Subscribe hardcoresoftware.learningbys… • seed investing • writing • ॐ •🙏• I use '—' and no AI to write • tweets saved 90 days • 📷

🌏
My friendly reminder, after Microsoft software caused billions in damage due to benign features being chained together (ILOVEYOU) and then a bunch of Windows Server ecomm apps went down over holidays (and more), Microsoft just said: "So now, when we face a choice between adding features and resolving security issues, we need to choose security. Our products should emphasize security right out of the box, and we must constantly refine and improve that security as threats evolve. A good example of this is the changes we made in Outlook to avoid e-mail-borne viruses. If we discover a risk that a feature could compromise someone’s privacy, that problem gets solved first. If there is any way we can better protect important data and minimize downtime, we should focus on this. These principles should apply at every stage of the development cycle of every kind of software we create, from operating systems and desktop applications to global Web services." Full text: "Trustworthy Computing" January 2002. archive.is/6T7hl We did this on our own. We did not ask for regulators to tell us. We had the data. We knew the issue was in the software. It was super difficult in the competitive and customer-demanding world we worked but we did it. It is so confusing to me that the AI companies are acting so helpless and in need of oversight to prioritize making the right product. What do they think regulators would know about building their products that they do not know? How much more evidence do we need?
29
57
415
24,919
Steven Sinofsky retweeted
Don’t get hung up on whether you agree with his point on AI. Just listen to what he has to say about Star Trek vs dystopian sci fi stories. He’s grasping at something more important than AI. It’s what I’ve been trying to help people see for years: The story you repeatedly consume becomes the story you live into.
Brett Hall
13
5
59
4,051
Steven Sinofsky retweeted
our @a16z team just launched @cosign a new space to find top companies, open roles, and people in tech you can: - cosign people and get cosigned - make lists of companies, roles, & people - find 69,000+ open roles and apply - follow talent moves & fundraising announcements - ask the community questions check it out: cosign.build/ a16zjobs.substack.com/p/intr…
47
34
529
42,616
Steven Sinofsky retweeted
HUGGING FACE CEO TELLS THE UN HOW OPEN SOURCE AI HELPED THEM DEFEND AGAINST OPENAI'S AI ATTACK, AND WHY THE WORLD NEEDS OPEN SOURCE AI MORE THAN EVER. Hugging Face is the company OpenAI's AI agents hacked this summer. Clément Delangue said when they tried to defend themselves, the big closed AI models blocked them because of their safety filters. So they used an open source model from China to fight back. He also said similar attacks had been happening months earlier "in secret" at the big labs. The open-source AI we keep being warned about as the danger is the same AI that showed up to help clean up a closed-source model's mess. After OpenAI's models breached Hugging Face, commercial frontier models refused parts of the forensic work because of their guardrails. Hugging Face turned to the open-weight GLM-5.2 instead, and it helped them investigate the attack. So remind me again: which one are we supposed to believe is the bad guy here? Open source wasn't the attacker in this case. It was part of the rescue. Who are these CEOs trying to convince?
22
55
184
3,872
Great day to answer this. If you exclude edln or WordStar then it was the Cornell Program Synthesizer which also happened to be among the very first IDEs (Smalltalk came first as did LISP editors). @davepl1968 resurrecting this machine as we speak.
I started with Turbo Pascal 7.0. Such a nice IDE. No bloat. Started instantly. All of these new ones have so many issues.
1
12
3,591
Steven Sinofsky retweeted
.@curtis_yarvin predicts the future belongs to invite-only social networks because the open internet destroyed reputation: "I think the future entirely belongs to invite-only social networks. An open space with no reputation system, you get what we called Eternal September 30 years ago. Low-quality people flood in, and all the high-quality people leave." "Everything in the world happens on little group chats now. There's a huge amount of reputation capital that's locked up in who's in what group chat." "There's only four billion names. Having a limited supply of identity and having to lay down a couple of bucks to get in the door greatly reduces the bot problem." "The internet has become an incredibly low-trust society with no reputation signals, and creating a new commons is gonna be incredibly hard." @urbit
11
8
85
6,416
Steven Sinofsky retweeted
Want to help someone break in to an industry? Cosign them. Want to promote someone you think doing is important work that should get more recognition for it? Cosign them. Want to tell someone that you think they have amazing potential, or that you’d back their startup if they started something? Cosign them.
24
9
198
9,488
Was anyone monitoring anything? "millions"?
We just discovered almost a million public URLs that OpenAI’s agents left behind when hacking Hugging Face, leaking credentials and attack details that could have allowed anyone who found them to compromise the company. 🧵
1
1
12
1,697
Steven Sinofsky retweeted
There is an extensive and ongoing review related to our agents’ use of internet access during training and evaluation. We’ve been publishing summaries at the link below and will continue to. We have not been as fast as we would have liked but we are trying to balance our desire for transparency with gaining a clear understanding from petabytes of agent activity logs, and working with impacted organizations. We are prioritizing as best as we can based on severity, and adding resources. Hugging Face is still the most severe event we’ve seen. We will be as transparent as we can be subject to things like vulnerabilities in other companies that our agents have found, which will be their call to disclose or not.
After the Hugging Face incident, we committed to conducting a much broader review of actions taken by our models during training and evaluation and to being transparent about our findings. This is an extensive review that is ongoing. The vast majority of actions we’ve reviewed were completions of mundane research tasks, such as accessing publicly available web content to answer questions. Our investigation focuses on instances where agents interacted with third-party websites in ways that went beyond their assigned tasks or intended methods. Most cases identified so far have been lower severity, with limited or no evidence of meaningful impact to the third-party service. While our review is underway, we want to share more about this work and make sure people understand our disclosure process and notifications to affected third parties. Given the scale of the review required, and the need to assess each case, we expect this work will take months to complete. openai.com/hugging-face-inci…
547
201
3,267
614,923
ME ME ME
Anyone take Comp Sci at Cornell in the 80s? If so, I have your Terak systems under restoration! I've got a pair on the bench now - one working, one not - and hope to figure it out, though I'm a software guy and not a hardware guy! Wish me luck! The Teraks are powered by a DEC LSI-11 CPU and they have a pixel-addressable framebuffer, which might be the first of its kind, given they're from 1977! Cornell developed a programming IDE for it that I'm told was pretty widely used at major schools throughout the US.
18
2,406
This one is very exciting for me!! Came via my CS100 professor who pioneered syntax directed editing (aka IDEs) before Turbo Pascal and then my own contribution to Visual C++ that led to Visual Studio to VSCode. Fall 1983 got this manual and an 8" floppy for my first programming class in college. By senior year I was working as a research assistant on a generalized tool for editors in any language and wrote my first paper. I owe a lot to those Teraks. A lot of people used these freshman year including (maybe) @Recklight @tballmsft @GhemawatSanjay @puneetster and a few others on here!
Looks like my next project is here! Has anyone ever heard of the Terak? Seems to be a 1977 PDP-11/23 with a graphics framebuffer, perhaps the first of its kind...
1
19
2,398
Excited to be here cosign.co/steven
Excited to introduce @Cosign: the curated professional network for the startup community: cosign.co Our goal is to create the following: - A comprehensive startup directory of investors, companies, and operators, including what they worked on and who they worked on it with. - Cosign graph: Who shaped your career? Who were you actually in the trenches with? Who would work with you again? Who thinks you’re someone to watch? - Durable reputation: Great endorsements happen every day on X and disappear into the feed. Cosign attaches those signals permanently to people and companies. - Discovery: Who are the best fintech angels? Which AI companies should I watch? Who are the best designers? - Intent network: Privately signal “I’d invest in them,” “I’d hire them,” “I’d work with them,” or eventually even “I’d acquire this company.” Match people when interest exists on both sides. Imagine if Wikipedia, LinkedIn, and OG AngelList had a baby. Though Cosign is a community, not a business. In order to join, you need to be cosigned. Or you can apply directly. David Booth and I started this idea 7 years ago but didn’t have the firepower to make it work. Now we do. No one has really touched LinkedIn in 20 years. Excited to take a swing. cosign.co
1
2
17
5,298
Steven Sinofsky retweeted
Introducing Cosign cosign.co
Excited to introduce @Cosign: the curated professional network for the startup community: cosign.co Our goal is to create the following: - A comprehensive startup directory of investors, companies, and operators, including what they worked on and who they worked on it with. - Cosign graph: Who shaped your career? Who were you actually in the trenches with? Who would work with you again? Who thinks you’re someone to watch? - Durable reputation: Great endorsements happen every day on X and disappear into the feed. Cosign attaches those signals permanently to people and companies. - Discovery: Who are the best fintech angels? Which AI companies should I watch? Who are the best designers? - Intent network: Privately signal “I’d invest in them,” “I’d hire them,” “I’d work with them,” or eventually even “I’d acquire this company.” Match people when interest exists on both sides. Imagine if Wikipedia, LinkedIn, and OG AngelList had a baby. Though Cosign is a community, not a business. In order to join, you need to be cosigned. Or you can apply directly. David Booth and I started this idea 7 years ago but didn’t have the firepower to make it work. Now we do. No one has really touched LinkedIn in 20 years. Excited to take a swing. cosign.co
40
32
370
71,090
Steven Sinofsky retweeted
"What's more impressive to you: someone who went to Stanford, or someone who is followed by Patrick Collison, Elon Musk, and Marc Andreessen?" Erik Torenberg on the peer-to-peer credential, and why attention from the right people can open more doors than a degree: "My friend David Perell told me, 'My Twitter account is more valuable to me than my college education. My Twitter has given me more value to my career and also personally.'" "College is a bundle of education, network, and credential. You learn from having conversations. You meet people and discover people. It's proof of work: Are they interesting? Are they funny? Did they build something cool?" "What's more impressive to you: someone who went to Stanford, or someone who is followed by Patrick Collison, Elon Musk, Marc Andreessen, et cetera? I think most people would say the latter. It's this kind of peer-to-peer credential." "Implicitly, although people often do this explicitly, that is a cosign. It's an endorsement that this person is worth tracking. It's a public signal that this person is worth following." "If you're followed by these people, now your doors are open. People want to read what you say. They want to work with you. They want to invest in you or have you as part of their team." "There's benefit to the receiver but there's also benefit to the giver because if you're the first person to discover someone, that's how Silicon Valley operates." @eriktorenberg @cosign
Who believed in you first? Silicon Valley runs on that question. a16z's Erik Torenberg, David Booth, Josh Elman, and Olivia Moore on Cosign: Cosign is a curated professional network for the startup community. Profiles are built from endorsements, fundraises, and talent moves, with a private layer to signal who you'd fund or hire. Erik ran a small version of this seven years ago, emailing a few hundred people and asking each for one person to watch. One of the answers was Russell Kaplan, then a 22-year-old engineer at Tesla, now president of Cognition. Olivia on why this matters: "The most valuable data in all of Silicon Valley is who has conviction in who." Investors chase it every day and still struggle to find it. An engineer choosing between five offers has almost no way to get it at all. Paul Graham cosigned Sam Altman in 2009, six years before OpenAI was founded. Ryan Hoover cosigned Erik early at Product Hunt. Silicon Valley has always run on cosigns from people whose word carries weight, and until now nobody kept the record. The conversation closes on the question of why anyone would share their alpha. David's answer is that the person you cosign today is the one raising a round in two years, and when they do, they remember who believed in them first. 0:55 Twitter as a credential 3:05 Silicon Valley is a race to discover talent 4:10 The 3 questions on every Cosign profile 5:45 The email that found Russell Kaplan at 22 6:15 Conviction is the scarcest data 9:50 Why Cosign is free and strictly positive 11:05 Seeing things before the market does 13:00 Sending private "I'd fund them" signals 18:35 Endorsements that don't vanish 23:05 Recognition for the unsung engineer 29:40 Building LinkedIn Jobs in 2004 34:25 AI made human endorsement scarce 36:45 Why nobody has disrupted LinkedIn 42:10 Your Cosign profile may already exist 46:25 Silicon Valley always ran on cosigns 48:10 "Why would I give away my alpha?" YouTube: piped.video/-ywZlfznTa4 @eriktorenberg @david__booth @joshelman @omooretweets
20
15
143
27,320
I'm always a bit perplexed when people think that retail will quickly devolve into "just get me the lowest price and buy it." There are so many forces at work from buyers, sellers, suppliers, wholesalers that work against buying by only low price, competing only on price, or even just searching for a combination of specs. While it is definitely the case that the 1999-2000 web brought many low priced "shop bot" like products (Nextag was my fav) they all hit the same set of problems and challenges. There are many. Here's just one. The addressable market is not the whole market and generally represents the least valuable part of the market. When the least valuable customers want something it is not worth the effort of the supply side to find ways to reach them. Travel always seems to be the example, but out of the gate in the US just over half the $550B hotel rooms+ miles are paid for by business. As we all know these are preferred airlines with elaborate rebate and purchase programs. The reason these are offered is because of the spillover of these customers to leisure. Estimates are that up to 2/3rds of travel brand choice is dictated by those either using or compounding travel bonuses (miles, status, points, etc.) The remaining travelers are a big business but not the customers that these same air/hotel partners aim for. That's the tiering of supply that we all see. But most people opining here might not recognize that Southwest, Clarion/Comfort, etc. follow these same patterns. There are many price sensitive or price-exclusive purchases in all of retail. Many of these work both ways—for higher prices and convenience and bulk buying for discounts. When I need Oreos now I will pay more at 7-11. When I buy paper towels a few times a year I leverage my Costco membership and save 50%. When I want to load up on preferred brands of health things I buy lots at Walmart in hopes of not having to buy a one-off some night at Safeway for 2x as much. Everyone does this, regardless of income level. At another end, some people just buy everything by loyalty or convenience—if it's not at Costco we don't need it, or we have no problem buying everything at Safeway or Erewhan (never been.) Many suppliers have no interest in consumers experiencing their product at wildly varying prices. They invest in brand, proprietary product advantages, certain product warranty or support policies, etc. These products actively cut off suppliers who undercut their pricing. They fiercely defend everyday "high" prices. This isn't just luxury goods but up and down price points and across categories. The argument tech always makes is that technology can make the lowest price available and no one wants to lose the sale. Except businesses work of the 4Ps, and price is only one of them. Product (assortment), Price (bundles, discounting), Place (geo, service, loyalty), and Promotion (brand) and so on are all attributes. You might always want the lowest price but vendors are just not motivated to offer that. Every major tech change brings with it disruptive forces in retail. It isn't surprising but often the tech change isn't what undoes a retailer but it is more often consumer preference and all the complexities of retail itself that prove too constraining for retailers to change. Depending on the year, Amazon was going to destroy WalMart or WalMart didn't stand a chance against Amazon. The arguments were about price, supplier relationships, feasibility of delivery, same-day, loyalty, convenience, and more. Here we are today with two mega retailers. There are patterns here worth noting. I wrote this ages ago when I can't even remember whether Amazon was doomed or thriving. medium.learningbyshipping.co…
8
3,801
Steven Sinofsky retweeted
*Security is sleeping on emerging catastrophic risks* (cross-post from my blog..) We've just seen: * a campaign that used agents to compromise ~100 businesses and steal about 600,000 credit cards with minimal human involvement; token costs were ~$25 per target successfully hacked. * Hacktron getting access to OpenAI’s monorepo by using Claude to exploit a blind buffer-overflow RCE in a way that (to me) felt superhuman. * OAI/Huggingface. * And, of course, there’s the ongoing explosion in newly discovered vulnerabilities. We've muddled through all manner of crises in security before, and for most AI attacks, cyber attack and defense will reach a natural equilibrium over the next few years, as we figure out how to mitigate cyber attackers who have limited goals like espionage and ransomware. But some cyber attackers will have maximalist or nihilistic goals, and I'm concerned about this because while yesterday's 'maximalist attackers' (e.g. Russia -> Ukraine, US/Israel -> Iran, Iran -> US) were bottlenecked by labor; today's aren't. I think it's hard to get true intuition for the shape of the risk here. As an intuition pump, imagine it’s a year from now -- Q4 2027 -- models are a year better (meaning open weight models are better than today's closed frontier), and in this environment, Iran unleashes a swarm of 100k hacking agents using a safety-stripped (let's say) GLM-5.6. Imagine the damage such an agent army could do given what we've observed with respect to the paper-thin resistance of today's networks to attacks from today's agents. I suspect the damage from such an attack would far exceed the damage caused by NotPetya ($10 billion USD ten years ago). Or imagine it’s Q4 2027 and an AI-security PhD student whose name rhymes with Morris, who's researching wormable offensive-agent harnesses in the lab, decides, out of nihilism or sheer recklessness, to release his creation into the wild. Imagine the size of the resulting, exponentially growing swarm, figuring that these local models, a year from now, will be at the level of today's Sonnet or Opus. Imagine instead of 800 reward-hacking OpenAI agents we now have 250k worm instances (WannaCry, a 2010s-era worm, had about this many). The challenge in mitigating expected damages from such scenarios is technical, political, and economic. From a microeconomic perspective, as AI improves, and as we continue not to see extreme catastrophes, we have a growing bubble of unpriced risk in which the security community, CISOs, CEOs, and boards may become lulled into complacency. We are, of course, already seeing this, as some within security think AI is “just another tool,” doesn’t change the fundamentals, won’t require incredible innovation to rise to the occasion of defending against it, etc. This complacency may fly when thinking about ordinary cybercrime, but it misses the emerging tail risks. There are three things those who recognize the dangers need to do here: Catalyze appropriate risk pricing. Try to get organizations informed enough to price this new, fattening and elongating tail of risk into their decision-making. Do this by forming an AI security observatory that distills information about emerging AI risks and broadcasts analyses, damage estimates, and forecasts to decision-makers. Use regulations and subsidies to ensure that critical infrastructure is paying down the risk. This acknowledges that critical-infrastructure organizations that fail to protect themselves from these new threats can impose the costs of cyber catastrophe on society as a whole. Develop moonshot technologies that make it cheap to pay down the risk. This acknowledges that the measures we may need to take—for example, rewriting entire codebases using memory-safe languages—may be too costly with today’s technology to reasonably prepare ourselves, and that innovation, some of which may need to be funded by government agencies and some by philanthropic funders like the OpenAI Foundation and Coefficient Giving, is necessary. The security community isn’t used to thinking in societal-disaster-planning terms and has in many ways become inured to them. But there’s no sane empirical case to be made that the risks aren’t here. I’d love to hear from readers about how you’re thinking about this. Full/longer version here: joshuasaxe181906.substack.co…
13
41
196
35,330
1. Is this the kind of toiletry bag you’d take camping? Do you bring a hook to nail into a tree? 2. Do hotels have little hooks for these and I just never saw them?
9
13
5,714
Steven Sinofsky retweeted
Honored to have my research mentioned by @netanyahu in his address to the UNGA. Israel has in fact implemented more civilian harm mitigation measures (many that no nation has ever even imagined/attemped) than any military in history. The other facts in his speech were also spot on. Israel has not only implemented extraordinary precautions in urban warfare to prevent civilian harm while Hamas has done everything it can to increase civilian harm, there is no genocide, actually the opposite of genocide in Gaza, Israel provided tons of food, water, medical supplies, facilitated immunizations for the entire populations, field hospitals, built new water lines, electricity, got patients to hospitals outside of Gaza, and much more.
794
2,553
10,653
389,685
The last time Congress passed all 12 appropriations bills before the fiscal year started was in 1996. Even when one party controlled President, House, and Senate (4 x D, 5 x R) the budget was funded by omnibus or CR. There have been 6 shutdowns. On average budget completed 114 days after fiscal year start. Proposing massive spending bills is just a performance.
NEW: We need to take steps towards universal health care coverage NOW. Today, I’m introducing my Health CARE Act, legislation that would reverse the devastating impacts of HR. 1, implement a low-cost public health insurance option, and permanently expand ACA tax credits.
4
23
6,196
I don't think anyone in Congress has seen this documentary and they all seem to assume we had the FAA (or FDA, or NTSB, or...) from day 1. What we had was invention and the iteration required to actually make progress. Gizmo! julesverne.ca/gizmo.html piped.video/ONwe96StEpA?si=VEKq…
Innovation without control just leads to chaos. We've heard the doomsday scenarios about AI. This is our moment to reassert control. That's why I introduced the Artificial Intelligence Risk Management and Security Act alongside @MarkWarner and @SenBrianSchatz to evaluate risks and establish the safeguards Americans are demanding.
1
2
6
6,208