I Refrain from Infosec Punditry

surprisetalk1 pts0 comments

Why I refrain from infosec punditry - lcamtuf’s thing

lcamtuf’s thing

SubscribeSign in

Why I refrain from infosec punditry<br>Apr 16, 2026

56

Share

If you know about my professional background, the most puzzling aspect of this Substack must be that I don’t use it to talk about my primary field of expertise: information security. In fact, it feels like self-sabotage; most of people who recognize my handle would probably rather read my take on Mythos — the new LLM tool from Anthropic that’s promising to revolutionize vulnerability discovery — than listen to what I have to say about chicken coops or the foundations of math.<br>The reason why I keep biting my tongue is simple: I dabbled in infosec punditry for nearly two decades, but I’ve come to realize that it’s a way to make yourself busy without accomplishing anything. The industry deals with nearly-constant drama — new breaches, new product claims, new controversies — but almost none of it has any bearing on long-term trends. As a practical example, cryptocurrencies and the associated ransomware industry have reshaped the landscape of enterprise security far more than any advances in vulnerability research. Heck, even on the topic of vulnerability research, the discourse is often dictated by PR efforts, not reality. In the 2010s, you’d see dozens of stories about symbolic execution research from Microsoft; I don’t recall a single Ars Technica article about Address Sanitizer, an unassuming open-source feature that helped squash tens of thousands of bugs. I have many other spicy examples, but all I’d accomplish by listing them is upsetting some of my peers.<br>The relentless pace of infosec drama also makes our punditry remarkably shallow. You’re not doing deep dives; you’re offering TikTok-level hot takes on the headline of the day. You’re right half the time, wrong the other half, and you’re usually rewarded simply for saying things that are provocative, with no one holding you accountable if you miss the mark.

Subscribe

56

Share

Discussion about this post<br>CommentsRestacks

lcamtuf’s thing reply rules

Wyrd Smythe<br>Apr 16

Liked by lcamtuf

For the record, I far prefer the interesting topics you do write about.

Reply

Share

mids<br>Apr 17

Liked by lcamtuf

I appreciate your TikTok-level hot take on this subject :)<br>But seriously, your blog covers subjects I found sorely lacking in the blogosphere, and does great justice in explaining them, that's why I follow it.

Reply

Share

5 more comments...

TopLatestDiscussions

No posts

Ready for more?

Subscribe

© 2026 lcamtuf · Publisher Privacy<br>Substack · Privacy ∙ Terms ∙ Collection notice

Start your SubstackGet the app<br>Substack is the home for great culture

This site requires JavaScript to run correctly. Please turn on JavaScript or unblock scripts

lcamtuf from infosec punditry share refrain

Related Articles