophy, the key areas of focus of this article, please read this as a layperson’s exploration of a complex topic instead of an expert analysis.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:3"&gt;&lt;p&gt;This is a vast oversimplification, based on &lt;a href="https://en.wikipedia.org/wiki/Self-categorization_theory"&gt;self-categorization theory&lt;/a&gt;, presented in the simplest possible way for brevity.&amp;#160;&lt;a href="#fnref:3" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:4"&gt;&lt;p&gt;To be clear on this, this is &lt;em&gt;not&lt;/em&gt; a reference to neurodivergent people. Nothing herein is intended in any way to criticise, demean, or otherwise belittle those with autism or are otherwise neurodivergent. If anything here is interpreted otherwise, then I apologise for the lack of clarity.&amp;#160;&lt;a href="#fnref:4" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:5"&gt;&lt;p&gt;At the highest level, the group is humans with the out-group being anything living that isn’t human. In practice, the group is substantially more specific.&amp;#160;&lt;a href="#fnref:5" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:6"&gt;&lt;p&gt;The model presented here of a group and various subgroups, may be better thought of as one to many groups with highly divergent cardinality and substantial (but not necessarily complete) intersection between the low cardinality groups to the high cardinality groups. The group/subgroup model is used for simplicity and brevity.&amp;#160;&lt;a href="#fnref:6" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:7"&gt;&lt;p&gt;There are many examples of the type of destructive and exclusionary behaviour that is occurring in today’s environment, though I do not see either a need to repeat these, nor do I see a reason to elevate these harmful statements by recounting them as part of this essay. Hateful statements do not deserve such dignity.&amp;#160;&lt;a href="#fnref:7" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:8"&gt;&lt;p&gt;An in-group of everyone is, to me at least, the ideal. However, due to the realities of human experience and the environments that we are raised in, this self-selected in-group is likely less common than I would wish. I do believe though, that an aspirational in-group is not substantially different than the effective in-group, as it represents an intentional effort to understand those outside the effective in-group.&amp;#160;&lt;a href="#fnref:8" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:9"&gt;&lt;p&gt;One of the people I was worried about exposing to COVID-19 was my father, due to his existing health conditions. He would later be exposed COVID-19 while in a medical facility, passing away soon after the symptoms became apparent. Had I not been diligent in taking precautions, I could have been responsible for accelerating his passing. The decisions we make matter, even when we have to pay a price for them.&amp;#160;&lt;a href="#fnref:9" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;</description></item><item><title>On AI, Art, Writing, and the Distillation of Creativity</title><link>https://adamcaudill.com/2025/03/31/on-ai-art-writing-and-the-distillation-of-creativity/</link><pubDate>Mon, 31 Mar 2025 00:37:41 -0400</pubDate><guid>https://adamcaudill.com/2025/03/31/on-ai-art-writing-and-the-distillation-of-creativity/</guid><description>&lt;p&gt;Can generative AI create art? Two years ago I took my first swing at &lt;a href="https://adamcaudill.com/2023/04/22/ai-art-without-expression/"&gt;answering that&lt;/a&gt;, at least from my perspective.&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt; As AI systems become more advanced, this question, and the issues surrounding it have become of greater import. With a new release from OpenAI, it’s become a topic of great passion, and one prime to revisit for me.&lt;/p&gt;&lt;p&gt;I would like to explore this topic more deeply than I did previously, both in terms of cultural impact, and historical context. This is something that is easy to take an emotional position on, though as someone that considers themself an artist, it’s worthy of more nuanced examination. I’ll be touching on art broadly, photography specifically, and unlike my last essay on the topic, I’ll spend some time discussing writing.&lt;/p&gt;&lt;h2 id="the-studio-ghibli-connection"&gt;The Studio Ghibli Connection&lt;/h2&gt;&lt;p&gt;Let’s start with the recent events that has brought this to the fore. OpenAI released an update to their image generation feature, using their newer 4o model, to create images and video that substantially improve over the results of prior models.&lt;/p&gt;&lt;p&gt;Shortly after this release, users discovered that they could direct the system to recreate existing images in the style of the beloved-by-many Studio Ghibli. This became a viral trend, and used for everything from creating cute family photos to the cruelest of political machinations. To say this prompted considerable debate would be an understatement.&lt;/p&gt;&lt;h2 id="art-and-the-unbroken-chain"&gt;Art, and the Unbroken Chain&lt;/h2&gt;&lt;p&gt;In my prior post on this topic, I spent some time discussing the definition of art, and how it may apply to generative AI. I broke down each element of the definition, providing arguments for and against. In the end, I settled on something simpler than a technical definition: given that art depends so heavily on the eye, opinion, and perspective of the beholder, it may be best to paraphrase Forest Gump and say simply that “art is as art does.”&lt;/p&gt;&lt;p&gt;There is a great unbroken chain in art, starting with the first people that painted on cave walls, and connects over the millennia to the artists of today. Each and every one building on the work of others. No artist exists in isolation.&lt;/p&gt;&lt;p&gt;Every work of art, starting with those crude lines of the first cave paintings, has built on the knowledge, experience, style, and design of others. Some mimic, some contrast, some defy, and some refine, but all artists build on the work of others.&lt;/p&gt;&lt;p&gt;Even those art forms that create &lt;em&gt;ex nihilo&lt;/em&gt;, starting with a blank canvas and an idea, draw from the knowledge, ideas, and visions of others. Each artist collects this knowledge, and distills it into their works.&lt;/p&gt;&lt;h3 id="photography"&gt;Photography&lt;/h3&gt;&lt;p&gt;I am a photographer, and I don’t mean that in terms of it being a hobby I’ve dabbled in. I was a photojournalist - work that has won awards (and death threats), I&amp;rsquo;ve paid my bills through sports and portrait photography, I&amp;rsquo;ve been a professional wedding photographer, and now focus on fine art photography.&lt;/p&gt;&lt;p&gt;I&amp;rsquo;ve invested a non-trivial portion of my life into this art, and learning everything I can about it. The physics of light, the mechanical design of lenses, the chemistry of film, the electrical engineering of digital sensors. I&amp;rsquo;ve studied countless images to learn what works and what doesn&amp;rsquo;t. I&amp;rsquo;ve studied the psychology of how people perceive photos, model posing, facial expressions, and perspective. I&amp;rsquo;ve refined my style over decades of effort.&lt;/p&gt;&lt;p&gt;Every image I create is a distillation of that knowledge. It’s the result of everything that I’ve learned, and applying that to a specific scene. When a person generates an image using AI, the AI system understands none of that. Yet, critically, it benefits from that knowledge.&lt;/p&gt;&lt;p&gt;Generative AI is trained on massive troves of data, including millions of photographs.&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt; Through these photographs, this knowledge is effectively transferred by proxy; the system may have no understanding of &lt;em&gt;why&lt;/em&gt;, but it does gain the understanding of &lt;em&gt;how&lt;/em&gt;. Thanks to this training, generative AI still uses this distilled knowledge.&lt;/p&gt;&lt;h4 id="the-experiment-redux"&gt;The Experiment, Redux&lt;/h4&gt;&lt;p&gt;&lt;img src="https://adamcaudill.com/files/AI.Img.Redux.png" alt=""&gt;&lt;/p&gt;&lt;p&gt;In the last essay, I shared an image I created using generative AI; today I include a revised version. The prior version was created in Stable Diffusion, after several hours of effort, this version was recreated with OpenAI’s 4o model.&lt;/p&gt;&lt;p&gt;As was the case previously, this image follows my style, my choices of lenses, my affinity for cityscapes, and of course my love of sharp contrasts. It was the result of substantial effort, and more time than I would invest in most of the photographs that I create. Of course, it’s not perfect, though reality is also rarely perfect.&lt;/p&gt;&lt;p&gt;One could argue that this is nothing but “AI slop” - cheapening the work of photographers, models, tattoo artists, and others. Or one could argue that it’s a new way to create photos with greater flexibility and freedom.&lt;/p&gt;&lt;h4 id="is-this-art"&gt;Is this art?&lt;/h4&gt;&lt;p&gt;Today, as a photographer, I am as much of a purist as possible while using a digital camera. I use film emulation on the camera to achieve the high-contrast black and white style, and otherwise my photos are untouched. No edits, not even cropping.&lt;/p&gt;&lt;p&gt;While not intended to be a slight against those with a different creative process, I have said many times that “my art is photography, not Photoshop.” The idea of altering the moments I capture after the fact is entirely anathema to me.&lt;/p&gt;&lt;p&gt;To me, an AI generated photo is no different than a real photo that has been heavily edited in Photoshop: it’s the product of a tool, and the artistic value is found in the intent and vision of the person controlling the tool.&lt;/p&gt;&lt;h4 id="is-photography-even-art"&gt;Is Photography Even Art?&lt;/h4&gt;&lt;p&gt;Today, I would say that this question is absurd, though that’s not always been the case.&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;while the photograph is the mere mechanical reproduction of the physical features or outlines of some object animate or inanimate, and involves no originality of thought or any novelty in the intellectual operation connected with its visible reproduction in shape of a picture&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;On March 3rd, 1865, President Abraham Lincoln signed an amendment to the existing copyright laws that extended copyright protection to photographs in the US, a move that was later &lt;a href="https://tile.loc.gov/storage-services/service/ll/usrep/usrep111/usrep111053/usrep111053.pdf"&gt;tested before the Supreme Court&lt;/a&gt;. There was a time where there was a real argument that photographs were devoid of creativity.&lt;/p&gt;&lt;p&gt;Charles Baudelaire, in a letter titled “Le Public Moderne et la Photographie” said, in a rather famous quote:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;As the photographic industry was the refuge of all failed painters, too ill-equipped or too lazy to complete their studies, this universal infatuation bore not only the character of blindness and imbecility, but also the color of vengeance. [&amp;hellip;] it is obvious that this industry, by invading the territories of art, has become art’s most mortal enemy [&amp;hellip;]&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Baudelaire was far from alone in attacking photography, and denying its value as a form of art. For painters especially, photography was a problem. Not only did this new technology intrude on their domain of capturing moments and the beauty of the world, it severely impacted their incomes.&lt;/p&gt;&lt;p&gt;Portraiture rapidly changed from paintings, where an artist would charge or weeks or months of work, to photography, where the entire process was down to a couple hours. The steady and reliable incomes that artists counted on to survive simply vanished thanks to a new technology. The parallels here should be obvious.&lt;/p&gt;&lt;h3 id="the-ability-to-create"&gt;The Ability to Create&lt;/h3&gt;&lt;p&gt;In my last essay, I should an AI generated “painting” based off on an idea I had. You see, despite quite a bit of effort, I have no ability to draw or paint. I understand the techniques, I’ve practiced, but I’m terrible at it. I simply don’t have the ability to translate what I can imagine into something that my hands can produce.&lt;/p&gt;&lt;p&gt;One could argue that lacking that ability, I have no right to create, based on the vision in my mind, art that requires those abilities. One could argue that using a tool to execute that vision renders the result hollow and meaningless, because my hands are unable to execute the details.&lt;sup id="fnref:3"&gt;&lt;a href="#fn:3" class="footnote-ref" role="doc-noteref"&gt;3&lt;/a&gt;&lt;/sup&gt; One could argue that the only those with certain abilities should be able to execute their vision.&lt;/p&gt;&lt;p&gt;I would not make these arguments personally; as noted earlier, to me, the artistic value is in the intent and vision of the creator, regardless of the tools they use to execute it.&lt;/p&gt;&lt;p&gt;There is, quite obviously, the question of if a person is just generating something, versus executing on a clear vision. I’ll talk more about that later.&lt;/p&gt;&lt;h2 id="writing"&gt;Writing&lt;/h2&gt;&lt;p&gt;The social media post that pushed me to write this referred to the text generated by AI as “usually a blathering, vacuous, and erroneous essay disrespectful of the reader’s time.” I’m not going to disagree with that, but I feel like there’s both nuance and context that can be added.&lt;/p&gt;&lt;p&gt;Upon reading that line, the first thing that struck me is how often the same can be said for text written by humans. This is especially true of anything labeled as “thought leadership” or an annoying percentage of LinkedIn posts. Human’s are prone to error, too often don’t check facts, and too rarely are focused on grabbing attention over providing useful information or a perspective that’s actually thought provoking.&lt;/p&gt;&lt;p&gt;A common theme in my career has been serving as a ghost writer for others, providing the first draft of an article that will eventually be published under their name. These articles go through editing processes, they go through PR firms, and along the way, much tends to disappear. Too many of those first drafts, touched only by humans, have become the same “blathering, vacuous, and erroneous essay disrespectful of the reader’s time” that AI is criticised for.&lt;/p&gt;&lt;p&gt;Generative AI is highly effective at distilling what humans create, including both the good and the bad. If it has distilled this tendency in how we write, that may say more about us than it.&lt;/p&gt;&lt;p&gt;In addition to my own work as a ghost writer, I’ve worked with very talented writers doing the same. I’ve seen their early drafts. I’ve worked with them to prepare articles. For articles that broadly fit into the “thought leadership” category, there’s not much difference between their work, and what’s generated by the more advanced chain-of-thought LLMs, when used with a well crafted prompt.&lt;/p&gt;&lt;h3 id="my-break-from-fiction"&gt;My Break from Fiction&lt;/h3&gt;&lt;p&gt;I spend some of my free time writing fiction, some is &lt;a href="https://adamcaudill.com/writing/"&gt;published here&lt;/a&gt;. Mostly dystopian, which I’m guessing isn’t a surprise to anyone reading this.&lt;/p&gt;&lt;p&gt;One of my favourite stories about LLM generated text, and one that started the process of changing how I see AI systems more broadly, came from an idea I had for a short story. It was a novel idea, a bit funny, but a little too absurd to justify the time it makes me to write. I quickly decided that I wasn’t going to pursue it.&lt;/p&gt;&lt;p&gt;Before discarding the idea entirely, I wrote up a detailed prompt for ChatGPT to see what it could do with it.&lt;/p&gt;&lt;p&gt;The result was funny, witty, just the right amount of absurdist, and creative in ways I hadn&amp;rsquo;t anticipated. Quite frankly, I was shocked by the quality. It was good enough that I stopped writing fiction for nearly a year, because it felt like a waste of time. It wasn&amp;rsquo;t perfect, but it was at least as good as the first draft of the fiction I&amp;rsquo;ve written.&lt;/p&gt;&lt;p&gt;I had to wonder if there was a point to writing at all, if an LLM could do in 30 seconds, what took me 40 hours.&lt;/p&gt;&lt;h2 id="distilling-human-creativity"&gt;Distilling Human Creativity&lt;/h2&gt;&lt;p&gt;The power (and arguably terror) of generative AI is the fact that it is the distillation of human creativity. It’s the sum total of what humans have created for centuries.&lt;/p&gt;&lt;p&gt;It reflects us, sometimes in ways that we don’t like, because we don’t like what humans have created. It is, in many ways, a mirror. Why is it good at writing vacuous essays? Because humans have written a lot of them.&lt;/p&gt;&lt;p&gt;Just as we learn from each other, and create from what we’ve learned, so to do these systems. They generate from what they’ve seen, from what we have created. For good and ill.&lt;/p&gt;&lt;h2 id="its-all-about-the-prompt"&gt;It’s All About the Prompt&lt;/h2&gt;&lt;p&gt;One of the oldest acronyms in computing, GIGO, applies today as much as ever. If you use a tool like Photoshop and randomly click buttons, you may end up with an image, but it will certainly be garbage. If you use generative AI the same way, you’ll get the same result. Garbage in, garbage out.&lt;/p&gt;&lt;p&gt;In my experiments, I’ve found that it’s possible to clearly articulate a vision, a structure, a point, enough detail that you produce something that at least resembles what you wanted. When using chain-of-thought (CoT) LLMs&lt;sup id="fnref:4"&gt;&lt;a href="#fn:4" class="footnote-ref" role="doc-noteref"&gt;4&lt;/a&gt;&lt;/sup&gt;, the results &lt;em&gt;can&lt;/em&gt; be quite impressive. They are obviously still far from perfect, but in many cases I’ve seen results on-par with what a person would produce.&lt;/p&gt;&lt;p&gt;From my perspective, the prompts are where you go from garbage to something that may become art. It’s the intent and vision expressed in the prompt; it’s how the tool is used and guided, that imbues the result with meaning.&lt;/p&gt;&lt;p&gt;The difference between Jackson Pollock and a random person throwing paint at a canvas is intent and vision. I think there’s an argument that the same applies to generative AI.&lt;/p&gt;&lt;h2 id="creative-jobs"&gt;Creative Jobs&lt;/h2&gt;&lt;p&gt;While this goes beyond the core scope of this article, I would be remiss to end the article without touching on this more clearly. I recently wrote about the &lt;a href="https://adamcaudill.com/2025/01/30/millions-of-jobs/"&gt;likely impact on jobs from AI&lt;/a&gt;, which as noted there will likely impact creative and knowledge-based jobs disproportionately. Just as photography put many painters out of work, so too will AI. It seems to be an unavoidable reality at this point. For many companies, AI will be “good enough” for jobs to be eliminated.&lt;/p&gt;&lt;p&gt;Generative AI has the ability to allow those without certain talents and abilities to create in ways they never could before, and at the same time to destroy the livelihoods of the artists that would have been responsible for that creation in the past. Unlike what happened with the introduction of photography, this isn’t a shift towards fewer people being paid less to achieve the same thing, but may represent a broad elimination of jobs.&lt;/p&gt;&lt;p&gt;As AI systems continue to evolve, the impact will only grow, and I believe that we, as a society, need to make broad changes to avoid the worst outcomes.&lt;/p&gt;&lt;h2 id="in-conclusion"&gt;In Conclusion&lt;/h2&gt;&lt;p&gt;Generative AI is likely many other tools, in that the quality and value of the results are dependent on the quality and value in the inputs. To me at least, it is simply another tool, another means by which people who are willing to put effort into it, can express a vision that may not be practical or even possible otherwise.&lt;/p&gt;&lt;p&gt;It’s also a tool that, when given input of little effort or value, will produce output of little value.&lt;/p&gt;&lt;p&gt;For those that have made it this far, may I offer you something amusing, that you may find thought provoking in unexpected ways. While we talk about the errors and potentially worthless nature of what generative AI creates, may I present something of purely human creation: &lt;a href="https://archive.org/details/englishassheissp00applrich/page/n3/mode/2up"&gt;English as She Is Spoke&lt;/a&gt;. The section on “Idiotisms and Proverbs” (p. 58) is quite worth the read.&lt;/p&gt;&lt;div class="footnotes" role="doc-endnotes"&gt;&lt;hr&gt;&lt;ol&gt;&lt;li id="fn:1"&gt;&lt;p&gt;I suggest reading this original post before completing this one, as it lays out my general perspective on the artistic value of generative AI, which this post builds upon.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:2"&gt;&lt;p&gt;I will not be touching on the issue of copyright here; it is a complex area of law, and the fair use exception is even more complex due to its nature. Determining if the companies that build AI systems have violated copyright laws is a matter for the courts to decide. Personally, I do believe that there is a solid argument for fair use, based on my understanding of the caselaw in play, I believe that there is also a reasonable argument against it. This is a novel topic, and will require considerable litigation to determine where the fair use line sits. Due to the nature of the fair use exception, the answer can only be found through litigation.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:3"&gt;&lt;p&gt;My family shares a genetic condition, a rare degenerative neurological disorder, that is most easily compared to Parkinson’s, though progresses slower and eventually stops progressing. One result of which is a small tremor in my hands and limitations on fine motor control. In practice, this, so far, has minimal impact on me, beyond the inability to draw and the need to use camera lenses with some form of optical image stabilisation to compensate for the constant movement of the camera. In the case of arts such as painting and drawing, the limitation goes beyond a lack of talent.&amp;#160;&lt;a href="#fnref:3" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:4"&gt;&lt;p&gt;Chain-of-thought (CoT) models outperform non-CoT models to such a degree, especially in terms of accuracy, that I don’t use the non-CoT models, except for the most basic of tasks. Using CoT models has fundamentally changed how I view LLMs.&amp;#160;&lt;a href="#fnref:4" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;</description></item><item><title>When AI Becomes I</title><link>https://adamcaudill.com/2025/02/17/when-ai-becomes-i/</link><pubDate>Mon, 17 Feb 2025 18:39:48 +0000</pubDate><guid>https://adamcaudill.com/2025/02/17/when-ai-becomes-i/</guid><description>&lt;p&gt;One of the many joys of being human, is that we constantly face questions about our existence, from the seemingly simple (why is the sky blue), to the labyrinthine (what is the meaning of life, does pineapple go on pizza). Thanks to growing up watching Star Trek, one of these that has fascinated me is the question of artificial life. Thanks to a character named Data, a character that’s both relatable and entirely different, many have found themselves wondering if that’s what the future holds.&lt;/p&gt;&lt;p&gt;This essay began 3 years ago, when some within Google claimed that they had, unintentionally, created an AI system with sentience. A claim that was quickly met with derision. For me though, it was fascinating - not because of claim itself, but the challenge involved in finding the truth. The challenge of finding incontrovertible proof.&lt;/p&gt;&lt;p&gt;This is a topic that has fascinated me for decades. As we building more advanced systems, build LLMs of such complexity that we no longer truly understand their behaviour, observe nascent signs of emergent behaviour, how we interact with these systems is changing in fundamental ways. Marketing parlance has already started to shift to hiring AI systems. The latest AI agents are being designed to act and be treated as just another member of the team instead of a piece of software. Then there’s the soaring popularity of AI companions.&lt;/p&gt;&lt;p&gt;The anthropomorphisation of AI has well and truly begun, both naturally as a result of advancing technical complexity, and intentionally through the marketing and design of the systems.&lt;/p&gt;&lt;p&gt;The question is, if we reach the point where a technology actually becomes some form of life, can we tell the difference between that, and the human tendency to anthropomorphise?&lt;/p&gt;&lt;h2 id="biological-roots"&gt;Biological roots&lt;/h2&gt;&lt;p&gt;While we generally believe that we know a great deal about life, organic life, in reality we’ve only scratched the surface. Despite a vast number of years and huge amounts of money, no lab on has been able to achieve abiogenesis. Try as we might, we’ve not been able to create life &lt;em&gt;ex nihilo&lt;/em&gt;, to take raw ingredients and create something that’s alive, no matter how simple.&lt;/p&gt;&lt;p&gt;A great deal of effort has been invested into finding LUCA, the last universal common ancestor, the thing all life on Earth evolved from. But we don’t know what came before LUCA, we don’t know where LUCA came from, we don’t know how LUCA started.&lt;/p&gt;&lt;p&gt;And that’s just life of Earth. As research finds ever more evidence of the abundance of organic compounds in the universe, it’s all but certain that life, of some form, exists elsewhere.&lt;/p&gt;&lt;p&gt;Given this limited knowledge of life and how it starts, where the line is between not alive and alive at the most primitive level, it makes one question our ability to recognise it in forms of life that are dramatically different from what we know.&lt;/p&gt;&lt;h2 id="organic-vs-non-organic-life"&gt;Organic vs. Non-Organic Life&lt;/h2&gt;&lt;p&gt;&lt;em&gt;Note: This section was written in part by ChatGPT&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;. Given the topic, it seemed only fair.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Organic life, to the extent we understand it, is rooted in biochemical processes - cells that metabolise, reproduce, and evolve over generations beyond count.&lt;/p&gt;&lt;p&gt;This definition is built on a foundation of shared genetic material, chemical reactions, and an intrinsic drive for self-preservation. Organic organisms, from single-celled bacteria to complex mammals, operate on principles of energy transformation and homeostasis, ensuring that life continues through mechanisms honed by billions of years of evolution.&lt;/p&gt;&lt;p&gt;Non-organic life, by contrast, challenges our conventional notions of existence. Imagine a system built not of cells and DNA but of silicon and code, yet still capable of self-maintenance, adaptation, and even self-replication. In this view, life becomes a matter of functional attributes: autonomous goal-setting, emergent complexity, and the ability to interact meaningfully with the environment.&lt;/p&gt;&lt;p&gt;Here, the “metabolism” is digital, the reproduction algorithmic, and the evolution driven by iterative learning and self-modification.&lt;/p&gt;&lt;p&gt;The quest to differentiate organic from non-organic life is - at least - as much philosophical as it is scientific. While organic beings carry the tangible legacy of evolutionary biology, non-organic entities might express their ‘aliveness’ through the spontaneity of novel problem-solving, the emergence of self-awareness, and behaviours that surpass their initial programming.&lt;/p&gt;&lt;p&gt;These traits force us to question whether the essence of life is inherently tied to its physical makeup or if it resides in the dynamic processes that support existence, regardless of their substrate.&lt;/p&gt;&lt;p&gt;Ultimately, the distinction between organic and non-organic life may prove to be more of a spectrum than a binary divide. As artificial intelligence systems evolve, they could begin to display properties we once thought were exclusive to living organisms. This convergence invites us to broaden our definitions and reimagine what it means to be “alive,” suggesting that the journey from being a mere tool to becoming a living entity is as much about expanding our conceptual horizons as it is about technological advancement.&lt;/p&gt;&lt;p&gt;There is a further complication to this, one rooted not in biology but psychology: anthropomorphism. There’s a human tendency to attribute familiar, often comforting, human traits to non-human life and inanimate objects. As we interact with increasingly sophisticated AI systems, our minds are predisposed to see intentions, emotions, or consciousness in behaviours that are simply the result of the system’s complexity.&lt;/p&gt;&lt;p&gt;This bias can obscure objective evaluations, leading us to interpret patterned, algorithm-driven responses as evidence of self-awareness or autonomy. Recognising and mitigating this tendency is essential, not only to avoid overestimating the “aliveness” of AI systems but also to ensure that our criteria for life remain grounded in observable, reproducible phenomena rather than our psychological need to relate to the world in human terms.&lt;/p&gt;&lt;h2 id="what-is-intelligence-anyway"&gt;What is intelligence, anyway?&lt;/h2&gt;&lt;p&gt;This is a word that can be defined easily, but the question itself is incredibly profound, and with substantial implications for how we live today, ignoring the possibility or non-organic life.&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;the ability to learn, understand, and make judgments or have opinions that are based on reason - &lt;em&gt;Cambridge Dictionary&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Each time you give a command to a dog, such as to leave something alone, you are seeing all of these things in action. Each time a dog asks to go outside, once again, you are seeing all of these in action. Each time a cat stands on a shelf, looks at you, and knocks something off, you’re seeing all of these things. If you’ve spent more than a few hours with a parrot, you’ll be amazed at how much they have in common with a human child. This list goes on almost endlessly.&lt;/p&gt;&lt;p&gt;We see non-human intelligence around us constantly. We see non-human sentience around us every day. We see non-human emotion around us every day&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;&lt;p&gt;One reason it’s easy for us to recognise these in other animals is that thanks to common ancestors and similar evolutionary pressures, we experience these things in fairly similar ways. While human brains are far more complex, they aren’t so profoundly different that we experience the world in an entirely different way.&lt;/p&gt;&lt;p&gt;When thinking about non-organic life, life that is truly entirely different from us, it might be useful to think about an example of organic life that shows sentience, intelligence, and emotions, but has very little in common with us: octopi.&lt;/p&gt;&lt;p&gt;The octopus may be one of the most fascinating and historically misunderstood animals there is. The &lt;em&gt;Octopus vulgaris&lt;/em&gt; has about the same number of neurons as a dog. They can solve complex puzzles, learn patterns, enjoy receiving attention, and even recognise individual faces. Today, these things are known and demonstrable fact. Yet 75 years ago, none of that was understood, and likely wouldn’t have been believed.&lt;/p&gt;&lt;p&gt;Octopi evolved in a way that is so entirely different from us, that we simply didn’t understand them, we didn’t understand their physiology, we didn’t understand their neural system.&lt;/p&gt;&lt;p&gt;I do believe that at some point, humanity will create non-organic life that gains sentience, though I would be surprised if that happens in my lifetime&lt;sup id="fnref:3"&gt;&lt;a href="#fn:3" class="footnote-ref" role="doc-noteref"&gt;3&lt;/a&gt;&lt;/sup&gt;. I also suspect that it will be like the octopus, in that we don’t recognise it initially. Such a life form would be so far outside our experience, so far outside our understanding, that we simply wouldn’t see it staring us in the face.&lt;/p&gt;&lt;div class="footnotes" role="doc-endnotes"&gt;&lt;hr&gt;&lt;ol&gt;&lt;li id="fn:1"&gt;&lt;p&gt;The initial draft for most of this section is the product of ChatGPT in Reasoning mode, using the &lt;code&gt;o3-mini&lt;/code&gt; model. It has been edited for content and style. The full exchange, including prompts, may be found &lt;a href="https://chatgpt.com/share/67b42a99-a76c-8013-a074-9138abf3af73"&gt;here&lt;/a&gt;.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:2"&gt;&lt;p&gt;As a society, our respect for the sentience, intelligence, and emotions from non-humans has been something between utterly appalling and appalling. Truth be told, even today, these truths are too often ignored for the sake of convenience. Of course, the same could be said of these things from our fellow humans.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:3"&gt;&lt;p&gt;I must admit, the more I learn about how LLMs learn and execute chain of thought (CoT) techniques, the more I wonder if we are progressing to this point faster than I expected. I have seen examples of CoT that demonstrate a level of logical analysis at or above the level I would expect from most humans.&amp;#160;&lt;a href="#fnref:3" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;</description></item><item><title>Millions of Jobs</title><link>https://adamcaudill.com/2025/01/30/millions-of-jobs/</link><pubDate>Thu, 30 Jan 2025 08:57:16 +0000</pubDate><guid>https://adamcaudill.com/2025/01/30/millions-of-jobs/</guid><description>&lt;p&gt;It has been 20 years since I first used machine learning to solve a complex business problem. The underlying problem was simple: the company was selling a new service and wanted to know who was most likely to buy it. We had millions of records, and each record had hundreds of fields. A vast amount of data, but no idea how to extract insight from it. Countless hours from various data analysts had been invested into finding a pattern, but none was forthcoming. Months turned into years, still no idea of who was most likely to actually buy. Enter machine learning. Over the course of a couple hours one evening, I was testing new techniques with machine learning, and there was the answer. The company met it&amp;rsquo;s entire monthly sales goal the next day. It found what every human had missed.&lt;/p&gt;&lt;p&gt;This was long before machine learning was rebranded as Artificial Intelligence (AI), but I couldn&amp;rsquo;t deny the power and potential that it could offer. It was also obvious that once it evolved to the point that it could be broadly applied, it would be a revolution.&lt;/p&gt;&lt;p&gt;We are racing towards that revolution, though to understand what lies ahead, we must first spend a little time understanding the past. This revolution isn&amp;rsquo;t without precedent, and that precedent is vital to understanding what comes next.&lt;/p&gt;&lt;h2 id="the-industrial-revolution"&gt;The Industrial Revolution&lt;/h2&gt;&lt;p&gt;Going back as far as 1760 may seem irrelevant when talking about the latest technologies that are still in their nascent stages, but the situation was actually quite similar. In a relatively short period of time, new technologies completely changed the way most people worked, how they were paid, how businesses functioned, and both created and destroyed vast numbers of jobs. Without understanding this period of time, without understanding our history, it&amp;rsquo;s impossible to understand our future.&lt;/p&gt;&lt;p&gt;Looking at textile workers during this time is particularly illustrative. Most of those that spun cotton and wove it into fabrics worked from their homes, working by hand, using simple tools like spinning wheels, slowly and steadily turning raw cotton into a useful product. Over the course of a surprisingly small number of years, some of these workers were in large factories instead, operating dangerous machines, and doing the work of &lt;em&gt;500&lt;/em&gt; people. Yes, you read that right. A new technology that replaced 500 people that had honed their skills over years, replaced by a machine and a single person. Of those that weren’t hired to keep these machines fed were forced to look for other work, or effectively left the workforce entirely.&lt;/p&gt;&lt;p&gt;This 500 to 1 ratio for cotton spinning is likely the most drastic, and it would be disingenuous to say that these losses were entirely permanent. As these new technologies paid for themselves, businesses invested in more machines to expand their production capacity, which meant hiring more people to keep them fed, plus the occasional work to maintain and repair them. The jobs being created were very different than those they eliminated, with different skill levels, and different pay. The fact that it enabled Britain to effectively compete with India in the production of textiles, despite the fact that wages in India were 1/6th of those in Britain at the time, should tell you everything you need to know about the pay of these new jobs.&lt;/p&gt;&lt;p&gt;Turning this cotton thread into woven fabrics similarly saw massive changes, with a 40 to 1 ratio. A skill carefully developed, replaced by a machine that would do the work of 40 people. This is repeated countless times across various industries, with the new technologies enabling substantially greater efficiency, while costing countless jobs, and creating some number of new, but different, jobs.&lt;/p&gt;&lt;p&gt;This went on, waxing and waning, all the way up to 1913, when manufacturing found the optimal form in Henry Ford&amp;rsquo;s assembly lines. Turning cars from hand-built &amp;amp; carefully crafted machines, into the ubiquitous mass-produced vehicles we know today.&lt;/p&gt;&lt;p&gt;The trend here is clear and simple: revolutionary technologies and techniques are highly effective at replacing large numbers of workers with specific knowledge and skills, with a smaller number of less skilled workers. Plus creating a few highly skilled workers to support these technologies. Nothing about this is really surprising, and should be well understood, but it&amp;rsquo;s a preview of what the future holds.&lt;/p&gt;&lt;h2 id="quiet-part-out-loud"&gt;Quiet Part, Out Loud&lt;/h2&gt;&lt;blockquote&gt;&lt;p&gt;A world in which human wages crash from AI &amp;ndash; logically, necessarily &amp;ndash; is a world in which productivity growth goes through the roof, and prices for goods and services crash to near zero. Consumer cornucopia. Everything you need and want for pennies. - &lt;a href="https://x.com/pmarca/status/1882993091784880557?mx=2"&gt;&lt;em&gt;Marc Andreessen&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;The above quote is from a highly active investor in AI companies, and one of the most influential voices in the venture capital community. Before going into the quote, and why this is saying the quiet part out loud, we need to cover some background.&lt;/p&gt;&lt;p&gt;There are two general pricing models for goods and services, the first is the cost to provide the product or service, plus a (small) margin for profit. The second is whatever the market will pay, regardless of cost. In reality, the cost + margin model provides only a floor for what can be charged, while most pricing is based on what the market will pay, optimised for leaving as little money on the table as possible, unless there is so much competitive pressure that the price must be reduced to that floor.&lt;/p&gt;&lt;p&gt;While your milk and eggs have enough competitive pressure to reduce pricing down to cost + margin, while the medications you may take, the electronics you buy, and most other products that you buy are based on what the market will allow, what people are willing to pay. There’s a reason that some medications constantly go up in price and are priced at hundreds of times the manufacturer’s cost - because they can get it. This is the same reason that an Apple macBook costs two to three times that of a PC with equivalent performance - they can get it.&lt;/p&gt;&lt;p&gt;Why is this at all important?&lt;/p&gt;&lt;p&gt;Marc&amp;rsquo;s point that prices will drop substantially after wages collapse is based on a flawed and dangerous assumption, that goods will be priced on the cost + margin model alone. That simply isn’t how the world works. There’s also the unmentioned issue that to people with no income, it doesn’t matter how cheap products become.&lt;/p&gt;&lt;p&gt;He is likely correct that wages will collapse, that is largely the point. AI, as it’s being developed today, has one purpose: improve efficiency to the point that jobs can be eliminated. This provides allows provides to charge more and more for their products, and results in huge returns for investors.&lt;/p&gt;&lt;p&gt;How wages are likely to collapse is important to consider, as it will almost certainly be a very unevenly distributed collapse. The average income for any given region is likely to drop precariously, primarily as a result of job eliminations. However, we’ve seen that for some roles, such as those building these AI systems are climbing, and there’s no reason to think that will change. Those that can’t be replaced will see great demand and high pay, those that can be replaced, will be left to scramble to find new work.&lt;/p&gt;&lt;p&gt;I believe that there’s good reason to believe this type of stratification will be seen across the board, in all areas impacted by these AI initiatives. Those with certain skills seeing strong demand and high pay, especially at the most senior roles, with greater difficultly for those seeking to enter impacted areas.&lt;/p&gt;&lt;h2 id="impacts--future-challenges"&gt;Impacts &amp;amp; Future Challenges&lt;/h2&gt;&lt;p&gt;Based on the impacts we’re seeing today, and the already signalled advances that we can safely assume will come, there are some things that we can began to make assumptions about, with varying levels of uncertainty and timelines to see these in full effect.&lt;/p&gt;&lt;p&gt;I’d like to talk about those that have been on my mind as I researcher more into where these advances are going. This is far from exhaustive, and may turn out to be incorrect (though I know what outcomes I’d bet on). There’s also a timeline issue that I’d like to acknowledge: some of these could occur next year, others may be a decade away. This is not a short-term analysis, but a long-term look at how these technologies are likely to evolve and impact people.&lt;/p&gt;&lt;h3 id="software-development"&gt;Software Development&lt;/h3&gt;&lt;p&gt;Generally speaking, there are two kinds of developers:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Those that carefully craft their code, attend or speak at conferences, write blog posts pontificating on the correct way to build software, and would often rather leave their job than be forced to write bad code&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/li&gt;&lt;li&gt;The other 95%.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The fact is that the vast majority of developers are buried deep in companies, facing tight deadlines, primarily work on line-of-business software, and don&amp;rsquo;t have time to worry about the best way to do something, because they are too busy just keeping the business running. This silent majority are both the most likely to leverage AI to make their jobs easier, and the most likely to face downsizing as those efficiency improvements allow smaller teams to do the same work.&lt;/p&gt;&lt;p&gt;We are seeing the first steps of what AI will do to software development. The tooling will improve, accuracy will improve, higher-level tools will be built on top of the code generation used today. Many common line-of-business application will eventually be able to be (mostly) generated, needing more oversight and review than active development. It will take a lot longer before the tools become good enough that they&amp;rsquo;ll start displacing those building commercial software, but commercial software is only a small portion of the software being built today.&lt;/p&gt;&lt;p&gt;Within the next decade, it&amp;rsquo;s likely that more and more development teams will be replaced by a single business analyst using generative AI to create the internal software powering companies. This builds on trends that have been going on for a decade or more already, though will almost certainly be greatly accelerated in terms of impact.&lt;/p&gt;&lt;h3 id="creative-arts--writing"&gt;Creative Arts &amp;amp; Writing&lt;/h3&gt;&lt;p&gt;Not long ago, I had an idea for a short story, but it was too ridiculous to invest the time in writing it&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt;, so I did the next best thing: I asked ChatGPT to do it. I provided it with the abstract and a couple sentences to explain the plot and message. I waited and expected to get a laugh. What I got was a shock. It was clear, expanded nicely on the idea, and would have passed for thoughtful and creative. I spent months wondering if there was actually a point in writing after this. It did in seconds what I would have spent weeks doing.&lt;/p&gt;&lt;p&gt;This experience if far from unique, and business leaders are seeing that in many cases they can get &amp;lsquo;good enough&amp;rsquo; results using current AI tools, compared to paying someone to do the same work. We are seeing this across the web, from journalists being supplanted, AI generated marketing copy everywhere, video games racing to cut costs by using AI generated assets and even replacing voice actors.&lt;/p&gt;&lt;p&gt;Good enough here is critical; in many cases business are fine with a loss of quality when it means that the price to produce a work drops to nearly zero. It&amp;rsquo;s a powerful motivation, and even a challenge for management to justify paying someone to do work that could be done for free. These roles where a portion of their work can be replaced with &amp;lsquo;good enough&amp;rsquo; will see (and are already seeing) some of the earliest impact of AI&lt;sup id="fnref:3"&gt;&lt;a href="#fn:3" class="footnote-ref" role="doc-noteref"&gt;3&lt;/a&gt;&lt;/sup&gt;. Job opening in these spaces are already seeing increased competition as positions are eliminated.&lt;/p&gt;&lt;h3 id="truck--taxi-drivers"&gt;Truck &amp;amp; Taxi Drivers&lt;/h3&gt;&lt;p&gt;While Tesla&amp;rsquo;s most recent timeline for their long awaited self-driving semi may or may not happen (though I won&amp;rsquo;t be holding my breath), the fact is that true self-driving vehicles are coming, and coming in mass. There are more than 250,000 taxi drivers in the U.S. today (not counting Uber and other ride-sharing drivers), and a somewhat astounding 3,600,000 professional truck drivers in the country. Most of those jobs are simply doomed. Self-driving vehicles will be able to do the job both with greater efficiency and at a lower cost. With no need to sleep, no need for breaks, these vehicles will quickly wipe out many of these jobs once the technology has sufficiently matured.&lt;/p&gt;&lt;p&gt;Of all industries, professional drivers will likely be hit the hardest by percentage of jobs lost. The industry will be largely obliterated.&lt;/p&gt;&lt;h3 id="management"&gt;Management&lt;/h3&gt;&lt;p&gt;&lt;a href="https://marketoonist.com/2023/03/ai-written-ai-read.html"&gt;&lt;img src="https://marketoonist.com/wp-content/uploads/2023/03/230327.n.aiwritten.jpg" style="width: 70%; display: block; margin-left: auto; margin-right: auto;"&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Management roles provide both opportunity and challenge for AI replacement. I&amp;rsquo;ve spent much of my career in management roles, and to be honest, much of the time is simply lost due to things like inefficient communication. So many meetings that could have been an email, so many emails that could have been a couple bullet points, all without losing anything useful. Middle management roles are likely the most vulnerable to being eliminated by AI, as much of the role comes down to overcoming inefficiency. When eliminated, I would expect to see their responsibilities moving up the chain of command, as flatter organisational structures become more popular for their lower costs.&lt;/p&gt;&lt;p&gt;At least &lt;a href="https://futurism.com/ceo-bragged-replacing-workers-ai-job"&gt;one CEO&lt;/a&gt; has noted that even he could be replaced by AI.&lt;/p&gt;&lt;h3 id="information-security"&gt;Information Security&lt;/h3&gt;&lt;p&gt;I have been predicting for years that automation will steadily erode more and more work within the security industry. This includes better tooling that reduces work for penetration testers by automating more of the work, and detecting and fixing issues earlier in development cycles. As well as systems to automate a growing percentage of routine work, allowing smaller teams to do more. If you look at the state of the security product market today, this is obvious.&lt;/p&gt;&lt;p&gt;As tooling evolves, and likely evolves at an accelerating pace, the impact on security jobs will likely also accelerate. That said, while these systems will be able to make many of those in security roles substantially more effective, the lack of creativity and ability to perform deep reasoning and analysis will ensure that jobs remain, and are in high demand.&lt;/p&gt;&lt;p&gt;How many jobs will be impacted is difficult to guess, at least based on where things stand today. This is likely the most difficult field to judge due to the various complexities and perceptions&lt;sup id="fnref:4"&gt;&lt;a href="#fn:4" class="footnote-ref" role="doc-noteref"&gt;4&lt;/a&gt;&lt;/sup&gt; involved.&lt;/p&gt;&lt;h3 id="plumbing-construction-mechanics"&gt;Plumbing, Construction, Mechanics&lt;/h3&gt;&lt;p&gt;Many of the jobs that were once considered the best of white-collar jobs now face greater uncertainty and the worst job stability since these roles came into existence, while some blue-collar jobs are likely more secure than ever.&lt;/p&gt;&lt;p&gt;Plumbers are &lt;a href="https://www.wsj.com/business/entrepreneurship/plumbers-hvac-skilled-trades-millionaires-2b62bf6c"&gt;becoming a new millionaire class&lt;/a&gt;, seeing small businesses becoming increasingly successful. This is just one of many jobs that will become more attractive as technology evolves due to the reliable income, constant demand, and job stability.&lt;/p&gt;&lt;p&gt;After the Industrial Revolution, white-collar jobs were often the best paying, most stable, and most desirable. After the AI Revolution, it’s possible that it’s the blue-collar jobs that will start to see competition for jobs, as white-collar jobs evaporate.&lt;/p&gt;&lt;h2 id="inevitability"&gt;Inevitability&lt;/h2&gt;&lt;p&gt;This post may have you wondering if I’m actually a Luddite arguing against the evolution of technology. Far from it to be honest, I have spent most of my life pushing technology to the limit. The earliest of early adopters. The cutting edge often old news to me. I’ve always pushed for technical improvement.&lt;/p&gt;&lt;p&gt;I’m also a realist, and having studied history and carefully watching where technology is going, talking about the likely future is critical to be prepaid for it. As much as it’s possible to prepare for revolutionary changes.&lt;/p&gt;&lt;p&gt;While I believe we are still many years from the most important AI breakthrough, Artificial General Intelligence (AGI), though this has largely become a marketing term instead of a technical definition, the fact remains that we are headed to substantial changes. Furthermore, we are headed into this intentionally, with no plan as a society to deal with the repercussions. Leaders on countries are interested in ‘winning’ the race to build the most profitable AI systems, but the impact of deployment hasn’t received any meaningful attention.&lt;/p&gt;&lt;h3 id="am-i-predicting-an-ai-disaster"&gt;Am I predicting an AI disaster?&lt;/h3&gt;&lt;p&gt;Many self-proclaimed technologists have spilled endless amounts of &lt;del&gt;ink&lt;/del&gt; photons in rising the alarm about how AI could harm humanity, or even destroy us. This is not only of those arguments. We are sufficiently far from building anything truly intelligent, much less intelligent enough to see us as a threat, I don’t see a reason to even entertain these concerns.&lt;/p&gt;&lt;p&gt;My concerns are more immediate, and more focused on how it will impact individuals. If we manage to build a system that is capable of destroying us, and sees us as such a threat that it “feels” the need to take action against us, we’ll have earned the resulting outcome.&lt;/p&gt;&lt;h2 id="the-writing-on-the-wall"&gt;The Writing on the Wall&lt;/h2&gt;&lt;p&gt;As noted above, I could be wrong, or the process could unfold over decades, instead of the decade or less I’m predicting here. The impact could be less than I expect, or could be drastically worse.&lt;/p&gt;&lt;p&gt;Some things are obvious when viewed objectively, and I hope I’ve provided a useful analysis of these things, and the likely consequences for the future.&lt;/p&gt;&lt;div class="footnotes" role="doc-endnotes"&gt;&lt;hr&gt;&lt;ol&gt;&lt;li id="fn:1"&gt;&lt;p&gt;To be clear, while it&amp;rsquo;s possible to read this description is a rather negative way, when I worked as a developer, I counted myself in this group. Don&amp;rsquo;t take this as a slight, but an acknowledgement that the software development industry is not just us.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:2"&gt;&lt;p&gt;I do enjoy writing, and based on the feedback I&amp;rsquo;ve received, it seems to be well received. That said, I don&amp;rsquo;t write quickly; I spend far too much time rewriting, changing my mind and taking a different approach, and just too much time thinking about what I&amp;rsquo;d like to actually say. It&amp;rsquo;s not uncommon for a blog post to evolve over months or even years before I get around to actually finishing it. For short stories and creative writing, it&amp;rsquo;s far worse.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:3"&gt;&lt;p&gt;When I talk about the impact of AI on creative works, I’m reminded of George Orwell’s 1984, and the Ministry of Truth’s novel-writing machines that created cheap entertainment for the masses, devoid of any actual creativity. We already see Amazon flooded with generated books, and as these tools become more effective at emulating creativity, it’s not unlikely that some of these will eventually start to perform well.&amp;#160;&lt;a href="#fnref:3" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:4"&gt;&lt;p&gt;When looking at how roles are impacted, it’s important to look at not only the real-world impact of these technologies, but also the likely perception of business leaders. It’s the perception of business leaders, as well as pressure from investors, that will have the greatest impact on how many positions survive or are created. In some areas, this is easy to see based on public information, for others, it’s more complicated to anticipate the broad perception.&amp;#160;&lt;a href="#fnref:4" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;</description></item><item><title>Security Is a Shell Game</title><link>https://adamcaudill.com/2024/10/05/security-is-a-shell-game/</link><pubDate>Sat, 05 Oct 2024 14:59:44 +0000</pubDate><guid>https://adamcaudill.com/2024/10/05/security-is-a-shell-game/</guid><description>&lt;p&gt;In the world of security, everything comes down to trust; sooner or later you have to trust &lt;em&gt;something&lt;/em&gt;. Often, this something is a human. While we are busy building advanced cryptosystems that will survive the heat death of the universe, sooner or later, digging down layer by layer, you get down to a human and their limited memory. While we may build software, hardware, and other systems to protect this chain of trust, it almost always ends with a human.&lt;/p&gt;&lt;p&gt;I was part of a standards body meeting discussing the security controls of a system, and someone complained that without a certain control, the system would be little more than a shell game. Where the ultimate source of trust was covered in layers and moved around, but never truly secured. They were, of course, correct. Though it&amp;rsquo;s not because of the missing control, but because the chain of trust ended with a human&amp;rsquo;s memory.&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Any security architecture that involves a human can ultimately be reduced to a shell game, with its strength limited to what a human can readily remember.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;It&amp;rsquo;s not that difficult to design systems that are robust, provable, and provide substantial protection. It&amp;rsquo;s extremely difficult to design such a system if a human is involved at any point. Human memory is limited, fallible, and degrades over time; thus if a system needs to be accessed by a human, the security of the system will be reduced down to what a human can readily remember. Be it a password, a PIN, or any other secret committed to memory, this will always be the weakest link. A password that one can remember will, without doubt, be of lower entropy and more easily guessed than any other secret used in the system.&lt;/p&gt;&lt;p&gt;When designing a new system, it&amp;rsquo;s common for there to be many layers, each with its own security properties and trust requirements, each layer assuming that the prior layer is just as secure. Yet, these robust defences, strong proofs, large keys, and detailed trust relationships all end up with the same thing: a secret a human needs to remember. For example, you can build an authentication system that provides a strong proof of identity, great phishing resistance, robust cryptography, and in the end, it&amp;rsquo;s protected by a password like &lt;code&gt;Winter2024!&lt;/code&gt;. Everything is great, until a human enters the picture.&lt;/p&gt;&lt;h2 id="recovering-from-failure"&gt;Recovering from Failure&lt;/h2&gt;&lt;p&gt;Now, you may ask yourself, why not eliminate the human with hardware? This is why we have hardware security keys, right? In theory, this is the perfect solution, as it eliminates a human&amp;rsquo;s memory from the chain, and allows every secret in a system to be truly random. There&amp;rsquo;s a problem though, people don&amp;rsquo;t have perfect memory and tend to lose things, including hardware.&lt;/p&gt;&lt;p&gt;Once you introduce hardware&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt; as the final link in the chain of trust, you face a challenge: what happens when that hardware is lost or broken? There are generally two options here:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Say &amp;rsquo;too bad&amp;rsquo; and accept that whatever was behind this system you&amp;rsquo;ve designed is lost.&lt;/li&gt;&lt;li&gt;Implement a recovery mechanism, which adds new links to the chain. Links that end with a human&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt;.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Option 1 doesn&amp;rsquo;t sit well with users (and can have devastating effects), and option 2 doesn&amp;rsquo;t avoid the problem of relying on a human&amp;rsquo;s poor memory - it just moves the problem to another part of the system. This is often the case with security, the problem just gets moved because there isn&amp;rsquo;t a good solution.&lt;/p&gt;&lt;p&gt;This is the point where many otherwise incredibly secure systems show their weaknesses. You can use a secure authentication system like passkeys, strong phishing resistance, randomly generated so they are impossible to guess. Yet the security is reduced to the password for the service you use to sync them (such as an Apple account or password manager) and thus the security of the mechanism to reset that password.&lt;/p&gt;&lt;h2 id="always-the-same-problem"&gt;Always the Same Problem&lt;/h2&gt;&lt;p&gt;Many years ago when I was becoming more involved in the crypto&lt;sup id="fnref:3"&gt;&lt;a href="#fn:3" class="footnote-ref" role="doc-noteref"&gt;3&lt;/a&gt;&lt;/sup&gt; community, one of my favourite questions to ask was how key management should be implemented. What’s the right way to protect that final secret? The answer was always the same: &amp;ldquo;that&amp;rsquo;s a good question&amp;rdquo; followed by quickly changing the topic. The reason is that while it’s easy to hide the ultimate root of trust, add layers, move it around, and build complex systems that would protect against even the most advanced attackers, handling that ultimate key is a &lt;em&gt;very&lt;/em&gt; hard problem.&lt;/p&gt;&lt;p&gt;A lot of progress has been made to limit the impact of relying on human memory. Passkeys and password managers allow for far stronger secrets to be used, and with the associated improvements against common attacks such as phishing, this represents a vast amount of progress. However, the same underlying issue still exists.&lt;/p&gt;&lt;p&gt;The fact is that this is an effectively unsolved problem; the solutions could address it add far too much complexity for end users to rely on, and no amount of additional layers or moving the key around will fix it.&lt;/p&gt;&lt;p&gt;Key management has always been the greatest challenge for protecting secrets, and it will continue to be for the foreseeable future. As long as the chain ends with a human, the security of the system will be reduced to what that human can remember.&lt;/p&gt;&lt;p&gt;This isn’t to say that we should stop finding ways to better secure users, data, and the secrets that are critical to protecting them. Incredible progress has been made, and is still being made. Data is better protected today than it’s ever been. That said, that protection is often weaker than we would all like it to be.&lt;/p&gt;&lt;div class="footnotes" role="doc-endnotes"&gt;&lt;hr&gt;&lt;ol&gt;&lt;li id="fn:1"&gt;&lt;p&gt;This applies equally to hardware surrogates, such as password managers that play the same role that a hardware key would, just with a longer chain of trust involved.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:2"&gt;&lt;p&gt;This is effectively true, though not strictly true. It’s entirely possible to build recovery systems that rely on additional hardware tokens, though due to the complexity to implement and execute recovery, such mechanisms are far from common. For consumers and the vast majority of enterprise systems, systems like this effectively don’t exist. Only systems that need the highest security and can justify the additional costs and complications consider designs like this. As this post is focused on the common systems that most people are exposed to, any design that’s impractical for broad use won’t be considered.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:3"&gt;&lt;p&gt;Crypto means cryptography. Yes, that&amp;rsquo;s a hill I&amp;rsquo;ll die on.&amp;#160;&lt;a href="#fnref:3" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;</description></item><item><title>AI: Art Without Expression?</title><link>https://adamcaudill.com/2023/04/22/ai-art-without-expression/</link><pubDate>Sat, 22 Apr 2023 21:19:21 +0000</pubDate><guid>https://adamcaudill.com/2023/04/22/ai-art-without-expression/</guid><description>&lt;p&gt;Generative AI&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt; is changing the world, and is doing so faster than most of us could realise. While I don&amp;rsquo;t share the fear that it&amp;rsquo;ll destroy humanity (something we&amp;rsquo;re doing quite well at, without help), I do see that it&amp;rsquo;s having an impact on how we work, how we interact, and will have a growing impact on what jobs survive into the next generation. Just as switchboard operators, pin setters, and lift operators are all essentially extinct today, advances in technology will steadily eliminate some jobs, while creating new ones.&lt;/p&gt;&lt;p&gt;I have much to say on how it impacts developers, writers, graphic artists, and others, though for the moment it&amp;rsquo;s photographers I&amp;rsquo;d like to talk about. Photography is my &lt;a href="https://photo.adamcaudill.com/perspective"&gt;art form of choice&lt;/a&gt;, and I&amp;rsquo;m something of a purest - I don&amp;rsquo;t edit my photos (other than minor corrections), and they are published just as they were when they left the camera. It&amp;rsquo;s something I have strong feelings about.&lt;/p&gt;&lt;h2 id="the-quote"&gt;The Quote&lt;/h2&gt;&lt;p&gt;I recently saw a quote that pushed me to think more, and to experiment more. I wanted to understand, is what Generative AI produces art, or something else?&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;You’re Consuming Art That Has No Expression Behind It - &lt;em&gt;&lt;a href="https://www.hollywoodreporter.com/news/music-news/fall-out-boy-patrick-stump-ai-chatbot-lyrics-1235364265/"&gt;Patrick Stump, Fall Out Boy&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;To start answering this question, we have to look at both how we define art, and how generative AI models are trained, and I&amp;rsquo;ll start with the later.&lt;/p&gt;&lt;h3 id="ai-models"&gt;AI Models&lt;/h3&gt;&lt;p&gt;For a generative AI system to do anything at all, it needs to be trained on a vast quantity of samples - the more samples, the better the results. For a generative AI that produces photorealistic images, that means being trained on huge numbers of photographs. It then takes this vast dataset and uses elements learned from the countless images to produce what it was asked for. These elements are combined in unique ways, based on the description (known as a prompt) that was provided by the user, along with some randomness to produce different &amp;amp; interesting results. How this prompt is structured, what it contains, what&amp;rsquo;s left out, and what&amp;rsquo;s indicated as something unwanted all play a role in what is finally created (this is evolving into a new field of its own, prompt engineering).&lt;/p&gt;&lt;p&gt;While the AI system creates the image, it does so based on what the user tells it. It&amp;rsquo;s useless without training, and it&amp;rsquo;s aimless without careful decisions from the user.&lt;/p&gt;&lt;h3 id="what-is-art"&gt;What is Art?&lt;/h3&gt;&lt;blockquote&gt;&lt;p&gt;the conscious use of skill and creative imagination especially in the production of aesthetic objects - &lt;em&gt;&lt;a href="https://www.merriam-webster.com/dictionary/art"&gt;Merriam-Webster&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;There are some important words here that complicate matters for AI, in fact, almost every one of them:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;conscious - AI systems aren&amp;rsquo;t conscious, so they aren&amp;rsquo;t able to do anything consciously.&lt;/li&gt;&lt;li&gt;skill - AI has great information to work with, far more than what a human could learn from working with more experienced artists, though it has no innate skill, only the ability to combine elements that it&amp;rsquo;s learned from other&amp;rsquo;s works.&lt;/li&gt;&lt;li&gt;creative - AI doesn&amp;rsquo;t create anything that&amp;rsquo;s truly new, it can only combine what it&amp;rsquo;s learned.&lt;/li&gt;&lt;li&gt;imagination - Without consciousness, imagination isn&amp;rsquo;t possible, seeing what doesn&amp;rsquo;t exist but could isn&amp;rsquo;t something that software is suited for, and may never be.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you were to write a definition or art that was intended to ensure that AI could never meet the definition, this is exactly what you would likely arrive at. The definition is broad in meaning, but exacting in the exclusion of anything lacking clear consciousness.&lt;/p&gt;&lt;p&gt;Though, is it actually excluding AI? Let&amp;rsquo;s take another look at that list, and see how it could be read if we assumed that AI output is art:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;conscious - While there&amp;rsquo;s no good argument for consciousness, the process is not unlike consciousness. The process is deliberate, goal orientated, and structured to complete the task using what it&amp;rsquo;s learned.&lt;/li&gt;&lt;li&gt;skill - Humans, like all animals, learn from others; our skill is built on the knowledge and experience of others. We learn what works and what doesn&amp;rsquo;t from others. We learn the foundations of our skills from others. We learn what others appreciate, what&amp;rsquo;s atheistically pleasing, what works, and what doesn&amp;rsquo;t, all from others. AI models do something very similar, though at an incredible scale, a scale no human could match.&lt;/li&gt;&lt;li&gt;creative - Humans create things that are unique constantly. This blog post is a unique work, it has never existed in the history of the universe until I wrote it. AI creates unique things as well, while elements may be built from the things it&amp;rsquo;s learned (not unlike most art today), the output is still entirely unique in the universe.&lt;/li&gt;&lt;li&gt;imagination - AI systems &lt;a href="https://en.wikipedia.org/wiki/Hallucination_(artificial_intelligence)"&gt;hallucinate&lt;/a&gt; fairly often, creating new things that aren&amp;rsquo;t based on their training, or anything else identifiable. This isn&amp;rsquo;t quite imagination as human&amp;rsquo;s know it - though we just may be better at managing it.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;As you can see, there&amp;rsquo;s an argument to be made that it isn&amp;rsquo;t as simple as some people make it out to be. The expression of a generative AI system don&amp;rsquo;t &lt;em&gt;directly&lt;/em&gt; represent the expression of a human, but it does &lt;em&gt;indirectly&lt;/em&gt; represent the expression of millions.&lt;/p&gt;&lt;p&gt;The United States government has been clear that it doesn&amp;rsquo;t consider &lt;a href="https://www.theverge.com/2022/2/21/22944335/us-copyright-office-reject-ai-generated-art-recent-entrance-to-paradise"&gt;non-human expression&lt;/a&gt; to be subject to copyright protection, which doesn&amp;rsquo;t help the argument for this being art.&lt;/p&gt;&lt;p&gt;Though, given that art depends so heavily on the eye, opinion, and perspective of the beholder, it may be best to paraphrase Forest Gump and say simply that &amp;ldquo;&lt;em&gt;art is as art does&lt;/em&gt;.&amp;rdquo;&lt;/p&gt;&lt;h2 id="the-experiment"&gt;The Experiment&lt;/h2&gt;&lt;p&gt;&lt;img src="https://adamcaudill.com/files/IMG_0994.PNG" alt=""&gt;&lt;/p&gt;&lt;p&gt;What you see above is an image created with &lt;a href="https://stability.ai/"&gt;Stable Diffusion&lt;/a&gt;, while I don&amp;rsquo;t often shoot portraits, this does align with my &lt;a href="https://photo.adamcaudill.com/perspective"&gt;style&lt;/a&gt;. Creating this image required rendering a few hundred images and the final prompt consists of approximately 50 terms. Creating this image wasn&amp;rsquo;t a matter of feeding the system a simple command and getting exactly what I was looking for. It was a matter of trial and error, tweaking parameters, adjusting the prompt, steadily improving the image. After hours of work, I had something I was happy with.&lt;/p&gt;&lt;p&gt;This is something that I created, yet was also created by a machine. It is the product on many hours of effort - and honestly more time than I would put into most of the photographs I make. With most portraits, it is a collaboration between photographer and model, though in this case, the model isn&amp;rsquo;t the human kind.&lt;/p&gt;&lt;h3 id="is-it-art"&gt;Is it art?&lt;/h3&gt;&lt;p&gt;This is something I&amp;rsquo;ve struggled with. Looking at my role in the creation, the role of the generative AI, and the role of the countless people that contributed to the model that was used to produce it - it&amp;rsquo;s complicated. It&amp;rsquo;s impossible to say that this is purely my creation, as it isn&amp;rsquo;t. It&amp;rsquo;s creative, it&amp;rsquo;s new &amp;amp; unique, it&amp;rsquo;s my style, and it&amp;rsquo;s imaginative - from my own imagination, but is it actually art?&lt;/p&gt;&lt;p&gt;Yes. I would argue that generative AI can be a powerful tool for artists to guide creation of otherwise difficult or impossible works - just as Photoshop has been a powerful tool to enable the creation of otherwise difficult or impossible works. When guided by a human with a vision, generative AI can create amazing things that fulfil that vision. Where it becomes complicated is that it can also create something with no vision - just as a 5 year old can create something that is on the surface comparable to a Jackson Pollock work. It&amp;rsquo;s the vision, the purpose, the message, that separates a pointless creation into art. &lt;em&gt;The tool used for creation is less important that than the vision behind it.&lt;/em&gt;&lt;/p&gt;&lt;h2 id="greater--lesser-art-forms"&gt;Greater &amp;amp; Lesser Art Forms&lt;/h2&gt;&lt;p&gt;Personally, I see art forms as being on a spectrum, with the extremes being the most difficult to create to the least difficult. The most difficult to create are those that require the most skill, the most creativity, the most imagination, and the most consciousness. These are generally those that are creations from nothing, creating from a blank canvas, starting with nothing but a vision. These are the greater art forms, they require a special level of skill, and a special mind.&lt;/p&gt;&lt;p&gt;The lesser art forms allow the artist to start with something, and build on it. For a photographer, this is the world around them - leveraging what people and nature have created. No true photograph is a work of pure creation, but capturing the world from a unique perspective.&lt;/p&gt;&lt;p&gt;&lt;img src="https://adamcaudill.com/files/IMG_0995.PNG" alt=""&gt;&lt;/p&gt;&lt;p&gt;What you see here is a &amp;ldquo;painting&amp;rdquo; - created with generative AI, and in about 5 minutes. It&amp;rsquo;s a unique creation, it&amp;rsquo;s a unique expression, it&amp;rsquo;s a unique work of art. It&amp;rsquo;s also a lesser form of art. Unlike a true painting, the level of skill, vision, and imagination are far lower. It may be art, but it&amp;rsquo;s a lesser form of it. As someone that has little ability to draw or paint, I would be proud of this if it was a creation of my hand - but it isn&amp;rsquo;t, it&amp;rsquo;s a few minutes of typing and GPU time.&lt;/p&gt;&lt;p&gt;Generative AI can serve to greatly reduce the skill, investment, effort, and vision required to create something, and in this, the art itself is less meaningful. While it&amp;rsquo;s possible to invest heavily in achieving a particular vision, the creation is reduced by the reduced influence of the artist. It&amp;rsquo;s a lesser creation, and its artistic value is thus limited.&lt;/p&gt;&lt;h2 id="art-is-art"&gt;Art is Art&lt;/h2&gt;&lt;p&gt;Regardless of the tools used to achieve expression, art is about expression and vision. As technology has changed, from simple beads and cave paintings, to generative AI, art has changed with it. Some forms become less popular, new techniques are created, realism comes and goes, but it&amp;rsquo;s the vision, the expression that matters. Just as photography changed the world of art, replacing paining as the way the world is captured, AI will push art in new directions. As long as there&amp;rsquo;s a vision guiding the creation, it&amp;rsquo;s still art.&lt;/p&gt;&lt;div class="footnotes" role="doc-endnotes"&gt;&lt;hr&gt;&lt;ol&gt;&lt;li id="fn:1"&gt;&lt;p&gt;While I deeply hate the conflation of Machine Learning and Artificial Intelligence (one we&amp;rsquo;ve been doing for decades, the other, we aren&amp;rsquo;t there yet), though I&amp;rsquo;ve given up that fight. I apologise to those still fighting the good fight.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;</description></item><item><title>On Productivity</title><link>https://adamcaudill.com/2022/05/22/on-productivity/</link><pubDate>Sun, 22 May 2022 19:59:14 +0000</pubDate><guid>https://adamcaudill.com/2022/05/22/on-productivity/</guid><description>&lt;p&gt;Productivity and efficiency have been passions of mine from a young age, I&amp;rsquo;m not sure why, but achieving as much as possible, as quickly and efficiently as possible has always driven much of my thoughts, actions, and plans. I was around 10 years old when I learned that there were people that specialised in worker productivity, which led me to researching process design, why restaurants are setup the way they are, the psychology of work and motivation, and a variety of other related topics.&lt;/p&gt;&lt;p&gt;This resulted in a life-long love of psychology, a passion for usable technology, countless hours studying and understanding user experience, and an almost obsessive focus on productivity improvements as a manager.&lt;/p&gt;&lt;p&gt;Inspired by a &lt;a href="https://twitter.com/THEROSSHARKNESS/status/1501890629533683712"&gt;recent Twitter post&lt;/a&gt;, I&amp;rsquo;d like to share my thoughts, struggles, success, and tools that I&amp;rsquo;ve found useful over the years.&lt;/p&gt;&lt;h2 id="write-a-lot"&gt;Write, a Lot&lt;/h2&gt;&lt;p&gt;One of the best things you can do for yourself, and for others, is to invest the time to write, and do so in detail. I&amp;rsquo;ve &lt;a href="https://adamcaudill.com/2020/11/27/write-like-you-are-running-out-of-time/"&gt;written before&lt;/a&gt; about the importance of writing, and the choice of where you write, though I&amp;rsquo;d like to offer some specific points for this discussion.&lt;/p&gt;&lt;h3 id="notes"&gt;Notes&lt;/h3&gt;&lt;p&gt;Writing notes for yourself, or to be shared with others, is critical to being productive. Spending a few minutes during the course of your day can make a remarkable difference in terms of clarity, and your ability to come back and refresh your memory. Look at your notes as an extension of your mind, a way to gain additional storage of details, beyond what your mind can do alone.&lt;/p&gt;&lt;p&gt;I&amp;rsquo;ve used nearly every major note taking tool on the market, with varying degrees of success.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://logseq.com/"&gt;Logseq&lt;/a&gt; - This is my tool of choice, and I&amp;rsquo;m a &lt;em&gt;huge&lt;/em&gt; fan. It&amp;rsquo;s open-source, all storage is local (but can be synced in a number of ways), and evolving rapidly. In short, it&amp;rsquo;s a form of wiki that runs locally, it&amp;rsquo;s an outliner, so everything is a bullet-point list, creates daily journal notes, and it&amp;rsquo;s all in Markdown for easy editing. This just scratches the surface though, I can&amp;rsquo;t recommend it enough, if you haven&amp;rsquo;t tried it, you should.&lt;/li&gt;&lt;li&gt;&lt;a href="https://roamresearch.com/"&gt;Roam Research&lt;/a&gt; - Before moving to Logseq, this was my tool of choice. It&amp;rsquo;s similar to Logseq in most of the important ways, though everything is hosted on their servers, and there&amp;rsquo;s essentially no transparency when it comes to the security of your data. Moving from a traditional note taking tool to Roam was a life changing experience, though a poor mobile experience, constant delays on promised features, and a bizarre and aggressive approach to dealing with users drove me away.&lt;/li&gt;&lt;li&gt;&lt;a href="https://standardnotes.com/"&gt;Standard Notes&lt;/a&gt; - This is a hosted, but highly secure, solution for your more traditional note taking needs. I&amp;rsquo;ve been following the effort from its earliest days, and played a role in their first security audit - everything I&amp;rsquo;ve seen has been impressive. While it didn&amp;rsquo;t end up meeting my specific needs, I still highly recommend trying it.&lt;/li&gt;&lt;li&gt;&lt;a href="https://evernote.com/"&gt;Evernote&lt;/a&gt; - I&amp;rsquo;ve used Evernote since 2009 (at the latest), and I still have a substantial amount of content in it. While their security pales in comparison to Standard Notes and Logseq, it&amp;rsquo;s a robust tool that is extremely useful, especially for certain use cases (such as searching with PDF files). It&amp;rsquo;s this ability to search that keeps it around in my digital life, though in a steadily diminishing way.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;I&amp;rsquo;ve also used pen &amp;amp; paper (not having it away from the office became too annoying), &lt;a href="https://www.goodnotes.com/"&gt;GoodNotes&lt;/a&gt; on my iPad, and even a &lt;a href="https://www.remarkable.com/"&gt;ReMarkable&lt;/a&gt; (which tends to just collect dust for weeks at a time). There have been numerous others that I&amp;rsquo;ve tried, though didn&amp;rsquo;t use enough to make this list.&lt;/p&gt;&lt;p&gt;What&amp;rsquo;s important, is that you find a tool, workflow, something that works for you, and use it consistently. Notes are only valuable when you are consistent in taking them, and referencing them, you have to stick to it to get the most value out of the time invested.&lt;/p&gt;&lt;h3 id="communications"&gt;Communications&lt;/h3&gt;&lt;p&gt;Brevity is the enemy of clarity. When trying to convey a point to another, brevity isn&amp;rsquo;t a positive attribute, it opens the door for incorrect assumptions and misunderstandings. I&amp;rsquo;ve written about the need for &lt;a href="https://adamcaudill.com/2021/06/25/crew-resource-management-for-security-teams/#communication"&gt;effective communication&lt;/a&gt;, for &lt;a href="https://adamcaudill.com/2021/09/24/communicating-with-respect/"&gt;respectful communication&lt;/a&gt;, and will be writing about communication again soon.&lt;/p&gt;&lt;p&gt;While talking about taking more time when communicating may seem counter to the goals of an article on productivity, it really isn&amp;rsquo;t. Ineffective and insufficient communication take far more time, attention, and effort to correct than just getting it right the first time. Good communication takes time, time to write, time to read, time to understand - but in the long run, it&amp;rsquo;s a valuable investment.&lt;/p&gt;&lt;h2 id="focus-time--calendar-blocking"&gt;Focus Time &amp;amp; Calendar Blocking&lt;/h2&gt;&lt;p&gt;The ability to focus on a task and see it through to completion is critical to being productive, and that&amp;rsquo;s not possible with constant meetings and interruptions. I strongly suggest that everyone should set 1 day a week aside on their calendar just to focus and get things done. No meetings (unless they are critical), avoid instant messaging, and check off as much as possible on your todo list.&lt;/p&gt;&lt;p&gt;For me, this day is Monday. There is an event on my calendar that blocks the entire day, the details of the event are public, and it&amp;rsquo;s listed as &amp;ldquo;Important meeting only please&amp;rdquo; - making it clear that in an emergency, I&amp;rsquo;m available. This gives me a full day to work on larger tasks, without the normal stream of interruptions.&lt;/p&gt;&lt;p&gt;If you work remotely, put your lunch break on your calendar. This ensures that you have time to eat, relax, refresh, and recharge. When working remotely, and especially across time zones, it&amp;rsquo;s difficult for people to know when they are stepping on lunch or other breaks, blocking that time on your calendar ensures that it&amp;rsquo;s respected.&lt;/p&gt;&lt;p&gt;I also have 15 minutes at the end of each day blocked out to update my notes, todo list, and prepare for the next day. This is essentially a wind-down task, allowing me to perform a brain dump before stepping away. The serves to ensure that I make time to do it, and is a reminder that it&amp;rsquo;s time to call it a day and wrap up.&lt;/p&gt;&lt;p&gt;The other benefit of blocking out time like this is it creates accountability, if only to yourself.&lt;/p&gt;&lt;h2 id="prioritise-ruthlessly"&gt;Prioritise, Ruthlessly&lt;/h2&gt;&lt;p&gt;Time is precious, and so is mental bandwidth - to make the best use of both of these, prioritise tasks and limit what you try to focus on to just a few things, and the most important things, at any time. Once those are done, look at your list and prioritise again.&lt;/p&gt;&lt;p&gt;If it&amp;rsquo;s not that important, if it doesn&amp;rsquo;t move the needle, move it down to a lower priority. If you are trying to work on too many things during a day, you are likely setting yourself up for failure, frustration, and burn out.&lt;/p&gt;&lt;p&gt;If it get&amp;rsquo;s moved down too far, just drop it completely. Not everything is going to happen, some things are just going to get dropped.&lt;/p&gt;&lt;p&gt;Ruthless prioritisation is difficult, and it requires being able to say no, to push back, and to accept the limitations of your time. This is a skill that is developed over time, but an important one if you actually want to get things done.&lt;/p&gt;&lt;h2 id="understand-your-peaks--valleys"&gt;Understand your Peaks &amp;amp; Valleys&lt;/h2&gt;&lt;p&gt;You have natural, biological rhythms that define when your energy peaks and when it drops, and you need to understand these rhythms. You want to tackle your hardest tasks when you are at your peak, and save the easier tasks for the valleys. This ensures that you are at your best when you are tackling the hardest challenges.&lt;/p&gt;&lt;p&gt;For me, I use &lt;a href="https://www.risescience.com/"&gt;RISE&lt;/a&gt;, an app that tracks sleep, sleep debt, circadian rhythm, and other useful bits of data. This level of insight has helped me to better plan my days, and improve how I work.&lt;/p&gt;&lt;h2 id="understand-your-motivations-passions-and-challenges"&gt;Understand your Motivations, Passions, and Challenges&lt;/h2&gt;&lt;p&gt;You are an amazingly complex being, and most people really don&amp;rsquo;t understand how or why they do what they do. For example, why do people play the lottery? Because &lt;a href="https://www.alleydog.com/glossary/definition.php?term=Intermittent+Reinforcement"&gt;random rewards&lt;/a&gt; (intermittent reinforcement) are more effective than predictable rewards. Just as random punishments (intermittent negative &lt;a href="https://en.wikipedia.org/wiki/Reinforcement"&gt;reinforcement&lt;/a&gt;) can create a culture of fear and doubt more quickly than consistent punishments.&lt;/p&gt;&lt;p&gt;If you feel like your work is making a difference, the time will be more productive, where if you feel like it&amp;rsquo;s pointless or meaningless, it&amp;rsquo;s likely that the work will take longer and the time spent less productive.&lt;/p&gt;&lt;p&gt;If you suffer from an anxiety disorder (something amazingly common in the security industry), you may avoid tasks that would otherwise be simple and straightforward, because it&amp;rsquo;s uncomfortable. This can cause delays (which cause further issues), result in communication failures, and a variety of other problems. You need to understand how this impacts your work, how it impacts your motivation, and then you can begin adjusting for it.&lt;/p&gt;&lt;p&gt;If you suffer from ADHD, there are a variety of issues that can pop up, all of which impact how you work. You may be subject to &lt;a href="https://www.webmd.com/add-adhd/hyperfocus-flow"&gt;hyperfocus&lt;/a&gt;, which causes you to get lost in a task, at the cost of all else. You may find it difficult to stay focused on a single task, causing you to jump around constantly. You may find it difficult to stay organised and manage time efficiently. As with the impact of anxiety, you need to understand how these symptoms impact you, so that you can adjust your day and your planning to compensate.&lt;/p&gt;&lt;p&gt;Only with an understanding of how you work can you optimise for what drives you, what holds you back&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;, what makes you want to start work in the morning, and what makes you count the minutes till the day is over. You are the only person that can build a workflow that&amp;rsquo;s suited for you, and makes you as productive as possible.&lt;/p&gt;&lt;h2 id="just-do-it"&gt;Just Do It.&lt;/h2&gt;&lt;p&gt;If a task is only going to take a few minutes&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt;, just do it now. Don&amp;rsquo;t write it down, don&amp;rsquo;t add it to your list, just get it done and move on with your day. These little tasks take up mental bandwidth, slow down prioritisation, and add to the burden of making real progress.&lt;/p&gt;&lt;p&gt;Whatever you&amp;rsquo;re doing, you can afford those few minutes, and it&amp;rsquo;s an investment in making the rest of your day easier.&lt;/p&gt;&lt;h2 id="build-confidence-then-build-wins"&gt;Build Confidence, then Build Wins&lt;/h2&gt;&lt;p&gt;Don&amp;rsquo;t start with the hardest tasks, either your day, or a new project, start instead with easy wins, the low-hanging fruit. As you work through the easier tasks, you build confidence, understanding, insight, and context, so that when you do take on the hardest parts, your mind is in an ideal position to tackle it.&lt;/p&gt;&lt;p&gt;Saving the hardest for when you&amp;rsquo;ve built up confidence sets you up for success (a tip I learned from an art conservator), and when aligned with your peak energy for the day, you&amp;rsquo;ll find that it&amp;rsquo;s easier and quicker than expected.&lt;/p&gt;&lt;h2 id="work-hard-play-hard"&gt;Work Hard, Play Hard&lt;/h2&gt;&lt;p&gt;When you are working, minimise distractions, focus on specific tasks, take breaks to refresh, and move on to the next. When you are working on a specific task, try to avoid instant messaging, email, Twitter, and anything else that will draw your attention away. Focus as much as you can, and move on. While this can sometimes be a challenge, avoid distractions is a key to improved productivity.&lt;/p&gt;&lt;p&gt;When possible, group your meetings so that you can power through them, and then go back to focused work. Having meetings scattered through the day, with 30 minute breaks is a great way to generate a lot of wasted time.&lt;/p&gt;&lt;p&gt;When you are done working for the day, be done. Step away, go do something you enjoy. As a workaholic, this is certainly something I struggle with, but working more hours doesn&amp;rsquo;t translate into getting more done - working more hours just means that you are more tired, less focused, and less productive. You need to get away from work and do other things to recharge to be as productive as possible.&lt;/p&gt;&lt;p&gt;Dedicate time to hobbies and passions, make time for the activities and people you love.&lt;/p&gt;&lt;div class="footnotes" role="doc-endnotes"&gt;&lt;hr&gt;&lt;ol&gt;&lt;li id="fn:1"&gt;&lt;p&gt;I call out anxiety and ADHD as I live with both of these, and have had to find ways to manage the symptoms as best I can. Sometimes I do this effectively, sometimes I&amp;rsquo;ve utterly failed. It&amp;rsquo;s a challenge, but you must understand yourself to be able to change things in a way that works for you.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:2"&gt;&lt;p&gt;Some say the cutoff for these do it now tasks should be 2 minutes, others say five minutes, what matters is that you set a limit that works for you, and follow it as consistently as you can.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;</description></item><item><title>Taking Responsibility for the Spotlight</title><link>https://adamcaudill.com/2021/09/25/taking-responsibility-for-the-spotlight/</link><pubDate>Sat, 25 Sep 2021 17:27:42 +0000</pubDate><guid>https://adamcaudill.com/2021/09/25/taking-responsibility-for-the-spotlight/</guid><description>&lt;p&gt;Today, something happened that made me think carefully about my platform, my time in the spotlight, and how to best leverage my position to help others. Hopefully, you&amp;rsquo;ll find this to be thought-provoking and consider your own position and how it can be used.&lt;/p&gt;&lt;h2 id="your-platform--your-responsibility"&gt;Your Platform &amp;amp; Your Responsibility&lt;/h2&gt;&lt;p&gt;As a leader, there&amp;rsquo;s an undeniable responsibility to help others. This may mean being a mentor to someone just joining the industry, or giving opportunities to someone that would otherwise not get the break they need. As someone that&amp;rsquo;s been fortunate enough to earn leadership roles and something of a reputation in the field, I&amp;rsquo;m keenly aware of the responsibilities on my shoulders.&lt;/p&gt;&lt;p&gt;There are many things expected of those in positions of power, being a wise leader, compassionate and protective, leveraging the position to help others instead of greed and attention. But, unfortunately, so many that have built a name have become consumed by their ego, and lost sight of their responsibilities to the community and the world.&lt;/p&gt;&lt;h2 id="understanding-your-platform--power"&gt;Understanding Your Platform &amp;amp; Power&lt;/h2&gt;&lt;p&gt;Be it in professional or social venues, there is an undeniable influence that comes with the exposure of being known or having an important title. This platform can be ignored, sitting dormant and benefitting none, it can be abused to cause harm, it can be used to boost one&amp;rsquo;s ego or bank account. However, that platform can also be used to help others, drawing attention to causes that matter, to people who deserve to be heard, lift others up, and give them a chance.&lt;/p&gt;&lt;p&gt;An idle word by some can make or break a career, or even make or break a person.&lt;/p&gt;&lt;p&gt;The platform we each have can be a tool for good or evil; it&amp;rsquo;s up to us to understand our influence and how to best use it.&lt;/p&gt;&lt;h3 id="a-case-study-the-manager-looking-for-brides"&gt;A Case Study: The Manager Looking for Brides&lt;/h3&gt;&lt;p&gt;A dear friend of mine, who passed away far too soon, once shared a story from early in her career that she had never shared publicly. Hopefully, she wouldn&amp;rsquo;t mind me telling it here.&lt;/p&gt;&lt;p&gt;She worked as a developer for a government agency, one of the few that are often seen as a goal to work for; a place kids aspire to build a career at. She was very good at her job (she was one of the most brilliant people I ever met), and her performance reviews reflected the value she added. When she was eligible for a promotion, she had every reason to believe she would get it. However, when she met with her manager to talk about it, not only was she passed over, he made her question all of her decisions and questioned her own value.&lt;/p&gt;&lt;p&gt;He explained that she not only didn&amp;rsquo;t get the promotion, but she wouldn&amp;rsquo;t be getting one in the future. It had nothing to do with her technical ability, soft skills, or anything else. It had to do with the reason he had hired her in the first place.&lt;/p&gt;&lt;p&gt;You see, this manager firmly believed that a woman&amp;rsquo;s place was at home, waiting on her husband. The only things he thought a woman should do is take care of her husband&amp;rsquo;s house and carry his babies.&lt;/p&gt;&lt;p&gt;The office she worked in was in the middle of nowhere, and people found very few reasons to stay — especially younger men. Unless they had settled down with a family, that is. This manager had developed a strategy to keep his male developers from moving away to better jobs, hire young &amp;amp; attractive women, and hope they would turn into brides.&lt;/p&gt;&lt;p&gt;She was hired for the sole purpose of being an anchor, to keep a man from moving away. Not for her intellect, ability, knowledge, but her looks and ability to bear children.&lt;/p&gt;&lt;p&gt;In a two-minute conversation, he broke her spirit, her hope for the future, her career goals, and her belief in herself. Words from those in a position of power can be devastatingly powerful.&lt;/p&gt;&lt;h2 id="the-event"&gt;The Event&lt;/h2&gt;&lt;p&gt;During a meeting to discuss an upcoming webinar, I was asked if I would be the only speaker; my photo and bio would be posted, I would be the one on camera, it would promote my name just a little bit more. This isn&amp;rsquo;t anything new for me; I&amp;rsquo;ve been working to build a name in the field for years, establishing myself as a trustworthy source of information and insight. But an important thought ran through my mind before I could answer the question.&lt;/p&gt;&lt;p&gt;It wasn&amp;rsquo;t a question of who could do it better (I&amp;rsquo;m sure anyone involved would do great), or how to best leverage just a bit more exposure for myself, or who would enjoy it more; none of these crossed my mind. Instead, it was a question of who would be best served by more time in the spotlight.&lt;/p&gt;&lt;p&gt;I&amp;rsquo;ve tried to help everyone I can; I&amp;rsquo;ve tried to be fair, compassionate, I&amp;rsquo;m a fierce protector of my team, I &lt;a href="https://adamcaudill.com/2020/11/30/leading-experts/"&gt;listen to the experts&lt;/a&gt; on my team — though I&amp;rsquo;m not sure now, looking back, that I&amp;rsquo;ve done as much as I could to share the spotlight.&lt;/p&gt;&lt;p&gt;For those newer to the field, those less represented, those that too often feel they are alone in this industry, the spotlight can be important to building their own name, and showing others that there is room for them too. Three women on the team volunteered to help with the project; I don&amp;rsquo;t need the spotlight, but it could have far more impact for them.&lt;/p&gt;&lt;p&gt;The last thing the world needs is yet another webinar led by a relatively stereotypical boring white security guy — what is needed is for those less represented to be given a chance to get ahead, build their name, and show others that there&amp;rsquo;s room &amp;amp; opportunities. In a split second, I could claim this particular spotlight for myself, share it with others, or hand it to them, so it&amp;rsquo;s their own.&lt;/p&gt;&lt;p&gt;I handed it to them, so they are front &amp;amp; center.&lt;/p&gt;&lt;h2 id="sharing-the-spotlight"&gt;Sharing the Spotlight&lt;/h2&gt;&lt;p&gt;As leaders, we have many of these decisions to make, simple things that can make a massive difference to those we work with. When we look for them, look for chances to elevate others, there&amp;rsquo;s no shortage of opportunities or people that deserve them. What we do lack, as an industry, is enough people that are keeping their eyes open and leveraging their position to lift instead of belittling.&lt;/p&gt;&lt;p&gt;Looking for opportunities to place someone else in the spotlight comes at no harm to leaders, and helps to create future leaders. This isn&amp;rsquo;t some substantial sacrifice as would seem from the number of people that don&amp;rsquo;t even try; it&amp;rsquo;s just a matter of awareness of your position and ability to impact others positively. Unfortunately, this awareness of impact, both of words and actions, is missing more often than it should &lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;&lt;p&gt;To be a great leader, you have to lift everyone up, give them the chance to grow, the opportunity to be better. If you do your job right, you&amp;rsquo;ll create leaders that are better than you; that&amp;rsquo;s not a failure on your part, it&amp;rsquo;s success, it means the future will be better.&lt;/p&gt;&lt;p&gt;We all have obligations to others and the future. We all have a duty to leave the world better than we found it.&lt;/p&gt;&lt;div class="footnotes" role="doc-endnotes"&gt;&lt;hr&gt;&lt;ol&gt;&lt;li id="fn:1"&gt;&lt;p&gt;I recently wrote about the unintentional impact of words in &amp;ldquo;&lt;a href="https://adamcaudill.com/2021/09/24/communicating-with-respect/"&gt;Communicating With Respect&lt;/a&gt;&amp;rdquo; — it&amp;rsquo;s too common for a person to misinterpret something that is said due to issues with communication style and tone.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;</description></item><item><title>Communicating With Respect</title><link>https://adamcaudill.com/2021/09/24/communicating-with-respect/</link><pubDate>Fri, 24 Sep 2021 20:31:09 +0000</pubDate><guid>https://adamcaudill.com/2021/09/24/communicating-with-respect/</guid><description>&lt;p&gt;Communication can be a real challenge; working across cultures, backgrounds, experiences, and perspectives can result in different interpretations — and this is under the best of circumstances. However, when it&amp;rsquo;s written communication, the challenge is multiplied due to the lack of feedback cues from facial expressions, body language, and the like. These challenges make it exceedingly easy to create a situation where what a person hears is entirely different from what the speaker (or writer) intended.&lt;/p&gt;&lt;p&gt;These disconnects can create many negative impacts &amp;amp; make productive communication impossible. When communicating as a professional, there are a number of things to keep in mind, a few of which I&amp;rsquo;ve collected here.&lt;/p&gt;&lt;h2 id="perception-is-reality"&gt;Perception is Reality&lt;/h2&gt;&lt;p&gt;What you &lt;em&gt;intend&lt;/em&gt; is effectively irrelevant when communicating with others; it&amp;rsquo;s their perception that matters, as that&amp;rsquo;s what they will act on. For example, you may intend to be supportive, and it could instead be seen as patronizing. You may intend to say something that spurs conversation and instead shut it down. Perhaps you intend to take a strong position on something you care about, but in the process, you come across as a bully. These perceptual mismatches are all too easy to create through less than ideal communication, and, likely, we&amp;rsquo;ve all confused our listeners many times by making mistakes like these. When a person reacts to your communication, they can only infer your intent - and it can be drastically different than your actual intent.&lt;/p&gt;&lt;p&gt;Just because the intent was good doesn&amp;rsquo;t mean that the result will be; philosophy has an entire school of thought about this, &lt;a href="https://en.wikipedia.org/wiki/Consequentialism"&gt;consequentialism&lt;/a&gt;. In consequentialism, one&amp;rsquo;s intent isn&amp;rsquo;t considered when determining if an act (or lack of action) is right or wrong. Only the result it produces is considered. If you do something with the honest intention to do good, but it works out to cause more harm than good, then the action was wrong. While consequentialism is about morals, it also works for communication. How a person perceives what you have to say matters, not the intent in your mind while saying it.&lt;/p&gt;&lt;p&gt;With so much that can go wrong, we must be diligent in placing ourselves in the recipient&amp;rsquo;s shoes — try to do our best to see how something would be perceived, and adjust as needed to minimize the risk of them coming away with a different meaning. Of course, it&amp;rsquo;s impossible to get this correct 100% of the time, but it is possible to try 100% of the time.&lt;/p&gt;&lt;h3 id="words-matter"&gt;Words Matter&lt;/h3&gt;&lt;p&gt;Words have meanings, often more than one, and sometimes different meanings to different groups. What may seem innocent to one group, may be insulting or demeaning to another. What may be a minor expression of opinion to one, maybe inflammatory or aggressive to another. Thus, our choice of words is critical to ensuring that our communications achieve our intent, instead of leaving the meaning up to the ambiguity of inference, or worse, creating a perception entirely at odds with the original purpose.&lt;/p&gt;&lt;p&gt;The use of inflammatory terminology, calling an entity evil, for example, can send discourse into dangerous territory and lead to people feeling attacked or bullied. It can lead to shutting down a conversation or leave it spiraling out of control, becoming ever more problematic. If you find yourself using any of the following, you should likely reconsider your word choice.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Always, Never, Everyone, No-one, Best, Worst - This is a sign of oversimplification and generalization.&lt;/li&gt;&lt;li&gt;Overstatements &amp;amp; Exaggerations - Statements should be fact-based, clear, and accurate.&lt;/li&gt;&lt;li&gt;Extreme Words - The use of words that evoke extremes (evil, obnoxious, devil, etc.) set the stage for hostility and degradation of discourse.&lt;/li&gt;&lt;li&gt;Name Calling - While one wouldn&amp;rsquo;t generally do this in a professional context, it happens more often than it should, especially when referring to external entities. This is another dangerous territory, and can have particularly harmful effects even when the target isn&amp;rsquo;t part of the conversation.&lt;/li&gt;&lt;li&gt;Implications - It is easy to make assumptions about the feelings and positions of the recipient, and imply certain things without directly stating them. This can lead to varying understandings, and even outright wrong interpretations when those assumptions are incorrect.&lt;/li&gt;&lt;li&gt;Omissions - By omitting details, such as other facts, different opinions, mitigating factors, and the like, it&amp;rsquo;s possible to create an inaccurate view, and create a variety of interpretations among those with portions of the missing information.&lt;/li&gt;&lt;li&gt;Facts vs. Opinions - There are places and times that opinions are perfectly appropriate, but they need to be expressed as what they are, opinions. Care should be taken to avoid a listener (or reader) confusing opinion for fact. This is particularly important for professional opinions versus personal opinions; my personal opinion of something may be quite different from my professional opinion of the same thing. Professional opinions are held to a higher standard and are more influential; as such, it&amp;rsquo;s vital that they not be mixed.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Sexist language, racist, homophobic, transphobic, and so many other categories should be avoided at all costs, even when quoting another source. There are many types of exclusionary and offensive language, all of which are harmful regardless of who the intended target is, or if the intended target ever hears it. Generally speaking, if you have to ask if it could be offensive, it&amp;rsquo;s best to look for other options (or completely reevaluate what you are saying).&lt;/p&gt;&lt;h3 id="words-have-meaning"&gt;Words Have Meaning&lt;/h3&gt;&lt;p&gt;As the speaker, the onus is on you to understand what a statement means and how different people could understand it. At times, people will use a term that they believe to be innocent, but is problematic. While the intent isn&amp;rsquo;t to offend, it doesn&amp;rsquo;t make the use of such a term less offensive. This requires a conscious effort to understand different groups and how they use terminology, soliciting and listening to feedback. A constant process of education to ensure that your understanding of a term is accurate and not offensive.&lt;/p&gt;&lt;p&gt;This requires self-awareness, sensitivity to others, and the willingness to invest in being a better and more effective communicator. Not everyone does this naturally; for some, this is a more significant and more conscious effort, though it&amp;rsquo;s an effort that is necessary.&lt;/p&gt;&lt;p&gt;Given that perception is the reality to the listener, it&amp;rsquo;s imperative to make this investment and clearly understand every word and its various meanings.&lt;/p&gt;&lt;h2 id="dont-close-the-door"&gt;Don&amp;rsquo;t Close the Door&lt;/h2&gt;&lt;p&gt;Professional and respectful discourse should be encouraged; this means being open to contrary views, opinions, and perspectives. Unfortunately, it&amp;rsquo;s all too easy to shut down a conversation through poorly considered communication, leaving others involved with no desire to continuing to engage. Even worse, it can create an environment where ideas and opinions are withheld out of fear of the response. When the door for respectful and honest communication is closed, it comes at a cost — great ideas that are never considered, new perspectives that go unheard, useful information goes unshared, and the potential for adversarial relationships to develop.&lt;/p&gt;&lt;p&gt;There&amp;rsquo;s no expectation for everyone to always agree, but everyone deserves to be heard, and have their thoughts and ideas fairly considered. This is impossible when they are reluctant to share them because of poor and ineffective communication styles. Progress isn&amp;rsquo;t made when ideas are suppressed; success isn&amp;rsquo;t achieved when thoughts are held up by fear.&lt;/p&gt;&lt;p&gt;Discourse should be open, honest, and respectful. Anything less than this is an error that should be addressed as quickly as possible, lest a culture of fear and isolation develop.&lt;/p&gt;&lt;h2 id="everyone-deserves-respect"&gt;Everyone Deserves Respect&lt;/h2&gt;&lt;p&gt;Every person, regardless of innate trait or choice, deserves to be treated with respect, deserves to be heard, deserves to work without fear, or degradation, or condescension, or a thousand other things that place barriers, restrictions, limits, or otherwise hold them back from being their best. There&amp;rsquo;s never a valid reason for being disrespectful in professional communication or a professional environment (or, frankly, in any communication or environment).&lt;/p&gt;&lt;p&gt;Think about how the people you are communicating with will feel, what they will think, how your words will impact them. Try to understand the world from their perspective and consider your words in that light; this can often expose issues that would otherwise be missed; empathy is crucial to good communication. Coming to a conversation from a point of empathy allows you to understand issues and challenges easier, will enable you to find better solutions, and more quickly come to a shared understanding. If you engage without empathy, without understanding the other parties, you are not only working with woefully incomplete information, you are allowing your own biases and opinions to color the discussion. This likely means you are missing crucial points that could be addressed if you were working with a better understanding, and more open to their perspective.&lt;/p&gt;&lt;p&gt;It is your duty, no matter your role, to treat everyone with respect, including hearing them (not just letting them speak) and engaging in a good-faith manner. Nothing less than that should be accepted.&lt;/p&gt;&lt;h3 id="hearing-vs-allowing-speech"&gt;Hearing vs. Allowing Speech&lt;/h3&gt;&lt;p&gt;Allowing a person to speak is a simple and inactive task; hearing them, on the other hand, is an active task that requires several things:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Paying attention to what they are saying and how.&lt;/li&gt;&lt;li&gt;Understanding their perspective, challenges, and issues.&lt;/li&gt;&lt;li&gt;Setting aside your biases and preconceived notions so that you can empathize and actually understand them.&lt;/li&gt;&lt;li&gt;Reserving judgement until you are fully informed, instead of making decisions or forming positions based on incomplete information.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you don&amp;rsquo;t make an effort to actually hear a person, you are doing them and everyone else a disservice, and you are not truly engaged; if you are in a conversation just to support your own views and opinions, you are almost certainly speaking without adequate insight to form a meaningful position. Thus, you&amp;rsquo;re doing more harm than good. While you may still come to a position that disagrees with others you are communicating with, this position should be born of careful consideration of all relevant information, not just the information you came into it with.&lt;/p&gt;&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;&lt;p&gt;Take time to think about what you say, how others will feel, and you&amp;rsquo;ll be able to engage at a more meaningful level. This does require effort, but it&amp;rsquo;s a worthy investment, and you owe it to those you work with. These more meaningful conversations lead to better results, better ideas, better solutions, better relationships, and a better environment.&lt;/p&gt;&lt;p&gt;Everyone deserves respect, and it should be demonstrated in how you communicate.&lt;/p&gt;</description></item><item><title>On Software Subscriptions</title><link>https://adamcaudill.com/2021/09/12/on-software-subscriptions/</link><pubDate>Sun, 12 Sep 2021 06:39:33 +0000</pubDate><guid>https://adamcaudill.com/2021/09/12/on-software-subscriptions/</guid><description>&lt;p&gt;Like many in this field, I am always looking for ways to improve my workflow, improve my productivity, achieve more. Part of this is evaluating new tools that help me get work done, tools that become critical to my process. While looking at something that could be useful, I had a startling realization — but there are a couple of things I&amp;rsquo;d like to cover first.&lt;/p&gt;&lt;h2 id="supporting-what-you-love"&gt;Supporting What You Love&lt;/h2&gt;&lt;p&gt;I always try to pay for things that make my life better and support businesses that give me real value. When I worked in an office, I would always eat lunch at locally-owned restaurants; I wanted them to succeed, I wanted them to stay in business, so they got my money. There are many things that I pay for that I don&amp;rsquo;t have to, but I want them to keep making my life better. I don&amp;rsquo;t need to pay for a Twitter client, but I do. I don&amp;rsquo;t need to pay for a note-taking tool, but I do. I don&amp;rsquo;t need to pay for a to-do list tool, but I do.&lt;/p&gt;&lt;p&gt;You see where this is going. There are a lot of ways to keep a few dollars in your pocket, but this comes with the risk of that tool that&amp;rsquo;s making each day just a tiny bit better going away sooner. Support businesses that make your life better and invest in their future, so they will still be around.&lt;/p&gt;&lt;h2 id="tools-i-use--love"&gt;Tools I Use &amp;amp; Love&lt;/h2&gt;&lt;p&gt;I use several tools every day that make me better at what I do, more effective &amp;amp; productive. I&amp;rsquo;m sharing these because they make life better for me, but there&amp;rsquo;s also an interesting point here.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://roamresearch.com/"&gt;Roam Research&lt;/a&gt; (Subscription) - This app has been close to life-changing; being able to easily extend my memory has had a remarkable impact. While it&amp;rsquo;s easy to see this as just another note-taking tool, until you&amp;rsquo;ve used it, you don&amp;rsquo;t know what you&amp;rsquo;re missing out on.&lt;/li&gt;&lt;li&gt;&lt;a href="https://tapbots.com/tweetbot/"&gt;TweetBot&lt;/a&gt; (Subscription) - I spend a fair bit of time on Twitter, and this is by far the best interface available, no ads, no refreshing while you&amp;rsquo;re reading, no nonsense. If it weren&amp;rsquo;t for TweetBot, I probably would have given up on Twitter.&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.rememberthemilk.com/"&gt;Remember the Milk&lt;/a&gt; (Subscription) - I&amp;rsquo;ve been a paying user of RTM for quite a few years and use it for everything. From reminding me to take out the trash to tracking long-term projects. It&amp;rsquo;s been an essential part of my work from the first day I used it.&lt;/li&gt;&lt;li&gt;&lt;a href="https://ulysses.app/"&gt;Ulysses&lt;/a&gt; (Subscription) - Undoubtedly the best dedicated writing app on the market, especially for truly long-form writing projects. Excellent focused interface, and a pleasure to use.&lt;/li&gt;&lt;li&gt;&lt;a href="https://1password.com/"&gt;1Password&lt;/a&gt; (Subscription) - While it shouldn&amp;rsquo;t be a surprise that I use 1Password given that I work for them, I was a paying customer for several years before I joined the company. This is the first application that gets installed when I get a new device, and holds my entire life, COVID-19 vaccination card, driver&amp;rsquo;s license, social security numbers for my whole family, all of my credit cards. You name it. I don&amp;rsquo;t use 1Password because I work for them; I work for them because I use 1Password.&lt;/li&gt;&lt;li&gt;&lt;a href="https://evernote.com/"&gt;Evernote&lt;/a&gt; (Subscription) - While I mainly use Roam for capturing notes, I have used Evernote since 2008, and there are some use cases where nothing else competes. The use of OCR to allow searching within documents has made it vital for me, as it allows me to quickly find important information in a vast archive.&lt;/li&gt;&lt;li&gt;&lt;a href="https://ia.net/writer"&gt;iA Writer&lt;/a&gt; (One-Time Fee) - For larger projects, I find Ulysses to be the best option, though for smaller efforts (like this post), I&amp;rsquo;ve found iA Writer to be a better and more natural fit. Great focused writing environment (even beyond what Ulysses offers), and just the right feature set to do what you need to, without any clutter or complications.&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.jetbrains.com/"&gt;JetBrains Developer Tools&lt;/a&gt; (Subscription) - Almost all of my development work is done in one of their tools, so I&amp;rsquo;ve subscribed to their &amp;ldquo;All Products Pack&amp;rdquo; for almost seven years. Every time I see the transaction hit my credit card, I honestly smile. The value for the money I&amp;rsquo;m spending is just incredible. (They offer &lt;a href="https://www.jetbrains.com/community/opensource/#support"&gt;free licenses&lt;/a&gt; for open-source developers — but I love the products enough that I&amp;rsquo;d rather pay for them.)&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.adobe.com/creativecloud/photography.html"&gt;Adobe Photography Plan&lt;/a&gt; (Subscription) - Given my history as a photojournalist and my continuing love of &lt;a href="https://adamcaudill.com/photo/"&gt;photography&lt;/a&gt; as an art, having good tools to manage and correct photos is important.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;All of these are important to me, and have a profound impact on not just my ability to work efficiently, but also impact my hobbies, and my day-to-day life in important ways.&lt;/p&gt;&lt;h2 id="evaluating-things"&gt;Evaluating Things&lt;/h2&gt;&lt;p&gt;The &amp;ldquo;&lt;a href="https://culturedcode.com/things/"&gt;Things&lt;/a&gt;&amp;rdquo; application is a popular and extremely well-reviewed task manager — and I&amp;rsquo;m always looking to up my game — so I thought I&amp;rsquo;d check it out. A critical aspect of my workflow is the ability to work from a variety of devices:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;MacBook Pro - My primary work device, though large and hot, so it typically stays on my desk.&lt;/li&gt;&lt;li&gt;iPhone - I spend a surprising amount of time working from just my phone, because it gives me access to everything I need for a number of my tasks.&lt;/li&gt;&lt;li&gt;iPad - My iPad is my go-to device when I&amp;rsquo;m writing or need to get away from my desk.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Looking at reviews, checking out features, seeing what people are saying about it, everything looked like it would be a viable option. Then I saw something that was surprising, but moreso, my immediate reaction surprised me even more.&lt;/p&gt;&lt;img src="https://adamcaudill.com/files/things_pricing.png" alt="Pricing details for the Thing app."&gt;&lt;p&gt;The macOS app is $49.99, the iPhone app is another $9.99, and the iPad app is $19.99 — that&amp;rsquo;s $79.97 for all three platforms. Thankfully, they offer a trial for the macOS application, but given my workflow, just using that trial wouldn&amp;rsquo;t be enough to know if it would work for me. I need to use all three to understand if it makes things better.&lt;/p&gt;&lt;p&gt;Before I go on, I want to make it clear that I have no problem spending the money on good tools; their impact on productivity and quality of life is often more than worth it.&lt;/p&gt;&lt;p&gt;When I saw the fact that each platform is priced separately, my immediate reaction was comprised of two things:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Disappointment at needing to spend almost $80 just to know if it&amp;rsquo;s worth spending money on it.&lt;/li&gt;&lt;li&gt;Disappointment and surprise that they didn&amp;rsquo;t offer a subscription.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The fact that my immediate reaction was disappointment that they &lt;em&gt;weren&amp;rsquo;t&lt;/em&gt; offering a subscription rather surprised me.&lt;/p&gt;&lt;h2 id="the-move-to-subscriptions"&gt;The Move to Subscriptions&lt;/h2&gt;&lt;p&gt;Looking at the list of the most critical tools in my life today, all but one are subscription-based. Some of them have always been subscriptions, but a number started out selling licenses at a one-time fee, then later switched pricing models. Given that only one still charges a one-time fee, it&amp;rsquo;s clear just how powerful this trend is.&lt;/p&gt;&lt;p&gt;But why? Why are so many companies moving to this pricing model?&lt;/p&gt;&lt;p&gt;A few important factors apply to this decision; some are obvious, and some aren&amp;rsquo;t. Let&amp;rsquo;s compare a few of the key differences between the two models, and how they impact the business and ultimately impact the user.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Revenue predictability — there are some substantial differences in how predicable the flow of cash is between these two models, which has a considerable impact on how a business operates:&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Subscriptions&lt;/strong&gt;: This shouldn&amp;rsquo;t come as a surprise; companies like to know how much money they are going to bring in. Keeping in mind that the national average (U.S.) for a Software Engineer (according to Glassdoor) ranges from $108,000 to $141,000+ depending on level (though it can be substantially more), it&amp;rsquo;s good to know if you&amp;rsquo;ll be able to make payroll. This is just one of many places where being able to guess how much money will be coming in makes a big difference.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;One-time Fee&lt;/strong&gt;: Unlike subscriptions, the one-time fee model makes it much harder to predict revenue, and thus makes it more difficult for a company to invest in the future (as they need to keep larger cash reserves). This leads to slower growth, fewer features, less support, and a variety of other decisions that can be bad for end-users. This also leads to some interesting risks, such as a new macOS release breaks a key feature, and you miss your ship date — does this put the company at risk of depleting its cash reserves?&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Spending control &amp;amp; predictability - One difference often cited when comparing these models is control of spending and predictability of spending:&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Subscriptions&lt;/strong&gt;: Costs are predictable, typically billed monthly or annually. It&amp;rsquo;s easy to understand what you&amp;rsquo;re spending and when it&amp;rsquo;ll happen; that said, you have no choice about these regular payments if you wish to keep using it.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;One-time Fee&lt;/strong&gt;: Some like the fact that with one-time fees, they get to decide when they are spending money on a product, instead of having recurring charges. Of course, you don&amp;rsquo;t know when a new version will come out, or if it&amp;rsquo;ll have the killer feature you&amp;rsquo;ve been waiting for, so there is control but less predictability.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;When do new features get released - due to the differences in business models that the different pricing models drive, there are fundamental differences in how new features get into the hands of users.&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Subscriptions&lt;/strong&gt;: New features are typically released as soon as they are ready, with no need to wait. This gets improvements into the user&amp;rsquo;s hands as quickly as possible, constantly improving the value proposition.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;One-time Fee&lt;/strong&gt;: Every time you build a new feature, you have to ask if it goes into the current version or is held back for the next paid upgrade. This means that users are missing out on what they want while companies save up new features until they have enough to justify a paid upgrade. Then, instead of releasing new features when they are ready, they get held back to produce more income.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Support - supporting users in these two models is rather different, and given the cost of providing quality support, it can make a big difference.&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Subscriptions&lt;/strong&gt;: It&amp;rsquo;s easier to keep the majority of users on the latest version, with all the known bug fixes in place — this keeps support costs down and quality high.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;One-time Fee&lt;/strong&gt;: There is likely a broader range of versions in use (as some users won&amp;rsquo;t pay for the upgrade), leading to more customer support work and longer resolution times. This can put a business in a difficult position, deciding how much to invest in fixes for old versions that aren&amp;rsquo;t generating any revenue, when to cut off support for older versions, or what level of support is tolerable given the demands of supporting multiple versions. All of this leads to customers having a less than ideal support experience.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Is a paid upgrade just a money grab? When a new paid upgrade is released, you have some users who will immediately pay, but you&amp;rsquo;ll also have some who think it&amp;rsquo;s just a way to get more revenue. Is it being released because it&amp;rsquo;s ready, or because the company needs to make payroll? Every paid upgrade will make some people happy, but will destroy the hard-earned goodwill with others.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Many more points could be added here, though it&amp;rsquo;s clear that the one-time fee model comes at a cost for both the company and the customer — for little, if any, advantage. The one-time fee model really is a relic of the days when software was shipped on a floppy disk (a 3D-printed save icon for the younger crowd). It wasn&amp;rsquo;t used in the past because it was the best model, but it was the only practical option.&lt;/p&gt;&lt;p&gt;Moving to subscriptions delivers more value &amp;amp; delivers it faster. While not everyone is happy with this model, there&amp;rsquo;s no denying that it&amp;rsquo;s where the industry is heading — and increasingly, what customers expect. Much to my surprise, it&amp;rsquo;s what I&amp;rsquo;ve come to expect.&lt;/p&gt;</description></item><item><title>Win by Building for Failure</title><link>https://adamcaudill.com/2021/08/22/win-by-building-for-failure/</link><pubDate>Sun, 22 Aug 2021 19:30:33 +0000</pubDate><guid>https://adamcaudill.com/2021/08/22/win-by-building-for-failure/</guid><description>&lt;p&gt;Systems fail; it doesn&amp;rsquo;t matter what the system is. Something will fail sooner or later. When you design a system, are you focused on the happy path, or are you building with the possibility of failure in mind?&lt;/p&gt;&lt;p&gt;If you suffered a data breach tomorrow, what would the impact be? Does the system prevent loss by design, or does it just fall apart? Can you easily minimize loss and damage, or would an attacker have free rein once they get in? How would your customers or clients be impacted?&lt;/p&gt;&lt;h2 id="going-down-the-wrong-happy-path"&gt;Going Down the Wrong (Happy) Path&lt;/h2&gt;&lt;p&gt;These are essential questions that should be asked when you are working on a new system, but too often, it&amp;rsquo;s the happy path that gets all the attention. That path where nothing is unusual or exceptional, where you get to show off your skills and make everyone excited. Here&amp;rsquo;s the thing about building a system that can withstand failure: most of the important work should never be noticed and never excite anyone — at least if you did the job right.&lt;/p&gt;&lt;p&gt;Designing for the happy path is easy, it&amp;rsquo;s comfortable, it makes for great demos and glowing reviews. But, unfortunately, it&amp;rsquo;s also a path to disaster. The reality is that things do go wrong; sooner or later, something will push you off that happy path.&lt;/p&gt;&lt;p&gt;If you want something that can stand the test of time, and give your customers the assurances they deserve, you need to build for failure.&lt;/p&gt;&lt;h2 id="defining-building-for-failure"&gt;Defining Building for Failure&lt;/h2&gt;&lt;p&gt;It&amp;rsquo;s all about defense in depth and resilience; it&amp;rsquo;s designing an architecture that anticipates failure modes and includes mitigations in the core of the design (not as an afterthought to please an auditor). Great systems fail gracefully, not just in the face of common issues, but also in the face of attackers.&lt;/p&gt;&lt;p&gt;While I may be biased, my favorite example is one of the more critical security features that my employer (1Password) uses: the Secret Key. This is a high-entropy string that is mixed into the authentication process by the client, and thus is required to access an account or derive the encryption keys to access data. This provides a &lt;em&gt;very&lt;/em&gt; important security property: if someone gains access to the 1Password database, they have no hope of getting into a user&amp;rsquo;s data. Because 1Password never has the Secret Key, the database is useless alone — only when you have the data, the user&amp;rsquo;s password, and the Secret Key can data be accessed.&lt;/p&gt;&lt;p&gt;This is building for failure; while 1Password doesn&amp;rsquo;t expect to be breached (and never has been), the system is designed so that if it ever happened, users would be protected.&lt;/p&gt;&lt;p&gt;How this can be implemented obviously varies depending on the system, but using additional defenses such as cryptographic controls (i.e., keys that you don&amp;rsquo;t control) can add substantial protection. In addition, ensuring you have proper monitoring, alerting, and segregation of your infrastructure can slow an attacker down, or prevent them from pivoting to more valuable targets — and this has to apply as much to a rogue employee as it does to an outside attacker. There are a number of these steps that should be taken to ensure that if an attacker is able to get in, they don&amp;rsquo;t get anything valuable.&lt;/p&gt;&lt;p&gt;What&amp;rsquo;s important here though, is that it requires changing the way you think about threats to your customers in an important but non-obvious way — you are always a threat to them. When you design with that in mind, seeing yourself as one of the threats, you can build more robust systems that are far more likely to withstand attacks. It&amp;rsquo;s this perspective that allows you to see with better clarity how you can defend your customers most effectively. I&amp;rsquo;m not saying that you shouldn&amp;rsquo;t trust your employees; while insider attacks do happen, they aren&amp;rsquo;t that common. I&amp;rsquo;m arguing for a change in perspective so that it doesn&amp;rsquo;t matter who the malicious actor is.&lt;/p&gt;&lt;p&gt;When you define a threat model — even an informal one — always include yourself as one of the threat actors. While your intentions may be pure, there could be a breach of your systems, a rogue employee, demands from a hostile government, or a thousand other things that make you a genuine threat to your customers.&lt;/p&gt;&lt;h2 id="honesty--transparency"&gt;Honesty &amp;amp; Transparency&lt;/h2&gt;&lt;p&gt;During a job interview a few years ago, I was asked a question that I had never heard before; it struck me as interesting as there was only one possible answer&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;&lt;p&gt;&lt;em&gt;When is it okay to lie to a customer?&lt;/em&gt;&lt;/p&gt;&lt;p&gt;I paused for a moment to think this through; the singular answer was so obvious that I wondered if I had missed something. I replied with &amp;ldquo;never,&amp;rdquo; and then we discussed the question at length — it turns out that a surprising number of people see no problem with deceiving customers, or identify countless exceptions or justifications.&lt;/p&gt;&lt;p&gt;Never, ever, for any reason at all, ever lie to a customer.&lt;/p&gt;&lt;p&gt;There is no easier way to destroy trust, to kill longstanding relationships, eliminate goodwill, and poison future prospects. Customers value honesty, and even moreso when it&amp;rsquo;s painful. It&amp;rsquo;s easy to lie, to keep secrets, to hide damaging information; while being honest can be quite difficult — but, as with all things in life, there&amp;rsquo;s a price to be paid for taking the easy option.&lt;/p&gt;&lt;p&gt;When something goes wrong, own it. Be transparent, be open, be honest, and give your customers the information they need&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt;. There may be pain in the short-term, but long-term, you earn respect for how you handle painful situations.&lt;/p&gt;&lt;h2 id="blameless-remediation"&gt;Blameless Remediation&lt;/h2&gt;&lt;p&gt;When something does go wrong, how do you respond? Is it a hunt for who to blame, or is it an opportunity to learn? Placing blame is not only ineffective, it&amp;rsquo;s actively harmful — people will protect themselves at the cost of their employer or users if they have to. They will shift blame, withhold information, hide errors, or even hide breaches when they think their job is on the line.&lt;/p&gt;&lt;p&gt;There are two ways to view these events:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;A human error, where blame is assigned, and punishment is needed.&lt;/li&gt;&lt;li&gt;A systems failure, where learning and improvements are needed.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;One of these leads to a loss of talent and a deeply hostile and dysfunctional environment, and the other leads to continuous improvement. If you are building with a long-term view, only one of these is rational.&lt;/p&gt;&lt;p&gt;Blame should never be placed on an individual&lt;sup id="fnref:3"&gt;&lt;a href="#fn:3" class="footnote-ref" role="doc-noteref"&gt;3&lt;/a&gt;&lt;/sup&gt;, but instead seen as a flaw in the system that allowed the error to progress to the point that it had an impact. If you call out those involved by name anywhere in the process, you are almost certainly doing it wrong.&lt;/p&gt;&lt;p&gt;While certain information is needed to ensure a proper understanding of an issue, such as the Pull Request that introduced the issue, the focus should not be on who was involved, but instead on the specific details of when it was introduced, if policies were followed, and what&amp;rsquo;s wrong that allowed the issue to go unnoticed. Again, the focus should not be on the individuals, but the process.&lt;/p&gt;&lt;p&gt;To foster an open and effective environment, everyone needs to feel comfortable presenting the bad news; nobody should ever feel fear when something goes wrong.&lt;/p&gt;&lt;p&gt;It&amp;rsquo;s a learning opportunity, and one too valuable to waste.&lt;/p&gt;&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;&lt;p&gt;While nobody expects to suffer a painful security failure, it&amp;rsquo;s vital to build for them from the beginning. By doing this, by seeing yourself as part of the threat model, you build a system that is far more able to withstand attacks than a system build under the assumption that everything will always go right.&lt;/p&gt;&lt;p&gt;It&amp;rsquo;s more work to build with failure in mind, progress seems slower, designs are more complex, you spend countless hours on details that will hopefully never matter — but in the moment they do matter, they will change everything. Sometimes engineering secure systems is thankless work, but it&amp;rsquo;s vital if you care about your customers.&lt;/p&gt;&lt;div class="footnotes" role="doc-endnotes"&gt;&lt;hr&gt;&lt;ol&gt;&lt;li id="fn:1"&gt;&lt;p&gt;I take a &lt;a href="https://en.wikipedia.org/wiki/Utilitarianism"&gt;utilitarian&lt;/a&gt; view of the world, and try to apply this philosophy to all my actions. While automatically seeing a lie as morally wrong may seem closer to deontological than consequentialist, the long-term impact is almost always net-negative when considering second-order effects of a lie. A lie may seem to be a net-positive in the short-term as it may deflect initial negative reactions. However, in the long-term, it creates a cascading series of further deceptions, a significant risk of discovery, and a much stronger negative reaction when the deception fails — thus creating a more substantial net-negative impact than the truth possibly could. This has been your philosophy lesson for the day; thank you for attending.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:2"&gt;&lt;p&gt;As I wrote in &amp;ldquo;&lt;a href="https://adamcaudill.com/2015/11/19/responsible-disclosure-is-wrong/"&gt;Responsible Disclosure Is Wrong&lt;/a&gt;&amp;rdquo; the priority must always be making decisions in the best interest of the user. This is not always simple; one must balance the need to alert users, and the risk of enabling more attacks. This requires a careful case-by-case analysis based on the unique factors of the event, as no two security incidents are identical. No matter what is done though, the interest of the user must always be the singular driving factor.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:3"&gt;&lt;p&gt;Some argue that those involved in an incident should be removed from their position, and excluded from future positions — this is a deeply flawed view, and one I addressed in &amp;ldquo;&lt;a href="https://adamcaudill.com/2021/05/18/best-practices-vs-inane-practices/"&gt;Best Practices vs Inane Practices&lt;/a&gt;&amp;rdquo; in particularly brutal form.&amp;#160;&lt;a href="#fnref:3" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;</description></item><item><title>Parasitic &amp; Symbiotic Business Models</title><link>https://adamcaudill.com/2021/08/22/parasitic-symbiotic-business-models/</link><pubDate>Sun, 22 Aug 2021 16:46:06 +0000</pubDate><guid>https://adamcaudill.com/2021/08/22/parasitic-symbiotic-business-models/</guid><description>&lt;p&gt;Does your business model thrive as your customer thrives, or does it drain the life from your customers? After a recent&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt; conversation on the impact of improved privacy tools (i.e., the eventual &lt;a href="https://blog.google/products/chrome/updated-timeline-privacy-sandbox-milestones/"&gt;elimination of third-party tracking cookies&lt;/a&gt;), I realized that the most significant effect of these improvements would be to companies with a parasitic business model. A business model which I see no problem in disrupting.&lt;/p&gt;&lt;p&gt;For many years, the web has existed as an advertiser&amp;rsquo;s dream&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt; — minimal privacy limitations, technical controls that had &lt;a href="https://www.fastcompany.com/90308068/how-the-tragic-death-of-do-not-track-ruined-the-web-for-everyone"&gt;little impact&lt;/a&gt;, and a strong lobbying arm that has been able to derail many efforts to improve the situation. Now, this is not to say that all advertising is evil, but that it&amp;rsquo;s ripe for abuse by those that get too greedy. In many cases, this has opened the door to parasitic business models that offer no real value, and in fact, only extract value from the end-user.&lt;/p&gt;&lt;h2 id="what-is-a-parasitic-business-model"&gt;What is a Parasitic Business Model?&lt;/h2&gt;&lt;p&gt;A great example of this is data aggregators and location tracking; services that exist to collect, connect, extend, and sell data about users. Too often, this is done without the user having any idea that it&amp;rsquo;s happening — much less having willfully agreed to it. This business model relies on the ability to collect vast amounts of data on users, and build profiles that can be sold to others, primarily for ad targeting &amp;amp; tracking.&lt;/p&gt;&lt;p&gt;There is no inherent benefit to the user for this activity; it doesn&amp;rsquo;t enable better services, or allow them to access the applications that collect this data at a lower cost. The value to an application developer is relatively small compared to other revenue sources, as the data &lt;em&gt;they&lt;/em&gt; collect has fairly little value of its own. It becomes valuable when it is merged with other datasets that the aggregator has acquired; it is this merging that creates value from noise. So we have a user giving up personal information (often unwittingly) for no benefit, some financial benefit for the application developer (though less than other viable revenue streams), and the bulk of the benefit going to the company collecting and selling the data.&lt;/p&gt;&lt;p&gt;You have to ask, what does this business model add to the end user&amp;rsquo;s experience? Do they benefit from the relationship, or are they being &lt;em&gt;used&lt;/em&gt; in the relationship? If you study the business model these companies employ, it&amp;rsquo;s clear that only one party benefits, and it&amp;rsquo;s not the user.&lt;/p&gt;&lt;p&gt;This is just one example of this type of business model that focuses on growth at the cost of the user. As improvements are mode to technical controls around privacy that are now being pushed by browser makers (such as implementing &lt;code&gt;SameSite=Lax&lt;/code&gt; &lt;a href="https://duo.com/decipher/google-rolls-out-samesite-cookie-changes-to-chrome"&gt;by default&lt;/a&gt;), life will steadily become more difficult for businesses in parasitic relationships.&lt;/p&gt;&lt;h2 id="healthy-business-relationships"&gt;Healthy Business Relationships&lt;/h2&gt;&lt;p&gt;A healthy business relationship should be symbiotic for all parties involved; each party becoming happier &amp;amp; healthier as the relationship develops, and thriving due to the relationship — not in spite of it. These relationships often have a few key traits:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Each party is fully aware of the relationship; no parties are being intentionally hidden.&lt;/li&gt;&lt;li&gt;Transactions are mutually beneficial; for example, paying for a service that provides value to the user. The service receives revenue to compensate them for the service, and the user gains the use of something that they see as valuable to them.&lt;/li&gt;&lt;li&gt;Each party has the opportunity to gain greater value from the relationship as the other parties thrive. To continue the paid service example, as the service receives revenue, it is able to invest more in improving the service, providing even greater value.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;These symbiotic relationships are a win for everyone involved, unlike parasitic relationships that are full of quick profit for one party and nothing but loss for the other. While parasitic business models do indeed lead to greater short-term profits, there is no loyalty developed, there is no long-term health in relationships, and the business model can break at any time with changes to technology.&lt;/p&gt;&lt;p&gt;In a symbiotic business model, the relationship develops over time, becoming stronger — customers become more loyal, more interested and invested, more passionate, and turn into promoters and ambassadors. Revenue climbs more slowly, but that growth is more likely to continue and expand long-term. This is a relationship built on mutual respect and benefit.&lt;/p&gt;&lt;h2 id="the-costs-of-a-parasitic-business-relationship"&gt;The Costs of a Parasitic Business Relationship&lt;/h2&gt;&lt;p&gt;When you are engaged with a parasitic entity, knowingly or otherwise, there are costs involved. For users, this can be anything from a &lt;a href="https://arstechnica.com/tech-policy/2021/07/catholic-priest-quits-after-anonymized-data-revealed-alleged-use-of-grindr/"&gt;loss of privacy&lt;/a&gt;, &lt;a href="https://www.bellingcat.com/news/2021/05/28/us-soldiers-expose-nuclear-weapons-secrets-via-flashcard-apps/"&gt;revealing&lt;/a&gt; &lt;a href="https://www.wired.com/story/strava-heat-map-military-bases-fitness-trackers-privacy/"&gt;secrets&lt;/a&gt;, bypassing &lt;a href="https://www.engadget.com/secret-service-bought-location-data-locate-x-165531624.html"&gt;legal safeguards&lt;/a&gt;, or even risking &lt;a href="https://www.vice.com/en/article/8xwngb/t-mobile-put-my-life-in-danger-says-victim-of-black-market-location-data"&gt;personal safety&lt;/a&gt;. For businesses, there are &lt;a href="https://www.theverge.com/2021/2/26/22302709/lastpass-android-app-trackers-security-research-privacy"&gt;repetitional risks&lt;/a&gt; — failing to respect the privacy of users can lead to a substantial backlash. There are also &lt;a href="https://techcrunch.com/2020/12/10/france-fines-google-120m-and-amazon-42m-for-dropping-tracking-cookies-without-consent/"&gt;monetary risks&lt;/a&gt; for failing to follow legal requirements. And a variety of others — the list keeps going.&lt;/p&gt;&lt;p&gt;There&amp;rsquo;s only one winner here, just as with any parasitic relationship. Placing these risks and burdens on users is not just risky for a business; it is, in my opinion, highly unethical. Regardless of legal status, it&amp;rsquo;s morally wrong to exploit users who are acting in good faith and put them at risk for a quick profit — and there are some companies that have turned this practice into a business.&lt;/p&gt;&lt;p&gt;Because of how these relationships are structured, end-users are too often unaware of the relationship and how it impacts them; they aren&amp;rsquo;t in a position to make an informed decision. Likewise, businesses enter these relationships without an accurate understanding of how data is used, and sometimes without even understanding what data is being collected&lt;sup id="fnref:3"&gt;&lt;a href="#fn:3" class="footnote-ref" role="doc-noteref"&gt;3&lt;/a&gt;&lt;/sup&gt; — and may not gain that understanding until it&amp;rsquo;s been abused and they are in the news.&lt;/p&gt;&lt;h2 id="in-conclusion"&gt;In Conclusion&lt;/h2&gt;&lt;p&gt;Some business models should be disrupted, as they are fundamentally against the interests of those they interact with. This is not to say that all advertising, analytics, monitoring, or other similar systems are evil or immoral — but some very much are. It is those, those that have become too greedy, those that have abandoned morals for easy profit, those that harm others for their own benefit, those are the ones that need to have their business models disrupted.&lt;/p&gt;&lt;p&gt;Businesses have an ethical obligation to protect those they have a relationship with (directly or indirectly), not exploit them.&lt;/p&gt;&lt;div class="footnotes" role="doc-endnotes"&gt;&lt;hr&gt;&lt;ol&gt;&lt;li id="fn:1"&gt;&lt;p&gt;By recent, I mean last November when I started writing this blog post. At the time of the original draft, there was a lot of discussion around Google&amp;rsquo;s push for privacy improvements in the browser; it&amp;rsquo;s in this context that this was written.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:2"&gt;&lt;p&gt;It should be noted that the golden age of digital advertising and the golden age of mass surveillance occurred at the same time. The implications of this fact should be clear.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:3"&gt;&lt;p&gt;It&amp;rsquo;s especially true for SDKs provided by third parties; their actual behavior isn&amp;rsquo;t understood, nor is the privacy impact. Blindly incorporating an SDK into an application can easily result in substantial security and privacy risks.&amp;#160;&lt;a href="#fnref:3" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;</description></item><item><title>Declaring War on Ransomware</title><link>https://adamcaudill.com/2021/07/04/declaring-war-on-ransomware/</link><pubDate>Sun, 04 Jul 2021 05:52:33 +0000</pubDate><guid>https://adamcaudill.com/2021/07/04/declaring-war-on-ransomware/</guid><description>&lt;p&gt;It’s time for everyone from the industry, developers, and the government to declare war on ransomware and make it as hard as possible for them to ply their insidious trade. There have been false starts and baby steps, diligent fighters without enough resources, and vendors that have only given a nod to the issue. It’s time to use every tool reasonably available to stop this scourge.&lt;/p&gt;&lt;p&gt;For so many in the industry that have dedicated so much of their time and effort to this fight, this statement may seem to diminish their efforts, but that is not my intent. The story here is that for too long, this issue hasn’t been addressed seriously by too many, and it’s time for that to change.&lt;/p&gt;&lt;h2 id="todays-ransomware-landscape"&gt;Today’s Ransomware Landscape&lt;/h2&gt;&lt;p&gt;To understand where we are today, it’s important to look at how ransomware has evolved over the years.&lt;/p&gt;&lt;p&gt;Ransomware has been around for many years, starting no later than 1989 with the &lt;a href="https://en.wikipedia.org/wiki/AIDS_(Trojan_horse)"&gt;AIDS Trojan&lt;/a&gt;, which targeted the healthcare industry and charged $189 per infected machine (via a P.O. Box in Panama). If we fast forward to the mid-2000s, ransomware was becoming more popular, and the fee being extorted was up to $300 per machine — a decent payday for not much work. Then, jumping ahead to 2013, we see the introduction of CryptoLocker, which charged $400 per device. But CryptoLocker was different from others in a significant way; it provided proof that there was serious money to be made — estimated to be up to $27 million. This changed the game.&lt;/p&gt;&lt;p&gt;As the years have gone by, the ransom demanded has increased quite significantly, with payments in the millions now being so common as to barely warrant notice. Of the major players, DarkSide is &lt;a href="https://www.cnbc.com/2021/05/18/colonial-pipeline-hackers-darkside-received-90-million-in-bitcoin.html"&gt;reported&lt;/a&gt; to have pulled in $90 million, Ryuk is &lt;a href="https://twitter.com/campuscodi/status/1394650267174543362"&gt;estimated&lt;/a&gt; to have made $150 million, REvil has made $100 million, and Maze comes in at $75 million.&lt;/p&gt;&lt;p&gt;The profit these attackers make is simply extraordinary, and this has changed tactics and created a dangerous business model.&lt;/p&gt;&lt;p&gt;In the past, ransomware attacks were largely untargeted, going after anything that stumbled across them. The operators didn’t concern themselves with who they hit or how much money they had. Now, it’s very much about finding companies with &lt;a href="https://www.microsoft.com/security/blog/2020/03/05/human-operated-ransomware-attacks-a-preventable-disaster/"&gt;weak security&lt;/a&gt; and taking them for as much money as possible. Ransomware moved from opportunistic to targeted, and the profits have soared.&lt;/p&gt;&lt;p&gt;Another significant change is the move to ransomware as a Service (&lt;a href="https://www.crowdstrike.com/cybersecurity-101/ransomware/ransomware-as-a-service-raas/"&gt;RaaS&lt;/a&gt;), professional teams developing the ransomware and providing it to attackers that find vulnerable targets and deploys it. While one may talk about a group such as REvil conducting an attack, the reality is more complex. REvil provides software and a service to the actual attackers, and then the profit is split between them. This has allowed a division of work, the development of better ransomware, and allowed attackers to focus on finding vulnerabilities (instead of needing to write code for the ransomware first). All in all, this is a logical evolution from a business perspective.&lt;/p&gt;&lt;p&gt;A final note to set the stage for what’s going on today is that many of these RaaS operators treat their enterprises as genuine businesses; legality isn’t part of the equation for them.&lt;/p&gt;&lt;h2 id="paying-ransom-hurts-everyone"&gt;Paying Ransom Hurts Everyone&lt;/h2&gt;&lt;p&gt;When a ransom is paid, everyone suffers. Funneling money to criminals allows them to expand, finance new attacks, recruit more people, and continue their crusade to make the world a little more dangerous.&lt;/p&gt;&lt;p&gt;While some may find themselves in a position where, due to their organization’s failures, they have no hope but to pay the ransom and hope the criminals actually help them, they do so at the cost to everyone. Funding criminal enterprises is, without question, morally wrong — it’s also self-defeating as it reverts funds away from better investments, and provides additional resources that will be used for future attacks. Just because an organization has paid the ransom doesn’t mean that the gang will leave them alone forever.&lt;/p&gt;&lt;p&gt;Each dollar that these gangs receive makes the world a little worse, and a little more dangerous for everyone. Each dollar they receive enables them to do more damage. Each dollar they receive motivates them to do it again.&lt;/p&gt;&lt;p&gt;Disrupting their business model must be a key goal of everyone involved, and that means making sure they receive as little money as possible.&lt;/p&gt;&lt;h2 id="fighting-on-multiple-fronts"&gt;Fighting on Multiple Fronts&lt;/h2&gt;&lt;p&gt;There is no silver bullet that will suddenly bring this problem to a halt; it needs to be addressed on a number of fronts simultaneously. This requires actions on the part of all stakeholders, and requires this action to be taken quickly and effectively. While ransomware will never be eliminated, the growing profits and increasing impact of attacks make it clear that not enough is being done.&lt;/p&gt;&lt;h3 id="technical"&gt;Technical&lt;/h3&gt;&lt;p&gt;The industry, the entire technology sector, has largely failed to address this issue adequately. While some progress has been made, it’s still far too easy to successfully execute these attacks.&lt;/p&gt;&lt;h4 id="platforms"&gt;Platforms&lt;/h4&gt;&lt;p&gt;O.S. vendors should be investing far more heavily in sandboxing applications, limiting their ability to quietly access all of the data on a system. Something akin to &lt;a href="https://en.wikipedia.org/wiki/AppArmor"&gt;AppArmor&lt;/a&gt; on all platforms would go a long way to limiting what these destructive tools can do.&lt;/p&gt;&lt;p&gt;Vendors should also reevaluate the traditional tiered approach to permissions, where system management functions also permit access to files and information that is unlikely to be needed. The principle of least privilege isn’t appropriately applied in O.S. permission models; instead of giving administrative users only the necessary access to perform the specific tasks needed, administrative users are often able to access things they have no real need to, greatly increasing the attack surface. Instead of tiers of administrative users, each level gaining more access, there should be a greater focus on types of administrative users, with each being limited to the least privileges possible. The concept of all-powerful user accounts is, and always has been, a mistake.&lt;/p&gt;&lt;p&gt;Platform vendors have a responsibility to address this issue and implement reasonable controls that limit what malicious software can do; while there are commercial tools that address these concerns, it’s the platform itself that should be providing more robust protection and providing organizations with a safe by default environment.&lt;/p&gt;&lt;h4 id="msps-services-mdm--integrations"&gt;MSPs, Services, MDM, &amp;amp; Integrations&lt;/h4&gt;&lt;p&gt;Too often, the keys to the kingdom are passed out freely, creating massive new attack vectors. The &lt;a href="https://hackrs.io/2021/07/03/ransomware-attack-on-kaseya-systems/"&gt;Kaseya attack&lt;/a&gt; is an excellent example of this; the attackers leveraged the privileged access that the Kaseya VSA product has to attack MSPs, and then used their access to attack their clients. This type of excessively privileged scenario creates such a large attack surface that an organization’s security because &lt;em&gt;entirely&lt;/em&gt; dependent on a third party.&lt;/p&gt;&lt;p&gt;As above, there should be a greater focus on properly adhering to the principle of least privilege and minimizing the risks and attack surfaces created. Too often, such integrations require levels of access and privilege that genuinely aren’t needed; this needs to change.&lt;/p&gt;&lt;p&gt;When a third party takes on privileged access to a client, they accept a substantial responsibility, one that not enough take as seriously as they should.&lt;/p&gt;&lt;h4 id="it--infrastructure-management"&gt;IT &amp;amp; Infrastructure Management&lt;/h4&gt;&lt;p&gt;I.T. is a mess. It’s that simple. In the decades that the field has had to evolve, many of the same problems persist from year to year, decade to decade.&lt;/p&gt;&lt;p&gt;The tools to manage systems in a secure way are often inadequate or introduce their own issues (here’s a fun &lt;a href="https://adamcaudill.com/2015/12/18/dovestones-software-ad-self-password-reset-cve-2015-8267/"&gt;example&lt;/a&gt;). Corners are often cut, taking the easier approach over the more secure approach; it’s easier, it’s faster, and often results in fewer complaints. In penetration tests, it’s common that the tester gains a substantial degree of access due to countless errors and missing controls. The list of issues goes on and on.&lt;/p&gt;&lt;p&gt;To gain the upper hand, organizations need to invest in making resilient networks that are both resistant to attacks and able to recover quickly.&lt;/p&gt;&lt;h4 id="wheres-the-backup"&gt;Where’s the Backup?&lt;/h4&gt;&lt;p&gt;An absolutely critical change that needs to occur is that backups should be protected, readily available, and tested. The fastest way to recover from a ransomware attack is restoring the encrypted data from backup; it doesn’t require approvals, payments, or supporting international criminal gangs.&lt;/p&gt;&lt;p&gt;Every organization should implement a robust backup strategy to recover effectively and efficiently if they are victimized. Too often, backups are nonexistent or untested and fail when needed — if there’s one thing that organizations take from these attacks, it should be how important it is to get backups right.&lt;/p&gt;&lt;p&gt;There’s no legitimate excuse to get this one wrong.&lt;/p&gt;&lt;h4 id="endpoint-security-vendors"&gt;Endpoint Security Vendors&lt;/h4&gt;&lt;p&gt;Slow, invasive, error-prone, ineffective, expensive, productivity inhibitors, privacy nightmares, security threats — these are just some of the ways I’ve heard endpoint security products described over the years. Unfortunately, this field has a real problem. This isn’t just a perception issue; it’s a real problem that professionals see every day.&lt;/p&gt;&lt;p&gt;It’s fairly uncommon to hear genuinely go things about an endpoint security product from those that work with them regularly. For all the marketing hype and bluster, they often fail to do the one thing they are meant for, and too often have a huge attack surface and excessive privileges that can lead to attacks that wouldn’t otherwise be possible.&lt;/p&gt;&lt;p&gt;These vendors need to look at their products and listen to the feedback that those in the field have been shouting at them for years. Then, stop spending so much of their budgets on impressing the C-suite and focus on building something that really does make the world a safer place. This is a field with substantial potential, but has failed to live up to it.&lt;/p&gt;&lt;h3 id="legal"&gt;Legal&lt;/h3&gt;&lt;p&gt;While there are substantial consequences to these crimes, prosecutions are still too rare. Greater international cooptation is needed, and there need to be more significant penalties for the gangs and all of those that support them — especially those that touch their money.&lt;/p&gt;&lt;p&gt;Cryptocurrency exchanges that handle money that came from an attack (and that have a reasonable way of learning this) should be targeted aggressively, making these ransomware gangs too toxic to work with. Making it harder for them to launder their money effectively will reduce their profits and thus their motivation and ability to finance future attacks.&lt;/p&gt;&lt;p&gt;The entire support infrastructure for these gangs should be targeted with all available tools.&lt;/p&gt;&lt;h3 id="financial"&gt;Financial&lt;/h3&gt;&lt;p&gt;Governments have a strong interest in stopping these attacks, from protecting national security and critical infrastructure to economic stability. Governments also have powerful tools at their disposal that can aid in this fight. I will focus on the U.S. government here, but there are typically equivalents for other countries.&lt;/p&gt;&lt;p&gt;Disrupting the business model that these criminal enterprises are based on should be a key goal for governments; by attacking the ability to easily profit from attacks, it’s possible to reduce the motivation and increase the risk for those involved. While there are many ways to fight this scourge, this is one that can be enacted quickly and is likely to have a notable impact.&lt;/p&gt;&lt;p&gt;In 2020, the Office of Foreign Assets Control (or OFAC) issued &lt;a href="https://home.treasury.gov/policy-issues/financial-sanctions/recent-actions/20201001"&gt;guidance&lt;/a&gt; pointing out the risk to companies that pay ransomware, as they may be violating sanctions that the government has implemented. This guidance was released following the 2019 decision to &lt;a href="https://home.treasury.gov/news/press-releases/sm845"&gt;sanction Evil Corp&lt;/a&gt; for their attacks; though since then, this tool has been underutilized.&lt;/p&gt;&lt;p&gt;To stem the flow of easy profits, the government needs to take quick and decisive action against these gangs — reducing their profits and making their companies less attractive targets.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Implementing sweeping sanctions against known gangs, their members, and those known to support them. Targeting their support infrastructure, be it cryptocurrency exchanges, infrastructure providers, or even nation-states, will make these groups too dangerous to work with safely. While they may go further underground, anything that makes it more challenging to collect profits is a win for all.&lt;/li&gt;&lt;li&gt;OFAC should only grant licenses to allow payment when there is a demonstrated need and substantial impact. This shouldn’t be a rubber stamp process, but instead, one that demands proof that it’s vital that the victim works with the attacker to recover.&lt;/li&gt;&lt;li&gt;The IRS has &lt;a href="https://www.reuters.com/business/finance/us-treasury-says-can-shrink-7-trillion-tax-gap-by-10-over-next-decade-2021-05-20/"&gt;proposed&lt;/a&gt; a reporting requirement that would demand that companies treat cryptocurrency transactions like cash transactions; thus, a transaction worth over $10,000 would have to be reported. This would help to identify these crimes, and support the sanction effort.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;There are a variety of other tools the government could leverage, but these have precedent and allow enough flexibility to minimize the risk of unintended harm to victims.&lt;/p&gt;&lt;h4 id="prohibition-vs-regulation"&gt;Prohibition vs. Regulation&lt;/h4&gt;&lt;p&gt;There are some that wish to implement a blanket ban on ransom payments, or even cryptocurrency itself, as a way of addressing this problem — this would be a mistake.&lt;/p&gt;&lt;p&gt;If these payments were made illegal with no opportunity to seek approval when there’s no other practical option, victims would be left in an impossible position. Face the loss of critical systems and perhaps face complete collapse, or violate the law. If they chose the latter, they would expose themselves and their organization to criminal penalties, and would open the door to ongoing blackmail to keep the payment secret. This would be an absurd outcome.&lt;/p&gt;&lt;p&gt;Proper regulation can achieve the goal of making targets less attractive without the risk of turning victims into criminals. Of course, it will require striking a careful balance, but it’s a safer route than an outright ban.&lt;/p&gt;&lt;h2 id="in-summary"&gt;In Summary&lt;/h2&gt;&lt;p&gt;The war on ransomware will never truly be won, and the fight will go on forever. However, the rate of successful attacks demonstrates how urgent it is that more be done, and that we all take steps to fight them.&lt;/p&gt;&lt;p&gt;As I said above, there’s no silver bullet, but there is a lot we can do.&lt;/p&gt;</description></item><item><title>On Automatic Updates and Supply Chain Attacks</title><link>https://adamcaudill.com/2021/07/03/on-automatic-updates-and-supply-chain-attacks/</link><pubDate>Sat, 03 Jul 2021 17:58:44 +0000</pubDate><guid>https://adamcaudill.com/2021/07/03/on-automatic-updates-and-supply-chain-attacks/</guid><description>&lt;p&gt;Once again, a supply chain attack is in the news; this time, it&amp;rsquo;s a ransomware attack &lt;a href="https://hackrs.io/2021/07/03/ransomware-attack-on-kaseya-systems/"&gt;against Kaseya&lt;/a&gt; which has impacted hundreds if not thousands of businesses. According to &lt;a href="https://twitter.com/GossiTheDog"&gt;Kevin Beaumont&lt;/a&gt;, the attackers &lt;a href="https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b"&gt;used a 0day vulnerability&lt;/a&gt; in the Kaseya VSA appliance to deploy a fake update to all systems it managed; that update is actually the REvil ransomware. As this is a VSA is used by Managed Service Providers (MSPs), this resulted in an attack not just on the MSPs but also their customers.&lt;/p&gt;&lt;p&gt;This event raises an interesting question on update mechanisms and how they play into supply chain attacks. This is what we&amp;rsquo;ll be discussing today.&lt;/p&gt;&lt;h2 id="a-history-of-abuse"&gt;A History of Abuse&lt;/h2&gt;&lt;p&gt;Update mechanisms have been leveraged by attackers for many years and have, in some cases, had a substantial impact:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The &lt;a href="https://arstechnica.com/gadgets/2021/04/hackers-backdoor-corporate-password-manager-and-steal-customer-data/"&gt;Passwordstate attack&lt;/a&gt; used updates to insert malicious code that stole credentials.&lt;/li&gt;&lt;li&gt;The &lt;a href="https://arstechnica.com/information-technology/2020/12/18000-organizations-downloaded-backdoor-planted-by-cozy-bear-hackers/"&gt;attack on SolarWinds&lt;/a&gt; pushed malware via updates to steal data from a variety of organizations, including the U.S. government.&lt;/li&gt;&lt;li&gt;&lt;a href="https://arstechnica.com/information-technology/2017/06/petya-outbreak-was-a-chaos-sowing-wiper-not-profit-seeking-ransomware/"&gt;NotPetya&lt;/a&gt; resulted in massive damage and was deployed via a &lt;a href="https://arstechnica.com/information-technology/2017/07/heavily-armed-police-raid-company-that-seeded-last-weeks-notpetya-outbreak/"&gt;backdoored version of M.E.Doc&lt;/a&gt;, once again delivered as an update.&lt;/li&gt;&lt;li&gt;&lt;a href="https://blog.1password.com/flames-and-collisions/"&gt;Flame&lt;/a&gt;, perhaps the most famous example of this type of attack, leveraged the Windows Update system to deploy its malware.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;These are but a few notable examples of incidents where an update mechanism is used to deploy some form of malware. Given this, one has to ask, are updates and especially auto-update mechanisms even safe to use?&lt;/p&gt;&lt;h2 id="why-automatic-updates-exist"&gt;Why Automatic Updates Exist&lt;/h2&gt;&lt;p&gt;Update mechanisms, automatic or otherwise, exists for a couple of primary reasons:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Ensuring that users are on a recent version, if not the latest. This allows developers to focus their efforts only on newer versions, which simplifies support, reduces the need to deal with compatibility, and gives users the latest and greatest features quickly.&lt;/li&gt;&lt;li&gt;Ensuring that users have the latest security fixes and improvements installed, to reduce the risk of being attacked by a known issue and provide additional protections.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;It&amp;rsquo;s a well-understood fact that users aren&amp;rsquo;t good at manually installing updates, even when there are important security fixes. As such, there is a high likelihood that users will be rather behind the most recent version, and this is where automatic updates come in. By updating automatically, users don&amp;rsquo;t have to think about it, security teams don&amp;rsquo;t have to worry about it, and users get the best protection with the least effort.&lt;/p&gt;&lt;p&gt;The importance of updates should be clear to everyone, and the use of automatic updates plays an essential role in getting these updates deployed in a timely manner.&lt;/p&gt;&lt;h3 id="security-updates-arent-just-fixes"&gt;Security Updates Aren&amp;rsquo;t Just Fixes&lt;/h3&gt;&lt;p&gt;Before going on, I&amp;rsquo;d like to digress for a moment to address something that is too often overlooked. When most people think of a security update, they assume it fixes a vulnerability that was discovered — though that&amp;rsquo;s not always the case.&lt;/p&gt;&lt;p&gt;Updates may include additional hardening, which doesn&amp;rsquo;t address a known vulnerability, but instead adds extra protection to prevent exploitation or mitigate unknown vulnerabilities. This is more important than many people realize, as in some cases, these hardening improvements can block entire classes of vulnerabilities.&lt;/p&gt;&lt;p&gt;Such improvements don&amp;rsquo;t have a CVE, as they don&amp;rsquo;t represent a flaw, but without them, there may be an additional risk. Too often, these updates are skipped in manual update systems because it&amp;rsquo;s not clear enough what it does.&lt;/p&gt;&lt;h3 id="accidental-fixes"&gt;Accidental Fixes&lt;/h3&gt;&lt;p&gt;Another issue that is overlooked is how often vulnerabilities that are unknown or unreported are fixed unintentionally during refactoring or other code changes. Some updates may contain important security fixes; it&amp;rsquo;s just that the developer doesn&amp;rsquo;t know it.&lt;/p&gt;&lt;p&gt;One of the advantages of always using the latest version is that it increases the odds of these accidental fixes.&lt;/p&gt;&lt;p&gt;This fact may be surprising to those that don&amp;rsquo;t regularly work in vulnerability research, but it&amp;rsquo;s more common than one would expect.&lt;/p&gt;&lt;h2 id="the-importance-of-securing-update-infrastructure"&gt;The Importance of Securing Update Infrastructure&lt;/h2&gt;&lt;p&gt;To implement any update mechanism, and especially an auto-update mechanism, it&amp;rsquo;s vital that the infrastructure be hardened as much as possible, and the fewest number of people possible have access to it. There are few assets in a development shop more critical to protecting users than this infrastructure.&lt;/p&gt;&lt;p&gt;Servers must be locked down, psychical access restricted, code carefully reviewed, and operating system &amp;amp; software fully up to date.&lt;/p&gt;&lt;p&gt;Penetration testing should be conducted regularly, of not only the update infrastructure itself, but the entire system from end to end. For example, access to version control systems, build systems, signing systems, deployment &amp;amp; update systems, update notification, and update installation. Every step needs to be carefully reviewed and tested to ensure that there&amp;rsquo;s minimal risk of an attacker being able to influence what&amp;rsquo;s released.&lt;/p&gt;&lt;h2 id="weighing-the-risks"&gt;Weighing the Risks&lt;/h2&gt;&lt;p&gt;The challenge now is this, how do the risks compare to the rewards? While this could be a case for a complete threat modeling exercise, I believe that there is an easier way to analyze this.&lt;/p&gt;&lt;p&gt;While some notable examples were listed above, the reality is that these attacks, while happening at an increasing pace, are still quite uncommon. After all, would we be having this discussion otherwise? Moreover, given how often auto-updating works, and the fact that with proper controls in place, the odds of a successful attack are small, there is a particularly strong argument that the rewards do indeed outweigh the risks involved.&lt;/p&gt;&lt;p&gt;While no system can achieve 100% security (&lt;a href="https://adamcaudill.com/2013/09/06/making-android-nsa-proof/"&gt;give or take&lt;/a&gt;), we can achieve a high level of security by following the proper practices. It&amp;rsquo;s cutting corners and failing to properly invest in security that often leads to successful attacks against these mechanisms. While it&amp;rsquo;s true there&amp;rsquo;s risk, in reality, far more attacks are prevented than triggered.&lt;/p&gt;</description></item><item><title>Crew Resource Management for Security Teams</title><link>https://adamcaudill.com/2021/06/25/crew-resource-management-for-security-teams/</link><pubDate>Fri, 25 Jun 2021 21:21:24 +0000</pubDate><guid>https://adamcaudill.com/2021/06/25/crew-resource-management-for-security-teams/</guid><description>&lt;p&gt;Over the last year or so, I’ve become quite a fan of &lt;a href="https://www.smithsonianchannel.com/details/series/802"&gt;Air Disasters&lt;/a&gt;, a television show dedicated to analyzing plane crashes and similar incidents. As I watched the show, I started seeing many ways that the lessons and procedures around aircraft safety also apply to running a security team; this valuable and hard-won wisdom, often born out of tragedy, can be of significant impact if appropriately applied. In this article, I will explore &lt;a href="https://en.wikipedia.org/wiki/Crew_resource_management"&gt;Crew Resource Management&lt;/a&gt; and how it can be applied to Information Security to make teams run better. Hopefully, these insights help you achieve more and fulfill the critical missions we are entrusted with.&lt;/p&gt;&lt;h2 id="what-is-crew-resource-management"&gt;What is Crew Resource Management?&lt;/h2&gt;&lt;p&gt;In 1977, the deadliest airline disaster in history occurred at &lt;a href="https://en.wikipedia.org/wiki/Tenerife_airport_disaster"&gt;Tenerife&lt;/a&gt;, when two 747s (KLM 4805 and Pan Am 1736) collied and cost 583 people their lives; this happened for a variety of reasons, though would have been prevented if the captain had listened to his team. The following year &lt;a href="https://en.wikipedia.org/wiki/United_Airlines_Flight_173"&gt;United flight 173&lt;/a&gt; crashed on the way to Portland, Oregon; the flight crashed because the captain was distracted by a malfunctioning landing gear and ran out of fuel (despite warnings from the crew). These accidents are the direct result of human errors, which account for as many as 80% of all accidents. These events, along with many others, led to the development and implementation of Crew Resource Management (CRM) and forever changed the way airliners are operated.&lt;/p&gt;&lt;p&gt;The implementation of CRM has drastically reduced the number of accidents that occur and has made air travel vastly safer than decades ago.&lt;/p&gt;&lt;p&gt;The value of these lessons has been applied in a number of other areas, such as firefighting, ship operations, air traffic control, healthcare, and others. To not take advantage of these lessons would be a missed opportunity for the security community to advance our practices.&lt;/p&gt;&lt;h3 id="what-exactly-is-crm"&gt;What, exactly, is CRM?&lt;/h3&gt;&lt;p&gt;CRM is intended to address a number of human factors, which is to say, preventing or mitigating entire classes of human errors through training focused on group dynamics, leadership, interpersonal communication, and decision-making. The focus is on seven specific areas:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Mission Analysis&lt;/li&gt;&lt;li&gt;Situational Awareness&lt;/li&gt;&lt;li&gt;Communication&lt;/li&gt;&lt;li&gt;Adaptability / Flexibility&lt;/li&gt;&lt;li&gt;Decision Making&lt;/li&gt;&lt;li&gt;Assertiveness&lt;/li&gt;&lt;li&gt;Leadership&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;These will be discussed in more detail below.&lt;/p&gt;&lt;p&gt;It should be noted that CRM alone is not a silver bullet; CRM compliments technical skills — to quote an FAA document on the topic:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Demonstrated mastery of CRM concepts cannot overcome a lack of proficiency. Similarly, high technical proficiency cannot guarantee safe operations in the absence of effective crew coordination.&lt;/p&gt;&lt;/blockquote&gt;&lt;h2 id="crm-focus-areas"&gt;CRM Focus Areas&lt;/h2&gt;&lt;p&gt;As CRM focuses on several different areas, we’ll look at each individually and discuss how they apply to our security work and the environments we work in.&lt;/p&gt;&lt;h3 id="mission-analysis"&gt;Mission Analysis&lt;/h3&gt;&lt;blockquote&gt;&lt;p&gt;A leader is responsible for understanding the task at hand, and all its potential risks and benefits, and developing plans to safely meet the objectives.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;When setting out on any task, it’s critical to fully understand not only the work, but what could go wrong. It’s disturbingly easy to create new issues in the process of trying to fix something; not understanding the implications of a change is responsible for a substantial number of security issues.&lt;/p&gt;&lt;h3 id="situational-awareness"&gt;Situational Awareness&lt;/h3&gt;&lt;blockquote&gt;&lt;p&gt;Loss of awareness of what’s happening around you can easily end in tragedy. Situational awareness must be a constant state of understanding what’s happening, combined with the alertness to notice changes.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Understanding what’s going on can be quite a challenge, especially in a complex and fast-moving environment — but when we lose sight of what’s going on, there’s a substantial risk of things going wrong. There are, thankfully, some warning signs that we can watch for to identify when we risk losing our situational awareness.&lt;/p&gt;&lt;h4 id="ambiguity"&gt;Ambiguity&lt;/h4&gt;&lt;p&gt;Do we understand the details clearly? Do we have enough information to make a sound decision? Can we trust the information we have? Can it be interpreted in more than one way?&lt;/p&gt;&lt;p&gt;All of these are warning signs that we aren’t working with sufficient information, and caution is required. While we can’t be paralyzed by bad data, we must evaluate what we know carefully and move ahead with care.&lt;/p&gt;&lt;h4 id="distraction--overload"&gt;Distraction / Overload&lt;/h4&gt;&lt;p&gt;Can you focus on the task at hand, or are you constantly being pulled in multiple directions at once? Can you complete your work correctly, or are you constantly leaving things half-done? Do you know where you left off from your last task?&lt;/p&gt;&lt;p&gt;If we can’t focus and complete routine tasks because of so many other things happening, it becomes impossible for us to understand what’s going on and where things stand. While we have to remain flexible to changing priorities, we can’t push ourselves so far that we lose sight of where we are.&lt;/p&gt;&lt;h4 id="fixation"&gt;Fixation&lt;/h4&gt;&lt;p&gt;On the opposite side of distraction is fixation, becoming so focused on a single task that we can no longer see the big picture — missing important information and events because we become blind to everything else.&lt;/p&gt;&lt;p&gt;This is particularly dangerous as it makes it easy to be confident that things are under control, when in reality, we have no idea what’s actually happening.&lt;/p&gt;&lt;h4 id="complacency"&gt;Complacency&lt;/h4&gt;&lt;p&gt;If we become too comfortable that everything is going well, we can let our guard down and miss the signs that something is going wrong. It’s vital that we are always alert and watching for signs of trouble — constantly aware of what’s going on, and the risks that these events present.&lt;/p&gt;&lt;h4 id="unresolved-discrepancy"&gt;Unresolved Discrepancy&lt;/h4&gt;&lt;p&gt;When something is odd, do you follow it down to the root cause, or ignore it and focus on other tasks? If we ignore things that aren’t right, we may miss important information about what’s going on — these discrepancies are essential clues to help us establish and maintain awareness. We can’t ignore things when they don’t add up; there’s always a reason for these situations, and we need to understand what it is.&lt;/p&gt;&lt;h4 id="lack-of-control"&gt;Lack of Control&lt;/h4&gt;&lt;p&gt;In aircraft terms, it would be “nobody is flying the plane” — in our world, we would say that nobody is actually in charge. This can be anything from abandoned tickets to a lack of leadership, a failure to ensure that the work that needs to be done is actually being done. Thanks to huge backlogs and understaffed teams, it’s easy for security to become disconnected from the rest of the company. Projects and tasks move forward without anyone from security involved — and this is a setup for failure.&lt;/p&gt;&lt;p&gt;While I don’t suggest that security should be in control of everything, but I do suggest that without security being involved, efforts can go in any direction because nobody is guiding the security properties or handling the threats that arise.&lt;/p&gt;&lt;h3 id="communication"&gt;Communication&lt;/h3&gt;&lt;p&gt;One of the most vital skills, if not the most critical skill, in working in a team environment is &lt;em&gt;effective&lt;/em&gt; communication. In reality, we are all communicating constantly, but too often, communication isn’t actually effective, and as a result, things can quickly go wrong because the information isn’t received as intended. There can be a wide variety of reasons, on either side, that causes these simple breakdowns in understanding — but the result can be incredibly damaging as it increases the likelihood of an error and makes it impossible for us to act effectively.&lt;/p&gt;&lt;p&gt;One method that CRM teaches is to use a 5-step process to make an assertive statement:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Opening - A clear statement to indicate who the message is directed towards to ensure that you have their attention.&lt;/li&gt;&lt;li&gt;State the Concern - Clearly articulate what it is that you think is wrong, what you’ve seen, or what you’re worried about.&lt;/li&gt;&lt;li&gt;State the Problem - Now that you’ve made it clear what you’re worried about, explain the issue as you understand it. This helps to ensure that both parties are on the same page.&lt;/li&gt;&lt;li&gt;Solution - Offer a solution to address the problem. Make it clear that action is needed and that you are suggesting a specific course of action to address the issue.&lt;/li&gt;&lt;li&gt;Agreement - Clearly ask for approval or consent to implement the suggested solution.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;All of these components play an essential role in communicating an issue and determining how to respond to it; if any element is left out, there may be confusion about what’s going on, why something would be done, or if the solution should be implemented. This technique also opens the door to further discussion around other solutions, as it ensures that everyone has the same understanding of what’s going on and what options may exist.&lt;/p&gt;&lt;p&gt;It’s important to understand that many factors play into effective communication. Developing this skill may require changes to personal habits, as well as changes to culture to allow this type of communication to exist and be effective.&lt;/p&gt;&lt;h4 id="communication-failure-types"&gt;Communication Failure Types&lt;/h4&gt;&lt;p&gt;There are many ways that communication attempts can go wrong, and thankfully for us, some of these have been documented to help us avoid them ourselves and spot them when they occur. We’ll focus on both errors from the person providing the information, and receiving the information.&lt;/p&gt;&lt;h5 id="provider"&gt;Provider&lt;/h5&gt;&lt;p&gt;There are a variety of ways that we can fail to effectively communicate information when we are trying to provide it to another, such as:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;No frame of reference - If you provide information without context or to a person who doesn’t possess the knowledge you assume, they may not understand the information or processes it as intended.&lt;/li&gt;&lt;li&gt;Missing information - If there is information or ambiguity, it’s easy for the receiver to come away with a different or incorrect understanding.&lt;/li&gt;&lt;li&gt;Inserting bias or opinion - If you include your personal opinion or show signs of bias, the information may seem less trustworthy, and the facts may not be accepted as such. It’s essential to keep personal views out of critical communication or clarify what’s a fact and what’s opinion.&lt;/li&gt;&lt;li&gt;Body language &amp;amp; tone - When speaking face to face, it’s important to be mindful of our body language and tone, as we may unintentionally alter the message or how it’s perceived.&lt;/li&gt;&lt;li&gt;Unwillingness to repeat - In high-stress situations, there is often a desire to move quickly and not waste time, and repeating something can undoubtedly feel like wasting time. However, we must be willing to repeat, in full, as needed to ensure that everyone understands what we are trying to convey. Many errors are introduced by repeating information and leaving bits out during that process.&lt;/li&gt;&lt;li&gt;Disrespectful or hostile communication - If the message is perceived (regardless of intent) in a disrespectful or aggressive manner, it’s unlikely that effective communication will occur. While it’s easy to become upset in times of high stress, this can lead to compounding mistakes and make a situation harder to recover from.&lt;/li&gt;&lt;/ul&gt;&lt;h5 id="receiver"&gt;Receiver&lt;/h5&gt;&lt;p&gt;Just as there are many errors that the provider can make, there is also a number that the receiver can make:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Prejudice - If we make up our mind before &lt;em&gt;understanding&lt;/em&gt; all of the information, it will impact and change our understanding and lead to new mistakes. It’s essential to have as complete a picture of the situation as possible before proceeding.&lt;/li&gt;&lt;li&gt;Attention - It’s far too easy to become distracted or not give a person full attention. This can lead to missing important parts of a message and either not understanding the situation or having a flawed understanding. Listening requires concentration and focus, and this fact must not be ignored.&lt;/li&gt;&lt;li&gt;Thinking ahead - In our field, it’s easy to hear someone and start to extrapolate or make assumptions about where they are going — if these assumptions are incorrect, it can lead to adverse outcomes. If you hear someone say “let me finish” or “hear me out,” it’s a clear warning that this is occurring.&lt;/li&gt;&lt;li&gt;Ignoring non-verbal cues - People communicate in a variety of ways, including voice tone and body language. These additional methods may contain valuable insight or other information that isn’t being presented verbally; it’s important to pay attention to these and adjust our understanding accordingly.&lt;/li&gt;&lt;li&gt;Clarification - Failing to ask for clarification, failing to seek more details, failing to gain a useful understanding all lead to making a situation more complicated. There’s no shame in asking someone to explain; while we may feel like we should already know something, missing the chance to gain understanding and moving ahead with a flawed perspective makes things worse.&lt;/li&gt;&lt;li&gt;Disrespectful or hostile communication - Knee-jerk reactions are often incorrect and lead to further mistakes. Becoming angry or seeking to assign blame often lead to additional errors. Information should be received and carefully considered, and thoughtful responses given.&lt;/li&gt;&lt;/ul&gt;&lt;h4 id="managing-tone"&gt;Managing Tone&lt;/h4&gt;&lt;p&gt;When communicating with others, especially during a high-pressure event, it’s important to be aware of the tone we use and avoid charged language. If we accuse someone of making a mistake, or making a suggestion that isn’t wise, we put that person on the defensive, and communication becomes ineffective.&lt;/p&gt;&lt;p&gt;The focus must be on addressing the situation, not on placing blame on anyone. Making this mistake can easily take a situation and make it far worse.&lt;/p&gt;&lt;p&gt;It doesn’t matter who’s to blame; what matters is how we respond.&lt;/p&gt;&lt;h3 id="adaptability--flexibility"&gt;Adaptability / Flexibility&lt;/h3&gt;&lt;blockquote&gt;&lt;p&gt;Adaptability/Flexibility refers to the ability to alter one’s course of action contingent upon or as a function of another’s action and/or situational demands.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;In most cases, it’s best to have clear procedures that are followed; this allows everyone to understand their role and know exactly what’s expected of them — that is, until procedures aren’t enough. No matter how well we plan, what procedures and policies we enact, there will always be situations where we need to adapt. There will always be situations where we need to adjust rapidly, alter plans or behavior, find ways to help others, and find constructive options under pressure.&lt;/p&gt;&lt;h3 id="decision-making"&gt;Decision Making&lt;/h3&gt;&lt;blockquote&gt;&lt;p&gt;Effective decision-making refers to the ability to use logical and sound judgment based on the information available.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Making sound decisions is quite obviously critical to our work, and there are a few guidelines that CRM offers us to make better decisions:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Accessing the problem.&lt;/li&gt;&lt;li&gt;Verifying information.&lt;/li&gt;&lt;li&gt;Identifying solutions.&lt;/li&gt;&lt;li&gt;Anticipating consequences of decisions.&lt;/li&gt;&lt;li&gt;Telling others of the decision and rationale.&lt;/li&gt;&lt;li&gt;Evaluating the decision.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;These should be fairly familiar as they also factor into the guidelines for effective communication that we covered above; good decision-making and effective communication are very closely linked. Without effective communication, good decision-making isn’t possible.&lt;/p&gt;&lt;h4 id="imperfect-information"&gt;Imperfect Information&lt;/h4&gt;&lt;p&gt;While the best decisions occur when everyone is fully informed and has a clear understanding of the situation, the reality is that these situations are rare. Most decisions are made with information missing. While sometimes derided, there is an apt &lt;a href="https://en.wikipedia.org/wiki/There_are_known_knowns"&gt;quote&lt;/a&gt; that explains this well:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&amp;hellip; there are known knowns; there are things we know we know. We also know there are known unknowns; that is to say we know there are some things we do not know. But there are also unknown unknowns—the ones we don’t know we don’t know. - &lt;em&gt;Donald Rumsfeld&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;There are things we know and understand, there are things we don’t know or don’t understand (but we recognize they exist), and things that we don’t know and have no idea that we don’t know. When evaluating information, it’s important to keep this in mind, as this concept plays a vital role in determining what is and what isn’t actionable.&lt;/p&gt;&lt;h3 id="assertiveness"&gt;Assertiveness&lt;/h3&gt;&lt;blockquote&gt;&lt;p&gt;Assertiveness refers to the willingness to actively participate, and the ability to state and maintain your position, until convinced by the facts (not the authority or personality of another) that your position is wrong.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;This is a particular challenge in our field due to the variety of personality types that exist, and how many people are excessively assertive (often without realizing) or are too introverted to be comfortable being assertive. While this is a challenge, it’s one that must be addressed.&lt;/p&gt;&lt;p&gt;CRM gives us a few ways that team members can assert themselves:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Providing relevant information without being asked.&lt;/li&gt;&lt;li&gt;Making suggestions.&lt;/li&gt;&lt;li&gt;Asking questions as necessary.&lt;/li&gt;&lt;li&gt;Confronting ambiguities.&lt;/li&gt;&lt;li&gt;Maintaining their position when challenged.&lt;/li&gt;&lt;li&gt;Stating opinions on decisions/procedures.&lt;/li&gt;&lt;li&gt;Refusing an unreasonable request.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Of course, it’s important to remember that, as discussed above, all communication needs to be respectful, and being assertive does not mean that the chain of command can be ignored. Team members should be empowered to do the right thing, though leaders are ultimately responsible for everything a team does.&lt;/p&gt;&lt;h4 id="most-conservative-response-rule"&gt;Most conservative response rule&lt;/h4&gt;&lt;blockquote&gt;&lt;p&gt;Occasionally there is a disagreement in the cockpit that cannot be resolved due to lack of information. It is best to agree in advance to take the most conservative action in these situations until additional information is available.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;What happens when there are multiple options (with different outcomes), and we aren’t sure which path to take? Following a rule like this helps to provide guidance and settle disagreements so that progress can be made quickly.&lt;/p&gt;&lt;h4 id="two-challenge-rule"&gt;Two challenge rule&lt;/h4&gt;&lt;blockquote&gt;&lt;p&gt;In extreme situations, if the pilot does not respond to two demands (e.g., “Waveoff, waveoff!”),the copilot should take the controls.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Does everyone on the team know what to do when they don’t get a response? When there’s no reaction (leaders are unavailable, for example), is there a way to handle issues, or does everything freeze until a leader is finally available?&lt;/p&gt;&lt;p&gt;In fast-moving situations, it’s crucial that everyone knows what to do and is able to act, even when others don’t.&lt;/p&gt;&lt;h4 id="sandbag-syndrome"&gt;Sandbag syndrome&lt;/h4&gt;&lt;blockquote&gt;&lt;p&gt;The Sandbag Syndrome is based on a comforting premise that one or more other crew members have the situation under control and are looking out for your best interest. It can be experienced by any crew position, resulting in that person being “along for the ride.”&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;This is likely the most critical part of assertiveness, as it’s incredibly common and creates many problems. Assuming that someone else will handle something works fairly often, because someone else may well handle it — but there’s no way to be confident; it could be missed completely. Each and every team member should assume ownership for issues that they see, even if it’s just confirming that someone else is actually aware.&lt;/p&gt;&lt;p&gt;This is not to say that people that fall into this trap are lazy or avoiding work, but they may be uncomfortable jumping in, they may not be sure who is responsible (if anyone), or maybe they are worried about what happens if something goes wrong. There are a hundred reasons that someone will sit back and expect someone else to do something, but it’s a problem waiting to happen.&lt;/p&gt;&lt;p&gt;If there is a single thing that should be achieved encouraging assertiveness, it’s addressing this specific problem.&lt;/p&gt;&lt;h3 id="leadership"&gt;Leadership&lt;/h3&gt;&lt;blockquote&gt;&lt;p&gt;Leadership is the ability to direct and coordinate the activities of other crew members and to stimulate the crew to work together as a team.&lt;br&gt;Being a good leader involves inspiring your crew to work up to their potential; a good leader can bring out the best in their crew. The leader is in control of the situation and has certain responsibilities.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Let’s start by looking at what CRM tells us a leader should be able to do:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Direct and coordinate the crew’s activities.&lt;/li&gt;&lt;li&gt;Delegate tasks.&lt;/li&gt;&lt;li&gt;Make sure the crew understands what is expected of them.&lt;/li&gt;&lt;li&gt;Focus attention on the crucial aspects of the situation.&lt;/li&gt;&lt;li&gt;Keep crew members informed of the mission information.&lt;/li&gt;&lt;li&gt;Ask crew members for mission-relevant information.&lt;/li&gt;&lt;li&gt;Provide feedback to the crew on their performance.&lt;/li&gt;&lt;li&gt;Create and maintain a professional atmosphere.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;None of these should come as a surprise; this is a brief but accurate portrayal of what leadership is. Though there’s much more to being a good leader than a few bullet points, a topic I’ve &lt;a href="https://adamcaudill.com/2020/11/30/leading-experts/"&gt;written about&lt;/a&gt; before.&lt;/p&gt;&lt;h4 id="authority"&gt;Authority&lt;/h4&gt;&lt;p&gt;In CRM, authority is reinforced through a few practices:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Ensuring mission effectiveness.&lt;/li&gt;&lt;li&gt;Fostering respectful communication.&lt;/li&gt;&lt;li&gt;Establishing clearly defined goals.&lt;/li&gt;&lt;li&gt;Including crew input.&lt;/li&gt;&lt;li&gt;Establishing clear assignments.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;As a leader, it’s essential to take responsibility and ownership while also listening to your team and taking full advantage of their knowledge and perspective. Establishing and maintaining authority does not mean excluding others, but acknowledging responsibility.&lt;/p&gt;&lt;h4 id="mentoring"&gt;Mentoring&lt;/h4&gt;&lt;p&gt;Every leader is responsible for mentoring those on their team, sharing knowledge and experience they’ve gained to help their team members grow. This helps to ensure that the team not only maintains technical competence but helps to establish trust in leaders.&lt;/p&gt;&lt;h4 id="conflict-resolution"&gt;Conflict Resolution&lt;/h4&gt;&lt;p&gt;Conflicts can and (and do) arise in every team, and can lead to growth if appropriately handled. It’s up to the team leader to resolve conflicts and act as a mediator when needed. It’s important to listen attentively, don’t become emotionally involved, and gain a clear understanding of the underlying cause of the conflict.&lt;/p&gt;&lt;h4 id="followership"&gt;Followership&lt;/h4&gt;&lt;p&gt;In an organization, essentially everyone is a follower, even if they are a leader as well. As such, it’s essential to understand how to follow effectively in addition to leading effectively. Being an effective follower isn’t passive, but a conscious effort and one that requires one accept certain responsibilities, such as:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Respecting authority.&lt;/li&gt;&lt;li&gt;Keeping ego in check.&lt;/li&gt;&lt;li&gt;Properly balancing respect and assertiveness.&lt;/li&gt;&lt;li&gt;Requesting clear assignments.&lt;/li&gt;&lt;li&gt;Reporting on the status of tasks honestly and clearly disclosing any issues.&lt;/li&gt;&lt;li&gt;Acknowledging mistakes.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Under the CRM model, followers are empowered to challenge leaders when a situation demands it, but this is dependent on followers exercising this right responsibly.&lt;/p&gt;&lt;h4 id="hazardous-attitudes"&gt;Hazardous Attitudes&lt;/h4&gt;&lt;p&gt;Keeping an eye out for hazardous attitudes — attitudes that can lead to mistakes — is helpful to spot issues before they happen. Some examples are:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Anti-authority: “Don’t tell me.”&lt;/li&gt;&lt;li&gt;Impulsivity: “Do it quickly.”&lt;/li&gt;&lt;li&gt;Invulnerability: “It won’t happen to me.”&lt;/li&gt;&lt;li&gt;Machismo: “I can do it.”&lt;/li&gt;&lt;li&gt;Resignation: “What’s the use?”&lt;/li&gt;&lt;li&gt;Pressing: “Let’s hurry up so we can go home.”&lt;/li&gt;&lt;li&gt;Airshow syndrome: “I’m going to look amazing!”&lt;/li&gt;&lt;/ul&gt;&lt;h4 id="personal-factors"&gt;Personal Factors&lt;/h4&gt;&lt;p&gt;It’s vital as a leader to understand that you are working with humans, not machines. Many factors heavily impact how well a person works, such as:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Hunger or thirst.&lt;/li&gt;&lt;li&gt;Fear of punishment or &lt;a href="https://www.psychologytoday.com/us/blog/fulfillment-any-age/201204/the-paradox-procrastination"&gt;failure&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6901841/"&gt;Noise&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;a href="https://adaa.org/managing-stress-anxiety-in-workplace/anxiety-disorders-in-workplace"&gt;Anxiety&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Drugs or alcohol.&lt;/li&gt;&lt;li&gt;&lt;a href="https://en.wikipedia.org/wiki/Effects_of_fatigue_on_safety"&gt;Fatigue&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Outside stress.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;When working with your team, it’s important to remember that these factors may exist and may be impacting them in ways that aren’t immediately obvious.&lt;/p&gt;&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;&lt;p&gt;I do hope that this has been useful and thought-provoking. While not everything in CRM applies quite the same way to the situations we face, hopefully, you can find ways to use these lessons in your own work. There are a vast number of resources on CRM, and I encourage you to look into it more.&lt;/p&gt;</description></item><item><title>Leading Experts</title><link>https://adamcaudill.com/2020/11/30/leading-experts/</link><pubDate>Tue, 01 Dec 2020 00:19:48 +0000</pubDate><guid>https://adamcaudill.com/2020/11/30/leading-experts/</guid><description>&lt;p&gt;A friend of mine recently asked for my thoughts on leading people who have more experience or expertise in a topic than they do; this is an important question and one that I felt deserved more thought and exploration. Leading people can be difficult, but when leading people that know more than you do about a given topic, it&amp;rsquo;s a different challenge. This was particularly well-timed, as I&amp;rsquo;ve found myself in just that situation, as I&amp;rsquo;ve just hired a specialist in incident response. While I&amp;rsquo;m fairly confident in my knowledge there, it pales in comparison to hers.&lt;/p&gt;&lt;p&gt;I&amp;rsquo;ll try to explore the issue and how it can be anything from different to difficult to effectively lead, when you are the one that needs to know more.&lt;/p&gt;&lt;h3 id="its-easy-when-youre-the-expert"&gt;It&amp;rsquo;s easy when you&amp;rsquo;re the expert&lt;/h3&gt;&lt;p&gt;Often in technical fields, those with the most expertise are promoted to lead those in the same field – as such, the leader has the most experience to draw on and the greatest level of knowledge. This gives those leaders a certain degree of additional confidence, as they can rely not only on the information they receive from their team, but also on their own knowledge and experience. This allows decisions to be made faster, with greater assurance that it&amp;rsquo;s correct, and hopefully, with the best possible information available.&lt;/p&gt;&lt;p&gt;In the real world, it&amp;rsquo;s not quite so simple. Leaders may overestimate the extent of their knowledge; they may fail to properly value the knowledge their team brings to the conversation; they may grow overconfident.&lt;/p&gt;&lt;p&gt;While we hope that leadership skills are present or will develop, the fact is that – most of the time – the people with the greatest knowledge and skill will be moved into leadership roles. They will have a team, and they will need to listen to them to achieve success. Leading from the front, when you&amp;rsquo;re at the forefront, is fairly easy. Leading when you know how much you don&amp;rsquo;t know is harder.&lt;/p&gt;&lt;h4 id="encouraging-disagreement"&gt;Encouraging disagreement&lt;/h4&gt;&lt;p&gt;I would like to digress for a moment to talk about disagreements. If you are a leader, and someone on your team disagrees with you – it&amp;rsquo;s a good thing. Some people view a disagreement as a challenge to their knowledge or their authority; some will go so far as to call disagreement insubordination. In fact, it&amp;rsquo;s an &lt;em&gt;opportunity&lt;/em&gt;. Treating it as anything less is a waste, harming both you and your team.&lt;/p&gt;&lt;p&gt;When a decision is challenged, it presents an opportunity for a couple of different things to happen:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;You learn something. Maybe there was something that you missed, didn&amp;rsquo;t think of, or weren&amp;rsquo;t aware of. Maybe there&amp;rsquo;s more going on, maybe there&amp;rsquo;s been a breakthrough, maybe there&amp;rsquo;s a perspective to the problem that you hadn&amp;rsquo;t seen. While admitting you&amp;rsquo;re wrong can be difficult, it&amp;rsquo;s necessary to learn. Only by finding your own weaknesses can you become stronger. Only by learning about your blindspots can you learn to see more.&lt;/li&gt;&lt;li&gt;They learn something. There may be factors, perspectives, or details that they weren&amp;rsquo;t aware of. This gives you a chance to share your knowledge to make them better, more effective, stronger.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;These disagreements should always be handled with respect, by all involved, but they represent an important opening for growth. Don&amp;rsquo;t discourage disagreement, don&amp;rsquo;t become defensive, don&amp;rsquo;t guard your position – open the door to ideas, grow as a team.&lt;/p&gt;&lt;h3 id="listening-to-the-experts"&gt;Listening to the experts&lt;/h3&gt;&lt;p&gt;As a leader, it&amp;rsquo;s critical to surround yourself with smart people, and when possible, hire people smarter than you. What&amp;rsquo;s more challenging is to step back and accept that for all your knowledge and experience, they may know more than you. The ego is a powerful thing, and setting it aside isn&amp;rsquo;t always easy. Being proud of accomplishments is a good thing; letting your ego get in the way of being a good leader isn&amp;rsquo;t.&lt;/p&gt;&lt;p&gt;First, it&amp;rsquo;s important to understand the value in your team, the expertise they bring, and actively acknowledge that value. When you hire an expert, let them know that you both understand what they are bringing to the table, and how much you appreciate that expertise. When their expertise exceeds your own, this is vital. If you fail to do this, they may feel unwelcome, undervalued, unappreciated. When they share their knowledge and experience, they are helping &lt;em&gt;you&lt;/em&gt;, don&amp;rsquo;t forget that.&lt;/p&gt;&lt;p&gt;Second, understand the limits of your own knowledge. If you believe that you know more than anyone else, you are not only almost certainly wrong, but you are actively harming your team. The best managers bring smart people together, give them the tools and support they need, then stay out of the way. You must understand how your knowledge overlaps, and see where it doesn&amp;rsquo;t, so that you can leverage your team to make sure that you are operating with the best information available. We all have our limits; we all have blindspots – I know I do.&lt;/p&gt;&lt;p&gt;Third, listen. It&amp;rsquo;s that simple. Listen. When you have a team full of smart people, you are the best leader when you leverage everyone&amp;rsquo;s combined knowledge, not just your own. Get their opinions, get their thoughts, get their perspectives, and then, and only then, make decisions. Get the best information available, and then you can take informed actions.&lt;/p&gt;&lt;h4 id="leading-by-committee-versus-leading-by-knowledge"&gt;Leading by committee versus leading by knowledge&lt;/h4&gt;&lt;p&gt;I shall digress, again, to attempt to make a clear point: listening to others isn&amp;rsquo;t leading by committee; it&amp;rsquo;s leading by knowledge. The collective knowledge of a team, with the knowledge of experts and specialists in their field, is greater, more accurate, and more impactful than the knowledge of any individual. This isn&amp;rsquo;t to say that a leader shouldn&amp;rsquo;t make decisions – as a leader, that&amp;rsquo;s the responsibility. However, it&amp;rsquo;s also the responsibility of a leader to make fully informed decisions. Fully informed decisions are never made in a vacuum.&lt;/p&gt;&lt;p&gt;It&amp;rsquo;s sometimes slower, it&amp;rsquo;s sometimes more complicated, it&amp;rsquo;s sometimes harder, but it&amp;rsquo;s better.&lt;/p&gt;&lt;h3 id="giving-everyone-a-seat-at-the-table"&gt;Giving everyone a seat at the table&lt;/h3&gt;&lt;p&gt;There is no greater wasted opportunity, or greater harm to a team, than to ignore knowledgable voices. For a team to do well, every person, from the most junior to the most senior, deserves a seat at the table, a chance to be heard, to teach, or to learn. Give everyone a seat at the table.&lt;/p&gt;</description></item><item><title>Developers, Developers, Developers</title><link>https://adamcaudill.com/2020/11/28/developers-developers-developers/</link><pubDate>Sat, 28 Nov 2020 08:02:35 +0000</pubDate><guid>https://adamcaudill.com/2020/11/28/developers-developers-developers/</guid><description>&lt;p&gt;&lt;em&gt;Note: This was written in 2012, but not published at the time. The point is still valid, perhaps moreso than ever and deserves to be made publicly. The content has been updated as appropriate, though the core of this article remains intact from the 2012 draft. I would like to note that this doesn&amp;rsquo;t apply to every environment, there are some where developers are very knowledgeable about security, and write code with minimal issues – my current employer happens to be one of those rare &amp;amp; exciting places. I hope that some of these issues have improved over the last 8 years, though in many places, these issues are alive and well.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;During a server migration, an ASP.NET application was discovered&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt; that no members of the team were aware of&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt;; this mystery application was old, broken, undocumented, and a surprise to all involved. It was partially deployed, in that some key files had been removed at some point during its history which prevented it from executing properly. While not currently functional, there was no way to know when it had last worked or what it was used for – it was a surprise for all involved. As this was on a production server, I researched the application, both to understand what this application was, and if it had presented any risk to the company.&lt;/p&gt;&lt;p&gt;I found quickly that the code for the application wasn&amp;rsquo;t present in the company&amp;rsquo;s source control system – I had personally overseen the migration from an older system to the current system, and knew for a fact that everything had been imported. Not being there meant that it had never been added to source control in the first place. Thankfully for me, most of the source code files were available on the server (along with older source files for a Classic ASP version of the application); not ideal, but enough to get a decent idea of what was going on.&lt;/p&gt;&lt;p&gt;Within the first five minutes of the review, I spot a SQL command being built from strings that were pulled from user input, no validation, no sanitization. SQL injection in the most classic form. This was the first of many issues found in the hours that followed. As I worked though the code, it was clear that security wasn&amp;rsquo;t a consideration when this application was built.&lt;/p&gt;&lt;p&gt;This application was &lt;em&gt;public facing&lt;/em&gt;, and had been in production for a number of years, and nobody had noticed the glaring vulnerabilities. They even survived a rewrite from Classic ASP to ASP.NET, the vulnerabilities persisted despite rewrite and at least a couple years of maintenance. Seemingly unnoticed by attackers, thankfully.&lt;/p&gt;&lt;p&gt;While this specific application had an unusually high number of vulnerabilities for such a small application, seeing this sort of thing is nothing new. It&amp;rsquo;s not really even enough to get excited about anymore, and I wouldn&amp;rsquo;t have, if it wasn&amp;rsquo;t for something else I&amp;rsquo;ve been thinking about recently.&lt;/p&gt;&lt;h2 id="developers"&gt;Developers&lt;/h2&gt;&lt;p&gt;My heart sits in two worlds, torn between my love of creating things, and a passion for breaking things. Because of this, I tend to have a somewhat different perspective on issues from some others in either the security or development realm. I&amp;rsquo;ve built a career on combining these passions to create better software, regardless of the type of team (red or blue) I&amp;rsquo;m working with.&lt;/p&gt;&lt;p&gt;Developers are extremely good at finding solutions to problems, and at figuring out how to make things work, but too often are profoundly poor at understanding how it will be attacked in the wild. Thinking like at attacker is something that doesn&amp;rsquo;t come naturally to most – it&amp;rsquo;s a skill that takes time to develop, and unfortunately many developers are never given the chance to do that. Security education for developers has always been an issue (as &lt;a href="https://adamcaudill.com/2013/03/26/first-do-no-harm-developers-and-bad-apis/"&gt;I&amp;rsquo;ve noted before&lt;/a&gt;), too few developers are given even a basic introduction to secure development practices in college and public example code is often riddled with errors. Because of this, vulnerabilities are common and work in the various security fields is plentiful.&lt;/p&gt;&lt;p&gt;There are many methodologies and techniques for addressing security issues during the development process, yet they don&amp;rsquo;t seem to work in many environments – they are too expensive, too complex, too slow, etc. Many of the issues won&amp;rsquo;t be discovered until the security professionals get involved, including the simple issues that never should have been created. Much time has been spent, and much hot air expelled, in the quest for a solution to this problem – debating who&amp;rsquo;s at fault, and who&amp;rsquo;s responsible for fixing it. Yet, here in &lt;s&gt;2012&lt;/s&gt; 2020, SQL injection is still alive and well.&lt;/p&gt;&lt;p&gt;There was a tweet that really made me think more about this problem:&lt;/p&gt;&lt;blockquote class="twitter-tweet" lang="en"&gt; &lt;p lang="en" dir="ltr"&gt; &lt;a href="https://twitter.com/redrail1"&gt;@redrail1&lt;/a&gt; You can't keep blaming developers … yes they're PART of the problem but if they are, why haven't WE solved "them" yet? &lt;/p&gt; &lt;p&gt; &amp;mdash; Rafał Łoś (@Wh1t3Rabbit) &lt;a href="https://twitter.com/Wh1t3Rabbit/status/248910236344258562"&gt;September 20, 2012&lt;/a&gt; &lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;As both a security professional and developer, and as someone that truly loves development and the development community, I had to admit something painful: &lt;em&gt;we suck&lt;/em&gt;.&lt;/p&gt;&lt;h2 id="why-does-this-keep-happening"&gt;Why does this keep happening?!?&lt;/h2&gt;&lt;p&gt;Some of this may be cultural, in some environments the view is that security belongs to the security people, not the developers. Of course, that couldn&amp;rsquo;t be more wrong. Too often though, that&amp;rsquo;s the mentality, developers that don&amp;rsquo;t take real ownership of their security &lt;em&gt;bugs&lt;/em&gt;. There&amp;rsquo;s a testing phase in the SDLC, and that&amp;rsquo;s where too many developers believe security fits in. In reality of course, security belongs in every phase of the process.&lt;/p&gt;&lt;p&gt;Developers also tend to be ignorant of how attackers work, of the devastating impact of attacks that are so simple to perform. It&amp;rsquo;s this ignorance that I believe is the real issue, it&amp;rsquo;s not laziness or the inability to do the job right, it&amp;rsquo;s that they really don&amp;rsquo;t know better. Education continues to fail developers around the world by neglecting to provide useful information on security issues, and the methods and mentality of attackers. I&amp;rsquo;ve spoken to many developers on security issues, speaking at conferences and leading secure development training classes, what I found was consistent: most developers believe strongly in taking the time and effort to build secure systems, though they lack the knowledge and insight to do it effectively. Without an education in the darker arts of computer science, most are simply unequipped to perform their job properly.&lt;/p&gt;&lt;p&gt;As a security professional, this is were we have to admit something pailful: &lt;em&gt;we&amp;rsquo;ve failed them&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;The security community has done a fantastic job of sharing information (with &lt;a href="https://adamcaudill.com/2016/09/28/need-open-security-journal/"&gt;some caveats&lt;/a&gt;), though our efforts to present this information outside of our realm has seen more limited success. Too many developers are still unaware of the implications of their decisions, and the repercussions of seemingly minor changes. The answer to these issues isn&amp;rsquo;t to be found in expensive products, over-reliance on consultants, or magic boxes with lots of blinking lights, there&amp;rsquo;s one answer: education. While tools and frameworks are getting better, and making some mistakes harder to make, that only solves part of the problem. Without understanding more about common vulnerabilities, techniques and methods used by attackers, the attacker thought process, and tools that attackers use, these &lt;em&gt;bugs&lt;/em&gt; will continue to be introduced, and continue to be missed during changes and peer reviews.&lt;/p&gt;&lt;p&gt;If there was hope, it must lie in the developers.&lt;/p&gt;&lt;div class="footnotes" role="doc-endnotes"&gt;&lt;hr&gt;&lt;ol&gt;&lt;li id="fn:1"&gt;&lt;p&gt;The code discussed here was discovered in the fall of 2012, when this piece was originally drafted. It is safe to say that this event has long been forgotten by all involved, except as preserved here.&amp;#160;&lt;a href="#fnref:1" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li id="fn:2"&gt;&lt;p&gt;Based on the file metadata, it appears that the application had last been updated almost a decade earlier (2002-2003). This meant that not a single member of the current development team was aware of the existence of the application, who wrote it, or what it did.&amp;#160;&lt;a href="#fnref:2" class="footnote-backref" role="doc-backlink"&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;</description></item><item><title>Write Like You Are Running Out of Time</title><link>https://adamcaudill.com/2020/11/27/write-like-you-are-running-out-of-time/</link><pubDate>Sat, 28 Nov 2020 01:10:43 +0000</pubDate><guid>https://adamcaudill.com/2020/11/27/write-like-you-are-running-out-of-time/</guid><description>&lt;p&gt;The cultural phenomenon that is Hamilton, brought back to the forefront due to its streaming release, is an artistic feat, but it also serves as an opportunity to refresh our memories on the history behind these characters, and look for opportunities to learn lessons that apply today. This is exactly what I&amp;rsquo;ve been doing.&lt;/p&gt;&lt;p&gt;For all of his flaws, one thing that I have to respect about Alexander Hamilton (as well as his wife, &lt;a href="https://en.m.wikipedia.org/wiki/Elizabeth_Schuyler_Hamilton"&gt;Eliza&lt;/a&gt;) is the understanding of the long-term impact of the written word. Many things fade as the years go on, though few things will last as long, or can be so easily preserved as what you write.&lt;/p&gt;&lt;p&gt;In the play, Hamilton is referred to as someone that is writing like he was running out of time – and history does support that he was a prolific writer. This is a good (though unpleasant) reminder that in reality, we are all running out of time. We each only have a certain (and certainly unknown) amount of time left, we should all apply a certain amount of wisdom to how we use that time.&lt;/p&gt;&lt;h3 id="of-keystrokes-and-the-ultimate-deadline"&gt;Of Keystrokes and the ultimate deadline&lt;/h3&gt;&lt;blockquote&gt;&lt;p&gt;There are a finite number of keystrokes left in your hands before you die. – &lt;a href="https://www.hanselman.com/blog/do-they-deserve-the-gift-of-your-keystrokes"&gt;Scott Hanselman&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;If you dedicate much of your time to writing, you may have hundreds of millions of words left that you could write, or tens of millions, or you could, as a couple of my friends have, discover very suddenly that it’s only tens of thousands. There is a finite number of keystrokes left for each of us, and each minute, hour, day, month, year that goes by, that number inexorably drops.&lt;/p&gt;&lt;p&gt;Given that most of us don’t spend 6-8 hours a day writing, the real number of words we will actually write is far lower, and thus those words that we do produce become so much more important.&lt;/p&gt;&lt;p&gt;This is a sad thought, but one that we should acknowledge for a variety of reasons:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;No matter how much you try, there’s only so much knowledge you can communicate.&lt;/li&gt;&lt;li&gt;Every tweet, email, blog post, or document consumes some of those limited keystrokes. Is that the best use of those words, is it the best venue, the best way to make that knowledge useful to the future?&lt;/li&gt;&lt;li&gt;Is a reply worth it? Could that effort be better used?&lt;/li&gt;&lt;li&gt;When deciding what to write, is it the best, most useful thing to write about?&lt;/li&gt;&lt;li&gt;When these words are read in 1 year, 5 years, 10 years, 20 years, what will it say about you?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Few things have the potential to live as long as what you write; how you’re remembered may well be defined by the words you leave behind.&lt;/p&gt;&lt;h3 id="vast-knowledge-doomed-to-nothingness"&gt;Vast Knowledge, Doomed To Nothingness&lt;/h3&gt;&lt;p&gt;Many of us that work in technology write in huge quantities, though much is in the form of emails that will eventually be deleted or lost, in internal systems that will never be seen by the outside world, or will eventually be lost as companies close or systems are lost or retired. Too much of the knowledge that we document, and the insights that we share are seen but by a very few.&lt;/p&gt;&lt;p&gt;Most of the words that we write are doomed to be lost. In the vast quantity of knowledge that is committed to the written word every year, so much is lost, forgotten, deleted, and slips out of existence. No matter the value to the future, the insight it could provide, the aid it could provide, it’s locked away in systems that have a limited life and will eventually be gone. Every year, a vast quantity of documented knowledge slips away into nothingness.&lt;/p&gt;&lt;p&gt;Humanity generates an unimaginably vast amount of knowledge every year, yet every year the knowledge lost to humanity is also truly vast.&lt;/p&gt;&lt;h3 id="finding-relevance-over-the-years"&gt;Finding relevance over the years&lt;/h3&gt;&lt;p&gt;As technologists, many of our words have a half-life – as time goes on, their relevance diminishes. A lengthy and well thought out discussion over Slack likely has a half-life of minutes, maybe hours. A debate over technology via email with a coworker? Its half-life is hours to days. Looking at the traffic to this site, the most popular technology-specific article has a half-life of roughly 9 months – every 9 months or so, the number of hits that it gets drops by half. Every day, the carefully crafted words, the deeply thoughtful ideas become less and less valuable.&lt;/p&gt;&lt;p&gt;Some things, though, have a half-life of years; these are the things that continue to matter not just year after year, but one decade to the next.&lt;/p&gt;&lt;h4 id="venue"&gt;Venue&lt;/h4&gt;&lt;p&gt;One key to writing for long-term value is the choice of venue. Some venues work well, and others are doomed from the start – there’s no chance of it surviving or having much value in the years to come.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Twitter can be fun (when it’s not awful), but between the short format and the minuscule attention span, it’s a terrible place to write.&lt;/li&gt;&lt;li&gt;Slack &amp;amp; Discord are the same; no matter how much thought and care you put into something, it’ll disappear in the mass of other content and be lost.&lt;/li&gt;&lt;li&gt;Email, it depends – email within a company is doomed to a short half-life and doomed to be lost sooner or later.&lt;/li&gt;&lt;li&gt;Email mailing lists and the like are better, in at least there’s a chance that it’ll be preserved and could be found in the future. However, it’s so easy to be lost in the noise, and so likely that it’ll be so difficult to find that it won’t actually provide that much value.&lt;/li&gt;&lt;li&gt;Blogs can be good, but so many come and go that they aren’t seen as stable in general. Accounts get deleted, servers go down, backups are lost, domains expire, and their owners pass away. For example, this blog has been running (on this domain) for 15 years, but how long will it continue should something happen to me?&lt;/li&gt;&lt;li&gt;Academic and industry journals are useful for some content, but only a small portion of what we write during our lives fits this venue&amp;rsquo;s very specific requirements.&lt;/li&gt;&lt;li&gt;Books are certainly preserved the longest, but they also require a huge amount of work, generally quite focused, and also most technical books have a clear and limited half-life.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;These are, of course, just a few examples, there are various others, each with their own pros &amp;amp; cons. There are a variety of services that host public &amp;amp; less public content, though those may close, suffer a data loss, and may or may not be preserved for the future.&lt;/p&gt;&lt;p&gt;When writing, ask yourself which venues are available (obviously things that are work-related have a different list of options), of those, which have the best long term value, and can you use a hybrid approach, writing the content with the most long-term value in one venue and reference that from a shorter-term venue. There have been times that I have written on this blog or a corporate blog, just to support an email – making as much of the valuable content public and useful to others.&lt;/p&gt;&lt;h4 id="content"&gt;Content&lt;/h4&gt;&lt;p&gt;Writing about ideas, concepts, problems &amp;amp; their solutions have much more value as the years go on than writing about specific technologies, or even worse, specific versions of a product. While writing that has only short-term use (such as about a version of a product) can be very valuable, but the useful lifespan diminishes quickly; within a year or two, it may be entirely irrelevant. Much ink (or today, electrons) have been spilled on writing for relevance, so I&amp;rsquo;ll not belabor the point here – I&amp;rsquo;ll simply say that the words you write that offer the most value are those most focused on high-level issues and ideas, and least on technical options or solutions.&lt;/p&gt;&lt;h3 id="tomorrow-comes-ready-or-not"&gt;Tomorrow comes, ready or not&lt;/h3&gt;&lt;p&gt;It&amp;rsquo;s so easy to put off to tomorrow what could be done today, and then again, and again. Each delay means that many keystrokes have been lost, words that could have been written, now the opportunity lost and will never be written. We each have a chance to write a legacy that can be remembered for years. It&amp;rsquo;s up to us to take it.&lt;/p&gt;</description></item></channel></rss>