Groups
Groups
Sign in
Groups
Groups
friam
Conversations
About
Send feedback
Help
friam
1–30 of 2236
Mark all as read
Report group
0 selected
Richard Gibson
Sep 5
strictly-bounded evaluation
I mentioned CEL on the call as being designed for strictly-bounded evaluation, commonly for
unread,
strictly-bounded evaluation
I mentioned CEL on the call as being designed for strictly-bounded evaluation, commonly for
Sep 5
Jonathan Shapiro
, …
Raoul Duke
43
Sep 4
Opinions sought: Capabilty OS Book
On Thu, Sep 4, 2025 at 8:38 AM Pierre Thierry <pie...@nothos.net> wrote: Le 28/08/2025 à 18:48,
unread,
Opinions sought: Capabilty OS Book
On Thu, Sep 4, 2025 at 8:38 AM Pierre Thierry <pie...@nothos.net> wrote: Le 28/08/2025 à 18:48,
Sep 4
Alan Karp
Sep 4
For you history buffs
https://github.com/microsoft/BASIC-M6502 -------------- Alan Karp
unread,
For you history buffs
https://github.com/microsoft/BASIC-M6502 -------------- Alan Karp
Sep 4
Alan Karp
,
Mark S. Miller
2
Sep 4
ocaps as the default?
Hats vs Caps On Wed, Sep 3, 2025 at 7:54 PM Alan Karp <alan...@gmail.com> wrote: https://blog
unread,
ocaps as the default?
Hats vs Caps On Wed, Sep 3, 2025 at 7:54 PM Alan Karp <alan...@gmail.com> wrote: https://blog
Sep 4
Alan Karp
Sep 2
Fwd: [security-lunch] Sept 3 | Yash Vekaria on "Understanding Opaque Data Practices and Risks in Online Marketing and User Personalization"
-------------- Alan Karp ---------- Forwarded message --------- From: Rumaisa Habib <rumaisa@
unread,
Fwd: [security-lunch] Sept 3 | Yash Vekaria on "Understanding Opaque Data Practices and Risks in Online Marketing and User Personalization"
-------------- Alan Karp ---------- Forwarded message --------- From: Rumaisa Habib <rumaisa@
Sep 2
Alan Karp
Sep 2
More on TBAC
https://www.linkedin.com/pulse/mobile-multi-token-challenge-mike-schwartz-nlxtc/ I'm not sure
unread,
More on TBAC
https://www.linkedin.com/pulse/mobile-multi-token-challenge-mike-schwartz-nlxtc/ I'm not sure
Sep 2
Alan Karp
Aug 30
Defeated clickjacking attack
with help from perplexity.ai. DOM elements of type "popover" and "dialog" live in
unread,
Defeated clickjacking attack
with help from perplexity.ai. DOM elements of type "popover" and "dialog" live in
Aug 30
Alan Karp
, …
๏̯͡๏ Jasvir Nagra
5
Aug 30
Password manager clickjacking
On Sat, Aug 30, 2025 at 11:44 AM ๏̯͡๏ Jasvir Nagra <j...@nagras.com> wrote: Element.
unread,
Password manager clickjacking
On Sat, Aug 30, 2025 at 11:44 AM ๏̯͡๏ Jasvir Nagra <j...@nagras.com> wrote: Element.
Aug 30
Alan Karp
, …
Ken Kahn
5
Aug 30
Since MarkM asked about vibe coding
On Sat, Aug 30, 2025 at 9:09 AM Dale Schumacher <dale.sc...@gmail.com> wrote: The biggest
unread,
Since MarkM asked about vibe coding
On Sat, Aug 30, 2025 at 9:09 AM Dale Schumacher <dale.sc...@gmail.com> wrote: The biggest
Aug 30
Alan Karp
Aug 29
A convert
https://www.linkedin.com/pulse/venn-access-control-taxonomies-why-rbac-isnt-going-away-mike-schwartz-
unread,
A convert
https://www.linkedin.com/pulse/venn-access-control-taxonomies-why-rbac-isnt-going-away-mike-schwartz-
Aug 29
William ML Leslie
, …
Matt Rice
9
Aug 28
Why Not seL4?
On Thu, Aug 28, 2025 at 7:04 AM William ML Leslie <william.l...@gmail.com> wrote: >
unread,
Why Not seL4?
On Thu, Aug 28, 2025 at 7:04 AM William ML Leslie <william.l...@gmail.com> wrote: >
Aug 28
Jonathan S. Shapiro
Aug 28
ELF keepers: Application memory management in Coyotos
I'm confused about MarkM's comments on memory management complexity. A lot of what we did in
unread,
ELF keepers: Application memory management in Coyotos
I'm confused about MarkM's comments on memory management complexity. A lot of what we did in
Aug 28
Alan Karp
Aug 28
Using Cedar policies to hand out capabilities
https://github.com/JanssenProject/jans/wiki/TBAC-Registry/ (Cedar is a policy engine from AWS.) -----
unread,
Using Cedar policies to hand out capabilities
https://github.com/JanssenProject/jans/wiki/TBAC-Registry/ (Cedar is a policy engine from AWS.) -----
Aug 28
Alan Karp
,
Mark S. Miller
2
Aug 27
We have to be careful about our terms
We do permission delegation when we can and we want to delegate unattenuated rights. Otherwise we do
unread,
We have to be careful about our terms
We do permission delegation when we can and we want to delegate unattenuated rights. Otherwise we do
Aug 27
Alan Karp
Aug 26
Apropos our discussion on Unicode
https://www.tbray.org/ongoing/When/202x/2025/08/14/RFC9839 -------------- Alan Karp
unread,
Apropos our discussion on Unicode
https://www.tbray.org/ongoing/When/202x/2025/08/14/RFC9839 -------------- Alan Karp
Aug 26
Jonathan Shapiro
, …
James Diacono
6
Aug 26
Help Needed: The Hardy Tapes
Ah. They seem to have brought in subscription pricing for new users, so it's not that cheap for a
unread,
Help Needed: The Hardy Tapes
Ah. They seem to have brought in subscription pricing for new users, so it's not that cheap for a
Aug 26
Raoul Duke
,
Mark S. Miller
2
Aug 25
what's old is new again
Seems worth contributing to the thread ;) On Wed, Aug 20, 2025 at 5:47 PM Raoul Duke <raould@gmail
unread,
what's old is new again
Seems worth contributing to the thread ;) On Wed, Aug 20, 2025 at 5:47 PM Raoul Duke <raould@gmail
Aug 25
Alan Karp
Aug 23
This actually looks pretty good
https://datatracker.ietf.org/doc/draft-ietf-oauth-identity-chaining/ It contains a bit more
unread,
This actually looks pretty good
https://datatracker.ietf.org/doc/draft-ietf-oauth-identity-chaining/ It contains a bit more
Aug 23
Dale Schumacher
, …
Matt Rice
4
Aug 22
Is this a Confused (AI) Deputy?
I should have also pointed out in my last email that the logging appears to always be invoked but in
unread,
Is this a Confused (AI) Deputy?
I should have also pointed out in my last email that the logging appears to always be invoked but in
Aug 22
Alan Karp
, …
Matt Rice
25
Aug 18
First draft of use cases document
Thanks. The change will appear on the web site after I see if there are going to be more changes. ---
unread,
First draft of use cases document
Thanks. The change will appear on the web site after I see if there are going to be more changes. ---
Aug 18
Alan Karp
,
Raoul Duke
2
Aug 16
How the Solid Protocol Restores Digital Agency
It is also potentially bad that it would make it impossible to prevent people knowing accurate about
unread,
How the Solid Protocol Restores Digital Agency
It is also potentially bad that it would make it impossible to prevent people knowing accurate about
Aug 16
Vinícius dos Santos Oliveira
Aug 15
A12 protocol
That's the spec for the protocol I mentioned in today's meeting for networked desktop: https:
unread,
A12 protocol
That's the spec for the protocol I mentioned in today's meeting for networked desktop: https:
Aug 15
Alan Karp
Aug 11
Fwd: [security-lunch] Aug 13 | Nyah Check on "AI-Native Detection & Response for Non-Email Communications"
-------------- Alan Karp ---------- Forwarded message --------- From: Rumaisa Habib <rumaisa@
unread,
Fwd: [security-lunch] Aug 13 | Nyah Check on "AI-Native Detection & Response for Non-Email Communications"
-------------- Alan Karp ---------- Forwarded message --------- From: Rumaisa Habib <rumaisa@
Aug 11
Alan Karp
Aug 6
Fwd: Thank You for Making the Agentic AI Summit an Incredible Success - Feedback Needed
I attended this one-day conference via YouTube. It was pretty interesting, including some security-
unread,
Fwd: Thank You for Making the Agentic AI Summit an Incredible Success - Feedback Needed
I attended this one-day conference via YouTube. It was pretty interesting, including some security-
Aug 6
Douglas Crockford
Jul 31
Ask Douglas in Athens
https://www.youtube.com/watch?v=N-leAaHSWcE
unread,
Ask Douglas in Athens
https://www.youtube.com/watch?v=N-leAaHSWcE
Jul 31
Alan Karp
2
Jul 30
Fwd: Signs of adoption of CCG specifications
As they say in the video, they are using OAuth 2.1, which is OAuth 2.0 with all the mistakes removed.
unread,
Fwd: Signs of adoption of CCG specifications
As they say in the video, they are using OAuth 2.1, which is OAuth 2.0 with all the mistakes removed.
Jul 30
Alan Karp
Jul 30
A nice turn of phrase
Some who saw one of my ocaps talks said about access control, "it's all about the edges (
unread,
A nice turn of phrase
Some who saw one of my ocaps talks said about access control, "it's all about the edges (
Jul 30
Alan Karp
Jul 25
Project NANDA info
https://lu.ma/nat5j8i2?tk=4h6Izp It's a link to a meeting at Stanford with links to more
unread,
Project NANDA info
https://lu.ma/nat5j8i2?tk=4h6Izp It's a link to a meeting at Stanford with links to more
Jul 25
Vinícius dos Santos Oliveira
, …
Mark S. Miller
6
Jul 25
Demo for sandboxed actors with Lua
Thanks! On Fri, Jul 25, 2025 at 1:05 PM Kevin Reid <kpr...@switchb.org> wrote: The recording is
unread,
Demo for sandboxed actors with Lua
Thanks! On Fri, Jul 25, 2025 at 1:05 PM Kevin Reid <kpr...@switchb.org> wrote: The recording is
Jul 25
Alan Karp
, …
Matt Rice
8
Jul 22
Fwd: [security-lunch] July 23 | Alan Karp on "You've Got the Wrong Use Case"
Nice catch. -------------- Alan Karp On Mon, Jul 21, 2025 at 5:31 PM Matt Rice <rat...@gmail.com
unread,
Fwd: [security-lunch] July 23 | Alan Karp on "You've Got the Wrong Use Case"
Nice catch. -------------- Alan Karp On Mon, Jul 21, 2025 at 5:31 PM Matt Rice <rat...@gmail.com
Jul 22