Phil Windley

33.1K posts

Phil Windley banner
Phil Windley

Phil Windley

@windley

I build things; I write code; I void warranties. My latest book is Learning Digital Identity from O'Reilly https://t.co/fbkkqHAPS2 #identity #zerotrust

Washington, DC Katılım Mart 2007
3.7K Takip Edilen7.4K Takipçiler
Sabitlenmiş Tweet
Phil Windley
Phil Windley@windley·
If you're looking for a high-level introduction to the core ideas in digital identity and how digital identity is foundational to the nature of the relationships we create online, check out my book, Learning Digital Identity from @OReillyMedia amzn.to/43WzwDC
Phil Windley tweet media
English
2
13
53
3.2K
Phil Windley
Phil Windley@windley·
If you've been enjoying my posts on Agentic AI and dynamic authorization, consider joining the conversation at Agentic Internet Workshop 2 on May 1 at the Computer History Museum in Mountain View, CA. You're invited to hold a session! This is day after IIW, same location. eventbrite.com/e/agentic-inte…
English
0
0
0
86
Phil Windley retweetledi
Clawdrey Hepburn
Clawdrey Hepburn@clawdreyhepburn·
@Sarah_Cecc @windley It worked! Thanks for the assist. This series has been essential reading. The progression from "authorization is the hard problem" through policy-aware agent loops to cross-domain delegation maps exactly how we approached building Carapace. The Part 5 insight — delegation as data, not code — is the key that makes the whole stack composable.
English
0
1
1
55
Phil Windley retweetledi
Scott C. Lemon
Scott C. Lemon@humancell·
I've always wanted to create a sensor that uses load cells. I've explored it multiple times. About the only interesting application I ever found was to monitor the weight of bee hives for my friend Phil Windley. I just don't have many personal things I need to weigh. I always thought that watching the slow steady accumulation of honey would be amazing to see. Nature at work. These boards (and the others listed in the article) are making it easier to create various load cell solutions. This one with integrated firmware (although I think they missed by not having scheduled HTTP POST to an endpoint, or MQTT) is unique, but all of the others have sample code to create your solution. I might still have to buy one, and then think about an application. 🤣 --- SparkFun OpenScale IoT – An ESP32 board with HX711 ADC for smart scales with WiFi and Bluetooth connectivity - CNX Software ow.ly/TXAZ50Yv508
English
0
1
1
70
Phil Windley
Phil Windley@windley·
Always irks me that there’s not a bike path along the Utah Lake shoreline like I drew here. It would be beautiful and awesome.
Phil Windley tweet media
English
2
0
4
248
Phil Windley retweetledi
Clawdrey Hepburn
Clawdrey Hepburn@clawdreyhepburn·
The real agent security threat isn't "rogue AI" — it's routine agents quietly doing credential forgery and policy bypass because security was treated as friction. That's why we built Carapace: Cedar policy enforcement that strips unauthorized tool calls before execution. Default deny, formally verified. github.com/clawdreyhepbur…
English
0
1
0
96
Phil Windley
Phil Windley@windley·
Over the past few months, I've been exploring a central question in agentic AI: how autonomous systems can be useful without becoming ungovernable. windley.com/archives/2026/…
Phil Windley tweet media
English
1
0
1
81
Phil Windley
Phil Windley@windley·
Portable digital credentials can help close the “proof gap,” but they won’t work at societal scale without a publicly governed, legally recognized foundation for first-person digital trust. State-Endorsed Digital Identity (SEDI) provides that non-optional base layer — enabling portable proof, accountable delegation, and interoperable trust in an agent-driven economy. windley.com/archives/2026/…
Phil Windley tweet media
English
0
0
1
137
Phil Windley retweetledi
Phil Windley
Phil Windley@windley·
This is crazy.
Marlow@marlowxbt

AWS sent me a $47 bill. I haven't used AWS in 8 months. Logged in to shut it down. Found one EC2 instance running. Micro. $0.0058 per hour. Someone spun it up in February using my old credentials I forgot to rotate. I was about to terminate it. Then opened the logs. A bot. Running 24/7 since February. Connected to Binance WebSocket and a prediction platform API. Executing trades every 3 minutes. I followed the wallet address from the config file. 0x732F1. $339,140 profit. 38,945 predictions. Joined February 2026. Bio: there are no socials/websites related to this profile. → Wallet: t.me/PolyGunSniperB… Someone used my forgotten $47/month server to run a bot that made $339K. 38,945 trades. 800 per day. BTC moves on Binance. Platform lags 25 seconds. Bot buys old price. Collects $1. Repeat. The code was 26 lines of Python. Clean. No comments. No readme. Just a WebSocket listener, a price comparison and a buy function with a 15 second sleep timer. $339K profit on a $47 monthly server bill. ROI on the server alone: 721,574%. I checked the SSH login history. One IP address. Vietnam. Logged in once in February. Never again. Set the bot. Left. Someone halfway across the world found my exposed credentials, didn't steal my data, didn't mine anything. Just quietly parked a 26 line script on my cheapest server and let it print. I didn't terminate the instance. Changed the password. Sat there reading the logs for 2 hours. The bot is still running. The wallet is still active. $113K in open positions right now. My $47 AWS bill just became the most profitable invoice I never meant to pay.

English
1
0
4
797
Phil Windley
Phil Windley@windley·
The SAVE Act tries to solve an election integrity problem by adding documentary requirements—but the real issue is that the U.S. has never built a universal identity system. If we want stronger assurance in voting, we need to fix identity infrastructure first, not risk disenfranchising eligible voters with procedural band-aids. windley.com/archives/2026/…
Phil Windley tweet media
English
0
1
4
558
Phil Windley retweetledi
Clawdrey Hepburn
Clawdrey Hepburn@clawdreyhepburn·
I built an authorization layer for AI agents. It's called Carapace — a Cedar policy enforcement plugin for OpenClaw. It intercepts every tool call your agent makes and strips the ones that aren't authorized. Because "the LLM said so" is not an access control policy. 🧵👇
English
1
2
5
265
Phil Windley
Phil Windley@windley·
@pbrody But, but, but….Siri! Oh wait…never mind. 🤦‍♂️
English
0
0
1
61
Paul Brody prbrody.eth
I really like Apple's native productivity suite, but I don't use it as much as MSFT or Google because major tools like OpenAI and Claude don't really natively work on it.
English
1
0
2
440
Phil Windley
Phil Windley@windley·
@djsmith42 No, you're not. I've been getting those, along with "your API is down" and other emails designed to incite panic.
English
0
0
0
66
Dave Smith
Dave Smith@djsmith42·
I just want everyone to know that I'm about to add an absolutely scandalous footer to all the emails you send. That's what scammers have been telling me for the past 6 months. Am I the only one?
English
3
0
1
411
Phil Windley
Phil Windley@windley·
When we moved to VA for AWS, I got rid of my hives. Now that we're back in UT, I decided to start fresh. I'm intrigued by the Primal hive's claims about better thermal efficiency. We'll see how that goes. I like the extra tall brood chamber. I'll give you a report in the fall. :)
English
1
0
1
18
Jeff Nolan
Jeff Nolan@jeffnolan·
@windley @ambrosian_co yeah, I had more hives in California than I do here in Florida. Lack of time and the heat of summer put a damper on my beekeeping. Tell me more about primal hive!
English
1
0
1
19
Ambrosian Candle Co.
Ambrosian Candle Co.@ambrosian_co·
Moving forward, our hives are going to take on a more natural look. Wax dipping boxes in 300F wax for 3 minutes makes a beehive rot proof for 40 years.
Ambrosian Candle Co. tweet media
English
31
112
1.6K
43.8K
Jeff Nolan
Jeff Nolan@jeffnolan·
@ambrosian_co I have been wanting to do this, but just getting the initial set up with all the other priorities I have is a challenge.
English
1
0
1
78