RC RANDOM CHAOS

delegated trust

7 posts

Bearer tokens vouch for nobody
Article

Bearer tokens vouch for nobody

Alibaba's restriction of Claude Code exposes how OAuth 2.0 bearer tokens resolve a past verification instead of validating the entity acting now.

OAuth converts consent into standing permission
Article

OAuth converts consent into standing permission

OAuth 2.0 issues a token, not an identity. It verifies authority once at consent and honours the reference thereafter, without ever revalidating the grant.

Seizing the domains left the machine untouched
Article

Seizing the domains left the machine untouched

The FBI seizure of NetNut and the Popa botnet infrastructure exposes a structural fault in delegated trust: systems that resolve a reference but never revalidate what it points to.

When Broadcom bought VMware, Tesco moved 40,000 workloads
Article

When Broadcom bought VMware, Tesco moved 40,000 workloads

Tesco moving 40,000 workloads off VMware shows how systems execute on reference, not validation, and why inherited trust does not survive a change of owner.

The valet's key still opens your Civic
Article

The valet's key still opens your Civic

How a Honda Civic keeps granting access long after the conditions of trust expire, and why reference replaces verification across systems.

Nothing broke when your router died
Article

Nothing broke when your router died

Motorola's routers stopped as a class not from damage but because every device resolved a shared reference that no longer meant what it once did.

The trust contract just broke
Article

The trust contract just broke

Pentagon threat elevation exposes the federated identity flaw: signature checks do not evaluate issuer state. Trust without re-validation is not control.