Evidence receipt / belief
Published · transcript-backedNathan Labenz: belief
19 Apr 2026 The Cognitive Revolution Vibe-Coding an Attention Firewall, w/ Steve Newman, creator of The Curve
“I think you put your finger on something there that is like, I very much associate this style of thinking with you of kind of coming at it's and the, you know, it's in the title of the, of the Substack second thoughts as well, coming at these core questions from both perspectives.”
Source trail
Everything needed to verify it.
- Speaker
- Nathan Labenz
- Attribution
- Verified speaker
- Claim type
- belief
- Recorded
- 19 Apr 2026
- Publisher
- The Cognitive Revolution
Transcript context
…Yeah, and I hear you. And it's a great point about, you know, your data is also other people's data. And it's, yeah, like, The trade-off between security and utility is really building, right? Like, you know, like it's getting really, you know, the, you know, open claw and every, or I don't even remember what we're supposed to call it now. And, you know, and I keep waiting for a shoe to drop there. I keep waiting for the stories of people really regretting their, their life choices around, you know, and like, There's been the one or two anecdotes that circulate, but hardly anything. And you have to think those are juicy stories. And if people were really getting burned by prompt injection or whatever, or just bots deleting production databases, deleting your e-mail history or whatever. Again, there's one or two stories, but I've only seen a couple. So it's hard to explain why things aren't, there have been more problems other than Maybe it's harder to exploit this stuff than you'd think. And even, you don't have to have malicious problems. You can also just have sort of overeager bot problems. And I think probably part of it is the model developers and the tool developers are working, they're adding classifiers and whatever. I haven't followed it closely, but it feels like every new model report card says we've reduced prompt injection susceptibility by another X percent or whatever. Somehow we're keeping ahead of the curve. And yet at the same time, everyone agrees that fundamentally, this whole system is totally insecure and broken if you trust it with anything. And so I don't understand how that tension is going to resolve. I think this is going to be very interesting to keep following. But meanwhile, I kind of feel like the guy in Raiders of the Lost Ark, Asps, very dangerous, you go first. Yeah. Yeah. I mean, even this is happening at like every level, right? I mean, the, the model level, obviously with Mythos, we see greater utility, greater security concerns. When you give access to tools, it's the same thing. Even like upgrading software has suddenly become this kind of weird Damned if you do, damned if you don't, because you're like, well, there's supply chain attacks that are starting to get scary. So I've seen people say, don't update anything until the package is seven days old. But then the flip side of that is if we're patching critical vulnerabilities that just got discovered, you want those patches fast. And so now do I have to keep track of all these dependencies? What a nightmare. So yeah, I don't know. It is weird. I think you put your finger on something there that is like, I very much associate this style of thinking with you of kind of coming at it's and the, you know, it's in the title of the, of the Substack second thoughts as well, coming at these core questions from both perspectives. And just a lot of times seemingly we end up kind of confused. Like there's not great answers. We could probably touch on a number of those things as we go, but Is there, I mean, are we just in a, are you personally just in a total state of confusion when it comes to like, give, I mean, I think the security vulnerabilities are pretty real and pretty obvious. And we've even talked about this a little bit offline in terms of like, why aren't we seeing more phishing scams? I feel like I have seen a little uptake or uptick recently in a couple sophisticated, seemingly scammy emails coming my way, but not nearly as much as one might have thought. And the same thing is true with like election you know, deepfake things like, you know, that didn't really happen. Do you have a story for any of that, or are you just kind of still confused about it? Mostly confused. You know, it's, you know, I think you could argue that there's just sort of a lot of precedent that sort of bad guys can be just as slow to innovate and adopt as anyone else. And, you know, like, it's easy to... You know, it's easy to point back-- like, you know, in the-- I think it was in the '80s, the-- do you remember the Tylenol scare? There was this incident, I think, in the early '80s where someone, if I'm remembering correctly, put cyanide in a couple of pill bottles or a small number of containers of cyanide on store shelves. I don't remember whether they were tampering with them in the-- like, walked into the store and tampered there or exactly how it happened, but a handful of people fell ill. I think there were a couple of fatalities. And to this day, that's why so many products you buy have the safety seal on them, a little plastic wrap or whatever. And anyone could have done that at any point in the last however many hundred years. It didn't happen until the '80s, and then it happened once. It could still happen. There are plenty of things you buy at a store and put in your mouth that don't have that safety seal, whether it's produce or whatever. You know, there's just, you know, in every walk of life, there's sort of so much low-hanging harmful fruit that I don't entirely understand why most of these things don't happen. I'm glad that they don't. And so, you know, one theory is that just, you know, whatever complex sociological factors are going on there continue to apply here. Now, that's a little hard to completely believe in because we also have a lot of sort of opposite case studies in cybersecurity, like if a server is vulnerable to a well-known attack, some script kiddie is going to get in there, or some bot is going to get in there. There are definitely systematic bad things that happen on the internet, and going back decades, I think the statistic was like, if you just took an unpatched installation of Microsoft Windows and connected it directly to the internet, it would be owned within five minutes or something, that goes way, way, way back. So I don't know how to reconcile those two patterns of the world. And if anyone can shed light on this, I think that like I think it's a very important question to ponder, but I don't actually have any insight into it.…
Stored transcript either side of the excerpt. The highlighted words are the published quote; the surrounding text is unedited source, never generated.