<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Risk on Local First AI</title><link>https://localfirstai.eu/tags/risk/</link><description>Recent content in Risk on Local First AI</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 20 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://localfirstai.eu/tags/risk/index.xml" rel="self" type="application/rss+xml"/><item><title>We Found the Credentials. We Didn't Rotate Them.</title><link>https://localfirstai.eu/posts/2026-09-20-we-found-the-credentials/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate><guid>https://localfirstai.eu/posts/2026-09-20-we-found-the-credentials/</guid><description>A red-team pass on our own inference machine found live credentials readable with one plain command and no exploit. Then we decided, on purpose, not to rotate them. Here&amp;#39;s the reasoning, the strongest objection to it, why &amp;#39;accept the risk&amp;#39; is a real answer rather than a cop-out, and the part where the tool doing the audit leaked the secrets itself.</description></item></channel></rss>