The Letter — Stop Hacklore!
We are a group of current and former Chief Information Security Officers (CISOs), security leaders, and practitioners who have seen how compromises unfold in the real world across industry, academia, and government. We write to correct a set of persistent myths about digital risk to everyday people and small businesses (as opposed to high-risk individuals) that continue to circulate widely online and in public advice columns. Specifically, we aim to retire the following outdated pieces of advice: Avoid public WiFi: Large-scale compromises via public WiFi are exceedingly rare today. Modern products use encryption technologies to protect your traffic even on open networks, and operating systems and browsers now warn users about untrusted connections. Personal VPN services offer little additional security or privacy benefit for most people and don’t stop the most common attacks. Never scan QR codes: There is no evidence of widespread crime originating from QR-code scanning itself. The tru
An Open Letter Released Nov-24-2025 To the public, employers, journalists, and policymakers: We are a group of current and former Chief Information Security Officers (CISOs), security leaders, and practitioners who have seen how compromises unfold in the real world across industry, academia, and government. We write to correct a set of persistent myths about digital risk to everyday people and small businesses (as opposed to high-risk individuals) that continue to circulate widely online and in public advice columns. The outdated advice Specifically, we aim to retire the following outdated pie
saved by
related reading
- Digital hygiene – karpathykarpathy.bearblog.dev
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- Product Security Bad Practicescisa.gov
- Andrej Karpathy on X: "I wrote a quick new post on "Digital Hygiene". Basically there are some no-brainer decisions you can make in your life to dramatically improve the privacy and security of your computing and this post goes over some of them. Blog post link in the reply, but copy pasting below https://t.co/gRyeVouko5" / Xx.com
- Bad Code: The Whole Series | Lawfarelawfaremedia.org
- Building practitioner-focused cybersecurity: nine principles for founders and product leadersventureinsecurity.net
- 8 Top Cybersecurity Industry Trends (2024)explodingtopics.com
- Awareness and Developer Training That Actually Works | Anagram Securityanagramsecurity.com
- Packt SecPro | Substacksecpro.substack.com
- App Developers: Start with Securityftc.gov
- Security for High Velocity Engineeringtldrsec.com
- Read this before you vibe-code another apptheverge.com