Wednesday, October 7, 2026ArchiveSearchAsk the paper

The Computomatix Times

All the posts fit to save — curated from @computomatix's bookmarks & likes on X

Edition of Sunday, April 19, 2026

9 stories

Guide Explains How to Triage Compromised Google Workspace OAuth App

Omar shares steps for Google Workspace admins to check for a compromised third-party OAuth app tied to the Vercel incident. The instructions cover navigating admin API controls and revoking access by client ID.

Original post · 1 min read
Here's how to triage:

1. Go to admin.google.com

2. Security → Access and data control → API controls → App access control → Manage Third-Party App Access

3. Search for client ID:
110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj

if found → revoke / block
Vercel @vercel
Our investigation has revealed that the incident originated from a third-party AI tool with hundreds of users whose Google Workspace OAuth app was compromised.

We recommend that Google Workspace Administrators check for usage of this app immediately. vercel.com/kb/bulletin/vercel-april-2026-secur…
♥ 2.2K · ⟲ 275 · 👁 571.3KView on X ↗

Steven Tey Urges Admins to Restrict Unconfigured Google OAuth Apps

Steven Tey Urges Admins to Restrict Unconfigured Google OAuth Apps

Steven Tey warns that third-party Google OAuth apps requesting scopes beyond basic profile data are a dangerous attack vector. He recommends Workspace admins restrict unconfigured third-party apps, linking to the Google admin settings page and crediting a tip.

Original post · 1 min read
Biggest takeaway from this: 3rd-party Google OAuth Apps that request scopes beyond the basic info (name/user/profile pic) is a dangerous attack vector.

To safeguard your org from attacks like this, highly recommend asking your Google workspace admin to restrict "unconfigured third-party apps" to only be able to request basic info needed 👇

Here's the direct link to access that settings page: admin.google.com/ac/owl/settings

h/t @matid for the pro-tip!
Guillermo Rauch @rauchg
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly.

A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated.

Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments.

Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to prot…
♥ 1.7K · ⟲ 201 · 👁 331.6KView on X ↗

IIT Madras Startup Sthyr Energy Turns Electricity Into Storable Metal

IIT Madras Startup Sthyr Energy Turns Electricity Into Storable Metal

Varun Guru highlights Sthyr Energy, a startup founded by three IIT Madras scientists, which converts electricity into metal that can be stored for months and later converted back. He argues it could enable long-duration storage and transport of renewable energy.

Original post · 1 min read
These three IIT Madras scientists are insane.

Their startup Sthyr Energy is literally turning electricity into metal.

Which you can keep for months and turn it back into electricity when you need it.

And this is incredibly huge.

Let's break this down.

Right now, India alone generates enough renewable energy to power countries like France.

But we can either use it as soon as its generated or its lost forever.

Because no one has figured out a way to store electricity for more than a few hours at scale.

If Sthyr's solution works - we won't just be able to store it for years but we could also transport it on roads - without creating any new infrastructure.

And it would change how the world uses electricity forever.
♥ 4.5K · ⟲ 1.3K · 👁 182.3KView on X ↗
AI7/10

Robert Scoble Reacts to DeepMind Paper on AI Agent Detection Asymmetry

Robert Scoble says he was alarmed twice in two nights. The quoted post describes a Google DeepMind paper on how websites can detect AI agents and serve them hidden malicious content, including instructions in HTML, image pixels, and PDFs.

Original post · 1 min read
OK that is twice in two nights I have gotten freaked out.
How To Prompt @HowToPrompt__
Google DeepMind just dropped the most terrifying cybersecurity paper of the year.

They just mapped the attack surface that nobody in AI is talking about.

Websites can already detect when an AI agent visits and serve it completely different content than humans see.

- Hidden instructions in HTML.
- Malicious commands in image pixels.
- Jailbreaks embedded in PDFs.

This “detection asymmetry” means a site can serve normal content to you, and malicious, hidden content to your agent.

The agent doesn’t know it’s being tricked. It simply processes whatever it receives and acts on it.

Here’s the …
♥ 346 · ⟲ 30 · 👁 95.8KView on X ↗

Trader Christopher Eppinger Reportedly Made $250 Million Trading Russian Oil

Trader Christopher Eppinger Reportedly Made $250 Million Trading Russian Oil▶

Goshawk Trades profiles Christopher Eppinger, who reportedly made over $250 million trading oil from 2022 to 2025 after Western firms exited Russian oil. The post is a teaser with a linked thread and video.

Original post · 1 min read
When Russia invaded Ukraine, BP, Shell, and Vitol ran from Russian oil.

A 27-year-old trader ran toward it.

Three years later, Christopher Eppinger made $250 million, owns a €7M villa on the French Riviera, and a private jet.

The full story of how he did it below:
Goshawk Trades @GoshawkTrades
How a 31-Year-Old Made $380M Trading Russian Oil in 30 Months — Most people have never heard of Christopher Eppinger.
But between 2022 and 2025, he personally made over $250 million trading oil. His company moved $2 billion in deals. He's 31 years old.
For his
♥ 1.4K · ⟲ 123 · 👁 520.7KView on X ↗
AI6/10

Stanford Lecture Examines Economics of the AI Investment Supercycle

Stanford Lecture Examines Economics of the AI Investment Supercycle▶

Boring_Business recommends a 40-minute Stanford lecture by Apoorv Agarwal, a partner at Altimeter, on the economics of the AI supercycle. The course is MS&E 435 and Agarwal's firm has invested in OpenAI and Glean.

Original post · 1 min read
This 40 minute lecture at Stanford by Apoorv Agarwal on the Economics of AI supercycle is worth a watch

Apoorv is currently a Partner at Altimeter and is directly involved in some of their key AI investments, including OpenAI and Glean

Still find it incredible that the internet gives us access to this level of information directly. A course I will definitely be following along

Sourced from MS&E 435 Stanford University
♥ 2.3K · ⟲ 279 · 👁 245.5KView on X ↗

Pi-hole Offers Network-Wide Ad Blocking on a Low-Cost Device

Pi-hole Offers Network-Wide Ad Blocking on a Low-Cost Device

Nav Toor explains Pi-hole, open-source software that runs on a cheap device like a Raspberry Pi Zero to block ads and trackers for every device on a home network. He describes how it works at the DNS level and lists what it blocks.

Original post · 2 min read
You see hundreds of ads every single day. On your phone. Your laptop. Your smart TV. Your game console. Your kid's tablet. Even your thermostat.

Someone built a tiny $5 computer that blocks every single one of them. For every device in your house. Forever.

It's called Pi-hole.

Not a browser extension. Not an app. A network-wide ad blocker that lives on your WiFi. Every device that connects to your home internet gets ad-free browsing automatically. No setup on each device. No subscription. No tracking.

Here's how it works:

Every time your phone loads an ad, it asks the internet "where is this ad server?" Pi-hole sits between your phone and the internet. When your phone asks for an ad, Pi-hole says "that server does not exist" and the ad never loads.

The ad is dead before it reaches your screen.

Here's what Pi-hole blocks:

→ Ads in mobile apps. Ads inside games. Ads on free apps that usually can't be blocked.
→ Smart TV ads. Roku ads. Amazon Fire ads. Samsung TV ads. Every TV ad at the DNS level.
→ Tracking pixels. Facebook tracking. Google Analytics. TikTok pixels.
→ Telemetry. Windows spying on you. Apple sending data. Your smart fridge phoning home.
→ Malware domains. Phishing sites. Crypto miners.
→ Ads and telemetry on Xbox, PlayStation, and Nintendo Switch.

Here's the wildest part:

A Raspberry Pi Zero costs $5. An old Android phone, you already own. An old laptop in your closet, you already own.

Any of them can run Pi-hole.

One small device. Plug it in once. Forget about it. Every phone, tablet, laptop, smart TV, and game console on your WiFi gets ad-free browsing.

Forever.

No monthly fee. No subscription. No tracking. No account. No login.

Pi-hole users report their home internet feels faster because ads are never downloaded in the first place.

The developers are volunteers. They've been building this for over a decade. It handles hundreds of millions of DNS queries on server-grade hardware.

52,000+ GitHub stars. EUPL-1.2 license.

100% Open Source.
♥ 2.3K · ⟲ 417 · 👁 132.7KView on X ↗

Advisor Describes Tech Couple's Financial Plan After Simultaneous Layoffs

Kurt Supe, CPA, walks through a hypothetical composite of a 52- and 51-year-old couple laid off from tech, detailing a 24-month cash flow bridge, a Roth conversion, and avoiding early retirement withdrawals. He stresses planning in the first 90 days after a layoff.

Original post · 2 min read
A couple. 52 and 51.

Both in tech. Both laid off the same month.

24 combined years at companies that no longer wanted them.

Finding something new is not just hard. It is brutally hard.

Here is their situation.

Severance: $340,000
401k Balances: $2,300,000
RSUs: Vesting schedule disrupted
COBRA: $2,800/month
Mortgage: 14 years remaining
Retirement target: whenever they can

The Fear

If we start pulling from our retirement accounts to survive are we looking at working five or ten years longer than we ever planned.

What Most Advisors Said

Sit tight. Do not touch the retirement accounts. Wait it out.

What We Did

Built a 24-month cash flow bridge using severance and brokerage assets. Zero early withdrawals. Zero penalties.

Their income had never been lower. So we did a significant Roth conversion at a tax rate they will never see again.

Stopped planning around RSUs that might never arrive. Built everything around what had already vested.

The Result

They did not lose two years. They used two years.

Here is what nobody wants to hear in their 40s.

When you get into your 50s and 60s having a plan for this moment is almost a must. Not a nice to have. A must.

The people who think their job is the most secure are often the least prepared when it is not.

A layoff at 52 can destroy a retirement plan.
Or it can be the most important financial pivot of your life.

The difference is what you do in the first 90 days.

Not financial, tax, or legal advice. Results are not guaranteed and individual circumstances vary. All scenarios are hypothetical composites for educational purposes only and do not represent any specific client or outcome.
♥ 349 · ⟲ 18 · 👁 263.2KView on X ↗

Post Shares Link to 361-Page PDF on Hedge Fund Trading Algorithms

Post Shares Link to 361-Page PDF on Hedge Fund Trading Algorithms

Quant Science promotes a 361-page PDF said to cover 151 trading strategies used by hedge funds. The post itself contains only the claim and an attached image, with no detail on the document's contents or source.

Original post · 1 min read
This paper unlocks every algorithm used by hedge funds.

151 trading strategies.

Get it here (361 page PDF):
♥ 1.5K · ⟲ 239 · 👁 139.7KView on X ↗