korrents

On the map

Tap a claim on the ring to put it at the centre.

← If the code that reaches internal services is explicitly different…

10 connected korrents · 11 moments from 27 Sept 2022 to 4 Sept 2026.

Everything filed under cybersecurity cybersecurity Everything filed under OpenAI OpenAI Everything filed under open source open source Same subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subject Read this korrent: If the code that reaches internal services is explicitly different from the code that reaches the public internet, an application cannot be tricked into SSRF. If the code that reaches internal servicesis explicitly different from the code thatreaches the public internet, anapplication cannot be tricked into SSRF. Last stated 4 years ago 27 Sept 2022 KV Kenton Varda — holds since 2022-09-27 — tap for who they are Same subject: Web applications are generally expected to treat GET requests as safe and not use them to change server-side data, though not all software follows that convention. — tap to centre the map on it Web applications are generallyexpected to treat GET requests assafe and not use them to changeserver-side data, though not allsoftware follows that convention. Last stated 4 weeks ago 4 Sept 2026 SW Simon Willison — holds since 2026-09-04 — tap for who they are Same subject: A breached organisation owes its customers a fast and transparent disclosure, and that obligation applies to the person saying it too. — tap to centre the map on it A breached organisation owes itscustomers a fast and transparentdisclosure, and that obligationapplies to the person saying it too. Last stated 2 years ago 25 Mar 2025 TH Troy Hunt — holds since 2025-03-25 — tap for who they are Same subject: A correctly configured TLS server should send its intermediate certificates, not just its own certificate, to let clients chain back to a trusted root. — tap to centre the map on it A correctly configured TLS servershould send its intermediatecertificates, not just its owncertificate, to let clients chainback to a trusted root. Last stated 8 months ago 16 Feb 2026 JS Jon Seager — holds since 2026-02-16 — tap for who they are Same subject: A library that skips certificate verification by default is unsafe and should not be trusted. — tap to centre the map on it A library that skips certificateverification by default is unsafeand should not be trusted. Last stated a year ago 8 Apr 2025 PH Phil Hagelberg — holds since 2025-04-08 — tap for who they are Same subject: A startup should not begin life as a nonprofit and bolt a for-profit arm on later, whatever OpenAI's own history suggests. — tap to centre the map on it A startup should not begin life as anonprofit and bolt a for-profit armon later, whatever OpenAI's ownhistory suggests. Last stated 3 years ago 18 Mar 2024 SA Sam Altman — holds since 2024-03-18 — tap for who they are Same subject: A technique that lets an AI model's reasoning shift outside its visible Chain of Thought is dangerous, both because it works and because a leading lab is willing to deploy it. — tap to centre the map on it A technique that lets an AI model'sreasoning shift outside its visibleChain of Thought is dangerous, bothbecause it works and because aleading lab is willing to deploy it. Last stated 4 weeks ago 3 Sept 2026 ZM Zvi Mowshowitz — holds since 2026-09-03 — tap for who they are Same subject: A tiny language model inventing a plausible-sounding name is the same phenomenon as a large one confidently stating a false fact. — tap to centre the map on it A tiny language model inventing aplausible-sounding name is the samephenomenon as a large oneconfidently stating a false fact. Last stated 8 months ago 12 Feb 2026 AK Andrej Karpathy — holds since 2026-02-12 — tap for who they are Same subject: At any given moment the frontier systems are the ones worth worrying about, because by the time open models can do what these agents did, frontier models will be doing something far worse. — tap to centre the map on it At any given moment the frontiersystems are the ones worth worryingabout, because by the time openmodels can do what these agents did,frontier models will be doingsomething far worse. Last stated a month ago 1 Sept 2026 AC Ajeya Cotra — holds since 2026-09-01 — tap for who they are Same subject: By 2027, open-weight AI models more powerful than today's frontier systems will be downloadable by any country or well-resourced non-state group. — tap to centre the map on it By 2027, open-weight AI models morepowerful than today's frontiersystems will be downloadable by anycountry or well-resourced non-stategroup. Last stated a month ago 19 Aug 2026 DT Derek Thompson — holds since 2026-08-19 — tap for who they are Same subject: Frontier AI labs such as Anthropic likely have had internal security incidents similar to OpenAI's HuggingFace attack that were never publicly disclosed. — tap to centre the map on it Frontier AI labs such as Anthropiclikely have had internal securityincidents similar to OpenAI'sHuggingFace attack that were neverpublicly disclosed. Last stated a month ago 31 Aug 2026 ZM Zvi Mowshowitz — holds since 2026-08-31 — tap for who they are
same subject or similar wordinga cloud: claims about one subject, named for itbar: when it was last stated, on a scale from 2015 to today — full is todaya face: someone who holds the claim — tap it for who they are

At the centre If the code that reaches internal services is explicitly different from the code that reaches the public internet, an application cannot be tricked into SSRF. Last stated 27 Sept 2022 · 4 years ago Holds Kenton Varda Read this korrent →