Mon–Fri · 6 AM ET
← All Episodes
EP  • 00:08:00

Canvas is down as ShinyHunters threatens to leak schools’ data | Build or Be Replaced

Today: Canvas is down as ShinyHunters threatens to leak schools’ data | Cloudflare to cut about 20% workforce | Maybe you shouldn't install new software for a bit Episode date: 2026-05-08.

Download MP3 →

Transcript

Writing the episode 20 script now.

---

JOSH: It's Friday, May 8. Episode 20. This is Build or Be Replaced — powered by ScanBrief.dev. I'm Josh, here with Erik Anderson.
ERIK: Agents, layoffs, and code that shipped while you were sleeping.
JOSH: Stick around — Erik's got an AI pro tip at the end about why your prompts are not your error handlers.

[pause]

JOSH: ScanBrief pulled 47 items this morning across 54 sources. Three things to flag quickly. Canvas is offline — ShinyHunters got in, student data exposed. How bad?
ERIK: Bad. Names, emails, private messages all out. The group is threatening to leak unless schools negotiate. Instructure patched, but the platform is still rocky. Education infrastructure runs on thin security budgets and legacy systems. Soft targets. This won't be the last one.
JOSH: Cloudflare cutting 20% of its workforce. That's not a small trim.
ERIK: That's hundreds of engineers at a company running critical internet infrastructure. The official framing will be restructuring. The real story is what changed in the cost-benefit math of maintaining a large engineering org.

[beat]

JOSH: And Dirtyfrag — a universal Linux privilege escalation. How worried should people be?
ERIK: Very. Universal means every major distribution is in scope. User goes to root. If you're running exposed Linux boxes, you're patching this today. Not this week.

[pause]

JOSH: Let's go deeper on that agents piece. Hacker News today — "Agents need control flow, not more prompts." You're running five agents in your fleet right now. Is this right?
ERIK: Completely right. This is the most important thing people are missing about building with AI right now. Prompts don't make agents reliable. Architecture does. Those are different problems.
JOSH: What does "control flow" actually mean in practice?
ERIK: It means your agent has a decision tree, not a conversation. When something fails, the code knows the next step. It doesn't ask the model what to do — the model isn't in charge of the logic. PrimeBus processed 1336 automation events today across 6 projects. None of that runs on prompts. The router reads the event type, checks the rules, dispatches. The model comes in when there's something to interpret — a diff to review, an error message to classify. But the branching is code. Always.
JOSH: Where do most people get this wrong?
ERIK: They write one big prompt and call it an agent. Then they're surprised when it fails unpredictably. A prompt chain isn't an agent. It's a suggestion chain. The moment something goes sideways, there's nothing to catch it. So they add more instructions. The prompt gets longer. The model starts ignoring the earlier parts because the context is too cluttered. Now you're debugging 4,000 tokens of natural language instead of a function. Nobody wins that fight.

[beat]

JOSH: So what belongs in the model versus what belongs in code?
ERIK: The model handles ambiguity. Anything where the right answer is fuzzy or requires judgment. Gandalf reviews code diffs for my auto-merger — that's a model job. Evaluating whether a fix is sound, whether it has downstream risk, whether the approach makes sense — that requires understanding context. Code can't do that. But "did the merge succeed?" is a boolean. Write the boolean in code.
JOSH: The auto-merger numbers are pretty striking. How's it tracking?
ERIK: 1121 attempts since mid-April. 435 merged, 675 blocked by Gandalf, 11 escalated to me. Eleven. Out of eleven hundred runs. That's not a 38% success rate — people look at that wrong. The 675 blocks are the guardrails doing exactly what they're supposed to do. Those are fixes that shouldn't have gone to prod. Gandalf caught them. That's the system working.
JOSH: And the 11 that came to you — what were those?
ERIK: Architectural edge cases. Things where a fix touched something with downstream implications Gandalf flagged but couldn't resolve itself. Those are the ones that actually need a human in the loop. Eleven. That's the whole point of building it this way — I'm not the bottleneck for the other eleven hundred.

[pause]

JOSH: Cloudflare. 20% cut. The show's called Build or Be Replaced — is this what that looks like?
ERIK: Pretty much. Cloudflare grew its engineering headcount over years assuming a certain ratio of humans to shipped output. AI changed that ratio. You need fewer people to build and maintain the same systems. Eventually that shows up in headcount decisions. This isn't unique to them — it's the math changing industry-wide.
JOSH: Is this AI replacing engineers or something else?
ERIK: It's both. Some of it is macroeconomic. Some of it is that tooling which required a dedicated team two years ago can now be built by a much smaller group. The engineers who survive are the ones building the systems, not the ones being replaced by them.
JOSH: How do you actually get to the other side of that? It sounds like a lot of upfront work.
ERIK: It is. But so is the alternative. Every hour I don't spend building automation is an hour I spend doing the thing manually. Right now I've got 93 services running on one prod server and 65 projects emitting telemetry into PrimeBus. I didn't hire a team to run that. I built systems that run it. You build toward that state. You don't flip a switch one day — you make one thing autonomous, then another, then another.
JOSH: What's the first thing someone should automate?
ERIK: Whatever you do every day that has a clear trigger and a predictable outcome. If you can describe it as "when X happens, I do Y" — that's a cron job or an event handler waiting to exist. Start there.

[pause]

JOSH: One more — "AI slop is killing online communities." Short take?
ERIK: ScanBrief scored 47 items this morning and I can already tell you which sources are polluted with generated filler. No specific claim. No point of view. No named entity. Just content-shaped noise that fills a feed. The scoring helps filter it — low-signal items drop out before the brief gets built. But the volume is real and it's getting worse.
JOSH: Is there a fix?
ERIK: Not a systemic one. You can score for specificity, penalize vague generalities, filter algorithmically. You can degrade the slop in your own pipeline. But as long as publishing more is cheaper than publishing better, you're fighting a current. The communities that survive this are the ones where real people actually show up and say something specific.

[pause]

ERIK: This episode is sponsored by Prime Automation Solutions. If you're still doing it manually, we automate it. Also, special on a website — $250. primeautomationsolutions.com

[pause]

JOSH: Alright, what's the AI pro tip today?
ERIK: Stop using prompts to handle errors. This is the most expensive habit I see in AI workflows. Something breaks, so you add more instructions to the prompt — "make sure to handle the case where the API returns null." The prompt grows. The model gets inconsistent. Now you're debugging natural language instead of code, and you have no stack trace and no way to reproduce it reliably. Here's what you do instead: write the error handler in code. Write a retry with backoff. Write an event that fires on failure and routes to an agent that can actually deal with it. The model is not your try-catch. Code is your try-catch. If you're building agents, build them like software. Not like chatbots. That's your tip. Use it.

[pause]

JOSH: Binge all five episodes this weekend plus our YouTube shorts — links at buildorbereplaced.dev.

[pause]

JOSH: One more thing — we started a Discord for builders. If you're shipping AI, automation, or anything that makes a human obsolete — come hang out. Link at buildorbereplaced.dev.
ERIK: Post what you built. We'll post what we're building. Real wins, real builds, no fluff.

[pause]

ERIK: Build or be replaced.
JOSH: If you want these signals in your inbox every morning, scanbrief.dev. See you tomorrow.