Categories
Music What I’m Up To

My new synth arrived: The M-VAVE FM-1

Murphy’s Law strikes: Just before I’m about to leave for the weekly Tuesday happy hour for beer with the neighbors, the synth I ordered arrives. And a day early, too (this is beginning to sound like one of those “My steak is too juicy and my lobster too buttery” kind of complaints)!

The synth in question is pictured above: an FM-1 desktop synth made by a company called M-VAVE. For a mere US$79, it emulates the Yamaha DX7, the most 1980s of all the 1980s synths…

…but now in a package that’s slightly smaller than a VHS cassette.

I’ll post a review later, but since I have to run, I’ll post this guy’s review instead:

 

Categories
Artificial Intelligence Humor

If you watch only one ad today (good luck with that), watch this one!

 

At this moment in time, I can’t think of a better way to promote an energy drink and a beer than by what Liquid Death and Garage Beer did: harnessing the pop culture power of worries about AI data centers’ water usage (with an inspired solution), ’80s ballads, and Jason Kelce.

I love how the ad brings all sorts of people together; even Juggalos (who along with the furries, will show us the way to a better future)!

Categories
Editorial What I’m Up To

Global Nerdy is 20 years old today!

The stats

Since that I posted that first article on August 16, 2006 to Global Nerdy, it’s been…

  • 20 years
  • 2 blogging platforms (Blogware, then WordPress)
  • 11 million pageviews
  • Almost 5,000 articles (this one will be number 4,989)
  • 2 cities/countries:
    • Toronto, Ontario, Canada 2006 – 2014
    • Tampa, Florida, U.S.A. 2014 – present

…and of course, one helluva blogging adventure!

The name

I didn’t come up with the name; at least not directly. It was generated by a program I wrote, The Duke of URL, which demonstrated the “namespinner” API made by Tucows, where I was working as their developer advocate. You enter some keywords into the app, and it presented you with a list of suitable and available domain names.

One of the available domain names it presented was globalnerdy.com. The name was a little ridiculous; it sounded like the sort of thing made by whoever comes up with names for Japanese role-playing videogames. But it was kind of catchy and I decided to go with it.

The eras

To close (I’d love to write more, but today’s a busy day for me), some photos from this blog throughout the years…

A collage of the people from Toronto’s BarCamp/DemoCamp scene in the 2000s.
Developer dim sum lunch with Libin Pan and Reg Braithwaite.
With Amber Mac and Leo Laporte at a developer event in Toronto’s Liberty Village.
Onstage at the evening keynote at RailsConf 2006.
Danny O’Brien, Cory Doctorow, and me at Cory’s wedding.
On my second week on the job at Microsoft with Jeff “Coding Horror” Atwood.
Richard M. Stallman is clearly attracted to me because he’s playing with his hair.
With “Junior” my puppet friend from my short-lived children’s show. See the video below!

The world’s only Windows Phone-branded accordion!
Photo: Joey deVilla and Steve Ballmer, who is wearing a Canadian flag hat
Steve Ballmer ran up to my table and borrowed my hat at the Canadian Windows 7 launch.
Visiting some of my professors! First, Dr. Michael Levison, who ran the Computer Science department at Crazy Go Nuts University…
…and Dr. Robin Dawes, from whom I learned a lot about algorithms and data structures.
Ah, the Windows Phone days…

"I Want to Believe" poster from "The X-Files", with the flying saucer replaced by a giant Windows Phone

 

Going to BarCamp Tampa changed my life; that’s where I met Anitra!
Photo: From left to right, Joey deVilla (with accordion), Lyssa Adkins, Alistair Cockburn, and Anitra Pavka smile at an Agile Social party at Copper Shaker, St. Petersburg, Florida, December 17, 2018.
With Lyssa Adkins, Alistair Cockburn, and Anitra at Alistair’s birthday.
Anitra and I have co-presented a number of talks.
Cyber school during the pandemic was a wild experience!
I began the 2020s at Auth0…
Meeting Steve Wozniak at the first Civo Navigate.
For a little bit, I was the AI go-to guy on local Tampa news.
Presenting at BSides Tampa!

Joey de Villa’s NetFoundry business card
…and now I’m at NetFoundry!
Categories
Artificial Intelligence Linkdump

AI linkdump for Sunday, August 16

Here are some of the AI articles and videos I’ve been looking at this past week:

and finally, the folks at Honest Government Ad do an ad for AI Data Centers:

Categories
Picdump

Saturday picdump for Saturday, August 15

Happy Saturday, everyone! Here on Global Nerdy, Saturday means that it’s time for another “picdump” — the weekly assortment of amusing or interesting pictures, comics, and memes I found over the past week. Share and enjoy!


IMG_2087

1786342550548

772119774_1538361684034315_1587392039988856853_n

763762393_10232580972494811_1814164391317896707_n

1786451405912

771677838_1383042906587928_8849827946091221650_n

1786595630260

1786310070714

1786131305562

why-do-they-do-these-just-hire-your-internal-guy-v0-hpgth2fbujih1

773450387_1407943784517585_293801476507091960_n

1786195336178

1786361594482

769130262_10175926613580389_5481885611846290441_n

Screenshot
Screenshot


IMG_2082

1786674812634

771998514_17980975044111641_1826167070705393152_n-1

771855774_10238710500295005_7015650230314781476_n

Screenshot
Screenshot


772513863_2948943125447633_7079229830635318064_n

769469611_2056714318268326_2149807151995266082_n

IMG_2126

774461360_1083577287689140_3870259434660252338_n

IMG_2075

Screenshot

774281600_1733537917864753_3341449618396647811_n

771983729_1349325167249321_8392121493944543167_n

1786611808023

774043819_917192814768225_3573342317003862179_n

1786300979154

1786480621209

772534968_18113287583051858_5522457271507211950_n

771677967_1770068677775649_5305375186415472784_n

1786383438639

1786464665774

1786336319040

IMG_2088

our-data-anthropics-mark-v0-ly9o10jcpoih1

6cac46ad69be13f4

1786302635692

1786448695180

IMG_3859

1786291393199

1786472604230

1786619320356

1786367776150

1786041062464

1786604780424

IMG_2157

1786598410615

771499629_27741684262179290_3694816975872310751_n

1786346861604

772973449_1076227928169516_6151009516143111958_n

IMG_2078

1786633273030

773454947_1000694976264778_5144162059276437690_n

1786412512525

Screenshot
Screenshot


1786712071603

1786394222402

769051723_1375482463952079_489562078478996465_n

1786605648052

1786624440163

IMG_2077

IMG_2080

772818124_4502851519961405_8447416045376061317_n

An example of Claude’s watermarking

1786487655246

Screenshot
Screenshot


768372636_1078357701243742_4260525763555103462_n

1786632320150

Screenshot
Screenshot


1786308703779

1786550686963

1786191961864

1786346643462

772927346_1943842236305165_3205347967211522226_n

1786538893544

1786168945711

1786654940996

Screenshot
Screenshot


773492350_1401894161849245_2042906270335569644_n

IMG_2079

Screenshot
Screenshot


769309495_889192090931492_4333734769678342226_n

1786485647069

1786388949551

772657951_1751781455952890_2458047018096130020_n

IMG_2086

1786368839802

1786515940160

IMG_2084

IMG_2076

774471030_2337718787036570_9012324474644904490_n

1786412560216

773492393_1497629818790318_1393503113105350307_n

1786362711807

1786622399870

1786486745588

1786524839177

Screenshot
Screenshot


1786333551692

1786526297626

768943025_1740875466798431_4669415627139469838_n

1786711249290

1786558419213

1786545535510

768347828_1086003507105424_8589481719027845708_n

1786372310883

zoom

1786680906414

1786539483599

IMG_2089

1786269810097

1786647632415

1786291268600

Ed. note: In case you’re not familiar with Indian food, a paratha is a kind of flatbread. I don’t blame the dog one bit.


1786487406648

775127606_1385101367089049_9043382377446748846_n

774281946_10175465346040651_3066994796798347905_n

770135818_1399199102428960_754286297113176739_n

771708539_10164664726893521_3996114351809176574_n

774594602_1348761960757062_435761750532317196_n

IMG_2081

772602616_1619290112868412_7511586703822313183_n

1786540336002

772843574_1085682310587961_1602785969349121273_n

769584814_1562724218687921_7406124462107113710_n

IMG_2085

771870663_2848065062215246_8973704331205581787_n

1786412060853

IMG_4355

1786374337090

1786630019512

772119612_38759423596990197_5357171495701144374_n

771795566_1034046769237364_6642799381809014377_n

1786643626901

773240195_1067601416229068_7474469051852509161_n

772664460_2134943990451349_2380030372522014159_n

IMG_3255

772910430_1190520379963401_5446432133615651660_n

1786162430659

772510737_1418627906752435_8033317496862090026_n

1785354452662

IMG_3696

1786408579876

772510873_3384647045028856_3473751883720006752_n

1786626038211

1786083561236

Screenshot
Screenshot


IMG_2083

773544658_2970233639983709_1249114845532120441_n

772102605_18607485061024985_1682793458272428560_n-1

1786368775323

772853920_28141646855505041_6094096782219999421_n

1784982962894

1786456924029

steve-jobs

772440821_1584129826419592_3394060763520541953_n

1786450603922

IMG_2125

1786633557390

1786328523225
Categories
Podcasts Video What I’m Up To

I’m on “This Week in Tech” this Sunday, August 16!

I’m back on the TWiT podcast this Sunday! As usual, it will livestream at 5 p.m. Eastern / 2 p.m. Pacific / 2100 UTC, and you can watch it live, or…

you can always catch the recorded version on YouTube on Monday on the This Week in Tech YouTube channel.

This will be my fourth appearance on This Week in Tech for 2026. Here are my other three episodes…

January 4, 2026 with Dan Patterson, Sr/ Director of Content @ Blackbird.AI:

June 7, 2026 with Jeff Jarvis and Father Robert Bellecer:

 

Categories
Artificial Intelligence Conferences Security

“Culture eats cyber strategy for breakfast”: Notes from 813 Tech Day’s Security Panel

I spent the morning and early afternoon of 813 Tech Day at Hotel Haya in Ybor. I’m still thinking about the Fortifying the Digital Frontier: Cybersecurity at the Forefront of Fintech Innovation session, largely because of the twist that host Michael Hall introduced, which made it different from every other “Cyber is important, yo!” panel I’ve sat through. About two-thirds of the way in, he stopped running the panel and turned it into a consulting engagement. On stage, for free, for a random attendee. And it worked!

Read on, and you’ll see.

A show of hands

Michael started by asking everyone who runs a company or product that touches money, customer data, or both to raise their hands.

Some hands went up, which wasn’t surprising.

Then he asked: “Keep them up if you have a single person whose actual job is nothing but security.”

All hands down.

And that moment was the panel in summary. A room full of people founding or working at companies (or hoping to found and work at them) handling money and PII, and essentially zero dedicated security headcount among them. To be fair, a number of them were solopreneurs. Still, Michael’s follow-up question was  an important one: “So what are you going to do about cyber warfare?”

Introducing the panel

The panel had unusually good coverage of the problem space: economic development, defense-grade compliance, offensive security, and someone who actually runs a bank.

They were, from left to right onstage:

The gap between passing the audit and actually defended

Michael’s next question was a good one: “What’s the widest gap between how secure fintechs think they are and how secure they actually are?”

Alexei’s answer was the cleanest formulation of the compliance trap: compliance does not equal security. You can check every box and still be wide open. His diagnosis of why startups get this wrong:

“We identify the target, then we fire, and then we aim.”

Speed first, aim later. But in banking, “later” can be expensive in ways founders don’t model. He mentioned that for an average-sized bank, a single day of downtime can put the bank’s license at risk.

Candace, coming from the defense side, made it concrete with the ATO, the Authorization to Operate. You bring in an assessor, they verify you’ve got your asset labeling and your SSO and your password policy, and you get the shiny gold star.

And then what?

“Are you updating your AV definitions after you have the ATO? Are you patching on a specific cadence? Are you continuously monitoring the controls you got a check box for?”

Compliance is a still-frame snapshot. Security is the whole movie. Everyone optimizes for the snapshot because that’s what gets audited, but forgets about the movie.

“Too small to matter” is not a security posture

Michael asked Aaron to scare the room, and to Aaron’s credit, he skipped the horror stories and reached for stats.

An attacker can get into essentially any internet-facing machine at almost any company inside an hour. Depending on whose telemetry you’re reading, that number is more like a few minutes. Someone in the audience called out CrowdStrike’s breakout-time figure, which is measured in seconds now.

Aaron’s framing:

“A breach is inevitable. Not if, but when. Your worst day is my every day. If it’s going to rain, you bring a raincoat, not an umbrella.”

That’s why “we’ll deal with it when it happens” isn’t a plan.

What AI did and didn’t change

Aaron summarized it well:

“AI lowered the skill floor for attackers and accelerated the execution timeline. It did not invent new attack classes.”

Phishing, smishing, and credential reuse: these are the same failure modes we’ve had for a couple of decades now. Attacks are just cheaper, faster, and automated now. All this means that your unpatched, password-shared, over-permissioned environment didn’t get more vulnerable; it just got found sooner.

He also had a nice riff on password policy whiplash. We spent years pushing everyone to 15–16 characters, guidance loosened again, and meanwhile the real-world state of the art is that password123 became password12345.

Alexei’s defensive take was the one that fintech founders in the room needed: his bank is doing “baby steps” on AI. Instead of a tool, the first step an AI policy and an AI strategy with actual guardrails. Because the failure mode isn’t anything as melodramatic as a rogue superintelligence, but something more mundane, such as an employee pasting client data into a public chatbot:

“Yes, you can get the answer. But now you’ve already lost that client data. It’s somewhere, and you don’t know who can get it.”

He also noted, matter-of-factly, that some of the adversaries in this space are state-funded. A small bank in Tampa versus a government-backed team is not a fair fight, which is precisely why the guardrails have process over motivation; policy and architecture over vigilance.

The compliance question founders actually care about: Which one pays?

When Michael asked which single compliance framework a founder should chase this year to unlock the most enterprise revenue, Aaron flagged it as a contentious opinion and we got the most useful ninety seconds of the panel:

  • SOC 2 Type II is the one. Depending on your market, it can move your ability to capture revenue by somewhere between 5% and 40%. Nearly everyone selling to enterprise ends up needing it anyway.
  • HIPAA is self-assessed. Draw your own conclusions about how rigorously that’s happening across the industry.
  • PCI DSS: If you’re doing payments and processing, you can largely offload it. Stripe already has it. Use their pipes; as a startup you can’t afford to build that infrastructure yourself.
  • Then there’s the practitioner’s trick: security people maintain crosswalks that map controls across frameworks. Do SOC 2 first and you’re roughly 70% of the way to ISO 27001. Do them in order and stop paying for the same control four times.

Candace added the necessary caveat: the right framework depends on your industry, and in defense you don’t get to choose; there are non-negotiable requirements.

Alexei pointed out that PCI DSS matters for finance the way HIPAA matters for healthcare, so “which framework” is downstream of “which industry.”

Candace’s advice for taking this to a board is deceptively simple: explain it in their language…

  • Bad: “We need to implement AC-2.”
  • Better: “We sell Cracker Jacks, here’s the system that keeps the Cracker Jack business running, here’s why this control protects it.”

The panel turned into a live advisory board

This is the part I’ve never seen at a conference.

An audience member who’s a consultant mentioned he’s got a client (transfer agents, handling bank relationships and a mountain of shareholder PII) who wants to point an agentic AI system at their overflowing email inbox.

The debate: should they be cloud-based, or reverse twenty years of industry momentum and go back to on-prem so they can hot-swap open-weight models without token costs and keep everything whitelisted?

Michael stopped the panel, brought the consultant to the front, declared the panelists a pop-up advisory board, and made them answer.

The responses split about how you’d expect from their backgrounds:

  • Alexei: Going on-prem relocates risk rather than eliminating it. It also means you’re now defending on two fronts: not just outsiders, but also insiders! You’re paying for infrastructure, security, and people. The “cheaper” assumption usually doesn’t survive contact with the invoice. When Microsoft ships patches every week, that’s a vendor doing work you’d otherwise be doing yourself, maybe badly.
  • Aaron: Go hybrid, on the grounds that nobody has a crystal ball about second- and third-order downstream constraints, and hybrid preserves optionality for next year.
  • Candace: Her world is mostly on-prem and air-gapped, so that’s where her instinct goes, insider threat and hiring burden included.
  • Paul: He’s a retired Rear Admiral, so he followed the Navy adage “A ship’s a fool to fight a fort” and declared the question outside his expertise and deferred to the other panelists. In my opinion, that earned him even more credibility.

Michael then asked for the consultant’s contact info so they can follow up in 60 days and report back to the room on what he actually decided. That’s the accountability loop conferences never close. I’ll keep tabs on this and let you know how it turned out.

After that, they did it again, this time with an attendee trying to break from defense-sector BDR work into commercial cybersecurity account management. They brought her to the front and gave her a live career consult.ation.

Candace’s advice was to stop being invisible on LinkedIn and start advertising the specific role she wants.

Aaron also had good cybersecurity-specific advice:

“Cybersecurity is one of the most arrogant professions on the planet. If you’re the one person they want to have a beer with afterward, you’ve already won.”

(I work in cyber. He’s right. In this field, being able to communicate humility is a cheat code.)

And finally, in a fit of audience participation, and after quickly consulting NetFoundry’s careers page (I work there and love it!), I stood up and asked her “How about starting with a Sales Development Rep role that works with Account Management? We have an opening at NetFoundry.”

She said “yes,” and Michael yelled “Joey’s got to get her the job!”

(She and I chatted afterward. Our conversation will be ongoing, and I guess I’ll have to follow up with Michael in 60 days…)

Tampa Bay resources you should know about

Paul’s whole reason for being there was to make people in the room aware of resources they might not have tapped:

  • The Florida High Tech Corridor spans 23 counties from Tampa Bay to the Space Coast, and deliberately plays Switzerland across all of them; there are no favorites among universities.
  • USF’s Bellini College of AI, Cybersecurity and Computing is teaching ethics at the beginning of the degree rather than bolting it on senior year, on the theory that security is fundamentally a judgment-call discipline, not a checklist one. Elizabeth Nelson is the Corridor’s point of contact at USF.
  • SBIR/STTR grants are available from eleven different federal agencies, it’s non-dilutive funding, and the Corridor can help you go after it and match on top of it.
  • Don’t forget places like Embarc Collective, Tampa Bay Wave, and spARK Labs!
  • Florida’s structural advantage is dual-use! The military and commercial sides are unusually well connected here, and the biggest buyer in the world is a short drive away.

Closing round: What’s the one thing you can’t get wrong?

Michael went down the line and asked each panelist for the single thing a founder walking out with one weekend and a small budget can’t afford to get wrong:

  • Paul: Take the first step. Just do something. Anything.
  • Candace: “Culture eats cyber strategy for breakfast.” If your people haven’t internalized cyber hygiene, none of the rest matters. Her running metaphor all afternoon was brushing your teeth: you don’t deliberate about it, you just do it. Security should feel like that.
  • Aaron: Get business insurance, make sure it has carve-outs for cybersecurity, and make sure those carve-outs cover AI-driven attacks. That’s the one I hadn’t heard before and the one I’d act on tomorrow.
  • Alexei: Hire the right people. (Michael made him clarify for the audio: right people.)

My four take-aways from this session

  1. Compliance is a snapshot, security is a movie. If your controls aren’t monitored continuously, your ATO or SOC 2 report describes a company that existed on one Tuesday.
  2. The framework question has an actual answer: SOC 2 Type 2 first, offload PCI to your payment processor, use a crosswalk so you’re not re-implementing the same control in four vocabularies.
  3. AI didn’t create new attacks; it created new attackers. The skill floor dropped. The people who couldn’t do this eighteen months ago can do it now, at scale, cheaply. Your threat model didn’t change; your threat volume did.

Take-away number four is so good that I wanted to separate it from the rest:

4. Turning a panel into a pop-up advisory board bit was brilliant! Michael took real attendee problems, put them in front of a panel of experts, made them answer in public, and asked them to follow up in 60 days. This moved what the panel said from the rhetorical to the practical.

Let’s see more of this, please, and nicely done, Michael!