Pages

2026/09/19

Some Help With the Resume

I'd like to try this out. It may get you past the resume scanner, and even the psychology of a human reader as well. If you do, let me know how it works out for you.



The Best Upgrade Might Already Be Installed




 

Picture a help desk receiving the same question every week.


The answer is technically available. It lives in an old document, linked from a page whose title makes sense only if you already know the answer.


A proposal arrives for a new knowledge platform.


It might be justified. But first, someone tries a smaller experiment: rewrite the instructions, replace the broken screenshot, give the page a name users would actually search for, and ask a person unfamiliar with the process to follow it.


No launch event. No migration schedule. Just a test of whether the existing service can finally do its job.


This is the kind of work that can disappear inside the word “maintenance,” as though keeping something useful were less consequential than introducing something new.


Yet the person trying to reset a password does not experience our roadmap. They experience the next instruction.


Can they understand it? Does it match what is on their screen? Can they finish without calling someone?


There are times when old systems need replacing. Age alone does not make a system dependable, and familiarity does not excuse a security or accessibility problem.


But neither does a new purchase relieve us of the obligation to understand what is failing.


Before adding another platform, we can watch someone use the one we have. We can find out where they stop. We can correct what is within reach and see whether it helps.


That work deserves to count as progress.


Sometimes the most useful thing an IT team delivers this week is not a new capability.


It is an existing promise, finally kept.



Image by Pexels from Pixabay




2026/09/18

AI Can Write the Report. Who Needs to Read It?

 



Imagine a team using AI to turn a weekly status update into a polished report. Another team uses AI to summarize it.


Somewhere between those two accomplishments, it might be worth asking what decision the report is supposed to support.


I enjoy what these tools make possible. A rough thought can become a useful explanation. An intimidating blank page becomes something you can work with. That is real help.


But making something easier to produce does not automatically make it worth producing.


Suppose the weekly report exists because someone needed to track a problem two years ago. The problem was resolved. The report survived. Now it has better formatting, an executive summary, and a faster production cycle.


We have improved the machinery without examining the assignment.


The difficulty is that a new tool gives us something visible to demonstrate. Questioning an old requirement gives us a conversation we may have been avoiding.

Who uses this? What happens because they read it? Could the same need be met with three sentences—or a notification when something actually changes?

Sometimes the answers justify the whole report. Good. Now we know why we are doing it.

Sometimes they give someone back an hour.

For people working in technology, that is a useful distinction to carry into the next AI discussion. There is value in learning how to generate more. There is also value in knowing when more creates another obligation for somebody else.

Before we ask AI to help us keep up with the work, perhaps we should make sure the work still deserves to be kept.




Image by franganillo from Pixabay



2026/09/05

Part I: The New Loyalty - What it Looks Like 17 Years Later

The taste of betrayal. Why was I calling it quits even as things were just getting started?


2026 retrospective: I rage-quit the iPhone in 2009. Seventeen years later, I was wrong about what would disappear—but surprisingly right about what would get worse.

Reading this again feels less like revisiting an obsolete technology rant and more like an archaeological excavation of problems that never really went away. EDGE disappeared. Netbooks mostly disappeared. The original iPhone is now a museum piece. But rapid obsolescence, expensive ecosystems, constant connectivity, recurring fees, digital lock-in, and the uneasy distinction between buying something and merely retaining permission to use it are all still with us.

Apple has become considerably better at avoiding the brutal kind of technological cutoff early adopters sometimes experienced. The leap from EDGE to 3G was especially painful: suddenly a recently purchased, premium device could feel generations behind simply because the underlying wireless technology had advanced so dramatically. I still remember waiting what felt like forever just to send an email with a single photo attachment.

What I miss most from that era, strangely enough, is physical media. You bought a CD, DVD, book, or piece of software and—barring damage—it remained yours. Digital distribution brought enormous convenience, but ownership became more conditional. Accounts, DRM, subscriptions, licensing changes, compatibility requirements, and discontinued services can all stand between you and something you once thought you had purchased.

So the title still works: Why I Ditched My Apple iPhone. The reasons have changed clothes, but many of them are still hanging around.


2026/09/04

AI Briefing - Friday, Sept 4 - 2026


 

OpenAI’s latest AI model release, major legislative movement in California, new Windows developer tools from Microsoft, and notable industry updates shaped this week’s AI news. Key highlights include OpenAI’s cybersecurity‑rated GPT‑6 Astra, new state AI regulations awaiting approval, Broadcom’s surge in custom chip sales, and emerging tools like Project Zenith and Sirenfall. Additional notes cover recent vulnerability discoveries, upcoming AI events, and practical tips for managing security workflows.

Here are the takeaways:

  • OpenAI released GPT‑6 Astra, a highly capable model with significant cybersecurity implications and limited early access.
  • California passed a set of AI‑related bills covering chatbots, job‑displacement notifications, and rules ensuring human-led instruction.
  • Microsoft announced Project Zenith, a stripped‑down Windows 11 environment tailored for developers on high‑end hardware.
  • Broadcom reported a major jump in custom AI chip sales, though market response remained modest.
  • A new web experiment called Sirenfall demonstrates realistic air‑raid siren physics using Web Audio technology.
  • AI models identified over 14,000 previously unreported software vulnerabilities across open‑source projects, driving recommendations for virtual patching.
  • OpenAI Academy sessions continue, covering ChatGPT for Work and workspace best practices.
  • Key upcoming events include AI Infra Summit, Dreamforce, and OpenAI DevDay.
  • Suggested tip: use AI tools to score and prioritize vulnerabilities based on exposure rather than grinding through them sequentially.


Image by DeltaWorks from Pixabay


The Tools Are Becoming Symmetrical. The Incentives Aren’t.


 

There is an interesting paradox developing in cybersecurity.

As increasingly capable AI systems become able to inspect software, identify vulnerabilities, analyze configurations, and potentially discover flaws humans have overlooked, much of the attention naturally goes toward the offensive possibilities.

What happens when malicious hackers have access to these tools?

It is a reasonable concern.

But something else is happening at exactly the same time.

The defenders have them too.

A security team can theoretically have AI crawling its own perimeter, examining source code, reviewing dependencies, inspecting configurations, detecting anomalies, and looking for weaknesses before someone outside the organization finds them.

There is a useful word for this: simultaneity.

Both things are happening at once.

The attacker is looking for the hole.

The defender is looking for the same hole.

And increasingly, both may be using machines capable of conducting that search at extraordinary speed.

At first glance, that sounds almost reassuring. Give both sides comparable tools and perhaps they cancel each other out.

Except they don't operate under comparable conditions.

The defender still has to ask permission

Imagine a defensive AI discovers a serious vulnerability.

It reports:

This service is vulnerable. Here is the likely attack path. Here is the remediation.

Technically, that's extraordinary.

Organizationally, what happens next might sound considerably less futuristic.

Submit a change request.

Determine the system owner.

Schedule testing.

Wait for application approval.

Present the change to the review board.

Coordinate with the vendor.

Find an acceptable maintenance window.

Confirm that the fix won't interrupt another department's workflow.

Meanwhile, the attacker has a substantially shorter process:

Does it work?

That may become one of the strangest contradictions of AI-era cybersecurity.

We could possess defensive systems capable of discovering vulnerabilities at machine speed while the organizations surrounding them continue operating at committee speed.

The bottleneck isn't necessarily intelligence anymore.

It may be institutional latency.

How quickly can an organization move from:

observation → decision → authorization → remediation

without abandoning the safeguards that change management exists to provide?

That question feels much less glamorous than talking about AI discovering zero-day vulnerabilities.

It may also matter more.

Then there is the incentive problem

There is another asymmetry that technology alone doesn't solve.

Consider the incentives on each side.

A salaried information-security analyst may spend day after day monitoring systems, reviewing logs, applying patches, checking alerts, documenting vulnerabilities, and keeping infrastructure healthy.

Success often looks like this:

Nothing happened.

No breach.

No ransomware.

No outage.

No angry executives.

No emergency conference call.

That is excellent security work.

It is also psychologically quiet.

The attacker's incentives can look very different.

There may be money.

Status.

Reputation.

Competition.

Novelty.

Ideology.

Curiosity.

And sometimes simply the adrenaline rush of getting somewhere you weren't supposed to get.

Probe.

Discover.

Exploit.

Escalate.

Each successful step provides another little reward.

Then there is the financial asymmetry.

The defender goes to work and earns the dollar that buys the lottery ticket.

The attacker is playing for the jackpot.

One successful intrusion might produce access to an entire enterprise, valuable data, extortion opportunities, cryptocurrency payments, credentials, intellectual property, or an underground reputation that opens the door to the next target.

Hundreds of unsuccessful attempts may mean very little if attempt number 301 works.

That leads to an uncomfortable equation:

Defense has to be consistently good. Attack only has to be occasionally right.

We reward explosions better than we reward prevention

Organizations have another problem.

We are often much better at recognizing incident response than prevention.

When something breaks, everyone notices.

Teams assemble.

Executives join calls.

Resources suddenly appear.

People work late.

There are status reports, postmortems, recovery plans, and eventually stories about the people who helped save the organization.

Quiet prevention rarely receives that kind of attention.

Nobody normally calls an all-hands meeting after six uneventful months and announces:

Congratulations. Nothing happened.

Yet "nothing happened" may represent thousands of good decisions.

A patch installed before an exploit existed.

A suspicious login investigated.

A configuration corrected.

A credential rotated.

A firewall rule questioned.

A server retired.

A user who reported an odd email instead of clicking it.

The absence of disaster is difficult to dramatize.

That makes cybersecurity an unusual profession: some of its greatest victories are events that never occur.

AI doesn't remove the human system around the technology

This may be the larger lesson.

When powerful new technology arrives, we naturally focus on what the tool can do.

But capability does not automatically become organizational capacity.

An AI may detect a vulnerability in seconds.

That does not mean an organization can remediate it in seconds.

An AI may recommend the correct action.

That does not mean anyone has authority to perform it.

An AI may continuously patrol the perimeter.

That does not mean the people responsible for the perimeter have the autonomy, staffing, incentives, or processes necessary to act on what it finds.

The technology may eventually expose weaknesses that have very little to do with technology.

Ownership.

Bureaucracy.

Communication.

Incentives.

Decision rights.

Risk tolerance.

Trust.

The vulnerability may be sitting in the software.

But sometimes the real weakness is the organization surrounding the software.

The next arms race may be organizational

This is why I suspect the cybersecurity competition created by advanced AI will not simply be:

AI attacker versus AI defender.

It may increasingly be:

AI-speed attackers versus organizations capable of operating at AI speed.

That doesn't mean eliminating oversight or allowing automated systems to make consequential changes without controls.

It means recognizing that our operating models were often designed for a world in which humans discovered problems, humans investigated them, humans proposed solutions, and humans executed each step.

Machine-speed discovery changes one part of that equation dramatically.

The rest of the organization eventually has to adapt.

And somewhere inside that transition is perhaps the most interesting paradox of all.

The offensive and defensive technology may increasingly resemble each other.

The motivations won't.

The permissions won't.

The economics won't.

The bureaucracies certainly won't.

The tools are becoming symmetrical faster than the incentives are.



Image by geralt from Pixabay


Grace at Work

Sometimes grace arrives as the patience to explain something for the fourth time.

Sometimes it arrives in a simple "thank you" that couldn't have been faked.

But when we're the ones who make the mistake, every explanation seems to sound like an excuse.

We often extend patience to others without hesitation.

May we learn to offer ourselves that same grace when we need it most.