Security conference talks fall into two categories
* we designed a distributed entropy siphon to perform a black-box hypervisor side channel escape and chain-load a persistent rootkit into the CPU cache
* we looked behind the sofa and found an entire industry of products/services that have made no attempt at security at all and are therefore vulnerable to the most basic issues that we've been finding in everything for the past 30 years, and no-one else had bothered to look.
Richard Stephens
mastodon 4.7.3Software engineer
Currently building a deep stealth cloud tech startup. Formerly Tink, Atlassian
Bazel, Kubernetes, CI, Devops.
Much more lurker than poster.
Signficant segments of the tech industry think we’re months away from not needing to review LLM-agent code anymore.
I just reviewed an LLM-generated PR in which it quietly switched two out of 100 calls to the get_customer_data() function to the variant that doesn’t check that the customer owns the requested data.
I’m sure this is fine.
There is something just viscerally jarring about listening to a deep metaphysical discussion about the conflicts between general relativity and quantum mechanics and the very nature of reality itself, but before we continue, a quick word from our sponsor, another roll-up mattress company with a 120-night risk free trial.
Today I am implementing a lightweight Docker/OCI registry and I'm finding myself wondering if perhaps some of the weird technical decisions in the spec have completely rational explanations if you instead consider them as business decisions by the companies involved.
You seem to be implying that would be a bad thing.