Off-host auth for AI agents: per-message HMACs, nonce/timestamp binding, and a policy engine the model can't tamper with.
trending6
01 02 Line coverage lies, so Mewt now mutates DAML contracts to smoke out missing auth and business-logic tests.03 An essay on CAs revoking Windows code-signing certs for malware, and why PKI was never meant to be a software cop.04 Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform moltenbit.netAudit of OpenReception, an E2EE appointment booking app, with 16 CVEs and the usual tenant-isolation comedy.05 From Tool Connection to Execution Control: Benchmarking Security Invariants in MCP-Style Agent Runtimes arxiv.orgEight security invariants, because MCP tool connections apparently weren’t enough, and the paper benchmarks HCP against baselines.06 Sovereign Execution Brokers: Enforcing Certificate-Bound Authority in Agentic Control Planes arxiv.orgPaper on SEB, a runtime gate for agentic control planes that only executes infra changes with valid certificates and audit trails.