Daniel Stinson

392 posts

Daniel Stinson banner
Daniel Stinson

Daniel Stinson

@shellcromancer

Building a new product! Used to do security engineering @ Brex, and Cloudflare. Dogs are better than people.

Austin, TX Katılım Haziran 2018
2.9K Takip Edilen1K Takipçiler
Sabitlenmiş Tweet
Daniel Stinson
Daniel Stinson@shellcromancer·
Check out audit-logs.tax - we want to crowdsource a list of vendors who don't prioritize high quality, widely available audit logs. We started with a list of apps we're focused on but happy to take issues/PRs for logs you're focused on: github.com/shellcromancer…
julie agnes 🌈@JulieASparks

🧵 Have you ever been trying to ingest audit logs as a security engineer and been frustrated by the quality and cost of the logs? Well so were @shellcromancer and I, so here's an attempt to get them to prioritize the security engineer as a core customer: audit-logs.tax

English
1
7
29
6.1K
Daniel Stinson
Daniel Stinson@shellcromancer·
> The refactor itself typechecks conceptually; Name that Agent!
Daniel Stinson tweet media
English
0
0
3
71
Daniel Stinson
Daniel Stinson@shellcromancer·
Big day: toddler’s first data breach!
Daniel Stinson tweet media
English
1
0
12
869
Daniel Stinson retweetledi
Logan Carmody
Logan Carmody@endorseurgirl·
We at @cotoolai are stoked to announce our $7.4m fundraise from @a16z . Offensive cyber operations are now JIT code; we started Cotool to give defenders their leverage back. Grateful to everyone who took the bet early, especially @koomen @garrytan @MaikaThoughts @zanelackey.
Logan Carmody tweet media
English
1
3
12
416
Daniel Stinson retweetledi
Rustam X. Lalkaka
Rustam X. Lalkaka@lalkaka·
Today we're introducing @usefiretiger. You and your AI agents write code. Firetiger makes sure it works. Our team and I have plenty of incident war stories building @Cloudflare, @segment, @Twitch. In the agentic coding era, the volume of code changes + quality issues in prod is ever increasing, but observability vendors aren't incentivized to close the gap. They make money when you write more data to them, not when your software actually works. Firetiger is the agentic operations layer for the agentic coding era. We combine production observability data, codebase understanding, and knowledge of your business to find problems before your customers do and fix them before they notice. We've raised $7.6 million led by @sequoia with participation from angels who believe in better software, including @eastdakota, @calvinfo, @NicoRosberg, @dok2001, @jeffawilke, and @alanaagoyal. You can sign up for @usefiretiger today, self serve. We charge for agents that directly make your software better and more reliable, not for observability data ingested, with plans starting at $599/month. Observability is dead. Long live outcome engineering.
English
25
23
176
74.4K
Daniel Stinson
Daniel Stinson@shellcromancer·
Effective Cloudflare ad from whatever ai(.)com is
Daniel Stinson tweet media
English
0
0
0
289
Daniel Stinson
Daniel Stinson@shellcromancer·
Using ChatGPT Pulse to read my newsletter inbox and show me cute card summaries is really nice. The intro name in today’s was a little off though…
Daniel Stinson tweet media
English
1
0
1
143
Daniel Stinson
Daniel Stinson@shellcromancer·
How many apps have a shortcut to email their CEO? 👀 I’m guessing it’s a short list with only @matter
Daniel Stinson tweet media
English
0
0
1
178
Daniel Stinson
Daniel Stinson@shellcromancer·
Some days I worry about AGI taking my job, other days I know I'm safe for a few years... Both gpt-5-codex high, and Claude Code both spun their wheels for 15+ minutes pointing to a compiler toolchain issues even given a git commit where the issue must be... this was the fix!
Daniel Stinson tweet media
English
0
0
1
325
Daniel Stinson
Daniel Stinson@shellcromancer·
Got prompted to use a Passkey in the Costco app, it’s a good day 👌
English
0
0
6
223
Daniel Stinson retweetledi
tuckner
tuckner@tuckner·
Cursor is now using Open VSX to install code editor extensions from. You must understand the implications of this right now. There has been an attack campaign happening for more than a month with extensions that install ScreenConnect. Below is ANOTHER example.
zak.eth@0xzak

I've been in crypto for over 10 years and I’ve Never been hacked. Perfect OpSec record. Yesterday, my wallet was drained by a malicious @cursor_ai extension for the first time. If it can happen to me, it can happen to you. Here’s a full breakdown. 🧵👇

English
5
34
167
27.6K
Daniel Stinson
Daniel Stinson@shellcromancer·
The latest OCSF release has some IAM goodies. It's almost as if identity is the new perimeter 💡 * Group Management: handles subgroups now! (I helped with this one 🎉) * new IAM Analysis Finding class, and many new dictionary items related to identities github.com/ocsf/ocsf-sche…
English
0
0
3
206
Daniel Stinson
Daniel Stinson@shellcromancer·
this might become a daily thread on how I'm absolutely right
Daniel Stinson tweet media
English
0
0
1
91
Daniel Stinson
Daniel Stinson@shellcromancer·
didn't save me this time ☠️
Daniel Stinson tweet media
English
1
0
0
191
Daniel Stinson
Daniel Stinson@shellcromancer·
LLMs are incredible for rubber-ducky debugging. As I type out my message to the homies Sonnet and Opus 4, explaining how things work, I often spot the bug and don’t have to waste tokens. 💡🦆 Saves me from the "You're absolutely right!" flattery
English
1
0
2
303
Daniel Stinson
Daniel Stinson@shellcromancer·
#id-provide-the-visibility-and-control-to-manage-and-harden-identities_id-1-allow-one-active-login-method-and-require-external-re-verification-to-change-to-another" target="_blank" rel="nofollow noopener">pushsecurity.com/blog/minimum-v… audit-logs.tax
ZXX
0
0
0
54
Daniel Stinson
Daniel Stinson@shellcromancer·
Great to see @PushSecurity reference to the audit-logs[.]tax site in their Minimum Viable Identity Security post🤌 If you're paying the tax for a site that's not listed yet, lmk and we can get them on there
English
1
0
1
127