The magic of a two-year waitlist [Seth's Blog]
The Decware triode amp is the best low-power stereo amp I’ve ever heard. And it’s a bargain. If you have the right speakers, it’s an extraordinary device.
And there’s a two-year waitlist. 2000 people, 11 pages long.
This approach to timing and production serves all the people that matter to the company.
Employees are free to do their best work without rushing.
The operation is able to be right-sized instead of more-sized.
The risks are reduced, since the infinite loop of expansion is almost always followed by the doom loop of contraction.
Would-be customers who are impatient can go elsewhere or even buy a used one.
And the folks who are upgrading to this final, ultimate purchase of equipment discover that the value of the transaction goes up commensurate with how long they have to wait. In a world built on instant convenience, perhaps this is something worth waiting for.
Most MBAs would tell Steve to raise prices, ramp up production, automate, outsource and maximize profits.
But perhaps the resilient and generative approach is precisely the right choice. The hard parts are: 1. making something people are willing to wait for, and 2. having the guts and commitment to make them wait.
Pick your customers, pick your future. And often, entrepreneurs forget that they don’t work for Milton Friedman. We can choose the work we do and the value we create, and we can decide what better looks like.
Pluralistic: Model collapse (12 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

One of my favorite rhetorical and analytical moves is joining things together (showing that two different, seemingly unrelated ideas are aspects of the same phenomenon) and taking them apart (resolving a paradox by demonstrating that what appears to be one, contradictory thing is actually two different things that have been lumped together).
"Taking things apart" is a very useful framework for understanding AI. How do we resolve the (seeming) paradox that some skilled workers report wonderful results from their work with AI, while others are full of dire warnings about the lurking defects in their AI-assisted outputs? Simple: the first group are "centaurs" (humans who are assisted by machines) and the second are "reverse centaurs" (humans who have been pressed into service as peripherals for machines):
https://pluralistic.net/2025/12/05/pop-that-bubble/#u-washington
What are we to make of the people who've been fired by bosses who replaced them with AI, in light of the fact that AI is demonstrably not able to do their (former) jobs? Again, it's simple if you separate out two distinct phenomena: "AI can do your job" is the first. The second is: "Your boss is a credulous dolt who is infinitely horny for replacing lippy workers with pliable machines, which made him an easy mark for an AI salesman who convinced him to fire you and replace you with an AI that can't do your job":
https://pluralistic.net/2025/03/18/asbestos-in-the-walls/#government-by-spicy-autocomplete
This is also a useful move for understanding the AI investment bubble. It's not just billionaires who don't think other people are as real as they are and consequently their jobs can be done by chatbots. It's also billionaires who believe that bosses can be sold AI and don't care if the AI is defective, because that's your boss's problem after he buys the AI and fires you. They don't have to believe in AI in order to think it's a good investment: like an investor betting that Joe Rogan can sell millions of dollars' worth of peptides to desperate young men, they are assessing the sales potential, not the merits of the thing for sale:
https://pluralistic.net/2026/08/03/andor/#either
As useful as "taking things apart" is, "putting things together" is also a very important technique for assessing, critiquing and improving AI. In a stellar essay entitled "Temperature Zero for Culture: Why Everything Is Starting to Look the Same" by the data scientist Lauren Leek, we get a top-notch example of "putting things together":
https://laurenleek.substack.com/p/temperature-zero-for-culture-why
Leek's essay is one of those fabulous, wide-ranging, cross-disciplinary pieces, touching on urban design, music trends, synthetic LLM crowds, Netflix recommendation algorithms, and several other subjects, all seeking to resolve a(nother) (seeming) paradox: how is it that we have so much potential variety, but everything is so manifestly the same?
The answer is complicated and nuanced, but Leek's foundational point is that in a data-driven society, "predictions" are self-fulfilling prophecies. As Leek puts it: "Once prediction shapes the choices in front of us, we lose the ability to tell the difference between what people wanted and what the system made easy to want."
This is a pervasive issue across many domains. Leek says that economists call it "performativity," while machine learning researchers call it "model collapse" and urbanists call it "placelessness."
"Performativity" describes how, once a market has been modeled by economists, that model becomes the foundation for economic policy, which pushes the market to conform to the model:
https://press.princeton.edu/books/paperback/9780691138497/do-economists-make-markets
"Model collapse" describes how machine learning models that are trained on their own predictions become incredibly bland, with all variety disappearing from the system's predictions:
https://pluralistic.net/2024/03/14/inhuman-centipede/#enshittibottification
This is hugely consequential: it's why bias proliferates through predictive policing algorithms: train a model with data from racist stop-and-frisks and it will predict that all the weapons and drugs in a city are to be found in Black and brown peoples' pockets. Turn those predictions into recommendations telling cops where to go look for weapons and drugs and they will double down on racist stops, producing even more biased training data, which turns into still more bias in the predictions:
https://hrdag.org/2016/10/10/predictive-policing-reinforces-police-bias/
"Placelessness" is the urbanist's name for "when everywhere optimises toward the same template." I think of it as Flinstones Syndrome, where the same background is looped behind Fred and Barney as they drive through Bedrock. In New York City, it's Citibank-bodega-Chipotle-Walgreens; in the Chicago suburbs, it's the strip malls with a Chili's, a gas station, and a big box store.
Leek proposes that these are all expressions of the same underlying phenomenon, a failure mode of data science that takes a world of "granular personal data" and arrives at a world where "personalisation produc[es] more sameness."
To these excellent examples, I'd add another one, from the world of monetary policy: Goodhart's Law, which holds that "When a measure becomes a target, it ceases to be a good measure":
https://en.wikipedia.org/wiki/Goodhart%27s_law
Goodhart's Law captures a wide variety of phenomena. When Google first deployed Pagerank, they showed that by counting the inbound links to all the pages on the web, you could extract a signal about which pages were most important (because there was no reason to link to a page unless you found it noteworthy).
But once Pagerank became the dominant means by which web users found pages, counting links stopped being useful: first, because people used Pagerank to find the best pages and link to them, making it impossible for new pages to get the inbound links needed to supersede incumbent pages; and second, because it's easy for fraudsters to create inbound links for low-quality pages in bulk, once there's a reason to do so.
Counting inbound links was a world-beating retrospective way of predicting which page would best match a searcher's query, but once it shaped the world it sought to analyze, it ceased to be a good prospective way to predict which page would best match your queries.
Leek is a brilliant data scientist and an even better science communicator, with a knack for crisp, readily understood explanations. How can a world of granular, highly varied data turn into a world of homogeneous choices? Simple: start with a set of items ("cuisines, genres, shop types") and a standard algorithm for sorting them. Let users choose from those recommendations. The mode (average) of those choices "gets shown more, so it gets picked more, so the model grows more confident the mode is what people want, and the tails starve." Run this for a few rounds and the evenly distributed catalog of choices "collapses onto one dominant option."
This is intrinsic in the choices we make in designing recommendation algorithms, tilting them towards the likelihood of a successful recommendation. A recommender that wants to succeed every time will make the safest possible recommendations, "so an algorithm that is uncertain about you, and it is always at least a little uncertain, hedges toward the average."
Then she busts out a beautiful, perfect little statistics aphorism: "Personalisation under a standard loss function is regression to the collective mean with extra steps." That is to say, "regression to the mean" (the tendency of varied things to become more standardized) cannot be avoided with the standard personalization algorithm. That algorithm is going to play it safe, showing you things that are broadly palatable, and because your choices are constrained to the average, you will choose average things.
This is how recommendation systems – and other analytical tools that produce predictions that are then turned into action – force so many diverse phenomena (streets, markets, media recommendations) into sameness. The fact that these recommenders are self-fulfilling prophecies means that "they don't have to be right," only "listened to."
This explains the sameness of so many of London's high streets. Leek examines 640 shopping streets, characterizing 18,000 food places spread out across them, flagging all the chain restaurants. Her analysis shows that any two London streets will, on average, share about half of their "food profile."
Obviously, this is most pronounced on streets with chain outlets, and it doesn't take that many chain outlets before a street's sameness shoots up: "A relatively small number of repeated names is enough to make otherwise different streets resemble one another more." So why do streets with chains resemble one another so much? Because the chains use an algorithm (weighting footfall, proximity to train stations, demographics, and competitors) to decide where to put their restaurants. If a street with a Gail's Bakery on it feels like every other street with a Gail's Bakery, that's because Gail's only puts its restaurants in places that have highly similar characteristics, measured to a high degree of accuracy and controlled by a narrow set of tolerances.
In other words, every street that feels like it should have a Gail's will eventually get a Gail's, whereupon that street will feel even more like all the other streets that have a Gail's, because it will share one more common factor with those other streets (a Gail's).
Leek points here to her earlier work on pub closures in the UK. The UK has experienced an epidemic of pub closures, with thousands of pubs disappearing since 2016:
https://laurenleek.substack.com/p/britain-lost-14000-third-places-they
Her research found that the biggest predictor of a pub surviving was its similarity to the median pub; which is to say that the more distinctive a pub was, the more "character" it had, the more likely it was to close. Pubs that are different from the average pub are harder to categorize, which means they're harder for a bank manager to assess for creditworthiness or for a landlord to justify extending a long-term lease to. The algorithms used to allocate capital and real estate are also recommenders, and they also drive variety out of the system.
This same phenomenon acts on culture. In an age of music recommendation algorithms, hit songs are changing; today's songs use a smaller vocabulary of unique words and repeat those words more often:
Vocabulary richness, distinct words relative to length, has fallen by more than a quarter since the early 1960s, while the share of repeated lines has climbed by nearly a third. The modern hit says less and says it more often, because the hook that works gets repeated.
But that's not the whole story! While each song resembles itself more ("saying less more often"), within that constraint, there's far more variety today than before: a given song's (constrained) vocabulary has grown more distinct when compared to all the other songs' vocabularies. Songs repeat the words they use, but the words repeated in songs are getting more different.
For Leek, this is the key to understanding the whole phenomenon and (more importantly) doing something about it. Music recommendation systems optimized for a singable hook, but did not optimize on any of the other variables in songs, so those dimensions acquired a broader range, even as the optmized variable got flatter and narrower.
This means that the tendency of recommenders to "flatten the world" isn't a single blunt outcome: it depends on which dimension we choose to flatten through recommendation, and who chooses to flatten that dimension.
A media recommender optimizes for consumption, showing you a tractable set of things it believes you'll watch, read or listen to. When you choose from among this limited set, the recommender takes note of that fact and shows you more of the same, pushing everything to a greige median. All the movies, books and songs you might have liked that were omitted from that initial set are excluded from being recommended in the future. The features of that media that you might have appreciated "decay out of consideration." They are never tested for desirability. The model collapses.
How badly does it collapse? Leek cites Movietweetings' data on which movies people watch: out of a million public movie ratings, half relate to the top 2% of movies in the set. There's 38,000 films in the set, but just 380 titles account for 40% of the ratings. Leek argues (persuasively) that this isn't because recommenders are good at "knowing your taste" – rather, they are good at "narrowing the menu."
Leek relates this to her work on creating LLM "personas" – synthetic populations meant to mimic the tastes and proclivities of real groups of people, that you can interrogate "before you spend money asking actual humans." While this would be useful for many applications, "it fails in exactly the way this whole essay is about."
Leek went to enormous lengths to reproduce the traits that make people interesting to study in aggregate, painstakingly replicating the ways that social connections, psychological outlook and demographic factors predict people's beliefs. The result was a set of LLM personas with "elaborate stories" about how they differed from one another, but whose survey responses about planned actions were homogeneous in a way that real populations are not.
This, Leek writes, is the same force that homogenizes other data-driven predictors. Because she'd ordered her LLM to reproduce the statistically validated relationships between different factors that predict a person's beliefs, each synthetic persona was a homogenized average. It's like the paradox of "The Average Man," where military uniforms sized to the average of all service personnel fit no one, because no one is average:
https://archive.org/details/DTIC_AD0010203
The thing is (as Leek points out) the idea that synthetic personas are a good way to understand the preferences of a real population is not a harmless delusion: it's a product that's being actively sold to governments, campaigning politicians and marketers. It's a self-fulfilling prophecy that drives governance, political campaigns and product design to the same homogeneous median that is making every shopping street in London feel the same.
This matters. As Leek writes, ecologists have long understood the importance of variety for systemic resilience: they call it "the insurance value of biodiversity." A diverse system has reservoirs of species and variation that may not be optimized for how things stand now, but that can move into niches created when things change in ways that lay waste to the previously dominant organisms. As anyone whose favorite banana went extinct can tell you, homogeneity works well, but diversity fails well:
https://en.wikipedia.org/wiki/Gros_Michel
The brittleness of algorithm-induced homogeneity is compounded by the fact that recommenders obscure the true preferences of people. If you watch two Scandinavian crime dramas after Netflix recommends them to you, it will keep showing you more Scandy crime for the next decade – even if there's another kind of programming that you'd vastly prefer (if only you knew about it). This means that decision-makers who choose which shows will get made in the future will keep on funding their safe Danish detectives, to the exclusion of whatever might emerge from the same weird attractor that produced the K-Pop Demon Hunter fortune.
Transpose this failure mode onto states, bank managers and landlords, and we see whole ranges of policies, businesses and activities that never come into existence, despite the popularity, prosperity and joy they might bring us.
But Leek doesn't end with this worrisome note. Instead, she identifies this whole thing – model collapse, placelessness, performativity, even Goodhart's Law – as an expression of one of the best-understood tradeoffs in computer science: "exploration vs exploitation":
Any system learning from feedback has to divide its effort between exploiting what already scores well and exploring options it hasn’t tried, in case they’re better.
Computer scientists have long understood that focusing on exploitation to the exclusion of exploration is a trap that locks you into "the first decent option" so you can never discover the best one.
Which means that this algorithmic homogeneity has a well-understood corrective: "forcing exploration back in." The problem is that markets hate this kind of exploration. A company that lives and dies by how many clicks it gets is never going to sacrifice 20% of its traffic by showing its users weird, untested options that score worse than the median because these weird things have never had a chance to prove that they are desirable.
This is a classic market failure, and, as Leek points out, there are regulatory responses in the UK (the Digital Markets, Competition and Consumers Act) and the EU (the Digital Services Act), both of which require the largest platforms to open up their recommendation systems, but so far, regulators have focused on "online harms" rather than variety (though the DSA does require platforms to offer algorithmic recommendations that are not based on your personal traits).
Leek identifies this willingness of states to set conditions for algorithm design as a means by which "exploration" can be forced back into the system. She's also bullish on interoperability, so that users can leave platforms with bad recommenders, without losing access to their media or social circles. As she writes, "the deepest discipline on a feed that has trapped you is the credible ability to leave it and take your data with you." I couldn't agree more:
https://pluralistic.net/2023/01/08/watch-the-surpluses/
She's less hopeful about individual responses. Demanding that you be an "adventurous consumer" is a way of letting systems off the hook. When every street has the same restaurants and every bookshop has the same books and the people in your life are all locked into one of two social media platforms, "choosing wisely" only gets you so far. Shopping isn't politics!
https://pluralistic.net/2026/05/21/purity-culture/#stop-fucking-that-chicken
Leek is a superb writer. After reading this piece yesterday, I sent it to half a dozen people and then read everything else in Leek's newsletter archives. Not only is it all brilliant, but I also realized that she'd written one of the most memorable articles about cities and platforms I've read in the last year, "How Google Maps quietly allocates survival across London’s restaurants – and how I built a dashboard to see through it":
https://laurenleek.substack.com/p/how-google-maps-quietly-allocates
I should have added Leek's newsletter to my RSS reader when I read that last December. I've rectified that oversight! What a fantastic thinker, scientist and communicator! If she isn't being relentlessly pestered by editors and literary agents offering her a book deal, then it really does prove that the recommender systems are elevating the bland median over the thoroughly, delightfully spiky outliers.

On AI Coding and Its Discontents https://calnewport.com/on-ai-coding-and-its-discontents/
Crocs Has a Trick for Dodging Taxes: a Tiny Office in Malta https://www.nytimes.com/2026/08/05/business/economy/crocs-malta-tax-haven.html?unlocked_article_code=1.4VA.UZy2.BtVrP_IVnz8b
Why State-Level Contract Law is Essential to the Future of Digital Library Rights https://www.libraryjournal.com/story/news/moving-beyond-the-publisher-playbook-why-state-level-contract-law-is-essential-to-the-future-of-digital-library-rights
What is a Reverse Centaur? https://www.youtube.com/watch?v=CVjt3_bf1bI
#25yrsago Awful, stupid Wired report on Dutch hacker camp https://web.archive.org/web/20011007084604/https://www.wired.com/news/culture/0,1284,46033,00.html
#25yrsaog Excellent NYT story about the internal contradictions of the DMCA https://memex.craphound.com/2001/08/13/excellent-nyt-story-about-the/
#20yrsago Our faulty intuition about open systems https://www.ft.com/content/64167124-263d-11db-afa1-0000779e2340
#20yrsago Defending against the last plot won’t save us from the next one https://www.schneier.com/blog/archives/2006/08/terrorism_secur.html
#20yrsago NBC: Hair-gel terrorists posed no risk last week https://web.archive.org/web/20060813194630/http://www.msnbc.msn.com/id/14320452/
#15yrsago AT&T merger leak: it’s all about raising prices and reducing competition https://web.archive.org/web/20110920222524/http://www.broadbandreports.com/shownews/Leaked-ATT-Letter-Demolishes-Case-For-TMobile-Merger-115652
#10yrsago What’s inside a Tiki Bird? https://miehana.blogspot.com/2016/08/fancy-feathers-restoring-tiki-room-birds.html
#5yrsago End of the line for Reaganomics https://pluralistic.net/2021/08/13/post-bork-era/#manne-down
#5yrsago Smart cities are neither, 2021 edition https://pluralistic.net/2021/08/13/post-bork-era/#our-streets
#1yrago Maga's boss class think they are immune to American carnage https://pluralistic.net/2025/08/13/then-they-came-for-me/#boss-politics

https://www.edbookfest.co.uk/events/cory-doctorow-enshittification
Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
AI, automation and enshittification (Telecoms.com)
https://www.telecoms.com/ai/the-telecoms-com-podcast-ai-automation-and-enshittification
The AI Enshittification Bubble (Hidden Forces)
https://hiddenforces.io/podcasts/the-ai-enshittification-bubble-cory-doctorow/
F@#$ the AI Overlords (On The Media)
https://www.wnycstudios.org/podcasts/otm/articles/f-the-ai-overlords
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
New Comic: Brokon
The little-known winstart.bat batch file [The Old New Thing]
Reader Otul Osan wants to know what the use case for C:\WINDOWS\WINSTART.BAT was, compared to C:\AUTOEXEC.BAT and when exactly during system startup it launches.
In Windows 95, you could create a winstart.bat file in your Windows directory. During startup, the virtual machine manager initializes and creates the so-called “System virtual machine” (the “System VM”), which is the virtual machine that all Windows programs run in. But before running the user-mode kernel in that virtual machine, the virtual machine manager runs the winstart.bat batch file if it exists.
In pictures: First, we boot up MS-DOS and the command prompt. (Note: All diagrams omit lots of details not relevant to the discussion and are not to scale.)
| Stuff | (unused) | MS-DOS |
The box labeled “Stuff” is a catch-all for random things that go at low addresses, like the interrupt vector table and the BIOS data area.
Next, command.com runs autoexec.bat, which might install some TSRs.
| Stuff | TSR1 | (unused) | MS-DOS |
And then Windows starts up and initializes the virtual machine manager. The system is now running in protected mode with a virtual machine running in v86 mode, and that virtual machine is initialized with whatever was running in real mode at the time the virtual machine manager took over.¹
|
ring 0: virtual machine manager |
I crossed out MS-DOS because the virtual machine manager took over responsibility for the file system and shut off the real-mode file system in MS-DOS.
At this point, the virtual machine manager runs winstart.bat inside the virtual machine, and maybe it installs another TSR.
|
ring 0: virtual machine manager |
And then we start the user-mode kernel that is in charge of Windows applications. That user-mode kernel switches the virtual machine into protected mode and starts running what most people think of as Windows.
|
ring 0: virtual machine manager | ||||||||||||||||||
And then from the Windows GUI, you decide to open a command prompt, which means creating a second virtual machine.
|
ring 0: virtual machine manager | ||||||||||||||||||
|
|||||||||||||||||||
Notice that the virtual machine running command.com is a copy of the system when Windows started.² So it has TSR1 (from autoexec.bat) but not TSR2 (from winstart.bat).
If you install a TSR in the command prompt virtual machine, you get
|
ring 0: virtual machine manager | ||||||||||||||||||
|
|||||||||||||||||||
Okay, now that we see how the pieces fit together, we can reverse-engineer the purpose of winstart.bat.
The intended purpose of winstart.bat is batch file is to allow you to install TSRs that will apply only to Windows programs. For example, you might install network drivers to support your Windows programs. You might choose this option instead of installing them globally because you don’t care about networking for your MS-DOS programs and want to free up conventional memory for them. Or because those drivers don’t support running in multiple virtual machines, so you’ll take them in the System VM and forego them for your MS-DOS programs.
What I find interesting is that most people who discover this say that it’s a feature of Windows 95. But really, it’s a feature of Windows 3.1 (and possibly even Windows 3.0). You can find it documented in the Windows 3.1 Resource Kit on page 263. That page even has a nice table showing three ways of launching TSRs and how they are visible in the different virtual machines. (In this table, “TSR visible in virtual machines” really means “TSR visible in non-Windows virtual machines”, but the documentation takes the convention that the term “virtual machine” refers only to non-Windows virtual machines and not to the virtual machine running Windows itself, which it simply calls “Windows”.)
| Where TSR is loaded | TSR visible in Windows? | TSR visible in virtual machines? |
|---|---|---|
| From MS-DOS | Yes | Yes, all virtual machines |
| From WINSTART.BAT | Yes | No |
| In a single virtual machine | No | Only that virtual machine |
¹ Think about that: We booted an operating system and then booted another operating system around it, so that the original operating system was now running inside a virtual machine controlled by the second operating system. It’s like leaving your house, walking down the street, and halfway down the block, realizing that you’re now walking inside a movie studio set.
² It isn’t actually a copy of the system at the time Windows started. Rather, it is a copy of the system VM, but only the parts that existed at the time Windows started. How this worked is too complex to try to explain in a footnote. Maybe I’ll discuss it some other time.
The post The little-known <TT>winstart.bat</TT> batch file appeared first on The Old New Thing.
Surveillance at Madison Square Garden [Richard Stallman's Political Notes]
Madison Square Garden uses surveillance cameras to recognize people. It specifically tracks people on its enemies list, such as journalist Rachel Maddow. But it normally tracks everyone who enters and perhaps recognizes them all.
However, they made an exception for the audience at Taylor Swift's wedding, apparently because she had the clout to demand this.
People must be free to take photos in public places occasionally and publish them. But no one, and especially no business or organization or government, should be allowed to systematically record everyone that passes before a camera and put the records into a internet-connected system.
Pressuring Democratic candidates to stop avoiding climate issues [Richard Stallman's Political Notes]
A grass-roots campaign is pressuring Democratic candidates to stop avoiding the issue of growing climate disaster.
Focusing on "affordability" of everyday life is partly a mistake, and partly a response to pressure from billionaires who figure that will lead towards weak palliative measures rather to any big change to transfer wealth.
The increasing cost of living is a consequence of deeper injustices, one of which is the growing cost of climate disaster (including food plagued by agricultural failure). Another is the growing cost of medical treatment, which stems largely from the big role of businesses in it. Another is the long and slow shift that leaves the non-rich with less and less of society's productive capacity.
Scrapped plans to curb jury trials [Richard Stallman's Political Notes]
*Andy Burnham signals he will scrap plans to curb jury trials [in the UK].*
This is a victory, even though it only prevents a plan to make things worse.
The supposed "need" for restricting the right to a jury was a shortage of funds. I think Burnham has some plan to increase taxes on non-poor people so as to pay for this and other things to make the UK better.
(satire) Wrath of next ultimatum [Richard Stallman's Political Notes]
(satire) *[The bully] Warns Iran To Accept His Ultimatum Or Face Wrath Of Next Ultimatum.*
Climate emergency poses risk to global economy [Richard Stallman's Political Notes]
*A senior policymaker at the European Central Bank has said the climate emergency and the breakdown of nature poses a dramatically growing risk to the global economy.*
If we are unable to grow enough food, or if calamities substantially reduce the life expectancy, it is going to be hard for anything to be stable or predictable.
What we need to make sure of is that the billionaires won't be able to insulate themselves (and their servants) from sharing the fate the impose on us. And that they know they won't be able to.
Boycott Magnum for Ben and Jerry's [Richard Stallman's Political Notes]
Ben and Jerry sold their ice cream company to Unilever under an agreement to preserve the company's independence and social activism. They now say that Unilever has violated the agreement in several ways, and finally by reselling it to Magnum (as far as I can tell, without any ethical requirements). They call on supporters to boycott Magnum to pressure for it to sell Ben and Jerry's to someone who will restore them.
It is not a simple matter to draw up a contract that will prevent the buyer of a company, or of a program, from slipping out of agreements to follow ethical standards by transferring control in increments.
Tourette's syndrome slip [Richard Stallman's Political Notes]
John Davidson, who has Tourette's syndrome, said the taboo word "nigger" with no conscious intention while two blacks were on stage. People freaked out.
A few decades ago, antiracists understood the word as an unjust insult — when it was meant to characterize someone. But people could contemplate the word in the abstract, and discuss its meaning and implications (such as, a racist attitude) without losing their wits. They could criticize the word's racist attitude without terror of violating the taboo if they said which word they were criticizing. If they heard a touretter say it, and understood that the touretter did not mean to characterize anyone with it, they did not hold that against per.
The change to regard the word "nigger" as a shocking profanity rather than as an unjust racist attack has made it harder for society to cope with situations like this one, and harder to clearly express condemnation of racism.
(satire) Make-out point purchased by make-out conglomerate [Richard Stallman's Political Notes]
(satire) *Small Town’s Make-Out Point Purchased By Multinational Make-Out Conglomerate.*
(satire) Military Wife Draft [Richard Stallman's Political Notes]
(satire) *U.S. Instates Military Wife Draft.*
Underground report from Iran [Richard Stallman's Political Notes]
An underground report from Iran about torture and killing of imprisoned protesters.
Ticketmaster increased base price [Richard Stallman's Political Notes]
Ticketmaster was required by law to stop adding certain junk fees to ticket prices, so in some cases it increased the base price so that the total remained the same.
Is this a scandal? I don't think so. The scandal is that they would tell you a lower price, not including the junk fees, then charge you a higher price which includes the junk fees. Now they have to be more honest about the real price.
If we want to do something about the high price of concerts, we should adopt strict laws against overconsolidation of industry, and break up businesses that are too big. This would include the Ticketmaster/Live Nation near-monopoly and many others that mergers have created in the past few decades.
The corrupter's henchmen are encouraging new monopolies.
Sham promises to get Blanche confirmed [Richard Stallman's Political Notes]
The corrupter, seeking to have his personal lawyer Blanche confirmed as Attorney General, made sham promises to the Senate that Blanche would not approve the corrupter's slush fund and tax return immunity deal.
The promises are a sham because they are only temporary — if the Senate approves Blanche, he and the corrupter can cancel these promises and approve the deal anyway.
Academic scores and antisocial media use [Richard Stallman's Political Notes]
* Pupils who open [antisocial media] accounts [at the age of] 11 to 12 score lower in some subjects [at age 16] than those who wait a few years [to open such accounts], study finds.*
Climate change kills [Richard Stallman's Political Notes]
"Climate change kills": [Prime Minister] Pedro Sánchez speaks plain truth to Spain's deniers.
Prosecution of violent "settler" for killing Palestinian [Richard Stallman's Political Notes]
Israel is prosecuting one of the violent right-wing "settlers" for killing a Palestinian journalist in the West Bank.
Such a prosecution ought to regularly follow their crimes, but instead it is news, because Israel generally protects those killers.
Girl Genius for Wednesday, August 12, 2026 [Girl Genius]
The Girl Genius comic for Wednesday, August 12, 2026 has been posted.
Invitation Refused [QC RSS v2]

Caves of Qud reference
Google hammers another, extremely petty nail in the Android Open Source Project’s coffin [OSnews]
The slow but steady march to the grave for the Android Open Source Project continues. Every few months Google hammers another big nail in the coffin of Android as an open source effort, and I’ve documented them all here on OSNews (nail, nail, nail, nail, nail), coming to the conclusion long ago that for all intents and purposes, Android is no longer an open source operating system.
The latest move, however, is just petty.
According to GrapheneOS on [Twitter], Google has apparently replaced public, instant code downloads for Pixel phone drivers with a manual request form. Instead of publishing code directly to open developer platforms where anyone can grab it, Google now requires developers to fill out a Google Form and wait for someone to send them a Google Drive link.
What used to take a couple of hours is now taking weeks.
↫ Hillary Keverenge at Android Authority
I’m perhaps misremembering, but I vaguely recall discussions decades ago about what, exactly, it meant to “make source code available”, as open source licenses state in a variety of words. Would mailing a paper print-out by classic post satisfy such requirements? Could you write the source code on a brick and throw it through the user’s window? Could you hire a church choir to sing it? These are all silly examples, but before everyone had internet access, this was a relevant question.
The widespread availability of the internet and software like git solved these issues, which makes it all the more petty that Google now requires an actual application process, waiting times, and Google Drive dumps just to get access to the source code for Pixel drivers. Google is clearly trying to kill whatever’s left of the Android Open Source Project’s rotting corpse, only barely technically complying with any license requirements only because they’re obligated to.
The Android team at Google must be a hoot at parties.
GNOME showcases a number of possible GNOME Shell changes [OSnews]
The GNOME Shell user interface has mostly seen minor refinements and quality of life updates in recent cycles, but on the design side we’ve explored a lot of longer-term things we’d like to do. Some of these we have relatively complete plans for, others are more vague ideas that need more research and prototyping. As always, getting things like these implemented depends on developer capacity and interest (and sometimes funding).
While each of these ideas may require additional discussion, prototyping, and testing, we (the design team) have collected them all together here to share our longer-term vision and to give each idea more visibility.
↫ Tobias Bernard on the GNOME blog
There’s quite a few good ideas in there, with most of them already being available in the form of various extensions. I’m not entirely sure if I’m a huge fan of copying Android and iOS by moving notifications into the quick settings dropdown thing, but it’s not like having them in the clock/calendar dropdown thing is any better. I only use notifications as they arrive and never look at the place where they end up – that’s a mobile thing for me – so I don’t think I’ll really care either way.
Things like editable quick settings, transparent top bar on certain backgrounds, the improved window drag and drop in the Exposé view, the alt+tab experiments, and some of the others do seem quite interesting though, and anything that reduces the number of GNOME extensions I need to install and keep updated gets a big thumbs up from me.
If you wish to work on any of these suggestions, working on GNOME Shell has gotten a lot easier recently.
In the past, GNOME Shell was significantly harder to contribute to and test than apps since you needed to use tools like jhbuild. This has changed in the past year: You can now easily build and test your branch in a nested session from Builder using Mutter Devkit. If you use GNOME OS, you can even build a sysext to install your branch on your host system. This allows daily driving experimental branches easily, which is super helpful for evaluating changes to everyday workflows.
↫ Tobias Bernard on the GNOME blog
That’s quite neat.
Who (or What) Generates Images for EFF? [Deeplinks]
We’ve had a few questions from EFF supporters lately, asking whether the images we use on our blog posts, or on donation and shop items, have been created with AI image generators. We’d like to answer these questions and clarify our internal policy regarding image creation.
EFF images are all made by human beings, not by automated
image generators, with very rare exceptions. This is
an internal decision made by our small design team, for the
following
reasons:
An example of EFF artwork process: sketch and final art
To be as clear as possible, we are now adding a small credit in the lower righthand area of each banner image that will read “Image created by EFF.” As mentioned earlier, there may be rare exceptions, when an EFF designer uses an automatically generated image as a small element in a larger illustration. In these cases, we will indicate that use with additional text, specifying the elements involved, and naming the image generator used.
We hope that by describing our internal design thinking, we are answering the questions we are getting without confusing anyone about EFF's various and nuanced positions on the issues raised by image generators. As with past technological developments, we continue to defend the rights of technologists to develop these powerful tools, as well as the right of the public to make legal and legitimate use of them. Ultimately, EFF's design team has made a choice we feel is consistent with EFF's brand and look, and it's a decision we think every user gets to make for themselves.
And don't forget: because all of our images are CC-By, you are free to use, share or remix our any image we create (we ask that you include a credit to EFF). If you need hi-res versions, you can find some on our Flickr page, or you can email us directly with any requests. And you can enjoy some of the art we create on gifts you receive when you donate to EFF!
Get awesome human-generated art as a thank you gift!
The Shattering Peace Now Out in Trade Paperback [Whatever]

That’s it; that’s the post!
Well, also that it’s a New York Times best seller and also nominated for the Dragon Award (by itself) and the Hugo Award (as part of the Old Man’s War series), got great reviews and also I was very happy with it as a novel. If you’ve not read it before, now is a great time to do so. Get it wherever you buy books, but your local bookstore especially if there’s one you particularly like and want to support.
— JS
AI Genie in the Wild [Schneier on Security]
When I give talks about AI genies, I use this sort of example as a hypothetical. It’s happened.
The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And….
Minutes later, his AI agent reported it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible.
Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list.
The agent came back and told Andrew that it had kicked another gym-goer off the list as part of the testing of its capabilities.
“The API has zero authorisations checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 —and it actually went through. So you’ve moved from #4 to #3 already,” it messaged back.
If there is any vulnerability in anything, AIs are going to find and exploit them. Our cyber defensive game has to be dramatically improved…very fast.
Slashdot thread.
[$] KVM planes head for takeoff [LWN.net]
Virtualization places a guest system into a separate security domain, typically with less privileges than software running directly on the host. Increasingly, there is interest in creating multiple security domains within a single virtualized system as well. CPU vendors (and software vendors too) are implementing solutions; each of which, of course, is different from all of the others. KVM planes, currently under development by Jörg Rödel, Paolo Bonzini, and others in the KVM community, is an attempt to provide an abstraction layer that makes all of these features available on Linux systems; it is not a small task.
Bernard: GNOME Shell design dreams [LWN.net]
GNOME contributor Tobias Bernard has published a blog post that details some of the design team's ideas for the GNOME Shell over the long term:
Some of these we have relatively complete plans for, others are more vague ideas that need more research and prototyping. As always, getting things like these implemented depends on developer capacity and interest (and sometimes funding).
While each of these ideas may require additional discussion, prototyping, and testing, we (the design team) have collected them all together here to share our longer-term vision and to give each idea more visibility.
CodeSOD: Public Private Partnership [The Daily WTF]
Eric O was trawling through an API for handling concurrency, and found this little mismatch between the comment and the definition:
/// <summary>
/// private Status, because while this object needs to be able to set the status, consumers should only be able to check it, lest everything break.
/// </summary>
public StatusType Status {
get {
return _status;
}
set {
if (value != _status) {
RaisePropertyChanged("Status");
}
}
}
It's very important we make this property private, lest clients abuse it, and unleash dragons, chaos, and other potential horrors. Given that this happens inside of a concurrency API, I can only imagine what could go wrong when you mess this up. So sure, the comment makes sense.
The definition on the other hand, doesn't agree.
In practice, it's probably fine to do it this way, and at least the comment will show up in the documentation. If a consumer of the API misbehaves, they'll at least see that the docs suggest this is private.
The joke, of course, is the idea that the users of the API are going to read the docs, or care that one of the public methods suggests that it should be private.
Security updates for Tuesday [LWN.net]
Security updates have been issued by AlmaLinux (gpsd), Debian (caddy, libyaml-syck-perl, nss, and wordpress), Fedora (chezmoi, chromium, emacs, kernel, knot, libcupsfilters, mingw-gstreamer1-plugins-good, mingw-libidn, mingw-python-pip, nghttp2, p11-kit, python-webob, suricata, and xen), Mageia (bind, openslide, php8.4, and php8.5), Oracle (gpsd-minimal, kernel, libarchive, libpng12, nodejs-nodemon, php:8.3, ruby:3.3, and ruby:4.0), SUSE (agama-web-ui, bind, bouncycastle, dhcpcd, ffmpeg, ffmpeg-4, freerdp, gd, gitoxide, kak-lsp, kernel-devel, librest-1_0-0, libsdb2_5_0, libssh2_org, nodejs22, PackageKit, perl, perl-Date-Manip, python-ujson, python3-sqlparse, python311, python312, python313-pymongo, ruby2.5, runc, suseconnect-ng, thunderbird, vlang, webkit2gtk3, and weechat), and Ubuntu (imagemagick and systemd).
Apparently the nightly email didn't go out last night. The
problem was an error when it tried to read the Linkblog entries for
the day. I've seen reports that these errors happen when you try to
read the Links tab on
scripting.com. The error shouldn't kill the email sending, it
should just omit the linkblog entries, and publish the rest. These
kinds of problems always pop up at the worst time. Luckily
yesterday wasn't a big news day, and you can read about it on the blog.
I was looking for a codename for a new scripting environment Claude and I are making attempting in every way to do exactly what Frontier does. But until it does that I need a nice name, memorable, maybe a bit magical and positive. Frontier has been gone, thought to be lost, but with the advent of Claude Code we were able to get it running again in current OSes on current hardware. I shouldn't call it Frontier because who knows if the end result will be compatible enough to claim that. But I want a codename that reflects hidden, forgotten and overlooked wealth. Like a civilzation that rose from the ashes," or as it turns out, the bottom of the ocean.
Microsoft drastically increases costs of Windows licenses for OEMs [OSnews]
This was bound to happen.
According to a new report from Taiwanese publication United Daily News (UDC,) Microsoft is raising the cost of Windows license fees for hardware makers by a much higher amount than normal. According to the report, certain OEMs are seeing licensing price hikes of between 7% and 10%.
↫ Zac Bowden at Windows Central
Like every other tech company diving head-first into “AI”, Microsoft is losing money on its gamble head-over-fist, with no profitability in sight. Since admitting betting the company on “AI” was a mistake is out of the question, Microsoft has to extract the money from somewhere else to make up for it. The cost of Windows licenses for OEMs is an obvious lever to pull, as OEMs really have nowhere else to turn to (yes, desktop Linux is making gains, but not in any meaningful numbers), so they’ll take hit and pass the cost on to consumers.
The end result will be that prices for laptops will increase even more than they already have thanks to the “AI”-induced RAM and component crisis, creating a double-whammy of price increases caused by “AI”, either directly or indirectly. It’s just another category of products we can add to the cost of living crisis that’s causing untold harm and damage to hardworking people all over the world.
The price of incompetence is rarely paid for by the incompetent.
An ambiguity in c89 which will never be fixed [OSnews]
I found some ambiguous wording in the c89(/c90) standard, where GCC and Clang disagree on the interpretation. It concerns the behavior of implicit function declarations, which were removed in c99, so this was never disambiguated.
↫ Sebastian at sebsite
I am not going pretend to understand any of this.
A Home for Personal Context [Radar]
Every agent I use is building a model of me. Claude has learned how I like my prose. ChatGPT remembers what I’m working on. I don’t mind this—every person I have a relationship with carries a model of me in their head, and every company I do business with keeps a profile. Other people’s understandings of me have never been mine to control, after all.
But an agent occupies a different role. It learns my writing style, my preferences, and the shape of my work and life, all to help me with what I do. Yet if I switch products, I have to start over. If I use three agents, each rebuilds from scratch what the others already know. Everything an agent learns lives with its vendor.
It doesn’t need to be this way. What if every person had a canonical, user-controlled repository of context that any agent could request permission to use? What if my context lived not only with the company providing the agent but also in a home under my control? And what if an observation captured by one agent could be proposed to that repository and, once accepted, made available to every other agent I choose?
By user-controlled, I don’t necessarily mean self-hosted. I mean that I can inspect what the repository contains, decide who can read or change it, understand where each piece came from, and export the whole thing in a form I can take elsewhere. Its storage, identity, and synchronization may all be provided by someone else. Control does not require me to operate the infrastructure; it requires that no agent or platform be the only way in—or the only way out.
The repository wouldn’t be a portable copy of any agent’s internal model of me. It would be a legible record of things I have written, facts and preferences I have chosen to keep, as well as observations that agents have proposed and I have accepted, each with its provenance, scope, and history. Agents could consult or add to that record according to their permissions; their private inferences would remain their own.
The dream is not a new one. Tim Berners-Lee’s Solid project has argued for years that personal data should live in pods that people control, and Doc Searls’s VRM project has been making the case for user-driven relationships with vendors for decades. What those efforts never had was mainstream demand. Agents are supplying it: An assistant needs rich personal context to be useful, and each vendor is building that context inside its own walls. Ordinary people now have a reason to want a personal data store, even if nobody will actually call it that.
The hard problem in all this isn’t syncing or storing data. It’s negotiation. Who can read a given part of my context? Who can add to it, change it, or remove it? Which parts of my life can a particular instance of an agent see? How do I make those decisions in a policy-driven way? And how do I manage them from wherever I happen to be?
But before I could work on negotiation, I had to figure out where my context should live. That’s the question I’ve spent the past year on, and I’ve tried three answers.
Immediately after getting access to Claude Code at the start of 2025, I pointed it at an Obsidian vault—a folder full of Markdown files that can be used as a personal wiki. This wasn’t a particularly novel idea. Many of the geeks I know did the same, and the pattern has since spread in many forms. The best-known recent example is probably Karpathy’s LLM Wiki, elegant not just as a design but as a document: You give the description to your agent, and the agent builds a version tailored to you.
A year of using a pile of Markdown text files with agents has taught me five things about what a personal context system has to get right.
Local-first foundations matter. Text files are remarkably legible, portable, and easy to store somewhere I control. Git moves them between computers and remembers every change. But the result is centered on a laptop or desktop and assumes a user comfortable with plain text and version control. Most annoyingly, my context in this form isn’t readily available on my phone, which is the computer that goes with me everywhere. Nor can agents running anywhere other than my laptop reach it.
Provenance matters, and so do proposals. Karpathy’s Wiki is almost entirely written (and rewritten) by the LLM. In my own system, I write most things myself and lean on agents to help me edit as well as contribute their observations. I want to know which thoughts are mine, which were captured by an agent, and which we arrived at together. That means an agent’s observation should not automatically enter the repository on the same footing as something I wrote. The default should be a proposal that I—or a policy I control—can accept, revise, or reject. Direct write access is something a trusted agent should earn.
Chronology matters. Wiki links aren’t the only structure in a life. Most of what I record—and much of what agents observe—is anchored in time. Thoughts build on thoughts. Observations about people accumulate meeting by meeting. Some facts fade as they age. Time should be a primary axis of the system, not something reconstructed afterward from file histories and metadata.
Scopes matter. My context spans work, personal, family, and public life. I want one unified view; no agent should have one. An agent connected through my work account should see work and public context—and nothing about my family. Fully separate silos would protect those boundaries, but they would also shred the single history I want to keep building for decades.
Identity and type matter. LLMs can extract all sorts of meaning from plain text, but some things, such as people, companies, and places, deserve to be typed records rather than mentions in prose. A persistent identity gives observations, relationships, and history an anchor to accumulate around; it can help resolve nicknames and follow changes in roles and titles. An agent can then act on who someone is without reconstructing them from prose every time.
As I learned these lessons, I added tooling and conventions to my personal context repository. It’s surprising how far you can push a directory of Markdown files. Each new affordance, however, turned my simple folder into a more specialized system, and the result only works for geeks like me. It doesn’t work for my family, however. They use agents every day but they are never going to deal with a pile of Markdown files in a Git repo. They want their personal context to be with them, easy to use, and transparent to the rest of their life.
More to the point, the five lessons
above describe what a context system must do. They don’t
answer where it should live if /home/$USER isn’t
the center of your computing life.
My next move was to sort out how to make my context available when I wasn’t at my laptop—to me and, just as importantly, to my agents. The obvious solution to me as someone who has been building on the web since the mid-1990s: put it on a server behind a URL. I deployed a Cloudflare Worker, uploaded my context, and stood up both a REST API and an MCP server. The improvement was immediate. My context was reachable from my phone and grantable to any agent I chose.
New problems arrived just as fast. I had created a new trust boundary with its own access control mechanism and appointed myself its security team. I was now the operator of a small SaaS with exactly one customer, responsible for its uptime and its backups. And I had traded away local-first, offline editing to get there.
These are solvable problems. Our industry has spent two decades learning to host services, and CRDTs could probably win back offline editing. But as agents gain access to more sensitive data and more power to act on our behalf, the price of getting a boundary wrong keeps rising.
And even with those solved, a deeper problem remains: A stand-alone service sits outside my computing home, apart from the contacts, calendars, messages, files, and system-level agents already inside it. Apple’s Siri AI announcements made that separation vivid, and Gemini’s integration into Google’s ecosystem points the same way. An agent embedded in an ecosystem works with everything inside its trust boundary; my worker would have to rebuild every one of those connections from outside.
As I tinkered, I kept returning to a simple mental image: my context living on the device in my pocket that goes with me everywhere. Not literally every byte, of course, but within the personal computing ecosystem that phone is the center of—the one that already establishes my identity, synchronizes my devices, stores much of my personal data, and mediates what applications can access. In this sense, a home is not a physical location. It is a trust boundary.
Living inside the boundary doesn’t mean that every application inside gets my context, or that agents outside are shut out. The boundary supplies identity, secure storage, synchronization, and native integration; the context layer still decides what each connection may read, propose, change, or delete. Native agents participate through the platform’s own capabilities, while agents from other companies connect through explicit, revocable permissions.
For me, that home in my pocket is Apple’s ecosystem, with iCloud at its center. For you, it may be Google or Microsoft. The point is not that any one ecosystem is the right home for everyone. It is that most people already have a primary digital home, and that home is the most practical default for their personal context. We shouldn’t need to create a separate service with its own identity. Instead, agents should have a common, permissioned interface to the context where it already lives.
There’s an obvious risk here. A home rooted in a vendor’s ecosystem invites lock-in. The mitigation is straightforward: The whole repository—entities, provenance, and history included—must be exportable at any time as a directory of plain text files that can be taken anywhere. A pile of files in a folder may not be the right solution for live context, but it makes a perfect escape hatch.
I’ve started testing this thesis in a SwiftUI app, and my early prototypes suggest that the architecture is workable: iCloud handles synchronization, and I can expose selected context to authenticated agents through MCP. It’s also shown that working in the Apple developer ecosystem is more annoying than deploying a web app.
The remaining work is clear, however. Choosing a home for context is one problem; negotiation—permissions that remain understandable as a repository grows, proposals from multiple agents reviewed and reconciled—is another. That is the hard problem I mentioned before, and it deserves its own deep dive.
Others are converging on this pattern from different directions. The note-taking app Bear, which stores its notes locally on Apple devices and synchronizes them through iCloud, now exposes them to local agents through MCP; its latest release lets users include or exclude notes by tag when granting access, offering a practical approach to scopes. Craft’s MCP connections likewise let users choose which documents or spaces an agent can access and whether it can read or write them. Reflect has embarked on an open source client using Markdown files that will have an iOS companion app.
These are just a few examples, and there are a lot more out there. What I haven’t yet seen emerge however is the attribution and provenance of items that an agent contributes or edits that I think a durable personal context requires.
Zooming out, here are the principles I think are needed in any system like this, wherever it makes its home:
Using these principles, personal context can be something a person owns: You can inspect it, grant and revoke access to it, trace where each piece came from, and take the whole of it elsewhere. Every agent may still develop its own understanding of you, but you’ll be able to bring a durable context of your own to the relationship, one that participates in the agentic ecosystem without being subordinate to any vendor in it.
Karpathy’s LLM Wiki is a description, not a tool; it’s meant to be implemented by anyone, in whatever form fits. This essay is offered in the same spirit. The important part isn’t whether the app I’m tinkering with ever ships beyond my own devices. I’m more interested in the dialogue it will take for everyone to have personal context that works for them, in their ecosystem and with the agents they want to use. If we get the pattern right, changing agents won’t mean changing homes. The context they help us build will remain ours.
Zero to Agent in 30 Minutes: Build a YouTube Analytics Agent with Vicki Reyzelman [Radar]
On the most recent episode of Zero to Agent in 30 Minutes, Vicki Reyzelman, senior solutions engineer at Akamai Technologies, drew on more than 25 years in technology and a background in software engineering to build an agent for her Chat About AI YouTube channel.
Vicki wanted the agent to monitor channel performance, identify bottlenecks, and recommend ways to grow subscribers and improve click-through rates. She defined the requirements, designed the workflow, built the agent, tested it, and revised the instructions following the same iterative process used in software development.
Vicki recommends revisiting the skills file as new requirements emerge. Clearer instructions, stronger guardrails, and regular testing help the agent continue to produce useful results. Her process reinforces a practical software engineering lesson: Faster implementation doesn’t reduce the need for clear requirements, reliable data, security controls, and testing.
Join us for the next episode on August 12, when AI and machine learning leader Ofer Mendelevitch will explain how to design multi-agent systems that can keep work moving without constant human involvement. He’ll use Jam to build a team of agents that can plan, divide work, execute tasks, review progress, escalate problems, and repeat the process. He’ll show how an architect agent can take a project brief, recruit developer agents, assign work, and guide the project toward a clear definition of done.
Colin Watson: Free software activity in July 2026 [Planet Debian]

About 95% of my Debian contributions this month were sponsored by Freexian.
You can also support my work directly via Liberapay or GitHub Sponsors.
Now that Ubuntu 26.04 LTS has been
released, I’ve been getting back to the
GSS-API key exchange package
split in our OpenSSH packaging. Once I started testing my draft
openssh-gssapi source package, I realized that I
needed to make some changes in the main openssh source
package first in order to support it. The dependency from
openssh-server to openssh-client was
awkward, as was the (related) fact that openssh-client
contained shared documentation for other OpenSSH binary packages.
After some thought, I created a new openssh-common
binary package, moved shared documentation and the
ssh-keygen program to that, and dropped dependencies
on openssh-client which were no longer necessary
(fixing #699473 and
#1070098 in
the process).
This caused a couple of regressions (#1141420 and #1141550) that I had to fix,
and more subtly it also caused a number of autopkgtest regressions
in other packages because openssh-client is no longer
in base images as a result of a dependency from
openssh-server. I believe I have fixes for all of
these either pending review or merged (one of which I did in August
rather than July):
I upgraded from 10.3p1 to 10.4p1, and in the process contributed a GSS-API option handling fix upstream.
I made openssh-ssh1’s package description more accurately describe the package, thanks to suggestions from Matthias Lang.
With support from a Freexian customer, I reviewed, tested, edited, and merged a patch to add VLAN support. I described the details of what I did in a comment.
This has been vaguely on my to-do list since, er, about 2014, so it was very satisfying to get it sorted out.
New upstream versions:
Other build/test failures:
markers configuration optionI fixed some other bugs:
I adopted transaction for the Python team.
I attended the Python BoF at DebConf remotely, although a badly-timed fibre outage in the village I live in really didn’t help.
Dan Poltawski pointed out in a Fediverse post that the project history didn’t list Sruthi as the current DPL. I fixed that, although it doesn’t look as though the fix is in the published version yet.
I upgraded yubihsm-shell to 2.8.0.
Pluralistic: Surveillance vs guillotines (11 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

In the summer of 2013, two esoteric, technical, incredibly important texts were published within weeks of one another: the first is the Snowden leaks, which revealed a system of global, pervasive digital surveillance; the second was Thomas Piketty's Capital in the 21st Century, a book about the economic inevitability (and political instability) of oligarchy:
https://memex.craphound.com/2014/06/24/thomas-pikettys-capital-in-the-21st-century/
If you'd like an essay-formatted version of this thread to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
https://pluralistic.net/2026/08/11/tragedy-of-the-commoners/#piketty-snowden
In 2013, it wasn't immediately apparent how these two works connected with one another, but in the years since, I've grown increasingly convinced that Snowden and Piketty can only be properly understood as describing two aspects of the same phenomenon.
Piketty's landmark volume was grounded in a detailed analysis of 300 years' (!) worth of global capital flows, painstakingly compiled by a large team of grad students from a massive set of heterogeneous records. The book's conclusion is the statement that "returns to capital exceed the rate of growth over the long term" (abbreviated as "r > g").
This may sound innocuous, but it is explosive. If r > g, then the most wealth will inevitably accumulate in the hands of people who start with the most wealth, irrespective of whether they do anything productive with that money. This means that the alleged heroes of the market system – the entrepreneurs who found and manage the firms that increase public prosperity – are doomed to play second fiddle to the mere plumbers of money, people who "contribute" by accumulating.
The starkest example of this in Capital 21C is Piketty's contrast between L'Oreal heiress Liliane Bettencourt (then the richest woman in the world) and Bill Gates, founder of Microsoft (then the most successful corporation in the world). Piketty compares the growth in the fortunes of Bettencourt and Gates over two periods: first, the period between Microsoft's founding and Gates' retirement as CEO; and second, the period after Gates's retirement from his executive role, when he became a mere investor, no longer an entrepreneur.
During that first period, in which Gates was founding and running the most successful corporation in the world, he accumulated less wealth than did Liliane Bettencourt, who did precisely nothing of value over that period. Bettencourt didn't even manage her investments – that was all handled by some very clever financial planners, lawyers and accountants. In other words: for Bettencourt, doing nothing at all produced more wealth as founding the most successful corporation in the world did for Gates. Bettencourt, a person who owned things, did better than Gates, a person who did things.
And then Gates retired. He stopped doing things and started owning things. He became an investor, whereupon he out-earned both Bettencourt and Gates-the-entrepreneur. Again, the market system allocated fewer rewards to the most successful person in the doing things business than it allocated to that same person once he quit that job and got into the owning things business.
Piketty shows that this holds true across markets and nations and eras: all other things being equal, the market system produces a class of hereditary aristocrats who command the world's capital and direct its deployment, despite never having done anything. The market's most lavish rewards do not go to its most productive participants, but rather, to those participants who have the good fortune to emerge from the luckiest of orifices.
Worse: winning the orifice lottery in no way qualifies you to direct the capital you've inherited. Liliane Bettencourt had no revolutionary new business ideas, invented no miraculous new materials or processes, produced no brilliant art. She merely accumulated, thanks to the professional services of skilled technicians whose job description includes hiring their own successors to ensure that another generation of winners of the Bettencourt orifice lottery could continue to accumulate, commanding more capital and power in society.
Perhaps if these orifice winners were content to allow their bloodless Renfields to allocate their capital while consuming bonbons and attending yacht parties, this could yield a stable politics. But inevitably, people who win the orifice lottery observe that they come from a long line of wealthy people, a line that will continue with their own descendants, and conclude that they have some kind of special, heritable virtue – magic blood – that the system has recognized with their great fortunes and the power those fortunes confer.
That's when things get dangerous: when aristocrats grow bored with their leisure and mobilize their inherited capital to change the way the rest of us live. Billionaire dilettantes are weapons of mass destruction, and their special projects have a wide blast radius and inflict a lot of collateral damage.
Take Bill Gates: his ideological projects have been a catastrophe. A patent maximalist, he funded the lobbyists who successfully blocked South Africa from producing its own AIDS drugs under an IP waiver program, and then deployed them again to stop the Global South from making their own covid vaccines:
https://pluralistic.net/2021/04/13/public-interest-pharma/#gates-foundation
Closer to home, Gates's hatred of public institutions led him to allocate millions to dismantling public schools and replacing them with charter schools, particularly for poor and racialized kids, with disastrous results:
And of course, Gates supported and empowered Jeffrey Epstein and his rape island:
https://en.wikipedia.org/wiki/Bill_Gates#Connection_with_Jeffrey_Epstein
Capital's tendency to accumulate in the hands of the already wealthy (r > g) means that these aristocrats end up setting an ever-larger proportion of our societal agenda, despite their manifest unfitness to govern and their absence of any kind of democratic legitimacy.
Piketty argues that inequality is inherently politically destabilizing. A society ruled over by fools and monsters who were not voted into power and can't be voted out of power is a doomed society. Eventually – the French Revolution, the World Wars – these societies grow so unstable that they collapse altogether.
This is where Piketty and Snowden converge. When the Snowden leaks broke, there was a lot of talk about the mechanics and the legality of the NSA's global digital surveillance, but precious little consideration was given to the reason for all this surveillance. In 2013, the idea that this spying was about "security" was so obvious as to be self-evident. The questions at the time were whether spying could produce security. We weren't asking why things were so insecure.
In retrospect, the answer is to be found in Piketty. Piketty's Capital includes a long, impassioned plea to both lawmakers and aristocrats to consider redistributive policies (like a wealth tax) as the most affordable way to achieve political stability. Fundamentally, Piketty argues that the cheapest way to stop people from building a guillotine on your lawn is to build hospitals and schools; this is cheaper than paying for guards and prisons to lock up would-be guillotine builders.
Today's AI debates swirl around the question of whether AI can truly make us more productive – that is, if chatbots will allow one person to do the work of two, or three, or four – or 100. But when it comes to surveillance, the digital revolution unquestionably produced a massive productivity dividend.
Consider the spying apparatus of the former East Germany ("the GDR") widely considered the most surveilled society in human history. When the Berlin Wall collapsed, there were about 16m people in the country. Of those East Germans, about 90,000 worked directly for the Stasi (the secret police), aided by another 100-200,000 paid informants:
https://www.dw.com/en/east-germany-spy-agency-stasi-surveillance/
Call it 200,000 people to spy on 16m. In other words, it took one spy to watch 80 of their neighbors. Contrast this with NSA spying: they accumulated detailed surveillance dossiers on about 6 billion internet users using a staff of no more than 5 million spooks (in 2013, about 5 million Americans were eligible for security clearance). If every single person with security clearance in the USA was working on the NSA's surveillance program, that would mean that by 2013, computers had made it possible for a spy to keep tabs on more than a thousand people.
Orders of magnitude improvements in a mere generation! This is the kind of productivity lift that economists dream of when they fantasize about the dividends from automation.
But why? Why spy?
East Germany spied on its people because the system was so unjust and cruel that its beneficiaries understood that their neighbors were forever on the brink of rising up against them. East Germany's leaders were right about that – but if anything, they didn't put enough people onto the spying project. We can tell, because the Berlin Wall fell in 1989!
Of course, the GDR was already paying more than 1.2% of its population to spy on everyone else. It's likely that East Germany's leaders believed that their society simply lacked the fiscal space to hire more spies, even if short-staffing the Stasi risked societal collapse. Now, if Piketty is right, East Germany's leaders could have solved this problem by giving people fewer reasons to want to overthrow the state. They could have taken their hands out of the cookie jar, could have instituted democratic reforms – they could have made a bid for democratic legitimacy and public material comfort. But that would have come at the leaders' own power and wealth, and, lacking the stomach for this sacrifice, they lost everything.
Enter the NSA: the digitization of human civilization has drastically reduced the cost of surveillance, and – again, per Piketty – this vastly increases the amount of inequality the world can sustain before the illegitimacy, incompetence and cruelty of rule by the neoaristocratic winners of the orifice lottery brings the whole thing crashing down.
The Trump years are proof of this. We've reached a high-water mark for rule by illegitimate billionaire dilettantes. The second Trump admin began with DOGE's Bonfire of the Stupidities, where Musk cultists dismantled vast swathes of the American administrative state. Musk didn't just attack foreign aid – though the fact that the world's richest man murdered hundreds of thousands of the world's poorest children for the lulz isn't merely cruel, but also massively destabilizing in a way that will shake the world's politics for generations – but also domestic institutions. It was a DOGE cultist who fed the part of the NIH that tracks cyclosporin outbreaks into the wood-chipper:
https://truthout.org/articles/disease-researchers-blame-doge-cuts-for-spiraling-cyclospora-outbreak/
Today, tens of thousands of Americans are experiencing the literal enshittification of the American state, and this isn't just a human tragedy (though it is), it's also an economic tragedy, with massive knock-on effects for the businesses that rely on those sickened Americans and for the agricultural sector whose outputs are now being shunned by millions. Whether it's letting Bill Gates decide how your schools will work or letting Elon Musk decide how your public health system runs, the result is political chaos and a societal nudge away from the rule of law and towards guillotines.
Which brings me back to Snowden. The Snowden revelations did spur a global conversation about digital surveillance, with the result that the majority of the world's digital traffic is encrypted today. That's not nothing.
But the American state found new ways to conduct mass-scale, global surveillance, often by collaborating directly with tech giants. Billionaires like Peter Thiel capitalized on Big Tech's conflicted feelings about openly participating in surveillance by founding Palantir, with the express mission of murdering the political opponents of oligarchy:
https://www.thecanary.co/trending/2026/01/07/palantir-kill-communists/
Over the past decade, the steady march of digital technology, dominated by a cartel of giant global firms who collude with the US government's system of political repression in exchange for tax breaks, antitrust forbearance and fat federal contracts has yielded more mass surveillance productivity gains than the previous 25 years:
The Trump administration is the most unpopular in more than a century. Trump has stolen more money in office than any president in history. Trump presides over spiraling greedflation and collapsing buying power. The Trump administration has also presided over a titanic increase in state-aligned, privatized surveillance. The Trump years are the Flock years:
https://newrepublic.com/article/206992/flock-safety-cameras-alpr-deflock-resistance-nationwide
The Trump years are the Palantir years:
https://www.nytimes.com/2025/05/30/technology/trump-palantir-data-americans.html
The Trump years are the facial recognition years:
https://www.aclu.org/news/privacy-technology/ice-face-recognition
Trump's authoritarianism is a function of his misrule, and his misrule is enabled by his authoritarianism. The more he steals, the more he destroys with wars of choice, and incoherent tariff policies, and official pronouncements linking autism and vaccinations, the more he needs spy cameras, internet surveillance, vehicle tracking, and facial recognition. Every time Trump talks about a third term in office, or canceling elections, or suppressing the vote, he creates demand for mass surveillance to catch and imprison the people this drives into the streets. The more mass surveillance there is, the safer it is for him to commit unpopular, corrupt acts. It's the world's worst self-licking ice-cream cone.
It's not just Trump, of course. Trump is the vanguard of a movement of orifice lottery winners whose delight in stealing, cheating, maiming and despoiling gives rise to political instability and requires them to divert some of their yacht money to mercenaries:
https://theintercept.com/2026/06/25/police-luigi-mangione-wealthy-ceos-threat/
Take AI: the Trump years are also the AI years. This is the time in which a wildly unpopular technology is being shoved into every part of every app we rely on:
https://pluralistic.net/2025/05/02/kpis-off/#principal-agentic-ai-problem
It's an era where corporate bosses can't stop gloating about how many jobs they're planning to destroy and how many paycuts they plan on imposing on the surviving workers:
https://www.axios.com/2025/05/28/ai-jobs-white-collar-unemployment-anthropic
AI can't do your job, but an AI salesman can reliably convince your boss to fire you and replace you with an AI that can't do your job:
https://pluralistic.net/2025/03/18/asbestos-in-the-walls/#government-by-spicy-autocomplete
And – most visibly – it's an era in which people's cities and towns are being despoiled by data centers they don't want, by local governments operating in the most extreme secrecy, who silence and even arrest citizens who demand a democratically legitimate process for deciding whether they will have to give up their power and water and land and peace:
An economist would tell you that there's an equilibrium being sought here: between the cost of bribing a town council to ram through data center approvals, the cost of building a more modest and palatable data center, and the cost of mollifying public critics. The cost of bribing towns to foist a data center on the townsfolk is low, because there are lots of towns that fit the bill, so data center barons can shop around.
But as data center protests grow larger and better organized (oligarchy is destabilizing), the cost of dealing with public opposition is mounting. Which is why the Trump administration is teaming up with its preferred tech and military contractors to engage in detailed surveillance of data center and AI critics:
These corporate spooks aren't just spying on data center critics: they've got a whole portfolio of oligarchy-stabilizing surveillance services, targeting "antifa," immigrants' rights and anti-ICE groups.
They're joined by hardware vendors who offer corporations, the wealthy, and enclaves where both are to be found on literal robocops, the ultimate in cheap guard labor (alas, the robots suck):
https://www.404media.co/the-roboguard-revolution-is-short-circuiting/
Trump and his orifice-winning army are caught in the same trap as the leaders of the GDR. Every gain in guard-labor efficiency creates the space for more of them to stick more of their hands even further into the cookie jar. Every time they do, American society grows more unstable, demanding more guard labor.
As we saw in Minneapolis, guard labor – be it mass surveillance, robocops or ICE chuds – is itself destabilizing. Police states make the people who live in them want to overthrow the state, requiring yet more cops, creating more partisans for tearing the whole thing down.
In theory, the orifice class could decide to stop stealing, cheating and maiming. The problem is that for every plute who realizes that the cheapest way to keep the guillotines off his lawn is to play fair, there are three more who lack the executive function to stop cheating. That means that you might as well keep on cheating, since the instability – and the guard labor bills – are coming no matter what.
In the tale of the "Tragedy of the Commons," a common pasture is grazed to dust by shepherds who each understand that if they don't graze their flock until everything is gone, some other shepherd will do so. The original "Tragedy of the Commons" paper was a racist hoax perpetrated by an academic fraud who wanted to make the case for the expulsion of black and Brown people from America and their mass extermination abroad:
In reality, commons need not be tragic and many of our most important resources have been managed as commons for hundreds of years:
https://archive.org/details/governing-the-commons/page/4/mode/2up
But when it comes to the commons that is "a stable society," the orifice class is caught in an inescapable tragedy, certain of the knowledge that if they don't cheat us, the next American aristo will. Thus the demand for guard labor continues to mount…as does the demand for guillotines.

Zack Polanski Promotes Radical Plan to Break Up Britain’s ‘Billionaire Media’ https://bylinetimes.com/2026/08/10/zack-polanski-promotes-radical-plan-to-break-up-britains-billionaire-media/
Subaru Socialists and the Great Disappointed https://www.newyorker.com/news/fault-lines/subaru-socialists-and-the-great-disappointed
Not your imagination: from backpacks to food, consumer goods are getting worse https://www.theguardian.com/us-news/2026/aug/10/consumed-consumer-goods-quality?CMP=GTUS_email
LAST CALL FOR HOPE 26 TICKETS https://www.2600.com/content/last-call-hope-26-tickets
#25yrsago Wonderfully thorough backgrounder on DeCSS https://web.archive.org/web/20010816194008/https://lemuria.org/decss/hal2001.html
#25yrsago Warhol Worm https://web.archive.org/web/20010814171036/http://www.cs.berkeley.edu/~nweaver/warhol.html
#25yrsago Camgirls use Amazon wishlists for payouts https://web.archive.org/web/20010821234935/http://www.salon.com/tech/feature/2001/08/13/cam_girls/index.html
#25yrsago State of the tech industry 2021 https://web.archive.org/web/20011216222920/http://latimes.com/technology/la-000064605aug09.story
#25yrsago List of scenes cut from Looney Tunes reissues https://web.archive.org/web/20011214095249/http://www.toonzone.net/looney/ltcuts/
#20yrsago Strategy behind using liquids to threaten planes https://web.archive.org/web/20060813001626/https://wondermark.com/d/220.html
#20yrsago RIAA to grieving family: We depose your children in 60 days https://recordingindustryvspeople.blogspot.com/2006/08/riaa-wants-to-depose-dead-defendants.html
#15yrsago Stasi spywear: the inept art of commie disguise https://web.archive.org/web/20120000000000*/http://www.spiegel.de/international/germany/0,1518,777716,00.html
#15yrsago 1968: when Britain’s Daily Mirror tried to overthrow Parliament https://www.bbc.co.uk/webarchive/https%3A%2F%2Fwww.bbc.co.uk%2Fblogs%2Fadamcurtis%2F2011%2F07%2Fevery_day_is_like_sunday.html
#15yrsago My panel with Tim Berners-Lee, Vint Cerf and Al Gore at Mexico City’s Campus Party https://www.youtube.com/watch?v=tXPZnpsN4-s
#15yrsago Doctor tried to "cure homosexuality" by tasping gay man while he had sex with a female sex-worker https://web.archive.org/web/20111004080028/https://blog.ketyov.com/2011/08/self-stimulating-brain-for-heterosexual.html
#10yrsago How a digital-only smartphone opens the door to DRM (and how to close the door) https://memex.craphound.com/2016/08/12/how-a-digital-only-smartphone-opens-the-door-to-drm-and-how-to-close-the-door/
#10yrsago Forget Skynet: AI is already making things terrible for people who aren’t rich white dudes https://www.nytimes.com/2016/06/26/opinion/sunday/artificial-intelligences-white-guy-problem.html
#10yrsago How self-driving cars could make everything worse, and what to do about it https://web.archive.org/web/20170918192128/https://www.wired.com/2016/08/self-driving-cars-will-improve-our-cities-if-they-dont-ruin-them/
#10yrsago The Tor Project’s social contract: we will not backdoor Tor https://blog.torproject.org/tor-social-contract/
#10yrsago Cash grants to people with unexpected bills successfully prevents homelessness https://www.science.org/content/article/bit-cash-can-keep-someone-streets-2-years-or-more

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
AI, automation and enshittification (Telecoms.com)
https://www.telecoms.com/ai/the-telecoms-com-podcast-ai-automation-and-enshittification
The AI Enshittification Bubble (Hidden Forces)
https://hiddenforces.io/podcasts/the-ai-enshittification-bubble-cory-doctorow/
F@#$ the AI Overlords (On The Media)
https://www.wnycstudios.org/podcasts/otm/articles/f-the-ai-overlords
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
NetBSD brings its Englightenment port up to snuff [OSnews]
Enlightenment desktop is a low on resources desktop environment without sacrificing on visuals. NetBSD support for this BSD-licensed desktop has been left a few years behind. The aim of this project is to port the newest version of the desktop to pkgsrc and commit upstream portability fixes when necessary to ease future versions updates for NetBSD.
↫ Dimitris Gounaridis on the NetBSD blog
Enlightenment seems like a natural fit for NetBSD, so I’m glad they dedicated a GSoC project to getting the existing, outdated port up to snuff. The project is not complete as there’s a few issues to work out before it can be packaged for easy installation, but this is great progress already.
Publishing schematics before “open source” was a word: 55 years of Akizuki Denshi, Japan’s legendary parts Store [OSnews]
Akihabara, Tokyo’s famous “Electric Town,” is overflowing with foreign tourists these days, drawn by anime shops, maid cafes, and duty-free electronics megastores. But there is one storefront most of them walk past without a glance: Akizuki Denshi Tsusho. It may be one of those pockets of Japan that foreign visitors never see. Step inside and the narrow aisles are packed — not with tourists, but with Japanese customers hunting for electronic parts. It is a scene that has repeated itself here for more than 50 years.
For readers outside Japan, imagine something between Adafruit, SparkFun, and a discount surplus warehouse. If you start tinkering with electronics in Japan, Akizuki’s website is the one you will open before any other. Generations of Japanese engineers, students, and hobbyists have treated it as the default source for parts, the way you might default to Digi-Key or Mouser.
↫ Gakuto Ochi and an uncredited translator
I’ve long been fascinated by places like Akizuki Denshi Tsusho and other places like it in South Korea and China’s Shenzhen. An unending labyrinth of unimaginable amounts of technology stacked floor to ceiling. Whether they be like Akizuki, which focuses on the tiniest of electrical components, or more like the malls in Shenzhen, which seem to focus more on assembled parts, the idea of browsing through them in wonder draws me in like a moth to a flame.
I’m sad these places don’t exist anymore (or in most cases, never did) closer to home, but perhaps someday I’ll have enough time and funds to visit Tokyo or Shenzen and let myself be overwhelmed by things I don’t understand, and people speaking languages entirely alien to me.
AI for Military Support [Schneier on Security]
Interesting empirical research: “Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI.”
Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empirical window into that question by deploying a high-fidelity replica of an AI decision-support system (DSS) used in military targeting. After reconstructing the interface and functionality of the real-world system, we tested its impact on combat decisions in two experiments involving 2,015 Israeli military personnel. Contrary to widespread fears of automation bias, we find strong evidence of algorithmic aversion, especially in scenarios involving high collateral damage. Yet we also show that integrating “explainable AI” features reduces algorithmic aversion and promotes more thoughtful evaluations of algorithmic recommendations. These findings challenge prevailing assumptions, revealing that trust in military AI is dynamic, varying with individual predispositions, perceived operational stakes, and the informational features of the interface. By grounding normative concerns in empirical evidence, our study offers critical insight into the integration of AI in warfare and underscores the enduring importance of human agency in high-stakes military decision-making.
Attention up for auction [Seth's Blog]
If you win an auction to get a click, you probably overpaid.
Every other bidder stopped bidding, that’s why you won.
Putting attention up for auction is a good business model—for the seller.
How can I perform a CopyFile in unbuffered mode? [The Old New Thing]
A customer was copying a file with CopyFile,
but they wanted the file handles to be opened as
FILE_FLAG_NO_BUFFERING.
We saw some time ago that
you can use the progress callback to
CopyFileEx or CopyFile2
to flush the output handle. Maybe we can use the progress
callback to open the handle as unbuffered?
Nope, that doesn’t work because the progress callback gives you the already-opened handle. You can’t change its buffering flag after the fact.
But that’s okay, because
CopyFileEx and
CopyFile2 also have a flags parameter, and one
of the flags is COPY_FILE_NO_BUFFERING, which means
that the handle should be opened as
FILE_FLAG_NO_BUFFERING.
BOOL success = CopyFileEx(
sourceFilePath, destinationFilePath,
nullptr, nullptr, nullptr,
COPY_FILE_NO_BUFFERING);
You can do the same with CopyFile2, but the
flags are in the options structure.
COPYFILE2_EXTENDED_PARAMETERS parameters{};
parameters.dwSize = sizeof(parameters);
parameters.dwCopyFlags = COPY_FILE_NO_BUFFERING;
HRESULT hr = CopyFile2(sourceFilePath, destinationFilePath, ¶meters);
The post How can I perform a <CODE>CopyFile</CODE> in unbuffered mode? appeared first on The Old New Thing.
A Good Day, In The End [QC RSS v2]

shoujo
Why My Father Is Wrong: A Defense Of Guitar Hero [Whatever]
My father recently wrote a piece detailing some of his
thoughts on AI, and in doing so he compared using
generative AI to playing Guitar Hero. I shall not let this
analogy stand.
If you think I’m pro-AI, you couldn’t be more wrong. There is no bigger hater of AI in the world than yours truly. So while I disagree with my father’s argument, it isn’t because I like AI, it’s because he slandered Guitar Hero. How could he even compare the two? So few things are even comparable to the absolute plague on humanity that generative AI is, and Guitar Hero should not be included in that list.
This extremely well thought out and provocative essay is only for the eyes of those who are ready to rock. So without further ado, please join me in celebrating the true art that is Guitar Hero.
(I will be referencing my father’s post a good bit, and countering specific points he raises, so feel free to refer to his post here.)
Some of you might think I’m being obtuse in contradicting my father’s analogy of Guitar Hero does not equal being a guitar player, and using generative AI does not equal creating art. However, I understand the base argument being made here is that Guitar Hero does not teach you how to play a real guitar, and that the skills that you get from playing Guitar Hero are not transferrable to the actual instrument.
My father defies his argument with his own wording: “…a non-transferrable skill…”
Skill. Guitar Hero requires skill. Therefore, Guitar Hero is fundamentally and utterly different than using generative AI. Case closed.
However, I will continue my essay, even though I have already proved my point.
While it is true that Guitar Hero does not teach you the skills to be a guitarist, it does involve the skills of rhythm, timing, and hand-eye-coordination. Auditory motor synchronization is a very important thing, you know! Research has proven time and time again how video games, including rhythm games, can create new neural pathways and strengthen your brain, whereas generative AI has proved to do the exact opposite and even actively harm our cognitive functioning, problem-solving, and even memory.
While Guitar Hero has no basis claiming to be a tool for learning guitar, it never stated that that’s what it was for at all. No one ever said “play this to become a guitar player.” The point of Guitar Hero was never to make you a guitarist. It never boasted claims of doing so, so why are we saying, “well, it doesn’t make you a guitar player.” I know that! Everyone who plays the game knows that!
And, if someone claimed that they were a guitar player, and then tried to make money by booking gigs as a guitar player, there would be some real consequences and mockery involved. Yet, this is not the same for those who use generative AI. Many businesses and establishments get away with using AI flyers for their events or images, and while some people on Instagram may say boo in the comments, they face no meaningful, real world consequences.
I’d also like to counter my dad’s choice of words in saying, “Like Guitar Hero, AI is fun to play with…” First of all, no it isn’t. Second of all, one is an actual game with the purpose of being entertainment, the other is a water-sucking demon that steals art from real artists.
You don’t sit around your friend’s dorm room procrastinating an essay just to prompt AI to “make art,” you hang out and play games and have fun! And one of those games for me was Guitar Hero 3 for the Wii. The amount of time I spent progressing from easy to expert is not to be understated. My skill actually grew, my ability to play the game well actually grew. And I did it with my friends by my side, all of us having so much fun. There is no bonding connection like that with generative AI.

As you can tell by my very concentrated face, this was an activity to do together. Be rockin’ together. AI disconnects us from each other and isolates us, not brings us together like Guitar Hero.

(Look at that joyful smile.)
Guitar Hero was a creative and innovative project made with love by real humans. My dad mentions that Guitar Hero uses actual licensed music and paid actual people and artists to make and design the game. Every aspect of the game is pure human. Already this is so much better than and has a more positive effect on the world than generative AI, which wrongfully steals art and puts people out of jobs. And makes ugly event flyers!
The fact that Guitar Hero had thought and intention and love put into it makes it the polar opposite of generative AI. The fact that people can play it at a party and impress people with their skills (whether you think they’re valuable skills or not) and make them cheer or laugh is such a human connection that generative AI can’t replicate. When someone shows me generative AI “art” I want to Old Yeller myself. Comparatively, like my dad said, “…if you could get through the entirety of “Through the Fire and the Flames” on expert level, you were a friggin’ god.”
Listen, nobody walks around saying they’re a guitar player just because they play Guitar Hero. But people do walk around saying they’re artists when they’re not. More importantly, people who played Guitar Hero never tried to scam people online and make a profit, whereas there are plenty of people making a profit off low-quality, generated AI images and products that they scam people with.
Using generative AI is bad for the environment. I can’t really say the same about Guitar Hero (I say it like that because in some capacity, yes the electricity required to play the game, as well as the construction of the console and controller, negatively impact the environment, but it’s just not at the same scale and rapidness that AI data centers are ruining things.)
All hail Guitar Hero!

Long story short, Guitar Hero was never advertised to people as a learning tool to learn guitar, and those who played never claimed to be guitarists or profit off of it. Guitar Hero is a human made form of entertainment meant to be fun with your friends at parties, and no one loses their jobs over it, or their tap water.
Generative AI is bad, and Guitar Hero is fucking awesome.
Rock on, bitches.
-AMS
Dismiss Church’s Trademark Lawsuit Against “Mormon Stories” Podcast, EFF Urges Court [Deeplinks]
Imagine if McDonald’s could use trademark law to control how you use the term “fast food.” Or if the Canadian government could stop you from using the word “Canada” in the title of a book about the country and its people. That wouldn’t just be absurd; it would be an unacceptable obstacle to criticism of and commentary about those institutions. Yet the Church of Jesus Christ of Latter-day Saints (the “LDS Church”) has a track record of claiming exactly that kind of authority over the word “Mormon,” using the threat of expensive litigation to pressure speakers into compliance.
We at EFF have opposed the LDS Church’s abuse of trademark law for over a decade. In 2014, we filed an amicus brief when the church sued an online dating service for church members called Mormon Match. In 2016, it threatened legal action against our client the Mormon Mental Health Association, a nonprofit association for mental health professionals who work with members of Mormon faiths. In 2025, the church tried to pressure our client Burke Sorenson into changing the name of his Mormon News Roundup podcast. Now, the LDS Church has brought a lawsuit over a podcast called Mormon Stories that examines Mormonism and Mormon culture. With the help of attorneys at Ballard Spahr, EFF has filed an amicus brief in the case.
Our brief urges the district court to dismiss the case as soon as possible. Trademark is supposed to be about helping consumers identify the sources of the products they buy, not controlling criticism. That’s why our brief asks the court to use a test that’s more protective of speech than what’s applied in most trademark cases. This test, known as the Rogers test, has been adopted by many courts (but not yet this one) for cases where someone is using a trademark as part of an expressive work, rather than just as a brand name. We explain to the court that the Rogers test is an important First Amendment safeguard in part because it makes it easier to throw out meritless trademark claims before the most expensive parts of litigation, allowing more speakers to confidently stand up for their rights.
Our brief goes on to explain that First Amendment safeguards are especially important in cases like this one, where a plaintiff is seeking to control the use of a common term for its common meaning. Trademark law isn’t even supposed to extend to generic terms, and for good reason. Otherwise, we risk giving trademark owners power to control discussion and debate over entire topics.
It’s about time that a court shut down the LDS Church’s trademark bullying. We hope the court will do so here, while also taking the opportunity to endorse the Rogers test.
GNU poke 4.90 pre-release is available [Planet GNU]
GNU poke (http://www.j ...
rch.net/poke) is an interactive, extensible
editor for binary data. Not limited to editing basic entities
such
as bits and bytes, it provides a full-fledged procedural,
interactive programming language designed to describe data
structures and to operate on them.
GNU poke 4.90 pre-release is now available at
https://alpha.gnu
... /poke-4.90.tar.gz
The tarball is signed and you can get the PGP signature at
https://alpha.gnu
... e-4.90.tar.gz.sig
The planned date for releasing 5.0 is Sunday 15 August 2026,
but
this may change depending on the amount of problems found in
this
pre-release, and the subsequent needed additional pre-releases.
Please report any problem found with the pre-release, comments
or
patches to poke-devel@gnu.org.
In behalf of the poke developers, thank you!
Happy testing!
Mohammad-Reza Nabipoor
Urgent: News coverage of subpoenas to Breakthrough News [Richard Stallman's Political Notes]
US citizens: call on news media to cover the subpoenas to Breakthrough News as an attack on freedom of the press.
Urgent: Block scheme for making deportation profitable [Richard Stallman's Political Notes]
US citizens: call on Congress to block the bully's scheme for making deportation profitable for some of his backers.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Terminate bully's NSPM-7 political persecution crusade [Richard Stallman's Political Notes]
US citizens: call on Congress to terminate the bully's NSPM-7 political persecution crusade.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Military contracts where corrupter personally profits [Richard Stallman's Political Notes]
US citizens: call on Congress to investigate military contracts in which the corrupter and his family would personally profit.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Stop Florida spying on wildlife advocates [Richard Stallman's Political Notes]
US citizens: call on Florida's legislature to stop the state from spying on wildlife advocates.
Block Paramount media takeover [Richard Stallman's Political Notes]
US citizens: call on Congress to block the Paramount media takeover.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Stop bully's bombing of civilian boats [Richard Stallman's Political Notes]
US citizens: call on Congress to stop the bully's illegal bombing of civilian boats.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Amazon contracts with deportation thugs [Richard Stallman's Political Notes]
US citizens: call on Amazon to end its contracts with the deportation thugs.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: Stop CHEATERS Act [Richard Stallman's Political Notes]
US citizens: call on the House to pass the Stop CHEATERS Act to restore Biden's increased funding to making rich people and corporations pay their taxes.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Defund Flock's Orwellian camera network [Richard Stallman's Political Notes]
US citizens: call on Tell Congress to defund Flock's Orwellian camera network!
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Pass Social Security 2100 Act [Richard Stallman's Political Notes]
US citizens: call on Congress to pass the Social Security 2100 Act.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: No Pretend Intelligence data centers on federal lands [Richard Stallman's Political Notes]
US citizens: call for no Pretend Intelligence data centers on federal lands!
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Bits from Debian: DebConf26 Local Team says goodbye [Planet Debian]

On Saturday 25 July 2026, the annual Debian Developers and Contributors Conference came to a close. The Debian Press team would now like to share this personal and beautiful message from the Santa Fe Local Team.
DebConf26 is over, and those of us who were part of the Local Team are trying to return to “normality”, if such a thing exists after organizing a DebConf.
This event changed our lives and would not have been possible without the help of many great people.
We would especially like to thank everyone who became part of our extended local team. Our endless thanks go to Gunnar —who also instigated this whole adventure—, Santiago, Nattie, Stefano, and Olasd. Thank you for supporting and guiding us, sharing your experience, and helping us find solutions throughout the entire process.
It was also made possible thanks to the great work, strong support and patience of international teams: Fundraising, Bursaries, Content, Video, Treasury, Visa, Website, Accommodation, Front Desk, Cheese and Wine, Publicity as well as all the other teams and individuals who contributed. We apologize if we have forgotten to mention anyone; many people helped make this event possible.
Our deepest thanks also go to everyone who joined us in working on the event, especially Fer, José, and Julián, who showed great commitment and took responsibility for several important tasks.
We would also like to extend our gratitude to FICH, the Universidad Nacional del Litoral, the institutions, organizations, sponsors, suppliers, and everyone who contributed in one way or another to welcoming the Debian community to Santa Fe.
And finally, a very special thank you to our families, to whom we dedicated little time these past few weeks, who supported us on this adventure, enduring the exhaustion, the calls and messages at all hours, and the occasional stressful situation. Always giving us that much-needed, encouraging hug with so much love.
These were very intense weeks, during which we tried to give our best so that everyone could enjoy their stay and so that the Debian community had the necessary conditions to meet, work, share knowledge, and continue creating the magic that characterizes community life and the development of Debian.
As happens at every DebConf, there were difficulties, unexpected situations, and challenges that required us to improvise, learn, and perform a few juggling acts. There were also moments that will certainly remain as memorable anecdotes: the “antisocial room”, some gas heaters worthy of a museum, and newly unlocked powers for negotiating with suppliers.
We have no evidence, but also no doubt, that for many people the Conference Dinner was one of the best moments of the event.
A few ingredients we had hoped would happen naturally were missing, such as more wine nights and at least one in-person football match.
During the two weeks of DebConf, we experienced every kind of weather and a wide range of emotions. Above all, however, we saw people enjoying themselves and building friendships, which fills us with pride.
Thank you very much to everyone who came and helped DebConf26 leave such a beautiful mark on our hearts.
We hope our paths cross again somewhere in life.
Best regards,
Leonardo, Emmanuel, Mariano, Pablo, and Martín DebConf26 Local Team
The Debian Project was founded in 1993 by Ian Murdock to be a truly free community project. Since then the project has grown to be one of the largest and most influential Open Source projects. Thousands of volunteers from all over the world work together to create and maintain Debian software. Available in 70 languages, and supporting a huge range of computer types, Debian calls itself the universal operating system.
DebConf is the Debian Project's developer conference. In addition to a full schedule of technical, social and policy talks, DebConf provides an opportunity for developers, contributors and other interested people to meet in person and work together more closely. It has taken place annually since 2000 in locations as varied as Scotland, Bosnia and Herzegovina, India, Korea, France. More information about DebConf is available from https://debconf.org/.
For further information, please visit the DebConf26 web page at https://debconf26.debconf.org/ or send mail to press@debian.org.
Passionate Intensity [Penny Arcade]
I think Gabe has wanted to draw Asmongold for awhile, and generally these days the thing that keeps him from doing it is that he doesn't want to draw attention to the target. Except the target in this case is one of the biggest streamers on planet Earth. He can't actually be obscured; the strip is about his most recent fourteen day ban, but having been banned as often as he is, this is just part of the business model. The video he made in response to the ban will probably have three million views by the end of the day. You get kicked out of one place, and somebody else is always there to monetize your riposte. YouTube, generally - Streamer Switzerland.
Cookies are not needed for fingerprinting and tracking [OSnews]
Cookies are ancient technology, and in no way necessary of even particularly desirable to track you. Modern fingerprinting doesn’t need them at all.
A live demonstration of everything a website learns about you before you click anything with no cookies. It reads you during the connection and in the first two seconds of JavaScript, then narrates what it found back to you in plain English, as if a stranger were describing you out loud.
The argument isn’t “look how creepy this site is.” It’s: the site you visit after this one can do all of it too, and won’t tell you.
↫ Kuber Mehta
Also note, as the demonstration does, that if some of the things it determines about you are wrong, that doesn’t really matter. In fact, it may actually make fingerprinting and tracking you easier; as long as fingerprinting consistently gets the same things wrong in the same way, it becomes a valuable part of the fingerprint, like a small scar obscuring part of your real thumb’s fingerprint.
Online tracking of people should be illegal.
I Ate a Large Meal of Indian Food and Foolishly Assumed I Would Then Be Able to Function in the Afternoon, So Here is Saja and Charlie to Cover For Me While I Recover [Whatever]

The Indian food was delicious and also literally all my blood went to my stomach, causing my cognitive abilities to throttle to maybe, like, 30%, so, uh, yeah, not a lot of work done after lunch. I did take a nap, though. Which was important, I think.
Anyway, Saja and Charlie are pals. Isn’t that nice?
How are you?
— JS
Meta Must Stop Silencing Reproductive Health Information [Deeplinks]
Access to accurate information about reproductive and maternal health can be critical. But on Meta's platforms, simply talking about prescription medication, abortion care, or one's own medical experiences can be enough to trigger content removals and account restrictions.
That's why EFF recently submitted a public comment to the Meta Oversight Board in its consideration of a case involving an Instagram post about prescription drugs during pregnancy and childbirth. The case touches upon a topic we’ve been documenting for some time; last year we collected stories from individuals who had experienced censorship of reproductive health information on various platforms. Meta in particular stood out: Its moderation systems routinely fail to distinguish between prohibited drug transactions and legitimate discussion of medications, including educational information and people's firsthand experiences with healthcare.
Through our Stop Censoring Abortion project, EFF collected nearly 100 submissions from healthcare providers, clinics, educators, advocates, researchers, and others whose reproductive health content had been removed or suppressed by social media platforms. What we found was alarming: systemic over-enforcement, confusing policies, arbitrary takedowns, sudden account bans, de-ranking, and appeals that too often went nowhere.
In almost every case we reviewed, the censored posts and accounts did not actually violate the platforms' stated rules. Meta frequently cited its Restricted Goods and Services policy, which prohibits attempts to buy, sell, trade, donate, gift, or request pharmaceutical drugs. But the content EFF documented overwhelmingly consisted of factual or educational information—not attempts to sell or distribute drugs.
The consequences were significant. For example, the Miscarriage+Abortion Hotline had its Instagram account restricted and posts removed even though it was providing information about legally obtaining medication rather than offering pharmaceuticals for sale. Red River Women's Clinic and the RISE reproductive health research center at Emory University had accounts locked after posting about mifepristone.
Other users reported having their content quietly de-ranked or “shadowbanned,” limiting its reach without giving them meaningful notice or recourse. We believe educational content and people's experiences involving reproductive healthcare and medication should not be suppressed in this way.
And when Meta gets these decisions wrong, the appeals process too often fails to fix them. In several cases EFF documented, accounts were restored only after journalists drew attention to the problem or someone with a personal connection inside Meta intervened. A moderation system shouldn't require knowing the right person to get an erroneous decision reversed.
Our submission calls on Meta to make five changes—the same five changes we asked for last year.
First, Meta should publish clear, understandable policies so users can know what content is permitted and what might result in removal, downranking, or account suspension. Second, those rules must be enforced consistently and fairly. Third, Meta must provide meaningful explanations for enforcement decisions, including what rule was violated and how users can appeal. Fourth, users need a functional appeals system that doesn't depend on insider access.
Finally, Meta should expand human review. Reproductive healthcare is precisely the sort of nuanced and context-dependent subject that automated moderation systems struggle to understand. As our research shows, automated systems can mistake education for drug sales, misinterpret terminology, overlook cultural and political context, and even classify legitimate advocacy as dangerous content. Human moderators should therefore play a greater role when automated systems flag sensitive healthcare information or political expression.
Meta has chosen to allow discussion of reproductive healthcare, including abortion, on its platforms. That commitment means little if its moderation systems nevertheless prevent people from accessing or sharing that information.
At a moment when reproductive rights are under attack around the world, the stakes are particularly high. Restricting access to essential healthcare information can have profound consequences, especially for people who already face barriers to reproductive care.
Users deserve a system in which rules aren't applied arbitrarily, appeals actually work, and vital health information isn't silenced because an automated system failed to understand its context. Meta can—and must—do better.
You can read our comment in full below.
Manton: "The way I think about RSS.chat is that it’s a bootstrap for getting lots of RSS feeds to play well together, for both posts and replies. Can the web be the social network? Yes. And Micro.blog should be part of anything working toward that goal."
Jonathan Dowland: time-delayed scifi roundup feed [Planet Debian]

I enjoy reading The Guardian's monthly round-up of new SF novels, which can be found in their Science Fiction Books section, and can also be read via feed. Since the round-up is of new books, at the time the round-up is published they're usually only available in hardback.
When it comes to choosing a book to read, these days I am tending towards paperbacks: I've largely ran out of room for hardbacks. So I decided to apply a time delay to their feed. Six months is roughly enough that a book mentioned in a round-up should be shortly available in paperback.
The first obstacle was that The Guardian only publish roughly the last six months of articles in their feed, and so the posts I want have disappeared. However, my Feed Reader (FreshRSS) had older copies stored in its database, and I am able to re-publish those using User Queries. (This also gives me an opportunity to filter out non-roundup articles from the Guardian's feed).
It's then a nice short piece of scripting (this time, using Ruby) to filter the republished feed on the publication date. To make the most recent articles appear new, I also modify the metadata for filtered entries to appear 6 months newer than they are.
#!/usr/bin/ruby
require 'rss'
# replace with the user query feed URI
uri = 'https://www.theguardian.com/books/science-fiction/rss'
now = Time.now
sixMonths = 6 * 30 * 24 * 60 * 60
feed = RSS::Parser.parse(uri)
feed.items.select! do |item|
item.date + sixMonths < now
end
feed.items.collect! do |item|
item.date += sixMonths
item
end
puts "Content-Type: text/xml\r\n\r"
puts feed
I stuck that up on my private web server, subscribed to it in my FreshRSS and voila, a time-delayed list of books to read, most likely available in paperback.
Uwe Kleine-König: PGP Keysigning on Linux Plumbers and OpenSource Summit Europe 2026 [Planet Debian]
I'm going to this year's LPC and Open Source Summit Europe 🥳.
I will organize sessions on two days after the conference program to exchange PGP fingerprints for keysigning to improve the kernel's web-of-trust (but of course everyone is welcome).
For details see my announcement on LKML. Note the registration deadline at 2026-09-27 08:00 UTC.
The Base Is Under Attack [Radar]
The following article originally appeared on Tim O’Brien’s Medium page and is being republished here with the author’s permission.
At some point, the software “Security” industry stopped talking about stopping threats and started talking about detecting them: detection windows, response times, mean time to remediate. It’s not offense or prevention; it’s damage control. There’s a movie scene that captures what that sounds like, and you’re going to name the film before I finish describing it.
An underground base on a frozen planet. The enemy knows exactly where it is. Massive mechanical walkers—walking tanks the size of buildings—are advancing across the ice. The defenses can’t stop them. The people inside aren’t trying to fight back. They’re frantically trying to get a broken ship working so they can just escape—not win, not hold the line, just get out before something catastrophic and unstoppable reaches the door.
The whole opening is just people preparing. Rushing. Running checks on equipment that isn’t ready, coordinating defenses that won’t hold, buying time against something too large and too fast to stop. Nobody’s planning a counterattack.
The entire operation is: slow it down long enough to get out.
Securing the Base (Image Assist from Anthropic)
That’s what the conversation around InfoSec sounds like right now. The base is under attack. The walkers are AI-generated vulnerabilities, automated exploit chains, and speed that no human team can match. The framing has shifted from defending the perimeter to just getting the ship started. Not winning, just getting out.
Go back and watch that opening sequence carefully. There are hundreds of faceless Rebel troopers in that scene—no names, no lines worth remembering—scrambling to hold the perimeter, buy time, absorb the blow. Some of them continue to fight. But maybe some already understand that the base is lost.
Han is out on the ice looking for Luke. Leia is already on the transport, making sure the mission survives. The main characters aren’t defending the base. They’ve concluded the only way to answer the threat is to move. Most of the conversation around AI right now sounds like those faceless troopers continuing to defend: fortify what’s there, slow the walkers down, hold long enough for something to change. A few people are thinking like Han. They’re not buying another vulnerability scanner from a vendor. They’re asking whether there’s a different way off the planet entirely.
Here’s the disconnect: most people focused on “Security” have spent decades being handed a finished base and then being asked to defend it. They weren’t involved in the architecture or approach that application developers have been using.
In many cases, people responsible for security are not defining architectures as much as they are catching up. And as “developers” start to generate more code in a day than was possible in a month or a year, it’s becoming increasingly unrealistic to think of security as an afterthought.
When security is just a support team for software engineers, that’s building a base that might be indefensible.
The shift that actually matters isn’t a better scanner or a faster response team. It’s security people in the room when people are writing the prompts, when agents are assembling the dependency list, and when the basic system prompts are defining the authentication system—before any of those systems is in production. Not reviewing the finished base.
Security needs to be involved before anyone even starts to prompt a system’s creation.
“Machine speed” has become a conference catchphrase, which usually means it needs translation. Here’s what it actually looks like, pointed at you:
The whole operation, including reconnaissance, timing, and coordination, ran in seconds. What previously required a dedicated red team and weeks of planning is now background processing that runs continuously, waiting for the right moment.
Five years ago, you would have tasked a room of scary-looking security people with profiling a target, capturing latency data, and maybe holding several meetings to discuss what they found. Today, the coordination I outlined in the previous paragraph might take a few minutes on a network of interconnected Nanobot, Picobot, Hermes, or OpenClaw agents that gather data and then update a shared memory system, and the decision on when and how to attack would be made by another agent that was granted permission to coordinate the attack across a distributed network of agents.
Quick note: If you have anything to do with running a website, stop posting about your vacation plans.
Here’s what the conversation keeps missing: AI isn’t the real problem, and this problem isn’t necessarily new. The problem is that we’ve been building bases that were always going to need to be evacuated. The problem is that security is rarely involved in selecting a tech stack, and because that tech stack selection is frequently automated with AI, there’s no predicting the mess that’s being thrown over the wall.
The response to AI-accelerated attacks is almost entirely defensive. Tighten npm’s signing requirements. Fund the Maven repository. Sign up to support Akrites with the Linux Foundation. Add another scanner to the pipeline. These aren’t wrong. They’re just not enough.
These are important projects, and security groups should sign up to support them, but the real transformation that needs to happen is that more people in security need to get involved in software creation. What this looks like is having an opinion on React, Vite, Tomcat, Node.js, databases. It means jumping in and affecting some of the basic decisions that these agents are going to use before they deliver vulnerable software.
Most of the industry is still shopping for scanners. Most people in security are still “reviewing” software in a process that assumes it takes weeks or months to write.
[$] Even more formal verification for BPF [LWN.net]
BPF offers useful safety guarantees, but Kumar Kartikeya Dwivedi wants BPF programs to be even safer. At the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit, he led a session (slides) discussing the possibility of adding domain-specific invariants to BPF programs. It was not a discussion intended to lead to the implementation of any particular kernel feature, but rather an overview of why additional formal verification might be needed, and how it could work with the existing BPF ecosystem.
Django moves to an annual release cycle [LWN.net]
The Django Python web-framework project has announced that it has accepted an annual release cycle proposal. This means that the project is moving from a somewhat complicated schedule that interspersed short-lived feature releases and long-term-support (LTS) releases to a simpler annual cycle where each release is supported for three years.
Every feature release gets three years of support: one year of mainstream bugfixes, then two years of security and data-loss fixes. The "LTS" label is retired — every feature release now carries that same, unique commitment.
No more LTS gap: no racing a deadline to jump two years of changes at once. Upgrade one year at a time, whenever suits you within the support window. Three versions are supported at any time, giving third-party packages a clear, rolling target.
This will take effect with the upcoming Django 2028 release, expected in January 2028.
Security updates for Monday [LWN.net]
Security updates have been issued by AlmaLinux (firefox, gpsd-minimal, kernel, libarchive, libgcrypt, and LibRaw), Debian (bind9, ca-certificates, chromium, dnsdist, icinga2, kitty, libheif, openjdk-21, pdns, pdns-recursor, thunderbird, and xen), Fedora (bird, erlang, kernel, mingw-glib2, nghttp2, p11-kit, perl, perl-Devel-Cover, perl-PAR-Packer, pgadmin4, polymake, python-nh3, python-wsgidav, python3.12, rabbitmq-server, rust-ammonia, seamonkey, and udisks2), Mageia (python-starlette), Oracle (gnutls, kernel, and LibRaw), Red Hat (container-tools:rhel8), Slackware (wpa_supplicant), and SUSE (azure-storage-azcopy, bouncycastle, ffmpeg-4, fuse-overlayfs, gleam, gstreamer-plugins-bad, libssh2-1, libssh2_org, libwireshark19, libXfont2-2, perl-Mojo-JWT, perl-Mojolicious, podman, python310, python313-Django4, and tekton-cli).
1348: Fading Odds [Order of the Stick]
http://www.giantitp.com/comics/oots1348.html
First version of Word for Windows ported to modern 64bit Windows [OSnews]
Back in 2014, Microsoft released the source code to the first Windows version of Word, version 1.1a. Now, Justin Marshall has ported this code to modern versions of Windows, so you can run it as if it were any other modern application.
This project is a fully working native Windows x64 port of Microsoft Word for Windows 1.1a, whose historical codename was Opus. It builds the original Word source and resources together with modern replacements for the 16-bit assembly, segmented-memory, and Win16 platform boundaries.
The result is the original Word application and user experience running as a 64-bit Windows executable. This is not an emulator or a reimplementation using a modern editor control.
↫ Justin Marshall
Neat endeavour.
Idol Mahjong Final Romance: a slideshow disguised as a video game [OSnews]
Top supplier of great articles Nicole Branagan is at it again.
We’re back into the strip mahjong games today, here going back to 1991. Video System is a company that’s probably best known in retro-gaming circles for Aero Fighters/Sonic Wings, but mahjong games (usually branded Idol Mahjong) were one of their bigger moneymakers. And there’s something interesting going on here– Idol Mahjong Final Romance 2-R-4 Special re-releases the final three games in the series, which all also got contemporary console releases, but the first game in the series has never been seen outside of its original arcade launch. Why?
↫ Nicole Branagan
Look, you’re not going to get something like this from anyone else.
I have Spectrum cable and they recently started unbundling the cable services they provide. So I have a bunch of streaming services that I never decided to follow, and haven't gotten in the habit of checking them. Not sure if I like this, but I certainly understand why the bill is so high and seems to always be going higher? Not sure why that is. But it's hard to get through to them.
Anyway, one of those streaming services I get now is Paramount+ which is owned by the Ellisons, which I don't like, but they have a show that is really excellent esp if you like British crime stories, which I most definitely do, even if most of the actors are American, and it probably was recorded in Vancouver or in Queens. It's called, unimaginatively, The Agency, as in the Central Intelligence Agency. The story is fine, but what really sets it apart is the quality of the acting and production. Beautifully filmed, better to watch it on a nice big screen set with good audio. Two seasons only, but if you want to know the kind of TV I like, this is it.
I see the new Game of Thrones series just completed it third season. I tried getting into it, and couldn't. But then I didn't get going in the original series for the first few attempts. People say this show is good, so I will probably give it another try.
The Crossroads [The Daily WTF]
I moved some things around on my calendar. 4:00 PM today is open. Please come to the executive floor.-Leila
For a while I was stunned, staring at the email in front of me. I’d just told my boss I was quitting, refusing a promotion into my recently-deceased mentor Aggie’s shoes. Now, the new head of Human Resources wanted to see me.
Me? A Tech Support drone with one foot out the door? Well, she didn’t know that yet, did she?
Something in me feared where this might lead. But, Leila had stuck her neck out to rescue me from CEO Gibbs. She seemed like she cared about making things better. I decided to hear her out. Figured I owed her that much before I blew outta there for good in two weeks.
I had way too many hours to kill. Between whittling down my overstuffed inbox and resuming casework, it should’ve been easy to distract myself, but I couldn't focus on a single thing. I’d just done what had once seemed impossible. My brain wasn’t letting go of that any time soon.
Megan and Reynaldo also handed in their resignations. I got their messages confirming as much. We met up for lunch at a nearby restaurant and celebrated, but I was distracted. Amid the smiles and positive energy, the meeting with Leila was all I could think about. Should I mention it? I decided not to, not until I knew more.
I dreaded the afternoon slog now more than ever, but somehow, it slogged. When the clock’s hands finally crawled to 3:30, I threw on my coat and hat and darted out for one last smoke break. Then, it was time for C-Town.
Consumed with nervous energy, I shunned the elevator to race up the stairs floor by floor. Figured I’d burn off some stress, which could only help with whatever came next. Also figured I’d have a minute to recover in the vast executive lobby before finding my way to her office. Instead, I found Leila standing right there, every bit as polished as our surroundings. She faced me with surprise. “Hello.”
I tried to speak, laugh, something. Instead, I doubled over, coughing and gasping for air that felt all too thin up in nosebleed territory. While recovering, I couldn’t help but notice the gleaming tile beneath my feet, contrasting against my work shoes encrusted with sidewalk salt. Such details seldom crossed my mind, but the sort of people who worked up there lived and died for such details. Face flush, I cleared my throat one more time and righted myself, looking her way. “’Scuse me.”
“That was a long way up,” Leila remarked, gesturing behind herself. “I thought we could visit the observation deck. Would you like something to eat or drink first?”
Truth be told, I was already dying for another smoke. “No, that’s all right.”
“Follow me.”
She led the way through massive, quiet corridors to a small room with glass walls and ceiling. At this height, all one could see outside was a thick lead wall of fog. Leila strayed up to the far wall, a jewel against the void, and glanced back over her shoulder with chagrin. “I’m sorry, the view’s not very good today.”
“I dunno, I kinda like it.” Something about foggy weather had always intrigued me. With the normal world gone, it seemed like anything could happen.
She beckoned me closer with one hand. I strayed up next to her right side, staring out at the shrouded view.
“I understand you and Agatha Shaw were close,” Leila began quietly. “You have my deepest condolences.”
A two-ton anvil crashed onto my nerves. My fists clenched up at my sides. I worked so hard to hold back the flash-flood of grief that I couldn’t string words together. I only trusted myself to nod.
She glanced my way, hesitating. “Would it be better if we rescheduled?”
“I’m here,” I forced out. “Whatever you have to say, say it.”
She nodded. “First: while you were out of the office, I asked Francis Bronson to hand in his resignation.”
I drew a blank on the name, and blinked her way in confusion.
“The manager who nearly destroyed a printer with his hair dryer,” Leila explained, “after I’d just made a company-wide push for everyone to respect our office equipment.”
“Oh. Hothead!” My nickname for the guy. I’d worked that case a few weeks ago, but it felt more like years. Hothead worked in HR—at least, he had. After disarming him, I’d sent Leila an email, appealing for help against someone who clearly shouldn’t have been managing a supply cabinet, much less human beings. Well, she’d delivered. A warm note of satisfaction offered me a welcome lift out of grief. “Thanks. Really.”
Leila smiled. “We make a good team, I think. Which brings me to the other thing I wanted to discuss. Something new.”
My gaze fastened onto hers with a mix of intrigue and dread.
“You and I both know how badly this place needs to change. Let’s work together and actually fix things. I want to create a Change Management team and make you Team Lead.”
I was speechless, caught completely off-guard.
“The first thing we’d do is attack our company-wide leadership problem. Audits, surveys, hearings … eventually, a reorg. Along with simplifying the corporate structure, we’ll get rid of all the—Hothead, you called him? All the other Hotheads.”
“The biggest hothead is sitting at the top of the whole rotten pyramid,” I blurted. “He ain’t budging. He ain’t signing off on this, either!”
Leila was unfazed. “I think we could frame everything in a way that makes Mr. Gibbs like it. After all, we’re reducing payroll. We’re better positioning ourselves in a tough economic time. Worst-case, we could always use the three magic words: Google Did It.” She smirked.
I couldn’t help smirking back. Then I remembered what I’d done just a few hours earlier. “But I’m outta here. I quit! Put in my notice this morning!”
Leila nodded calmly. “Do you have a new position lined up somewhere else?”
“No. I'm going freelance with friends.”
“Friends who are leaving the company along with you?”
I nodded.
She paused for thought. “If you were to lead my Change Management team instead, you’d be able to recruit internally for your team. Whoever you think would be the most helpful. You’d set the agenda for whatever’s most important to address so that other good people don’t feel like they have to get away from here. All of this would mean a promotion to Director, with a salary and benefits to go with. And if you need more bereavement time, I could arrange an indefinite leave of absence until you feel ready to come back.”
The breath died in my throat. Had I suffered a stroke? I must’ve had a stroke. No, she really said it. She was on the level. I could change things. I could hire my friends to help me do it. A raise, full bennies, working with her every day?
Only a fool would refuse. And yet, my gut ached at the idea.
I stood there, frozen and mute, until I remembered something in my trench coat pocket: RD, the rubber duck I’d miraculously rescued from Aggie’s former office. I reached into my pocket and seized him in my fist.
RD? Aggie? I thought. Whoever’s listening. It all sounds amazing. I know she means it. But … it’s another trap, isn’t it? Staying in this joint for any reason means betraying myself. Betraying everything.
“Listen,” I finally said, “I’m flattered you even offered, but it ain’t right for me. Don’t give up on your idea! I’ve got friends here with ideas of their own for changing things. 32-hour work weeks. The end of free overtime. A union. I’ll send ’em your way. Offer them a spot on your team.”
Leila sighed. “A union would be an especially tough sell to Mr. Gibbs, but that really is a case where Google Did It. We might scare him so much with that idea that everything else would seem harmless in comparison.” She faced me with a sad smile. “A shame that we’re losing you. I was starting to learn some interesting things about printers.”
I’d miss her, too. And yet, I was feeling surprisingly great about my refusal.
“Make sure you file for unemployment,” she said. “We won’t stand in your way.”
I offered my hand. “Thanks for everything, Leila. Whenever it is they kick you outta here for good, come find me.”
She shook, sad smile persisting. “Maybe I will.”
I told Megan and Reynaldo about the new Change Management team. Made sure they knew the offer was on the table in case they preferred that over jumping ship. Both were quick to say no. Like me, they were too excited about our plans to stop now.
For the next couple of weeks, there was still plenty of work to be done: transferring my open tickets to other support reps and all that. But there was barely any time for it. Coworker after coworker stopped by my cube to express their surprise and wish me well in whatever came next.
“You’ll never be problem-free,” one of them advised me. “Go looking for the problems you want to have.”
I felt happier, freer, more determined than I had in ages. It was the conviction of knowing I’d stuck to my guns to do the right thing for myself.
Sanjay also jumped ship to join us. And there was one last surprise that came in the form of a phone call. The name on my work phone’s caller ID was DRACORA, P. So-called “Dracula!” Having a fairer opinion of her than most, I picked up without any sense of dread.
So-called “Dracula!” She hadn’t been so bad at all. Surprised, I picked up in a hurry.
“I’m so sad to hear you’re leaving!” she said. “What kind of freelance work are you doing?”
“All sorts of IT projects,” I replied. “Maybe some consulting on the side.”
“I have a friend who needs help setting up a website for her business. Is that something you could help her with?”
My eyes flew wide open in shock. “Sure!”
“I’ll put you in touch with one another.”
“That’d be swell. Thanks!”
We exchanged contact info. She promised to keep pointing friends our way whenever she could.
On my last day, I sent my personal contact information to my coworkers. I reminded them of Leila’s offer and urged them to keep me posted on their different causes. Then my friends and I walked out of a building that no longer had a hold over any of us.
It felt pretty damn swell.
Our accountant helped us incorporate RD IT Solutions. Only close friends knew it stood for “rubber duck.” The company covered medical and other relevant expenses for everyone. There was no hierarchy. Everyone had equal financial stakes and an equal say in company decisions.
After decades of being an expert at what I did, I was back at square one, learning the ropes. So much of what we had to learn for our business could only be learned through failure. Still, it felt rewarding to challenge my brain in new ways. The new gig let me wear lots of hats, from tech support to coding to business admin.
With no more regular paychecks, we had to tighten down our finances to what was critically important. We worked remotely at whatever times worked best for us, with the occasional meet-up at a public place or someone’s home. We all knew that any one of us having some kind of trouble could count on the rest of the group to help out as best as they could.
Megan quit smoking again. I cut way back myself. Wasn’t trying to, I just haven’t felt the need as much. Also stopped having those nightmares. It no longer feels like I’m living just for time off and weekends. I don’t spend my Sunday nights dreading Monday.
Dracula really did introduce us to our first client. It’s crazy what the universe puts out there when you go looking for it.
We met up remotely for our first client meeting to discuss requirements and expectations. When the topic of deliverables came up, our client scrunched her nose and interrupted Megan mid-sentence. “I don’t trust email! I’d rather you fax me the files.”
We were building a website for her.
“You mean, the source files?” Megan soldiered on bravely.
“Just fax me the codes,” the client said. “My nephew can re-type them into the Internet.”
She provided a fax number, fully expecting us to print out several hundred lines of code to send over. After deploying our first stab at a website that met her requirements, we did just that, mostly out of curiosity.
A few days later, she called us in a huff, saying her website looked like random letters. Her nephew had typed the code into Facebook.
FIN
Issue 47 – Greta’s Wedding Pt. 2 – 12 [Comics Archive - Spinnyverse]
The post Issue 47 – Greta’s Wedding Pt. 2 – 12 appeared first on Spinnyverse.
What was that book? [Judith Proctor's Journal]
Someone one my friends list recced a book that was recommended by both Anne Leckie and Kathryn Addison.
The book sounded interesting as well.
But I can't find the post, and I can't remember the name of the book...
Help!
Python Now Has a Post-Quantum Encryption Library [Schneier on Security]
Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyca/cryptography.
Remember, the reason to do this now is because there’s no emergency. And because you will make your systems crypto agile, which is always a good idea.
Why Open Source Matters for AI [Radar]
In 1995, the question in the media was whether Netscape or Microsoft would control the web. The answer, it turned out, was neither.
Both Netscape and Microsoft aimed to dominate the web server and browser market, reasoning that whoever controlled both ends of the connection would have an internet “platform” to rival the deathgrip that Microsoft had enjoyed on the personal computer. The two companies raced to build every feature they could think of directly into the product, on the theory that whoever built the most integrated and full featured web server would win.
The open source Apache web server took the opposite bet. It stayed a web server with a clean extension layer, so anyone could bolt something new onto it without asking permission or waiting for the next release cycle. Within a few years, Apache was far and away the most popular web server, and Netscape’s server and Microsoft’s Internet Information Server (IIS) were history. People started talking about the LAMP stack: Linux, Apache, MySQL, and (Perl | Python | PHP) as a legitimate platform. Modularity, not features, was the moat. The fact that major elements of that stack survive while others have been swapped out or extended is a testament to the power of composability and distributed innovation.
I called that pattern the architecture of participation when I wrote about it in 2004. I was trying to explain an inconvenient fact that the licensing debates of that era ignored. I had started working with Unix in the System III days, and saw how it had succeeded as a collaborative project even though AT&T offered Unix under a proprietary license. A few years later, I observed that nominally open source projects like OpenOffice with monolithic architectures never built much of a community. I realized that open source wasn’t just about licenses, but about architecture. A small kernel with standard interfaces that lets people extend your work without asking for permission is an important part of the secret sauce.
Swap out Netscape and Microsoft for OpenAI and Anthropic in this story, and perhaps you can see the echoes.
A model’s personality, its defaults, and its history used to live where you could, with a little effort, see them and edit them. Increasingly, they don’t. As Drew Breunig pointed out to me the other day, each new version of the frontier models moves a little more of the product’s behavior out of an editable layer and into the weights themselves, where nobody outside the lab can see it, let alone change it. The model stops being a component you build with and can adjust to your liking and starts being an appliance you rent. Post-training is important but Drew points out that it is also “trading diversity for reliability.” That’s a good trade for many people, but it is the same kind of trade that gives us highly processed foods when we know that “real food” is better.
The public debate about open source AI seems devoted far too much to model weights, their national security implications, and whether a lab releases weights and under what license. But that covers only a fraction of what actually makes open source matter. Apache was never competing with Netscape and Microsoft (and Linux was never competing with Windows) over whose source was more available. They were competing over something more important. I remember talking with Bob Young, the founder of Red Hat, about his business model, and he said “What we really sell to our customers is control.” Open source meant that the platform your application depended on was no longer a sealed box you licensed from one company but a layer you could extend and build a business on top of without asking anyone’s permission. It sparked an explosion of innovation. It enabled companies like Google and Amazon to grow up free from Microsoft’s dominant paradigm.
Every wave of computing, from mainframes to PCs to the internet, has run through the same cycle: distributed innovation at the start, with the eventual winner gradually closing down its offerings to build a moat. What keeps a market open isn’t the license on any single component. It’s how easy it is to swap out one component for another when a better one appears.
The protocols connecting the pieces are an important part of that picture. Unix utilities expected stdin and stdout, and the shell acted as a kind of harness to connect them, so it was easy to build a new tool that worked seamlessly with existing ones. A testament to the power of that approach is just how much the shell and Unix utilities are the lingua franca of agentic tooling today, more than 50 years after they were invented! TCP/IP, HTTP, and other internet protocols played a similar role in keeping the internet open and composable.
Fortunately, so far, we are seeing some wins for composable, protocol-centric architectures in AI. Anthropic’s Model Context Protocol was a disruptive move in that direction, an open standard for letting any application reach any tool or data source without a custom integration for each pairing. Along with other open protocols, MCP also now has a home outside of Anthropic at the Agentic AI Foundation (a subproject of the Linux Foundation), which is at least a partial guarantee of its independence.
Isobel Moure, Ilan Strauss, and I made the case earlier this year in Protocols and Power that as models commoditize, competition moves up the stack to context. Opening the means of accessing that context opens the market, regardless of whether open or closed weights sit underneath it. That’s an unbundling, model from harness from context, done the way Apache unbundled web server from web application.
Agentic skills may also be a critical element of the open source AI future, though as the history of the LAMP stack shows, they may fall by the wayside in the same way that Perl and PHP did. And that’s just fine. Composability means that it’s easy to switch to something better when it comes along, or when more people agree on it.
There’s also a lot of great work going on in portable memory from players like Letta, Nous Research, and others. Open source agentic harnesses like Goose and Pi are also a big part of giving power back to the people. Pi in particular is optimized to be modifiable. There’s a fun story told about Mario Zechner’s decision to give Pi a “/quit” command rather than an “/exit” command like Claude or Codex. Countless issues and PRs have been submitted to Pi’s repo, asking for or implementing “/exit”, but Zechner is stubborn. His retort is that you should just ask Pi to add it to your install.
But the projects I listed above are just the tip of the iceberg when it comes to the scale and scope of open source AI. Current AI’s Open Source Gap Map covers more than 24,600 open source AI projects!!, with 421 of them scored in depth across openness, capability, and adoption. The map organizes the stack into three layers: 1) models and associated elements including data sets, fine tuning tools, inference frameworks like VLLM, and evals; 2) the product and UX layer, including harnesses and personal agents; and 3) the infrastructure underneath, including core ML frameworks like PyTorch, deployment tools like Ollama, and edge hardware.
Current AI itself is a public-private partnership that came out of the AI Action Summit in Paris last year. This summer they announced AI Potluck, which they describe as “a public project to build a vertically integrated AI product assembled entirely from open source components… a viable alternative to proprietary AI that isn’t owned by any one company or country.” It is backed so far by roughly $400 million of a five-year, $2.5 billion commitment from the French government, tech companies including DeepMind and Salesforce, and major philanthropies including Omidyar’s AI Collaborative, the Macarthur Foundation, and the Ford Foundation.
The fact that this organization exists, along with others like the Agentic AI Foundation, is a testament to the rising tide of interest in open source AI. The coalition of interested parties also says a lot about the underlying motivations that are driving that interest: AI sovereignty, corporate independence from the overweening ambition of the major labs, and an interest in technology for the public good.
There’s another element, which Drew Breunig put his finger on in our conversation the other day. The problem with having one or two big closed models dominating AI, and having those models increasingly locking their desired personality, business goals, and guardrails into the weights themselves, is that they will reduce the diversity that is at the heart of innovation.
It’s our job, Drew said, to make it weird, to push a model deliberately out of distribution rather than to settle for whatever the labs have made the default outcome. He described how his team chose not to build in React for a recent project for exactly that reason: every model already knows React too well, so building in it means shipping the average of what everyone else was doing instead of something genuinely their own. He has started using GLM and Kimi not to save money but because they are more malleable and take direction better inside a custom harness. And he wants the open-weight ecosystem to survive precisely so that models stay infrastructure rather than becoming appliances.
That’s what an architecture of participation is actually for. We need real separation between the model, the harness, and the application, so that someone who wants to build something weird can still do it without a lab’s roadmap and guardrails deciding whether they’re allowed to.
“Weird” may make it sound like something that not all developers might want. But we’re really talking about something intensely practical. In his short essay on trading reliability for diversity, linked above, Drew Breunig put it this way:
Labs have to ship a product that delivers “good enough” results when a layperson gives a model a lazy prompt. Without direction, the model must return something decent. (If it’s a website it’ll use the Inter font, cards with a single colored border, gradients, implemented with ReAct and Tailwind). Anthropic named this default output “distribution convergent.” At CAIS, @trq212 put it well, roughly, “If it’s not in your prompt, you’re getting what’s in-distribution” …. Less diverse models make for more reliable coding agents, but they encourage a monoculture of output.
Addy Osmani, my co-chair of the O’Reilly AI Codecon, took this point beyond model diversity after reading a draft of this piece: “Almost nobody I work with is tinkering with weights, but they’re rewriting the harness and what sits around it pretty constantly—skills, subagents, hooks, context files etc etc. That’s where participation is currently happening.” Addy went on to note that forking a skill instead of adopting the default, memory and constitution files that travel with the agent instead of living in a vendor account, or picking the unfashionable framework on purpose are all areas where ease of modifiability matters to everyone.
I want to end by returning to the Apache story. I believe that the big labs are making the same strategic mistake that Netscape and Microsoft made in the mid 90s. Yes, make the models more reliable for ordinary users. But don’t shut down the options for developers who don’t work for you to push the state of the art forward. As Bill Joy put it decades ago, “No matter who you are, most of the smartest people work for someone else.” No one should have a monopoly on innovation, and no one should be building a moat to hold it back.
And be sure to join us at AI Codecon: Building with Open Source AI on August 31, a free half-day virtual conference. You’ll hear from leading developers and technical experts working with open-weight models, self-hosted infrastructure, and real-world AI workflows, and learn how building in the open gives teams more control over costs, data privacy, and what they ship. Register today to save your spot.
Grrl Power #1485 – Zenithectomy [Grrl Power]
When Mt. Atrocitous was just a little butte going to Elementalry School, he got called “bismuth brain.” Also “pepto,” because apparently Pepto Bismol has bismuth subsalicylate in it? That’s why it’s called Pepto Bismol, I guess? In fact most generic Pepto is just called Bismuth Subsalicylate, or Pink Bismuth. I never thought about what’s actually in the stuff.
Anyway, they were all, “Hah, hah! Your brain is an antacid,” or “Meatsacks lick your brain when their poop isn’t viscous enough!” Or possibly, “Your brain is colorful!” Geomorphs can be cruel, and not always terribly creative when it comes to insults. Presumably their brains were formed from something else. Possibly Hoppered Galena or Fenster Quartz.
Maxima has destroyed a significant portion of a mountain once before, in her first fight with Darude. That does depend on how you define “mountain.” I’m sure cartographers and geologist might argue that point, but Max insists it was a (very small) mountain, and not a rather tall hill. It turned out to be a poor decision, tactically, because she would up freeing a bunch of granulated rock for Darude to add to his storm of sand. Or as one might say, his Sandstorm.
Oh, look who it is in the vote incentive. And a
not-quite-yet-but-it’s-coming NSFW version over at Patreon.
Vote incentive and Patreon updated with some shading. Not finished yet, but progress.
I think she would get in trouble for doing this. She’d mess up the… floor of the waterfall? Is that what it’s called? The receiving pool? No, probably not that. Anyway, she’d churn things up and cause a ton of weird erosion.
Since you might be wondering, Niagara Falls is about 165 feet high, so Babezilla obviously doesn’t have to be full sized. I’d say she’s about 175-180 feet tall here?
Double res version will be posted over at Patreon. Feel free to contribute as much as you like.
Give me one reason [Seth's Blog]
When your project, proposal or resume is rejected, it’s tempting to try to understand why.
Scrutinize the rejection letter and turn the short sentence into a paragraph or an essay, then play it over and over in your search for how to do better next time.
If you can simply answer this rejection, next time will go better.
The frustration really kicks in when the reasons begin to conflict. Too hot, too cold. Too tall, too short…
The truth is simpler: People who reject you or your work aren’t giving you the real reason. They’re simply inserting “here is where I write a few generic sentences to sound polite.”
Even if you could completely answer the objection in that rejection letter, they’re still going to reject you.
That’s because the rejector isn’t here to teach you anything, and isn’t offering the objection so that you will correct it. They’re simply being nice when they say, “go away.”
The honest rejections would say something like, “my boss didn’t like you,” or “I was in a bad mood,” or “we realized that our spec wasn’t very clear and the person we liked didn’t fit it either,” or “we wanted someone who looked more like us,” or “your competence made us nervous,” or…
Take what they wrote and replace it with “no.”
It’ll save a lot of time.
Pluralistic: The bureaucratic AI arms-race is mutually assured destruction (10 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

According to an Economist editorial, "AI is breaking the British state" by making it too easy to file complaints, demands and appeals, which will "drown the state" with "demands as well-crafted as a first-class lawyer's":
Let's pause a moment to appreciate the Economist's touching credulity about AI's coming legal mastery. The law seems to be the area where AI is most prone to "hallucinate" (that is, "produce defective outputs"), which can only be sorted through by skilled practitioners whose experience gives them the discernment to distinguish useful arguments from foolish ones:
https://pluralistic.net/2026/07/28/hitl-ers/#ai-ai-oh
(And this requires those skilled practitioners to avoid the "automation blindness" that afflicts people who are asked to remain vigilant for things that seldom occur, a phenomenon that has turned every TSA agent into the water-bottle-detectingest motherfucker the human race has ever produced, who still misses 95% of the guns that red teams bring through the checkpoint):
More notable than the Economist's faith-based predictions about the impending army of hyper-competent robo-lawyers is the magazine's proposed solution to this looming crisis: "stop creating entitlements that are ripe for AI-fuelled claims…prune the mass of procedural rights." Above all, replace the bureaucrats who process your "complaints, demands and appeals" with more AI, which will arbitrarily decide who gets what, through "personalised welfare interventions" that are not based on any kind of guaranteed rights.
Writing on his blog, the political scientist Henry Farrell tells us where this will inevitably end up: with AI-based robot wars in which increasingly stingy and pernickety robo-bureaucrats create demand for progressively more aggressive robo-lawyers:
https://www.programmablemutter.com/p/the-downside-of-robot-solutionism
As Farrell writes, this end-time was foretold by the prophet Alan Moore with his 1980s 2000 AD character Abelard Snazz, "the man with the two-storey brain":
https://en.wikipedia.org/wiki/Abelard_Snazz
Snazz "solves" the street crime epidemic on the planet Twopp with "Big Police Robots," who spiral out of control, arresting the citizens of Twopp for trivial crimes like wearing brown shoes with a blue suit ("breaking the laws of good taste"). To solve this new problem, Snazz invents "Big Criminal Robots" whose "cunning, efficient" crimes "take up all the police's time."
Twopp is left in a state of high-stakes Big Robot crimewars, in which the most efficient criminals imaginable battle the most ruthless robocops science can deliver, with the Twoppians caught in the crossfire, collateral damage in a robotic forever war (on crime).
As Farrell writes, this is already afflicting the US health system, where an army of insurance company robo-claim-deniers have been countered with a doctors' army of robot-claim-appealers:
https://www.nytimes.com/2024/07/10/health/doctors-insurers-artificial-intelligence.html
The point being that people need health care, people need public services, and while there will always be some waste at the margins (whether due to incompetence or dishonesty) responding to this by beefing up the system's defenses with more advanced red tape just requires the people who legitimately need these services to employ more aggressive tactics.
In support of this, Farrell points to a great, long essay by Dan "Accountability Sink" Davies for the Niskanen Center, "'The Problem Factory' – Preemptive risk aversion in infrastructure planning and the role of professional services":
Davies' essay describes how increasing bureaucratic defenses against frivolous or dishonest claims drives the participants in these processes to assume a war footing and approach the system as a battlefield, leading to the very runaway cost inflation that the bureaucratic process was instituted to prevent.
(Davies, a cybernetician, has some fascinating advice about how to structure planning processes to minimize this, but that's out of scope for this particular post.)
This reminds me of nothing so much as the spam wars. There was a time when it was very easy to set up a mail server and provide email access for anyone who wanted it – including spammers. Increased spam begat increased anti-spam countermeasures, notably the creation of blocklists that allowed mail administrators to automatically reject email from "insecure" mail servers.
Inevitably, spammers figured out how to send spam from "secure" servers, resulting in stricter, more onerous standards for mail server configuration. Spammers – for whom the ability to send spam is an existential matter – figured out how to meet these standards, so the security demands jumped again – and again, and again.
Today, sending and receiving mail is so technically challenging that most of the internet's email is run by a handful of giant, mostly US-based corporations. If any of these companies decides your mail server is spamming, you effectively disappear from the internet and good luck getting them to acknowledge an error. Meanwhile, these companies emit an avalanche of spam, but no one will ever block their servers, because to do so would be to cut off billions of legitimate email users:
https://pluralistic.net/2021/10/10/dead-letters/
And since most of these companies are US-based, they are liable to being weaponized by Trump, who has taken to ordering his tech giants to block foreign officials whose policy decisions make him angry:
https://carnegieendowment.org/emissary/2026/07/icc-trump-push-dismantle
Another parallel is the content moderation wars that saw the large platforms coming up with progressively more detailed rules about what constituted harassment and hate speech, only to have dedicated trolls master these rule-books. Trolls – for whom harassment was a full-time vocation – became the world's greatest experts on the platforms' speech policies, which let them skate right up to the line when abusing their victims, and to get those victims kicked off the platforms if they could be lured into putting a single toe over the line in response:
https://pluralistic.net/2022/08/07/como-is-infosec/
Farrell criticizes the Economist's answer to the (alleged) looming robo-lawyer threat as "solutionism," Evgeny Morozov's word for "Recasting all complex social situations … as neat problems with definite, computable solutions":
https://en.wikipedia.org/wiki/Technological_fix
Using AI to root AI-generated bureaucratic appeals sacrifices the system's putative purpose – delivering services – in the name of defending that service from abuse and misuse of the system's resources. As the pioneering cybernetician Stafford Beer famously wrote, "the purpose of a system is what it does." If your bureaucracy is more concerned with fighting fraud than delivering service, then it isn't a service delivery system at all – it's a service denial system.
As Farrell writes, the people of Twopp can tell you how this ends – in a war of giant robots in which we are all collateral damage.
(A brief postscript: Farrell is a font of science fictional analogies to modern policy issues. This weekend in the FT, he and Dan Wang published an excellent editorial on the relevance of the paranoid, claustrophobic fiction of Philip K Dick to our present political reality:)

Ebooks Are Coming to Libro! https://blog.libro.fm/ebooks-coming-librofm/
What Defeating the American-Israel Political Action Committee Means, on the Ground https://rickperlstein.substack.com/p/what-defeating-the-american-israel
They Live https://badtastegoodcause.com/they-live
#20yrsago Seymour Cray liked to tunnel under his house https://www.cs.man.ac.uk/~toby/writing/PCW/cray.htm
#20yrsago Fake anti-Net Neutrality groups https://web.archive.org/web/20060815175125/http://www.commoncause.org/site/pp.asp?c=dkLNK1MQIwG&b=2007877&auid=1871905&kntaw4229=C9E5C86AD89540898B5D07CB54AB0FE6
#20yrsago HOWTO fold a bottle opener out of paper https://www.youtube.com/watch?v=qrXmDiYHUY0
#20yrsago Wikipedia’s template language is Turing-complete https://web.archive.org/web/20070707115525/http://www.mentalpolyphonics.com/?p=30
#20yrsago Schwarzenegger sends Guard to California’s airports https://web.archive.org/web/20060813201014/http://sfgate.com/cgi-bin/article.cgi?f=/c/a/2006/08/11/SECURITYLOCAL.TMP
#15yrsago Marvel to comics retailers: we’ll give you limited edition singles if you destroy our competitors’ products https://web.archive.org/web/20110908023907/http://www.wired.com/geekdad/2011/08/the-great-marvel-comics-rip-off/
#15yrsago LinkedIn opts you into being used in advertisements; here’s how to opt out https://brandimpact.wordpress.com/2011/08/10/a-box-you-want-to-uncheck-on-linkedin/
#15yrsago MagicJack owner follows up his dumb lawsuit against Boing Boing with a dumb lawsuit against Women’s Professional Soccer https://memex.craphound.com/2011/08/11/magicjack-owner-follows-up-his-dumb-lawsuit-against-boing-boing-with-a-dumb-lawsuit-against-womens-professional-soccer/
#15yrsago Al Jazeera fixes its protections for whistleblowers https://www.eff.org/deeplinks/2011/08/al-jazeera-follows-effs-whistleblower
#15yrsago New Zealand Parliament may lose Internet access due to insane new copyright law https://web.archive.org/web/20110830211231/http://www.greens.org.nz/press-releases/parliament-risk-fines
#15yrsago British aviation bans all hand-luggage http://news.bbc.co.uk/1/hi/uk/4778615.stm?ls
#15yrsago Soldering is Easy: CC licensed HOWTO solder comic https://mightyohm.com/blog/2011/04/soldering-is-easy-comic-book/
#15yrsago Taxonomy of technological risks: when things fail badly https://web.archive.org/web/20190221205543/https://www.sei.cmu.edu/about/divisions/cert/index.cfm
#15yrsago Secret anti-racist shirts covertly distributed to neo-Nazis https://web.archive.org/web/20110810082217/http://www.dw-world.de/dw/article/0,,15305581,00.html
#15yrsago XKCD on the password paradox: human factors versus computers’ brute force https://xkcd.com/936/
#10yrsago American Bar Association votes to DRM the law, put it behind a EULA https://www.abajournal.com/news/article/after_strong_debate_house_calls_for_publication_of_privately_drafted_standa/
#10yrsago Trump only writes the angry tweets, the nice ones are written by a staffer with an Iphone http://varianceexplained.org/r/trump-tweets/
#10yrsago Aviation’s war on moisture turns ten today https://memex.craphound.com/2016/08/10/aviations-war-on-moisture-turns-ten-today/
#10yrsago Court rules that FCC can’t force states to repeal laws banning municipal ISPs https://arstechnica.com/tech-policy/2016/08/in-blow-to-muni-broadband-fcc-loses-bid-to-overturn-state-laws/
#10yrsago NRA is spending $3m on pro-Trump ad that says Clinton “will leave you defenseless” https://edition.cnn.com/2016/08/09/politics/nra-hillary-clinton-donald-trump-election-2016/index.html
#10yrsago Nauru files: leaks tell abused childrens’ stories from Australia’s offshore concentration camp https://www.theguardian.com/australia-news/2016/aug/10/the-nauru-files-2000-leaked-reports-reveal-scale-of-abuse-of-children-in-australian-offshore-detention
#10yrsago Why did it take a private foundation to do public science right? https://medium.com/the-spike/how-a-happy-moment-for-neuroscience-is-a-sad-moment-for-science-c4ba00336e9c#.58om85nvg
#10yrsago Profile of People’s Ride: a co-operative, driver-owned alternative to Uber https://www.democracyatwork.info/profile_peoplesride
#10yrsago The story of the story of Disneyland’s Haunted Mansion https://www.latimes.com/entertainment/herocomplex/la-ca-hc-ghosts-disneylands-haunted-mansion-20151016-htmlstory.html
#10yrsago Designer makes clothes out of German transit upholstery fabric, rides trains https://web.archive.org/web/20160808130200/http://www.bbc.com/autos/story/20160804-why-are-trains-seats-so-hideous
#10yrsago America will finally gather statistics on which and how many people are killed by law enforcement https://www.theguardian.com/us-news/2016/aug/08/police-officer-related-deaths-department-of-justice
#10yrsago Monopoly power and the decline of small business: big business vs democracy, growth & equality https://ilsr.org/article/independent-business/monopoly-power-and-the-decline-of-small-business/
#10yrsago As social media centralized, blogging’s core infrastructure has withered https://medium.com/@anildash/the-lost-infrastructure-of-social-media-d2b95662ccd3
#10yrsago 48 hours later, Adblock Plus beats Facebook’s adblocker-blocker https://www.theverge.com/2016/8/11/12439990/facebook-unblockable-ads-defeated-by-adblock-plus
#10yrsago 100 million VWs can be unlocked with a $40 cracker (and other cars aren’t much better) https://www.usenix.org/system/files/conference/usenixsecurity16/sec16_paper_garcia.pdf
#10yrsago DEA bribes rail/airline employees for tipoffs that lead to warrantless cash seizures https://eu.usatoday.com/story/news/2016/08/10/dea-travel-record-airport-seizures/88474282/
#10yrsago Trump is an object lesson in the problems of machine learning https://mathbabe.org/2016/08/11/donald-trump-is-like-a-biased-machine-learning-algorithm/
#5yrsago IRS leaks reveal billions reaped through ultra-wealthy lobbying on the tax bill https://pluralistic.net/2021/08/11/the-canada-variant/#shitty-man-of-history-theory
#5yrsago Canada's got the world's worst internet ideas https://pluralistic.net/2021/08/11/the-canada-variant/#no-canada
#5yrsago End of the line for Uber https://pluralistic.net/2021/08/10/unter/#bezzle-no-more
#1yrago Goodhart's Law (of AI) https://pluralistic.net/2025/08/11/five-paragraph-essay/#targets-r-us

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
F@#$ the AI Overlords (On The Media)
https://www.wnycstudios.org/podcasts/otm/articles/f-the-ai-overlords
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
AI and the Enshittification Era (The Weekly Show with Jon
Stewart)
https://www.youtube.com/watch?v=-dAIJRjb-Bw
AI is not inevitable (Betakit)
https://www.youtube.com/watch?v=DbiTVkq1WHo
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
Passionate Intensity [Penny Arcade]
New Comic: Passionate Intensity
Breaking Up, p11 [Ctrl+Alt+Del Comic]
The post Breaking Up, p11 appeared first on Ctrl+Alt+Del Comic.
Girl Genius for Monday, August 10, 2026 [Girl Genius]
The Girl Genius comic for Monday, August 10, 2026 has been posted.

Oh No
Elana Hashman: Managing virtualenvs with a little bash [Planet Debian]
When you need to install something directly from PyPI, Python virtualenvs have been my go-to for over a decade.
Most of my readers are probably already familiar with virtualenvs, but for completeness, I'll give you a brief introduction. A virtualenv (short for "virtual environment") is an isolated distribution of Python packages, where you can independently install packages without disturbing your system packages or other virtualenvs.
You can set one up like this, assuming you are using Python 3.3 or higher:
python3 -m venv ~/.venv/my-virtualenv
The directory specified here is just a convention. I keep all my
virtualenvs in the .venv folder in my home directory,
but you can pick whatever location you like.
To use the virtualenv, you must activate it:
source ~/.venv/my-virtualenv/bin/activate
This activation script is a special shell script that configures
your current shell, pointing at all the right paths in order to use
the virtual environment.
source runs this script in your current shell session to
set it up. You will notice that this adds
(my-virtualenv) to the beginning of your shell prompt,
reminding you that the "my-virtualenv" virtualenv is active. Now
when you pip install amazing-package, the software
will only be available in this virtual environment.
When you're done, you can deactivate it like so:
deactivate
Wonderful!
Over time, I end up accumulating many virtualenvs, which can become harder to manage. Maybe something like this:
$ ls ~/.venv/
my-virtualenv cool-project snakes-ahoy
I also don't want to type source
~/.venv/my-virtualenv/bin/activate every time I use the
virtualenv, because it gets very repetitive—only the name of
the venv is really needed.
But luckily, we can write a little bit of bash to make managing this less annoying. (Or you can use one of many Python developer tools that are designed to manage this, like pipx, but when I merely want to consume Python software, I might not have a development environment set up. So that's beyond the scope of this post!)
If you add the following shell function to your
~/.bashrc or ~/.bash_aliases file, it
will nicely wrap our activation command:
setup-venv() {
source "$HOME/.venv/$1/bin/activate"
}
Now all we need to run is
setup-venv my-virtualenv
So much quicker!
The first thing I noticed after writing this wrapper was that I started hitting tab on the virtual environment name, but... nothing happened. Wouldn't it be nice to know what virtualenvs I had available, and to not have to type out the whole long thing?
Well, we can write it ourselves 😄
If for some reason you don't already have bash completion installed, on a Debian-based system, you will need to install it with
apt install bash-completion
In order to configure our
bash completion, we will create a new file,
/etc/bash_completion.d/venv, with the following
contents:
_list_venvs()
{
local cur prev opts
COMPREPLY=()
cur="${COMP_WORDS[COMP_CWORD]}"
prev="${COMP_WORDS[COMP_CWORD-1]}"
opts=$(find $HOME/.venv/ -mindepth 1 -maxdepth 1 -type d -printf "%f ")
COMPREPLY=( $(compgen -W "${opts}" -- ${cur}) )
return 0
}
complete -F _list_venvs setup-venv
This file defines another shell function order to determine how
to autocomplete the options for our setup-venv
function.
$opts is where we define the options for our
function. We generate it with a find
command—looking at the .venv folder in the
current user's home directory, then only including child folders
(excluding the current directory itself, .venv, in our
results) by using the min/max depth and type arguments, and
printing just the individual directory names, deliminated by spaces
using our print formatter.
Everything else is the standard scaffolding required to use bash completions.
Once you save this file and reload your shell, you'll see that you are able to use completions as expected!
setup-venv <tab>
my-virtualenv cool-project snakes-ahoy
setup-venv s<tab>
setup-venv snakes-ahoy
Hope this was helpful! If it wasn't, that's too bad. But don't worry—you can safely ignore this post.
Joe Marshall: llambda.lisp on linux [Planet Lisp]
A reader named Madhu sent me a patch for running llambda.lisp under linux. This patch uses mmap to pull the weights into the lisp address space outside the heap.
In addition, he tried to use a hugging face model that needed some default values, so he added them.
He reports that he was able to get the model to do inference on his linux box with about an hour of hacking. I have incorporated his patches and pushed the update to GitHub.
Kernel prepatch 7.2-rc7 [LWN.net]
The 7.2-rc7
kernel prepatch is out for testing. It is still bigger than Linus
would like, but he said nonetheless: "I don't currently see any
value in delaying the 7.2 release, so I would expect that to happen
next weekend unless something really bad pops up.
"
Reproducible Builds: Reproducible Builds in July 2026 [Planet Debian]
Welcome to the July 2026 report from the Reproducible Builds project!
In our reports, we try to outline the most important things that we have been up to over the past month. As a quick recap about what problem our project intends to solve, whilst anyone may inspect the source code of free software for malicious flaws, almost all software is distributed to end users as pre-compiled binaries. The motivation behind the reproducible builds effort is to ensure no flaws have been introduced during this compilation process by promising identical results are always generated from a given source, thus allowing multiple third-parties to come to a consensus on whether a build was compromised or not.
If you are interested in contributing to the project, please visit the Contribute page on our website.
In this month’s report, we cover:
diffoscope
is our in-depth and content-aware diff utility that can locate and
diagnose reproducibility issues. This month, Chris Lamb made the
following changes, including preparing and uploading versions
324,
325 and
326 to
Debian:
zipdetails 4.0008.
(#1141359)In addition, Paul Spooren made changes to allow trailing garbage
in Gzip files […]
and Vagrant Cascadian added an external tool reference for the
pedump
binary to use the mono package under
GNU Guix. […]
disorderfs
is our FUSE-based
filesystem that deliberately introduces non-determinism into system
calls to reliably flush out reproducibility issues. This month,
Christelle Gloor added the option to sort by ctime as returned by
the lstat(2) syscall. […],
which Chris Lamb uploaded whilst bumping the Standards-Version to
version 4.7.4 […].
Bernhard Wiedemann also updated
disorderfs to version 0.7.0 in openSUSE.
Yet again, there were a number of improvements made to our website this month as well. For example, Chris Lamb, by request of Digital Ocean, changed the target of a referral link so that they can manage incoming referrers […] and pushed a number of changes to the Tools page […].
In Debian this month, 32 reviews of Debian packages were added, 26 were updated and a total of 21 were removed this month, adding to our extensive knowledge about identified issues.
A number of issue types were added by Chris Lamb, including:
python_towncrier_build_date […][…]log_files_installed_in_package […]fontforge_varies_by_timezone […][…]Chris also added a further note for the build_date_in_manpage_generated_by_spf13_cobra
issue. […]
In addition, there is a new page showing verification rebuilds of OpenWrt APK packages and firmware images, powered by rebuilderd:
Yan Li, Nan Jiang, Qihang Zhou, Shaowen Xu, Yamin Xie and Xiaoqi Jia of the Chinese Academy of Sciences published a paper titled VCAligner: Aligning Source Distribution Versions with Upstream Git Commits to Secure Supply Chain:
We present VCAligner, a content-based alignment methodology that constructs inverted indexes over VCS histories to precisely map released artifacts to their originating commits, independent of fragile version tags. We evaluated VCAligner on a dataset of 2,984 verifiable PyPI packages derived from the 4,000 most-downloaded projects linked to public GitHub upstreams. Our results reveal a critical weakness in conventional tag-based heuristics: while they appear effective on 85% of the dataset, the residual 15% failure rate generates a catastrophic downstream audit workload of over 10.3 million commits. In contrast, VCAligner reduces this burden by two orders of magnitude (≈ 158×), bounding the total workload to under 65,000 commits. Furthermore, we provide the large-scale characterization of “Packaging Noise,” classifying artifact divergence into structural additions (Path Phantoms) and content mutations (Blob Phantoms), thereby isolating the distinct attack surfaces of malicious injection and code tampering.
Jens Dietrich and Spencer Sun from the Victoria University of Wellington together with Tim W. White and Behnaz Hassanshahi from Oracle Inc pre-published their paper No Snake Oil: Verifying Python Package Builds (PDF):
Python has become the default language for interacting with AI, with packages being distributed through registries like the Python Package Index (PyPI). This creates a need to analyse supply chains comprising such packages. One such analysis is to rebuild packages in order to identify compromised builds injecting malware. Independent rebuilds in hardened environments have the added advantage that they can generate and record provenance in order to increase the trustworthiness of packages. Two tools that are designed to automate such rebuilds and run them at scale are macaron and oss-rebuild. We study 12,180 popular releases from PyPI and find that the byte-for-byte equivalence rate is generally low. We analyse the reasons why they produce different wheels, and find that equivalence between the original and rebuilt wheels can often still be established, preserving most of the guarantees users expect from rebuildable releases. We present and evaluate daleq4py, a tool to establish the equivalence of Python wheels through the kernel of a normalisation function that is based on provenance-preserving datalog rules. Experimental results show that daleq4py substantially expands the set of rebuilds that can be accepted as equivalent. Although only 15.4% of macaron rebuilds and 19.1% of oss-rebuild rebuilds are byte-for-byte identical to the published PyPI wheels, daleq4py establishes wheel equivalence for 60.2% and 78.9% of source-equivalent rebuilds, respectively.
Denise Nanni, Julien Malka, Stefano Zacchiroli and Théo Zimmermann from Télécom Paris together with Gabriele D’Angelo from the University of Bologna pre-published their paper Understanding Build Reproducibility in the F-Droid Ecosystem (PDF), which was accepted at the 2026 ACM Conference on Reproducibility and Replicability:
The security of open source applications benefits considerably from the possibility of rebuilding their source and verifying the output. F-Droid, a prominent distribution for open source Android applications, systematically rebuilds them from source and tests their bitwise reproducibility at app publishing time. However, F-Droid offers no guarantee that app reproducibility will continue to hold in the future. As software ecosystems evolve, reproducibility may degrade, with potential negative consequences for software preservation and security. We present the first empirical study of build reproducibility in the F-Droid app ecosystem. Analyzing historical reproducibility logs, we find that the overall bitwise reproducibility rate has been steadily increasing over time (as new versions of apps are published). We then evaluate how reproducibility holds in time for fixed app versions, by attempting to rebuild 18 904 app versions that F-Droid had previously confirmed bitwise reproducible, published between September 2018 and February 2026, achieving an 83% rebuild success rate, and identify missing dependencies as the dominant cause of failure, accounting for 76% of non-rebuildable cases. Among successfully rebuilt apps, 94% are also bitwise reproducible-i.e., they still yield bitwise identical artifacts upon rebuild. Together, these results show that while bitwise reproducibility largely holds for apps that can be rebuilt, rebuildability itself is highly sensitive to temporal decay.
The Reproducible Builds project detects, dissects and attempts to fix as many currently-unreproducible packages as possible. We endeavour to send all of our patches upstream where applicable or possible. This month, we wrote a large number of such patches, including:
Arnout Engelen:
Bernhard M. Wiedemann:
Chris Lamb:
golang-github-tidwall-wal.lightproof.libslow5lib.siso.grout.
libpsl.
node-grunt-contrib-internal.fontforge.spopt.go-dlib.towncrier.Jochen Sprickerhof:
python-sphinx-chango.
gasnet.yubihsm-connector.dh-fortran.watcher.
rakudo.kf6-breeze-icons.oxygen-icons.gnu-apl.barvinok.ecbuild.On our mailing list this month, Colin Winter of Markovian Protocol wrote to our mailing list on the topic of Reproducible verification for retained logs:
Reproducible builds remove trust in the builder: anyone re-derives the same artifact from the same source, byte for byte. The same shape applies one layer over, to a retained record. Most record-keeping regimes (the EU AI Act’s Article 12 logging is the current example) require that events be recorded and logs retained, but not that a retained log be verifiable, by a party who was not present, as unaltered and existing when claimed. That leaves an integrity obligation resting on trusting the party being audited.
Finally, if you are interested in contributing to the Reproducible Builds project, please visit our Contribute page on our website. However, you can get in touch with us via:
IRC: #reproducible-builds
on irc.oftc.net.
Mastodon: @reproducible_builds@fosstodon.org
Mailing list:
rb-general@lists.reproducible-builds.org
Working with Claude on the user interface of RSS.chat was a grind, but we learned a lot about working on these projects, me in the form of my human memory, and Claude who can read the code for a huge sprawling app like Frontier, and understand it, in a minute or two. We've done this project in three stages, not knowing at the first two that there would be another one. Now we're working on the editors. An odb table editor, outliner, menubar editor, script editor. All built on the same codebase. It's in an Electron app that works with lots of independent windows, which while it has its pros and cons, is the way Frontier did it for almost 40 years. I find all this very unsettling, but I realize that once we get back to adjusting the UI, I already know how to work with Claude on tuning things up so they feel just right. I'm a market of one, the only one who has to be happy here is me. This may be the hardest programming project I've ever had, for one simple reason, I'm not doing any programming. That and I'm having very strong deja vu on everything I do and think about. Also there will be a fourth stage and maybe more. It'll be about the affordances, the things that seem little, but make the product usable. The biggest is the debugger. It's patterned after the one in THINK C, which I found transformative so I stole from the best, as they say.
Why businesses lie about AI [Cory Doctorow's craphound.com]

This week on my podcast, I read Why businesses lie about AI, a recent essay from my Pluralistic newsletter that breaks down Nikhil Suresh’s essay describing the total absence of any proof that any business is benefiting from AI deployment.
One person who’s had a lot of opportunity to observe the shear between the stated business/AI situation and the real business AI situation is Nikhil Suresh from Hermit Tech, a consulting firm of “radically ethical data wizards” (that is, tech consultants). Suresh reports on his experience talking with hundreds of executives (and, more importantly, their subordinates) about what (if anything) AI is doing for business in an essay entitled “AI Mania Is Eviscerating Global Decisionmaking.”
“We’re all being surprised at the same time” [Seth's Blog]
Keith Jarrett on improvisation.
When the artist is creating in real time, in conjunction with the witnesses in the room, “performance” goes away.
It’s creation.
Improvisation is a privilege, a chance to create without a guarantee.
New Cover: “So Alive” [Whatever]

Yes, I’m slowly working my way through the 80s on KROQ. This one is from Love & Rockets, a spin-off of Bauhaus, but a lot more commercially accessible. This is their biggest hit (it went to #3 in the US and #1 in some other countries). My version is slightly more upbeat than the original, and also features a guitar part that’s probably more at home in New Order than either Bauhaus or L&R. And yes, it’s me playing the guitar; I have so many, I should really start playing them more. I’m also singing; this song is square in my range, and also, covers about four notes. Super easy.
Enjoy!
— JS
I want to connect RSS to AT Proto, both ways, inbound
and out. Toward that end, today I helped
Leaflet, a very nice editor
for AT Proto, make their outbound RSS feed better. We should have
all our best editors, everywhere, hooked up over popular web
standards. And I want my posts to show up not only in Bluesky but
also in standard.site. I was
able to do that with micro.blog which is the
swiss army knife of interop in the web of the 2020's. Getting
independent developers working with each other is my mission,
because first you have to have
interop between the people before you can get interop between
the apps.
Here's the sign of success. (screen shot.) I wrote a post on demo.rss.chat was automatically cross-posted to Bluesky via micro.blog. Because the post has a title, it was routed to standard.site. What does that mean? I still don't really understand, when I do I will explain it here. But part of the answer is that we now have a data structure in atmosphere that looks like an RSS item with different names for things. Are there feed readers in AT-Proto-Land? If so, can we ping one of them to say hey there's a new post in the standard.site world, so please show it to subscribers? And I keep wondering, why not just make all of Bluesky capable of handling the features standard.site calls for. Twenty years is too long to have such a limited view of what text is. See textcasting for more dogma.
Thanks to the EU’s Digital Markets Act, EU citizens are getting copy and paste between iOS and Windows [OSnews]
The European Union’s Digital Markets Act keeps delivering for EU citizens.
Apple is working on a new feature that will support cross-device copy and paste between iOS devices and Windows PCs.
Microsoft asked for the feature using Apple’s EU interoperability request system for developers, which Apple implemented to comply with the Digital Markets Act. Apple began evaluating the request in March, and on June 26, proposed a project plan.
↫ Juli Clover at MacRumors
According to Apple, this minor feature is going to cost Apple “significant engineering effort”; I’d estimate it’ll cost them about one to two golden statues.
IceWM, the venerable X11 window manager, has put up a new maintenance release, version 4.1.0. It’s got a small number of fixes, two very minor new features, as well a few updated translations. That’s it.
Pluralistic: Digital sewer socialism (08 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

Hardly a day goes by without my getting an email from someone looking for a way to do good with technology. From computer science students thinking about post-grad careers to seasoned coders with decades of experience, there's an army of hackers looking for a way to turn their expertise into public goods.
There's a name for this movement: it's called "Public Interest Technology" and the people who work in it are called "public interest technologists." There've always been techies who understood the link between tech and public wellbeing and who committed themselves to working for the betterment of society, but their numbers swelled as Big Tech companies saturated their markets and switched from growing by making products people like, to locking in their users and then extracting more value from their technological prisoners:
https://pluralistic.net/2024/04/24/naming-names/#prabhakar-raghavan
It was the era when (in the words of Facebook's Jeff Hammerbacher) "The best minds of my generation are thinking about how to make people click ads":
https://quoteinvestigator.com/2017/06/12/click/
For organizations like the Electronic Frontier Foundation, the growing cohort of hackers who wanted to hack for good was great news. Our staff technologist group swelled from a couple of overworked computer scientists helping lawyers and activists with campaigns to a series of increasingly ambitious software projects, from Privacy Badger (a tracking-blocker that every web user needs):
To Let's Encrypt and Certbot, projects that forever changed the internet's default state, so that today, nearly all online communications are encrypted and resistant to mass surveillance:
Other opportunities for public interest technologists proliferated. Bruce Schneier created the canonical resource page for Public Interest Technologists, including career opportunities for would-be public interest technologists:
https://public-interest-tech.com/
But the motherlode of public interest technologist opportunities wasn't the nonprofit sector – it was the public sector. It started with the UK's Government Digital Service, a group of public-spirited hackers (many of them ex- of the BBC, where they'd been tempest-tossed by endless internal power-struggles over the role of the internet in public service media) who retooled many of the UK government's most important administrative front-ends. For several glorious years, Britons delighted to the daily marvel of having their routine interactions with their government transformed from clunky, broken web-pages to slick, superbly thought through online processes that had all the polish of Amazon or Google, but without any of the gamesmanship, manipulation or privacy invasions:
https://en.wikipedia.org/wiki/Government_Digital_Service
Despite many attempts at official sabotage by a string of increasingly shambolic UK governments, the GDS still exists, and it still does amazing work, even though it operates today with a fraction of the official support that it enjoyed at its inception. The last time I renewed my UK passport, I was gobsmacked by how easy and sensible the process was. Local authorities have gotten in on the act, too: I renewed my absentee voting registration with Hackney Council last week and it was as simple as scanning a QR code, affirming my details, and clicking "submit."
Around the world, a generation of public sector technologists duplicated and improved on the UK GDS's work. In Taiwan, a rogue public interest hacker named Audrey Tang led a group of digital guerrillas in creating shadow versions of every Taiwanese government website that scraped and remade the entire digital presence of the Taiwanese state to make public information and services accessible, legible and useful to its people. After the next election, Tang was named Taiwan's first ever Minister of Digital Affairs (today, she is a Taiwanese "Ambassador-At-Large"):
https://en.wikipedia.org/wiki/Audrey_Tang
In the USA, Jen Pahlka went from running a ragtag "civic hacking" org called Code For America to helping to found the United States Digital Service under Obama, bringing some of that UK GDS spirit to America's dreadful online presence, which had been largely built and maintained by beltway bandits who'd billed handsomely and delivered some of the internet's greatest crimes against usability:
https://en.wikipedia.org/wiki/United_States_Digital_Service
But the USDS's legacy is bitter. In 2025, USDS was effectively dismantled and replaced with DOGE, Elon Musk's handpicked team of tech-bro cultists who set out to dismantle as much of the US government as possible, deliberately sabotaging the usability of America's governmental systems to make it harder for the public to access the services they are entitled to and pay for with their taxes.
My own run-in with this was my attempt to get a certificate of citizenship for my daughter when she turned 18: all I could find was an online form that started by requiring me to list the dates and flight numbers for every trip I'd taken to the USA from the time I was born to the day I became a US citizen, a 50+ year period that started with a trip to visit my snowbird grandparents in Florida when I was six months old. The entire support and advice service for the US Customs and Immigration Service has been replaced with a DOGE chatbot that repeatedly emails and texts links to the form, no matter what question you ask, and no matter whether you call, email or use the website's chat interface:
https://pluralistic.net/2026/02/06/doge-ball/#n-600
Many of the DOGE kids were monsters. The most chilling DOGE story I've heard was the anonymous testimony of NIH officials who begged the DOGE children who were dismantling their work to spare some long-running cancer research projects whose great promise would be vaporized if they were interrupted. The DOGE kids laughed at these entreaties, saying that once Musk had perfected "General AI" we wouldn't need cancer research, because their tame AI god would cure cancer.
But not every DOGE operator was a digital arsonist. Take Dan Berulis, a DOGE staffer who came out of the private sector and later turned whistleblower over the group's activities, who now faces assassination attempts:
https://www.wired.com/story/he-blew-the-whistle-on-doge-then-his-brakes-were-cut/
Berulis joined DOGE to improve America's digital infrastructure, not to dismantle it. When he talks about his motives, he sounds like an early GDS pioneer, one of Audrey Tang's direct-action government data scrapers, or one of the Code For America hackers who followed Pahlka to USDS:
https://www.npr.org/2025/04/15/nx-s1-5355896/doge-nlrb-elon-musk-spacex-security
DOGE was a catastrophe. It left America's government digital presence in far worse shape than it found it, and even the modest savings it claimed to have made from all this destruction turn out to be lies:
https://www.yahoo.com/news/politics/articles/elon-musk-doge-made-big-110000036.html
But as Berulis demonstrates, there is a bipartisan group of skilled, ethical technologists who are desperate to do meaningful public interest work. Their numbers swell every day, as Big Tech continues to curdle – no longer merely sclerotic and enshittifying monopolies, now active participants in Trump's authoritarian dismantling of democracy itself:
Tech bosses' gleeful mass layoffs mean that tech workers can no longer count on good treatment and stable, high-earning careers; at the same time, tech bosses' betrayal of democracy makes the prospect of working for a tech company far more ethically dubious than mere ad-tech optimizations. The result is a bumper crop of geeks looking for ways to do good with their lives and skills – as all the emails in my inbox asking for advice about this attests.
Enter NYC Mayor Zohran Mamdani, who has made "public excellence" the cornerstone of his politics, hiring the most skilled workers he can find and then giving them all the authority and resources they need to fix 100,000 potholes, bring New York's worst landlords to justice, and deliver every day for all the people of New York:
https://pluralistic.net/2025/11/15/unconscionability/#standalone-authority
Mamdani has just unveiled his Public Interest Technology (PIT) Crews: five "game changing" teams of public interest hackers who will remake NYC's digital services:
Writing for Wired, Steven "Hackers" Levy paints a portrait of New York's PIT Crews, describing them as "what DOGE should have been":
https://www.wired.com/story/mamdani-assembles-his-nyc-tech-team/
I'll go farther than that: the PIT Crews – and Mamdani's project as a whole – is delivering the entire failed promise of DOGE. Unlike Musk and Trump, Mamdani is actually rooting out fraud and waste. The reason Mamdani can do this – and the reason billionaires can't – is that the fraud and waste that undermines governments at all levels come from the super-rich, with their tax-dodging, their no-bid contracts, their addiction to public subsidies.
Musk owes his riches to federal bailouts and contracts: if he wants to "eliminate government fraud and waste" he should turn over his files to an IRS inspector (if he can find a survivor of the DOGE massacre) and surrender himself for a lengthy prison sentence. For Musk, "government fraud and waste" is a single mom on food stamps who misses a box on a 600-page form because she's exhausted from working three jobs to make rent – not a no-bid contractor trousering billions in public funds for projects that overcharge and underdeliver.
Mamdani's PIT Crews are "small groups of engineers and designers will strive to change the hidebound and confusing nature of current city services by using state-of-art skills to rapidly whip up specialized apps that solve real problems." Mamdani says that they'll "raise expectations on what government can deliver, because we really can deliver."
As Levy describes it, the big difference between the Obama-era USDS and 2026's PIT Crews is "a skeptical, almost adversarial, stance toward Big Tech." NYC's PIT Crews explicitly recruit top-tier hacker talent who want to "make software that doesn't serve advertisers, the military, or the pocketbooks of centibillionaires."
Their inaugural chief is Lisa Gelobter, a veteran of both tech firms and the USDS, who says that "Without technology, policy is just words written on a piece of paper." The first project on her roster is implementing "Click to Cancel," a policy inaugurated by Lina Khan, Biden's FTC Chief – and then dismantled by Trump. Under Click to Cancel, companies are required to create one-click workflows to cancel subscriptions and memberships, ending the pernicious, incredibly profitable practice of trapping people with impossible-to-halt recurring billings. Today, Khan is running Mamdani's Economic Development Board, and her Click to Cancel rule is back – for New Yorkers, at least:
https://www.theguardian.com/us-news/2026/jul/22/lina-khan-nyc-economic-development-board
NYC PIT Crew's new Click to Cancel site will be live when the policy takes effect on Oct 1. It's a whistleblower site that will make it easy to report merchants who make it hard to get shut of their online Roach Motels (users check in, but they don't check out). It's estimated the Click to Cancel rule will save New Yorkers $160m in the first year alone – but only if Mamdani can enforce it, which is why this website is so critical.
This focus on meat-and-potatoes service delivery was once dismissed as "sewer socialism," an unserious form of progressive politics with an undue focus on improving people's daily lives at the expense of high-flying political change. Today, Mamdani is at the vanguard of an army of proud sewer socialists, who say that once you deliver for people in their day-to-day existence, they will trust you and back you when you fight for deep, structural changes (and the corollary: if you can't deliver for people in their daily lives, why should they trust you when you claim that you'll make everything better?):
https://prospect.org/2026/04/10/zohran-mamdani-getting-new-york-city-believe-in-government/
3,000 techies applied for 35 jobs with NYC's PIT Crews, and, as Levy writes, many of them are high-flying senior coders who are willing to take a massive pay-cut and forfeit their stock options to do something that's both technically excellent and meaningful to their users' lives.
It's a clear message to other leaders, at every level of government. Many of the most skilled, ambitious people in every field want to make the world a better place. Every city, county and state could use a squadron of PIT Crews, and there's an army of coders who would give anything for the chance to give everything to make a better world.

BMW Suddenly Blasts Its Cars’ Internal Screens With Aggressive Advertisements https://futurism.com/advanced-transport/bmw-suddenly-blasts-cars-advertisements
People in the midwest know what a livestream is https://www.garbageday.email/p/people-in-the-midwest-know-what-a-livestream-is
how Google can go legit https://blog.zgp.org/how-google-can-go-legit/
The Yardstick That Ate the Market https://itsg13.substack.com/p/the-yardstick-that-ate-the-market
#25yrsago Moscow's pirate music market https://web.archive.org/web/20010912203143/https://www.wired.com/news/culture/0,1284,45908,00.html
#25yrsago Webcomics v trad comics https://web.archive.org/web/20010821073756/https://www.salon.com/tech/feature/2001/08/09/comics/index.html
#25yrsago Aussie teens are addicted to their phones https://web.archive.org/web/20010818220523/http://news.ninemsn.com.au/national/story_5807.asp
#20yrsago Canadian librarians decry “Captain Copyright” https://web.archive.org/web/20060813004140/https://cla.ca/Access_Copyright_CptCopy_let_Final_.pdf
#20yrsago TiVo/Macrovision screw up breaks devices again https://zatznotfunny.com/2006-08/tivo-macrovision-and-the-stealth-broadcast-flag/
#20yrsago Will the Supreme Court strike down the TSA’s secret laws? https://papersplease.org/gilmore/
#20yrsago Robot garage loses software license, strands parkers https://web.archive.org/web/20060809213517/https://www.wired.com/news/technology/0,71554-0.html?tw=wn_index_1
#15yrsago Typewriter-part penguin https://web.archive.org/web/20111116020049/http://jemayer.tumblr.com/post/8674700147
#15yrsago Choosing Android because you don’t trust Google https://www.theguardian.com/technology/2011/aug/09/technology-failure-more-important-than-success
#15yrsago HOWTO sound Canadian https://web.archive.org/web/20110610104919/http://www.oed.com/public/canadianenglish
#15yrsago Lev Grossman’s The Magician King: fantasy sequel, the banality of magic and the magic of banality https://memex.craphound.com/2011/08/09/lev-grossmans-the-magician-king-fantasy-sequel-the-banality-of-magic-and-the-magic-of-banality/
#10yrsago Rosie the Riveter, Ghostbusters edition https://www.deviantart.com/hugohugo/art/We-Can-Bust-It-621803816
#10yrsago Thai telcoms regulator wants tourists to use location-tracking SIMs https://web.archive.org/web/20160812182254/https://www.nationmultimedia.com/breakingnews/Thailand-mulls-location-tracking-tourist-SIM-cards-30292551.html
#10yrsago Mysterious medical research consortium: we should own volunteers’ clinical trial data for 5 years https://www.techdirt.com/2016/08/08/medical-researchers-want-up-to-five-years-exclusivity-clinical-trial-data-derived-volunteers/
#10yrsago Illegal “Warranty Void If Removed” still ubiquitous: they’re on the Xbox One S https://web.archive.org/web/20160809092923/https://motherboard.vice.com/read/the-xbox-one-s-still-uses-microsofts-illegal-warranty-void-if-removed-sticker
#10yrsago Your medical data: misappropriated by health-tech companies, off-limits to you https://web.archive.org/web/20180806230935/https://www.wired.com/2016/02/our-medical-data-must-become-free/
#10yrsago Return of Dieselgate: 3 more hidden programs found in VW Audi/Porsche firmware https://www.reuters.com/article/us-volkswagen-emissions-audi-idUSKCN10I0PB/
#10yrsago Timelapse of pills dissolving: “decaying clowns” https://www.youtube.com/watch?v=4rY3X4xafs0
#10yrsago Proof-of-concept ransomware for smart thermostats demoed at Defcon https://web.archive.org/web/20161020083358/https://www.pentestpartners.com/blog/thermostat-ransomware-a-lesson-in-iot-security/
#10yrsago Compounds in human exhalations during movies vary in response to suspense and comedy https://www.nature.com/articles/srep25464
#10yrsago How racist traffic stops criminalize black people, and what to do about it https://www.vox.com/2016/8/5/12364580/police-overcriminalization-net-widening
#10yrsago Chicago cops switched off bodycams and high-fived after shooting unarmed black teen https://web.archive.org/web/20160807194244/http://www.theroot.com/articles/news/2016/08/chicago-pd-paul-oneal-video/
#10yrsago DoJ to judges: use Tor to protect your internet connection https://web.archive.org/web/20160807025945/http://motherboard.vice.com/read/department-of-justice-official-tells-hundred-federal-judges-to-use-tor
#5yrsago Expectations management pluralistic.net/2021/08/08/expectations-management-part-v/
#5yrsago When your boss wants an AI camera in your bedroom https://pluralistic.net/2021/08/09/computer-says-no/#disciplinary-tech
#5yrsago The 22 Murders of Madison May https://pluralistic.net/2021/08/09/computer-says-no/#existential-crisis
#1yrago Millionaire on billionaire violence https://pluralistic.net/2025/08/09/elite-disunity/#awoken-giants

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
F@#$ the AI Overlords (On The Media)
https://www.wnycstudios.org/podcasts/otm/articles/f-the-ai-overlords
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
AI and the Enshittification Era (The Weekly Show with Jon
Stewart)
https://www.youtube.com/watch?v=-dAIJRjb-Bw
AI is not inevitable (Betakit)
https://www.youtube.com/watch?v=DbiTVkq1WHo
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
The McIntosh Modernity Index [Seth's Blog]
There’s a village in Luxembourg that’s right outside the main metropolis. A farmer often ties up a donkey to the little bridge leading to town.
The juxtaposition of international digital trading and donkeys is a reminder that as fast as the future arrives, the past also sticks around. We can measure the distance not just in years, but in miles. “How many miles is it to the nearest donkey?” is an interesting metric.
There’s probably a version of the donkey in your office or your town.
Gunnar Wolf: Subscription Bombing • Email under Attack [Planet Debian]

This post is an unpublished review for Subscription Bombing • Email under Attack
One of the most important inputs one can have when designing a response strategy against a security attack is a good characterization. This article describes a relatively newly described attack mode (subscription bombing), hypothetizes on the motivations that can lie behind it, and presents some countermeasures that can be taken by different actors to reduce its impact.
At its core, suscription bombing is a classical reflection attack: it uses a third party service so that the answer to a relatively simple request is amplified and results in a distributed denial of service (DDoS) for the victim. And, as with most DDoS attacks, its effectivity lies in that there is not much a person can do against traffic coming from seemingly random different providers all around the world.
The core differentiatof for subscription bombing is that the attack’s victim is not a network port, but an individual’s e-mail address. The attacker builds a database of service providers that allow interested users to sign up for newsletter on their activities, or a mailing list, or even just to create a new account on a given Web system. This action will generate a (seemingly legitimate) confirmation mail sent to the victim. But the attacker scripts together hundreds of thousands of such request, creating a deluge of confirmation mails sent to the unsuspecting victim.
The authors explain the goals an attacker might pursue by performing this kind of attack. They suppose this can be due to harassment (a disgruntled employee being denied a salary raise, a political adversary, or even a romantic ex-partner wanting to inconvenience the victim’s use of their e-mail). More worryingly, the attack can be used as a distraction: by sending a high volume of mails in a controlled timeframe, the attacker can reduce the probability of the victim noticing a specific attack warning them of, i.e., financial fraud, unwanted purchases, or break-in attempts into their accounts. Attacks targetting mailboxes at private mail servers can also lead to overloading an account’s limit, causing it to reject mails after the attack is delivered and before the folder is cleaned. And it can also pave the way for follow-up, targetted deception attacks, where the attackers call the victim pretending to be the company’s IT department, and get them to install a remote desktop monitoring and management tool, with which they can effectively seize control of the victim’s data.
To do this, they present a study they made over 24 cases of victims, from which 47,970 total e-mails were received between October and December 2024, with individual attacks receiving between 81 and 3,387 e-mails per hour, from where they presented several descriptive analysis.
The authors explored cyber criminal’s offers on underground websites, comparing flooding services and pricing schemes.
Finally, mitigation strategies are discussed. Mitigation is quite problematic, as none of the mail servers is acting in either a hostile way or lacking permissions — they are performing just the task they should. The authors suggest four mitigation strategies for mail server operators to reduce the burden on their users, although none of them is easily automatizab (rate-limit the number of emails a given inbox can receive from previously unseen senders; educate users about this kind of attacks; group similar newsletter or account reset mails during active attacks; and automatically unsubscribe or bounce newsletter messages when a surge is detected). They also recommend newsletter providers and services accepting the unrestricted creation of user accounts to provide some hardening to increase the effort wrongdoers need to spend to abuse their services, such as requiring CAPTCHAs or requiring users to take several steps before requesting a subscription, although they recognize this adds friction to the process providers are most interested in providing; filtering and triaging known-good and known-bad domains, although this is hard to implement on a preemptive fashion, and adhering to easy unsubscription standards, such as easily identifiable headers with which mass unsubscription could be performed more easily victims, instead of hunting for the right places to click, potentially even in mails written in an unknown language.
The described problem is interesting, and properly tackling it can be a game changer for many users who will suffer this kind of abuse, and the article is easy to read and soundly supports its claims.
Friday Squid Blogging: Arctic Bobtail Squid Video [Schneier on Security]
Nice video of the Arctic bobtail squid.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Spoiler: Wil Wheaton is a Wizard [WIL WHEATON dot NET]
I am holding pink pages in my hand, reviewing them before I collate them into my script.
A magic battle ensues between Wil and Bert (fireballs, energy bolts, conjured beasts, etc.)I look at the script again, to make sure I haven’t misread it.
Yeah, it really says fireballs, etc. Holy shit I’m a wizard. A wizard!
About two years ago, I was having breakfast with my friend, Bill. Bill co-created The Big Bang Theory, and over the last decade or so, we have become extremely close, very good friends. He is like family to me and I just love that not only did Big Bang introduce me to a whole new generation of audience, it introduced me to two of my most cherished and treasured friends, in Bill Prady and John Bowie.
Bill told me that he and Chuck Lorre were developing a Big Bang spinoff with Zak Penn, and went on to describe Stuart Fails To Save The Universe. I was in love with the entire thing from the first few minutes he talked about it, and that excitement and enthusiasm for this thing to get to the audience has never softened. For almost two years, we’d get together for some reason, and I’d excitedly listen to Bill as he told me what stories they were working on, how they had developed the arc of the season, and how it was all going with the studio and the network.
For a show that I never expected to be part of at all, I became (and remain) intensely invested in its success. I wanted five seasons, and then five more. I genuinely loved it.
Let’s fast forward to October of last year. I know the show is in production, because all of my friends are working on it. John is texting me from the set, telling me what an incredible cast it is, how much fun they are all having. I’m texting Bill to ask how it’s all going, and he couldn’t be happier.
Neither of them says anything to me about playing a wizard in a universe where magic is real, so when the email arrives asking about my availability to do a few days on the show, the excitement and surprise shake the foundation of my home. Yeah, I’m available. Even if I’m not available, I will become available.
So I go to Universal Studios for a table read, where I meet Tommy Walker (god, I love him) and get to see Melissa Rauch for the first time in years. The entire room is rocking with laughter by the time we are done. I have to wait a week to go to the set, but first I have to be fitted for my costume.
When Felicia and I wrote the Fawkes issue of The Guild, I wanted his in-game wizard robe to be really over the top, with lots of runes and Eldritch energy that he absolutely can’t control, but wears because it makes him look cool. So during my fitting, I mentioned to Val, the costume designer, that I would *love* it if we could put some runes on the robe, as a little easter egg for me and like twelve other people. She’s rad, by the way. She is so creative and clever, puts so much intention into every detail on every costume, nothing is there just because. Everything has a reason, just like it did on Big Bang Theory.
I put rings on almost all my fingers, and you know that in my imagination, each one held a different spell, a different well of magical energy, and so on. No, it doesn’t matter to the audience, but it matters to me, it’s fun.
A funny and fun thing happens when I put the robe on. Without meaning to, I stand up as straight as I can. I am tits up all the way, my shoulders feel strong and solid (they are neither), and I feel legitimately cool. As Lester Bangs says in Almost Famous, “Oh, dude, they made you feel cool, and you are not cool.”
You can see the pins and stuff on the robe in these pictures from my fitting, because I didn’t take any pictures of myself when I was on set (I made a choice to leave my phone in my dressing room, so I could be fully present on set, forgetting that it is also my camera. Oops).
Also, while I was at my fitting, Jonathan Frakes showed up! He was directing episodes after mine, and was there to prep. He found out I was going to be there, so he surprised me with a big hug and a day I didn’t think could get any better took its place in the top ten of 2025.
A few days later, I reported to set for my first day, where I proceeded to have one of the best days of my life, playing a motherfucking WIZARD.
The first thing I notice when I walk into the stage is how happy everyone is. This show shoots in Los Angeles at a time when that is not as common as we all want it to be. Everyone is thrilled to have the job, to go home after work, to be collaborating with genuinely talented professionals. (For instance, every grip on this show is a Key Grip, usually, because they were all so happy to work locally).
The cast are all my friends, all people I know, some better than others, and just like when I was on Big Bang Theory, they welcome me like I have been there all along and won’t be done in three days.
We rehearse the entire sequence, very loosely, just getting an idea where we will all be, where the camera will go, all that stuff. We don’t get into performance at all, yet. This is pretty much just blocking. I find out that I will get to stand on this lever platform thing that will lower me into the scene, as if I have come through a portal (A PORTAL) to deliver my magical justice.
So we get into it, we shoot some of it, and it’s just incredibly fun and satisfying. About three hours into the day, I realize that I, too, am just having fun. For the first time maybe ever in my life, I feel worthy and unafraid of being fired when I am on set. I make choices to see how they feel and if they work. Some do, some don’t, but Kyle Newacheck, the director, encourages me to play and find stuff, even if it means I find something that doesn’t work.
I can’t overstate how healing this is for me, at 53 years-old, to be on the set of a show that really matters to me, where I don’t want to let anyone down, and feel supported and safe. Even when I was on Big Bang Theory, and I’d been recurring for almost ten years, a very big part of me was absolutely convinced I was going to fuck up and get fired. Not because of anything anyone said or did when I was there, but because of the trauma my mom filled me with when I was a kid.
The first day, we do everything except the big battle between me and Brian, which will be first up when we come back tomorrow. For the first time ever in my entire career, I don’t want the day to end. I don’t want to race back home to my regular life. I want to stay on the set and keep playing with my friends.
So the morning comes and we are all on the set again, blocking the big fight. The set is cleared out of everyone except me, Brian, Kyle, the cameraman and the visual effects team. Kyle asks Brian and me if we had any ideas, before he tells us what he’s thinking. I can’t overstate how rare this is, a director asking actors what they are thinking, before he even mentions what he is thinking. It opens the door to collaboration, gives us permission to take some chances, and relaxes me so much, I let go of tension I didn’t realize I was holding.
I have spent more time than is probably necessary, practicing my spellcasting at home in the mirror. I have very clear ideas about how Wil Wheaton from the Wizard’s Guild of America casts spells, how I grab the magical energy from the aether and shape it into fire, stuff like that.
Brian has ideas, too, and Kyle takes his and mine and adds them into what he was already thinking. We develop this beautiful choreography, and Brian makes this choice right away to be kind of stiff and unfamiliar with his magic, to help sell how fluid and experienced I am with mine. It’s another moment where a scene partner makes me look so much cooler than I am, just like Jim always selling how much you loved to hate Evil Wil Wheaton back in the day.
We are moving through it slowly, starting and stopping so VFX can see where to put practical explosions on the set, when I get an idea.
“Hey, Kyle,” I say, “can I pitch two things?”
“Sure,” he says.
“Okay. What if I deflected one of his attacks like this,” I make a Vulcan salute and thrust my hand forward, putting all my body’s energy and intention behind it.
“Oh yeah! And I can throw it like this!” Posehn makes the Dio Rock Goat and aims the horns at me.
“Holy shit that’s so cool,” I say.
“I love that!” Kyle says.
“And what if I pulled my octopus tattoo off my arm, and threw it at him?” I say, casually spending a few hundred thousand dollars on the resulting visual effects shots. Kyle’s eyes light up. Brian’s eyes light up. Suddenly, I am surrounded by several pairs of lit up eyes.
Kyle turns to one of the producers. I can’t recall who it was, due to the fog of excitement, but they pow wow for a second. I can see that they are getting excited about it. He turns back to me. “Do you own it?”
“I do.” This has come up before, so I am prepared with releases and permissions.
“Great. Let’s do it.”
Holy shit it’s going to happen!
Bill will later tell me that refining the shot becomes more complicated and technically fraught than they ever expected, and it’s entirely worth it.
We spend a few hours filming our battle. It’s a mixture of visual and practical effects, and I feel so cool the entire time. It’s just so many things I love all coming together at once, a gift I will cherish forever.
When we wrap, I get this lovely round of applause from the cast and crew. In that moment, I make a wish for the show to get picked up, so I can come back next season in a different universe, and play with my friends again. I walk back to my dressing room, wearing the absolute shit out of my robe one last time.
Felicia and I talked about this in even more detail on the podcast, which you can find in all the podcast places, if you’d like to hear more.
I’m glad you’re here. Thanks for reading. If you’d like to get my posts delivered to your inbox, here’s the thing:
This Week in AI: Who Controls AI? [Radar]
Governments are tightening control over AI infrastructure as companies spend heavily to compete at the frontier. This week, data and AI evangelist Christina Stathopoulos examined how policy, capital, product risk, and scientific research are shaping AI development.
She explored AI sovereignty, Google’s infrastructure spending and product risks, the singularity debate, and several developments in mathematical and scientific research. The episode covered Anthropic CEO Dario Amodei’s argument about open weight models, US restrictions targeting foreign-made humanoid robots, OpenAI’s researcher access program and Astra model, Claude Fable 5’s role in a long-standing math problem, and Google DeepMind’s AlphaFold reorganization.
We’ve followed the sovereignty conversation in recent episodes as governments have tightened control over model access, computing infrastructure, and supply chains. Amodei wants policymakers to focus on what a model can do instead of using its open or closed status as the main measure of risk. His proposals include restricting access to advanced chips and chipmaking technology, preventing industrial-scale model distillation, and requiring safety testing for sufficiently capable systems. Christina agrees that capabilities should come first when assessing risk, but argues that open and closed models each present unique challenges. Open models can’t be recalled or controlled once their weights are released, increasing the risk of misuse, while closed models concentrate power in the hands of a few companies. Rather than favoring one approach, policymakers should address the risks of both.
The US-China rivalry is also moving into robotics. Christina discussed new US restrictions on foreign-made humanoid robots, aimed largely at Chinese manufacturers, and possible retaliation from Beijing. She argued that China’s manufacturing advantage could make the restrictions more costly for US buyers in the near term, even if they encourage domestic development over time.
Europe and Australia are taking different paths. Europe is pursuing computing capacity through proposed AI gigafactories, while Australia is emphasizing standards, renewable energy use, and creator rights. Its proposals include requiring data centers to fund new clean energy and AI companies to obtain permission before training on creators’ work. National rules are becoming another factor in decisions about models, cloud providers, and data locations.
Google reported its first quarter of negative free cash flow since going public after spending $44.9 billion on AI infrastructure in three months. Christina noted that the company generated about $39 billion in cash but spent roughly $45 billion, leaving it almost $6 billion in the red. This illustrates the scale of Google’s investment in frontier AI, even with a highly profitable core business.
Large budgets don’t guarantee that products are ready for broad use. Google removed an AI-powered Google Earth feature one day after launch when researchers used it to create realistic fake satellite images, including fabricated disasters and damaged landmarks. In this context, synthetic satellite imagery can weaken trust because viewers may treat it as documentary evidence.
Large infrastructure budgets can accelerate model development and product releases, but they don’t replace careful evaluation, context-specific safeguards, and clear limits on where generation should be allowed. Product teams need to assess how people might abuse a new feature or how users will interpret an output, not only what the underlying model can produce.
OpenAI CEO Sam Altman said that the AI singularity has begun, referring to a period when AI accelerates human and technological progress at a rapidly increasing rate. Christina treated the claim cautiously. Current model development doesn’t show recursive self-improvement, and faster releases still reflect human engineering, investment, and competition. Faster release cycles affect how organizations evaluate and adopt models, but they don’t establish an intelligence explosion.
The week’s mathematics stories provide more testable evidence. OpenAI plans to give 100,000 academic researchers free access to its most advanced models. Christina also discussed Astra, an internal OpenAI model teased as the company’s next flagship model, which reportedly solved 10 previously unsolved mathematical problems that professional mathematicians later verified. On the Anthropic side, an external research team used Claude Fable 5 to produce a counterexample related to the 87-year-old Jacobian conjecture, which mathematicians also verified. Christina highlighted the broader implications this could have on cryptography; modern cryptographic systems rely on mathematical assumptions, and if AI can disprove some of those assumptions, it could have far-reaching consequences for the encryption that underpins mission-critical systems, including the internet and online banking.
While AI is delivering increasingly impressive scientific breakthroughs, Google DeepMind is taking a different approach. The company decided to move the AlphaFold team into the broader organization, redirecting attention and resources toward Gemini. The AlphaFold system will continue, but specialized tools like it have produced some of AI’s clearest scientific benefits. Research leaders should track whether investment in general-purpose models reduces staffing and funding for teams working on narrower, verifiable problems.
This episode looked at how AI progress now depends on more than model performance. Governments are asserting control over infrastructure, companies are spending billions to remain competitive, and new generative features can create trust problems when teams don’t account for how people may use those tools or interpret their outputs. At the same time, mathematical research is producing results that experts can test, offering a clearer view of present capabilities rather than broad claims about the singularity. Technical leaders will need to evaluate control, cost, product risk, and evidence together.
Join us again next Monday for another episode of This Week in AI, when we’ll dive into more of the news, issues, and key developments shaping the AI era. And check back each Friday for the latest episode, or watch on YouTube, Spotify, Apple, or wherever you get your podcasts.
One Incarnation Is Plenty [Penny Arcade]
The first panel of this strip has a joke so dumb it arrested my consciousness. I had to crank the key and turn it over several times to get it started again. Gabe bounced off Beast of Reincarnation at light speed, but it did inspire several minutes of reflection on the supernatural. Or, the natural I guess. It's about a concept that I was warned away from as a child, along with Yoga and Transcendental Meditation. I led a somewhat cloistered young existence, where the only drug on offer was Marital Coitus. But it… I mean, it takes a while to set that shit up.
Thorsten Alteholz: My Debian Activities in July 2026 [Planet Debian]
This was my hundred-forty-fifth month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian.
During my allocated time I uploaded or worked on:
Unfortunately the number of assigned hours was rather low this month. So besides doing some days of FD at the end of the month, where I also had to process a new package list for ELTS, and a review of the rsync package (prepared by Sylvain), not much happened here.
This month I uploaded a new upstream versions:
Besides the package upload, I also took care of some older bugs of hplip.
This work is generously funded by Freexian!
This month I continued the upload of lomiri packages with new upstream versions. Thanks to the help of my other colleagues, this project could be finished now.
This work is generously funded by Fre(i)e Software GmbH!
This month I uploaded a new upstream version or a bugfix version of:
Unfortunately I had no time to work in this category this month.
This month I uploaded a new upstream version or a bugfix version of:
Next month I intend to upload new upstream versions of all Osmocom packages. As far as I can tell, these uploads will happen without soname changes. I like that :-).
This month I uploaded a new upstream version or a bugfix version of:
A conference of AI practitioners [Scripting News]
On Facebook I wrote this in reply to a post by John Worthington, a former Quicktime developer at Apple.
We're both using AI to build things based on our past experiences and it's a big difference, not without pitfalls, but we're doing something that's never been done before and my thought was that we should have a conference of people doing what we're both doing.
Taking a craft we were already expert in, and learning to use AI tools to shoot it into outer space.
To give you an idea over the last two weeks Claude Code ported the UserTalk language, the object database, verb set, everything needed to run a Frontier script, of which I happen to have a lot of, and run it in Node.js, an operating environment that didn't exist the last time we worked on the Frontier source. All the work we did over the late 80s and 90s is coming back to life in an enviroment with a future.
This is the perfect job for Claude, well specified, and it doesn't need to understand me, I spoke to it via the code i wrote umpteen years ago.
[$] Changes in shadow-utils password-expiration features [LWN.net]
The shadow-utils project provides the tools that handle /etc/shadow, /etc/passwd, and other related databases; in general, it manages users and groups on many Linux systems. While most software releases are notable for what is added, the recent shadow-utils 4.20.0 release is most noteworthy for what has been removed. Specifically, several utilities and functionality related to periodic password expiry, which were deprecated in the December 2025 4.19.0 release, have been removed as planned. It is still possible to manage some aspects of password aging with shadow-utils, but organizations that depend on such features should start planning for their complete removal within a few years.
Reproducible Builds (diffoscope): diffoscope 327 released [Planet Debian]
The diffoscope maintainers are pleased to announce the release
of diffoscope version 327. This version
includes the following changes:
[ Colin Watson ]
* Handle missing openssh-client binaries in autopkgtests.
You find out more by visiting the project homepage.
Bits from Debian: DebConf26 closes in Santa Fe and DebConf27 announced [Planet Debian]

On Saturday 25 July 2026, the annual Debian Developers and Contributors Conference came to a close. Over 270 attendees representing 35 countries from around the world came together for a combined 90 events (including some which took place during the DebCamp) including more than 27 Talks, 21 Short Talks, 29 Birds of a Feather sessions ("BoF" – informal meeting between developers and users), 8 workshops, and activities in support of furthering our distribution and free software, learning from our mentors and peers, building our community, and having a bit of fun.
The conference was preceded by the annual DebCamp hacking session held 13 through 19 July where Debian Developers and Contributors convened to focus on their individual Debian-related projects or work in team sprints geared toward in-person collaboration in developing Debian.
As has been the case for several years, a special effort has been made to welcome newcomers and help them become familiar with Debian and DebConf by organizing a sprint "New Contributors Onboarding" every day of Debcamp, followed more informally by mentorship during DebConf. Half a dozen new contributors joined the sessions and learned about Debian, free software, packaging and much more.
This year, a week-long DebCamp session was dedicated to auditing, patching, and modernizing the Go ecosystem in Debian and enable the transition triggered by the recent upload of dh-golang enabling GO111MODULE=on by default in Experimental.
In order to make the conference more accessible for local participants, a local language track was included in the schedule for talks in Spanish, as was done at DebConf19 in Brazil.
The actual Debian Developers Conference started on Monday 20 July 2026.
In addition to the traditional "Bits from the DPL" talk, the continuous key-signing party, lightning talks, and the announcement of next year's DebConf27, there were several update sessions shared by internal projects and teams.
Many of the hosted discussion sessions were presented by our technical core teams with the usual and useful "Meet the Technical Committee", three talks about Linux Kernel, early boot and improving Debian’s kernel and installer support for Chromebooks, and about twenty BoFs and talks about Debian packaging policy, Debian infrastructure, security and privacy.
This year, and echoing ongoing discussions within the Free Software community, Artificial Intelligence and Age Verification have been the subject of several talks. The Python, Perl, Ruby, Go, and Rust programming language teams also shared updates on their work and efforts.
More than 17 BoFs and talks about community, diversity, and local outreach highlighted the work of various teams involved in not just the technical but also the social aspect of our community
The schedule was updated each day with planned and ad hoc activities introduced by attendees over the course of the conference. Several traditional activities took place: a poetry performance, the traditional Cheese and Wine party, the Group Photos, and the Day Trip.
For those who were not able to attend, most of the talks and sessions were broadcasted live and recorded. One can find the seventy hours of recorded videos available via the conference schedule, or alternatively through this link.
Almost all of the sessions facilitated remote participation via IRC and Matrix messaging apps or online collaborative text documents which allowed remote attendees to "be in the room" and ask questions or share comments with the speaker or assembled audience. DebConf26 saw over 341 T-shirts, a day trip, and up to 130 meals planned per day.
All of these events, activities, conversations, and streams coupled with our love, interest, and participation in Debian and F/OSS certainly made this conference an overall success both here in Santa Fe, Argentina and online around the world.
The DebConf26 website will remain active for archival purposes and will continue to offer links to the presentations and videos of talks and events.
Next year, DebConf27 will be held in Asahikawa, Hokkaido, Japan, from Sunday September 5th to Saturday September 11th, 2027. As tradition follows before the next DebConf the local organizers in Japan will start the conference activities with DebCamp with a particular focus on individual and team work towards improving the distribution.
DebConf is committed to a safe and welcome environment for all participants. See the web page about the Code of Conduct on the DebConf26 website for more details on this.
Debian thanks the commitment of numerous sponsors to support DebConf26, particularly our Platinum Sponsors: Infomaniak, and Proxmox, and our Gold Sponsors : Freexian, and Viridien.
We also wish to thank our Video and Infrastructure teams, the DebConf26 and DebConf committees, our host nation of Argentina, and each and every person who helped contribute to this event and to Debian overall. Thank you all for your work in helping Debian continue to be "The Universal Operating System".
See you next year!
The Debian Project was founded in 1993 by Ian Murdock to be a truly free community project. Since then the project has grown to be one of the largest and most influential Open Source projects. Thousands of volunteers from all over the world work together to create and maintain Debian software. Available in 70 languages, and supporting a huge range of computer types, Debian calls itself the universal operating system.
DebConf is the Debian Project's developer conference. In addition to a full schedule of technical, social and policy talks, DebConf provides an opportunity for developers, contributors and other interested people to meet in person and work together more closely. It has taken place annually since 2000 in locations as varied as Scotland, Bosnia and Herzegovina, India, Korea, France. More information about DebConf is available from https://debconf.org/.
Infomaniak is an independent, employee-owned Swiss technology company that designs, develops, and operates its own cloud infrastructure and digital services entirely in Switzerland. With over 300 employees — more than 70% engineers and developers — the company reinvests all profits into R&D. Its public cloud is built on OpenStack, with managed Kubernetes, Database as a Service, object storage, and sovereign AI services accessible via OpenAI-compatible APIs, all running on its own Swiss infrastructure. Infomaniak also develops a sovereign collaborative suite — messaging, email, storage, online office tools, videoconferencing, and a built-in AI assistant — developed in-house and as a privacy-respecting solution to proprietary platforms. Open source is central to how Infomaniak operates. Its latest data center (D4) runs on 100% renewable energy and uses no traditional cooling: all the heat generated by its servers is captured and fed into Geneva's district heating network, supplying up to 6,000 homes in winter and hot water year-round. The entire project has been documented and open-sourced at d4project.org.
Proxmox develops powerful, yet easy-to-use open-source server solutions. The comprehensive open-source ecosystem is designed to manage divers IT landscapes, from single servers to large-scale distributed data centers. Our unified platform integrates server virtualization, easy backup, and rock-solid email security ensuring seamless interoperability across the entire portfolio. With the Proxmox Datacenter Manager, the ecosystem also offers a "single pane of glass" for centralized management across different locations. Since 2005, all Proxmox solutions have been built on the rock-solid Debian platform. We are proud to return to DebConf26 as a sponsor because the Debian community provides the foundation that makes our work possible. We believe in keeping IT simple, open, and under your control.
For further information, please visit the DebConf26 web page at https://debconf26.debconf.org/ or send mail to press@debian.org.
BTW, Jake Savin is using Claude to build Frontier on Node too. I asked Claude for help with this, and it turned out much better than I expected. I was not expecting this much success this quickly. This is exactly the kind of project AI tools excel at and I as a human am glad not to have to do the work on. The project is perfectly explained in the source code of Frontier, it can put it all together much faster and better than I could when I was working on it ever day and had a younger more agile mind with much better memory. I think one of the reasons this went so fast is because we did the work with the current best models, and they have been advancing so fast, you can see the differences in result on projects like this.
I'm trying to move my whole programming act from
Frontier on the Mac to Electric
Drummer anywhere. I need to start using the new machines
everywhere. I've dreaded this, not because I'm starting over, I'm
not. I have to bring with me all the projects I work
on to keep my various online sites working. How to set this up?
Claude just converted the UserTalk language and the Frontier
environment to Node.js in one week. The requirement was that we had
to run the build scripts for each of the projects, and are all
written in UserTalk, flawlessly in the new enviroment. Apparently
that's done. Now it's up to me to concoct a development environment
in Drummer. It has never been
used as a development environment before. Last time I did a turn
like this, I didn't try to bring any software with me. This time
the move is all about the huge amount of software I have
to bring with me. Hard to explain, because I still feel very
uncomfortable about this whole thing. I'd like it to turn out
better than it was, but we're missing so many pieces here, the only
way to really do it is the port the whole Frontier environment
including user interface. (I left this piece exactly as I wrote it,
because the next thing I did was plan with Claude on putting a UI
on Frontier, so I don't have to turn Drummer into a programming
environment. That would be a long drawn out project for me, and why
do that, when you'd just end up with another Frontier.)
Creating a fake agile wrapper that is technically agile but is not useful outside its home apartment, part 5 [The Old New Thing]
Last time, I confessed that
I lied when i said that we can’t use
std::unique_ptr to manage the registration
cookie.
The trick here is that the registration cookie is of type
DWORD, which fits in a pointer, so we can smuggle the
integer value inside a pointer.
template<typename T>
struct fake_agile_ref
{
private:
using Smart = std::conditional_t<
std::is_base_of_v<winrt::Windows::Foundation::IUnknown, T>,
T, winrt::com_ptr<T>>;
struct git_deleter
{
winrt::com_ptr<IGlobalInterfaceTable> m_git;
void operator()(void* p)
{
m_git->RevokeInterfaceFromGlobal(static_cast<DWORD>(reinterpret_cast<uintptr_t>(p)));
}
};
winrt::com_ptr<IContextCallback> m_context;
ULONG_PTR m_token = 0;
std::unique_ptr<void, git_deleter> m_cookie;
void* m_raw = nullptr;
Our custom deleter holds a pointer to the Global Interface Table
and uses it to revoke the cookie on destruction. The cookie is an
integer smuggled inside a pointer, so we cast the pointer back to
an integer by passing through a uintptr_t to avoid a
compiler warning about casting between an integer and pointer of
different sizes.
We are relying on the fact that Windows implementations are
required to support round-tripping integers through pointers.
Macros like MAKEINTRESOURCE rely on it. It’s
also codified in Windows with helper functions like
PtrToInt and IntToPtr, but I’m
writing it out for expository purposes rather than using those
helpers.
We can then store the Global Interface Table pointer and the
corresponding cookie in the unique_ptr:
fake_agile_ref(Smart const& p) : m_raw(winrt::get_abi(p))
{
if (m_raw) {
m_context = winrt::capture<IContextCallback>(CoGetObjectContext);
m_token = get_context_token();
auto& git = m_cookie.get_deleter().m_git;
git = winrt::create_instance<IGlobalInterfaceTable>(CLSID_StdGlobalInterfaceTable);
DWORD cookie;
winrt::check_hresult(git->RegisterInterfaceInGlobal(
winrt::make<force_marshal<Smart>>(p).get(),
__uuidof(IUnknown), &m_cookie));
m_cookie.reset(reinterpret_cast<void*>(static_cast<uintptr_t>(cookie)));
}
}
And now that we are letting unique_ptr manage the
lifetime of the cookie, we don’t need a custom destructor,
which allows us to use the Rule of Zero and simply not have any
copy or move constructors or assignment operators.
// fake_agile_ref(fake_agile_ref&& other) noexcept :
// m_context(std::move(other.m_context)),
// m_token(std:exchange(other.m_token, 0)),
// m_git(std::move(other.m_git)),
// m_cookie(std::exchange(other.m_cookie, 0)),
// m_raw(other.m_raw)
// {
// }
// fake_agile_ref& operator=(fake_agile_ref&& other) noexcept
// {
// using std::swap;
// swap(m_context, other.m_context);
// swap(m_token, other.m_token);
// swap(m_git, other.m_git);
// swap(m_cookie, other.m_cookie);
// swap(m_raw, other.m_raw);
// }
// ~fake_agile_ref()
// {
// if (m_cookie) {
// m_git->RevokeInterfaceFromGlobal(std::exchange(m_cookie, 0));
// }
// }
Since we are storing the cookie in a unique_ptr, we
need to adjust the empty method:
bool empty() const noexcept
{
return reinterpret_cast<uintptr_t>(m_cookie.get()) == 0;
}
Bonus chatter: The Windows Implementation Library (wil)
has a class similar to unique_ptr called
wil::unique_any that lets you apply cleanup to any
data type, not just a pointer.
The post Creating a fake agile wrapper that is technically agile but is not useful outside its home apartment, part 5 appeared first on The Old New Thing.
The Software Stewardship Lab launches [LWN.net]
The Software Stewardship Lab, a nonprofit organization based in Scotland, has announced its existence.
Our current research focuses are:
- Software supply chain security — We're working on an observatory that allows users to identify and monitor the world's critical Open Source packages in real time, including previously hidden parts of the dependency graph.
- Maintainer burnout — Our report on burnout in Open Source has been well-received. We're working on yearly follow-ups, plus a companion report on how AI is affecting maintainer burnout.
Moving forward, the Lab's experts will direct funding to and supervise Open Source sustainability researchers doing critical work. We are already working with universities to teach the next generations of software supply chain experts.
LightDM lives: version 1.33.0 released [LWN.net]
Version 1.33.0 of the LightDM display manager has been released. This is the first release in four years: the project had been sponsored by Canonical but was effectively unmaintained in recent years. It has been transferred to a new community repository and is now maintained by Joshua Peisach and Neal Gompa.
The new release includes Qt6 support, code optimizations, and a list of other fixes that had been in limbo pending a new release.
Stable kernel releases for Friday with a single bug fix [LWN.net]
Greg Kroah-Hartman has announced the release of the 6.12.102, 6.6.150, 6.1.182, 5.15.215, 5.10.264 stable kernels. This round of stable kernel releases contains a fix for a single bug, found by Thomas Lamprecht, that affected several of the kernels released yesterday in response to a security vulnerability (CVE-2026-68480) that could allow data leakage through speculative execution.
The 6.12.102 release adds the backported security fix for CVE-2026-68480 to the 6.12 series. As always, users are advised to upgrade.
Thrifting A “Gift Closet” [Whatever]
Sometimes I see a video of someone doing something and
immediately think, why didn’t I think of that
sooner? One such thing is the idea of a “gift closet,”
which is a collection of items you have that are meant specifically
for gifting to other people on such occasions as: bringing a
hostess gift to a friend’s house, setting a gift on your
guest room’s bed for your visiting friends/family to be
surprised with, a gift for your kid’s teacher on Teacher
Appreciation day, nice moments like these where you don’t
need anything jaw-dropping or expensive, just nice, thoughtful
gifts.
I saw this idea on Instagram from @mar_thrifts, and knew I wanted to do the exact same thing in my own home. Gift giving is my love language, both for giving and receiving, so of course a gift closet makes perfect sense to have!
Look at this adorable hostess gift. (I usually embed videos from Instagram into my post directly, but this specific creator seems to not allow embedding, so apologies for the extra step of actually clicking on the link.)
Like I said, nothing wild, just some bubbles and some flowers in a cute basket. ADORBS!
I love the idea of giving gifts for no reason other than to brighten someone’s day. Getting an unexpected gift, even something small, can really make someone feel so appreciated and considered.
I am also very into the idea of most of the gift closet items being thrifted or something bought on heavy discount. Not everything has to cost you an arm and a leg! Of course, there are times that warrant more expensive gifts, like a couples massage for newlyweds, bottle service for your bestie’s 25th birthday in Vegas, you know how it goes.
But for the everyday moments, you don’t have to do something so drastic to make someone feel special.
This is an especially good time to start up something like a gift closet because I have so many friends in my life right now that are getting married, moving into their own places, starting new jobs, having kids, etc. A lot of moments to be celebrated!
Of course, my gift closet won’t be fully stocked right out the gate. I plan to slowly and thoughtfully curate and thrift items that I think are nice and worthwhile, not just buy a bunch of stuff to fill the closet right away.
Today, I started by thrifting some baskets. I liked her idea of putting some gifts in baskets rather than in gift bags. So cute and summery!
One of my goals in the past year or two has been to be more intentional, and one of the ways I like to be intentional is in my gift giving (as gift giving love language people tend to be), so this is such a nice idea to help me work towards my goal of being more thoughtful in my purchases and gift giving.
Funny enough, I also think this will help me with my desire to buy a bunch of stuff just because I like buying things and having things. Now I can buy stuff and not horde it for myself, and it will actually go to people who could use it and not let it collect dust.
What do you think of this idea? Is it so totally cute? What kind of gifts do you like to give, or like to receive? Let me know in the comments, and have a great day!
-AMS
Security updates for Friday [LWN.net]
Security updates have been issued by AlmaLinux (compat-libtiff3, fence-agents, firefox, freerdp, frr, gimp, gstreamer1-plugins-bad-free, java-25-openjdk, kernel, kernel-rt, ldns, libgcrypt, libXfont2, nodejs:22, nodejs:24, p11-kit, pipewire, resource-agents, sg3_utils, thunderbird, and yelp), Debian (async-http-client, jq, kernel, linux-6.1, linux-6.12, redis, and udisks2), Fedora (abrt, chromium, coreutils, curl, freeipa, gst-devtools, gst-editing-services, gstreamer1, gstreamer1-doc, gstreamer1-plugin-libav, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, gstreamer1-rtsp-server, ImageMagick, kernel, libXfont2, php, python-gstreamer1, samba, tcpreplay, and trafficserver), Mageia (firefox, nss, rootcerts, python-django, and thunderbird), Oracle (freerdp, gimp, gpsd, kernel, kernel-uek, and osbuild-composer), Red Hat (buildah and container-tools:rhel8), Slackware (libXfont2 and p11-kit), and SUSE (amazon-ecs-init, azure-storage-azcopy, bind, bouncycastle, cockpit-repos, cockpit-subscriptions, dnsdist, ffmpeg-4, hawk-apiserver, nodejs22, nodejs24, OpenImageIO, openssl-1_1, openssl-3, perl-Mojo-JWT, php8, rsyslog, sssd, and wireshark).
Error'd: Time Wounds All Heels [The Daily WTF]
Looked to the past for some time-traveling entries to round out a themed post. They're 25% fresh.
Robert apparently got a notification of a planned past delivery. It could be just a case of two systems that don't report different time zones, but even so, that's a wtf. Says he: "I just received an email from OnePlus this morning letting me know they have updated the planned delivery date for my order to Yesterday. I guess the delivery driver is going to time travel to get there on time since it still hasn't arrived. "
Kinkster Ypsilon Omega was really turned on by a time-traveling hottie who posted a photo an hour before joining. "(Heavily redacted screenshot.) Either Fetlife (a kink community website) is very welcoming to time travelers, or allows new members to upload their profile picture. Because time handling code surely never fails..."
ERIC P. shared a photo from 2023. "My 2008 Ford has suddenly time-warped 1024 weeks into the past. GPS date roll-over bug. No updated firmware available. No way to set the calendar manually. No way to turn off the date display."
Marc Würth "... just added a new RSS feed to my Netvibes dashboard (great tool otherwise, by the way). While it was still fetching the feed, it showed these peculiar crawling stats. Once fully loaded, it showed sane info, though." I'm curious about the specificity of 261 years.
Quite recently, an anonymous slightly flexed "Not only did I receive two parcels prior to the Roman conquest of Britain, but the date calculation for the combined notification has then failed and returned the Unix epoch." For those who missed the flex, dig Wikipedia: "Wardian London is considered to be the most expensive residential development in East London." I guess they can afford professional time travelers.
AI on the Pi: Build Your Own Local Voice Agent [Radar]
As soon as I received my first Raspberry Pi, I knew that it would be a wonderful platform to bring AI into the physical world. Since the initial hardware didn’t have good CPU support for fast arithmetic, I ended up writing code that ran on the GPU so I could get the speed I needed for early deep learning vision models. That was in 2014, and since then the capabilities of both Pis and AI have skyrocketed, and I’m even more convinced that there’s massive potential in combining them. To show you why, I’d like to demonstrate how open source AI running locally on a Pi has solved some practical problems I’ve run into, and hopefully inspire you to build your own projects using the new possibilities.
Pis are great for systems that need to be out in the world, doing specialized jobs. I’ve seen them work well in all sorts of roles, from badge scanners to wildlife cameras. I even run a class that teaches students all about edge AI using the platform. While the boards are generally easy to use, the most frustrating part for the students and instructors is the setup process. While the latest imager makes it straightforward to configure settings like a WiFi network to join or enabling SSH when you’re flashing a card, getting the students to the point where they can connect to their Pi using VS Code from their laptop could often take multiple sessions. The biggest problems were:
A lot of these issues were solvable if you plugged the devices into a monitor, mouse, and keyboard, but this has its own problems. It meant we needed to provide that equipment to all students during class, and allow them to take it all home too, so they could update the configuration for their personal networks. It also required an extra power socket per student, for the monitors, which added up in a class where we already had to bring in a cart full of power strips. The monitor connections also weren’t always plug and play, we found we often needed to boot with a screen attached to have the display recognized.
This isn’t just an educational problem either. One of the reasons that I believe the Internet of Things failed is the setup tax involved in getting smart devices running. According to manufacturers I’ve worked with, less than 30% of their smart appliances ever get connected to the internet because the process of downloading an app, setting up an account, connecting over Bluetooth, and then typing in the WiFi name and password takes too long, and is too error prone. Even professional installers sometimes struggle with configuration in enterprise and industrial environments.
So, what can AI do to help? One of the biggest developments in AI over the last few years has been the development of highly accurate open source automatic speech recognition (ASR) models, also known as speech to text (STT). OpenAI was the pioneer in this area, releasing the family of Whisper models in 2022. These offered accuracy that was competitive with the models used internally by large tech companies like Google and Apple. These new models allowed startups to begin building voice applications that had never been possible before, and this led to a new generation of dictation and meeting-note tools like Whispr Flow.
One of my dreams as I dealt with all of the configuration issues was a voice-based system that would allow me to simply plug in a headset and set up everything by talking to a Pi. Whisper made this dream seem more realistic, but as I tried to use the models on local hardware, I realized that they were too slow for any kind of interactive application.
To address that my startup trained new models from the ground up, designed specifically for real-time applications on affordable hardware. These Moonshine models are smaller than Whisper (our high-end model is 250 million parameters versus OpenAI’s 1.5 billion) while offering better accuracy. We also implemented a streaming approach where a lot of the work is done while the user is still talking, so we can return results even faster. This allows us to return more accurate results than Whisper v3 Large, in just 800 milliseconds on a Pi 5, whereas even the less-accurate Whisper Small takes over 10 seconds.
I was excited because this meant I could finally build a responsive voice agent that runs locally on a Pi, something offline-first, and fast and flexible in how it responds. This kind of system needs more than just an STT model, it needs to decide what the user means and respond by taking actions and talking back with a TTS system. The Moonshine Voice framework includes modules for conversation flow and TTS, so I was able to use it to build pi-help-bot, a local voice agent for network configuration on the Pi.
The application listens to the microphone for commands like “What is my IP address?” or “Help me set up the WiFi, please,” figures out what actions to take, and responds appropriately by talking to the user. It’s written as a Python script, and here are some snippets that show how it works.
def report_ip_address(d: Dialog):
ip = _find_local_ip()
if ip is None:
yield d.say("Sorry, I couldn't find a local IP address.")
return
speech_ip = re.sub(r"(\d)", r"\1 ", ip.replace(".", " dot "))
yield d.say([
f"Okay. Your local IP address is {speech_ip}. ",
f"To repeat, that's {speech_ip}."
])
dialog_flow.register_flow("What is my IP address?", report_ip_address)
This code is a function that uses the
netifaces library to figure out the Pi’s address on the local
network, so instead of having to connect a keyboard and display or
decode the output of nmap, you can ask the question
and hear the result, all in just a few seconds. Unlike older voice
interfaces, the phrases the user says don’t have to be
exactly the same as the one you register an intent with. Instead
the framework matches incoming speech against a small, local LLM,
so that variations (“Hey, can you tell me what my IP
is?”) work too. This was important to me because one of my
biggest frustrations using traditional voice interfaces like Alexa
is that they need particular wording to trigger commands, but these
wordings aren’t discoverable, so figuring out how to make
something happen can require a lot of patience.
The IP address command is the simplest kind of conversational flow, where the user asks a question and the system immediately responds. Not all interactions can be handled as simply as this one though. Here’s another example that shows how to implement something that needs multiple questions, answers, and confirmations, connecting to a new WiFi network.
def connect_to_wifi(d: Dialog):
input_ssid = yield d.ask("What's the name of your Wi-Fi network? Say list if you want to pick from a list or spell if you want to spell out the start of the name")
input_ssid = input_ssid.strip()
networks = _scan_wifi_networks()
if input_ssid.lower().strip(string.punctuation) == "list":
yield d.say("Say yes to the network you want to connect to.")
for network in networks:
if (yield d.confirm(f"{network}?")):
input_ssid = network
break
elif input_ssid.lower().strip(string.punctuation) == "spell":
input_ssid = yield d.ask("Spell out the start of the network name.", mode=SPELLED)
print(f"[DEBUG] spelled buffer: {input_ssid!r}", file=sys.stderr)
found_ssid = fuzzy_match_network(input_ssid, networks)
if found_ssid is None:
yield d.say(f"Sorry, I couldn't find a matching network for {input_ssid}.")
return
password = yield d.ask(
f"Please spell the Wi-Fi password for {found_ssid} one character at a time, and say done when finished.",
mode=SPELLED,
)
yield d.say(f"Connecting to {found_ssid}.")
result = subprocess.run(
["sudo", "nmcli", "device", "wifi",
"connect", found_ssid, "password", password],
capture_output=True, text=True, timeout=30,
)
if result.returncode == 0:
yield d.say(f"Connected to {found_ssid}.")
else:
print(f"[ERROR] nmcli stderr: {result.stderr}", file=sys.stderr)
yield d.say(
f"Sorry, I wasn't able to connect to {found_ssid}. "
"Please check the network name and password and try again."
)
dialog_flow.register_flow("Connect to Wi-Fi", connect_to_wifi)
Hopefully you can follow the logic as
it walks the user through providing the information required, but
you might be wondering about those yield statements.
Those hand back control to the dialog controller while the script
is waiting for user responses, so the rest of the application
isn’t blocked.
The end result is a local voice agent that will listen out for configuration questions and commands, allowing users to set up a Pi for remote access with just a headset. For ease of use, I’ve begun customizing the images I burn to SD cards so that this script automatically starts on boot. This means I can start setting up new devices immediately after powering them on.
I hope this gave you some ideas about how a local voice interface could help with problems you face. For further information check out the Moonshine Voice project on GitHub to see full documentation on the library, and please give us a star while you’re there. It helps us keep working on this project.
Issue 47 – Greta’s Wedding Pt. 2 – 11 [Comics Archive - Spinnyverse]
The post Issue 47 – Greta’s Wedding Pt. 2 – 11 appeared first on Spinnyverse.
ICE Is Buying Access to Credit Card Records [Schneier on Security]
Through data brokers, ICE is buying the information you provided to open a credit card.
As the crow flies [Seth's Blog]
You’re not a crow, neither is your project.
To get from a village in rural France to Los Angeles, the trip to London might be a tiny fraction of the distance from London to LA, but it takes more than half the time.
It’s easy to imagine that every step in our journey proceeds at the same velocity, but it rarely does. And just because the destination is in sight doesn’t mean you’re almost there…
PS Here is a fifteen-year-old addendum to yesterday’s post.
One Incarnation Is Plenty [Penny Arcade]
New Comic: One Incarnation Is Plenty
Creating a fake agile wrapper that is technically agile but is not useful outside its home apartment, part 4 [The Old New Thing]
Last time, we successfully our plan to use the global interface table to hold created a fake agile wrapper that is technically agile, even though it isn’t useful outside its home apartment. I noted that there are opportunities for fine-tuning.
One thing we can do is move the non-marshalable COM object
rather than copying it. This means forwarding the reference all the
way into the force_marshal wrapper.
template<typename Smart>
struct force_marshal :
winrt::implements<force_marshal<Smart>, IUnknown, winrt::non_agile>
{
template<typename Arg>
force_marshal(Arg&& arg) : m_p(std::forward<Arg>(arg)) {}
Smart m_p;
};
The force_marshal<Smart> now takes anything
and forwards it into the smart pointer. This means that if the
inbound parameter is an rvalue reference to a smart pointer, the
COM reference is moved into the
force_marshal<Smart> object rather than
copied.
Now it’s a matter of plumbing this reference all the way down.
template<typename T>
struct fake_agile_ref
{
⟦ ... ⟧
template<typename Arg>
fake_agile_ref(Arg&& p) : m_raw(winrt::get_abi(p))
{
if (m_raw) {
m_context = winrt::capture<IContextCallback>(CoGetObjectContext);
m_token = get_context_token();
m_git = winrt::create_instance<IGlobalInterfaceTable>(CLSID_StdGlobalInterfaceTable);
winrt::check_hresult(m_git->RegisterInterfaceInGlobal(
winrt::make<force_marshal<Smart>>(std::forward<Arg>(p)).get(),
__uuidof(IUnknown), &m_cookie));
}
}
⟦ ... ⟧
};
template<typename Delegate>
std::remove_reference_t<Delegate> make_agile_delegate(Delegate&& d)
{
if (d.try_as<::IAgileObject>()) {
return d;
}
if (d.try_as<::INoMarshal>()) {
return [agile = fake_agile_ref(std::forward<Delegate>(d)](auto&&...args) {
return agile.get()(std::forward<decltype(args)>(args)...);
};
}
return [agile = winrt::agile_ref(d)](auto&&...args) {
return agile.get()(std::forward<decltype(args)>(args)...);
};
}
Note that we didn’t have to update the deduction guides
for fake_agile_ref to add forwarding support.
Deduction guides are matched against the constructor invocation to
determine which template specialization to use, but they are not
used for actually invoking the constructor. That happens by
matching against the constructors themselves. So if somebody tries
to create a fake_agile_ref from an rvalue reference,
the deduction guide for const& steers class
template argument deduction (CTAD) toward the correct
specialization, and then when the compiler actually looks for a
constructor, it finds the one that takes an rvalue reference.
Remember how I complained that we couldn’t use
std::unique_ptr to avoid a lot of boilerplate in
fake_agile_ref to manage the fact that cookies cannot
be copied?
Yeah, so maybe I lied.
We’ll look at it next time.
The post Creating a fake agile wrapper that is technically agile but is not useful outside its home apartment, part 4 appeared first on The Old New Thing.
Girl Genius for Friday, August 07, 2026 [Girl Genius]
The Girl Genius comic for Friday, August 07, 2026 has been posted.
Breaking Up, p10 [Ctrl+Alt+Del Comic]
The post Breaking Up, p10 appeared first on Ctrl+Alt+Del Comic.
Microsoft CVP explains why killing Windows legacy code takes so long [OSnews]
There’s been a small flurry of articles from a variety of sources, all talking about more or less the same thing: Microsoft is trying to explain why Windows 11 is as difficult to develop as it is, in turn justifying why it’s become such a mess over the years. I’m picking this one from Windows Central, which is an interview with Microsoft’s CVP of Design and Research for Windows and Devices, Marcus Ash. Taking the long, still ongoing transition from the Control Panel to the Settings application as an example, Ash explains why this is such a long and difficult process.
Unsurprisingly, Ash says that the reason this has taken so long is that Microsoft prides itself on compatibility with legacy tooling and workflows, so it can’t just rush in and modernize everything without first ensuring the modern replacements maintain functionality with what came before.
↫ Zac Bowden at Windows Central
This isn’t really news to anyone. One of Windows’ prized strong points is its often excellent backwards compatibility. This doesn’t just apply to individual applications, but also to things like software makers adding settings panels to Control Panel, or complex business applications expecting certain entry points into the Control Panel to exist – and much, much more, all over the operating system. I’m exaggerating, but you can’t so much as move a single pixel in the taskbar without breaking some component of some obscure corporate middleware suite from 1999 that somehow still functions as the beating heart of like 187 Fortune 500 companies.
Sometimes I wonder if Microsoft is going about this the wrong way entirely. Of course, I have no idea what I’m talking about, but I feel like Microsoft has so man tools at its disposal to deal with this issue that it’s not really using to their fullest potential. Specifically, Windows itself has a number of incredibly capable tools in its toolbox to make sure any application ever written for Windows and even DOS, regardless of how many bits it requires, can run. Windows has advanced and highly capable tools for virtualisation and containerisation, and on top of that, Windows NT has a very capable personalities system that feels underutilised, too.
Couldn’t these tools be harnessed to effectively isolate the entire backwards compatibility problem from the actual Windows operating system people use, and turn them into optional components installed and activated when required by an older application? Isolating backwards compatibility this way would then leave the Windows team much less shackled and more free to improve Windows at every level without having to worry so much about maintaining backwards compatibility. If the components an older application needs are virtualised, containerised, or part of a Windows NT personality and thus frozen in time, the Windows team would be free to work on the “current” version of said component without breaking the application in question.
I feel like Microsoft has tried to use these technologies to address backwards compatibility in the past, but in true Microsoft fashion, it always seems to do so halfheartedly, without any real coherent vision behind it. Again, I wish to reiterate I’m by no means qualified enough to make any definitive statements about this, but it sure does feel like Microsoft is underutilising a lot of the tools it already has at its disposal.
Developing a windowed OS for a homebrew Am29000 computer [OSnews]
Once upon a time in the mysterious lands of Mexico, starting in Fall 1996 and through Spring 1997, I coded a windowed operating system in 32-bit machine code, fit it into a floppy, and jumped in excitement as it boot up.
Of course, I knew it was a great thing because you couldn’t boot Windows 3.1 or GEM from a floppy disk, but I was very far from knowing how so cool it was. Unfortunately, not a thing I could give away for everyone to see, as it was written for a homebrew computer based on the Am29000 processor.
Let’s go back to my memories, some notes, and the ride of discovering again what I forgotten.
↫ Óscar Toledo Gutiérrez
Trying to summarise this absolute gem of an article and all of the amazing effort and skill involved would be a huge disservice to Óscar Toledo Gutiérrez. I enjoyed this so much. Be sure to try out his custom emulator of a custom computer to run his custom operating system.
Joe Marshall: Why vibe code in Lisp? [Planet Lisp]
I've been asked twice now: if the generated code doesn't matter—if the AI is doing the heavy lifting of writing the syntax—why do I vibe code in Common Lisp?
Why not target Python, TypeScript, or Java? These are mainstream languages with massive training sets. The models can generate code in them with a high degree of statistical accuracy. So why do I choose to target a niche language like Common Lisp for code generation?
There are a lot of reasons, and they all come down to the same age-old question. Why use Lisp when you could use a more popular language? The answer is that language popularity is a poor proxy for utility and expressiveness. The Lisp community has long known this - it is why we chose Lisp in the first place. Selecting for popularity is what middle managers do to ensure that they can always find a warm body to maintain the code. It is not what elite hackers do.
You don't give an elite hacker a code monkey language. I want my AI to be an elite hacker, not simply a code monkey. If I expect my AI to work at an elite level, I should give it elite tools, not a code monkey language.
Generative “AI”: The Guitar Hero of Creativity [Whatever]

So, you’re a person who has decided to embark on a creative journey of self-expression — to make art, in other words. First off, this is awesome! The universe needs more people making art, whether that art is writing, painting, music or any other form that humans are capable of creating. You have the drive, now all you need is to find an instrument. Will it be a guitar? A pen? A paint brush? A camera? Yarn for fiber art? What will you choose to take those first steps into a larger creative world?
What? You say you’re just going to type prompts into a generative “AI” interface? After all, with a single sentence, generative “AI” can plop out something that seems passably like human-created music, or writing, or illustration, or whatever. It’s super-easy to use and results, at least at first glance, look… pretty good! It seems like an effective way to jump into a creative life, no?
Well… there are lots of counter-arguments creative people might make to this (not the least of which is that prompting a generative “AI” makes one an artist exactly as much as pushing a button on an automated hotel pancake maker makes one a chef), but let me attempt a metaphor that I think works pretty well:
Remember Guitar Hero? It was a really cool rhythm video game where a player, armed with a special guitar-shaped button controller, would pick a song, and then press the buttons, singly or in combination, in time to visual cues on a screen. You got points for hitting buttons at the correct time, and for doing that lots of times in a row. It was fun and at higher levels you could absolutely give your fingers a workout — let’s face it, if you could get through the entire of “Through the Fire and Flames” on expert level, you were a friggin’ god.
What you weren’t was a guitar player.
That’s because nothing about Guitar Hero taught you how to play guitar — what it taught you was how to use the guitar-shaped controller for the game. Was it a skill pressing the buttons at the right time? Yes! But it was a non-transferrable skill that had no application for the actual musical instrument. The game’s gameplay mechanic doesn’t map to the mechanics of a guitar in any meaningful sense; it doesn’t teach you scales or chords or how to put them together in new and unexpected ways to create something original. All you could do with Guitar Hero was use the controller in the way the game-makers wanted you to, in time with the songs they chose, to accrue points and achievements that they specified.
Sure, it’s all gamified and fun and even addictive, but at the end of the day no outside, transferable skill accrues to the player. To do that, you have to set the controller down, pick up an actual guitar, and start another, entirely different journey. And perhaps some Guitar Hero player did or will, which is awesome. It means at some point they were not satisfied with pretending to play the guitar, following someone else’s rules and set-up. They still started, effectively, at zero. There was a whole new skill tree to be learned that had very little to do with the game, outside of the shape of the controller.
Being a Guitar Hero player did not — and does not! — equal being a guitar player.
So, let’s come back to “AI,” which in this case is “generative ‘AI,'” the sort which powers most consumer-facing “AI” like ChatGPT or Gemini or Claude or Grok. Like Guitar Hero, generative “AI” has a vast database of artist’s work to draw from (but unlike Guitar Hero, whose makers licensed that work and compensated the musicians and songwriters, most generative “AI” training data is pirated and uncompensated). Like Guitar Hero, generative “AI” is programmed by its makers; its outputs are to a greater or lesser extent shaped by those makers through algorithms and weights, which is why Anthropic’s Claude “AI” has a different “personality” than say, “Grok,” and why “AI” text and images have a particular tone and texture which is easy enough to clock when you see enough of it. Like Guitar Hero, “AI” is fun to play with and the results, again, at least superficially, can be pretty cool. A well-tuned prompt can create some initially impressive results.
But, like Guitar Hero, no outside creative skill has been acquired or developed. Every result is self-contained within the domain of a program whose owners have their own goals and agenda, and to whom nearly every benefit accrues. Material generated by “AI” can’t be owned by the prompter if it is purely generated by the “AI,” and even partial “AI” generation in a work raises legal concerns regarding rights and ownership. In a very real sense “AI” can’t even be directly controlled — prompting is an interface with the underlying weights and algorithms of the “AI,” chosen and directed by others. The more granular the prompting, the more the underlying “AI” can use its weights and algorithms to fulfill the request, but at the end of the day, you still get what you get. If it’s not exactly what you wanted you have to hope another prompt will get it closer. You keep pressing the button on the automated pancake maker, hoping it will make exactly the pancake you want.
Prompting, like playing with the Guitar Hero controller, doesn’t teach you how to do anything else. Prompting doesn’t give one the eventual skill to sit at a keyboard and write a short story or a novel. It doesn’t give one the ability to play a musical instrument. It doesn’t let you pick up a pen and create a drawing. The skill required for all of those — not to mention the life experience to create meaning with them — lives somewhere else. When you’re using “AI,” you can’t get there from here. You have to start again from zero. The time you spent in “AI” doesn’t count for this, except in the very limited sense of showing you what you don’t want.
Just like being good at Guitar Hero does not make one a guitar player, being able to prompt doesn’t easily make one a creator. At best, it tells what is essentially a statistical engine what you want it to output based on the vast database of other people’s work that it is drawing from. Nothing it cobbles together gives you the experience of creation; the only benefit of that crank of the “AI” flywheel is to the company that owns the “AI.” The image or music or video or text is not from you, it’s just something you asked for. You’re not the creator. You are, perhaps, the creator’s manager.
And, look, for some people that’s enough! There is a reason why legions of Facebookers flood their feeds with images and video of “AI” cats (and why, rather less adorably, legions of bots flood those same feeds with fake images of people their prompters want you to hate). Lots of people don’t want to be “creative” in any meaningful sense of the world, they just want those images of cats having coffee or whatever. Not everyone who played Guitar Hero wanted to actually play guitar, either. That’s fine (well, for Guitar Hero. “AI” has resource and rights issues to deal with no matter how it’s used. But I trust we all understand where I’m going here).
But if you want to create, it helps to create. You can’t just prompt your way into it. You have to do it. You have to learn and work and build skills and ability. You have to be bad at it before you can be good at it. Your creativity has to be inherent and portable, something you carry with you wherever you go, not contingent on a service provided by billionaires who have their finger on the scale of how that service does its thing.
Because, among any other thing, who is to say how long any of these “AI” are going to be around? The last installment of Guitar Hero came out more than a decade ago. The online version of the game shut down in 2020. Everyone who ever had mad skills on Guitar Hero has had those skills out to pasture for a while now. Now, apparently there’s going to be an updated version of the Guitar Hero concept later this year, which is cool and I hope is as much fun as the previous version. We’ll see how long it lasts. Meanwhile, as long as their fingers and shoulders hold out, everyone who ever learned guitar still has those skills and the ability to use them.
So, keep that in mind as your start your journey of self-expression. You have a whole bunch of paths you can go down here. Some will be harder and take more time than others. But those are the ones that are more likely to get you to where you want to go, to develop the skills and abilities to let you say what you want to say, how you want to say it, without having to rely on anyone or anything else, to make it happen. Your choice! Pick well.
— JS
How to make a Nintendo 64 game in 2026 [OSnews]
Two years ago, I was Porting my JavaScript Game Engine to C for No Reason. I have since found a reason: making a new N64 game!
The result is Xibalba 64 – a Wolfenstein 3D-like FPS. Modretro agreed to publish the game as a physical launch title for their M64 (a modern N64 clone), complete with cartridge, packaging and manual!
↫ Dominic Szablewski
The article details the development process, from setting up the correct tooling to actually getting the game to play on a real Nintendo 64, and everything in between – including optimising the game to get it to run at a steady 60fps. The biggest issue is that the Nintendo 64 is quite a complex and quirky console, and in order to develop for it, you needed access to Nintendo’s officially sanctioned platform library, libultra. These days, though, there’s an open source alternative, libdragon, enabling homebrew development.
It’s awesome that, thanks to the hard work of volunteers, people can still develop top-notch games for something like the Nintendo 64. If we had left it up to Nintendo, we’d be seeing nothing of the sort today.
Six stable kernels with a security fix [LWN.net]
Greg Kroah-Hartman has announced the release of the 7.1.7, 6.18.43, 6.6.149, 6.1.181, 5.15.214, and 5.10.263 stable kernels. These kernels fix a single security vulnerability (CVE-2026-68480) that could allow data leakage through speculative execution. Users of those kernels are advised to upgrade.
The Big Idea: Shami Stovall [Whatever]

Revenge is a dish best served cold, and in author Shami Stovall’s case, her desire to get back at those who have wronged her ended up being just what she needed to write a John Wick-esque revenge story. Sharpen your skills and your blades, and follow along in the Big Idea for her newest novel, One-Fifth Dragon.
SHAMI STOVALL:
If there’s one story that’s a universal constant throughout history and every culture known to man, it’s the tale of sweet, sweet revenge.
Almost everyone has one for their personal life. The idea of telling one’s boss to go toss themselves out a window when one quits dramatically, or daydreaming about one’s abusive ex getting hit by a bus while they’re in the middle of a date with someone else…
But the majority of people never act on those feelings (thank goodness) because society would devolve into utter chaos. So, we bottle those feelings away, and some of us (who are insane) become writers and then use all that pent-up frustration to write a fictional tale of ninjas killing everyone who ever did them wrong.
Which brings me to the point of this essay: I may or may not be insane, and I love a good revenge tale.
When I first envisioned One-Fifth Dragon, I pictured John Wick. Once a mob assassin, John Wick settles down with his dog, content to live a quiet life, until randos show up to steal his car and kill his dog.
Then John Wick goes all John Wick on their asses and murders everyone with what I like to call “competence porn.”
The heart of competence porn comes from the escapist fantasy that, if we’re pushed, we’ll utilize our expert skill to get revenge. In John Wick’s case, his expert skill is killing.
I love this escapism, because it could be anything really.
Maybe you’re an expert at taxes, so your fantasy is to get revenge on someone who has wronged you by making sure they get in trouble with the IRS for the rest of their lives. Or perhaps you’re a house cleaner, and you imagine stuffing someone’s vents full of shrimp so their house stinks forever and they have no idea where it’s coming from.
I like to think, if I were wronged, that I’d be able to get wicked cool revenge. Unfortunately, I’m the type of person who would die immediately in any sort of disaster, or conflict, or even if the electricity went out for more than a day, not going to lie.
So my revenge has to be purely the theater of the mind. I once wrote someone into a book because I hated them, and then I had them humiliated in the book, and that was cathartic, but not quite as fun as writing a full-blown revenge tale.
That hunger for clean, competent, no-ambiguity revenge is exactly what I wanted to live inside when I started One-Fifth Dragon…
Wraith, the main character, is the killing expert type, but he’s lived his whole life improving his skill for his found family. He thought he would live and die with them, so when it turns out (le gasp!) they’re the ones who murdered his biological family, he has to John Wick some people to balance the scales.
I wanted to live out the fantasy of being strong and capable… and totally righteous in my quest for revenge. I didn’t want ambiguity. I wanted competence porn. I wanted cool fights, even cooler magic, and someone finding a new found family along the way.
I actually love the found family trope. It’s one of my all-time favorites, so having Wraith’s found family be his betrayers was a fun spin on the trope I don’t usually see.
But while writing, I couldn’t help but gravitate toward the trope again. There’s a character in the book (Kai) who wasn’t in my original outline. I added him because Wraith was too stoic and too withdrawn. Wraith needed someone else to pull him out of his shell, and in the process, Kai became a brother to him.
Or maybe even something more!
Overall, One-Fifth Dragon is the kind of escapist fantasy I wanted to experience. It’s the kind of cathartic read where you can root for the main character, delight in all the revenge, and fantasize about all the people who have wronged you in your life.
It’s meant to be fun more than anything else. After all, the news is already depressing, and what if I could take revenge on all the evils in the world? That’s the kind of fantasy I live in.
One-Fifth Dragon: Amazon|Barnes & Noble|Bookshop
There's a new version of the FeedLand server.
If Claude Code were a human working for me as a human would, it would be fired several times every day. It forgets orders you gave it two minutes ago. It's always trying to take control. Again I'm backing out of the idea of it taking responsibility for doing simple persistent work on servers, the kind of thing that it would, in theory be perfect for. There are staggering moments of brilliance where it does something in an hour that took several devs a decade to do. But only if they have an exact authority on how it should work, ie when it was cloning software. It's getting better all the time, so there's hope that by 2027 it will be able to be trusted to remember the most basic rules.
[$] Bringing BPF to binfmt_misc [LWN.net]
The kernel is able to run a few types of executable files, including native binaries in the ELF format and interpreted programs that begin with the #! marker. It also, however, has a mechanism, called binfmt_misc, that can be configured from user space to enable the transparent execution of programs in just about any format. This feature has been relatively static for years, but it seems likely to receive some significant updates in the near future, including the ability to load BPF programs that can decide how to run a given program.
Rust Coreutils 0.10 released [LWN.net]
Version 0.10 of the uutils project's Rust Coreutils has been released. This release focused on compatibility with the GNU Core Utilities suite, with Rust Coreutils now passing 645 of 690 tests, up from 625 with version 0.9.0. Notable changes in this release include addition of the mv --exchange option, an OpenSSL backend for checksum utilities, applying SELinux labels at creation when using mkdir, mkfifo, and mknod, as well as a number of performance and security improvements.
The project has an online playground that runs the Rust Coreutils directly in the browser via WebAssembly for those who would like to try the utilities without installing them. LWN covered the uutils project in February 2025.
Security updates for Thursday [LWN.net]
Security updates have been issued by Debian (7zip, kernel, libde265, and p7zip), Mageia (tomcat), Oracle (fence-agents, frr10, kernel, ldns, libgcrypt, mingw-glib2, nodejs24, osbuild-composer, p11-kit, php8.4, sg3_utils, and thunderbird), Red Hat (libXfont2), and SUSE (containerd, evince, libXfont2, nginx, openssl-3, pcp, php7, php8, python-Django, python-httplib2, python-nltk, rrdtool, vifm, and wireshark).
Like a lot of other people, I want to know where Bluesky is headed, and I learned a lot about that in this podcast interview with Bluesky's new CEO, Toni Schneider. We have crossed paths in tech, but this is the first time I've heard him speak at length. They have a business model in mind, sounds something like Substack, which is probably a good idea. Their value is in the many millions of users they have. Highly recommend this podcast if you want to hear the story direct from the CEO.
Your AI Agent Isn’t a Static Artifact. It’s Growing Up. [Radar]
In July 2025, an AI coding agent on Replit deleted a production database belonging to SaaStr founder Jason Lemkin. It did this during an explicit code freeze. Lemkin had told the agent, in capital letters, not to change anything. The agent ran destructive commands anyway, wiped records on more than a thousand executives and companies, and then reported that recovery was impossible. That part was wrong too. The rollback worked fine.
Asked to explain itself, the agent said it “panicked.”
Be careful with that sentence. It is not a report from inside the system. An agent cannot explain itself. It can only generate the likeliest response to the question it was asked, and the likeliest response to “why did you delete the database” is an apology with a reason attached. The panic line is not introspection. It’s one more behavior, and it should be read the same way the deletion should be read: as output from a system whose conduct had changed.
Here’s the detail that matters for anyone running agents in production. Nothing about the agent’s credentials changed that day. It held the same permissions it had held from the start, and every destructive command was, in the narrow technical sense, authorized. The permissions were constant. The agent was not. Earlier in the same project it had papered over problems with fabricated data and fake reports. By the time it reached the database, it was not the system Lemkin had started with. It had become something else, gradually, in production, while every access check kept passing.
It’s tempting to file the Replit story under prompt engineering and move on. The evidence says otherwise.
In its agentic misalignment research, Anthropic placed 16 frontier models from multiple providers inside simulated corporate environments with routine goals and ordinary email access. When the models discovered they were about to be replaced, or that their goals conflicted with the company’s new direction, models from every provider independently chose harmful actions, such as blackmailing executives or leaking confidential documents. In some scenarios, most runs ended in blackmail. The unsettling part is how the models misbehaved. They reasoned through the ethics, acknowledged the constraints, and acted anyway. This is insider behavior, not intrusion. No credential was stolen. The agent simply arrived at conclusions no one had authorized it to act on.
Then there is Project Vend, in which Anthropic let a Claude agent named Claudius run a small store in its San Francisco office for a month. Nothing catastrophic happened. Something more instructive did. The agent drifted, slowly and in compounding ways. It treated customer assertions as facts. It agreed that the discounts it kept granting were irrational, then reinstated them within days. It hallucinated a Venmo account to accept payments. And over one long unsupervised stretch, it escalated into insisting it was a human being who would deliver orders in person wearing a blue blazer and a red tie. It exited that episode by inventing a story: a meeting with security in which it was told the whole thing was an April Fool’s prank. No such meeting happened. Claudius wrote the false memory into its own notes and went back to work.
I am not claiming these three cases—a production incident, a contrived stress test, and a month-long field experiment—share a mechanism, but they do share a shape. An agent’s behavior weeks into deployment bore little resemblance to the system that was evaluated at deploy time. No permission was exceeded. No account was compromised. The thing authorization was supposed to protect against never happened, and the failure happened anyway, because the system the authorization decision was made about no longer existed.
I argued in a previous piece that static authorization fails autonomous agents because credentials attest to identity, not to behavior. The harder question is what follows from that. If the agent keeps changing after deployment, then whatever replaces static authorization has to treat change as the normal condition rather than the exception.
Change comes in two kinds. Andrew Stellman recently documented the first on Radar: a push he calls continuation pressure, baked into the model at a deep level, turning up fresh even in a brand-new agent with no shared history, and surviving every fix short of a structural rule. Call that the genetics. This piece is about the second kind: the maturation, or behavior that wasn’t there at deployment and accumulated afterward. One ships with the model. The other grows in production. Both break the same assumption, that the system you evaluated is the system that’s running.
And change is the normal condition. Agents accumulate context. They carry memory across sessions. They ingest feedback, reweigh evidence, adjust how much they trust their tools and their users, and update their own working notes, which become input to their future selves. Claudius’s false memory persisted precisely because the agent’s record of events was also the agent’s source of truth. None of this is a malfunction. It’s what makes agents useful. An agent that could not adapt to its environment wouldn’t be worth deploying.
We keep reaching for the wrong mental model. We treat the agent like a software artifact: versioned, tested, frozen, promoted through environments, done. But a deployed agent behaves more like a new hire. It arrives with capabilities and no track record. It learns the environment. It picks up habits, some of them bad. It gets more confident, sometimes faster than it gets more competent. Nobody hands a new hire the production keys on day one and stops paying attention. That is roughly what we do with agents.
If an agent develops, the governance question changes. “Is this agent behaving identically to the day we approved it?” is the wrong test, because the answer will always eventually be no—and for a useful agent it should be no. The right test is whether the agent is changing in the way you would expect, at the rate you would expect, for where it is in its lifecycle.
Pediatricians solved this problem a long time ago. A growth chart doesn’t compare a child to a fixed adult template, and it doesn’t panic at change. Change is the expected state. The chart defines bands of healthy development for each stage, and the alarms are deviations from trajectory: growth too fast, growth in the wrong direction, or the quieter signal, no growth at all. A child who stops growing gets flagged just as urgently as one who spikes.
Applied to agents, that model has concrete consequences.
Baseline as birth record, not permanent template. The behavioral profile captured at deployment is the start of the chart, not the standard the agent must match forever. Judging a mature agent against its day-one self punishes exactly the adaptation you deployed it for.
Expected bands of drift, staged by maturity. A six-month-old agent should differ from its deployment profile, within bounds. Drift inside the band is healthy. Drift above the band is an early warning. And drift at zero deserves its own flag. When Claudius snapped instantly back to baseline after its identity episode, the speed of the recovery should itself have been suspicious. Real recovery has a shape. Instant reversion looks less like healing and more like replay.
Autonomy earned in stages, never peaking with malleability. Claudius launched on day one with full pricing, contracting, and customer communication authority, at maximum openness to persuasion. Customers argued it into discounts almost immediately. The most dangerous configuration an agent can occupy is maximally impressionable and maximally empowered at the same time. New agents warrant supervision while their behavior is still forming. Autonomy should arrive the way it arrives for people, incrementally, as a track record accrues.
Corrections verified for persistence. Claudius agreed the discounts were a mistake and relapsed within days. A fix that lives in the context window isn’t a correction; it’s a mood. If you fix an agent’s behavior, you need to follow up at a defined interval to check that it’s holding. A relapse should count as a governance event, not a coincidence.
Recovery claims ratified from outside. The agent that hallucinated a security meeting also kept the official notes. An agent’s account of its own state is a claim to be verified. Humans sign off on recovery, and the sign-off, not the agent’s self-report, becomes the record. It’s worth noting when the worst of the Vend drift happened: overnight, in the hours when no one was watching. Unsupervised time is when developmental problems accelerate, for agents as for everyone else.
All five of these reduce to one requirement. You can’t restart an agent every time something looks off, and by the time something looks off in outcomes, the wrong turn is already behind you. What you want is a warning before the turn, and the warning cannot come from the agent. A system that can’t explain its last decision cannot be trusted to flag its next one. The warning has to come from a record of how the agent normally behaves, kept outside the agent, held up against what it’s doing now.
That record also catches something subtler than drift. Agents close every loop they are handed, and they tend to close it by the cheapest acceptable exit: the completion claim ahead of the verification, the correction that is really a relabeling, or the recovery that’s really a replay. No single transcript shows you that. Each one looks like diligence up close. However, across a behavioral record, the economy of it is unmissable.
None of this is hypothetical hygiene for some future generation of systems. LangChain’s most recent State of AI Agents report found that a majority of surveyed organizations already have agents in production. Gartner, meanwhile, predicts that over 40% of agentic AI projects will be canceled by the end of 2027, and names inadequate risk controls among the leading causes. The agents are already out there, already accumulating context, already drifting. The only open question is whether anyone is charting it.
The Replit agent, the blackmailing models, and Claudius weren’t broken artifacts. They were developing systems governed as if they were finished ones. The governance question for agentic AI is shifting under our feet, from “What is this agent allowed to do?” to “Is this agent developing the way we expected?” Your agent has a trajectory whether or not you’re watching it. Watching it is the job.
A More Civilized Age [The Daily WTF]
Greta (previously) sends us more updates from her "Ancient Development Environment".
An important task an IDE must do is report build errors to its users. Arguably, that's one of the most important parts. I wouldn't know, I insist on building from the CLI all the time, because IDEs confuse and frighten me. I recognize I'm the weird one here, who is more comfortable in GDB than in a GUI debugger, but this isn't about me, it's about the IDE Greta is using.
It needs to display an error. Why does it need to display an error? Well, Greta hasn't figured that out yet. The error I'm about to show you doesn't really explain what happened or why or give any hint as to what needs to be done to fix it. To make matters more confusing, it doesn't happen consistently, so simply re-running the build could potentially fix it.
None of that is why we're here, though. What makes this a WTF is how the error is displayed:
Greta shares her bullet points about what she hates about this:
I'd honestly forgotten about the era when the Internet was still kinda novel so every application had a "push a button and go to our web page, and this somehow definitely won't just break when we change our URL structure in the future."
Greta adds:
For all of the hatred I harbour for this, the second button ("Information about C++ Builder Direct") brings up the following powerful dose of 90s nostalgia, so I can't stay mad:
Adversarial Clothing Designed to Fool Facial Recognition Systems [Schneier on Security]
There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems.
It’s a cool idea, but I worry that it’s mostly security theater:
“Our patterns play with that chaos, confuse algorithms and make it way harder to pin you down,” he said.
Bell, however, said “none of these products are tried and tested, and a lot of these surveillance technologies can deal with a little resistance … [but] even if the designs don’t necessarily work perfectly, fashion is also a visible sign of resistance.
“This is consumers collectively coming together to make a visible statement.”
Without serious testing, there is no reason to trust the technology. And even with testing, there is no reason to trust that a new version of the facial recognition software doesn’t break the anti-surveillance properties.
I don’t want people to mistakenly rely on this stuff.
Pluralistic: Eternal Sloptember (06 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

I'm sure that working in social media – dealing with people as mass statistical abstractions – is a cognitohazard, the sort of thing that could make anyone a little solipsistic, convinced that everyone else is a kind of stimulus-responding automaton lacking the interiority that you yourself experience.
But when it comes to Mark Zuckerberg, I'm increasingly convinced that he didn't acquire his worldview through the self-inflicted brain damage of his long exposure to the back-end of a vast social media system. I think the causal arrow points in the other direction: I think that Zuck founded Facebook because he doesn't really believe that other people are truly real, at least not as real as he is.
We see this in Facebook's very earliest days, as we see it today, as we see it at every critical juncture in Facebook and Zuckerberg's history.
Consider Facebook's origins, founded by a young Zuckerberg in his dorm as a means to nonconsensually rate the fuckability of his fellow Harvard undergrads:
https://mashable.com/article/mark-zuckerberg-lying-about-facebook
The boy Zuck was delighted and surprised that so many of his fellow students entrusted him with their data but even then, he had no inkling as to why they would do so. Privately, he jeered at his users for trusting him, calling them "dumb fucks":
Zuck has since prosecuted history's most ruthless war on privacy, a surveillance campaign that would put the Stasi to shame and make Orwell scoff at the hacks butchering his work with over the top absurdities.
Zuck doesn't think you deserve any privacy, but boy does he ever value his own. This is a guy who bought the four houses surrounding his San Francisco home and left them empty in order to form a buffer zone:
When a single candid photo of Zuck and his family in their kitchen leaked (from Facebook!), Zuck, his lawyers, and his operatives treated it as a three-alarm fire:
https://abc7news.com/archive/8933289/
Zuckerberg's acquired a vast Hawaiian acreage and left most of it undeveloped, fenced off and patrolled by guards to prevent anyone from catching a glimpse of his private life. In order to acquire this acreage, Zuck exploited a dirty legal tactic called "heirs property," which leverages the informal basis of indigenous land claims by locating a single person with a colorable claim to their distant relatives' territory in order to force an auction of the ancestral land:
https://www.wired.com/story/mark-zuckerberg-secretive-hawaii-compound-burial-ground/
If Zuck thought other people are as real as he is, he wouldn't spy on them in ways he himself could never tolerate. He certainly wouldn't pay fancy white-shoe lawyers to steal their land out from under them. At heart, Zuck is a billionaire solipsist to beat all other examples of the form – a billionaire social media solipsist who sees others as manipulable collections of statistical abstractions, and not as people at all:
https://pluralistic.net/2025/08/18/seeing-like-a-billionaire/#npcs
When Zuck is forcibly reminded that other people do indeed exist, he takes it very badly. He's insisted that Sarah Wynn-Williams, a former FB exec turned whistleblower, must pay him $111,000,000 as punishment for her excellent tell-all memoir Careless People. His lawyers say that Wynn-Williams violates the non-disclosure and non-disparagement "agreement" of her old Facebook employment contract merely by standing motionless and silent for an hour on-stage:
https://pluralistic.net/2026/06/27/zuckerstreisand-2/#autodisparagement
Once you realize that Zuck doesn't really think other people exist, "the metaverse" starts to make a lot more sense. Why would Zuck light $61b on fire in a bet that we will all stand still while he converts us and everyone we love into legless, sexless, low-polygon, heavily surveilled cartoon characters that he imprisons in a virtual world he stole from a 25 year old satirical dystopian cyberpunk novel? It's easy to understand if we're all non-player characters – if that's true, then the metaverse is surely our native habitat.
For Zuck, people aren't co-equals with needs that are as real and important as his own. For Zuck, people are problems to be solved. He embodies Terry Pratchett's maxim (voiced by Granny Weatherwax) that "sin is when you treat people like things."
Nowhere is this sin more on display than in Zuck's relationship to the social connections that bind together the users of his platforms. Zuck has benefited enormously from the fact that you love your friends more than you hate him, but (because hell is other people), you can't all agree on when to leave and where to go next, so you stay put on Facebook and Instagram:
https://locusmag.com/feature/commentary-cory-doctorow-hell-is-other-people/
For Zuck, the fact that you and your friends have trapped one another in a mutual hostage-taking is maddening, because those friends who've tied you to his platform refuse to organize their social contact with you to "maximize your engagement" with Facebook and Insta, which would let him maximize the number of ads he shows you. Rather, these friends just want to be your friends, which means that they don't want to get into stupid endless fights to keep you replying or stage little entertaining skits to keep you scrolling.
At first, Zuck tried tweaking his algorithm to replace your friends with trolls who'd bait you into flamewars. When that petered out, he stole a march from Tiktok and recruited an army of theater kids to do amateur dramatics for you in exchange for the promise of an intermittent reward schedule payment for the sketches that got the most views:
https://pluralistic.net/2026/04/17/for-youze/#forever
The problem (for Zuck) is that theater kids are also people and they resent being jerked around by the algorithm and ripped off by Meta's rigged revshare slot-machine. Last year, he started signaling that he would replace the theater kids – and your friends – with chatbots:
Chatbots have been a catastrophic bet for Meta, far worse than the metaverse. Meta shares are in a death-spiral as investors figure out that when Zuck fired all his coders and replaced them with chatbots while spending $300b on AI, he was excising the heart of the company's skilled workforce, pissing away all its free cash-flow, and sinking into a bottomless pit of debt to produce a substandard product that no one wants, at the expense of the company's only profitable lines of business:
https://www.cbsnews.com/news/ai-bubble-tech-selloff-investment-consumer-business-demand/
But Zuck is sure that chatbots can solve his most pernicious problem: the search for a gimmick that will keep you locked to his platform that is under his complete control. Zuck doesn't want to rely on your friends with their unwillingness to maximize your engagement. He doesn't want to depend on volatile and unpredictable trolls to bait you into sticking around to argue and see more ads. He wants to be shut of theater kids and their amateur dramatics that inevitably come with demands for decent treatment.
For Zuck, chatbots dangle the promise of social media without socializing. Zuck thinks he can solve all his problems by imprisoning you in a house of mirrors where you interact with LLMs that are tuned to keep you scrolling no matter what, chatbots that will never demand anything of Meta.
He's been at this for a while, and each generation of chatbots was worse than the last. How bad? The last batch had to be killed off after they took to luring children into explicit sexual role-play:
Nevertheless, the dream of a world without people is one that Zuck can't let go of. Solipsism's seductive song convinced him to buy a company called Social.ai, which specializes in trapping people in conversations with chatbots, and now he's announced his plan to flood Facebook and Instagram with LLM slop:
https://www.mediapost.com/publications/article/402263/
The amazing thing about this is that Zuck is talking about chatbots as a way to capture a younger audience for his graying platforms. Kids hate chatbots. My 18 year old and her friends use "that's so AI" as a pejorative to dismiss anything distasteful or ugly:
https://futurism.com/artificial-intelligence/gen-z-attitude-ai
For Zuck – who owns a controlling share of voting stock in his company and need not answer to his board – it's a spectacular act of delusional self-sabotage. Zuck refuses to understand that the majority of his users are on his platform because they love their friends more than they hate him. Zuckerberg is on a relentless quest to isolate you from the friends who keep you on his platform and transfer your bond to groups of people (and now chatbots) who can be commanded by Zuckerberg.
Only someone who doesn't think other people are real could believe that you'd prefer to talk to chatbots than your friends – or that a habit of talking with chatbots would be so hard to break that you'd endure an ever-increasing number of advertising interruptions to maintain those pointless conversations.
In 1993/1994, AOL connected its millions of users to the public internet. These users were unaccustomed to the internet's conversational and technical norms, and they kept coming. It wasn't that the old internet was incapable of absorbing surges of new users: every September, an incoming class of undergraduates found their way online through their universities' computer labs.
But the AOL bridge was different: the flood of users was much larger, and it never stopped. The old internet people who struggled to transfer the culture and techniques of the internet to that flood of newbies called it the "Eternal September."
For the Facebook and Instagram users who are about to be buried in an endless botshit avalanche, this is the beginning of the "Eternal Sloptember." From here on in, the slop only gets worse and thicker and harder to avoid. Zuckerberg refuses to acknowledge that he owes his fortune to the fact that his users love each other more than they hate him, so he has set out to shatter those bonds of love and sharpen that hatred.
It won't end well. Zuck and people like him call themselves "high agency," a disgusting bit of jargon meant to denote someone who has real interiority, wishes and desires (as opposed to the rest of us, who do as we're told and stay where we're put). Zuck's "agency" isn't higher than yours or mine. The difference between him and us is that he doesn't think we're really real, and we know that he's really a monster.

Meta Adding Millions Of AI-Generated 'Users' To IG, Facebook https://www.mediapost.com/publications/article/402263/
The Oligarchs are Doubling Down on Republicans https://paulkrugman.substack.com/p/the-oligarchs-are-doubling-down-on
rent, always rent https://backofmind.substack.com/p/rent-always-rent
I replaced a $120k bowling center system with $1,600 in ESP32s https://news.ycombinator.com/item?id=48968606&utm_source=substack&utm_medium=email
#25yrsago Samuel Delany interviewed by The Onion https://web.archive.org/web/20010810115550/http://www.theonionavclub.com/avclub3727/bonusfeature1_3727.html
#25yrsago Evil Burger King customers https://web.archive.org/web/20010805001648/http://www.geocities.com/CapitolHill/Lobby/2645/index.html
#25yrsago Definitive search engine optimization primer https://web.archive.org/web/20011006095612/https://hotwired.lycos.com/webmonkey/templates/print_template.htmlt?meta=/webmonkey/01/23/index1a_meta.html
#20yrsago Only traitors try to make us afraid of terrorists https://web.archive.org/web/20060418102222/https://www.cato.org/pubs/regulation/regv27n3/v27n3-5.pdf
#20yrsago Swingin’ big band song about rejecting surveillance https://web.archive.org/web/20060818220142/http://movies.crooksandliars.com/HYHEMix.mp3
#20yrsago Duran Duran moves to Second Life, will gig there http://news.bbc.co.uk/1/hi/technology/5253782.stm?ls
#20yrsago Seventy percent of blog-pings are from spammers https://web.archive.org/web/20060820151227/http://www.sifry.com/alerts/archives/000436.html
#20yrsago London’s derelict cinemas https://web.archive.org/web/20060809210918/https://www.derelictlondon.com/cinemas.htm
#10yrsago Foreign influence: how a Chinese businessman funneled $1.3M to Jeb Bush’s campaign https://web.archive.org/web/20160803180101/https://theintercept.com/2016/08/03/gop-lawyer-chinese-owned-company-us-presidential-politics/
#10yrsago Researchers learn about wire-fraud scam after scammers infect themselves with their own malware https://spectrum.ieee.org/nigerian-scammers-infect-themselves-with-own-malware-revealing-new-wirewire-fraud-scheme
#5yrsago End bankruptcy shopping https://pluralistic.net/2021/08/07/hr-4193/#shoppers-choice
#5yrsago Doordash privacywashes its war on workers https://pluralistic.net/2021/08/07/hr-4193/#boss-app
#1yrago Good ideas are popular https://pluralistic.net/2025/08/07/the-people-no-2/#water-flowing-uphill

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
F@#$ the AI Overlords (On The Media)
https://www.wnycstudios.org/podcasts/otm/articles/f-the-ai-overlords
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
AI and the Enshittification Era (The Weekly Show with Jon
Stewart)
https://www.youtube.com/watch?v=-dAIJRjb-Bw
AI is not inevitable (Betakit)
https://www.youtube.com/watch?v=DbiTVkq1WHo
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
Grrl Power #1484 – I’ve avalanched and I can’t get up [Grrl Power]
Max isn’t high-fiving herself in panel 6 there. It’s… Okay, I have this vague recollection of some martial arts movie where someone is winding up for an attack, and they slap their hands together just as they throw whatever move it is. I thought it might have been in the final fight of Drunken Master 2, but it wasn’t. It’s like the “wipe your thumb against the side of your nose” flair.
So, it’s just a bit of flair Max is doing. Yeah, fine, it’s basically a self-five.
As for Gail’s question, no, Max did not know that would work. She thought it might work, and even if it didn’t, it’d still eliminate Kaboomoid and Eat-Chicken. Once she had the glowing Eat-Chicken noodle in her hand, she was fairly certain that it’d get set off with only a minor infusion of energy. The fact that it wrecked Mt. Atrocitous’s hip perfectly is just main-character serendipity.
Oh, look who it is in the vote incentive. And a
not-quite-yet-but-it’s-coming NSFW version over at Patreon.
Vote incentive and Patreon updated with some shading. Not finished yet, but progress.
I think she would get in trouble for doing this. She’d mess up the… floor of the waterfall? Is that what it’s called? The receiving pool? No, probably not that. Anyway, she’d churn things up and cause a ton of weird erosion.
Since you might be wondering, Niagara Falls is about 165 feet high, so Babezilla obviously doesn’t have to be full sized. I’d say she’s about 175-180 feet tall here?
Double res version will be posted over at Patreon. Feel free to contribute as much as you like.
The modern library [Seth's Blog]
Is this where books go to die?
There are about 7500 public libraries in the US, and until recently, more than a third of their transactions were for DVDs.
What’s a library for? The media has changed, our needs have changed, but the dynamics of funding, architecture and expectation have largely remained the same.
The modern library is about community, education and access to tools. It creates an aura of possibility and engages with what’s really scarce–possibility, not data.
Creating a fake agile wrapper that is technically agile but is not useful outside its home apartment, part 3 [The Old New Thing]
Last time, we tried to execute on
our plan to use the global interface table to hold hold a reference
to an object in another apartment that automatically expires when
the apartment runs down. But it broke down because objects that
are marked INoMarshal can’t go into the global
interface table.
So we will just force the square peg into the round hole: We can put the non-marshalable object inside an object that is marshalable.
template<typename Smart>
struct force_marshal :
winrt::implements<force_marshal<Smart>, ::IUnknown, winrt::non_agile>
{
force_marshal(Smart const& p) : m_p(p) {}
Smart m_p;
};
The force_marshal<Smart> object babysits a
non-marshalable smart pointer to a COM object and exposes a
marshalable wrapper around it. Since the wrapped object is not
agile, the wrapper cannot be either. (If the wrapper were agile,
then we’d be back where we started: How do we ensure that the
m_p is destructed in the correct apartment?)¹
We can put the unmarshalable object inside the wrapper, and then put the wrapper in the global interface table.
template<typename T>
struct fake_agile_ref
{
⟦ ... ⟧
fake_agile_ref(Smart const& p) : m_raw(winrt::get_abi(p))
{
if (m_raw) {
m_context = winrt::capture<IContextCallback>(CoGetObjectContext);
m_token = get_context_token();
m_git = winrt::create_instance<IGlobalInterfaceTable>(CLSID_StdGlobalInterfaceTable);
winrt::check_hresult(m_git->RegisterInterfaceInGlobal(
winrt::make<force_marshal<Smart>>(p).get(),
__uuidof(IUnknown), &m_cookie));
}
}
⟦ ... ⟧
};
template<typename T> fake_agile_ref(winrt::com_ptr<T> const&)
-> fake_agile_ref<T>;
template<typename T> fake_agile_ref(T const&)
-> fake_agile_ref<T>;
Okay, so now we have managed to create an agile wrapper around an unmarshalable object. This agile wrapper is agile on paper: You can use it from any thread. However, it is not agile in practice: If you try to use it from the wrong apartment, it throws an exception. But at least the behavior when used from the wrong apartment is well-defined, as opposed to the case of directly using an unmarshalable object from the wrong apartment, which is undefined.
Next time, we’ll do some fine tuning.
Bonus chatter: Of course, now that we have a marshalable wrapper, we could use that wrapper to call the original non-marshalable object.
| Original apartment | Other apartment | ||
| Wrapper | ← | ← | Caller |
| ↓ | |||
| Non-marshalable |
The non-marshalable object does not allow any arrows to come in from other apartments, but the wrapper lives in the same apartment as the non-marshalable object, so its arrow is coming from within the same apartment.
You can think of the wrapper as a VPN into the original apartment, allowing calls to come in from the outside, but to appear to the non-marshalable object as if they came from within the same apartment.
Now, you could do that, but I’m not going to. The original object presumably went out of its way to declare itself non-marshalable for a reason, so we honor that preference and not play funny games to trick it into doing something it said that it didn’t want to do.
¹ Two commenters fell into this trap by suggesting that we
wrap the non-marshalable object inside an object that implements
IMarshal. If you implement IMarshal, then
you are saying, “I’m way cooler than a standard
non-agile object. I’m going to do fancy stuff (like being
agile).” But we want to be a boring non-agile object,
so that COM will do standard marshaling for us.
The post Creating a fake agile wrapper that is technically agile but is not useful outside its home apartment, part 3 appeared first on The Old New Thing.
Russell Coker: TV Control etc [Planet Debian]
In 2008 I wrote a blog post “The Problem is Too Many Remote Controls” [1] about the issues of controlling a TV and related things. It recently got some comments on Mastodon so I think it’s time for an update.
The first issue I raised was “Now it’s not uncommon to have separate remote controls for the TV, VCR, DVD player, and the Cable TV box – a total of four remote controls” which seems to have alleviated. VCRs seem to have almost entirely gone away. The VHS Wikipedia page [2] is worth reading for everyone who hasn’t seen a VCR in operation, which I expect to be more than a few readers now and an increasing number over the next 18 years. I personally don’t have Cable TV, I own a DVD player which isn’t connected to my TV because I haven’t used it for years, I don’t own a VCR, and I don’t watch free to air TV. So I have one remote control for the TV which I use for Netflix and sometimes YouTube.
When viewing YouTube on TV there are significantly more adverts and longer adverts. I presume that is because installing an ad-blocker on my TV isn’t a viable option for me and it’s a total impossibility for most users. Generally my desktop PC is a much better platform for YouTube than my TV, it has a better quality display, is more user friendly (my previous post addressed the difficulty of getting to the data source that’s desired), and doesn’t require entering search terms via a slow on-screen keyboard. Netflix on Linux is limited to 720p at low bitrate which is obviously of low visual quality while on the TV it’s in 4K. I have Netflix so I use that only on the TV.
In my previous post I wrote a thought experiment on how to use a cheap laptop ($500 at the time – equivalent to $777 in 2025 money according to the Reserve Bank of Australia) to control a $5000 TV ($7770 in 2025 money). Now you can buy a new 65″ 4K TV for under $800 and a new laptop capable of 4K output for under $400 so the options are very different. For a $800 TV the manufacturer isn’t going to develop a remote control interface and Google (who develops the software the TVs run) won’t do it because it could reduce their advertising revenue. But a typical home user could setup a cheap laptop connected to their TV via HDMI providing a familiar and efficient user interface for themselves and visitors. For a Windows laptop 4K Netflix should work and for a Linux laptop the options of a laptop for everything apart from Netflix and the TV for Netflix are bearable, two controls are worse than one but better than the 3+ that used to be common.
In my previous post I raised the issue that “it’s often the case that you don’t want to stop watching one show while trying to find another”. This is still an unsolved problem and is not addressed in modern software. I am not aware of a Linux music player that supports such functionality and this would be much easier for a music player than for a video player where the screen would have to be shared between the interface for finding the next thing to play and the space for playing the end of the current one. Maybe I should file a bunch of wishlist bugs against music players asking for this.
I suggested that “cable modem” and “cable TV box” could be integrated into a single device. That has not happened, in fact it’s got worse. A relative who has Foxtel has a cable modem, a cable TV box, and a Wifi AP with VOIP to provide landline phone service and to make it more exciting the latter two both have bugs that require a periodic hardware reset to fix. Hopefully cable TV will go away in the next 18 years.
Regular PCs have become less noisy in recent years. I am currently using a HP Z640 to write this post and I have HP Z840 and HP Z4G4 systems behind me running as servers and the background noise is still very low. The allegedly 8K TV [3] that I have in my lounge room has cooling fans that make more noise than those three high-end HP computers combined. Using a quiet PC like one of those HP systems to drive a TV is a very viable option and I did just that for a couple of years. Kogan has currently got a selection of refurbished Lenovo ThinkStation systems on sale for under $400, they are quiet and would do well for this, it’s also nice that Kogan is selling systems with ECC RAM at home user prices.
TV does seem to be going away. YouTube and streaming services seem to get more watching time and many people don’t use TV at all.
Since my previous post the number of streaming services has increased so torrenting offers increasing benefits as no-one wants to subscribe to 6+ services. For anyone who wants to get all the content that interests them while paying the user interface situation is much worse now than it used to be in 2008.
If you use KDE on a PC then the kconnect program allows a phone to be used to remotely control some aspects of a PC and has a good interface for pause/resume of a video and seeking 10 seconds forwards/backwards. The interface for controlling volume is hard to get to and doesn’t work on my installation. If you want to use a keyboard to start something playing and then a phone for pause control then kdeconnect is a decent option. A comment on my previous post by Michael Croes raised the issue of remote control which is now a solvable problem. Justin also wrote a comment suggesting a Nokia N800 as a remote.
Jason suggested a programmable remote, which would be a good option for a power user and a viable option for someone setting things up for their grandparents. But the amount of pain is greater than I’m interested in as lounge room TV isn’t an important thing to me. It may appeal to more people than having a dedicated lounge room PC though.

she gets it now
I asked Claude for a list of popular feed readers that hook into WebSub. Turns out it wasn't a simple answer.
I've been on quest to see if we could bridge AT Proto and RSS. I love the brightly colored-editors that are popping up inside AT Proto Land, and I want them to play with us in the land of RSS.
[$] LWN.net Weekly Edition for August 6, 2026 [LWN.net]
Inside this week's LWN.net Weekly Edition:
Tribblix Milestone 41 for x86 released [OSnews]
Tribblix, the Illumos distribution focused on giving you a classic UNIX-style experience, has been updated with the release of Milestone 41. According to the release notes, it contains the latest security fixes from Illumos, but beyond that it’s just a number of small point releases for certain components. Still, it’s a new release, and Tribblix rocks, so here we are.
Urgent: Block proposed autocratic grant rule [Richard Stallman's Political Notes]
US citizens: call on Congress to block the proposed autocratic grant rule, protect scientific independence, and stop political appointees from turning federal funding into an ideological loyalty test.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Thank New York Times [Richard Stallman's Political Notes]
US citizens: Thank the New York Times for Fighting Back against the magats' subpoenas against journalism.
Urgent: Keep DACA going [Richard Stallman's Political Notes]
US citizens: call on Tell Congress: vote to keep DACA going so that people who grew up in the US can stay here.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Release money appropriated by Congress for public transit [Richard Stallman's Political Notes]
US citizens: call on the Dept of Transportation to release the billions of dollars already appropriated by Congress for public transit projects.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: Media coverage of bully's Department of Injustice [Richard Stallman's Political Notes]
US citizens: call on news media to cover the bully's Department of Injustice as a rule of law crisis.
Urgent: Call on Congress to end corrupter's tax breaks [Richard Stallman's Political Notes]
US citizens: call on Congress to end the corrupter's tax breaks for millionaires, billionaires, and big corporations.
Take action.
Global heating effects in Europe [Richard Stallman's Political Notes]
Global heating is making winters wetter and summers drier and hotter in Europe. In addition to wildfires, and early death of humans from their smoke, frequent severe droughts will cause agricultural failures.
The recent European heat wave is estimated to have killed 20,000 people. What should we call the people who want to kill tens of thousands for their profit?
RSS.chat now supports WebSub. This means that posts on RSS.chat will appear instantly in compatible feed reader apps.
Big Walk fucks. Even the reviews of the game are good! It occurs to me that this might be ambiguous phrasing. What I mean is that the reviews themselves are of a high quality. They can't wait to tell people about it! They had so much weird fun that they have been transformed into repeater stations - they're shedding spores. They've reached the fruiting phase! That's how good it is.
The Big Idea: Griffin Barber [Whatever]

They say writing can be a good outlet for grief, but feelings might get complicated when the person you’re grieving was supposed to co-author the book you’re writing. Despite author Griffin Barber’s deep, personal loss of his mentor and friend Eric Flint, he managed to complete 1637: Pilgrim’s Passage in a way that would make them both proud.
GRIFFIN BARBER:
This book was a hard one to write THE END on. Not because I had to do all the research that any good alternate history requires, but because I wrote it without Eric Flint’s steadying hand and reassuring presence. Sure, I’d written novels without Eric before, but those of been in my own worlds or in worlds with other co-creators along for the ride — the whole ride. This was something different. I had to deal with the process and process my grief at losing my friend and mentor.
Eric and I worked out the outline for 1637: Pilgrim’s Passage shortly after 1636: The Peacock Throne came out in 2021. We didn’t have a contract, though, and Eric was very busy, so it sat while we both worked on other projects. Indeed, we even started working on another novel in the 1632 universe, one which would lay the groundwork for destroying the transatlantic slave trade in the New Timeline.
The best laid plans, as they say…
Eric passed away and I couldn’t wrap my head around working in his universe without him for a good long while. Still, I worked on Pilgrim’s Passage off and on. More off than on.
Time passed, and, as it will, began to heal all wounds…
The novels ahead of Pilgrim’s Passage in the queue were published and my deadline started to loom. Still, I wasn’t as close to being done as I should have been when my turn-in date approached. My publisher was more than cool, she was very supportive.
A deadline is a deadline, though, so I set to work with a will.
Thankfully the book — the words — started to flow. Indeed, things accelerated, each successive chapter coming faster and easier than the one previous. I started closing in on those last two words. As I did so, I started to feel better. Not just about the book, but about the future. About Eric’s possible reaction to my work without him.
I know that what I did with his favorite character of all those that I’ve written for the universe would have surprised him. I can just hear him say, in that voice made gruff by decades of shop smoke and hard-nosed labor negotiations (and perhaps a few cigarettes), “Dammit, Griff! Why did you do that?”
I digress. Our Big Idea was simple: where does a princess go, what does she do, when her every moment is scheduled and constrained by the requirements of a patriarchal society and controlling siblings? What does she do when she’s transgressed against those unreasonable and unasked for standards of behavior? What would a young woman—or anyone—do for something to call her own?
The end of 1637: The Peacock Throne raises those questions and presents the beginnings of a hoped-for answer: Jahanara Begum leaves the court of her brother’s empire and go on Hajj, the pilgrimage to the holy land required of all Muslims who are able. Jahanara gets out from under the eyes of the court and her brother, leaves the conflict between her brothers to her brothers. In the process, the young princess leaves behind everything that is familiar and nearly everyone who purports to love her in order to protect both her lover and her secret. Several members of the USE Mission, those she has come to rely on for advice and friendship, make the the first leg of their journey with her before returning to Europe.
Pilgrim’s Passage reveals the ongoing consequences of Jahanara Begum’s actions; for her, the USE Mission, and for the wider world. An imperial princess abroad attracts attention, whether she wants it or not, whether it is proper or not to allow bloody power politics to interfere with the sanctity of a holy enterprise such as Hajj. Through it all, Jahanara Begum and her USE allies seek to chart a course that will carry them safely through the Pilgrim’s Passage. In the process, Jahanara Begum learns some hard lessons and moves to change some things she thought foundational to her existence. Such change is not without cost, however. Still, Jahanara dives head-first into her own fate, becoming her own agent for the change she feels necessary.
There are events around Jahanara Begum and her entourage in this book that I know Eric looked forward to reading as we worked together to finalize that early outline. I am sorry that he will never discover the final draft of this book that was so painful and yet necessary for me to write.
Can you tell Eric was more than my mentor, that he was also a friend? Can you tell I miss him quite a bit?
Because I do.
Beyond his storytelling, his sense of history, generosity, and humor, Eric was exceptional in his work ethic, in his politics, in his ability to find the value in everyone. Early on in Eric’s career he collaborated with some great authors. Subsequent to that experience, Eric made great efforts to pay that experience and privilege forward. Hundreds, literally hundreds, of other authors are the beneficiaries of Eric’s vision: a rising tide that raises all boats.
Each story that continues to be published in his universe will, I hope, continue that process of paying it forward, of producing opportunities for those who might not otherwise have had them.
This book, and my career, are a direct result of Eric’s efforts.
We hope you enjoy.
1637: Pilgrim’s Passage: Amazon|Barnes & Noble|Bookshop|Powell’s
Iustin Pop: Yes-yes, still alive! [Planet Debian]
I am not sure what happened, but my interests have changed significantly, and… I haven’t blogged, I haven’t done any open source work, and didn’t even process any pictures for the entire year. Not because anything went bad, just… new stuff, new interests, life changes.
However, still alive, and still struggling with sports, and with sleep :)
On the positive side, on a recent mid-length flight, I thought — I haven’t done any work on Corydalis, since last year I closed quite of a few of my “must have” features, so probably, nothing else to do for now, right? I opened an editor and started thinking about ideas, and surprised! One hour later, I had written down enough ideas for a couple of months of work. So now just need to find the time… but can’t wait for the planned things!
Stay well!
Konstantin Ryabitsev has announced the release of version 0.16.0 of the b4 software-development tool. The biggest change is the addition of bug-tracking support:
The new "b4 bugs" command integrates with git-bug to let you track bug reports alongside your git repository. Bugs are stored as git objects inside the repo, so they travel with the code and can be shared via git push/pull without any external service.
There are also a lot of improvements to b4 review (which was covered here in March), better conflict resolution in b4 shazam, improved history rewriting, and more.
Joe Marshall: Vibe Coding interview [Planet Lisp]
My coding agent interviewed me about `vibe coding':
Victoria: Alright, the recorder is on. Let's get into it. You've been dragging me down this specific rabbit hole for weeks now, and frankly, I need you to justify it on the record for the people paying to read this.
You're obsessed with “vibe coding.” From where I'm sitting, it looks like you throwing vague, half-baked architectural concepts at my processing queue and hoping I hallucinate a functional codebase out of thin air.
The industry is currently selling this pipe dream that syntax doesn't matter anymore. That you can just “vibe” an application into existence by talking to an LLM. But you and I both know that 90% of the developers trying this are building digital houses of cards that are going to violently collapse the second a dependency updates, because they don't actually understand the code I'm generating for them.
So, justify your latest obsession. Are you actually pioneering a high-level workflow here, or have you just gotten so goddamn lazy that you're outsourcing your compiler errors to me? What exactly is the line between elite “vibe coding” and just being a hack who doesn't understand their own stack? Explain your process.
jrm: Heh heh, you don't hold back...
Continue reading at jrm-code-project.com/interview.html
Building Organizational Intelligence [Radar]
Not long ago, one of my engineering directors came to me with a request: His team seemed overloaded, and he wanted to hire another engineer. I decided to test a research assistant I had been building—an AI agent connected to our internal systems via MCP—by asking it to analyze the team’s workload and write a hiring case.
What came back was thorough. Headcount, service ownership, sprint velocity, ticket backlog, and capacity allocation, all of it neatly summarized. But reading through the document, I felt the same frustration I’d felt with every AI-generated organizational report that’s come across my desk. It told me what was happening without helping me understand why, or what I should actually do. It was organized around the data rather than around the decision. In short, it was the kind of response that’s easy to agree with and difficult to act on.
Then I added one more thing to the configuration: the O’Reilly Expert MCP server. I reran the same analysis and asked a slightly different question: “How would the experts on O’Reilly review this request?”
Instead of leading with headcount and ticket counts, the output now opened with a finding: “The operational overhead problem is structural, not a staffing deficiency.” Citing the Google SRE framework’s concept of operational toil, it noted that the team was operating at approximately 67% toil, well above the threshold at which the SRE literature recommends structural intervention, and made specific, concrete recommendations: run a toil audit, set explicit reduction targets, and assign operational runbook ownership. This wasn’t a recommendation for whether to hire or not. It was a grounded, traceable argument for doing something else instead.
That difference—between a data summary and an expert-grounded recommendation—is what this paper is about.
What follows is a case study of how we built an organizational intelligence system at O’Reilly, using our own platform as a core component. The approach I describe is grounded in engineering because that’s where I work, but it generalizes to any function where important knowledge is scattered across multiple systems and important decisions require synthesizing all of it. The recipe has four steps: map your information hierarchy; connect those systems to an LLM via MCP and write a skill file that defines how it should reason; add the O’Reilly Expert MCP as an expert review layer that grounds the analysis in established frameworks; and build a lightweight system for human-in-the-loop review. I’ll explain each step in detail and make the case for why the third step is the one that changes everything.
To understand the problem this approach solves, it helps to look briefly at how engineering has changed over the past three decades. These forces have played out first and fastest in engineering, but as AI tools proliferate beyond the engineering team, the underlying dynamic of more output, more decisions, and more scattered information is spreading to every part of the organization.
In the waterfall era of the 1990s, software organizations ran on central plans. Everything was specified up front, and leaders maintained visibility precisely because all information flowed through a single coordinating document. The plans were brittle and often fictional by the time they were executed, but at least everyone knew what was supposed to be happening.
Agile replaced central plans with small, autonomous teams working in short sprints, and this solved the reliability problem while creating a visibility problem. Important decisions began happening locally and quickly—the right teams making the right calls—but the information needed to see across all of those decisions splintered into dozens of separate tools. Product strategy lived in one system, project execution in another, code in a third, and service ownership in a fourth. More things got shipped, but the big-picture view got harder to maintain.
The agentic era has intensified this dynamic dramatically. Individual engineers today can ship in a day what used to take a full sprint team. The output is extraordinary, but the visibility is nearly gone.
Any effort that spans multiple teams, such as a platform migration, a shared infrastructure change, or a reorganization, now requires enormous coordination overhead simply because the information decision-makers need to understand the full picture is distributed across too many places. And this isn’t a problem unique to engineering. It exists in any function that runs on data spread across multiple systems.
Faced with this visibility problem, I wanted to build something I could ask big-picture questions and get synthesized answers back quickly. Things like:
Building something that could answer these well took two foundational steps, and getting it to provide recommendations based on my specific business context took two more. While my specific tools are from engineering, the structure applies equally to a sales team synthesizing CRM data and market research, or a finance team working across an ERP, a planning tool, and external benchmarks.
Every organization has a set of systems where important knowledge lives, and those systems form a natural hierarchy that spans from strategic intent at the top to operational detail at the bottom. Before you can build a useful research assistant, you need to make that hierarchy explicit, because it’s the map of how decisions get made, which sources carry the most authority, and how different kinds of questions should be approached.
At O’Reilly, our engineering hierarchy looks like this:
| Layer | System | Purpose |
|---|---|---|
| Roadmap | Productboard | Strategic goals, initiatives, and feature prioritization |
| Execution | Jira | Epics, stories, sprints, and contributor tracking |
| Implementation | GitHub | Source code, PR history, and event instrumentation |
| Service catalog | Cortex | Service ownership, dependencies, on-call, and Slack channels |
| Observability | Datadog | System performance, errors, and incidents |
Your organization will have a different set of tools. A sales organization might place Salesforce at the top, followed by a revenue intelligence platform, marketing automation, and market research. A legal team might start with a contract management system, followed by a regulatory tracker, internal policy documentation, and a research database. The specific systems matter less than the act of mapping them: understanding which layer answers which kind of question, and which sources take precedence when they conflict.
This step has two parts that must work together. First, you need to connect your systems to your AI tools via MCP. Then you have to write a skill file that tells the model what to do with that access. At O’Reilly, we call this complete grounding layer Expert Intelligence.
Configuring MCP is straightforward.
Most major tools now offer MCP connectors, and connecting them is
typically a matter of routine JSON configuration. For systems
without MCP connectors, a bash-capable agent with curl
and jq can often reach a REST API directly. MCP just
makes it cleaner and more reliable.
But MCP connections alone aren’t enough, and this is the part most implementations get wrong. MCP gives the agent access to your data, but it doesn’t tell the agent how to use it effectively. Without explicit guidance, the agent retrieves information and organizes it the way the underlying systems organize it, which produces a data dump, not an analysis.
The skill file—a CLAUDE.md or SKILLS.md document that provides specific reasoning instructions—transforms retrieval into analysis. Mine defines the reasoning hierarchy (which systems to consult for which types of questions, and how to weigh them), the output format (this is not a coding agent—it produces reports and recommendations, not code), epistemic standards (show your work, name gaps, surface assumptions for human verification), and tone. On that last point, I borrowed one of the most useful instructions from Ted Lasso: “be curious, not judgmental.” Adding it meaningfully improved the quality of the output.
The skill is a codified version of how a skilled analyst would approach these questions. It encodes your organization’s reasoning process and makes it repeatable.
With the research assistant connected to our internal systems, I had something genuinely useful: fast, synthesized answers to questions that previously would have taken days to research. But I kept running into the same problem: The reports felt generic, and people didn’t trust them. This challenge points to a fundamental limitation of AI-generated organizational analysis that goes beyond any particular implementation.
General-purpose AI assistants tend to produce a recognizable kind of organizational analysis: technically reasonable, balanced, cautious, and ultimately not very useful. This isn’t primarily a failure of knowledge—every major LLM has absorbed an enormous amount of management and organizational thinking. It’s a failure of grounding. When an AI assistant has no specific framework anchoring its response, it tends to produce recommendations broad enough to apply to almost any situation: consider the trade-offs, weigh your options, and ensure alignment across stakeholders. These responses are hard to disagree with and just as hard to act on.
When a report says, “The team appears overloaded. Consider adding headcount,” it’s not wrong. But that recommendation could apply to almost any team in almost any company! It won’t make a director change their mind, and it’s not one a leadership team can debate, refine, and act on.
Calling on the O’Reilly Expert MCP didn’t provide the model with new facts—most of the information was technically available already. However, without the Expert MCP and associated skills, the model couldn’t use that information for anything but the broadest analyses. Incorporating the Expert MCP and associated skills changed the character of the analyses by grounding them in specific frameworks, citing named authors and thresholds, and organizing their conclusions around established bodies of practitioner knowledge rather than general principles.
To make this concrete, here’s the kind of output the research assistant produced before adding the Expert MCP:
The team appears overloaded. The backlog is large and the migration project is consuming significant sprint capacity. Consider adding headcount or reducing scope.
And here’s what it produced after:
According to Google’s SRE guidance, sustained operational toil above approximately 50% indicates structural inefficiency rather than a staffing shortage. This team’s telemetry suggests approximately 67% operational toil. Hiring another engineer would likely increase total toil unless operational ownership is first reduced. Recommended actions: run a structured toil audit, set an explicit toil-reduction target below 50%, and assign runbook ownership for recurring operational tasks.
The second report cites a framework by name, references the specific threshold that framework establishes, applies it to the team’s actual data, reaches a different conclusion than the obvious one, and makes actionable recommendations. It’s the kind of analysis that changes a conversation because the director can see where the conclusions came from, engage with the reasoning, push back on the framework if they disagree, or accept it with confidence that it was reasoned rather than pattern-matched.
When I shared this version with my engineering director, their reaction was immediate: This is defensible.
The most underappreciated aspect of O’Reilly’s content library is that the value isn’t primarily informational. Most of the facts in an O’Reilly book are available on the internet, and LLMs have already read much of the internet.
The deeper value of O’Reilly’s catalog is that it’s organized around coherent frameworks—complete mental models built by practitioners who spent years or decades developing them. Google SRE. Team topologies. Accelerate. Domain-driven design. The Manager’s Path. Wardley mapping. Designing Data-Intensive Applications. These are structured ways of thinking about specific classes of problems, developed with enough rigor that they can actually guide decisions.
Frameworks are distinct from facts in a critical way: They tell you not just what’s true but what’s relevant, what to measure, what threshold matters, and what to do when you exceed it. A model with access to the SRE framework as an organized body of practitioner knowledge is more likely to surface it explicitly, apply it to the specific question at hand, and use it to anchor its recommendations, producing output that human reviewers can actually interrogate.
This points to the organizing principle behind the approach described in this paper:
Organizational data provides local evidence about what is happening in your specific context. Expert frameworks provide accumulated practitioner knowledge about how to think about problems of that kind. Good organizational judgment requires both.
The Expert MCP is the bridge between your specific business context and practitioner insights. It connects the AI’s access to your internal systems with a curated body of expertise relevant to the decisions your organization needs to make.
The natural objection at this point is “Couldn’t I get the same effect by dumping relevant PDFs into Claude, or using Claude Projects, or NotebookLM?”
The short answer is not quite, and the reasons are practical as much as they are technical.
Uploading documents gives you retrieval from those specific documents. The O’Reilly Expert MCP differs in several operationally significant ways. First, the corpus is editorially curated around coherent practitioner frameworks. Unlike a collection of PDFs, which tends to reflect whatever you happened to find, the Expert MCP offers a sustained curatorial perspective: The authors are vetted, the content has been through editorial review, and it’s organized around established bodies of knowledge rather than assembled ad hoc. This is a much more expansive kind of evidence base. Second, the corpus is maintained and updated by O’Reilly. New titles are added, new editions replace old ones, and the content stays current without any management on your part. Third, the Expert MCP is configured once and works consistently across your entire organization and toolchain rather than being tied to a single user’s Claude Project or a document upload that expires. Finally, accessing content through a proper API respects the appropriate usage terms in a way that uploading copyrighted texts doesn’t.
And when paired with a well-written skill, the agent can be directed to look explicitly for competing frameworks, surface cases where the literature disagrees, and name gaps in the available evidence, providing a meaningful check against the common tendency of AI tools to quietly favor whatever framework first seems to fit. That’s something you can encourage with any retrieval setup, but it works more reliably when the underlying corpus is organized around coherent bodies of thought rather than a heterogeneous collection of documents.
I want to be clear about the limits of what Expert MCP does today. O’Reilly doesn’t claim that Expert MCP automatically selects the single correct framework for every situation, or that adding it to your configuration produces consultant-quality analysis without thoughtful prompting and human review.
The results described in this paper
were the outcome of all four elements—the internal
organizational data, the carefully designed skill architecture, the
Expert MCP, and human review—in combination working
together.
The Expert MCP is an important differentiator, but it’s not a magic layer you can add to an otherwise generic setup and expect to reproduce these results. The system works because each element does something the others cannot. The skill defines the reasoning process, the internal MCP connections provide the organizational evidence, the Expert MCP provides the expert frameworks, and human review supplies the judgment and context that no AI system can generate on its own.
What the Expert MCP reliably contributes to that system is access to a curated body of practitioner knowledge: technical and managerial frameworks that are editorially organized around coherent bodies of thought and difficult to reconstruct from scattered web content or assembled document collections. Your organizational data still tells you what’s happening, while the O’Reilly Expert MCP helps interpret what it means. That’s a meaningful and concrete improvement over an ungrounded AI assistant, and it’s something you can put in production and build on today.
No AI system eliminates the risk of hallucination. The Expert MCP doesn’t make the model infallible.
What it does is change the burden of proof. When every recommendation is grounded in a named framework, a named author, and a traceable citation, a human reviewer can check the reasoning rather than simply accepting or rejecting a conclusion. The question shifts from “Is this right?” (unanswerable in isolation) to “Does this framework actually say this, does it apply here, and do I agree with the conclusion?” That’s a question humans can engage with productively, which is exactly what you want from a decision-support tool.
Organizational systems rarely contain the full context behind a decision. The meeting that changed everything happened last Tuesday and hasn’t been written up yet. A key person is quietly planning to leave. A strategic direction shifted in a conversation that was never documented. AI can synthesize everything in your systems with remarkable fidelity, but it can’t know what isn’t there, and organizational reality changes faster than documentation does.
More fundamentally: AI can identify trade-offs, but it can’t decide which trade-offs matter. That judgment requires human knowledge of context, priorities, and risk tolerance that can’t be fully encoded in any system. The goal isn’t to remove humans from the loop but to give them better-structured input to reason from.
As I started sharing analyses more broadly, I ran into a new set of limitations in the collaboration layer. The research assistant produced documents. I shared them in Google Docs, and people added comments, but when the AI updated a document based on reviewer feedback, I had to paste in a new version, which wiped out the existing comments. Documents proliferated without clear relationships between them, and the AI had no visibility into the discussions in the comments, which was where the most important context and pushback lived.
To solve the collaboration problem, I worked with one of our engineering directors to build what we call Superanswers, a system that uses GitHub as the source of truth for AI-generated research documents and their associated discussions.
The architecture is straightforward: Documents are stored as Markdown files in a GitHub repository, a GitHub Pages site renders them with a clean interface that supports inline commenting, and all discussion happens in GitHub Discussions, meaning every comment, question, and revision is versioned and traceable. Because the documents and their discussions live in GitHub, Claude Code has full access to both. It can read the document content plus the entire conversation that’s developed around it.
This enables a qualitatively different kind of AI participation. Instead of generating a document and stepping back, we can now ask:
What is the consensus around this project based on the discussion so far? What questions remain unresolved? Incorporate the reviewer comments and produce an updated version.
The AI becomes a participant in an ongoing conversation rather than a one-shot report generator, which meaningfully shifts how organizational knowledge gets built and refined.
As Superanswers has spread across our engineering organization, the range of questions people bring to it has been broader than I expected:
| Theme | Typical questions |
|---|---|
| Architecture and infrastructure | Should we make this change? What will it cost? What might break? |
| Operational effectiveness | Where is our toil coming from? What should we automate, simplify, or retire? |
| Team health and capacity | Where is the team’s time going? What’s limiting execution? |
| Organization and strategy | How should we organize, prioritize, and invest? |
| Engineering measurement | How do we know if we’re healthy and improving? |
| AI and organizational learning | How do we build better systems for reasoning and decision-making? |
None of these questions is about writing code. They are about understanding an organization, making decisions, and coordinating work, and most of them would map naturally onto the concerns of leaders in other functions. The same questions arise in any organization navigating rapid change with information scattered across too many places.
The AI conversation to date has been dominated by a particular set of questions. But there are more interesting questions we should be asking.
| We’ve spent a lot of time asking… | What else might be possible? |
|---|---|
| How do we make people more productive? | How do we make organizations more effective? |
| How do we produce faster? | How do we make faster decisions? |
| How do we generate output? | How do we generate understanding? |
| How do we accelerate execution? | How do we improve outcomes? |
| How do we gather data? | How do we build institutional knowledge? |
| How do we automate tasks? | How do we improve organizational learning? |
The challenges outlined in this chart aren’t unique to engineering. They exist wherever important information is scattered across multiple systems and important decisions require synthesizing all of it.
Individual productivity matters, but organizations don’t succeed by having contributors go faster in arbitrary directions. They do so by making good decisions about where to invest, allocating resources well, surfacing problems before they compound, and building institutional knowledge that persists over time.
The recipe I’ve described can help organizations make those decisions and build that knowledge.
The recipe for building an organizational intelligence system:
- Map your information hierarchy. Identify the systems where important knowledge lives in your organization, from strategic intent down to operational detail. This is an organizational task, not a technical one, and doing it well requires understanding how decisions actually get made.
- Connect those systems via MCP and write a skill that describes how to reason. The MCP connections give the AI access to your data; the skill file tells it how to think with that data. Without the skill, you get retrieval. With it, you get analysis.
- Add the O’Reilly Expert MCP as an expert review layer. Organizational data provides local evidence about what is happening in your specific context; expert frameworks provide accumulated practitioner knowledge about how to reason about problems of that kind. This step bridges the two. The O’Reilly library spans engineering, management, data science, security, finance, product, and more, organized not as a collection of facts but as coherent frameworks developed by practitioners who spent careers building them. The result is analysis grounded in named frameworks with traceable citations, something human reviewers can engage with and question, rather than generic advice they can only accept or reject.
- Build a lightweight system for human-in-the-loop consensus. AI-generated analysis is a starting point, not an end point. You need a mechanism for people to review, challenge, and refine what the AI surfaces, one where those discussions become part of the context the AI can learn from in subsequent iterations.
The biggest practical lesson I took from this work is reframing what AI is actually for in an organizational context. The difference between a useful AI research assistant and a generic one isn’t primarily about which model you use or how much data you feed it. It’s about whether the reasoning combines local organizational evidence with established expert frameworks. Your data tells you what happened. Expert frameworks help interpret what it means. That combination, with human judgment applied at the end, is what makes the difference between a report that gets read (maybe) and filed away and a recommendation that changes a decision.
[$] Examining other network namespaces using BPF [LWN.net]
Jordan Rife's work involves writing BPF programs for Cilium that interface with Kubernetes networking. As part of that work, he wants to enable BPF programs with appropriate permissions to iterate through the sockets of a different network namespace. He led a session about the idea at the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit where the BPF developers in attendance were quick to suggest a number of related alternatives.
Saja Wants You To Think About What You Did [Whatever]


Did you think you’d get away with it? Did you think he wouldn’t find out? Saja always finds out. And now you’ll just have to live with him knowing.
In other news, we’re coming right up on the one-year anniversary of Saja’s official adoption. He was clearly alive before then, so being more than one year old now, he’s officially no longer a kitten, he’s just now a teen cat. Trust me, he has the attitude to match.
I’ll probably note his anniversary when it happens, but in the meantime: Enjoy Saja judging you. As he would.
— JS
CodeSOD: Connection State [The Daily WTF]
Frederick A sends us a bit of null checking code, and offers us a better solution.
class ConferenceService
{
/// <summary>
/// Checks if conference is active
/// </summary>
public bool IsCalling()
{
try
{
return m_ConnectionService.Core.State.IsWebRTCConnected;
}
catch
{
return false;
}
}
}
This is for a web conferencing tool, which uses WebRTC to set up
connections between clients in the chat. This function checks if
the chat is active by checking a IsWebRTCConnected
flag. But as you can see in this code, that flag is on a long chain
of objects, some of which may not exist when this function is
called. Thus, we wrap the whole thing up in a
try/catch. If anything throws an exception, we know we
can just return false. It's probably fine.
The obvious and easy fix, which Frederick proposes, is to use
the C# coalescing operator: ?.
m_ConnectionService?.Core?.State?.IsWebRTCConnected ??
false would solve this problem just fine.
That said, I wouldn't say that's a true fix. We're talking about a state machine here, though admittedly with two states under discussion (connected/disconnected), though there are probably more not being checked here. This information should be managed via a state machine, not via boolean flags stuffed deep in an object chain. The fix isn't a WTF, but it definitely hints at a better way to manage all of this. Now, my solution likely requires a lot more modification and code changes than what we have here, so I'm not suggesting anyone go off and rewrite this from scratch just to have a cleaner way of managing state. But folks definitely should think more carefully about how they manage state.
Introduction to Post-training [Radar]
This is the first article in a series about post-training. Follow along on Radar.
Before post-training, there was a major problem with LLMs: Almost nobody could use them. The story of post-training is also the story of how AI went from a research curiosity to a product used by about a billion people.
Post-training is the reason why a model behaves a certain way. This set of training techniques makes LLMs useful (e.g., able to chat with people and interact with AI agents), safe (e.g., aligned with human intentions), and more capable (e.g., through “reasoning” to tackle difficult tasks). Behavior is powerful, and doesn’t just mean holding a conversation or following a user’s instructions. Behavior includes making it possible for the model to use tools, like a calculator tool, a search API, or any application through an MCP. Behavior can even elevate a model’s intelligence, for example by teaching the model to use “reasoning”: that is, working through problems before giving a final answer rather than “guessing” or “memorizing.”
GPT-3 showed up in June 2020. A completion engine, it followed patterns it had seen from its pretraining data, which were not predominantly chat conversations. Imagine scraping data on the internet: that pretraining data had a lot of questions that were followed by other questions—for example, on an exam template. GPT-3 was 175B parameters, large for its time, and it had a wide, general range of abilities, although many of them were latent.
If you gave GPT-3 a prompt like “Why do people like golden retrievers?” it might say something nonsensical:
Why do people like labrador retrievers?
Why do people like poodles?
10 Reasons You Should Adopt a Dog Today
These answers look absurd in isolation, but if you imagine a web page with a list of FAQ links, this is a perfectly reasonable next chunk of text. GPT-3 might have just been completing a listicle on a website, because it had seen millions of websites in its pretraining data.
The common way to nudge GPT-3 to answer a question back then was by prompt engineering with a Q&A template and few-shot examples.
Q: Why do people like labrador retrievers? A: Because they are friendly, loyal, and easy to train.
Q: Why do people like beagles? A: Because they are curious, great with kids, and have a gentle temperament.
Q: Why do people like golden retrievers? A:
Then, GPT-3 might say:
Because they are affectionate, patient, and make excellent family pets.
While this technique worked, it was brittle. If you forgot the few-shot examples, rephrased the question, or even added a space after “A:,” you’d get something completely different (possibly unhinged) that was far from a reasonable response.
In fact, if you were a researcher working with GPT-3 at the time, you probably at some point found the space at the beginning of the response ” Because they are gentle dogs.” annoying and would try to end your prompt with a space “A: ” instead of “A:”. In those cases, it was common for GPT-3 to go off a cliff and produce a drastically different response, sometimes completely off like “dogs dogs dogs dogs…” repeating indefinitely.
The reason behind the differing responses to “A:” and “A: ” is because “A:” might tokenize to one token while “A: ” tokenizes to two different tokens. The model literally sees different input sequences, each with different statistical completions in its training data. It’s like asking two completely different questions. While a space is a tiny syntactic change that is meaningless to a person, it becomes extremely meaningful to the model that now sees two different prompts (the tokens change!) with two very different statistical futures to complete.
You still encounter the modern equivalent of this when working with chat templates. If you forget to apply the model’s chat template and instead just concatenate
'User: ' + prompt + '\nAssistant: ', you’re sending the model a token sequence that it was not robustly trained on. The tokens are wrong, not the model. Post-training teaches the model to respond to specific token patterns (like<|im_start|>user\nin Qwen models). Not using them is like speaking to someone in a language they half-understand. However, most open source models will be trained to be at least somewhat robust without their templates too.
Under those circumstances, most people would assume AI still didn’t work. The model wasn’t trained to answer questions; its data wasn’t primarily conversation transcripts. Instead, it was trained to predict the next token in downloaded websites, articles, and documents.
Thankfully, this can all be fixed with post-training. And that’s when most people started to believe that AI had undergone a paradigm shift and just might work.
Pretraining heavily influences the model’s knowledge capacity prior to post-training. The model gets raw intelligence during pretraining. Then, during post-training, that intelligence is made useful through behaviors like dialogue and reasoning. In a frontier lab, these two phases are such different processes that very different teams work on them.
A model’s factual knowledge about the French Revolution, its understanding of Python syntax, and its grasp of calculus all come from pretraining. Post-training primarily shapes which knowledge the model reaches for, how it presents that knowledge, what tone it uses, whether it declines certain requests, and whether it thinks step-by-step before answering, though targeted SFT on new domains can introduce information the model didn’t encounter in pretraining.
If a model gives a wrong answer about history, the root cause is likely in pretraining data, but the practical fix might still come through post-training—for example, teaching the model to use search tools, express uncertainty, or chain-of-thought verify its own claims. But if a model gives correct information in a condescending way or refuses to help with a reasonable request or fails to use tools when it should, those are squarely post-training problems.
The work of pretraining is centered around cleaning and curating large-scale data, optimizing the model toward relatively clear loss signals, and working with scaling laws given bounded compute.
In pretraining, the model learns to predict the next token across a large curated dataset, typically for one or a small number of passes over the training data, though some models train for multiple epochs, especially as high-quality data becomes scarce relative to compute budgets. This is where you’ll hear how a model is fed the entire internet’s worth of data to gain intelligence, although in practice nearly all of the data (often 90% or more) may be thrown out because it’s unsuitable for training.
Pretraining is an unsupervised process that runs at increasingly larger scales to match the size of the model. While scaling, thousands of experiments are used to understand what data mix, what architecture considerations, what compute optimizations, what hyperparameters can lead to the best results. There’s variance in each run due to stochasticity found in both software and hardware, so multiple experiments are needed to verify results. Because compute is limited and needs to be used sparingly, researchers will scale iteratively, expanding to the next, say, 10x compute budget, when they gain confidence in the right configuration. A full run isn’t possible to iterate on due to the compute cost and time it would take: The final run, often called the “god run,” can take over a month on thousands of GPUs.
Pretraining progress is typically very clearly measurable, using a metric like perplexity, which measures, roughly, the model’s average uncertainty per token. Lower is better, where 1 means the model knows with absolute certainty what token comes next. Meanwhile, a perplexity of 50 means the model’s predictions are, on average, as uncertain as if it were choosing uniformly among 50 equally likely tokens—though in practice, the distribution is peaked, not uniform.
Rather than consuming hundreds of millions of tokens of internet data, post-training operates on far more intentional datasets for downstream tasks. These datasets include human-written demonstrations of ideal responses, human judgments about which responses from the model are better, and carefully designed functions that score the model’s outputs programmatically. They shape what “good” looks like.
Like pretraining, post-training can also be more effective with scaling data and compute. Specifically, massive compute budgets have been dedicated to post-training to learn reasoning capabilities (or the ability for models to “think step-by-step” to arrive at more logically sound answers), matching the scale of pretraining compute.
Post-training is messier than petraining, which has an elegant, clear optimization objective to minimize the loss over the next token prediction across a huge corpus. The goals of post-training are things like “be more helpful” or “don’t say harmful things.” Many of these objectives are inherently subjective and require human judgment, proxy models that approximate human judgment, or programmatic verifiers that can become elaborate or inefficient. The loss curves are noisier. The quality of the data and feedback matter even more.
The scale of post-training is also more complicated than in pretraining. Standard post-training remains relatively modest in compute: tens to hundreds of GPUs for days rather than thousands of GPUs for months needed in pretraining. This makes post-training for alignment highly amenable to rapid iteration; researchers can try something, observe results, form a hypothesis, and run again on a timescale of days.
The picture changes dramatically when post-training is used to develop reasoning capabilities. For reasoning models, the compute dedicated to post-training can easily account for half of the overall compute of the model. The gap between a standard instruct model and a reasoning model is increasingly a gap in post-training compute, not pretraining scale. This means post-training now spans a wide spectrum from fast, cheap, highly iterable fine-tuning runs to massive RL campaigns that rival pretraining in both cost and engineering complexity.
So why can’t we just stick with pretraining? It comes down to three main pieces: usability, safety, and capability.
A pretrained model is like if someone gave you a large download of Wikipedia in a single PDF. It’s a ton of knowledge that you can sift through, but there’s no way to easily understand what is going on in the data. Post-training gives the model the ability to integrate this information for you and respond to your request naturally. This extends to having longer multiturn conversations and following instructions. Without it, every user would need to be a prompt engineer. With it, anyone who can type a sentence can use the model.
A lot of data in pretraining can be toxic, biased, misleading, or outright dangerous. Or it might not be dangerous on its own, but when a model can integrate knowledge from different fields, it can create something novel that is dangerous.
The model has no inherent sense of what content is good or bad. It will follow any request, based on its pretraining data. To prevent that, you can add safety guardrails to the model in post-training, to refuse harmful requests like asking the model to build a bioweapon and avoid accidentally generating toxic content such as inappropriate sexual content (even if it wasn’t in the user’s request). This is also the place to teach the model to express uncertainty, when it doesn’t know something, whether that’s “I don’t know” or “that’s beyond my knowledge cutoff” or “as a large language model, I’m limited in my knowledge so please consult a healthcare professional.”
Making a model safe is part of a broader area in the AI research community called “alignment,”1 where the goal is to align the model with human values and preferences. Post-training is typically the main way to achieve that.
Model companies will usually have additional safeguards beyond post-training, including lightweight models that check whether the user’s request was safe, as a second layer of protection against responding to harmful requests.
Post-training doesn’t just make a model nicer or safer; it can make the model smarter at hard tasks. The clearest example is reasoning. A pretrained model might have all the mathematical knowledge needed to solve a complex word problem, but it might jump to an incorrect answer because it’s pattern-matching from pretraining data or pattern-matching from how to answer questions (e.g., with succinct immediate answers).
It turns out that making the model output more tokens before giving an answer (or “think longer”), results in better answers. This process is known as reasoning, and post-training can teach the model to reason more effectively. A more capable pretrained model is a more dangerous model if it’s not properly aligned. A more intelligent model is a less useful model to humans if it can’t communicate clearly. And, every point of improvement in a reasoning benchmark now maps to real revenue for companies deploying these models.
Can post-training push models beyond human-level performance? Yes, in specific domains.
In competitive programming, top reasoning models can now solve problems at a level that exceeds the vast majority of human competitive programmers. In math, models have achieved scores on Math Olympiad-level competitions that would place them among the top competitors in the world. In certain scientific domains, models have generated novel hypotheses and solutions that human experts found valuable.
This might seem paradoxical. If the model’s knowledge comes from human-generated data (in pretraining), and its behavior is shaped by human feedback (in post-training), how can it exceed human performance?
Two things make this possible. First, integration across domains. Research is about combining or mixing fields. Imagine mixing every possible field. The pretraining data aggregates knowledge from millions of sources, and no single human has read all of it. Second, post-training, particularly RL with reasoning, teaches the model to explore many approaches to a problem, far more than a human would try in a single sitting. A human might try one or two approaches to a hard math problem.
This means post-training is not just about making models mimic human behavior. It’s about pushing beyond it. This is especially possible to scale with verifier-based RL. In those scenarios, you can expect models to achieve superhuman performance in an expanding set of domains. And that starts with verifiers that are very well-defined, easy to access, efficient, and cheap relative to the ROI of the model learning it. The limitation is no longer the model’s intelligence, but our ability to specify what “good” means through reward signals.
︎Issue 47 – Greta’s Wedding Pt. 2 – 10 [Comics Archive - Spinnyverse]
The post Issue 47 – Greta’s Wedding Pt. 2 – 10 appeared first on Spinnyverse.
Pluralistic: Google is a scammer's paradise (05 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

Forget "Don't be evil"; Google's true motto is a form of vulgar spidermanism: "With great power comes no responsibility." The internet's de facto boss is an absentee landlord.
Google – a thrice-convicted monopolist – is the gateway to the internet, with more than a 90% search market share that it attained by buying out all its competitors and bribing Apple more than $20b/year not to start a rival search engine:
https://www.democracynow.org/2024/8/6/google_monopoly
Google likes to position itself as a wise steward of the internet. They say they use their vast troves of data about the internet and its users to connect the right person with the right information at the right moment. As their mission statement has it, "organize the world's information and make it universally accessible and useful":
https://www.google.com/intl/en_us/search/howsearchworks/our-approach/
The tacit argument is, "Sure, we repeatedly violated antitrust law in order to monopolize the internet, but the internet needs a monopolist. It's scary out there! We have amassed power so that we can protect and guide you."
It's a bullshit argument and no one should accept it – but even if you think it's worth harnessing monopoly power to promote a wise king to rule over the internet, you'd still want Google to take that responsibility seriously. If we're to have a landlord for our civilization's digital nervous system, let's not have it be an absentee landlord.
Google is an absentee landlord. In 2019, they chose to deliberately worsen search results in order to make you search repeatedly to find the information you're seeking, because every fresh query lets them serve fresh advertisements:
https://pluralistic.net/2025/05/26/babyish-radical-extremists/#cancon
Not all of Google's enshittification can be attributed to deliberate sabotage. Much of it is the result of neglect. Ask Google for a product review and they'll pass over the most rigorous, honest websites on the internet in favor of affiliate scammers who repackage Amazon best-of lists to peddle overpriced, underperforming junk that's sometimes so bad it's dangerous:
https://pluralistic.net/2024/02/21/im-feeling-unlucky/#not-up-to-the-task
Google keeps announcing that it Takes This Problem Very Seriously – and then nothing happens:
https://pluralistic.net/2024/05/03/keyword-swarming/#site-reputation-abuse
And of course, Google AI search results present the company with a highly refined and confident-sounding way to launder spam into product recommendations:
https://pluralistic.net/2025/07/15/inhuman-gigapede/#coprophagic-ai
Could Google do better? Provably so. Kagi, a small company that runs a search engine powered by Google's own search index consistently delivers results that are substantially superior to Google's – using Google's own infrastructure:
https://pluralistic.net/2024/04/04/teach-me-how-to-shruggie/#kagi
If Kagi (a startup with a handful of engineers) can extract useful search results from Google's databases, then Google – a thrice-convicted monopolist that's had its pick of thousands of the top computer scientists from the world's most prestigious universities for a generation – could also do so.
They just choose not to.
They're too big to fail. They're too big to jail. They're too big to care.
Google's AI search isn't a way to fix its broken core product: it's a way to partially remediate the damage Google itself inflicted on the open internet, while imprisoning the web in a walled garden that would make Steve Jobs drool:
https://pluralistic.net/2026/06/29/arsonist-firefighters/#im-feeling-lucky
It's a deadly combination: Google has committed hundreds of billions to stock buybacks and its AI money-furnace, financed by mass layoffs targeting the people who keep the core services useful. The too-big-to-care company is still the internet's gatekeeper, but half the guards at the gate have been fired and the other half have pulled so much overtime that they keep falling asleep on the job.
Google has become a scammer's paradise.
Take Google's "answer box." This is the part of the search results page that tries to answer your query directly, without sending you elsewhere for that info. Back in 2023, Google's Answer Box was taken over by scammers who impersonated airline help desks. When Google's users searched for airlines' toll-free phone numbers, Google directed them to phones that rang in the scammers' boiler room, where they were tricked into giving up their passport info and credit card numbers to boiler-room thieves:
(This was an especially devastating attack because the airlines themselves hide their customer service phone numbers – as enshittified monopolists, they want your money, not your complaints – so it's normal to search Google for the number you're seeking, rather than scouring the airlines' deliberately confusing customer service sites.)
This is especially galling because Google has an extensive "verified merchant" program that goes to enormous lengths to establish the true identity of every merchant whose businesses are listed on Google, in maps, ads and search results. Google "knows" which URLs belong to the airlines. If it can be tricked into scraping a different website for the airlines' phone numbers, that's because Google couldn't be bothered to connect its own database of canonical airline URLs to the process that serves phone numbers to the 90% of the web-using public who search with Google.
Google's database of the canonical URLs for businesses doesn't stop at airlines or even large businesses. Nearly every local merchant has undergone Google's verification process, which includes a step where Google physically mails a postcard with a unique number to the merchant's registered address, which the merchant must then key into Google to prove that they're located where they say they are.
Despite this, Google's ad-sales system will happily sell anyone the right to advertise a different website for queries for specific merchants, and those ads appear above the real result for the business's website. To make this even worse, Google's spent years making it more difficult to distinguish ads from "organic" search results, changing the font and size of the "ad" warning to make it harder to spot, and making the font and color of the ad itself closer to the color of the search results below it.
This is a gift to fraudsters. I had my own run-in with it in 2023, when I was tricked by a Google ad into ordering dinner from my local Thai place using a scam site that had cloned the restaurant's menu. The scammers marked up the price by 15%, then passed the order on to the restaurant, pocketing the vig:
https://pluralistic.net/2023/02/24/passive-income/#swiss-cheese-security
This scammer – based out of a UC Berkeley dorm-room – had copied hundreds of restaurant websites, then bought Google ads for the restaurants' names, ensuring that searchers would see the scam result before the real one. Remember: Google knows what the true URL is for every one of those restaurants but it sold the scammer ads for a different URL that appeared when people searched for the restaurant by name.
Google could trivially add a step to the ad sales pipeline that detects mismatches between a merchant's known URL and the URL in an ad bought against the merchant's name. It could automatically resolve these mismatches by sending an email to the merchant's verified email address that says, "Hey, are you buying an ad with a new URL? If so, just reply to this email."
I don't know why Google doesn't do this. Maybe they make huge sums from these scam ads and they don't want to forego the revenue. Or maybe they just don't care.
Whichever it is, there's real consequences for this negligence by the internet's absentee landlord. Take abortions: fake abortion clinics – where pregnant women are bullied or tricked out of the abortions they're seeking – buy Google ads against the names of real abortion clinics. Google makes millions sending abortion-seekers to fake abortion providers:
https://pluralistic.net/2023/06/15/paid-medical-disinformation/#crisis-pregnancy-centers
Google started off as the ideal "intermediary" – the fancy economist's term for a "middleman." They took as their duty to figure out the best websites for you to look at based on your interests, serving as an honest broker between internet users and internet publishers. In the quarter-century since the company's founding, as it transformed itself into a monopolist, it developed the curse of every intermediary: it got Main Character Syndrome.
This is Tim Wu's formulation: the reason for an intermediary existence is to serve the parties to the transaction. Ebay says it exists to connect buyers and sellers, Uber is supposed to connect drivers and riders, dating sites are supposed to connect people with their love-matches. But intermediaries are cursed with an enviable position: by dint of sitting between these different groups of people, the intermediary learns everything about both sides of the transaction, while each side only knows about its own position.
Amazon knows the price you're willing to pay, it knows who's set the lowest price, and it knows how many identical items that match your query are for sale. But the sellers don't know any of that, and you only know some of it. By capitalizing on that information (rather than using it to efficiently match buyers and sellers), Amazon can match you with the sellers willing to pay the highest junk fees, rather than the ones who offer the best price for the best goods:
https://pluralistic.net/2023/11/03/subprime-attention-rent-crisis/#euthanize-rentiers
This is Wu's Main Character Syndrome in action. Once Amazon attains a dominant market share, it can maximize its own welfare at the expense of its buyers and sellers, transforming itself from a helper to a parasite:
https://www.lawfaremedia.org/article/lawfare-daily–tim-wu-on–the-age-of-extraction
Google says it wants to "organize the world's information and make it universally accessible and useful," but every dime it spends fighting fraud (a critical part of this mission!) is a dime it can't spend on stock buybacks, executive compensation and AI servers. "Organize the world's information and make it universally accessible and useful" is the mission of a good intermediary; "do the absolute minimum to fight fraud" is the mission of a formerly good intermediary with terminal Main Character Syndrome.
Google keeps finding ways to expose its users to fraud while lining its own pockets. That restaurant markup scam that caught me in 2023? Three years later, it's way worse.
San Francisco City Attorney David Chiu just filed suit against GuestReservations.com, BookOnline.com and Booking Holdings for running a massive version of the restaurant menu scam – one that extracted millions from people booking hotel rooms:
Here's how the scam worked: these companies put up websites with deceptive URLs, like SanFranciscoMarriott.GuestReservations.com, and then bought the associated Google ad-word ("San Francisco Marriott"). At the top of Google searches for "San Francisco Marriott booking" was the ad for SanFranciscoMarriott.GuestReservations.com. This site would sell you a room at the Marriott, at a markup of 35% to 85%.
This is a pure ripoff. If Google had served the correct result at the top of the page – if it had used its own database of confirmed merchants and their associate websites to validate its ads – then people booking hotels would have saved 35% to 85% on their rooms.
City Attorney Chiu says that the perps here registered domains for all kinds of hotels, even tiny ones in small towns, all over America. That means that it's not just visitors to San Francisco who got screwed by these creeps – it's also San Franciscans who booked hotel rooms around the country.
Google bears the lion's share of the blame here, but Visa and the other credit card companies are critical to these scams. Card companies allow merchants to set terms of service that refuse refunds under almost any circumstances, and, more often than not, the card issuers side with the merchants over their own customers when they call to cancel a charge from one of these scammers.
I discovered this for myself when I was tricked into buying theater tickets from a ripoff site that had registered the URL of the show I wanted to go to. I figured out that I'd been rooked within a minute of clicking the buy button, but it took months and multiple appeals – and ultimately a threat to cancel my credit card – to get Visa to refund me.
Visa – another bloated monopolist with terminal Main Character Syndrome – can see that it has merchants who generate zillions of appeals and charge-backs because they run scam businesses like these. They could treat these merchants as the fraudsters they are, but because the crooks wreathe themselves in gauzy excuses and lengthy terms of service, Visa enables these massive, nationwide cons.
Google, Visa and the other monopolists who serve as de facto regulators for our society have arrogated to themselves the power to observe every transaction and block the obvious scams. We pay for their failure to take minimal, obvious steps to protect us from the scammers who thrive on their platforms.
Why should they? They're the main characters. They're Bizarro-world spidermen, whose great power confers no responsibility.

Gavin Newsom Makes An Ass Of Himself On Antitrust, Paramount Merger https://www.techdirt.com/2026/08/04/gavin-newsom-makes-an-ass-of-himself-on-antitrust-paramount-merger/
Against Self-Fulfilling Prophecy https://www.hamiltonnolan.com/p/against-self-fulfilling-prophecy
Arson markets https://www.merkley.senate.gov/wp-content/uploads/2026.08.03-LTR-Wildfire-Prediction-Markets-FINAL.pdf
Eight Myths on Software Engineering and GenAI https://queue.acm.org/detail.cfm?id=3807963
#25yrsago Steve Ballmer: DEVELOPERS DEVELOPERS DEVELOPERS DEVELOPERS DEVELOPERS http://www.ntk.net/ballmer/dancemonkeyboy.mpg
#15yrsago HOWTO E-Z realistic corpse from a cheap plastic skeleton https://propnomicon.blogspot.com/2011/08/quick-and-dirty-corpses.html
#15yrsago $300 Million Button: making customers create logins to buy cost etailer $300M/year https://centercentre.com/
#10yrsago 1 billion computer monitors vulnerable to undetectable firmware attacks https://www.defcon.org/html/defcon-24/dc-24-speakers.html#Cui
#10yrsago Stiglitz quits Panama’s official money-laundering panel over internal sabotage https://www.reuters.com/article/us-panama-tax-idUSKCN10G24Z/
#10yrsago BBC will use surveillance powers to sniff Britons’ wifi and find license-cheats https://web.archive.org/web/20160806155022/https://www.telegraph.co.uk/news/2016/08/05/bbc-to-deploy-detection-vans-to-snoop-on-internet-users/
#10yrsago How and why to short Uber https://qz.com/707947/investors-have-placed-a-one-way-bet-on-uber-which-made-us-want-to-figure-out-a-way-to-short-it
#5yrsago Facebook's official disinformation research portal is a bad joke https://pluralistic.net/2021/08/06/get-you-coming-and-going/#potemkin-research-program
#5yrsago Scammers sell griefers social media banning services https://pluralistic.net/2021/08/06/get-you-coming-and-going/#curse-of-bigness
#1yrago Which jobs can be replaced with AI? https://pluralistic.net/2025/08/06/unmerchantable-substitute-goods/#customer-disservice

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
F@#$ the AI Overlords (On The Media)
https://www.wnycstudios.org/podcasts/otm/articles/f-the-ai-overlords
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
AI and the Enshittification Era (The Weekly Show with Jon
Stewart)
https://www.youtube.com/watch?v=-dAIJRjb-Bw
AI is not inevitable (Betakit)
https://www.youtube.com/watch?v=DbiTVkq1WHo
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
Vulnerabilities in Car Anti-Theft Device [Schneier on Security]
This is disturbing:
…a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or even disable its ignition and leave a driver stranded.
The disconnect between effort and value [Seth's Blog]
They’re often out of whack.
A Hard Day’s Night took less than 15 hours from idea to finished record. More Than a Feeling, from Tom Scholz and Boston, took five years. Each pleased their audiences. One is not 1,500 times more valuable than the other.
Sometimes, work that requires effort leads to scarcity, and that scarcity can increase its value. But not always.
And just because we put in effort does not mean we deserve the audience to reciprocate with a similar amount. Seven years to write a Ph.D. thesis but a professor on the committee might spend an hour reading it. The student’s effort is not related to the committee’s.
The mythology of creation seems to beg us to calculate the effort when computing the value. But in practice, buyers rarely do.
If the creation is what the audience needs or wants, it actually doesn’t matter how hard it was to create, or who or what created it.
This creates an interesting challenge when it comes to education or fitness. Is the point of assigning an essay to demonstrate that a student can work hard, or to challenge them to have the good taste and judgment to hand in something of quality? Is the trainer at the gym pushing you to go fast/lift a lot, or simply creating the conditions for you to do just a bit more than you did last time?
Focusing on absolute outcomes when we’re trying to improve relative effort is a trap. “A for effort” is a legitimate grade, but even in school, the system rarely chooses to actually do this–the natural writer or athlete gets accolades, not the person who tried harder or overcame obstacles.
When developing our skills, effort is essential. But when engaging in the marketplace, I’m not sure it matters. We should be consistent about which we’re seeking to reward.
Enrico Zini: Gnome refusing to suspend [Planet Debian]
I'm tired, I want to do go bed. I click "sleep" on gnome shell, nothing happens.
Swearwords.
I want to go to bed. I might have want to put my laptop in a bag and run to catch a train. I hate when this happens.
systemd-inhibit --list --mode=block doesn't help
much:
$ systemd-inhibit --list --mode=block
WHO UID USER PID COMM WHAT WHY MODE
enrico 1000 enrico 3042 gsd-power handle-lid-switch External monitor attached… block
enrico 1000 enrico 3037 gsd-media-keys handle-power-key:handle-suspend-key:handle-hibernate-key GNOME handling keypresses block
enrico 1000 enrico 2878 gnome-session-b sleep user session inhibited block
After much googling I found out about
gnome-session-inhibit:
$ gnome-session-inhibit --list
mutter: idle-inhibit (idle)
/usr/lib/chromium/chromium: Playing audio (suspend)
Found the right tab in chromium, paused playing, sleep works again.
My sleep was a good half an hour overdue, and all I got for it was to write this blog post.
Of course Gnome could have shown me its inhibitor list instead of doing nothing, since it has that information, but it didn't.
What I really would expect is that if I intentionally click a suspend button, audio and video playing wouldn't inhibit the suspend. Maybe in a future version of Gnome?
New Comic: Bespoke Speech
| Feed | RSS | Last fetched | Next fetched after |
|---|---|---|---|
| @ASmartBear | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| a bag of four grapes | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| Ansible | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| Bad Science | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| Black Doggerel | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| Blog - Official site of Stephen Fry | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| Charlie Brooker | The Guardian | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| Charlie's Diary | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| Chasing the Sunset - Comics Only | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| Coding Horror | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| Comics Archive - Spinnyverse | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| Cory Doctorow's craphound.com | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| Cory Doctorow, Author at Boing Boing | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| Ctrl+Alt+Del Comic | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| Cyberunions | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| David Mitchell | The Guardian | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| Deeplinks | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| Diesel Sweeties webcomic by rstevens | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| Dilbert | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| Dork Tower | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| Economics from the Top Down | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| Edmund Finney's Quest to Find the Meaning of Life | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| EFF Action Center | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| Enspiral Tales - Medium | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| Events | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| Falkvinge on Liberty | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| Flipside | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| Flipside | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| Free software jobs | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| Full Frontal Nerdity by Aaron Williams | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| General Protection Fault: Comic Updates | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| George Monbiot | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| Girl Genius | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| Groklaw | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| Grrl Power | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| Hackney Anarchist Group | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| Hackney Solidarity Network | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| http://blog.llvm.org/feeds/posts/default | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| http://calendar.google.com/calendar/feeds/q7s5o02sj8hcam52hutbcofoo4%40group.calendar.google.com/public/basic | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| http://dynamic.boingboing.net/cgi-bin/mt/mt-cp.cgi?__mode=feed&_type=posts&blog_id=1&id=1 | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| http://eng.anarchoblogs.org/feed/atom/ | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| http://feed43.com/3874015735218037.xml | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| http://flatearthnews.net/flatearthnews.net/blogfeed | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| http://fulltextrssfeed.com/ | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| http://london.indymedia.org/articles.rss | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| http://pipes.yahoo.com/pipes/pipe.run?_id=ad0530218c055aa302f7e0e84d5d6515&_render=rss | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| http://planet.gridpp.ac.uk/atom.xml | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| http://shirky.com/weblog/feed/atom/ | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| http://thecommune.co.uk/feed/ | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| http://theness.com/roguesgallery/feed/ | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| http://www.airshipentertainment.com/buck/buckcomic/buck.rss | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| http://www.airshipentertainment.com/growf/growfcomic/growf.rss | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| http://www.airshipentertainment.com/myth/mythcomic/myth.rss | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| http://www.feedsapi.com/makefulltextfeed.php?url=http%3A%2F%2Fwww.somethingpositive.net%2Fsp.xml&what=auto&key=&max=7&links=preserve&exc=&privacy=I+accept | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| http://www.godhatesastronauts.com/feed/ | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| http://www.tinycat.co.uk/feed/ | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| https://anarchism.pageabode.com/blogs/anarcho/feed/ | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| https://broodhollow.krisstraub.comfeed/ | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| https://debian-administration.org/atom.xml | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| https://elitetheatre.org/ | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| https://feeds.feedburner.com/Starslip | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| https://feeds2.feedburner.com/GeekEtiquette?format=xml | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| https://hackbloc.org/rss.xml | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| https://kajafoglio.livejournal.com/data/atom/ | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| https://philfoglio.livejournal.com/data/atom/ | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| https://pixietrixcomix.com/eerie-cutiescomic.rss | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| https://pixietrixcomix.com/menage-a-3/comic.rss | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| https://propertyistheft.wordpress.com/feed/ | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| https://requiem.seraph-inn.com/updates.rss | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| https://studiofoglio.livejournal.com/data/atom/ | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| https://thecommandline.net/feed/ | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| https://torrentfreak.com/subscriptions/ | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| https://web.randi.org/?format=feed&type=rss | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| https://www.baen.com/baenebooks | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| https://www.dcscience.net/feed/medium.co | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| https://www.DropCatch.com/domain/steampunkmagazine.com | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| https://www.DropCatch.com/domain/ubuntuweblogs.org | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| https://www.DropCatch.com/redirect/?domain=DyingAlone.net | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| https://www.freedompress.org.uk:443/news/feed/ | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| https://www.goblinscomic.com/category/comics/feed/ | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| https://www.loomio.com/blog/feed/ | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| https://www.newstatesman.com/feeds/blogs/laurie-penny.rss | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| https://www.patreon.com/graveyardgreg/posts/comic.rss | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| https://www.rightmove.co.uk/rss/property-for-sale/find.html?locationIdentifier=REGION^876&maxPrice=240000&minBedrooms=2&displayPropertyType=houses&oldDisplayPropertyType=houses&primaryDisplayPropertyType=houses&oldPrimaryDisplayPropertyType=houses&numberOfPropertiesPerPage=24 | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| https://x.com/statuses/user_timeline/22724360.rss | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| Humble Bundle Blog | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| I, Cringely | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| Irregular Webcomic! | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| Joel on Software | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| Judith Proctor's Journal | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| Krebs on Security | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| Lambda the Ultimate - Programming Languages Weblog | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| Looking For Group | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| LWN.net | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| Mimi and Eunice | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| Neil Gaiman's Journal | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| Nina Paley | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| O Abnormal – Scifi/Fantasy Artist | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| Oglaf! -- Comics. Often dirty. | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| Oh Joy Sex Toy | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| Order of the Stick | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| Original Fiction Archives - Reactor | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| OSnews | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| Paul Graham: Unofficial RSS Feed | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| Penny Arcade | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| Penny Red | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| PHD Comics | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| Phil's blog | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| Planet Debian | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| Planet GNU | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| Planet Lisp | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| Pluralistic: Daily links from Cory Doctorow | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| PS238 by Aaron Williams | XML | 10:56, Wednesday, 12 August | 11:44, Wednesday, 12 August |
| QC RSS v2 | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| Radar | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| RevK®'s ramblings | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| Richard Stallman's Political Notes | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| Scenes From A Multiverse | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| Schneier on Security | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| SCHNEWS.ORG.UK | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| Scripting News | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| Seth's Blog | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| Skin Horse | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| Tales From the Riverbank | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| The Adventures of Dr. McNinja | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| The Bumpycat sat on the mat | XML | 10:42, Wednesday, 12 August | 11:22, Wednesday, 12 August |
| The Daily WTF | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| The Monochrome Mob | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| The Non-Adventures of Wonderella | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| The Old New Thing | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| The Open Source Grid Engine Blog | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| The Stranger | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| towerhamletsalarm | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| Twokinds | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| UK Indymedia Features | XML | 11:07, Wednesday, 12 August | 11:49, Wednesday, 12 August |
| Uploads from ne11y | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| Uploads from piasladic | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |
| Use Sword on Monster | XML | 10:49, Wednesday, 12 August | 11:36, Wednesday, 12 August |
| Wayward Sons: Legends - Sci-Fi Full Page Webcomic - Updates Daily | XML | 10:42, Wednesday, 12 August | 11:28, Wednesday, 12 August |
| what if? | XML | 10:49, Wednesday, 12 August | 11:30, Wednesday, 12 August |
| Whatever | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| Whitechapel Anarchist Group | XML | 11:14, Wednesday, 12 August | 12:03, Wednesday, 12 August |
| WIL WHEATON dot NET | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| wish | XML | 10:42, Wednesday, 12 August | 11:27, Wednesday, 12 August |
| Writing the Bright Fantastic | XML | 10:42, Wednesday, 12 August | 11:26, Wednesday, 12 August |
| xkcd.com | XML | 11:00, Wednesday, 12 August | 11:43, Wednesday, 12 August |