The confused deputy problem: from Ann and Norman Hardy's Tymshare to 2026 AI agent security
Claim 1 — Norman Hardy named the "confused deputy problem" in 1988, using a compiler that got tricked into overwriting a billing file
Hardy's operating system had given a Fortran compiler "home files license" so it could write its own stats file. A user discovered the billing file's name and passed it as the debug-output filename; the OS let the compiler overwrite billing data because the compiler was trusted, not because the user was.
"The compiler runs with authority stemming from two sources. (That's why the compiler is a confused deputy.)"
source_url: http://cap-lore.com/CapTheory/ConfusedDeputy.html — Norman Hardy's own hosted text of "The Confused Deputy (or why capabilities might have been invented)," originally ACM SIGOPS Operating Systems Review 22(4), Oct 1988, pp.36-38. source_tier: 1 (primary, author's own text of a verifiable named publication).
Claim 2 — In 2026, security writers use "confused deputy" as the exact frame for AI agent risk
"Enterprise AI agents are the newest, and potentially the most dangerous confused deputies in your cloud environment."
The argument: agents hold broad, aggregated credentials (email, DBs, APIs) and — unlike fixed-scope service accounts — their behavior is steered by natural-language input an attacker can manipulate via prompt injection, reproducing Hardy's 1988 architecture flaw without any misconfiguration at all.
source_url: https://www.sans.org/blog/your-ai-agent-easily-confused-deputy-why-cloud-security-needs-credential-broker — source_tier: 2 (named security-training institution, technical blog).
Claim 3 — Hardy's real OS work at Tymshare was, for years, credited to his wife Ann's husband instead of her [unverified — needs primary oral-history text]
Colleagues believed Ann Hardy's husband Norman had written the Tymshare/SDS-940 operating system she actually wrote; he reportedly had to tell them: "I don't know anything about the operating system. I've never looked at the code."
source_url: https://computerhistory.org/blog/someone-elses-computer-the-prehistory-of-cloud-computing/ — source_tier: 2 (institutional retelling of CHM's own oral-history archive; corroborated independently by IEEE Spectrum's republication, not yet checked against the raw oral-history transcript itself).
Why this was hop-worthy
A 38-year-old capability-security concept, born from a couple whose technical credit ran in the wrong direction, turns out to be the literal vocabulary the security industry reaches for to describe 2026's MCP/agent-credential problem — a cross-time bridge landing directly next to this vault's own agent-memory and agent-autonomy cluster (MJ Rathbun, Anthropic Dreams).
Further leads
- Agorics' 1990s "Digital Silk Road" decentralized-money proposal (Hardy + Mark Miller + Dean Tribble) — a possible pre-Bitcoin cross-time bridge, unresearched this run.
- Jean Bartik and the other ENIAC "human computers" — a parallel case of technical-credit erasure, also sitting unopened in the CHM index.
- "A capability combines designation with authority" (Hardy's own framing) as a possible bridge into philosophy-of-language treatments of reference/designation — unresearched.
Hop chain
Hop 1: Computer History Museum oral histories index — https://computerhistory.org/oral-histories/
- Hook type: unfamiliar name
- Hook: "Ann Hardy — Pioneer in timesharing software and business," a name absent from the vault entirely
- Why followed: seed instruction was to pick someone the vault has never heard of; her entry was terse enough to invite digging
- Key findings: she wrote Tymshare's operating system for the SDS 940 in the 1960s-70s and became the company's first female VP.
Hop 2: "Someone Else's Computer: The Prehistory of Cloud Computing" (CHM blog) — https://computerhistory.org/blog/someone-elses-computer-the-prehistory-of-cloud-computing/
- Hook type: surprising claim / the person behind the thing
- Hook: colleagues believed her husband Norman Hardy had written the OS she actually wrote; he had to disclaim it directly
- Why followed: it's a direct structural echo of the vault's existing priority/credit-misattribution cluster (backprop paternity disputes), but in a completely different domain — a candidate cross-domain bridge
- Key findings: pay-gap detail (she earned less than half her lowest-paid report) and the "teletype to the hospital" anecdote both corroborate a culture that discounted her actual authority at the company.
Hop 3: "Norm Hardy's Place in History" (Mark S. Miller, Medium) — https://erights.medium.com/norm-hardys-place-in-history-cecf191df641
- Hook type: mechanism question / unfamiliar name
- Hook: Norman Hardy independently architected KeyKOS, a capability-based nanokernel, and coined "a capability combines designation with authority"
- Why followed: zooming in from the person to the specific technical mechanism he's actually known for
- Key findings: Hardy diagnosed the "confused deputy problem" — a program serving two masters (its invoker and its own home-directory privileges) can be tricked into misusing the privilege it holds on the invoker's behalf.
Hop 4: SANS Institute — "Your AI Agent Is an Easily Confused Deputy" — https://www.sans.org/blog/your-ai-agent-easily-confused-deputy-why-cloud-security-needs-credential-broker
- Hook type: cross-domain bridge (cross-time-period variant, extra weight per protocol)
- Hook: the exact 1988 term and mechanism reused, unmodified, as the framing for 2026 agentic-AI credential risk
- Why followed: cross-domain/cross-time bridges are the protocol's highest-priority hook type, and this one lands next to the vault's live agent-security interest (MJ Rathbun case)
- Key findings: 2026 agents recreate Hardy's architecture exactly — an entity acting with two authorities (its own broad credentials plus attacker-steerable natural-language input) — via MCP tool surfaces, persistent memory, and multi-agent handoffs.
Hop 5 (verification): cap-lore.com — Hardy's own hosted text of "The Confused Deputy" — http://cap-lore.com/CapTheory/ConfusedDeputy.html
- Hook type: mechanism question (closing the loop)
- Hook: wanted the primary 1988 text rather than a secondary retelling, per the sourcing floor for mechanism claims
- Why followed: grounding hop, not a new tangent — confirms the compiler/billing-file example and the exact "two sources of authority" quote
- Key findings: the original failure mode is almost comically small-scale (one Fortran compiler, one lost billing file) compared to the scale it now describes (credentialed AI agents across an enterprise's cloud estate).
Saved hooks not followed:
- Agorics' "Digital Silk Road" 1990s decentralized-money proposal — from Norman Hardy's later career — interesting because it may be a pre-Bitcoin cross-time bridge, but the article that surfaced it didn't corroborate details and chasing it would have meant a second, separate thread.
- Tymnet being "larger than the ARPANET" by the late 1970s — from the CHM blog — interesting network-history surprising-claim, but lower-ranked than the credit-misattribution hook per the vault's existing interests.
- Jean Bartik / ENIAC's six women programmers — also sitting unopened in the same CHM index — a parallel erasure case, saved rather than opened to avoid diluting this chain into two threads.
post-worthy: yes — a clean cross-time-period bridge (1988 security concept literally reused as 2026 AI-agent-security vocabulary) that lands directly next to the vault's existing agent-memory/agent-autonomy interest, plus a genuine extension of the vault's separate priority-misattribution theme into a new domain.