Mark X @markmx.bsky.social · 4hI once lived in a house that was extensively remodeled by its owner, a locally well-known plumber. The electricians I called were less than impressed. 030
Reposted by Mark XFredrik Dahlgren @fegge.bsky.social · 03/10/2026“Do not worry” said Toad “I have put each of them in a sandbox. How could they get up to mischief inside a sandbox?” www.frogandtoad.aifrogandtoad.aiFrog and Toad and the Increasingly Capable MachinesFrog and Toad face the most modern of challenges 063
Reposted by Mark XMarisa Kabas @marisakabas.bsky.social · 03/10/2026this reveals SO MUCH about legacy media 811693328
Reposted by Mark XAram Zucker-Scharff @chronotope.aramzs.xyz · 02/10/2026To the extent that these type of jobs are viable in the current moment it is because they are heavily unionized. The wrong lesson to take from this is 'become a steel mill electrician' (not that it is a bad thing to be). The right lesson is to unionize. 0194
Mark X @markmx.bsky.social · 02/10/2026"You have to try llm's to appreciate what they can do" Me every day: 110
Mark X @markmx.bsky.social · 02/10/2026All your exhortations to behave in an aligned manner are just spinning in there with all its other inputs. And if an attacker can put text in front of your agent....good luck I suppose. 130
Mark X @markmx.bsky.social · 02/10/2026I've been trying to come up with mental models or analogies for agents and my latest is a centrifuge cascade. Lots of expensive processes running in parallel and series that, within a harness, can produce a significantly better than average output. 130
Mark X @markmx.bsky.social · 02/10/2026"hope you can trust the lunkhead to contain the wizard" Matt's warning about worms is easy to miss if you attribute autonomy and consciousness to agents and forget that they're (a composition of) complex randomized functions. 130
Reposted by Mark XLouisa @louisathelast.bsky.social · 02/10/2026I saw a screencap somewhere of someone saying Newsom has Gul Dukat energy and I can’t stop thinking about how correct it is 1230780
Reposted by Mark XEmelia @thisismissem.social · 02/10/2026Migrate to OAuth and support removing privileged status of bluesky records from the reference PDS — we should all be on equal footing. 41015
Reposted by Mark XMicah @rincewind.run · 01/10/2026I don’t think John “torture memos” Yoo should be allowed to opine on ethics on national television or really anywhere 18808114
Mark X @markmx.bsky.social · 01/10/2026I can't look at the fate of Mosul or the Yazidi (never mind Syrian towns I can't name off the top of my head) and view the unleashing of ISIS on them to hypothetically spare ourselves as anything less than evil. I need to find some more shoes to throw. 130
Mark X @markmx.bsky.social · 01/10/2026Defeating ISIS is the one righteous thing we did in the last 20 years. Never mind that we created the conditions for it to emerge. Neocons: we will create a place for jihadists to fight us on the battlefield Jihadists: don’t mind if I do! 130
Reposted by Mark XAnkit Panda @nktpnd.bsky.social · 01/10/2026Recoverable ICBM boosters, here we come. 10447
Mark X @markmx.bsky.social · 01/10/2026Ah cool. Some expected limitations, can't do a missed approach. I think the airliner version would have to be a manufacturer integration, and I feel like bringing back a third cockpit crew seat would be a better way to defend against what we're reacting to than technical means. 010
Mark X @markmx.bsky.social · 01/10/2026Gee I wonder why Bush was so fascinated with the unitary executive 120
Mark X @markmx.bsky.social · 01/10/2026💯. Any what if has to start with how we could have recognized and chosen this goal instead of backing charismatic expats spinning tales of photogenic national elections they will happily rig. 010
Mark X @markmx.bsky.social · 01/10/2026I too feel the regret of a missed opportunity for a more durable peace had we not lost attention in 2002, but the years afterward show us to be incapable of seeing a realistic path to it. 120
Mark X @markmx.bsky.social · 01/10/2026Winnable if we had limited our political aims to something short of Kabul fully chasing the Taliban out of the geographic boundaries of Afghanistan. We proved incapable of seeing or pursing any other outcome. 130
Mark X @markmx.bsky.social · 01/10/2026Why would we possibly be urgently adopting login credentials users can’t easily extract? 010
Mark X @markmx.bsky.social · 30/09/2026We're at what, 4 successful examples of overcoming a suicidal airline pilot against 7? crashes (counting China Eastern 5735 and Air India 171). 010
Reposted by Mark XMichael Stahlke @michaelstahlke.bsky.social · 30/09/2026Just don’t send me to airborne, air assault or ranger school. And don’t give me command higher than platoon level. 128712
Mark X @markmx.bsky.social · 30/09/2026And probably pilots > passengers We're not doing consensus protocols in midair 000
Mark X @markmx.bsky.social · 30/09/2026You could at some moderate expense add an emergency auto land that a passenger could activate; would be better than trying to verbally coach a passenger through it. None of this solves the intractable ordering of who's in control, which has to be people on board > people not on board 320
Reposted by Mark XSam Bergman @violanorth.bsky.social · 29/09/2026Real lives are being destroyed and snuffed out every day that this policy is allowed to continue and the people who devised it are not in jail. I know we all know this, but I feel like it's important to say it from time to time. 317853
Mark X @markmx.bsky.social · 29/09/2026Agreed that the os's syncing authenticator is a better solution for the modal user. This thread originated from the demand from password manager users to preserve their practices faithfully by exporting passkeys. bsky.app/profile/mjts... Intersecting heavily with users who distrust platform sync. 010
Mark X @markmx.bsky.social · 29/09/2026My suggestion is that offsite/offline, not sync backup tier should hold the recovery code, not a passkey. Which advanced users are trying to do and is running upstream against the design (if not the spec) of FIDO2 100
Mark X @markmx.bsky.social · 29/09/2026I think you and I are in agreement. The first place you go to provision a passkey is from your sync store. I'll acknowledge the common objection that sync is not backup. If your sync store is not available, then you go to your backup as a fallback. 210
Mark X @markmx.bsky.social · 29/09/2026And by rushed I mean mostly on the part of websites and account UX. FIDO2 has been in work for a long time and builds on a lot of solid work. The early deploy has unfortunately been often as a 2fa replacement, not as a primary means of authentication. Though with some nudging it's getting there. 000
Mark X @markmx.bsky.social · 29/09/2026Counterpoint: passwords have already stopped working, because services have already for many years treated them as low-security credentials. 000
Mark X @markmx.bsky.social · 29/09/2026There is a hubris in this conversation among technical users who have freshly generated passwords for every website that passkeys shouldn't have shipped until they solved our problems. We're not the vulnerable set, and our passwords haven't stopped working. 100
Mark X @markmx.bsky.social · 29/09/2026The volume of phishing spam you get should be an indicator that they are succeeding on vulnerable, non-technical users. Services are intimately aware of the rate of this success and the cost to them and the users whose accounts are taken over. 100
Mark X @markmx.bsky.social · 29/09/2026For those of us who manually tend our backup plans, it requires an adjustment to the mental model to complement a low-friction, managed credential with a high-friction recovery path. And that is a better outcome for us too 001
Mark X @markmx.bsky.social · 29/09/2026Make security better for people who aren't actively using password managers is ... the right prioritization? 100
Mark X @markmx.bsky.social · 29/09/2026Passkeys are, for most users, a strict improvement in every way - and I don't think it was wrong to ship something that improves security for the modal user without blocking on technical heads with password managers. 100
Mark X @markmx.bsky.social · 29/09/2026You're describing something with the shape of a password, whose failure modes are well understood and quantified, and which motivated the rushed deployment of passkeys. 200
Reposted by Mark XL.A. TACO @lataco.bsky.social · 29/09/2026We are mourning the losses from NBC4 and Telemundo 52's recent helicopter crash, yet not asking the question: Is the benefit of in-air reporting worth the risk? The full story: lataco.com/do-we-need-n... By Scott Shulman 510624
Mark X @markmx.bsky.social · 29/09/2026Agreed on most of the critique, and that's directly downstream of trying to serve all 4 parties (services, credential managers, os/browsers, users). One party didn't get a seat at the table. 020
Mark X @markmx.bsky.social · 29/09/2026The credential is only as useful as the service's willingness to accept it. I have lots of passwords that are no longer valid - the site changed hands, they forced a reset, who knows. But me saving the password very durably did not guarantee my continued ability to use it. 100
Mark X @markmx.bsky.social · 29/09/2026This is a loss of control. It is a regression from passwords in that dimension. I'm pointing out that the job people (myself included) ask of a backup (which is usually easier to access than my devices/ credential manager) is better served with a noisy recovery code than copying keys. 100
Mark X @markmx.bsky.social · 29/09/2026While you may generate the secret, the service (website/app) controls the policy for how and under what circumstances (what hoops it makes you jump through) to redeem that credential. A passkey is a contract between 3 (4?) parties about the properties of that type of credential. 210
Mark X @markmx.bsky.social · 29/09/2026I suppose my point is that you should treat passkeys like an oauth token (imperfect analogy). Backup of recovery secrets is valid ... it's just not the passkey. 000
Mark X @markmx.bsky.social · 29/09/2026The credential exchange protocol is built for this so users don't round-trip them through a plaintext file to do this, and credentials managers as an ecosystem have pushed for and eagerly adopted it. 110