AI in the human loop, not the other way around. This shift will transform how we combat loneliness, deliver
care, build systems, and educate ourselves in an era of rapid change.
Read my tech predictions for 2026 on All Things Distributed: https://t.co/NuNWVywy6C
Now, go build!
@jedisct1 Agreed. I'm still not convinced by most of the "utils" ones. Worst-case, the agent will write a script. The ones I've found useful so far are the browser automations MCP, where the LLM needs to (re)act and iterate over a non pre-determined flow.
Codex is here—and it ships.
@danshipper and @KieranKlaassen tested OpenAI’s new autonomous coding agent.
What it is, what it isn’t, and why it may be a senior dev's new best friend 🧵
i released my 2nd (and last) post about (un)coupling in distributed systems, this time discussing the redundancy fallacy and temporal decoupling, including the additional design options it brings: https://t.co/00nUUxjnWo
enjoy if you like ... ;)
Next.js dropped a CVSS 9.1 authentication bypass vulnerability (CVE-2025-29927) over the weekend. This flaw is trivially exploitable by sending the header `x-middleware-subrequest: true`. Over 300k hits in Shodan, find more at:
https://t.co/ewMXHIWyzA
These new guidelines aren't mandatory for operators, but they offer a glimpse of what may be in Singapore's upcoming Digital Infrastructure Act that will regulate #cloud and #datacentre service providers.
https://t.co/jQM8ZhaTjf
To the surprise of no one who has actually worked in cybersecurity, advances in AI continue to advantage defenders over attackers. Exciting! https://t.co/1kaNCt8N0D
I've been bearish on @Cloudflare because I wasn't sure you could actually build anything "real" on it. This might possibly change my mind. https://t.co/khhG83z7jo
Please share this far and wide. As far and wide as you can. NIST Password Guidelines for 2024 are in the process of being updated.
This is a HUGE pet-peeve of mine (when vendors in particular are still operating like its 2017 and keep changing passwords every 60 days, STOP DOING THIS, it's outdated and has been shown to put you MORE at risk than less -- NIST explains why it does in this document, meticulously outlining user behavior**) so I'm sharing this in the hopes all of you will pass it along to your bosses.
The Special Publication series governing passwords is SP 800-63 "Digital Identity Guidelines".
The 2024 version is 800-63-4.
Here: https://t.co/oX8YEJHxXg
The companion docs are also on that link. They are 800-63A, 800-63B and 800-63C. These are different documents for different scenarios in play at your org.
The previous update was in2020.
The changes in the 2020 version from the 2017 version were numerous but one of them was that the password verification method should NO LONGER require passwords be changed at specific intervals (i.e. every 60 days) but in the following circumstances instead:
1. After a breach/compromise
2. User request
2024 repeats this and adds a bunch more guidlines but here is a screenshot of page 13 of the new 800-63-4 (note the # 4 after it) which outlines how your systems should now and moving forward, be handling passwords.
This goes for Active Directory, too. All your systems which have passwords should align with these guidelines provided there isn't another standard or framework you must adhere to which overrules this.
Most frameworks, however, have moved away from arbitrary password resets and complexity rules.
**We cybersec researchers and hackers use wordlists from breaches in a variety of different ways. Hackers use them in tooling to crack passwords whereas researchers use breach dumps to see the kinds of passwords users are creating and the psychology behind them.
Using complexity rules gets you the user psychology of:
Password1
Password2
and so on
Use phrasing instead and allow for spaces, which is important. Humans type phrases with spaces. They also mention phish-resistant methods and most vendors are on-board with MS going to be turning off all Legacy Auth next month, across all free accounts and tenancies.
I'm so excited for the new changes!
Ok I'm off my soapbox.
Share the love! Thank you!
"Formal verification makes RSA faster — and faster to deploy" Doubling the speed of RSA on Graviton 2, with agressive optimizations enabled by formal verification. https://t.co/cV5t0YY5NS
I've been wanting to do this story for years and am thrilled it's finally out: inside the surprisingly small, highly specialized industry that repairs the internet cables on the bottom of the ocean https://t.co/ChlU0gzGIU
New blog post, on what the word "scalable" means in my head, and how thinking about marginal costs of adding work makes a lot of the debates about scalability go away:
https://t.co/PFWOOaoR0O
Cloud CISO Perspectives blog for end October is up, covering:
- Multi-cloud security
- AI risk governance
- Hardware security
- API security
- Mandiant threat intelligence
- Risk and benefits of LLMs for security
- and more.....
https://t.co/HjVddJF6wV