RC RANDOM CHAOS

access control

44 posts

A managed endpoint no longer bounds insider exposure.
Article

A managed endpoint no longer bounds insider exposure.

Apple Intelligence on Mac acts within existing user access with no confirmed runtime monitoring, creating an insider exposure the board must constrain now.

Your telemetry toggle was a file access control
Article

Your telemetry toggle was a file access control

Claude Code read AGENTS.md only when telemetry was on. Binding access to a diagnostic flag breaks least privilege. The fix closed the instance, not the class.

Every Prompt Is A Retrieval Request
Article

Every Prompt Is A Retrieval Request

Meta's Muse returned 6.8GB when asked for its filesystem. The response channel serviced a request for internal data with no enforcement at the boundary.

Two failures are not one attack.
Article

Two failures are not one attack.

A heap overflow and SSO misconfiguration compromised OpenAI internal repos. Two controls named as present, neither enforced in effect.

Baseten lost production GitHub admin in 25 minutes
Article

Baseten lost production GitHub admin in 25 minutes

Admin access to Baseten's production GitHub was reached in 25 minutes. A briefing on the identity boundary that failed and what the number means.

Every new feature makes iOS 27 less safe
Article

Every new feature makes iOS 27 less safe

iOS 27, iPadOS 27, and macOS 27 concentrate risk at one point: whether a capability re-checks identity at execution, not at the moment consent was captured.

You depended on access you never owned.
Article

You depended on access you never owned.

Google's anti-scraping update changed a control scrapers never owned, exposing the structural risk of building on an interface you cannot see or govern.

Chrome exempts Google's domains from user site-data controls
Article

Chrome exempts Google's domains from user site-data controls

Chrome does not enforce user site data settings against Google-owned domains. What the exempt scope means and how to treat the control.

The system ran one veteran 100 times
Article

The system ran one veteran 100 times

One person was queried 100+ times in a Flock tracking system. When identity is the only enforced gate, abuse completes exactly like legitimate use.

Verification became the leak
Article

Verification became the leak

An unauthorized live feed of every ID verification let attackers bypass MFA for over a year. Why readable verification output stops being proof.

Nobody had to hack your meetings.
Article

Nobody had to hack your meetings.

Over 180,000 tl;dv meetings were left open because access to recorded content was not conditioned on validated identity. What that failure exposes.

The record is the authority
Article

The record is the authority

A for-sale DNS record sells naming authority itself, and every control above DNS keeps validating the name for whoever now holds the record.