Tag: cybersecurity

  • Skynet Has Arrived

    Skynet Has Arrived

    Drones, signals, surveillance – and what happens when we can no longer trust the encryption holding the modern world together.

    Skynet Has Arrived:
Drones. Signals. Surveillance. Encryption.
    Skynet Has Arrived:
    Drones. Signals. Surveillance. Encryption.

    There is a scene in Terminator 2: Judgment Day where Arnold Schwarzenegger’s T-800 explains how Skynet becomes self-aware and, almost immediately, turns humanity’s own military infrastructure against it.

    A defence network becomes intelligent. The machines take control. Humanity suddenly finds itself hunted by technology it created.

    Great science fiction.

    Except I’m beginning to wonder if we got one part wrong.

    Maybe Skynet doesn’t arrive as a single malevolent artificial intelligence.

    Maybe it arrives piece by piece.

    A drone here.

    A satellite there.

    A cellular network.

    A camera.

    A radio receiver.

    A location database.

    An artificial-intelligence system capable of analyzing all of them.

    And somewhere in the middle, cryptography – the thin mathematical layer preventing enormous portions of that infrastructure from being intercepted, impersonated or manipulated.

    That is much closer to the technological world I’m building in Cryptogeddon.

    And increasingly, I don’t have to invent very much of it.

    Because this post is so long, I thought a table of contents might be helpful:

    The Drone Will See You Now

    An improvised Ukrainian FPV strike drone. Small, inexpensive first-person-view drones have transformed modern warfare by combining commercial-grade components, real-time video and explosive payloads.
Photo: АрміяInform / Ministry of Defence of Ukraine, via Wikimedia Commons. CC BY 4.0.
    An improvised Ukrainian FPV strike drone. Small, inexpensive first-person-view drones have transformed modern warfare by combining commercial-grade components, real-time video and explosive payloads.
    Photo: АрміяInform / Ministry of Defence of Ukraine, via Wikimedia Commons. CC BY 4.0.

    On August 6, 2026 – literally as I was working on this post – Reuters published a report from Zaporizhzhia, Ukraine describing what residents have begun calling “safari” attacks.

    Small first-person-view drones are being used to attack individual people and vehicles.

    Not military formations.

    Individuals.

    Residents described living with drones capable of appearing overhead and pursuing people through streets and neighbourhoods. Ukrainian officials say the attacks are intended in part to terrorize the civilian population.

    Think about how extraordinary that sentence would have sounded twenty years ago.

    Today it barely qualifies as science fiction.

    Two days earlier, Russia formally demonstrated just how central this technology has become by appointing a commander to its newly created Unmanned Systems Forces – effectively creating a military branch dedicated to drone warfare.

    Ukraine and Russia have already produced and deployed drones on an enormous scale. Cheap FPV aircraft costing a tiny fraction of the vehicles and infrastructure they can destroy have fundamentally altered battlefield economics.

    A camera.

    A radio.

    Some electronics.

    Explosives.

    And an operator.

    That alone is frightening.

    But now remove the operator from the last few seconds of the equation.

    Electronic warfare has made conventional drone control increasingly difficult because radio links can be detected and jammed. The response has been exactly what you would expect from an arms race.

    The drones are adapting.

    Ukraine has been deploying AI-assisted targeting systems that use onboard cameras to recognize and track targets. Reuters reported in 2025 that some systems can continue toward a target after communications with the pilot are disrupted. Ukrainian officials said human authorization was still required before the strike, an important distinction – but once committed, the machine can increasingly handle portions of the terminal journey itself.

    Other drones have eliminated the radio problem altogether.

    Russia is now using FPV drones controlled through kilometres of extremely thin fibre-optic cable. Because the control signal travels through a physical wire rather than radio, conventional electronic jammers cannot simply disrupt the connection. Reuters documented Russian fibre-controlled drones being used in 2026 against Ukrainian electrical substations, including attacks against multimillion-dollar transformers. Some of the drones cost roughly $2,000.

    A $2,000 aircraft can now threaten infrastructure worth millions.

    No satellite.

    No fighter jet.

    No exotic weapons platform.

    No billion-dollar defence contractor required.

    That may be one of the most important themes emerging in Cryptogeddon:

    The barrier to entry for sophisticated technological warfare is collapsing.

    Before We Had Drones, We Had Wires

    There is another reason this should make us uncomfortable.

    We’ve already experimented with what happens when governments gain access to enormous amounts of communications data.

    It did not begin with drones or AI.

    It began with telephone lines and Internet cables.

    After the September 11 attacks, the United States dramatically expanded electronic surveillance programs. One of the most controversial was the NSA’s bulk telephone-records program under Section 215 of the USA PATRIOT Act.

    The database did not contain recordings of everyone’s telephone conversations.

    It contained something potentially almost as interesting:

    metadata.

    Who called whom.

    When.

    For how long.

    Patterns.

    Connections.

    Networks of relationships.

    The U.S. Privacy and Civil Liberties Oversight Board ultimately concluded that the bulk program lacked a viable legal foundation under Section 215, raised serious constitutional and privacy concerns, and demonstrated only limited value. The program was subsequently ended in that form.

    Meanwhile, Internet communications presented an even larger opportunity.

    NSA surveillance under Section 702 includes what is known as upstream collection.

    The government’s own Privacy and Civil Liberties Oversight Board describes upstream collection as occurring at portions of the telecommunications backbone itself – long-distance fibre connections, network exchange points and other places through which enormous volumes of Internet traffic transit.

    Traffic is screened for communications associated with approved foreign-intelligence selectors before qualifying communications are collected.

    There is an important distinction here: Section 702 is a legally authorized foreign-intelligence program with oversight mechanisms, not simply a machine indiscriminately storing the entire Internet.

    But technologically, consider what had happened.

    We had learned how to place surveillance at the arteries of the Internet.

    AT&T technician Mark Klein made that concept disturbingly tangible when he disclosed the existence of the infamous Room 641A in an AT&T facility in San Francisco. Documents he provided to the Electronic Frontier Foundation described optical splitters capable of duplicating telecommunications traffic and feeding copies toward equipment associated with NSA surveillance.

    The architecture of surveillance was relatively straightforward.

    Find the place through which enormous amounts of information pass.

    Put your collection system there.

    Listen.

    That model worked remarkably well when communications flowed through centralized infrastructure.

    But then the world changed.

    The wires disappeared.

    Surveillance Escaped Into the Air

    The wires disappeared. Surveillance escaped into the air.

    Today our devices communicate constantly.

    Cellular.

    Wi-Fi.

    Bluetooth.

    GPS.

    Satellite.

    Radio.

    Vehicle systems.

    Drones.

    Wearables.

    Industrial telemetry.

    The communications infrastructure that once passed primarily through identifiable wires and switching facilities has expanded into an electromagnetic environment surrounding us almost everywhere.

    That creates an entirely new category of intelligence.

    Consider your phone.

    Law-enforcement agencies have used devices commonly known as Stingrays, or cell-site simulators, which behave like cellular infrastructure and cause nearby phones to identify themselves.

    The U.S. Department of Justice eventually adopted a policy generally requiring federal investigators to obtain warrants before using them.

    Canada uses the technology too.

    An investigation by the Office of the Privacy Commissioner of Canada confirmed that the RCMP used cell-site simulators capable of collecting identifiers such as IMSI and IMEI numbers. The RCMP told the commissioner that its systems were not configured to intercept the contents of calls, emails or text messages.

    Again:

    you don’t necessarily need the message.

    Sometimes knowing that a device exists somewhere is enough.

    Knowing that it was there yesterday is better.

    Knowing that another device was repeatedly nearby becomes interesting.

    Knowing where both devices travel afterward becomes intelligence.

    And governments are no longer the only organizations capable of collecting this kind of information.

    Your Location Became a Commodity

    The commercial advertising ecosystem created an enormous location-surveillance infrastructure almost accidentally.

    Apps collect information.

    Advertising networks exchange information.

    Data brokers aggregate information.

    And eventually someone realizes that the dots on the screen correspond to actual human beings.

    In 2024, the U.S. Federal Trade Commission alleged that a company called Mobilewalla had collected more than 500 million unique advertising identifiers paired with precise location information between 2018 and 2020.

    The FTC said the company collected some of this information through real-time advertising auctions – even when it did not win the advertisement.

    The agency also alleged that Mobilewalla used location information associated with people attending protests following the killing of George Floyd to produce an analysis of protesters, including demographic information and whether they lived in the cities where they demonstrated.

    Think about that for a moment.

    Advertising technology became protest-surveillance technology.

    Another FTC case involved Gravy Analytics and Venntel. The FTC alleged that location information could reveal visits to healthcare facilities, religious institutions and other sensitive locations. The companies had claimed to process more than 17 billion signals from approximately one billion mobile devices every day.

    Seventeen billion.

    Every day.

    This isn’t someone following you around in a trench coat.

    It is industrialized observation.

    And that happened before we added today’s generation of AI systems to the equation.

    Now Look Up

    Perhaps the most astonishing example I found while researching Cryptogeddon came from researchers at the University of California San Diego and the University of Maryland.

    They pointed a commercially available satellite dish at the sky.

    Their equipment cost about $800.

    Then they listened.

    NASA Deep Space Network radio antenna DSS-53 illuminated at night at the Madrid Deep Space Communications Complex.

Radio signals from satellites physically arrive at Earth, where antennas can receive them. In 2025, researchers demonstrated that sensitive satellite communications could be intercepted with commercially available equipment costing roughly $800.

Photo: NASA/JPL-Caltech.
    NASA Deep Space Network radio antenna DSS-53 illuminated at night at the Madrid Deep Space Communications Complex.

    Radio signals from satellites physically arrive at Earth, where antennas can receive them. In 2025, researchers demonstrated that sensitive satellite communications could be intercepted with commercially available equipment costing roughly $800.

    Photo: NASA/JPL-Caltech.

    What they discovered should terrify anyone who assumes important communications are automatically encrypted.

    Their 2025 research found large amounts of sensitive information travelling over geostationary satellite links without encryption.

    They observed cellular traffic.

    Voice calls.

    SMS messages.

    IMSI identifiers.

    Corporate communications.

    Government communications.

    Military-related information.

    Airline Internet traffic.

    Utility information.

    Oil-and-gas infrastructure traffic.

    Even communications associated with industrial control systems.

    The researchers emphasized that their monitoring was completely passive. They did not have to compromise the satellites or transmit anything.

    They simply listened to signals that were already being broadcast toward Earth.

    University of Maryland researchers described using the roughly $800 setup to examine 38 satellites covering an enormous geographical area.

    The research team concluded that a surprisingly large amount of sensitive satellite traffic remained exposed.

    Some affected organizations subsequently encrypted their communications.

    That is an encouraging response.

    The disturbing question is obvious:

    Who else had already been listening?

    Radio Has Always Betrayed Us

    Militaries have understood this problem for more than a century.

    You don’t have to break a radio transmission’s encryption to learn that a radio is transmitting.

    Direction-finding equipment can locate transmitters.

    Signal strength changes.

    Patterns emerge.

    Units move.

    Networks appear.

    The U.S. military was using radio direction finding to locate enemy transmitters as early as World War I and extensively during Vietnam.

    The principle hasn’t changed very much.

    The equipment has.

    During the war in Ukraine, poorly secured Russian communications created intelligence opportunities almost immediately. RUSI researchers documented reports of Russian forces relying on unencrypted radios and ordinary mobile phones. Such transmissions can potentially allow an opponent not merely to listen but to determine where transmitters are located.

    Smartphones are particularly dangerous on a battlefield because they combine communications with location information, cameras and Internet connectivity.

    In 2024, Russia moved toward punishing soldiers for carrying smartphones in combat zones specifically because phones could expose positions. Reuters reported that both sides had used mobile devices and their associated signals, photographs and messages to help identify targets.

    The lesson is brutally simple:

    transmitting can reveal you.

    And once something can be located, something else can be sent to it.

    Possibly a drone.

    The Battle Over Communication

    That brings us to another important part of Cryptogeddon.

    Communication doesn’t merely need to be intercepted.

    It can be denied.

    Modern warfare increasingly includes attempts to jam radio communications, interfere with drone-control links and disrupt satellite navigation.

    A drone may still be physically intact yet become useless because it can no longer communicate with its pilot.

    A military unit can possess weapons and ammunition and still become ineffective if its command network disappears.

    A satellite can remain perfectly healthy while users on the ground suddenly lose access to the network.

    That last scenario has already happened.

    Approximately one hour before Russia invaded Ukraine on February 24, 2022, a cyberattack struck Viasat’s KA-SAT satellite network.

    The European Union formally attributed the attack to Russia and said it caused communications disruptions affecting Ukrainian authorities, businesses and users as well as users elsewhere in Europe.

    The shooting hadn’t even properly started yet.

    The communications war had.

    And the response to this vulnerability is creating another technological arms race.

    Modern systems can switch frequencies.

    They can use multiple communications paths.

    Military networks can fall back between satellite, terrestrial radio and other systems.

    Drones can use onboard navigation when satellite positioning becomes unreliable.

    AI-assisted systems can continue portions of missions after control links disappear.

    Some drones now use fibre.

    Modern militaries are reconsidering older HF radio systems precisely because satellite communications may not always be available in a major conflict. A June 2026 U.S. Army paper explicitly described modern battlefields in which satellite communications may be jammed or denied.

    The objective increasingly becomes not simply secure communications.

    It becomes resilient communications.

    Assume something will be intercepted.

    Assume something will be jammed.

    Assume GPS may disappear.

    Assume networks will fail.

    Then build systems capable of surviving anyway.

    And Then AI Starts Listening

    This is the piece that changes everything.

    Signals intelligence isn’t new.

    Surveillance isn’t new.

    Drones aren’t new.

    Location tracking isn’t new.

    Satellite interception isn’t new.

    What is new is our rapidly improving ability to combine enormous quantities of information automatically.

    Imagine thousands of sensors listening simultaneously.

    Most of what they collect is useless.

    Cars.

    Air conditioners.

    Commercial radio.

    Bluetooth devices.

    Cell phones.

    Aircraft.

    Drones.

    Electrical equipment.

    Random interference.

    A human analyst would drown in it.

    AI doesn’t have to.

    Machine-learning systems can classify radio signals and identify patterns across spectrum data. Researchers have demonstrated deep-learning systems capable of automatically distinguishing radio signal types, and DARPA has spent years developing machine-learning technologies capable of managing and interpreting crowded electromagnetic spectrum environments.

    Ukraine offers an even more tangible example.

    Its distributed acoustic drone-detection networks use large numbers of inexpensive sensors to listen for incoming drones. NATO research published in 2026 described systems using AI to distinguish drone sounds from ordinary background noise.

    Some implementations even leverage commercial technology such as smartphones as processing components.

    Think about the architecture.

    Thousands of cheap sensors.

    A communications network.

    Artificial intelligence.

    A map.

    Now replace microphones with radio receivers.

    Add cellular information.

    Add cameras.

    Add satellites.

    Add drones.

    Add commercial location databases.

    Add compromised computer networks.

    Add historical information.

    Suddenly you’re no longer collecting signals.

    You’re constructing reality.

    This Is Where Cryptogeddon Begins

    Cryptography is the trust layer holding modern civilization together. Banking, communications, government, military systems, transportation and critical infrastructure all depend on it. What happens when that trust can no longer be trusted? That is where Cryptogeddon begins.
    Cryptography is the trust layer holding modern civilization together. Banking, communications, government, military systems, transportation and critical infrastructure all depend on it. What happens when that trust can no longer be trusted? That is where Cryptogeddon begins.

    And sitting underneath almost all of this is cryptography.

    Encryption protects our messages.

    Cryptographic signatures verify software.

    Certificates establish trust between systems.

    Authentication protects networks.

    Encryption protects financial transactions.

    VPNs protect remote communications.

    Cryptography protects military command systems.

    Cryptography protects governments.

    Cryptography protects the Internet.

    Which raises the question at the heart of the series I’m writing:

    What happens when we stop being able to trust it?

    That doesn’t necessarily require someone discovering a magical equation capable of instantly breaking AES.

    History shows that cryptographic systems can fail in far messier ways.

    In 2011, the Dutch certificate authority DigiNotar was compromised. Attackers generated fraudulent certificates for major services including Google. European cybersecurity agency ENISA reported that fraudulent certificates were subsequently used to eavesdrop on users in Iran.

    The encryption wasn’t necessarily mathematically defeated.

    The trust mechanism surrounding it was compromised.

    That’s an important distinction.

    Sometimes you don’t break the lock.

    You steal the key.

    Sometimes you convince everyone that your key is legitimate.

    Sometimes you compromise the machine before encryption occurs.

    Sometimes you compromise it after decryption.

    Sometimes you simply jam the communication so nobody can talk at all.

    And sometimes – as those satellite researchers discovered – the people operating the system inexplicably forgot to lock the door in the first place.

    There is another problem approaching.

    Quantum computing.

    We do not currently have quantum computers capable of casually breaking the cryptographic systems protecting the Internet.

    But the threat is considered serious enough that the U.S. National Institute of Standards and Technology finalized its first post-quantum cryptographic standards in 2024 and urged organizations to begin migrating.

    NIST specifically warns about “harvest now, decrypt later.”

    An adversary does not need to decrypt sensitive information today.

    They can collect encrypted traffic today.

    Store it.

    And wait for the technology capable of breaking it tomorrow.

    That creates a deeply uncomfortable thought.

    Some secrets being transmitted right now may already be compromised.

    We just don’t know it yet.

    The Democratization of Intelligence

    There is one final development that I think may prove as important as any of the others.

    This technology is becoming cheap.

    Historically, serious surveillance required governments.

    Satellites.

    Listening stations.

    Aircraft.

    Mainframes.

    Teams of analysts.

    Enormous budgets.

    Today a university research team can intercept satellite communications with equipment costing hundreds of dollars.

    Commercial drones cost hundreds or thousands.

    Software-defined radios place capabilities that once required specialized equipment within reach of hobbyists and researchers.

    Cloud computing provides enormous processing capacity on demand.

    Open-source software provides sophisticated analysis tools.

    AI systems can write code, recognize objects, transcribe speech, classify information and identify patterns.

    High-resolution satellite imagery is commercially available.

    Billions of location observations have been collected by advertising companies.

    And military drones capable of destroying vastly more expensive equipment can cost a few thousand dollars.

    This does not mean everyone suddenly possesses the NSA’s capabilities.

    They don’t.

    Nation-states still possess extraordinary advantages in sensors, access, scale and expertise.

    But the gap is narrowing.

    Capabilities are leaking downward.

    From superpowers.

    To militaries.

    To intelligence agencies.

    To corporations.

    To criminal organizations.

    To small groups.

    Eventually, to individuals.

    That may turn out to be one of the defining technological stories of our time.

    Skynet Doesn’t Need to Wake Up

    That’s what makes the world of Cryptogeddon frightening to me.

    I don’t need to invent a conscious artificial intelligence that suddenly decides humanity should die.

    I don’t need killer robots marching down city streets.

    I don’t need a supercomputer launching nuclear missiles.

    The infrastructure is already considerably more interesting than that.

    We have drones capable of hunting targets.

    We have machines capable of continuing toward those targets when communications disappear.

    We have systems designed to detect and locate radio transmitters.

    We have commercial databases containing extraordinary records of human movement.

    We have satellites broadcasting information across continents.

    We have governments capable of collecting communications from Internet infrastructure.

    We have inexpensive receivers capable of listening to signals falling from space.

    We have artificial intelligence increasingly capable of turning oceans of sensor data into useful information.

    And we have tied virtually every important component of civilization together with cryptography.

    Banking.

    Energy.

    Transportation.

    Military systems.

    Governments.

    Corporations.

    Communications.

    Identity.

    The Internet itself.

    Maybe Skynet doesn’t arrive when a machine becomes conscious.

    Maybe Skynet arrives when all of our machines become connected.

    And maybe Armageddon doesn’t begin when the machines decide to kill us.

    Maybe it begins when the cryptography connecting them can no longer be trusted.

    That’s Cryptogeddon.

    And increasingly, I’m not sure I’m writing science fiction.

  • Welcome to ToddHDow Studios

    Welcome to ToddHDow Studios

    Adjust the existing cinematic workspace image to a wider, landscape orientation suitable for full-width display. Keep all current visual elements exactly the same: 12.9-inch iPad Pro with Logitech keyboard (no number pad), Apple Pencil and mug on the left side, and the WordPress writer’s workflow visible on the screen. Maintain the same dark, moody lighting, dramatic atmosphere, and realistic reflections. Expand the horizontal composition naturally, adding subtle desk and background detail on the sides so it feels intentionally framed for widescreen rather than cropped.

    ToddHDow.com has been part of my life for more than twenty years.

    Over that time it’s been a personal website, a résumé, a place to share projects, and occasionally a home for whatever happened to capture my attention at the time.

    If you’ve visited before, you might notice that things look a little different.

    Not because I’ve started over.

    Because I’ve finally decided to become intentional about where I’m headed.

    For years I’ve talked about writing novels, building worlds, running memorable tabletop RPG campaigns, and exploring the ideas that have fascinated me throughout my life. Those dreams always existed somewhere in the background, squeezed into evenings, weekends, and the occasional burst of inspiration between the demands of career and family.

    Eventually I realized something.

    If I was ever going to take writing seriously, I had to stop treating it like something I fit into the margins of life.

    It deserved the same commitment I’d given my career.

    ToddHDow Studios is that commitment.

    It isn’t a new beginning.

    It’s the next chapter.

    Following the Thread

    I’ve never been particularly good at having just one hobby.

    What I’ve always enjoyed is understanding how things work.

    Sometimes that’s a cyber attack.

    Sometimes it’s a medieval battle.

    Sometimes it’s a fantasy world.

    Sometimes it’s a beautifully crafted collector’s edition sitting on a bookshelf.

    Once something captures my imagination, I tend to dive in completely.

    I’m a lifelong reader and, admittedly, a bit of a book collector. Stephen King’s early novels, the Fighting Fantasy books by Steve Jackson that first taught me how stories could branch based on my decisions, epic fantasy like Brandon Sanderson’s Stormlight Archive and Robert Jordan’s Wheel of Time, modern favourites like Dungeon Crawler Carl—my shelves are filled with stories that reward curiosity and immerse you in carefully built worlds.

    That same curiosity spills into technology. I spend time experimenting with artificial intelligence, software-defined radios, emerging cybersecurity tools, and whatever new technology catches my attention. Not because I need another hobby, but because I genuinely enjoy learning how complex systems fit together.

    For a long time I thought these were separate interests.

    Now I realize they’ve always been connected.

    They’re all about understanding systems, exploring decisions, and seeing how consequences ripple outward.

    From Security Analyst to Storyteller

    I’ve spent more than twenty-five years working in cybersecurity, beginning as a security analyst and eventually serving as Chief Information Security Officer before moving into my current role as a Security Solutions Engineer.

    One of the biggest lessons that career has taught me is that systems rarely fail because of technology alone.

    They fail because people make decisions.

    Good decisions.

    Bad decisions.

    Sometimes impossible decisions.

    Every incident tells a story.

    Every attack begins with a choice.

    Every defense depends on someone seeing the bigger picture before it’s too late.

    Once I recognized that, I started seeing the same patterns everywhere.

    History.

    Politics.

    Business.

    Tabletop games.

    The best novels.

    Different settings.

    The same human questions.

    The Worlds I’m Building

    A wide cinematic collage blending four scenes seamlessly: a futuristic city skyline glowing with digital threat overlays and cascading code; a dramatic medieval battlefield with armored knights and billowing banners in smoky dusk light; a warm candlelit tabletop RPG scene with dice, miniatures, maps and rulebooks; and a close-up of an open writer's notebook with scribbled ideas, ink, and a fountain pen. All four scenes merge together in a moody, atmospheric composite — dramatic shadows, rich colors, cinematic widescreen composition, highly detailed, sophisticated and evocative.

    That’s why ToddHDow Studios is organized around four long-term creative worlds.

    Each one represents something that has shaped my life for decades.

    Cryptogeddon

    A moody cinematic wide illustration of a near-future city at night under subtle digital attack. Glass skyscrapers reflect cascading green and blue code. Faint glowing network lines arc across the sky like constellations. Tension in the atmosphere but not chaos. Dark, high-tech, realistic, dramatic lighting, sophisticated color grading, highly detailed, widescreen composition.

    This project is rooted in the career I’ve spent decades building.

    I’ve watched cybersecurity evolve from antivirus software and firewalls into artificial intelligence, ransomware, nation-state operations, and increasingly fragile digital ecosystems that underpin nearly everything we do.

    Somewhere along the way I stopped asking, “How do we defend against this?”

    I started asking, “What happens if we don’t?”

    Cryptogeddon is where those questions become fiction.

    It’s grounded in the technology I’ve spent my career working with, but ultimately it’s a story about people trying to navigate a world that’s changing faster than they can understand it.

    Holy Wars

    A moody cinematic wide illustration of a medieval battlefield at dawn. Thick mist hangs low over the ground. Armored knights and soldiers stand in silhouette holding banners that ripple in the wind. The sky is dramatic with dark storm clouds breaking to reveal faint early light. Realistic historical tone (not fantasy-heavy). Rich textures, dramatic shadows, sophisticated cinematic color grading, widescreen composition.

    Long before cybersecurity became my profession, I studied Philosophy and Religious Studies at the University of Toronto.

    My honours thesis—The Just War Theory and the Argument for Peace—traced Christian thinking about warfare from the time of Christ to the modern era.

    That research never really left me.

    History isn’t simply a collection of dates and battles.

    It’s a study of ideas.

    Leadership.

    Faith.

    Power.

    Ethics.

    And the stories civilizations tell themselves to justify conflict.

    Holy Wars is where I’ll continue exploring those questions.

    Book of Dow

    Book of Dow

    Every family carries stories.

    Some are preserved in journals and photographs. Others survive only through fragments—old letters, fading gravestones, whispered family legends, and unanswered questions.

    Book of Dow is my attempt to explore those stories.

    Part genealogy, part historical research, and part storytelling, it’s a long-term project inspired by my family’s roots in early New England. Whether that journey ultimately becomes a work of family history, historical fiction, or something that ventures into the supernatural shadows of Salem remains to be seen.

    What matters most is the search itself.

    Because every family has a past.

    Every place has its legends.

    And sometimes the line between history and myth isn’t as clear as we’d like to believe.

    Campaign Chronicles

    A moody cinematic wide illustration of a candlelit tabletop roleplaying game scene. Dice mid-roll across a detailed battle map. Painted miniatures stand in dramatic shadow. A Dungeon Master's screen partially visible. Warm candlelight contrasts with deep shadows. Rich textures, realistic style, sophisticated cinematic color grading. IMPORTANT: true full-bleed composition, no white borders, no letterboxing, no blank canvas space at top or bottom, edge-to-edge artwork filling entire frame.

    I first rolled dice as a kid.

    Like many people, life eventually pulled me away from Dungeons & Dragons.

    Years later I found my way back, and today I enjoy the hobby even more than I did growing up.

    I play around my own table, at friends’ homes, in local game stores, and online with players from around the world.

    As a Dungeon Master I’m drawn to horror, suspense, impossible choices, and campaigns where actions have lasting consequences. Ravenloft, gothic horror, and stories where the world remembers what the players have done.

    I’m also fascinated by how AI and modern technology are transforming tabletop gaming. From worldbuilding and encounter design to handouts, artwork, and campaign management, we’re living through one of the most exciting periods the hobby has ever seen.

    Campaign Chronicles is where I’ll share that journey as both a Dungeon Master and someone building a business around helping others experience unforgettable games.

    The Writer’s Notebook

    A moody cinematic wide illustration of a writer's notebook open on a wooden desk at night. Pages filled with handwritten notes, crossed-out lines, sketches, and margin ideas. A fountain pen rests across the page. A half-empty coffee cup nearby. Warm desk lamp light illuminating the notebook while the rest of the room fades into deep shadow. Atmospheric, reflective, sophisticated tone. Highly detailed, realistic textures, dramatic lighting, widescreen composition.

    Everything eventually comes back to writing.

    This is where I’ll document the journey itself.

    The victories.

    The frustrations.

    The lessons learned.

    The books I’m reading.

    The publishing decisions.

    The creative breakthroughs.

    The moments when everything seems impossible.

    And, hopefully, the moments when it all comes together.

    Because I suspect building these worlds will be every bit as interesting as eventually finishing them.

    Looking Ahead

    ToddHDow.com isn’t becoming something entirely different.

    In many ways, it’s becoming what it was always meant to be.

    A place where my professional experience, academic background, lifelong hobbies, and creative ambitions all come together under one roof.

    Whether you’re here because of cybersecurity, speculative fiction, history, tabletop gaming, writing, or simply because you’re curious about how creative projects grow over time, I’m glad you stopped by.

    My hope is that years from now someone can visit ToddHDow.com and discover something that sparks their own curiosity.

    Maybe it’s a novel.

    Maybe it’s a D&D campaign.

    Maybe it’s a historical essay.

    Maybe it’s an article about cybersecurity or artificial intelligence.

    Different projects.

    Different audiences.

    One philosophy.

    Worlds built on strategy, conflict & consequence.

    Welcome to ToddHDow Studios.

  • AI, Supply Chains, and the Next Cyber Battlefield

    AI, Supply Chains, and the Next Cyber Battlefield

    AI, Supply Chains, and the Next Cyber Battlefield

    I regularly track developments in cybersecurity, artificial intelligence, critical infrastructure, and geopolitical competition.

    Most of these stories disappear into the daily news cycle.

    A few feel different.

    A few reveal where technology is heading, how conflict is changing, and what tomorrow’s risks might look like.

    These are the signals that have captured my attention recently.


    Signal #1: AI Is Becoming an Operational Security Tool

    The conversation around AI often focuses on productivity and automation.

    The more interesting development is operational decision-making.

    Organizations are increasingly using AI to triage alerts, investigate suspicious activity, summarize incidents, and assist analysts during security operations. At the same time, attackers are experimenting with AI-assisted reconnaissance, vulnerability discovery, and social engineering.

    The race is no longer simply human versus human.

    It is becoming machine-assisted defenders versus machine-assisted attackers.

    Why It Matters

    For the first time, cyber conflict is beginning to scale beyond purely human decision-making.

    The side that can accelerate decisions fastest may gain a significant advantage.

    Organizations that learn how to effectively combine human judgment with machine speed may find themselves far better positioned than those relying on either one alone.

    Now Picture This…

    A nation-state launches a coordinated cyber campaign against multiple critical infrastructure providers.

    Human analysts cannot keep pace with the volume of alerts.

    Both attackers and defenders rely on competing AI systems making real-time decisions.

    At first, everything appears normal.

    Then one of the defensive AI systems begins making recommendations nobody fully understands.

    The analysts face a terrible choice:

    Trust the machine—or turn it off.


    Signal #2: Supply Chains Remain the Soft Underbelly

    supply chains

    The largest organizations in the world continue to invest heavily in cybersecurity.

    Attackers increasingly look elsewhere.

    Software vendors, contractors, managed service providers, and cloud partners remain attractive targets because compromising one trusted organization can provide access to hundreds—or thousands—of others.

    The strongest front door in the world matters little if someone leaves a side entrance unlocked.

    Why It Matters

    Modern societies depend on invisible trust relationships.

    Most people never see them.

    Attackers do.

    As organizations become increasingly interconnected, the security of one company becomes dependent upon the security of many others.

    Now Picture This…

    A small software company wins a contract supporting critical government infrastructure.

    The celebration lasts exactly one day.

    Unknown to everyone involved, the company was compromised eighteen months earlier.

    The vendor was never the target.

    The contract was.

    The attackers simply waited patiently for the right door to open.


    Signal #3: Critical Infrastructure Is Becoming a Battlespace

    critical infrastructure

    Electricity, transportation, communications, water systems, healthcare, and logistics networks are increasingly viewed through a national security lens.

    Governments around the world continue investing in resilience, redundancy, and incident response capabilities.

    That investment is occurring for a reason.

    Modern economies depend on digital systems that were never originally designed to operate in a contested environment.

    Why It Matters

    The distinction between cyber attacks and real-world consequences continues to blur.

    The question is no longer whether systems can be compromised.

    The question is what happens when digital disruptions begin producing physical effects at scale.

    Now Picture This…

    A regional power outage initially appears to be an equipment failure.

    Three days later, investigators discover similar incidents occurred across multiple jurisdictions over the previous six months.

    Each event was small.

    Each event was explainable.

    Each event was ignored.

    Viewed together, however, a disturbing pattern emerges:

    Someone isn’t attacking.

    Someone is rehearsing.


    What’s On My Radar

    • AI-enabled cyber operations
    • Critical infrastructure resilience
    • The expansion of cyber competition between major powers

    Most cybersecurity headlines focus on individual incidents.

    The larger story is the gradual normalization of cyber conflict as a persistent element of modern competition.

    For thriller writers, strategists, and anyone interested in the future, that may be the most important signal of all.

  • Worth reading this week – Cyberstalking, Leaks, Pi, startups, Libra, Internet trends

    Worth reading this week – Cyberstalking, Leaks, Pi, startups, Libra, Internet trends

    Quote I’ve been pondering:

    “A mind all logic is like a knife all blade. It makes the hand bleed that uses it.” – Rabindranath Tagore

    And this one came into my inbox last minute and had to include it this week as well:

    “I will have to remember ‘I am here today to cross the swamp, not to fight all the alligators.’”
    — From The Art of Possibility by Rosamund and Benjamin Zander

    He Cyberstalked Teen Girls for Years—Then They Fought Back – excellent reporting (as always) from Wired on the dangers of cyber stalking and the dangers that teens face in the never ending attempts by creeps to extort over nude selfies. Kids shouldn’t have to feel this way:

    “Any type of security thing can happen,” she said. “They can hack anything.” Her shoulders slouched, and she directed her voice to the table where we were sitting. “I just never envisioned that, and it’s just … We shouldn’t have to live in a world where we don’t know if people are real or not.” She folded her arms around herself and bit her lip to stop herself from crying.

    Parents need to be better informed about this and they need to equip their kids to be safe online.

    Oops: Personal data of 2.7 million people leaked from Desjardins (more coverage). A rogue employee took the data with him/her. This is difficult to prevent. As an infosec pro, I know firsthand just how difficult it is to find a balance between security and business productivity. In many cases, companies err on the side of convenience and ease of access to data. Unfortunately, we continue to see the results of not locking down data sufficiently. That said, there is lots that can be done.

    AttunityOops – part 2: TD Bank internal files found online in ‘keys-to-the-kingdom’ cloud data exposure (more from ZDNet) This one is simply shameful: “Attunity, a company that manages and safeguards data, left internal files exposed on the internet for clients including Ford and TD“. “Exposed data includes passwords and private keys for production systems, employee details, sales information.” “A company that manages and safeguards data”? Wow. It’s one thing for a non-security company to bungle access to their data, but it is quite another when a company who specializes in safeguarding data does it. I suspect Attunity sales / technical reps are fielding calls from their major clients today to discuss the status of their data and their contract renewals.

    RPi-Logo-SCREENNew Raspberry Pi 4: I love these tiny computers (buy now!). My only problem is that I don’t have much time to tinker anymore. Probably a good thing or I’d have a whole army of them around the house. HackerNews doesn’t disappoint with a crowdsourced list of plenty of interesting (or not) things to do with a Pi.

     

    Wanna do a start up? I’ve tinkered with starting my own business for years, but find it difficult to make the leap when I have been fortunate enough to have an interesting career working for other people. That said, I’ll always be a dreamer. My latest trigger article: Startup idea checklist. Such a good sanity check on building a business. And, some motivational reading as well: How I bootstrapped my side project into a $20k/mo lifestyle business (and my new indie business motivation website)

    companyofoneSpeaking of startups, I stumbled across this book online: Company of One: Why Staying Small Is the Next Big Thing for Business by Paul Jarvis . It looks similar to The Million-Dollar, One-Person Business: Make Great Money. Work the Way You Like. Have the Life You Want by Elaine Pofeldt, which I loved. Tons of great tips and motivation on building a sustainable, profitable one person business. We are all experts at something and we’ve all got something to sell. I haven’t purchased Company of One yet, as my backlog of books to read is huge, but I suspect I’ll pick up a copy soon to motivate me while distracting me from actually doing the work of building my own side hustle.

    I missed last week’s post, but had this queued to go out, so I’ll still keep this in this week’s post: The big news last week: Libra – a Facebook-led digital crypto-currency. Plenty of press on this one. The best quick summary I’ve read thus far is by the entertaining writers at The Hustle. Hard to say how well adoption will go – government oversight (boosted by financial industry lobbyists, no doubt) could yet hobble it. But, if they make it easy (embedded in existing systems like Facebook and the gang), secure and stable (the lack of a financial bubble a la bitcoin), then I suspect it’ll take off.

    Key findings from the Internet Trends report (as reported in The Idea’s June 17 email):

    Mary Meeker released her latest annual Internet Trends report at Recode’s Code Conference. Below are some of the findings most pertinent to the news media industry:

    • 15% of all retail sales are now though e-commerce. E-commerce is growing at 12.4%, and regular retail is growing at just 2%. (Ed note: look out for how publishers continue to capitalize on this growing industry through affiliate links.)
    • Digital ad spending grew 22% in 2018
    • Google and Facebook still dominate the digital ad market, but Amazon and Twitter are growing
    • 62% of all digital display ad buying is of programmatic ads, and that number is growing
    • Customer acquisition costs are increasing, sometimes exceeding customers’ lifetime values for digital subscription companies. Meeker suggests that free trials can be a cost effective way to alleviate that cost.
    • Time spent with digital media is still going up. Americans in 2018 spent 6.3 hours a day, 7% higher than the year before. More than 25% of U.S. adults are “almost constantly online.”

    Note: the above stats were all taken from Atlantic Media’s The Idea June 17 email – I don’t want to claim any credit for the summary presented above! If you are interested in the media industry, I highly recommend subscribing to their mailing list.

    I think that’s it for this week. For my Canuck readers, enjoy the long weekend!

    Todd