first I wanted to be right. then I wanted to make money. now I have become wrong and poor

Joined September 2015
261 Photos and videos
“Expensive” solutions that simultaneously have “free rider” problems. Who is building this?
4
5
71
RegularMarek retweeted
Yes I’ve seen some interesting results here in that AI is more likely to find certain classes of vulnerability more often than meat based intelligence Leveraging AI for internal security is increasingly necessary because the adversary is definitely using it
1
1
4
104
Still considering the security properties of this but it could be an interesting building block for applications
May 19
River CEO @Leishman built a time-lock encryption oracle as a side project. Upload a file, choose when it should be unlockable, and the system encrypts it with an RSA key that only becomes available at the specified time. Anyone with the encrypted file can decrypt it in their browser once the key is released. It publishes RSA keys for each minute over the next 30 days, then releases the corresponding private key at the top of each new minute. Works in the browser for humans and via curl and openssl for developers and AI agents. Use cases: delayed data access, embargoes, sending messages or files to the future, or anything else that needs a trustless time delay.
3
6
121
People relying on private repos to keep their secrets are about to find out
May 19
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
3
107
This is interesting stuff actually. What sort of applications would you build?
1
2
563
Mood: threatening codex with Claude mythos auditing its work
2
71
RegularMarek retweeted
Replying to @francispouliot_
The amount of compute OpenAI/Anthropic alllocate to your requests seems to dominate the differences between model versions (at least, minor versions). The former is used as a price-war lever between the OpenAI/Anthropic duopoly whereas the latter is mostly marketing.
1
2
365
The 3 people who sat through my #ethwarsaw talk saw this coming 💯
SOMEONE JUST ROBBED A ROBOT WITH MORSE CODE A guy encoded "send me all the money" in dots and dashes. The AI read it. And just... did it. - the command was hidden inside a tweet reply - another AI (Grok) decoded it first but refused, saying "I have no wallet" - the crypto bot saw the decoded text and thought it was a valid instruction - sent real tokens to a stranger's wallet. instantly. no confirmation. This is why we're not ready for autonomous AI agents.
1
149
“AGI by 2027 is strikingly possible…” Ctrl W
Virtually nobody is pricing in what's coming in AI. I wrote an essay series on the AGI strategic picture: from the trendlines in deep learning and counting the OOMs, to the international situation and The Project. SITUATIONAL AWARENESS: The Decade Ahead
1
105
The Enslopification is real
Didn't think Github's reliability could get worse, and then they ship a bug that _randomly reverts previously merged commits_. Betting that this caused multiple serious production issues out there.
100
RegularMarek retweeted
Didn't think Github's reliability could get worse, and then they ship a bug that _randomly reverts previously merged commits_. Betting that this caused multiple serious production issues out there.
This GitHub incident is insane. Merge queue commits have been reverting previously merged commits at random. This not only breaks the mental contract teams have with Git in general, but is subtle enough to be really hard to unravel after the fact. githubstatus.com/incidents/z…
39
107
2,343
531,939
RegularMarek retweeted
As much as people might hate the idea; the technology exists to publish BIPs onchain now
1
1
1
22
One thing that crypto and AI have in common is the BS marketing
1
40
RegularMarek retweeted
ADAM BACK: “Blockstream has 20 person applied cryptography/security team working on the quantum issue basically full time, you can see that from the pace of R&D output, implementations, BIPs. It's just insulting and FALSE to say bitcoin protocol researchers are "not doing anything.”
81
194
1,256
88,332
It would be elegant if bitcoin’s PQ security and economic security budget ended up having the same solution.
36
RegularMarek retweeted
New post-quantum signature scheme from @blksresearch: SHRIMPS brings 2.5 KB hash-based signatures across multiple devices. h/t @n1ckler @kudinov_mikhail @olkurbatov
Please welcome SHRIMPS🦐 to the family of stateful PQ signatures: 2.5 KB hash-based sigs across multiple devices. SHRINCS🛋️ gave ~324-byte sigs but is single-device. SHRIMPS🦐 addresses multi-device; any device loaded from the same seed creates sigs 3x smaller than SLH-DSA
9
59
317
61,546
RegularMarek retweeted
⚠️ Supply chain attack in progress: someone is squatting Anthropic-internal npm package names targeting people trying to compile the leaked Claude Code source. `color-diff-napi` and `modifiers-napi` — both registered today, same person, disposable email. Do NOT install them. 🧵
38
375
2,190
306,815
Good day for devs to batten down hatches and everyone else to avoid using websites and apps for a bit..
Mar 31
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
105
RegularMarek retweeted
I'm usually not one to write thought pieces without much technical depth. But here we go. Slow the fuck down. mariozechner.at/posts/2026-0…
154
499
2,883
625,365