Jasvir Nagra's Avatar

Jasvir Nagra

@jasvir.bsky.social

Advisor & builder. Formerly security @dropbox, product @instart & @google, authored Surreptitious Software, TL for Caja. I love good food, fine wine & great JS.

206 Followers  |  86 Following  |  171 Posts  |  Joined: 02.05.2023  |  1.7087

Latest posts by jasvir.bsky.social on Bluesky

Yeah it hallucinates.

But instead of complaining, what if realized that was a feature and find use cases when a little hallucination is not merely desirable but phenomenal?

09.10.2025 16:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I think I saw the sequel based on Banach–Tarski but it was just a remake - practically a the same as the original.

25.09.2025 22:21 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Would be funny if I made a duplicate joke reply here with zero additional um material.

25.09.2025 22:21 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Bypassing CSP using polyglot JPEGs James challenged me to see if it was possible to create a polyglot JavaScript/JPEG. Doing so would allow me to bypass CSP on almost any website that hosts user-uploaded images on the same domain. I gl

You saying @garethheyes.co.uk and I should take down our GIF/JS polyglot writeups from way back when? ;-)

portswigger.net/research/byp...

(It's ok - mine is already offline but out of laziness rather than concern! :-) )

22.09.2025 21:52 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

...so you're um post gum?

22.09.2025 21:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I miss the simplicity of old Browsershots - "here's a url, give me a grid of screenshots". I had a tiny template which changed bgcolor of the page based on pass/fail. You could eyeball 100s of browser/version/OS at a glance.

New "dashboards" comparatively suck.

What do you use?

22.09.2025 20:28 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

A tshirt has 4 holes - when I turn it inside out, I sometimes pause in wonderment that no matter which one I use, the outcome is the same

When you turn a tshirt inside out, which one do you use most?
* Any (why think about it?)
* Bottom (I'm normal!)
* Neck (I'm a rebel!)
* Only sleeves (my peeps!)

19.09.2025 19:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

It's hard to convey how frustrating it is seeing people take away the wrong lesson from the npm worm & knowing it'll harden (heh) the wrong approach to addressing issues like it.

And to anyone wanting to ask me what I am doing about it - sadly nothing - I'm busy elsewhere.

16.09.2025 19:50 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The number of times I hear about a soon to be amazingly successful company who "merely" recreated anycast & DNS but badly is too damn high.

It would be fine if all they did was give it some much needed UX sugar but when they break its nice properties is when it hurts my soul.

15.09.2025 16:45 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

It took me a second to work out the whacky way PetSmart sorts fish tank sizes - but that there is only 1 30G & over tank but 11 40-54G tanks...seems wrong.

13.09.2025 17:16 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I too am considering starting every reply in a conversation in real life with how many seconds I have spent "thinking".

Incidentally, I thought for 6 seconds before crafting this message.

12.09.2025 16:15 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Forth was ahead of it's time with it's use of programmable syntactic whitespace.

11.09.2025 04:59 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Eh they didn't really.

09.09.2025 21:21 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Did you hear that X just killed Y? Here's why?

09.09.2025 21:21 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

You might also love Cockney rhyming slang. Or as no one but me would call it Cockney bang and clang. :p

09.09.2025 15:43 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Of course there's 3I/ATLAS - the Ramans always do things in threes.

09.09.2025 15:39 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The modern day version of that high school β€œdrop an egg without breaking it” contest is going to be β€œdrop a Tardigrade on a moon without killing it”.

08.09.2025 16:39 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I just realized that "jelly bean" is a spoonerism of "Billie Jean"! Brace yourself for a whole new genre of songs.

Jelly bean is not my candy
She’s just a bean who claims I’m the one
But the sweet tooth’s not my cavity
Just a lil snack travesty...

05.09.2025 18:21 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I assume @lahosken.bsky.social you just mean AI will never be as tasty as meat when paired with a Chianti.

02.09.2025 20:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It'll be funny to me if they brought out some kind of danger metric based on deaths per car to curb autonomous vehicles and had to ban humans from driving.

02.09.2025 20:34 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

When it doesn't just hallucinate but makes me wonder if I am hallucinating too! I definitely did not type index.htmll!

22.08.2025 20:24 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I’m trying to be objective but I still don’t understand why so many of y’all think that meat is better than silicon.

20.08.2025 16:53 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

You remain the winner of my Jeopardy references @mvsamuel.bsky.social !

20.08.2025 05:49 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

As I often tell web servers I talk to, listen 0x505249202a20485454502f322e300d0a0d0a534d0d0a0d0a ...

20.08.2025 01:38 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Something something something personality is just the emergent state that is a function of the sequence of events of a character's past - ie their backstory. ;-)

20.08.2025 00:40 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I do sometimes wonder how much of openai, gemini and anthropic core is now vibe coded. ...and what that means.

20.08.2025 00:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

The message itself was apparently 1 truss temporary.

14.08.2025 21:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

...a little problematic how often I find myself writing prose on various command lines rather than commands because I've gotten so used to everything being an LLM.

This bodes badly for me.

14.08.2025 21:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The amount of work I'm willing to do just for the lolz - even a little lolz - might be unbounded.

This is a feature ... except you know having to have to feed myself.

14.08.2025 16:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It's funny seeing the agentic community Igor their way to the actor model for security.

I know I'm being mean.

But I'm not wrong.

13.08.2025 00:29 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@jasvir is following 20 prominent accounts