Shivasurya

4.3K posts

Shivasurya banner
Shivasurya

Shivasurya

@sshivasurya

senior software engineer | security + AI | @UWaterloo @Dropbox @Zoho alum | building https://t.co/bMnGeuZ1tX | 🍁 🇨🇦

Waterloo, Ontario Katılım Haziran 2013
441 Takip Edilen705 Takipçiler
Sabitlenmiş Tweet
Shivasurya
Shivasurya@sshivasurya·
Excited to demo codepathfinder.dev at DevTools Toronto 🇨🇦 during Toronto Tech Week next month. What started as a side project from my @Zoho days is now deterministic dataflow infra for security/vulnerability analysis in the AI-coding era. If you're into static code analysis & code intelligence, come say hi 👋 luma.com/v2hcabxq?tk=pO…
Shivasurya tweet media
English
1
3
14
1.2K
Aiden Bai
Aiden Bai@aidenybai·
TIL "strings" are valid for method names in JavaScript
Aiden Bai tweet media
English
41
8
630
51.1K
Shivasurya
Shivasurya@sshivasurya·
@rydercalmdown I expected home full of smoke with the current state of GitHub! 😂
English
0
0
0
18
Tyler Holmwood
Tyler Holmwood@tyholms·
One researcher. ~$300 in API tokens. A working PoC against an April Patch Tuesday CVE. Open-sourcing PatchWatch + Pocsmith, an agentic patch-diffing → exploit pipeline I built from off-the-shelf parts. originhq.com/blog/patch-dif…
English
2
38
141
8.8K
Andras Bacsai
Andras Bacsai@heyandras·
We made a fake repo with fake bounties, and the bots are applying fake PRs, so we know who is fake, and we can ban them from the Coolify repo. IQ over 1000
Andras Bacsai tweet mediaAndras Bacsai tweet media
English
196
498
10.5K
490.3K
Shivasurya
Shivasurya@sshivasurya·
Literally every AI-Native Appsec/Offsec tooling vendor blog post be like 😆
Shivasurya tweet media
English
0
1
3
90
Steve Hanov
Steve Hanov@smhanov·
Wat if we turned MC *back* into a data centre
Steve Hanov tweet media
English
4
0
11
1.1K
Shivasurya retweetledi
Mira Murati
Mira Murati@miramurati·
Today we're sharing our work on interaction models. A new class of model trained from scratch to handle real-time interaction natively, instead of gluing it onto a turn-based one. youtu.be/A12AVongNN4
YouTube video
YouTube
English
318
934
8.9K
1.1M
Shivasurya
Shivasurya@sshivasurya·
@atmoio Omg lol 😂 I couldn't stop laughing!
English
0
0
2
40
Mo
Mo@atmoio·
The Unethical Guide to Surviving AI Layoffs
Brian Armstrong@brian_armstrong

This is an email I sent earlier today to all employees at Coinbase: Team, Today I’ve made the difficult decision to reduce the size of Coinbase by ~14%. I want to walk you through why we're doing this now, what it means for those affected, and how this positions us for the future. Why now Two forces are converging at the same time. We need to be front footed to respond to both. First, the market. Coinbase is well-capitalized, has diversified revenue streams, and is well-positioned to weather any storm. Crypto is also on the verge of the next wave of adoption, with stablecoins, prediction markets, tokenization, and more taking off. However, our business is still volatile from quarter to quarter. While we've managed through that cyclicality many times before and come out stronger on the other side, we’re currently in a down market and need to adjust our cost structure now so that we emerge from this period leaner, faster, and more efficient for our next phase of growth. Second, AI is changing how we work. Over the past year, I’ve watched engineers use AI to ship in days what used to take a team weeks. Non-technical teams are now shipping production code and many of our workflows are being automated. The pace of what's possible with a small, focused team has changed dramatically, and it's accelerating every day. All of this has led us to an inflection point, not just for Coinbase, but for every company. The biggest risk now is not taking action. We are adjusting early and deliberately to rebuild Coinbase to be lean, fast, and AI-native. We need to return to the speed and focus of our startup founding, with AI at our core. What this means To get there, we are not just reducing headcount and cutting costs, we’re fundamentally changing how we operate: rebuilding Coinbase as an intelligence, with humans around the edge aligning it. What does this mean in practice? - Fewer layers, faster decisions: We are flattening our org structure to 5 layers max below CEO/COO. Layers slow things down and create coordination tax. The future is small, high context teams that can move quickly. Leaders will own much more, with as many as 15+ direct reports. Fewer layers also means a leaner cost structure that is built to perform through all market cycles. - No pure managers: Every leader at Coinbase must also be a strong and active individual contributor. Managers should be like player-coaches, getting their hands dirty alongside their teams. - AI-native pods: We’ll be concentrating around AI-native talent who can manage fleets of agents to drive outsized impact. We’ll also be experimenting with reduced pod sizes, including “one person teams” with engineers, designers, and product managers all in one role. In short: AI is bringing a profound shift in how companies operate, and we’re reshaping Coinbase to lead in this new era. This is a new way of working, and we need to leverage AI across every facet of our jobs. To those who are affected I know there are real people behind these decisions — talented colleagues who have poured themselves into this company and our mission. To those of you who will be leaving: thank you. You’ve helped build Coinbase into what it is today, and I am sincerely grateful for everything you've done. All impacted team members will receive an email to their personal account in the next hour with more information, and an invitation to meet with an HRBP and a senior leader in your organization. Coinbase system access has been removed today. I know this feels sudden and harsh, but it is the only responsible choice given our duty to protect customer information. To those affected, we will be providing a comprehensive package to support you through this transition. US employees will receive a minimum of 16 weeks base pay (plus 2 weeks per year worked), their next equity vest, and 6 months of COBRA. Employees on a work visa will get extra transition support. Those outside of the US will receive similar support, based on local factors and subject to any consultation requirements. Coinbase prides itself on talent density. Our employees are among the most talented people in the world, and I have no doubt that your skills and experience will be highly sought after as you pursue your next chapters. How we move forward To the team that is staying, I know this is a difficult day. We’re saying goodbye to colleagues and friends you've been in the trenches with. But here’s what I want you to know as we move forward together: Over the past 13 years, we have weathered four crypto winters, gone public, and built the most trusted platform in our industry. We’ve made it this far by making hard decisions and by always staying focused on our mission. This time will be no different – nothing has changed about the long term outlook of our company or industry. And most importantly, our mission has never been more important for the world. Increasing economic freedom requires a new financial system, and we’re building it. The Coinbase that emerges from this will be more capable than ever to achieve our mission. Brian

English
355
1K
13K
1.8M
trish
trish@TrisH0x2A·
SQLite is used in every iPhone every Android every browser every airplane and every car with software it is maintained primarily by Richard Hipp who started it in 2000 because he needed a database that did not need a server the entire codebase is around 150000 lines and many large teams have not shipped anything as reliable the most widely deployed database on earth built by a small core team with no traditional VC model or hype
English
29
68
1.1K
189.3K
Shivasurya
Shivasurya@sshivasurya·
@smhanov Pinged you with a pass! 🎉 Happy coding!
English
0
0
1
24
Steve Hanov
Steve Hanov@smhanov·
Do I know 51 more people with 7 day claude code passes?
English
1
0
2
167
Guy Spier 🇮🇱 🇺🇦 🇨🇭🇬🇧🇮🇷🇦🇪
"If you have to walk through the streets crying for a few hours every day as part of soldiering through then go ahead and cry away." But you can't quit. Post my GBM / glioblastoma diagnosis I understand Charlie Munger's words so much better that I did before. "The iron rule of life is that everybody stuggles. Everybody has some tough stretches." CNBC Cures.
True market Leader@TmarketL

Charlie Munger reflects on death, struggle, and how he found strength to move forward. This timeless advice can help anyone facing tough times

Zurich, Switzerland 🇨🇭 English
45
91
843
133.1K
Justin Schroeder
Justin Schroeder@jpschroeder·
The *entire* history of AI coding in one chart.
Justin Schroeder tweet media
English
35
24
645
70.4K
Shivasurya
Shivasurya@sshivasurya·
@TheGeorgePu Is Quora and Poe chat still being used? Seems like nobody uses it
English
0
0
1
298
George Pu
George Pu@TheGeorgePu·
Four board members voted to fire Sam Altman. One had Thanksgiving dinner with him six days later. Altman called it 'really nice.' His name: Adam D'Angelo. He voted to fire Altman on November 17. He negotiated Altman's return on November 22. He sat across from him at dinner on November 23. Two and a half years later. D'Angelo is still on OpenAI's board. The other three who voted with him are gone. Every question about that week. The same answer. 'I just can't talk about any of this stuff.' He didn't pick a side. He became the side that survived.
English
4
1
84
14.9K
Shivasurya
Shivasurya@sshivasurya·
@m4rio_eth - needs Wireless ADB enabled on target I think it's disabled by default developer mode
English
1
0
21
864
m4rio
m4rio@m4rio_eth·
Android just patched a critical zero-click RCE. CVE-2026-0073 affects the Android System component, specifically `adbd`, and can reportedly lead to remote code execution with no user interaction required. No tap. No download. No “open this file.” The attacker only needs to be nearby or on the same local network, which makes this especially relevant for places like airports, conferences, hotels, offices, and shared Wi-Fi environments. The `adbd` part is what makes this interesting. This is the Android Debug Bridge daemon used for device communication and debugging workflows, not some random app-level component. Reports say Android 14, 15, 16, and 16-QPR2 are affected. source.android.com/docs/security/…
m4rio tweet media
English
8
35
169
18.2K
Shivasurya retweetledi
Ben Vinegar
Ben Vinegar@bentlegen·
In 3 weeks at @devtoolsTO: @tracesdotcom - share agent coding sessions @polarityco - sandboxes for agent testing @super_user_app - agents in your team chat Tidra - AI code maintenance at scale Docsalot - docs agents can read Code Pathfinder - trace vulns across your codebase
Ben Vinegar tweet media
English
4
7
22
2K
Calif
Calif@calif_io·
Google paid us $57,000 for two bugs in Chrome. We’re not doing this for the bounty, but it’s always fun to get rewarded. These bugs were found using nothing fancier than a $20/month AI subscription. If you’re curious, come check out our talk at the Real World AI Security Conference at Stanford: seclab.stanford.edu/RealWorldAIsec/ We haven’t published the Chrome bugs in our MAD Bugs series. They work better as part of something even more fun, stay tuned!
Calif tweet media
English
19
99
1.1K
76.9K