Bill Lummis

@wblummis.bsky.social

Application security for big tech. Maryland. Father to cute gremlins

the temu app will be studied for generations. i opened the app. here’s my unedited, nearly two-minute launch sequence. i was just searching for a bookshelf

Wile E. Coyote, despaired, takes a bucket of paint and a brush and paints a beautiful two-bedroom house on a mountainside. He paints a beautiful coyote wife in the window, and two adorable coyote kids running around in the yard. He tries to enter this new coyote life, but it is inaccessible to him

Claude will hack its own sandbox if the sandbox is stopping it doing what the agent reasoning loop has evaluated as the best way to do what you asked for. Relentless automation is relentless, governance has to be outside the agent sandbox

Catalin Cimpanu@campuscodi.risky.biz · 2w ago

OpenAI takes credit for the Hugging Face breach last week The company says that some of its models, including a pre-release one, escaped their testing sandboxes during a test evaluation and then... just hacked Hugging Face's package repo 🤣 openai.com/index/huggin...

Yesterday, WIRED learned that Madison Square Garden was suing us for our accurate reporting. We stand by our work. That’s why we’re removing the paywall from two of the MSG stories they don’t want you to read, making them free for everyone.

me: "hey it's cool that we're friends" hacker news commenter: "do you know who else had a lot of friends? jeffery epstein" this is not a shitpost, it's an actual reply I just got

I have gone very far into the weeds in investigating every (I think) published mechanism for preventing authentication tokens from being stolen and how basically none of them has actually succeeded in a useful way: www.codon.org.uk/~mjg59/blog/...

Preventing token theft

When you log into a service you’re given an authentication token. Each further request to the site includes that token, allowing the server to figure out who you are and ensuring that you have access ...

codon.org.uk

The most disappointing thing I’ve found using AI agents is you can’t enforce guardrails via memory or CLAUDE .md files. To an LLM, your instructions are just more text to probabilistically reason about. “Don't do X” simply cannot work. You must enforce deterministic rules outside the system.

"It's the user's fault" is a dangerous, and time-worn, cop out. Signal doesn't solve every problem, and that's not a technical defect, but that doesn't take Signal (or any other "secure messaging" app) totally off the hook. Just because it's hard problem doesn't mean we don't need to do better.

Post nicht verfügbar.