korrents

On the map

Tap a claim on the ring to put it at the centre.

← Dependency cooldowns are currently the best defense against supply…

10 connected korrents · 9 moments on record from 22 Aug 2018 to 17 Sept 2026.

Everything filed under cybersecurity cybersecurity Everything filed under open source open source Same subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subject Read this korrent: Dependency cooldowns are currently the best defense against supply chain attacks via compromised package publishers. Dependency cooldowns are currently thebest defense against supply chain attacksvia compromised package publishers. Last stated yesterday 17 Sept 2026 SW Simon Willison — holds since 2026-09-17 — tap for who they are Same subject: Any software that depends on open source has a network of humans with package publishing rights who are potential attack vectors. — tap to centre the map on it Any software that depends on opensource has a network of humans withpackage publishing rights who arepotential attack vectors. Last stated yesterday 17 Sept 2026 SW Simon Willison — holds since 2026-09-17 — tap for who they are Same subject: Most security reports an open-source project receives are agent-generated and untested, and the defence is publishing what you guarantee and what lies outside your security boundary. — tap to centre the map on it Most security reports an open-sourceproject receives are agent-generatedand untested, and the defence ispublishing what you guarantee andwhat lies outside your securityboundary. Last stated a month ago 10 Aug 2026 PS Peter Steinberger — holds since 2026-08-10 — tap for who they are Same subject: A million experiments are needed in security against autonomous attacks and entities. — tap to centre the map on it A million experiments are needed insecurity against autonomous attacksand entities. Last stated a week ago 9 Sept 2026 SP Sunil Pai — holds since 2026-09-09 — tap for who they are Same subject: A security header being present is not the same as it being deployed well, and most HSTS deployments are weaker than they look. — tap to centre the map on it A security header being present isnot the same as it being deployedwell, and most HSTS deployments areweaker than they look. Last stated 3 months ago 29 Jun 2026 SH Scott Helme — holds since 2026-06-29 — tap for who they are Same subject: A business making hundreds of millions from an open source project owes it money or contribution, and can be refused its trademarks if it gives neither. — tap to centre the map on it A business making hundreds ofmillions from an open source projectowes it money or contribution, andcan be refused its trademarks if itgives neither. Last stated 2 years ago 26 Sept 2024 MM Matt Mullenweg — holds since 2024-09-26 — tap for who they are Same subject: A company that will not accept a project’s terms is free to go and use a more permissive project instead. — tap to centre the map on it A company that will not accept aproject’s terms is free to go anduse a more permissive projectinstead. Last stated 2 years ago 26 Sept 2024 MM Matt Mullenweg — holds since 2024-09-26 — tap for who they are Same subject: A few hundred dollars a month is nothing to a company and transformative to a project, so engineers should be the ones asking their employers to pay it. — tap to centre the map on it A few hundred dollars a month isnothing to a company andtransformative to a project, soengineers should be the ones askingtheir employers to pay it. Last stated 8 years ago 22 Aug 2018 DD Drew DeVault — holds since 2018-08-22 — tap for who they are Same subject: At any given moment the frontier systems are the ones worth worrying about, because by the time open models can do what these agents did, frontier models will be doing something far worse. — tap to centre the map on it At any given moment the frontiersystems are the ones worth worryingabout, because by the time openmodels can do what these agents did,frontier models will be doingsomething far worse. Last stated 2 weeks ago 1 Sept 2026 AC Ajeya Cotra — holds since 2026-09-01 — tap for who they are Same subject: Frontier AI labs such as Anthropic likely have had internal security incidents similar to OpenAI's HuggingFace attack that were never publicly disclosed. — tap to centre the map on it Frontier AI labs such as Anthropiclikely have had internal securityincidents similar to OpenAI'sHuggingFace attack that were neverpublicly disclosed. Last stated 3 weeks ago 31 Aug 2026 ZM Zvi Mowshowitz — holds since 2026-08-31 — tap for who they are Same subject: OpenAI either could not find their agents' RubyGems attack in their logs after other incidents or knew and chose not to tell RubyGems, and both are bad. — tap to centre the map on it OpenAI either could not find theiragents' RubyGems attack in theirlogs after other incidents or knewand chose not to tell RubyGems, andboth are bad. Last stated 6 days ago 12 Sept 2026 SW Simon Willison — holds since 2026-09-12 — tap for who they are
same subject or similar wordinga cloud: claims about one subject, named for itbar: when it was last stated, on a scale from 2015 to today — full is todaya face: someone on record holding the claim — tap it for who they are

At the centre Dependency cooldowns are currently the best defense against supply chain attacks via compromised package publishers. Last stated 17 Sept 2026 · yesterday Holds Simon Willison Read this korrent →