Friday, August 21, 2026

ZKP for medtech and medical devices?

 

The medtech space is fascinating.  It used to be bolt on security and worry about it later. Some of that philosophy has changed , the FDA made regulations and compliance more mandatory and less checkbox assessments and governance non technical advice, but still , many challenges remain.  

What about trying to implement ZKP or homomorphic encryption into medical devices or embedded instruments?   Even Post Quantum security techniques merging techniques that crypto and blockchain have researched, Google has written some white papers on and cryptographers are testing ?

Looking more into medtech and how a lot of medical devices generate far more sensitive data now , and across a system of parties with different trust relationships is a growing concern. Think about what a medical device actually is now vs just some pacemaker.  They are a medical device, gateways,  hospital network, patient phone and network, cloud infrastructure, analytics platforms, providers, payers, and regulators. 

The problem is not simply protecting the device. It is deciding what each party can see, what each party can verify, and what happens when those trust assumptions change.  And devices may send electrical or other signals now not just Bluetooth connectivity. 

Conventional controls handle much of the foundation. Secure boot, signed firmware, hardware roots of trust, device identity, attestation, and authenticated communications establish device and software integrity. That trust chain begins long before deployment.  You have  factory provisioning of device credentials and keys, boot ROM and hardware root of trust integrity, and contract manufacturing custody that  determine whether the root of trust is valid from the moment the device is powered on. 

If the requirement is simply proving that a device is running approved firmware, a signed measurement is generally more appropriate than a zero knowledge proof.  We do assume manufacturing is trustworthy and not installing software or hardware backdoors. Should we though ?

Once deployed, a gateway may act as a transparent relay or, if local protocol translation or edge processing is required, as a plaintext trust boundary. The security problems diverge once data leaves the device. Homomorphic encryption can allow certain cloud computations without exposing the underlying plaintext to the compute environment, but its practical use remains limited to workloads where the performance and complexity are justified. 

It is not a solution for most real time physiological telemetry. Zero knowledge proofs address a different problem entirely.  Proving a defined claim about private data without disclosing the data itself. Neither technology establishes that a sensor measurement reflects physical reality. An attack against an analog sensor interface can alter a measurement before software or cryptographic controls ever see it.

That distinction matters because medical device security has different consequences. A confidentiality failure can expose protected health information and create regulatory and legal risk. An integrity or availability failure can affect a clinical decision or interrupt therapy. The controls, threat models, and acceptable failure modes are not the same.

The fifteen-year lifecycle compounds these risks. Cryptographic algorithms can be deprecated, keys can be compromised, standards can change and regulatory requirements can evolve. But the hardware ages too. Memory retention, component degradation, sensor drift, clock accuracy, physical tampering, side channel attacks, and limited processing, storage, and battery capacity can constrain what security changes are actually possible.  And who knows the more AI is pushed what else becomes a vulnerability.  

Cryptographic agility therefore cannot mean simply having the ability to install a new algorithm. The device has to have enough hardware capacity to support the migration, enough storage for recovery mechanisms and alternative trust material, and an update architecture capable of delivering the change. 

Maybe we need to look at how the Voyager spaceships still operate and can be updated and fixed after 40+ years.  And nobody can actually go land on the ship and change or fix it. Different use case but learning from that engineering philosophy may go a long way for medical devices and AI. 

 A medical device without reliable access to its trust infrastructure creates another problem.  A revocation and key replacement may not be available when needed. When trust anchors fail, the system requires defined safety-state policies such as graceful degradation to standalone operation. A security mechanism that bricks a safety-critical device is an unacceptable failure mode.

Regulation adds another constraint. A manufacturer can engineer for change, but a cryptographic modification can affect verification, validation, documentation, and the approved configuration of the device. Meanwhile, the manufacturer does not control every trust boundary. Cloud providers, EHR vendors, certificate authorities, network operators, and other third parties can change infrastructure and trust relationships independently.

The real design question is therefore not which cryptographic primitive to choose. It is which security assumptions are controlled by the manufacturer, which are delegated to third parties, how those assumptions can change over the device lifecycle, and what happens when they fail.

Which parties are trusted with plaintext? Which only need a verifiable claim? Which computations must remain confidential even from the infrastructure executing them? What happens when a key is compromised, a device is offline, hardware degrades, or a security update conflicts with clinical safety?

A long-lived medical device needs more than cryptographic agility. It needs a security architecture that can evolve without turning a change in the security environment into a change in patient safety.

The future is bright. It's also challenging. 

Thursday, August 20, 2026

Supply chain attacks and genAI

Many executives and leaders still treat AI tools as plug-and-play; buy it , trust it, install it, connect it, use it , automate it, scale it. 

That assumption is becoming a liability. A huge one.

The LiteLLM supply chain attack in March of this year (2026), exposed exactly this philosophy. Attackers didn't need to breach their targets directly. They compromised a trusted security scanner inside a development pipeline, used stolen credentials to distribute poisoned software updates, and gained access to cloud keys, Kubernetes secrets, and live AI provider credentials across corporate environments. The front door was never touched. It wasn't even knocked on in a sense. 

The same principle applies to attacks on municipal water systems. You don't have to breach the facility itself when you can compromise a trusted management interface and control what sits behind it. And some of these city and county water and wastewater management systems have old PLC and other technology that was never supposed to be connected. Never designed for it.  

AI platforms create a similar choke point. They connect companies to dozens of services, so compromising one trusted dependency can provide access far beyond that single system.

Yet many organizations still rely on periodic audits, vendor trust, and reactive credential rotation. They rely on MVP products sold as GA v1 enterprise ready and aren't even close. But not everybody vettes these or vendor politics at play so forced onto teams and employees. That security model was built for a threat environment that no longer exists.

Every external software update should be treated as an unverified artifact until its provenance is established. Zero trust to the extreme. Supply chain attacks, at scale, should be a priority.  

Every centralized access layer should be treated as an elevated-risk target requiring continuous logging and monitoring.

The executives and leaders who understand this aren't treating cybersecurity as an IT cost center. They're treating digital infrastructure like any critical supply chain; with verified provenance, real-time visibility and zero assumption that something is safe simply because the package carries a familiar name.

This blog and description has more details about that liteLLM hack back in March.

liteLLM Hack March 2026



Saturday, August 8, 2026

The amateur was bad

 The Amateur movie review on medium


I watched the movie , 'the Amateur' last night. Saw the trailer before, poking through Amazon prime and it was free, so figured why not. 

The premise was interesting even though it's been done a thousand times over.  Revenge. Fish out of water. Conspiracy. Second guessing.   Why not give it a shot. I remember thinking the trailer looked promising and some big names in the movie.  A few actors who have shown they make movies better than they should have been in the past.  Worth it. 

What a bad movie though.  The premise, again, interesting enough with a catch,  as the guy isnt Jason Bourne or some MMA ex military tough guy. A lot of the Mr. nice guy but was a former seal or secret agent troupe is overdone and kind of annoying. So at least it wasn't that. 

But it was like they took some of those movie ideas Jason Bourne like premise and then thought hey let's get the guy who played Mr Robot as a hacker to be this bored analyst with a revenge plot.  And it started early. Demands. Weird situations. World travel. Unlimited money. Random secret hacker like friends. It was like they had a room full of writers using chatgpt and throwing anything and everything and why not. Let's do that. 

It was slow. But no real build up to care. That's the worse for a show or movie. Slow buildup but too quick where you have no connection to any of these people or story. It's like some bad Saturday night live satire sketch that wasn't funny or dramatic or serious and the comedians just going through the motions. Or they brought in some big name who isn't exactly a great actor and it falls flat. 

The common Hollywood troupe of computer geeks and hackers is always annoying.  The Amateur though, he wasn't even a hacker. CIA threat intelligence analyst who seemed to have certain clearances and relationships, but macgyver like traits, breaking bad Walter chemistry knowledge, Jason Bourne like revenge and connections, Mr Robot like hacker skills and it was just ridiculous and annoying. 

  I wonder if it even gets made or winds up lost and hardly watcher if they casted someone else to be the lead. Casting directors probably thought, "hey he was a hacker in Mr Robot" let's get Rami. it was good casting to get the guy who played an intelligent hacker in a somewhat successful show to play the lead. 

So let's go with the CIA like threat intelligence analyst in the basement who is somewhat of a hacker.  Somehow all that intelligent mindset was lost as he's using credit cards , IDs given to him by the CIA,  knows they can track him, knows he's basically committing treason and being targeted and his boss director  will have it out for him.  It was really like chatgpt wrote the movie with no context and everybody thought, hey this sounds cool.   I understand the nature of stress , fish out of water, and he's in over his head but all the build up was too slow but too quick and the overall revenge played out more ridiculous than the next. 

Jason Bourne has many plot holes and points but at least the idea he was getting revenge, figuring stuff out and one bad mofo was legitimate. Even in Mr Robot , he was a hacker out to get shady bad guys and then conspiracy to the extreme, there was still some semblance of suspension of belief where some of to makes sense and you understand.  

The Amateur. It was so bad. 

Saturday, August 1, 2026

Flock needs a VP

 

Interesting after all the uproar and media buzz , flock has a VP of Product opening. Wonder if someone had enough and quit or the environment and culture is playing out in different circles and is at an inflection point.    It'll be interesting to follow and see what leader they wind up hiring for this and how things change or stays the same .



The posted job JD


"

VP Product

The Problem

As Flock expands into new markets and use cases, scaling our portfolio across hardware-enabled infrastructure, firmware, and cloud software requires dedicated executive product leadership. Maintaining product differentiation and earned trust across complex technology layers demands a strategic leader who can align engineering execution with long-term business goals. You will lead end-to-end product strategy across core product lines, mentor product managers, and represent our technology with clarity to cross-functional partners and external stakeholders.


What You'll Own

Lead end-to-end product strategy and execution for a multi-layered portfolio spanning cloud software, firmware, and hardware systems.


Direct and develop a team of Product Managers responsible for driving core product areas from initial roadmap conceptualization to market execution.


Partner with Engineering leadership to align product roadmaps with technical architecture, platform evolution, and delivery capabilities.


Translate customer needs, competitive dynamics, and market signals into prioritized product roadmaps that balance innovation, system reliability, and speed to market.


Represent Flock's product portfolio and guiding development principles in high-stakes external conversations with customers, partners, and public stakeholders.


What This Role is Not

This isn't a hands-off corporate strategy position, you will actively engage with engineering teams on technical tradeoffs and dive deep into product architecture.


This is not a single-product or software-only role, you will oversee an integrated portfolio combining hardware devices, firmware, and cloud platforms.


This isn't an isolated internal management function, you will serve as an external product spokesperson who can explain technical systems clearly to diverse audiences.


What You Bring

Proven track record leading and growing complex, multi-layered technology products across software platforms and hardware-adjacent systems.


Strong product judgment with the ability to prioritize effectively across competing demands and incomplete market information.


Demonstrated experience developing and managing product managers to drive cohesive execution across distinct product lines.


Capability to partner deeply with Engineering on platform architecture, technical sequencing, and development tradeoffs.


Clear executive communication skills with the ability to represent complex product capabilities to non-technical external stakeholders.


Compensation

In this role, you'll receive a starting salary between $280,000 and $300,000 as well as Flock Stock Options. Base salary is determined by job-related experience, education/training, as well as market indicators. Your recruiter will discuss this in depth with you during our first chat.


Why Flock

Every community deserves to be safe. Flock builds the technology that makes that real: last year we supported over 1 million criminal investigations and helped locate more than 10,000 missing people. We're 1,700 people building the impossible with over $1B in funding, and the expectations are high on purpose. If you want a role where the stakes are real and the pace matches, this is it.


Some problems get solved faster in the same room, so we prioritize candidates in Atlanta and Boston. Hub-based roles mean real in-person time with your coworkers. Remote roles exist, and when a posting is open to remote work, it says so.


Building the impossible takes every kind of mind. Flock is an equal opportunity employer, and we know the best solutions come from diverse perspectives, experiences, and skills working together with mutual respect

"



Definitely will follow this.



Thursday, July 30, 2026

Water systems challenge in Minnesota

 Water supply systems Minnesota

US blaming Iran

"Officials are investigating after a cyber attack targeted water systems in several Minnesota cities, but they say there is no threat to the drinking water. FOX 9's Bill Keller reports."



These old public utilities, parks and everything government related have a lot of old tech, forgotten about tech and maintained by a few people overworked and overextended who aren't IT or cybersecurity or OT individuals. Nor should be but it's easy to just say system is flawed and blame certain folks.

Sunday, March 1, 2026

Ice Rinks: The Reality Behind the Surface

 Ice Rinks: 

The Reality Behind the Surface

Guides , manuals, blogs , video's , old heads will tell you ice should be perfect. Thin. Level. Precise. But made to last and think long term not just short term. Especially old barns. 

In reality, most rinks don’t get that luxury. There isn't the time , patience , experience or equipment for all that.  The ice needs to be 1.5 inches thick or more to survive a day of high school games, beer league, clinics, and youth camps and games and part time temporary zamboni drivers

The people maintaining it are often part-timers. Ten minutes to cut and flood. Not really flood. Temperatures fluctuate. Old compressors wheeze. Pipes leak. Water quality varies. HVAC systems are aging, sometimes broken. You learn quickly that “ideal” ice is a fantasy.  And many people don't even care unless it's really bad. Or the locker rooms and bathrooms are a mess , then they start chomping about ice quality too. 

Every day, someone adjusts on the fly: adding water, watching the cracks, watching the puck slide differently depending on the morning temperature, last night's usage and the days schedule. It’s improvisation, judgment, and experience. And yet, somehow, the ice holds. Mostly. Even when it doesn't and the paint starts peeling or looks too bright , deep, dark its more about flooding , light cutting and get it back to 1.5. Somehow, games are played, practices happen, kids learn, and adults compete. Day after day, night after night, week after week, month after month and year after year. Mostly. 

Ice maintenance isn’t glamorous. It’s sweaty, precise, repetitive, and unforgiving. Ice depths can be as simple as a drill , pen and paper and a metal depth ruler. It requires attention to detail, patience, and an understanding that conditions change with every hour. It’s like life; rarely perfect, often frustrating, but always moving forward.

Sports technology can help. Sensors, analytics, monitoring systems add visibility, consistency, and insight. But no tech replaces judgment. And a lot of the tech was built by people who never played or stepped on the ice or drove a zamboni.  But that's silicon valley and tech startup culture.  Many never actually care about the customer much less spent any time actually getting to know the day to day and week to week and pain points.  AI replaces experience, but it doesn't. The rink survives because people care, notice, and adapt. That grumpy old Zamboni and rink operator actually cares about the rink, the ice and hockey, figure skating, sled hockey , broom ball, skippyball, boot hockey, curling and more. 

So when you step onto the ice, remember: there’s a world beneath the surface. One layer of frost at a time. And sometimes, that’s enough.





Saturday, February 28, 2026

Linkekdin has become a joke

 You open LinkedIn and everybody is posting about square and block and Jack laying off 40% of his workforce.  It sucks.  Its sad. It's blaming AI again. But linkekdin has become this click bait useless platform where recruiters proclaim the market is back and everybody is hiring and that AI isn't replacing everybody.  

You have other's post random quotes and stories like Olympic Men and women won gold , here is how that relates to NOTHING. It's just stupid posts. Tons of AI junk content. Recommendation that show linkekdin can't do recommendations right.  

And finally everybody jumping on some guy like Jack posting lay offs and AI and why this or why that. It's like who asked.     And oh yeah they all ignored that block shares went up right after the announcement. Guess Jack and his buddies made out. 

ZKP for medtech and medical devices?

  The medtech space is fascinating.  It used to be bolt on security and worry about it later. Some of that philosophy has changed , the FDA ...