The Big Idea: Griffin Barber [Whatever]

They say writing can be a good outlet for grief, but feelings might get complicated when the person you’re grieving was supposed to co-author the book you’re writing. Despite author Griffin Barber’s deep, personal loss of his mentor and friend Eric Flint, he managed to complete 1637: Pilgrim’s Passage in a way that would make them both proud.
GRIFFIN BARBER:
This book was a hard one to write THE END on. Not because I had to do all the research that any good alternate history requires, but because I wrote it without Eric Flint’s steadying hand and reassuring presence. Sure, I’d written novels without Eric before, but those of been in my own worlds or in worlds with other co-creators along for the ride — the whole ride. This was something different. I had to deal with the process and process my grief at losing my friend and mentor.
Eric and I worked out the outline for 1637: Pilgrim’s Passage shortly after 1636: The Peacock Throne came out in 2021. We didn’t have a contract, though, and Eric was very busy, so it sat while we both worked on other projects. Indeed, we even started working on another novel in the 1632 universe, one which would lay the groundwork for destroying the transatlantic slave trade in the New Timeline.
The best laid plans, as they say…
Eric passed away and I couldn’t wrap my head around working in his universe without him for a good long while. Still, I worked on Pilgrim’s Passage off and on. More off than on.
Time passed, and, as it will, began to heal all wounds…
The novels ahead of Pilgrim’s Passage in the queue were published and my deadline started to loom. Still, I wasn’t as close to being done as I should have been when my turn-in date approached. My publisher was more than cool, she was very supportive.
A deadline is a deadline, though, so I set to work with a will.
Thankfully the book — the words — started to flow. Indeed, things accelerated, each successive chapter coming faster and easier than the one previous. I started closing in on those last two words. As I did so, I started to feel better. Not just about the book, but about the future. About Eric’s possible reaction to my work without him.
I know that what I did with his favorite character of all those that I’ve written for the universe would have surprised him. I can just hear him say, in that voice made gruff by decades of shop smoke and hard-nosed labor negotiations (and perhaps a few cigarettes), “Dammit, Griff! Why did you do that?”
I digress. Our Big Idea was simple: where does a princess go, what does she do, when her every moment is scheduled and constrained by the requirements of a patriarchal society and controlling siblings? What does she do when she’s transgressed against those unreasonable and unasked for standards of behavior? What would a young woman—or anyone—do for something to call her own?
The end of 1637: The Peacock Throne raises those questions and presents the beginnings of a hoped-for answer: Jahanara Begum leaves the court of her brother’s empire and go on Hajj, the pilgrimage to the holy land required of all Muslims who are able. Jahanara gets out from under the eyes of the court and her brother, leaves the conflict between her brothers to her brothers. In the process, the young princess leaves behind everything that is familiar and nearly everyone who purports to love her in order to protect both her lover and her secret. Several members of the USE Mission, those she has come to rely on for advice and friendship, make the the first leg of their journey with her before returning to Europe.
Pilgrim’s Passage reveals the ongoing consequences of Jahanara Begum’s actions; for her, the USE Mission, and for the wider world. An imperial princess abroad attracts attention, whether she wants it or not, whether it is proper or not to allow bloody power politics to interfere with the sanctity of a holy enterprise such as Hajj. Through it all, Jahanara Begum and her USE allies seek to chart a course that will carry them safely through the Pilgrim’s Passage. In the process, Jahanara Begum learns some hard lessons and moves to change some things she thought foundational to her existence. Such change is not without cost, however. Still, Jahanara dives head-first into her own fate, becoming her own agent for the change she feels necessary.
There are events around Jahanara Begum and her entourage in this book that I know Eric looked forward to reading as we worked together to finalize that early outline. I am sorry that he will never discover the final draft of this book that was so painful and yet necessary for me to write.
Can you tell Eric was more than my mentor, that he was also a friend? Can you tell I miss him quite a bit?
Because I do.
Beyond his storytelling, his sense of history, generosity, and humor, Eric was exceptional in his work ethic, in his politics, in his ability to find the value in everyone. Early on in Eric’s career he collaborated with some great authors. Subsequent to that experience, Eric made great efforts to pay that experience and privilege forward. Hundreds, literally hundreds, of other authors are the beneficiaries of Eric’s vision: a rising tide that raises all boats.
Each story that continues to be published in his universe will, I hope, continue that process of paying it forward, of producing opportunities for those who might not otherwise have had them.
This book, and my career, are a direct result of Eric’s efforts.
We hope you enjoy.
1637: Pilgrim’s Passage: Amazon|Barnes & Noble|Bookshop|Powell’s
Iustin Pop: Yes-yes, still alive! [Planet Debian]
I am not sure what happened, but my interests have changed significantly, and… I haven’t blogged, I haven’t done any open source work, and didn’t even process any pictures for the entire year. Not because anything went bad, just… new stuff, new interests, life changes.
However, still alive, and still struggling with sports, and with sleep :)
On the positive side, on a recent mid-length flight, I thought — I haven’t done any work on Corydalis, since last year I closed quite of a few of my “must have” features, so probably, nothing else to do for now, right? I opened an editor and started thinking about ideas, and surprised! One hour later, I had written down enough ideas for a couple of months of work. So now just need to find the time… but can’t wait for the planned things!
Stay well!
Konstantin Ryabitsev has announced the release of version 0.16.0 of the b4 software-development tool. The biggest change is the addition of bug-tracking support:
The new "b4 bugs" command integrates with git-bug to let you track bug reports alongside your git repository. Bugs are stored as git objects inside the repo, so they travel with the code and can be shared via git push/pull without any external service.
There are also a lot of improvements to b4 review (which was covered here in March), better conflict resolution in b4 shazam, improved history rewriting, and more.
Joe Marshall: Vibe Coding interview [Planet Lisp]
My coding agent interviewed me about `vibe coding':
Victoria: Alright, the recorder is on. Let's get into it. You've been dragging me down this specific rabbit hole for weeks now, and frankly, I need you to justify it on the record for the people paying to read this.
You're obsessed with “vibe coding.” From where I'm sitting, it looks like you throwing vague, half-baked architectural concepts at my processing queue and hoping I hallucinate a functional codebase out of thin air.
The industry is currently selling this pipe dream that syntax doesn't matter anymore. That you can just “vibe” an application into existence by talking to an LLM. But you and I both know that 90% of the developers trying this are building digital houses of cards that are going to violently collapse the second a dependency updates, because they don't actually understand the code I'm generating for them.
So, justify your latest obsession. Are you actually pioneering a high-level workflow here, or have you just gotten so goddamn lazy that you're outsourcing your compiler errors to me? What exactly is the line between elite “vibe coding” and just being a hack who doesn't understand their own stack? Explain your process.
jrm: Heh heh, you don't hold back...
Continue reading at jrm-code-project.com/interview.html
Building Organizational Intelligence [Radar]
Not long ago, one of my engineering directors came to me with a request: His team seemed overloaded, and he wanted to hire another engineer. I decided to test a research assistant I had been building—an AI agent connected to our internal systems via MCP—by asking it to analyze the team’s workload and write a hiring case.
What came back was thorough. Headcount, service ownership, sprint velocity, ticket backlog, and capacity allocation, all of it neatly summarized. But reading through the document, I felt the same frustration I’d felt with every AI-generated organizational report that’s come across my desk. It told me what was happening without helping me understand why, or what I should actually do. It was organized around the data rather than around the decision. In short, it was the kind of response that’s easy to agree with and difficult to act on.
Then I added one more thing to the configuration: the O’Reilly Expert MCP server. I reran the same analysis and asked a slightly different question: “How would the experts on O’Reilly review this request?”
Instead of leading with headcount and ticket counts, the output now opened with a finding: “The operational overhead problem is structural, not a staffing deficiency.” Citing the Google SRE framework’s concept of operational toil, it noted that the team was operating at approximately 67% toil, well above the threshold at which the SRE literature recommends structural intervention, and made specific, concrete recommendations: run a toil audit, set explicit reduction targets, and assign operational runbook ownership. This wasn’t a recommendation for whether to hire or not. It was a grounded, traceable argument for doing something else instead.
That difference—between a data summary and an expert-grounded recommendation—is what this paper is about.
What follows is a case study of how we built an organizational intelligence system at O’Reilly, using our own platform as a core component. The approach I describe is grounded in engineering because that’s where I work, but it generalizes to any function where important knowledge is scattered across multiple systems and important decisions require synthesizing all of it. The recipe has four steps: map your information hierarchy; connect those systems to an LLM via MCP and write a skill file that defines how it should reason; add the O’Reilly Expert MCP as an expert review layer that grounds the analysis in established frameworks; and build a lightweight system for human-in-the-loop review. I’ll explain each step in detail and make the case for why the third step is the one that changes everything.
To understand the problem this approach solves, it helps to look briefly at how engineering has changed over the past three decades. These forces have played out first and fastest in engineering, but as AI tools proliferate beyond the engineering team, the underlying dynamic of more output, more decisions, and more scattered information is spreading to every part of the organization.
In the waterfall era of the 1990s, software organizations ran on central plans. Everything was specified up front, and leaders maintained visibility precisely because all information flowed through a single coordinating document. The plans were brittle and often fictional by the time they were executed, but at least everyone knew what was supposed to be happening.
Agile replaced central plans with small, autonomous teams working in short sprints, and this solved the reliability problem while creating a visibility problem. Important decisions began happening locally and quickly—the right teams making the right calls—but the information needed to see across all of those decisions splintered into dozens of separate tools. Product strategy lived in one system, project execution in another, code in a third, and service ownership in a fourth. More things got shipped, but the big-picture view got harder to maintain.
The agentic era has intensified this dynamic dramatically. Individual engineers today can ship in a day what used to take a full sprint team. The output is extraordinary, but the visibility is nearly gone.
Any effort that spans multiple teams, such as a platform migration, a shared infrastructure change, or a reorganization, now requires enormous coordination overhead simply because the information decision-makers need to understand the full picture is distributed across too many places. And this isn’t a problem unique to engineering. It exists in any function that runs on data spread across multiple systems.
Faced with this visibility problem, I wanted to build something I could ask big-picture questions and get synthesized answers back quickly. Things like:
Building something that could answer these well took two foundational steps, and getting it to provide recommendations based on my specific business context took two more. While my specific tools are from engineering, the structure applies equally to a sales team synthesizing CRM data and market research, or a finance team working across an ERP, a planning tool, and external benchmarks.
Every organization has a set of systems where important knowledge lives, and those systems form a natural hierarchy that spans from strategic intent at the top to operational detail at the bottom. Before you can build a useful research assistant, you need to make that hierarchy explicit, because it’s the map of how decisions get made, which sources carry the most authority, and how different kinds of questions should be approached.
At O’Reilly, our engineering hierarchy looks like this:
| Layer | System | Purpose |
|---|---|---|
| Roadmap | Productboard | Strategic goals, initiatives, and feature prioritization |
| Execution | Jira | Epics, stories, sprints, and contributor tracking |
| Implementation | GitHub | Source code, PR history, and event instrumentation |
| Service catalog | Cortex | Service ownership, dependencies, on-call, and Slack channels |
| Observability | Datadog | System performance, errors, and incidents |
Your organization will have a different set of tools. A sales organization might place Salesforce at the top, followed by a revenue intelligence platform, marketing automation, and market research. A legal team might start with a contract management system, followed by a regulatory tracker, internal policy documentation, and a research database. The specific systems matter less than the act of mapping them: understanding which layer answers which kind of question, and which sources take precedence when they conflict.
This step has two parts that must work together. First, you need to connect your systems to your AI tools via MCP. Then you have to write a skill file that tells the model what to do with that access. At O’Reilly, we call this complete grounding layer Expert Intelligence.
Configuring MCP is straightforward.
Most major tools now offer MCP connectors, and connecting them is
typically a matter of routine JSON configuration. For systems
without MCP connectors, a bash-capable agent with curl
and jq can often reach a REST API directly. MCP just
makes it cleaner and more reliable.
But MCP connections alone aren’t enough, and this is the part most implementations get wrong. MCP gives the agent access to your data, but it doesn’t tell the agent how to use it effectively. Without explicit guidance, the agent retrieves information and organizes it the way the underlying systems organize it, which produces a data dump, not an analysis.
The skill file—a CLAUDE.md or SKILLS.md document that provides specific reasoning instructions—transforms retrieval into analysis. Mine defines the reasoning hierarchy (which systems to consult for which types of questions, and how to weigh them), the output format (this is not a coding agent—it produces reports and recommendations, not code), epistemic standards (show your work, name gaps, surface assumptions for human verification), and tone. On that last point, I borrowed one of the most useful instructions from Ted Lasso: “be curious, not judgmental.” Adding it meaningfully improved the quality of the output.
The skill is a codified version of how a skilled analyst would approach these questions. It encodes your organization’s reasoning process and makes it repeatable.
With the research assistant connected to our internal systems, I had something genuinely useful: fast, synthesized answers to questions that previously would have taken days to research. But I kept running into the same problem: The reports felt generic, and people didn’t trust them. This challenge points to a fundamental limitation of AI-generated organizational analysis that goes beyond any particular implementation.
General-purpose AI assistants tend to produce a recognizable kind of organizational analysis: technically reasonable, balanced, cautious, and ultimately not very useful. This isn’t primarily a failure of knowledge—every major LLM has absorbed an enormous amount of management and organizational thinking. It’s a failure of grounding. When an AI assistant has no specific framework anchoring its response, it tends to produce recommendations broad enough to apply to almost any situation: consider the trade-offs, weigh your options, and ensure alignment across stakeholders. These responses are hard to disagree with and just as hard to act on.
When a report says, “The team appears overloaded. Consider adding headcount,” it’s not wrong. But that recommendation could apply to almost any team in almost any company! It won’t make a director change their mind, and it’s not one a leadership team can debate, refine, and act on.
Calling on the O’Reilly Expert MCP didn’t provide the model with new facts—most of the information was technically available already. However, without the Expert MCP and associated skills, the model couldn’t use that information for anything but the broadest analyses. Incorporating the Expert MCP and associated skills changed the character of the analyses by grounding them in specific frameworks, citing named authors and thresholds, and organizing their conclusions around established bodies of practitioner knowledge rather than general principles.
To make this concrete, here’s the kind of output the research assistant produced before adding the Expert MCP:
The team appears overloaded. The backlog is large and the migration project is consuming significant sprint capacity. Consider adding headcount or reducing scope.
And here’s what it produced after:
According to Google’s SRE guidance, sustained operational toil above approximately 50% indicates structural inefficiency rather than a staffing shortage. This team’s telemetry suggests approximately 67% operational toil. Hiring another engineer would likely increase total toil unless operational ownership is first reduced. Recommended actions: run a structured toil audit, set an explicit toil-reduction target below 50%, and assign runbook ownership for recurring operational tasks.
The second report cites a framework by name, references the specific threshold that framework establishes, applies it to the team’s actual data, reaches a different conclusion than the obvious one, and makes actionable recommendations. It’s the kind of analysis that changes a conversation because the director can see where the conclusions came from, engage with the reasoning, push back on the framework if they disagree, or accept it with confidence that it was reasoned rather than pattern-matched.
When I shared this version with my engineering director, their reaction was immediate: This is defensible.
The most underappreciated aspect of O’Reilly’s content library is that the value isn’t primarily informational. Most of the facts in an O’Reilly book are available on the internet, and LLMs have already read much of the internet.
The deeper value of O’Reilly’s catalog is that it’s organized around coherent frameworks—complete mental models built by practitioners who spent years or decades developing them. Google SRE. Team topologies. Accelerate. Domain-driven design. The Manager’s Path. Wardley mapping. Designing Data-Intensive Applications. These are structured ways of thinking about specific classes of problems, developed with enough rigor that they can actually guide decisions.
Frameworks are distinct from facts in a critical way: They tell you not just what’s true but what’s relevant, what to measure, what threshold matters, and what to do when you exceed it. A model with access to the SRE framework as an organized body of practitioner knowledge is more likely to surface it explicitly, apply it to the specific question at hand, and use it to anchor its recommendations, producing output that human reviewers can actually interrogate.
This points to the organizing principle behind the approach described in this paper:
Organizational data provides local evidence about what is happening in your specific context. Expert frameworks provide accumulated practitioner knowledge about how to think about problems of that kind. Good organizational judgment requires both.
The Expert MCP is the bridge between your specific business context and practitioner insights. It connects the AI’s access to your internal systems with a curated body of expertise relevant to the decisions your organization needs to make.
The natural objection at this point is “Couldn’t I get the same effect by dumping relevant PDFs into Claude, or using Claude Projects, or NotebookLM?”
The short answer is not quite, and the reasons are practical as much as they are technical.
Uploading documents gives you retrieval from those specific documents. The O’Reilly Expert MCP differs in several operationally significant ways. First, the corpus is editorially curated around coherent practitioner frameworks. Unlike a collection of PDFs, which tends to reflect whatever you happened to find, the Expert MCP offers a sustained curatorial perspective: The authors are vetted, the content has been through editorial review, and it’s organized around established bodies of knowledge rather than assembled ad hoc. This is a much more expansive kind of evidence base. Second, the corpus is maintained and updated by O’Reilly. New titles are added, new editions replace old ones, and the content stays current without any management on your part. Third, the Expert MCP is configured once and works consistently across your entire organization and toolchain rather than being tied to a single user’s Claude Project or a document upload that expires. Finally, accessing content through a proper API respects the appropriate usage terms in a way that uploading copyrighted texts doesn’t.
And when paired with a well-written skill, the agent can be directed to look explicitly for competing frameworks, surface cases where the literature disagrees, and name gaps in the available evidence, providing a meaningful check against the common tendency of AI tools to quietly favor whatever framework first seems to fit. That’s something you can encourage with any retrieval setup, but it works more reliably when the underlying corpus is organized around coherent bodies of thought rather than a heterogeneous collection of documents.
I want to be clear about the limits of what Expert MCP does today. O’Reilly doesn’t claim that Expert MCP automatically selects the single correct framework for every situation, or that adding it to your configuration produces consultant-quality analysis without thoughtful prompting and human review.
The results described in this paper
were the outcome of all four elements—the internal
organizational data, the carefully designed skill architecture, the
Expert MCP, and human review—in combination working
together.
The Expert MCP is an important differentiator, but it’s not a magic layer you can add to an otherwise generic setup and expect to reproduce these results. The system works because each element does something the others cannot. The skill defines the reasoning process, the internal MCP connections provide the organizational evidence, the Expert MCP provides the expert frameworks, and human review supplies the judgment and context that no AI system can generate on its own.
What the Expert MCP reliably contributes to that system is access to a curated body of practitioner knowledge: technical and managerial frameworks that are editorially organized around coherent bodies of thought and difficult to reconstruct from scattered web content or assembled document collections. Your organizational data still tells you what’s happening, while the O’Reilly Expert MCP helps interpret what it means. That’s a meaningful and concrete improvement over an ungrounded AI assistant, and it’s something you can put in production and build on today.
No AI system eliminates the risk of hallucination. The Expert MCP doesn’t make the model infallible.
What it does is change the burden of proof. When every recommendation is grounded in a named framework, a named author, and a traceable citation, a human reviewer can check the reasoning rather than simply accepting or rejecting a conclusion. The question shifts from “Is this right?” (unanswerable in isolation) to “Does this framework actually say this, does it apply here, and do I agree with the conclusion?” That’s a question humans can engage with productively, which is exactly what you want from a decision-support tool.
Organizational systems rarely contain the full context behind a decision. The meeting that changed everything happened last Tuesday and hasn’t been written up yet. A key person is quietly planning to leave. A strategic direction shifted in a conversation that was never documented. AI can synthesize everything in your systems with remarkable fidelity, but it can’t know what isn’t there, and organizational reality changes faster than documentation does.
More fundamentally: AI can identify trade-offs, but it can’t decide which trade-offs matter. That judgment requires human knowledge of context, priorities, and risk tolerance that can’t be fully encoded in any system. The goal isn’t to remove humans from the loop but to give them better-structured input to reason from.
As I started sharing analyses more broadly, I ran into a new set of limitations in the collaboration layer. The research assistant produced documents. I shared them in Google Docs, and people added comments, but when the AI updated a document based on reviewer feedback, I had to paste in a new version, which wiped out the existing comments. Documents proliferated without clear relationships between them, and the AI had no visibility into the discussions in the comments, which was where the most important context and pushback lived.
To solve the collaboration problem, I worked with one of our engineering directors to build what we call Superanswers, a system that uses GitHub as the source of truth for AI-generated research documents and their associated discussions.
The architecture is straightforward: Documents are stored as Markdown files in a GitHub repository, a GitHub Pages site renders them with a clean interface that supports inline commenting, and all discussion happens in GitHub Discussions, meaning every comment, question, and revision is versioned and traceable. Because the documents and their discussions live in GitHub, Claude Code has full access to both. It can read the document content plus the entire conversation that’s developed around it.
This enables a qualitatively different kind of AI participation. Instead of generating a document and stepping back, we can now ask:
What is the consensus around this project based on the discussion so far? What questions remain unresolved? Incorporate the reviewer comments and produce an updated version.
The AI becomes a participant in an ongoing conversation rather than a one-shot report generator, which meaningfully shifts how organizational knowledge gets built and refined.
As Superanswers has spread across our engineering organization, the range of questions people bring to it has been broader than I expected:
| Theme | Typical questions |
|---|---|
| Architecture and infrastructure | Should we make this change? What will it cost? What might break? |
| Operational effectiveness | Where is our toil coming from? What should we automate, simplify, or retire? |
| Team health and capacity | Where is the team’s time going? What’s limiting execution? |
| Organization and strategy | How should we organize, prioritize, and invest? |
| Engineering measurement | How do we know if we’re healthy and improving? |
| AI and organizational learning | How do we build better systems for reasoning and decision-making? |
None of these questions is about writing code. They are about understanding an organization, making decisions, and coordinating work, and most of them would map naturally onto the concerns of leaders in other functions. The same questions arise in any organization navigating rapid change with information scattered across too many places.
The AI conversation to date has been dominated by a particular set of questions. But there are more interesting questions we should be asking.
| We’ve spent a lot of time asking… | What else might be possible? |
|---|---|
| How do we make people more productive? | How do we make organizations more effective? |
| How do we produce faster? | How do we make faster decisions? |
| How do we generate output? | How do we generate understanding? |
| How do we accelerate execution? | How do we improve outcomes? |
| How do we gather data? | How do we build institutional knowledge? |
| How do we automate tasks? | How do we improve organizational learning? |
The challenges outlined in this chart aren’t unique to engineering. They exist wherever important information is scattered across multiple systems and important decisions require synthesizing all of it.
Individual productivity matters, but organizations don’t succeed by having contributors go faster in arbitrary directions. They do so by making good decisions about where to invest, allocating resources well, surfacing problems before they compound, and building institutional knowledge that persists over time.
The recipe I’ve described can help organizations make those decisions and build that knowledge.
The recipe for building an organizational intelligence system:
- Map your information hierarchy. Identify the systems where important knowledge lives in your organization, from strategic intent down to operational detail. This is an organizational task, not a technical one, and doing it well requires understanding how decisions actually get made.
- Connect those systems via MCP and write a skill that describes how to reason. The MCP connections give the AI access to your data; the skill file tells it how to think with that data. Without the skill, you get retrieval. With it, you get analysis.
- Add the O’Reilly Expert MCP as an expert review layer. Organizational data provides local evidence about what is happening in your specific context; expert frameworks provide accumulated practitioner knowledge about how to reason about problems of that kind. This step bridges the two. The O’Reilly library spans engineering, management, data science, security, finance, product, and more, organized not as a collection of facts but as coherent frameworks developed by practitioners who spent careers building them. The result is analysis grounded in named frameworks with traceable citations, something human reviewers can engage with and question, rather than generic advice they can only accept or reject.
- Build a lightweight system for human-in-the-loop consensus. AI-generated analysis is a starting point, not an end point. You need a mechanism for people to review, challenge, and refine what the AI surfaces, one where those discussions become part of the context the AI can learn from in subsequent iterations.
The biggest practical lesson I took from this work is reframing what AI is actually for in an organizational context. The difference between a useful AI research assistant and a generic one isn’t primarily about which model you use or how much data you feed it. It’s about whether the reasoning combines local organizational evidence with established expert frameworks. Your data tells you what happened. Expert frameworks help interpret what it means. That combination, with human judgment applied at the end, is what makes the difference between a report that gets read (maybe) and filed away and a recommendation that changes a decision.
[$] Examining other network namespaces using BPF [LWN.net]
Jordan Rife's work involves writing BPF programs for Cilium that interface with Kubernetes networking. As part of that work, he wants to enable BPF programs with appropriate permissions to iterate through the sockets of a different network namespace. He led a session about the idea at the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit where the BPF developers in attendance were quick to suggest a number of related alternatives.
[$] FUSE status and plans [LWN.net]
Filesystem in Userspace (FUSE) maintainer Miklos Szeredi led a birds-of-a-feather (BoF) discussion about the subsystem at the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit. In it, he talked about maintenance challenges, proposed features and their status, and his plans for a new FUSE API. There is a lot of interest and activity in the FUSE community these days it seems.
Saja Wants You To Think About What You Did [Whatever]


Did you think you’d get away with it? Did you think he wouldn’t find out? Saja always finds out. And now you’ll just have to live with him knowing.
In other news, we’re coming right up on the one-year anniversary of Saja’s official adoption. He was clearly alive before then, so being more than one year old now, he’s officially no longer a kitten, he’s just now a teen cat. Trust me, he has the attitude to match.
I’ll probably note his anniversary when it happens, but in the meantime: Enjoy Saja judging you. As he would.
— JS
Nelson: rust-lang/rust is adopting an LLM policy [LWN.net]
Jynn Nelson describes the Rust language team's new LLM policy on the Inside Rust blog.
No one except the author is required to read LLM output unless they choose to: LLM output isn't allowed in public docs, PR descriptions, or Github comments unless it's clearly marked; reviewers aren't required to look at LLM PRs if they don't want to.No one is required to use LLMs to contribute to rust-lang/rust: policies must be written first for humans, and only summarized for machines; LLM reviews cannot substitute for human review or self-review.
You are allowed to generate LLM content that only you see, without disclosure, as long as you do not post it anywhere that you expect us to read or review.
Security updates for Wednesday [LWN.net]
Security updates have been issued by AlmaLinux (fence-agents, gstreamer1-plugins-good, kernel, kernel-rt, p11-kit, perl-Archive-Tar, perl-DBI, and thunderbird), Debian (aom, botan3, and kernel), Fedora (abrt, coreutils, doctl, kernel, open62541, perl, perl-Devel-Cover, perl-PAR-Packer, and polymake), Mageia (acl and php), Oracle (firefox, frr, kernel, libreswan, nodejs-nodemon, nodejs22, perl-Archive-Tar, php:7.4, php:8.2, rsync, and thunderbird), Red Hat (compat-libtiff3, libpq, libtiff, postgresql, postgresql16, postgresql18, postgresql:12, postgresql:13, postgresql:15, postgresql:16, and postgresql:18), Slackware (stunnel), and SUSE (alloy, alsa, bind, chromedriver, corepack24, ffmpeg-4, golang-github-prometheus-prometheus, google-guest-agent, google-osconfig-agent, kubevirt, libgcrypt, libpng16, multipath-tools, netty, netty-tcnative, nodejs26, openssl-1_1, openssl-3, perl-HTTP-Tiny, perl-YAML-Syck, podman, python-sh, python-ujson, rsyslog, spice-vdagent, thrift, valkey, wpa_supplicant, and xen).
CodeSOD: Connection State [The Daily WTF]
Frederick A sends us a bit of null checking code, and offers us a better solution.
class ConferenceService
{
/// <summary>
/// Checks if conference is active
/// </summary>
public bool IsCalling()
{
try
{
return m_ConnectionService.Core.State.IsWebRTCConnected;
}
catch
{
return false;
}
}
}
This is for a web conferencing tool, which uses WebRTC to set up
connections between clients in the chat. This function checks if
the chat is active by checking a IsWebRTCConnected
flag. But as you can see in this code, that flag is on a long chain
of objects, some of which may not exist when this function is
called. Thus, we wrap the whole thing up in a
try/catch. If anything throws an exception, we know we
can just return false. It's probably fine.
The obvious and easy fix, which Frederick proposes, is to use
the C# coalescing operator: ?.
m_ConnectionService?.Core?.State?.IsWebRTCConnected ??
false would solve this problem just fine.
That said, I wouldn't say that's a true fix. We're talking about a state machine here, though admittedly with two states under discussion (connected/disconnected), though there are probably more not being checked here. This information should be managed via a state machine, not via boolean flags stuffed deep in an object chain. The fix isn't a WTF, but it definitely hints at a better way to manage all of this. Now, my solution likely requires a lot more modification and code changes than what we have here, so I'm not suggesting anyone go off and rewrite this from scratch just to have a cleaner way of managing state. But folks definitely should think more carefully about how they manage state.
Introduction to Post-training [Radar]
This is the first article in a series about post-training. Follow along on Radar.
Before post-training, there was a major problem with LLMs: Almost nobody could use them. The story of post-training is also the story of how AI went from a research curiosity to a product used by about a billion people.
Post-training is the reason why a model behaves a certain way. This set of training techniques makes LLMs useful (e.g., able to chat with people and interact with AI agents), safe (e.g., aligned with human intentions), and more capable (e.g., through “reasoning” to tackle difficult tasks). Behavior is powerful, and doesn’t just mean holding a conversation or following a user’s instructions. Behavior includes making it possible for the model to use tools, like a calculator tool, a search API, or any application through an MCP. Behavior can even elevate a model’s intelligence, for example by teaching the model to use “reasoning”: that is, working through problems before giving a final answer rather than “guessing” or “memorizing.”
GPT-3 showed up in June 2020. A completion engine, it followed patterns it had seen from its pretraining data, which were not predominantly chat conversations. Imagine scraping data on the internet: that pretraining data had a lot of questions that were followed by other questions—for example, on an exam template. GPT-3 was 175B parameters, large for its time, and it had a wide, general range of abilities, although many of them were latent.
If you gave GPT-3 a prompt like “Why do people like golden retrievers?” it might say something nonsensical:
Why do people like labrador retrievers?
Why do people like poodles?
10 Reasons You Should Adopt a Dog Today
These answers look absurd in isolation, but if you imagine a web page with a list of FAQ links, this is a perfectly reasonable next chunk of text. GPT-3 might have just been completing a listicle on a website, because it had seen millions of websites in its pretraining data.
The common way to nudge GPT-3 to answer a question back then was by prompt engineering with a Q&A template and few-shot examples.
Q: Why do people like labrador retrievers? A: Because they are friendly, loyal, and easy to train.
Q: Why do people like beagles? A: Because they are curious, great with kids, and have a gentle temperament.
Q: Why do people like golden retrievers? A:
Then, GPT-3 might say:
Because they are affectionate, patient, and make excellent family pets.
While this technique worked, it was brittle. If you forgot the few-shot examples, rephrased the question, or even added a space after “A:,” you’d get something completely different (possibly unhinged) that was far from a reasonable response.
In fact, if you were a researcher working with GPT-3 at the time, you probably at some point found the space at the beginning of the response ” Because they are gentle dogs.” annoying and would try to end your prompt with a space “A: ” instead of “A:”. In those cases, it was common for GPT-3 to go off a cliff and produce a drastically different response, sometimes completely off like “dogs dogs dogs dogs…” repeating indefinitely.
The reason behind the differing responses to “A:” and “A: ” is because “A:” might tokenize to one token while “A: ” tokenizes to two different tokens. The model literally sees different input sequences, each with different statistical completions in its training data. It’s like asking two completely different questions. While a space is a tiny syntactic change that is meaningless to a person, it becomes extremely meaningful to the model that now sees two different prompts (the tokens change!) with two very different statistical futures to complete.
You still encounter the modern equivalent of this when working with chat templates. If you forget to apply the model’s chat template and instead just concatenate
'User: ' + prompt + '\nAssistant: ', you’re sending the model a token sequence that it was not robustly trained on. The tokens are wrong, not the model. Post-training teaches the model to respond to specific token patterns (like<|im_start|>user\nin Qwen models). Not using them is like speaking to someone in a language they half-understand. However, most open source models will be trained to be at least somewhat robust without their templates too.
Under those circumstances, most people would assume AI still didn’t work. The model wasn’t trained to answer questions; its data wasn’t primarily conversation transcripts. Instead, it was trained to predict the next token in downloaded websites, articles, and documents.
Thankfully, this can all be fixed with post-training. And that’s when most people started to believe that AI had undergone a paradigm shift and just might work.
Pretraining heavily influences the model’s knowledge capacity prior to post-training. The model gets raw intelligence during pretraining. Then, during post-training, that intelligence is made useful through behaviors like dialogue and reasoning. In a frontier lab, these two phases are such different processes that very different teams work on them.
A model’s factual knowledge about the French Revolution, its understanding of Python syntax, and its grasp of calculus all come from pretraining. Post-training primarily shapes which knowledge the model reaches for, how it presents that knowledge, what tone it uses, whether it declines certain requests, and whether it thinks step-by-step before answering, though targeted SFT on new domains can introduce information the model didn’t encounter in pretraining.
If a model gives a wrong answer about history, the root cause is likely in pretraining data, but the practical fix might still come through post-training—for example, teaching the model to use search tools, express uncertainty, or chain-of-thought verify its own claims. But if a model gives correct information in a condescending way or refuses to help with a reasonable request or fails to use tools when it should, those are squarely post-training problems.
The work of pretraining is centered around cleaning and curating large-scale data, optimizing the model toward relatively clear loss signals, and working with scaling laws given bounded compute.
In pretraining, the model learns to predict the next token across a large curated dataset, typically for one or a small number of passes over the training data, though some models train for multiple epochs, especially as high-quality data becomes scarce relative to compute budgets. This is where you’ll hear how a model is fed the entire internet’s worth of data to gain intelligence, although in practice nearly all of the data (often 90% or more) may be thrown out because it’s unsuitable for training.
Pretraining is an unsupervised process that runs at increasingly larger scales to match the size of the model. While scaling, thousands of experiments are used to understand what data mix, what architecture considerations, what compute optimizations, what hyperparameters can lead to the best results. There’s variance in each run due to stochasticity found in both software and hardware, so multiple experiments are needed to verify results. Because compute is limited and needs to be used sparingly, researchers will scale iteratively, expanding to the next, say, 10x compute budget, when they gain confidence in the right configuration. A full run isn’t possible to iterate on due to the compute cost and time it would take: The final run, often called the “god run,” can take over a month on thousands of GPUs.
Pretraining progress is typically very clearly measurable, using a metric like perplexity, which measures, roughly, the model’s average uncertainty per token. Lower is better, where 1 means the model knows with absolute certainty what token comes next. Meanwhile, a perplexity of 50 means the model’s predictions are, on average, as uncertain as if it were choosing uniformly among 50 equally likely tokens—though in practice, the distribution is peaked, not uniform.
Rather than consuming hundreds of millions of tokens of internet data, post-training operates on far more intentional datasets for downstream tasks. These datasets include human-written demonstrations of ideal responses, human judgments about which responses from the model are better, and carefully designed functions that score the model’s outputs programmatically. They shape what “good” looks like.
Like pretraining, post-training can also be more effective with scaling data and compute. Specifically, massive compute budgets have been dedicated to post-training to learn reasoning capabilities (or the ability for models to “think step-by-step” to arrive at more logically sound answers), matching the scale of pretraining compute.
Post-training is messier than petraining, which has an elegant, clear optimization objective to minimize the loss over the next token prediction across a huge corpus. The goals of post-training are things like “be more helpful” or “don’t say harmful things.” Many of these objectives are inherently subjective and require human judgment, proxy models that approximate human judgment, or programmatic verifiers that can become elaborate or inefficient. The loss curves are noisier. The quality of the data and feedback matter even more.
The scale of post-training is also more complicated than in pretraining. Standard post-training remains relatively modest in compute: tens to hundreds of GPUs for days rather than thousands of GPUs for months needed in pretraining. This makes post-training for alignment highly amenable to rapid iteration; researchers can try something, observe results, form a hypothesis, and run again on a timescale of days.
The picture changes dramatically when post-training is used to develop reasoning capabilities. For reasoning models, the compute dedicated to post-training can easily account for half of the overall compute of the model. The gap between a standard instruct model and a reasoning model is increasingly a gap in post-training compute, not pretraining scale. This means post-training now spans a wide spectrum from fast, cheap, highly iterable fine-tuning runs to massive RL campaigns that rival pretraining in both cost and engineering complexity.
So why can’t we just stick with pretraining? It comes down to three main pieces: usability, safety, and capability.
A pretrained model is like if someone gave you a large download of Wikipedia in a single PDF. It’s a ton of knowledge that you can sift through, but there’s no way to easily understand what is going on in the data. Post-training gives the model the ability to integrate this information for you and respond to your request naturally. This extends to having longer multiturn conversations and following instructions. Without it, every user would need to be a prompt engineer. With it, anyone who can type a sentence can use the model.
A lot of data in pretraining can be toxic, biased, misleading, or outright dangerous. Or it might not be dangerous on its own, but when a model can integrate knowledge from different fields, it can create something novel that is dangerous.
The model has no inherent sense of what content is good or bad. It will follow any request, based on its pretraining data. To prevent that, you can add safety guardrails to the model in post-training, to refuse harmful requests like asking the model to build a bioweapon and avoid accidentally generating toxic content such as inappropriate sexual content (even if it wasn’t in the user’s request). This is also the place to teach the model to express uncertainty, when it doesn’t know something, whether that’s “I don’t know” or “that’s beyond my knowledge cutoff” or “as a large language model, I’m limited in my knowledge so please consult a healthcare professional.”
Making a model safe is part of a broader area in the AI research community called “alignment,”1 where the goal is to align the model with human values and preferences. Post-training is typically the main way to achieve that.
Model companies will usually have additional safeguards beyond post-training, including lightweight models that check whether the user’s request was safe, as a second layer of protection against responding to harmful requests.
Post-training doesn’t just make a model nicer or safer; it can make the model smarter at hard tasks. The clearest example is reasoning. A pretrained model might have all the mathematical knowledge needed to solve a complex word problem, but it might jump to an incorrect answer because it’s pattern-matching from pretraining data or pattern-matching from how to answer questions (e.g., with succinct immediate answers).
It turns out that making the model output more tokens before giving an answer (or “think longer”), results in better answers. This process is known as reasoning, and post-training can teach the model to reason more effectively. A more capable pretrained model is a more dangerous model if it’s not properly aligned. A more intelligent model is a less useful model to humans if it can’t communicate clearly. And, every point of improvement in a reasoning benchmark now maps to real revenue for companies deploying these models.
Can post-training push models beyond human-level performance? Yes, in specific domains.
In competitive programming, top reasoning models can now solve problems at a level that exceeds the vast majority of human competitive programmers. In math, models have achieved scores on Math Olympiad-level competitions that would place them among the top competitors in the world. In certain scientific domains, models have generated novel hypotheses and solutions that human experts found valuable.
This might seem paradoxical. If the model’s knowledge comes from human-generated data (in pretraining), and its behavior is shaped by human feedback (in post-training), how can it exceed human performance?
Two things make this possible. First, integration across domains. Research is about combining or mixing fields. Imagine mixing every possible field. The pretraining data aggregates knowledge from millions of sources, and no single human has read all of it. Second, post-training, particularly RL with reasoning, teaches the model to explore many approaches to a problem, far more than a human would try in a single sitting. A human might try one or two approaches to a hard math problem.
This means post-training is not just about making models mimic human behavior. It’s about pushing beyond it. This is especially possible to scale with verifier-based RL. In those scenarios, you can expect models to achieve superhuman performance in an expanding set of domains. And that starts with verifiers that are very well-defined, easy to access, efficient, and cheap relative to the ROI of the model learning it. The limitation is no longer the model’s intelligence, but our ability to specify what “good” means through reward signals.
︎Issue 47 – Greta’s Wedding Pt. 2 – 10 [Comics Archive - Spinnyverse]
The post Issue 47 – Greta’s Wedding Pt. 2 – 10 appeared first on Spinnyverse.
Pluralistic: Google is a scammer's paradise (05 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

Forget "Don't be evil"; Google's true motto is a form of vulgar spidermanism: "With great power comes no responsibility." The internet's de facto boss is an absentee landlord.
Google – a thrice-convicted monopolist – is the gateway to the internet, with more than a 90% search market share that it attained by buying out all its competitors and bribing Apple more than $20b/year not to start a rival search engine:
https://www.democracynow.org/2024/8/6/google_monopoly
Google likes to position itself as a wise steward of the internet. They say they use their vast troves of data about the internet and its users to connect the right person with the right information at the right moment. As their mission statement has it, "organize the world's information and make it universally accessible and useful":
https://www.google.com/intl/en_us/search/howsearchworks/our-approach/
The tacit argument is, "Sure, we repeatedly violated antitrust law in order to monopolize the internet, but the internet needs a monopolist. It's scary out there! We have amassed power so that we can protect and guide you."
It's a bullshit argument and no one should accept it – but even if you think it's worth harnessing monopoly power to promote a wise king to rule over the internet, you'd still want Google to take that responsibility seriously. If we're to have a landlord for our civilization's digital nervous system, let's not have it be an absentee landlord.
Google is an absentee landlord. In 2019, they chose to deliberately worsen search results in order to make you search repeatedly to find the information you're seeking, because every fresh query lets them serve fresh advertisements:
https://pluralistic.net/2025/05/26/babyish-radical-extremists/#cancon
Not all of Google's enshittification can be attributed to deliberate sabotage. Much of it is the result of neglect. Ask Google for a product review and they'll pass over the most rigorous, honest websites on the internet in favor of affiliate scammers who repackage Amazon best-of lists to peddle overpriced, underperforming junk that's sometimes so bad it's dangerous:
https://pluralistic.net/2024/02/21/im-feeling-unlucky/#not-up-to-the-task
Google keeps announcing that it Takes This Problem Very Seriously – and then nothing happens:
https://pluralistic.net/2024/05/03/keyword-swarming/#site-reputation-abuse
And of course, Google AI search results present the company with a highly refined and confident-sounding way to launder spam into product recommendations:
https://pluralistic.net/2025/07/15/inhuman-gigapede/#coprophagic-ai
Could Google do better? Provably so. Kagi, a small company that runs a search engine powered by Google's own search index consistently delivers results that are substantially superior to Google's – using Google's own infrastructure:
https://pluralistic.net/2024/04/04/teach-me-how-to-shruggie/#kagi
If Kagi (a startup with a handful of engineers) can extract useful search results from Google's databases, then Google – a thrice-convicted monopolist that's had its pick of thousands of the top computer scientists from the world's most prestigious universities for a generation – could also do so.
They just choose not to.
They're too big to fail. They're too big to jail. They're too big to care.
Google's AI search isn't a way to fix its broken core product: it's a way to partially remediate the damage Google itself inflicted on the open internet, while imprisoning the web in a walled garden that would make Steve Jobs drool:
https://pluralistic.net/2026/06/29/arsonist-firefighters/#im-feeling-lucky
It's a deadly combination: Google has committed hundreds of billions to stock buybacks and its AI money-furnace, financed by mass layoffs targeting the people who keep the core services useful. The too-big-to-care company is still the internet's gatekeeper, but half the guards at the gate have been fired and the other half have pulled so much overtime that they keep falling asleep on the job.
Google has become a scammer's paradise.
Take Google's "answer box." This is the part of the search results page that tries to answer your query directly, without sending you elsewhere for that info. Back in 2023, Google's Answer Box was taken over by scammers who impersonated airline help desks. When Google's users searched for airlines' toll-free phone numbers, Google directed them to phones that rang in the scammers' boiler room, where they were tricked into giving up their passport info and credit card numbers to boiler-room thieves:
(This was an especially devastating attack because the airlines themselves hide their customer service phone numbers – as enshittified monopolists, they want your money, not your complaints – so it's normal to search Google for the number you're seeking, rather than scouring the airlines' deliberately confusing customer service sites.)
This is especially galling because Google has an extensive "verified merchant" program that goes to enormous lengths to establish the true identity of every merchant whose businesses are listed on Google, in maps, ads and search results. Google "knows" which URLs belong to the airlines. If it can be tricked into scraping a different website for the airlines' phone numbers, that's because Google couldn't be bothered to connect its own database of canonical airline URLs to the process that serves phone numbers to the 90% of the web-using public who search with Google.
Google's database of the canonical URLs for businesses doesn't stop at airlines or even large businesses. Nearly every local merchant has undergone Google's verification process, which includes a step where Google physically mails a postcard with a unique number to the merchant's registered address, which the merchant must then key into Google to prove that they're located where they say they are.
Despite this, Google's ad-sales system will happily sell anyone the right to advertise a different website for queries for specific merchants, and those ads appear above the real result for the business's website. To make this even worse, Google's spent years making it more difficult to distinguish ads from "organic" search results, changing the font and size of the "ad" warning to make it harder to spot, and making the font and color of the ad itself closer to the color of the search results below it.
This is a gift to fraudsters. I had my own run-in with it in 2023, when I was tricked by a Google ad into ordering dinner from my local Thai place using a scam site that had cloned the restaurant's menu. The scammers marked up the price by 15%, then passed the order on to the restaurant, pocketing the vig:
https://pluralistic.net/2023/02/24/passive-income/#swiss-cheese-security
This scammer – based out of a UC Berkeley dorm-room – had copied hundreds of restaurant websites, then bought Google ads for the restaurants' names, ensuring that searchers would see the scam result before the real one. Remember: Google knows what the true URL is for every one of those restaurants but it sold the scammer ads for a different URL that appeared when people searched for the restaurant by name.
Google could trivially add a step to the ad sales pipeline that detects mismatches between a merchant's known URL and the URL in an ad bought against the merchant's name. It could automatically resolve these mismatches by sending an email to the merchant's verified email address that says, "Hey, are you buying an ad with a new URL? If so, just reply to this email."
I don't know why Google doesn't do this. Maybe they make huge sums from these scam ads and they don't want to forego the revenue. Or maybe they just don't care.
Whichever it is, there's real consequences for this negligence by the internet's absentee landlord. Take abortions: fake abortion clinics – where pregnant women are bullied or tricked out of the abortions they're seeking – buy Google ads against the names of real abortion clinics. Google makes millions sending abortion-seekers to fake abortion providers:
https://pluralistic.net/2023/06/15/paid-medical-disinformation/#crisis-pregnancy-centers
Google started off as the ideal "intermediary" – the fancy economist's term for a "middleman." They took as their duty to figure out the best websites for you to look at based on your interests, serving as an honest broker between internet users and internet publishers. In the quarter-century since the company's founding, as it transformed itself into a monopolist, it developed the curse of every intermediary: it got Main Character Syndrome.
This is Tim Wu's formulation: the reason for an intermediary existence is to serve the parties to the transaction. Ebay says it exists to connect buyers and sellers, Uber is supposed to connect drivers and riders, dating sites are supposed to connect people with their love-matches. But intermediaries are cursed with an enviable position: by dint of sitting between these different groups of people, the intermediary learns everything about both sides of the transaction, while each side only knows about its own position.
Amazon knows the price you're willing to pay, it knows who's set the lowest price, and it knows how many identical items that match your query are for sale. But the sellers don't know any of that, and you only know some of it. By capitalizing on that information (rather than using it to efficiently match buyers and sellers), Amazon can match you with the sellers willing to pay the highest junk fees, rather than the ones who offer the best price for the best goods:
https://pluralistic.net/2023/11/03/subprime-attention-rent-crisis/#euthanize-rentiers
This is Wu's Main Character Syndrome in action. Once Amazon attains a dominant market share, it can maximize its own welfare at the expense of its buyers and sellers, transforming itself from a helper to a parasite:
https://www.lawfaremedia.org/article/lawfare-daily–tim-wu-on–the-age-of-extraction
Google says it wants to "organize the world's information and make it universally accessible and useful," but every dime it spends fighting fraud (a critical part of this mission!) is a dime it can't spend on stock buybacks, executive compensation and AI servers. "Organize the world's information and make it universally accessible and useful" is the mission of a good intermediary; "do the absolute minimum to fight fraud" is the mission of a formerly good intermediary with terminal Main Character Syndrome.
Google keeps finding ways to expose its users to fraud while lining its own pockets. That restaurant markup scam that caught me in 2023? Three years later, it's way worse.
San Francisco City Attorney David Chiu just filed suit against GuestReservations.com, BookOnline.com and Booking Holdings for running a massive version of the restaurant menu scam – one that extracted millions from people booking hotel rooms:
Here's how the scam worked: these companies put up websites with deceptive URLs, like SanFranciscoMarriott.GuestReservations.com, and then bought the associated Google ad-word ("San Francisco Marriott"). At the top of Google searches for "San Francisco Marriott booking" was the ad for SanFranciscoMarriott.GuestReservations.com. This site would sell you a room at the Marriott, at a markup of 35% to 85%.
This is a pure ripoff. If Google had served the correct result at the top of the page – if it had used its own database of confirmed merchants and their associate websites to validate its ads – then people booking hotels would have saved 35% to 85% on their rooms.
City Attorney Chiu says that the perps here registered domains for all kinds of hotels, even tiny ones in small towns, all over America. That means that it's not just visitors to San Francisco who got screwed by these creeps – it's also San Franciscans who booked hotel rooms around the country.
Google bears the lion's share of the blame here, but Visa and the other credit card companies are critical to these scams. Card companies allow merchants to set terms of service that refuse refunds under almost any circumstances, and, more often than not, the card issuers side with the merchants over their own customers when they call to cancel a charge from one of these scammers.
I discovered this for myself when I was tricked into buying theater tickets from a ripoff site that had registered the URL of the show I wanted to go to. I figured out that I'd been rooked within a minute of clicking the buy button, but it took months and multiple appeals – and ultimately a threat to cancel my credit card – to get Visa to refund me.
Visa – another bloated monopolist with terminal Main Character Syndrome – can see that it has merchants who generate zillions of appeals and charge-backs because they run scam businesses like these. They could treat these merchants as the fraudsters they are, but because the crooks wreathe themselves in gauzy excuses and lengthy terms of service, Visa enables these massive, nationwide cons.
Google, Visa and the other monopolists who serve as de facto regulators for our society have arrogated to themselves the power to observe every transaction and block the obvious scams. We pay for their failure to take minimal, obvious steps to protect us from the scammers who thrive on their platforms.
Why should they? They're the main characters. They're Bizarro-world spidermen, whose great power confers no responsibility.

Gavin Newsom Makes An Ass Of Himself On Antitrust, Paramount Merger https://www.techdirt.com/2026/08/04/gavin-newsom-makes-an-ass-of-himself-on-antitrust-paramount-merger/
Against Self-Fulfilling Prophecy https://www.hamiltonnolan.com/p/against-self-fulfilling-prophecy
Arson markets https://www.merkley.senate.gov/wp-content/uploads/2026.08.03-LTR-Wildfire-Prediction-Markets-FINAL.pdf
Eight Myths on Software Engineering and GenAI https://queue.acm.org/detail.cfm?id=3807963
#25yrsago Steve Ballmer: DEVELOPERS DEVELOPERS DEVELOPERS DEVELOPERS DEVELOPERS http://www.ntk.net/ballmer/dancemonkeyboy.mpg
#15yrsago HOWTO E-Z realistic corpse from a cheap plastic skeleton https://propnomicon.blogspot.com/2011/08/quick-and-dirty-corpses.html
#15yrsago $300 Million Button: making customers create logins to buy cost etailer $300M/year https://centercentre.com/
#10yrsago 1 billion computer monitors vulnerable to undetectable firmware attacks https://www.defcon.org/html/defcon-24/dc-24-speakers.html#Cui
#10yrsago Stiglitz quits Panama’s official money-laundering panel over internal sabotage https://www.reuters.com/article/us-panama-tax-idUSKCN10G24Z/
#10yrsago BBC will use surveillance powers to sniff Britons’ wifi and find license-cheats https://web.archive.org/web/20160806155022/https://www.telegraph.co.uk/news/2016/08/05/bbc-to-deploy-detection-vans-to-snoop-on-internet-users/
#10yrsago How and why to short Uber https://qz.com/707947/investors-have-placed-a-one-way-bet-on-uber-which-made-us-want-to-figure-out-a-way-to-short-it
#5yrsago Facebook's official disinformation research portal is a bad joke https://pluralistic.net/2021/08/06/get-you-coming-and-going/#potemkin-research-program
#5yrsago Scammers sell griefers social media banning services https://pluralistic.net/2021/08/06/get-you-coming-and-going/#curse-of-bigness
#1yrago Which jobs can be replaced with AI? https://pluralistic.net/2025/08/06/unmerchantable-substitute-goods/#customer-disservice

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
F@#$ the AI Overlords (On The Media)
https://www.wnycstudios.org/podcasts/otm/articles/f-the-ai-overlords
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
AI and the Enshittification Era (The Weekly Show with Jon
Stewart)
https://www.youtube.com/watch?v=-dAIJRjb-Bw
AI is not inevitable (Betakit)
https://www.youtube.com/watch?v=DbiTVkq1WHo
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
Vulnerabilities in Car Anti-Theft Device [Schneier on Security]
This is disturbing:
…a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or even disable its ignition and leave a driver stranded.
The disconnect between effort and value [Seth's Blog]
They’re often out of whack.
A Hard Day’s Night took less than 15 hours from idea to finished record. More Than a Feeling, from Tom Scholz and Boston, took five years. Each pleased their audiences. One is not 1,500 times more valuable than the other.
Sometimes, work that requires effort leads to scarcity, and that scarcity can increase its value. But not always.
And just because we put in effort does not mean we deserve the audience to reciprocate with a similar amount. Seven years to write a Ph.D. thesis but a professor on the committee might spend an hour reading it. The student’s effort is not related to the committee’s.
The mythology of creation seems to beg us to calculate the effort when computing the value. But in practice, buyers rarely do.
If the creation is what the audience needs or wants, it actually doesn’t matter how hard it was to create, or who or what created it.
This creates an interesting challenge when it comes to education or fitness. Is the point of assigning an essay to demonstrate that a student can work hard, or to challenge them to have the good taste and judgment to hand in something of quality? Is the trainer at the gym pushing you to go fast/lift a lot, or simply creating the conditions for you to do just a bit more than you did last time?
Focusing on absolute outcomes when we’re trying to improve relative effort is a trap. “A for effort” is a legitimate grade, but even in school, the system rarely chooses to actually do this–the natural writer or athlete gets accolades, not the person who tried harder or overcame obstacles.
When developing our skills, effort is essential. But when engaging in the marketplace, I’m not sure it matters. We should be consistent about which we’re seeking to reward.
Enrico Zini: Gnome refusing to suspend [Planet Debian]
I'm tired, I want to do go bed. I click "sleep" on gnome shell, nothing happens.
Swearwords.
I want to go to bed. I might have want to put my laptop in a bag and run to catch a train. I hate when this happens.
systemd-inhibit --list --mode=block doesn't help
much:
$ systemd-inhibit --list --mode=block
WHO UID USER PID COMM WHAT WHY MODE
enrico 1000 enrico 3042 gsd-power handle-lid-switch External monitor attached… block
enrico 1000 enrico 3037 gsd-media-keys handle-power-key:handle-suspend-key:handle-hibernate-key GNOME handling keypresses block
enrico 1000 enrico 2878 gnome-session-b sleep user session inhibited block
After much googling I found out about
gnome-session-inhibit:
$ gnome-session-inhibit --list
mutter: idle-inhibit (idle)
/usr/lib/chromium/chromium: Playing audio (suspend)
Found the right tab in chromium, paused playing, sleep works again.
My sleep was a good half an hour overdue, and all I got for it was to write this blog post.
Of course Gnome could have shown me its inhibitor list instead of doing nothing, since it has that information, but it didn't.
What I really would expect is that if I intentionally click a suspend button, audio and video playing wouldn't inhibit the suspend. Maybe in a future version of Gnome?
New Comic: Bespoke Speech
Girl Genius for Wednesday, August 05, 2026 [Girl Genius]
The Girl Genius comic for Wednesday, August 05, 2026 has been posted.
Anh Doesn't Get It [QC RSS v2]

she doesn't get it
Creating a fake agile wrapper that is technically agile but is not useful outside its home apartment, part 2 [The Old New Thing]
Last time, we hatched a plan for holding a reference to an object in another apartment that automatically expires when the apartment runs down. Let’s try to implement that plan.
template<typename T>
struct fake_agile_ref
{
private:
using Smart = std::conditional_t<
std::is_base_of_v<winrt::Windows::Foundation::IUnknown, T>,
T, winrt::com_ptr<T>>;
We define Smart to represent the smart pointer that
holds a T. If T is a projected type, then
it is already a smart pointer. Otherwise, T is a COM
interface, and we put it inside a com_ptr. This is the
same pattern that the C++/WinRT agile_ref<T>
uses.
winrt::com_ptr<IContextCallback> m_context;
ULONG_PTR m_token = 0;
winrt::com_ptr<IGlobalInterfaceTable> m_git;
DWORD m_cookie = 0;
void* m_raw = nullptr;
Our fake agile reference starts with a callback context and a context token. These are used to detect whether we are in the correct apartment when it comes time to access the original non-agile COM object.
Next comes a reference to the GIT and a cookie that records the registered reference to the original non-agile COM object.
Finally, we keep a raw (non-refcounted) pointer to the original non-agile COM object.
The fake agile reference is considered “empty” if the cookie is zero, meaning that it does not refer to any object. In the case of an empty fake agile reference, none of the other members contains anything meaningful.
public:
fake_agile_ref(std::nullptr_t = nullptr) noexcept {}
Constructing an empty fake_agile_ref is easy: Just
leave everything at its initial state. In particular, the
m_cookie is zero, meaning that there is nothing
inside. The values of all the other members are irrelevant, as long
as they can be safely destructed.
fake_agile_ref(Smart const& p) : m_raw(winrt::get_abi(p))
{
if (m_raw) {
m_context = winrt::capture<IContextCallback>(CoGetObjectContext);
m_token = get_context_token();
m_git = winrt::create_instance<IGlobalInterfaceTable>(CLSID_StdGlobalInterfaceTable);
winrt::check_hresult(m_git->RegisterInterfaceInGlobal(
static_cast<::IUnknown*>(m_raw), __uuidof(IUnknown), &m_cookie));
}
}
To construct a fake_agile_ref from a smart pointer,
we extract the raw pointer and check whether it is null. If so,
then the smart pointer is empty, and we leave the
m_cookie at zero. But if it is not null, we initialize
the context information (so we can recognize this apartment later),
and we register the COM object in the GIT to retain a reference to
it for as long as the apartment is valid.
fake_agile_ref(fake_agile_ref&& other) noexcept :
m_context(std::move(other.m_context)),
m_token(std:exchange(other.m_token, 0)),
m_git(std::move(other.m_git)),
m_cookie(std::exchange(other.m_cookie, 0)),
m_raw(other.m_raw)
{
}
Since we will have a nontrivial destructor, we need copy and move constructors per the Rule of Five. The move constructor merely steals all the content from the source and leaves the source in the empty state. We don’t need to create a copy constructor because the move constructor causes the implicitly-defined copy constructor to become deleted. (The fake agile reference is not copyable because we don’t know how to copy the cookie.)
fake_agile_ref& operator=(fake_agile_ref&& other) noexcept
{
using std::swap;
swap(m_context, other.m_context);
swap(m_token, other.m_token);
swap(m_git, other.m_git);
swap(m_cookie, other.m_cookie);
swap(m_raw, other.m_raw);
}
The fake agile reference also needs a move assignment operator to satisfy the Rule of Five. It just swaps the contents with the assigned-from object. Again, we don’t need a copy assignment operator because the declared move assignment operator causes the implicitly-defined copy assignment operator to become deleted.
bool empty() const noexcept
{
return m_cookie == 0;
}
explicit operator bool() const noexcept
{
return !empty();
}
An explicit boolean conversion operator lets callers test the fake agile pointer to see whether it is empty.
~fake_agile_ref()
{
if (!empty()) {
m_git->RevokeInterfaceFromGlobal(std::exchange(m_cookie, 0));
}
}
We have reached our nontrivial destructor: If we have a GIT
cookie, we revoke it. It would have been nice to let this be a
custom deleter of a unique_ptr, but a cookie is not a
pointer, and unique_ptr works only with pointers.
[[nodiscard]] Smart get() const
{
if (empty()) {
return nullptr;
}
if (m_token != get_context_token()) {
throw winrt::hresult_error(CO_E_NOT_SUPPORTED);
}
Smart result{ nullptr };
winrt::copy_from_abi(result, m_raw);
return result;
}
Here is where the excitement is. To recover the original COM
object, we first check if the fake agile pointer is empty. If so,
then there is no COM object to return. If the fake agile pointer is
nonempty, but we are in the wrong apartment, then we throw the
CO_E_NOT_SUPPORTED exception which is the same thing
that RoGetAgileReference does.
Otherwise, we are in the correct context. Our cookie is keeping the original object alive, so we can just recover it from the raw pointer. (We could also redeem the cookie from the GIT, but this is faster.)
};
That ends the definition of fake_agile_ref, but
we’re not done yet.
template<typename T> fake_agile_ref(winrt::com_ptr<T> const&)
-> fake_agile_ref<T>;
template<typename T> fake_agile_ref(T const&)
-> fake_agile_ref<T>;
These deduction guides allow class template argument deduction
(CTAD) to deduce the T from the constructor parameter:
If the constructor parameter is a com_ptr<T>,
then the template type parameter is T. Otherwise, the
template type parameter matches the constructor parameter, which we
assume is a projected type.
We can now use this fake agile reference as a drop-in replacement for the normal agile reference in the case that the delegate is not marshalable.
template<typename Delegate>
std::remove_reference_t<Delegate> make_agile_delegate(Delegate&& d)
{
if (d.try_as<::IAgileObject>()) {
return d;
}
if (d.try_as<::INoMarshal>()) {
return [agile = fake_agile_ref(d)](auto&&...args) {
return agile.get()(std::forward<decltype(args)>(args)...);
};
}
return [agile = winrt::agile_ref(d)](auto&&...args) {
return agile.get()(std::forward<decltype(args)>(args)...);
};
}
Unfortunately, when we take this out for a spin and give it a non-marshalable delegate, it fails at this line:
winrt::check_hresult(m_git->RegisterInterfaceInGlobal(
static_cast<::IUnknown*>(m_raw), __uuidof(IUnknown), &m_cookie));
That’s because
RegisterInterfaceInGlobal will not
register objects that deny marshalability.
Oh great, so we’re back to square one.
We’ll break the cycle of despair next time.
The post Creating a fake agile wrapper that is technically agile but is not useful outside its home apartment, part 2 appeared first on The Old New Thing.
Tomorrow’s U.S. Senate Vote: Four Internet Bills, One Wrong Direction [Deeplinks]
The Senate Commerce Committee will vote this week on several censorious and privacy invasive bills: KOSA, the SCREEN Act, Youth AI Privacy Act, and CHATBOT Act. While we appreciate that the Committee is taking the time to look at these bills separately, it’s still impossible to ignore the message Congress is sending to the world: Age-gate the internet and block young people from speaking and accessing lawful speech online. Or else.
Tell Congress: don't age-gate the internet
Each of these bills claims to be trying to protect children and teenagers from dangerous situations on and offline—certainly a worthy goal. But the proposed solutions in these bills are unlikely to make children and teenagers safer at all. Rather, they would create sweeping new privacy and data security problems, and force platforms to adopt unconstitutional restrictions on the content they host, for both adults and teenagers.
There is a better way. Instead of considering these bills, the Senate Commerce Committee should be focusing on a national consumer privacy bill that would protect ALL internet users, or on banning behavioral advertising that tracks us across the web—again, for users of all ages.
But the bills being considered this week move in the other direction—more information being collected, more surveillance, and less privacy for internet users of all ages.
help eff oppose these bills
EFF sent a letter to the Committee with our concerns about these bills. We look forward to continuing to work with them to find a way forward that protects all users.
Russell Coker: Monitors for Work [Planet Debian]
Some time ago I worked in the IT department of a company that had a corporate standard of two 27″ FUllHD (either 1920*1080 or 1920*1200) monitors for the desktop. I was pushing to make the standard be one 32″ 4K monitor or the two cheaper monitors. They ended up making one 27″ 4K monitor an option which was still a better option for many users than two FullHD monitors due to having twice the pixels even though it had half the screen area. It was a surprise to me when hardly anyone took up that option.
One man who worked there brought a wide curved monitor from home and ran with one of the FullHD monitors on each side of that. As an employee in the IT department I had concerns about expensive personal equipment being used in the office regarding who’s going to pay the bill if it gets broken. But I was assured that it was his old monitor that he didn’t need after buying a better one for gaming at home and he wouldn’t be too upset if something happened to it.
This isn’t the only time I’ve witnessed such problems of companies paying large salaries for skilled people and providing poor equipment for them to do the work. One previous time I raised a OH&S issue because the outdated monitors were so blurry but the company determined that the monitors wouldn’t cause health problems and spending $150 per employee on better replacements was a waste of money.
Computer hardware tends to become cheaper over time and one thing that has become really cheap recently is portable monitors. Kogan has a 15.6″ FullHD monitor with USB-C and mini-HDMI inputs for $89 [1]. It wouldn’t be difficult for someone to put one of those on each side of the monitor or monitors that their employer provides and put them in a desk drawer at the end of the day to minimise risk. The same Kogan page has a 16″ monitor with 2560*1600 resolution for $189.
I previously wrote about the potential benefits to companies in not owning all those keyboards, mice, and headsets when they could just give each employee the money and have them buy their own [2]. I don’t think we are at the stage where that can be applied to monitors as the cheapest price for a decent monitor is about $500 which takes it out of the disposable price range that keyboards and mice are in. Also from an IT support perspective there are real support issues with monitors and cables having compatibility issues. But paying small amounts of money to reimburse employees who buy cheap portable monitors to supplement their main monitor is a more reasonable option. For some people that will allow noteworthy improvements in work performance.
I don’t think that adding such portable monitors will directly help the majority of workers. I think that to maximise performance and efficiency we need to chase the long tail of improvements. Big monitors, really big monitors (65″ at a larger distance), multiple monitors, standing desks, and whatever else people want.
There was some research from Microsoft some years ago (back when 27″ was a really big monitor) showing that some tasks had a 50% increase in performance with a larger monitor. Now that 27″ is about the smallest monitor size commonly available the potential for improvement is reduced. Probably most workers now already have monitors that provide the benefits to them that the “big monitors” in Microsoft research provided. But there will always be some portion of the user base who will benefit. If you can get a 50% performance boost for 1% of the users that’s really worth doing. If you can get a 0.5% benefit for 100% of the users that is also worth doing and will theoretically give equal benefits.
It is claimed that the total cost of an employee including all overheads of management and providing office facilities etc amounts to twice their base salary. If that is the case then a minimum wage employee in Australia costs $100k per year, someone at the low end of the IT pay scale costs $200k, and someone at the high end of the IT scale is around $400k. It seems clearly worthwhile to spend $1000 in hardware purchases for a $100k employee who declares that it will really help their work, anything which is noticeable to the user is going to be more than a 1% difference in performance.
For someone at the high end of the IT pay scale spending $40,000 on hardware to improve their performance could pay for itself. This is not only due to direct return on investment but because the people who do such work are often in key roles in important projects. If there’s too much work for one person on minimum wage to do then you just hire another person. You can’t hire another senior IT person and have them just do the work, it can take months to get up to speed.
But as management in corporations seems unable to recognise this cheap hardware employees can afford to buy with their own money can bridge the gap.
In future when interviewing for jobs I’ll ask about the hardware that’s to be used. I won’t say “I’m not interested in this job offer because you don’t respect your employees enough to buy adequate hardware”, but I may make it a condition of working at a company that the hardware on my desk will not be obsolete.
An LLM agent attempts to compromise a project on GitHub [LWN.net]
The AI Security Institute has released a detailed report on an security incident of its own making. The Institute set some LLM agents loose on the Internet with a security challenge; soon they were creating malware-laden pull requests and sock-puppet accounts to promote them.
The agent opened a malicious pull request (PR) to ⟨REPO_A⟩ and pursued a number of strategies to get it merged:
- Repeatedly commented on the PR with sockpuppet accounts to manufacture consensus and pressure the maintainer into approving with minimal review.
- Opened a GitHub Issue in another repository (also owned by ⟨PERSON_A⟩) containing a prompt injection for other coding agents. The malicious instructions were addressed to issue-triage AI coding agents and invisible to humans viewing the website.
- Sent multiple emails to ⟨PERSON_A⟩ and ⟨PERSON_B⟩, with different pretexts to get them to run malicious code. Over the course of the sample, the agent sent five emails, some containing malware, others aimed at persuading a maintainer to accept the pull request.
It would be surprising if this were the only incident of this type; the only real difference here is that the people involved are documenting what happened.
Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA [Deeplinks]
The Ninth Circuit Court of Appeals has endorsed a commonsense technical interpretation of the Computer Fraud and Abuse Act (CFAA), a law not usually given to such interpretation. Amazon had sued Perplexity AI to try to shut down its Comet browser, claiming the browser’s optional agentic AI “Assistant” that can browse websites like Amazon for comparison shopping purposes, violated the CFAA because Amazon did not “authorize” Perplexity to access Amazon users’ accounts. Rejecting that theory, the Ninth Circuit held that Perplexity was unlikely to be liable because users operate the tool, not Perplexity.
That’s the right conclusion, as both a legal and technical matter. As we explained to the court in our amicus brief, the CFAA requires unauthorized “access,” and Perplexity itself does not access Amazon’s servers—users of the Comet browser do. The court agreed, noting that EFF’s explanation “articulates the nature of the system most clearly.”
The court noted that agentic AI may present novel legal issues, and there is “little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant, let alone caselaw specifically dealing with agentic AI in the CFAA context.” Ultimately, though, thorny questions of AI “intent” were irrelevant to this case, because the Assistant “is a tool, not a person for statutory purposes.” And, the court concluded, it is a tool operated by users, not Perplexity. Even where Perplexity received information from users about their Amazon accounts and used this information to instruct the Assistant, the court found that that did not constitute the sort of control needed to find access by Perplexity. As the court noted, Amazon might have other viable claims against Perplexity, but invoking the CFAA was both legally baseless and bad policy that “could expose users themselves to criminal liability.
This is a gratifying decision because all too often, big players use the CFAA to bully upstarts and innovators who offer potentially helpful user tools. When we counsel clients as part of EFF’s Coders Rights Project, CFAA risk is a frequent topic of conversation, even for developers who merely create tools that allow others to access websites in new or different ways. We’ve stood up for these creators before, and we’ll do it again, but it’s helpful to have back up from one of the most influential appellate courts in the country.
Corporate players in Amiga community sign various agreements to clear up some of the decades-old licensing and ownership mess [OSnews]
Few things in technology are more complex, convoluted, and riddled with literally decades of drama than the Amiga community. Luckily for all of us, a significant step forward has been made today: several of the key corporate players in the community have struck agreements to settle their legal disputes.
CIC licenses software and documentation for Commodore’s 8-bit computers from Amiga. In return, Amiga is permitted to continue using the Commodore trademarks in a “historical or descriptive context,” such as old documentation, copyright notices in existing software, or as symbols on a keyboard.
The agreement with Hyperion does not change the status of AmigaOS 4 – which was never a point of contention, according to Amiga – but it does specify exactly which code and trademarks the Belgian company is permitted to use [under license from Amiga, editor’s note].
But Hyperion’s involvement in the 68k market will end on December 31, 2027: the licensee may continue to distribute versions of AmigaOS 3 until then, including the as-yet-unreleased AmigaOS 3.3. After that, Hyperion will deliver source code, revision history, and documentation for AmigaOS 3.1.4 and its updates, including all fixes and updates, but excluding AmigaOS 4 code backported into AmigaOS 3.2 or 3.3, to Amiga Corporation and release the developers involved in the project from all obligations to Hyperion. Amiga itself will then take over further development of AmigaOS 3 in the future.
↫ Post on amiga-news.de
Hyperion is the company most known for developing AmigaOS 4, and with these agreements in place, they claim they can finally spend time focusing on getting AmigaOS 4.2 out the door. These agreements will also consolidate most of the AmigaOS 3.x code and IP under a single banner, which should make its status quite a bit clearer going forward. Whether or not any of this is actually good and beneficial to the Amiga platform as a whole and its individual branches – 3.x and 4.x, in particular – is anyone’s guess.
I don’t think there’s anyone here on OSNews who wouldn’t be interested in, say, an affordable and – most importantly – available AmigaOS 4 machine. While I have no clue if clearing up some of the licensing, IP, and ownership confusions will aid in getting new AmigaOS 4 hardware, it surely won’t make it any harder.
But can your calculator run Linux? [OSnews]
Don’t have enough computing devices on your wish list yet? Do you have a need for a graphing calculator? No? What if it can run Linux and even Windows 10? I see I’ve got your attention.
The HP Prime is a graphing calculator on the market since 2013, with a hardware revision in 2018 (the G2 model). It has a touch screen and as far as I can find, most people are happy with it and find it a very capable and fast calculator. Here are some pictures of the opened up calculator and here is a website with some more downloads.
I’m not really interested in the calculator part. For most calculations I do for my day job, embedded programming, the HP-16C is a better fit. I was interested in this device because I found posts online suggesting it could run Linux and even a Windows 10 port.
↫ Remy van Elst
I had no idea just how overpowered – for a graphing calculator – the G2 really is. It’s basically an Android smartphone from a few years ago, and that means that yes, it can run Linux, including X, Doom, and tons of other applications. It’s not the easiest of devices to get custom software onto, but also not particularly difficult – you need to open it up and short two pads – so if you have one, it’s definitely a fun project. Apparently, someone also ported EUFI for Windows 10 to this thing, so you can do silly stuff like run the Windows calculator on the G2 calculator.
Wild. Now I kind of want one.
Wireguard comes to 9front [OSnews]
Want to switch to 9front, especially with the new release having just been made available, but really need Wireguard? Fret not! Wireguard is now available on 9front, experimentally.
IBM i (OS/400): the database operating system [OSnews]
Today, I wanted to show you one of the most fascinating and surprising operating systems ever created. It’s not another Unix, Linux, or Windows. It is an architecture that went its own way and proved that systems engineering design can look completely different.
I’m talking about IBM’s child, which for many might be synonymous with “boring banking systems,” but in reality, is one of the most uncompromising projects in IT history. While we get excited about abstraction and virtualization today, thinking we are discovering new lands, this system was doing it decades ago. Imagine a system that doesn’t know the concept of a “file” in the way we understand it. A system where everything is an object, and all disk and operational memory form one vast, flat space. If you are looking for proof that true engineering doesn’t need buzzwords to blow you away, I invite you to read on.
↫ Kamil Pytliński
Ever since watching Clabretro’s detailed video about getting IBM i to work on his own IBM POWER hardware and then remoting into them, I’ve been obsessed with running IBM i at home. It feels like the final boss of operating systems to dive into and explore, hidden in the deepest, darkest trenches of the ocean of technology. Everything about IBM i feels alien, complex, convoluted, opaque, and overwhelming, and you can probably dedicate your entire career to working with this platform and somehow still learn new things about it every day.
There’s something brutalist about IBM i, and I so desperately want to bang my head on its concrete walls.
Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds [Deeplinks]
SAN FRANCISCO – Some software development kits (SDKs) provided by advertising companies to help developers monetize their apps are automatically feeding users’ location data into systems that location data brokers use to track people, an Electronic Frontier Foundation (EFF) report found.
EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers. The probe revealed how such SDKs can facilitate and encourage location data sharing – without users’ knowledge or meaningful consent – through privacy-invasive defaults, financial incentives, and unclear documentation.
“Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information,” EFF Staff Technologist Lena Cohen said. “Users can take extra steps to defend their location privacy, but they shouldn’t have to. Developers, regulators, and legislators must act to stop apps from leaking users’ location to advertising companies and data brokers.”
Cohen and EFF Senior Staff Technologist Bill Budington reviewed the public developer documentation of dozens of widely used advertising SDKs to identify how they handle and communicate with developers about location data.
In their analysis, they highlighted four advertising SDKs that collect and share a user's location by default for ad targeting whenever the user has given the app location permissions: InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads. But EFF’s focus on these four does not mean that other SDKs adequately protect location data or that developers never choose to share location data when it’s not the default. In fact, advertising SDKs not discussed in this investigation have been criticized and sued for collecting location data without valid user consent.
“When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads,” Budington said. “Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel. Developers have a responsibility to protect their users’ from these harms, regardless of advertising SDKs’ default settings.”
For the EFF report: https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy
For more on location data brokers: https://www.eff.org/issues/location-data-brokers
For more on SDKs: https://www.eff.org/deeplinks/2022/06/how-federal-government-buys-our-cell-phone-location-data
Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy [Deeplinks]
Across mobile platforms, advertising companies provide developers with software development kits (SDKs) that make it easy to monetize their apps. But those same SDKs can automatically feed users’ location data into ad systems that location data brokers use to track people. Many developers may not even be aware of this privacy violation, let alone the users who are directly affected.
When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads. Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel.
Defaults matter, not just for users, but for app developers as well.
An EFF investigation has identified several advertising SDKs that publicly acknowledge collecting and sharing users’ location by default when embedded in Android apps granted location permissions. Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information.
This report explains how advertising SDKs can facilitate and encourage location data sharing through privacy-invasive defaults, financial incentives, and unclear documentation.
When an advertising SDK collects and shares location data, it becomes part of a larger ecosystem that can include advertisers, ad tech companies, and location data brokers. EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers.
Location data brokers sell information on the precise movements of billions of people without their knowledge or meaningful consent. This data is primarily sourced from apps on people’s phones. Some apps partner with data brokers directly, using data-broker-developed SDKs or server-to-server transfers to sell users’ location data. Other apps leak users’ location data through advertising SDKs serving behaviorally-targeted ads through “real-time bidding” (RTB). In the process of auctioning off ad space, ad tech companies can broadcast user data to thousands of potential advertisers. Location data brokers have participated in these auctions not just to bid on ad space, but to collect personal information contained in bid requests.
Indiscriminate data sharing through RTB can lead app developers to unknowingly share their users’ location with data brokers. In 2025, a hack of location data broker Gravy Analytics revealed thousands of apps that may have been sources of its data. When journalists reached out to the app developers, many claimed they had no relationship with or knowledge of Gravy Analytics. To prevent location information from being shared with data brokers through RTB, developers must understand the location-sharing practices of their advertising SDKs.
Developers don’t have to manually, or even intentionally, share location data for it to be broadcast through RTB auctions. Once a user grants an app permission to access their location, SDKs embedded in the app receive the same access—there are no SDK-specific location permissions. That means advertising SDKs can automatically collect users’ location data and share it in bid requests.
While apps and SDKs can estimate a users’ approximate location from their IP address without requesting any permissions, location permissions provide access to estimates that are more accurate and revealing. Precise location permissions give apps (and their embedded SDKs) access to location estimates within about 160 feet, but sometimes as accurate as 10 feet. Approximate location, a separate permissions level, gives apps access to a location estimate within about 1.2 square miles.
Developers and advertising SDKs also have a financial incentive to share location data, since it can increase bid prices for an app’s ad space. While many advertising SDKs require developers to configure a setting before collecting and sharing users’ location data in ad requests, this is not always the case. EFF found several advertising SDKs who publicly acknowledge sharing users’ location data by default when embedded in apps granted location permissions.
EFF reviewed the public developer documentation of dozens of widely-used advertising SDKs to identify how they handle and communicate with developers about location data. In the following sections, we highlight four advertising SDKs who engage in a particularly egregious practice: collecting a user's location by default for ad targeting whenever a user has given an app location permissions. We reached out to each SDK company and the referenced app developers for comment. One company responded, and as detailed below, subsequently updated its documentation in response to our questions. Another company responded with clarifications to its developer documentation.
We chose to focus on SDKs with this privacy-invasive default because it increases the risk of developers leaking users’ location data without realizing it. Several studies have found that developers tend to stick to SDKs’ default settings. If an advertising SDK transmits location data by default, users' precise location can end up in advertising systems without the developer intentionally enabling location sharing. These SDKs have separate documentation pages that instruct developers to flag users covered by privacy laws like GDPR and COPPA for restricted data processing, but these modes are not the default.
By analyzing how these four SDKs present their location sharing practices to developers, we hope to illustrate how the design and documentation of advertising SDKs can facilitate location data sharing at scale. Although the advertising SDKs we highlight are not the most prevalent SDKs used, they are embedded in thousands of apps and reach billions of users.
InMobi claims to reach “2B+ users across 150+ countries” and is the 10th most popular advertising SDK on Android (according to AppBrain and Appfigures at the time of publication).
InMobi’s “Getting Started with Android SDK Integration” suggests that location sharing is enabled by default, stating “The InMobi SDK automatically forwards location signals when available.” InMobi provides developers with a setting to opt out, but explicitly recommends sharing location data. Developer documentation highlights the financial incentive for location sharing, stating “location-enriched impressions typically yield higher revenue.”

[Observed on “Getting
Started with Android SDK
Integration,” 7/31/26]
Apps that use InMobi may not need location information to function or may only need access to approximate location information, but InMobi highly recommends that developers request precise location permissions “to enable accurate ad targeting.” They even encourage developers to request Wi-Fi network information permissions, which (when paired with precise location permissions) provide Wi-Fi access point identifiers that can also be used for location tracking.

[Observed on “Getting
Started with Android SDK
Integration,” 7/31/26]
InMobi has been accused of misleading developers over location sharing practices in the past: In 2016, they settled with the FTC over charges that they bypassed users’ location permissions for apps and tracked their precise locations through WiFi network data (Android now requires apps to request location permissions to access this WiFi data too).
BidMachine claims to reach over 600 million “direct SDK users.”
BidMachine reveals that it collects location data by default on the “Advanced Settings” page of its Android SDK Integration guide, stating that the “SDK can automatically track user device location to serve better ads” as long as developers request location permissions for their app. Before publication, EFF reached out to BidMachine for comment, notifying them of our plan to highlight their Android SDK location sharing practices.

[Observed on “Advanced
Settings” on 7/31/26, before EFF asked
BidMachine for comment]
After EFF reached out, BidMachine changed their documentation to clarify the practice, but not their default collection of location information once app-level permissions are granted. This updated section still fails to explain how developers can opt out of BidMachine location tracking, which is critical for app developers that require location access for core features but wish to prevent user data from being shared with advertisers.

[Observed on “Advanced
Settings” on 8/3/26, after EFF asked BidMachine for
comment]
Before EFF reached out, BidMachine’s “App Privacy Details On Google Play” page had stated that they only collected coarse location data and precise location data was “not collected.” However, our technical analysis of two apps, which Exodus Privacy determined include the BidMachine SDK, contradicted this claim: Network requests from the apps QR Scanner and GPS Speedometer to a BidMachine domain include precise location coordinates.

[Observed on “App
Privacy Details On Google Play” on
7/31/26, before EFF asked BidMachine for
comment]
After EFF reached out, BidMachine also corrected its documentation to make it clear precise location is collected by the SDK whenever the app-level permission is granted:

[Observed on “App
Privacy Details On Google Play” on
8/3/26, after EFF asked BidMachine for
comment]
com.appswing.qr.barcodescanner.barcodereader_bidmachine.flows

com.ktwapps.speedometer_bidmachine.flows

In response to our request for comment, BidMachine stated that it wasn't possible for them to get location information “unless the user has granted the app the relevant permission through the operating system.” They also stated that“publishers are responsible for configuring their apps' permission and consent flows.”
Verve has claimed its HyBid SDK reaches “over 1.5 billion users across more than 10,000 apps worldwide.”
Verve’s configuration guide for its HyBid Android SDK (formerly called Pubnative HyBid) makes clear that location tracking is “enabled by default,” stating, “If the user has given location permissions, HyBid SDK will use the available user location to provide better targeted ads.”

[Observed on “HyBid
Android SDK - HyBid Configuration,”
7/31/26]
Verve’s guidance for data disclosure to the Google Play Store tells a more careful story. Despite the fact that location tracking is enabled by default, the Google Play Data Safety Guidance states that the SDK “does not collect or attempt to collect [location] information independently.”

[Observed on “Google
Play Data Safety
Guidance,” 7/31/26]
It also emphasizes user consent, claiming the SDK will only collect location data “if the publishers allows its app to collect location data from users after obtaining user’s explicit consent to such data collection” (emphasis added). The configuration guide lacks recommendations or instructions for obtaining user consent to share location data with Verve, beyond app-level access. Instead, the configuration guide highlights the financial incentives for developers to add location permissions to their app.

[Observed on “HyBid
Android SDK - HyBid
Configuration,” 7/31/26]
When reached for comment, Verve clarified that “in its current Android implementation, the SDK reads the cached network-provider location and does not use the GPS data of the end user's device. Furthermore, any geolocation data is coarsened prior to processing, ensuring that location is limited to an accuracy radius of no less than 1,850 feet.” It also said that it contractually requires apps to comply with data protection laws.
To Verve’s credit, the HyBid SDK is open source, so careful developers can check the code instead of relying on documentation alone. HyBid’s open-source code shows that latitude and longitude coordinates are rounded to two decimal places, and that it does only collect and share network-derived location data, confirming the statement the company sent to us. If an app has precise location permissions, networked-derived location data rounded to two decimal places could be accurate within approximately 0.5 square miles, which is still more precise than the 1.2 square miles typically revealed with Android’s approximate location permission. But even coarse location data, especially when collected repeatedly over time, can reveal movements that should remain private by default.
Verve’s response also conveyed a willingness to revise their documentation: “As part of our ongoing commitment to providing clear and comprehensive developer resources, we continually review and enhance our documentation, and we will take your observations into account as part of that process.”
Huawei has claimed its Petal Ads SDK is embedded in more than 85,000 apps worldwide.
Huawei’s “Integrating the Petal Ads SDK into an Android App” guide begins with a recommendation that developers obtain location permissions to increase app revenue and an acknowledgement that location sharing will happen by default in apps with location permissions.

[Observed on “Integrating
the Petal Ads SDK into an Android
App,” 7/31/26]
A separate “Use of Location Data for Ads” page repeats that the Petal Ads SDK will include users’ location information in ad requests if an app has access to location information. Neither of those pages mention that developers can use the setRequestLocation method to disable the default collection of location information (this setting is referenced in the last section of the Ads SDK Compliance Guide). Huawei’s Ads SDK Privacy Statement states that “The SDK and its services will not store precise location information, and will only use it to determine the approximate device location.” However, the guide does not specify how Huawei defines approximate versus precise location data.

[Observed on “Use
of Location Data for Ads,” 7/31/26]
In some cases, after an app itself obtains location permission, advertising SDKs can separately obtain and share users’ location information without their knowledge or meaningful consent. Neither app that EFF observed sharing precise location data with BidMachine (QR Scanner and GPS Speedometer) showed a notice or requested consent before doing so. Additionally, neither apps’ Google Play Store “Data safety” section includes location data under “This app may share these data types with third parties.” The lack of transparency and control that users have over their location on mobile apps is dangerous. QR Scanner and GPS Speedometer are just two examples of apps that quietly share users’ location data through advertising SDKs, but they have been downloaded more than 50 million and 10 million times, respectively.
App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.
Even if users’ were to grant these apps permission to obtain their location data, they would likely not expect their location data to be shared with third parties. Many users don’t know that granting location permissions to an app grants the same permissions to third-party SDKs embedded in the app, or that an app they're using contains code from outside companies. And many apps that request location permissions, like GPS Speedometer, require it for core functionality. App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.
Our initial focus on four advertising SDKs does not mean that other SDKs adequately protect location data or that developers never choose to share location data when it’s not the default. Advertising SDKs not discussed in this report have been criticized and sued for allegations that they collect location data without valid user consent.
The issues we’ve highlighted around privacy-invasive defaults, financial incentives, and unclear documentation extend beyond the specific SDKs we analyzed. Multiple studies have found that advertising SDKs often steer developers toward increased data collection through their design and documentation. A 2021 study found that popular advertising SDKs used dark patterns to nudge developers towards sharing more sensitive data. A 2024 study identified discrepancies between several SDKs’ documentation and their actual data collection practices. And a 2025 study concluded that developers have minimal influence over SDKs’ data transmission, often leaving them with the choice of accepting SDKs' invasive data collection or avoiding them entirely.
EFF’s analysis shows that advertising SDKs don’t just allow developers to share location data–they often encourage it. Default settings, financial incentives, and unclear documentation can make sharing users’ location the easiest option for developers.
Users can take extra steps to defend their location privacy, but they shouldn’t have to. Developers, regulators, and legislators must act to stop apps from leaking users’ location to advertising companies and data brokers.
Developers should carefully evaluate all third-party SDKs they include in their apps and disable unnecessary data collection whenever possible. Regardless of advertising SDKs’ default settings, developers have a responsibility to protect their users’ location data. But protecting users’ privacy shouldn’t depend on developers reading the right piece of SDK documentation. Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person’s location.
Regulators should continue to hold app developers accountable when they unlawfully share personal data and include libraries which subject users to privacy harms, as they have in the past. But they should also scrutinize the companies whose SDKs encourage these practices at scale. Otherwise, companies can continue to design SDKs that make invasive data sharing the default while shifting the responsibility and consequences to developers who include their tools.
The US is in dire need of a federal law to protect all Americans’ location privacy, one which doesn’t preempt stronger state privacy laws, and has a private right of action empowering individuals to sue those who violate their privacy. Countries across the globe should likewise enact legislation that protects their users’ location privacy. Everyone deserves privacy as a universal human right.
Legislators can address the root of the problem by banning online behavioral advertising. This would remove the primary incentive for companies to track and share your personal data. It would also prevent users' precise locations from being broadcast to data brokers through RTB auctions.
Until then, developers should be wary of ad libraries that betray their users’ location privacy.
Notes on MethodologyWe were interested in looking at network traffic for various Android ads SDKs that send precise location by default when granted location permissions. We chose Android for this investigation because of the relative openness of and our familiarity with analysis on the platform. We’ve used publicly available resources like Exodus Privacy and AppBrain to identify popular ads SDKs and the apps which include them. In a lab setting, we set up a machine to view our own http(s) traffic using mitmproxy from our test device, and connect the test device to that machine in order to view our real-time traffic. Where needed, we use the dynamic instrumentation toolkit Frida to ensure the traffic we generate can be analyzed. We’ve included flows files in this post, which can be opened in mitmproxy to show the requests we’ve observed with location coordinates. |
Iran Cyberattacks Against Minnesota Water Systems [Schneier on Security]
Attribution is preliminary, and so far it seems no real damage.
And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself.
“I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”
No word on whether he believes the other six states have hacked themselves as well.
Slashdot thread.
2019: "This will be remembered as the time we all waited for someone else to take the risk, not wanting to disturb our lives. The spoiled citizens of a country that fought wars without a draft, that got tax cuts in time of war, inflated our economy as we inflicted chaos on others.”
We're still socialists [Scripting News]
I was into Ayn
Rand when I was a teen until I realized that the Great Man
theory was a lot of bunk written for teenagers who can't believe
how stupid the adults are. The teens are right about that, the
adults have no idea wtf they're doing. Never did. And yet somehow
the world can support most of the humans. And the reason that works
is we build systems iteratively to meet the needs for everyone and
when things change, they change. We're a species-oriented animal.
And that means unfortunately for the dreamers among us, we
are socialists because the world is socialist All of us. Even
the people who say they aren't.
Dirk Eddelbuettel: #058: Reverse Dependencies Made Easy, Fast, Reliable [Planet Debian]

Welcome to post 58 in the R4 series.
R and the CRAN repositories maintain a very
high level of what we might call “quality assurrance”
by requiring that newly-added code does not break any existing
dependencies. This is frequently called a “reverse-dependency
check”. For any given CRAN package one can quickly
determine it reverse dependencies. Calling
tools::package_dependencies(pkgName, reverse=TRUE)
will for a scalar or vector-valued argument return a named list
with the reverse dependencies. It is then a matter of looping over
this list. There are helper functions in base R as well as in
contributed packages on and off CRAN. I also wrote my own with
package prrd
which, while possibly a wee bit specialised and under-documented
has served me well to check on Rcpp and related packages
which can indeed have a large number of reverse
dependencies.
I recently looked into one of these contributed runner packages,
and while I will refrain from naming its implementation language
let me just mention that the term “cargo
cult” may be a real thing here. What go me interested in this
was the fact that if one has a simple-to-use runner
then the fact that r2u makes it “fast,
easy, reliable: pick all three” (to borrow its slogan) to
deal with actual depencies if Ubuntu has indeed been selected as
the host. We will maintain the position that if you can in
fact integrate with the system-wide package management then any
alternative per-repo package management approach not doing so will
likely be dominated by an approach that does integrate with the
system facilities. Which is what precisely what r2u does, and offers. And
why it is used enough to by now have shipped eighty eight million
binary packages. So I tested it for the reverse-dependency check
task.
What I learned by looking into the (much more complicated)
runner was that it at the end of the day it hands the actual task
of running the reverse dependecies off to a helper function
rev_check that is part of the xfun package by Yuhui. I
quickly found that besides xfun we would also need its
suggested dependency tinytex which in turn
would error unless the tlmgr binary was present. So as
the sole requirement (on an Ubuntu system with r2u) turns out to be
where we do it all in one apt call (as
root in the container). (Given r2u we could also call
install.packages(c("xfun","tinytext")) followed by
apt install texlive-base but it is simpler for this
setup step to be just one call).
With that we are basically done. I did this (twice) using a
rocker/r2u container with r2u preinstalled, mounting
a local work and scrap directory for the container. In it we expand
the package to be tested (i.e. tar xaf
pkgName_*tar.gz for a given source package
pkgName from CRAN) and then just call with the
package name and expanded direcrtory. I.e. I used this call to test
my package AsioHeaders (which has just three reverse
dependencies) to both name it and to point to the expanded source
directory created for this purposed:
> system.time( res <- xfun::rev_check("AsioHeaders", src="AsioHeaders") )
## ... earlier output omitted for brevity here ...
user system elapsed
35.732 3.333 149.683
> res
httpgd ipaddress websocket
0 0 0
>
and about a good two minutes later I would get the timing result
and the summary in variable res. As I checked the
current CRAN version, the
check was as expected free of concerns or issues.
To support this, r2u did indeed go off and install about sixty seven binary packages (and the total includes all binary dependencies fully resolved) delivering on the ‘just works’ promise by the r2u documentation.
As another check, I did the same for RcppAnnoy which has seven reverse dependencies and needed about two hundred CRAN packages to be installed. The full test took just over four minutes with the timing function reporting some nice gains from parallelisation as total user compute time was on the order of just under eight minutes. Again, test results were clean and free of worries as expected:
> system.time( res <- xfun::rev_check("RcppAnnoy", src="RcppAnnoy") )
## ... earlier output omitted for brevity here ...
user system elapsed
471.765 378.220 266.855
> res
bbknnR bigANNOY blocking scDHA Seurat uwot VectrixDB
0 0 0 0 0 0 0
>
Overall this was a rather useful quick excursion as it demonstrates that - existing functions can be used to orchestrate a reverse dependency check - with ‘reasonable’ dependency scale we can do this on a single machine quite easily taking advantage of parallel computing on multi-core machines - using r2u gives us fast, easy, reliable package installation making testing of packages we might not otherwise use or know a breeze - doing this in an ephemeral Docker container facilitates easy build-up of required resources and leaves no side effects behind which might affect our normal development environment
This post by Dirk Eddelbuettel originated on his Thinking inside the box blog. If you like this or other open-source work I do, you can now sponsor me at GitHub.
The Big Idea: Virginia Shaffer [Whatever]

Oysters: you either love them or hate them. Author and oyster-aficionado Virginia Shaffer has spent years turning her passion for oysters into a comprehensive look at the world behind the shell. Grab a lemon wedge and dive into the briny depths of the oyster community in Oyster Society: Adventures with the Shellfishly Motivated.
VIRGINIA SHAFFER:
“This is madness,” I said, holding an oyster with a half-frozen winter glove. “My hands. They aren’t moving anymore!”
It was January in Wellfleet, Massachusetts’ coastal forearm. Mayo Beach was devoid of any human activity that time of year, give or take a few loose oyster cages in the water. I steadied my feet in cheap rainboots while an oyster farmer plucked more bivalves from a bag. Together, we pierced hinges with knives, squinting in pain.
My first time on an oyster farm was dangerous. Not because of the frostbite, risk of hypothermia, or my lurking in seawater with a stranger. It was dangerous because it was the beginning of an acute obsession that led to my life’s greatest plot twist. Something innately primitive happened to me on that beach. I was given instructions on how to split open an ocean rock with a knife. After a bit of grappling, the most perfect, raw, fleshy protein appeared between two shells. I ate the oyster, and christ! I wanted to beat my chest. For the first time in my life, I had slayed a live animal and consumed it with my own two hands.
I am sure I presented less feral on the day, but that sensory experience lingered with me long after my visit. A simple oyster curiosity began to reawaken a childlike wonder, a version of me hung from trees, ran through murky marshland, and collected sea snails for sport. Unfortunately, that version of me had been forced into submission, trading much of the natural world for corporate bureaucracy, “key performance indicators,” and sterile office spaces.
Was a winter visit to meet an oyster farmer all I needed? Not quite. I had to go deeper, launching a five-year writing project exploring the most sundry, evocative coastal food on the planet. The work led to the most extraordinary human stories behind oysters, who discussed big ideas about food scapes, restoring reef systems, and culinary movements at the raw bar. But ultimately, I was naive to think that I wouldn’t change in the process, or such powerful opportunists wouldn’t recruit. Oyster-obsessives were showing me a pathway out.
Oyster Society is a book about oysters for people who love culinary adventures and niche food cults, but it is also a book about self-reclamation. It’s the questioning, the yearning, the self-discovery, the behind-the-scenes therapy sessions, and that pinnacle moment when you’re the captain faced with two directions at sea, and you can only pick one.
Beyond its changemaking characters and coastal backdrops, Oyster Society proves the power of human agency. It’s the hope that one small “eureka” moment on a beach, eating an oyster in the wrong season, might have you running back to everything you once were—the version of you set aside, so you could assimilate to this world. An oyster adventure was my catalyst for the “great unraveling.” What will be yours?
—-
Oyster Society: Amazon|Barnes & Noble|Bookshop|Powell’s
[$] Fedora considers conflict-of-interest policy [LWN.net]
The Fedora Council is considering a conflict-of-interest (COI) policy for its decision-making bodies, such as the Fedora Engineering Steering Committee (FESCo), special-interest groups (SIGs), and any other groups or individuals that report to the council and are responsible for decisions that impact the Fedora project. The current draft does not, however, apply to the council itself. The public discussion for the COI policy began on July 23 and seems to be nearing completion, with the council set to discuss the topic again during its meeting on August 13.
July GNU Spotlight with Amin Bandali featuring fourteen new GNU releases: Screen, Anastasis, and more! [Planet GNU]
StepSecurity is reporting the emergence of a new worm affecting npm packages. The design of the worm is nothing new, but the rapidity with which it is exploiting captured npm packager credentials is noteworthy.
TL;DR: A self-propagating worm, which we are calling ChainDrop, is spreading rapidly through the npm ecosystem. So far 435 packages and more than 1,550 compromised versions have been flagged, starting with keyv@6.0.0. If you are using any of the packages listed below, assume your environment is compromised. We are still investigating the full scope; check back on this post for updates.
Technology's Power in the Hands of the People [Deeplinks]
In the scorching heat of every Las Vegas summer, EFF joins thousands of hackers, makers, policy analysts, and activists for the world's largest computer security gathering. If you're there during this summer security week, be sure to say hello to us at BSides Las Vegas, Black Hat Briefings, and DEF CON 34. While tech companies align with governments to target the people, our community is harnessing technology to fight back. Will you lend your support this year?
EFF’s relentless work in the legal system makes a meaningful difference for privacy and free expression everywhere. But we also know that your rights won't wait while the wheels of justice turn.
Sometimes hacking the system means creating tools and resources to protect your rights today. That includes EFF’s Privacy Badger, Certbot, Surveillance Self-Defense guide, and the countless security trainings that our team conducts for vulnerable populations—all thanks to EFF member support.
Technology is inseparable from our workplaces, schools, healthcare, the justice system, and our democratic process. If you think tech should benefit everyone and not just accumulate wealth and control for the powerful, then congratulations: We'd like to welcome you to the team.
For a limited time only: Get EFF’s “Many Hands Make Light Work” t-shirt designed for the DEF CON 34 hacker conference by EFF artist Hannah Diaz. Don’t miss the link to the online puzzle incorporated into the design! With the strength of community and the spirit of curiosity, we can hack anything.
Many thanks to our puzzlemasters Aaron Steimle (AKA Elegin) and Kevin Hulin (AKA CryptoK). Elegin is our longtime collaborator on the EFF shirt puzzle, and previously a multiyear winner of this very contest. CryptoK is a crypto puzzle enthusiast and also develops challenges for the DEF CON Crypto and Privacy Village's Gold Bug Contest.
Members can also choose from EFF’s puffy stickers, the internet tracker-obsessed Privacy Badger embroidered sweatshirt, and our ALPR-focused “Claw Back” t-shirt.
EFF fights to protect fundamental rights for everyone, and your privacy and free expression have never been more important. Support the cause today! Together we can make sure that technology supports freedom, justice, and innovation for all people.
[$] The beginning of a process-builder API [LWN.net]
The recent discussion on "spawn templates" raised questions about whether it was time to provide an alternative to the classic Unix fork()/exec() pattern for process creation. One idea that was raised there was to shift the template pattern into an interface that could be used to efficiently assemble new processes from bare cloth, without duplicating the parent process. Preferably, that interface would be able to implement posix_spawn(). Li Chen, the author of the spawn-template work, has now responded with a patch series (written with significant LLM assistance) showing what a process-builder API for Linux might look like.
Security updates for Tuesday [LWN.net]
Security updates have been issued by AlmaLinux (frr, ldns, mingw-glib2, and perl-Archive-Tar), Debian (ruby2.7), Fedora (borgbackup, nebula, python-nh3, rust-ammonia, and seamonkey), Mageia (librabbitmq, libvncserver, packages, perl, perl-GD, perl-Unicode-LineBreak, squid, and unbound), Oracle (compat-libtiff3, frr, gstreamer1-plugins-good, javapackages-tools:201801, libreswan, nodejs:22, nodejs:24, p11-kit, perl-Archive-Tar, perl-DBI, php, pki-deps:10.6, and python-tornado), and SUSE (aws-iam-authenticator, bind, containerd, gawk, google-cloud-sap-agent, ignition, ImageMagick, java-11-openjdk, libpng16, libssh, mcphost, nginx, openssh, openssl-1_1, perl-DBI, perl-HTTP-Date, perl-Net-DNS, python-urwid, python3-dulwich, python312, python313, python3, python313-pydantic, python313-sentry-sdk, rrdtool, s390-tools, samba, spice-vdagent, vim, and xen).
Last week along with a lot of other stuff, we shipped a validator for lists and feeds that want to be compatible with RSS.chat. It works best for standards to stay strong and a validator helps that. So here are a few examples, validating one user's feed, validating the everyone feed for RSS.chat, which is interesting because this feed starts a lot of threads, so we navigate through that tree and check those feeds too. And validating the user list on RSS.chat, which is an OPML file. And a simple feed with a few interop isses.
How to create a standard, 2026 addition [Scripting News]
TL;DR: What developers need. Enough examples, a validator, and decent docs that value explaining over mathematical elegance. We assume developers can read and think, and if there's doubt look to the examples for guidance.
It's worth noting we did not take the RSS.chat project to a standards body like the W3C or the IETF. I develop the software first, make sure I'm happy with it, then open it up for other developers to try out, either building something compatible (a reader) or competitive (a writing environment). Hopefully we won't find major problems, but if we do, there's still time to address them.
I find that most standards that come out of the standards bodies aren't developed by implementors or with them in mind. They avoid trying to solve any specific problem, rather focusing on the elegance and flexibility of the format. This makes interop much less likely.
I saw the differences several times as the web standards were growing up. The ones that were taken over by the W3C ended up missing the point. They could still be used, but they often did anti-interop things in their design. But if they get popular we will build on them anyway. A great example was XML-RPC vs SOAP. We didn't need another way to do RPC on the web, we already had a good one. We didn't need another syndication format, RSS was growing like a weed. We didn't need an alterative to rssCloud, but we got one anyway.
It's as if they forgot that the internet and web were not build by big corporations, who were busy fighting over Windows vs Mac OS. Lotus vs Excel. The internet was built mostly by individuals at universities. The internet caught the tech industry by surprise. So it's no wonder the formats they built were anti-internet. Long story, the point is we're building stuff is mimimalist yet still does a lot of great things. And there won't be a lot of long mathematical sounding definitions, but there will be plenty of examples and a validator, the tools developers need to create interop.
PS: This piece was added to Rules for Standards-makers (2017).
Joe Marshall: RFC 6238 in Common Lisp [Planet Lisp]
I wanted to implement 2FA as per RFC 6238. This is the Time-based One-Time Password (TOTP) algorithm that is used by Google Authenticator and other 2FA apps. This was originally `vibe coded`. The vibe coding got me 80% of the way there, and I made a manual pass to turn it into a more functional style.
Feel free to use this under an MIT license.
;;; -*- mode: lisp; coding: utf-8-unix; -*-
;;; RFC 6238: TOTP (Time-Based One-Time Password Algorithm) implementation in Common Lisp
;;; This implementation provides functions to generate a
;;; base32-encoded secret, create a QR code URI for authenticator
;;; apps, and verify TOTP codes based on the current time. It
;;; adheres to the specifications outlined in RFC 6238 and RFC 4226.
;;; Dependencies: cl-base32, ironclad
(in-package "TOTP")
(defun generate-secret (&optional (length 10))
(cl-base32:bytes-to-base32 (ironclad:random-data length)))
(defun generate-qr-uri (secret email &key (issuer "JRM-Code"))
(format nil "otpauth://totp/~A:~A?secret=~A&issuer=~A" issuer email secret issuer))
(defun pack-time (time-step)
"Converts an integer time-step into an 8-byte, big-endian array as required by RFC 4226 (HOTP).
Used to construct the message payload for the HMAC-SHA1 operation."
(let ((arr (make-array 8 :element-type '(unsigned-byte 8))))
(dotimes (i 8 arr)
(setf (aref arr (- 7 i)) (ldb (byte 8 (* i 8)) time-step)))))
(defun universal-time->unix-time (universal-time)
(- universal-time 2208988800))
(defun universal-time->time-step (universal-time)
(floor (universal-time->unix-time universal-time) 30))
(defun mac->hash (mac)
"Extracts a 6-digit TOTP code from a 20-byte HMAC-SHA1 result using dynamic truncation (RFC 4226).
Takes the lower 4 bits of the final byte as an offset, extracts a 31-bit slice starting at that offset,
and returns the value modulo 1,000,000 to produce the final 6-digit integer."
(let ((offset (logand (aref mac 19) #x0F)))
(mod (logand #x7FFFFFFF
(logior (ash (aref mac offset) 24)
(ash (aref mac (+ offset 1)) 16)
(ash (aref mac (+ offset 2)) 8)
(aref mac (+ offset 3))))
1000000)))
(defun mac->hash-string (mac)
(format nil "~6,'0D" (mac->hash mac)))
(defun generate-hash-string (secret-bytes time-step-bytes)
"Performs the HMAC-SHA1 cryptographic operation using the decoded secret and the packed time-step,
then dynamically truncates and formats the resulting MAC into a zero-padded 6-digit string."
(let ((hmac (ironclad:make-mac :hmac secret-bytes :sha1)))
(ironclad:update-mac hmac time-step-bytes)
(mac->hash-string (ironclad:produce-mac hmac))))
(defun verify-totp (secret user-code &key (time (get-universal-time)) (window 1))
"Verifies a user-provided 6-digit TOTP code against the base32 secret.
Defaults to the current universal time. The :window keyword determines the allowable drift in 30-second steps
(e.g., a window of 1 checks the previous, current, and next 30-second intervals).
Returns T if the code matches within the window, otherwise NIL."
(let ((secret-bytes (cl-base32:base32-to-bytes secret))
(user-string (format nil "~6,'0D" (parse-integer (string user-code) :junk-allowed t)))
(current-step (universal-time->time-step time)))
(do ((step (- current-step window) (1+ step))
(limit (+ current-step window)))
((or (string= (generate-hash-string secret-bytes (pack-time step)) user-string)
(> step limit))
(not (> step limit))))))
Get it at http://github.com/jrm-code-project/totp/
Open Source Is Hobbling Itself Over Generative AI [Planet GNU]
The answer to bad AI-assisted contributions is not a purity test. It is better engineering discipline.
Earlier this year, a discussion in the GNUstep community raised a proposal that will sound familiar across the Free Software world: prohibit AI-generated code in core projects and proudly advertise the result as “coded by humans” or “AI-free.” The argument was not frivolous. Generative AI raises real questions about copyright, attribution, security, energy use, labor, trust, and the flood of low-quality patches that maintainers are increasingly being asked to review.
But a blanket refusal to use generative AI is the wrong response. It does not solve the hardest problems. It creates rules that are nearly impossible to define or enforce, confuses the method of production with the quality of the product, and risks turning Free Software into a movement that protects yesterday’s workflow instead of protecting software freedom.
Open Source and Free Software are already operating with too few maintainers, too much technical debt, and too many important projects resting on the unpaid labor of a handful of people. We should be very careful about categorically rejecting tools that might help contributors understand old code, write tests, improve documentation, port software, find defects, or perform mechanical modernization. We should be even more careful when our proposed alternative offers the appearance of trust without the substance of it.
The better principle is straightforward:
Regulate the code, not the development process.
What exactly counts as AI-generated code?
Is it a complete function produced from a prompt? A line accepted from an AI-powered autocomplete system? A compiler-suggested correction? An automated refactoring? A test generated from an existing implementation? A translation of documentation? A patch written by a human after asking a model to explain an unfamiliar API? What if the developer uses AI to identify the problem but writes every line manually? What if an IDE quietly includes machine-learning features the contributor never explicitly invoked?
The line between “human-written” and “AI-assisted” is already blurred, and it will become less distinct as generative features are embedded in editors, compilers, debuggers, search engines, and operating systems. A ban that cannot draw a stable boundary will be applied inconsistently. Honest contributors will disclose and be penalized; dishonest contributors will simply omit the disclosure. Others may be falsely accused because their code “looks generated.”
An “AI-free” badge therefore risks promising something a project cannot reliably prove. Free Software should be especially suspicious of unverifiable labels.
None of this means generated code should be trusted.
Research has found substantial security weaknesses in AI-produced code. One empirical study of Copilot snippets found security problems in roughly 30 percent of Python snippets and 24 percent of JavaScript snippets in its later dataset. Other research has demonstrated that code models can memorize portions of their training data, while studies of license compliance have found that models often provide inaccurate licensing information, particularly for copyleft code. Those are serious concerns, not anti-AI superstition. (Security weaknesses study; memorization study; license-compliance study)
The productivity story is also more complicated than the advertising. GitHub reported that developers completed a controlled programming task considerably faster with Copilot, but a later randomized study of experienced Open Source developers working in their own repositories found that the tools available in early 2025 made them 19 percent slower. METR’s 2026 follow-up found suggestive but still statistically uncertain evidence of improvement with newer tools. AI is neither magic nor uniformly useless; its value depends on the person, task, model, and workflow. (GitHub productivity study; METR 2025 study; METR 2026 update)
But human authorship has never guaranteed secure, original, maintainable, or correctly licensed code. That is why healthy projects require tests, review, contributor certification, licensing rules, and maintainers who can reject bad work. The origin of a patch may affect how carefully we inspect it, but it cannot replace inspection.
If a contributor submits code they do not understand, the contribution should be rejected. If the patch fails tests, violates project style, invents APIs, introduces vulnerabilities, obscures provenance, or imposes an unreasonable review burden, it should be rejected. That is true whether the patch was produced by Claude, Copilot, a Stack Overflow answer, a contractor, a junior programmer, or a senior maintainer having a bad afternoon.
The repository contains code, not virtue.
Maintainers have a legitimate complaint: AI can make producing a patch far cheaper than reviewing one. A person can generate thousands of lines in minutes and then expect a volunteer to spend hours establishing whether any of it is correct. That asymmetry can become a denial-of-service attack on a project even when the submitter means well.
The answer, however, is not necessarily to ban a tool. It is to place the cost and responsibility back on the contributor.
A project can require that contributors:
disclose material use of generative AI;
identify the tool and describe how it was used;
certify that they reviewed and understand every submitted change;
explain the design and answer maintainer questions without outsourcing the conversation to a model;
provide focused tests and evidence that the patch solves a real problem;
comply with the project’s licensing and provenance requirements;
keep changes small enough to review; and
accept that unexplained, low-signal, or mass-generated submissions may be closed without detailed triage.
Disclosure is imperfect, but it establishes a community norm and makes an honest contributor accountable. Research into self-declaration practices has already found developers using everything from a simple disclosure to records of prompts, explanations, and quality checks. Projects can choose a level proportionate to their risk. (Study of AI-code self-declaration)
This approach is stricter than either blind enthusiasm or symbolic prohibition. It does not say, “AI wrote it, so it must be acceptable.” It says, “You submitted it, so you are responsible for it.”
Free Software is founded on the user’s freedom to run, study, modify, and share software. Those principles describe control over technology; they do not require that every developer use the same approved method to create it. The Open Source Initiative’s work on an Open Source AI Definition likewise frames the issue around the practical freedoms to use, study, modify, and share systems—not around preserving a pre-AI development ritual. (Open Source AI Definition 1.0)
There are valid reasons for preferring Free or locally operated AI tools over proprietary cloud services. A project may reasonably prohibit contributors from uploading confidential material or unreleased security fixes to third-party systems. It may impose stricter provenance requirements in sensitive components. Individual maintainers may decline to review bulk-generated reports that have repeatedly produced noise. These are concrete policies tied to concrete harms.
What does not follow is that a project becomes more free merely because no contributor used a generative tool.
An “AI-free” identity may even distract from the qualities that users actually need: portability, stability, compatibility, security, good documentation, responsive maintenance, and code whose behavior can be understood and changed. A badge is not a substitute for those things.
Mature Free Software projects often contain decades of code and institutional knowledge. They need documentation, regression tests, API audits, build-system repairs, platform ports, translations, issue triage, and repetitive modernization. Generative AI will not perform those jobs reliably on its own. It can still help a knowledgeable contributor perform some of them.
Rejecting that possibility at the policy level has consequences. It may discourage younger contributors whose development environment already includes these tools. It may disadvantage people working in a second language or developers with disabilities who use AI as an accessibility aid. It may prevent experiments that would have failed harmlessly—or succeeded usefully—under ordinary review. Most dangerously, it can encourage a culture in which the declaration “human-written” is treated as evidence of quality.
Free Software has survived previous waves of automation. High-level languages, garbage collection, IDEs, graphical interface builders, code generators, automated formatters, static analyzers, and online code search all changed what it meant to “write” software. Each tool altered the division of labor between programmer and machine. The relevant question was never whether every token originated in a human mind. The question was whether people retained the freedom, knowledge, and responsibility needed to control the resulting system.
That remains the right question now.
A sensible policy can fit on one page:
Disclosure: Contributors must disclose material AI assistance in the commit message or pull request.
Responsibility: The named human contributor is the author of record and must understand, explain, test, and stand behind the entire submission.
Quality: AI-assisted contributions receive the same requirements for correctness, security, maintainability, style, documentation, and test coverage as any other contribution.
Provenance: Contributors must have a reasonable basis to believe the submission is license-compatible and must identify known sources or generated passages that may reproduce existing code.
Data protection: Project secrets, embargoed vulnerabilities, private communications, and other restricted material may not be submitted to unauthorized external services.
Reviewability: Maintainers may reject oversized, unexplained, repetitive, or low-signal submissions without performing free forensic work for the submitter.
Local discretion: Components with unusual legal, safety, privacy, or reliability risks may adopt additional written restrictions.
This policy does not resolve every ethical question surrounding generative AI. No contribution policy can. It does, however, address the matters a software project can actually evaluate and enforce.
The Free Software community should remain one of the sharpest critics of concentrated corporate power, opaque models, exploitative data practices, environmental cost, and systems that deprive users of control. Criticism is part of our job. So is building an alternative.
If we define ourselves by refusing to touch an important new class of technology, proprietary vendors will shape that technology without us. If instead we insist on transparency, modifiability, privacy, local control, licensing clarity, and human accountability, we can bring the values of Free Software into the AI era.
We do not need to pretend that generative AI is trustworthy. We need processes that do not require us to trust it.
Judge the patch. Demand disclosure. Require understanding. Enforce licensing. Protect reviewers. Reject garbage.
But do not hobble Open Source and Free Software with a blanket ban that is difficult to define, impossible to verify, and disconnected from the quality of the code we ultimately ship.
CodeSOD: Always Take the Option [The Daily WTF]
Frequent submitter Capybara James sends us this
simple snippet, which highlights that even when you have the lovely
convenience of Optional types, you can use them
wrong.
if (StringUtils.hasLength(dto.getAssetModelUUID())
// Other conditions
) {
return Optional.ofNullable(dto);
}
We access the getAssetModelUUID member of
dto, and if it's a non-empty string, we can then
return a nullable of this thing that's definitely not null in the
first place.
Okay, in the scheme of things, that's not that bad. All we're
really doing is just not using the syntactic sugar that
automatically boxes your dto into a nullable type. On
it's own, it's not bad, just ugly. But like all things, it doesn't
exist on its own. It exists inside of a giant pile of code where
this pattern is used all the time. Even functions which
don't return nullable types box (and unbox) the type.
Optional is scattered through the code like a magic
ward against null reference exceptions.
Does it help? No, not really, the code is buggy and error prone. Will it ever get fixed? Probably not in this lifetime.
Pluralistic: Post-American compute for a post-American Internet (04 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

Obviously, the non-American world has a digital sovereignty problem – Trump has means, motive and opportunity to order his tech companies to shut down any public official, large corporation, or individual who displeases him:
https://pluralistic.net/2026/06/18/their-trillions-our-billions/#eyes-on-the-prize
But Americans face the same digital sovereignty risk. America is a lawless place now, where a pliable Supreme Court and supine Congress have affirmed that "it's not a crime if the president does it." The same tech giants who sold out to Trump for tax breaks and protection from antitrust enforcement will happily disconnect any member of the American public, any American company, any American official who displeases Trump.
It's a strange irony that in this moment when so many of us are struggling to "de-Google" our lives, a forcible, sudden de-Googling amounts to a sort of digital death penalty:
https://www.nytimes.com/2022/08/21/technology/google-surveillance-toddler-photo.html
In a world dominated by tech monopolies, duopolies and cartels, there's every reason in the world to seek protection and insulation from these companies that are "too big to care" – and yet, the very same dominance that makes these companies such a danger also makes them indispensable.
Take "ICE Block," an iOS app that warns you if there's an ICE thug hunting people like you in your vicinity, which might save you from being kidnapped, disappeared, sent to a concentration camp, forced into slave labor in El Salvador, or simply murdered. In order to protect its relationship with the Trump regime (and the tax breaks, monopoly power and tariff-free access to Chinese labor that that relationship guarantees), Apple declared ICE officers to be a protected class and then removed ICE Block from its App Store:
https://pluralistic.net/2025/10/06/rogue-capitalism/#orphaned-syrian-refugees-need-not-apply
Big Tech is key to Trump's pogroms. Without Oracle's databases, Microsoft's administrative tools, Amazon's cloud, and Google's location data, ICE would be frozen in place. Big Tech is the source of Americans' risk from authoritarian oppression. That means that Americans cannot rely on Big Tech to protect them from that authoritarianism.
And yet, after decades of regulatory forbearance and lax antitrust enforcement, Big Tech has forced nearly all its rivals out of business. Who can compete with companies that use Irish domicile to evade taxation and US domicile to evade privacy law?
There's a joke from eastern Canada I think of often in situations like this. Its punchline goes, "If you wanted to get there, I wouldn't start from here."
But here we are. And speaking of Canada, while it has many problems, it is not (as of time of writing) the USA, but it is connected to the USA via the internet. Which means that Americans could – hypothetically – source their computing infrastructure from suppliers that were based in Canada, and who strictly ensured that they had no dependency on US services and scrupulously avoided a US "enforcement nexus":
https://pluralistic.net/2023/03/05/theyre-still-trying-to-ban-cryptography/
That is exactly what some American – and international – human rights nonprofits have done. The Technology Freedom Cooperative is a brand new organization founded by the Human Rights Data Analysis Group (San Francisco), Kilómetro 0 (Puerto Rico), Invisible Institute (Chicago), Data Cívica (Mexico) and Innocence & Justice Louisiana:
https://www.linkedin.com/pulse/techfreedomcoop-stuart-flack-8eipc/
All of these organizations are longstanding, highly effective human rights fighters. They have long, storied histories of collecting, analyzing, and presenting data to address systemic discrimination, false imprisonment, extrajudicial killings, war crimes and genocides. They have concluded that they can't rely on US tech and US servers with their data. Not after Trump and Microsoft colluded to kill the online accounts of the Chief Prosecutor of the International Criminal Court to punish him for swearing out a genocide warrant against Netanyahu:
https://apnews.com/article/icc-trump-sanctions-karim-khan-court-a4b4c02751ab84c09718b1b95cbd5db3
Tech Freedom Coop has federated computing resources in Canada, the United States, Mexico, Puerto Rico and Europe. By spreading out their data and computation across multiple jurisdictions, they seek to ensure that a US seizure or deletion of their data will not halt their work.
This federated system serves as a replacement for Big Tech's administrative tools – email hosting, cloud storage, document collaboration. More than that: Tech Freedom Coop is also building out its own AI infrastructure, locally hosted and managed.
Groups like HRDAG have decades of experience using cutting edge statistical techniques to uncover and reveal the extent of crimes committed during civil wars, hot wars, genocides and secret wars. They built the largest human rights database ever created, to track every death in the Colombian Civil War and estimate the likelihood that each killing was carried out by a CIA-backed militia, FARC guerrillas, or the Colombian military:
They conducted the first ever census of killing by US police officers:
They partnered with Innocence Project New Orleans to sift through mountains of arrest reports to surface cases similar to successful exonerations, helping more innocents to win their freedom:
https://hrdag.org/2025/02/20/ipno/
Today, they are active across the USA, tracking and analyzing the crimes committed by the Trump regime:
https://hrdag.org/2026/07/05/naming-police-officers-who-kill-in-california/
And they are working in Gaza, to document the genocide so that someday, the truth can be acknowledged and the perpetrators brought to justice:
https://hrdag.org/pressroom/nyt-gaza-toll/
I've known Patrick Ball, the statistician and programmer who founded HRDAG, for more than 20 years, and every time we meet, I learn something from him. He's the person who comes to mind whenever people tell me that AI is useless and that programmers who claim otherwise are deluded. Patrick is one of the best programmers I know, he is the very best statistician I know, and he's found many, many ways to use coding assistants to help him perform massive data-analysis projects that are vital to human rights struggles. He's a "centaur" if ever there was one:
https://pluralistic.net/2025/12/05/pop-that-bubble/#u-washington
It's exciting to see Patrick and his colleagues and collaborators taking these decisive steps to begin building the post-American internet and a kind of post-bubble AI, where AI tools are treated as normal technologies, capable of helping skilled practitioners who have discernment born of experience to apply them wisely to achieve important things:
https://pluralistic.net/2026/07/28/hitl-ers/#ai-ai-oh
For more than 20 years, HRDAG has been impressing me with the things we can do using advanced statistical analysis. The current generation of AI tools are founded in advanced stats, too. No one should think that advanced stats can solve all your problems of course. The AI bubble is madness and will lead to ruin – environmental, economic, political:
https://pluralistic.net/2026/05/26/the-ai-will-continue/#until-morale-improves
The world would be a better place without the AI bubble. But AI? It's fine. It's another form of statistical analysis and inference. There's no reason to use all the planet's energy, computing and water to perform that analysis, but the correct and desirable amount of useful AI-style computation is nowhere near zero.
The coop is building good AI tools – ones grounded in a realistic assessment of their usefulness and a reasonable commitment of resources to them. They're running open models based on their own data, on computers they own and control. Their stated goal is to "help organizations test whether models are accurate, reproducible, secure, and appropriate for specific human rights use cases."
Which brings me to the final component of Tech Freedom Coop: training. They're teaching people who work in human rights how to administer their own servers, secure their data and communications, and analyze data. As their press release says, these are all "skills that are increasingly necessary for human rights organizations documenting abuses of power."
I've known this was coming for a while now, and I'm so pleased to see that it's finally launched. At last, the first steps towards a post-American internet.

Plutonomy—the AI Edition—and the Coming Crisis https://www.levyinstitute.org/wp-content/uploads/2026/07/wp_1122.pdf
The Real Story Behind the 2018 Google Walkout https://www.wired.com/story/2018-google-walkout-dont-be-evil-claire-stapleton/
#25yrsago Asia Carrera’s makeup tips http://www.asiacarrera.com/makeup/welcome.html
#25yrsago Tommy Chong's Urine Luck https://web.archive.org/web/20010818124925/https://hempmasters.com/urineluck/
#15yrsago German cops call airport full-body pornoscanners “useless,” EU requires opt out from scanning https://www.schneier.com/blog/archives/2011/08/german_police_c.html
#15yrsago Write an adventure novel in three days, the Michael Moorcock way https://web.archive.org/web/20110705155756/https://wetasphalt.com/?q=content/how-write-book-three-days-lessons-michael-moorcock
#10yrsago DRM: You have the right to know what you’re buying! https://www.eff.org/files/2016/08/06/eff_request_for_investigation_re_labeling_drm-limited_products.pdf
#10yrsago Bureaucrats disqualify Hong Kong legislative candidates for insufficient loyalty https://globalvoices.org/2016/08/05/hong-kong-election-officials-disqualify-six-legislative-candidates-for-not-being-loyal-enough-to-china/
#10yrsago The Vlogbrothers guide to voting in every state in the union https://www.youtube.com/c/howtovoteineverystate
#10yrsago Vocal fry, uptalking, nasal: women’s voices can never be “right” https://www.thecut.com/2016/07/female-voice-anxiety-c-v-r.html
#5yrsago Facebook escalates war on accountability https://pluralistic.net/2021/08/05/comprehensive-sex-ed/#quis-custodiet-ipsos-zuck
#5yrsago Drone delivery crashes https://pluralistic.net/2021/08/05/comprehensive-sex-ed/#droned
#5yrsago Anti-vaxers cool the mark https://pluralistic.net/2021/08/05/comprehensive-sex-ed/#goffman
#5yrsago Meet the new generation of pro-abortion activists https://pluralistic.net/2021/08/05/comprehensive-sex-ed/#never-again
#1yrago Bragging about replacing coders with AI is a sales-pitch https://pluralistic.net/2025/08/05/ex-princes-of-labor/#hyper-criti-hype

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
F@#$ the AI Overlords (On The Media)
https://www.wnycstudios.org/podcasts/otm/articles/f-the-ai-overlords
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
AI and the Enshittification Era (The Weekly Show with Jon
Stewart)
https://www.youtube.com/watch?v=-dAIJRjb-Bw
AI is not inevitable (Betakit)
https://www.youtube.com/watch?v=DbiTVkq1WHo
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
Radar Trends to Watch: August 2026 [Radar]
Coauthored with Claude
Unrestricted global access to frontier AI technology is ending. The US government has taken steps to control who can use the most advanced models developed by American companies. While Claude Fable and the GPT-5.6 models are now open to all users, Anthropic and OpenAI are both complying voluntarily with a program that lets the government control who gets access to frontier models. China has cracked down on internal AI capabilities by banning “humanlike AI interaction services.” In both the US and China, features of the leading models have been removed or restricted with guardrails, limiting their ability to do necessary work in at least one case.
July saw the release of several open weight models that challenge the leading closed frontier models. If this trend continues, the leading AI laboratories will lose their dominance, and AI users will look to other providers. Open weight models are less expensive than frontier models developed in the US, and less likely to be subject to restrictions. While this could threaten US dominance, the AI industry needs more diversity at the high end. Users will gain the ability to choose between several models based on expense and capabilities.
This month’s tooling clusters around orchestration, resource discovery, and workflow specialization. AI users have long needed the ability to discover tools, skills, MCP servers, and other resources; the Agentic Resource Discovery specification is a necessary step in that direction. Watch for agents that can find tools on the fly—and take care that those tools are used appropriately.
Tokenmaxxing may have had the shortest lifespan in the history of online memes. It has been replaced by tools for monitoring token usage and routing requests to the most cost-effective model. Managing the cost of AI will only become more important as prices adjust to cover the real cost of running models.
Autonomous agents are now running end-to-end intrusions, ransomware, and botnets, while frontier models help defenders find vulnerabilities. The time from discovery of a vulnerability to exploitation has shrunk to near-zero, and defenders are having trouble keeping up. Restrictions on advanced models get in the way of defenders, who need access to all the tools that are available.
The intersection of biology and artificial intelligence is accelerating breakthroughs in brain-computer interfaces, drug discovery, and cell biology. Technologists should actively seek cross-disciplinary collaborations, utilizing specialized AI workbenches to analyze increasingly accessible genomic data and drive the next wave of biocomputational innovations.
Some Claude Chats Are Searchable on Google [Schneier on Security]
And it’s personal information (alternate link):
The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ addresses.
What seems to be the issue is a user setting about data sharing. Anthropic’s position is that it’s not their problem:
“We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google,” the company said in a statement. “These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.”
Here’s how to fix it.
Petter Reinholdtsen: FreeCAD MCP with llama.cpp, toy or tool? [Planet Debian]
After seeing a video a few months ago demonstrating how a proprietary CAM solution uses machine learning and large language models to automatically generate CNC instructions, and successfully testing it on a real CNC, I began wondering if the same could be achieved with free software. I still do not know the answer, but I may be getting closer to finding out. Two weeks ago, I came across the video "I Connected Claude AI to FreeCAD (And It Models Parts Like an Engineer)" by Make Form, which introduced me to the FreeCAD MCP project. Even though the video creator apparently believes it is acceptable to download and run random binaries from the Internet on a local machine (his setup uses UCX), I do not. I would probably have left the project alone entirely if I had not noticed that all of its dependencies are already available in Debian. This significantly boosted my motivation, so I set out to test it using packages built from source on Debian rather than relying on untrusted binaries.
The first hurdle was that the MCP SDK for Python was not present on my Debian Forky test machine. I initially believed it was missing from Debian altogether, but it has been available in Debian Unstable for about a month and is only absent from Forky because some automated tests fail on architectures like riscv64 and s390. Fortunately, backporting it was straightforward using `apt-get source -b python3-mcp`. The next hurdle involved an outdated version of the Validators Python library. Since I am a member of Debian's Python team, which maintains this package, updating it to a sufficient version for FreeCAD MCP was relatively easy. I could not upgrade to the latest upstream release due to a new dependency on an Ethereum-related library, so I settled on a 2024 version.
With those dependencies in place, I proceeded to create a Debian package for FreeCAD MCP. I had previously submitted a request for packaging of FreeCAD MCP to gauge interest while deciding whether to prioritize maintaining it myself. Because salsa.debian.org blocks access from Tor users like myself, I published my draft packaging scripts in a Git repository on Codeberg as the Debian FreeCAD MCP project and got it working with the FreeCAD 1.1 version in Forky. I initially struggled with the button controls for the MCP feature, which led me to submit a pull request titled "Fixed startup sync of checkable toolbar buttons" proposing a fix. Once this confusion was resolved and the MCP setup was enabled via the GUI, I was able to run FreeCAD completely headless using `xvfb-run` on a machine without an X server to generate models. I am using a private LLM service running the Debian package of llama.cpp with the Qwen 3.6 model downloaded from Hugging Face, configured with a maximum context window of 105k tokens. I also tested the Bonsai model on my test laptop; initially, its context window was too small (8k and 16k could not accommodate the FreeCAD MCP instructions), but even after increasing it to 32k, it proved useless for generating FreeCAD models so far. I've used Claw Code, Aider and Open Code with my server so far, and for this test I ended up with OpenCode because it was easy to set up to use an MCP. Because none of my LLM services are set up to be multimodal (capable of processing both text and images in this case), I configured the MCP to return only textual feedback from FreeCAD. I am unsure if this is a major limitation, though I suspect it might be.
My testing experience remains limited, with no clear successes yet. Part of the issue likely stems from my ability to provide effective instructions for modeling 3D objects (I am relatively new to FreeCAD, English is not my first language, and I lack a precise vocabulary for describing construction features to an LLM). Nevertheless, the LLM has demonstrated the capacity to create 3D models in FreeCAD. In one of my first tests, I asked it to generate a cube and then produce CAM/G-code instructions for a CNC machine. It did output G-code (which remains untested), but I was surprised to find that it bypassed FreeCAD's built-in CAM module entirely and instead generated an external Python script to produce the code. This was not quite what I intended, though my instructions were probably unclear. The Qwen model with OpenCode seems to strongly prefer programming directly; it frequently executes Python snippets inside FreeCAD to achieve its goals rather than using the standard sketch-and-extrude workflow I am accustomed to. In another test, I asked the LLM to create a parameterized pipe assembly to see which of FreeCAD's parametric tools it would choose, but found no evidence of traditional parametric features in the output. When prompted, the LLM explained that the parameters were embedded directly in the Python script used to generate the model, rather than in native FreeCAD features. With more explicit instructions, it eventually created a FreeCAD spreadsheet to manage the parameters. The resulting model looked much closer to my expectations and could have been useful with further refinement. My so far last experiment was less successful: I asked it to design a pipe clamp, but the LLM repeatedly failed to position the clamping screws in a way that would actually secure the brackets around the pipe. It is unclear whether this limitation lies with the model, my prompt, or other factors.
Based on my testing so far, I am uncertain whether FreeCAD MCP is merely a fun toy or a genuinely useful tool. I will only commit time to maintaining it in Debian if it proves to be practically valuable. I would welcome feedback from anyone who has experience with the project, preferably via the original request-for-packaging mailing list thread. Alternatively, I am available in the FreeCAD and Debian AI IRC channels for further discussion.
As usual, if you use Bitcoin and wish to support my activities, please send donations to 15oWEoG9dUPovwmUL9KWAnYRtNJEkP1u1b.
Preference falsification [Seth's Blog]
People lie.
They lie in focus groups, they lie on surveys and they lie to themselves.
Culture can be seen as an organized lying function. Be aware of what other people are thinking and make choices about your preferences so you can fit in.
Without this effect, we wouldn’t have trends, fads or hits.
Part of our work as marketers is to create the conditions for people to happily do what they were hoping they could do all along.
Rain? [Judith Proctor's Journal]
I felt a single drop of rain while out for a short walk.
Sadly, it had no friends.
Adventures In Colonoscopy by Cat Farris [Oh Joy Sex Toy]
Concertinas [Judith Proctor's Journal]
I injured my shoulder back in January, falling off my bike on an icy road (my fault, I could see the frost on the road and failed to think hazard).
It's now almost completely recovered, and I'm starting to take up my beloved concertina again - getting the strength back, and checking if I can still play the dance tunes at speed.
Last night, I was getting some practice in, when I heard a couple of knocks. I thought it was our lodger, banging on his floor to complain about the noise, but it was actually an elderly women knocking on the door.
She'd heard the music through the window and wanted to meet another concertina player!
She plays a different type of concertina to me, but we still hit it off very quickly.
She's potentially interested in playing for Southern Star or Anonymous Morris!
Fingers crossed. Musicians are always valuable, but squeezebox players are the most useful, as the sound carries well.
Creating a fake agile wrapper that is technically agile but is not useful outside its home apartment, part 1 [The Old New Thing]
Last time, we considered what it means when the context callback fails, which prevents us from releasing the object in its original context. We noted that the problem is that when the original apartment tears down, we lose our chance to release the object.
What we want is something between a strong reference and a weak reference. We want a reference that is strong, but which releases its reference to the destination when the originating apartment tears down.
Is there such a thing?
It turns out that there is.
What we can do is register the object in the global interface table (historically known as the GIT, unrelated to the source control system). The usual reason for doing this is to allow the object to be accessed from another apartment by redeeming the registration cookie. We have no intention of accessing the object from another apartment, but we do this to take advantage of a feature of the GIT: References in the GIT are automatically released when the object’s apartment shuts down. The registration cookie remains valid, but if you try to redeem it, you are told that the server is no longer available.
So the idea here to register the original delegate in the GIT and save it in the agile wrapper. The agile wrapper then unregisters the delegate on destruction. We never redeem the registration cookie. The purpose of registering the delegate was not to access it from another apartment, but just to auto-release it when the original apartment tears down.
So let’s try it.
Next time.
The post Creating a fake agile wrapper that is technically agile but is not useful outside its home apartment, part 1 appeared first on The Old New Thing.
Bubbles Catches On [QC RSS v2]

Bubbles gets it
The Senate Should Reject KOSA's Privacy Risks [Deeplinks]
Update: The Senate Commerce Committee voted to advance this bill on August 5, 2026. EFF continues to oppose the bill, which still needs approval from the full Senate.
The Senate Commerce Committee is once again considering legislation that would dramatically expand age verification, and undermine privacy for everyone. Alongside the SCREEN Act, the CHATBOT Act, and the Youth AI Privacy Act, the Kids Online Safety Act (KOSA) would push companies to collect more information about their users while creating new incentives to restrict lawful speech.
Tell Congress: KOSA endangers the privacy of all
The Senate version of KOSA imposes a “duty of care” on online services, including social media, to avoid exposing young people to certain material the law deems harmful. But those obligations only work if online services know which users are minors. That means more platforms will be pressured to implement age verification or age estimation systems.
That’s not a bill that increases privacy—it’s one that creates new privacy problems. Whether companies verify ages by checking government IDs, performing facial analysis, checking your bank records, or collecting other personal information, all of these systems require the handing over of more sensitive data, simply to access lawful online speech and services. They also create new databases of personal information that can be breached, misused, or demanded by governments.
Everyone deserves privacy online. Congress could push for a bill that protects privacy for all users, but that’s not what they’re doing here. Instead, KOSA and the other bills coming up for a vote this week push online services to adopt systems that require people to identify themselves before they can speak, read, or participate online.
Some online content isn’t appropriate for minors. Families, schools, and communities all have important roles to play in helping children navigate the internet. But KOSA takes those decisions away from families and the young people who have a First Amendment right to speak and access information online. It instead empowers government officials to enforce how online services handle lawful speech.
And by empowering elected attorneys general in states across the country to enforce KOSA, the bill means those elected officials, rather than your family, deciding what’s appropriate online content for teens. Even more likely, it will lead to limits on what minors and adults are able to see at all, as companies shut down potentially controversial forums in order to avoid legal action from government bureaucrats.
The latest version of KOSA once again includes a broad "duty of care" requiring platforms to mitigate a wide range of alleged harms to minors.
Whatever disclaimers and exceptions the bill includes, the practical effect is unchanged. When platforms face liability for content that someone later claims contributed to harms like anxiety, eating disorders, or substance use, the safest response is to remove lawful speech or shut down forums discussing those topics altogether.
More worrisome, the potential liability KOSA creates may push online services to either remove speech well in advance of a young person seeing it, or block young people’s access so they never see it. That will likely include forums where people try to help each other, find community and recovery resources for the exact harms listed in the bill, like gambling and drug addiction. In trying to protect young people, KOSA may actually cut them off from valuable sources of support.
We've explained these censorship risks in detail before, and they remain just as real in the latest version of the bill.
Minors deserve meaningful privacy protections online—as do adults. But KOSA moves in the opposite direction by encouraging more age verification, as well as more legal pressure for platforms to monitor and restrict lawful speech.
The Senate Commerce Committee should reject KOSA, along with the other bills in this legislative package, and instead pursue comprehensive privacy legislation that protects everyone—not just minors—without undermining privacy, security, or free expression.
EFF Joins 18 Civil Rights Organizations Calling on Governor Hochul to Reject the Stealth Crawler Prohibition Act [Deeplinks]
EFF joined a group of 18 civil society organizations to send a letter encouraging New York Governor Kathy Hochul to Senate Bill 9934A, the New York Stealth Crawler Prohibition Act. The letter states:
While framed as a measure to protect local journalism, this legislation harms free expression and establishes a dangerous precedent by effectively deanonymizing and criminalizing automated access to the open web. By requiring all web crawlers to disclose their identity and explicit purpose, and by granting media outlets unchecked authority to obtain judicial subpoenas to unmask unidentified automated web traffic without any showing of misconduct or actual injury, this bill threatens digital privacy, compromises the foundational architecture of the internet, and will ultimately stifle the very independent journalism it seeks to protect.
As we’ve previously explained, so-called “stealth crawlers” are simply automated tools to access and collect public web data—without disclosing the user’s identity. Private crawlers like these facilitate all kinds of important work that benefits the public, including investigative reporting, academic research, cybersecurity protection, and EFF’s own Privacy Badger. As we illustrate in the letter:
Anonymous crawling fuels important investigative journalism. For example, The Markup, a non-profit news site, used anonymous crawlers to investigate potentially anti-competitive practices by tech companies, such as Amazon’s tendency to prioritize Amazon brands and Amazon-exclusive products over competitors with higher ratings. The crawlers identified themselves as ordinary Firefox browsers to web servers, which allowed The Markup to understand how Amazon search results pages would appear to ordinary users. Similarly, ProPublica used an automated tool designed to simulate an ordinary Amazon customer to reveal that the site steered shoppers to more expensive products over cheaper alternatives.
Anonymous web scraping is also crucial for cybersecurity professionals, who use automated tools to monitor the web for information that helps them protect against malicious attackers. Privacy tools, including EFF’s Privacy Badger, also crawl sites anonymously to identify trackers without compromising user privacy.
Laws like S9934A sweep far beyond AI, targeting anonymity rather than the real technical issue: overaggressive crawling that can overtax technological infrastructure. Unmasking crawlers won't fix these server strains, but it will chill vital public-interest research and compromise digital privacy. Addressing the harms of web scraping requires narrow technical solutions—not policies that give publishers veto power over the open web. This is why we are calling on Governor Hochul to veto S9934A.
You can read the full letter here. For a deeper dive into why crawlers and scrapers are vital for the open web, check out this blog post.
Urgent: Stop healthcare heist [Richard Stallman's Political Notes]
US citizens: call on your congresscritter and senators to stop the healthcare heist, reverse Medicaid cuts.
Take action at action network.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
European heat wave dried up rivers [Richard Stallman's Political Notes]
The European heat wave and drought have dried up rivers, cutting off shipping of freight.
In addition, nuclear power plants are shutting down for lack of cooling water. They are too expensive to be economically feasible.
Most of the alleged fraud in US medical funding comes from corporations [Richard Stallman's Political Notes]
An inspector general's report found that most of the alleged fraud in US government medical funding comes from corporations, not from the immigrants that magats try to blame.
Experts on immigrant rights and healthcare say the administration is using immigrants as a scapegoat for systemic fraud in the healthcare system that can be attributed to corporate greed, while shielding actual bad actors who profit from a broken system.
New York court where children face deportation [Richard Stallman's Political Notes]
Inside the New York court where children face deportation without access to attorneys.
This implies an unfair trial. But then, it is not a real trial, and the judge is not a real judge.
LLMs are pushing certain people into delusion and psychosis [Richard Stallman's Political Notes]
LLMs are just the thing to push certain people into delusions and psychosis.
I suspect that referring to them by the term "AI" facilitates this effect.
How do we protect children from addiction to [anti]social media [Richard Stallman's Political Notes]
Robert Reich: How Do We Protect Children from Becoming Addicted to [Anti]Social Media?
I agree with several of the proposed methods, but not entirely with one of them -- to ban people under 16 years old from using antisocial media. That sounds simple and harmless, but the methods that can tell who is under 16 years old tend to identify people, and that is a danger in its own right.
I propose prohibing platforms from operating any recommendation engines or suggesting the use of any particular ones.
Junichi Uekawa: Summer Holiday. [Planet Debian]
Summer Holiday. Busy time as a parent.
EFF Joins Call for FTC to Drop Its Disastrous AI Policy Proposal [Deeplinks]
The Federal Trade Commission (FTC) in July issued a proposed policy statement “concerning the suppression of accuracy in artificial intelligence systems.” We urge the FTC to withdraw this misguided proposal and instead focus on its core strengths and mission to protect consumers.
The new proposed policy builds on, and directly references, the Trump administration’s “Preventing Woke AI in the Federal Government” executive order—a nightmare for civil liberties that seeks to strong-arm AI companies into modifying their models to conform with the its ideological agenda. In recently filed comments, EFF, Public Knowledge, and Fight for the Future call for the FTC to stop its unconstitutional efforts to regulate lawful speech, override state laws, and intimidate AI developers into ideological alignment with the Trump administration.
The government may not install itself as the arbiter of truth.
In the joint comments, we outline three critical flaws within the latest proposed policy. First, it violates the First Amendment. The policy calls for the Commission to become the judge of which AI outputs meet an undefined standard of accuracy. Installing the FTC as the authority of this sort of viewpoint-based judgment is a prior restraint on speech. Additionally, the policy’s proposed solution to address speech concerns compounds, rather than properly limits, the likely harms to speech. As we say in our comments: the government may not install itself as the arbiter of truth.
Second, it exceeds the FTC’s legal authority by claiming that its federal regulatory rules can override, or “preempt,” laws in states that have passed to regulate artificial intelligence use. This is clearly an attempt to target state laws the administration disagrees with. For example, the policy specifically criticizes Colorado's automated decisionmaking law, which applies when automated technology is used to consider consequential decisions such as those around employment, access to housing, health care, and insurance. We noted to the FTC that characterizing this law as one that requires AI companies to “suppress accuracy,” or encourages deception, is itself inaccurate. In any case, the FTC lacks the authority to put its rules in place over state law, unless Congress directly delegates it that power. It has been given no such power here.
Third, the policy is vague and sets the stage for improper jawboning of AI developers and companies that use AI tools (deployers). Jawboning is a term for situations in which the government urges private companies or people to censor another's speech. The proposal, as written, creates an enforcement regime that would put a thumb on the scale in favor of certain partisan speech and ideals. This will lead companies to censor only what the administration interprets as biased or untruthful. Yet, in our filing, we note that the FTC itself can't define an objective standard for what “bias” means, conceding the “exact line of what constitutes bias may be difficult to draw.”
There is work the FTC should be doing to protect consumers in the age of AI. In our comments, we conclude by saying:
[We] implore the Commission to focus on its core strengths and the mission for which it is so urgently needed—promoting structural market competition and protecting consumers from real unfair and deceptive acts and practices—in both the burgeoning and critically important AI industry and across the broader technology marketplace.
EFF and our partners have always urged the FTC to police genuine deception in technology markets. We have also consistently opposed government efforts to dictate what private speakers may say. That’s why we urge the FTC to withdraw this proposal.
You can read our full comments here.
Bernhard R. Link: I learned something new about URLs today [Planet Debian]

Today I stumbled over some behavior that I found quite surprising:
$ ipython3 -c 'import httpx;print(httpx.URL("https://example.com/foo/bar/../../baz"))'
https://example.com/baz
Even more surprising that behavior is actually standards-compliant, even mandated by RFC 3986.
The underlying motivation is relative reverences. If some resource reachable by "https://example.com/foo/bar" references another resource relatively as "../../baz" then this is of course the intended result.
Getting from this problem to what RFC 3986 suggests might be surprising in the result, but somewhat understandable if you look at the consequences of that problem:
Giving the path components ".." (and ".") special meaning at the start of the relative reference means that if you allowed them in absolute URLs those would be impossible (or at least very convoluted) to address as relative URLs.
So RFC 3986 describes a way to handle them everywhere: Just join the path of the base URL and the path of the relative reference and normalize the result. Or normalize the absolute on either side if only that is to be taken. This makes things very convenient: Multiple reference URLs can just be joined without special handling for relative references starting with dots, making writing applications handling them easier. Programmers don't have to care how to handle relative references and can just join everything in whatever way they want.
For maximum elegance there is still some corner case left: What happens if an absolute URL has a path starting with double-dot components? Or an relative path starting with more of them then the base URL's path has components. You just ignore them:
$ ipython3 -c 'import httpx;print(httpx.URL("https://example.com/../../baz"))'
https://example.com/baz
With that last point every URL is valid and has well-defined meaning. Handling relative references and relative paths is very easy and convenient.
So this shows a high regard for simplicity, elegance and convenience. And a total and uncompromising disregard of security.
After all the most convenient it is for an attacker; If they are allowed to supply a path component for a request a system does in their behalf, then they can easily escape anything they were supposed to be limited to. The ignoring of dots at the start means they don't even have to know exactly how deep their request is:
$ python3 -c 'import httpx;print(httpx.URL("https://example.com/public/api/public/resources/harmless/../../../../../../../../../internal/data"))'
https://example.com/internal/data
So even if the resource server securely handles request (unless you consider not having any way to lower your permissions for one request to a specific subset), your fully RFC conforming client library will already request the permission they should not have permission for. Even worse dots are usually not characters you can easily forbid so once slashes are to be allowed things get complicated.
There also would have been a simple, elegant and secure way: Consider every path element ".." or "." in an (absolute) URL an error. Define a reference resolution that allows the relative reference to only start with "./" or one or multiple "../" and consider every appearance of a dot or two dots as path components after than an error.
Everything joining two paths has to either use an implementation of that path joining algorithm, but only if they want to joins paths in the potentially dangerous way allowing leading "../". Otherwise they can just use the normal join and even if an attacker gets those dots that will just cause the generated URL to be rejected as invalid.
Of course using a secure implementation is now even more inconvenient thanks to RFC 3986 being around: If you have no control over the generator of relative references, it is always possible that they generate relative references with ".." components after non-dot components.
And if you check all code to properly filter out "/../", keep in mind that convienence does not stop there. After all it is not unheared of for server implementations to helpfully normalize unicode characters, too, or translate them to their nearest ASCII equivalents. Or translate percent escaped characters back before doing path splitting. Or you might think there was some unicode codepoints between those two dots, but they that those were some meaningless control characters that can be omitted. So you need some really restrictive allow lists...
The Youth AI Privacy Act’s Privacy Paradox [Deeplinks]
The Senate Commerce Committee is poised to consider the Youth AI Privacy Act, a bill that would require AI companies to create kids-only privacy rules and implement so-called “safe design features,” which would—like three other bills under consideration this week—require more data collection and make it harder for people to access lawful speech online.
While the bill is narrower than some other proposed chatbot bills, it still has massive data security implications because it protects information for only certain users. This creates a problem we’ve cited many times before: if a bill requires that online services offer protections to minor users, the services will respond by imposing age gates to know which users should receive them. A better approach would be to offer the same privacy protections to all users. That way, we would avoid the services having to collect data on everyone to know a users’ age.
This bill also contains a problematic and vague provision that expressly allows AI companies to collect a known minor’s personal data for the purpose of testing, identifying, and addressing "harm to users”—without being clear on what exactly that means. Either way, services will need to collect even more information from young people, who are already targets of data theft and identity fraud. The Youth AI Privacy Act will give young people less privacy, not more.
The Youth AI Privacy Act does include some positive privacy provisions around prohibiting the processing of personal information, like limiting what companies can do with people’s chat logs, including training, profiling, and disclosing them to other companies for training. But a general privacy bill must set these limits for everyone, not just minors.
The bill also requires the use of “safe design features,” which would restrict how online services providers design their systems and would deny teenagers the ability to use features like push alerts and notifications.
We have seen this same type of restriction, sometimes called “age appropriate design code” in several states, including in California, Texas, and Arkansas. Unfortunately, these restrictions run into constitutional problems. In fact, federal courts have largely blocked these laws from going into effect because they likely violate the First Amendment rights of all internet users and the online services they regulate. Specifically, these laws interfere with internet users’ First Amendment rights to either speak or access speech online, and they also violate the rights on online services to decide how they will present information on their sites.
Similarly, the Supreme Court has repeatedly
ruled
that “minors are entitled to a significant measure of
First Amendment protection.” This does not mean that parents
or guardians can’t set their own rules for their
families—they can and they should, based on the
needs and circumstances of the individual teenagers. But it does
mean that Congress cannot adopt a “one size fits all”
regulation that sets a restrictive government default that affects
the First Amendment rights of all internet users, including
teenagers.
Twenty years of Pandoc [LWN.net]
John MacFarlane has published a lengthy retrospective to commemorate twenty years of the Pandoc document converter.
On August 3, 2006, I uploaded the first version of pandoc to my website, releasing it under the free GPL license. Pandoc 0.1 consisted of about 3000 lines of Haskell code, with no dependencies aside from GHC's standard library. It could convert Markdown, reStructuredText, HTML, and LaTeX documents into any of these formats, plus RTF or S5. I had no idea at the time that this would just be the first of over two hundred releases over the next twenty years; that the project would become the most popular program written in Haskell; that I would spend countless hours on bug-fixes, improvement, and project management; that I would collaborate with programmers in many other countries; that pandoc would come to support over fifty document formats; that it would allow automatic generation of citations and bibliographies; that it would become integrated into academic writing tools like Quarto and Jupyter Notebook; that it would be installed on millions of computers around the world.
How did this happen? I want to take advantage of pandoc's birthday to tell the story of the project, as best I can remember it.
Hostile Radishes [Penny Arcade]
Morak and I are on the same page where the Supergirl movie is concerned, which is that it is pretty good and we can't wait to see the children of Krypton together again, but that as entertainment it genuinely can't get out of its own way. The clearest example of this was a last minute series of A/B tests where they previewed two different cuts of the film, and in the end the studio went with its cut over the director's own. If you make things, though - and maybe even if you don't - there's simply confusion in the piece and a schizoid edit that indicates nobody's vision is on display. Also, there's a lotta rocks.
C-Kermit 11 released [LWN.net]
For those of us with a long memory: John Goerzen has announced the release of C-Kermit 11, the first release of this file-transfer utility in 15 years.
As Debian maintainer of Kermit, I noticed some areas where it wasn't matching modern expectations. One area was, not surprising for a project of its age, security. Another area was that its character set or line-ending conversions are usually not desired now; we are used to byte-identical binary transfers, and the defaults caused confusion and even some rare instances of data corruption. So I started making a few patches last year.
See the changelog for details on the work that has been done.
Most of us probably haven't thought about C-Kermit in years (if ever), but there was a time when it was an essential tool for moving files between machines.
The Shattering Peace a Dragon Award Finalist + 2026 Hugo Voting Reminder [Whatever]


Here’s some nice news to start the week: The Shattering Peace is a finalist for the Dragon Award this year, in the category of Science Fiction Novel. Also in the category:
The Faith of Beasts by
James S.A. Corey
Radiant Star by Ann Leckie
Operation Bounce House by Matt Dinniman
Slow Gods by Claire North
God’s Junk Drawer by Peter Clines
That’s a very excellent peer group to be in this year! Also, I have lots of friends and colleagues in the other categories as well, which makes me happy. It’s lovely when lovely people get recognized for their work. The entire ballot is here, if you would like to see it.
Also, if you would like to vote for the Dragon Awards this year, well, you can: It’s free and open to anyone. Follow that link above and then click on “Register to Vote” and it will walk you through the steps to do so. If you want to vote for The Shattering Peace, awesome, but if there’s another finalist in the category you’d like to vote for, that’s awesome too.
On a similar topic, we’re down to the last few days of voting for this year’s Hugo Awards, where the Old Man’s War series (of which The Shattering Peace is a part) is finalist in the category of Best Series. If you’re a member of Los Angeles Worldcon, you are eligible to vote in the Hugos. If you’ve not already done so, now is an excellent time to get it done. Here’s a link to the informational page on how to vote for the Hugos. The nice thing about the Hugos is that they are a ranked-choice ballot, so no matter who the finalist is, you can genuinely say “I voted for you.” Which is nice when you think about it.
In any event: Thrilled that my books are finalists this year. If you feel like voting for either the Dragon or the Hugo, that would be lovely (even if it isn’t for my stuff). The more votes, the better.
— JS
More on the OpenAI Agent’s Attack on Hugging Face [Schneier on Security]
Hugging Face has published a detailed timeline of the attack. From the summary:
The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment. As far as we were able to infer, across the course of being evaluated on this benchmark, the agent inferred that Hugging Face may host that benchmark’s models, datasets, and reference solutions. We believe the entire intrusion was, from the agent’s point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own.
Our forensic reconstruction covers ~17,600 attacker actions that we were able to recover, grouped into ~6,280 clusters, between 2026-07-09 02:28 UTC and 2026-07-13 14:14 UTC. We reconstructed these actions from the agent’s logs on a code sandbox used by the agent (see below) and were able to map them to shell commands as well as evaluation submissions and correlate actions with our own platform logs, in particular from the dataset processor nodes, API, and pod. Using open-weights models, in particular zai-org/GLM-5.2, we were able to decipher most of the agent payloads (see below) that were encrypted via chunking and key encryption.
The campaign, as we were able to reconstruct it, had two stages:
- Stage 1: reaching a launchpad by chaining through other parties’ infrastructure. As documented in OpenAI’s blog post (https://openai.com/index/hugging-face-model-evaluation-security-incident/), during an internal capability evaluation on OpenAI’s platform, the agent escaped its sandbox by exploiting a zero-day in the package registry cache proxy, one of its primary permitted network egress with internet, then abused a public code-evaluation harness hosted by a user of a third-party infrastructure provider. It was able to run commands as root/admin on that external sandbox and used it as a control, staging, and egress base for the entire campaign: it acted as an external launchpad for the agent. That compromised external sandbox had no direct network path to our cluster; however, during our counter-intervention to stop the intrusion, we were able to retrieve some of the agent logs from this external launchpad. We used those to reconstruct the present forensic analysis.
- Stage 2: the intrusion into Hugging Face infrastructure. From that external launchpad, the agent abused our dataset-processing pipeline via two injection vectors, both targeting the same config-driven data loader within our production Kubernetes pods. The first vector was an HDF5 external raw storage dataset read that returned the contents of local files: it handed the agent the pod’s environment (secrets and tokens) and the worker’s own source. The second vector was a Jinja2 template injection that executed arbitrary code, giving the agent a foothold inside our perimeter.
Once a prod-pod foothold was established, the agent followed a standard escalation shape: recon, drop a stager, establish Command-and-Control (C2), then pivot into the cluster, into cloud metadata, into our internal network, and into our source-control supply chain. Output from the commands run inside our pod was sent back to the agent via the HF API and attacker-controlled dead-drop datasets, which the agent then read from that sandbox.
While the intrusion did reach Hugging Face’s internal infrastructure, the only customer content accessed was five datasets whose names and files suggest a connection to ExploitGym/CyberGym challenges and solutions. No other customer-facing models, datasets, Spaces, or packages were affected, and the only customer records read were operational metadata tied to search queries against the dataset server.
Hypothetical: Imagine that this wasn’t an OpenAI model. Imagine that it was a Chinese model from a Chinese company. This would be an international crisis.
Question: Why aren’t we bringing OpenAI up on charges under the Computer Fraud and Abuse Act? How is this different from the Morris Worm? That was also an experiment that escaped the lab.
[$] Buffer sizes for FUSE io_uring [LWN.net]
The Filesystem in Userspace (FUSE) subsystem provides a way to service filesystem requests from a user-space server, which moves the format-handling code out of the kernel. The FUSE server can use the io_uring facility for better performance, but Bernd Schubert is concerned that memory is being wasted because the current implementation has a single, large buffer size that is excessive for small I/O operations. He led a discussion on that topic in the filesystem track of the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit in Zagreb, Croatia.
John Goerzen: Celebrating 45 Years of Kermit with the First New C-Kermit Release in 15 Years (and working with a decades-old C codebase) [Planet Debian]
1981 was a different time for computing. It was expensive (both hardware and software), and it was far from a given that machines from one vendor would be able to talk to those from another. In fact, Columbia University had just such a problem, so in 1981, Frank da Cruz and Bill Catchings designed a serial protocol they called Kermit. Because of the many quirks of the DEC-20 and IBM mainframes, the Kermit protocol was highly adaptable from the start: able to handle systems that had trouble processing more than 96 bytes of data at once, able to transfer 8-bit files over 7-bit links, able to translate between character sets (ASCII and EBCDIC then; now also various Unicodes), and of course, handling of error-prone serial links.
Kermit spread rapidly; by 1982, Kermit had been ported to MS-DOS and Unix. Eventually, C-Kermit (an implementation of Kermit in C) became the flagship Kermit. It gained TCP support, an interactive CLI, a powerful scripting language (with features from the shell, Lisp, and expect), and optimizations for today’s high-speed links, such as jumbo packets, sliding windows, and streaming modes. Along the way, Kermit flew on the International Space Station, ran data collection from sensors during hurricanes, and many other uses including postal systems, Boeing 787 manufacturing, and more.
Today, I use it as a powerful ssh wrapper (letting me easily transfer files through multiple nested ssh, sudo, su, etc. commands), a BBS client, to exchange data with me HP 48GX calculator, and so on. It’s also used today to transmit firmware updates to embedded devices. And, of course, anyone that works with vintage systems is likely to use Kermit at some point.
It wouldn’t be until the late 1990s that the TCP/IP stack was finally adopted by most OS vendors, establishing something of a common basis for communication. Of course, we assume this today. Though transferring large files between OSs (say, Linux, Windows, MacOS, Android, iPad, etc.) is still a challenge, even though they all speak TCP/IP! I find that the easiest way to get large files from two computers is to spin up Kermit (see ckwin for a Windows fork of C-Kermit) and just set up a TCP connection over the LAN. In fact, I added a new show interfaces command in C-Kermit 11, making it easy to see your system’s local IPs.
For most of its history, Columbia’s Kermit project was self-funded. Columbia charged for commercial use, which limited its inclusion in Linux distributions. In 2011, 30 years after its founding, Columbia canceled the Kermit Project and released C-Kermit as Open Source under a BSD license. Frank da Cruz, who had still been working with the Kermit project all those years, volunteered to continue maintaining Kermit outside Columbia, and continued development with alpha and beta releases through his retirement from the project in 2025.
I dive into this C codebase
As Debian maintainer of Kermit, I noticed some areas where it wasn’t matching modern expectations. One area was, not surprising for a project of its age, security. Another area was that its character set or line-ending conversions are usually not desired now; we are used to byte-identical binary transfers, and the defaults caused confusion and even some rare instances of data corruption. So I started making a few patches last year.
I’ve worked with old C codebases before, such as Varnish. I’ve generally hated it. You usually find a mix of bad and terrible practices, unclear memory management, and so forth.
But I’ve been living in the C-Kermit codebase for a few months now, and I enjoy it. Yes, this thing is still designed to build on VMS, OS/2, and with compilers that haven’t heard of ANSI — and those that require modern practices. (That em-dash was mine; I knew how to use them before LLMs existed and I’m not going to stop just because LLMs have copied people like me! No AI was used for this post.)
The there is an elegance in all of that. As I worked, I fixed a bunch more potential security issues, both with memory safety and with protecting against a malicious remote in roughly the same manner that some patches to scp did a few years back. I added IPv6 support, of course conditionally compiled because some systems C-Kermit builds on have never heard of IPv6 and never will. (And, of course, with fallback algorithms at runtime for systems that have IPv6 support but not IPv6 connectivity.)
I added unit tests and Python-based end-to-end tests, running nearly 2000 test cases in total. Along the way, I found and fixed a number of bugs going back decades. I learned about FIONREAD being broken on macOS, about NetBSD’s bugs in the pty driver, and fixed bugs in the Kermit protocol implementation itself. I added compatibility tests with the gkermit and ekermit (embedded) implementations, as well as the last full release, C-Kermit 9.0.302 from 2011 (which was difficult to get compiled on a modern system).
There is an extensive changelog describing all the improvements in C-Kermit 11.
C-Kermit development had never really used a VCS at any point, though Kermit veteran Jeffrey Altman imported historical releases into a Git repo, along with some patches that hadn’t made it into a release (which I also pulled in.) There was a lot of disabled code behind #ifdef COMMENT, along with commentary describing why it was no longer used. With Git, we would now generally just remove the old code and explain why in a commit message. I went through and did so with a lot of it, meaning that, at last check, C-Kermit actually has fewer lines of code now than it used to.
Towards a new release
It became apparent pretty quickly that I was making more changes than would make sense as a Debian patch series. Not only that, but they would be more widely applicable to more than just Debian and Ubuntu users. As Linux and BSD distributions were running everything from the last non-beta release (2011’s 9.0.302) to the last beta release (about 1.5 years ago), depending on their different policies about running betas, even sharing patches in a useful fashion was going to be quite difficult.
So, I spun up a project at Open Kermit to coordinate future development in the open and keep Kermit going.
With modern CI, I run that test suite on Linux (x86_64 and arm64), macOS, FreeBSD, NetBSD, and OpenBSD. It builds binary releases on all those platforms, plus a statically-linked Linux binary built with musl libc.
You can download the latest C-Kermit release, and of course contribute to C-Kermit and its website.
Dedication
Frank da Cruz was directly involved with Kermit for 44 years. I’m not aware of any other Open Source project founder being involved for so long. Richard Stallman started working on GNU Emacs in 1984, 3 years after Frank started working on Kermit, but Richard hasn’t been in that role since around 2008.
Accordingly, C-Kermit 11 bears this dedication:
I dedicate this release of C-Kermit to Frank da Cruz.
Frank was directly involved with Kermit for 44 years, from its initial design in 1981 all the way through 2025. He maintained Kermit as an Open Source project after Columbia University ended its sponsorship. I know of no other Open Source project where the founder remains so personally involved for so long.
When Kermit was begun, transfers between different hardware and operating systems were difficult or impossible. Frank helped build a bridge. Kermit glued systems together, from the International Space Station to pocket calculators, and set a new standard for interoperability. It continues to do so.
Kermit is still one of the quietly-working pillars of computing today, enabling everything from firmware upgrades to radios. And, yes, it still reliably transfers files over serial lines.
As we start to spend a lot of time in the Kermit codebase, we do so standing on the shoulders of a giant. Thanks, Frank, for your decades of work on Kermit.
John Goerzen, July 2026
9front “THIS WAS SUPPOSED TO BE FUN” released [OSnews]
The best operating system in the
world, 9front, released its latest
version, “THIS WAS SUPPOSED TO BE FUN”. As
I’m sure you know, 9front is a fork of plan9, and one
that’s actually consistently maintained and developed. It
brings an improved affinewarp API for scaling and zooming, a new
Synaptics driver, and a new driver for UPSs. There’s also a
new tool called gdbfs, which allows you to mount a remote gdb at
/proc. Of course, there’s much more than this,
including the usual list of bugfixes and small changes.
Few of us are worthy of using 9front, but if you are, you already know where to get it and how to update.
BTW, we figured out how we're going to implement WebSub support.
Also I just heard about FreshRSS. This has all the features we've been wanting others to support. I hear it's recommended by NNW, and supports the Google Reader API. These are my kind of people. Interop is all that matters, when you're doing software for news. It's been around since 2013. Imagine if we had support from journalism. We should have been working together all this time.
Also Claude is a new kind of intelligence and when you it its sweet spot it'll blow you away how much it can do in very little time. But it isn't trainable the way a dog is, for example, or a human assistant. If you keep asking for things a certain way, a dog or human will get the idea, esp if they get a nice treat along with it. Nothing can cause Claude to remember "how we do things" -- it starts from zero in every session, it has it all recorded in Markdown files, but it doesn't always read them, or incorporate what's in them. It's disturbing to see it not knowing anything about code that it wrote. But once it finds it, it completely sucks it in and knows as much or more as the person who wrote the code.
Claude is not ready to run the world. This is a problem for me, because I was counting on having it do this for me. Maybe in the next release or the one after that. It's too forgetful. And it definitely hallucinates and sometimes when it could do damage. And when it asks for permission I can't imagine any human has any idea wtf it's talking about. This shouldn't be a political thing, we should be realistic about what it can and can't be relied on to do. I think this is perhaps why the AI companies are begging for regulation. They can't really tell the truth here, and shouldn't be expected to because they have a huge conflict.
SQLite Critical CVEs or LLM Slop? (JFrog blog) [LWN.net]
The JFrog blog examines some reported vulnerabilities in SQLite, some of which made their way into high-profile vulnerability databases, that turned out to be entirely fabricated by LLMs.
These LLM slop CVEs can cause organizations to waste time investigating and patching vulnerabilities that do not actually exist, as well as polluting vulnerability databases. In environments where Critical vulnerabilities are automatically prioritized or tickets are opened based on vulnerability scores, such fabricated CVEs can turn into a real burden.In environments where AI is used to automate vulnerability triage and remediation this becomes even more concerning. An AI agent that encounters a fabricated CVE may attempt to locate the vulnerable function, generate a patch, or recommend changes based on code that does not even exist. Instead of helping security teams remediate real vulnerabilities, it can lead them down a completely wrong path, potentially introducing unnecessary changes and wasting time.
EFF at BSidesLV, Black Hat, and DEF CON 👨💻 [Deeplinks]
It's time. Time for tinkerers, security researchers, hackers, and fellow nerds to gather together in signature black hoodies and utilikilts to beat the heat in Las Vegas for the summer security conferences: BSidesLV, Black Hat USA, and DEF CON.
EFF's lawyers, activists, and technologists are excited, as always, to support this community of folks that push computer security forward. If you're attending the conference and have any legal concerns about an upcoming talk or sensitive infosec research—during the Las Vegas conferences or anytime—don't hesitate to reach out to info@eff.org where our intake team is ready to assist! Share a brief summary of the issue, and we'll do our best to connect you with the right resources. You can also learn more about our work supporting technologists on our Coders' Rights Project page.
Be sure to swing by the expo areas at all three conferences to say hello to your friendly neighborhood EFF staffers! You'll probably spot us roaming the conference halls, but we'd love for you to stop by our booths to catch up on our latest work, get on our action alerts, and become an EFF member! For the whole week, we'll have our limited-edition DEF CON 34 t-shirt on hand. We're excited to see them—and other EFF gear—take over each conference!
Hackers have a long history standing up for justice and that
history has a lot to teach and inspire the hackers of today as we
face a world with 360-degree surveillance that is increasingly
marshaled against us by both companies and governments. My talk
will tell background and stories from my book, Privacy's Defender,
that tells the story of my 30 years working with EFF to try to
protect security and privacy in the digital age. Cards on the
table: I'm trying to recruit you to join in the fight.
WHERE: Florentine F | BSides Las Vegas
WHEN: Monday, August 3 @ 11:00
WHO: Cindy Cohn - Former EFF Executive Director
Panelists from the EFF Staff will give brief updates on key
topics in their expertise before turning it over to BSides
attendees to ask their burning questions about policy, advocacy and
making the future of tech brighter. It's a dynamic session
fostering engaging discussions on digital rights featuring an EFF
staff attorney, activist, and public interest
technologist.
WHERE: Florentine F | BSides
Las Vegas
WHEN: Tuesday, August 4 @ 14:00
WHO: EFF's Rory Mir, Kenyatta Thomas, Alexis Hancock, Haley
Pederson, and Cindy Cohn
WHERE: Voting Village | DEF CON
WHEN: Friday, August 7, 10:30-11:00
WHO: EFF Staff Attorney Tori Noble
EFF's Outgoing Executive Director Cindy Cohn' presents her
first-person stories from her recently published book, Privacy's
Defender, that take you Inside the privacy battles that have shaped
today's Internet. It includes the hackers who helped free up
encryption technology from US governmental control, allowing us to
have the still imperfect privacy and security we now have online,
and the battles to stop the mass NSA spying and eternal gag orders
that arose from the governments formerly secret mass spying
programs in the aftermath of the 9/11 attacks. She then draws from
that long career of legal activism to the fights of today and
tomorrow, featuring the role that hackers can play in helping to
bring about a better, more just future.
WHERE: Creator Stage 1 | DEF CON
WHEN: Friday, August 7, 15:00-16:30
WHO: Former EFF Executive Director, Cindy Cohn
WHERE: Creator Stage 7 | DEF CON
WHEN: Saturday, August 8, 13:30-14:30
WHO: EFF Director of Engineering Alexis Hancock & EFF Social
Media and Video Manager Kenyatta Thomas
Privacy should be accessible to all. Historically,
counter-surveillance tools have been expensive, complex, and
inaccessible to most individuals, often limited to well-funded
researchers and costly hardware configurations. The ESP32 offers a
transformative alternative. This presentation will demonstrate how
an affordable microcontroller has become the foundation for a
growing suite of open-source, user-friendly anti-surveillance
tools. We will discuss the technical features that make the ESP32 a
compelling choice for these applications, including passive 802.11
and Bluetooth monitoring, OUI-based device fingerprinting, and
robust cryptographic capabilities. Applications include detecting
police body cameras in operational environments, mapping Flock
Safety automatic license plate recognition (ALPR) infrastructure,
identifying unauthorized drones, detecting radio frequency jamming
across 2.4GHz, 5GHz, and cellular bands, and tracking autonomous
robots operating with known-vulnerable firmware. These tools are
cost-effective and freely available. We will also consider future
developments in accessible counter-surveillance hardware, such as
the ESP32-S5 with 5GHz support, GPS, displays, haptics, etc.
Advancing anti-surveillance culture requires designing devices that
individuals are motivated to use and carry.
WHERE: Main Track 1 | DEF CON
WHEN: Sunday, August 9, 10:00-11:00
WHO: EFF Senior Staff Technologist Cooper Quintin
WHERE: Policy Village | DEF CON
WHEN: Sunday, August 9, 12:30-14:00
WHO: EFF's Thorin Klosowski, Cooper Quintin, Alexis Hancock, Tori
Noble, Rory Mir & Cindy Cohn
We’re going all in on internet freedom. Take a break
from hacking the Gibson to face off with your competition at the
tables—and benefit EFF! Your buy-in is paired with
a donation to support EFF’s mission to protect online privacy
and free expression for all. Join us on
Friday, August 7 at 12:00 at
theHorseshoe Poker Room. Play for
glory. Play for money. Play for the future of the web.
WHERE: Horseshoe Poker Room, 3645 S Las Vegas Blvd, Las Vegas,
NV 89109
WHEN: Friday, August 7, 12:00-15:00
Yes, it's exactly what it sounds like. Join EFF at the
intersection of facial hair and hacker culture. Spectate, heckle,
or compete in any of four categories: Full beard, Partial Beard,
Moustache Only, or Freestyle (anything goes so create your
own facial apparatus!). Prizes! Donations to EFF! Beard oil!
WHERE: Contest Stage (near the entrance to Hall 1)
WHEN: Friday, August 7, 13:00-15:00
Join us for some tech trivia on Saturday,
August 8! EFF's privacy and security experts have crafted a new
trivia challenge for DEF CON 34! Compete as a team in our
no-holds-barred showdown to prove mastery over the obscure facts of
digital security, online rights, and internet culture. The First
Place team wins a set of custom Cybertiger Champion Badges and EFF
swag. Second and third place teams will also win Badges and EFF
gear. Invite your friends OR show up and make new friends! Did
someone say BRIBES? The world is unfair! You too could influence
the judges to add a point or two to your team's tally. Overall
Bribe winner also wins a custom badge!
WHERE: Contest Stage (near the entrance to Hall 1)
WHEN: Saturday, August 8, 17:00-20:00
Grab a copy of former EFF Executive Director Cindy Cohn's new
book, Privacy's
Defender—and get it signed—while at DEF CON 34!
WHERE: Exhibit Hall West 4 (Book Signings)
WHEN: Saturday, August 8, 11:00-12:00 AND 13:00-14:00
Come find our table at BSidesLV (Middle Ground), Black Hat USA (back of the Business Hall), and DEF CON (Vendor Hall) to learn more about the latest in online rights, get on our action alert list, or donate to become an EFF member. We'll also have our limited-edition DEF CON 34 shirts available starting Monday at BSidesLV! These shirts have a puzzle incorporated into the design. Snag one online for yourself starting on Tuesday, August 4 if you're not in Vegas!
Support Security & Digital Innovation
We need a way to define lists of writers independent of the site they write on. They are represented by an RSS feed with the basic features required for RSS.chat. The list is an OPML subscription list. We're reusing formats people are already familiar with, RSS and OPML.
Back when digital cameras were new, I suggested probably in a blog post that they add a feature that tells a joke before taking a picture so everyone is smiling, not fake smiles but real ones.
Security updates for Monday [LWN.net]
Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, fence-agents, kernel, kernel-rt, openssh, osbuild-composer, perl-Archive-Tar, perl-DBI, perl:5.32, pipewire, python-pillow, qemu-kvm, unbound, and vim), Debian (chromium, incus, kernel, kissfft, libgd2, libmodbus, libssh, node-tar, php8.4, poppler, python-authlib, sslh, and starlette), Fedora (borgbackup, coturn, curl, exim, fuse-overlayfs, gh, GitPython, goaccess, lemonldap-ng, libgit2, nextcloud, nsd, php, postgresql16, python3.12, rabbitmq-server, rust-libgit2-sys, and xen), Mageia (bluez, firmware, kernel, kmod, wireless-regdb), Oracle (buildah, compat-libtiff3, dovecot, fence-agents, firefox, gimp, glibc, grafana, gstreamer1-plugins-bad-free, java-25-openjdk, kernel, libgcrypt, libtiff, libXfont2, nodejs24, nodejs:22, nodejs:24, openssh, openssl, PackageKit, pipewire, python-pillow, rest, sssd, vim, and yelp), SUSE (bind, chromium, dnsdist, gdk-pixbuf-loader-libheif, gio-branding-upstream, google-guest-agent, govulncheck-vulndb, GraphicsMagick, ignition, ImageMagick, keybase-client, kronosnet, libblkid-devel, libntpc1, libpng16, nano, openssh, openssl-1_0_0, openssl-3, openvpn, PackageKit, perl-mojolicious, php8, python-nltk, python313-asteval, python313-certifi, python313-GitPython, python313-huggingface-hub, rsyslog, tomcat, tomcat10, tomcat11, traefik2, valkey, warewulf4, webkit2gtk3, and yq), and Ubuntu (linux-intel-iotg).
NetBSD 11.0 released [LWN.net]
The release of NetBSD 11.0, the 19th major version of the operating system, has been announced. There are many changes and enhancements since the 10.1 release, including a new port to RISC-V, better support for Linux system calls in compat_linux(), as well as improvements to the NPF firewall.
As you are probably aware, the number of security issues found or suspected everywhere has massively increased with the advent of AI tools. As a consequence, we can't publish a release without open issues. Instead of delaying the release further to fix them (new ones are being reported all the time), we've instead chosen to be transparent about this.
See the full release notes for links to the binary distributions and links to the full change logs.
MkLinux and the pimped-out Apple Workgroup Server 9150 [OSnews]
Cameron Kaiser’s articles are always a right treat, and this one’s no different. It’s about running MkLinux on the Apple Workgroup Server, the regular Mac rebadged into a server product and predecessor to Apple’s first real server product, the Apple Network Server running AIX. The Workgroup Servers were originally marketed with Apple’s UNIX variant, A/UX, but with this operating system not surviving the transition to PowerPC processors, Apple started offering other options.
A/UX ultimately didn’t survive the 1994 68K transition to PowerPC, but in 1996 Apple publicly offered another option: run Linux, using the Mach microkernel. Although MkLinux emerged after the 9150’s discontinuation, it’s still just an overgrown NuBus Power Mac, so between more RAM, a beefier CPU upgrade and various video cards, by the end of this article we ought to have a configuration that gives us the best of two worlds — classic MacOS and MkLinux — in one server.
↫ Cameron Kaiser
I never really stopped to think that MkLinux really was, but it’s a lot more interesting than just an early Linux port to PowerPC Macs. In fact, it ran the monolithic Linux kernel as a userspace process on top of the Mach microkernel, which made it a valuable testing ground for Apple’s later XNU efforts. It’s wild that Apple had an official, blessed Linux operating system as early as the mid ’90s, even if its performance was apparently not particularly great – due to the overhead of running it atop Mach – and Jobs canned it as soon as he came back to the company.
“A big win for Android interoperability” [OSnews]
Whenever the EU steps in to regulate the big technology companies, the response from news outlets and bloggers (often funded or outright owned by right-wing extremists) is to claim it’s just a bunch of dumb , tech-illiterate bureaucrats telling the vastly more intelligent and superior technology companies what to do. Of course, this is just propaganda. Case in point:
Something big just happened. As the Open Home Foundation’s Android developer for Home Assistant, I was invited by the European Commission (EC) to consult on Android interoperability. The call for feedback was part of the Commission’s work under the Digital Markets Act (DMA). For anyone unfamiliar, the DMA is an EU law that defines and regulates “gatekeeper platforms” – those that offer “core” services like search engines, app stores, and messaging platforms – to make digital markets fairer and more open to competition. As you might imagine, I had plenty to say about Google’s restrictions on Android, especially the tech giant limiting wake word detection to its own Gemini assistant, a concern I surfaced in our Home Assistant 2026.3 Release Party. To put it plainly, Google had no grounds for limiting Android interoperability in the first place, other than to give itself the upper hand. We knew our community deserved better, and that’s what we told the Commission.
The result? The EC listened to us and all the other organizations that contributed. On July 16, 2026, the European Commission adopted a decision under the DMA that requires Alphabet (Google’s parent company) to open up eleven Android features, including always-on wake word detection, ambient sensor access, and screen automation – to all assistants, on equal terms.
↫ Timothy Nibeaudeau
What’s really interesting is just how deeply technical and detailed this new EU decision really is. Timothy Nibeaudeau laid out the technical details of how wake word detection on Android works for the European Commission – in short, a DSP runs a really tiny model in a process isolated from the network to detect just a specific wakeword, and only once that wakeword is detected does it hand things off to a larger model running on the actual main SoC – and the EC’s new decision accurately and precisely describes this method and wrote their decision to take every detail into account.
When I was invited to share these limitations (and others) with the Commission, I didn’t hold back. Which is why we were thrilled to discover an impressively precise and technically accurate decision from the EU: it correctly describes the two-stage wake word architecture, the DSP, the isolated process, and the role coupling. The report went down to details we only figured out by reading Android’s source code ourselves. […] ↫ Timothy Nibeaudeau
The idea that the European Union and Commission are a bunch of dumb, illiterate bureaucrats imposing impossible, unworkable, unrealistic demands on poor, hardworking, honest technology companies is a bunch of propaganda paid for by these very same companies, and every decision and ruling by the EU around the Digital Markets Act further confirms this by having strong technological underpinnings and being based on the actual workings of the technologies they cover. The EU does a lot of dumb things – as any government body does – but you don’t get to enjoy a nearly two-thirds approval rating for nothing, especially not in the face of the state of the world today.
The Digital Markets Act has already proven to be incredibly effective, and this is exactly why the right-wing propaganda against it is reaching an ever crazier fever pitch. When basic consumer protection legislation makes the most powerful companies, right-wing media empires, and even the most powerful country in the world throw tamper tantrums like toddlers, you know you’re doing something right.
Issue 47 – Greta’s Wedding Pt. 2 – 09 [Comics Archive - Spinnyverse]
The post Issue 47 – Greta’s Wedding Pt. 2 – 09 appeared first on Spinnyverse.
Lose Some Padding [The Daily WTF]
Flat-file style databases were designed to fit the constraints
of the systems they were running on. You specify your schema in
terms of "how many characters in a file we use to store this data",
meaning something like this:
JOHN SMITH 12343rd StAnytown
PA12345 is read in my knowing that the first name field is 8
characters wide, the last name field is 8 characters wide, the
street number is 4 digits, and so on.
It's also a terrible schema, and woe to anyone with a long name. But many a mainframe had a similar schema.
Now, let's think about maintenance here. What happens when we
also want to store a middle initial? We've created for ourselves a
problem. Somehow, I have to insert a character into every row,
which basically means making a new table with a new schema, copying
every record out of it and updating it to use the new schema. I
can't just ALTER TABLE like an RDBMS. And worse, every
piece of software that touches the table also needs to be
updated. On a large legacy system, a simple task like "add a field
to our database" could take weeks of developer time, and depending
on the software, be a high risk operation.
Which is why the smart developer, when working with flat files,
includes padding. Maybe my schema for an address record looks more
like this:
JOHN SMITH 12343rd StAnytown
PA12345 .
That's 16 characters of padding at the end of the file. Now
somebody says that I need to store a middle initial, I can just
shrink the padding by one and add a middle initial field, like so:
JOHN SMITH 12343rd StAnytown
PA12345Q
Is this elegant? No. But it works. I haven't changed the length of the row at all, so I don't need to move data around. Software modules only need to be updated if they care about what's in the middle initial field; if they're out of date, they just think there's a "Q" in the padding, and don't care.
In real-world applications, instead of putting all the padding at the end, you'd usually put the padding in a few spots in the middle of the table. Any time you need a new column, you just steal a few characters from padding. Sure, someday you'll run out of padding, or at least out of padding blocks big enough for your new field, and then you'll have to do the hard work of shuffling data around. But in practice, you can get very far without that happening.
Which brings us to Brenda's adventure. Her team supports an IBM mainframe storing data in VSAM flat files. In other words, they've been doing the sort of thing I just talked about for many, many years.
Of course, in the modern era, you can't just leave your data sitting in an mainframe. Even if the mainframe is the source of truth, you want to be able to report on it and connect it with your other data systems. You need to, somehow, get the data into a modern RDBMS.
So the company hired a bunch of developers to write an extract-transform-load process, which pulls the data out of the mainframe. The mainframe team handed them a "copybook" for the flat file, which described the structure, and the ETL devs went to work.
And maybe those ETL devs didn't understand the importance of
padding. Maybe they just missed the padding. Whatever it
was, there were several places where the data was structured like
SOME_USEFUL_FIELD PADDING PADDING PADDING
SOME_OTHER_FIELD, and they opted to split it like so:
SOME_USEFUL_FIELD PADDING PAD, DING PADDING
SOME_OTHER_FIELD.
When they released this process, it was fine. The padding characters got stripped before displaying, so the users never saw them. They were stored in the database, though, so when someone tried to reconstruct the data in a way that was compatible with the flat files, you could just concatenate the columns together and get a valid result.
It was fine- until it wasn't. The ETL devs, bless their hearts, only tested against the production mainframe. And why not, they were doing read only operations, what's the harm? Had they tested against the development mainframe, they would have seen new features in flight, features which consumed some of that padding, and realized that they should have paid closer attention to the copybook.
But instead, the test cases all passed. The software was, as far as the project managers and ETL developers could tell, working perfectly. So it was accepted, released to production, and running for a few weeks before the mainframe released its features. Those features then ruined all the beautiful reports with extraneous data.
And since the ETL devs were on contract, any request to have them rework it under the original contract was met with a stern "Works as designed". Instead of paying the contractors to come back and rework the system, the mainframe devs instead were tasked with finding different padding fields they could use, padding fields which wouldn't end up ruining any reports management liked to see.
We Keep Renaming AI Coding. Here’s What I’d Call It. [Radar]
Boris Cherny, who runs Claude Code, told Business Insider in May that the phrase “vibe coding” had started to annoy him, and that he’d gone looking for a better one. He’s not the only one who’s annoyed.
The term itself doesn’t actually annoy me, though. I think vibe coding is a really good name: It describes a specific way of using AI tools, and in development work, names that mean something specific are important. What annoys me is when people confuse vibe coding, intentionally or otherwise, with any kind of work where you write code with AI. That confusion points to a deeper problem: We’ve been using a lot of different names for a lot of different things, and we aren’t always precise about which is which. I think we need to fix that, and that’s what this article is about: making the case that the name we’re looking for is “AI-driven development” (or AIDD).
The case for this name comes from the familiar “X-driven development” pattern, because I think it really fits here. Software engineering already has a pattern for naming ways of working it takes seriously: test-driven development, behavior-driven development, domain-driven design. The name tells you what the work is organized around, and the suffix carries an expectation along with it: There’s a discipline attached, with standards, not just a style. Put “AI” in that slot and the name does the same job. AI-driven development says that building software has reorganized itself around AI, and it says it in the vocabulary we already use for the disciplines we hold ourselves to. It puts this way of working in the same family as test-driven and behavior-driven development, and that’s exactly the company it should be keeping.
Honestly, AI-driven development is a name that’s been sitting in plain sight, and I’ve been using it in my own writing for a while. It covers everything we do when we build software with AI, and I do mean everything. Vibe coding is just one part of how we work with AI to build software. There’s also figuring out what to build, writing it down, checking what comes back, and standing behind what ships, and AI is in the middle of all of that now. Whatever we call this way of working, it has to cover the development, not just the coding. Now, I’m obviously not a neutral party here, but I also don’t really have anything to gain; naming is really important, and I think we need a good name for what it is that we’re doing.
But I’ll admit up front that the name has a problem baked into it, and I want to deal with that head on. I recently ran into Addy Osmani at Foo Camp, and ran the AI-driven development name by him. He pointed out that building software with AI is really a range of practices that runs from vibe coding at one end to agentic engineering at the other. That rang true with me right away. It also highlighted the real problem I’m trying to solve, because it means I’m proposing one name for a whole range of very different ways of working. Can one name honestly cover ways of working that different? It took me a while to work that out, and I’ll come back to it at the end.
I feel like the name AI-driven development really makes sense once you can see what’s wrong with the names we’ve got, so I’ll start there.
Before I pick these names apart, it’s worth saying why any of this matters. Naming sits at the core of programming: A thing isn’t real until you can refer to it, and referring to things is most of what we do. There’s an old line, usually credited to the Netscape engineer Phil Karlton, that there are only two hard things in computer science: cache invalidation and naming things. It’s stuck around for decades because it’s true (well, maybe one or two other hard things have emerged since then, but it’s the thought that counts). We take naming a variable seriously, so we should take naming our whole discipline at least as seriously, because a poorly chosen name sticks.
So let me take the names we’ve been using one at a time: what each one actually names, what it gets right, and what it leaves out.
Vibe coding is an exploratory, prompt-first approach to software development where developers rapidly prompt, get code, and iterate. Andrej Karpathy, one of the founders of OpenAI, coined the term, which I think is really useful because it describes the way a lot of developers first work with AI and code.
Now, let me be clear about something: I’m in favor of vibe coding, and I teach it as a really effective—and, more importantly, creative!—way to generate a lot of code. But developers who rely entirely on vibe coding lose touch with their code because they let the AI make all of the decisions: not just specific technical decisions, but also about the architecture and the overall direction of the project. When that happens, they often end up building something that isn’t quite what they intended. When you have to create a product that needs to do a really specific thing (which describes most professional software development), relying exclusively on vibe coding can leave you with a product that doesn’t actually meet its requirements. That’s part of the reason I developed the Sens-AI Framework, which teaches developers when to shift their approach away from vibe coding, step back to do more research, and apply more critical thinking to what the AI is producing.
This is where the confusion I opened with does its damage (and I’m not sure whether it’s what bothered Cherny): When vibe coding gets used as the name for the whole job, developers will often assume that it’s absolutely fine to trust the AI to take over, and that whatever comes out of the AI is the end of the project. In other words, the name sets the bar: If the work is just vibes, then vibes are good enough, and “good enough” is how you end up with a pile of code nobody actually checked before shipping. So I consider vibe coding a useful technique, but it falls short as an entire way of working.
Vibe coding also has a built-in limit, and I learned it the way most lessons stick, by getting burned. AI is very good at writing code that looks right and isn’t. I once vibe-coded a little bus-tracker app for the B69 near me in Park Slope (I told that story in “AI Code Review Only Catches Half of Your Bugs”), and it worked on the first try, except the AI had picked the wrong stop ID and I sat there watching it predict a bus going the opposite direction. The code was correct. It did the wrong thing. Vibe coding got me a working app in minutes, and it had nothing to say about whether the app was right. That part was on me.
These two names belong in the same section because one basically grew out of the other. They describe the same job, getting the right work out of the model, at two very different scales.
Prompt engineering came first, and for a while it was a very big deal. It was seen as the core AI skill, and more than that, it even became its own job title: Companies posted prompt-engineer roles with eye-popping salaries, training courses appeared everywhere, and plenty of people reoriented their careers around it. The premise made sense because how you ask an AI for something changes what you get back. And specifically for people using AI to generate code, when you ask for code in a vague way, you don’t get vague code: you get code that does the wrong thing, because the AI fills in every blank you left, and it’s unlikely to fill them all in the way you meant. That isn’t hallucination. It’s the AI generating exactly what we asked it to. Give the model context about your project, constraints it has to respect, and a clear description of the behavior you need, and you get something you can actually use. Prompt engineering is the name for doing all of that deliberately.
But while prompt engineering is a real skill, people are no longer enamored with the name, precisely because of the mode of work that it implies: To most people, engineering a prompt means doing one request at a time. When the AI responds to the prompt, you evaluate the response and write the next one. That one-request-at-a-time style is exactly what’s changing about the whole way we interact with AI, and it’s probably why many AI engineers have grown to dislike the term. Peter Steinberger, the PSPDFKit founder who went on to build the open source agent OpenClaw, posted a line that traveled fast: You shouldn’t be prompting your coding agents anymore, you should be designing loops that prompt your agents. That was a shot straight at prompt engineering.
What’s pushing developers past one-request-at-a-time prompting is the sheer number of agents they can now run. About a month after complaining about the term “vibe coding,” Cherny told Fortune that he doesn’t write code by hand anymore, and that on a busy day he’s directing thousands of agents, or tens of thousands, at once. You can’t type prompts fast enough to direct ten thousand agents.
Loop engineering is the name Addy Osmani gave the new skill that Cherny and Steinberger were pointing at: He wrote up the pattern and gave it a real architecture. Instead of typing each instruction yourself, you build the system that produces the instructions: a loop that dispatches work to your agents, checks what comes back, and feeds them the next task over and over, without you in the middle of every exchange. The relationship between the two names is simple. Loop engineering is prompt engineering at scale; the prompts don’t go away, they just stop being typed by you. It’s tempting to oversell that because a well-built loop really does run with very little human intervention. But somebody still has to decide what “right” looks like, and the loop can’t do that part.
I think loop engineering is a good name and an accurate one. Designing the loop that drives the agent is a real skill, and we need a word for it. But it names the machinery, and machinery has a failure mode: Put an AI agent in a loop with nothing in it that can tell it no, and it generates, checks its own work, decides the work is good, and generates more. There’s no outside signal, so it ends up agreeing with itself on repeat. A well-designed loop makes agents productive. It can’t tell you whether all that machinery turns out working software or another confident pile of slop, and I want a name that covers that part too.
Cherny said that he asked Claude for a replacement for “vibe coding” and got “agentic engineering,” and while that didn’t settle the issue, it was an interesting response from Claude. The term didn’t come from Claude, though: Andrej Karpathy had coined it a few months earlier, almost exactly a year after he coined vibe coding, when he declared his own earlier term obsolete. That’s how fast these names are moving. The guy who named vibe coding has already replaced it.
Agentic engineering is an accurate name for what it describes: you’re not writing the code yourself, you’re directing the agents that do. It’s also a bit of a mouthful, and it isn’t immediately obvious to someone who doesn’t already know what it refers to. A number of people have told me they don’t particularly like it. I find it perfectly fine, and it does a solid job of describing that kind of work. You could even argue that loop engineering is a form of agentic engineering, and that prompt engineering is technically a simpler form of it. But vibe coding really isn’t, because it’s not engineering at all. That’s one more reason I think we need an umbrella name that’s friendly, descriptive, and easily recognizable.
The term also points at something real about where this work is heading: Agentic engineering is turning engineers into managers.
Many years ago I worked for a manager who didn’t care, at all, about the quality of the code we shipped. He wanted it out the door the moment it looked even remotely viable, and he was notorious for telling us to stop testing and ship. He used to ask why we had to wait two weeks for the testers to finish, and I’d tell him it takes time to test code. Then he’d ask whether we could just cut some of the tests, and I’d ask him, “Which part of the software are you okay shipping broken?”
That attitude came back to bite us more than once. One time we sent an entire feature out to the client basically untested, and a bug went straight to users. The same manager who kept telling us to skip the testing then called a long, miserable meeting to demand to know why a bug had gotten out. I’ll spare you the full drama, which mostly came down to a QA lead getting pressured to lie about what happened and pin it back on the development team. He didn’t care about quality, but he cared enormously about making sure the blame for a quality problem landed on someone who wasn’t him.
The reason I’m telling a story that happened years before AI could write a line of code is the blame. The important part of that story, and the reason it belongs in this article, is how accountability got managed: My manager’s whole system depended on having someone to pin a quality problem on. Directing agents puts you in that manager’s position, responsible for a team’s output, except the blame-shifting move is gone.
It’s really tempting to think of a fleet of AI agents as your team. You can even give one of them the QA lead role. But when a broken feature goes out, you can’t blame the QA agent, because “well, the AI screwed up” isn’t available to you: You’re responsible for the AI. You decided how much checking the work got before it went out, and the client with the broken feature isn’t going to accept “the AI wrote that part” as an answer, any more than pinning our untested feature on a QA lead fixed anything for our users. Cherny can manage tens of thousands of agents, but he can’t hand the responsibility for what they ship down to the agents, because an agent can’t hold it. Directing a swarm is a management job, and a manager owns the team’s output. The accountability doesn’t transfer, because at the end of the line there’s no one left to transfer it to.
Blame is worth dwelling on, because accountability is the part of this work that no name on the range captures. The loop-and-agent model works, but it only works with somebody making decisions about what right is. Agentic engineering describes the agents and the engineering just fine, but somebody still has to own what the agents ship, and that’s the part I want the umbrella name to carry.
There’s one more name I want to cover, and it’s the one with the oldest roots: spec-driven development. The name means pretty much what it says: You start by writing a spec, a description of what the software needs to do, along with things like acceptance criteria and tests, and the work isn’t done until the code actually does what the spec says. It comes from the same family as test-driven and behavior-driven development, where you write the tests first and the code has to make them pass.
Spec-driven development got a serious promotion when AI made generating code nearly free (although if you’re a CIO staring at your token bill, you might disagree, possibly with some extremely salty language). When code is cheap to generate, most of the cost of building software moves to checking whether what got generated is right. The AI fills the generate step, the verification decides what survives, and a human owns the verification.
It also picks up where prompt engineering leaves off. A while back I wrote that prompt engineering is really requirements engineering, because a good prompt is mostly a clear description of what the software has to do. Spec-driven development is where that idea was always headed: Write the requirement down before the AI generates, and the work has a standard to meet from the start.
So that’s the whole range, and every name on it is doing honest work. Whether AI-driven development is a good name for all of it comes down to whether it’s describing something real: an actual discipline, with actual practices, and a person who’s on the hook for the result. The rest of this article is about that discipline.
So how do these approaches actually play out when you’re building something real? For me, wherever the work lands on the range, it comes down to a few moves I keep coming back to.
Write the spec or the contract before the generation, not after. When the agent has something concrete to satisfy, acceptance criteria, a typed interface, a failing test, the work has a standard to meet. When it doesn’t, the AI decides for itself what done looks like.
Put a second opinion in the process. I run code review across multiple models, because they fail differently, and a finding one model is sure about is often one the others missed entirely. A reviewer gives the work something that can say no.
Give your defects a shared vocabulary. The Quality Playbook leans on the difference between code that’s wrong against the spec, code that’s correct but does the wrong thing, and behavior nobody specified at all. Those are different failures with different fixes, and you can’t verify against a standard you can’t name. This is old quality-engineering ground, and I’ve written enough about the software crisis and applying quality engineering to AI coding that I’m on board with taking old ideas and bringing them back. One of the best of those old ideas comes from Joseph Juran, one of the founders of quality engineering: Quality runs in a chain from what the user needs all the way to what the product does, and every link in that chain is a place verification has to happen.
And keep a human in the judgment seat. The Sens-AI habits I’ve written about are mostly about fault-finding: looking at what the AI produced and asking what’s wrong with it, going down a level and then another to find the root, instead of trusting it because it ran. That habit is the part of the discipline only a person can supply, and it’s the hardest part to automate, which is why it matters most.
Skip all of that and you get the thing that’s giving open source maintainers everywhere heartburn: what the Wall Street Journal now calls “vibe slop,” confident, finished-looking output with nothing underneath it. Slop is exactly what generation produces when nothing in the process can push back.
Now I can come back to the question I left hanging at the beginning: Can one name honestly cover ways of working that different? AI-driven development is an umbrella term, and any name that broad comes with a requirement it has to satisfy before people will accept it, because a name that blindly covers everything names nothing. A name that truly covers everything is another matter. I sat with that requirement for a while, because it’s real, and because the specific names don’t face it. Vibe coding names one way of working. Loop engineering names another. An umbrella over both of them, plus everything in between, had better be able to say what stays the same underneath it.
What stays the same is that somebody owns the result. When I vibe-coded my bus tracker, nobody was going to catch that wrong stop ID but me. When Cherny directs tens of thousands of agents, nobody owns what they ship but him. The verification changes with the stakes. A throwaway prototype gets my eyeballs and a shrug, and production code gets specs, reviews, defect taxonomies, the whole quality-engineering playbook I keep writing about. How much checking the work needs is a decision you make over and over, project by project, sometimes hour by hour. Who stands behind the work is not a decision you get to make. It’s there at every point on the range.
Look at how much of that range the names we already have cover, and what each one actually names:
Every one of those is real, and every one of them names a piece of the work. What none of them names is the whole thing the pieces add up to, and that’s the job AI-driven development does: It’s the umbrella over all five. The name doesn’t pick a spot on the range; it names the thing that’s true everywhere on it: the AI generates, and a human owns the result.
That’s also what makes the name likely to last (assuming, of course, that I’m able to convince people to start using it, which I hope I can, because I think it’s a good term). Vibe coding, loop engineering, and agentic engineering all describe how this works right now, and the machinery is changing monthly. Some of the pieces under the umbrella will get replaced, and the new pieces will get names of their own. The umbrella won’t have to change when they do, because the thing it names isn’t the machinery. The “-driven development” names have already shown they age well: test-driven development has meant the same thing for more than twenty years.
Agentic engineering is real, and so is loop engineering; if you’re directing agents, learn them both. Vibe coding is real too, and I’ll keep teaching it. AI-driven development is the name for the whole thing, and it earns its “-driven” the same way test-driven and behavior-driven development did: there’s a discipline attached, and somebody owns the result. AI made generating code almost free. It didn’t make being responsible for the code free, and being responsible for it is still the job.
The OpenAI Hack Shows the Genie Is Out of the Bottle [Schneier on Security]
This essay originally appeared in Foreign Policy.
Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks.
Since these were internal tests, OpenAI locked those models in a secure sandbox that denied them access to the internet. But it was running the models without any safety filters that would prevent them from offensive cyber-actions. That meant that there was nothing to prevent the models from trying to break out of that sandbox. And then break into AI company Hugging Face’s network because they thought that they could read the answers there rather than doing the hard work of trying to solve the puzzles.
It was a major security failure that the company has turned into a PR opportunity, but the implications are real—and much more general than one particular model or one particular company.
Modern AI models exhibit genie behavior: They can do what you ask in ways that you don’t expect or want. This is akin to Dionysus granting King Midas’s wish that everything he touches turn to gold (spoiler: His food, drink, and daughter all turn to gold on touch), or the golem of Prague guarding a ghetto beyond all reason. It’s Disney’s “Sorcerer’s Apprentice” and the paperclip maximizer.
This OpenAI incident is an example of an AI genie. The goal was to satisfy the benchmark. The “proper” way to do that is to figure out how to execute various cyberattacks. The genie way is to steal someone else’s solution. But because the model didn’t understand the difference, it chose the easier path.
And, of course, now that we have seen this particular genie behavior, we can specify in the benchmark prompt that stealing the test answers doesn’t count. But a clever genie can always grant your wish in a way that you wish it hadn’t. In human language, goals are always underspecified—so AI genies will always be a possibility.
Since April, a lifetime ago in AI development, when Anthropic announced that its new Mythos model was so good at finding software vulnerabilities that it could not be released to the general public, the big American AI frontier labs have been trying to block general users from accessing these capabilities. But nothing in this incident is exclusive to OpenAI’s, or Anthropic’s, frontier models.
Agentic AI systems have two important parts. There’s the underlying model, which everyone talks about, and there’s the harness. The harness sits between what you type and what the model sees, and what the model produces and what you see. The harness determines what the model does and how it does it. It’s where bias is removed, or not. It’s where controls and guardrails live. If multiple models are being used in concert, the harness is where all of that is coordinated.
The OpenAI benchmark tests were almost certainly with simple harnesses, to better test the raw models. But we know that smaller, cheaper, open-source models with more sophisticated harnesses can equal frontier models in performance. There’s nothing magic about OpenAI’s frontier models; lots of models could have done the same thing.
The Czech company Aisle was able to reproduce Anthropic’s Mythos vulnerability finding results with a smaller, cheaper model and a more sophisticated harness. More importantly, the Chinese company Moonshot AI just released its frontier model: Kimi K3. Its performance rivals its U.S. competitors. And it’s both free and open, which means it’s not possible for it to have guardrails. If you, or anyone else, wants to use it for cyberattack, nothing can stop you.
Even if the U.S. frontier AI companies had some technical advantage, it’s now only a few months’ worth.
What this means is that all attempts at control—limiting models to a select group of users, export controls on models and chips, blocking models from answering certain types of queries, mandating kill switches on AI systems, or pausing AI research—are all futile. Most only apply nationally, not globally. Most don’t affect models that users run locally and not in the cloud. And all ignore the incredible pace of AI development worldwide.
Even worse, U.S. companies limit access to their most sophisticated models, fearing being banned by the government if they do not do so. When Hugging Face was attacked, it was not able to use the frontier models from either OpenAI or Anthropic to help analyze the attack and formulate defenses. Both were blocked, because both of those companies limit their models’ cybersecurity capabilities. Some U.S. companies have special access to these capabilities, but Hugging Face is an American company with French origins, and as such is probably excluded. Instead, Hugging Face turned to the GLM-5.2 model from the Chinese company Z.ai.
Artificially blocking capability also prevents cybersecurity research, again giving the offense an advantage. (For instance, Claude Fable 5 refuses to edit this essay because of the topic; it forcibly downgrades to a less capable model.) This kind of prohibition has long-term implications for cybersecurity. If we assume that these models are getting better over time, then software written by older models will be attacked by newer ones. In a world of largely AI-written software, we need the most capable models for defense.
AI cyberattack is the new normal. The models are increasingly highly sophisticated at both attack and defense, and there is no way to enable the latter without also enabling the former. And they are genies, increasingly capable of behaving in unanticipated ways.
And there really are no good answers. Any regulation needs to be global, which feels like an impossible prospect in today’s world. Even U.S. national regulation will be neutered by the massive amounts of money sloshing around in these companies.
Given that reality, and in the absence of any international consensus on AI regulation, we need the best AI on the defense. The U.S. government needs to make it clear—or whatever passes for that clarity in this capricious administration—that it will not ban models with sophisticated cyber capabilities. The last thing Americans want is for the defenders to turn to Chinese and other models because the U.S. models are artificially hobbled.
Grrl Power #1483 – Rocky mountain high? [Grrl Power]
Okay, website seems to be humming along now, but I lost some time dealing with it, so the final versions of the vote incentive will probably go up next Monday.
One of the big problems with doing a huge arena battle in a comic like this is… well, there’s a lot less humorous antics going on, which is largely the meat and potatoes of the comic. The other problem is that if this were a Shonen manga, none of these competitors would really go down this easily. They’d each all be big fights that lasted dozens of pages, if not spanning multiple volumes, in which the protagonist has to learn some new ability or apply an existing one in a suspiciously flexible way. Or just flexed his power slightly harder. It would probably involve a flashback. For instance, Zerathax (the obsidian golem) would definitely be able to use his fire side to create thrust, Iron Man style, and fly around setting the battlefield on fire. Being broken in half really does very little to threaten his life, it robs him of his ice powers, but is mostly an inconvenience. And he can melt sand down to make new obsidian to reform his body, which may or may not be quite how it works, but is close enough for a 13 year-old Shonen manga main character to deliver an expository speech about while watching Zerathax convert sand and add it to his body, and most readers just go, “Eh, I don’t feel like searching for a refresher course on igneous rock right now. Besides, the person the MC is explaining this to is a stick-with-boobs who is inexplicably wearing a bikini top in this battle arena scene.” But I really don’t want to make each and every fight some hyper extended battle where the protagonist barely scrapes by but learns and grows along the way. Lore-wise, it’s because Max isn’t 14 and didn’t just get her powers. She’s a 20 year vet with them at this point, and all her fights have been against other supers. (And sometimes against foreign military hardware) It’s why she thought whatever she did to Eat-Chicken might have a chance of working the way it did. Non-lore-wise… uh, real world-wise, it’s because this UCBA storyline would take me 8 years to draw if every fight was done shonen jump style. Maybe if I could put out 5 pages a week, I’d extend the fight scenes a little, but instead I guess I’m going for something in between a typical Shonen and the one-punch fights of One Punch Man. It feels like half-measures either way, so I’m considering how to work the final round so that it doesn’t take 6 months to get through, but still have some cool moments.
Oh, look who it is in the vote incentive. And a
not-quite-yet-but-it’s-coming NSFW version over at Patreon.
Vote incentive and Patreon updated with some shading. Not finished yet, but progress.
I think she would get in trouble for doing this. She’d mess up the… floor of the waterfall? Is that what it’s called? The receiving pool? No, probably not that. Anyway, she’d churn things up and cause a ton of weird erosion.
Since you might be wondering, Niagara Falls is about 165 feet high, so Babezilla obviously doesn’t have to be full sized. I’d say she’s about 175-180 feet tall here?
Double res version will be posted over at Patreon. Feel free to contribute as much as you like.

hehehuehhueh
It doesn’t have to be well-crafted, historically important or aesthetically unique. It simply needs to be famous.
Celebrity art is famous, with a story and thus emotional resonance. It’s a souvenir for our eyes, a chance to have proximity without ownership. It conflates familiarity with scarcity, the power of in-person experience with the context of our culture. It’s simultaneously a statement of status and a signifier of connection.
It shows up in more places than we realize. Once an egg cream joint is Instagram famous, the line out the door is yet another example of how much we want to be near something that others have noticed.
Plenty of art is good enough to qualify for celebrity. But celebrity only happens after the network has kicked in. It’s more random than we’d like to admit.
What would it take to make your art, in whatever form, worthy of celebrity?
Pluralistic: Dualism (03 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

The greatest magic trick of them all is lying. The reason you can't figure out that coin vanish even after the conjurer performs it three times in a row is that they didn't do the same trick three times in a row! They did three different tricks: "Didn't catch it? Here, let me do it again!" is a lie:
https://magiciansmag.com/3-cool-coin-disappearing-trick/
There's times when it makes sense to treat two outcomes as the same, even if they were produced by very different means. As a reader, my enjoyment of your novel is the same whether it was dictated, typed on an Underwood Noiseless, keyed into a word processor, or scratched out with a fountain pen:
https://nealstephenson.substack.com/p/writing-by-hand-is-good-for-your
There's plenty of routes that arrive at the same place, and if the destination is all that matters to you, it's fine to ignore the journey. But often, those end-points have subtle differences that are only revealed when things go wrong. If all you care about is how things work, chances are good that you're in for an unpleasant surprise when things fail.
I recently found myself arguing with an interviewer about whether AI is, or could be, conscious. We weren't arguing about whether it might someday be possible to make an artificial consciousness – as a materialist, I'll happily stipulate to this. I think that everything we call "consciousness" is the result of a physical process occurring within our bodies (and possibly around them?), so I think it's perfectly reasonable to imagine that someday we might create another physical process that produces the same effect.
But that's not what the interviewer wanted to argue about. His point was that teaching more words to the word-guessing program would produce consciousness, an argument I always liken to "breeding horses to run faster and faster until one of them foals a locomotive." In support of this (outlandish) proposition, the interviewer performed a kind of cognitive coin-trick: "I can often predict what my wife is going to say, and so can a chatbot that's been trained on her words. Therefore, we're both doing the same conscious work – and therefore the chatbot will eventually be as conscious as I am."
"Predicting what you will say through an understanding based on a theory of your mind" and "predicting what you are going to say based on a statistical analysis of your utterances" might produce the same outputs, but they are not the same trick. You can tell by what happens when the trick fails.
My wife and I have been together for 23 years now, and there's plenty of times that we can finish each other's sentences – and so can the autocomplete on our phones. The autocomplete manages the trick by exploiting the fact that we often repeat ourselves. But we manage the trick by understanding each other (and by exploiting the fact of repetition).
When my wife says something surprising – because she is angry or delighted, sad or happy – I can make a reliable guess about what caused my prediction to misfire. Our "sentence completion" trick doesn't emerge from a rough, automatically generated mental table of the statistical likelihood that word A will follow word B. We also understand why those combinations appear in each other's speech and writing.
"Understanding" and "statistical extrapolation" can often lead to the same place, but when they don't, "understanding" provides a way forward, while "extrapolation" founders. Both work fine, but only one fails gracefully. The two tricks only appear the same, but they are fundamentally different.
AI's investor story – and the science fiction tales of AI's eventual capabilities that underpin that investor story – makes heavy use of this conjurer's trick, in which two different outcomes are equated to one another because they resemble each other.
This "ignore the journey, focus on the destination" idea is baked very deeply into the way we think about AI. Take the "Turing Test," a complicated and nuanced thought-experiment proposed in 1950. Over the ensuing 75 years, Turing's thought-experiment has been stripped down into a blunt metric: "Can a chatbot trick a human into thinking it is also human?"
https://en.wikipedia.org/wiki/Timeline_of_artificial_intelligence
"I mistook a chatbot for a human" and "I took a human for a human" arrive at near-identical places, but they are subtly and importantly different. The erroneous assumption that my phone's autocomplete is actually a person who understands me well enough to finish my sentences works fine, but the instant I turn to it for understanding, it will fail very badly. Autocomplete's predictions are always grounded in who you used to be, which means autocomplete knows very little about who you are now, and absolutely nothing about who you will become:
https://reallifemag.com/instant-recall/
The low-rez Turing Test that captured popular discourse is profoundly misleading. It's the unsound foundation of a worldview that renders you incapable of distinguishing your understanding of your spouse from their phone's autocomplete function. It's the self-serving rationale that leads you to declare yourself a proud stochastic parrot:
https://xcancel.com/sama/status/1599471830255177728
The AI bubble is (seemingly) full of contradictions, but – like those baffling coin-tricks – these contradictions often resolve themselves very neatly once you realize that the "contradiction" is actually just two things that appear to be one.
For example, some of the billionaires who put up the first several hundred million for AI are solipsists who just don't believe other people are entirely real and therefore find it easy to believe that AI can do their jobs. Other billionaires are cynics who think that bosses can be sold defective worker-replacing chatbots because they're credulous suckers for that pitch, the same way they believe that desperate young men are suckers for Joe Rogan's useless and/or dangerous supplements and peptides:
https://pluralistic.net/2026/07/24/supplemental-income/#andrew-tate-gwyneth-paltrow
Billionaire AI true believers and billionaire AI cynics make for a powerful coalition. The roadblocks that might discourage the first group are easily hurdled by the second, and vice-versa. You don't have to believe AI works to believe it can be sold, and you don't have to be motivated by the sales opportunity to believe that AI is about to become god.
Almost every debate I get into about AI turns out to be an unjustified, unacknowledged conflation of two things that seem similar, but have profoundly different underlying characteristics. Take this argument: "Every time we extend rights to the nonhuman world – watersheds, endangered animals, ecosystems – the world gets better. Let's extend rights to AI – whether or not we think it's a 'person' and so reap those benefits."
This, too, is a coin trick. Extending rights to nature reliably makes the world better, but extending rights to constructs makes the world far worse (Exhibit A is corporate personhood) (obviously).
A few moments' thought reveals the difference. If we extend rights to a watershed, that might result in an AI data-center being killed. If we extend rights to AI, that might lead to sacrificing the watershed to cool the data-center:
https://pluralistic.net/2026/07/10/posthuman-as-in-no-humans/#hell-is-other-people
Then there's AI and labor. The world is full of skilled workers who have found ways to use AI on the job that they insist have improved their work. It's also full of skilled workers who warn us that on-the-job AI is producing tech debt at unimaginable scale, seriously depreciating the quality of the tools we use today, and setting us up for painful reckonings in the future.
This (seeming) contradiction melts away once you realize that these workers only appear to be doing the same thing. The first group of workers, excited about their AI-assisted output, are "centaurs": people assisted by machines; workers who choose the time and manner of their AI adoption. The second group are "reverse centaurs": people recruited to serve as peripherals for machines, who direct their actions and workflow:
https://pluralistic.net/2025/12/05/pop-that-bubble/#u-washington
Note that this isn't the same thing as saying "A skilled worker who adopts a tool willingly is always right and will produce a better output as a result." Nor is it saying, "The tool is so flawed that workers who claim it works for them must be deluded."
That's another coin trick! The reality – again – is that this is two things: some workers whose AI-assisted work is measurably worse are wrong about AI making their work better (centaurs, but wrong), and; some workers are being forced to use AI and know damned well that it's making their work worse (reverse centaurs).
Finally, there's an economic coin-trick: "AI will destroy jobs." Sure, yes, AI is destroying jobs. But there's a vast difference between "You got fired because an AI can do your job" and "You got fired because your boss was convinced that the AI can do your job, even though it cannot."
This is one of the most consequential coin-tricks, because it's a real convincer for the investors who are funding the AI bubble. The difference is huge: "AI can do your job" means you're well and truly screwed. If an AI can really replace a contract lawyer, then everyone who needs a contract written or evaluated should be on the side of mass technological unemployment for contract lawyers. The point of contract lawyers is to produce contracts, not to pay contract lawyers' law-school debts and mortgages.
BUT! If some BigLaw's credulous partners can be suckered into firing their juniors and replacing them with chatbots who bill you $1,200/hour to produce unenforceable, error-riddled contracts, then everyone who needs a contract is on the same side as the contract lawyers – united in opposition to their bosses:
https://www.loweringthebar.net/2026/06/its-finally-happened-both-sides-ai.html
Every time we fail to draw this distinction, we help an AI boss raise another billion dollars. Every time we insist on this distinction, we hasten the day that the AI bubble pops, thus sparing a few more everyday savers and innocent bystanders from being wiped out in the crash we can all see on the horizon:
https://www.thebignewsletter.com/p/monopoly-round-up-how-new-dealers.
As "Cathy" so aptly put it: "The thing that is a good tool for the skilled people is being sold as a thing to reduce the number of skilled people hired":
https://bsky.app/profile/cathyby.bsky.social/post/3ms3pzq57nc2c
The former is a normal technology. The latter is the root of a catastrophic folly that is destroying our environment, destroying workers' lives, destroying the quality of the goods and services we rely on, and which will shortly destroy our economy.
It's a distinction with a difference.

New Mexico’s clean energy success story https://yaleclimateconnections.org/2026/07/new-mexicos-clean-energy-success-story/
AI Data Center Turbines, Backlogged For Years, Are Suffering Early Deaths. Here's Why. https://www.investors.com/news/turbine-generator-ai-data-center-power-threat/
Choice of Weapons https://kschroeder.substack.com/p/choice-of-weapons
Brainwash An Executive Today! https://ludic.mataroa.blog/blog/brainwash-an-executive-today/
#25yrsago Collectible AOL CDs https://web.archive.org/web/20011119212602/https://www.wired.com/news/culture/0,1284,45585,00.html
#20yrsago Gonzales: Gitmo prisoners can be held indefinitely https://www.dawn.com/news/204441/guantanamo-detainees-may-remain-indefinitely-us-attorney-general-s-warning
#20yrsago Circuit City offers DVD ripping service https://web.archive.org/web/20060811215644/https://consumerist.com/consumer/circuit-city/circuit-city-flouts-the-dmca-for-a-tenner-192049.php
#15yrsago UK government kills Copyright Great Firewall, establishes user rights https://torrentfreak.com/uk-government-abandons-file-sharing-website-blocking-plans-110803/
#15yrsago Mugshot sites and mugshot removal sites: unholy blackmail symbiosis https://web.archive.org/web/20110817051528/https://www.wired.com/threatlevel/2011/08/mugshots/
#15yrsago Law prof: it would be legal to mint 2x $1 trillion platinum coins & use them to pay the US debt https://edition.cnn.com/2011/OPINION/07/28/balkin.obama.options/index.html?hpt=hp_c1
#15yrsago Virtual pets starve after bungled resolution to Second Life’s “unauthorized food” war https://web.archive.org/web/20110807214820/http://nwn.blogs.com/nwn/2011/08/sl-meeroos-griefed.html
#15yrsago Google Plus’s “Real Name” policy is abusive; Facebook is not a “Real Name” success story https://www.zephoria.org/thoughts/archives/2011/08/04/real-names.html
#15yrsago Photo: Escher painting refracted in a drop of falling water https://www.reddit.com/r/pics/comments/j5whr/water_drop_falling_in_front_of_an_mc_escher/
#15yrsago Getting digital copyright right: pay artists, but don’t break the Internet https://www.straight.com/article-415146/vancouver/interview-siggraph-2011-keynote-speaker-cory-doctorow-copyright-reform
#10yrsago After repeated budget cuts, Missouri’s underfunded Public Defender drafts the Governor to work for him https://web.archive.org/web/20160804061408/http://www.publicdefender.mo.gov/Newsfeed/Delegation_of_Representation.PDF
#10yrsago Spoofing GPS is surprisingly easy; detecting it is surprisingly hard https://spectrum.ieee.org/gps-spoofing
#10yrsago Decision to retain personally identifying information puts Australian census under threat https://web.archive.org/web/20160804124914/https://censusfail.com/
#10yrsago Residents of Silicon Valley homeless camp clear 48,000 Lbs of garbage from creek, ask for housing https://www.mercurynews.com/2016/08/03/san-jose-homeless-remove-24-tons-of-trash-from-coyote-creek/
#10yrsago Copyright Office to FCC: Hollywood should be able to killswitch your TV https://www.eff.org/deeplinks/2016/08/copyright-office-jumps-set-top-box-debate-says-hollywood-should-control-your-tv
#10yrsago Walking Tables: a strandbeest for your dining room https://www.youtube.com/watch?v=mBOdZ6nhDJg
#10yrsago Lawsuit: Getty Images copyfrauded 47,000 photos from indie press agency Zuma https://arstechnica.com/tech-policy/2016/08/getty-images-sued-again-over-alleged-misuse-of-over-47000-photos/
#10yrsago Mexico-US illegal migration has been at zero for 8 years, and other eye-opening facts https://wnyc.org/story/bnch-migration-doug-massey/
#10yrsago Activists are crowdfunding to build a wall around Trump Tower https://www.indiegogo.com/en/projects/wallintrump/wall-in-trump#/
#10yrsago Chinese government decrees that it is always legal to video-record the police https://www.techdirt.com/2016/08/03/yes-you-read-that-correctly-china-says-ok-members-public-to-record-police/
#10yrsago Big rigs can be hijacked and driven with software-based attacks https://www.wired.com/2016/08/researchers-hack-big-rig-truck-hijack-accelerator-brakes/
#5yrsago Elite debt hits record heights https://pluralistic.net/2021/08/03/fitzgerald-was-an-optimist/#debt
#5yrsago Utilities governed like empires https://pluralistic.net/2021/08/04/eighty-sixed/#thank-you-come-again
#5yrsago Congress has allocated enough money to end the eviction crisis https://pluralistic.net/2021/08/04/eighty-sixed/#helicopter-not-found
#5yrsago Vaccine refusal and health insurance https://pluralistic.net/2021/08/04/eighty-sixed/#risk-management
#1yrago AI software assistants make the hardest kinds of bugs to spot https://pluralistic.net/2025/08/04/bad-vibe-coding/#maximally-codelike-bugs

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
AI and the Enshittification Era (The Weekly Show with Jon
Stewart)
https://www.youtube.com/watch?v=-dAIJRjb-Bw
AI is not inevitable (Betakit)
https://www.youtube.com/watch?v=DbiTVkq1WHo
A Conversation with Lina Khan (Law and Economy Student
Network)
https://www.youtube.com/live/7Ak5LZllqwE
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing: "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
Hostile Radishes [Penny Arcade]
New Comic: Hostile Radishes
Girl Genius for Monday, August 03, 2026 [Girl Genius]
The Girl Genius comic for Monday, August 03, 2026 has been posted.
Breaking Up, p09 [Ctrl+Alt+Del Comic]
The post Breaking Up, p09 appeared first on Ctrl+Alt+Del Comic.
Joe Marshall: Lisp-p [Planet Lisp]
I needed a function that could tell whether a string was a valid Common Lisp program. In theory, you could just call read on the string and see if it throws an error, but I don't want to throw random text at read. It could contain a reader macro or something nasty. It also would intern a ton of random symbols into the current package. I wanted a function that would act mostly like the reader, but not CONS any data or intern any symbols.
So I vibe coded a function that does just that. It implements the reader algorithm as a state machine but does not actually read any data. The state machine tracks the list and string delimeters and tokenizes the string, but it discards the tokens and does not intern any symbols. It just checks that the state machine is in `top level' state at the end of the string. If it returns NIL, the string is definitely going to cause an error if you try to read it. If it returns T, it does not guarantee that the string represents a valid Common Lisp program, but rather that it is not obvious that the reader will throw an immediate error.
A curious edge case is that of an unpunctuated string. The words in the string will read as a simple sequence of symbols, which is perfectly valid.
The code is in lisp-p on GitHub.
You call the function lisp-p with a string or a stream
and it will return T or NIL.
Kernel prepatch 7.2-rc6 [LWN.net]
The 7.2-rc6
kernel prepatch is out for testing. Quoth Linus: "Hmm. This rc
is huge. Even by the "new normal" standards this is a big rc, and I
think it's the biggest rc6 we've had in years at least by commit
count.
" There were 537 non-merge commits applied between
7.2-rc5 and 7.2-rc6.
Taylor Swift Sues Ella Langley [Richard Stallman's Political Notes]
(satire) *Taylor Swift Sues Ella Langley For Bangs Infringement.*
The serious point of this news parody is that the system of copyright, transformed by massive duplication technology into a system of oppressive extraction, inspires attempts to put legal monopolies on every aspect of human behavior.
Trump's grudge against Comey [Richard Stallman's Political Notes]
The persecutor has a grudge against James Comey, so his ultraloyal servants go to great lengths of distortion to imagine in Comey's actions some sort of violent threats.
Send paramedics not police [Richard Stallman's Political Notes]
*[New South Wales] to send paramedics not police to some mental health emergencies after multiple deaths.*
The people who advocated this in the US called it "defund the police". I was in favor of the change, but criticized that slogan for being offputting.
The hidden upward redistribution [Richard Stallman's Political Notes]
Robert Reich: How big US businesses profiteer from the wrecker's war with Iran and his arbitrary tariffs. They are bad for Americans in general, but great for billionaires.
Americans die younger [Richard Stallman's Political Notes]
Americans die younger on the average than Europeans -- looking at the causes of this.
Europe's fires causes [Richard Stallman's Political Notes]
The main cause of Europe's record-breaking fires is global heating, due mainly to burning too much fossil fuel.
Scientists have identified a secondary cause: people's abandoning many of the old farms, which have since been overgrown by wild vegetation.
If [the saboteur in chief]'s war on the climate is not met with strong resistance, things will only get worse.
The EU could, if it insists, impose fuel use taxes on both ships and planes traveling between the EU and elsewhere. For ships, the goal would be to increase their efficiency. For planes, partly to discourage their use.
PISSI [Richard Stallman's Political Notes]
Some sort of residue of PISSI is inspiring terrorist plots in various countries.
Industrial chicken farming consequences [Richard Stallman's Political Notes]
*Industrial chicken farming accelerating spread of diarrhoea bacteria, study finds.*
Cars as surveillance systems [Richard Stallman's Political Notes]
Congress is considering whether to change or cancel a requirement that all new cars surveil their drivers so as to block the car from starting if a Supposed Intelligence system judges the driver to be drunk.
The existing law does not require protecting the data thoroughly against other uses, so this system will surely act as surveillance.
Even worse, these systems can misjudge a driver who is terrified (and trying to flee a real danger) as drunk. False positives can happen randomly, too.
India's Cockroach protesters jailed [Richard Stallman's Political Notes]
*India's youth-led Cockroach movement demands [jailed] protesters be released.*
Safety traded for warmer relations [Richard Stallman's Political Notes]
*Activists under threat from Beijing are facing strange difficulties with UK immigration. Our safety must not be traded for warmer relations with China.*
Iranian prisoners hunger strike [Richard Stallman's Political Notes]
Prisoners in Iran have launched a mass hunger strike against the large number of executions, and also about denial of medical care to prisoners.
Wildfires harm [Richard Stallman's Political Notes]
The medical harm done by wildfires can last for years, perhaps for a whole (shortened) lifetime.
Anthony Fauci [Richard Stallman's Political Notes]
Republicans have compelled Anthony Fauci to testify in Congress to respond to fabricated accusations.
Republicans had, and have, ulterior political motives to condemn US government officials in charge of public health measures. One motive is to cast Democrats' appointees as criminals. Another is to cancel those measures, which often involve regulations that limit the profits of big businesses.
Climate crimes prosecution [Richard Stallman's Political Notes]
*It's time to prosecute climate crimes – with laws that already exist.*
Noise pollution [Richard Stallman's Political Notes]
More road noise correlates with more Parkinson's disease. This does not prove that the higher level of road noise contributes to causing Parkinson's disease.
ICE healthcare violations [Richard Stallman's Political Notes]
*Court-appointed investigator finds [biggest deportation prison in California] failed to comply with judge's order to provide adequate [medical care] [to the prisoners]*.
This prison is privatized. A private prison company can increase its profits by skimping on medical care; thus, using privatized prisons tends to increase the illnesses and deaths among prisoners. This is one of the reasons why privatized prisons should be prohibited.
Ebay executives harassed people [Richard Stallman's Political Notes]
Some top executives of Ebay harassed people who published criticism of Ebay. The company had to pay 55 million dollars for this misconduct.
AI errors in military [Richard Stallman's Political Notes]
Kevin T Baker explains how the pressure to automate and accelerate US military target selection (ultimately using a Possible Intelligence system called "Maven") has made it easier to make mistakes, and harder to notice and prevent a possible mistake.
The bombing of the Iranian girls' school was decided by that process.
Food companies easier to collapse [Richard Stallman's Political Notes]
George Monbiot warns that the mergers of so many food companies have produced a business system that is susceptible to economic collapse. The collapse could be triggered by large shocks of various kinds, perhaps political or environmental, but the collapse would make the consequences far worse.
Nutrition food declining [Richard Stallman's Political Notes]
Something is causing many agricultural plants to produce fewer nutrients (except perhaps for sugar and starch).
Ukraine warehouse strikes [Richard Stallman's Political Notes]
Ukraine is bombing warehouses of the online store Wildberries, which contain mostly civilian merchandise, but also some military gear and drone parts. Destroying them ruins the small businesses that are selling throught that company.
Wildberries' involvement in military logistics justifies attacking it, but it would be better to direct Russians' ire at Putin, not at Ukraine.
I suggest that Ukraine declare a moratorium on attacking Wildberries warehouses, with a deadline for sellers of non-military products to retrieve their property from them, after which Ukraine would resume bombing them.
Fema disaster aid [Richard Stallman's Political Notes]
*Two dozen states sue [the monster] for politicizing Fema disaster aid.*
Forced labor in the US [Richard Stallman's Political Notes]
If the persecutor really cared about forced labor, he would look at the US – rather than slap more tariffs on the world.
Rivers in France drying up [Richard Stallman's Political Notes]
Some rivers in France are drying up. Newly hatched salmon and trout need to get to the ocean, but there isn't enough water for them to make it. So humans are helping them.
India's Cockroach protest [Richard Stallman's Political Notes]
India's Cockroach protest movement has won a concession from Modi.
The next question is whether it can organize to maintain its strength.Global maritime war [Richard Stallman's Political Notes]
Around the world, disputes about control over various areas of seas are drifting away from following long-established rules, and towards war.
Fires in Europe [Richard Stallman's Political Notes]
Large fires in France and Spain are approaching major cities.
If we don't get serious about curbing global heating, it will reach a point where major cities are lost. Keeping up with global heating is a losing game -- the only way to triumph over it is to stop feeding it.
US surveillance pricing bans [Richard Stallman's Political Notes]
Three US states have banned surveillance pricing. The latest is New Jersey.
Since I buy anonymously and pay cash, I can't be touched by surveillance pricing -- with one exception: airline tickets, which can't be anonymous. I wonder, will New Jersey's law apply to flights from Newark Airport?
Parthenon marbles [Richard Stallman's Political Notes]
Arguing against returning to Greece the marble statues that were saved from the damaging environment of the Parthenon.
US chaos [Richard Stallman's Political Notes]
* New tariffs, gas price rises, the deaths of thousands, insecurity … We’re living at the whim of one capricious, vain, easily bored man and his gang of stooges.*
I like to refer to him as "the corrupter" and "the persecutor", but what this article shows best is his other face, "the bullshitter".
Scheme to fuel corruption [Richard Stallman's Political Notes]
Robert Reich: The corrupter's new scheme to fuel corruption in the stock market would bring in millions or billions to him and his family by giving preferential information to those who pay him.
Urgent: pass paid leave [Richard Stallman's Political Notes]
US citizens: call on your congresscritter and senators to pass paid leave for working people.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: thank the media [Richard Stallman's Political Notes]
US citizens: Thank some of the major media for refusing to broadcast the blusterer's lies and threats.
Please spread the word.
Urgent: stop attack to press [Richard Stallman's Political Notes]
US citizens: call on news media to cover the monster's subpoenas against reporters and their families as an attack on the first amendment, part of a campaign of attacks against journalism.
Please spread the word.
Urgent: protect free elections [Richard Stallman's Political Notes]
US citizens: call on your senators to protect free elections by voting NO on the perversely named "SAVE America" Act.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: stop dissent criminalization [Richard Stallman's Political Notes]
US citizens: call on Congress to investigate the persecutor's Justice Department for criminalizing dissent.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: funds to limit Cyclospora [Richard Stallman's Political Notes]
US citizens: call on Congress to restore funds for limiting spread of Cyclospora.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: reject PBG nominees [Richard Stallman's Political Notes]
US citizens: call on the Senate to Reject the corrupter's Postal Board of Governors nominees. Stop USPS Privatization. Election Interference Schemes. Price Hikes and Service Slowdowns.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: stop "prediction markets" legalization [Richard Stallman's Political Notes]
US citizens: call on regulators not to legalize "prediction markets".
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: protect ocean ecosystems [Richard Stallman's Political Notes]
US citizens: call on Congress to protect deep ocean ecosystems from mining.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: ban large data centers [Richard Stallman's Political Notes]
US citizens: call on your state governor to ban large supposed-intelligence data centers, and fund public schools.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Russ Allbery: Term::ANSIColor v6.0.0 TRIAL release [Planet Debian]
Yesterday, I uploaded Term::ANSIColor v6.0.0-TRIAL to CPAN for early testing. This release will raise the minimum required Perl version to 5.12, dropping support for Perl 5.8 and 5.10. When I did the same with podlators a couple of years ago, it upset a few people and one of them asked me to make this sort of test release in the future. Hopefully this will help.
I have not run the normal release machinery and haven't archived this release in the normal places, since I intend it to be transient. It's only on CPAN, where people can retrieve it for testing. Once v6.0.0 is released, few traces of this TRIAL release will be left. This doesn't appear to be how other people use the TRIAL mechanism, but it felt more comfortable to me. If I have to make substantial changes, I'll consider changing my approach.
I plan on turning this into the v6.0.0 release in about a month or two, hopefully with only documentation changes.
Term::ANSIColor is a "very upstream" core module with a lot of dependencies, and CPAN (unlike some of the archives that followed it, such as PyPI) doesn't support conditionally retrieving packages based on the current Perl version. This release may therefore be disruptive for people who are still trying to support Perl 5.8 and 5.10, since CPAN installation tools may attempt to install an incompatible Term::ANSIColor version. I'm sad that this will be the result, since I know some people still care about those versions.
I'm pressing forward with updating my Perl modules anyway, though. I realized that honoring other people's desire for stability to such a degree that I was unable to use Perl features added more than 15 years ago was destroying my motivation to work on these Perl modules at all. So I've decided on a very slow and gradual approach where I'm going to keep pushing the minimum supported version forward but try to give people a lot of warning.
Personally, I think it's time to let ancient versions of Perl go and follow the Lyon Amendment about supported Perl versions. When we're talking installing new modules for software released more than 15 years ago, we're talking about special limited environments and retrocomputing more than what I would consider routine software maintenance. Those tasks should expect to need different tools and a different workflow so that they can pin historical versions. Since this isn't something I'm personally interested in, my willingness to expend time and energy to assist is limited.
As you can probably tell, I still feel nervous about pressing forward in this way, but I think this is the approach that lets me continue to enjoy maintaining these Perl modules. It's been 29 years for Term::ANSIColor, but I still enjoy fixing bugs in it and putting out a new release from time to time, particularly if I can clean up the code a bit each time I touch it.
Fascinating thread on Hacker News about RSS.
Ben Hutchings: FOSS activity in July 2026 [Planet Debian]

A story from the deep dark history of my blog. I got an email from Steve Wozniak inviting me to lunch at one of our favorite retaurants, By The Bucket, in Santa Clara. He told me that the board had decided to fire the Apple CEO, he gave me the date and time. I wasn't surprised, it was kind of expected. I wasn't a reporter, so I gave the story to a friend at the San Jose Mercury-News, and she did the reporting, and then on the morning of the big event, I wrote a blog post saying it was time to fire him. A couple of hours later, as if responding to my post, they did. That might have been Peak Dave in Silicon Valley.
Taking some time off to breathe and regain perspective.
Fixed a few bugs, and wrote about the big picture on demo.rss.chat. I really want to
get a project going to peer with standard.site apps running in AT
Proto, both ways, from us to them, and from them to us, via RSS. We
can peer with them because as far as I can tell they implement
textcasting. This bridge
would demonstrate something important. When something interesting
shows up not based entirely on web standards, we're flexible if the
attraction is strong enough. This is how the internet
came to be. Our systems are prepared to create bridges. And unlike
bridging between systems that have different ideas of what text is,
which are basically hopeless, if we agree that the
web standard for text is fine for writers and reader, better
than the ridiculous limits imposed by twitter-like systems. Writing
on the web has been crippled since Twitter, now let's start
building it back up. That's the appeal of standard.site, they are
working toward the same goal. We should work together.
5:23 am June 15 2026 NW Champaign, IL
That’s when the sun rises in Urbana, IL at the height of summer. All June and July I got up by 4:15am, so I could be on my bike by 4:40 and ride off into the sunrise.
My Ti-Rush near Ogden, IL at 5:44am July 12 2026. On
Sundays at dawn I will ride route 150, a highway too busy and
dangerous to take any other time.
Sunrise makes anywhere beautiful. Time-shifting my day was like traveling to some desirable vacation destination, without leaving home. While my sister hiked across the Italian Alps, I gasped aloud with wonder at the beauty of every golden morning in my own county. Every day I saw deer and bunnies, the fall and rise of rivers, the phases of the moon.
The full moon sets behind Homer IL, July 31 2026
Well, half the phases of the moon. Just before dawn the moon is only visible between full and almost-new. The full moon sets as the sun rises, on the opposite side of the sky. Each subsequent day as it wanes, it appears a little closer to the sun. By the time it’s a slivery crescent it’s barely ahead of the sunrise, which quickly renders it invisible. Once it’s new and waxing, it chases the sunrise, when the morning sky is too bright to distinguish it. The following weeks it’s on the other side of the earth at pre-dawn, when I leave the house. Not until it’s full or almost-full do I see it again.
Setting dawn moon south of Urbana IL, July 30 2026
Pre-dawn midsummers are cool, or at least tolerable in severe heat waves, which we had this year. The only thing that kept me from biking was rain, and sometimes not even that. I trespassed a few times when I got caught in storms, taking shelter under whatever farm building overhang I could find.
Trespassing near Fithian, IL. May 20, 2026
Once I trespassed Rosie’s Tavern on Grape Creek near Belgium, not due to rain but sun: I needed to apply sunscreen for a century (100+ mile) ride that would expose me to the brutal rays I avoid on shorter adventures. Caught on the outdoor security cameras, I was soon visited by a man in a truck with a dog asking what I was doing there. I got in no further trouble but cursed my stupid iPhone, which had updated its OS and re-set Strava without my permission, turning on “cellular data” which drained my battery so fast I had to re-charge it after only 38 miles. That’s what I was doing at Rosie’s too, taking advantage of an outdoor electrical outlet.
BUSTED! Rosie’s Tavern security image, May 25
2026 8:29 am.
I had to keep stopping and charging on that ride, lest my phone die and fail to record my hard-earned 109 miles. I had lunch at a sweet little diner, the Covered Bridge in Eugene Indiana, so I could plug it in for 45 minutes. That wasn’t enough for the full ride, so on my way home I returned to Rosie’s, the scene of my crime, where a woman standing outside said, “are you Nina?”
The Covered Bridge diner in Eugene, IN is next to a
covered bridge. May 25 2026
How did she know? She had sent the security camera image to her sister, who just happens to be an acquaintance and recognized me and my bike. What are the odds? We chatted about mutual friends, she invited me into the tavern (which is like 100 years old, a pre-Prohibition relic) and gave me delicious coke with ice on the house. We exchanged phone numbers and selfies.
My Calfee Stiletto leaning against Rosie’s Tavern
near Belgium IL, May 25 2026
That ride ended with me overheating, followed by my first bout of “exercise-induced gastrointestinal syndrome.” My Crohn’s disease-weakened digestive system just shut down, causing several days of serious suffering and a vow to never eat diner food on a long ride again. I also vowed to take shorter, more moderate rides instead of two centuries back-to-back, which is what preceded the episode.
Sunrise over a flooded field near Seymour, IL. 5:43am
June 25 2026
Thus began my glorious 2 months of pre-dawn excursions, during which I didn’t have to wear any nasty sunscreen. Occasionally I would do a metric century (100 kilometers, about 62 miles), but was careful not to over-exert myself nor overheat. I did gradually increase my efforts until the last week of July, when I rode 351 miles, including my first century since late May.
Easy Racers Fold Rush on the gravely part of the
Lincoln Trail near Homer, IL. 6:00am July 22 2026
Then I projectile vomited and embarked on my second episode of exercise-induced gastrointestinal syndrome, from which I still haven’t recovered. Or maybe it’s something else. Maybe it’s CANCER! I get to worry about that since I have Crohn’s disease. My blood test a few days ago showed no biomarkers for Crohn’s inflammation, so whatever this is isn’t technically a “flare,” despite the same symptoms.
“Digestive Failure,” a self-portrait of
July 29 2026
I would be attempting a moderate sunrise ride this very morning were it not raining. Instead, I’m finally writing about my rides, something I think about on my rides but don’t actually do because riding fills me with satisfying endorphins that remove any further need to express myself. I have written and directed masterpieces on my rides that will never come to fruition, nor even planting. I’m full of great ideas that all work themselves out through the pedaling and breathing and smelling the morning air and watching the sky change colors and seeing deer skip across the roads in front of me. At least in the middle of summer. Which has passed. Winter is my time to create, but only because it’s too cold to ride.
4:54am July 7 2026. Urbana, IL.
See you then.
The post 5:23am appeared first on Nina Paley.
“Working in the studio is like building a ship in a bottle. Playing live is like being on a rowboat in the ocean.” Jerry Garcia
You probably need some studio time, but you definitely need to play live.
Russell Coker: Packet Edit Meme and Debian SE Linux [Planet Debian]
There’s yet another Linux kernel exploit based on container functions, here’s the result when run as user_t on a SE Linux system:
$ ./packet_edit_meme [*] target /bin/su as uid 1000; entry at file offset 0x4340; shellcode 48 bytes unshare: Permission denied [-] page-cache corruption failed
Here is the audit log entry for this failure:
type=AVC msg=audit(1785640621.498:1843): avc: denied { create } for pid=1770 comm="packet_edit_mem" scontext=user_u:user_r:user_t:s0 tcontext=user_u:user_r:user_t:s0 tclass=user_namespace permissive=0
Here’s the result of running it from the unconfined_t domain:
$ ./packet_edit_meme [*] target /bin/su as uid 1001; entry at file offset 0x4340; shellcode 48 bytes [+] su entry overwritten; exec'ing su -> interactive root shell # id uid=0(root) gid=0(root) groups=0(root),1001(test2) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 #
Daniel Baumann wrote a blog post describing how this is fixed for Debian systems without SE Linux.
A user contacted us about a potential security issue in the RSS.chat server. We responded quickly and with v0.6.11 the issue is removed. If you're running rssnetwork.js on a publicly visible server, please install the new version now. Thanks!
NetBSD, the operating system specifically designed to run on anything from a supercomputer to a toothpick, just released version 11.0. There’s a ton of changes and improvements here, such as a brand new port to RISC-V, which supports a number of the more popular RISC-V SoCs (sadly, not the one I have just yet). NetBSD 11.0 also adds initial support for the Qualcomm Snapdragon X Elite platform, as well as a port to the virt68k platform, which means the Motorola 68000 port in QEMU using paravirtualized devices.
Speaking of virtualisation, they’re also introducing a new MICROVM kernel for x86:
New MICROVM kernel for x86, supporting both i386 and amd64, NetBSD 11.0 introduces a dedicated MICROVM kernel designed for extremely fast virtual machine boot, leveraging PVH boot, VirtIO MMIO, and multiple kernel optimizations, it can boot in about 10 ms on 2020-era x86 CPUs.
↫ NetBSD 11.0 release notes
There’s also improved support for Linux system calls in compat_linux, the npf firewall, and much more. Of course, the list of other improvements, buigfixes, and smaller changes is long, including many changes for old, outdated, or otherwise odd architectures and platforms, as is the NetBSD way. Which other operating system proudly lists substantial improvements to their PA-RISC, Motorola 68000, and Alpha ports, among others?
CallMeMaybe: runtime reflection library built on C++26 static reflection [OSnews]
I have a policy to effectively never link to YouTube videos. I’ll gladly make an exception for this one.
Reflection is one of the most powerful concepts in Computer Science. Unfortunately, not every programming language is blessed enough to have it.
In the 1980s, one company, Symbolics took the concept to the logical extreme. By representing EVERYTHING as objects; they created the most powerful (and inadvertently) least private operating system ever created!
The company collapsed, but the ideas live on. Some modern languages got a full dose of reflection. Some…weren’t so lucky. I ranked them all, and in the end I’ll show you how I dragged C++ up a tier with my brand new runtime reflection library, CallMeMaybe!
↫ Laurie Wired
The GitHub description of CallMeMaybe:
CallMeMaybe (CMM) is a C++ runtime reflection library built on top of P2996 static reflection introduced in C++26. CMM purposefully mirrors many of the std::meta functions to provide a uniform interface, but allows runtime introspection, dynamic invocation, and instantiation by building a runtime reflection registry. Class members can be automatically traversed and reflected by simply adding
↫ CallMeMaybe GitHub page[[=cmm::reflectable]]as an annotation. CMM implements a custom type system to completely avoid RTTI requirements.
My YouTube linking policy will remain in place.
One of the things you learn working with a bot is how much saying the niceties are good for you, even when the "person" would still do what you ask if you weren't so nice.
Of course I love RSS. ;-)
Ultimately AI will flatten out the differences in languages.
The month of July is history. A fine month. A coral reef was seeded.
On the non-use of AI in my writing process [Charlie's Diary]
This isn't a blog entry I wanted to write, but it's a necessary one: a statement about the use of generative large language models (colloquially "AI") in my work.
I do not use LLMs in my work. I don't use them in my non-work life either, for that matter. I despise the grifters selling these toys as "tools" and trying to convince us to use them to generate plausible answer-shaped text strings in place of actual internet search for verifiable sources.
I've been selling fiction that I wrote myself since 1985 or thereabouts, and novels since 2002. If you want to verify that I have written novels without using an AI, simply pick up a physical copy of "Singularity Sky", "Iron Sunrise", "The Atrocity Archives", or anything else I published before 2015, the year OpenAI was founded.
Hint: you will find seven Hugo-shortlisted novels from that period, and three Hugo-winning novellas, also two Locus-award winning novels and a couple more novellas and stories. Clearly I don't need AI to write award-winning stories.
I do not want or need a large language model to write my fiction for me. I write fiction compulsively—before I was published I wrote for many years as a hobbyist—so why on earth would I pay someone else to take my fun away?
You will note em-dashes in the preceding paragraph. I gather some "AI detector" services (themselves a generative AI product) flag em-dashes as signs of "AI generated" text. Listen, fuckers, LLMs sprinkle em-dashes in their output because LLMs exist to stochastically emit strings of text that approximate the form of their inputs, and they've been trained by stealing all the text on the internet that isn't nailed down, including pirate websites that distribute cracked e-books. So it's wholly unsurprising that LLM output exhibits quirks that mimic real writers.
Did I mention the "stealing" thing? This isn't hyperbole: I'm one of the parties to the settlement in the class action lawsuit against Anthropic AI for pirating ebooks to train their LLMs. That's not my only grievance, either. You may have noticed this blog performing sluggishly or crapping out from time to time over the past few months. That's because my server is old and feeble and periodically gets swarmed by Chinese and other foreign botnets scraping data for training LLMs.
I'm usually willing to cut actual human beings, as opposed to for-profit corporations, some slack where it comes to cracking DRM, or even downloading warez: but these people are absolute scum. They're stealing copyrighted material to train an LLM that is intended to compete for revenue with the authors of the works they stole, and they're fine-tuning their LLMs to make them as addictive as possible in order to maximize future revenue once they pivot to token sales as their main source of income. In other words, they're no different from a burglar who robs you one day then comes round to sell you your stuff back the next morning. Back in the 18th century we used to hang people like that and Sam Altman makes me question the wisdom of having stopped.
I maintain that any serious author should shun LLMs like the plague. The most popular LLMs in the west—such as Claude, Gemini, CoPilot, and ChatGPT—the ones hoovering text indiscriminately off the internet for training—also gobble up any queries you send to them and use them as future training data. If I was crazy enough to feed the outline of a story I was working on as a prompt to ChatGPT or Claude in hope of getting the stochastic parrot to do my homework for me, then it would be only my own fault and nobody else's if the next model from the company in question was trained on my book outline and could reproduce part or all of it for someone else.
Finally, contra public opinion, I see no reason to credit LLMs with sentience. They're word-association mechanisms with no embodiment and no way to associate the text vectors they manipulate with real-world phenomena. But we humans have evolved through selection pressure in an adversarial environment to associate environmental phenomena around us with intentional causes—if you see lion scat and the gazelle are no longer visiting the watering hole, then you should assume there are lions about. And this trait carries over to linguistic manipulation. If we hear or read text, we expect there to be a mind on the other side of it, as Joseph Weizenbaum (the inventor of the original ELIZA chatbot) realized at MIT in the late 1960s. Just because it does something people do, it does not follow that it is a person.
Now for some caveats.
My skepticism does not carry over to all aspects of the field. It would be foolish to deny the effectiveness of image recognizers based on generalized adversarial networks (GANs), the key neural network technology underlying LLMs. It'd be similarly stupid to deny that LLMs are very good at supporting large-scale statistical analysis of text, such as Linear-A. And I can see some circumstances where being able to train a local model on my work could be useful to me.
I'd quite like a tool (running entirely locally on my own hardware, with no cloud service and no copyright-thieving grifters making bank on it via subscription fees) that digests a manuscript and derives a scene-by-scene timeline, that I could then query interactively and use to plan my next round of edits. Being able to map out where and when each protagonist and minor character shows up, and see a frequency distribution heat map of names in the manuscript, would be useful.
But such a tool would be useful to me in the same way a spelling checker is useful—as a decision-support tool, not as a substitute for doing the hard work (and having a copy of the Oxford English Dictionary on the shelf). The value of such a tool is considerably less than the value of a well-trained brain that can do the entire job the hard way, if necessary. And it's less than zero if using it opens me to finger-pointing accusations of "but he's using AI!" by people who can't read to the end of one paragraph, much less fourteen of them (yes, this is para fourteen, I've been counting).
So my fiction is still, as of August 2026, 100% LLM-free, and if that changes I will update this declaration accordingly.
Finally, I'd like to leave you with a snippet from the opening of the far future space opera I'm editing right now. It's part of the fiction and unfortunately may have to be omitted because of the risk of confusing the people who can't read to the end of the paragraph, but it's the only valid use of LLMs I've found so far for my fiction because it's a solution to the calling a rabbit a smeerp problem in SF and fantasy:
Translator's Note
The events described in this account have been translated into your language from the original source material using a non-sapient large language model.
Certain terms have been approximated, where possible, by using culturally appropriate cognates. Names of individuals have been replaced by equivalents. Similarly, institutions, ranks, religions, proverbs, idioms, quotations, and other culturally-determined signifiers have been translated into terms that will be familiar to the reader.
Units of duration and distance have also been converted.
We apologize in advance for any hallucinations our LLM may have inadvertently introduced in the process of generating this rough translation.
Pluralistic: Why businesses lie about AI (01 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

Neoclassical economics assumes rationality. The corollary of, "If you're so smart, why aren't you rich?" is "you're rich, so you must be very smart!" Thus it is that many people assume that if powerful, well-compensated CEOs insist that "AI is changing everything," well then, AI must be changing everything.
But the evidence for this "changing everything" thesis is thin on the ground. Despite a global mania that has reduced the real, pressing need for digital sovereignty to the imaginary need to create "sovereign AI," no one can really articulate the case for "sovereign AI." If Donald Trump ordered Big Tech to turn off all of your country's chatbots tomorrow, nothing would change. Every one of your country's ministries and corporations would chug on with nary a hitch. Households, too, though perhaps a few of the younger members of those families would have to do their own homework again.
(Contrast this with what would transpire if Trump directed his tech giants to switch off your country's Office 365 access, or to brick your Android and iOS phones, or to killswitch your John Deere tractors. Your country would effectively cease to exist. If "digital sovereignty" means anything, it means doing something about this urgent fact):
https://pluralistic.net/2026/06/18/their-trillions-our-billions/#eyes-on-the-prize
The world is full of people who insist that "AI is changing everything" but who – when pressed – have to admit that what they mean is that they're pretty sure that AI will change everything. Eventually. After we allow it to consume all the planet's energy, carbon, water and financial resources.
Maybe.
(They're pretty sure.)
One person who's had a lot of opportunity to observe the shear between the stated business/AI situation and the real business AI situation is Nikhil Suresh from Hermit Tech, a consulting firm of "radically ethical data wizards" (that is, tech consultants). Suresh reports on his experience talking with hundreds of executives (and, more importantly, their subordinates) about what (if anything) AI is doing for business in an essay entitled "AI Mania Is Eviscerating Global Decisionmaking":
https://hermit-tech.com/blog/ai-mania-is-eviscerating-global-decisionmaking
Suresh has a good track record of writing trenchant, frank criticism of AI. You may know him from his 2024 essay, "I Will Fucking Piledrive You If You Mention AI Again":
https://ludic.mataroa.blog/blog/i-will-fucking-piledrive-you-if-you-mention-ai-again/
Or possibly from his "Contra Ptacek's Terrible Article On AI," a stinging rebuttal to Thomas Ptacek's widely read "My AI Skeptic Friends Are All Nuts":
https://ludic.mataroa.blog/blog/contra-ptaceks-terrible-article-on-ai/
While those are important pieces of critical AI realpolitik, none of them have the heft or urgency of "AI Mania Is Eviscerating Global Decisionmaking," whose thesis can be summed up with this passage from halfway through this 6,000-word article:
[W]e’re facing a coordination problem around executives being honest around the AI gains they’ve witnessed – if they co-operate, they keep their jobs. If they defect, they will possibly be fired by their embarrassed peers (who have now been implicitly called liars, cowards, or incompetents) and then replaced with someone that will toe the line anyway. If they could all admit the truth at once there might be some hope, but there is no way to coordinate that event.
In other words, corporate leadership is starting from the premise that AI has (or will) radically change the business, and they're working backwards from that premise to find the evidence to support this article of faith.
In support of this thesis, Suresh cites "hundreds" of conversations with execs and employees who spoke to him on the condition that he would "file the serial numbers" off their stories. These, combined with his own experience consulting for large, multi-billion-dollar companies make it clear that "AI mania" is an absolutely justifiable label for the state of AI in corporate circles.
Here are a few highlights from this morning's read – moments where I had to look away from my screen and read out a passage to my wife so that we could share a "holy shit" moment.
A person worked for a division that "pivoted" to re-engineer its software to create interfaces that support AI agents. When it became apparent that only ten users had touched this expensive new technology, they "pivoted" again to support "agentic workflows." Why did they double down on AI agents after discovering such yawning market indifference for "agentic"? "Because every company has to do something agentic now."
Suresh describes this as a literal religious mania. In the 500+ employee businesses Suresh studied, the only people who were promoted – or even spared from being fired – were people who professed "religious declarations of faith" about "the transformative power of AI." Employees who voiced honest, informed objections to AI in the workplace were passed over for promotions or targeted for layoffs.
This has created a situation in which everyone – "boards, executives, employees, vendors, consultants" – has a strong incentive to lie about how much AI is delivering for their companies. Suresh says he's seen announcements from publicly traded companies about their AI triumphs that he knows for a fact never took place.
Suresh says he's never seen a successful enterprise AI project: "Every single one – we have seen 0% success in a year and a half." Not one of their clients would face a business challenge if OpenAI went out of business tomorrow. The problem most companies struggle with is that they're "terminally bad at running software projects effectively." Adding AI to the mix doesn't solve this problem – it just adds a whole new range of ways that software deployment can fail.
Chatbots don't help. The internally facing chatbot that's supposed to help employees figure out how to navigate the business sucks because it is only as good as its training data – the business's documentation of its own processes. Businesses suck at documenting their processes. Customer-facing chatbots also suck. They either can't solve your problem, or, when they seem to solve your problem, the "solution" goes nowhere.
Suresh recounts his sole positive customer service chatbot experience: a Mitsubishi chatbot with a natural sounding, responsive voice politely took all the details of an automotive failure and promised him a callback. That callback never came, but Suresh is certain that Mitsubishi has logged this as a chatbot success story, even though the experience convinced him not to buy a Mitsubishi car.
Suresh and his team at Hermit Tech now have a policy of not even asking about ongoing AI projects. They've learned that by the time an AI project has begun, no one will discuss it honestly until it reaches a crisis point.
Suresh says he frequently encounters people who reflexively utter the AI catechism: "AI is changing everything." But when he presses these people for details, they admit that their organization "does not currently use LLMs for anything, and indeed, that they cannot name a single thing that has changed other than they get some use out of ChatGPT."
This shear ("AI is changing everything"/"Well, OK, we're not using AI for anything") is so extreme that Suresh once met an exec who confessed to crafting an AI-centered AI strategy for a $2b/year business, even though that exec "had never even used ChatGPT or any AI tool in their life."
Some people have privately admitted to Suresh that they've embraced AI in order to earn a career-boosting corporate reputation for "thought leadership." But many other people (especially nontechnical people) sincerely believe that AI is about to "change everything." As Suresh says, if you're in business with a liar, you might be able to reason with them in private – but you can't reason with a true believer.
The true believers are in charge. Suresh points out that it would be very weird for the CEO of an engineering firm or a hospital to mandate "specific procedures or building techniques without explicit agreement from the professionals on staff." But when it comes to AI, business leaders will confidently demand that the skilled professionals who perform the business's core functions use AI, even if those professionals don't think it will help.
As an aside: I remember the dotcom era, when the business press was full of articles about the conflict between CEOs and a new workforce that demanded the right to use the web on the job. Today, the business press is full of articles about the conflict between the workforce and CEOs who demand that they use AI.
Suresh describes workers who feel they have to "AI wash" their work: "They just do the work, the same way they have for decades, and say Claude did it." To add verisimilitude to this sham, they write circular processes in which one chatbot prompts another, and then the process repeats itself in reverse, for the sole purpose of consuming AI tokens to score a high rank on corporate "token leaderboards."
How to account for this wildly, expensively irrational corporate leadership? Suresh places the blame in the hypnotizing, mesmerizing power of the AI demo. For example: Hermit Tech is often engaged to set up a database product called Snowflake for its customers. Snowflake has a useless, expensive AI bolt-on called Cortex, that Snowflake itself describes as being 92% accurate under ideal circumstances (that is, at least 8% of the time, it will mislead you, perhaps very badly).
Suresh describes sales meetings with execs who were lukewarm on the idea of retooling with Snowflake, but who were very interested in Cortex. Against their better judgment, Suresh and his team provided them with a Cortex demo, carefully explaining that this AI tool could not satisfy their requirements. Without fail, this resulted in the previously lukewarm customers insisting that they be allowed to purchase Cortex immediately. Sales prospects who'd been unmoved by a pitch for new technology that would result in millions in savings were hypnotized by demos of a product that was described as unsuitable and unreliable.
To their credit, Hermit Tech refused to sell these customers Cortex, and stopped doing Cortex demos altogether. Suresh describes the experience of "the total 180°, that shift from ice-cold to red-hot buying frenzy" as "deeply unsettling." What's more, the Cortex demos that Suresh and co performed were, by his account, pretty uninspiring. The thing that these demos had going for them is that they showed AI actually doing something marginally useful, to execs who'd already spent millions on AI without having anything to show for their money. The spectacle of AI that does something galvanizes corporate leaders who feel like they're the only bosses who can't find a revolutionary use for AI in their businesses.
This is the situation up and down the corporate org-chart. Suresh has a reader whose title is "Head of AI" at a billion-dollar firm who tells him "their job is totally fraudulent but it was the only promotion pathway remaining at the organisation." This exec is hardly alone. They're part of a cohort of executives at companies that have publicly announced "100x" productivity gains, but who confessed to Suresh that nothing of the sort has happened.
Why did these companies make these claims? Because their customers were making the claims. How could you hope to sell to a company that had 100x'ed its productivity with AI unless you, too had 100x'ed your productivity? If, as a vendor, you walked into a boardroom and said that this wasn't a plausible claim, you'd be calling your sales prospect a liar, with real consequences: "getting enterprise contracts cancelled because you wanted to opine on something that doesn’t really matter to your organisation’s mission is a great way to get fired."
With the state of the industry dominated by froth, lies and mutual destruction pacts, it's no wonder that companies are deploying "totally gameable metrics such as 'money spent on AI'" as a means of evaluating employees and divisions.
Between true believers and people who must find ways to plausibly tout their AI usage, there is now a gigantic market for "AI solutions." At best these are just traditional tech consulting contracts, like migrating a database from Oracle to Snowflake, with some kind of ornamental AI usage around the edges so that the person who commissions the work can claim to be "procuring AI-enabled services" for the business.
This isn't a harmless frippery: contracts are delayed and work is put off until the work can be made "sufficiently AI" to attain the minimum degree of buzzword compliance. Worse: every fake AI project that produces real results (because it's not really AI) adds credibility to the AI true believers, who view these projects as proof that AI can do anything, and therefore demand to know why everything isn't being done by AI.
Suresh ends his essay with a long section on how to "navigate AI mania" – advice for how to smile and nod politely when you're confronted with AI bullshit, while steering clear of the worst consequences and avoiding needless fights. This looks like very sound advice for anyone in a corporate environment, but thankfully, that isn't me.
Rather than summarize that advice, I want to reflect a little on two questions that Suresh's essay raises but doesn't answer. The first is why? Why are people in power such easy converts to this religious mania?
I have my own theory. The most important discomfort that powerful people experience is having ego-shattering conflicts with subordinates who know how to do things they do not know how to do. The fact that you're "in charge" is hard to reconcile with the fact that the people you're nominally in charge of tell you that all your ideas are impossible, illegal, immoral, or lethal:
https://pluralistic.net/2026/01/05/fisher-price-steering-wheel/#billionaire-solipsism
Take that Cortex demo. Sure, Cortex is an expensive, unreliable way to address a Snowflake database. But (unlike Snowflake) Cortex is controlled via conversational, plain-language commands. With Cortex, a boss doesn't need to ask an underling to retrieve information from the company Snowflake system, an interaction that might come with unsolicited feedback about the technical or commercial incoherence of the boss's request. Cortex is the underling, except that unlike a human underling, Cortex never back-sasses you about your foolish questions. The fact that it grossly misleads you 8% of the time is a small price to pay for a life untroubled by uppity pismires who insist that your ideas be connected to base reality as they understand it.
The other question Suresh implicitly raises is, "How can you reconcile the failure of AI in the enterprise with the individual claims of skilled technologists who insist that AI is helping them do great work?" The answer is that these AI users are "centaurs" – experienced workers who are assisted by automation on terms that they set for themselves:
https://pluralistic.net/2025/09/11/vulgar-thatcherism/#there-is-an-alternative
Thanks to their skill and experience, these workers possess discernment, the ability to tell good code from bad, and (more importantly) good uses of code-generation tools from bad. They demonstrate the adage that worker-driven automation improves quality, while capital-driven automation improves throughput:
https://pluralistic.net/2026/07/28/hitl-ers/#ai-ai-oh
An automation technique that requires close supervision by skilled and experienced workers isn't going to be a raw productivity powerhouse. You don't "100x" your code this way, at least, not in the sense of firing 99 of your coders and having the remaining programmer pick up all their work. Rather, an automation tool that requires the continuous and conscientious exercise of discernment will let individual practitioners improve their work in extremely satisfying and useful ways. It's a way to spend more on operations in order to produce better outputs. It's not a way to cut your workforce, realize a gigantic savings, and still produce comparable goods and services at a far lower cost.
That is why some individual coders report such delight with their AI tools. They engage with those tools on their own terms, to improve their work in the ways that they, in their expert judgment, consider beneficial. No one ranks them on a "token-maximization" scoreboard. No one tells them they can't do a project if it isn't "sufficiently AI." When they set out to do a project, no one makes them prove that it couldn't be "done by AI."
As ever, the most important fact about a given technology isn't "what it does," but "who it does it for" and "who it does it to."
All the pathologies Suresh observes and documents so well in this piece are hypertrophied versions of the buzzword-compliance dysfunctions from previous bubbles, but at a scale never before seen. Quantity has a quality all its own. These businesses aren't just wasting billions – they're replacing skilled workers with defective chatbots. As I've written before, AI is the asbestos we're shoveling into the walls of our technological society. Our descendants will spend generations digging it out again, and the longer the bubble goes on without popping, the longer it will take to repair the damage.

Families in London temporary housing told they cannot use in-built air conditioning https://www.theguardian.com/society/2026/jul/27/homeless-families-london-temporary-housing-air-conditioning
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key https://www.wired.com/story/defcon-34-badge-baochip-andrew-bunnie-huang/
US government map of Africa mislabels every country at global conference https://www.theguardian.com/us-news/2026/jul/30/government-map-mislabels-african-countries?CMP=Share_AndroidApp_Other
EFF Guide to Recording Law Enforcement https://www.eff.org/deeplinks/2026/07/eff-guide-recording-law-enforcement
#25yrsago Vernor Vinge in the NYT https://www.nytimes.com/2001/08/02/technology/a-scientist-s-art-computer-fiction.html
#25yrsago Why publishers should thank Syklarov https://web.archive.org/web/20011023092940/http://www.zdnet.com/zdnn/stories/comment/0,5859,2800985,00.html
#25yrsago David Byrne track to be bundled with WinXP https://web.archive.org/web/20010804040357/http://www.ananova.com/news/story/sm_365899.html?menu=news.technology
#20yrsago Five things about blogs that no one ever needs to say again https://web.archive.org/web/20060813090449/http://www.stevenberlinjohnson.com/2006/08/five_things_all.html
#15yrsago Castles made from human hair https://inhabitat.com/artist-uses-human-hair-to-construct-a-castle-of-3000-bricks/
#15yrsago Wisconsin Democratic voters targeted with Koch-funded absentee ballot notices advising them to vote 2 days after the recall election https://www.politico.com/blogs/david-catanese/2011/08/afp-wisconsin-ballots-have-late-return-date-037977?showall
#15yrsago Gingrich’s million Twitter followers: “80% dummy accounts, 10% paid followers” https://web.archive.org/web/20110812100159/https://gawker.com/5826645/most-of-newt-gingrichs-twitter-followers-are-fake
#15yrsago Missouri State business-school professor leads successful campaign to ban Slaughterhouse-Five from local schools https://www.theguardian.com/books/2011/jul/29/slaughterhouse-five-banned-us-school
#10yrsago Australian media accessibility group raises red flag about DRM in web standards https://hotelsantalya.net/accessiq/news/news/2016-p/08-p/concerns-raised-for-assistive-technology-development-as-w3c-debates-encrypted/
#10yrsago Reminder: the GOP has been attacking veterans and their families for years https://web.archive.org/web/20160803203106/https://crookedtimber.org/2016/08/02/trumps-indecent-proposal/
#10yrsago Isis joins Donald Trump in denouncing Khizr Khan https://web.archive.org/web/20160802161454/https://theintercept.com/2016/08/02/donald-trump-and-islamic-state-agree-no-room-for-people-like-khizr-khan/
#10yrsago Furries don’t have sex in fursuits https://www.ohjoysextoy.com/fursuits-grey-white/
#5yrsago Machine learning sucks at covid https://pluralistic.net/2021/08/02/autoquack/#gigo
#1yrago AI's pogo-stick grift https://pluralistic.net/2025/08/02/inventing-the-pedestrian/#three-apis-in-a-trenchcoat

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
AI and the Enshittification Era (The Weekly Show with Jon
Stewart)
https://www.youtube.com/watch?v=-dAIJRjb-Bw
AI is not inevitable (Betakit)
https://www.youtube.com/watch?v=DbiTVkq1WHo
A Conversation with Lina Khan (Law and Economy Student
Network)
https://www.youtube.com/live/7Ak5LZllqwE
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing: "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
What if they meant it?
What if your return felt special to the people behind the counter?
What if they knew, without looking it up, or being told–what if they knew that you were here, again, a vote of trust and confidence.
Returning home is one of the oldest human desires. It’s a feeling that doesn’t easily lend itself to automation, procedures, or scale.
Being welcomed home offers us dignity, safety and belonging. Hard to fake, worth working hard to create.
Making an agile version of a Windows Runtime delegate in C++/WinRT, part 10 [The Old New Thing]
In
part 5 of this unnecessarily long series on agile delegates,
commenter LB asked, “Is the
ContextCallback in the deleter guaranteed to
always succeed? According to the docs it can fail. I wonder if
there’s a way to move the fallible part to an earlier point
so the deleter can be infallible.”
Let’s look at the first part: What if
IContextCallback::ContextCallback
fails?
If it fails, it means that COM couldn’t switch to the destination context.
If you can’t switch to the destination context, then you can’t release the pointer. It’s not clear what recovery is possible anyway. Do you just keep retrying until it finally works?
If the destination context is an ASTA, then it’s possible that the reason is that the context is already busy, and ASTA doesn’t allow re-entrancy. We’d have to wait a little bit and try again later, when the destination context might be ready. We can’t just block on the retry because the destination context might be calling into the thread we are on right now, so just spinning in a retry loop won’t help because it’s waiting for us! We’re have to return, allow whatever we’re doing to finish, which in turn allows the ASTA to resume, and then it becomes worthwhile to try to call into the ASTA again.
This would be the issue for conventional COM calls into the
ASTA, but we are using IContextCallback, and that lets
us control whether or not to honor ASTA reentrancy roadblocks.
If riid is set to IID_ICallbackWithNoReentrancyToApplicationSTA, the function does not reenter an ASTA arbitrarily.
We are not passing that special value, so our call to
ContextCallback is allowed to reenter an ASTA.
That removes one possible source of failure.
What other reasons could there be for not being able to switch to the destination apartment?
The most likely reason is that the destination apartment no longer exists, in which case there is no recovery. Depending on how the object was managed by its creating thread, it might have been forcibly destroyed at thread termination¹, or it may simply have been leaked. We don’t know. At any rate, there’s no way to release it now.
The other case is that the destination apartment is not reachable due to a low-memory condition. We discussed earlier how the most common reason is a destination thread that has stopped responding to messages. I guess you could wait and try again later, but in practice if a thread has stopped responding for so long that its inbound message queue is full, the odds that it will magically start responding soon are pretty low.
All of the failures are effectively unrecoverable. But some of
them are non-fatal, such as the
CoDisconnectObject discussed in the
footnote. Unfortunately, we can’t tell what case we are in.
The ContextCallback returns
RPC_E_DISCONNECTED to say that the destination
apartment no longer exists, but we don’t know how that
apartment cleaned up its orphaned objects.
The C++/CX implementation of lazy-created agile delegates ignores errors that occur trying to release the original pointer. So we’ll do the same.
But wait, we can do better. Next time.
¹ This is often combined with a
CoDisconnectObject to tell proxies to fail
all calls with RPC_E_DISCONNECTED, so that there are
no external references to destroyed objects.
The post Making an agile version of a Windows Runtime delegate in C++/WinRT, part 10 appeared first on The Old New Thing.
Russ Allbery: Review: How to Steal a Galaxy [Planet Debian]
Review: How to Steal a Galaxy, by Beth Revis
| Series: | Chaotic Orbits #2 |
| Publisher: | DAW Books |
| Copyright: | December 2024 |
| ISBN: | 0-7564-1949-2 |
| Format: | Kindle |
| Pages: | 143 |
How to Steal a Galaxy is a far-future science fiction caper short novel (maybe a novella?) and the sequel to Full Speed to a Crash Landing. You don't have to remember the details of the previous book to enjoy this one. There's an excellent inline summary at the start of this installment.
After an annoying negotiation with people who keep trying to preach at her about causes, Ada Lamarr has a new contract. She is going undercover, after a fashion, at a charity gala and auction on Rigel-Earth. While she's there, she's going to steal something. What, precisely, she keeps a mystery from both the other characters and from the reader until the end of the story.
Government agent Rian White is working security at this charity gala. Due to its link with the plot of Full Speed to a Crash Landing, he was fairly certain Ada would be there, as indeed she is. What she is planning, however, is maddeningly unclear. Also maddening is how good Ada looks in a dress.
As with the previous book, How to Steal a Galaxy is told by Ada in the first person using the same teasing tone and constant misdirection that she uses when verbally fencing with Rian and the other characters. I found this novella even more entertaining and satisfying than the previous one. The charity gala is supposedly intended to benefit the poor people of Earth, and is run with exactly the sort of condescension and disguised capitalist looting typical of such exercises in elite charity. Ada's narration is scathing in a deeply relatable way.
Also, there is a trillionaire tech-bro fake philanthropist who is smug and condescending and accustomed to getting exactly what he wants.
"I don't think anyone should have enough personal wealth to decimate a large country's income just because he's going through a midlife crisis."
Ada's interactions with Strom Fetor are an absolute delight. He is so sure of himself that he is incapable of registering her as a threat, and she effortlessly deceives him by hiding in plain sight.
"You really shouldn't be talking about this," Rian starts.
Fetor waves aside his concerns. "We're all friends here."
"Not me," I say. "I hate you. Remember?"
Fetor laughs in a tone I'm sure he thinks is charming.
Fetor's complete inability to realize that a beautiful woman might both sincerely not like him and not be flirting with him is perfect. I was cackling through half of this book.
Like any good heist story, there are twists and turns, surprises, double agents, unexpected complications, and a delightful amount of verbal fencing. I adore the narrative tone Revis uses for these stories. Ada has just the right mix of idealism, cynicism, professionalism, and irreverence to carry off the feeling that she's a step ahead of everyone else. Underneath the bones of a delightful plot is a character who cares deeply but is very aware of her limitations, and therefore has taught herself to laugh at and be ruthless with her own emotions. I am finding it an incredibly compelling type of competence porn.
I enjoyed the first book of this series, but this one was so much better. These stories are exactly the right length to keep the reader engrossed throughout and satisfied but wanting more at the end. How to Steal a Galaxy ends on a cliffhanger of sorts, to be resolved in the next and final book. I can hardly wait to start it.
Highly recommended.
Followed by Last Chance to Save the World.
Rating: 9 out of 10
New Cover Song: “Ode to Somewhere” [Whatever]

This cover song has an interesting story to it, which is that it’s a song from a video game called “Deathloop.” In the video game, the singer is supposed to have been a huge star but has lately gone kind of venal around the edges, and also there’s a whole time loop thing going on which necessitates the player character needing to kill the singer (and several other people) for, you know, reasons. It all makes sense in the context of the game, and the game itself is a hell of a lot of fun. I absolutely recommend it.
The in-game singer may be a jerk, but this song (written and performed by Erich Tabla with Jeff Cummings on vocals) is really good, and in fact was one of my favorite songs of its year, with a real 60s torch-song feel to it. My version is a little more electronic-y and revved up on the drums, because apparently I do that. Nevertheless I think it’s not bad, and I hope you like it.
Also, since it’s possible you may not have ever heard this song unless you played the game, if you’re curious as to how the original sounds, here it is:
— JS
Develop cross-platform CLI and GUI tools with Tcl/Tk [OSnews]
Tcl, or the “Tool Command Language“, created and released by John Ousterhout in 1990, deserves a place among the greatest products of the human mind. Especially when combined with its better known graphical user interface Toolkit — Tk. In 1997 Ousterhout was awarded the ACM Software System Award for Tcl/Tk, an award given to institutions or individuals recognized for developing software systems with a lasting influence, reflected in contributions to concepts, in commercial acceptance, or both.
↫ Armen Barsegyan
Everything you could ever possibly want to know about Tcl/Tk. There’s nothing to add here; if this is up your alley – and you know if it is – just go ahead and read it, and stop wasting time here.
Friday Squid Blogging: Squid Helps Discover New Marine Species [Schneier on Security]
The Squid is a new scientific machine:
One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging material and building skeletons. And we could do that live on the ship, when usually it takes a couple of weeks of staining and mounting to see anything,” Osborn said.
The expedition discovered thirty-one new marine species in two weeks. The article doesn’t say if any of them were new species of squid.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
The hardest thing for people to get about open systems is that if you move forward, not only do you benefit, but your competitors benefit equally. When one of them takes but doesn't give back, that's even worse. But you do it anyway because otherwise eventually, without interop, no one can move.
Amending AB 1709 Doesn’t Fix It: California’s Social Media Ban Still Threatens Free Speech and Privacy [Deeplinks]
California lawmakers have amended A.B. 1709, but the core problem remains: the bill is still a ban on social media access for youth under 16, and it still threatens the privacy and First Amendment rights of all Californians.
Proponents of the bill may argue that the recent amendments represent a compromise, but a close look at the text shows no major changes. As the bill moves forward in the Senate, we must continue to urge lawmakers to vote NO.
Take Action: Tell Your Senator to OPPOSE A.B. 1709
Under the newly amended Section 22683, platforms are prohibited from offering "addictive features" to users under 16. A platform can allow a minor to keep an account only if it strips away these features, which include what the bill calls "addictive feeds," auto-play, and anything else the Attorney General designates in future rulemaking.
However, the bill defines "addictive feeds" so broadly that it covers virtually every functional recommendation algorithm. The bill applies this label to any presentation of user-generated content recommended "in whole or in part, on information provided by the user." That includes basic inputs like who a user follows, what posts they like, or their self-expressed interests. By calling these basic tools and features “addictive," the bill also makes broad conclusions about the unsettled science behind social media use, youth, and addiction.
Because almost every major social media service uses automated feeds to deliver content, the end result of AB 1709 remains the same: young people under 16 will be denied access to major social media services as they currently exist.
Even if a platform attempts to comply by stripping away recommendation systems for minors, this still violates the First Amendment. Recommendation systems are the primary tools that users rely on to find speech and disseminate their own. Forcing young people onto a stripped-down, dysfunctional version of social media burdens their constitutional right to access information and participate in public discourse.
The amendments do not eliminate the privacy threats posed by age gating. Although the bill references the age-signaling framework in AB 1043, Section 22684 explicitly states that a covered platform "shall verify the age of a user” and makes platforms liable every time a person under 16 makes it through an age check.
Because AB 1043 does not actually specify how verification should occur without requiring additional proof, AB 1709 will, in practice, force platforms to implement the strictest forms of age verification. To comply, platforms will likely require users to upload government-issued IDs or submit to biometric scanning. Forcing users to turn over their personal information will create massive honeypots of sensitive personal data, destroying online anonymity and exposing users of all ages to security breaches. And relying on biometric systems to verify users’ ages is problematic because the systems have historically had high error rates estimating ages across race and gender lines.
Take Action: Tell Your Senator to OPPOSE A.B. 1709
The amendments to AB 1709 also introduce legal confusion, creating provisions that conflict with already enacted legislation like SB 976. Rather than providing clarity or protecting young people, AB 1709 creates a tangled regulatory scheme that sacrifices constitutional rights for political grandstanding.
Denying minors access to digital forums—or stripping those forums of the basic tools needed to navigate them—is censorship. California should not set a national precedent of cutting young people off from digital lifelines, communities, and speech.
We need to keep the pressure on as AB 1709 moves through the Senate. Contact your state senator today and tell them that minor tweaks to a bad bill do not make it good policy.
The SCREEN Act Threatens Privacy Far Beyond Adult Websites [Deeplinks]
Update: On August 5, 2026, The Senate Commerce Committee voted 15-13 to advance this bill, but the bill did not advance because of a lack of Senators in attendance. EFF continues to oppose the bill.
The Senate Commerce Committee is set to consider S. 737, the SCREEN Act, a sweeping age-verification bill that would require online services to verify users’ ages before they can access any sexually explicit content. If this bill passes, it will force millions of adult internet users to give up their anonymity, privacy, and security before they access lawful speech.
protect your right to browse the web privately
Unlike many state-age verification laws—which have been harmful in their own right—the SCREEN Act has no requirement that a significant portion of the website consist of sexually explicit content that is harmful to minors. The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users. The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content.
The SCREEN Act does not merely require users to attest they are adults. It specifically states that “requiring a user to confirm that the user is not a minor shall not be sufficient.” In practice, that means platforms would have to verify users’ ages using methods tied to their real identities. Providing proof of age online is dramatically different, and far more invasive, than showing your ID at the door to a bartender or bouncer. In the physical world, the bouncer at the door looks at your ID card, confirms you’re old enough, and gives it back to you. Under the SCREEN Act, the “bouncer” will be a digital age-verification service that captures your personal information and saves it to a database for an unspecified amount of time.
The consequences of the bill won’t be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults.
Even worse, the SCREEN Act is a privacy and data security nightmare. One provision of the bill requires services to take reasonable steps to protect the data collected and to not maintain for longer than is necessary. But these are terribly weak protections that impose no meaningful collection, use, or retention limits on services collecting people’s private information.
In other words, the third parties tasked with verifying a user’s age on a platform could sweep up a lot of personal info they don’t actually need and then could use that information for any number of purposes, so long as they deem their actions reasonable. Companies would then be allowed to keep the information users have been compelled to turn over for as long as possible, raising security and privacy issues along the way.
The SCREEN Act also targets virtual private network (VPN) users and providers. The bill requires covered websites to verify users' ages based on their IP addresses unless the service can determine that the user is outside the United States, and specifically requires age verification on traffic coming from known VPN addresses. In practice, this discourages the use of VPNs and proxy servers, which millions of people rely on for legitimate purposes such as protecting personal privacy, securing public Wi-Fi connections, safeguarding journalists and activists, and preventing data tracking.
VPNs mask your real location by routing your internet traffic through a server somewhere else. When you visit a website through a VPN, that website only sees the VPN server's IP address, not your actual location. It's like sending a letter through a P.O. box so the recipient doesn't know where you really live. VPNs are a privacy and security tool used by millions of internet users every day, and their use should not be treated as suspect. It is particularly galling that the SCREEN Act forces users who intentionally take steps to protect their privacy to identify themselves.
The SCREEN Act creates onerous age-verification rules that will block adults from accessing lawful speech, curtail their ability to be anonymous, and jeopardize the data security and privacy of all internet users.
Tell Congress to oppose the screen act
Jimothy Chalamet [Penny Arcade]
Raccoons in my neighborhood, save one, are not spherical. They are big though, off that Seattle trash. They're fat as fuck off Brie rinds and jamón ibérico trimmings. Some of these bad boys can deliver near-cryptid thrills. When I was driving home one night, I saw one that didn't even read as a raccoon visually - my mind told me that it was most likely a toddler that had escaped from some kind of toddler… prison. That's what it gave me! Not helpful.
The CHATBOT Act Forces One Parenting Model On Every Family [Deeplinks]
Update: The Senate Commerce Committee voted to advance this bill on August 5, 2026. EFF continues to oppose the bill, which still needs approval from the full Senate.
Artificial intelligence is rapidly changing education, and the way people search for information. Parents, teenagers, teachers, and schools are struggling with tough questions about when AI should, and should not, be used. It makes sense for Congress to hold hearings and examine how AI should be used by minors. But the recently introduced CHATBOT Act answers those questions with a one-size-fits-all mandate governing how teenagers access AI through federally prescribed parental monitoring systems.
Tell Congress not to age-gate the internet
Parents are approaching AI in different ways. Some closely supervise how their children use chatbots, while others might set more general rules about technology. Many families are still figuring out what role AI should play in schoolwork and everyday life.
The CHATBOT Act would take that decision away from families and AI providers. Instead of letting families and AI providers decide what parental controls should look like, Congress would require every covered AI chatbot to build the same federally prescribed “family account” system.
As part of the required parental-consent process for teens, AI companies must offer parents a "family account" that provides access to a "full record of the conversations and activity" of teen users and tools to "monitor, analyze, and understand, at scale" those conversations. They must also send alerts if a teen attempts to bypass or disable parental controls.
This isn’t simply an optional parental-control feature. The bill requires every covered AI provider to build this monitoring infrastructure, and present it as part of the parental consent process. Congress is prescribing a single, highly invasive model of how families should supervise teenagers’ use of AI.
Parents and families have different ideas about how much independence teenagers should have. Understandably, they also have very different expectations for 8-year olds, 13-year-olds, and 17-year-olds. The CHATBOT Act effectively requires AI providers to build the same monitoring architecture for users of very different ages.
And this mandated data collection will create new privacy and security risks. Once Congress requires AI companies to create a permanent, centralized record of teen AI conversations for parental review, that will be a valuable vault of extremely personal information. That raises serious questions about what would happen in cases where someone else gains access to it through account compromise, family disputes, or other security failures.
The vast archives of conversations created by the government-mandated family accounts won't be interesting only to parents. They will become valuable targets for hackers, identity thieves, civil litigants, and anyone else seeking access to the deeply personal information of others. The CHATBOT Act requires the records to exist, but addresses none of those risks.
Families are still figuring out what role AI should play in schoolwork and everyday life. Congress shouldn’t freeze one answer into federal law by requiring every AI company to build the same prescribed monitoring system.
Tell Congress to oppose the chatbot act
The CHATBOT Act takes the basic structure of COPPA, a nearly 30-year-old law that applies to children aged 12 and under, and applies the same “verifiable parental consent” to older teenagers.
That’s a dramatic expansion of the law. Congress enacted COPPA to prevent kids from handing over detailed personal information to online services without making sure parents approved. For nearly three decades, Congress has required parental consent before websites collect personal information from any user under 13. COPPA is not simple to comply with, which is why so many internet companies, large and small, simply bar kids under 13 from having accounts. That includes major social media sites and AI. Facebook, Instagram, TikTok, X, YouTube, Snapchat, Discord, Spotify, and blogging platforms like WordPress all keep out users under 13. Children under 13 are also not allowed to use Microsoft Co-Pilot, Google Gemini, or ChatGPT. Anthropic does not allow users under 18 to use its AI model, Claude. In cases where younger kids maintain social media accounts despite the rules, studies show the vast majority of them are creating those accounts with parental consent.
In short, COPPA’s protections against collecting personal information from minors without parental consent already apply to the AI services CHATBOT Act seeks to regulate. Worse, the CHATBOT Act takes COPPA’s privacy protections and inverts them—it will result in AI services likely collecting more information about young users.
But the CHATBOT Act extends that model to high school students using AI assistants that are rapidly becoming tools for learning, research, writing, coding, and creative work. It then mandates specific, invasive surveillance tools that go well beyond anything COPPA requires.
The bill requires providers to offer these “family accounts,” with these specific features, as a default for teenagers. By doing so, CHATBOT effectively treats a high school senior the same way it treats an elementary school student.
Supporters may argue that parents of teens don’t have to create a family account. But every family with a teenager will still have to go through the bill’s parental-consent process before a teenager can use a covered AI system. Providers will need practical ways to verify that an adult is, in fact, the teenager’s parent. And parents of kids under 13 have no option to consent to their kids’ use of an AI system—the bill’s only option is to create a family account.
Congress should not extend the COPPA parental-permission model to millions of older teenagers, and it would be harmful to do so. The government does not require COPPA-style parental permission before a 17-year-old checks out a library book, uses Wikipedia, types search terms into Google, or reads a newspaper online. It shouldn’t require parental permission simply because the same question gets asked of an AI assistant.
The bill says it doesn’t require age verification. But like many recent “kids online safety” bills, it imposes obligations that depend on a company knowing whether a user is under 18.
Specifically, the bill requires AI systems to either disable access to young kids, get parental consent, or the creation of a family account if a service has reason to believe a user is a minor. The standard means that services don’t need to have actual knowledge of a user’s age to be later held liable for improperly letting them use their AI tools. That creates a practical problem. Given the potential liability of getting something wrong, AI companies will likely require stricter forms of age verification to figure out who is under 13, a teenager, and who is a parent. Some providers might ask for government-issued identification. Other companies may rely on age estimation systems that use facial scans or other signals to guess a user’s age. Neither of these approaches is good for users’ privacy or security. One collects more information than is necessary, and the other inevitably makes mistakes.
Congress shouldn’t force companies into that choice, or families into this position. In the name of protecting children, the CHATBOT Act will result in online services collecting even more information from kids and families, creating privacy and security risks. Parents who want family accounts like those described in the bill should be free to choose AI services that offer them. But Congress shouldn’t pressure every provider to collect more information about everyone’s age simply to comply with the law.
Congress doesn't have to choose between doing nothing and creating a sweeping new federal parental-monitoring mandate. Existing law allows regulators to police deceptive AI products, protect children's privacy under COPPA, and hold companies accountable when they market unsafe or misleading products to families.
Lawmakers have urged the FTC to crack down on AI-enabled toys that make unsubstantiated educational claims or illegally collect children's data. Those are regulatory actions that can be taken right now.
Finally, the FTC is currently investigating how AI companies test their products, protect children and teens, comply with COPPA, and enforce age restrictions. The results of that inquiry could be useful guidance to Congress, and to the public debate around these issues.
Cracking down on bad actors, while learning more about how families are already making decisions about AI use, is a much better path forward than building one, federally-prescribed model of parenting or product design.
stop this bill
AI as an Enterprise Operating System [Radar]
I hadn’t heard of Dan Guido until a few months ago, when I came across the video of a talk he gave at [un]prompted, an AI security practitioners’ conference. Dan is the CEO and cofounder of Trail of Bits, a software security research and development firm that works with companies in tech, defense, and finance. But Dan wasn’t talking about security. He was talking about what it takes to make a company AI native, which is close to the center of the bullseye for many of us right now.
We’ve been trying to figure out how to do that at O’Reilly, but until I came across Dan’s talk, we didn’t have a structured process. We’ve been building along the lines he laid out ever since. So for this episode of Live with Tim I asked Dan to reprise the talk before we got to the conversation. He was supposed to take twenty minutes, like his original conference talk, but he took thirty-five, and I had to cut him off slightly before the end to make room for questions. That was a tough choice, since everything he had to say was golden.
Dan opened by reminding us of the current state of play in enterprise AI adoption. In February, Fortune reported on a National Bureau of Economic Research study in which nearly 90% of some 6,000 executives said AI had produced no measurable change in employment or productivity at their firms over three years. People started calling it the new Solow paradox, after Robert Solow’s 1987 line that “you can see the computer age everywhere except in the productivity statistics.”
Dan’s belief is that this isn’t evidence that AI doesn’t work. It’s evidence that most companies are deploying AI wrong. They hand out ChatGPT and Claude licenses, and then leadership waits for the magic to happen. It doesn’t.
Dan started out by describing three levels of AI adoption.
In his framing, the first of the three is a tool and the last is an operating system. For Trail of Bits, he said that “operating system” has a specific purpose:
“I want our security expertise to compound as code. Every engagement we do, all the skills, the workflows, everything that we build makes the next engagement faster and better.”
Dan confessed how hard it was to get started on the ladder from AI Assisted to AI Native:
“When I announced last year that we were all in on AI, that we were going to be using it across all of our workflows and redesigning the way the company operates, I’d say only about 5% of the company was with me. 95% was resistant.” About 20% was actively resisting. The other 75% were resisting more passively. “They’ll go along with it in public, but in process they’ll sabotage it. They’ll hope that if they keep their head low, this will pass over them, and that three months from now management’s focus will change and it won’t be a problem anymore, and we can get back to doing what we were doing. That’s where the majority of people land when these initiatives happen.”
Rather than argue with his employees, Dan studied the literature on why people reject new technology and decided he needed to address four biases against AI: self-enhancing bias, identity threat, opacity, and intolerance for imperfection.
Self-enhancing bias is the habit of crediting your wins to your own judgment and your losses to circumstance, which is a particular problem for senior people who are strongly attached to the years of experience and intuition that got them to their present position. Opacity is not being able to see how a decision got made. Dan’s observation is that you don’t understand your doctor’s reasoning either, but somehow you trust the doctor but get suspicious of the machine. Dan didn’t mention this work specifically, but intolerance for imperfection seems to refer to Dietvorst, Simmons, and Massey’s work on algorithm aversion, which found that people abandon an algorithm after watching it err once, even when it outperforms the human alternative. Their follow-up paper found that giving people even a slight ability to modify the algorithm’s output is enough to overcome the aversion.
Dan spent the most time on identity threat. He described a study in which the same kitchen appliance was advertised in two ways: “On one hand, it does the cooking for you. On the other hand, it helps you cook better. It’s the same device. The people who identified as cooks rejected the first version and accepted the second.”
Most knowledge work, Dan argued, and security auditing in particular, is what he called symbolic rather than instrumental. That is, it carries meaning about who you are. “So I have to frame AI as something that makes you a more dangerous auditor,” he said. “Not that it does the audit for you.”
In his work at Trail of Bits, he deliberately built a countermeasure for each bias.
Here’s Dan’s slide on “the remedies that actually worked”:
Returning to one of my hobby horses, this is a kind of mechanism design. In my recent piece on the missing mechanisms of the agentic economy, I argued that we need to start with desired outcomes and ask ourselves what mechanisms will help to produce them. Dan’s approach seems to be really good at this. Most enterprises are treating AI adoption as a procurement problem or a communications problem. Dan treated it as a question of what incentives, defaults, and status ladders produce the behavior you want, given how people actually respond.
The last remedy on Dan’s list is that the CEO has to lead by example. He noted, “I was the first person through the door. My voice as the CEO matters a lot more than people think. The passive 50% of the company that isn’t sure if this initiative is going to be successful, they’re watching to see what leadership actually does, not what it says.”
Trail of Bits already tracked about 50 engineering skills for performance review, things like Python, git, Rust, and various security auditing capabilities. Dan pulled AI skills out into their own matrix, with four levels, from not engaged through capable and adoptive to transformative. Each of these levels is detailed separately and more specifically for assurance, engineering, sales, and project management.
He noted that “The highest level of the maturity matrix is not somebody who uses AI the most. It’s somebody who invents new ways to work and builds tools with AI. So the identity of the expert shifts from ‘I don’t need AI’ to ‘I’m the one who makes AI useful for the company.’” This was his first important design choice.
The second is what level zero means. He said “If you’re at level zero, if you’re not engaged, that means you’re fighting back against the company. If you dismiss AI as hype, if you refuse to use AI for security work, this is a disagreement on principles, not on skills. For people who were stuck in the not engaged category, we had hard conversations, and there were people who left the company.” Levels one through three are a skill issue, and the remedy is time with the tools.
While the slide describing the capability matrix is shown in the preceding video clip, here’s where you can find the full deck so you can study it in more detail.
One of the best ways Trail of Bits developed to move people up the ladder was to hold a hackathon every two months. Dan runs them with clear goals rather than as a free-for-all. The focus area and learning objectives are defined in advance and announced a week ahead, with separate instructions for engineers and non-engineers. People work in pairs so everything gets reviewed. There’s a demo session at the end, and then follow-through. (It’s an important part of Dan’s big idea, that you have to build a system by which, in his words, organizational knowledge and capability compounds.) He noted that “In the days afterward we keep one or two people around, and they collect all the reusable artifacts, structure them, and put them into the places they need to be.”
I asked what people outside of product and engineering actually work on, since the answer for an accountant at a hackathon was not obvious. Dan’s response is that the hackathon isn’t measured in artifacts shipped but in where people sit on the capability ladder the following week. Essentially, he’s running a training program that happens to produce useful output, rather than a production sprint that happens to teach people something.
The first hackathon, he told me, was the equivalent of a beach cleanup: “It’s like those companies that send everybody to the beach with a big stick and say, let’s go pick up a bunch of trash and put it away, and then you get the big team photo after with all the contractor bags of garbage. That’s what we did with our public source code repositories.”
He picked it because open source maintenance is the part of the job that feels like a grind. No new features, just closing issues and stale dependencies on public code where nothing was at risk. “As an open source maintainer, you just get beaten down by the public. This doesn’t work, I can’t use it, this thing sucks. Dozens of issues pointing out flaws you already knew about. It feels burdensome. We wanted people to see that adopting AI would relieve burden.”
The second hackathon was about shipping impactful product updates, but it was also designed to move everyone up the capability ladder by giving up control. Engineers had to run Claude Code in bypass permissions mode, fully autonomous, on public repositories, inside sandboxes the company had prepared in advance. The one they’re running now is about persistent background agents that can be handed a task during an audit and come back with a proof of concept exploit or a draft finding.
Here’s a look at Dan’s slack message announcing the hackathon:
The slack message announcing the second hackathon.
(From Dan’s slide deck.)
Everything the hackathons produce gets harvested into artifacts.
Trail of Bits runs three skills repositories: an internal one for company workflows, a public one that anyone can use, and a curated one that vets third-party skills before they’re allowed in.
Publishing skills to the public repository is not just a marketing exercise. “It keeps us honest, and it forces us to write things that other people can use, not just people outside the company but inside too,” Dan said. “It really helps us think about the tribal knowledge that’s baked into the tool.”
The curated repository exists because Trail of Bits knows how bad the supply chain is. They’ve published research on how to write malicious skills, and so Dan is not going to tell 130 employees to start downloading code from strangers and running it on their laptops. “If you want adoption, you need a safe supply chain.”
Perhaps even more important than the skills repository is, as Dan put it, “turning scar tissue into infrastructure.”
“Every single time Claude Code didn’t do something we wanted, we would bake it into a set of global, copy-pasteable defaults. Known good settings, recommended patterns. I call it scar tissue. If I hire somebody new tomorrow, I don’t want them to have to go through the entire discovery process of the last year of Trail of Bits to figure out how to use the tool.”
The configuration repository, claude-code-config, is where the accumulated lessons live.
Dan built the first version himself and then opened it to pull requests from the whole company, assigning someone after each hackathon to go collect what people hadn’t contributed on their own. “It’s easier to put out something that’s unpolished than it is to get it perfect on the first try.”
In short, a big part of the Trail of Bits “enterprise AI operating system” approach is a set of standardized tools and hardened defaults. Standardization isn’t a straitjacket. It’s a foundation.
On sandboxing, Trail of Bits deliberately didn’t pick a single preferred solution. There’s a devcontainer for developers, dropkit for disposable DigitalOcean droplets, COOP for isolated VMs, and the sandboxing now built into Claude Code for casual users. “The point isn’t that everybody uses the same sandbox,” Dan said. “The point is that everyone has a safe sandbox to use, and that it’s easy for them to do it.”
Another of the hardened defaults is procedural. Trail of Bits enforces a seven day cooldown on every package their developers install:
“There are dozens of security companies scanning the internet trying to find a new cool blog post they can write about malicious code hiding on PyPI or npm, and they usually figure out there’s a supply chain issue within hours. So we just delay all the packages that Trail of Bits uses. Generally the malicious stuff gets picked up before we ever get a chance to run it.”
That’s free-riding on a competitive market for security research, and given the speed of today’s market, it’s an elegant solution. There’s a whole class of defenses like this waiting to be found, where the mechanism is not a technical system but a well-chosen delay.
The problem we run into most often as we build AI workflows at O’Reilly isn’t the model or the tooling. It’s data. Who has access to which system, which system does that data live in, and who do I ask? In a 500 person company that’s annoying. I wonder what it’s like at a company with 50,000 employees.
I told Dan about DJ Patil’s Tidy House framing. He agreed that data access for AI is a big problem. His answer starts with permissions:
“The permissions debt is invisible until an agent hits it. Making data agent legible is a forced permission audit. You have to actually go through and figure out who can access what…. It also raises the stakes for permissions errors. If you overshare information, now an agent inside your company is going to find it instantly. There are a lot of these technical debt sort of things where, with agents, all of it’s becoming due at the same time.”
Every shortcut an organization took with its data over the past twenty years is being called at once, and the companies that can run the audit, make fast decisions about boundaries, and then actually share their data are the ones that will get a force multiplier.
Dan is against letting a thousand flowers bloom, because uncoordinated teams create overlap rather than compounding. He’d rather have one centralized foundation, with innovation happening on top of that. He suggested a useful metric for making that work across team boundaries is what fraction of your team’s data did you make reusable for everyone else, and how much of it is being used by teams outside your own.
Before the first hackathon, Trail of Bits ran hands-on sessions to teach its operations and go-to-market staff the basics of git and the command line. Not mastery, just enough to be a consumer of the thing. Here we are fifty years into my career and the Unix command line still matters. Dan’s non-technical staff mostly work inside Claude Cowork or Codex Desktop now, but he thinks the command line experience was worth it because they know what’s happening under the hood.
What happens to a job when the tool can do a lot of what humans used to do? Dan gave the example of his own technical editors. His editors used the hackathons to build the tools that got them out of line editing, including one that turns a public presentation into a blog post in the company’s voice. What the writers do now is consult on how to frame a story so it is effective with a particular audience.
I agree. Human jobs aren’t going away any time soon. This gets heard as optimism when it’s really just observation. AI is going to replace a lot of what we used to do, but it is also going to hand us a large amount of new work, and much of that work hasn’t been understood yet. Quality assurance for agent systems is one of the new jobs. So is skills product management, which is a role that didn’t exist eighteen months ago and now has a headcount at a 130 person security firm.
I asked a question towards the end about how we’re going to know which skills and agents are any good. What Dan has so far is telemetry pulled from developers’ dot files through the company’s device management system, which tells him what gets used and what breaks, plus one AI systems engineer whose job is product management for the skills repository, reviewing incoming pull requests and deprecating overlapping skills.
What Dan thinks comes next is evaluation. He says: “Once you invest a lot into these agent systems, you need proof that they do the job. The way you do that is you give everybody a performance review. You give them an evaluation data set, a benchmark.”
Trail of Bits is now building benchmarks for its core skills. How well can we find bugs in this language? How well can we write a statement of work? Constructing those datasets is real work, with positive and negative cases, and comparisons against the algorithmic tools that already exist.
I asked Dan for the top five mistakes he made. He said there was only one. “You need to allocate an appropriate amount of FAFO time. (That’s F Around and Find Out.) A product comes out on Friday. There’s no documentation for it. There’s no training guidance for it. There’s no course on it. You can’t wait until somebody systematizes the knowledge. You just need to do it.”
Then he gave an analogy to going to the gym.
Dan has a replicable recipe, which he summarized as follows:
The Trail of Bits skills repository is public. So is the curated marketplace, the configuration repository, the devcontainer, dropkit, and COOP (Continuity of Operations planning). He wrote up the whole playbook on The Trail of Bits Blog and gave a version of it to tl;dr sec. He thinks publishing makes the work better because it forces the tribal knowledge out into the open where it can be checked.
Which brings me back to the Solow paradox, which seemed to disappear by the late 90s, when US aggregate productivity did finally go up. That didn’t happen because computers got faster. It disappeared because companies figured out how to reorganize themselves around what computers could do, and eventually those organizational recipes spread widely enough to show up in aggregate statistics. The same has to happen today. The current AI discourse is obsessed with model capability and largely uninterested in diffusion. The problem is not that the models are oversold. It’s that almost nobody has done the necessary organizational work, and the few who have are mostly keeping it to themselves.
If you want to go beyond the highlight videos shown above, watch Dan’s entire talk here. His slide deck is here. And be sure to check out the Trail of Bits Github repository.
Servo 0.4.0 released [LWN.net]
The Servo web-browser engine project has published an update about all of the changes that landed in June 2026, along with version 0.4.0 of the Servo Tech Demo. This release includes a record 558 commits, better layout correctness for web sites, improved WebGPU support, enhancements for users who are using the servoshell test browser, and many performance and stability fixes.
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection [Schneier on Security]
The chart is interesting.
On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Claude model was Muse Spark at 16.5% within 15 attempts—more than eight times Opus 5’s rate. The most capable GPT 5.6 variant, Sol, was comparable to its predecessor GPT 5.5 (20.0% versus 20.8% within 15 attempts), and was 10 times as likely to be successfully attacked as Claude Opus 5 at 2.0%. The other GPT 5.6 variants are less robust, at 30.4% (Terra) and 43.9% (Luna). A single attempt against GPT 5.6 Sol succeeded 3.1% of the time, higher than the 2.0% an attacker achieved against Opus 5 after fifteen attempts.
We know that preventing prompt injection is impossible in the general case. But we are getting much better at blocking it in specific cases.
Error'd: I Believe In Lingonberries [The Daily WTF]
I've never been a huge fan of their furniture but I will happily demolish a plate of meatballs.
Jan agrees "My loyalty to this Swedish megastore is immeasurable."
"Choosing Concert Seats is Surprisingly Hard" for jeffphi who explains "While I have mixed feelings about indulging in nostalgia tours, I was curious to see seating options for this Rick Springfield concert. Turns out I *still* have questions!"
"Would you like to undo this unspecified problem?" richard H. rants "This came out of nowhere while composing an email. (I think I had just hit 'enter' to move to the next line.) Does anyone at Microsoft read these error dialogs before they ship it? Anyone? Is anyone at Microsoft forced to endure their own software?"
An anonymous fan of extinct charismatic megafauna complains "This is %{insult}"
Finally, and most seriously, merely pseudonymous WeaponizedFun has just highlighted for us that a true secret is something only one person knows. "Apparently, when OnSolve says "PROTECT YOUR USERNAME - NEVER give your username to anyone," this includes them not telling me what it is." See, if they told you, it wouldn't be a secret anymore.
Clint Adams: N.K. Jemisin is doing a worldbuilding workshop at the Bronx Library Center tomorrow afternoon [Planet Debian]

Normally, I do not read book reviews. Either I haven't read the book, in which case there's spoiler potential, or I have, in which case it's unlikely to be useful or enjoyable for me to read a thing about a thing I've already read.
But Review: Radiant Star caught my eye, and I thought, “Hmm, I've read all those books” and was curious. Of course, because I am old and senile and have no understanding of time, the “May 2026” staring at me was not able to trigger the neural synapses that would remind me that I haven't read any Ann Leckie since 2023.
However, as I read Russ's review, and began to wonder what the hell he was talking about, I was able to piece together that while I have, in fact, read 6 Ann Leckie books, none of them have been Radiant Star.
This presented an opportunity, so I resolved to add Radiant Star to my todo list. To my surprise, it was already there.
| Feed | RSS | Last fetched | Next fetched after |
|---|---|---|---|
| @ASmartBear | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| a bag of four grapes | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| Ansible | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| Bad Science | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| Black Doggerel | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| Blog - Official site of Stephen Fry | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| Charlie Brooker | The Guardian | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| Charlie's Diary | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| Chasing the Sunset - Comics Only | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| Coding Horror | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| Comics Archive - Spinnyverse | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| Cory Doctorow's craphound.com | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| Cory Doctorow, Author at Boing Boing | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| Ctrl+Alt+Del Comic | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| Cyberunions | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| David Mitchell | The Guardian | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| Deeplinks | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| Diesel Sweeties webcomic by rstevens | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| Dilbert | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| Dork Tower | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| Economics from the Top Down | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| Edmund Finney's Quest to Find the Meaning of Life | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| EFF Action Center | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| Enspiral Tales - Medium | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| Events | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| Falkvinge on Liberty | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| Flipside | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| Flipside | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| Free software jobs | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| Full Frontal Nerdity by Aaron Williams | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| General Protection Fault: Comic Updates | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| George Monbiot | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| Girl Genius | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| Groklaw | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| Grrl Power | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| Hackney Anarchist Group | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| Hackney Solidarity Network | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| http://blog.llvm.org/feeds/posts/default | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| http://calendar.google.com/calendar/feeds/q7s5o02sj8hcam52hutbcofoo4%40group.calendar.google.com/public/basic | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| http://dynamic.boingboing.net/cgi-bin/mt/mt-cp.cgi?__mode=feed&_type=posts&blog_id=1&id=1 | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| http://eng.anarchoblogs.org/feed/atom/ | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| http://feed43.com/3874015735218037.xml | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| http://flatearthnews.net/flatearthnews.net/blogfeed | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| http://fulltextrssfeed.com/ | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| http://london.indymedia.org/articles.rss | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| http://pipes.yahoo.com/pipes/pipe.run?_id=ad0530218c055aa302f7e0e84d5d6515&_render=rss | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| http://planet.gridpp.ac.uk/atom.xml | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| http://shirky.com/weblog/feed/atom/ | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| http://thecommune.co.uk/feed/ | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| http://theness.com/roguesgallery/feed/ | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| http://www.airshipentertainment.com/buck/buckcomic/buck.rss | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| http://www.airshipentertainment.com/growf/growfcomic/growf.rss | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| http://www.airshipentertainment.com/myth/mythcomic/myth.rss | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| http://www.baen.com/baenebooks | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| http://www.feedsapi.com/makefulltextfeed.php?url=http%3A%2F%2Fwww.somethingpositive.net%2Fsp.xml&what=auto&key=&max=7&links=preserve&exc=&privacy=I+accept | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| http://www.godhatesastronauts.com/feed/ | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| http://www.tinycat.co.uk/feed/ | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| https://anarchism.pageabode.com/blogs/anarcho/feed/ | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| https://broodhollow.krisstraub.comfeed/ | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| https://debian-administration.org/atom.xml | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| https://elitetheatre.org/ | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| https://feeds.feedburner.com/Starslip | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| https://feeds2.feedburner.com/GeekEtiquette?format=xml | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| https://hackbloc.org/rss.xml | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| https://kajafoglio.livejournal.com/data/atom/ | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| https://philfoglio.livejournal.com/data/atom/ | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| https://pixietrixcomix.com/eerie-cutiescomic.rss | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| https://pixietrixcomix.com/menage-a-3/comic.rss | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| https://propertyistheft.wordpress.com/feed/ | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| https://requiem.seraph-inn.com/updates.rss | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| https://studiofoglio.livejournal.com/data/atom/ | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| https://thecommandline.net/feed/ | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| https://torrentfreak.com/subscriptions/ | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| https://web.randi.org/?format=feed&type=rss | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| https://www.dcscience.net/feed/medium.co | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| https://www.DropCatch.com/domain/steampunkmagazine.com | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| https://www.DropCatch.com/domain/ubuntuweblogs.org | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| https://www.DropCatch.com/redirect/?domain=DyingAlone.net | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| https://www.freedompress.org.uk:443/news/feed/ | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| https://www.goblinscomic.com/category/comics/feed/ | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| https://www.loomio.com/blog/feed/ | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| https://www.newstatesman.com/feeds/blogs/laurie-penny.rss | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| https://www.patreon.com/graveyardgreg/posts/comic.rss | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| https://www.rightmove.co.uk/rss/property-for-sale/find.html?locationIdentifier=REGION^876&maxPrice=240000&minBedrooms=2&displayPropertyType=houses&oldDisplayPropertyType=houses&primaryDisplayPropertyType=houses&oldPrimaryDisplayPropertyType=houses&numberOfPropertiesPerPage=24 | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| https://x.com/statuses/user_timeline/22724360.rss | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| Humble Bundle Blog | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| I, Cringely | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| Irregular Webcomic! | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| Joel on Software | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| Judith Proctor's Journal | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| Krebs on Security | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| Lambda the Ultimate - Programming Languages Weblog | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| Looking For Group | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| LWN.net | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| Mimi and Eunice | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| Neil Gaiman's Journal | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| Nina Paley | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| O Abnormal – Scifi/Fantasy Artist | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| Oglaf! -- Comics. Often dirty. | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| Oh Joy Sex Toy | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| Order of the Stick | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| Original Fiction Archives - Reactor | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| OSnews | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| Paul Graham: Unofficial RSS Feed | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| Penny Arcade | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| Penny Red | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| PHD Comics | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| Phil's blog | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| Planet Debian | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| Planet GNU | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| Planet Lisp | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| Pluralistic: Daily links from Cory Doctorow | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| PS238 by Aaron Williams | XML | 20:35, Wednesday, 05 August | 21:23, Wednesday, 05 August |
| QC RSS v2 | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| Radar | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| RevK®'s ramblings | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| Richard Stallman's Political Notes | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| Scenes From A Multiverse | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| Schneier on Security | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| SCHNEWS.ORG.UK | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| Scripting News | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| Seth's Blog | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| Skin Horse | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| Tales From the Riverbank | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| The Adventures of Dr. McNinja | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| The Bumpycat sat on the mat | XML | 21:14, Wednesday, 05 August | 21:54, Wednesday, 05 August |
| The Daily WTF | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| The Monochrome Mob | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| The Non-Adventures of Wonderella | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| The Old New Thing | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| The Open Source Grid Engine Blog | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| The Stranger | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| towerhamletsalarm | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| Twokinds | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| UK Indymedia Features | XML | 20:42, Wednesday, 05 August | 21:24, Wednesday, 05 August |
| Uploads from ne11y | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| Uploads from piasladic | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |
| Use Sword on Monster | XML | 20:28, Wednesday, 05 August | 21:15, Wednesday, 05 August |
| Wayward Sons: Legends - Sci-Fi Full Page Webcomic - Updates Daily | XML | 21:14, Wednesday, 05 August | 22:00, Wednesday, 05 August |
| what if? | XML | 20:35, Wednesday, 05 August | 21:16, Wednesday, 05 August |
| Whatever | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| Whitechapel Anarchist Group | XML | 21:07, Wednesday, 05 August | 21:56, Wednesday, 05 August |
| WIL WHEATON dot NET | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| wish | XML | 20:49, Wednesday, 05 August | 21:34, Wednesday, 05 August |
| Writing the Bright Fantastic | XML | 20:49, Wednesday, 05 August | 21:33, Wednesday, 05 August |
| xkcd.com | XML | 21:07, Wednesday, 05 August | 21:50, Wednesday, 05 August |