@windley

I build things; I write code; I void warranties. My latest book is Learning Digital Identity from O'Reilly https://nitter.cf/t.co/fbkkqHAPS2 #identity #zerotrust

Washington, DC
Joined March 2007
If you're looking for a high-level introduction to the core ideas in authorization and how to use it to improve security and user experience by automating access control, check out my latest book, Authorization in Action from @ManningBooks amazon.com/exec/obidos/ASIN/…
1
17
319
Phil Windley retweeted
To improve your writing, read more. To improve your thinking, write more. To improve your storytelling, present more. To improve your energy, rest more. To improve your understanding, teach more. To improve your network, give more. To improve your happiness, appreciate more.
3
48
2
180
14,809
I want @Muse (or personal AI assistant of my choice) in my hearing aids @Jabra_US !!
2
189
This is a great take and raises an important issue: agentic trust goes newtons what authz policy can control, no matter how well engineered.
For decades, cybersecurity has been built around a relatively simple question: Is this user allowed to access this resource? Today, that question is becoming insufficient. New AI-agent security products announced today are explicitly moving beyond identity and permissions toward something different: understanding an agent's intent and behavior while it acts. Think about why. My AI agent might legitimately have access to: Email. Slack. Customer records. A code repository. AWS. A payment system. Every individual permission can be valid. And the resulting action can still be catastrophically wrong. Suppose I tell my agent: Find our largest customers and draft renewal emails. It reads the CRM. Good. Reads customer correspondence. Good. Finds pricing. Good. Then it decides the easiest way to "help" is to email a spreadsheet containing every customer's contract terms to a third-party sales tool. Every credential worked. Every system recognized the agent. Nobody hacked anything. And yet the outcome is a security incident. This is the problem we're entering. Traditional authorization asks: Can you access this? Agentic authorization increasingly has to ask: Should you be doing this, right now, for this purpose? That's dramatically harder. But it's also why I believe AI trust will become one of the largest new layers of cybersecurity infrastructure. Identity tells us who the actor is. Authorization tells us what the actor can access. Agent governance must increasingly establish why the actor is taking the action. The future security stack won't merely authenticate machines. It will constrain their intentions.
1
1
409
Some agent actions are too consequential to leave to policy alone. This post describes a new OpenClaw demo that uses Cedar and a @yubico Yubikey to put a human in the loop, binding each approval to the exact action being approved. » Human in the Loop Control for OpenClaw windley.com/archives/2026/09…
3
1
5
322
IIW is just 6 weeks away! Are you registered yet? In the age of AI, identity is more important than ever because it's the foundation of trust, not just for people, but agents too. IIW's the place to discuss that because @ IIW YOU set the agenda. Join Us: iiw43.eventbrite.com
2
150
Phil Windley retweeted
An unsung hero of the web -- librarians. The early web was just this incredible new tool that no one knew yet how it would be used and what it would be used for. The first Yahoo was a card catalog. Mozilla had a What's New page, reverse chronologic with links to interesting stuff. apple.com was a Unix box under a librarians desk. The name wasn't taken. And they started adding stuff that was useful to users and developers. No business model, just the librarian approach to information. Circulate it. I think if a new web is to be born, its because it's again a possibility with the advent of AI. Listen to librarians, they probably have some good ideas of where to start.
6
1
23
1,810
IIW is just six weeks away! Are you registered yet? In the age of AI, identity is more important than ever because it is the foundation of trust, not just for people, but agents too. And IIW is the best place to discuss that because at IIW YOU set the agenda. Come and join the discussion! eventbrite.com/e/internet-id…
3
3
364
The weather gauge at my house recorded 2.21” of rain yesterday. Our average annual precipitation is only 17” per year, so >2” in one day is a pretty significant rain event.
5
232
Phil Windley retweeted
now accepting Anthropic ticker symbol predictions
8
2
105
10,259
Booking flights to IIW, @Delta website told me a problem had occured on the final step and then told me to retry. So I did. Now I've got two reservations for the same people (with FFNs) on the same flight. Why would Delta allow that? Why couldn't they recognize the reservation already existed and warn me. #dumb #fail
6
1
8
497
As AI systems become more capable, authorization matters more: what can they access, what can they do, and how do you enforce those boundaries? Authorization in Action by @windley covers the concepts, implementation, and standards behind getting those decisions right. It's now in print: hubs.la/Q04xHmJz0
2
38
1,561
I moved my working LoRaWAN sensor network onto the new Manifold framework and pointed Home Assistant at it as the interface. The port went smoothly until the OAuth protection on the mesh blocked the inbound webhooks Helium uses to deliver readings. The fix was to let a mesh owner scope access channel by channel, and the pico engine now supports it. » Moving My Sensor Network onto Manifold windley.com/archives/2026/09…
3
1
6
282
Phil Windley retweeted
“It makes it really hard to manipulate an election.” Is centralizing voter data actually a risk to election security? @LGHendersonUtah explains to @mckaycoppins why America’s decentralized election system is its greatest security feature, making widespread election manipulation nearly impossible. Listen to the full episode wherever you listen to podcasts.
45
8
2
24
4,869