Nancy Wang

415 posts

Nancy Wang banner
Nancy Wang

Nancy Wang

@NancyZWang

Security & AI builder @1Password | ex-@AWS @Rubrik | Investor @Felicis

San Francisco, CA Katılım Mart 2017
467 Takip Edilen1.7K Takipçiler
Nancy Wang
Nancy Wang@NancyZWang·
“Claude, reschedule my dentist appointment. Again.” “And cancel the free trial I definitely meant to cancel three months ago.” This is exactly the kind of life admin agents should take off our plates. @1Password for Claude launches today so when Claude needs to sign in, it asks 1Password. The credential goes straight into the page and your password and OTP never reach its context, memory, or Anthropic. Give Claude the errand, not the keys to your digital life. Try Agentic Mode:
English
1
0
4
161
Nancy Wang
Nancy Wang@NancyZWang·
Agents need standards. The AIUC-1 Consortium comprises over 150 members of security and AI leaders across top organizations like Meta, Databricks, NVIDIA, and more. I was honored to help co-write the first @aiunderwriting paper back in Feb; it’s an amazing community that I hope others join. Learn more here: aiuc-1.com
Nancy Wang tweet media
English
0
0
1
85
Nancy Wang
Nancy Wang@NancyZWang·
If you knew your agent was compromised, how would you build it? @travismcpeak and I explore the new defaults: scoped access and observable behavior to contain risk. Not blocked agents. Just systems designed so failure doesn't create risk. New Zero-Shot Learning with @cursor_ai's Head of Security @travismcpeak youtube.com/watch?v=oV4k8Z…
YouTube video
YouTube
English
3
1
3
132.1K
Nancy Wang
Nancy Wang@NancyZWang·
Congrats @berman66 and the @runlayer team! Every company is trying to figure out how to let people use AI for real work without creating a new shadow IT problem. Excited to see Runlayer giving teams a more practical path to say yes with visibility and control.
Andy Berman@berman66

Today, we’re announcing Runlayer has raised $30M from Felicis and Khosla Ventures to help companies go all in on AI. Runlayer is the golden path for AI: enablement, security, and control in one platform. So, how does it give your team the right tools for AI? 🧵

English
0
0
7
239
Nancy Wang
Nancy Wang@NancyZWang·
The gap between a blank canvas and a working product keeps getting smaller. Which is why the bottleneck is shifting from creation to authorization. Check out the new Zero-Shot Learning episode with @tomocchino from @vercel: youtube.com/watch?v=AFr8WT…
YouTube video
YouTube
English
0
0
0
312
Nancy Wang
Nancy Wang@NancyZWang·
@nickbaum Thanks for the @1Password shout! We agree that shared subscription with separate identities/contexts is the way.
English
0
0
1
31
Nick Baum
Nick Baum@nickbaum·
I wish Codex and Claude adopted 1Password’s model, where you get a personal account as part of your team account. I want to use them for work and personal, and I want a single subscription with shared quotas, but I want to keep the accounts separate (including MCP connections).
English
4
0
8
720
Nancy Wang retweetledi
Alex Konrad
Alex Konrad@alexrkonrad·
AI is making areas of security previously considered solved, like email, rise to the forefront again, says listmaker and @sublime_sec CEO Josh Kamdjou (@jkamdjou). "They’re getting revitalized with new and better ways of doing things," he says. “It’s coming from a place of concern, but not necessarily fear,” says CTO Nancy Wang (@NancyZWang) of fellow listee @1Password.
Alex Konrad tweet media
English
1
2
11
755
Nancy Wang retweetledi
1Password
1Password@1Password·
Join @1Password CTO @NancyZWang and @JeffMalnick, VP of Engineering of Developer & AI, at Agentic + AI Coding Night in SF on May 7, alongside leaders from @OpenAI, @Anthropic, @Databricks, and @Datafold. Nancy and Jeff join Richard Liu to explore the risk of AI agents executing the wrong action in the wrong context under valid authorization, and how contextual policy evaluation and just-in-time credentialing can better constrain agent behavior at runtime. 📅 May 7 | 3:30–9pm PST | SF 🔗 luma.com/agenticaiobsni…
1Password tweet media
English
0
1
2
2.9K
Nancy Wang
Nancy Wang@NancyZWang·
Interesting project from the @brexHQ team github.com/brexhq/CrabTra… - the notion of using LLMs as a judge to evaluate an agent's context as it's evolving. Being able to act as a circuit breaker when the context gets toxic or violates organizational policies is a unique way to think about this problem. A step towards least agency. Nicely done
English
1
0
2
166
Nancy Wang
Nancy Wang@NancyZWang·
While a lot has already been said about the recent @vercel incident, here’s what isn’t: 1) @rauchg and the Vercel team handled the disclosure well. They were clear about what happened, specific about the access path, and avoided speculation. Having this level of transparency is not easy in the middle of an incident, but we should hope it becomes the norm. Instead of a vague post or PR speak, Vercel gave details on exactly what happened, what steps to take, and what it was doing going forward. And they’ve been updating customers along the way. This kind of transparency helps the rest of the industry focus on the actual problem instead of reacting to incomplete narratives and jumping to conclusions. 2) This is about more than a single tool or decision, it is about how access works today. An employee connects a third-party application using OAuth. The permissions are granted through a standard flow. That connection persists. If at some later point, the external service is compromised, then the token becomes the access path. While nothing is “technically wrong,” this is where the identity model of security starts to break down. Identity systems were built around controlling access at login. That creates a gap between what is allowed and what should happen in context. At @1Password, we are shifting from managing identity to governing how access is used in practice. We are co-building with our partners now, to help them secure their agents and their access. Credit to the Vercel team for surfacing this issue 🙏
Guillermo Rauch@rauchg

Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated. Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments. Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration. We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel. At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community. The recommendation for all Vercel customers is to follow the Security Bulletin closely (vercel.com/kb/bulletin/ve…). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature. In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback. We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance. It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.

English
1
2
49
16.1K
Nancy Wang retweetledi
1Password
1Password@1Password·
Agents are moving from experimentation to real execution inside enterprises. And as @NancyZWang, CTO at 1Password, pointed out, “Agents also have secrets or passwords just like humans do.” This reality changes everything.
1Password tweet media
English
1
2
1
1.3K
Nancy Wang retweetledi
Vintage Investment Partners
Vintage Investment Partners@Vintage_Inv·
Three events. One packed week. A truly global crowd. 🎥🌍 We’re kicking off 2026 with a look back at our most recent gatherings. Our Annual Meeting, 11th CEO Summit, and 19th VC Summit brought together the broader Vintage network for several days of focused conversations, meaningful connections, and shared perspective. The week, by the numbers: 🔷3 events 🔷30+ speakers 🔷700+ attendees from around the world 🔷90+ curated 1:1 meetings between corporates and startups - Huge shoutout to the Value+ team led by Ilan Leiferman, Chief Value Officer, and Niv Hanan, Director of BD, for making those connections happen 🙌 Don’t just take it from us. Hear directly from Danny Ritter (Richter), @rick_nathan (@KensingtonFunds), @Amanda_Herson (@fcollective), @nwintroub (@jpmorgan), @bradsvrluga (@PrimaryVC), and @NancyZWang (@1Password). Grateful to everyone who joined and helped shape a high-signal, highly curated week. More summit content coming soon. 🎯
English
0
2
6
273
Nancy Wang
Nancy Wang@NancyZWang·
@evanyou @1Password We’ll be publishing a postmortem covering what went wrong, the timeline, and the concrete changes we’re making to how we build and release future browser extension updates.
English
1
0
2
104
Nancy Wang
Nancy Wang@NancyZWang·
@evanyou @1Password I want to thank everyone who called our attention to this and explain what happened and what we’re doing about it.
English
6
0
6
393
Evan You
Evan You@evanyou·
.@1Password browser extension is injecting Prism.js *globally* on every page, which then applies its syntax highlighting logic on all blocks matching [lang=*] regardless of whether it’s meant to be compatible, thus breaking original highlighting. Terrible negligence and even more so that this made to prod while already flagged during beta. Been a user for a long time but this will def push me to an alternative if not fixed soon.
English
116
205
2.7K
813.5K
Nancy Wang
Nancy Wang@NancyZWang·
@evanyou @1Password What we’re doing about it: We’ve completed the fix and submitted it to the Chrome Web Store. We expect the Chrome Web Store to review and roll it out over the next few days.
English
0
0
1
99
Nancy Wang
Nancy Wang@NancyZWang·
@evanyou @1Password I want to emphasize that vault security was not impacted. At 1Password, protecting our customers’ privacy, passwords, and credentials is our highest priority.
English
0
0
2
83
Nancy Wang
Nancy Wang@NancyZWang·
@evanyou @1Password This interfered with code formatting on certain sites. I apologize for the inconvenience this caused.
English
0
0
1
65
Nancy Wang
Nancy Wang@NancyZWang·
@evanyou @1Password What happened: Prism.js is a syntax-highlighting library we use for our Labs Snippets feature. While optimizing our build to reduce bundle size, we unintentionally bundled Prism.js into the extension in a way that caused it to run on pages where it shouldn’t.
English
0
0
2
119