I installed every package on PyPI to look for malicious activity. I've published the results here: https://t.co/9tSE90fKFt
I'd like to talk a little about how this all works and why it's important: 🧵
Slowly, the world is discovering the value of provisioning hardware-bound cryptographic credentials.
The Internet is slowly catching up to the level of security of tapping to pay for a cup of coffee.
🔍 I wanted to learn more about how certificate transparency logs work. So this weekend, with help from Claude, I built a small site that shows end-to-end verification in action.
https://t.co/7khJsASpTy
We open sourced the tool used to detect the Axios supply chain compromise! I built it Friday after a red eye home from RSAC. Also, wrote up the full story, including the hectic moments after that first critical alert
https://t.co/HAm8eMr8vO
For Confer, we want private AI chat to be simple, but many end-to-end encrypted apps still have a level of friction that make them feel like they’re from another era.
Here's how Confer uses passkeys to make E2E encryption feel as simple as logging in:
https://t.co/FDZkpKJ3uG
@moxie I also came across @TinfoilAI which looks similar. Combining remote TEE attestation with @projectsigstore artifact bundles is neat!
https://t.co/hyKiLa5Grf
This e2ee LLM interface is, as always, stellar work from @moxie 🔥
I spent a couple hours trying to understand how it works from a client side. I don't have all the details, so take this with a grain of salt. Here's what I *think* I know from an oversimplified high level 🧵
I've been building Confer: private AI chat where your conversations are end-to-end encrypted so that only you can access them.
It's still new, but I've been using it every day and beta testing it with friends. Let me know what's missing!
https://t.co/EsRRPWWpYj
In the meantime, I'm a paying customer and will be trying out Confer as my daily-driver for a while. I love the idea and the implementation looks great. Keep up the great work, @moxie . ❤️