Agent-era security needs customer keys, proof-of-presence, and hardware-backed identity
dhadfieldmenell · x · 2026-07-23
A security-first take on defending software in an agentic world:
- The post argues that application development has drifted too far toward convenience, while attackers are now willing to expend extreme effort.
- It recommends defaulting to customer-managed keys, decrypting at the point of use, and checking proof-of-presence at every authorization boundary close to the data or operation.
- It also calls for hardware memory encryption by default and a move away from symmetric keys toward hardware-backed keys, including for worker identity.
- The quoted line frames this as long-overdue cyber hardening: the “best” time was 30 years ago, and the next best time is now.
More from AGI Musings
- A proof prompt should restate the problem, list traps, and call in adversaries — burny_tech · 2026-07-23
- ChatGPT adoption could make developer experience everyone’s experience — jxnlco · 2026-07-23
- Investor says Google’s Gemini and DeepMind are too central to lose compute priority — firstadopter · 2026-07-23
- AGI-era retreat idea: islands where AI is banned to force hardship and human relationships — SuperbRiver7763 · 2026-07-23
- Liang Wenfeng’s cash-flow-backed AGI bet is a business model few founders can copy — yongqianme · 2026-07-23
- Multiple LLMs on one project start treating collaboration structure as a core feature — repligate · 2026-07-23