Sign in

Adrian Mouat

@adrianmouat.com
1K followers 543 following 744 posts

Technical community advocate at Chainguard. Bad guitarist. He/him.

PostsRepliesMedia
Reposted by Adrian Mouat
Gergely Orosz @gergely.pragmaticengineer.com · 17h
The last time building software sped up ~10x (early 2000s, the agile movement), a massive interest in automated testing followed almost immediately (unit tests, TDD, XP etc) Today, building software sped up 10x, easily: and a similar massive interest in automated testing + verification is following
11927
Reposted by Adrian Mouat
Baldur Bjarnason @baldurbjarnason.com · 18h
“In response to “The death of web development education” ” bell.bz/in-response-to-the-death-of… > The most effective way I can contribute, in my opinion, is a crude sketch I just did of Piccalilli‘s Stripe chart for all time sales: That graph is eye-opening
bell.bz
In response to “The death of web development education”
I read Mat​hia⁠s S​chäf⁠er’s excellent post, titled The death of web development education. I was thinking about how I can contribute to the conversation and really struggled to articulate the problem...
14512
Reposted by Adrian Mouat
Bryan Cantrill @bcantrill.bsky.social · 28/09/2026
Fool's Expertise bcantrill.dtrace.org/2026/09/27/f...
bcantrill.dtrace.org
Fool's Expertise | The Observation Deck
59120
Adrian Mouat @adrianmouat.com · 26/09/2026
Oh wow. This show was a lot of fun. I was completely useless both times. I did have quite a nice hack once tho
010
Reposted by Adrian Mouat
David Flanagan @rawkode.dev · 25/09/2026
Klustered … returns! Apply now!
rawkode.academy
Klustered Winter 2026 starts 30 October
Klustered returns on Friday, 30 October 2026. Contestants race the clock to diagnose and fix deliberately broken Kubernetes clusters.
044
Adrian Mouat @adrianmouat.com · 23/09/2026
Lol, 3 of my favourite companies right there. And they are all complementary.
011
Adrian Mouat @adrianmouat.com · 20/09/2026
"Unlimited tolerance must lead to the disappearance of tolerance. If we extend unlimited tolerance even to those who are intolerant, if we are not prepared to defend a tolerant society against the onslaught of the intolerant, then the tolerant will be destroyed, and tolerance with them." Popper
032
Adrian Mouat @adrianmouat.com · 18/09/2026
That's pretty similar really. Except the foreign language :)
010
Adrian Mouat @adrianmouat.com · 17/09/2026
I think I just can't deal with real life any more 😂
110
Adrian Mouat @adrianmouat.com · 17/09/2026
Has anyone had a similar experience? I actually stopped reading books completely for a while until I realised sci-fi and fantasy were fine (both enjoyable and helped me).
200
Adrian Mouat @adrianmouat.com · 17/09/2026
I guess this is just the need for escapism, but it's amazingly strong. Like, I might manage to force myself to read a few pages of a novel, but then I have to give up. It's almost painful.
100
Adrian Mouat @adrianmouat.com · 17/09/2026
For years now, I've been unable to read straight fiction. I used to read lots of books and "literature", especially stuff from all time lists etc. Now I almost exclusively read sci-fi and fantasy, with the odd bit of non-fiction thrown in (but not bios).
100
Adrian Mouat @adrianmouat.com · 17/09/2026
Yes! I maybe should have linked your article directly rather than the first one. It's hard to reason out where all this ends...
110
Adrian Mouat @adrianmouat.com · 17/09/2026
The way to make a quick million is now to influence llms so that models integrate your product by default.
110
Adrian Mouat @adrianmouat.com · 17/09/2026
For your moment youtu.be/2Ng9Pf_p7Fw?...
youtu.be
The Orb - Little Fluffy Clouds (Official Music Video)
YouTube video by Not and Now Available on Youtube!
010
Reposted by Adrian Mouat
Aaron Ross Powell @aaronrosspowell.com · 16/09/2026
I've been on an AT Protocol podcast binge and I know tons of people hate it here and hate the devs and think the focus should be building something that's just like Twitter but tuned to the hater's particular tastes, but, man, what's getting built has me optimistic about the future of the internet.
512512
Adrian Mouat @adrianmouat.com · 14/09/2026
And my suggestion is to unplug the ai, not the power station/banking system/healthcare.
000
Adrian Mouat @adrianmouat.com · 14/09/2026
I meant proof not evidence fwiw.
100
Adrian Mouat @adrianmouat.com · 14/09/2026
I was mainly joking. I will of course change the WiFi password as well.
000
Adrian Mouat @adrianmouat.com · 14/09/2026
Ok. That's part of the point though - we should be being a bit more careful with the hyperbole.
100
Adrian Mouat @adrianmouat.com · 14/09/2026
I've thought about this more and I must be misunderstanding -- do you really mean "there's a 10% chance AI could kill all humans" isn't an extraordinary claim?
100
Adrian Mouat @adrianmouat.com · 14/09/2026
You're right, I need to deal with the battery.
100
Adrian Mouat @adrianmouat.com · 14/09/2026
And how does any of that lead to the extermination of the human race?
000
Adrian Mouat @adrianmouat.com · 14/09/2026
Why? What proof do you have for that? Why would we let it? And just to be clear: your worry is AI going "rogue", not who is using the AI?
200
Adrian Mouat @adrianmouat.com · 14/09/2026
Remember, if it takes over your roomba, you can just unplug it.
daleks are foiled by a set of stairs
230
Adrian Mouat @adrianmouat.com · 14/09/2026
This is an important read for anyone alarmed by the AI extinction predictions. To sum it up; extraordinary claims require extraordinary evidence, and that just doesn't exist at the minute.
263
Reposted by Adrian Mouat
Bryan Cantrill @bcantrill.bsky.social · 13/09/2026
The contagion of fear bcantrill.dtrace.org/2026/09/13/t...
bcantrill.dtrace.org
The contagion of fear | The Observation Deck
1624083
Reposted by Adrian Mouat
Sarah Andersen @sarahseeandersen.bsky.social · 12/09/2026
The image is of a four panel comic.
The title for the first two panels is "Young Me".
In panel one we see a young version of Sarah, the protagonist. She says, "I want to achieve great things".
In panel two we zoom in a little on young Sarah's face. She continues, "An astounding career! An amazing house! World peace!"
The title for the last two panels is "Adult Me".
In panel three we see adult Sarah, looking down.
In panel four we zoom out and see she is in front of a basil plant. She simply says "I want to grow a basil plant".
102117701917
Adrian Mouat @adrianmouat.com · 11/09/2026
There's a lot of room left in the world for humans to do thinking.
010
Adrian Mouat @adrianmouat.com · 11/09/2026
AI is an efficient way of doing things you should never have done at all. In a way that's great -- you can quickly figure out a thousand ways that don't work. But it's also easy to spend a fortune and waste your own time going down hopeless paths that would have been avoided by applying some thought
100
Adrian Mouat @adrianmouat.com · 11/09/2026
When using AI I keep coming back to this Peter Drucker quote: "There is surely nothing quite so useless as doing with great efficiency what should not be done at all"
101
Reposted by Adrian Mouat
Gergely Orosz @gergely.pragmaticengineer.com · 11/09/2026
A couple of trends I'm seeing across the industry. Which ones are you observing that I missed?
2120017
Adrian Mouat @adrianmouat.com · 10/09/2026
I was pretty astonished by this one, you'd have thought they would think twice after 1password. Actually don't know what to say. DHH is entirely open about his politics, it's not like people can plead ignorance.
080
Reposted by Adrian Mouat
puerco @puerco.mx · 10/09/2026
I had a lot of fun building some cool, futuristic stuff with Marina to achieve builds with attested hermeticity.
152
Adrian Mouat @adrianmouat.com · 08/09/2026
Basically, the issue is that any CVEs announced now may have zero days (-ve TTE), but can't actually have +ve TTE as the future hasn't happened yet. So it will always trend to the bottom.
000
Adrian Mouat @adrianmouat.com · 08/09/2026
I've used this graph in slides recently, and only just realised how misleading it is. Apologies to anyone I have in turn misled. zerodayclock.com have now changed their graphs.
100
Adrian Mouat @adrianmouat.com · 08/09/2026
Yeah, this makes sense. For the current year it's nearly always going to be negative because of the zero days, but it will rise over time as known vulnerabilities are exploited. I feel bad for using this graph now.
000
Adrian Mouat @adrianmouat.com · 08/09/2026

Why do you not publish a time to exploitation metric?
Because it fails in three separate ways, and each of them flattens the line for reasons that have nothing whatever to do with attacker behaviour.

First, and most importantly, it ignores aging. The metric compares years that have had wildly different amounts of time in which to accumulate evidence. A vulnerability published six years ago has had six years in which somebody might notice it being exploited, whereas one published last quarter has had a few weeks. Recent years therefore look artificially fast and older years look artificially slow, and a large part of any trend you draw through them is simply the passage of time rather than a change in the world.

Second, it saturates. Time to exploitation is floored at zero. Once a large share of exploitation is landing on the day of publication, the metric has nowhere left to go and cannot represent any further acceleration. A vulnerability exploited quietly for months before anybody knew it existed and one exploited on the morning of disclosure both record the same value, which is to say the metric stops being able to tell apart the two situations that matter most.

Third, the next real change would move both ends at once, and an average cannot show that. As the cost of finding and weaponising a vulnerability falls, we would expect to see more exploitation arriving at or before disclosure, and at the same time more exploitation of the long tail of older vulnerabilities that was previously protected by nothing more than attacker labour cost. That tail is already where a great deal of the damage sits. Mass moving toward zero and a tail growing fatter offset one another inside a mean, so the number could sit perfectly still while both halves of the distribution moved.

We are not claiming that this shift has already happened. We are saying that a time to exploitation metric could not tell you whether it had, and that on its own is reason enough to stop using it.
100
Adrian Mouat @adrianmouat.com · 08/09/2026
Ah, it's on the About page: zerodayclock.com/about#faq
000
Adrian Mouat @adrianmouat.com · 08/09/2026
Anyone know why zerodayclock.com got rid of the time to exploitation graphs?
zerodayclock.com
Zero Day Clock
A public scoreboard for vulnerability management and exploitation.
200
Adrian Mouat @adrianmouat.com · 04/09/2026
Users are at put at risk and have nothing they can do about it. This may force projects to start publishing releases *before* the associated source code. But that breaks the fundamentals of Open Source. And how could the code be shared with rebuilders like Linux Distros (and @chainguard.dev)?
000
Adrian Mouat @adrianmouat.com · 04/09/2026
LLMs saw the update and immediately went to work creating and verifying the exploit based on the code in the PR. This places Open Source in a horrible position. Opening a PR to fix an issue means attackers can create and start using exploits before a fixed release is available.
100
Adrian Mouat @adrianmouat.com · 04/09/2026
This week I read a blog post by @anil.recoil.org . In it he describes creating a PR for an OCaml library to fix a security issue -- minutes later his own webserver is being probed for the vulnerability.
100
Reposted by Adrian Mouat
Elle Cordova @ellecordova.bsky.social · 03/09/2026
Rough Draft vs Final Draft
253116683307
Adrian Mouat @adrianmouat.com · 03/09/2026
If you're at @containerdays.bsky.social and interested in surviving the 🌋vulnpocalypse🌋 that is now upon us, come to my talk at 9.30 in Room 4. Which is handily near the @chainguard.dev booth.
000
Adrian Mouat @adrianmouat.com · 02/09/2026
I'm going to refer to this in a talk tomorrow. This puts open source in a horrible position.
010
Adrian Mouat @adrianmouat.com · 02/09/2026
This is completely insane. The existence of a patch for a project means attackers can build an exploit in minutes. So attackers are actively exploiting vulnerabilities before you have any chance of apply the patch or mitigations.
010
Reposted by Adrian Mouat
Matteo Bianchi @mbianchi.dev · 28/08/2026
I shouldn't, especially on a Friday but... Starting in September I'll have more time for freelance work, if you know folks in need of Kubernetes/Cloud/Platform Engineering knowledge, send them my way 🫡
002
Adrian Mouat @adrianmouat.com · 28/08/2026
This was particularly clear in the write-up from the OpenAI and Hugging Face incident, where agents "went rogue" to solve their given task (or even the tasks of other agents if they didn't make headway on their own!).
000
Adrian Mouat @adrianmouat.com · 28/08/2026
AI Agents often fail the "Jurrasic Park" test: they become obsessed with what they can do and forget to think about if they "should". To everyone using AI right now -- please keep at least half an eye on *how* your agents are completing tasks. (Credit to @chainguard.dev CTO Matt Moore for this!)
110