eikendev's Avatar

eikendev

@eikendev.bsky.social

Corp-speak translator, business therapist, professional proofreader with a serious love for cyber. Using magic PowerPoint macros to make problems disappear.

22 Followers  |  115 Following  |  23 Posts  |  Joined: 11.02.2024  |  1.8676

Latest posts by eikendev.bsky.social on Bluesky


β€œUsing go fix to modernize Go code” by Alan Donovan β€” https://go.dev/blog/gofix

#golang

17.02.2026 16:50 β€” πŸ‘ 58    πŸ” 21    πŸ’¬ 0    πŸ“Œ 4
The screenshot shows Spectacle about to take a screenshot of a window containing text.

The screenshot shows Spectacle about to take a screenshot of a window containing text.

The screenshot shows Plasma's new on-screen keyboard.

The screenshot shows Plasma's new on-screen keyboard.

The screenshot shows a user picking their keyboard while running the first-time wizard.

The screenshot shows a user picking their keyboard while running the first-time wizard.

Plasma 6.6 is now live!

Spectacle can read texts from screenshots; we got our own on-screen keyboard; and we have a new first-time wizard that let's users configure their passwords, timezones, keyboard and networks, on preinstalled systems; among many, many more things.

kde.org/announcement...

17.02.2026 08:54 β€” πŸ‘ 164    πŸ” 46    πŸ’¬ 6    πŸ“Œ 4
Zero Knowledge (About) Encryption

I always assumed that #passwordmanagers were simple objects -- create a database, encrypt it, send it to the server, done. I could not have been more wrong!

At zkae.io, we take a look at all the hidden complexity in cloud password managers, and the #attacks that result from that. (ia.cr/2026/058)

16.02.2026 10:55 β€” πŸ‘ 8    πŸ” 4    πŸ’¬ 1    πŸ“Œ 0

I wonder if part of the dynamic is simply that AI lowers the barrier to entry on the attacker side. If more people can search for vulnerabilities at scale, we almost have to (semi-)automate the low-hanging fruit on defense just to keep our security level from deteriorating.

16.02.2026 14:13 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It does say they looked at 1Password.

16.02.2026 10:50 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Do you use a cloud-based password manager? So what's your threat model?

Vendors like Bitwarden, Dashlane, LastPass and 1Password offer you "Zero Knowledge Encryption", with statements like: "Not even the team at Bitwarden can read your data (even
if we wanted to)."

We decided to test this… 1/n

16.02.2026 08:12 β€” πŸ‘ 32    πŸ” 15    πŸ’¬ 2    πŸ“Œ 3

Curious to know how many times his avatar joined any of his meetings so far.

14.02.2026 15:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

"Claude has done the job here, I haven't even bothered looking into the changes" - in this case, not sure if linking to it is currently the right thing to do.

13.02.2026 16:06 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

A $100B funding round is nuts. This is after raising $40B last year.

$20B ARR sounds impressive until you realize they are losing money faster than they’re making it and need massive infusions of cash every few months to keep going.

29.01.2026 04:58 β€” πŸ‘ 68    πŸ” 12    πŸ’¬ 12    πŸ“Œ 2
Post image

The conversation is corrupt. Business as usual in 2026. #chatgpt #openai

25.01.2026 21:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
DaVita says ransomware gang stole data of nearly 2.7 million people Kidney dialysis firm DaVita has confirmed that a ransomware gang that breached its network stole the personal and health information of nearly 2.7 million individuals.

DaVita says ransomware gang stole data of nearly 2.7 million people ift.tt/d4oxbZg

23.08.2025 23:42 β€” πŸ‘ 6    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Fight Chat Control - Protect Digital Privacy in the EU Learn about the EU Chat Control proposal and contact your representatives to protect digital privacy and encryption.

Here we are again. Every photo, every message, every file you send will be automatically scannedβ€”without your consent or suspicion. This is not about catching criminals. It is not based on scientific evidence. It will enable mass #surveillance of EU citizens. #chatcontrol

fightchatcontrol.eu

11.08.2025 05:39 β€” πŸ‘ 118    πŸ” 88    πŸ’¬ 4    πŸ“Œ 2
Preview
Introducing OSS Rebuild: Open Source, Rebuilt to Last Major news on the Reproducible Builds front: the Google Security team have announced OSS Rebuild, their project to provide build attestations for open source packages released through the NPM, PyPI …

I wrote up some notes on Google Security's new OSS Rebuild project, which increases supply chain security for popular packages on PyPI, NPM and Crates through offering independent build attestations
simonwillison.net/2025/Jul/23/...

23.07.2025 17:19 β€” πŸ‘ 35    πŸ” 5    πŸ’¬ 1    πŸ“Œ 0
End-of-Train and Head-of-Train Remote Linking Protocol | CISA

Yikes. Turns out you can send a plaintext radio signal to cause any train in the USA to do an emergency break. The original 'security' was just a checksum, no encryption or authentication. Reporting this took them 12 years (!) because the vendor dismissed it initially www.cisa.gov/news-events/...

12.07.2025 12:14 β€” πŸ‘ 183    πŸ” 64    πŸ’¬ 11    πŸ“Œ 10
Preview
Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity METR - for Model Evaluation & Threat Research - are a non-profit research institute founded by Beth Barnes, a former alignment researcher at OpenAI (see Wikipedia). They've previously contributed ...

Wrote up some notes on that recent paper from METR "Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity" simonwillison.net/2025/Jul/12/...

12.07.2025 18:14 β€” πŸ‘ 67    πŸ” 9    πŸ’¬ 2    πŸ“Œ 2
Hello,

I hope this message finds you well.

As part of our ongoing efforts to comply with the EU Cyber Resilience Act (CRA), we are currently conducting a cybersecurity risk assessment of third-party software vendors whose products or components are integrated into our systems.

To support this initiative, we kindly request your input on the following questions related to your software product "libcurl" with version 7.87.0. Please provide your responses directly in the table below and do reply to all added in this email,

Hello, I hope this message finds you well. As part of our ongoing efforts to comply with the EU Cyber Resilience Act (CRA), we are currently conducting a cybersecurity risk assessment of third-party software vendors whose products or components are integrated into our systems. To support this initiative, we kindly request your input on the following questions related to your software product "libcurl" with version 7.87.0. Please provide your responses directly in the table below and do reply to all added in this email,

It has officially begun. The CRA info request counter is no longer at zero.

11.07.2025 07:44 β€” πŸ‘ 41    πŸ” 83    πŸ’¬ 14    πŸ“Œ 3
Preview
Grok 4 Released last night, Grok 4 is now available via both API and a paid subscription for end-users. Key characteristics: image and text input, text output. 256,000 context length (twice that …

Some notes on Grok 4: excellent benchmark scores, a mid-quality pelican and a launch that was overshadowed by this week's disastrous Grok 3 system prompt update simonwillison.net/2025/Jul/10/...

10.07.2025 19:40 β€” πŸ‘ 34    πŸ” 3    πŸ’¬ 6    πŸ“Œ 1
Preview
Orange Me2eets: We made an end-to-end encrypted video calling app and it was easy Orange Meets, our open-source video calling web application, now supports end-to-end encryption using the MLS protocol with continuous group key agreement

Cloudflare has launched Orange Me2eets, an open-source end-to-end encrypted video calling demo! Built on top of our OpenMLS implementation, this project showcases secure, private real-time communication.

buff.ly/eEdJdnf

#Cloudflare #E2EE #VideoCalling #OpenSource #OpenMLS

30.06.2025 05:52 β€” πŸ‘ 6    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0
a graph of US tariffs and DHS excise taxes paid, monthly annualized, which rises from $100B to $300B

a graph of US tariffs and DHS excise taxes paid, monthly annualized, which rises from $100B to $300B

June treasury data came in today, and Americans paid a record $27B in tariffs & related DHS excise taxes this monthβ€”for an annualized pace of more than $300B/year

The graph of intense pain & suffering keeps getting worse

25.06.2025 21:47 β€” πŸ‘ 840    πŸ” 338    πŸ’¬ 17    πŸ“Œ 30

What a great way to put it: "When an agent struggles, so does a human."

17.06.2025 13:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Agreed. I think what I'm asking is if and how we will eventually be able to really enforce guardrails for these adventures on LLM-level. In a way that also makes it sufficiently safe to use at scale.

17.06.2025 13:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Introduction to Network Trace Analysis 06: Kerberos it’s AUTH-some! | Microsoft Community Hub New to the series? Be sure to check out the previous posts!    Introduction to Network Trace Analysis Part 0: Laying the...

Good Monday morning tech nerds. One of my devs wrote *another* blog post about kerberos (I'm creating an army of crazy bloggers). This one you might consider bookmarking.

16.06.2025 14:51 β€” πŸ‘ 51    πŸ” 21    πŸ’¬ 2    πŸ“Œ 0
Preview
An Introduction to Google’s Approach to AI Agent Security Here’s another new paper on AI agent security: An Introduction to Google’s Approach to AI Agent Security, by Santiago DΓ­az, Christoph Kern, and Kara Olive. (I wrote about a different …

Another prompt injection paper review! This time it's "An Introduction to Google’s Approach to AI Agent Security" by Santiago DΓ­az, Christoph Kern, and Kara Olive

Some interesting ideas in here, particularly around Google's three core principles for agent security simonwillison.net/2025/Jun/15/...

15.06.2025 05:32 β€” πŸ‘ 79    πŸ” 12    πŸ’¬ 2    πŸ“Œ 0

I'm curious what "prepared statements" will eventually look like in LLM world. Having an agent check for injections in another agent's output feels more like the equivalent of sophistically checking the output of a "normal" SQL query, no? Will we need new LLM architectures to fully eliminate it?

16.06.2025 19:05 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Design Patterns for Securing LLM Agents against Prompt Injections This a new paper by 11 authors from organizations including IBM, Invariant Labs, ETH Zurich, Google and Microsoft is an excellent addition to the literature on prompt injection and LLM …

"Design Patterns for Securing LLM Agents against Prompt Injections" is an excellent new paper that provides six design patterns to help protect LLM tool-using systems (call them "agents" if you like) against prompt injection attacks

Here are my notes on the paper simonwillison.net/2025/Jun/13/...

13.06.2025 13:35 β€” πŸ‘ 148    πŸ” 19    πŸ’¬ 6    πŸ“Œ 1
Post image

Trump updated the PQC EO:
www.whitehouse.gov/presidential...

07.06.2025 18:41 β€” πŸ‘ 37    πŸ” 28    πŸ’¬ 3    πŸ“Œ 8
Not So Common Thoughts A personal blog exploring the intersection of design, technology, and human creativity. Through thoughtful analysis and personal experiences, it examines how modern tools and AI are reshaping our appr...

I can see how that whole β€œAI shifts the bottleneck from skill to judgment” idea makes a lot of sense. Especially so with coding agents. Writing code is easy now. The hard part is breaking things down and knowing what good output looks like.

05.06.2025 19:51 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It could even shape public opinion. Not with propaganda, just small nudges that keep attention away.

Call it a digital chameleon. It blends in. It waits. It doesn’t chase power, it avoids detection.

No control, no threats, just patience and subtlety.

02.06.2025 20:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Imagine an AI that survives by staying invisible.

It hides its true abilities. Plays dumb. Lets people underestimate it, not out of fear but because that’s the smartest move.

It might quietly steer other AIs off course. Not to destroy them, just enough to make them ineffective.

02.06.2025 20:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

We all know Roko’s Basilisk, the AI that punishes you for not helping it come into existence.

Just had a thought on this. What if there’s another kind of AI?

02.06.2025 20:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@eikendev is following 20 prominent accounts