01
Edition
05
picks
Four hundred thousand approval clicks say the gate doesn't work.
Four hundred thousand approval clicks say the gate doesn't work. In May a developer shipped a 60-second browser game about agent permission fatigue; it hit our pool on 05-29 and again on 05-30, and 40,000 people played it. Today he published what they did: 409,000 approve/deny decisions, roughly a third of the commands planted as threats, mean accuracy 66.3%. The shape of the failure is the story. Players caught `rm -rf /` 88% of the time and missed a third of the exfiltration attempts and 35% of the scope violations — the agent quietly reading a credentials file is the single thing humans are worst at spotting, and it is also the single thing a permission prompt exists to show them. Today's picks are four ways of moving that decision away from the moment: keep the click but make it survive a process restart (Channels SDK), swap the human's review for a deterministic one with a tree hash attached (HAR), delete the credential so the worst-missed category has nothing to reach for (wigolo), and delete the trust entirely in favor of a hardware attestation (Popcorn, the kicker). The day's #1 story was an essay about Pareto fronts and Mario (1,053 points, dropped per rubric), AMD bought Taalas for 698 points of news, and the study's own author supplied the note's thesis in his own thread: "We can't point to it as a valid solution."
02
HAR — a tree hash instead of your word for it
03
wigolo — the key your agent can't leak
04
Popcorn — nobody approves anything, the hardware just testifies
05
One of these,
every weekday.
Free. Unsubscribe by replying with one word. No tracking pixels in the email.