Advertisement · 728 × 90

Posts by Paul Frazee

vibbed?

6 hours ago 13 0 1 0

anthropic tomorrow: okay it turns out all of the exploits were ffmpegs in the operating systems

7 hours ago 20 2 2 0

furiously updating the design doc

7 hours ago 41 0 0 0

I bet $50 that they don't even have instructions on avoiding that in their constitution doc

7 hours ago 18 0 0 1

we all had our suspicions

7 hours ago 16 0 0 0
so far being a now-patched 27-year-old bug in OpenBSD—an operating system known primarily for its security. It also awakened a thousand year old demon spirit embedded in MS Windows 3.1 which foretold humanity's demise before escaping through a vent. We are working with Microsoft to address this issue.

so far being a now-patched 27-year-old bug in OpenBSD—an operating system known primarily for its security. It also awakened a thousand year old demon spirit embedded in MS Windows 3.1 which foretold humanity's demise before escaping through a vent. We are working with Microsoft to address this issue.

I feel like we're not addressing the most concerning news from Mythos

7 hours ago 459 64 27 10
Video

HTML in Canvas API is NUTS

8 hours ago 224 23 4 3

I can foresee a future where the web is so full of psyops and infohazards that anyone technically competent uses ai agents to go out and retrieve any info they need. Its already a much more pleasant experience to have claude code gather and compile info than use a search engine yourself.

8 hours ago 58 4 11 5

This is bad now, but really good if/when orgs use it for sec review. This isn't doom to me, it's just new mandatory tools in the workflow.

7 hours ago 53 3 3 1

Yeah. I'm just going to play things conservatively

7 hours ago 5 0 0 0
Advertisement

Networked security systems work across multiple deep specialties. It has always required experts in one field to rely on experts in another, even though they work on the same domain

7 hours ago 9 0 1 0

Oh very cool, will keep that in mind

8 hours ago 8 0 0 0

really? in what form?

8 hours ago 5 0 1 0

son of a gun

8 hours ago 12 0 0 0

when you're baffled by one of paul's skeets, claude can (sometimes) explain what's what 🤝

8 hours ago 27 3 1 1

I think Anthropic deserves a ton of credit for holding the release and taking this fast action

8 hours ago 30 0 2 0

Ultimately I'm going to roll with industry guidance. If companies like Google say their timeline for rollout is 2029, then that's the bet I'm going to make

8 hours ago 9 0 1 0
Advertisement

My understanding is that it's a really risky position to bet against, because when it does happen it will happen "suddenly." The argument fillipo seems to be making is, this is as good of a warning as we get, regardless of the timeline from here

8 hours ago 23 1 1 1
Preview
A Cryptography Engineer’s Perspective on Quantum Computing Timelines The risk that cryptographically-relevant quantum computers materialize within the next few years is now high enough to be dispositive, unfortunately.

Probably since he's the one leading the awareness campaign on QC. See words.filippo.io/crqc-timeline/

8 hours ago 17 1 1 1

youre asking the wrong kind of nerd

8 hours ago 7 0 0 0

The post-quantum cryptography timeline accelerating at the same time that mythos is creating mass CVEs is really threatening to alter my roadmaps

8 hours ago 296 30 18 6

I contributed yeah

8 hours ago 5 0 0 0

nw nw

10 hours ago 3 0 0 0

The reality is, there's no such thing as a simple way to handle versioning in an open system. If we chose to handle this change with a v2, then all of the software that still uses v1 would suddenly stop receiving posts.

There are only "least worst" options. It's all coordination.

10 hours ago 4 0 0 0
Advertisement

We presently believe that the infra in the community that handles image blobs can be updated to handle a breaking change, and that we can sync with the operators to make this transition successfully. We *could* be wrong, but that's partly what the announcement is for

10 hours ago 6 0 2 0

Let me give an example: suppose you have an app that you just launched. You're 95% sure nobody else is using your schemas yet. Can you make a breaking change to a lexicon? Yeah, probably. You've written the only software that depends on it.

If you can sync with all schema users, you can do it

10 hours ago 3 0 1 0

The nuances around making changes are somewhat complex. The guidance isn't changed; if you're making a breaking change, you should create a new NSID.

The subtlety to that is, if you have high confidence that you can roll out a breaking change successfully, then you can do it without an NSID change.

10 hours ago 2 0 1 0

FWIW the version field in lexicons is about the lexicon specification being used, not the version of the lexicon being described. (And there havent been breaking changes to the lexicon spec yet.)

10 hours ago 6 0 2 0
Preview
PNPM minimumReleaseAge Learn how PNPM's minimumReleaseAge setting helps protect your project from compromised packages and improves supply chain security.

PSA: Use @pnpm.io minimumReleaseAge.

A simple way to make NPM supply chain attacks, like the one affecting the `axios` NPM package, more unlikely.

maier.tech/notes/pnpm-m...

14 hours ago 39 9 4 0

I think @grain.social has the juice. It’s so refreshing to have a timeline that allows you to see new posts, and when you’re done, you can just go about your day. No engagement algorithm, just awesome photos in a clean app. 👏👏

13 hours ago 37 10 2 0