Matthew Garrett

16.1K Followers
168 Following
6.2K Posts
Former biologist. Actual PhD in genetics. Security at Nvidia, OS security teaching at https://www.ischool.berkeley.edu. Blog: https://codon.org.uk/~mjg59/blog . He/him.
Bloghttps://codon.org.uk/~mjg59/blog
Signal@mjg.59
This culminated in Easter Monday resulting in my kitchen being absolutely full of hot cross buns and Sainsbury's having paid him 12 pounds for the privilege
They ended up being donated to the halfway house next door but also I know there are people reading this who can absolutely guess who that person was
It's been 20 years since someone showed up at my house and slept on the sofa for a while but in that period visited Sainsbury's and discovered that their implementation of "Buy one get one free" was to remove the price of one object from the total, and the implementation of "Reduced price" was to charge the full price and then remove a chunk and the combination was buy two objects, have both reduced in price, and then deduct the full price of one object

I will be at the Linux Security Summit in Minneapolis next month, talking about enabling hibernation on systems with lockdown enabled.

(The context is that I'm the person who disabled hibernation when lockdown is enabled and I've been promising to fix it forever, and then it came up twice in my nvidia interviews last year, so I've committed to speaking about it so I actually do it)

Google kindly sending me an earthquake alert 4 minutes after I opened the fridge and was confused why everything was vibrating as a result
This isn't me saying that what's happening is good, it's me saying that we've had decades of trying to force new people into existing norms and the trend is that it doesn't work and what's our answer to that going to be
Identity is a hard problem and it's just been made harder and also the environment is moving fast enough that everyone trying to sell something is focused on MCP and we've somehow decided that 2026 is the year that The Unix Philosophy finally reenters the ring to rousing music
All I'm actually saying here is that (waves broadly) a lot more people who have never opened a PR or maintained a project being in a position to either open a PR or maintaining a project is going to result in them not behaving within the social norms we've developed as a group that is, to be fair, far less insular than in the 90s but is still somewhat insular compared to society as a whole and yes we are going to have to get used to the equivalent of HTML mail and top posting

You have an agent running on your local system. You want it to have access to a restricted set of things, both locally and remote. What is the technical mechanism you use to ensure that it has a subset of the access that you, as an individual logged into the same system, do?

(I am uninterested in "Don't run an agent" because while yes I see your point that doesn't mean it's not happening and security professionals have to deal with what's happening not what we want to be happening)

Democratising software development inherently means that people are going to develop software in ways you don't like and which seem objectively wrong and welp that's also the argument people made against Linux so, it;s impossible to say if its bad or not