CategoriesSchoolTechnology

Cognitive Offloading

“The danger of the future is not that machines will begin to think like humans, but that humans will begin to think like machines.”

— Sydney J. Harris | #CognitiveOffloading

I have a confession to make, and it’s embarrassing: my spelling and grammar have gone directly into the toilet over the last eighteen months.

It didn’t happen because I suffered a head injury, and it didn’t happen because I suddenly forgot how the English language works. It happened because modern Large Language Models have gotten so terrifyingly good at parsing whatever phonetic slurry I vomit into the prompt box that my brain simply stopped bothering with syntax. When you’re in the zone, trying to push progress forward at 100 miles per hour, you realize the machine doesn’t give a damn about commas, capitalization, or whether you used “their,” “there,” or “they’re.” It interprets your chaotic garbage with surgical precision.

So, in the sacred name of momentum, all writing discipline went out the window. My prompts look like a drunk raccoon ran across a mechanical keyboard at 3:00 AM. And because the AI spits back a pristine, articulate answer every single time, my brain’s laziness circuit got a big, juicy hit of dopamine. That was warning shot number one.


1. Using a Nuke to Hammer a Nail

There is a specific kind of modern insanity where you commit staggering, planetary-scale computational overkill just because the input box is sitting open on your second monitor.

Case in point: last week I needed a corporate logo for a rapid prototype mockup. In the sane, pre-AI world, the protocol was elementary. You open a new browser tab. You type the company name into Google Images. You click “Tools,” filter by “Color: Transparent,” right-click the PNG, and drag it into your canvas. Time elapsed: 8 seconds. Compute expenditure: roughly 0.00004 watt-hours.

Instead, what did I do? Like an absolute lunatic, I opened Midjourney and burned through an ungodly cluster of liquid-cooled enterprise GPUs in a remote data center to hallucinate a synthetic approximation of a logo that already exists on six thousand free public CDNs.

It is the literal definition of using a thermonuclear warhead to hammer in a picture hook.

Figure 1: Architectural diagram of my daily workflow. High voltage, zero common sense, like this image

It brings out our worst, most slothful human impulses. But if you have ADHD like I do, AI doesn’t just make you lazy; it puts your hyper-fixation engine into uncontrolled redline. In the past, having a weird technical itch came with built-in speed bumps. If I wanted to resurrect an obscure 1998 PC abandonware game by reverse-engineering the binary to patch memory leaks on modern x86_64 silicon, the sheer friction of tooling would usually talk me out of it by midnight. Or I would get tired of it and find some new shiney project to work on.

Now? The friction is dead. The barrier between “I wonder if I could decompile this DLL” and “Holy shit, it’s compiling” has shrunk to twenty minutes. It’s intoxicating. It hands you superpowers, but it also leaves you at 4:00 AM with nineteen half-deployed GitHub repos, four domain names you just registered, and an attention span that looks like a shredded tire.


2. Telemetry and Studies: Is AI Actually Rotting Our Brains?

It turns out that creeping sensation of mental flabbiness isn’t just self-loathing. It’s measurable neurology.

Cognitive psychologists have tracked cognitive offloading for years. Its the process of delegating memory and processing to external hardware. But recent research from the MIT Media Lab put hard telemetry to it. By hooking participants up to EEG monitors during analytical writing exercises, researchers found that users who outsourced synthesis and drafting directly to generative AI registered the lowest levels of frontal lobe engagement compared to those doing standard manual search or raw writing. When you eliminate the sweat of structuring an argument, your neural retention flatlines.

The starkest breakdown of this dynamic comes from a landmark working study conducted by Wharton researchers Hamsa Bastani, Osbert Bastani, and Alp Sungu: Generative AI Can Harm Learning. They tracked thousands of high school students tackling STEM curriculum under controlled conditions:

  • The Crutch Effect (Raw LLM Access): Students given unfettered access to standard ChatGPT solved 48% more practice problems during study drills. They felt invincible. But when they sat down for independent proctored exams without the AI, they bombed—scoring 17% worse than students who had never touched an AI tool at all. They had confused the bot’s competence with their own.
  • The Tutor Effect (Scaffolded Guidance): When the researchers constrained the model to act as a Socratic tutor, refusing to spit out answers, providing conceptual hints, and forcing the student to execute the logic it all reversed.

The empirical takeaway is brutal in its clarity: Using AI to generate your answers rots your brain. Using AI to interrogate your own thinking sharpens it into a scalpel.


3. The Gentrification of the Web: RIP to My 90s Fantasy Football Site

Beyond our frying synapses, there is an aesthetic tragedy unfolding across the internet: the wholesale murder of human weirdness in web design.

AI has caused the commoditization of frontend engineering. Anyone with twenty bucks and an API key can prompt a responsive web application into production. On paper, that democratization is a miracle. In practice, because these models are trained on the median aesthetic consensus of Silicon Valley venture-capital pitches, every single new website looks exactly the damn same.

You know the look: rounded Bento box grids, pastel blur gradients, 48-pixel floating sans-serif headers, and acres of empty glassmorphism panels that display four pieces of data across an entire 27-inch 4K monitor. It is sterile, corporate, AI maximalist beige.

Here is my villain origin story: I belong to a fantasy football league that has been running uninterrupted since the early 1990s. For over two decades, our league was hosted on an independent platform that had not touched its UI codebase since roughly 2002. It was glorious. It had raw HTML tables. It had high information density. It wasn’t flashy like the ESPN or Yahoo apps, but you could see every roster, matchup, and waiver wire transaction on a single screen with zero latency.

Two weeks ago, we logged in for our annual draft. Some well-meaning developer had clearly taken a prompt-to-code tool and unleashed a full AI-maximalist overhaul across the entire stack. Everything was hidden behind floating accordion menus. Player cards took up half the viewport. The draft board looked like an uninspired SaaS landing page for an enterprise cloud analytics suite. I wanted to throw my mac book through the drywall.

I miss the jagged, unpolished edges of human web design. I miss ugly, bespoke utilities built by people who cared about solving an actual problem rather than showing off how many animated CSS backdrop-filters their framework could render before your laptop fans spun up.


4. Incident Review: Where the Leverage is Unbeatable

So am I ready to smash my silicon and retreat to the woods? Not yet. Because when you strip away the Silicon Valley marketing slop, the real-world operational multipliers are staggering. In my own life, AI has become needed in two high-stress domains:

A. The Cybersecurity Degree Grind

I am currently grinding through my Bachelor’s degree in Cybersecurity. In technical domains, relying on an LLM to write your assignments is suicide. I wouldn’t survive a single live technical interview or certification exam. But using it as an adversarial sparring partner? Fuck me.

Think about the historical shift: our parents went from thumbing through microfiche and library card catalogs to querying early AltaVista and Yahoo. That leap compressed weeks of research into hours. AI represents that exact same generational leap forward. When I’m analyzing packet captures in Wireshark, auditing firewall configurations, or staring at x86 disassembly, I don’t ask the model for the answer. I have it spin up targeted diagnostic quizzes, explain obscure RFC edge cases, and challenge my mitigation logic. It turns passive cramming into active, high-tempo red-teaming. Though I admit sometimes I just want the answer.

B. First-Generation “AI Parenting” at 2:00 AM

My wife and I have zero family living nearby. When our kid wakes up at 2:15 AM screaming inconsolably with an unusual symptom, or when a bizarre behavioral curveball hits at school, our parents aren’t always awake or available on speed dial.

We are among the very first generation of human beings raising children with large language models on our nightstands. I plan to write an extensive standalone piece on this dynamic, but the candid reality is that AI has been an indispensable, unflappable triage partner. It doesn’t replace our pediatrician, or any required professional but it does lend the proverbial hand. The reason it works is simple is pretty simple. I grew up in the era where teachers docked full letter grades if you failed to cite primary sources, and where quoting Wikipedia was treated like academic treason. That battle-tested reflex is permanently hardwired into my nervous system: Trust, but verify. Hopefully thats the same in todays school but I have a feeling its not.


5. Postmortem: Cutting Through the Hype

Let’s be real about Big Tech’s current rhetoric: the venture-backed sales pitch is 80% breathless bullshit. AGI is not showing up next Tuesday to take your job, write your novels, and solve the heat death of the universe. The hype is suffocating, and the grifters are out in force. Yet, sneering at the technology and pretending it’s a useless toy is just as stupid. Across infrastructure engineering, vulnerability research, and everyday household triage, the practical leverage is real, permanent, and compounding. It sucks because peoples lives will and are being affected.

The dividing line isn’t technological; it’s behavioral. If you use AI as a mental couch potato machine to avoid the sweat of thinking, it will hollow out your grammar, dull your reasoning, and turn your creative output into generic corporate sludge. But if you treat it like an on-demand sparring partner and you force it to test you, question you, and accelerate the hard work, it’s the most potent tool since the invention of the compiler.

Keep your grammar tight. Respect the struggle. And for the love of God, leave the 2002 fantasy football layouts alone.

Authors Note: I am trying to get back into writing posts. For reasons already listed here I need to keep my brain challenged or I am going to end up typing everything in wingdings. I look forward to chatting with everyone again and keeping my little piece of the internet lively and green.

CategoriesTechnology

Complex Realities: In Defense of Microsoft’s Recent Cloud Breach

Defending against cyber threats is like guarding a fortress in a digital realm – every byte counts in the battle for security. -Unknown

Update: When I wrote this post, Microsoft had not completed their investigation of the cyber attack. Specifically, they hadn’t figured out how the key was stolen. A couple days ago they announced they had discovered how the key was stolen and boy its a doozy. The system where the key was stored, was in fact a secure system. Employee’s were background checked, required special permissions to access the system, and overall it was tightly controlled. At some point the system crashed and created a crash dump. A engineer investigating the issue, did not have the tools they needed on system and the dump was moved to an insecure system. That engineers credentials were eventually stolen and were used to access where the crash dump lived. The attackers discovered the keys in the crash dump and the rest is history. Just goes to show you what you are up against, when you join cyber security.

On July 11th, Microsoft announced that customers in their Azure and Office365 environments had been breached. The affected customers were mostly US Federal Agencies, and per Microsoft, the attacker was most likely a nation-state actor from China. As more and more information came out, articles were written by countless organizations stating “Countless Problems” and how “grossly irresponsible” Microsoft was in terms of Security. I’ve written about my qualms with Microsoft in the past, but as someone who worked there, the amount of blowback isn’t warranted. The attack certainly deserves an external review and an internal one, but certainly not to the level it’s currently getting. The complex realities are that vulnerabilities exist in everything because they were built by humans and are used by humans.

What Happened?

For those who are unaware, here is what happened:

In July 2023, Microsoft revealed details about a cyber espionage campaign conducted by a threat actor called Storm-0558. This group, believed to be China-based, targeted various organizations with forged authentication tokens to access user email accounts. The attack was focused on government agencies and consumer accounts within the public cloud, with the objective of unauthorized email data access. Microsoft has thwarted this campaign and taken steps to enhance security measures and inform affected customers.

Threat Actor and Objectives: Storm-0558 is a China-based cyber threat actor engaged in espionage. The group’s activities involve targeting diplomatic, economic, and legislative entities in the US, Europe, as well as individuals connected to geopolitical interests like Taiwan and Uyghurs.

Attack Techniques: The group employs tactics like credential harvesting, phishing campaigns, and OAuth token attacks. The use of OAuth applications, token theft, and token replay in Microsoft accounts is noted. In this attack they used a stolen inactive MSA key. At this time Microsoft doesn’t know how they obtain the key. See Token Forgery Section.

Initial Access and Exploits: Once inside, they deploy malware like China Chopper and a shared tool named Cigril.

Compromised System Access: After infiltration, Storm-0558 acquires credentials from sources such as LSASS process memory and Security Account Manager (SAM) registry hive. With valid account credentials, the actors access compromised users’ cloud email accounts to extract information.

Discovery and Analysis: Microsoft detected anomalous data access on June 16, 2023, and attributed it to Storm-0558 based on prior tactics. The initial assumption of token theft was revised when it was found that the actors were forging Azure Active Directory (AD) tokens.

Token Forgery: Storm-0558 exploited an acquired Microsoft account (MSA) consumer signing key to forge authentication tokens. This allowed them to access Exchange Online data. Azure AD keys were not affected. Microsoft has taken corrective measures to prevent this kind of attack.

Access Techniques: The threat actor used forged tokens to authenticate via legitimate client flows. They exploited a flaw in the GetAccessTokenForResource API to obtain new tokens, enabling access to mail messages from the Outlook Web Access (OWA) API.

Actor Tooling: Storm-0558 utilizes PowerShell and Python scripts to make REST API calls against the OWA Exchange Store service. These scripts can download emails, attachments, and conversations. The group employs proxies and disguises its activity with various User-Agents.

I would highly recommend anyone who is interested in security to go read the write-up about the event here. In my defense of Microsoft, I have to credit them for releasing this article on the events of how things happened. Many companies will follow Federal disclosure guidelines and then proceed with a ton of hand-wavey bullshit that everything is fine. Crafting this article aids companies and security engineers in detecting and safeguarding against additional cyberattacks, ultimately benefiting the entire cybersecurity community.

In Defense

The most critical article I have seen is this one from Arstechnica. In it, the author talked about a Senator from Oregon putting Microsoft on blast for “negligent cybersecurity practices” and how the CEO of Cyber Security firm Tenable took to Linkedin explaining how they had warned Microsoft this would happen. Tenable had discovered the issue with one of their banking clients, and it scared their security team so much they rushed to get Microsoft to fix the issue. The CEO goes on to explain that Microsoft took their time fixing the issue and was breached in the process. The senator from Oregon, on the other hand, believes that Microsoft should have never deployed systems in the states they were in and failed basic security practices.

Generated using AI

That being said, I disagree with what is being said. There are different levels of threats and vulnerabilities, and based on those levels, the most critical should be acted on first. It’s part of the reason we have CVE and CVSS scores. Microsoft is huge, and we have no idea what other vulnerabilities they were dealing with at the time of the disclosure. On top of that, this attack doesn’t look like it could have been carried out without having some level of access to the system already. The attack required a key to chain together with the actual vulnerability, allowing an inactive key to generate tokens that allowed access to all sorts of data. If I am Microsoft and I have a CVE of 9 that I am currently fixing, and a 3rd party company comes in with a CVE of, say, 7.5 and says, with the right key, this API can be abused, what would you do? It’s a priority, but you will keep fixing the higher critical issues. Microsoft’s response might not have been as swift as some expected, resulting in vulnerabilities being exploited. However, it’s unlikely that they remained inactive. Their subsequent actions upon discovering the issue demonstrate their proactive approach.

While I can’t get into too much detail, I will say of all the places I have worked in my career, Microsoft had the best security controls. Segregation of permissions and the network were everywhere. Getting access to business-critical systems or customer data was never permanent. Regarding their Federal Office365 environment, security was taken to a different level. I had to get my fingers printed for a background check, and we worked in a secure room. The amount of controls in place to do anything in that environment was unlike anywhere else I have worked. From an external perspective, Microsoft has enormous legacy debt while also trying to provide the same level of service as AWS and GCP. It looks like in their move to “move fast and break stuff,” they deployed a keystore outside policy and in an unsafe manner. I would be curious to find out how the attacking group got hold of the key, but we may never know.

Unlike certain companies that view security as an impediment, prioritizing progress over protection, Microsoft takes a fundamentally different approach. They don’t engage in mere checkbox security theater or heed advice only post-breach. Microsoft’s proactive stance stands in stark contrast, valuing security as an integral part of their operations rather than an afterthought. At least, that was the case when I worked there.

They Aren’t Perfect

Despite my defense of Microsoft, I do need to state that they did make some mistakes:

  • Deploying a keystore with valuable keys where one could leave the company is a big mistake. Maybe it was an inside actor; perhaps it was scraped off an employee’s machine. Either way, a key that could generate that much access should be locked down tight with processes involved in retrieving it.
  • Certificates that don’t expire or are valid for years. I’ve worked at multiple companies where this is true. I can’t say I am surprised, but since it’s Microsoft policy never to have certificates that last that long, they should practice what they preach.
  • The fact that a customer found out something was wrong before Microsoft is not a good look. I can’t imagine how much data they ingest, but as a security engineer, it always leaves you on the wrong foot when a customer tells you something is wrong before you know.
A look east at the Microsoft Campus, with the Redmond Technology Station on the far left.

These challenges extend beyond Microsoft’s domain; however, given their significant presence as a leading cloud provider, they rightly bear a greater responsibility. Their pivotal role in the cloud landscape necessitates a higher standard of security and accountability.

After Thoughts

I readily acknowledge my skepticism toward cloud technology. With the three major US cloud providers collectively hosting countless businesses, vulnerabilities loom large. A single update, misconfigured keystore, or even a single rogue employee can potentially compromise these platforms. Like hunters drawn to a massive whale in the vast ocean, hackers are irresistibly drawn to cloud providers in the United States, lured by the sheer abundance of businesses hosted on their platforms, making them high-value targets for cyber intrusions. Microsoft messed up, they can do better, but this attack isn’t some gross irresponsibility.

Anyway, I hope enjoyed the latest article. Once again good luck to all the engineers out there, and until next time, stay safe!

The Northeast Blackout of 2003