korrents

On the map

Tap a claim on the ring to put it at the centre.

← The xz backdoor falls short of a Ken Thompson-style 'trusting trust' compromise, but comes a step closer to one.

12 connected korrents · 11 moments from 26 Jul 2017 to 17 Sept 2026.

Everything filed under cybersecurity cybersecurity Everything filed under open source open source Everything filed under design design Same subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subject Read this korrent: The xz backdoor falls short of a Ken Thompson-style 'trusting trust' compromise, but comes a step closer to one. The xz backdoor falls short of a KenThompson-style 'trusting trust'compromise, but comes a step closer toone. Last stated 2 years ago 2 Apr 2024 RC Russ Cox — holds since 2024-04-02 — tap for who they are Same subject: The xz backdoor marks a watershed moment in open source supply chain security. — tap to centre the map on it The xz backdoor marks a watershedmoment in open source supply chainsecurity. Last stated 2 years ago 2 Apr 2024 RC Russ Cox — holds since 2024-04-02 — tap for who they are Same subject: People who do not yet trust each other are better served by tightly limited ways to interact. — tap to centre the map on it People who do not yet trust eachother are better served by tightlylimited ways to interact. Last stated 4 years ago 1 Jan 2023 DC Daniel Cook — holds since 2023-01-01 — tap for who they are Same subject: Much of the received wisdom about passwords has been reversed, yet organisations still apply yesterday’s patterns to today’s threats. — tap to centre the map on it Much of the received wisdom aboutpasswords has been reversed, yetorganisations still applyyesterday’s patterns to today’sthreats. Last stated 9 years ago 26 Jul 2017 TH Troy Hunt — holds since 2017-07-26 — tap for who they are Same subject: A malicious or broken package is typically caught and pulled or patched within about a week of being published. — tap to centre the map on it A malicious or broken package istypically caught and pulled orpatched within about a week of beingpublished. Last stated 8 months ago 18 Jan 2026 IS Ivan Santos — holds since 2026-01-18 — tap for who they are Same subject: A years-old unfixed default in GitHub Actions is the root cause of a wave of software supply-chain attacks. — tap to centre the map on it A years-old unfixed default inGitHub Actions is the root cause ofa wave of software supply-chainattacks. Last stated 4 months ago 22 May 2026 TC Tyler Cipriani — holds since 2026-05-22 — tap for who they are Same subject: Any software that depends on open source has a network of humans with package publishing rights who are potential attack vectors. — tap to centre the map on it Any software that depends on opensource has a network of humans withpackage publishing rights who arepotential attack vectors. Last stated 2 weeks ago 17 Sept 2026 SW Simon Willison — holds since 2026-09-17 — tap for who they are Same subject: By 2027, open-weight AI models more powerful than today's frontier systems will be downloadable by any country or well-resourced non-state group. — tap to centre the map on it By 2027, open-weight AI models morepowerful than today's frontiersystems will be downloadable by anycountry or well-resourced non-stategroup. Last stated a month ago 19 Aug 2026 DT Derek Thompson — holds since 2026-08-19 — tap for who they are Same subject: Dependency cooldowns are currently the best defense against supply chain attacks via compromised package publishers. — tap to centre the map on it Dependency cooldowns are currentlythe best defense against supplychain attacks via compromisedpackage publishers. Last stated 2 weeks ago 17 Sept 2026 SW Simon Willison — holds since 2026-09-17 — tap for who they are Same subject: Most security reports an open-source project receives are agent-generated and untested, and the defence is publishing what you guarantee and what lies outside your security boundary. — tap to centre the map on it Most security reports an open-sourceproject receives are agent-generatedand untested, and the defence ispublishing what you guarantee andwhat lies outside your securityboundary. Last stated 2 months ago 10 Aug 2026 PS Peter Steinberger — holds since 2026-08-10 — tap for who they are Same subject: At any given moment the frontier systems are the ones worth worrying about, because by the time open models can do what these agents did, frontier models will be doing something far worse. — tap to centre the map on it At any given moment the frontiersystems are the ones worth worryingabout, because by the time openmodels can do what these agents did,frontier models will be doingsomething far worse. Last stated a month ago 1 Sept 2026 AC Ajeya Cotra — holds since 2026-09-01 — tap for who they are Same subject: Frontier AI labs such as Anthropic likely have had internal security incidents similar to OpenAI's HuggingFace attack that were never publicly disclosed. — tap to centre the map on it Frontier AI labs such as Anthropiclikely have had internal securityincidents similar to OpenAI'sHuggingFace attack that were neverpublicly disclosed. Last stated a month ago 31 Aug 2026 ZM Zvi Mowshowitz — holds since 2026-08-31 — tap for who they are Same subject: OpenAI either could not find their agents' RubyGems attack in their logs after other incidents or knew and chose not to tell RubyGems, and both are bad. — tap to centre the map on it OpenAI either could not find theiragents' RubyGems attack in theirlogs after other incidents or knewand chose not to tell RubyGems, andboth are bad. Last stated 3 weeks ago 12 Sept 2026 SW Simon Willison — holds since 2026-09-12 — tap for who they are
same subject or similar wordinga cloud: claims about one subject, named for itbar: when it was last stated, on a scale from 2015 to today — full is todaya face: someone who holds the claim — tap it for who they are

At the centre The xz backdoor falls short of a Ken Thompson-style 'trusting trust' compromise, but comes a step closer to one. Last stated 2 Apr 2024 · 2 years ago Holds Russ Cox Read this korrent →