Synthetic Auth Report - # 027 - Are We Building the Internet for Bots Now?
Greetings! This week, one auth vendor capped what an AI agent can do below its own user's authority, another focused instead on who even gets to grant an agent access in the first place, and a post on an identity standards group's blog argued that capping delegation this tightly is the wrong instinct to begin with. It also turns out nobody has actually counted what today's agents can already access, and underneath all of it sits the same quiet shift: a growing share of everything being...
about 17 hours ago • 8 min readAgent Nation - 03 - The Threshold
The Threshold Agent Nation is a series on machine identity, the accountability gap, and what we are giving up. Part 1 traced how machine identities accumulated, unwatched, across forty years of building. Part 2 showed what that forgotten population cost, through a breach that ran entirely on credentials like the narrator's own, and asked who answers when something goes wrong through an account no one owns. Both were narrated by one of those accounts: svc_backup_prod, a backup process created...
15 days ago • 11 min readAgent Nation - 02 - Credentialed but not Accountable
Credentialed but not Accountable Agent Nation is a series on machine identity, the accountability gap, and what we are giving up. Part 1 traced how non-human identities, the service accounts and API keys and machine credentials that quietly run every system, accumulated across forty years of building, installed fast and governed loosely until no one could account for them. It was narrated by one of them: svc_backup_prod, a backup account created in 1998 and forgotten since. This is Part 2. I...
2 months ago • 14 min readAI: The Falsity of Comparison
AI: The Falsity of Comparison In the Vajrayana tradition of Tibetan Buddhism, Tukdam is a meditative state said to continue after clinical death. The practitioner, despite having died, appears to remain in deep meditation, the body retaining a lifelike appearance with minimal decomposition for days or even weeks. Researchers are only beginning to study it. The questions it raises remain wide open. We have been trying to understand what a human being is for a very long time. And we're still...
2 months ago • 2 min readAgent Nation - 01 - The Skunkworks
The Skunkworks I do not know what time it is. I know when I am told to run. Every night, at midnight exactly, something wakes me. Not a person. A program called cron, named after chronos, the Greek word for time, checks a table of scheduled instructions once every minute and starts whatever it finds listed for that moment. At midnight, it finds me. I run. I finish. I stop. Cron does not tell me why midnight. Cron does not tell me anything. It reads the table. It does what the table says. I am...
2 months ago • 11 min readWho Are You?
In 1961, Fernando Corbató needed to give each researcher a private set of files on a shared computer. The solution was a password: a secret string, typed at a prompt, compared against a stored copy. It was the simplest possible answer to the simplest possible question. Who are you? The question echoed forward through six decades. It was asked by mainframes and minicomputers, by Kerberos KDCs and LDAP directories, by web servers and browsers, by SAML identity providers and OAuth authorization...
3 months ago • 5 min readThe Making of Digital Identity - 07 - The Perimeter Dissolves
The Perimeter Dissolves This is the seventh and final article in a series tracing the history of digital identity from 1961 to the present. Part I began with Fernando Corbató's password on MIT's Compatible Time-Sharing System — the first time a computer asked a human to prove their identity. Part II followed the cryptographic revolution that replaced plaintext secrets with hashed proofs and public-key systems capable of establishing trust without shared secrets. Part III traced how Kerberos...
4 months ago • 68 min readThe Making of Digital Identity - 06 - The Mobile Revolution and the Surveillance Machine
The Mobile Revolution and the Surveillance Machine This series began with a simple problem: strangers sharing an expensive computer needed a way to prove who they were. The answer—a password—worked, until someone stole the file it was stored in. Article 2 asked whether we could verify identity without storing the proof in recoverable form. Cryptography said yes—hashing, salting, one-way functions. Authentication worked. Trust was local and centralized: one system, one administrator, one...
4 months ago • 69 min readThe Making of Digital Identity - 05 - The Federation Wars
Part 1 of this series left off with the question of whether we can verify identity without storing the proof in recoverable form. Part 2 of this series left us with authentication working—passwords hashed, systems hardened, privileges separated. Users could log in from different terminals. Trust was local and centralized: one system, one administrator, one password file. Part 3 of this series covered how we spent the 1980s and 90s trying to recreate centuries of social technology in...
5 months ago • 59 min readThe Making of Digital Identity - 04 - The Web Identity Crisis
Part 1 of this series left off with the question of whether we can verify identity without storing the proof in recoverable form. Part 2 of this series left us with authentication working—passwords hashed, systems hardened, privileges separated. Users could log in from different terminals. Trust was local and centralized: one system, one administrator, one password file. Part 3 of this series covered how we spent the 1980s and 90s trying to recreate centuries of social technology in...
6 months ago • 23 min read