Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

G :donor: :Tick:

@cirriustech@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

I do Cloud Security

1997 Followers
1483 Following
45 Posts
Joined October 28, 2022
Website:
https://www.cirriustech.co.uk/
LinkedIn:
https://uk.linkedin.com/in/graham-gold
GitHub:
https://github.com/goldjg
Ko-Fi:
https://ko-fi.com/cirriustech
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 3mo ago
5
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 3mo ago
4
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 3mo ago
3
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 3mo ago
I accidentally built a control plane for coding agents. It started as a simple goal: GitHub AI Credits arrived, CopeLimit started watching the meter, and being a Scot I was suddenly very much doing Invoice Avoidance Driven Development. Make AI coding agents produce smaller PRs, follow boundaries, validate properly, and stop treating “add JSON output” as permission to invent a new architectural religion. That forced the real question: Are we governing AI-assisted engineering, or just writing better prompts and hoping? My answer: prompting is not the control plane. AADLC became the lifecycle. cARL became the repo-native governance layer. CopeLimit made the cost visible. Headroom points toward the optimization layer. cARRIE is the future resource-insights engine. The benchmark runs made the pattern clearer: Same repo. Same workflow. Same acceptance criteria. No human steering. Sonnet 4.6: 441 credits, 34m58s, 7/7 accepted. GPT-5.4: 708 credits, 58m48s, 7/7 accepted. Sonnet plan + GPT execute: 581 credits, 48m18s, 7/7 accepted. The interesting question was not “which model is best?” It was: What shape of delegation does this work need? Because the model matters. The delegation system matters more. https://cirriustech.co.uk/blog/prompting-was-never-the-control-plane/ #AI #SoftwareEngineering #DevSecOps #GitHubCopilot #AgenticAI #FinOps
cirriustech.co.uk

Prompting Was Never the Control Plane | CirriusTech | Serious About Tech

2
0
2
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 4mo ago

GitHub spelunking continues

3
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 8mo ago
Replying to
@Viss@mastodon.socialhttps://github.com/search?q=path%3A.claude%2Flogs%2F*.md&type=code&query=path%3A.claude%2Flogs https://github.com/search?q=path%3A.claude%2Flogs%2F*.md&type=commit&query=path%3A.claude%2Flogs https://github.com/search?q=path%3A.claude%2Flogs%2F*.json&type=code&query=path%3A.claude%2Flogs https://github.com/search?q=path%3A.claude%2Flogs%2F*.json&type=commits&query=path%3A.claude%2Flogs
Build software better, together
GitHub

Build software better, together

GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

9
6
5
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 4mo ago

Sleep is overrated apparently

2
2
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 3mo ago
Replying to
@bobthomson70@mastodon.social that’sa lovely photo mate
1
1
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 4mo ago

So tonight is an inevitable eventuality. A painful, complicated one. I not sure how I feel. Or how I thought I’d feel. Or how I’ll feel in 5 minute or 5 hours or 5 days. Is their grief? Yes. Regret? Strangely no (yay therapy I guess).

1
1
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 4mo ago

I did not have building a miasma crawler on my bingo card today but…

1
0
1
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 4mo ago

weird today. Defo an MECFS flare Or in the edge of one. Brain is half working, body is complaining. meh

1
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 8mo ago
𝗪𝗵𝗮𝘁 𝗧𝗵𝗲 𝗘𝗻𝘁𝗿𝗮 𝗙𝘂𝗱𝗴𝗲?! 🤨🍫 I’ve just published a new blog post: 👉 “𝗔𝗹𝗹𝗼𝘄 𝗢𝗻𝗲, 𝗔𝗹𝗹𝗼𝘄 𝗔𝗹𝗹: 𝗪𝗵𝗲𝗻 𝗖𝗼𝗻𝗱𝗶𝘁𝗶𝗼𝗻𝗮𝗹 𝗔𝗰𝗰𝗲𝘀𝘀 𝗟𝗼𝘀𝗲𝘀 𝘁𝗵𝗲 𝗣𝗹𝗼𝘁” It’s the first post in a new series I’m calling 𝗪𝗵𝗮𝘁 𝗧𝗵𝗲 𝗘𝗻𝘁𝗿𝗮 𝗙𝘂𝗱𝗴𝗲?! - a place for those moments where you follow the docs, design sensible Conditional Access policies… and Entra still does something that makes you stop, squint at the sign-in logs, and quietly question your life choices. This first post looks at how 𝗗𝗲𝘃 𝗕𝗼𝘅, 𝗔𝘇𝘂𝗿𝗲 𝗩𝗶𝗿𝘁𝘂𝗮𝗹 𝗗𝗲𝘀𝗸𝘁𝗼𝗽, 𝗮𝗻𝗱 𝗪𝗶𝗻𝗱𝗼𝘄𝘀 𝟯𝟲𝟱 𝗮𝗹𝗹 𝗮𝘂𝘁𝗵𝗲𝗻𝘁𝗶𝗰𝗮𝘁𝗲 𝘁𝗵𝗿𝗼𝘂𝗴𝗵 𝗮 𝘀𝗵𝗮𝗿𝗲𝗱 𝘀𝗲𝘁 𝗼𝗳 𝗳𝗶𝗿𝘀𝘁-𝗽𝗮𝗿𝘁𝘆 𝗮𝗽𝗽𝘀 𝗮𝗻𝗱 𝗯𝗿𝗼𝗸𝗲𝗿𝘀, and why that can quietly turn “𝘢𝘭𝘭𝘰𝘸 𝘰𝘯𝘦” into “𝘢𝘭𝘭𝘰𝘸 𝘢𝘭𝘭” at the Conditional Access boundary. This isn’t a vuln drop. It’s not Microsoft-bashing. And it’s definitely not “you configured it wrong”. It’s about 𝗺𝗲𝗻𝘁𝗮𝗹 𝗺𝗼𝗱𝗲𝗹𝘀 𝘃𝘀 𝗿𝘂𝗻𝘁𝗶𝗺𝗲 𝗿𝗲𝗮𝗹𝗶𝘁𝘆, and how to design securely once you realise those two don’t always line up. 👉 Blog link: https://cirriustech.co.uk/blog/allow-one-allow-all-conditional-access/ --- 𝗜’𝗱 𝗹𝗼𝘃𝗲 𝘆𝗼𝘂𝗿 𝗵𝗲𝗹𝗽 𝘄𝗶𝘁𝗵 𝘁𝗵𝗲 𝘀𝗲𝗿𝗶𝗲𝘀 👇 If you’ve ever had a moment where you thought: • “Wait… why does that app affect 𝘵𝘩𝘪𝘴 workload?” • “Why did blocking X suddenly break Y?” • “Why does Conditional Access behave nothing like the diagram in my head?” …that’s a 𝗪𝗵𝗮𝘁 𝗧𝗵𝗲 𝗘𝗻𝘁𝗿𝗮 𝗙𝘂𝗱𝗴𝗲?! moment. Drop a comment, DM me, or message me with your own WTEF stories. No naming-and-shaming - just shared learning, clearer mental models, and fewer 2am sign-in-log staring contests. More posts coming soon on Graph, ARM, portal behaviour, and identity monoculture. Welcome to 𝗪𝗵𝗮𝘁 𝗧𝗵𝗲 𝗘𝗻𝘁𝗿𝗮 𝗙𝘂𝗱𝗴𝗲?! 😄
cirriustech.co.uk
3
0
2
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 5mo ago

It’s alive!

1
0
1
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 8mo ago
Replying to
@sassdawe@infosec.exchange @Viss@mastodon.social ngl I immediately rushed off to check my own repos where I’ve been using GitHub Copilot lol
2
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 8mo ago
Replying to
@Viss@mastodon.social I’m sure there are better searches lol
2
1
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 9mo ago
Replying to
@GossiTheDog@cyberplace.social elastic need a kicking tbh Also which security vendor?
2
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 4mo ago

Shutting my brain off would be cool

0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 3mo ago
macOS GitHub runners have been dead since around 18:30 BST today, and GitHub status page says all is green
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
Why are you never more hopelessly awake than when you have an 04:30 alarm to catch a flight and it’s under 5 hours from now?
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 4mo ago

The Miasma worm source code that uses GitHub as infrastructure has popped up in 4 repos so far in the last 24hrs - all reported but GitHub need to be faster on takedowns (all still fully available)

0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 3mo ago
Replying to
@bobthomson70@mastodon.social https://infosec.exchange/@cirriustech/116818701345827297
infosec.exchange
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
Genuine question, as someone who has paid sponsorship to some GitHub creators (admittedly I need to do it more often), but who has singularly failed to receive any myself - what would convince you to make a sponsorship payment to a GitHub project (one-off or recurring)?
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 3mo ago
Trying to agentic code a security scanner with Fable 5 is… frustrating…
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
Another reason, if one were needed, not to logon to a windows OS with a Microsoft account… https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/
Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint
Windows Latest

Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint

GDID is the persistent Windows ID that helped FBI trace a Scattered Spider hacker despite VPNs. Here's how it works and how to limit it.

0
1
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
I thought it was warm in Scotland but… 🫠
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 3mo ago
Swap the album to Seventh Son of a Seventh Son and yep, my metal origin story! https://youtube.com/shorts/h312tzIkxnc
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 3mo ago
Absolute crushing anxiety plus crushing sadness are not a great combo
0
1
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 4mo ago

Feelings are overrated

0
1
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 1mo ago
Is the VirginMedia/O2 backbone screwed? VM 1 Gb fibre currently giving 560kbps and o2 4G giving 2Mbps
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
Replying to
@corq@infosec.exchange it’s copilot lol
0
1
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 4mo ago

I hate that that I was basically paralysed by depression and anxiety and emotion today and didn’t feel at all useful or productive

0
1
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
Explaining cARL in 5 seconds: Same Dog. Same Chaos. Different Boundary. https://github.com/goldjg/cARL #AI #AgenticCodingGovernance #ConstrainedProbabilism
github.com
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
Early
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
Little Portuguese bakery beside Cardiff Castle called Nata & Co. Castle De Nata (or Castel de Nata) was right there!
0
1
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
Today was fucking hard
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 3mo ago
I was sure I’d pre grieved. I was wrong
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 3mo ago
Replying to
In London
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
Replying to
Context: if I hadn’t gone no contact with my parents in 2022 because of my mother, I wouldn’t still be here - the dark thoughts are what made me cut them off. Doesn’t make today any easier though
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
The recent wave of agent sandbox escapes is being treated as something fundamentally new. Mostly, it is not. We spent decades accumulating security debt, brittle trust, overprivilege and accidental reachability. Agents are making the exploration of those decisions cheap, persistent, parallel and very, very fast. I talk a LOT about this in my latest blog post: https://cirriustech.co.uk/blog/we-automated-dave/ #AI #Sandbox #SecurityDebt
cirriustech.co.uk
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 1mo ago
Station Eleven is weird
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
Anyone here with an Apple Developer Program account able to download an App Store Connect API Key when they generate it? On an iPhone?
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 2mo ago
Thank you Spotify algorithm for playing Wasted Years by Iron Maiden (which I do indeed love) at a time when it hit me like a freight train!
0
0
0
0
Open post
G :donor: :Tick: @cirriustech@infosec.exchange
· 4mo ago

Definite depression and anxiety today and going between emotional and flat

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 09:39:22 UTC