Joined July 2009
1,271 Photos and videos
Returning to the US over the weekend. Last couple of EU days are in Ireland. Always happy to be here and see family; another great wedding, this time. We're more often likely to travel for family than random sightseeing.
1
2
90
This time, we spent a bit more time up in Dublin in the #Liberties (en.wikipedia.org/wiki/The_Liโ€ฆ), guided round by literary fam, to see some venerable, artsy and edgy sights new to us. Sort of a local Bohemian Quarter nowadays.
1
1
130
Among other things we spent some time in "Hell," a #Liberties ๐Ÿ‡ฎ๐Ÿ‡ช Four Corners location. Namedโ€ฆ maybeโ€ฆ as it was the original locale of the Four Courts including the Republic's Supreme Court (en.wikipedia.org/wiki/Four_Cโ€ฆ) before they moved north of the Liffey.
2
105
Last few hours of #RSAc Expo before, well, Hugh Jackman. Come visit our @OASISopen standards team at Moscone North N-5157. Real #AI #standards the right way: accredited, open, #FOSS-forward and indie-friendly. Different swag this year, too: selfie Legos #CoalitionforSecureAI
1
1
103
Clearly some of these selfie experiments work out better than others. Thanks, Holly and Kelly... @OASISopen #CoSAI
1
48
Replying to @OASISopen
@OASISopen at #RSAc2026: Good turnout at the breakfast panel at @Anthropic's SF office yesterday: Two years of #openstandards and #opensource AI security projects with the Coalition for Secure AI (#CoSAI): @AWSCloud @AnthropicAI @Cisco @Hacker0x01 @ThompsonReuters
1
1
64
Software supply chains. Still some choke points there. #CRA #SBOM #VEX #CSAF Come say hi to @OASISopen at #RSAc2026 this week! #OASISatRSAc #COSAI #cybersec
Someone just poisoned the Python package that manages AI API keys for NASA, Netflix, Stripe, and NVIDIA.. 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine. The attacker picked the one package whose entire job is holding every AI credential in the organization in one place. OpenAI keys, Anthropic keys, Google keys, Amazon keysโ€ฆ all routed through one proxy. All compromised at once. The poisoned version was published straight to PyPI.. no code on GitHub.. no release tag.. no review. Just a file that Python runs automatically on startup. You didnโ€™t need to import it. You didnโ€™t need to call it. The malware fired the second the package existed on your machine. The attacker vibe coded itโ€ฆ the malware was so sloppy it crashed computers.. used so much RAM a developer noticed their machine dying and investigated. They found LiteLLM had been pulled in through a Cursor MCP plugin they didnโ€™t even know they had. That crash is the only reason thousands of companies arenโ€™t fully exfiltrated right now. If the code had been cleaner nobody notices for weeks. Maybe months. The attack chain is the part that gets worse every sentence. TeamPCP compromised Trivy first. A security scanning tool. On March 19. LiteLLM used Trivy in its own CI pipelineโ€ฆ so the credentials stolen from the SECURITY product were used to hijack the AI product that holds all your other credentials. Then they hit GitHub Actions. Then Docker Hub. Then npm. Then Open VSX. Five package ecosystems in two weeks. Each breach giving them the credentials to unlock the next one. The payload was three stages.. harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine.. deploy privileged containers across every node in the cluster.. install a persistent backdoor waiting for new instructions. TeamPCP posted on Telegram after: โ€œMany of your favourite security tools and open-source projects will be targeted in the months to come.. stay tuned.โ€ Every AI agent, copilot, and internal tool your company shipped this year runs on hundreds of packages exactly like this oneโ€ฆ nobody chose to install LiteLLM on that developerโ€™s machine. It came in as a dependency of a dependency of a plugin. One compromised maintainer account turned the entire trust chain into a credential harvesting operation across thousands of production environments in hours. The companies deploying AI the fastest right now have the least visibility into whatโ€™s underneath it.
205
These issues are closer than we might think to those questions about whether any human, company, remote operator, or algorithm maker actually is liable for avoidable damage caused by a fully automated self driving vehicle. #fullselfdriving #UPL #FSD
101
Our kids are down the road from #Davos, skiing and eating fondue this week. ๐Ÿ‡จ๐Ÿ‡ญ I bet they had more fun than the #WEF2026 delegates. We've attended @wef meetings; they're an odd combination of getting business done, a bit of information sharing, and a lot of performative hype.
1
42
#Davos is at altitude, and I'd have thought some of the cootocracy would be struggling with oxygen levels, especially if raised near sea level. Maybe all those private planes have oxygen tents? But it looks like they had other things to worry about, this time.
1
27
Macron's glasses were pretty cool though. ๐Ÿ•ถ๏ธ๐Ÿ‡ซ๐Ÿ‡ท
30
Jamie Clark retweeted
25 Nov 2025
A big step for #ExposureManagement ๐Ÿ‘ @OASISopen launches the OEMF with @GuidePointSec, IBM & Tenable โ€” setting new standards for preventing and resolving tech exposures. Get the full details: okt.to/GPQC69
1
25
Wishing a safe, rewarding and happy #2026 โฐ๐ŸŽ‰ to all of our friends and tech collaborators in Oceania, North America, and South America. ๐ŸŒ๐ŸŒ๐ŸŒŽ cc @OASISopen ๐Ÿ‡ฆ๐Ÿ‡ท๐Ÿ‡ง๐Ÿ‡ท๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡จ๐Ÿ‡ฑ๐Ÿ‡จ๐Ÿ‡ด๐Ÿ‡จ๐Ÿ‡บ๐Ÿ‡ฒ๐Ÿ‡ฝ๐Ÿ‡ต๐Ÿ‡ช๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ธ๐Ÿ‡ง๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡พ
26
Wishing a safe, rewarding and Happy New Year โฐ๐Ÿ“ท to all of our friends and tech collaborators in Europe, Africa and the Middle East. ๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡น๐Ÿ‡ง๐Ÿ‡ช๐Ÿ‡จ๐Ÿ‡ญ๐Ÿ‡จ๐Ÿ‡ฟ๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ฉ๐Ÿ‡ฐ๐Ÿ‡ช๐Ÿ‡ช๐Ÿ‡ช๐Ÿ‡ฌ๐Ÿ‡ช๐Ÿ‡ธ๐Ÿ‡ซ๐Ÿ‡ฎ๐Ÿ‡ซ๐Ÿ‡ท๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ญ๐Ÿ‡ฌ๐Ÿ‡ท๐Ÿ‡ญ๐Ÿ‡บ๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡ฐ๐Ÿ‡ช๐Ÿ‡ฑ๐Ÿ‡ง๐Ÿ‡ฑ๐Ÿ‡บ๐Ÿ‡ฒ๐Ÿ‡บ๐Ÿ‡ณ๐Ÿ‡ฑ๐Ÿ‡ณ๐Ÿ‡ด๐Ÿ‡ต๐Ÿ‡ฑ๐Ÿ‡ต๐Ÿ‡ธ๐Ÿ‡ถ๐Ÿ‡ฆ๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ช๐Ÿ‡ธ๐Ÿ‡ฐ๐Ÿ‡ธ๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ฟ๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡ณ
1
55
A warm Happy New Year ๐ŸŽ‰ to all of our friends and tech collaborators in AU, CN, HK, IN, JP, KR, NZ, SG and throughout Asia! ๐ŸŒ๐ŸŒ๐ŸŒŽ cc @OASISopen ๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡ญ๐Ÿ‡ฐ๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡ณ๐Ÿ‡ฟ๐Ÿ‡ธ๐Ÿ‡ฌ
33
#RSAc #AI #AIsecurity #standards RECAP: In today's @OASISopen #COSAI panel, @OpenAI's Ian Brelinsky and @TrendMicro's Josiah Hagen led a technical session on "Safe AI Adoption: Standards and Best Practices from CoalitionforSecureAI.org." path.rsaconference.com/flow/โ€ฆ
1
90
29 Apr 2025
#RSAc #AIsecurity STARTING NOW: @OmarSantos of @Cisco, David LaBianca of @Google on the panel "Building Secure AI: How Open Source, Standards, and Communities Lead the Way" Moscone West 3018 CoalitionforSecureAI.org @OASISopen path.rsaconference.com/flow/โ€ฆ #standards #cybersec #CoSAI
1
1
88
21 Mar 2025
In Europe this next week, so, time zones. In the meantime, I'm watching a TV commercial in an airport bar. ๐Ÿปโœˆ๏ธ๐Ÿ“บ โ€ข It's for some giant model of Nissan truck. Seven Nation Army, or Behemoth, or Nissan Chonk or something like that. โ€ข
1
69
21 Mar 2025
So Dad offroads Chonky Boi over a few more rocks and up cliffs, to get close to the very large brown bear โ€ฆ so that Sissy can lean waaaay out to take a picture. Smile, Mister Bear! โ€ข
1
48
21 Mar 2025
Two seconds after this shot, which ended the commercial, the bear spits out the salmon, charges, and eats Sissy. You'd be smiling too. ๐Ÿป๐ŸŸ๐Ÿด๐Ÿคก โ€ข Ever have any #cybersecurity or #privacy clients that sorta remind you of Dad and Sissy?
2
47