Categories
Picdump

Saturday picdump for Saturday, October 3

Happy Saturday, everyone! Here on Global Nerdy, Saturday means that it’s time for another “picdump” — the weekly assortment of amusing or interesting pictures, comics, and memes I found over the past week. Share and enjoy!




833185410_1997237607629187_844700334112969509_n

825353160_1105784312407001_6603282812836984020_n

790626361_122183219510922814_817025324763958250_n

830754617_1619775169739372_3689585515847424804_n

825268282_1820329809125550_2168064261760964982_n

1790602698460

828831768_10162653546286114_3233663811465673943_n

829648438_1091134366640796_2133014560788286084_n

831313237_1800225061312288_6706389912819529725_n

825271268_10237574668480905_5051879753282920515_n

1790602189305

802f72d749ea7379-1

828525226_18637975513031267_2959244851529844248_n

IMG_3653

825274102_10239323786925801_6696127705436025165_n

826395569_28290299070661967_3384109608266425462_n

825293015_1138204265535560_8917809646396028441_n

52be56bfeef1d15c

825340823_1612300950336698_121566736849194268_n

828121598_29562987713289950_1063985721105520336_n

af36aff1d991e56b

IMG_3676

828598235_122352233942236772_3720081285654693954_n

724824405_27160812536915325_6789026503998681427_n

1790468146409

IMG_3669

825329599_28789447100691945_4301635849012725533_n

827484405_3562868997212620_5121518993470781912_n

eaipyiaosish1

830219044_10163893943053318_5181037286090873653_n

hr-job

828280824_2307863916638792_371382727602069593_n

i-dont-get-it-v0-66zqiazs8bsh1

830212387_4573077966348182_2365471511711063446_n

791419352_10162691869095836_1149149065566359066_n

816087455_17946813633345627_8568518195429596777_n-1

825336951_10245793400674316_6943483556310154663_n

825292822_10236211914092375_5358908964710347089_n

1790731774217

825350967_10175341803330253_8433576268650667404_n

president-trump-meets-with-ai-executives-at-the-white-house-v0-hasmsw291jsh1

833494193_10239747476856809_5853588473883365802_n

833276513_1926974134941572_8803301808890462840_n

lizzie-borden

825614900_4568507026805276_2918528961071489884_n

qaddh26we3th1

827282045_10162470276691619_3637312872394030912_n

832736521_1406620201596960_7710899457724862949_n

829576296_122145276393348315_1790858944550807989_n

795015363_1377581617417923_3367414714176935811_n

825267731_10175347780485253_471868121750680159_n

825266938_10168164932269447_6402991209975561005_n

830324959_1873519994014700_2408359317195822807_n

c2qydh6yzmsh1

829196477_2273450263507145_8211345287984214986_n

IMG_3717

IMG_3691

828471257_28306350882340531_9126293007716343667_n

829196631_10239983750064344_6380005325793939780_n

825274271_10239598358529907_8531939746790452466_n

795629296_10163143095241674_3957286787487984760_n

825279671_10240632110854467_823232006939952534_n

ai-so-easy-to-spot

445eb39aeda050c1

pdl5qr8ieqsh1

825280356_4569367006719278_1342979510463590913_n-1

yxunpm7pfrrh1

1790605883315

830573564_1087596987581285_7996528999860371721_n

830181128_1774824693776845_5468570312794874660_n

829323046_2209006417158727_1393148019658761326_n

Screenshot
Screenshot

831506734_10104073415190155_5918106384641385807_n

825329515_1810325600320101_6706173715301115589_n

825271373_10175425850515304_3249899851705046771_n


Screenshot


Screenshot

Screenshot









Screenshot


Categories
Current Events Meetups Tampa Bay

Tampa Bay tech, entrepreneur, and nerd events list (Monday, October 5 – Sunday, October 11)

Here’s what’s happening in the thriving tech scene in Tampa Bay and surrounding areas for the week of Monday, October 5 through Sunday, October 11!

This list includes both in-person and online events. Note that each item in the list includes:

✅ When the event will take place

✅ What the event is

✅ Where the event will take place

✅ Who is holding the event

This week’s events

Monday, October 5

Event name and location Group Time
Venice Area Toastmasters Club #5486
Online event
Toastmasters District 48 7:30 AM to 9:00 AM EDT
Speakeasy Toastmasters #4698
Online event
Toastmasters District 48 6:00 PM to 8:00 PM EDT
ACE Advanced Toastmasters 3274480
Online event
Toastmasters Divisions C & D 6:00 PM to 7:30 PM EDT
Sarasota Blood on the Clocktower
Clocktower meetup
Board Games and Card Games in Sarasota & Bradenton 6:00 PM to 10:00 PM EDT
Games at Barriehaus Trinity
Barriehaus Beer Company, Trinity
Advance 3 Spaces Neurodivergent Social Gaming 6:00 PM to 8:00 PM EDT
MTG: Commander Night
Critical Hit Games
Critical Hit Games 6:00 PM to 11:00 PM EDT
Toast of Lakewood Ranch Toastmasters Club
Lakewood Ranch Town Hall
Toastmasters District 48 6:30 PM to 7:30 PM EDT
North Port Toastmasters Meets Online!!
Online event
Toastmasters District 48 6:30 PM to 8:00 PM EDT
Clearwater Streamline Coding with Claude AI
1811 N Fort Harrison Ave
Building Better Software With Claude Code 6:50 PM to 7:50 PM EDT
Euchre – Voodoo Brewery
Voodoo Brewery
Euchre- At Voodoo Brewery 6:50 PM to 9:15 PM EDT
Lakeland (FL) Toastmasters Club #2262
GFWC United Women’s Club of Lakeland
Toastmasters Division E 7:00 PM to 8:30 PM EDT
Let’s Talk Toastmasters
Online event
Toastmasters Divisions C & D 7:00 PM to 8:30 PM EDT
Hidden Gems Night, Presented by A Duck!
Online event
Nerdbrew Events 7:00 PM to 10:00 PM EDT
Playing Nintendo Games (Nintendo Switch and Switch 2)
Online event
Nintendo Meetup Central Florida 7:00 PM to 9:00 PM EDT
Are We Wasting Our Lives? Seneca and the Art of Using Time Wisely
Online event
Philosophy for Everyday Life – Talks and Classes in Florida 7:00 PM to 8:00 PM EDT
DigiMondays
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:30 PM to 9:30 PM EDT
Weekly General Meetup
Online event
Beginning Web Development 8:00 PM to 9:00 PM EDT
Where is Bitcoin Going?
Online event
Bitcoiners of Southwest Florida 9:00 PM to 10:00 PM EDT
Return to the top of the list

Tuesday, October 6

Event name and location Group Time
Clearwater Level Up With Claude Code
X428+VH Clearwater
Building Better Software With Claude Code 1:23 AM to 2:23 AM EDT
v-Lean Coffee
Online event
Tampa Bay Agile 7:30 AM to 8:30 AM EDT
CEO Toastmasters
Online event
Toastmasters Divisions C & D 8:00 AM to 9:00 AM EDT
Bounce Back From A Layoff
Online event
Tech Success Network 10:00 AM to 11:00 AM EDT
Disney Lorcana Night
Critical Hit Games
Critical Hit Games 6:00 PM to 11:00 PM EDT
Hobby Night
Critical Hit Games
Critical Hit Games 6:00 PM to 11:00 PM EDT
Loner Seekers Euchre – Tampa
Shamrocks Ale House
Loner Seekers Euchre – Tampa 6:30 PM to 9:30 PM EDT
D&D @ Critical Hit Games (Full)
Critical Hit Games
RPG-Pinellas 6:30 PM to 11:00 PM EDT
Find Your Voice: Dunedin Toastmasters
Unity Community Church
Dunedin Toastmasters 2166 7:00 PM to 8:30 PM EDT
Winter Springs Toastmasters Club
Online event
Toastmasters Divisions C & D 7:00 PM to 8:15 PM EDT
St. Pete Beers ‘n Board Games Meetup for Young Adults
3 Daughters Brewing
St. Pete Beers ‘n Board Games for Young Adults 7:00 PM to 10:00 PM EDT
Boards & Bones Table Top RPGs
Gambit Games
Nerdbrew Events 7:00 PM to 10:00 PM EDT
Yu-Gi-Oh Evening Tournament
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:00 PM to 11:00 PM EDT
Badass Babes – Weekly Movie Night
Online event
Nerdbrew Events 7:30 PM to 9:30 PM EDT
Trading Tuesday
Online event
Bitcoiners of Southwest Florida 8:00 PM to 9:00 PM EDT
Return to the top of the list

Wednesday, October 7

Event name and location Group Time
World Toasters Toastmasters Club
Online event
Toastmasters Division E 7:05 AM to 8:00 AM EDT
Tampa Highrisers Toastmasters
Hyde Park United Methodist Church
Toastmasters District 48 7:45 AM to 8:45 AM EDT
Computer Repair Clinic
2079 Range Rd
Tampa Bay Technology Center 8:30 AM to 12:30 PM EDT
Productivity Wednesday
300 E State Street
Kazba Cafe – Oldsmar FL 10:00 AM to 3:00 PM EDT
Launch a Brand People Remember: Name, Story and Voice with Claude [ONLINE]
Online event
The AI Launchpad 2:00 PM to 3:00 PM EDT
Clearwater Building Faster with Claude Code
X4V9+XX Clearwater
Building Better Software With Claude Code 3:51 PM to 4:51 PM EDT
Wednesday Night Gaming
Nerdy Needs
Brandon Boardgamers 5:00 PM to 10:00 PM EDT
40k Escalation League
Battlebrush Games
Battlebrush Games: Paint Minis & Play Warhammer/Warmachine 5:00 PM to 9:00 PM EDT
CNC Wednesday’s
MakerSpace St. Petersburg
Makerspaces Pinellas Meetup Group 5:30 PM to 7:30 PM EDT
Building Agentic AI Assistants with Graphs Retrieval Augmented Generation
Entrepreneur Collaborative Center
Tampa Bay Biotech 5:30 PM to 7:30 PM EDT
Wednesday Board Game Night
Bridge Center
Tampa Gaming Guild 5:30 PM to 11:00 PM EDT
Orlando Chess Association
West Osceola Library
Greater Orlando Chess 5:30 PM to 8:30 PM EDT
Tech meetup @Yuengling Draft Haus
Yuengling Draft Haus & Kitchen 11109 N 30th St · Tampa, FL
Tampa Bay New-In-Tech 6:00 PM to 8:00 PM EDT
Board game night at CHG!
Critical Hit Games
Saint Pete Boardgamers 6:00 PM to 11:00 PM EDT
Casual Commander Wednesdays
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 6:00 PM to 11:00 PM EDT
Social Happy Hour
Ed’s Tavern
Bradenton Woman’s Book Club 6:00 PM to 8:00 PM EDT
Blockchain & Crypto Investors & Enthusiasts – International Blockchain Group
Grand Central Brewhouse
Blockchain and Crypto Investors and Enthusiasts 6:30 PM to 8:30 PM EDT
Together Women Rise Book Circle: Bring a Book, Bring an Idea
Together Women Rise: Sarasota Book Circle 6:30 PM to 8:30 PM EDT
Magic Pioneer Event
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 6:45 PM
Sun Coast Euchre Club
The Hanger Restaurant & Flight Lounge
Suncoast Euchre Club -St Pete 6:50 PM to 8:50 PM EDT
Carrollwood Toastmasters Meetings meet In-Person and Online
Jimmie B. Keel Regional Library
Toastmasters District 48 7:00 PM to 8:30 PM EDT
Games & Grog! Board game night @ Peabodies
Peabodies
Nerdbrew Events 7:00 PM to 11:00 PM EDT
St Pete Wednesday Game Night
Right Around The Corner
St Pete Game Night 7:00 PM to 9:00 PM EDT
Board Games at M+M
M+M videogames
Tampa 20’s and 30’s Social Crew 7:00 PM to 9:00 PM EDT
Cardfight Vanguard!! OverDress Weekly
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:30 PM to 9:30 PM EDT
October meetup – The Sailor Who Fell From Grace With The Sea by Yukio Mishima
Pier 22
Reading the Classics 7:30 PM to 9:30 PM EDT
Return to the top of the list

Thursday, October 8

Event name and location Group Time
Sarasota Speakers Exchange Toastmasters
Online event
Toastmasters District 48 12:00 PM to 1:00 PM EDT
Open Board Gaming Day at Dark Side
Dark Side Comics & Games
Board Games and Card Games in Sarasota & Bradenton 4:00 PM to 10:00 PM EDT
Omni Toastmasters Club 6861
Online event
Toastmasters Divisions C & D 5:45 PM to 7:00 PM EDT
Tampa Design Hangout @ Sky Puppy Brewing
Sky Puppy Brewing
Tampa Bay Designers 6:00 PM to 9:00 PM EDT
[AL] Phandelver and Below: The Shattered Obelisk [APL 4 Tier 1]
Coliseum of Comics Kissimmee
Adventurers of Central Florida 6:00 PM to 9:00 PM EDT
HP Guild Games BotC Monthly
HP Guild Games
Blood on the Clocktower Tampa Bay 6:00 PM to 9:00 PM EDT
Board Game Night
Unrefined Brewing
Tarpon Springs Community Fun & Games 6:00 PM to 9:00 PM EDT
Warhammer Night
Critical Hit Games
Critical Hit Games 6:00 PM to 11:00 PM EDT
Tampa Fright Club Presents: Other Mommy (Fan Event Screening) in Dolby!
AMC Veterans 24
Tampa Fright Club 6:00 PM to 9:00 PM EDT
Creative Writing club
Foxtail coffee
Cozy Club 6:30 PM to 8:00 PM EDT
Open Claw + Local Ai For All! Ai for Beginners – Advanced
82°West Distilling
Tampa Open Claw Set Up Function 7:00 PM to 9:00 PM EDT
Palm Harbor Toastmasters Club #8248
1500 16th St
Toastmasters District 48 7:00 PM to 8:30 PM EDT
FABulous Thursdays
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:00 PM to 11:00 PM EDT
One Piece Thursdays
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:00 PM to 10:00 PM EDT
Pathfinder Society
Critical Hit Games
Critical Hit Games 7:00 PM to 10:00 PM EDT
The Social Reckoning
AMC Veterans 24
Tampa Movie Group 7:00 PM to 9:00 PM EDT
Thursday Tacos & Tax Write Offs
Online event
Nerdbrew Events 7:30 PM to 10:30 PM EDT
Game Night!
Lucky Spartan
Tampa 20’s and 30’s Social Crew 7:30 PM to 9:30 PM EDT
Return to the top of the list

Friday, October 9

Event name and location Group Time
Escape Room @ Escape FLA
2480 E Bay Dr
The Bay Society 11:59 PM
Osceola Toastmasters Club
Kissimmee Utility Authority (KUA)
Toastmasters Division E 7:30 AM to 9:00 AM EDT
Computer Repair Clinic
2079 Range Rd
Tampa Bay Technology Center 8:30 AM to 12:30 PM EDT
Friday Night Margaritas!!! Remember how we used to do this????? Let’s DO IT!
Grasshopper Mexican Restaurant
Sara-so-tall 4:30 PM to 6:30 PM EDT
Age of Sigmar: Escalation League
Battlebrush Games
Battlebrush Games: Paint Minis & Play Warhammer/Warmachine 5:00 PM to 9:00 PM EDT
Friday Board Game Night
Bridge Club
Tampa Gaming Guild 5:30 PM to 11:00 PM EDT
MTG: Commander FNM
Critical Hit Games
Critical Hit Games 6:00 PM to 11:00 PM EDT
Vintage Board Game Night At Jason’s Deli!!!
Jasons Deli
Adventure Group of Lakeland 6:30 PM to 8:30 PM EDT
Halloween Werewolf – October 2026
Gamers’ Command
Werewolves by the Bay 7:00 PM to 11:00 PM EDT
Modern FNM
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:00 PM to 10:30 PM EDT
Meditations – Marcus Aurelius
Online event
Orlando Stoics 7:00 PM to 8:30 PM EDT
Friday Pokemon Tournament
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:30 PM to 11:30 PM EDT
Return to the top of the list

Saturday, October 10

Event name and location Group Time
Book Review & Dinner in SRQ
Gen X’ers Dining Out in SRQ 5:00 PM
Clearwater Mastering Claude Code for Developers
1133 Granada St
Building Better Software With Claude Code 4:05 AM to 5:05 AM EDT
Kissimmee Toastmasters
Online event
Toastmasters Division E 9:30 AM to 11:00 AM EDT
Saturday Chess at Wholefoods in Midtown, Tampa
Whole Foods Market
Chess Republic 9:30 AM to 12:00 PM EDT
EZ Stock (Stock, Options, Market)
2079 Range Rd
Tampa Bay Technology Center 10:00 AM to 12:00 PM EDT
Saturday Gaming
Nerdy Needs
Brandon Boardgamers 1:00 PM to 6:00 PM EDT
NNO Book Club: Little Eyes
Craft Street Kitchen
Nerd Night Out 1:00 PM to 3:00 PM EDT
FREE Fab Lab Orientation
Faulhaber Fab Lab
Suncoast Makers 1:30 PM to 2:30 PM EDT
D&D (5e) @ Game-o-Storus (FULL)
Game-o-Storus
St Pete and Pinellas Tabletop RPG Group 1:30 PM to 5:30 PM EDT
D&D @ Game-O-Storus (FULL)
Game-o-Storus
RPG-Pinellas 1:30 PM to 5:30 PM EDT
Saturday Chess @ Driftwood Kava & Roastery St. Pete
Driftwood Kava & Roastery St. Pete
Chess Republic 2:00 PM to 5:00 PM EDT
Bitcoin Social in St. Petersburg
Beech Kombucha
Tampa Bay Bitcoin 3:00 PM to 4:00 PM EDT
NATIONAL CAKE DECORATING DAY – GAME NIGHT! Saturday, October 10, 2026
Red Lobster
Tampa (Citrus Park Area) Games Meetup Group 4:15 PM
Board Brews
Zephyrhills Brewing Company
Nerdbrew Events 5:00 PM to 10:00 PM EDT
Warmachine Journeyman League
Battlebrush Games
Battlebrush Games: Paint Minis & Play Warhammer/Warmachine 5:00 PM to 9:00 PM EDT
Annual Halloween / Cosplay Event!
Plant City Railroad Museum
The Lakeland Shooters, Polk County Photography & Modeling 5:00 PM to 8:00 PM EDT
Game Night, Oct 10th – Join us!
IHOP
New Port Richey Game Night 5:30 PM to 9:00 PM EDT
DAGGERHEART ONESHOT
Collect.GG Collectables
St Pete and Pinellas Tabletop RPG Group 6:00 PM to 9:00 PM EDT
Yu-Gi-Oh Evening Tournament
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!
Sunshine Games 7:00 PM to 11:00 PM EDT
Return to the top of the list

Sunday, October 11

Event name and location Group Time
Clearwater Building Faster With Claude Code
25CM+JW Dunedin

Building Better Software With Claude Code 2:53 AM to 3:53 AM EDT
Clearwater Mastering Claude Code for Developers
399 3rd St

Building Better Software With Claude Code 10:17 AM to 11:17 AM EDT
Halloween Resin Crafting! ‍⬛
Linda’s House

St. Pete Life & Fun 50+ 1:00 PM to 4:00 PM EDT
Adventures of the Tomb of Annihilation (5e 2024 D&D Campaign)
Cozy Dragon Games

Adventurers of Central Florida 2:00 PM to 6:00 PM EDT
Sunday Chess at Wholefoods in Midtown, Tampa
Whole Foods Market

Chess Republic 2:00 PM to 5:00 PM EDT
D&D Adventurers League
Critical Hit Games

Critical Hit Games 2:00 PM to 7:30 PM EDT
Book Discussion: Cutting for Stone
Bayboro Brewing Co.

St Pete Women’s Book Club 3:00 PM to 5:00 PM EDT
Sunday Pokemon League
Sunshine Games | Magic the Gathering, Pokémon, Yu-Gi-Oh!

Sunshine Games 4:00 PM to 8:00 PM EDT
Community Hang-out Night
Online event

Nerdbrew Events 6:00 PM to 9:00 PM EDT
A Duck Presents NB Movie Night
Discord.io/Nerdbrew

Nerd Night Out 7:00 PM to 11:30 PM EDT
Tides of Tethered Terror: Tampa Ghost Tours

Tampa Bay Haunt Crew | Halloween & Horror Events 8:00 PM to 10:00 PM EDT
Return to the top of the list

About this list

How do I put this list together?

It’s largely automated. I have a collection of Python scripts in a Jupyter Notebook that scrapes Meetup and Eventbrite for events in categories that I consider to be “tech,” “entrepreneur,” and “nerd.” The result is a checklist that I review. I make judgment calls and uncheck any items that I don’t think fit on this list.

In addition to events that my scripts find, I also manually add events when their organizers contact me with their details.

What goes into this list?

I prefer to cast a wide net, so the list includes events that would be of interest to techies, nerds, and entrepreneurs. It includes (but isn’t limited to) events that fall under any of these categories:

    • Programming, DevOps, systems administration, and testing
    • Tech project management / agile processes
    • Video, board, and role-playing games
    • Book, philosophy, and discussion clubs
    • Tech, business, and entrepreneur networking events
    • Toastmasters and other events related to improving your presentation and public speaking skills, because nerds really need to up their presentation game
    • Sci-fi, fantasy, and other genre fandoms
  • Self-improvement, especially of the sort that appeals to techies
  • Anything I deem geeky
Categories
Artificial Intelligence Security Video

Ziti TV Oct 2 2026 – LLM Gateway meets the OpenZiti Appetizer!

Ain’t livestreaming grand? We had a few rough-around-the-edges moments in today’s episode of Ziti TV (I worked on the demo a *little* too late last night), but the important thing is: THE DEMO WORKED.

The demo built on the previous episode’s work where we took the OpenZiti Appetizer (a service that displayed whatever text you feed it on a public web page via a secure zero-trust OpenZiti overlay) and added a RoBERTa classifier to it to prevent users from entering offensive messages for the Appetizer to display. There are lots of people out there who seem to not have aged past 12, and that’s what this is supposed to handle.

RoBERTa classifiers are good at handling profanity and direct insults like “You are too stupid to understand this”. It *will* miss more subtle jabs like “Nobody wants you here and everyone knows it”, but try saying that to a cop who’s writing you a speeding ticket, and they will classify it very differently.

So in this week’s, the classifier keeps its job, but when it isn’t sure, it asks for a second opinion. LLM Gateway, the OpenZiti-based open source OpenAI-compatible gateway, decides which LLM gives that opinion: a small model on your own machine for everyday messages, and Claude for the subtle ones. You won’t change a line of the Appetizer’s code.

I did the demo without much chance for a rehearsal, and I’ll post a GitHUb repo with all the steps and material you need to try it out for yourself. But in the meantime, catch Clint and I work our way through the demo!

Categories
Security

99% of orgs are PLANNING microsegmentation, but only 9% have followed through

Pictured above: Another one of my totally organic, AI-free, hand-drawn “back of a literal envelope” diagrams showing the “limit the blast radius” benefits of network segmentation and microsegmentation.

Jack Poller, NetFoundry’s VP Product Marketing, kicked off a six-part microsegmentation series with the gap that nobody in the space likes to say out loud.

An Omdia survey of 352 security decision-makers found that:

  • 99% of organizations are implementing or planning microsegmentation, and
  • only 9% had protected more than 80% of their critical systems.

Half of them had been through a lateral-movement attack in the previous year, which is the exact thing microsegmentation is supposed to stop.

Here’s the article: The Microsegmentation Trap: Why 99% Are Planning It and Only 9% Protect Their Critical Systems.

Jack argues that the conventional playbook is the problem: Discover every flow, model the policy for the whole environment, simulate, then enforce. Each phase gates the next, and phase one never finishes because reality collides with your best laid plans:

  • Applications talk to more things than anyone documented and
  • dependencies shift while you’re charting them.

In the end, your initiative languishes in discovery for quarters and the crown jewels stay exactly as exposed as they were on day one.

The proposed fix? Turn the order upside down! Protect the single most critical asset first, one workload at a time, starting now.

Of course, this approach works only if enforcement stops depending on network location. As long as policy is based on IP ranges and zones, you’re back to needing the full topology before you can trust a rule. If you base policy on cryptographic identity, you can wrap one asset in tight policy today without having mapped what’s around it.

Once again, Jack’s article is here: The Microsegmentation Trap: Why 99% Are Planning It and Only 9% Protect Their Critical Systems.

Categories
Artificial Intelligence Humor

How NOT to promote an AI initiative

Yup, that’s an actual Tweet from the official White House account. That’s another data point for the “Everyone is 12 now” theory. 

I’m just sayin’: if you’re trying to promote AI as a beneficial thing, maybe the whole Terminator 2 motif is something you might want to avoid. Those AIs, Arnie’s T-800 excluded, were not our friends!

In the meantime, let’s enjoy the classic line from that film:

Categories
Artificial Intelligence Current Events

Trump’s executive order to rebrand “AI” as “SI”

If there’s one thing that Donald Trump and his sycophants love to do, it’s name or rebrand things to name them after hinself, make them sound more “extra”, or both. Consider:

…and the list goes on.

And now the idiocy meaningless renaming has come to tech:

John McCarthy, coiner of the term “Artificial Intelligence”, creator of the Lisp programming language and garbage collection, influencer on ALGOL, which influences most programming languages.

The executive order, titled INAUGURATING THE ERA OF SUPER INTELLIGENCE, basically declares that “AI”, a term that we’ve been using since 1955 when John McCarthy coined it, should now be referred to as “Super Intelligence” or “SI” in executive-branch communications.

It says that agencies of the federal executive branch must use the new terms in official correspondence, public communications, websites, reports, policy documents and other non-statutory documents. Thankfully (because it would mean a lot of pointless work otherwise), existing regulations, presidential actions, contracts, grants and historical documents don’t have to be changed.

It also means that any content I make aimed at a U.S. government buyers or techies (especially tutorials, presentations, and documentation) will need to include the “SI” terms for both practical (for example, search terms) and political (“We call it ‘SI’ here, son.”). I’m already not looking forward to this.

For now, “SI” means exactly what “artificial intelligence” already means under 15 U.S.C. § 9401(3).; only the name has changed.

Sometime in the next 60 days, Michael Kratsios, the Director of the White House Office of Science and Technology Policy (OSTP), will have to propose legislative language for a federal definition of SI. It’ll have to say whether that definition should modify or replace the statutory definition of AI, and include any conforming amendments and follow-on executive actions. If such changes are made, expect them to be dumb.

Unsurprisingly, it didn’t take long for the first kiss-ass to use the term in Trump’s presence:

 

Categories
Artificial Intelligence Security Tools Video

Super Cyber Friday: “Hacking Microsegmentation for Machine Workloads” (or: Old cybersecurity tricks don’t work with new AI agents))

Last Friday, NetFoundry’s CEO Galeal Zino appeared on the weekly live YouTube show Super Cyber Friday, hosted by tech journalist David Spark.

Super Cyber Friday is about cybersecurity practitioners and vendors, and every episode has a title that follows a “Hacking [Topic]” format. This particular episode’s title is Hacking Microsegmentation for Machine Workloads, and features:

  • Galeal Zino, NetFoundry CEO (and my boss’ boss, and therefore the best damned skip-level in the world)
  • Howard Holton, Founder and Principal Counsel at Phronia Counsel, an independent technology analyst and advisory firm

If you’re wondering what microsegmentation is, here’s the short version:

Microsegmentation is the practice of carving your network into tiny zones so that when something gets compromised (and something will), the damage stays in one small room instead of spreading through the whole house.

Everyone agrees it’s a good idea, almost nobody enjoys doing it, and few actually do it. It’s the brushing and flossing of cybersecurity.

Before the notes, some disclosure

You should know:

  • I do developer advocacy work at NetFoundry in exchange for money, health insurance, and to convince people I’m more than just an accordion-playing reprobate.
  • Once again, Galeal is my boss’s boss. And he’s a great boss’ boss!
  • NetFoundry sponsored this episode.

Feel free to apply the appropriate amount of skepticism to this writeup, but keep in mind that this episode features both a CEO who builds security stuff with an analyst who’s had to live with the results. The episode’s a little more blunt than your typical PR piece.

The tl;dr

C’mon, this article isn’t that long! But still, if you want a very quick summary, here it is…

The old way What machine workloads need
What you segment by IP addresses, subnets, CIDR blocks, VLANs A cryptographic identity for every machine, plus attestation
Where enforcement happens Firewalls and middleboxes at the edge Inside the application, via an identity-driven overlay
How AI agents get treated “It’s basically an employee” or “It’s basically an app” As a non-human actor with explicitly bounded access
What failure looks like Firewall surgery, configuration bloat, shelfware A contained blast radius
What the board says “We better never get hacked.” “How bad will it be when we get hacked?”

“Early microsegmentation sucked so bad…”

Howard set the tone in the first minute, when David asked for his microsegmentation pet peeve (0:08):

“Early microsegmentation sucked so bad that it’s hard to get people to listen when you talk about microsegmentation.”

For the record, Howard is a big microsegmentation fan. What drives him (and us at NetFoundry too) up the wall is the feedback he hears most often: “Nope, we did that before, we’re not doing it again.” People tell him it was too complicated and a waste of money. He hates that feedback because, in his words, “it’s just wrong.”

Later in the show (7:25), he explained how early rollouts earned that reputation. Teams would get frustrated during the discovery stage, put some segments in place, and then cause an outage by blocking something that only ran once every 30 days and that nobody had planned for. After that happened a few times, they’d shelf whatever microsegmentation tool they were using. His summary: “Complexity always bites you in the ass.”

If you’ve ever been anywhere near a rollout like that, you probably just winced. The problem wasn’t the idea. Least privilege and blast-radius reduction are good ideas! The problem was that vendors tried to implement them with the tools that just happened to be conveniently lying around: IP addresses, subnets, VLANs, and firewalls.

When an audience member asked whether application-level or network-level microsegmentation is more effective, Galeal didn’t mince words (9:05):

“Network-level is DOA: dead on arrival. It’s an oxymoron to begin with… It’s spilled milk, and you can’t put it back in the bottle. If you’re going to try and use IP addresses, VLANs, and firewalls to do ‘microseg,’ good luck to you. It’s not going to happen.”

That’s coming from someone who’s been doing network engineering for 30 years. Here’s the core problem, especially for machines: an IP address tells you where something is, not what it is. In a world of containers, autoscaling, and serverless functions, the IP address your billing service has this morning might belong to something completely different by the time lunch rolls around. Writing security policy against IP addresses is like keeping track of your friends by remembering which seats they sat in the last time you all went to the movies. Or, as Galeal put it later in the show (35:10), “IP addresses are not identities.”

Howard then described what happens when you try to brute-force it anyway (10:03):

“Microsegmentation and segmentation are not the same thing… If you’re like, ‘Well, I’m going to create 437 subnets in my network and I’m going to create 300 VLANs and I’m going to turn on host-based firewalls,’ you’ve just created a nightmare that no one is ever going to be able to manage after you. And you have failed job number one, which is make sure that the next person can be as successful as you are.”

“Make sure that the next person can be as successful as you are.” I want that on a poster, and not just for network engineers. It applies to code, documentation, and pretty much anything you build that someone else will inherit.

And if you try to do it the classic way regardless, making your firewalls enforce all that traffic between your services? According to Galeal (29:48), that’s the first lesson you’ll learn: “You will melt your firewalls.”

Credentials aren’t identity

My first bearer tokens.

My favorite moment in the episode came from an audience question. Sierra Montgomery asked (11:05):

“If a compromised workload acquires valid credentials and begins behaving like a legitimate service, what signal does your microsegmentation architecture use to distinguish legitimate machine-to-machine communication from lateral movement?”

Galeal’s answer was one word: Attestation. His reasoning: a credential doesn’t prove whether Howard, David, or an AI agent should have it. Credentials, he said, are “necessary but not sufficient.”

Explaining bearer tokens is something that goes back to my first article for Auth0, which was also my “take-home assignment” in the job interview process. The concept always needed the most careful explaining, even though the name told you everything: whoever bears the token gets the access. The token doesn’t know or care who’s holding it. It’s more like cash than a credit card.

That’s fine as long as you know where the token is. The trouble starts when you don’t. A credential proves that something possesses a secret. It doesn’t prove that the thing should have that secret, and it says nothing about whether the machine presenting it is in the state it’s supposed to be in. Attestation fills that gap: it’s verifiable evidence that the workload is what it claims to be, and that it’s running where and how it’s supposed to.

Take the pwning like a champ

At a DEF CON party a long time ago, a few friends and I came up with a joke talk title for the following year’s edition of the conference: “Security is for lightweights. Take the pwning like a champ.”

But behind the joke was an important idea: every boxer gets hit. What makes a champ isn’t never getting punched; it’s being able to take the punch and stay on your feet. Security works the same way. Sooner or later, one of your credentials is going to end up in the wrong hands, whether it’s through a phished password, a leaked API key, or a token that got copied out of a log file. Back then, planning on getting pwned was a punchline. These days, it’s a design principle, and it’s exactly where Galeal starts.

The DEF CON joke came to my mind when an audience member asked how a platform can alert on a compromised token moving laterally (16:06). Galeal’s answer was in the spirit of “Take the pwning like a champ”: Assume that tokens will be compromised, and design your system so that a token by itself doesn’t grant access.

If your architecture opens the door and grants network reachability before it verifies identity, an ill-gotten token can be a starting point to explore your network. The “Take the pwning like a champ” approach that NetFoundry takes verifies identity first and uses policies to spells out which identities can talk to which services. A stolen token doesn’t open any new doors, because the path the attacker wants isn’t accessible to them.

AI agents are chaos monkeys nobody scheduled

History time! If you were a developer around the time the iPad came out, you might remember Chaos Monkey, Netflix’s tool designed to randomly shut down servers in production. The idea behind it could be summarized as “The random shutdowns will continue until resiliency improves”. Netflix’s dev teams were forced to build in such a way that their systems would survive failure. It’s a brilliant (if sadistic) idea, and it works because Netflix chose to unleash it deliberately, with rules.

This isn’t all too different from a pattern Galeal described (28:56): taking an AI agent and saying, “Hey, cool. Here’s some API keys. Here’s the internet. Here’s some enterprise resources. Go do something useful.”

Howard’s response: “I see that like 40 times a week.” That’s a chaos monkey too, except nobody scheduled it, nobody wrote the rules, and it will explain its reasoning very confidently afterward.

My last job prior to my current Developer Advocate gig at NetFoundry was optimizing an MCP server, so this isn’t a hand-wavey “some customer has this issue” thing to me. Every tool or function you expose through an MCP server is something an agent can decide to call, whenever it wants, for reasons you didn’t anticipate. Its network traffic doesn’t follow a script.

When an audience member asked how to segment an AI agent whose needed connections change with each task, Howard’s advice was (27:27):

“If you try to design something that is entirely flexible, what you’re going to end up with is opening yourself up for AI chaos in your network… If you do it the other way around and hope that your microsegmentation tool set is going to keep up with your AI, you’re basically saying, ‘I want microseg to follow my chaos monkey.’ Do it the other way around. Use microsegmentation to restrict the chaos monkey.”

Galeal’s answer to the same question (26:43) supplies the other half: The old bag of tricks isn’t going to work on agentic flows. Treat agents as identities, define a graph of what each one can talk to and under what conditions, and have the visibility and enforcement to make sure they stay on that graph.

That’s the right mental model. An AI agent isn’t a human employee sitting behind your SSO portal, and it isn’t a cron job that does the same thing at the same time every night. It’s a whole new thing.

As Howard put it later in the show, it isn’t another application, and it doesn’t act like a human either. It needs boundaries defined up front, including things like:

  • A specific identity,
  • ashort list of things it’s allowed to reach, and i
  • solation that travels with it whether it’s running in AWS, on bare metal, or in an OT facility.

What this looks like if you write code

Time for me to put my work hat on for a minute. The table above mentions “an identity-driven overlay” enforced “inside the application,” which is a mouthful, so here’s what it means in practice.

OpenZiti is the open source zero trust networking platform that NetFoundry builds, and one of the things it lets you do is embed zero trust directly into your application with an SDK. Your app gets its own cryptographic identity, and it can only reach the services that policy says it’s allowed to reach. On the other side, services don’t need open inbound ports at all, so there’s nothing sitting on the network for an attacker to scan, probe, or point a stolen token at.

Galeal’s “kill switch” (more on that below) gets pretty concrete here too: if an identity is compromised, you revoke it or change the policy, and its paths go away. No firewall surgery required.

If you want to try it yourself, the docs and quickstarts are at openziti.io.

What do you tell the board?

Near the end, David read an audience question: Which metric best shows leadership that microsegmentation is working? Galeal boiled his answer down to three questions (39:11):

  1. The graph: Can you answer the question “What identity can talk to what identity, according to what policy?” (Note that he said identity, not IP address.)
  2. The kill switch: When something unexpected happens, where’s the kill switch that lets you deal with it without compromising uptime, human safety, or business continuity?
  3. Centralized governance: How much of all this can you see and govern from one place, instead of going to a bunch of different environments and firewalls?

Then Howard put on his gloves (41:27): “I couldn’t disagree more.” Speaking as a CISO, he said:

“What my board said 10, 15 years ago was, ‘We better never get hacked.’… Today they say, ‘How bad will it be?’ That is their question to me. That is the question they want me to answer in every board meeting they invite me to.”

My answer would be “Take the pwning like a champ”.

David pointed out that the two answers aren’t really in conflict: Galeal was describing what you measure for yourself and your security team, and Howard was describing what you tell the board. Galeal agreed. Howard then explained why the board version has to be so compressed (43:29):

“I get one slide as a CISO… I get like five minutes… I make that one slide tell them how I’m spending money to make it less bad than the last time they gave me money.”

Ah, the dreaded “You get one, and only one, slide” directive for board meeting presentations. Replace “board” with “VP of Engineering” or “whoever approves your budget,” and it’s still excellent advice.

My takeaway

If I had to boil the whole episode down to one idea, it wouldn’t be about AI, firewalls, or attestation. It would be Howard’s “job number one”: make sure the next person can be as successful as you are.

Galeal landed in the same place from a different direction. When David asked why he started NetFoundry (24:00), he said that after years of beating his head against walls like microsegmentation, he wanted to tilt the playing field so that the next person who has to solve these problems doesn’t have to.

That’s the real case against building microsegmentation out of subnets and VLANs. Even if you get it working, you’ve built something nobody else can understand, let alone maintain.

A policy that says “the billing service can talk to the orders database, and the AI agent can talk to these three APIs and nothing else” is something the next person can read, reason about, and change without breaking everything. And when some of the things doing the talking are AI agents that nobody can fully predict, that kind of clarity is what keeps the chaos monkey in its cage.

Go watch the episode, and if you’re a developer who wants to see what identity-first networking looks like from the inside, take OpenZiti for a test drive!