Lea Kissner
banner
leak.bsky.social
Lea Kissner
@leak.bsky.social
Security, privacy, respect. Was the Twitter CISO until it was terrible. Now LinkedIn CISO. they/them
I know perfectly well there are bilingual people at Google, so what were they thinking by having YouTube automatically translate videos with no way to turn it off? Thank goodness they haven't managed to translate every language yet, so I can coherently watch at least some non-English videos
January 4, 2026 at 4:00 PM
This is one of the nightmares of modern security. We need to know where every single one of those is, what we're trusting it to do and not do, and how to make it stop *immediately*.

And every time someone wants to use a new one we need to figure out whether we can trust it as far as we can throw it
I worked at a 4,000-person event tech company for about five years. At one of the annual team all-hands, our CEO shared a PowerPoint slide that contained every SaaS vendor logo that enabled our daily work.

Uncountable. Hundreds. Names you’ve never seen. A universe of invisible workers.
You have no idea how many Software as a Service products are out there that you don’t think about but would basically shut down wherever you work if they stopped working
January 1, 2026 at 6:35 PM
Bluesky buddies, I now have a 3D printer in my house, a relatively simple design little counter design I've had sketched out for several years, and a complete inability to 3D model.

Does anyone know someone who could work with me to get this together? Happy to pay the going rate, whatever that is.
December 26, 2025 at 6:05 PM
Prop 13 has had some wild effects on schools in California. Even back when I was in high school in Palo Alto, which is the well-off and education-focused town where Stanford is, they made the chemistry classes enter competitions so people would send us lab equipment.
I love this quote from Time Magazine published on June 19, 1978 after Prop 13 passed

“Ignoring warnings that schools may not be able to educate, libraries may close and crime rates may climb, the voters”

It’s funny how long timers love to at how things were better 40-50 years ago… because it was!
December 21, 2025 at 3:26 PM
Reposted by Lea Kissner
As a security person, I SO appreciate great bits like this open letter around bad security advice ( www.hacklore.org/letter), especially given that it's got reputable people like @leak.bsky.social signed on.

I agree that outdated advice and half-truths are just as bad as giving wrong advice.
The Letter — Stop Hacklore!
www.hacklore.org
December 5, 2025 at 3:52 PM
I considered adding a picture of my study but the piles of books are sprouting piles of books.

And I just ordered some more books.
Twitter accounts are based in Russia. BlueSky accounts are based in homes with, frankly, too many books, plants, obsolete cables, and pieces of rustic pottery, that could do with a bit of a tidying up, to be honest.
November 25, 2025 at 6:35 AM
The comment thread here is the embodiment of :lolsob:

There is legitimate promise to LLM-assisted coding, but there are also legitimate risks. Like this. And no one here is malicious!
One of the many joys of using AI for programming is the creation of huge PRs on complex topics that the authors barely understand, but still suggest "because they work". Here's a great example from #OCaml github.com/ocaml/ocaml/...

Kudos to OCaml's maintainers for handling this so gracefully.
DWARF support for macOS and Linux by joelreymont · Pull Request #14369 · ocaml/ocaml
DWARF v5 Debugging Support for OCaml Native Compiler This PR adds DWARF v5 debug information to the OCaml native compiler, allowing proper source-level debugging in GDB and LLDB. What's Impleme...
github.com
November 24, 2025 at 9:25 PM
Reposted by Lea Kissner
now everyone together quote @leak.bsky.social
November 22, 2025 at 3:38 AM
The "Gear" series on the Articles of Interest podcast has convinced me that if for some reason I was in the armed forces (and I wasn't doing the obvious things for me to do) I would want to be in the quartermaster corps. The complexity in clothing alone 🤯

www.articlesofinterest.co/podcast
EPISODES | Articles Of Interest
www.articlesofinterest.co
November 21, 2025 at 2:40 AM
If my emails ever get leaked, just know that I'm not sub-literate, I'm lazy.
November 13, 2025 at 3:43 AM
A performance plan (PIP) is incredibly hard on everyone involved. The person going through it, the manager, and *the entire team*.

When I'm running one, I deeply want to help the person going through it find whatever's missing so that they do an awesome job and we can keep working together.
1/🧵
November 10, 2025 at 7:25 PM
Up until a few weeks ago, the conversation virtually always went like this:

Them: "why are you wearing a mask?"
Me: "because I don't want to accidentally kill my mom. Plus I hear COVID is no fun."
Them: *vivid story of how terrible COVID is*

It sounds less fun than wearing a mask, y'all 🤷
Sometimes when people ask me why I’m wearing a mask I say I’m traveling or have some important thing soon and can’t afford to get sick and miss it and that’s pretty much always true but I think it would be nice if it were more normalized to just say “I don’t want to get sick” and leave it at that
November 9, 2025 at 4:53 PM
New life goal unlocked
November 9, 2025 at 4:40 PM
I hired a director recently and this was my screening question: can you please explain the difference between public-key and symmetric-key cryptography.

Virtually all the candidates, who universally claimed security engineering expertise of some kind (some cryptography-related) could not. At all.
November 7, 2025 at 4:57 PM
"Betteridge's law of headlines is an adage that states: "Any headline that ends in a question mark can be answered by the word no.""

en.wikipedia.org/wiki/Betteri...
November 6, 2025 at 5:30 PM
"Worked for" is an exaggeration here -- while there may be actual staff in this group, these scan centers are mostly operated by victims of human trafficking.

This is one of the many reasons we need stronger online security across the board: to break the incentives behind this horror.
India is repatriating on Thursday the first batch of hundreds of its nationals who last month fled to Thailand from Myanmar, where most had been working at a notorious center for online scams.
Indians who fled a Myanmar cyberscam center are being flown home from Thailand
India is repatriating the first batch of hundreds of its nationals who last month fled to Thailand from Myanmar, where most had been working at a notorious center for online scams.
bit.ly
November 6, 2025 at 1:33 PM
Would you like to work on LinkedIn? InfoSec is hiring! We have both manager and IC roles -- and more coming.

I'm here because I want to help protect people and not work with jerks. If that's what you like, then I hope you'll join us.

Jobs in 🧵
November 5, 2025 at 11:27 PM
Encryption without key rotation is just sparkling obfuscation
October 23, 2025 at 7:11 PM
Not being a jerk is a shockingly underrated hiring strategy.
look, one reason workplaces started making us all go to HR's "be polite to others" class is because you alienate people when you're a bigoted asshole, and that can lose you both talent and business www.ft.com/content/8e6d...
Sequoia COO quit over Shaun Maguire’s comments about Islamism
Sumaiya Balbale left the venture firm after it decided not to discipline outspoken investor for posts about Zohran Mamdani
www.ft.com
October 22, 2025 at 1:11 PM
Reposted by Lea Kissner
pleasures of the flesh fade, other people however much you love each other will sometimes let you down, the world is filled with sorrows. but from today until the last day of your life, wherever you are if you pay attention there is something new to learn. it's a great comfort.
October 13, 2025 at 6:30 PM
The number of people who don't seem to realize that people in the same field, even in the same team, talk to each other is astonishing.

A security vendor invited me to a dinner with featured guest the "VP of IAM at LinkedIn". There is no such person. I'm so curious who; the vendor wouldn't answer.
This morning's spam from a scammer claiming to be Andy Weir, asking me to send a link to my own work and maybe he'll check it out (aka the opening salvo to sending the scammer money) and I'm all, look pal, I know Andy's read my stuff already, he said so WHEN WE WERE DOING A FUCKING EVENT TOGETHER
September 22, 2025 at 1:36 PM
TIL that setting LESSSECURE makes you more secure
September 15, 2025 at 9:24 PM
Fully most of what I travel with for any trip is food, which I am not willing to risk the airline losing, but speaking as someone who packs light to the point where I did a 4-day trip with only a briefcase (pre-having-to-carry-all-of-my-food situation), this is the hard way to travel light!
Personally, I'd rather just check a large bag for a long trip, than have to deal with randomly shipping stuff home and buying entirely new things at unpredictable intervals

(speaking as someone who spends a lot of time traveling internationally for extended periods myself)
September 8, 2025 at 4:03 PM
At one job someone decided to argue with me about whether my pronouns are grammatical.
a) yes they are I have citations
b) what an extremely odd fight to pick at work

In summary, there are so many ways not to be a jerk and not being a jerk is one of my life goals
roses are red
violets are blue
singular they
predates singular you
Another day, another whiner complaining that I use the singular "they" in my work, and of course they can go fuck themselves

(you see what I did there)

(also, gift link)

wapo.st/3JEdPUv
September 3, 2025 at 10:34 PM
Vibe coding is a lot easier if you don't care about breaking things
#ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly, which it then executes 1/7
August 26, 2025 at 11:50 PM