Evidence receipt / belief
Published · transcript-backedSteve Newman: belief
19 Apr 2026 The Cognitive Revolution Vibe-Coding an Attention Firewall, w/ Steve Newman, creator of The Curve
“You can also just have sort of overeager bot problems. And I think probably part of it is the model developers and the tool developers are working, they're adding classifiers and whatever.”
Source trail
Everything needed to verify it.
- Speaker
- Steve Newman
- Attribution
- Verified speaker
- Claim type
- belief
- Recorded
- 19 Apr 2026
- Publisher
- The Cognitive Revolution
Transcript context
…I'm not conservative by nature in general. I'd say I usually, um, my attitude on computer security has been historically borderline negligent over time. But this has changed my mindset. Like I definitely find myself being, I've always in the past been like, who really, do I really have anything that valuable? Or, you know, I'm not like a big target, who cares? But now it's like, I don't know, you know, as I give a, AI access to not just everything that I've ever written, but like everything anybody's ever sent me. You know, I feel like a certain kind of duty of care to guard their information, you know, that they trusted me with and never really thought that it was going to be going into some AI that hadn't even been contemplated at the time that it was sent in some, you know, I've had my same Gmail account for 20 years. So that definitely has caused me to slow down and take a more deliberate approach to try to figure out, like, under what circumstances do I give how much access and when do I want the thing to kind of draft something for me versus when do I think it might be more helpful for it to try to play the role of an assistant? And I'm definitely still feeling my way through a lot of that stuff as well. But it is striking that I'm like compelled to, I feel compelled to take my time when usually I would just sign up and let it rip on just about any other software experience in the past. Yeah, and I hear you. And it's a great point about, you know, your data is also other people's data. And it's, yeah, like, The trade-off between security and utility is really building, right? Like, you know, like it's getting really, you know, the, you know, open claw and every, or I don't even remember what we're supposed to call it now. And, you know, and I keep waiting for a shoe to drop there. I keep waiting for the stories of people really regretting their, their life choices around, you know, and like, There's been the one or two anecdotes that circulate, but hardly anything. And you have to think those are juicy stories. And if people were really getting burned by prompt injection or whatever, or just bots deleting production databases, deleting your e-mail history or whatever. Again, there's one or two stories, but I've only seen a couple. So it's hard to explain why things aren't, there have been more problems other than Maybe it's harder to exploit this stuff than you'd think. And even, you don't have to have malicious problems. You can also just have sort of overeager bot problems. And I think probably part of it is the model developers and the tool developers are working, they're adding classifiers and whatever. I haven't followed it closely, but it feels like every new model report card says we've reduced prompt injection susceptibility by another X percent or whatever. Somehow we're keeping ahead of the curve. And yet at the same time, everyone agrees that fundamentally, this whole system is totally insecure and broken if you trust it with anything. And so I don't understand how that tension is going to resolve. I think this is going to be very interesting to keep following. But meanwhile, I kind of feel like the guy in Raiders of the Lost Ark, Asps, very dangerous, you go first. Yeah. Yeah. I mean, even this is happening at like every level, right? I mean, the, the model level, obviously with Mythos, we see greater utility, greater security concerns. When you give access to tools, it's the same thing. Even like upgrading software has suddenly become this kind of weird Damned if you do, damned if you don't, because you're like, well, there's supply chain attacks that are starting to get scary. So I've seen people say, don't update anything until the package is seven days old. But then the flip side of that is if we're patching critical vulnerabilities that just got discovered, you want those patches fast. And so now do I have to keep track of all these dependencies? What a nightmare. So yeah, I don't know. It is weird. I think you put your finger on something there that is like, I very much associate this style of thinking with you of kind of coming at it's and the, you know, it's in the title of the, of the Substack second thoughts as well, coming at these core questions from both perspectives. And just a lot of times seemingly we end up kind of confused. Like there's not great answers. We could probably touch on a number of those things as we go, but Is there, I mean, are we just in a, are you personally just in a total state of confusion when it comes to like, give, I mean, I think the security vulnerabilities are pretty real and pretty obvious. And we've even talked about this a little bit offline in terms of like, why aren't we seeing more phishing scams? I feel like I have seen a little uptake or uptick recently in a couple sophisticated, seemingly scammy emails coming my way, but not nearly as much as one might have thought. And the same thing is true with like election you know, deepfake things like, you know, that didn't really happen. Do you have a story for any of that, or are you just kind of still confused about it?…
Stored transcript either side of the excerpt. The highlighted words are the published quote; the surrounding text is unedited source, never generated.