Matthew Gamble's Blog
M

Matthew Gamble

Reflections by Matthew Gamble

Hard Conversations

The Ice Cream Invitation Problem

Earlier this week I was at the mall with my friend "Dave" (not his real name), shoe shopping. The reason we were at the mall isn't important, but it sets the scene. We left the shoe store, Dave turned...

ai

Did I Just Talk to a Person?

Over the weekend I had to call a plumbing service. Tenant had a broken toilet, bad timing, the usual Saturday night special. Like most after-hours services, I didn't get connected to a plumber. I got...

Security

Stop Weaponizing CVE Counts

I've watched many teams score vendors on raw CVE counts. Not on response times, not on disclosure transparency, not on architectural controls. On the number of CVEs. I've seen it first-hand, in the...

Security

The Security Mindset Problem

Security requires a particular mindset. Security professionals (at least the good ones) see the world differently. They can't walk into a store without noticing how they might shoplift. They can't use...

code

Welcome to Conduit (new blog engine)

If you're reading this, you're looking at a completely rebuilt blog. Not a theme change. Not a migration. A from-scratch rebuild of everything – the content system, the search, the social layer, and...

code

When Critical Isn't Critical

Last week I was reviewing a vulnerability scan report for a client when something caught my eye. Buried in a list of "critical" findings was a Log4j vulnerability - you know, the one that broke the...