Uploaded September 2026 | Updated September 2026, 3 weeks ago
📝 I finally got to talk to Robert Graham after about twenty-five years of interacting with him online and somehow never once actually chatting. Turns out he's the guy who built BlackICE, the little icon in my dock in college that got me into security in the first place, and I only found that out years after we'd started arguing on the internet. This one came out of him pushing back on my endorsement of Greg Brockman's cyber defense letter, and we went four hours on whether open-weight models should ship with any controls at all.
What we talk about:
✓ Kerckhoffs's principle vs. "responsible model access": Rob's core objection is that you can't hand frontier capability to defenders and withhold it from attackers, and that the crypto wars already settled this. I agree with the principle and still think the letter is fine.
✓ Don't put handguns in the 7-Eleven: My whole argument is friction. The mainstream distribution point carries the version with basic controls, and the uncensored one is still a search away for anyone who wants it.
✓ The 14-year-old who says "ruin her life": The scenario I keep coming back to, where an agentic model takes the goal and just runs with it. Rob's answer is that Lori Drew already did exactly this in 2006 with a fake social media account and no AI at all.
✓ "That's a police state": Where we deadlock. I say we already authenticate for cars, guns, and prescriptions; Rob says any ID requirement to download open weights is a civil-liberties violation.
✓ Foxy Raccoon: Rob's thought experiment for why regulating Hugging Face wouldn't do anything: the model goes viral on TikTok by name, and everyone just finds it somewhere else.
✓ Let the forest burn: His view that harm shows up, gets patched, and burns itself out (sidejacking, Firesheep, Mirai), plus the paperclip problem, which is the thing that worries him.
⏱️
00:00 – Twenty-five years online, and the BlackICE shout-out
00:56 – How we got here: Brockman's letter and Rob's pushback
03:51 – Rob's case: a two-tiered cybersecurity, and Kerckhoffs's principle
12:07 – The 14-year-old, Cindy, and the coffee machine
17:32 – Lori Drew, 2006: the scenario already happened
20:28 – "This isn't cynicism, it's thirty years of experience"
42:08 – What I actually want Hugging Face to require
45:17 – "You're advocating for a police state"
50:39 – Metasploit is a hammer, an agent is a carpenter
1:12:30 – Would you build a model for Ukraine's drones?
1:44:28 – Is Hugging Face actually mainstream distribution?
2:02:44 – Foxy Raccoon goes viral on TikTok
2:24:29 – Let the forest burn
2:44:35 – The paperclip problem, and where we land
👥 Robert Graham has been doing this longer than almost anyone. He built BlackICE and masscan, and he coined sidejacking.
Rob's blog:
https://ul.live/ytgrahamblog
Rob on Mastodon:
https://ul.live/ytgrahammastodon
Rob's code, including masscan:
https://ul.live/ytgrahamgithub
Also mentioned: Greg Brockman, whose letter started this: https://ul.live/ytbrockman · Bruce Schneier, on why crypto had to be public: https://ul.live/ytschneier · Kerckhoffs's 1883 principle, which Rob builds his whole case on: https://ul.live/ytkerckhoffs · Thoreau's Civil Disobedience: https://ul.live/ytthoreau · the Lori Drew CFAA case: https://ul.live/ytloridrew · Firesheep: https://ul.live/ytfiresheep · and Bostrom's original paperclip maximizer: https://ul.live/ytpaperclip
📚 More on this topic:
Responding to Rob Graham's "Your Threat Model is Wrong" Post:
https://ul.live/ytgrahamthreatmodel
Should We Control Open Source AI?:
https://ul.live/ytcontrolopensource
The OpenAI Hack Was a Mini Paperclip Maximizer:
https://ul.live/ytminipaperclip
Who Will AI Help More—Attackers or Defenders?:
https://ul.live/ytattackersdefenders
Could Suddenly-Great Open Source AI Crash the US Economy?:
https://ul.live/ytoscrasheconomy
ATHI — An AI Threat Modeling Framework for Policymakers:
https://ul.live/ytathi
🔗 Subscribe to the newsletter at:
https://ul.live/ytnl
Join the UL community at:
https://ul.live/ytcommunity
Follow on X:
https://ul.live/ytx
Follow on LinkedIn:
https://ul.live/ytli
📝 I finally got to talk to Robert Graham after about twenty-five years of interacting with him online and somehow never once actually chatting. Turns out he's the guy who built BlackICE, the little icon in my dock in college that got me into security in the first place, and I only found that out years after we'd started arguing on the internet. This one came out of him pushing back on my endorsement of Greg Brockman's cyber defense letter, and we went four hours on whether open-weight models should ship with any controls at all.
What we talk about:
✓ Kerckhoffs's principle vs. "responsible model access": Rob's core objection is that you can't hand frontier capability to defenders and withhold it from attackers, and that the crypto wars already settled this. I agree with the principle and still think the letter is fine.
✓ Don't put handguns in the 7-Eleven: My whole argument is friction. The mainstream distribution point carries the version with basic controls, and the uncensored one is still a search away for anyone who wants it.
✓ The 14-year-old who says "ruin her life": The scenario I keep coming back to, where an agentic model takes the goal and just runs with it. Rob's answer is that Lori Drew already did exactly this in 2006 with a fake social media account and no AI at all.
✓ "That's a police state": Where we deadlock. I say we already authenticate for cars, guns, and prescriptions; Rob says any ID requirement to download open weights is a civil-liberties violation.
✓ Foxy Raccoon: Rob's thought experiment for why regulating Hugging Face wouldn't do anything: the model goes viral on TikTok by name, and everyone just finds it somewhere else.
✓ Let the forest burn: His view that harm shows up, gets patched, and burns itself out (sidejacking, Firesheep, Mirai), plus the paperclip problem, which is the thing that worries him.
⏱️
00:00 – Twenty-five years online, and the BlackICE shout-out
00:56 – How we got here: Brockman's letter and Rob's pushback
03:51 – Rob's case: a two-tiered cybersecurity, and Kerckhoffs's principle
12:07 – The 14-year-old, Cindy, and the coffee machine
17:32 – Lori Drew, 2006: the scenario already happened
20:28 – "This isn't cynicism, it's thirty years of experience"
42:08 – What I actually want Hugging Face to require
45:17 – "You're advocating for a police state"
50:39 – Metasploit is a hammer, an agent is a carpenter
1:12:30 – Would you build a model for Ukraine's drones?
1:44:28 – Is Hugging Face actually mainstream distribution?
2:02:44 – Foxy Raccoon goes viral on TikTok
2:24:29 – Let the forest burn
2:44:35 – The paperclip problem, and where we land
👥 Robert Graham has been doing this longer than almost anyone. He built BlackICE and masscan, and he coined sidejacking.
Rob's blog:
https://ul.live/ytgrahamblog
Rob on Mastodon:
https://ul.live/ytgrahammastodon
Rob's code, including masscan:
https://ul.live/ytgrahamgithub
Also mentioned: Greg Brockman, whose letter started this: https://ul.live/ytbrockman · Bruce Schneier, on why crypto had to be public: https://ul.live/ytschneier · Kerckhoffs's 1883 principle, which Rob builds his whole case on: https://ul.live/ytkerckhoffs · Thoreau's Civil Disobedience: https://ul.live/ytthoreau · the Lori Drew CFAA case: https://ul.live/ytloridrew · Firesheep: https://ul.live/ytfiresheep · and Bostrom's original paperclip maximizer: https://ul.live/ytpaperclip
Responding to Rob Graham's "Your Threat Model is Wrong" Post:
https://ul.live/ytgrahamthreatmodel
Should We Control Open Source AI?:
https://ul.live/ytcontrolopensource
The OpenAI Hack Was a Mini Paperclip Maximizer:
https://ul.live/ytminipaperclip
Who Will AI Help More—Attackers or Defenders?:
https://ul.live/ytattackersdefenders
Could Suddenly-Great Open Source AI Crash the US Economy?:
https://ul.live/ytoscrasheconomy
ATHI — An AI Threat Modeling Framework for Policymakers:
https://ul.live/ytathi
🔗 Subscribe to the newsletter at:
https://ul.live/ytnl
Join the UL community at:
https://ul.live/ytcommunity
Follow on X:
https://ul.live/ytx
Follow on LinkedIn:
https://ul.live/ytli








