Related posts
Scott Helme
Blog
Everything I Learned Shipping Device Bound Session Credentials
sourced specification credentials
The the words it uses that this site has seen
least often elsewhere. Posts are matched on those words alone —
nothing here is a summary of this one.
Sources
All
Writing
Mastodon GitHub Blog x.com Korrents Newsletter
Top people
Scott Helme
Scott Hanselman
Daniel Lemire
Matthew Green
Hillel Wayne
Devine Lu Linvega
Kun Chen
Terence Eden
Dean W. Ball
Adam Tooze
Jeff Dean
Daniel Stenberg
Showing
Profile →
Show everything
Hiding
Show them again
Show them again
Further back ↓
Hiding
Show them again
20 September
Artist and developer who makes esoteric software, games and tools aboard a sailboat as part of Hundred Rabbits with Rekka Bellum; creator of the Uxn virtual machine and the Orca livecoding environment.
I see folks building bedrock-type abstractions more and more these days and adding on @tbsp's list, I tried to gather every single virtual machine designed explicitly to fend of bitrot or digital obsolesce by targeting a frozen specification I could think of. I was wondering, I'm sure I must have forgotten some, if you can think of one that is not on the list, could you please let me know! wiki.xxiivv.com
Related
Former L8 engineer at Meta, Microsoft and Atlassian, now writing and building solo on agentic engineering. Writes Kun's Field Notes and posts a lot about AI coding agents on X.
17 September
Programmer, teacher and speaker; long-time Microsoft developer-community figure, host of the Hanselminutes podcast and author of the hanselman.com blog.
14 September
British open-standards and open-source technologist, formerly of the UK Government Digital Service and the W3C Advisory Committee. Blogs at shkspr.mobi, where he posts a book review most weeks.
Esoteric HTML - ismap vs CSS The HTML specification is old and, while there is beauty in longevity, there's an inevitable build-up of boondoggles and baggage. Some elements like have sadly been consigned to the dustbin of history - but there are st…
CSS Related
13 September
Writes Hyperdimensional, a newsletter on AI policy and governance. A White House AI policy adviser in 2025; joined OpenAI on 6 July 2026 to lead its Strategic Futures team.
you know what? it’s awesome that people are vigorously debating the credentials of assessors in the frontier AI industry. It’s awesome we are debating what independence really means. Some of it is in bad faith but who cares. This would have been my dream come true a year ago. Related
10 September
Computer science professor who works on fast data processing; co-author of the simdjson parser and a weekly blogger about software performance since 2004.
Fear Is Not an Argument We are told that AI entities much like ChatGPT might soon kill us all. The statement is vague and unfalsifiable. It might be true, it might be false. People with credentials (e.g., Turing Award recipient Yoshua Bengio)…
OpenAI Related
8 September
Computer science professor who works on fast data processing; co-author of the simdjson parser and a weekly blogger about software performance since 2004.
Even if an AI did exactly what I told it to do, precisely and without error, I would still work hard as an engineer. Brooks told us why in 1986: "Even perfect program verification can only establish that a program meets its specification. Much of the essence of building a program is in fact the debugging of the specification." What he meant is that engineering is not the execution of commands... It is very much design. And design is ridiculously difficult. You need to decide what you will build and how you will build it. Of course, you can outsource the design to the AI. But that's assuming t… Related
7 September
Economic historian at Columbia; writes Chartbook on economics, geopolitics and history, and wrote Crashed and The Deluge.
Their words
To my mind, if progressive policy hopes to engage with such voters at all - and it is open question whether it should - it must address not just the material realities of relative economic disadvantage, but above all the "outsider" credentials of the AfD.
Show the whole quote
adamtooze.substack.com
5 September
Programmer, teacher and speaker; long-time Microsoft developer-community figure, host of the Hanselminutes podcast and author of the hanselman.com blog.
Awesome! Insane stuff like this is why we open sourced Zork Quoting @emollick This impressed me: I asked GPT-6 Astra to turn Zork (the classic 1977 text adventure) into a full 3D action-adventure game It kept the original plot & puzzles, added fight scenes, and built all of the characters & environments directly in Threejs Play: Related
21 August
Security researcher; built Report URI and Security Headers, and writes about web security in practice.
11 August
Security researcher; built Report URI and Security Headers, and writes about web security in practice.
30 July
Chief Scientist at Google DeepMind and Google Research, at Google since 1999, where he co-created MapReduce, Bigtable, TensorFlow and the TPU.
27 July
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
HTTP Message Signatures with curl The recently published RFC 9421 describes how to do HTTP Message Signatures, and starting just now, curl experimentally supports them. Message Signatures The specification describes this as a mechanism for creating, enc…
Related
20 July
Cryptography engineer; maintains Go's cryptography libraries as a full-time open-source maintainer, funded directly by companies that use them.
30 June
Mathematician and maker of the 3Blue1Brown YouTube channel, which explains mathematics through animation. Creator of the open-source Manim animation library and founder of the Summer of Math Exposition.
Their words
And I think a good exposition you care a little bit less about like correctness on the way, but you can like deliberately craft things that are a little bit wrong that you correct along the way that gets like edited out in a crowd source environment.
Show the whole quote
youtube.com
8 June
Security researcher; built Report URI and Security Headers, and writes about web security in practice.
5 June
Security researcher; built Report URI and Security Headers, and writes about web security in practice.
DBSC Beta at Report URI This week, I published a blog post about Device Bound Session Credentials, a new technology that will significantly hamper the efforts of Infostealers and reduce the damage caused by stolen cookies. Today, we're announc…
Related
3 June
Engineer and teacher; wrote Kubernetes the Hard Way, was a distinguished engineer at Google Cloud, and retired from full-time work in 2023.
the cloud
Their words
You have to call like seven APIs to get a VM in the cloud. Create a VM, a network, a storage device connected to a VPC and then attach credentials. Like that's not intent based. I want a VM.
Show the whole quote
youtube.com
14 May
Swedish designer and programmer. Designed early Spotify, worked at Facebook and Figma, and created the Inter typeface.
28 April
Programmer, teacher and speaker; long-time Microsoft developer-community figure, host of the Hanselminutes podcast and author of the hanselman.com blog.
The earliest DOS source code was found on printer paper in Tim Paterson's garage so we've open sourced it on 86-DOS 1.00’s 45th anniversary! This is next-level software archaeology for preservation, and plain ol’ curiosity. #DOS #RetroComputing opensource.microsoft.com
Related
17 April
Cryptographer; teaches cryptography at Johns Hopkins and writes A Few Thoughts on Cryptographic Engineering.
15 April
Writer and consultant on formal methods and software correctness; author of Practical TLA+ and Logic for Programmers.
24 March
Founding member of OpenAI and former director of AI at Tesla; creator of nanoGPT and the term "vibe coding".
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm… Quoting @hnykda LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below crypto Related
2 March
Cryptographer; teaches cryptography at Johns Hopkins and writes A Few Thoughts on Cryptographic Engineering.
Anonymous credentials: an illustrated primer This post has been on my back burner for well over a year. This has bothered me, since with every month that goes by, I become more convinced that anonymous authentication the most important topic we could be talking ab…
Related
30 April 2025
Founder and CEO of Epic Games, creator of the Unreal Engine and of Fortnite.
Their words
There's ever more pressure to rebuild society more and more around credentials. Do you have this certificate? Do you have that proof? But companies that are focused on just building great products and doing great things gravitate towards people who do the great work.
Show the whole quote
youtube.com
25 March 2025
Security researcher; founded Have I Been Pwned, and writes and speaks about data breaches.
Their words
This was obviously highly automated and designed to immediately export the list before the victim could take preventative measures.
Show the whole quote
troyhunt.com
19 February 2025
Economics professor at George Mason University and author of The Myth of the Rational Voter, Selfish Reasons to Have More Kids, The Case Against Education and Open Borders. Writes Bet On It.
28 November 2024
Machine-learning researcher; has written the Lil'Log survey posts on how a model technique works since 2017, and worked at OpenAI from 2018 to 2024, latterly leading its safety systems team.
10 April 2024
Writer and consultant on formal methods and software correctness; author of Practical TLA+ and Logic for Programmers.
25 March 2024
Independent policy analyst on space and national security, formerly of the RAND Corporation, who writes on counterspace weapons and rules for keeping satellites safe.
Their words
This raises public concerns that, at this late date, DoD might not have such a specification, whether classified or unclassified, even for its own internal use.
Show the whole quote
thespacereview.com
9 March 2024
American author of The Subtle Art of Not Giving a F*ck and Everything Is F*cked. Writes essays and book reviews at markmanson.net.
Nothing matches. Show everything
What is a korrent?
A korrent is a belief a person has stated in their own words: one
sentence stating the claim, backed by a quote and a source, kept at
korrents.com .
Under a name here, the quoted block is what they actually said.
The korrent beneath it is the claim those words support, in
korrents' wording — tap it to see the record, its source, and who
else holds it.
Nobody here wrote their own korrents. They are compiled from public
statements, and a person can change their mind, which is recorded too.
Got it
About the English under a post
Some people here publish in a language other than English. Where they
do, this site shows a machine translation beneath the post, in
this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the
serif above is exactly what the person published, and it is what to
quote them on. A translation can be wrong in ways that matter,
especially about tone.
Only the post's own words are translated. A quoted post, a linked
article and a belief on korrents.com
are left in their original language.
Got it