Most cybersecurity PoCs succeed. Thats the problem.
A test that can't fail is a sales tour.
Before install, write down: measurable outcomes, operational cost, one deliberate failure.
If success wasnt defined before the PoC started, it didn't succeed. It just ended.
Day 10 of 30
Every AI tool fails at least one of these 4 questions:
1. What can it see?
2. What can it do without a human saying yes?
3. How do I know when it's wrong?
4. What breaks when it goes down?
Day 9 of 30.
9 years evaluating security tools.
The demos that lose all die the same way:
60 minutes proving the product exists, while the buyer wonders what breaks on Tuesday morning.
Day 8 of 30.
Day 7 of 30.
Today I did nothing on purpose.
Rest isn't the opposite of the grind. It's what funds it.
Schedule it like everything else. The version of you that shows up Monday depends on it.
Day 6 of 30: I haven't manually edited a single video this challenge.
Film messy. Flub lines. Keep rolling. One AI instruction cleans it up: cut dead air, add captions. Five minutes.
Left my screwups in this one on purpose. The barrier was never talent or time. It's friction.
You can hack an AI without touching a line of code.
It's called indirect prompt injection. Number one on OWASP's Top 10 for AI apps.
Today's lesson: how it works and the 4 defenses that hold up.
The model is the new user. You never fully trust a user.
Day 5 of 30.
Day 4 of 30.
There is no life between the work right now.
Day job: security, 200+ locations.
Night job: my own company.
Third job: this video, daily.
Sleep: 6h 55m.
Not balance. A season.
Most people show you the result. I'm showing you the price.
I turned the full inspection into a free Security Tool Preflight Checklist. 15 checks, red flags word for word, and a scoring verdict.
https://t.co/EhqEYvpEDX
Most security tools would fail a helicopter preflight.
The aircraft doesn't care which part you checked. It cares about the part you didn't.
Find out the 3 questions to ask
Day 3 of 30.
I broke into cybersecurity in 2017 with no degree, right as the cloud wave hit. Everyone said security wouldn't survive it. The questions survived. The systems changed.
AI is that wave again.
Day 2 of 100: all in on AI security.
Are you translating yet, or waiting?
Day 1 of 30. Iβm done waiting until everything feels ready.
Iβm building Crestvale, moving deeper into AI security, and documenting the work publicly. That includes ideas, failures, applications, and numbers.
First action: applying for UGC opportunities. Letβs see what happens.
@orichic Or when people who you thought were annoying when you were younger, try to be friends with your little brother to finally be cool with you. As though thatβs going to change their mind. π