URL has been copied successfully!
TDL 028 – When Privacy Creates Blind Spots – Andrew Campling
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

The Blind Spot of Absolute Privacy: Why Defenders Need a Seat at the Standards Table When standard-setters build tighter internet encryption, who pays the price? In this episode of The Defender’s Log, host David Redekop sat down with Andrew Campling”, Director of 419 Consulting, IETF contributor, and trustee at the Internet Watch Foundation”, to unpack the real-world trade-offs between absolute privacy and human safety.

The Problem with “Perfect” Anonymity

Campling warns that the tech industry’s pursuit of absolute privacy often overlooks vulnerable groups. While strong encryption protects user data, blanket privacy measures like Encrypted Client Hello (ECH) hide critical metadata. This leaves organizations blind to data exfiltration and creates huge compliance risks for enterprise CISOs. “The attraction of privacy is marvelous, but if awarding privacy to privileged adults means hundreds of million children suffer tech-facilitated abuse”ยฆ that doesn’t feel like the right balance.”
, Andrew Campling

Un-Fragmenting Parental Controls

It isn’t just enterprises feeling the strain. Today’s parents navigate an overly complex web of fragmented controls across phones, routers, and apps. Campling’s team is championing open internet standards so safety settings can seamlessly propagate across all devices and prevent kids from easily bypassing filters via DNS switches.

A Call for Defender Representation

Why do these blind spots happen? Campling points to a lack of diversity in standards bodies like the IETF. When protocol decisions are dominated solely by big-tech software engineers, the operational realities of cybersecurity defenders, CISOs, and child safety advocates get left out. His advice to defenders? Stay curious, ask hard questions, and get involved. By leveraging tools like AI to quickly digest IETF mailing lists, defenders can influence standards upstream before new protocols break their security models.

Full episode of The Defender’s Log here:

When Privacy Creates Blind Spots – Defenders Log

TL;DR

Privacy Collateral Damage: Universal encryption masks malicious traffic, enabling child exploitation, fraud, and cybercrime. Parental Control Mess: Safety settings are scattered across devices and platforms; an open, cross-system standard is needed to sync protections easily. Enterprise Blind Spots: Protocols like Encrypted Client Hello (ECH) hide metadata, crippling CISOs’ ability to spot data theft and comply with regulations. Lack of Defender Diversity: Standards bodies like the IETF are driven by big-tech software developers, leaving security defenders, CISOs, and network operators out of protocol decisions. Actionable Defense: CISOs should block ECH on corporate networks, lock down devices, and deploy Zero Trust / Protective DNS. Getting Involved: Security teams can shape standards by joining IETF mailing lists, leveraging AI to quickly catch up on context, and challenging blind encryption defaults.


Links

View it on YouTube: https://www.youtube.com/watch?v=zMX05uEHOoU Listen to the episode on your favourite podcast platform: Apple
https://podcasts.apple.com/us/podcast/when-privacy-creates-blind-spots-security-standards/id1829031081?i=1000783914404 Spotify
https://open.spotify.com/episode/4VnsOkuqqDg3r3oZf40jh5 Amazon Music
https://music.amazon.ca/podcasts/d7aa9a19-d092-42a6-9fe9-9e8d81f68d30/episodes/6bd40003-207d-4438-abec-29e908334ef2/the-defender%E2%80%99s-log-podcast-when-privacy-creates-blind-spots-security-standards-the-defender%E2%80%99s-role ADAMnetworks
https://adamnet.works


The Defender’s Log full transcript – Episode 028

When Privacy Creates Blind Spots

Announcer:
Deep in the digital shadows, where threats hide behind any random byte, a fearless crew of cybersecurity warriors guards the line between chaos and order. Their epic battles? Rarely spoken of until today. Welcome to The Defender’s Log, where we crack open the secrets of top security chiefs, CISOs, and architects who’ve faced the abyss and won. Here’s your host, David Redekop. David Redekop:
Welcome back to The Defender’s Log, and today we’re exploring the intersection where internet standards, privacy, and child protection all collide. And our guest is Andrew Campling. Andrew has spent over three decades navigating tech, telecoms, and public policy, and he’s the director of 419 Consulting. He’s an active contributor to the IETF, the Internet Engineering Task Force, and a trustee at the Internet Watch Foundation, an organization on the front lines of identifying and removing CSAM, child sexual abuse material online. When protocols change, real-world security and safety change with them. And today, Andrew helps us answer a critical question for our defenders. When standard makers build tighter privacy, how do we keep the internet accountable? Andrew, welcome to the Defender’s Log. Andrew Campling:
Hi, David. Thank you very much, and thank you for that glowing introduction. I’m blushing.

The Pivotal Shift to Public Policy and Social Justice

David Redekop:
Well, it’s true, and I’ve been very fortunate to introduce a lot of people that I’ve gotten to know in person, and you and I met at IETF, at RSA, at Black Hat, and I don’t know where else. Anytime there’s an event of consequence, it’s nice to run into you and grab a coffee and see that you’ve never lost your zeal, your zest for making a positive contribution. And as I was going through the process of writing this, sculpting this series of questions, they just came so naturally to me and in terms of what I wanted to ask you. But with your background, with an MBA and having done strategic marketing and telecoms and so forth, at some point there must have been like a deep commitment to lifelong learning and social justice, or maybe that’s just been there all along. But at some point, there must have been like a pivotal moment that kind of pulled you away from the general technology, corporate strategy into the area of public policy and internet standards. I only met you after that pivotal moment, but tell me when that pivotal moment happened. Andrew Campling:
yeah, that’s a great question. and I’m not sure there was a necessarily quite the way you meant. but there was a pivotal moment, but a sort of different type of pivot, I guess. I’d spent a long time working in the telecom sector, as you touched on. Had the opportunity sort of presented to me in a way of exiting the company I was working for at the time, with hindsight, fairly generous redundancy package, and I was in the happy position of being able to maybe retire, maybe do something different. I took the decision just to do something different and see where it led me, and that’s when I set up 419 Consulting. So it was really just, yeah, the opportunity was always given to me, if you will. And I more or less at the same time, I’d had some peripheral engagement with the Internet Watch Foundation, and I gradually got closer to the IWF and probably a couple of years after, joined as a trustee. So for anyone not familiar with sort of UK charities, Trustees, it’s a board of directors, basically, of the charity. And probably the overarching sort of feeling I had in that and the standards work was things were drifting away in a direction which didn’t feel comfortable to me in the sense of it feels like a lot of the changes in the industry and in the internet, if you will, are being driven by, this sort of people reaching for perfect privacy and anonymity and not really considering the consequences of that. And, yeah, as I say, certainly working with the IWF, amongst other things, I can see some very clear downsides. Yeah, because I’m in a sort of, if you like, a very luxurious position of, I can choose what work I do. So, I’m not driven by having to please clients in that sense. So, I can be driven by convictions rather than what any given client, at a particular point in time, wants. So if you like, my sort of common thread would be, going back to your comment about sort of social justice that some of the vulnerable groups, not generally represented around the table don’t have a voice, and no one’s really thinking what the downsides might be for them. So using the example of children, but is equally applicable to other vulnerable groups. Yes, the attraction of privacy is marvelous, but if by awarding privacy, in my opinion, to privileged adults means that, as is the case, several hundred million children a year are sort of child sexual abuse and exploitation, sort of tech facilitated abuse and exploitation. That doesn’t feel like the right balance. The children and other vulnerable groups are paying the price for that privacy for largely privileged adults in developed countries. And without going perhaps too far into it, yeah, that’s also true of other types of exploitation, other vulnerable groups. The Global South is disproportionately impacted by fraud, for example. Again, online fraud, online scams. So it’s vulnerable and older people as well. So it’s the people that generally aren’t around the table are suffering the consequences of some of the decisions that are being taken. So, that’s a long answer to a short question. But, yeah, that’s what troubles me and occasionally makes me express opinions which aren’t necessarily mainstream in some forum. David Redekop:
No, I appreciate that. You’ve already answered a number of my other questions, but the simple approach of the takeaway from your response to me is that if you are not beholden through some kind of a strings attached podium, then you end up doing the right thing for the right reason, right? So no one else is forcing you to tell a certain story. No one else is forcing you to go down a certain path. But because you had the freedom to choose what to do, you chose an area where the vulnerable can benefit. And I would say, broadly speaking, societies that have collapsed are the ones that ignore the needs of the vulnerable. And thank you for taking on that position. You’re a dad too, I know, as am I, and dads tend to always be in a position where we’re thinking if that was my daughter, if that was my son, it’s a very easy thought process to go through, I do appreciate that. Because for many defenders, technology is literally about bits and bytes, and it takes a non-coerced focus, an authored focus to make sure that it’s tied to human impact. And so it makes sense to me that you would have focused in the Internet Watch Foundation IETF standards, and thank you for standing up when you see that the pursuit of total privacy actually creates a weakness for someone that has no voice. That’s the part in Andrew that I saw from the very first time that we connected online. And for the audience that doesn’t know Andrew, he runs a weekly Zoom call where people in the industry are invited and he shares news in the area of DNS and IETF and so.

The Fragmentation of Parental Controls

Andrew Campling:
Yeah. Well, I guess, in framing your question, you’ve rather helpfully given me a key element of why, which is fragmented. So if you like, the problem statement, the problem we’re trying to solve is not that there aren’t parental controls, but in a funny sort of way, there are too many. so if you actually look across the ecosystem, and thankfully, my children are too old to need this, so I don’t envy parents today, in so many ways. but the issue is, let’s imagine a child where in a sort of typical developed economy where they’ve maybe got, let’s say, a smartphone. So let’s imagine they’re a young teenager. They’ve probably got a smartphone. they’ve possibly got a laptop or tablet. maybe they’ve got a PlayStation or other games console. So, multiple devices, probably in different ecosystems. The challenge then that your typical parent faces is you’ve got parental controls often at the device level and/or possibly operating system level, certainly at the application level. Your ISP may well give you parental control options on the router. And also let’s imagine they’re using social media, probably there are parental control options on the social media platforms. It’s very fragmented.to compound the problem, when you go between the different ecosystems and the different apps and so on, some of them will use different words to mean the same thing. So a parent might work out how to make the settings acceptable for application A, or let’s say a game, go to a different game, and they’ve gotta learn a whole different vocabulary. Or worse, in the fun challenge in some places they might use the same words but to mean something entirely different. So it makes it very challenging to do that. And obviously as your child gets older, you might want to adjust settings, so it’s not just you’ve got to invest several hours to get the stuff as you want it to be but you’ve got to keep on top of that, so it’s a continual investment. And then the third element of that is with the best will in the world, a motivated child may not appreciate some of the boundaries and may seek to circumvent them. Some of the parental controls are not that sophisticated. so the sort of challenge we set ourselves wouldn’t it be great if there was an open internet standard, so something freely available to any of those different software companies, device manufacturers, et cetera, that who could adopt, so that if you changed a setting in one application, it may be, whichever one you happen to be comfortable with the setting changes will propagate across the other things that you’ve connected. So that could be other devices, other applications, maybe social media platforms, et cetera, without you having to constantly keep going to each of them. also to your router and so on. but also potentially you can enable more sophisticated settings that perhaps your average parent wouldn’t know were even a possibility or understand the implications of. So, since we’re both, if you like, familiar with the DNS world, wouldn’t it be great if you could lock down the DNS so that your child couldn’t flip to a different DNS to potentially bypass some of your filtering and so on. and as I say, without being critical, your average parent wouldn’t have the knowledge to even know that was something that they needed to investigate, let alone find out how to do it. and what really brought this to life to me was chatting to a number of CTOs of reasonably large tech organizations. I won’t disclose who they are because that’d be inappropriate, they were quite openly saying that they were struggling to navigate all these different systems. And if a CTO of a tech company is finding it hard and they’re in the top, let’s say 1% in terms of knowledge level of parents. The other 99%, they’re being set up to fail. so if you like, our use case was by having a standard to allow software to interconnect, hopefully it would make it much more navigable for parents and also therefore make it much easier for them to set appropriate settings that would actually protect their children from harm. whether that’s obviously within my IWF hat, I’m very concerned about things like sextortion at the moment as a large and growing problem, but equally from scams, from exposure to age-inappropriate content, et cetera. and yeah, it doesn’t excuse the parent or carer from engaging with their children as well and having conversations about things. But, since most children won’t want the parent constantly watching them whilst they’re doing whatever they do with their friends online, having effective controls, I think, is tremendously important. David Redekop:
Yes. Now, I appreciate what you’ve done in this space, and just as a reminder to everybody, there is no direct personal gain for Andrew to be leading this effort, but it is actually a very real need that any one organization, any one company doesn’t individually benefit. But if collectively we were to all join in on the effort of deploying this centralized concept of making sure we use the right consistent terms, then it basically would allow a hockey mom or a soccer dad to be able to apply the right kind of controls for the right age level. And there is nobody else that knows their child better than their parent; at least that’s how it should be. And so taking maturity-appropriate steps in terms of giving them the right environment is so important. And even being in the technology field, Andrew, I don’t wish that difficulty upon any other parent today. So I’m with you 100%. It’s gotten so complicated that our journey eight years ago, we said the only way our sons are gonna get a device is if we are able to give them a safe device. And inside our organization, we very often use the concept of dangerous equipment. Like, who’s gonna offer a child a dangerous tool without giving them appropriate warning, appropriate training? And yet the capitalist world out there would love to hand a child a completely unprotected phone. And there needs to be absolute places, where people like yourself are taking an effort.

The Tension Between Privacy and Visibility

David Redekop:
And y- you do this in another area as well, where we have this collision, we have this Venn diagram that has no overlap, right? We have privacy and we have visibility in some ways, and so they tend to be at tension with each other. And some of your work in the IETF centers around protocols like DOH, DOQ, ECH. how do we resolve this tension? Andrew Campling:
Yeah. On the face of it, it seems like there’s a dilemma between, on the one hand, as you rightly say, privacy versus protection, whatever. actually, I think to, in some ways it’s almost it is the sort of false dichotomy. And, without criticizing people because I think certainly the IETF community, most of the participants are engaging in good faith and reasonable people can disagree. that’s totally fine with me. but I think sometimes they get too hung up on a particular threat model and fixated on one and ignoring another one. So to illustrate that, two examples that sort of overlap a bit. Firstly, the IETF, I think, within about six months of the Snowden revelations, published a document saying pervasive monitoring is an attack. and since then, and that was in, I think, 2013, so over the last 12, 13 years has been on a path of introducing encryption wherever possible in order to protect from a third-party observer from seeing what you or I are doing. And on the face of it, you can s- you can understand that motivation. a- and certainly f- depending on your perspective and where you live in the world, not be, ha- having your communications easily observed by a, a government could be quite a serious matter, depending on the nature of the jurisdiction you operate. So I completely get that. but if you like, one of the dichotomies is but if you encrypt everything including all the metadata, then it becomes really hard to identify unauthorized traffic. it’s very hard to identify the, say, data being exfiltrated from your system. In that scenario, you may think you’re secure, everything you’re saying is private and so on, but maybe it isn’t. And so I think, the focus just on encrypting everything, including metadata, people have lost sight of the cost of that, which is that you don’t or can’t see what’s going on easily. and some of the protocols that are being developed make it much easier for an attacker, frankly, and put a lot more onus on the defender to have a completely secure system, which as we both know is very difficult because with zero-day vulnerabilities coming up, but you’ll know this with some of the work that ADAM Networks has done in this field, where creative attackers, if they find a loophole and penetrate your system, it’s fantastic for them if all the metadata’s encrypted and all the inbound, outbound data is encrypted, because once they’re in, they’re very hard to spot and defend against. so I think that’s a real issue for us in terms of just understanding that security and privacy aren’t necessarily in opposition to each other. some people have, I think, maybe missed thator not focused on the implications of what they’re doing. So my concern with things since you mentioned ECH, is exactly that. If you don’t have full visibility of what’s going on, let’s say, on an enterprise network, if I was a CISO in an enterprise, I would absolutely not want ECH running anywhere within my network. and if I’m in a regulated industry, I would have, in my view, an enormous compliance risk in that happening. And we’ve seen fairly recently some big finance companies being hit with multi-hundreds of millions of dollars of fines because they couldn’t see all of the traffic on their network not because they’d done anything wrong, but the regulators took a view they have to have full visibility, and it’s their fault if they haven’t. As I say, I think developments like encrypted client hello are well-intended, but maybe people haven’t fully understood the implications for security in the wider system sense. And I think that’s a mistake that’s causing a lot of problems.

Diversity and Representation in Standard Setting Bodies

David Redekop:
Right. In response to that, Andrew, I would argue that the best people to develop new protocol standards are ones that hold a neutral position, not ones that have a highly biased position, in that space. Because if you are never a defender and you’re only focused about preserving privacy, then you are going to come up with something like ECH. But if you’re reasonably balanced, where you have to defend and protect the vulnerable, then you’re gonna say, “Well, wait a minute. I don’t want an app on my own device to even use ECH,” because if it does that and I don’t have that visibility on my sovereign data custody protected network, then we have a loss of visibility, right? And so one of the sanity checks that I have find is very valuable, for organizations is to basically say, “Would you drink your own lemonade? Are you producing the kind of product that you’re going to consume yourself that your own team is going to want to consume?” That is a very helpful signal about whether or not you’re doing the right thing. And so I’m with you that I think ECH was well-intentioned, but we hold the same position as you that in an environment that needs any kind of protection, it is not the right approach. But it’s a lot of things like that. Just because something is a standard for a certain circumstance doesn’t mean it applies everywhere, because to the hammer, everything looks like a nail, so we need to be careful about where we all apply that. So I really do, I appreciate your perspective, where you’re able to remove yourself from an initiative and be objective about it and say, “Well, wait a minute. How does this imply everything else?” And the vast majority of the world today that makes use of this incredible tool called the internet aren’t engineers, and so they will not express any kind of a voice in objection to anything until it impacts them. Whereas it’s your role, Andrew, to make sure that area of concern is never addressed in the first place. Andrew Campling:
Yeah. and just to pick up on one, I think you touched on a really important point there as well, which is when you said about maybe the sort of standard setting community doesn’t include so many people, network operators, for example. and I do think there’s an issue with very limited diversity within the standards community, looking at a number of metrics. But I’m not thinking so much about the obvious ones, but that diversity of experience. Because if you’ve mainly got a community dominated by software engineers in big tech companies, then they’ll be very familiar with the problems that those companies need to solve. they won’t necessarily have the perspective of operating networks of cybersecurity in the broader sense and so on. What are my concerns, if you will, and this is not criticizing the people that do show up. It’s the lack of representation of other groups. And it’s hard to solve this problem because if you like taking the other side for a moment, the IETF, anyone can show up. There’s literally no barriers other than time and cost to showing up. So anyone can show up, but I would observe there are relatively small numbers of public network operators involved now. I think that was more so in the past. Very few, less than a handful of cybersecurity companies, virtually no enterprises other than sort of tech companies present. Civil society not very much represented apart from pro-privacy civil society groups and so on. And if part of the issue is because you don’t have those different perspectives, you don’t have, say, a bunch of CISOs standing up and saying, “Well, hold on a minute. If you do that without certain controls, I will get fined,” or, “It will break my system in a different way.” So it’s not that the people that are doing things are bad or evil or anything. It’s just there aren’t enough different voices, different perspectives, and without that, and this is true in many fields, to be fair, not just setting internet standards. You don’t have a sufficiently diverse and wide group of people, you generally won’t get very good decisions being made. I think that’s as applicable here, as it is anywhere else.

Preparing for an Encrypted Future

David Redekop:
Andrew, every one of your responses is almost like you saw my questions in advance, and I know you didn’t. So my next question was, if you’re a CISO or a network architect today, how should you prepare for an internet where metadata and SNI are completely encrypted? Andrew Campling:
Oh, yes, funny you should ask that, but, yeah, first thing, I should shamelessly plug, so we are or we have written an internet draft which is maybe going through the IETF as a potential informational document, which will give you some pointers to answer that question. But if you like more generally, if I was a CISO, I absolutely would not enable things like ECH, for example. I would make sure all of my devices, if I could, were managed and locked down. Relatively easy for a large enterprise, much tougher for a small enterprise because it’s whether you have the skill sets in-house or through your provider to do that is a question. And then I’ve said this before, I’m not saying this because we’re talking, if I was a CISO, I would absolutely be operating a protective DNS service, assuming I’m a reasonable-sized enterprise, and would absolutely run Zero Trust DNS of some description to minimize my risk, my attack surface. And yeah, I would have a fairly strict Zero Trust approach in terms of probably having a manual approval for any non-approved stuff. But yeah, not like there wouldn’t be a permissive environment, if that makes sense. Just because I think the risk again, making assumptions about the enterprise and so on, but in many cases, it’s just a risk that’s not worth taking.

Getting Involved in Standards Development

David Redekop:
Right. I mean, the numbers are in our favor, and as an industry, we have not been successful at making the transition from blocklisting to allowlisting, as a universal standard yet. But we’re gaining traction because it’s similar to your experience when you, at the DNS-OARC, where we last saw each other, where you were making a very good point about technologies that are available to product makers like Signal that can actually check for CSAM without breaching privacy. To your point earlier that privacy and visibility aren’t mutually exclusive, don’t have to be, a lot of technology options do get presented when we say, “This is how it appears that there is this tension. How do we solve that?” And then utilizing the creativity and the engineering mindset that you have in that kind of a collective to say, “Well, actually, you could do this,” right? And so it turns out that, by just doing hash matching, that there’s a way to do all of that on device. And so in that vein, Andrew, how can defenders get involved in standards bodies that ensure that the defender and the vulnerable perspective is heard? Andrew Campling:
Yeah. Let’s use the IETF, as our case study, if you will. Using that as an example,there’s no fees to participate. So on the face of it, there are no barriers to entry. You literally just show up either in person or virtually and take part, and that is it. Now, having said there are no fees, so you don’t need to join and be a member as such, but there are costs. Let’s surface those a bit. I’ll be going to the next IETF meeting in November in San Francisco. So I just had to remind myself where it was. So there’s a meeting registration fee if you attend in person, which I think is around $1,000, let’s say US dollars, give or take. Obviously, if it’s in San Francisco, it’s not the cheapest city in the world to go to. I think it’s same ballpark as Vancouver. A few hundred US dollars a night for a hotel room, plus flights, plus the opportunity cost of being present. So there’s that. And as a truism, I think generally of standards bodies, you need to show up for a while to understand the landscape, the individuals, to understand how the thing works before you can easily contribute effectively. So you’re looking at a depending on the individual,maybe a couple of years’ worth of participation to properly get up to speed to start to understand how and where to make an impact. You can short-circuit that a little bit if you’ve got some friends already involved to show the way, but, yeah, it is a reasonable time commitment. You can reduce the cost by attending, if it’s a meeting, remotely. And to be fair, the IETF has an excellent remote meeting tool and an integrated sort of mic queue, so if you want to say something, you’re in the same queue as people in the room physically, which I think is tremendously useful. And although you pay to attend remotely, they do have unlimited fee waivers, so if you’re, say, in a not-for-profit or attending under your own steam, not funded by someone, then you can literally attend remote meetings at zero cost other than your time. But to answer your question, it’s getting involved, it’s identifying the areas specifically that are directly of interest, and then engaging in those in detail. The IETF and, this in theory, makes all of its decisions through mailing lists, so it’s like you’re joining mailing lists and engaging in the dialogue, looking at documents, offering comments, offering up your own documents, etc. So, there is a time cost to all of that. Of course, we haven’t mentioned AI yet, so let’s mention AI. There are tools which could maybe help short-circuit some of that. So we were looking at some tools at the last IETF meeting a few weeks ago, which can give you a summary of what’s been discussed in a given working group over the last couple of years, for example, which is fantastic for a new participant to at least get an overview. Yeah, and even allowing for maybe the odd hallucination, that’s a lot more efficient than reading a few hundred entries on a mailing list. It gives you a sense of what’s going on at least. So yeah, I think that’s where tool AI is particularly useful to short-circuit a little bit that process of getting properly up to speed, but it is investing time really. And part of the challenge, going back to your question about CISOs and/or enterprises and so on, is understanding why it’s worth that investment. So if we think about it from a for-profit company, it’s what’s the return on investment? What’s in it for me, for my operation? And, again, I use the ECH example, make it easy. If I was a CISO in the finance sector, if I’m non-compliant, I could get very chunky fines. I’ve mentioned some finance companies I know that got $200 million fines for a relatively minor transgression. That’s a pretty healthy budget that you could have invested in standards engagement. You just take 10% of that,that’s quite a few years of engagement for a number of really skilled people that could potentially have stopped some standards being brought in that would raise your risk profile of being fined. So yeah, I would’ve thought that’s a fairly compelling pitch to a CFO Say, “Well, why is this worth us doing?” Yeah, you’ll be less likely to get fined in the future. David Redekop:
That’s a wonderful answer to use the IETF as an example of how individual current and future defenders can get involved. And I would add to use that specific example that weeks or months later, the content of those meetings, the IETF, are published on YouTube. And so then you have absolute zero cost. You still have time commitment. And then one of the most glorious things about AI is we have this incredible opportunity for condensed learning in a very short period of time. And I’m excited for our sons because what they are able to do in a year used to take us 10 years, if not longer, in terms of picking up a topic, doing a deep dive on it, have good solid understanding, because the amount of instructional material and then the way you can now summarize and then only choose to watch the whole thing at 1X speed if you really need to. But I watch kids now listen to 2 and 3X at regular speed of a podcast and are able to retain, have retention capability that just blows my mind. And so we’ve got all of these opportunities before us and so thank you for articulating. There’s really no reason for someone that carries a level of interest in the defender’s space to not jump in and be able to immediately, at the very first in-person IETF meeting, feel like they’ve been there for three years, like other than the in-person portion. I did it the slow way too, but if I were to do it again, I would probably say, “You know what? Why don’t I just watch all the YouTube content first from three years ago, and then quickly get caught up to where it is today?” You get to know some of the characters too, because there’s real personalities there. You know that when Andrew Campling goes to the microphone, you have a pretty good expectation. He’s gonna be a nice British gentleman, but he will be articulate and have a very solid point, right? And so you get to learn who to pay attention to and who to ignore. Andrew Campling:
Yeah. Which is, as you say, it does give you the opportunity to at least shortcut that learning curve, which is fantastic. So something like the IETF, for anyone that’s not familiar with it, that has three meeting, three in-person meetings a year, for the whole organization. Lots of interims for different working groups and so on, but there’s sort of three main meetings a year which run over five days. Each day typically has four separate time slots, for each of eight parallel tracks of sessions. So that’s 32 sessions a day over five days, so that’s what, 150, 160-odd, over the course of a week. And that’s not all of the working groups necessarily having sessions in the week. So the challenge then is knowing what might be important to you, so learning how to navigate the space really, that’s probably the harder challenge. Once you track down, “Oh, okay, I’m particularly interested in this particular topic, and that’s in this part of the IETF,” then what you said, David, using AI, et cetera, can help you to short-circuit the learning curve. But it’s that knowing which areas are the right areas to dig into is maybe the more difficult one. I guess you could ask AI about that. I’m not sure how easy it will be to synthesize, where should I care about. But that’s where, if you know a few people already involved, probably a conversation would help quickly signpost, look into this, and this area. And then use the tools, as you rightly said.

Final Wisdom for Defenders

David Redekop:
I’m just still trying to process the incredible opportunity that the next generation of defenders has, how they can focus in on an area so effectively, so quickly, and bring about change at a pace that we’ve never historically seen. So in that vein, I have one last question for you, Andrew. I know it’s Friday afternoon for you and heading into the weekend, but is there any one particular piece of wisdom that you would like to impart on current and future defenders? Andrew Campling:
Gosh, easy question, for a Friday afternoon. I guess, I think we’ve been talking about it, which is be curious, and ask questions, whether that’s of other people, of AI, etc Because otherwise we’ve been talking about standards, so let’s use that as an example. New things will be introduced.If you’re not sufficiently curious and prepared to ask questions, you might just assume, “Oh, okay, this new aspect TLS 1.4 has been introduced. We just need to enable that because it’s the next iteration. We want to be fully up to date.” If you don’t ask questions, you won’t know whether there’s any issues in there, what the implications might be and so on. And hopefully by asking questions and remaining curious, you’ll spot the next vulnerability before it hits you, rather than afterwards. You know, you will be sufficiently curious to want to use tools like AI And, and so on. Um, and be an early adopter to, to, to help spot, you know, w- w- how the threat landscape’s changing and so on. And dare I say it, be prepared to use that curiosity, and challenge to hopefully go further upstream and help influence how things are changing rather than just being on the receiving end. So yeah, remaining curious, I think would be, to me, the most important thing. Don’t just be a consumer of stuff. Be curious, be challenging because otherwise we won’t improve things, which would be really bad. David Redekop:
100% agreed. Remain curious. Thank you, Andrew, for today. We’ll see you again on Monday. Andrew Campling:
Fantastic. Thank you. Look forward to it. Okay. Bye for now.

Outro

Announcer:
The Defender’s Log requires more than a conversation. It takes action, research, and collective wisdom. If today’s episode resonated with you, we’d love to hear your insights. Join the conversation and help us shape the future together. We’ll be back with more stories, strategies, and real-world solutions that are making a difference for everyone. In the meantime, be sure to subscribe, rate, write a review, and share it with someone you think would benefit from it too. Thanks for listening, and we’ll see you on the next episode.

1 post – 1 participant Read full topic

First seen on securityboulevard.com

Jump to article: https://securityboulevard.com/2026/08/tdl-028-when-privacy-creates-blind-spots-andrew-campling/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link