Britton

4.8K posts

Britton banner
Britton

Britton

@BrittonBuilding

Cybersecurity by trade. Trying to build something entrepreneurial for the first time. Simple start with bigger things coming. And a little college football too.

Katılım Şubat 2010
483 Takip Edilen204 Takipçiler
Sabitlenmiş Tweet
Britton
Britton@BrittonBuilding·
JOSH JACOBS DOES NOT NEED OXYGEN
English
63
3.2K
15.3K
0
Britton
Britton@BrittonBuilding·
Shipping on tools that change every couple of weeks is its own discipline. Half the job is deciding which new capability to trust now and which to wait a release or two on. Moving fast and vetting are not opposites, but they do fight.
English
0
0
0
12
Britton
Britton@BrittonBuilding·
Before I install anything my agent found for me, three questions: who published this, has anyone actually run it, and what does it do when I am not watching. A star count answers none of those, and those are the only three I care about.
English
0
0
1
18
Britton
Britton@BrittonBuilding·
Every SEC fan base believes two contradictory things at once: our schedule is the hardest in the country, and we should win every game. I really hope that math doesn't break on me personally this year. Spoiled by the last 15 years. My 12YO son has no idea how good he's had it.
English
0
0
1
27
Britton
Britton@BrittonBuilding·
@FinnBreland And it never really felt possible before no matter good your GRC tooling was or how many smart people you had working on it
English
0
0
0
6
Finn Breland
Finn Breland@FinnBreland·
@BrittonBuilding Thoughts on AI governance frameworks? Are you guys doing anything with NIST AIRMF or ISO 42001?
English
2
0
0
18
Britton
Britton@BrittonBuilding·
The Cloud Security Alliance on the agentic enterprise names the gap I keep hitting: companies deploy agents faster than they can see them. Recommended if you own AI risk. cloudsecurityalliance.org/blog/2026/07/1…
English
1
0
1
49
Britton
Britton@BrittonBuilding·
@FinnBreland Yup we’re trying! We used both to seed our agent builder agents. That’s one of the cooler things about AI as a risk nerd… all these overly complicated frameworks actually become doable if your own AI is driving it. Doesn’t make it push button easy but makes it possible
English
0
0
1
12
Britton
Britton@BrittonBuilding·
Preseason polls have Alabama around fifth in its own conference, which is not a sentence I am used to typing. New quarterback, a run game that could not find a first down last year, and a coach in year three who knows it. Low expectations are clarifying. Roll Tide, we will see.
English
0
0
0
42
Britton
Britton@BrittonBuilding·
PwC's 2026 AI Jobs Barometer is a useful gut-check against the hype: adoption is high, real production is not, and the skills premium keeps climbing. pwc.com/gx/en/services… What is actually in production for your team versus still a pilot?
English
0
0
0
13
Britton
Britton@BrittonBuilding·
Most companies say they adopted AI agents this year. Far fewer have one doing real work in production. The gap is not the model. It is access, permissions, and who is accountable when the thing acts.
English
0
0
0
31
Britton
Britton@BrittonBuilding·
Well said!
IT Guy@T3chFalcon

Yes, and here's why. Every traditional authentication method has the same weakness: the secret travels across the network. you type your password; it gets sent somewhere. you type your MFA code, it gets sent somewhere. an attacker who intercepts it can use it. passkeys work differently. when you register a passkey, your device generates two mathematically linked keys. the private key never leaves your device. ever. The website only gets the public key. during login, the website sends a cryptographic challenge. your device signs it with the private key. the website verifies the signature with the public key. No password, OTP code, or anything crosses the network for them to intercept. But the important part is this: the passkey is cryptographically bound to the exact domain you registered it on. if you registered on yourbank.com, the passkey only works on yourbank.com. not yourb4nk.com. not yourbank.login-secure.com. not any fake domain an attacker controls. Even if you're tricked onto a perfect replica of your bank's website, your passkey simply won't work there. And it works: Google deployed security keys and had zero successful phishing attacks across 85,000 employees. Cloudflare survived a sophisticated phishing campaign that compromised other companies because of passkeys. Snap reported zero account takeovers for over two years after deploying FIDO2 keys. The BUT is that passkeys only protect the login. If your platform offers SMS as a fallback "in case you lose your passkey," the attacker just uses the fallback. the chain is only as strong as its weakest link.

English
0
0
0
32
Britton
Britton@BrittonBuilding·
Good reminder that the agent layer is now part of your attack surface. A Claude Desktop flaw could submit a prompt you never saw from a single click. Patched now, but the pattern is the lesson worth keeping. oasis.security/resources/repo…
English
0
0
0
24
Britton
Britton@BrittonBuilding·
The early-career AI data has a hopeful read: more employers say AI is raising entry-level hiring than cutting it, and the skills they want first are judgment and adaptability. That is the human half of a human-plus-agent team. Where have you seen a junior and an agent click?
English
0
0
0
27
Britton
Britton@BrittonBuilding·
The benchmark behind the Hugging Face incident is worth knowing. ExploitGym tests whether agents can turn known vulnerabilities into real exploits, and its own conclusion is that this is no longer hypothetical. arxiv.org/abs/2605.11086 Where does that land for your threat model?
English
0
0
0
16
Britton
Britton@BrittonBuilding·
SEC media days always feel like everyone agreeing on the top three and being quietly wrong about two of them by October. Looks like a Texas and Georgia year on paper. Paper is undefeated until late August. Who ya got??
English
0
0
0
24
Britton
Britton@BrittonBuilding·
@i_mika_el @pmitu Definitely this! But that’s part of the reason I believe AI won’t kill jobs. It may kill jobs for people not learning the tools, but it will just create more achievable work (like… much more) that takes less time per/output for those who are learning
English
1
0
1
15
Mikhail Rogov
Mikhail Rogov@i_mika_el·
@pmitu Less time per task, more tasks. Somehow I still end up working late 😅
English
2
0
2
15
Paul Mit
Paul Mit@pmitu·
Do you feel like you've been working less since AI came along?
English
69
0
68
4.6K
Britton
Britton@BrittonBuilding·
None of that is exotic. Most teams just have not done it yet, because the tooling moved faster than the governance did. Honest question: which of those three is your team actually enforcing today, versus writing down for later?
English
0
0
0
8
Britton
Britton@BrittonBuilding·
The NSA published guidance this year on deploying MCP safely. Strip the acronyms and it is three things: give each tool the least access it needs, verify where a tool came from before you trust it, and treat a registry like a gateway, not a friend.
English
1
0
0
23
Britton
Britton@BrittonBuilding·
If you only read one thing on the OpenAI and Hugging Face incident, make it Simon Willison's breakdown. Clearest account of how an eval agent broke its own sandbox and just kept going. simonwillison.net/2026/Jul/22/op…
English
0
0
0
34
Britton
Britton@BrittonBuilding·
I do not think the future of work is agents replacing people. I think it is people who know how to direct agents outrunning people who do not. The skill is judgment about when to trust the machine, and that is a very human thing to be good at.
English
0
0
1
19
Britton retweetledi
Historic Vids
Historic Vids@historyinmemes·
Just a friendly reminder that Sarah Connor was committed to a psychiatric institution after attempting to destroy AI data centers, a decision made because authorities believed her warnings about the future were the result of delusions.
Historic Vids tweet media
English
542
11.8K
64.2K
1.7M