0:00
/
0:00
Transcript

Ep 35: Exploring Security After Determinism with Jens Ernstberger

In this episode, we sit down with Jens to explore why AI agents fundamentally break traditional security assumptions, from API keys and browser sessions to composability and access control.

Drawing parallels to DeFi exploits and smart contract failures, he explains why agent identity, short-lived delegated authorization, and zero trust aren’t optional add-ons, but the foundation for safely running autonomous systems.

We also dive into context compression as both a performance and security challenge, the real difference between MCP and skills, and a future where humans may stop reviewing code altogether. As agents become the primary actors on the internet, even writing itself begins to change in an AI-scraped world.

If agents are non-deterministic by design, the real question becomes: where do we reintroduce determinism?

00:00 — AI agents as the next security reset moment. History repeating: automation + composability = new attack surfaces

03:25 — Challenges of context compression in AI

07:39 — Access control in a non-deterministic system and compaction issues

11:22 — MCP vs skills: horizontal infrastructure meets vertical execution logic

18:06 — Agent identity and security practices. Static credentials collapse under autonomous agent behavior

30:06 — The future of coding with AI agents

31:31 — DeFi attacks, composability issues, and how non-determinism multiplies risk

35:14 — Writing for humans vs writing for LLMs. Content, authenticity, and the economics of scraping

44:42 — Transition from academia to startup founder

Tune in for a deep dive!

Connect with Jens Ernstberger:

Website: https://ernstberger.xyz/

LinkedIn: https://www.linkedin.com/in/jens-ernstberger-phd-96b0ba14a/

Connect with Anshuman:

LinkedIn: ⁠⁠⁠⁠⁠⁠anshumanbhartiya⁠⁠

X: ⁠⁠⁠⁠⁠⁠https://x.com/anshuman_bh⁠⁠

Website: ⁠⁠⁠⁠⁠⁠https://anshumanbhartiya.com/⁠⁠

⁠⁠⁠⁠Instagram: ⁠⁠anshuman.bhartiya⁠

⁠⁠⁠Connect with Sandesh:

LinkedIn: ⁠⁠⁠⁠⁠⁠anandsandesh⁠⁠

X: ⁠⁠⁠⁠⁠⁠https://x.com/JubbaOnJeans

Thanks for reading The BoringAppSec Community! Subscribe for free to receive new posts and support my work.

Discussion about this video

User's avatar

Ready for more?