How I Learned to Stop Worrying and Publish the Feed - Dr. Strangelove as a Threat Intelligence Manual
Stanley Kubrick released Dr. Strangelove or: How I Learned to Stop Worrying and Love the Bomb in 1964. It is a film about an automated retaliation system, a communications gate that fails at the worst possible moment, a room full of confident men reading a board that is already wrong, and a conspiracy theory built entirely out of correlation.
We spent this week measuring our own automated blocking system. Every single one of those turned out to be a documented failure mode we could point at in our own data. The film is sixty-two years old and it is a better operations manual than most vendor whitepapers.
Here is the rundown, in roughly the order the film hands them to you.
"The whole point of the Doomsday Machine is lost if you keep it a secret!"
This is the film's central joke and it is the entire argument for open threat intelligence.
The Soviets build a doomsday device that triggers automatically, with no human able to stop it. It is technically magnificent. It is also completely useless, because they were saving the announcement for the Party Congress. A deterrent nobody knows about deters nobody. Strangelove — delighted, appalled — has to explain this to the room.
The threat intelligence industry has built the same machine, thousands of times over. Detection that lives inside one organisation protects one organisation. The indicators sit in a private platform, priced beyond the reach of the people getting hit hardest, and the adversary's behaviour never changes because the adversary never learns anything.
There is a second effect the film does not get to, because nobody in that war room ever admits a mistake. A published feed gets corrected. When you put indicators where strangers can pull them, strangers tell you when you are wrong. A private feed's errors are immortal — no outsider can see them, so nothing ever forces the fix. Publishing is not just distribution. It is the error-correction mechanism.
The Big Board is not the war
The war room's centrepiece is an enormous illuminated map showing exactly where everything is. It is beautiful, it is authoritative, and for most of the film it is describing a situation that has already stopped being true.
Our shield ran green the entire time it was making a mistake. It reported healthy, because from its own point of view it was doing precisely what it was configured to do. Nothing alerted. Nothing could have alerted — the system had no way to know that one of the things it was refusing was something we wanted.
We only found it because we went looking, on a hunch, on a Sunday. That is not a process. That is luck wearing a lab coat, and the correct response is to build the check that catches it next time rather than congratulating yourself for the hunch.
A green dashboard is a claim, not evidence. It tells you the system is doing what it was told. It cannot tell you whether what it was told is correct. Those are different questions and only one of them is on the board.
General Ripper and the fluoridation of everything
Brigadier General Jack D. Ripper launches a nuclear strike because he has noticed a correlation between fluoridated water and his own fatigue, and reasoned outward from there into a total theory of Communist infiltration. He is not stupid. He is pattern-matching without a denominator.
This is the single most common failure in open-source intelligence work, and it is seductive precisely because the pattern is usually real. Yes, those addresses are related. Yes, that infrastructure overlaps. The question Ripper never asks is how often does that happen anyway — because a correlation with no base rate is not a finding, it is a Rorschach test.
We caught ourselves doing it this week, twice. We flagged a set of crawlers as wrongly blocked, and when we checked properly, three of the four were impostors — rented cloud machines wearing a well-known crawler's name to walk past naive filters. Then we over-corrected and briefly concluded a genuine crawler was fake too, because we ran a reverse-DNS check against an operator that publishes no reverse DNS. Wrong instrument, confidently read.
The discipline is unglamorous: before you publish the pattern, establish what the pattern looks like when nothing is wrong.
The CRM-114 discriminator, or: fail-closed has a bill
The bomber cannot be recalled because its receiver — the CRM-114 — will only accept messages preceded by the correct three-letter prefix, and the receiver has been damaged. The gate works perfectly. That is the problem. It is so rigorously fail-closed that the legitimate operator cannot get through either.
Every authentication decision is this trade, and it does not have a free answer. Fail-open and your control is decorative. Fail-closed and you will eventually lock out the person who needed in.
We shipped a fail-open bug this week and had it caught in review within the hour. The logic looked reasonable when written: if we cannot verify a crawler because DNS is misbehaving, let it through, because wrongly blocking a search engine is expensive. Reasonable, and wrong — because the only thing upstream was a self-declared name. Anyone could have claimed to be a search engine and walked past the entire system.
The error underneath was a definitional one. We had equated not verified with blocked. They are not the same. Failing verification just meant being treated as ordinary traffic, which a real crawler sails through anyway. Once you see that, the trade collapses: failing closed cost almost nothing, and failing open cost everything. Most fail-open decisions are made by people who have quietly mispriced one side of that ledger.
Brute-forcing the recall code
To recall the bomber they need Ripper's three-letter prefix, which he never wrote down. So they start guessing systematically — OPE, OPO, POE — and eventually get it, because a three-character keyspace is not a keyspace.
This is a credential-stuffing run performed by the Pentagon, in 1964, and it works for exactly the reason it works today: the secret was small enough to enumerate and nobody had modelled that as a risk. Anything guessable will be guessed, and the guessing will be done by a machine that never gets bored.
A related and more uncomfortable version: our own automated permutation searches turned out to be roughly half the query volume in our search logs. We had been measuring our own robot and calling it audience. Enumeration is powerful, which is why the other side uses it too, and why you should always ask which side of your data a machine is standing on.
"We must not allow a mineshaft gap!"
In the final scene, with the world ending, General Turgidson pivots seamlessly to warning that the Soviets will build better post-apocalyptic mineshafts than the Americans. The rivalry survives the apocalypse. He is inventing a gap in a domain that does not exist yet, because a gap justifies a budget.
The security industry runs on mineshaft gaps. Every quarter has a new category, a new acronym, and a new number describing how far behind you are. Some of it is real. A great deal of it is Turgidson, extrapolating a threat into a domain nobody has entered yet, because fear converts to budget more reliably than evidence does.
The antidote is boring and it works: publish your denominator. How many did you look at, how many were bad, and how do you know? A vendor who will not answer that is selling you a mineshaft.
Major Kong rides it down
The most famous image in the film is a man riding a falling bomb, whooping, hat in hand. Kong is not a villain. He is diligent, brave, and extremely good at his job. That is exactly why the ending happens — he presses on through damage and jamming and does precisely what he was ordered to do, long after the order stopped making sense.
Automation is Major Kong. It will execute the instruction with total commitment and no capacity to notice that the world changed. Our shield made 5,288 blocking decisions in sixteen days with zero human involvement, and it was right the overwhelming majority of the time — and it also could not have told us about the one case where it was wrong, because being wrong was not a thing it could perceive.
That is not an argument against automation. Automation at that scale is the only thing that makes cheap security possible for people who will never hire an analyst, and we are firmly in favour of it. It is an argument that the human's job moved. You are no longer in the loop making the decision. You are outside the loop, auditing the decisions, on a schedule, with a denominator — because the machine cannot audit itself and will never once tell you it is having a bad day.
What the film actually gets right
Dr. Strangelove is not a film about weapons. It is a film about systems that behave exactly as designed while producing an outcome nobody wanted, and about the confident people watching a board that no longer describes reality.
Everything in our field that goes badly wrong has that shape. The automation is correct and the assumption underneath it rotted. The dashboard is accurate and measuring the wrong thing. The gate is rigorous and locked out the only person who could have stopped it. The pattern is real and means nothing. The deterrent is magnificent and nobody was told.
Kubrick's ending is the one lesson we would rather not take. Ours does not have to end that way — but only if we keep telling the world what the machine is doing, and keep checking whether it is still true.
We cap our confidence at 95 percent on principle, which in this context means: something in our own stack is currently wrong in a way we have not found yet. So is something in yours. The difference between a working security programme and a war room is entirely in what you do about that sentence.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=how-i-learned-to-stop-worrying-and-publish-the-feed-dr-strangelove-as-a-threat-intelligence-manua




Comments