Security Architects
  • Services
  • About
  • Vintage
  • Contact
  • Privacy Policy
  • News
  • Products

News

Announcements and research commentary from Security Architects.

July 21, 2026

Introducing Cone of Silence: hardened agent pods

Today we’re opening early access to Cone of Silence — agent pods secure enough for the original Chief and Agent.

A pod is your own always-on AI agent: Claude, working for you around the clock on a dedicated, hardened machine, reachable from your phone over Telegram. Message it like a person; it reads, researches, codes, and runs real tools — while everything it touches stays inside a security boundary we built and operate.

read more
July 18, 2026

Tens of thousands of exposed AI agents — sandboxing must be the default

The always-on personal AI agent is the most exciting thing happening in computing right now — and the most exposed. Between late January and early February of this year, Bitsight’s internet-scale scanning observed more than 31,000 distinct exposed instances of the most popular personal-agent stack, listening on its default port across technology, healthcare, finance, government, and insurance networks. Independent scanning teams reported even larger numbers, including thousands of instances vulnerable to remote code execution.

read more
July 14, 2026

Authinator3 is now open source

We’ve published the core of Authinator3 as open source under the ISC license: gitlab.com/jowolf/authinator3.

Authinator is a web login gateway for firewalls. Authenticate over HTTPS, click once, and your current IP address is granted passage through the firewall — everyone else sees a wall. It replaces both permanently-open management ports and brittle port-knocking schemes with something anyone can operate from a phone: a login page.

Authinator has guarded our own production gateways in one form or another since 2007. Authinator3 is the modernized cross-platform release: a single self-contained Go binary per platform, driving OpenBSD pf tables (confined by pledge/unveil, no sudo, no shell calls) or Linux nftables sets (under a locked-down systemd service). Default-deny, explicit allow, with an audit view of every address currently cleared through.

read more
© Security Architects 2026