Sunday, August 23, 2026

The Infrastructure Disappears. The Relationship Remains.

My kids play video games.  Sometimes too much. It used to be Roblox and Minecraft and then Fortnite and who knows what else as they gravitated from PlayStation and Xbox to basic mobile games and then eventually PC games.  The console vs PC philosophy I guess. 

What I noticed over the years is how much has changed since I was younger and had my Ultima and Star Control and Diablo 2 and Fable and then Elder Scrolls and NHL and Madden experiences is that everything is in app purchases and subscriptions now.  Buy an Xbox game and have to update and subscribe and take an hour to set it up. No more throw in the dvd or cartridge and start playing. Different times.  

Thinking on all these payment layers and back to some Pagarba VR and AR and decentraland and blockchain crypto tokenization and gamification angles and projects we did , it's fascinating how far the spaces have come, but how far they still need to go for a broader audience reach.  

The web3 gaming, prediction markets and digital wallets have adapted and are now  converging on the same problem; who owns the customer relationship when payments, digital assets and commerce become part of the product.

The answer is becoming less about blockchain and crypto tokens itself and more about who controls the layer between the customer and the transaction.

Web3 gaming did not struggle because blockchain stopped working. It struggled because blockchain became the user's burden.  And a lot of web3 games were awful.  And the virtual land and decentraland variations were just worse versions of second life honestly.  

And blockchain and crypto have had that UX and UI challenges for a decade now.  Users or players are expected to create wallets, protect seed phrases, understand gas fees, approve transactions and think about tokens before they could simply play a game or use the application.  

That is a product problem, it's a user experience problem and not a cryptography problem. The technology became visible at exactly the point where it needed to disappear.  And then you has the typical tech bro response of calling users too dumb to use it. That never goes well and never works. 

The numbers reflect the problem. Web3 gaming funding fell sharply in 2025, while daily active wallets declined to roughly 4.8 million in the second quarter, the lowest level since early 2023.

The underlying technology continued to operate. The user experience did not create enough value to justify the additional complexity.

The Ronin bridge exploit showed what happens when infrastructure becomes part of the trust relationship.

In March 2022, attackers compromised validator keys associated with the Ronin Network and used them to authorize fraudulent withdrawals totaling roughly $625 million.  Think about that. $625 million.   

The technical details were sophisticated, but the customer experience was simple as the assets were no longer safe.  Reputation for financial and gaming are huge.  Don't trust any of it and nobody wants to use it. And it's not as simple as a master card fraud charges where there are processes in place to cancel those transactions and get your money back. Cancel the card and so on.  Blockchain and crypto seemed to forget hackers exist, people forget passwords all the time and bad things can happen.  Nobody wants to think they're just screwed.

Users do not care whether the failure happened in a validator set, bridge contract, custody system or payment processor.

They care whether their money, assets and account are still there. 

The next generation of Web3 products is therefore taking the opposite approach.  So there is progress and hope. 


Make the infrastructure disappear.


If you're familiar with gaming and payments, Xsolla is one of the bigger players. There are many companies like them who do well , have many paying customers, many employees globally yet if you know you know and if you don't, you never heard of them but maybe saw them somewhere.  

I used to work at a company called ESET. Great efficient and cost effective anti virus software company. Nobody heard of them but a few people.  Yet I worked for them like 16 years ago and they still are around and have their products on display at Microcenter now.    

Which brings me back to Xsolla and their plans for blockchain and backpacks and wallets and payments and zero knowledge proof.   Xsolla has started implementing their Xsolla ZK and maybe it's part of the wave of the future for web3 products and features.  It's not tech trying to find a problem.  It's a problem being solved by technology. 

Xsolla originally positioned ZK as ZKsync-based infrastructure for managing digital assets and verifiable ownership. Its broader Web3 strategy has increasingly focused on ownership, programmable value exchange, interoperability and player participation without requiring the player to understand the underlying blockchain infrastructure.   Nobody cares about a wallet or token.  They just want things to work and work fast and be tustworthy.

That direction makes considerably more sense than asking every gamer to become a crypto user.

The best blockchain product may eventually be the one where the customer never knows blockchain was involved.  

But that creates a much bigger competitive problem for Xsolla.

Because the financial industry is moving in the same direction.

Coinbase is moving deeper into regulated financial infrastructure. The OCC conditionally approved Coinbase's national trust bank charter application in 2026.

The OCC also conditionally approved five national trust bank applications in December 2025. First National Digital Currency Bank and Ripple National Trust Bank received conditional approvals for new national trust bank charters, while BitGo, Fidelity Digital Assets and Paxos received conditional approvals to convert existing trust companies into national trust banks.


The distinction matters.


These companies are not simply trying to become traditional retail banks. They are moving pieces of custody, settlement, fiduciary services and digital asset infrastructure closer to the regulated financial system.

PayPal is pursuing a different version of the same strategic direction. It has applied to establish an industrial bank in Utah, seeking greater control over parts of its financial infrastructure and the services it provides to businesses. That is another example of a platform trying to bring more of the financial relationship under its own control rather than depending entirely on external institutions.

Robinhood is doing something similar from the consumer finance side. It has expanded from brokerage into crypto, prediction markets, futures and derivatives. In late 2025, Robinhood announced a joint venture with Susquehanna International Group, with Robinhood as the controlling partner, to acquire MIAXdx and build an independent CFTC-licensed exchange and clearinghouse. The acquisition closed in January 2026. Robinhood reported more than 12 billion event contracts traded in 2025.

That is important because Robinhood is not simply adding another feature to its app. It is investing in the infrastructure underneath the feature.

MetaMask is moving in the opposite direction from a traditional financial institution. 

It starts with the wallet.

Then it adds the payment layer.

MetaMask has launched its own stablecoin and connected its wallet to a Mastercard payment product, allowing users to spend assets held through the wallet.

Kraken has similarly moved from exchange infrastructure into consumer payments with its Kraken Card, bringing crypto balances into a conventional card experience.


The strategic pattern is difficult to miss.


Financial companies are moving toward wallets.

Wallet companies are moving toward payments.

Payment companies are moving toward stablecoins.

Stablecoin companies are moving toward regulated financial infrastructure.

And gaming companies are trying to make digital ownership and value exchange part of the commerce experience.


The boundaries are collapsing.


Traditional payment networks are not standing still either.


Mastercard has been building stablecoin and wallet capabilities with companies including MetaMask and Kraken.


The important point is that Web3 payment products are not necessarily replacing traditional payment networks.


In many cases, they are using them.


The blockchain may provide the asset layer.

The wallet may provide the customer relationship.

The stablecoin may provide the settlement asset.

The card network may provide the merchant acceptance layer.


The customer simply taps a card.


That is the real convergence.  It's not what the original Bitcoin and cryptocurrency and blockchain world dreamed of and it's certainly far from Decentralization, but maybe that's just how it stays relavent and changes things in its own way. 


Visa's own analysis estimated that adjusted stablecoin transaction volume was on track to exceed $10 trillion in 2025 after removing high frequency trading wallets, smart contract addresses and bot activity.


The precise number depends on methodology, but the strategic signal is difficult to ignore.


Stablecoins are no longer simply a crypto trading instrument.

They are becoming financial infrastructure.

And that changes the competitive landscape.


The real competition is not blockchain versus Visa.


It is control of the customer relationship.


Who owns the wallet?


Who controls the payment experience?


Who owns the rewards layer?


Who controls identity and attribution?


Who gets the next transaction?


The company controlling those relationships can increasingly capture value across multiple layers of the transaction.


That is why Xsolla's position is interesting.


Xsolla already sits inside the commerce relationship between game developers, publishers and players.


It does not need to convince a player to download a cryptocurrency application simply to establish a financial relationship.


The commerce relationship already exists.


That gives Xsolla a potential advantage.


But it also creates a much larger competitive field.


Xsolla is not simply competing with other merchant of record providers. It is competing with platforms that already control enormous customer relationships.


Coinbase has the financial account.

MetaMask has the wallet.

PayPal has merchant relationships and consumer payments.

Robinhood has the retail financial customer and the exchange infrastructure underneath it.

Visa and Mastercard control enormous payment acceptance networks.


The strategic question is therefore not whether Xsolla can build blockchain infrastructure.


It can.


The question is whether it can use that infrastructure to strengthen the relationship it already has with the gaming ecosystem.


That is a much more interesting product question.


Prediction markets provide another example of financial infrastructure becoming embedded in consumer platforms.


Robinhood's prediction market strategy is not simply about putting event contracts in an app. It is increasingly about the infrastructure underneath them: exchange access, clearing, liquidity, distribution and the customer relationship.


That distinction matters.


The market is moving away from standalone products toward integrated financial ecosystems.


A user does not necessarily care whether the company behind the experience is technically an exchange, wallet provider, payment company, bank or gaming commerce platform.


They care that the account works.

They care that the money moves.

They care that their assets are available.

They care that rewards arrive.

They care that checkout is fast.

They care that someone is accountable when something goes wrong.


The distinction between a wallet and a bank may become increasingly irrelevant from the customer's perspective.


What matters is who owns the relationship.


That is also why the competitive advantage will increasingly migrate away from blockchain mechanics.


The first generation of Web3 asked users to enter the blockchain.


The next generation is trying to put blockchain behind the experience.


That is a much better product strategy.


But it also changes what companies are actually competing for.


Wallets, payments, rewards, identity, commerce and settlement are converging into a single customer relationship.


The companies that control that relationship will have the strongest position.


Xsolla has a legitimate opportunity because it already controls an important piece of the gaming commerce relationship.


But Coinbase, MetaMask, Kraken, PayPal, Robinhood, Visa and Mastercard are all moving toward adjacent pieces of the same territory.


The question was never who has the best blockchain.


The question is who can make the entire financial and commerce experience feel invisible.


The infrastructure disappears.

The relationship remains.


And eventually, when the infrastructure is badly designed, the customer finds it anyway.

Friday, August 21, 2026

ZKP for medtech and medical devices?

 

The medtech space is fascinating.  It used to be bolt on security and worry about it later. Some of that philosophy has changed , the FDA made regulations and compliance more mandatory and less checkbox assessments and governance non technical advice, but still , many challenges remain.  

What about trying to implement ZKP or homomorphic encryption into medical devices or embedded instruments?   Even Post Quantum security techniques merging techniques that crypto and blockchain have researched, Google has written some white papers on and cryptographers are testing ?

Looking more into medtech and how a lot of medical devices generate far more sensitive data now , and across a system of parties with different trust relationships is a growing concern. Think about what a medical device actually is now vs just some pacemaker.  They are a medical device, gateways,  hospital network, patient phone and network, cloud infrastructure, analytics platforms, providers, payers, and regulators. 

The problem is not simply protecting the device. It is deciding what each party can see, what each party can verify, and what happens when those trust assumptions change.  And devices may send electrical or other signals now not just Bluetooth connectivity. 

Conventional controls handle much of the foundation. Secure boot, signed firmware, hardware roots of trust, device identity, attestation, and authenticated communications establish device and software integrity. That trust chain begins long before deployment.  You have  factory provisioning of device credentials and keys, boot ROM and hardware root of trust integrity, and contract manufacturing custody that  determine whether the root of trust is valid from the moment the device is powered on. 

If the requirement is simply proving that a device is running approved firmware, a signed measurement is generally more appropriate than a zero knowledge proof.  We do assume manufacturing is trustworthy and not installing software or hardware backdoors. Should we though ?

Once deployed, a gateway may act as a transparent relay or, if local protocol translation or edge processing is required, as a plaintext trust boundary. The security problems diverge once data leaves the device. Homomorphic encryption can allow certain cloud computations without exposing the underlying plaintext to the compute environment, but its practical use remains limited to workloads where the performance and complexity are justified. 

It is not a solution for most real time physiological telemetry. Zero knowledge proofs address a different problem entirely.  Proving a defined claim about private data without disclosing the data itself. Neither technology establishes that a sensor measurement reflects physical reality. An attack against an analog sensor interface can alter a measurement before software or cryptographic controls ever see it.

That distinction matters because medical device security has different consequences. A confidentiality failure can expose protected health information and create regulatory and legal risk. An integrity or availability failure can affect a clinical decision or interrupt therapy. The controls, threat models, and acceptable failure modes are not the same.

The fifteen-year lifecycle compounds these risks. Cryptographic algorithms can be deprecated, keys can be compromised, standards can change and regulatory requirements can evolve. But the hardware ages too. Memory retention, component degradation, sensor drift, clock accuracy, physical tampering, side channel attacks, and limited processing, storage, and battery capacity can constrain what security changes are actually possible.  And who knows the more AI is pushed what else becomes a vulnerability.  

Cryptographic agility therefore cannot mean simply having the ability to install a new algorithm. The device has to have enough hardware capacity to support the migration, enough storage for recovery mechanisms and alternative trust material, and an update architecture capable of delivering the change. 

Maybe we need to look at how the Voyager spaceships still operate and can be updated and fixed after 40+ years.  And nobody can actually go land on the ship and change or fix it. Different use case but learning from that engineering philosophy may go a long way for medical devices and AI. 

 A medical device without reliable access to its trust infrastructure creates another problem.  A revocation and key replacement may not be available when needed. When trust anchors fail, the system requires defined safety-state policies such as graceful degradation to standalone operation. A security mechanism that bricks a safety-critical device is an unacceptable failure mode.

Regulation adds another constraint. A manufacturer can engineer for change, but a cryptographic modification can affect verification, validation, documentation, and the approved configuration of the device. Meanwhile, the manufacturer does not control every trust boundary. Cloud providers, EHR vendors, certificate authorities, network operators, and other third parties can change infrastructure and trust relationships independently.

The real design question is therefore not which cryptographic primitive to choose. It is which security assumptions are controlled by the manufacturer, which are delegated to third parties, how those assumptions can change over the device lifecycle, and what happens when they fail.

Which parties are trusted with plaintext? Which only need a verifiable claim? Which computations must remain confidential even from the infrastructure executing them? What happens when a key is compromised, a device is offline, hardware degrades, or a security update conflicts with clinical safety?

A long-lived medical device needs more than cryptographic agility. It needs a security architecture that can evolve without turning a change in the security environment into a change in patient safety.

The future is bright. It's also challenging. 

Thursday, August 20, 2026

Supply chain attacks and genAI

Many executives and leaders still treat AI tools as plug-and-play; buy it , trust it, install it, connect it, use it , automate it, scale it. 

That assumption is becoming a liability. A huge one.

The LiteLLM supply chain attack in March of this year (2026), exposed exactly this philosophy. Attackers didn't need to breach their targets directly. They compromised a trusted security scanner inside a development pipeline, used stolen credentials to distribute poisoned software updates, and gained access to cloud keys, Kubernetes secrets, and live AI provider credentials across corporate environments. The front door was never touched. It wasn't even knocked on in a sense. 

The same principle applies to attacks on municipal water systems. You don't have to breach the facility itself when you can compromise a trusted management interface and control what sits behind it. And some of these city and county water and wastewater management systems have old PLC and other technology that was never supposed to be connected. Never designed for it.  

AI platforms create a similar choke point. They connect companies to dozens of services, so compromising one trusted dependency can provide access far beyond that single system.

Yet many organizations still rely on periodic audits, vendor trust, and reactive credential rotation. They rely on MVP products sold as GA v1 enterprise ready and aren't even close. But not everybody vettes these or vendor politics at play so forced onto teams and employees. That security model was built for a threat environment that no longer exists.

Every external software update should be treated as an unverified artifact until its provenance is established. Zero trust to the extreme. Supply chain attacks, at scale, should be a priority.  

Every centralized access layer should be treated as an elevated-risk target requiring continuous logging and monitoring.

The executives and leaders who understand this aren't treating cybersecurity as an IT cost center. They're treating digital infrastructure like any critical supply chain; with verified provenance, real-time visibility and zero assumption that something is safe simply because the package carries a familiar name.

This blog and description has more details about that liteLLM hack back in March.

liteLLM Hack March 2026



Saturday, August 8, 2026

The amateur was bad

 The Amateur movie review on medium


I watched the movie , 'the Amateur' last night. Saw the trailer before, poking through Amazon prime and it was free, so figured why not. 

The premise was interesting even though it's been done a thousand times over.  Revenge. Fish out of water. Conspiracy. Second guessing.   Why not give it a shot. I remember thinking the trailer looked promising and some big names in the movie.  A few actors who have shown they make movies better than they should have been in the past.  Worth it. 

What a bad movie though.  The premise, again, interesting enough with a catch,  as the guy isnt Jason Bourne or some MMA ex military tough guy. A lot of the Mr. nice guy but was a former seal or secret agent troupe is overdone and kind of annoying. So at least it wasn't that. 

But it was like they took some of those movie ideas Jason Bourne like premise and then thought hey let's get the guy who played Mr Robot as a hacker to be this bored analyst with a revenge plot.  And it started early. Demands. Weird situations. World travel. Unlimited money. Random secret hacker like friends. It was like they had a room full of writers using chatgpt and throwing anything and everything and why not. Let's do that. 

It was slow. But no real build up to care. That's the worse for a show or movie. Slow buildup but too quick where you have no connection to any of these people or story. It's like some bad Saturday night live satire sketch that wasn't funny or dramatic or serious and the comedians just going through the motions. Or they brought in some big name who isn't exactly a great actor and it falls flat. 

The common Hollywood troupe of computer geeks and hackers is always annoying.  The Amateur though, he wasn't even a hacker. CIA threat intelligence analyst who seemed to have certain clearances and relationships, but macgyver like traits, breaking bad Walter chemistry knowledge, Jason Bourne like revenge and connections, Mr Robot like hacker skills and it was just ridiculous and annoying. 

  I wonder if it even gets made or winds up lost and hardly watcher if they casted someone else to be the lead. Casting directors probably thought, "hey he was a hacker in Mr Robot" let's get Rami. it was good casting to get the guy who played an intelligent hacker in a somewhat successful show to play the lead. 

So let's go with the CIA like threat intelligence analyst in the basement who is somewhat of a hacker.  Somehow all that intelligent mindset was lost as he's using credit cards , IDs given to him by the CIA,  knows they can track him, knows he's basically committing treason and being targeted and his boss director  will have it out for him.  It was really like chatgpt wrote the movie with no context and everybody thought, hey this sounds cool.   I understand the nature of stress , fish out of water, and he's in over his head but all the build up was too slow but too quick and the overall revenge played out more ridiculous than the next. 

Jason Bourne has many plot holes and points but at least the idea he was getting revenge, figuring stuff out and one bad mofo was legitimate. Even in Mr Robot , he was a hacker out to get shady bad guys and then conspiracy to the extreme, there was still some semblance of suspension of belief where some of to makes sense and you understand.  

The Amateur. It was so bad. 

Saturday, August 1, 2026

Flock needs a VP

 

Interesting after all the uproar and media buzz , flock has a VP of Product opening. Wonder if someone had enough and quit or the environment and culture is playing out in different circles and is at an inflection point.    It'll be interesting to follow and see what leader they wind up hiring for this and how things change or stays the same .



The posted job JD


"

VP Product

The Problem

As Flock expands into new markets and use cases, scaling our portfolio across hardware-enabled infrastructure, firmware, and cloud software requires dedicated executive product leadership. Maintaining product differentiation and earned trust across complex technology layers demands a strategic leader who can align engineering execution with long-term business goals. You will lead end-to-end product strategy across core product lines, mentor product managers, and represent our technology with clarity to cross-functional partners and external stakeholders.


What You'll Own

Lead end-to-end product strategy and execution for a multi-layered portfolio spanning cloud software, firmware, and hardware systems.


Direct and develop a team of Product Managers responsible for driving core product areas from initial roadmap conceptualization to market execution.


Partner with Engineering leadership to align product roadmaps with technical architecture, platform evolution, and delivery capabilities.


Translate customer needs, competitive dynamics, and market signals into prioritized product roadmaps that balance innovation, system reliability, and speed to market.


Represent Flock's product portfolio and guiding development principles in high-stakes external conversations with customers, partners, and public stakeholders.


What This Role is Not

This isn't a hands-off corporate strategy position, you will actively engage with engineering teams on technical tradeoffs and dive deep into product architecture.


This is not a single-product or software-only role, you will oversee an integrated portfolio combining hardware devices, firmware, and cloud platforms.


This isn't an isolated internal management function, you will serve as an external product spokesperson who can explain technical systems clearly to diverse audiences.


What You Bring

Proven track record leading and growing complex, multi-layered technology products across software platforms and hardware-adjacent systems.


Strong product judgment with the ability to prioritize effectively across competing demands and incomplete market information.


Demonstrated experience developing and managing product managers to drive cohesive execution across distinct product lines.


Capability to partner deeply with Engineering on platform architecture, technical sequencing, and development tradeoffs.


Clear executive communication skills with the ability to represent complex product capabilities to non-technical external stakeholders.


Compensation

In this role, you'll receive a starting salary between $280,000 and $300,000 as well as Flock Stock Options. Base salary is determined by job-related experience, education/training, as well as market indicators. Your recruiter will discuss this in depth with you during our first chat.


Why Flock

Every community deserves to be safe. Flock builds the technology that makes that real: last year we supported over 1 million criminal investigations and helped locate more than 10,000 missing people. We're 1,700 people building the impossible with over $1B in funding, and the expectations are high on purpose. If you want a role where the stakes are real and the pace matches, this is it.


Some problems get solved faster in the same room, so we prioritize candidates in Atlanta and Boston. Hub-based roles mean real in-person time with your coworkers. Remote roles exist, and when a posting is open to remote work, it says so.


Building the impossible takes every kind of mind. Flock is an equal opportunity employer, and we know the best solutions come from diverse perspectives, experiences, and skills working together with mutual respect

"



Definitely will follow this.



Thursday, July 30, 2026

Water systems challenge in Minnesota

 Water supply systems Minnesota

US blaming Iran

"Officials are investigating after a cyber attack targeted water systems in several Minnesota cities, but they say there is no threat to the drinking water. FOX 9's Bill Keller reports."



These old public utilities, parks and everything government related have a lot of old tech, forgotten about tech and maintained by a few people overworked and overextended who aren't IT or cybersecurity or OT individuals. Nor should be but it's easy to just say system is flawed and blame certain folks.

Sunday, March 1, 2026

Ice Rinks: The Reality Behind the Surface

 Ice Rinks: 

The Reality Behind the Surface

Guides , manuals, blogs , video's , old heads will tell you ice should be perfect. Thin. Level. Precise. But made to last and think long term not just short term. Especially old barns. 

In reality, most rinks don’t get that luxury. There isn't the time , patience , experience or equipment for all that.  The ice needs to be 1.5 inches thick or more to survive a day of high school games, beer league, clinics, and youth camps and games and part time temporary zamboni drivers

The people maintaining it are often part-timers. Ten minutes to cut and flood. Not really flood. Temperatures fluctuate. Old compressors wheeze. Pipes leak. Water quality varies. HVAC systems are aging, sometimes broken. You learn quickly that “ideal” ice is a fantasy.  And many people don't even care unless it's really bad. Or the locker rooms and bathrooms are a mess , then they start chomping about ice quality too. 

Every day, someone adjusts on the fly: adding water, watching the cracks, watching the puck slide differently depending on the morning temperature, last night's usage and the days schedule. It’s improvisation, judgment, and experience. And yet, somehow, the ice holds. Mostly. Even when it doesn't and the paint starts peeling or looks too bright , deep, dark its more about flooding , light cutting and get it back to 1.5. Somehow, games are played, practices happen, kids learn, and adults compete. Day after day, night after night, week after week, month after month and year after year. Mostly. 

Ice maintenance isn’t glamorous. It’s sweaty, precise, repetitive, and unforgiving. Ice depths can be as simple as a drill , pen and paper and a metal depth ruler. It requires attention to detail, patience, and an understanding that conditions change with every hour. It’s like life; rarely perfect, often frustrating, but always moving forward.

Sports technology can help. Sensors, analytics, monitoring systems add visibility, consistency, and insight. But no tech replaces judgment. And a lot of the tech was built by people who never played or stepped on the ice or drove a zamboni.  But that's silicon valley and tech startup culture.  Many never actually care about the customer much less spent any time actually getting to know the day to day and week to week and pain points.  AI replaces experience, but it doesn't. The rink survives because people care, notice, and adapt. That grumpy old Zamboni and rink operator actually cares about the rink, the ice and hockey, figure skating, sled hockey , broom ball, skippyball, boot hockey, curling and more. 

So when you step onto the ice, remember: there’s a world beneath the surface. One layer of frost at a time. And sometimes, that’s enough.





Saturday, February 28, 2026

Linkekdin has become a joke

 You open LinkedIn and everybody is posting about square and block and Jack laying off 40% of his workforce.  It sucks.  Its sad. It's blaming AI again. But linkekdin has become this click bait useless platform where recruiters proclaim the market is back and everybody is hiring and that AI isn't replacing everybody.  

You have other's post random quotes and stories like Olympic Men and women won gold , here is how that relates to NOTHING. It's just stupid posts. Tons of AI junk content. Recommendation that show linkekdin can't do recommendations right.  

And finally everybody jumping on some guy like Jack posting lay offs and AI and why this or why that. It's like who asked.     And oh yeah they all ignored that block shares went up right after the announcement. Guess Jack and his buddies made out. 

Wednesday, October 15, 2025

Frozen Frontier: Sustainability, AI, and My Education on the Ice

The Journey of a Rink Family

Some families spend weekends at soccer fields or baseball diamonds, but mine grew up at the rink—from the high summer heat in Atlanta, the desert cool at night in Southern California, to the deep freeze mornings in Minnesota. My kids’ hockey bags have collected red Georgia clay, bits of Los San Diego beach sand, and the muddy lake water or melted snow and ice particles of Minneapolis and Edina and everywhere in between. I didn’t just become a hockey parent or a techie fascinated with next-generation rinks ...

I became a regular at the helm of a Zamboni, learned the quirks of resurfacing, and joined the ranks of rink maintenance crews who keep the game alive for everyone willing to lace up.

This is not a distant issue for me. I have felt, smelt, and shoveled the ghost ice. I have worked with control panels older than me, juggled compressor faults in real time, and debated with managers on the merits of hot- versus cold-water resurfacing. It’s in these personal trenches, with kids on the ice and a wrench in hand, that the crisis and and opportunity of sustainable rinks became clear.

Hockey’s Hidden Cost: The Energy and Climate Challenge

Hockey is a thread in the fabric of North American communities. There are 4,800 indoor rinks in North America, with an average age over 30 years, most built before sustainability featured in facility designs[1].

The core problem? 

Rinks are energy hogs. They are expensive and complicated.  Refrigeration accounts for about 43% of total rink electricity use, with heating, lighting, and humidity control making up much of the rest. The typical older rink burns through 1–1.5 million kilowatt-hours (kWh) each year, releasing up to 800 tons of CO₂e—a climate footprint rivaling small manufacturing operations[2]. 

In many municipalities, rinks account for 20–30% of civic building emissions. For any community promising a “net zero” commitment, rinks are a central challenge and opportunity[2].

For operators like me and rink managers everywhere these numbers are felt every month in utility bills. The idea of  five-figure electric bills in the Upper Midwest, even in the spring, and gas bills that spike in the deep of winter, not from heating the stands but from keeping compressors churning are real.  Get down into the southeast heat or Southwest and California summers and it's even more costly. 


Ghost Ice and the Human Factor

Another rarely discussed challenge is operational inefficiency.  

What some people call “ghost ice”: the invisible layers or variable thicknesses due to cautious but outdated maintenance. Many rinks over-flood between events or struggle with uneven resurfacing, leading to ice layers up to 20% thicker than necessary.

Each extra millimeter of ice not only diminishes the quality of play but increases energy demand by thousands of kWh per season. Case studies estimate a single rink’s excess thickness can waste $50,000 per year...money literally locked in ice and melted away by compressors[2][3]. As a rink worker, the drive is always to avoid “soft” moments or dangerous ridges, but often this leads to overcompensating with water, and in turn, energy loss.


Regulatory Sword: R-22 Phase-Out and the Cost of Delay

There’s a regulatory shadow falling across this landscape. Many rinks still rely on R-22 refrigerant, which destroys ozone and has been regulated out of production in most of North America[2]. Existing stores are dwindling, prices are rising, and in 2030 the final legal loopholes will close. Failure to convert means the risk of fines in the tens of thousands per day, a true existential threat for community-run operations.


A New Era: Green Rinks and Next-Generation Solutions

Turning this crisis into an opportunity is neither science fiction nor a tech utopia; it’s happening today, facility by facility, through bold investments and smarter planning.

Case Study: Great Park Ice — The West Coast Standard

Consider the Anaheim Ducks’ new 280,000 square foot Great Park Ice facility, the flagship for sustainable design in California[1]. Despite high upfront costs, the rink brings together a portfolio of green solutions:

  • Recycled Water
    •  All ice is produced with 100% reclaimed water, reducing potable water demand in drought-prone Orange County.
    • Electric Zamboni
      •  Eliminates the indoor air hazards and fossil fuel use of older resurfacers.
    • EV Charging and Green Design:
      • Parking lots feature extensive electric vehicle charging, and landscaping is drought resistant.
    • High-Efficiency Refrigeration
      • Advanced automation allows precise control of ice temperature and humidity, minimizing waste.


Great Park Ice is a candidate for LEED Silver certification[1][3]. The message for parents and staff is that “green costs more at the start, but pays society back for decades.” I’ve watched my own kids’ tournaments, games and practices here and felt the ice quality—hard, fast, consistent—and noticed how the air smells fresh, not chemical-heavy like the older rinks.


Canada’s Net Zero Cohort: Leading with Community and Data

Canada is setting the global bar for community-driven transition. A recent project brought together seven southern Ontario municipalities to develop real retrofitting roadmaps for their nine most-used rinks[2]. Their findings:

  • Big Impact:
    • Operations alone (training, automation, anti-idling practices) can reduce emissions by 26%. 
    • Coupled with capital retrofits (heat recovery, modern chillers), 85% reduction is achievable
      • up to 99% in best-case scenarios.
  • Real Savings:
    • Each roadmap anticipated savings of over 243 tons CO₂e by 2050 per rink. Collectively, this will eliminate 2,189 tons of emissions.
  • Economic Win:
    • Over a rink’s 40-year life, net-zero upgrades pay back, not just in utility savings, but in lower maintenance, higher occupancy, and community value.


Their method? 

Zero-over-time: use every replacement or capital improvement as a chance to add an energy upgrade. Integrated design and cohort-planning ensured that mistakes and lessons are shared, not repeated[2].


My Zamboni Dream: Sustainability From the Driver’s Seat

Where do I fit in? For me, sustainability is not an abstraction. Every shift on the Zamboni is a learning lab in heat transfer, efficiency, and technology transfer.

  • Water Choices
    • I’ve experimented with both hot-water and cold-water resurfacing. Hot water melts and smooths ice well, but is energy intensive; cold-water systems, now proven at several Canadian sites, do nearly as well with technique and slash gas bills.
  • Ice Thickness:
    • Digital sensors and “smart sticks” are replacing the old coin-on-a-rope method for measuring ice. 
    • I can now ensure we maintain a bare inch—no more, no less—cutting both water waste and compressor run-time.
  • AI and Automation:
    • Early-adopter rinks are turning to digital Building Automation Systems (BAS). 
      • These monitor compressor cycles, forecast weather, and directly control brine temperatures and energy loads for maximum efficiency
      • a quantum leap from the patched-up control panels

Simple changes, backed by data and guided by collective expertise, add up fast. I’ve seen operator morale rise when they receive training and new tools; the pride in maintaining “perfect ice” with a lower footprint is real.


Barriers and Lessons: What Still Gets in the Way?

Progress is slowest when data is incomplete, or when managers and staff fear new techniques might sacrifice ice quality. In the Canadian study, missing blueprints and records created delays[2]. Often there is institutional inertia, if a method worked for 20 years, why change now?

Financially, capital retrofits are daunting. Even with incentives, budget cycles favor crisis response, not prevention. But life-cycle costing is turning the tide: planned, staged upgrades, timed with equipment failure, are vastly cheaper and smarter[2].

Knowledge-sharing is now critical. Webinars, workshops, and peer mentoring are bridging the learning gap. When I get an invite to a “cold resurfacing” demonstration, the learning comes straight from veteran operators, easing mistrust.

Innovation Beyond the Rink: AI, Automation, and New Business Models

Looking to the future, the most exciting area is the integration of AI-driven energy optimization, digital twin modeling, and alternative funding models.

  1. Digital Twins and Predictive AI
    1. SmartICE projects in Canada and advanced automation at Dallas Stars’ facilities in Texas have proven the value of digital twins
      1. virtual copies that can be tested for compressor failure, power outages, or optimization scenarios without risking actual downtime[4][2].
      2.  AI controls can now anticipate peak demand windows and pre-cool at the lowest rates, reaching annual energy cuts of 20–35% and improving operational uptime.
  2.  Community and Web3 Funding
    1. Increasingly, communities are experimenting with tokenized or “community bond” models
      1. enabling families, local businesses, and even global hockey fans to fund sustainable upgrades. 
      2. While still an emerging space, these models, alongside public grants, are unlocking retrofits that would otherwise remain unfunded.
  3. Environmental Social Governance (ESG) as Rink Value
    1. Many municipalities now publicly report on rink emissions, using their successful upgrades as a core plank in broader community climate pledge
      1. a public win that builds stakeholder support for the upfront expenses.


Bringing Sustainability Home: The Future for Hockey Families

For me, rink sustainability is not just about LED bulbs or smarter chillers. It’s about the assurance that my children, and their teammates in Atlanta, San Diego and Orange County, and Edina , St Louis Park, Minneapolis, will grow up with affordable, accessible, safe, and quality rinks[1][2].

It’s also a matter of pride: knowing that our small changes, smart resurfacing, careful thickness management, speaking up for retrofit, contribute to a much bigger movement. When I walk into a rink that smells fresh, hums quietly, and posts energy usage stats above the front desk, I know we’re skating into a brighter future.


Conclusion: One Rink, Many Lessons

Hockey may always be costly, cold, and logistically complex, but it doesn’t have to be unsustainable, or inaccessible. The green revolution in rink technology proves that with the right mix of ambition, data, community, and personal commitment, we can solve this hidden climate challenge, one Zamboni lap at a time[1][2].

As both a parent and a rink worker, every practice becomes a classroom: one where I’m still learning, and sometimes teaching, how to keep hockey’s legacy alive for generations-and climates-to-come.



References:

  • Ducks practice facility incorporates latest environmental technology | NHL[1]  
  • Case Study: Creating a shared path to net zero ice rinks | Green Municipal Fund[2]  
  • Great Park Ice and FivePoint Arena - Irvine Ranch Water District[3]
  • Dallas Stars Ice Skating Rink | Trane Commercial HVAC[4]  


Citations:

[1] Ducks practice facility incorporates latest environmental technology https://www.nhl.com/news/anaheim-practice-facility-incorporates-latest-environmental-technology-306973030

[2] Case Study: Creating a shared path to net zero ice rinks https://greenmunicipalfund.ca/case-studies/case-study-creating-shared-path-net-zero-ice-rinks

[3] Great Park Ice and FivePoint Arena - Irvine Ranch Water District https://www.irwd.com/waterstar-business/great-park-ice-and-fivepoint-arena

[4] Dallas Stars Ice Skating Rink | Trane Commercial HVAC https://www.trane.com/commercial/north-america/us/en/about-us/newsroom/case-studies/community/dallas-stars-ice-skating-rink.html

Wednesday, September 10, 2025

River of Signals: The Silent Crisis of American Maritime Connectivity



From the fog-shrouded shores of the Puget Sound to the endless, muddy artery of the Mississippi , to the mostly peaceful and warm gulf of Mexico and the vast, freshwater seas of the Great Lakes, a silent crisis is brewing. We know this.  We see it.  Nobody really ignores it , but everybody lets it fade into the background. 

The maritime industry, the very essence of American commerce, are facing a communications breakdown. In an age of ubiquitous digital connection, the nation's most vital waterways remain a vast, analog expanse, where reliance on fragile terrestrial networks and decades-old protocols leaves vessels, commerce, and lives at risk.

This is a dystopian reality cloaked in a utopian dream. While the world of technology races toward fully autonomous systems and seamless digital orchestration, our off-grid maritime networks are caught in a time warp. The problem isn’t a lack of desire for innovation, but a fundamental gap in the infrastructure needed to support it. This is a story of a digital divide that separates a futuristic, connected world from the rugged reality of our inland seas.

The Digital Dark Ages on the Water

The challenges are everywhere. On Lake Superior, a tugboat captain navigating through a blizzard has no reliable way to communicate with a remote port manager about a last-minute schedule change. On the Mississippi, a barge moving a critical cargo of grain struggles with spotty satellite coverage, its on-board sensors unable to transmit vital data about its engine's health to a maintenance crew miles downstream.Not even an hour north of Seattle in the Puget sound, a Coast Guard patrol boat can't share real-time position data with a sister vessel, hindering a rescue operation.

Current solutions are a patchwork of insufficient technologies. Satellite communication is expensive, suffers from latency, and is often unreliable in areas with dense foliage or challenging weather. Traditional radio is a limited resource, and its signals don't offer the data-rich capabilities that modern autonomous systems require. 

The result is a system of disconnected silos, where docks, ports, shipyards, and marine vessels operate on their own islands of data, unable to share information with each other in real-time. This isn’t a small problem, it's a critical vulnerability for the small businesses, ports, and individuals who rely on the waterways for their livelihoods.

A centralized, perfect system is a theoretical ideal, but in the sprawling, decentralized chaos of the real world, it's destined to fail. The utopia of a fully connected, autonomous maritime industry is out of reach unless we address the very real, very human-scale problems of connectivity.

But the future isn't bleak. A new wave of startups and innovators are recognizing that the solution isn't to build a new centralized system, but to embrace the decentralized, redundant nature of the waterways themselves. A handful of forward-thinking companies are looking at Web3 protocols and distributed ledger technologies as the foundation for a new kind of maritime infrastructure. Others are knee deep into AI and autonomous robotic vessels.  

They envision a system where every vessel, every dock, and every barge acts as a node in a peer-to-peer network. In this model, tugboats, barges, and merchant marine vessels could use off-grid radio protocols to form a mesh network, relaying data from one vessel to the next.

This system would be anchored to a blockchain, where every critical piece of information starting with a ship's manifest, a sensor reading, a crew member's badge information and it's all cryptographically signed, timestamped, and made verifiable. This digital twin of a mission or a cargo's journey would be stored on-chain, creating an unassailable record. This offers a path toward a verifiable, resilient, and unstoppable communications fabric.

The dream is to transform the maritime industry from a loose collection of independent actors into a cohesive, intelligent network. Ports would have real-time visibility into incoming cargo. Shipyards could receive automated alerts about a vessel's maintenance needs. And most importantly, the Coast Guard could have a persistent, real-time map of all vessels in a given area, enhancing safety and response times in emergencies.

A Call for a New Navigator

The path forward requires a new kind of navigator and philosophy.  It's not just a captain or sailor, but an innovator who understands both the harsh realities of the water and the boundless potential of decentralized technology. This is a call to action for small businesses, ambitious startups, and established ports to look beyond the limitations of centralized systems and invest in a future built on redundancy, verifiability, and community-owned infrastructure. The sea is a realm of unforgiving chaos, but with a new digital compass, we can finally steer our way into a hopeful and connected future.


Friday, May 9, 2025

AI & medical devices and the future

In the sterile fluorescence of hospital corridors and the quiet hum of machines that promise life, a new yet old player has entered the stage: artificial intelligence.  The hype behind genAI and LLMs as well as the ever change nature of NLP, neural networks, deep learning , machine learning and more has been eaten by the dream of genAI and LLMs and RAGs. 

 The U.S. Food and Drug Administration (FDA) stands at the forefront of this technological revolution, embracing AI in both its internal processes and the medical devices it approves. Yet, as with all revolutions, this one is fraught with both promise and peril. 

Healthcare has always been a few steps , a few decades behind.  It is the nature of the beast.  But even they cant escape the hope, dreams And allure of AI in Medicine and medical devices and drug discovery. 

AI's potential in healthcare is undeniable. From assisting in diagnosing abnormalities in radiological imaging to predicting disease progression, AI-driven tools offer the promise of enhanced efficiency and accuracy and far more intelligent automated processes and tools in patient care. The FDA's recent completion of its first AI-assisted scientific review pilot underscores this potential, with officials noting significant reductions in review times for new therapies .

Moreover, the agency's initiative to deploy AI tools across all its centers by June 30, 2025, signals a commitment to integrating AI into the very fabric of medical regulation . This move aims to streamline processes, reduce repetitive tasks, and accelerate the approval of new medical interventions.  But is it more hype and bias vs real change. 

There are now people who pretend data don't matter. You have tech folks selling synthetic DNa sampling is better than real DNA data. Others promote the idea of synthetic and manipulated radiology x-ray data scans.  

The shadows in the Data and it's almost always swampy chaos run amok with extreme bias and controversy yet often ignored.  

With all this being said , ignoring quality real dads will be the death of these new movements or the death of real human beings and animals 

A perfect example of this philosophy lies far beneath the surface of these medical devices and systems and AI automation projects and agentic agents. A comprehensive analysis of over 500 FDA-approved AI medical devices revealed that approximately 43% lacked reported clinical validation data . Some devices were even validated using computer-generated images rather than real patient data, raising concerns about their effectiveness in real-world clinical settings. 

This gap in validation not only undermines the credibility of these devices but also poses potential risks to patient safety. As AI tools become more prevalent in critical diagnostic and therapeutic roles, the absence of rigorous clinical testing becomes a glaring oversight.

In an effort to address these concerns, the FDA has introduced amendments to its Quality System Regulation, aiming to harmonize U.S. standards with international benchmarks . These changes are designed to ensure that medical devices, including those powered by AI, meet stringent quality and safety requirements. 

Yet, the rapid proliferation of AI technologies challenges traditional regulatory frameworks. The FDA's finalized recommendations to streamline the approval process for AI-powered devices, allowing manufacturers to update their products without resubmitting documentation, reflect an attempt to keep pace with technological advancements . However, these guidelines are not legally binding, leaving room for variability in implementation. 

Despite AI's capabilities, the human touch remains irreplaceable in medicine. AI tools can assist in diagnosing conditions like skin cancer, but they lack the nuanced understanding that comes from direct patient interaction . Moreover, concerns about AI's ability to accurately assess diverse populations persist, emphasizing the need for inclusive and comprehensive training data. 

The integration of AI into healthcare must be approached with caution, ensuring that technological advancements do not outpace ethical considerations and patient safety. 

The intersection of AI and medicine presents a landscape of both opportunity and challenge. While the FDA's initiatives signal a forward-thinking approach to integrating AI into healthcare, the lack of rigorous clinical validation for many AI-powered devices raises critical concerns. As we navigate this new frontier, a balanced approach that marries innovation with stringent oversight is essential to safeguard patient well-being and maintain public trust.

Saturday, February 8, 2025

The Code Inscribed on the Stone of Time

 

It's a simple Ballad of Memecoins and Bitcoin Ordinals, for the Age of Machines...


The chains hum beneath the weight of numbers,

A ledger vast as the oceans cold dark abyss,

Each satoshi, carved with symbols, whispers ...

Whispers into the night,

Cries during the day ...

The Ordinals speak, but do they listen?


And then something, someone, down the river hearing fire and rain , singing simply tonic methodology ...

They began as jesters, dog-faced and grinning, Cat eyes and playful...

A joke told too many times, until laughter turned to gold.

Dogecoin, a shrug against the bankers,

Shiba Inu, a dream of the decentralized street.

But behind the flashing gifs and roaring tweets,

A deeper code unfolds,

Memecoins teach the machine to read intent—

To scrape the sentiment from digital crowds,

To open up the future of futures,

To taste the market’s fevered pulse

And dance before the crash.

Or songs singing in the digital rain clouds. 


Could they train the models, or could AI inspired creative fantasy across digital and physical realms...

These viral echoes of human whim?

Or something sinister?

Maybe just a fun plot for the masses. 

Could a memecoin-backed network

Feed an LLM a diet of unfiltered,

Unwashed, raw cultural madness,

And teach it humor, folly, risk even creativity ?


Then came the Ordinals, whispering permanence,

Marking each satoshi like monks etching prayer wheels,

No longer mere transaction, but memory, creativity, hope and desire.  

A ledger that forgets nothing, creates anything... everything. 

Ethereum carved its art in contracts,

A mutable scripture,

Bitcoin now inscribes its ghosts in the chain,

A permanent gallery of digital creative  relics,

Untouched by time, unswayed by humanity 

And what if the machines could read these, think on them , analyze them, love them ?

What if LLMs trained not just on words,

But on the cold, immutable past lives , 

A data-layer of eternal truth?

A network where AI sees provenance,

Knows not just the what, but the who, how , when, and most importantly, the why—

A generative mind that traces back its own roots, creating its own future and legacy,

Sees the first token inscribed in 2023

And understands history as it was coded,

Not rewritten. Not fantasy. 

A Future Chiseled in Code

The memecoins teach the machines to dream, to love, to hate. 

To guess at the market’s beating heart.

The Ordinals teach them to remember,

To hold time in a satoshi’s weight.



And somewhere between speculation and permanence,

Between the laughing currency and the sacred stone,

A future unfolds, cold and electric—

Digital and physical...

Where LLMs do not just generate,

But understand.

And create. 

Wednesday, April 17, 2024

Fortifying the Cyber Frontier: Safeguarding LLMs, GenAI, and Beyond

In the ever-evolving world of cybersecurity and infosec, the convergence of cutting-edge emerging technologies like Large Language Models (LLMs), Generative AI (GenAI), vector databases, graph databases, and LangChain presents unparalleled opportunities alongside formidable challenges.

Understanding the Complexity of LLMs and GenAI

Large Language Models (LLMs) and Generative AI (GenAI) have transcended their novelty status to become pivotal pillars of technological advancement. However, beneath their facade of innovation lies a labyrinth of vulnerabilities, bugs, and ethical quandaries, waiting to be exploited by both malicious and non-malicious actors.

Exploring the Spectrum of Attack Vectors and Vulnerabilities

In the realm of LLMs and GenAI, the threat landscape is vast and varied. From prompt injection and model poisoning to adversarial attacks and data manipulation, vulnerabilities abound, posing risks such as misinformation propagation, data breaches, and algorithmic biases. But the dangers extend beyond the obvious; insecure output handling, data leakage, compromised model performance, and network bandwidth saturation are among the lurking threats. These vulnerabilities and attack don't even include the hallucinations that happen by default

Securing LLMs and GenAI: Best Practices and Strategies

To safeguard LLMs and GenAI against the myriad of threats, organizations must adopt a holistic defense in depth and security and privacy by design with the shift-left philosophy approach to LLM cybersecurity, addressing both technical and operational aspects.

Threat Modeling for Large Language Models (LLMs) and GenAI Systems: A Comprehensive Guide

Threat modeling emerges as a cornerstone of cyber defense, empowering organizations to preemptively identify, assess, and mitigate potential risks. By meticulously analyzing system architecture, data flows, source code, AI models, open-source models, and data repositories, stakeholders can anticipate vulnerabilities and deploy proactive countermeasures.

—————————————————————Frameworks for Effective Threat Modeling

  • FAIR (Factor Analysis of Information Risk): Quantifies risk and assesses the impact of threats on LLMs and GenAI systems. Through asset identification, threat analysis, risk assessment, and mitigation strategies, FAIR equips organizations to prioritize and address security concerns.

    • Asset Identification: Identify critical assets related to LLMs and GenAI, such as trained models, open-source models, data repositories (public and proprietary), and APIs. Understand the value and impact of these assets on the organization.

    • Threat Analysis: Assess potential threats specific to LLMs and GenAI, considering factors like prompt injection, data leakage, and model vulnerabilities. Quantify the likelihood and impact of each threat.

    • Risk Assessment: Apply FAIR's risk measurement scales to evaluate the overall risk associated with LLMs and GenAI. Consider factors like data quality, model performance, and system architecture.

    • Mitigation Strategies: Develop countermeasures based on risk assessment results. Address vulnerabilities through secure coding practices, access controls, and monitoring.


  • PASTA (Process for Attack Simulation and Threat Analysis): Adopts an attacker's perspective to comprehensively evaluate threats. By focusing on asset-centric approaches, threat modeling, risk prioritization, and mitigation strategies, PASTA enables organizations to simulate attacks and validate defenses.


    ——————————————————————

Cybersecurity for LangChain: Protecting the Next Frontier

LangChain, an open-source framework for LLM-powered application development, introduces its own set of security considerations. From chaining LLMs to code analysis and secure development practices, LangChain demands a tailored approach to threat modeling and cybersecurity.

Mitigating Risks with Advanced Security Measures

A multi-layered approach to cybersecurity is paramount. Stringent access controls, robust encryption mechanisms, continuous monitoring, and regular security updates are indispensable components of a robust security posture.

Challenges and Opportunities in the Age of GenAI

The rise of Generative AI brings both promise and peril. While GenAI unlocks unprecedented creative potential, it also introduces risks such as deepfakes, synthetic media, and algorithmic biases. By embracing advanced threat modeling techniques, organizations can harness the transformative power of GenAI while mitigating its inherent risks.

Embracing a Future of Resilience and Innovation

As we navigate the dynamic cyber frontier, one thing is certain: the journey towards resilience is ongoing. By fostering collaboration, innovation, and vigilance, we can secure the promise of LLMs, GenAI, and emerging technologies for generations to come

Monday, April 8, 2024

The Silent Pandemic: Cybercriminals Infiltrate Hospital IT Help Desks, Exploiting Trust and Wreaking Havoc

In the shadows of the digital landscape, a new breed of predator has emerged, preying upon the very institutions we rely on in our most vulnerable moments. The U.S. Department of Health and Human Services (HHS) has raised the alarm, warning hospitals across the nation of a chilling trend: hackers targeting IT help desks with ruthless precision and devastating consequences.

These faceless criminals, cloaked in the anonymity of cyberspace, have set their sights on the beating heart of our healthcare system. Employing social engineering tactics with surgical precision, they exploit the trust and urgency that define the relationship between medical staff and their IT support teams. By impersonating employees, often from financial departments, these malicious actors manipulate unsuspecting IT personnel into granting them access to the very systems designed to protect patient data and lives.

There used to be a variance of a ‘do no evil’ like code amongst hackers and life and death systems were sort of off limits or avoided.  How the times have changed.  There were always outliers and nefarious actors , but now the nefarious seem to outweigh the curious.  

The new trademark  is as insidious as it is effective. Armed with stolen identity verification details, including corporate IDs and social security numbers, the attackers weave a web of deceit. They claim their smartphones are compromised, convincing IT help desk staff to enroll new devices under the attacker's control for multi-factor authentication (MFA). This seemingly trivial action opens the floodgates, granting cybercriminals unfettered access to sensitive data and critical systems and much more.

Once inside, the consequences are nothing short of catastrophic. Business email compromise attacks redirect legitimate payments to attacker-controlled bank accounts, siphoning millions of dollars from already strained healthcare budgets. Worse still, patient data is held hostage, encrypted by ransomware like the notorious BlackCat/ALPHV strain, which has been linked to over 60 breaches in just four months.

The human cost is immeasurable. When medical records vanish into the digital void, when life-saving treatments are delayed by frozen systems, when the trust between patients and providers is shattered – the true toll of these attacks becomes clear. It is not just financial loss, but the erosion of the very foundation upon which our healthcare system is built.   And for many places, including the US, people already have a love hate relationship with hospitals, doctors , healthcare insurance providers and the like. 

The HHS's warning is a clarion call to action. Hospitals must fortify their defenses, not just with cutting-edge cybersecurity measures and intrusion detection systems while thinking in a more  proactive long term , big picture threat modeling philosophy and with a culture of vigilance and training. 

IT help desks, SOC, small red, white , blue , yellow , green security teams on the front lines of this digital war, must be hardened against infiltration. Staff and patient’s must be trained to recognize the telltale signs of social engineering, to verify caller identities through callbacks and in-person requests, and to monitor for suspicious changes to financial systems.

Even as we bolster our technological and security defenses, we must also confront the uncomfortable truth that our adversaries are not just lines of code or faceless email addresses. They are human beings, driven by greed, desperation, or a twisted sense of power. To truly combat this threat, we must address the underlying social, economic, and psychological factors that give rise to such malevolence.

The battle against cybercriminals targeting hospital IT help desks is not just a fight for the security of our data – it is a struggle for the very soul of our healthcare system. It is a battle that will be waged not just in server rooms and boardrooms, but in the hearts and minds of every person who has ever sought healing within those hallowed walls.


As we stand on the precipice of this new era, we must recognize that our greatest weapon is not just technology or processes, but the unwavering commitment to protect the sacred bond between patient and provider. By fostering a culture of compassion, support, and unyielding vigilance, we can inoculate ourselves against the very vulnerabilities that make us targets.

The silent pandemic of cybercrime targeting hospital IT help desks is a threat we cannot ignore. The price of failure is measured not in dollars, but in lives and trust. It is a price we cannot afford to pay, for the future of our healthcare system and society hangs in the balance.

The Infrastructure Disappears. The Relationship Remains.

My kids play video games.  Sometimes too much. It used to be Roblox and Minecraft and then Fortnite and who knows what else as they gravitat...