Featured Article

Beloved hacking veteran Kelly ‘Aloria’ Lum passes away at 41

Aloria will be remembered for her hacking acumen, memorable memes and unparalleled karaoke skills

Comment

Kelly "Aloria" Lum poses for a portrait photo.
Image Credits: Patricio Robayo (opens in a new window)

Kelly Lum, better known in hacking circles as Aloria, passed away on Sunday.

Aloria was a veteran of the cybersecurity community, especially the one in New York, her home for many years. The Twitter account of the New York City security conference SummerCon announced her death on Monday, prompting a seemingly endless list of people to publicly mourn her loss and pay tribute to her life.

People who knew her call her an “angel,” an “incredible woman,” “so prickly and dark and funny, and yet warm and welcoming,” “brilliant, sharp, deeply witty […] a daring adventurer, a kind soul,” “one of the funniest, kindest and most honest people” on Twitter, “unique and memorable,” “a legend […] brilliant, generous, hilarious,” the “the archetypal hacker, both technical and unconventional in the non-technical,” “kind and welcoming,” someone whose “magic was making us all feel seen & appreciated just as we were,” an “inspiration,” “the peak of original content, a real character,” and someone who “truly did change stuff for the better.”

According to the SummerCon official Twitter account, “Kelly did not take her own life, but passed due to progressed critical illness, in a hospitalized setting surrounded by her family.”

Aloria was 41, and she’s survived by her husband.

Some people remember her for her qualities as a person, and for her contributions to hacking culture, more than for her technical abilities, even though she was very knowledgeable and a remarkable cybersecurity professional.

“I feel like Aloria represented what the infosec industry is at its best: performing fantastic feats of problem-solving with playfulness, ingenuity, and authenticity. She was an industry legend and a trailblazer, but I don’t think she ever saw herself that way,” said Kelly Shortridge, who knew her for more than a decade as both she and Aloria were part of the New York City hacking scene. “Unlike most security luminaries, she actually lived her life as to what fulfilled her rather than what inflated her ego. She was generous and the antithesis of a gatekeeper; she welcomed me in the industry when few others did.”

Image Credits: Screenshot / Kelly ‘Aloria’ Lum

Zach Lanier, who knew her for more than a decade, said she was like “a sibling” to him, and one of his best friends. When he and Aloria lived in New York City at the same time in the early 2010s, they would have a tradition of going out with other cybersecurity folks every Thursday, first to a Mexican restaurant in Union Square, where they would order “too many tacos and margaritas,” and then to a karaoke bar.

Aloria loved to sing Separate Ways by Journey. The two would also sing Forgot About Dre, with Aloria singing Dr. Dre’s parts, and Lanier singing Eminem’s parts, Lanier said.

“She would nail it and knock it out of the park every time,” he said.

“You don’t want to go after her because it’s like: ‘Oh, God, how do I follow that up?’ It’s as if your opening act is a professional and you are an amateur,” said another friend of Kelly who works in cybersecurity, who asked not to be named as his company doesn’t allow him to speak to the press.

Her death, Lanier said, is particularly tragic because from his point of view, “she found a semblance of happiness that I had not seen for a while.”

“She was the happiest she’s ever been,” said Erik Cabetas, another veteran of the New York cybersecurity scene who knew her since 2009.

Clippy meme
A meme memorial made by Erik Cabetas. “She would have particularly liked this,” he said pointing at Clippy. Image Credits: Erik Cabetas

Katie Moussouris, who also knew her for more than a decade, highlighted the fact that Aloria had been part of the cybersecurity industry for around 20 years — one of the few women to have done so. Other than her technical qualities as a hacker and cybersecurity professional, Moussouris said that Aloria “was so giving not just with her time, but her spirit. Anything she could share that would help a person she would, and she did.”

“She was just a beautiful tortured soul,” Moussouris said. “Her whole existence and everything that she gave to everybody — I was like: how does she even have it left given her struggles?”

Aloria often talked openly about having bipolar disorder, a chronic — and often misunderstood — condition that I also suffer from. It’s impossible to quantify something like this, but having someone so prominent and well known in the cybersecurity scene talk so openly about mental health probably inspired and helped so many people overcome the stigma that mental health issues, particularly bipolar disorder, unfortunately still carry.

“I’ve been trying to explain away stigma, and it kind of occurred to me that that’s not how you erase stigma. I suffer from Bipolar II disorder and I’m also a multiple suicide attempt survivor,” she said in a 2016 video. “You don’t rationalize away stigma, you can erase it by being a positive example of someone who has gone through these things and come out on top, being successful at overcoming the challenges that they are faced with.”

“If there hadn’t been so much stigma associated with bipolar disorder I might have been diagnosed earlier,” she continued, explaining that she was only diagnosed recently, despite struggling with her mental health for a long time. “And I wouldn’t have had to spend 20 years struggling and becoming hopeless because I didn’t think there was a solution for me.”

“My life now is — I’m not gonna say it’s perfect. I still have dark days but I have done so many amazing things, traveled to some awesome countries, have awesome friends, flew a plane once,” she said. “It’s a long hard road ahead sometimes, but that doesn’t mean that the journey isn’t going somewhere, and it isn’t worthwhile.”

A picture of Aloria wearing a funny t-shirt.
A picture of Aloria wearing a funny t-shirt. Image Credits: Zach Lanier

Lanier said that Aloria “was always very helpful… she always wanted to help people,” by being open and honest about her own mental health struggles.

Matthew Bischoff, a former Tumblr product and engineering manager, who worked with Aloria at the social media network, said that Aloria’s “ability to meme almost anything will stick with me for a very long time.”

“Her sense of humor, commitment to doing the right thing for users and fierce advocacy for the causes she believed in were all hugely impactful on me and my career,” they said.

While at Tumblr, Aloria advocated for turning on HTTPS by default on the site, which would make users’ connections to the site more private and secure. The well known Twitter user SwiftOnSecurity wrote that her “pushing HTTPS and LetsEncrypt at such a massive blogging platform had real waves across the industry.”

“She was also an unsung hero, and a lot of things she did, she didn’t really like to broadcast. I think that’s true of a lot of — especially women in the security community,” her anonymous friend said. “Because of how unfair the security community can be, I think a lot of women are hesitant to stand out.”

“Many people know her for her iconic retro computing swag, [the meme account] Infosec Reactions, and other cultural contributions to infosec but she wrecked many systems. In fact, I suspect her humility relative to her peers is why her fierce exploitation prowess was not mentioned as often,” Shortridge said. “She could deftly navigate compromising systems as well as defending them, and her views were always well-reasoned rather than self-serving — again in contrast to many of her peers.”

Cabetas said that Aloria was a great hacker, but also asked me to “let people know that she was about the lulz.”

Indeed, she was. In her spare time, Aloria maintained the hilarious Twitter parody account “Infosec Reactions,” 3D-printed things like a pickle with Nicholas Cage’s face, collected silly t-shirts and hats, traveled the world — Lanier said she set foot on all continents, including Antarctica — and took beautiful pictures that she would post on her Instagram and Tumblr.

And, of course, she was a formidable karaoker.

More TechCrunch

Jasper Health, a cancer care platform startup, laid off a substantial part of its workforce, TechCrunch has learned.

General Catalyst-backed Jasper Health lays off staff

Live Nation says its Ticketmaster subsidiary was hacked. A hacker claims to be selling 560 million customer records.

Live Nation confirms Ticketmaster was hacked, says personal information stolen in data breach

Featured Article

Inside EV startup Fisker’s collapse: how the company crumbled under its founders’ whims

An autonomous pod. A solid-state battery-powered sports car. An electric pickup truck. A convertible grand tourer EV with up to 600 miles of range. A “fully connected mobility device” for young urban innovators to be built by Foxconn and priced under $30,000. The next Popemobile. Over the past eight years, famed vehicle designer Henrik Fisker…

9 hours ago
Inside EV startup Fisker’s collapse: how the company crumbled under its founders’ whims

Late Friday afternoon, a time window companies usually reserve for unflattering disclosures, AI startup Hugging Face said that its security team earlier this week detected “unauthorized access” to Spaces, Hugging…

Hugging Face says it detected ‘unauthorized access’ to its AI model hosting platform

Featured Article

Hacked, leaked, exposed: Why you should never use stalkerware apps

Using stalkerware is creepy, unethical, potentially illegal, and puts your data and that of your loved ones in danger.

10 hours ago
Hacked, leaked, exposed: Why you should never use stalkerware apps

The design brief was simple: each grind and dry cycle had to be completed before breakfast. Here’s how Mill made it happen.

Mill’s redesigned food waste bin really is faster and quieter than before

Google is embarrassed about its AI Overviews, too. After a deluge of dunks and memes over the past week, which cracked on the poor quality and outright misinformation that arose…

Google admits its AI Overviews need work, but we’re all helping it beta test

Welcome to Startups Weekly — Haje‘s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. In…

Startups Weekly: Musk raises $6B for AI and the fintech dominoes are falling

The product, which ZeroMark calls a “fire control system,” has two components: a small computer that has sensors, like lidar and electro-optical, and a motorized buttstock.

a16z-backed ZeroMark wants to give soldiers guns that don’t miss against drones

The RAW Dating App aims to shake up the dating scheme by shedding the fake, TikTok-ified, heavily filtered photos and replacing them with a more genuine, unvarnished experience. The app…

Pitch Deck Teardown: RAW Dating App’s $3M angel deck

Yes, we’re calling it “ThreadsDeck” now. At least that’s the tag many are using to describe the new user interface for Instagram’s X competitor, Threads, which resembles the column-based format…

‘ThreadsDeck’ arrived just in time for the Trump verdict

Japanese crypto exchange DMM Bitcoin confirmed on Friday that it had been the victim of a hack resulting in the theft of 4,502.9 bitcoin, or about $305 million.  According to…

Hackers steal $305M from DMM Bitcoin crypto exchange

This is not a drill! Today marks the final day to secure your early-bird tickets for TechCrunch Disrupt 2024 at a significantly reduced rate. At midnight tonight, May 31, ticket…

Disrupt 2024 early-bird prices end at midnight

Instagram is testing a way for creators to experiment with reels without committing to having them displayed on their profiles, giving the social network a possible edge over TikTok and…

Instagram tests ‘trial reels’ that don’t display to a creator’s followers

U.S. federal regulators have requested more information from Zoox, Amazon’s self-driving unit, as part of an investigation into rear-end crash risks posed by unexpected braking. The National Highway Traffic Safety…

Feds tell Zoox to send more info about autonomous vehicles suddenly braking

You thought the hottest rap battle of the summer was between Kendrick Lamar and Drake. You were wrong. It’s between Canva and an enterprise CIO. At its Canva Create event…

Canva’s rap battle is part of a long legacy of Silicon Valley cringe

Voice cloning startup ElevenLabs introduced a new tool for users to generate sound effects through prompts today after announcing the project back in February.

ElevenLabs debuts AI-powered tool to generate sound effects

We caught up with Antler founder and CEO Magnus Grimeland about the startup scene in Asia, the current tech startup trends in the region and investment approaches during the rise…

VC firm Antler’s CEO says Asia presents ‘biggest opportunity’ in the world for growth

Temu is to face Europe’s strictest rules after being designated as a “very large online platform” under the Digital Services Act (DSA).

Chinese e-commerce marketplace Temu faces stricter EU rules as a ‘very large online platform’

Meta has been banned from launching features on Facebook and Instagram that would have collected data on voters in Spain using the social networks ahead of next month’s European Elections.…

Spain bans Meta from launching election features on Facebook, Instagram over privacy fears

Stripe, the world’s most valuable fintech startup, said on Friday that it will temporarily move to an invite-only model for new account sign-ups in India, calling the move “a tough…

Stripe curbs its India ambitions over regulatory situation

The 2024 election is likely to be the first in which faked audio and video of candidates is a serious factor. As campaigns warm up, voters should be aware: voice…

Voice cloning of political figures is still easy as pie

When Alex Ewing was a kid growing up in Purcell, Oklahoma, he knew how close he was to home based on which billboards he could see out the car window.…

OneScreen.ai brings startup ads to billboards and NYC’s subway

SpaceX’s massive Starship rocket could take to the skies for the fourth time on June 5, with the primary objective of evaluating the second stage’s reusable heat shield as the…

SpaceX sent Starship to orbit — the next launch will try to bring it back

Eric Lefkofsky knows the public listing rodeo well and is about to enter it for a fourth time. The serial entrepreneur, whose net worth is estimated at nearly $4 billion,…

Billionaire Groupon founder Eric Lefkofsky is back with another IPO: AI health tech Tempus

TechCrunch Disrupt showcases cutting-edge technology and innovation, and this year’s edition will not disappoint. Among thousands of insightful breakout session submissions for this year’s Audience Choice program, five breakout sessions…

You’ve spoken! Meet the Disrupt 2024 breakout session audience choice winners

Check Point is the latest security vendor to fix a vulnerability in its technology, which it sells to companies to protect their networks.

Zero-day flaw in Check Point VPNs is ‘extremely easy’ to exploit

Though Spotify never shared official numbers, it’s likely that Car Thing underperformed or was just not worth continued investment in today’s tighter economic market.

Spotify offers Car Thing refunds as it faces lawsuit over bricking the streaming device

The studies, by researchers at MIT, Ben-Gurion University, Cambridge and Northeastern, were independently conducted but complement each other well.

Misinformation works, and a handful of social ‘supersharers’ sent 80% of it in 2020

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Okay, okay…

Tesla shareholder sweepstakes and EV layoffs hit Lucid and Fisker