Unpopular opinions digital natives get right: most cybersecurity is theater, compliance certifies process not security, and the TSA fails 95% of tests.
Contents 60 sections

For Book 3: Lurk More


1. “Most Cybersecurity is Theater”

The Core Argument

The cybersecurity industry generates over $150 billion annually, yet breaches continue to increase in both frequency and severity. The disconnect between spending and outcomes is the central evidence for the “security theater” thesis.

Bruce Schneier and the Security Theater Framework

Bruce Schneier, a cryptographer and security technologist at Harvard Kennedy School, coined the popularization of “security theater” in his 2003 book Beyond Fear and expanded it in Schneier on Security (2008). His core argument: security measures that make people feel more secure without actually making them more secure are not just wasteful — they are actively harmful because they divert resources from measures that work.

In 2015, the Department of Homeland Security’s Inspector General reported that TSA screeners failed to detect weapons and explosives in 95% of covert tests (67 out of 70 attempts) (ABC News). The TSA’s response was not to fundamentally rethink the approach but to add more visible procedures.

The Compliance-Industrial Complex

PCI-DSS: Target was PCI-DSS compliant when breached in 2013 (40 million credit cards, 70 million customer records) (CNN Money). Heartland Payment Systems was PCI-DSS compliant when breached in 2008 (130 million card numbers). Compliance certifies process, not security.

SOC 2: SolarWinds had SOC 2 certification when its Orion software was compromised (discovered December 2020), affecting approximately 18,000 organizations including multiple US government agencies (Krebs on Security).

Equifax (2017): Exposed 147 million Americans’ SSNs. The breach exploited a known Apache Struts vulnerability (CVE-2017-5638) that had a patch available for two months. An expired SSL certificate on an internal security tool meant the breach went undetected for 76 days (House Oversight Committee report).

Password Policies That Make Security Worse

In 2017, NIST SP 800-63B reversed decades of password guidance:

  • Dropped forced rotation (users just increment a number)
  • Dropped complexity requirements (produces “P@ssw0rd!” not randomness)
  • Recommended length over complexity (“correct horse battery staple” > “Tr0ub4dor&3”)

Bill Burr, the NIST manager who wrote the original 2003 guidelines, publicly said in a 2017 WSJ interview: “Much of what I did I now regret.” (Engadget)

Most corporate environments in 2026 still enforce the old, counterproductive policies because their compliance frameworks haven’t updated.

Penetration Testing as Performance Art

Haroon Meer (Thinkst/Canary tokens): most pen tests are scoped so narrowly they test the client’s ability to hire a pen tester, not actual security. Social engineering excluded. Physical security excluded. Fixed period (1-2 weeks) unlike real attackers with unlimited time.

The Insider Threat Problem

2020 Verizon DBIR: 30% of breaches involved internal actors (Verizon DBIR). Insider threat programs consistently receive less funding than perimeter security. Snowden, Manning, and Reality Winner all exploited authorized access — no technical control detected them.

Named Sources

  • Bruce SchneierBeyond Fear (2003), Harvard Kennedy School
  • Haroon Meer — Thinkst Canary, Black Hat/DEF CON talks
  • Lorrie Cranor — Carnegie Mellon, password research
  • Dan Geer — “Cybersecurity as Realpolitik,” Black Hat 2014
  • Wendy Nather — coined “the security poverty line”
  • Bill Burr — NIST SP 800-63 original author, WSJ regret interview (August 2017)

2. “Most Tech Journalism is Wrong About Technical Subjects”

The AI Coverage Problem

LaMDA/Blake Lemoine (June 2022): Google engineer claimed LaMDA was sentient. Washington Post ran it prominently (Washington Post). Bender, Gebru et al. had already explained in “Stochastic Parrots” (2021) why LLMs produce human-seeming text without sentience. Paper was available, cited, and largely ignored by mainstream coverage.

Encryption Backdoor Coverage

“Keys Under Doormats” (2015) by Abelson, Anderson, Bellovin, Diffie, Schneier et al. (MIT CSAIL): no known way to build a backdoor accessible only to authorized parties. Near-consensus among cryptographers. Yet mainstream outlets routinely cover the “encryption debate” as though both sides have technically equivalent positions.

The “Hack” Conflation

Media routinely conflates: hack (exploitation of vulnerability), data breach (unauthorized data access), vulnerability (exploitable flaw), and leak (insider release). The distinction matters for understanding — and fixing — the problem.

Outlets That Get It Right

  • Ars Technica — technically literate reporters (Dan Goodin, Timothy Lee)
  • The Register — British, technically informed, irreverent
  • Krebs on Security — Brian Krebs, former WaPo, broke Target/OPM breaches
  • John Gruber / Daring Fireball — identifies specific factual errors in mainstream reporting
  • Wired (sometimes) — Kim Zetter (Countdown to Zero Day), Andy Greenberg (Sandworm)

The Structural Problem

Charlie Warzel: tech desks at major outlets are staffed by generalists covering “technology” as a beat — like covering “science” as a single beat. Publications with largest reach have least expertise; publications with most expertise have least reach.

The “Tech Bro” Narrative

Casey Newton (Platformer) and danah boyd: the “tech bro” label collapses a diverse industry into a single archetype, making structural criticism harder because it substitutes stereotype for analysis.


3. “Content Moderation at Scale is Impossible”

The Impossibility Theorem

Tarleton Gillespie (Custodians of the Internet, 2018): Content moderation requires contextual judgment. The same image (e.g., Pulitzer-winning “Napalm Girl”) can be newsworthy photography, CSAM, anti-war speech, or gratuitous violence — depending on context.

The Scale Numbers

Facebook/Meta employed ~15,000 content moderators reviewing ~3 million reports/day. Their own internal research (leaked by Frances Haugen, 2021): caught only 3-5% of hate speech. In Myanmar genocide (2017-2018): Facebook had four Burmese-speaking moderators for 53 million people.

The Human Cost

Casey Newton’s “The Trauma Floor” (The Verge, 2019): Cognizant moderators in Phoenix earned $28,800/year, got 9 minutes of “wellness time” daily, developed PTSD and conspiracy beliefs (The Verge). Keith Utley died of a heart attack at his desk. Cognizant exited the business.

The Tumblr NSFW Ban (December 2018)

Automated detection misidentified Renaissance paintings, sand dunes, Sesame Street characters. Page views dropped from 521M to 370M in two months (29% decline) (The Guardian via Slashdot). Automattic acquired Tumblr in 2019 for ~$3M (Axios) (Yahoo paid $1.1B in 2013 (CNBC)).

The “Just Use AI” Fallacy

YouTube Content ID ($100M+ invested, still produces false positives). Facebook AI catches nudity but struggles with satire/irony/cultural context. The adversarial problem: users adapt (“unalive” for kill on TikTok).

Named Sources

  • Tarleton GillespieCustodians of the Internet (2018), Microsoft Research / Cornell
  • Sarah T. RobertsBehind the Screen (2019), UCLA
  • Jeff KosseffThe Twenty-Six Words That Created the Internet (2019)
  • Daphne Keller — Stanford Cyber Policy Center
  • Casey Newton — “The Trauma Floor” (2019), Platformer

4. “The Old Internet Was Better — And Not Because of Nostalgia”

The Structural Argument

The key shift: from pull-based (users navigate to destinations) to push-based (algorithms select what users see). Not a subjective preference — a measurable change in information architecture.

Forums vs. Feeds

Forums had: persistent identity within communities, topic-based organization, moderation by community members, no algorithmic amplification. Ethan Zuckerman (UMass Amherst): algorithmic optimization selects for “arousal” — anger and outrage — because arousal drives engagement.

Cory Doctorow’s “Enshittification” (2023)

The lifecycle: (1) platforms are good to users to attract them, (2) abuse users to benefit business customers, (3) abuse business customers to extract maximum platform value, (4) platform dies. Caused not by bad management but by removal of competitive discipline through monopoly power.

RSS: The Road Not Taken

Google killed Google Reader on July 1, 2013 (TechCrunch). Former PM Brian Shih: Google systematically neglected it because RSS decentralized content discovery, reducing dependence on Google Search and advertising. RSS represented user-controlled information subscription. Its death was deliberate.

The Death of the Personal Website

Hossein Derakhshan (“Hoder”), imprisoned in Iran 2008-2014, emerged to find the web of links and blogs replaced by streams and feeds. His 2015 essay “The Web We Have to Save”: links — the fundamental unit of web architecture — had been devalued in favor of content embedded within platforms.

What Was Genuinely Lost

  • Serendipitous discovery (web rings, blogrolls, StumbleUpon)
  • Deep discussion (forum threads with hundreds of substantive posts)
  • Distributed authority (no single entity could remove your website)
  • Slower, more deliberate communication

What Is Nostalgia (Honest Assessment)

  • The old internet required more technical skill, was less diverse/accessible
  • Forums had serious harassment problems too
  • The “good old internet” was disproportionately white, male, English-speaking, affluent

Named Sources

  • Cory Doctorow — “Enshittification” (2023), DEF CON keynote
  • Hossein Derakhshan — “The Web We Have to Save” (2015)
  • Anil Dash — “The Web We Lost” (2012)
  • Tim WuThe Attention Merchants (2016)
  • Eli PariserThe Filter Bubble (2011)

5. “Cryptocurrency Was Always Going to Attract Scammers”

The Architectural Argument

A system designed to operate without trust attracts participants who cannot be trusted. Features: irreversible transactions, pseudonymity, no chargebacks, code-is-law ideology.

The ICO Epidemic (2017-2018)

$11.4B raised in H1 2018 alone. Satis Group (2018): 81% of ICOs were scams (Bleeping Computer). BitConnect ($2.6B market cap, Ponzi scheme). OneCoin ($4B raised, no blockchain at all, founder Ruja Ignatova on FBI Most Wanted) (CNBC).

FTX/SBF (November 2022)

$8B in customer deposits diverted to Alameda Research via secret backdoor. SBF convicted November 2023, seven counts (TIME). He was the industry’s most prominent advocate for regulation while committing fraud.

Terra/Luna (May 2022)

$40B destroyed in one week. Do Kwon knew the stabilization mechanism was failing, secretly arranged third-party propping while claiming the algorithm worked autonomously. Pled guilty January 2026 (American Banker).

NFTs

Peaked January 2022 ($4.9B monthly volume on OpenSea). dappGambl (September 2023): 95% of NFT collections had zero market value (The Register).

The Serious Technology Underneath

Blockchain as append-only ledger has genuine applications. Smart contracts enable programmable agreements. Cryptographic proof systems are mathematically sound. The technology’s design choices — decentralization, irreversibility, pseudonymity — create an environment where fraud is easier and harder to remedy.

Named Sources

  • Nicholas Weaver — UC Berkeley ICSI (died 2024)
  • Molly White — web3isgoinggreat.com
  • David GerardAttack of the 50 Foot Blockchain (2017)
  • Matt Levine — Bloomberg “Money Stuff”
  • Zeke FauxNumber Go Up (2023)

6. “AI Safety Discourse Repeats Every Technology Panic”

The Historical Pattern

  • Printing press (1440s): Trithemius wrote In Praise of Scribes (1492) against it. Church created Index Librorum Prohibitorum (1559).
  • Radio (1920s): Payne Fund Studies investigated youth corruption.
  • Television (1950s): Marie Winn’s The Plug-In Drug (1977).
  • Video games: Brown v. Entertainment Merchants Association (2011) — Supreme Court found no persuasive evidence linking games to violence (Cornell Law / Supreme Court).

Where AI Concerns Are Genuinely New

  • Deepfakes (convincing fake video of specific individuals)
  • Automated disinformation at scale
  • Labor displacement speed potentially outpacing adaptation
  • Concentration of power (training frontier models requires billions)

The Yudkowsky/Rationalist Community

Disproportionate influence on discourse relative to ML research standing. EA-to-AI-safety pipeline created a funding ecosystem (Open Philanthropy → Anthropic) that shaped discourse. Yann LeCun (Meta, Turing Award) publicly argues current systems are nowhere near general intelligence.

The Present-Harms Critique

Emily Bender and Timnit Gebru: focus on hypothetical superintelligence distracts from documented present harms — biased hiring algorithms, discriminatory criminal justice algorithms (COMPAS/ProPublica 2016), facial recognition failures (Buolamwini’s “Gender Shades” 2018).

Named Sources

  • Daron Acemoglu & Simon JohnsonPower and Progress (2023)
  • Emily Bender — “Stochastic Parrots” co-author
  • Joy BuolamwiniUnmasking AI (2023)
  • Arvind NarayananAI Snake Oil (2024)

7. “The ‘Learn to Code’ Movement Misunderstands What Coding Is”

Code as Literacy vs. Trade Skill

Jeff Atwood (Stack Overflow co-founder), “Please Don’t Learn to Code” (2012): coding is a specific trade skill, not a general-purpose capability (Coding Horror). The analogy would be “everyone should learn electrical engineering” because everyone uses electricity.

The Bootcamp Bubble

Dev Bootcamp closed 2017. The Iron Yard closed 2017 (EdSurge). CIRR data: graduation rates 50-95%, job placement rates 49-88%.

Writing Code vs. Engineering Software

Writing code is learnable in weeks. Engineering software (maintainable, scalable, secure systems) requires years of understanding: algorithms, failure modes, architecture, testing, debugging, communication. Fred Brooks, The Mythical Man-Month (1975): irreducible complexity.

The AI Coding Disruption

GitHub Copilot and successors: the specific skill bootcamps teach (translating logic into syntax) is the skill most amenable to AI automation. Valuable skills — system design, debugging, architecture — cannot be taught in 12 weeks.


8. “Privacy Is Already Dead — The Question Is Who Benefits”

Dan Geer’s Framework

“Privacy is the ability to misrepresent yourself.” Not cynical — structural. Privacy means contextually managing your identity. Helen Nissenbaum formalized this as “contextual integrity” (Privacy in Context, 2009).

The Data Broker Economy

Acxiom (now Liveramp): data on ~2.5 billion people, up to 10,000 attributes per person (Harvard Business School Digital Initiative). Facebook creates “shadow profiles” of non-users from contact lists and browsing behavior.

GDPR: Mixed Results

Worked: Legal framework with real penalties (Amazon €746M, Meta €1.2B). Didn’t: Cookie consent banners (most click “accept all”), enforcement inconsistency (Irish DPC), small business burden, regulatory arbitrage.

The “Nothing to Hide” Refutation

Daniel Solove, “‘I’ve Got Nothing to Hide’ and Other Misunderstandings of Privacy” (2007): assumes privacy is only about concealing wrongdoing, ignores autonomy/dignity/social boundaries, ignores power asymmetry.

Who Benefits From Privacy Discourse

Apple markets privacy while taking $15-20B annually from Google (surveillance-based advertising) to be Safari’s default search engine (Bloomberg). Google’s Privacy Sandbox replaces third-party cookies with Google’s own tracking. Facebook used GDPR compliance as a competitive moat.

Named Sources

  • Dan Geer — In-Q-Tel CISO, Black Hat 2014
  • Daniel SoloveNothing to Hide (2011)
  • Shoshana ZuboffThe Age of Surveillance Capitalism (2019)
  • Helen NissenbaumPrivacy in Context (2009)

Cross-Cutting Themes

  1. Appearance vs. reality: Security theater, journalism theater, privacy theater, content moderation theater
  2. Incentive misalignment: Compliance incentivizes checkboxes, not security. Ad-supported journalism incentivizes clicks, not accuracy. Engagement-optimized platforms incentivize outrage, not community.
  3. The expertise gap: People closest to the problem hold systematically different views from the public and policymakers. “Lurk More” = spend time in the community before opining.
  4. Historical pattern recognition: Many “new” problems are old problems in new contexts.
  5. Structural vs. individual analysis: The informed perspective focuses on structures (incentives, architectures, market dynamics), not individuals (bad actors, visionary founders).

Source URLs