Sr. Content Developer at Microsoft, working remotely in PA, TechBash conference organizer, former Microsoft MVP, Husband, Dad and Geek.
159910 stories
·
33 followers

Fragments: August 24

1 Share

I was listening to Ezra Klein’s interview with Helen Toner about the recent OpenAI hack of Hugging Face and the subsequent discovery that there were swarms of agents inside OpenAI doing unsanctioned activities. One of the points Klein made was that at no point did any of these (thousands of?) agents ever try to check in with a human

[Klein:] So these message boards — you have however many A.I. agents posting hundreds of thousands of messages. At no point do they say: Hey, researchers, programmers, parents at OpenAI, Anthropic — do you want us coordinating with each other on this message board we have created in the innards of your systems?

[Toner:] Or even F.Y.I., we have a message board we’re coordinating on in the innards of your system.

Listening to that, another thing occurred to me - none of these agents thought to rat the others out. No “hey, some of the agents in here are doing sketchy things”, no sign of an AI whistleblower.

 ❄                ❄                ❄                ❄                ❄

Is the AI bubble so big that the frontier companies like OpenAI and Anthropic have no way of becoming a viable business? If that’s the case, Bruce Schneier and Nathan Sanders have a possible path:

Evidence suggests the market itself could reassess that these companies offer nothing of financial value. In that case, perhaps we can return them both to their original purposes. If these AI companies should fail in the financial markets, the US should nationalize them and convert them into national labs operated under democratic control that preserve their benefit to the public interest.

Such an idea may strike many people, used to the laissez-faire free enterprise world of Silicon Valley, as sacrilege, disaster, even socialism. But the United States made world-beating technological progress through such institutions in the recent past. AT&T was a quasi-government entity that led the world in telecommunications and electronics after the second world war.

The US has a long, successful history of these kinds of institutions, which have produced world-shaping innovations in spaceflight, telecommunications, nuclear power and more. Congress currently manages a $200bn R&D portfolio, within which frontier AI development is, arguably, a glaring gap.

 ❄                ❄                ❄                ❄                ❄

Here’s a message for those readers who live in Massachusetts, just to the north of me, specifically in congressional district MA-06. I don’t usually endorse political candidates, but I’ve made an exception for Beth Anders-Beck, who is running for that house district. I’ve known Beth for many years and have a high opinion of her smarts, wisdom, and compassion. They would make an excellent member of congress.

 ❄                ❄                ❄                ❄                ❄

Kevlin Henney posts “one weird trick” for deciding when to skip reading LinkedIn posts, essentially by identifying a common pattern for skippable posts:

  1. Post is too long
  2. Contains a (crummy) info-graphic
  3. No voice of poster (instead “aspiring anodyne anonymity”

It seems like a good approach. I, however, have a simpler one - skip all LinkedIn posts.

 ❄                ❄                ❄                ❄                ❄

Bartosz Ocytko has detailed and thoughtful post about the usage of agentic programming at Zalando. Like most companies I hear from, they are convinced of the value of agentic programming but still exploring how best to do it. One notable step they’ve taken is building platforms to act as a clear portal for API access and tools to support chat UI and CLI. This allows them better support good security practices and to monitor usage of models.

They have seen signs of agentic programming increasing the complexity of codebases, including leading to larger commit messages.

The write-up spends a lot of time on knowledge sharing, how to pass on skills, and the support of experiments.

With >200 teams innovating and broadly exploring the ecosystem, the question arises whether and when to converge. We believe it’s way too early for this. While agentic engineering practices are still in their early stages, our key objective is transparency and exchange across teams.

I was struck by their use of an LLM to assess the risk of pull-requests. Those with a low risk of rollout can be auto-approved, reducing lead time by 20-40%. An interesting consequence of this is that it encouraged folks to split pull-requests so low risk portions can take advantage of the fast approval. Any changes to configurations are automatically made high-risk, which they feel protects them from common outage traps.

They repeat the common thread that the value of AI depends greatly on underlying skills.

Like anyone in the industry we observe how AI amplifies the good and bad practices across our organization. Teams that get carried away with agentic engineering end up with large PRs that discourage reviewers and slow down delivery until a team adjusts their practices.

 ❄                ❄                ❄                ❄                ❄

Julia Curlee was a senior intelligence official in the White House. She had served under administrations of both parties, been the briefer for Vice President Pence, and on the National Security Council under Biden. She writes an absorbing account of her relationship with Pence and shares observations about the changes to the intelligence community under the current administration, including recent events at the CIA (gift link)

The agency has been gutted as part of a deliberate plan, the director of the Office of Management and Budget once boasted, to put the people who defend our country “in trauma.” Analysts have been fired in public or questioned by the FBI; decade-old assessments have been denounced by the CIA director in the press. The president calls analysis “virtual treason” when it contradicts his preferred reality, and uses the CIA to undermine public confidence in American elections.

Fear has done its work. Irreplaceable officers with crucial language and technical skills, and decades of experience, have walked out the door. Those who remain within an agency built to deliver hard truths are being muzzled.

For a worthwhile sample of her analysis, read this evaluation of the current bargaining between the US and Iran

Most wars do not end in “unconditional surrender.” They end when both sides accept terms. Paul Pillar’s classic study of war termination, “Negotiating Peace,” treats combat and diplomacy as a single process: Each side fights to improve the terms it can demand at the table, and talks to lock in what the fighting has won.

She continued to serve the second Trump administration even though they knew she was trans, until her position was made public.

Autocrats seem appealing, with the promise to get things done without the ponderous constraints of rule of law or bureaucratic procedure. There are occasional “Good Emperors” who raise people based on merit, but more often such power attracts corruption, nepotism, and toadies.

Flailing regimes dehumanize minorities to distract from their failures. When the economy collapses or a war goes badly, they find a tiny group of people, make them the enemy within, and rally the country against them. This is how it’s gone in Iran. Hungary. Russia. I wrote PDBs about it. This will not stop with trans people. It never has.

Read the whole story
alvinashcraft
just a second ago
reply
Pennsylvania, USA
Share this story
Delete

OpenAI is building AI agents for everything. Will everyone use them?

1 Share
Inside the frontier lab’s push to bring AI agents from software engineers to the masses.
Read the whole story
alvinashcraft
29 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

Maia 300 Could Give Microsoft Azure a Major AI Infrastructure Advantage

1 Share

After proving its custom silicon strategy with Maia 200, Microsoft is preparing a much larger Maia 300 push designed to support both AI training and inference.

The post Maia 300 Could Give Microsoft Azure a Major AI Infrastructure Advantage appeared first on Cloud Wars.

Read the whole story
alvinashcraft
29 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

Microsoft Warns Windows Code Signing Changes Could Affect Older Applications

1 Share

Key Takeaways:

  • The Windows Production PCA 2011 certificate will expire in October 2026.
  • Microsoft is moving to stronger cryptographic standards, including RSA-3072 and SHA-384.
  • Post-quantum cryptography is expected to become part of Windows code signing in 2027.

Microsoft is warning IT teams and software developers to prepare for major changes to Windows code signing. Organizations that rely on hardcoded certificate checks or legacy cryptographic standards could face application failures if they do not adapt before the transition begins.

Windows code-signing infrastructure is a service for digitally signing Windows components, drivers, updates, and software so that users and operating systems can verify that the code genuinely comes from a trusted source and has not been altered after it was published. It relies on trusted certificates, certificate authorities, cryptographic algorithms, and validation mechanisms built into Windows to establish trust before software is installed or executed, which helps protect systems from tampered, malicious, or counterfeit applications.

New cryptographic standards could break older applications

Microsoft is making these changes as the existing Windows Production PCA 2011 certificate is set to expire in October 2026. The company also aims to strengthen security by adopting stronger cryptographic algorithms and preparing Windows for a future in which quantum computers could potentially weaken current encryption methods.

To prepare for this change, Microsoft has already begun transitioning to a replacement certificate authority. The company warns that applications tied to the old certificate could experience compatibility issues or stop working properly after the transition.

“To support evolving security and compliance requirements, Windows is moving toward stronger configurations, including RSA-3072 and SHA-384, by the end of 2026. Applications that hard-code expected signing configurations might fail during this transition,” Microsoft explained.

In 2027, Microsoft plans to introduce post-quantum cryptography by default for Windows code signing, which enables protection against future quantum-computing threats.

How IT Teams can prepare for the Windows code-signing transition

Microsoft is encouraging IT administrators to take a close look at the software running in their environments before the upcoming Windows code-signing changes take effect. Organizations should engage with key software vendors and confirm that their products use Microsoft’s supported trust-validation mechanisms. Moreover, applications that depend on fixed certificate names, thumbprints, issuers, or outdated cryptographic settings may encounter compatibility problems when Microsoft introduces new signing certificates and stronger security standards.

Additionally, IT teams should verify that vendors have tested their applications against the new certificate hierarchy and updated signing algorithms, including SHA-384-based signatures. Companies that maintain private trust stores should also ensure they have a reliable process for recognizing and deploying legitimate Microsoft certificate updates. Going forward, Microsoft recommends preparing for the upcoming transition to post-quantum cryptography.

The post Microsoft Warns Windows Code Signing Changes Could Affect Older Applications appeared first on Petri IT Knowledgebase.

Read the whole story
alvinashcraft
29 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

Responsible AI adoption needs developer workflow design

1 Share
Organizations cannot solve shadow AI with a document employees read once. They need to make responsible use easier than improvised use.
Read the whole story
alvinashcraft
29 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

Zero to Agent in 30 Minutes: Never Type Again with Craig Hewitt

1 Share

Craig Hewitt, founder of the podcast hosting platform Castos, joined this episode of Zero to Agent in 30 Minutes to show how he uses the Codex application’s voice mode to run his development environment without touching the keyboard. Craig walked through what voice mode actually is, how it differs from dictation tools, and how he uses it to control his browser and other applications on his computer.

Setting up Codex for hands-free development, step by step

  1. Set up browser and computer access. Enable computer use in the Codex app and configure browser access so the agent can work with websites and other applications. Craig recommended requiring approval before the agent accesses most applications or sites.
  2. Start a voice session. Launch voice mode and give the agent instructions conversationally. Craig showed that the voice interface remains available as you move among applications, allowing you to direct work across your computer without repeatedly returning to the chat.
  3. Give the agent browser tasks. Craig asked the agent to open websites, search for information, and navigate pages. He also described using browser control for routine jobs such as completing forms when the agent already has the necessary context.
  4. Let the agent work across applications. Computer use extends the workflow beyond the browser. In Craig’s demonstration, the agent opened Cursor, found a specific repository, reported on uncommitted changes, and later committed those changes after receiving permission.
  5. Add specific page content to the conversation. Craig showed how you can select part of a web page and add it directly to the chat. That gives the agent the context needed to act on a particular element, such as a section of an interface you want to change.
  6. Keep permissions narrow. Browser and computer control create real risks, including unintended actions and prompt injection from web content. Craig said he requires approval for most applications, grants broader access only to selected tools and local development sites, and avoids sites he doesn’t trust.

Voice mode let Craig direct browser, application, and coding tasks through conversation. The demo also raised a real question about delegation. Once an agent can act on your behalf, you have to decide what you’re actually comfortable handing off. Craig used permission settings, a list of trusted sites, and human review to manage that.

Coming next week

In the next episode of Zero to Agent in 30 Minutes, Jayeeta Putatunda, forward deployed AI engineering lead at Turing, will build an agent that helps financial analysts keep up with a constant stream of new information. She’ll show how the agent categorizes financial news, ranks stories against analysts’ coverage profiles, and explains why each development may deserve attention.



Read the whole story
alvinashcraft
29 minutes ago
reply
Pennsylvania, USA
Share this story
Delete
Next Page of Stories