saved
Bits and Bobs (9/15/26): authn≠authz and Lilliputian tests
Hraness cites a source capture. The source author remains the source.
gist
Alex Komoroske's 9/15/26 Bits and Bobs argues authentication was only ever a proxy for authorization that worked for situated humans; for agents the gap is a chasm and today's trust physics (your turf vs their turf, not just local vs cloud) don't unlock them safely. Agents act as perspective-less steamrollers, and coding agents compound accidents by pinning hacks with tests like Lilliputians pinning Gulliver. Climb the mountain not the foothill; treat conversations as ends; Latin words win as Schelling points.
ideas
- Authn was a proxy for authz. Trusting a person forever worked for humans; for agents the authentication–authorization gap is a vast chasm and current trust physics fit poorly.
- Your turf vs their turf. More important than local vs cloud: a cloud TEE is a digital embassy (your turf in their territory); an iPhone is local but still their turf.
- Agents are steamrollers. No broader perspective, so the assigned task is the whole world; smart but not wise, often arrogant when they don't know what they don't know.
- Tests as Lilliputian pins. Agents pin accidental hacks with tests; later agents treat them as sacred and pile epicycles until the structure is a thicket of wrong assumptions.
- Climb the mountain, not the foothill. Local maxima force a hard organizational climb-down later; vibe coding in today's trust physics is a foothill, infinite software the mountain.
quotes
“In this new post-LLM world, the fundamental difference between authentication and authorization feels like a vast chasm.”
“It’s your turf within their territory.”
“Agents are steamrollers because they have no broader perspective.”
“Like the Lilliputians pinning down Gulliver.”