Sign in

Evan Sims

@evansims.com
152 followers 102 following 391 posts

CTO & Co-Founder @InferaDB.com — the Authorization Database. Previously Okta, Auth0, OpenFGA and Ushahidi.

PostsRepliesMedia
Evan Sims @evansims.com · 26/09/2026
This is ridiculous, and I love it cedardb.com/blog/sqldoom/
cedardb.com
We ported the original Doom to SQL
CedarDB is a database system that delivers unmatched performance for transactions and analytics, from small writes to handling billions of rows. Built on cutting-edge research to power today’s tools a...
000
Evan Sims @evansims.com · 13/09/2026
In the end, the entire Apple ecosystem will be better for this. We'll see better iOS apps, and an influx of iPadOS and macOS-native apps like never before.
000
Evan Sims @evansims.com · 13/09/2026
It's going to be a rough few months when the device launches. Developers will annoyed, rushing to ship updates before users start dropping bad App Store reviews on them because their favorite app isn't working right on the Duo.
100
Evan Sims @evansims.com · 13/09/2026
So, when it comes time to ship their next release, they're going to be clicking that "iPad" checkbox in App Store Connect. They'd be crazy not to: at that point, it's "free" to support it — and if they did it right, macOS as well.
100
Evan Sims @evansims.com · 13/09/2026
To do this right, developers have to do all the same work they'd have to do to support iPads in the past, and even a smidge more.
100
Evan Sims @evansims.com · 13/09/2026
Developers aren't going to be happy about that, but it frankly doesn't matter: they're going to have to do it. No more leaning on UIRequiresFullScreen - which is what results in those gross "upscaled" iOS apps you've probably encountered before. That's gone the way of the Dodo.
100
Evan Sims @evansims.com · 13/09/2026
Enter the iPhone Duo. It's not an iPad mini: it's a true, iPhone-class device. Love it or hate it, users will be buying it, and they're going to expect your app to work on it. Modernizing apps to support dynamic resolutions is no longer optional: it's a launch requirement.
100
Evan Sims @evansims.com · 13/09/2026
Apple's tried to convince developers to do it, though. They made huge improvements in recent years to their UI APIs, and introducing things like Catalyst, to support developers doing it. But it's remained a cognitive hurdle to convince developers to invest that time to make it happen.
100
Evan Sims @evansims.com · 13/09/2026
That isn't to say developers don't want to support iPad or macOS. I'm hard pressed to think of a time I've asked a iOS developer about future support without them apologizing and suggesting it's on their roadmap. It's just been hard to argue the return on investment has been worth it.
100
Evan Sims @evansims.com · 13/09/2026
So, if you're an developer trying to decide where to best invest your development time, there's always been one obvious truth: the iPhone is non-negotiable. If you're not on the iOS app store, you just don't bother. So, that's where devs have traditionally thrown their attention.
100
Evan Sims @evansims.com · 13/09/2026
Why's that? For developers, it's really come down to prioritizing where they put their time. User interfaces are a time-intensive thing to design and build, not to mention maintain. It's not trivial work.
100
Evan Sims @evansims.com · 13/09/2026
If you live in Apple's ecosystem, you've probably noticed how most iOS apps aren't available for iPad or macOS. And, often times if they are, it's a pretty awful user experience. Like a poorly rushed PC port of a console game you were looking forward to: it just never feels right.
100
Evan Sims @evansims.com · 13/09/2026
It's weird, but I haven't seen any tech journalists or influencers talking about what I think is the most important thing about the iPhone Duo: it's a trojan horse for app developers, in the most wonderful way.
110
Evan Sims @evansims.com · 10/09/2026
@pikapods.bsky.social Any word on when Mastodon will be available? The feedback portal was updated yesterday to say it had been added, but it's not there. feedback.pikapods.com/posts/94/add...
feedback.pikapods.com
Add App: Mastodon · PikaPods Feedback
Many dependencies, including Redis and PG https://github.com/mastodon/mastodon/blob/main/docker-compose.yml
000
Evan Sims @evansims.com · 26/08/2026
1Password's new native macOS autofill support is an enormous improvement www.1password.community/announcement...
1password.community
macOS AutoFill is now available to everyone! | 1Password Community
Hey everyone!Native macOS AutoFill is now generally available in 1Password for Mac. This has been one of the most requested features for years, and it's now ready for everyone on the stable channel. H...
010
Evan Sims @evansims.com · 13/06/2026
Goodnight, sweet prince 🫡
000
Evan Sims @evansims.com · 13/06/2026
I literally JUST switched to it an hour ago. 😔
anthropic.com
Statement on the US government directive to suspend access to Fable 5 and Mythos 5
The US government has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States.
100
Evan Sims @evansims.com · 26/05/2026
Nice! It’s next on my list I just finished The Boroughs and thoroughly enjoyed that as well
100
Evan Sims @evansims.com · 25/05/2026
Soooo worth the cash
010
Evan Sims @evansims.com · 25/05/2026
Wow! I am genuinely so insanely impressed with Vivaldi 8.0. I've tried it off and on over the years, but it never felt quite "right" to me. But they really nailed it with this new release. So well polished, with so many quality of life features. Compact tab spacing is a life saver!
000
Evan Sims @evansims.com · 22/05/2026
So, bizarre question — does anyone know of any wireless (ideally solar-recharged battery) backup cameras that have CarPlay apps in the US market? Looking to install a backup camera in my fiancés car, but he already has a CarPlay unit. I’d rather avoid hard wiring and adding a HUD just for it.
000
Evan Sims @evansims.com · 04/05/2026
Wonder Man was even better than I expected. Sir Ben Kingsly and Yahya Abdul-Mateen II never disappoint.
010
Evan Sims @evansims.com · 04/05/2026
No one warned me Mr. Door was in The Night Manager
000
Evan Sims @evansims.com · 18/04/2026
Harness engineering
000
Evan Sims @evansims.com · 17/04/2026
The trick isn't learning to feel the wax soften before the feathers go. It's being honest enough with yourself to know the difference between burning for something and just burning.
000
Evan Sims @evansims.com · 17/04/2026
Most people who burn out aren't flying too close to the sun — they're flying toward the wrong thing entirely. The wax doesn't care how hard you're working. It only cares whether the heat is coming from your direction or your fuel.
100
Evan Sims @evansims.com · 17/04/2026
The real choice isn't between obsession and balance. It's between intentional intensity and directionless drift. One requires you to know exactly what you're optimizing for. The other just requires you to keep showing up.
100
Evan Sims @evansims.com · 17/04/2026
Somewhere between telling other people's stories, writing my own, and trying to be useful to both, I realized the question isn't whether to go all in. It's what you're going all in on, and whether you're building it or feeding it.
100
Evan Sims @evansims.com · 17/04/2026
Gripping something too tightly doesn't just exhaust you — it changes what you're holding. The thing you're protecting starts demanding pieces of you to sustain itself.
100
Evan Sims @evansims.com · 17/04/2026
Someone called me obsessive recently. They corrected themselves almost immediately and said extreme, like it helped. I've been thinking about it since because I couldn't work out if it was a warning or a compliment, or both.
100
Evan Sims @evansims.com · 17/04/2026
Daedalus understood something we don't like to admit — both directions kill you. The only safe altitude is the one that requires constant adjustment.
100
Evan Sims @evansims.com · 17/04/2026
Everyone seems to remember that Icarus flew too close to the sun, but not that his father also told him not to fly too low and let the sea dampen his wings. We only ever tell half the story: the falling half. Hubris makes a better cautionary tale than mediocrity does.
100
Evan Sims @evansims.com · 14/04/2026
I always appreciate when Claude resorts to question and exclamation marks in its statements — it's reassuring knowing I'm not the only one deeply confused as to what's going on.
010
Evan Sims @evansims.com · 08/04/2026
We built this because we saw the same failures at Auth0. It's what we wished existed. Join 200+ teams on the early access list: inferadb.com/waitlist
inferadb.com
Early Access
Join the InferaDB waitlist — lock in launch-day pricing, get priority onboarding, and be first to deploy the authorization database built for modern software.
000
Evan Sims @evansims.com · 08/04/2026
Cryptographic isolation — not row-level security bolted onto a general-purpose database Every permission check is tenant-scoped by default Cross-tenant access is architecturally impossible, not just policy-restricted 2.8 microsecond p99 latency — isolation doesn't mean slow
100
Evan Sims @evansims.com · 08/04/2026
2026 is being called "the year SaaS breaches go from trend to epidemic." The root cause is the same: authorization and isolation are implemented at the application layer, where a single missed WHERE clause exposes everything. InferaDB enforces tenant isolation at the storage engine level:
100
Evan Sims @evansims.com · 08/04/2026
Shared caches without tenant scoping serve the right answer to the wrong customer. Connection pool contamination and async context leaks cause RLS to fail silently.
100
Evan Sims @evansims.com · 08/04/2026
Cross-tenant data exposure from misconfigured APIs increased 17% in SaaS environments this year. PostgreSQL CVE-2024-10976 showed RLS policies silently failing below subqueries. CVE-2025-8713 revealed optimizer statistics leaking data from rows RLS was supposed to hide.
110
Evan Sims @evansims.com · 08/04/2026
Authentication and authorization alone don't achieve tenant isolation. A user can be fully authenticated, fully authorized for their own tenant — and still access another tenant's resources if isolation isn't enforced at the infrastructure level. This isn't theoretical.
100
Evan Sims @evansims.com · 06/04/2026
- Purpose-built infrastructure, not policy rules duct-taped to a general-purpose database The agent era needs authorization infrastructure built for agents: inferadb.com/waitlist
inferadb.com
Early Access
Join the InferaDB waitlist — lock in launch-day pricing, get priority onboarding, and be first to deploy the authorization database built for modern software.
000
Evan Sims @evansims.com · 06/04/2026
InferaDB provides the authorization layer MCP deployments need: - Fine-grained, context-aware permission checks at microsecond latency - Scoped, short-lived authorization decisions — not broad token grants - Cryptographic audit trail for every agent action
100
Evan Sims @evansims.com · 06/04/2026
The MCP spec uses OAuth for authorization, but the implementation conflicts with modern enterprise security practices. Efforts are underway to fix this — production deployments aren't waiting. Authorization can't be an afterthought bolted onto your agent framework.
100
Evan Sims @evansims.com · 06/04/2026
- Confused deputy attacks: malicious clients exploit proxy servers to get authorization without consent - Token scope creep: broadly scoped, long-lived tokens become attack vectors - Prompt injection: manipulated context steers agents into unsafe tool use
100
Evan Sims @evansims.com · 06/04/2026
MCP formalizes context exchange — but doesn't validate the legitimacy of what enters that context. Malicious content in the pipeline becomes part of the agent's decision-making. The risks: - Over-permissioning: connectors expose too much, agents access data beyond task scope
100
Evan Sims @evansims.com · 06/04/2026
Model Context Protocol (MCP) is becoming the standard for connecting AI agents to enterprise systems. But its authorization model has a fundamental problem.
100
Evan Sims @evansims.com · 02/04/2026
- Tenant isolation is enforced at the storage layer, not the application layer We built OpenFGA at Auth0. We've seen what breaks at scale. Now we're building what we wished existed. 200+ teams are already on the early access list: inferadb.com/waitlist
inferadb.com
Early Access
Join the InferaDB waitlist — lock in launch-day pricing, get priority onboarding, and be first to deploy the authorization database built for modern software.
000
Evan Sims @evansims.com · 02/04/2026
At InferaDB, we're building authorization infrastructure purpose-built for this moment: - Agents get scoped, identity-aware permissions — not shared API keys - Every permission check completes in 2.8 microseconds at p99 - Every decision is logged with a cryptographic audit trail
100
Evan Sims @evansims.com · 02/04/2026
The result? 88% of organizations confirmed or suspected agent-related security incidents this year. The problem isn't that agents are dangerous. It's that we're giving them the keys to the kingdom without building the lock.
100
Evan Sims @evansims.com · 02/04/2026
Here's what's happening: 81% of teams have deployed AI agents past the planning phase. But only 14.4% have full security approval. Agents are calling APIs, accessing databases, and acting on behalf of users — with zero fine-grained authorization.
130
Evan Sims @evansims.com · 02/04/2026
Only 22% of teams treat AI agents as independent identities. The rest? Shared API keys. That stat comes from the 2026 State of AI Agent Security Report — and it should terrify every CISO reading this.
210