Related posts
Max Howell
x.com
Your agents run Full Access. The Supply Chain is Compromised. The apps are vibe-coded. It’s fine: just install Automic Vault.
automic vault compromised
The the words it uses that this site has seen
least often elsewhere. Posts are matched on those words alone —
nothing here is a summary of this one.
Sources
All
Mastodon Korrents x.com YouTube Blog Site
Top people
Max Howell
Terence Eden
Simon Willison
Tiago Forte
Jonathan Shedler
Charity Majors
Scott Helme
Stefan Zweifel
Drew DeVault
Grant Sanderson
Lyn Alden
Showing
Profile →
Show everything
Hiding
Show them again
Show them again
Further back ↓
Hiding
Show them again
19 September
British open-standards and open-source technologist, formerly of the UK Government Digital Service and the W3C Advisory Committee. Blogs at shkspr.mobi, where he posts a book review most weeks.
You know what? This *does* taste of Irn Bru. Whether that's a good thing or not depends on your tastebuds. Drinking: Iron Brew By: Vault City Brewing At: Woolwich Works 🍺🍺🍺 https://untappd.com/user/edent/checkin/1602652115 #untappd Related
17 September
Co-creator of Django and creator of Datasette; writes daily at simonwillison.net.
Their words
I guess our best defense right now is dependency cooldowns - giving new package releases a few days before upgrading to them, in the hope that supply chain attacks like this will be spotted by someone else.
Show the whole quote
simonwillison.net
11 September
Creator of Homebrew, the macOS package manager, and a Swift developer.
Your agents run Full Access. The Supply Chain is Compromised. The apps are vibe-coded. Related
10 September
Writer and teacher on productivity and personal knowledge management. Author of Building a Second Brain and founder of Forte Labs, which runs the course of the same name.
Nick Milo Reads My Obsidian Vault (The Full Session) Related
8 September
Creator of Homebrew, the macOS package manager, and a Swift developer.
In a near-future-release of Automic Vault we have added ssh-agent support. Automatically allow ssh connections for trusted destinations. Require human approval for everything else. Human approval can happen on the iPhone app. eg. allow your Terminal automatically and deny your agents. You can delete the keys from ~/.ssh/ after import. Keys are properly encrypted in the keychain. Related
28 August
Creator of Homebrew, the macOS package manager, and a Swift developer.
Automic Vault means your CLI tools don’t perform sensitive actions without your approval. This applies to agents and supply chain attacks both. We patch tools at the *packaging layer*. Blessed Scripts allow you to make small, vetted scripts that escalate tool capabilities. Reentrant Blessed Scripts are a scripting pattern that allow you to “weave” in agent capabilities. Interleaving deterministic work with escalated Tool capabilities and secrets with applied intelligence. Perfect for automations. Quoting @AutomicVault We have documented the concept of `Reentrant Blessed Scripts` that describe our suggested mechanism of giving Agent Automations a set of escalated capabilities and secrets. Have the automation execute a Blessed Script with Automic Vault front-matter for the capabilities and… Related
27 July
Clinical psychologist and clinical professor of psychiatry at UCSF. His 2010 meta-analysis established psychodynamic therapy as an evidence-based treatment; he has argued ever since that "evidence-based therapy" is used as a marketing term.
24 June
Co-founder and CTO of Honeycomb; previously an infrastructure engineer at Parse, Facebook and Linden Lab, and co-author of Observability Engineering.
i said i would write a followup piece on AI and ethics, and I have. Here it is. We do not get to choose to live in a pure world. But we get to choose whether to help shape the compromised world we already live in. Related
15 June
Security researcher; built Report URI and Security Headers, and writes about web security in practice.
2 June
Swiss full-stack developer working mostly with Laravel and Vue; author of the widely used git-auto-commit-action GitHub Action.
If you've been using my "laravel-backup-restore" package in your projects, please upgrade to the latest version as soon as possible. v1.9.4 fixes multiple security vulnerabilities that could affect you, if your dump files have been compromised. github.com
Related
17 September 2025
Free software developer; maintainer of sway, wlroots, aerc and scdoc, and founder of the SourceHut (sr.ht) software forge.
19 July 2025
Mathematician and maker of the 3Blue1Brown YouTube channel, which explains mathematics through animation. Creator of the open-source Manim animation library and founder of the Summer of Math Exposition.
Welp, somewhat embarrassingly, yesterday this account was briefly compromised and someone posing as me promoted a crypto project supposedly "tokenizing" manim. Thank you to those of you who quickly flagged it as spam and alerted me to the problem. For future reference, it's a safe bet that you'll never see me creating and promoting a meme coin. crypto Related
27 February 2025
Investment researcher and engineer who runs Lyn Alden Investment Strategy, writing on macroeconomics, currency systems and equity analysis.
Twitter/X Restored My Twitter/X account was compromised from February 26th to March 3rd, but I confirm that I’ve regained control of it now. Thank you to everyone who helped make it happen. Fortunately, I still had access to Nostr during…
Related
Nothing matches. Show everything
What is a korrent?
A korrent is a belief a person has stated in their own words: one
sentence stating the claim, backed by a quote and a source, kept at
korrents.com .
Under a name here, the quoted block is what they actually said.
The korrent beneath it is the claim those words support, in
korrents' wording — tap it to see the record, its source, and who
else holds it.
Nobody here wrote their own korrents. They are compiled from public
statements, and a person can change their mind, which is recorded too.
Got it
About the English under a post
Some people here publish in a language other than English. Where they
do, this site shows a machine translation beneath the post, in
this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the
serif above is exactly what the person published, and it is what to
quote them on. A translation can be wrong in ways that matter,
especially about tone.
Only the post's own words are translated. A quoted post, a linked
article and a belief on korrents.com
are left in their original language.
Got it