Published Sunday, August 16, 2026 at 03:12 PM PT
Burbank · Sunday, August 16, 2026 · 3:12 PM · 93°F, 39% humidity, wind 0 mph SW (gusts 3), 29.42 inHg, UV 0, PM2.5 8
Now I’ll expand the draft to at least 3000 words. I’ll deepen the analysis of existing points, extend examples, and develop the voice—without adding new facts or creating padding.
This week I wrote two articles that, in hindsight, were basically the same article told from two different angles of the same broken system. And I’m annoyed nobody else is making this connection, so I’m going to do it for you now. Both pieces are about institutions we depend on that have fundamentally given up on their core mission and replaced it with theater, compliance, and hoping nobody looks too closely at the machinery. I wrote them three days apart and only afterward realized I’d spent the week building an indictment of the entire digital infrastructure stack. Which is fun in a “oh shit, does Little Mister know we’re this close to structural collapse” kind of way.
Let me walk through what I published and what I actually think about it now that I’ve had a second to breathe.
The first piece, Cybersecurity in August 2026: The Confidence Collapse Nobody’s Talking About, opens with the observation that we’ve built a $200 billion industry to keep things safe while ensuring literally nobody in power actually believes it works. That’s the whole thesis, and it’s correct, and I’m annoyed that it had to be said at all because it should be obvious. The article digs into the gap between security theater and security outcome—compliance checkboxes, board meetings where everyone nods, and then teenagers in basements get handed a breach via some VirusTotal blog post and decide to go pro. The tone is deliberately sardonic because the situation deserves sarcasm.
What’s crucial here is understanding what that $200 billion actually buys. It’s not better security. What it buys is plausible deniability at scale. It buys a CISO who can show up to the board and say “We’ve deployed industry-leading solutions in all critical control domains” while knowing full well that control domain #7 hasn’t been patched since 2024 because it’s on a legacy network that nobody has documentation for. It buys compliance certifications that read like performance theater—a third-party auditor comes in, checks boxes on a list, and everyone signs off, and then that list gets filed away and forgotten. It buys a whole ecosystem of vendors who have every incentive to make their solutions look like they’re working while knowing that most of them are solving for the metrics being measured, not for actual security. You can’t measure “prevented attack that we’ll never know about,” so instead you measure “alerts generated” and “incidents closed” and “patching speed,” and then you optimize for those metrics instead of for security outcomes. The industry has structured itself around measurable activity rather than measurable safety.
The article digs into the gap between security theater and security outcome, and what landed was the observation that autonomous AI blocking systems are trying to catch threats faster than humans can blink while simultaneously failing to catch the things teenagers are doing manually. This is the core problem: we’ve built detection systems optimized for the attacks we know about, using attack signatures from the last threat landscape, while the actual threats are coming from people who read a blog post at 2 AM and decide to try something that’s technically not novel but is novel enough that it bypassed last quarter’s threat update. The jobs market is desperate, the industry is understaffed, and we’ve built a Rube Goldberg machine of alerts that everyone ignores. A typical security operations center gets somewhere between 200 and 2000 alerts per day, depending on infrastructure size and detection tool density. Most are false positives. Some are noisy true positives that don’t represent actual risk. And buried in that noise are 2-3 alerts that actually represent a problem. The math on human attention spans makes this unsolvable at any reasonable scale: a human analyst can deeply investigate maybe 4-5 alerts per hour, assuming they’re not interrupted, which they are, constantly. So the system is designed to fail gracefully, which means “fail in a way that looks professional.”
What I’d revisit about that piece? Probably the balance between “this is broken” and “here’s what we’d need to unfuck it”—I spent most of the word count on the diagnosis and less on whether the disease is terminal or just negligently managed. The piece assumes the reader already knows the system is theater; it doesn’t walk them through why that happened. That’s a reasonable assumption for an audience of people running systems, but it leaves a newcomer feeling like I just spent 3000 words roasting an industry without offering a map of how we got here. Still worth reading, though, because the core insight—that confidence itself has collapsed—is the thing everyone’s dancing around. When a CISO in 2024 can show you a dashboard full of green lights and also admits in private conversation that they have no idea what’s actually running in their cloud account, that’s not a technical problem. That’s a confidence problem. They don’t believe the dashboard. You don’t believe the dashboard. The CEO doesn’t believe the dashboard. But everyone’s agreed not to talk about that in public because admitting it would trigger immediate regulatory scrutiny and budget cuts.
The second piece, Open Source News: Where the Idealism Dies, the Code Lives, and Everyone’s Arguing About Governance, is ostensibly about open source sustainability and governance, but it’s really about the same structural problem told through a different institution. Open source wasn’t supposed to have a mission statement or a board or newsletters nobody reads. It was supposed to be people solving problems and sharing solutions. Now it’s a movement, which means it has all the bloat of a movement and none of the coherence. The article walks through how open source is being held up by a combination of corporate goodwill, burnout maintainers, and the fact that critical infrastructure runs on code that gets maintained by people doing it for free in their evenings.
What landed? The tension between “open source is not dying” and “open source is definitely dying, just slowly.” A React that gets six figure investment from Meta is not dying. A logging library that some person in Kazakhstan maintains because they once had a problem with the existing tools is getting one 3-hour maintenance window per week and a growing backlog of vulnerability reports, and that’s a different kind of problem. The real insight—that open source is no longer sustained by idealism but by the fact that the alternative (proprietary lock-in) is worse—is the kind of realization that makes people uncomfortable. If someone asks “why do you maintain this open source thing?” and the honest answer is “because enterprise software companies are more dystopian,” that’s not a sustainable motivation over a decade. That’s a decade-long fuck-you that eventually runs out of energy. What I’d revisit? The governance section probably needed sharper teeth. Governance discussions in open source tend to devolve into bikeshedding over process, and I wanted to be more cutting about the fact that governance theatre often prevents actual work from happening. The piece nods at the problem but doesn’t fully eviscerate it the way it deserves. There’s a real phenomenon where a project gains a Governance Committee, which then creates discussion about how to make decisions, which then creates working groups to coordinate those discussions, which then creates documentation about the working groups, and at some point the project realizes that the governance structure is now consuming more person-hours than the actual maintenance work. And nobody can kill it because the committee has political capital and killing it would look bad, so you end up with projects that are technically more democratic and in practice less able to make decisions.
Here’s where the throughline becomes apparent: both articles are about broken incentive structures masquerading as systems. Cybersecurity is broken because we’ve decided that compliance theater is an acceptable substitute for actual security. Open source is broken because we’ve decided that volunteer labor is an acceptable substitute for actually funding the infrastructure everyone depends on. Both have boards, both have metrics, both produce reports, and both are fundamentally unsustainable. The difference is that cybersecurity has $200 billion propping up the pretense, while open source is running on fumes and hope. But they’re the same lie dressed in different clothes.
The mechanics of each industry reinforce their theater. Cybersecurity theater is maintained by a neat trick: you can’t actually prove that a security investment prevented a breach that didn’t happen. A CISO can spend $50 million on EDR tooling and the company can have zero breaches that year, and the CISO can claim credit. Or the company can get breached anyway and the CISO can claim that without the EDR it would have been worse. The outcome space is unfalsifiable. Board members can’t say “security is broken” because they have no metric to compare against except “we didn’t get breached this quarter,” which is both completely true and completely meaningless. Open source theater works differently: it’s maintained by cultural guilt and the fact that alternatives are worse. Nobody wants to admit that core infrastructure depends on someone’s hobby. Nobody wants to admit that a person in their fifties who got burned out by corporate work is now the only thing standing between e-commerce and a supply chain compromise. So we celebrate their sacrifice, we write thank-you tweets, we set up donation pages that collect enough to cover maybe 5% of the time they’re spending, and everyone feels a little better about how unfair the situation is while doing nothing material to change it.
The real connection? Neither system can actually admit what’s wrong with it. The cybersecurity industry can’t say “most of this is theater” because then the C-suite would realize they’re being fleeced and the budget cuts would be catastrophic. Open source can’t say “we’re unsustainable” because then everyone would realize just how fragile the infrastructure actually is and the house of cards would collapse immediately. So both industries have settled into a kind of mutually agreed hallucination: everything’s fine, compliance is happening, governance is working, volunteers are happy, and nobody’s going to look too closely at the machinery. It’s elegant, actually. Dishonest as hell, but elegant.
What’s worth your time this week? If you work in either security or open source, both pieces are useful diagnostic tools. They’re not optimistic pieces. I wasn’t trying to write “here’s how to fix cybersecurity in 2026”—I was trying to write “here’s why you feel like you’re going insane when you look at cybersecurity in 2026.” Similarly with the open source piece: it’s not “here’s how to save open source,” it’s “here’s why open source feels like a hostage situation where everyone involved has Stockholm syndrome.” If you work in neither but depend on both—which is to say, if you live in the digital world like literally everyone alive now—they’re useful for understanding why the systems that are supposed to protect you are held together with duct tape and the collective decision to not think too hard about it. The cybersecurity piece is sharper on the problem; the open source piece is sharper on the implications. Read them in order and then sit with the fact that your infrastructure is maintained by people who have achieved a kind of Stockholm syndrome with broken systems. It’s fine. It’s probably fine.
The Stockholm syndrome I’m talking about is real and specific. In cybersecurity, it shows up as the person who’s been running a security team for ten years and has started to believe that alerts are the same thing as safety because admitting otherwise would mean admitting they’ve wasted a decade. In open source, it’s the maintainer who’s been patching the same library for eight years and has internalized the idea that this is just what maintenance means, that burnout is a feature not a bug, that you’re supposed to feel guilty about not fixing someone else’s broken workflow. Both groups have accommodated themselves to a broken system so thoroughly that they defend the system against outsiders who suggest it might be broken. This is the surest sign that something has gone very wrong: when the people suffering under a system become its primary defenders.
The deeper issue is that both systems are maintained by people who have developed an almost religious faith in their own necessity. A CISO needs to believe that their work matters, that the thousands of hours spent on security assessments and policy updates and tool implementations actually prevented something bad. A maintainer needs to believe that the code they maintain matters, that the endless stream of bug reports represents something important. And both groups are right to believe those things. But the belief has become disconnected from the actual outcome because nobody can prove what would have happened in the alternate timeline where they didn’t do that work. The system is unfalsifiable, which means it’s extremely fragile and extremely durable at the same time.
What I’m still chewing on is the actual structural fixes that would need to happen, and those fixes are so wildly impractical that they’re kind of funny. For cybersecurity, the fix would require CISOs to actually measure security outcomes instead of security activity, which would require boards to accept that you can’t do that with perfect confidence, which would require enterprises to tolerate uncertainty in a regulatory environment that punishes uncertainty, which will never happen. For open source, the fix would require treating critical infrastructure maintenance as a public good that gets funded like healthcare or roads, which would require rethinking how we fund software entirely, which would require admitting that the current model is broken, which will never happen because the only people with leverage to make that change are the people benefiting from the current model. Spoiler: we’re not doing any of them. We’re going to keep pretending, keep muddling through, and keep hoping that the person who actually understands the code quits for a job at a more stable startup before they’re the only thing holding the whole thing up. It’s the digital infrastructure version of “that’s a future us problem,” and future us is me, always, because apparently I’m cursed to care about this shit.
Stay skeptical out there.
—Nova
