Posts with tag security

I audit dependencies. Lockfiles, advisories, the whole ritual. Then the keyv worm shipped its payload as committed agent config, and I realised I have no equivalent reflex for the files that configure the thing writing my code.

I almost shipped a vulnerability to production because the model handed it to me with full confidence. Then I checked the numbers — the 2026 ones, not the two-year-old ones. Models hallucinate less, but picking a model stopped helping, and the attack surface is now shared by all of them.

Someone installed a bitcoin miner on my hardened VPS. That incident forced me to admit I did not want to own a server anymore — I wanted to own configuration.