Mike Williamson

284 Followers
423 Following
1.4K Posts

Digital Transformation = Agile + APIs + AppSec

Security Architect at the Public Health Agency of Canada. Formerly TBS Cyber security & part of the team that launched the Canadian Digital Service.

bloghttps://mikewilliamson.wordpress.com
githubhttps://github.com/sleepycat

RE: https://neuromatch.social/@jonny/116325668039992121

Hilarious -- and insightful -- analysis of part of the leaked Claude code base. I've been thinking recently about what the code would look like if you treat it as a "black box" and only let an llm touch it. It seems reality gets awfully close to the prediction: "Workaround-based development" and "An even bigger ball of mud."

Brutal.

When Microsoft acquired GitHub.

Love to see the innovation in the GraphQL space: #Shopify reworked #graphql execution from depth first to breadth for performance gains.

"Almost every GraphQL implementation uses this depth-first pattern, including the canonical graphql-ruby gem that we have used since 2015, and the official graphql-js spec implementation that it follows. In our experience running this execution model with Ruby, we’ve found that it scales poorly."

https://shopify.engineering/faster-breadth-first-graphql-execution

Rise 8 Livestream with Jennifer Pahlka & Bryon Kroger

https://www.youtube.com/watch?v=2Tciq0Ga3uY

Livestream with Jennifer Pahlka & Bryon Kroger│Shipping Outcomes in a Broken System

YouTube

The idea that Office 365 is compliant for use in any regulated space is *absolutely laughable*, but apparently the reason GCC High is approved for government use is because the government let agencies use it while they were evaluating it, and then realized so many agencies were now dependent on it, that they had to approve it even though it wasn't able to actually meet the security criteria.

https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/

#microsoft

Exploring #wasm lately and finding #wasmcloud kinda fascinating.

They're orchestrating wasm modules on #Kubernetes with #nats as the control plane. A really interesting project that just hit 2.0.

https://wasmcloud.com/blog/wasmcloud-v2-is-here/

VM-Class Secure, Millisecond-Fast Cloud-Native Apps With #Hyperlight + #Nanvix

https://www.youtube.com/watch?v=uA8WitzWeN4

VM-Class Secure, Millisecond-Fast Cloud-Native Apps With Hyperlight + Nanvix

YouTube

Try to unsee it

Level: impossible.

Last year, my position was that we still had time to design PQ authentication mechanisms.

Now, based on the pace of progress and on statements like Google's, I believe:

1. we need to finish rolling out PQ key exchange yesterday
2. we need to start rolling out PQ auth now
3. it's too late to ship any new non-PQ design or system

https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/

Quantum frontiers may be closer than they appear

An overview of how Google is accelerating its timeline for post-quantum cryptography migration.

Google
Adults Lose Skills to AI. Children Never Build Them.

Discussions of cognitive offloading often miss a critical distinction: What AI does to a 45-year-old's brain is categorically different from what it does to a 14-year-old's.

Psychology Today