The a16z Show

Snapshot · The a16z Show

The Reality of AI-Powered Cyberattacks | Truffle Security & Socket

Explore episode Aug 7, 2026

Where this was said

Credential Spread and Blast Radius Limitation

At 16:01 · chapter starts 14:30

Having established how worms get in, Dylan Ayrey now interrogates what happens next. The post-install hook's first job is credential harvesting — and credentials are everywhere on developer machines precisely because the tools that need them put them there deliberately. npm writes a credential to a known location. AWS CLI writes one too. That's not a bug; that's how these tools function. Even enterprise-grade secrets managers create the same problem at one level of abstraction higher: the credential to access HashiCorp Vault or 1Password still lives somewhere on the endpoint. Ayrey asks Feross directly how to limit the blast radius and prevent lateral movement once that first credential is stolen — a candid admission that this problem does not yet have a clean solution.

Similar snapshots