Related posts
vulnerability afternoon directory
The the words it uses that this site has seen
least often elsewhere. Posts are matched on those words alone —
nothing here is a summary of this one.
Sources
All
Writing
Bluesky GitHub Mastodon Korrents x.com Site Blog Recommends
Top people
Jessamyn West
Daniel Stenberg
Kit Yates
Tobias Lütke
Bruce Schneier
John Scalzi
Brad Fitzpatrick
Paul Graham
Yihui Xie
Mitchell Hashimoto
Rasmus Andersson
Patrick McKenzie
Showing
Profile →
Show everything
Hiding
Show them again
Show them again
Further back ↓
Hiding
Show them again
19 September
American science fiction novelist (Old Man's War, Redshirts, The Kaiju Preservation Society); has run the blog Whatever since 1998.
What Saturday afternoon looks like here Related
Programmer known for LiveJournal, memcached, OpenID and gearman; worked on the Go programming language at Google and later joined Tailscale.
18 September
Librarian, technology instructor and writer in rural Vermont; longtime community manager at MetaFilter and author of a book on the digital divide.
Friday afternoon reminder to not empty your inbox at the expense of someone else's. This is the weekend I get my wood in (i.e. have pellets delivered) so I'm thinking of chillier days even though it's 70° outside. Trust me, you'll feel better if you make some plans for what's ahead, however you interpret that. Have a good weekend. Image credit: Library of Congress, on Flickr Commons flickr.com
Related
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
Last year I blogged about the vulnerability reporting process in #curl. It remains the same, just with about 3-4x the volume... daniel.haxx.se
Related
Co-founder of Y Combinator and Viaweb; essayist at paulgraham.com.
Their words
It's isn't just to people with ADHD that this happens. Some tasks inherently take a certain amount of time. An appointment that breaks the afternoon into two blocks of time could leave you with no block long enough to complete a task.
Show the whole quote
@paulg on X x.com
17 September
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
Between all the vulnerability report work, I made curl's date parser twice as fast as before... curl.se
Related
16 September
Statistician and software engineer who writes R packages for reproducible research and publishing, including knitr, bookdown and blogdown.
11 September
Librarian, technology instructor and writer in rural Vermont; longtime community manager at MetaFilter and author of a book on the digital divide.
Friday afternoon reminder to not empty your inbox at the expense of someone else's. My "big plans" today involve sawhorses and telephones and catching up on my newspaper reading. Argue all you want about AI, the analog world will be here when you're done, mostly. Schedule those emails. Have a good weekend. Image credit: State Library of New South Wales, on Flickr Commons flickr.com
Related
8 September
Co-founder of Superlogical, started in 2026 to build server-side terminal infrastructure; creator of Ghostty. Co-founded HashiCorp and created Vagrant and Terraform before that.
A quick look into remote persistent sessions with Superlogical! Not just remote sessions, but some functionality like remote directory lists, too. Superlogical can actually be a full SSH replacement (I don't run SSH on my servers anymore), and I talk about that briefly, too. Related
6 September
Swedish designer and programmer. Designed early Spotify, worked at Facebook and Figma, and created the Inter typeface.
Astra in codex is a thirsty thing. A single agent burned through all usage for a $200/mo account in about 14 hours (I took one of my account limit resets yesterday afternoon.) Related
4 September
Librarian, technology instructor and writer in rural Vermont; longtime community manager at MetaFilter and author of a book on the digital divide.
Friday afternoon reminder to not empty your inbox at the expense of someone else's. I'm deep in my Massachusetts visit, becoming one of those people who can't look at a place without remembering what used to be there. My birthday is tomorrow, so there are all sorts of opportunities for reflecting and remembering. Oh and I guess it's a holiday weekend in the US, so maybe schedule those emails for Tuesday. Image credit: Library of Congress, on Flickr Commons flickr.com
Related
3 September
Mathematical biologist; Senior Lecturer in the Department of Mathematical Sciences at the University of Bath and author of The Maths of Life and Death and How to Expect the Unexpected.
x.com I'm going to be on BBC Inside Science at 16:30 this afternoon discussing a new way to date "ancient" artefacts and the discovery of a new polygon on Saturn. Sound interesting? See you there. bbc.co.uk
Related
Bluesky I'm going to be on BBC Inside Science at 16:30 this afternoon discussing a new way to date "ancient" artefacts and the discovery of a new polygon on Saturn. Sound interesting? See you there. Related
2 September
Writer on the intersection of technology and finance. Author of the Bits about Money newsletter and host of the Complex Systems podcast; previously at Stripe.
An increasingly common pattern in my boring-administrivia workflows is creating a new folder with an inbox/ or unsorted/ subfolder, starting a Claude Code instance, and telling it "Watch that for changes, read incoming files, rename and organize into a directory structure." Anthropic Related
1 September
Professor of Cognitive and Computational Neuroscience at the University of Sussex, co-director of the Sussex Centre for Consciousness Science, and author of Being You: A New Science of Consciousness.
Sudden swarm of password attacks on my @X account, all within 2 minutes this afternoon. Revenge of the AI agents? Related
Technical staff at METR, where she works on threat modelling and risk assessment for loss-of-control risks from advanced AI.
Their words
But in many of these cases, this vulnerability is just not broad or deep enough to ever actually be exploitable to get the flag. So a bunch of exploit gym problems are just unintentionally impossible. The authors estimate roughly 30 to 40% of these problems are impossible in this way.
Show the whole quote
youtube.com
28 August
Librarian, technology instructor and writer in rural Vermont; longtime community manager at MetaFilter and author of a book on the digital divide.
Friday afternoon reminder to not empty your inbox at the expense of someone else's. I'm out of town helping my sister after she recovers from a medical procedure (she's doing well!). I'm out of my routine and pretty well out of my inbox and DEFINITELY out of it after 5 pm. Be mindful about what you ask for from other people, but just do your best. Have a restful weekend. Image credit: National Library of Medicine, on Flickr Commons flickr.com
Related
27 August
Technical educator, conference speaker and developer relations engineer based in Ottawa, Canada. Author of the Anubis bot filter and of over 400 articles at xeiaso.net.
Their words
This is due to the affected components being written in C, the only programming language where these vulnerabilities regularly happen.
Show the whole quote
xeiaso.net
26 August
Creator of Ruby on Rails, CTO of 37signals, and creator of Omarchy.
Their words
So the irony here is that when you look at that field, it seems like we've reached levels of intelligence that virtually no human can match because many of these security holes are about stringing combo moves together. You find one little vulnerability here that by itself might not be the worst thing in the world, but then you combine it with four others, and suddenly you have RCE, remote command execution. Humans who are able to do that are very rare.
Show the whole quote
youtube.com
25 August
Co-founder and CEO of Shopify; long-time Linux user and Omarchy contributor.
Their words
With thousands of developed in a mono repo, it just does happen that one directory is missing one of the two files and this means that a subset of devs work with lobotomy. We fix this with automation but it’s a stupid complexity tax that shouldn’t have to be paid.
Show the whole quote
@tobi on X x.com
22 August
Co-founder and CEO of Shopify; long-time Linux user and Omarchy contributor.
21 August
Librarian, technology instructor and writer in rural Vermont; longtime community manager at MetaFilter and author of a book on the digital divide.
Friday afternoon reminder to not empty your inbox at the expense of someone else's. I'll be headed down to Massachusetts to spend some time with my sister next week and I've already got my clipboard out and am making lists. Maybe I'll catch Super Troopers 3 at the local movie house. Either way, my mind is nowhere near my email. Fortunately it does not have to be. Image credit: Randolph Historical Society, on Flickr Commons flickr.com
Related
20 August
Mac developer and writer at brettterpstra.com; makes the apps Marked and nvALT and writes extensively about Markdown and automation.
18 August
Programmer, teacher and speaker; long-time Microsoft developer-community figure, host of the Hanselminutes podcast and author of the hanselman.com blog.
Programmer on the Dart language at Google and author of Game Programming Patterns and Crafting Interpreters; previously a game developer at EA.
Spent an afternoon at Highgate Cemetery when on vacation in the UK and this is one of my favorite photos from the trip. #photography #cemetery #victorian Related
Design engineer and illustrator; makes visual essays on programming, anthropology and what language models do to the way people write.
August 2026 I'm writing this from a homely Jacobean-manor-turned-hotel in the West Country, covered in layers of green vines and circled by centenarian trees, on a rare weekend away. Everything is warm: the late afternoon sun, the…
Related
9 August
Creator of the Zig programming language; president and lead developer of the Zig Software Foundation.
8 August
Programmer and technology writer known for his long Mac OS X reviews at Ars Technica; co-hosts the Accidental Tech Podcast and Hypercritical.
Ever since Xcode 26, SwiftUI previews haven't worked at all unless I disable sandboxing in my app. If I don't do that, I get this error: XOJITError: Could not create code file directory for session: Permission denied I keep hoping a new version of Xcode and/or macOS will fix it, but it's the same in the latest 27 betas. (Editor → Canvas → Use Legacy Previews Execution also doesn't fix it, but does change the error.) Apple folks: FB24222556 Related
3 August
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
30 July
Web developer and writer; an early GitHub employee, author of speaking.io and of widely read essays on startups and product.
Been nice seeing some of the cold approach stories in the HN comments of my post this afternoon: https://t.co/r1mfJXzPq3 You forget how little things (to you) might mean a lot to others! Related
29 June
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
Do excellent vulnerability reports Over the years, we have received, read and handled way over one thousand vulnerability reports filed against curl. We have seen most kinds. It is time for me to try to help future reporters by providing a short guide on…
Related
23 June
British designer and technologist; co-founder of the design studio BERG, which made Little Printer, and writer of the blog Interconnected.
Took the afternoon off to do kid wrangling because the school is closed from the heat (trading with other families who take over kid wrangling other days this week) and I think that is my first “climate day” as a reason for not working? Related
Cryptography engineer; maintains Go's cryptography libraries as a full-time open-source maintainer, funded directly by companies that use them.
15 June
Scottish software developer on the Statamic core team; runs a one-person business maintaining Statamic addons such as Runway and writes at duncanmcclean.com.
Something is wrong with my Claude Code and I can't figure it out... The latest model I can use is Opus 4.5. It claims that updates are available but Homebrew says I'm on the latest version. I've tried re-installing and clearing my .claude directory to no avail. I couldn't have used Fable last week even if I tried 😢 Any ideas? Anthropic Related
8 June
Security technologist and author of books including Applied Cryptography and Data and Goliath; writes the Schneier on Security blog and the monthly Crypto-Gram newsletter.
7 June
Mathematician and Senior Lecturer in the Mathematics department at Columbia University. Author of the book Not Even Wrong and of the long-running physics blog of the same name.
1 June
Security technologist and author of books including Applied Cryptography and Data and Goliath; writes the Schneier on Security blog and the monthly Crypto-Gram newsletter.
20 May
Rust engineer at Google working on Android; maintains Tokio and works on Rust in the Linux kernel.
30 April
Web developer; former head of engineering at Flickr, author of Building Scalable Web Sites, and co-founder and CTO of Slack.
21 April
Member of technical staff at Anthropic. He has led ML/AI teams at Amazon, Alibaba and Lazada, and writes about LLMs, recommender systems and engineering at eugeneyan.com.
Great writeup by @mozilla: Mythos found 271 vulns (fixed in Firefox 150); Opus 4.6 found 22 (fixed in Firefox 148) https://t.co/wzTCxmTKbe > "So far we’ve found no category or complexity of vulnerability that humans can find that this model can’t." > "The defects are finite, and we are entering a world where we can finally find them all." ❤️ Related
2 April
Founding member of OpenAI and former director of AI at Tesla; creator of nanoGPT and the term "vibe coding".
LLM Knowledge Bases Something I'm finding very useful recently: using LLMs to build personal knowledge bases for various topics of research interest. In this way, a large fraction of my recent token throughput is going less into manipulating code, and more into manipulating knowledge (stored as markdown and images). The latest LLMs are quite good at it. So: Data ingest: I index source documents (articles, papers, repos, datasets, images, etc.) into a raw/ directory, then I use an LLM to incrementally "compile" a wiki, which is just a collection of .md files in a directory structure. The wiki… LLMs Related
Co-founder of Ethereum. Publishes long essays on mechanism design, governance and what cryptography is for, and returns to earlier positions to say which parts they no longer hold.
Their words
The verdict: pi plus a basic searxng skill outperformed Local Deep Research. Also, pi is just much more configurable: I can easily just tell it to use not just internet searches, but also my own world_knowledge directory.
Show the whole quote
vitalik.eth.limo
16 December 2025
Software developer who wrote Winamp and Gnutella, and now develops the REAPER digital audio workstation at Cockos.
27 August 2025
Full-stack Laravel developer based in Madison, Wisconsin; maintains open-source Laravel, Livewire and Alpine.js packages and writes at randallwilk.dev.
13 February 2025
Writes jvns.ca, turning "hard and scary" topics — networking, debugging, Linux internals — into plain explanations and hand-drawn comics. Publishes Wizard Zines, illustrated programming zines. Software developer based in Montreal.
14 October 2024
Co-founder of WordPress and founder of Automattic; blogs at ma.tt.
Their words
If WP Engine didn’t want this to happen, they should not have published their code under the GPL or distributed it through WordPress.org’s directory.
Show the whole quote
Response to DHH ma.tt
30 July 2024
Founder and chief executive of Replit. Previously an engineer at Facebook and Codecademy. Writes essays on programming, philosophy and entrepreneurship at amasad.me.
25 June 2024
Egyptian front-end developer and course creator; writes for CSS-Tricks, publishes courses on Udemy and blogs at alialaa.dev.
4 March 2024
Historian of Ukraine at Harvard; wrote The Gates of Europe, Chernobyl and The Russo-Ukrainian War.
Their words
But next accident would actually expose new vulnerability. You deal with Chernobyl and then tsunami comes. You deal with tsunami and then war comes.
Show the whole quote
youtube.com
12 February 2024
Creator of the Keras deep-learning library and the ARC-AGI benchmark.
10 November 2023
Indian software developer working with React and TypeScript; writes and publishes a newsletter at sreetamdas.com.
Re: [patched] critical vulnerability in Sentry's Next.js SDK Of course it's regex 😅 Related
24 October 2023
Software engineer and educator; creator of Testing Library and of the EpicWeb.dev and EpicReact.dev courses.
Their words
Most people who love the next.js app directory would also love remix nested routing for many of the same reasons.
Show the whole quote
@kentcdodds on X x.com
17 October 2013
Data scientist and machine-learning researcher; chief scientist at bitly, founder of Fast Forward Labs and Hidden Door.
17 April 2012
Software developer; created Firebug, helped create Firefox on the Netscape browser team, and built the original Facebook iPhone app.
Nothing matches. Show everything
What is a korrent?
A korrent is a belief a person has stated in their own words: one
sentence stating the claim, backed by a quote and a source, kept at
korrents.com .
Under a name here, the quoted block is what they actually said.
The korrent beneath it is the claim those words support, in
korrents' wording — tap it to see the record, its source, and who
else holds it.
Nobody here wrote their own korrents. They are compiled from public
statements, and a person can change their mind, which is recorded too.
Got it
About the English under a post
Some people here publish in a language other than English. Where they
do, this site shows a machine translation beneath the post, in
this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the
serif above is exactly what the person published, and it is what to
quote them on. A translation can be wrong in ways that matter,
especially about tone.
Only the post's own words are translated. A quoted post, a linked
article and a belief on korrents.com
are left in their original language.
Got it