High Signal Podcasts Evidence ledger
Method
Browse
← Back to evidence

Evidence receipt / preference

Published · transcript-backed

Daniel Miessler: preference

1 Jun 2026 The Cognitive Revolution Inside Nathan's Second Brain: Daniel Miessler, Security Expert & Creator of PAI, Audits My AI Setup

“There's also one called head scale, which is an open source version which you can kind of run like just on Cloudflare or whatever. So I, I'm, I'm using both of those, I like to not have anything facing the Internet because of the kind of the mythos effect.”

— Daniel Miessler

Source trail

Everything needed to verify it.

Speaker
Daniel Miessler
Attribution
Verified speaker
Claim type
preference
Recorded
1 Jun 2026
Publisher
The Cognitive Revolution

Transcript context

…Is I think amazing, although I definitely want to understand and maybe you can help me understand better. Like what I'm exposing myself to with doing that. But this makes it really easy at least, you know, as long as the security problem isn't so bad for me to connect these computers. And then there there are multiple ways in which they can be connected. I use the screens app on my phone to log into the UI on either the laptop if it's like still sitting at my desk and I'm away, or the Mac mini, which is always there. And then I also have Termeus, which is a mobile terminal client that s s HS in again through this, you know, all through the the tail scale private network and can then, you know, go in and do shell stuff on on either computer. And this has been like pretty good for setting. It took me a while to get to it, but it's, it's now pretty good, you know where I can kind of have pretty seamless connectivity from a phone to both computers, regardless of where I am. And, and that's key because I just keep finding that like something always needs a little reboot. You know, it'll like work for days, but then, you know, for some reason the Telegram channel just like isn't connecting anymore. You know, why isn't it connecting? Restart, open claw, restart cloud code, you know, and then it'll start working again. But if you, if you can't reach that computer in a way that gives you the level of access to be like, I'm going to just run this command. Then, you know, you take a trip and you're 3 days into your trip and the thing doesn't work anymore. And you're like, I went to all this in trouble and I couldn't, you know, and now I'm still somehow locked out. So I think that networking setup has been really good for me. But I'm but I'm, I'm so I'm very mindful, used to never really care about security. I always felt like security by obscurity was enough for me. Now I'm like, well, not in the AI. You know, you're of possible mass surveillance. It's not right. And obviously mythos and everything else. So maybe first concrete question, how would you feel about that set up from a security standpoint? Yeah, I don't. I don't think it's bad. I don't think it's bad. I do worry a little bit about small apps that you use to the extent that anyone uses them that are just kind of useful and you're just like, well, it couldn't be that big of a deal. But those smaller companies, the smaller the company, the less the chance that they have a security person, you know, like if they have passwords or whatever, like they just might be part of a breach. Like at any point they could easily be part of a breach, especially with like agents running around basically hacking and doing bounties all the time. So I, I worry about like how many companies have I given access to? So that's my first sort of heuristic is like give anything sensitive to the fewest number of companies. I think tail scale is a great solution. There's also one called head scale, which is an open source version which you can kind of run like just on Cloudflare or whatever. So I, I'm, I'm using both of those, I like to not have anything facing the Internet because of the kind of the mythos effect. But I mean, this is my background is actually doing attack service attacking and monitoring. So having because IP SACK and PPTP, the VPN's all listen on the Internet, which means a worm or something of vulnerability can hit them, whereas Tailskill is outbound. So it's not, you don't have anything open technically. The downside is if Tailscale gets compromised, they're just going to walk around on everyone's internal network, right? And unfortunately it gets, it's pretty easy to have a prompt that says what are the highest leverage compromise points and let's steer our attack towards those types of things. The only piece of security that I think someone like us has there is that if Tailscale were to be compromised, they would be hitting other places before us and hopefully we would know beforehand we'd be able to turn everything off and block everything or whatever. But that is a major consideration is where is your choke point? How many people are you giving your stuff to? But in general I would say Tailscale is not a bad solution. OK, sort of. I guess I'm still, that boils down to in some sense I'm still security through obscurity. A couple of follow up questions on on that and and maybe a couple other tools as well. So the other tools I'm using to share access. One is 1 password where I've got a family account vaults that are specifically intended to be shared with agents, command line installed on the Mac mini and the the agents can access passwords through the command line. As of now I think they have more advanced stuff, but it might only be at the moment for enterprise. What I was able to, you know, immediately sign up for, for a few bucks a month or whatever as a consumer and did not have a human in the loop to approve the sharing of a password with an agent at runtime. So it was instead the solution I came up with in consultation of course, with Claude was have two different vaults and just have the agents instructed that this vault, which is the agent's auto vault, is you're just free to use that whenever you want. You know, so things like brave search, ceramic search, whatever, I mean, all, you know, a bunch of actually quite a few different things.…

Stored transcript either side of the excerpt. The highlighted words are the published quote; the surrounding text is unedited source, never generated.

Search evidence