Hook

Their other posts in the index, biggest breakout first.
APIs were built for trusted users. And what I mean by that is like they were meant to be used by engineers who know how to do engineering, they review each other's code. There's a whole bunch of rituals and processes that we've built over the last couple of decades. They rate limit a key, all that stuff. And underneath all that is human judgment. Good human judgment of people I trust, right? So if you wipe all that away, you've got a big problem. Because if you think about a typical API, for example, it's probably going to mix data that has very different levels of sensitivity. Like, I've got an HR system in our company. That HR system has a list of everybody and their time zone. That's really useful. It's also got, probably, I'm guessing, I'm not totally sure, but I think it has like their 401k contribution information or their health information. Probably not something people should have. I think we have to look at these agents as untrusted and even adversarial. How many people are reading this code? Or like, think about I think events of the last months with like OpenAI and the DoD, really tell us how little we really know about what's happening inside some of the models and the harnesses.