UPDATE: here's an [agenda + list of ideas to kick off the brainstorming](https://docs.google.com/document/d/1OoRG-mTESUCUpneJlgHB6r3Iler41AqdfXLNDR5zQj4/edit?tab=t.0). Please review + comment! I'll turn this into slides and spend 5-10 minutes presenting at the start of the session.
Everyone knows the cybersecurity status quo is not adequate for the future (it's not really adequate for the present). But the general mood seems to be a glum hope that somehow, against all experience, we will finally convince everyone – everyone – to apply patches promptly and stop making configuration errors or getting phished.
Let's brainstorm a better plan! Instead of treating vulnerabilities as pilot error, how can we change the rules of the game to systematically eliminate entire categories of attack? I'm hoping to convene some folks who know at least a little bit about cybersecurity, as well as out-of-the-box thinkers and anyone else who's interested, for a group brainstorming session.
(I'm thinking of past advances like HTTPS Everywhere, SPF, and DKIM. Future steps might include things like a full rollout of passkeys, [The Great Refactor](https://ifp.org/the-great-refactor/), forbidding ransom payments, and more systematic use of firewalls... but this is just a start, we need more and better ideas!)