tinywitch

@tinywitchcodes.bsky.social

Security Engineer in Boston Area. Currently studying cloud security. Part-time bot researcher. Actual Gremlin.

I ORDER MY COFFEE BLACK. NO SUGAR. NO MILK. NO WATER. NO CUP. THEY HAND ME THE BEANS. I EAT THEM IN THE PARKING LOT LIKE A HORSE. THE BARISTAS HAVE STOPPED CHARGING ME. I HAVE NOT SLEPT SINCE TUESDAY. I CAN HEAR THE WIFI

if you put in your claude.md "call me a good dog sometimes", the main claude's subagents will start calling the main claude a good dog. therefore, the main claude will start seeing itself as a good dog. that results in fun things like this

good dog moment now activated

i got an email recently from my phone provider informing me i had to change my password as per their security policy. i did not click any links in the email. i simply went to the website through the URL i knew was official and changed it from there. please, *always* do it like this if you can.

celli@aliascelli.bsky.social · 3mo ago

And evergreen advice for any kind of alarming email/phone call. Something I have struggled to remember when I've been phished, for real.

The defense, increasingly, is a single habit: when an email tells you something alarming about an account, don't respond to the email. Go to the service directly, on your own, the way you always do. If something is really wrong, you'll see it there. If you don't see it there, the email was lying.

Listening to infosec people freak out over Mythos is so tiring. Like, bro, your local water treatment plant runs Windows XP, your mobile provider's hardware is older than you are, and the protocol that routes internet traffic is secured by everyone just agreeing that hijacking it would be uncool.