Sign in

Tom Thorogood

@tmthrgd.at
153 followers 127 following 9 posts

I'm a mid-tier corporate nobody doing nothing for no one. ADL, AUS // tomthorogood.net

PostsRepliesMedia
Reposted by Tom Thorogood
Ed Zitron @edzitron.com · 22/09/2026
Free newsletter: I estimate that ~50% of AI chip sales - $200bn to $300bn+ - are sitting in warehouses, with NVIDIA selling hundreds of billions of GPUs years in advance. Data centers take way longer to build than hyperscalers are leading us to believe. www.wheresyoured.at/wherere-all-the-ai-chips/
wheresyoured.at
https://www.wheresyoured.at/wherere-all-the-ai-chips/
If you liked this piece, you should subscribe to my premium newsletter, and you can subscribe on the following links: $70 a year, $18 a quarter, or $7 a month. In return you get a weekly premium…
29839214
Reposted by Tom Thorogood
Filippo Valsorda @filippo.abyssdomain.expert · 29/07/2026
I know it’s not most folks‘ primary concern, but LLMs or not, I’m unimpressed by how soft these infrastructure services are. What do you mean HF had a Jinja2 template injection. And I’m still not over GitHub’s unsandboxed RCE. Geomys might need to self-host code/CI to avoid a weak link.
1020119
Reposted by Tom Thorogood
Matthew Green @matthewdgreen.bsky.social · 19/07/2026
I’m not sure I like this new world where we write software for other software to use. What’s even the point of it?
5468
Reposted by Tom Thorogood
Matthew Garrett @mjg59.eicar-test-file.zip · 02/07/2026
I have gone very far into the weeds in investigating every (I think) published mechanism for preventing authentication tokens from being stolen and how basically none of them has actually succeeded in a useful way: www.codon.org.uk/~mjg59/blog/...
codon.org.uk
Preventing token theft
When you log into a service you’re given an authentication token. Each further request to the site includes that token, allowing the server to figure out who you are and ensuring that you have access ...
44116
Reposted by Tom Thorogood
Filippo Valsorda @filippo.abyssdomain.expert · 28/06/2026
Bernstein's main achievements, by decade: 1990s: Bernstein v. United States 2000s: ChaCha20, Poly1305, Curve25519, Ed25519 2010s: SPHINCS 2020s: sabotaging the post-quantum transition This is so f***ing frustrating. And sad. But mostly frustrating.
mailarchive.ietf.org
[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
Search IETF mail list archives
1111316
Reposted by Tom Thorogood
spooky Deirdre Connolly¹ ² at a distance @durumcrustulum.com · 26/06/2026
me: isogenies are beautiful and elegant and allow small sizes also me: vroom vroom lattice go vroom
1172
Reposted by Tom Thorogood
aaron @hillenjoyer.myatproto.social · 24/06/2026
i’m going to make a fake pcpartpicker website where you can shop a whole build using 2019-like prices and you don’t actually pay money or get a computer but at least everyone has a little fun
0113
Reposted by Tom Thorogood
Filippo Valsorda @filippo.abyssdomain.expert · 22/06/2026
There we go. US Gov tightens post-quantum cryptography transition deadlines for high-value systems to 2030 for key exchange and 2031 for signatures. Also, speeding up the CMVP (FIPS 140 validation) processes. That’s how you know the rush is real. The quantum computers are (potentially) coming.
whitehouse.gov
Securing the Nation Against Advanced Cryptographic Attacks
By the authority vested in me as President by the Constitution and the laws of the United States of America, it is hereby ordered: Section 1.  Background
411030
Reposted by Tom Thorogood
hype man for a log flume @youfoundryan.bsky.social · 22/06/2026
i'm a software engineer and once got budget from my director to hire a writing instructor for the department. cost was peanuts to us (like $5k?) but the benefits were enormous. she wound up sending all the managers through it too. massive low hanging fruit for any eng director who wants it
1425
Reposted by Tom Thorogood
Filippo Valsorda @filippo.abyssdomain.expert · 20/06/2026
There would have been responsible ways to write that rule, by the way. For example, by making it turn itself off after a few months if not updated. Palo Alto has no incentive not to harm the Internet or their customers though, because IDS/IPS are usually mandated.
1292
Reposted by Tom Thorogood
Filippo Valsorda @filippo.abyssdomain.expert · 20/06/2026
In 2020, OpenSSL had a vuln related to the signature_algorithms_cert ext. openssl-library.org/news/secadv/... Palo Alto apparently "solved" this in their IPS by blocking connections with "unknown" algs in sigalg_cert. Six years later, we can't add ML-DSA to sigalg_cert in Go. sigalg_cert is dead.
github.com
crypto/tls: TLS 1.3 handshake timeout with tip, Go 1.26 can connect successfully · Issue #79626 · golang/go
What version of Go are you using (go version)? $ go version go version go1.27-devel_bfbbe9667e Fri May 22 15:49:08 2026 -0700 darwin/arm64 Does this issue reproduce with the latest release? No What...
48516
Reposted by Tom Thorogood
Matthew Green @matthewdgreen.bsky.social · 09/06/2026
I wrote a new post about the privacy risks of on-phone agents like Apple’s new Siri, and how private inference isn’t any sort of silver bullet. blog.cryptographyengineering.com/2026/06/09/a...
blog.cryptographyengineering.com
The future of Siri, or: why private inference isn’t private enough
Yesterday Apple announced a big step towards deploying real AI in their Siri ecosystem. In most ways this is good and inevitable: Siri is one of the world’s most widely-used voice agents, and…
1211850
Reposted by Tom Thorogood
Better Things Are Possible @internethippo.bsky.social · 07/05/2026
Modern technology could learn from older stuff that does what it's supposed to and doesn't bother you. My toilet just works and never sends me emails like "Good news! Flush® is now Floosh®"
643200522
Reposted by Tom Thorogood
Filippo Valsorda @filippo.abyssdomain.expert · 30/04/2026
I mean "why is there a special IPSec AEAD in the kernel wired up to splice() and why is that enabled by default in everyone's kernel" complexity.
1192
Reposted by Tom Thorogood
Mitch McConnell's shambling corpse 🧟‍♂️ @checarina.bsky.social · 23/06/2024
super excited for the day AI will be able to take over the most tedious tasks of daily life such as making art, engaging with art, maintaining human relationships, etc., so that I can focus on my true passion: creating value for shareholders
5938276
Reposted by Tom Thorogood
Tom Warren @tomwarren.co.uk · 24/04/2026
yesterday I reported on GitHub employee concerns about reliability and leadership, and then hours later GitHub suffered a catastrophic outage 😬 www.theverge.com/news/918001/...
3582158
Reposted by Tom Thorogood
Olúfẹ́mi O. Táíwò @olufemiotaiwo.bsky.social · 22/04/2026
listen hun if you can't handle the Washington Post editorial board at their the Texas gerrymander "freakout" is "not a threat to democracy" you don't deserve them at their "Virginia plunges America deeper into the gerrymandering abyss"
screenshot of WashPo editorial board August 20 2025 "The Texas Gerrymander freakout
What's happening in the Lone Star State is not a threat to democracy" screenshot of April 21 Wash PO editorial board: "Virginia plunges America deeper into the gerrymandering abyss
The redistricting scheme was always a power grab by Democrats. Voters went along with it."
623750785
Reposted by Tom Thorogood
Crowsa Luxemburg @quendergeer.bsky.social · 19/04/2026
Palantir are about six months away from ordering their employees to leave audio logs scattered around their offices
8892422095
Reposted by Tom Thorogood
Filippo Valsorda @filippo.abyssdomain.expert · 19/04/2026
It's April 2026, 1 year 8 months since FIPS 204. The IETF TLS WG is busy debating the concept of ML-DSA hybrids, and whether they should be composite, concatenated, or separate. The complexity of hybrid auth is, however, firmly denied. In the distance, sounds of a pure ML-DSA PKI being built.
2235
Reposted by Tom Thorogood
Steve Crosby @stevecrosby.bsky.social · 17/04/2026
☂ internetfriends.llc
internetfriends.llc
Internet Friends LLC
A software company in California.
1132
Reposted by Tom Thorogood
Filippo Valsorda @filippo.abyssdomain.expert · 17/04/2026
31537
Reposted by Tom Thorogood
Ben Adida @benadida.com · 09/04/2026
Setting up SAML between an app and an identity provider should be two clicks. Instead, it's 20 manual steps of copying and pasting and clicking, as explained in a bespoke PDF for each app. With multiple failure modes that will lock you out. Huge failure of protocol design.
061
Reposted by Tom Thorogood
Russ Cox @swtch.com · 09/04/2026
I have been saying for a while that given use of unsafe languages and terrible dep hygiene you’d think things would be much worse than they are. With better LLMs and more determined attackers like in the Trivy and Axios attacks, I’ve stopped saying that. Worse arrived slowly, then all at once.
192
Reposted by Tom Thorogood
David Crawshaw @crawshaw.io · 08/04/2026
The idea that big tech companies will inherently have better security tools than me because of enterprise access deals makes me sad.
0112
Reposted by Tom Thorogood
Rachit Dubey @rachitdubey.bsky.social · 07/04/2026
🚨New preprint and our results are rather concerning.. We find the "boiling frog" equivalent of AI use. Using large-scale RCTs, we provide *casual* evidence that AI assistance reduces persistence and hurts independent performance. And these effects emerge after just 10–15 minutes of AI use! 1/
261533684
Reposted by Tom Thorogood
Matthew Green @matthewdgreen.bsky.social · 08/04/2026
We should be able to slow down AI takeover by a few years just by telling the model to find every bug in ffmpeg.
5859
Reposted by Tom Thorogood
Dan Olson @foldablehuman.bsky.social · 05/04/2026
“Everyone from Walmart to your local bodega will need to maintain a presence in Fortnite to stay relevant” is so profoundly stupid I’m just glad I have the documentation to prove someone legitimately believed it.
171705164
Reposted by Tom Thorogood
Filippo Valsorda @filippo.abyssdomain.expert · 06/04/2026
Two papers came out last week that suggest classical asymmetric cryptography might indeed be broken by quantum computers in just a few years. That means we need to ship post-quantum crypto now, with the tools we have: ML-KEM and ML-DSA. I didn't think PQ auth was so urgent until recently.
words.filippo.io
A Cryptography Engineer’s Perspective on Quantum Computing Timelines
The risk that cryptographically-relevant quantum computers materialize within the next few years is now high enough to be dispositive, unfortunately.
11303123
Reposted by Tom Thorogood
Russ Cox @swtch.com · 06/04/2026
On the topic of tokens, it is very wrong that a project on GitHub or NPM can insist on 2FA for people logging in, but then those same systems allow using these short easily stolen strings as 1FA methods with equivalent power. Recent attacks demonstrate the significant lateral movement this enables.
131
Reposted by Tom Thorogood
Russ Cox @swtch.com · 02/04/2026
Dan Lorenc is exactly right: "I blame[] the Trivy breach on GitHub. The design of Actions is plain irresponsible today and ignores a decade of supply chain security work from other ecosystems." www.linkedin.com/posts/danlor...
linkedin.com
GitHub Actions Security Flaws: Immutable Tags, Token Access, and More | Dan Lorenc posted on the topic | LinkedIn
Yesterday I blamed the Trivy breach on GitHub. The design of Actions is plain irresponsible today and ignores a decade of supply chain security work from other ecosystems. Here's what they would have...
2436
Reposted by Tom Thorogood
Eric Rescorla @rtfm.com · 28/03/2026
This week on the newsletter: "How not to mandate device-based age assurance" educatedguesswork.org/posts/device... In this post, we examine a number of enacted or proposed requirements for device-based age assurance and some of the ways they can go wrong.
educatedguesswork.org
How not to mandate device-based age assurance
Software design by legal mandate
154
Reposted by Tom Thorogood
Kevin Jones @vcsjones.dev · 27/03/2026
Still annoyed by this.
       both SEQUENCE {
         seed OCTET STRING (SIZE (64)),
         expandedKey OCTET STRING (SIZE (2400))
         }
131
Reposted by Tom Thorogood
Matthew Garrett @mjg59.eicar-test-file.zip · 24/03/2026
It's been years, but finally got around to hanging this
A wall with a framed poster for Hackers (1995) next to a Robert Tinney print of a DNA double helix except one strand is a rainbow coloured ribbon cable
4912
Reposted by Tom Thorogood
rmhrisk @rmhrisk.bsky.social · 17/03/2026
The WebPKI is something we all rely on every day, and most people do not even know it exists. What is interesting is that even those who do often do not understand it as well as they think they do. To help more people understand how it works, I put together the WebPKI Observatory.
webpki.systematicreasoning.com
WebPKI Observatory — Certificate Authority Trust Ecosystem Analysis
Quantitative analysis of 96 trusted CAs: market share, concentration risk, compliance incidents, distrust history, and root program governance. Updated daily.
132
Reposted by Tom Thorogood
CardiOnCryptography @bsky.gay · 17/03/2026
A smooth Bernie meme, but with the “dlss 5 on” badge added
062
Reposted by Tom Thorogood
Marcus Brinkmann @lambdafu.bsky.social · 16/03/2026
Just putting this out there: the amount of software that exists in production vastly exceeds our global capacity to maintain it. And AI is going to make this an ultimate nightmare as often it is now easier to start from scratch than building a framework. Liability law will need updates.
012
Reposted by Tom Thorogood
Matthew Green @matthewdgreen.bsky.social · 04/03/2026
The crazy thing is that this is a Chinese firm, which just announced that it’s going to maintain the ability to mine huge amounts of UK and European citizens’ private comms, but the BBC is leading with the “it’s good that they can intercept our data” spin.
2318
Reposted by Tom Thorogood
Man in Business Suit Levitating @dfeldman.org · 26/02/2026
$10 billion gross profit last year on $24 billion revenue, with 17% growth year over year. Firing half their employees. There is no social contract: your employer can be among the world’s most successful and still get rid of everyone.
5183
Reposted by Tom Thorogood
Peter Milley 🇨🇦 @petermilley.bsky.social · 26/02/2026
Because the billion-dollar problem that "AI" is meant to solve is salaries.
031
Reposted by Tom Thorogood
Matthew Green @matthewdgreen.bsky.social · 25/02/2026
And right on schedule: there goes pseudonymity on the Internet. arxiv.org/abs/2602.16800
arxiv.org
Large-scale online deanonymization with LLMs
We show that large language models can be used to perform at-scale deanonymization. With full Internet access, our agent can re-identify Hacker News users and Anthropic Interviewer participants at hig...
49862
Reposted by Tom Thorogood
rob pike @robpike.io · 23/02/2026
STOP LAUNCHING CRAP WE DON'T NEED OR WANT It's staggeringly depressing how blithely they plan to ruin everything. Everything. I went to a dark site last week so I could say goodbye to the sky. Took a little hand-held photo and guess what? A satellite trail appeared. Just stop!
417326
Reposted by Tom Thorogood
Mike Schuster @mcs212.bsky.social · 07/02/2026
Breaking: Tragedy at the Winter Olympics
Image of the Yeti in the skiing Windows game SkiFree eating the player
7186222550
Reposted by Tom Thorogood
what a ghoul believes ☎️ @sayambular.bsky.social · 05/02/2026
I used to love computer it was my friend. Now I have hate in my heart
34187991
Reposted by Tom Thorogood
Tim Murphy @timothypmurphy.bsky.social · 30/01/2026
there's this new dynamic where the DOJ cannot win in court and is (relatedly) incapable of meeting the minimum threshold of professional legal conduct, and so an increasing percentage of its actions are purely for intimidation and content
8367431804
Reposted by Tom Thorogood
Ben Collins @bencollins.bsky.social · 19/01/2026
www.garbageday.email/p/am-i-too-s...
I can’t speak for everyone, but my mind tends to treat writing an article, making a video, writing a song, cooking a meal, drawing an image, and, apparently, designing software the same way. It’s not a matter of just “generating” something perfect from my head, but exploring the tension that exists between what I’m imagining and the limitations of my stupid meat body. That’s actually the exciting part. It also lets me figure out if something has turned out wrong or just resulted in a happy accident. Vibe coding, like every new trend coming out of Silicon Valley, turns this process — the entire act of creativity, itself — into a slot machine. One more pull on the AI and maybe it will figure it out for you. You won’t understand how any of it works, of course, or feel particularly proud of what you’ve done, but maybe you’ll have something. Just a few more dollars for some more tokens. C’mon, just pay a bit more.
613897836
Reposted by Tom Thorogood
Filippo Valsorda @filippo.abyssdomain.expert · 05/01/2026
PSA: go.sum is not a lockfile. You never need to look at go.sum. go.mod has everything you need.
words.filippo.io
go.sum Is Not a Lockfile
In Go, go.mod acts as both manifest and lockfile. There is never a reason to look at go.sum.
513325
Reposted by Tom Thorogood
Ash G. @kilomonster.bsky.social · 19/12/2025
Funny animal videos no longer being trustworthy just fucking sucks all around. I love the wonder of animal behavior and what it says about the experience of being alive. It's because it happened in reality that it's so fun. It's not fun if it was just made up. There's no wonder there.
475311930
Reposted by Tom Thorogood
Kyle Marquis @moochava.bsky.social · 17/12/2025
Yeah I only use AI for the fun part right at the beginning where we're kicking ideas around and not worried about budget or expectations. Just the best part of any group creative endeavor, me and my team challenging each other with our most visionary ideas, I'm looking to automate that
11918248
Reposted by Tom Thorogood
Matthew Green @matthewdgreen.bsky.social · 16/12/2025
Imagine it’s 2013 and you see this document from the UK sent back from the future. You’ll assume something went very wrong in that timeline.
63812