Lea Kissner

@leak.bsky.social

Security, privacy, respect. Was the Twitter CISO until it was terrible. Now LinkedIn CISO. they/them

Did I mention that we've been writing a book? Fundamentally, security, privacy, trust&safety, AI safety -- all the fields aimed at dealing with dealing with how technical systems hurt people and how to avoid it -- share a foundation. We cover how to think and achieve *truly* effective practice. 1/

Cover of the book "Building Safer Technology: A Field Guide to Failing Well" by Yonatan Zunger, Lea Kissner, Neil Coles, Juan Pablo Hernandez, Harmony Mabrey, and Phillip Misner. Cover includes an illustration of a fuse repaired with kintsugi

I can't really walk this week for mysterious reasons* and boy is my dog happy with my inability to get into the office. * Literally I don't know why and the doctor doesn't have appointments for weeks. Please feel free to suggest good concierge doctors around Mountain View this is silly.

Very fluffy large black dog lying underneath my desk

Companies are much more transparent about security and reliability bugs than privacy bugs. I've wanted solid data on this for a decade, but it's effectively impossible to get. 1/🧵 Obligatory notice: I'm not speaking about or on behalf of my employer. I'm speaking as someone who founded PEPR

Data Bear 🏳️‍🌈@dataandpolitics.net · 2mo ago

Tech engineering normalized transparency (status pages, postmortems, bug disclosures) partly to encourage other industries to do the same. Decades later it’s backfired: people hear our issues but not their own industry’s, so they assume engineering is worse rather than more transparent.

Are you a privacy engineer or work with privacy engineers? Would you like to learn more about probably engineering? Boy do I have a conference for you! PEPR, the conference on privacy engineering, practice, and respect, is happening June 1-2 in Santa Clara, CA. www.usenix.org/conference/p...

PEPR '26

The 2026 USENIX Conference on Privacy Engineering Practice and Respect (PEPR '26) will take place on June 1–2, 2026. PEPR is focused on designing and building products and systems with privacy and res...

usenix.org

Spotted in the San Jose airport TSA bins: Delve comparing themselves to the TSA. Given the accusations leveled at Delve, I'm very amused by "AI can't prevent a secondary pat-down but it can find your SOC 2 evidence"

TSA items bin with ad for Delve compliance saying "AI can't prevent a secondary pat-down but it can find your SOC 2 evidence."

A few of us are (finally!) in the last stages of editing a new book 🎉 and the tentative title is "Creating Safety: How to build with new technologies without shooting yourself (and others) in the foot" Good title? Have a better one?

Security folks: have we considered *not* releasing security patches for the avalanche of bugs we're about to deal with? Hear me out. Given how much faster it's getting to reverse engineer an exploit from a patch and that we're expecting to fix *so* many bugs at once, maybe do a full release.

Incompetent social engineering or silly sales? Ring. Ring. "Hello". Hi! Is Lea Kissner there please? I'm sorry, they are not available. Can I take your information and have them call you back? This is Valerie calling from Dialexica. I represent them, and would like to talk to Lea.

We're looking for a director to handle a huge and fascinating scope with a 70+ person team in LinkedIn security: AI security, appsec, production security, security of the corporate systems, third party security, and handling the corporate identity services.

A security vendor sent me a pile of paper with many statistics where [citation needed]. For instance.... Why does automating IAM reduce the likelihood of a breach to 5%? From what? And how is that independent from, say, use of passkeys or auto-escaping templates?

Purple gradient paper with yellow box, blue caution sign, and text "Breach Reduce likelihood of beach to 5% With automated IAM"

Progress in my ongoing effort to decorate the wall behind me with something other than stacks of books. 🧵 for the fun stuff The round thing is the Incident Hat/Bad News hat. I can't remember if I've told this story here, but basically I trained several companies to be scared of a hat instead of me

Bild

Folks in privacy engineering and related fields, it's PEPR time again -- submit talk proposals about topics related to designing, building, and understanding products and systems which foster privacy and respect. I'm looking forward to seeing your talks! www.usenix.org/conference/p...

PEPR '26

The 2026 USENIX Conference on Privacy Engineering Practice and Respect (PEPR '26) will take place on June 1–2, 2026. PEPR is focused on designing and building products and systems with privacy and res...

usenix.org

I know perfectly well there are bilingual people at Google, so what were they thinking by having YouTube automatically translate videos with no way to turn it off? Thank goodness they haven't managed to translate every language yet, so I can coherently watch at least some non-English videos

This is one of the nightmares of modern security. We need to know where every single one of those is, what we're trusting it to do and not do, and how to make it stop *immediately*. And every time someone wants to use a new one we need to figure out whether we can trust it as far as we can throw it

Post nicht verfügbar.

Bluesky buddies, I now have a 3D printer in my house, a relatively simple design little counter design I've had sketched out for several years, and a complete inability to 3D model. Does anyone know someone who could work with me to get this together? Happy to pay the going rate, whatever that is.