
cole murray
7.4K posts

cole murray
@_colemurray
ai/ml | cto | second time founder | former sr. sde @ amazon




@euboid How do you prevent a targeted crash becoming the attack vector into the codebase? if the error injects instructions into codex, what's to prevent codex exfiltrating, or shoving some hidden payload into the codebase that might get missed by a reviewer in a pr review?

btw their supabase storage bucket is publicly accessible via any signed url token 😭 exposes: > employee background checks > equity vesting schedules and grant amounts > performance reviews > session tokens for stripe, notion, etc > screenshots below 🧵 i also got access to their notion 😛







I was finally convinced by a friend to set up openclaw set it up on a rpi and hooked in telegram asked it to scan my local network, find any available devices found my hue lights and then (after pairing them) can now control it and that’s the end of this experiment LOL. Absolutely not





Wait, hold on, Delve left a bucket with the screenshots of our network architecture diagram open to the public? That's a lot of IP!




Spoke to a CRO of a hot Series B startup yesterday: “We don’t have the knowledge internally to implement AI and agents into our process.” Toast. You are toast. That is unacceptable. Everyone can learn. There is zero excuse for the above.



Self-healing software is coming


I noticed something interesting: Claude Code auto-adds itself as a co-author on every git commit. Codex doesn’t. That’s why you see Claude everywhere on GitHub, but not Codex. I wonder why OpenAI is not doing that. Feels like an obvious branding strategy OpenAI is skipping.




me and my pal Jensen


A detailed and brutal look at the tactics of buzzy AI compliance startup Delve "Delve built a machine designed to make clients complicit without their knowledge, to manufacture plausible deniability while producing exactly the opposite." substack.com/home/post/p-19…






