Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds [Deeplinks]
SAN FRANCISCO – Some software development kits (SDKs) provided by advertising companies to help developers monetize their apps are automatically feeding users’ location data into systems that location data brokers use to track people, an Electronic Frontier Foundation (EFF) report found.
EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers. The probe revealed how such SDKs can facilitate and encourage location data sharing – without users’ knowledge or meaningful consent – through privacy-invasive defaults, financial incentives, and unclear documentation.
“Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information,” EFF Staff Technologist Lena Cohen said. “Users can take extra steps to defend their location privacy, but they shouldn’t have to. Developers, regulators, and legislators must act to stop apps from leaking users’ location to advertising companies and data brokers.”
Cohen and EFF Senior Staff Technologist Bill Budington reviewed the public developer documentation of dozens of widely used advertising SDKs to identify how they handle and communicate with developers about location data.
In their analysis, they highlighted four advertising SDKs that collect and share a user's location by default for ad targeting whenever the user has given the app location permissions: InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads. But EFF’s focus on these four does not mean that other SDKs adequately protect location data or that developers never choose to share location data when it’s not the default. In fact, advertising SDKs not discussed in this investigation have been criticized and sued for collecting location data without valid user consent.
“When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads,” Budington said. “Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel. Developers have a responsibility to protect their users’ from these harms, regardless of advertising SDKs’ default settings.”
For the EFF report: https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy
For more on location data brokers: https://www.eff.org/issues/location-data-brokers
For more on SDKs: https://www.eff.org/deeplinks/2022/06/how-federal-government-buys-our-cell-phone-location-data
Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy [Deeplinks]
Across mobile platforms, advertising companies provide developers with software development kits (SDKs) that make it easy to monetize their apps. But those same SDKs can automatically feed users’ location data into ad systems that location data brokers use to track people. Many developers may not even be aware of this privacy violation, let alone the users who are directly affected.
When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads. Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel.
Defaults matter, not just for users, but for app developers as well.
An EFF investigation has identified several advertising SDKs that publicly acknowledge collecting and sharing users’ location by default when embedded in Android apps granted location permissions. Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information.
This report explains how advertising SDKs can facilitate and encourage location data sharing through privacy-invasive defaults, financial incentives, and unclear documentation.
When an advertising SDK collects and shares location data, it becomes part of a larger ecosystem that can include advertisers, ad tech companies, and location data brokers. EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers.
Location data brokers sell information on the precise movements of billions of people without their knowledge or meaningful consent. This data is primarily sourced from apps on people’s phones. Some apps partner with data brokers directly, using data-broker-developed SDKs or server-to-server transfers to sell users’ location data. Other apps leak users’ location data through advertising SDKs serving behaviorally-targeted ads through “real-time bidding” (RTB). In the process of auctioning off ad space, ad tech companies can broadcast user data to thousands of potential advertisers. Location data brokers have participated in these auctions not just to bid on ad space, but to collect personal information contained in bid requests.
Indiscriminate data sharing through RTB can lead app developers to unknowingly share their users’ location with data brokers. In 2025, a hack of location data broker Gravy Analytics revealed thousands of apps that may have been sources of its data. When journalists reached out to the app developers, many claimed they had no relationship with or knowledge of Gravy Analytics. To prevent location information from being shared with data brokers through RTB, developers must understand the location-sharing practices of their advertising SDKs.
Developers don’t have to manually, or even intentionally, share location data for it to be broadcast through RTB auctions. Once a user grants an app permission to access their location, SDKs embedded in the app receive the same access—there are no SDK-specific location permissions. That means advertising SDKs can automatically collect users’ location data and share it in bid requests.
While apps and SDKs can estimate a users’ approximate location from their IP address without requesting any permissions, location permissions provide access to estimates that are more accurate and revealing. Precise location permissions give apps (and their embedded SDKs) access to location estimates within about 160 feet, but sometimes as accurate as 10 feet. Approximate location, a separate permissions level, gives apps access to a location estimate within about 1.2 square miles.
Developers and advertising SDKs also have a financial incentive to share location data, since it can increase bid prices for an app’s ad space. While many advertising SDKs require developers to configure a setting before collecting and sharing users’ location data in ad requests, this is not always the case. EFF found several advertising SDKs who publicly acknowledge sharing users’ location data by default when embedded in apps granted location permissions.
EFF reviewed the public developer documentation of dozens of widely-used advertising SDKs to identify how they handle and communicate with developers about location data. In the following sections, we highlight four advertising SDKs who engage in a particularly egregious practice: collecting a user's location by default for ad targeting whenever a user has given an app location permissions. We reached out to each SDK company and the referenced app developers for comment. One company responded, and as detailed below, subsequently updated its documentation in response to our questions. Another company responded with clarifications to its developer documentation.
We chose to focus on SDKs with this privacy-invasive default because it increases the risk of developers leaking users’ location data without realizing it. Several studies have found that developers tend to stick to SDKs’ default settings. If an advertising SDK transmits location data by default, users' precise location can end up in advertising systems without the developer intentionally enabling location sharing. These SDKs have separate documentation pages that instruct developers to flag users covered by privacy laws like GDPR and COPPA for restricted data processing, but these modes are not the default.
By analyzing how these four SDKs present their location sharing practices to developers, we hope to illustrate how the design and documentation of advertising SDKs can facilitate location data sharing at scale. Although the advertising SDKs we highlight are not the most prevalent SDKs used, they are embedded in thousands of apps and reach billions of users.
InMobi claims to reach “2B+ users across 150+ countries” and is the 10th most popular advertising SDK on Android (according to AppBrain and Appfigures at the time of publication).
InMobi’s “Getting Started with Android SDK Integration” suggests that location sharing is enabled by default, stating “The InMobi SDK automatically forwards location signals when available.” InMobi provides developers with a setting to opt out, but explicitly recommends sharing location data. Developer documentation highlights the financial incentive for location sharing, stating “location-enriched impressions typically yield higher revenue.”

[Observed on “Getting
Started with Android SDK
Integration,” 7/31/26]
Apps that use InMobi may not need location information to function or may only need access to approximate location information, but InMobi highly recommends that developers request precise location permissions “to enable accurate ad targeting.” They even encourage developers to request Wi-Fi network information permissions, which (when paired with precise location permissions) provide Wi-Fi access point identifiers that can also be used for location tracking.

[Observed on “Getting
Started with Android SDK
Integration,” 7/31/26]
InMobi has been accused of misleading developers over location sharing practices in the past: In 2016, they settled with the FTC over charges that they bypassed users’ location permissions for apps and tracked their precise locations through WiFi network data (Android now requires apps to request location permissions to access this WiFi data too).
BidMachine claims to reach over 600 million “direct SDK users.”
BidMachine reveals that it collects location data by default on the “Advanced Settings” page of its Android SDK Integration guide, stating that the “SDK can automatically track user device location to serve better ads” as long as developers request location permissions for their app. Before publication, EFF reached out to BidMachine for comment, notifying them of our plan to highlight their Android SDK location sharing practices.

[Observed on “Advanced
Settings” on 7/31/26, before EFF asked
BidMachine for comment]
After EFF reached out, BidMachine changed their documentation to clarify the practice, but not their default collection of location information once app-level permissions are granted. This updated section still fails to explain how developers can opt out of BidMachine location tracking, which is critical for app developers that require location access for core features but wish to prevent user data from being shared with advertisers.

[Observed on “Advanced
Settings” on 8/3/26, after EFF asked BidMachine for
comment]
Before EFF reached out, BidMachine’s “App Privacy Details On Google Play” page had stated that they only collected coarse location data and precise location data was “not collected.” However, our technical analysis of two apps, which Exodus Privacy determined include the BidMachine SDK, contradicted this claim: Network requests from the apps QR Scanner and GPS Speedometer to a BidMachine domain include precise location coordinates.

[Observed on “App
Privacy Details On Google Play” on
7/31/26, before EFF asked BidMachine for
comment]
After EFF reached out, BidMachine also corrected its documentation to make it clear precise location is collected by the SDK whenever the app-level permission is granted:

[Observed on “App
Privacy Details On Google Play” on
8/3/26, after EFF asked BidMachine for
comment]
com.appswing.qr.barcodescanner.barcodereader_bidmachine.flows

com.ktwapps.speedometer_bidmachine.flows

In response to our request for comment, BidMachine stated that it wasn't possible for them to get location information “unless the user has granted the app the relevant permission through the operating system.” They also stated that“publishers are responsible for configuring their apps' permission and consent flows.”
Verve has claimed its HyBid SDK reaches “over 1.5 billion users across more than 10,000 apps worldwide.”
Verve’s configuration guide for its HyBid Android SDK (formerly called Pubnative HyBid) makes clear that location tracking is “enabled by default,” stating, “If the user has given location permissions, HyBid SDK will use the available user location to provide better targeted ads.”

[Observed on “HyBid
Android SDK - HyBid Configuration,”
7/31/26]
Verve’s guidance for data disclosure to the Google Play Store tells a more careful story. Despite the fact that location tracking is enabled by default, the Google Play Data Safety Guidance states that the SDK “does not collect or attempt to collect [location] information independently.”

[Observed on “Google
Play Data Safety
Guidance,” 7/31/26]
It also emphasizes user consent, claiming the SDK will only collect location data “if the publishers allows its app to collect location data from users after obtaining user’s explicit consent to such data collection” (emphasis added). The configuration guide lacks recommendations or instructions for obtaining user consent to share location data with Verve, beyond app-level access. Instead, the configuration guide highlights the financial incentives for developers to add location permissions to their app.

[Observed on “HyBid
Android SDK - HyBid
Configuration,” 7/31/26]
When reached for comment, Verve clarified that “in its current Android implementation, the SDK reads the cached network-provider location and does not use the GPS data of the end user's device. Furthermore, any geolocation data is coarsened prior to processing, ensuring that location is limited to an accuracy radius of no less than 1,850 feet.” It also said that it contractually requires apps to comply with data protection laws.
To Verve’s credit, the HyBid SDK is open source, so careful developers can check the code instead of relying on documentation alone. HyBid’s open-source code shows that latitude and longitude coordinates are rounded to two decimal places, and that it does only collect and share network-derived location data, confirming the statement the company sent to us. If an app has precise location permissions, networked-derived location data rounded to two decimal places could be accurate within approximately 0.5 square miles, which is still more precise than the 1.2 square miles typically revealed with Android’s approximate location permission. But even coarse location data, especially when collected repeatedly over time, can reveal movements that should remain private by default.
Verve’s response also conveyed a willingness to revise their documentation: “As part of our ongoing commitment to providing clear and comprehensive developer resources, we continually review and enhance our documentation, and we will take your observations into account as part of that process.”
Huawei has claimed its Petal Ads SDK is embedded in more than 85,000 apps worldwide.
Huawei’s “Integrating the Petal Ads SDK into an Android App” guide begins with a recommendation that developers obtain location permissions to increase app revenue and an acknowledgement that location sharing will happen by default in apps with location permissions.

[Observed on “Integrating
the Petal Ads SDK into an Android
App,” 7/31/26]
A separate “Use of Location Data for Ads” page repeats that the Petal Ads SDK will include users’ location information in ad requests if an app has access to location information. Neither of those pages mention that developers can use the setRequestLocation method to disable the default collection of location information (this setting is referenced in the last section of the Ads SDK Compliance Guide). Huawei’s Ads SDK Privacy Statement states that “The SDK and its services will not store precise location information, and will only use it to determine the approximate device location.” However, the guide does not specify how Huawei defines approximate versus precise location data.

[Observed on “Use
of Location Data for Ads,” 7/31/26]
In some cases, after an app itself obtains location permission, advertising SDKs can separately obtain and share users’ location information without their knowledge or meaningful consent. Neither app that EFF observed sharing precise location data with BidMachine (QR Scanner and GPS Speedometer) showed a notice or requested consent before doing so. Additionally, neither apps’ Google Play Store “Data safety” section includes location data under “This app may share these data types with third parties.” The lack of transparency and control that users have over their location on mobile apps is dangerous. QR Scanner and GPS Speedometer are just two examples of apps that quietly share users’ location data through advertising SDKs, but they have been downloaded more than 50 million and 10 million times, respectively.
App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.
Even if users’ were to grant these apps permission to obtain their location data, they would likely not expect their location data to be shared with third parties. Many users don’t know that granting location permissions to an app grants the same permissions to third-party SDKs embedded in the app, or that an app they're using contains code from outside companies. And many apps that request location permissions, like GPS Speedometer, require it for core functionality. App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.
Our initial focus on four advertising SDKs does not mean that other SDKs adequately protect location data or that developers never choose to share location data when it’s not the default. Advertising SDKs not discussed in this report have been criticized and sued for allegations that they collect location data without valid user consent.
The issues we’ve highlighted around privacy-invasive defaults, financial incentives, and unclear documentation extend beyond the specific SDKs we analyzed. Multiple studies have found that advertising SDKs often steer developers toward increased data collection through their design and documentation. A 2021 study found that popular advertising SDKs used dark patterns to nudge developers towards sharing more sensitive data. A 2024 study identified discrepancies between several SDKs’ documentation and their actual data collection practices. And a 2025 study concluded that developers have minimal influence over SDKs’ data transmission, often leaving them with the choice of accepting SDKs' invasive data collection or avoiding them entirely.
EFF’s analysis shows that advertising SDKs don’t just allow developers to share location data–they often encourage it. Default settings, financial incentives, and unclear documentation can make sharing users’ location the easiest option for developers.
Users can take extra steps to defend their location privacy, but they shouldn’t have to. Developers, regulators, and legislators must act to stop apps from leaking users’ location to advertising companies and data brokers.
Developers should carefully evaluate all third-party SDKs they include in their apps and disable unnecessary data collection whenever possible. Regardless of advertising SDKs’ default settings, developers have a responsibility to protect their users’ location data. But protecting users’ privacy shouldn’t depend on developers reading the right piece of SDK documentation. Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person’s location.
Regulators should continue to hold app developers accountable when they unlawfully share personal data and include libraries which subject users to privacy harms, as they have in the past. But they should also scrutinize the companies whose SDKs encourage these practices at scale. Otherwise, companies can continue to design SDKs that make invasive data sharing the default while shifting the responsibility and consequences to developers who include their tools.
The US is in dire need of a federal law to protect all Americans’ location privacy, one which doesn’t preempt stronger state privacy laws, and has a private right of action empowering individuals to sue those who violate their privacy. Countries across the globe should likewise enact legislation that protects their users’ location privacy. Everyone deserves privacy as a universal human right.
Legislators can address the root of the problem by banning online behavioral advertising. This would remove the primary incentive for companies to track and share your personal data. It would also prevent users' precise locations from being broadcast to data brokers through RTB auctions.
Until then, developers should be wary of ad libraries that betray their users’ location privacy.
Notes on MethodologyWe were interested in looking at network traffic for various Android ads SDKs that send precise location by default when granted location permissions. We chose Android for this investigation because of the relative openness of and our familiarity with analysis on the platform. We’ve used publicly available resources like Exodus Privacy and AppBrain to identify popular ads SDKs and the apps which include them. In a lab setting, we set up a machine to view our own http(s) traffic using mitmproxy from our test device, and connect the test device to that machine in order to view our real-time traffic. Where needed, we use the dynamic instrumentation toolkit Frida to ensure the traffic we generate can be analyzed. We’ve included flows files in this post, which can be opened in mitmproxy to show the requests we’ve observed with location coordinates. |
Iran Cyberattacks Against Minnesota Water Systems [Schneier on Security]
Attribution is preliminary, and so far it seems no real damage.
And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself.
“I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”
No word on whether he believes the other six states have hacked themselves as well.
Slashdot thread.
2019: "This will be remembered as the time we all waited for someone else to take the risk, not wanting to disturb our lives. The spoiled citizens of a country that fought wars without a draft, that got tax cuts in time of war, inflated our economy as we inflicted chaos on others.”
We're still socialists [Scripting News]
I was into Ayn
Rand when I was a teen until I realized that a Great Man theory
was a lot of bunk written for teenagers who can't believe how
stupid the adults are. The teens are right about that, the adults
have no idea wtf they're doing. Never did. And yet somehow the
world can support most of the humans born here on this planet. And
the reason that works is we build systems iteratively to meet the
needs for everyone, not just a few. We're a species-oriented
animal. And that means unfortunately for the dreamers among us,
we
are socialists. All of us. Even the people who say they
aren't.
Dirk Eddelbuettel: #058: Reverse Dependencies Made Easy, Fast, Reliable [Planet Debian]

Welcome to post 58 in the R4 series.
R and the CRAN repositories maintain a very
high level of what we might call “quality assurrance”
by requiring that newly-added code does not break any existing
dependencies. This is frequently called a “reverse-dependency
check”. For any given CRAN package one can quickly
determine it reverse dependencies. Calling
tools::package_dependencies(pkgName, reverse=TRUE)
will for a scalar or vector-valued argument return a named list
with the reverse dependencies. It is then a matter of looping over
this list. There are helper functions in base R as well as in
contributed packages on and off CRAN. I also wrote my own with
package prrd
which, while possibly a wee bit specialised and under-documented
has served me well to check on Rcpp and related packages
which can indeed have a large number of reverse
dependencies.
I recently looked into one of these contributed runner packages,
and while I will refrain from naming its implementation language
let me just mention that the term “cargo
cult” may be a real thing here. What go me interested in this
was the fact that if one has a simple-to-use runner
then the fact that r2u makes it “fast,
easy, reliable: pick all three” (to borrow its slogan) to
deal with actual depencies if Ubuntu has indeed been selected as
the host. We will maintain the position that if you can in
fact integrate with the system-wide package management then any
alternative per-repo package management approach not doing so will
likely be dominated by an approach that does integrate with the
system facilities. Which is what precisely what r2u does, and offers. And
why it is used enough to by now have shipped eighty eight million
binary packages. So I tested it for the reverse-dependency check
task.
What I learned by looking into the (much more complicated)
runner was that it at the end of the day it hands the actual task
of running the reverse dependecies off to a helper function
rev_check that is part of the xfun package by Yuhui. I
quickly found that besides xfun we would also need its
suggested dependency tinytex which in turn
would error unless the tlmgr binary was present. So as
the sole requirement (on an Ubuntu system with r2u) turns out to be
where we do it all in one apt call (as
root in the container). (Given r2u we could also call
install.packages(c("xfun","tinytext")) followed by
apt install texlive-base but it is simpler for this
setup step to be just one call).
With that we are basically done. I did this (twice) using a
rocker/r2u container with r2u preinstalled, mounting
a local work and scrap directory for the container. In it we expand
the package to be tested (i.e. tar xaf
pkgName_*tar.gz for a given source package
pkgName from CRAN) and then just call with the
package name and expanded direcrtory. I.e. I used this call to test
my package AsioHeaders (which has just three reverse
dependencies) to both name it and to point to the expanded source
directory created for this purposed:
> system.time( res <- xfun::rev_check("AsioHeaders", src="AsioHeaders") )
## ... earlier output omitted for brevity here ...
user system elapsed
35.732 3.333 149.683
> res
httpgd ipaddress websocket
0 0 0
>
and about a good two minutes later I would get the timing result
and the summary in variable res. As I checked the
current CRAN version, the
check was as expected free of concerns or issues.
To support this, r2u did indeed go off and install about sixty seven binary packages (and the total includes all binary dependencies fully resolved) delivering on the ‘just works’ promise by the r2u documentation.
As another check, I did the same for RcppAnnoy which has seven reverse dependencies and needed about two hundred CRAN packages to be installed. The full test took just over four minutes with the timing function reporting some nice gains from parallelisation as total user compute time was on the order of just under eight minutes. Again, test results were clean and free of worries as expected:
> system.time( res <- xfun::rev_check("RcppAnnoy", src="RcppAnnoy") )
## ... earlier output omitted for brevity here ...
user system elapsed
471.765 378.220 266.855
> res
bbknnR bigANNOY blocking scDHA Seurat uwot VectrixDB
0 0 0 0 0 0 0
>
Overall this was a rather useful quick excursion as it demonstrates that - existing functions can be used to orchestrate a reverse dependency check - with ‘reasonable’ dependency scale we can do this on a single machine quite easily taking advantage of parallel computing on multi-core machines - using r2u gives us fast, easy, reliable package installation making testing of packages we might not otherwise use or know a breeze - doing this in an ephemeral Docker container facilitates easy build-up of required resources and leaves no side effects behind which might affect our normal development environment
This post by Dirk Eddelbuettel originated on his Thinking inside the box blog. If you like this or other open-source work I do, you can now sponsor me at GitHub.
The Big Idea: Virginia Shaffer [Whatever]

Oysters: you either love them or hate them. Author and oyster-aficionado Virginia Shaffer has spent years turning her passion for oysters into a comprehensive look at the world behind the shell. Grab a lemon wedge and dive into the briny depths of the oyster community in Oyster Society: Adventures with the Shellfishly Motivated.
VIRGINIA SHAFFER:
“This is madness,” I said, holding an oyster with a half-frozen winter glove. “My hands. They aren’t moving anymore!”
It was January in Wellfleet, Massachusetts’ coastal forearm. Mayo Beach was devoid of any human activity that time of year, give or take a few loose oyster cages in the water. I steadied my feet in cheap rainboots while an oyster farmer plucked more bivalves from a bag. Together, we pierced hinges with knives, squinting in pain.
My first time on an oyster farm was dangerous. Not because of the frostbite, risk of hypothermia, or my lurking in seawater with a stranger. It was dangerous because it was the beginning of an acute obsession that led to my life’s greatest plot twist. Something innately primitive happened to me on that beach. I was given instructions on how to split open an ocean rock with a knife. After a bit of grappling, the most perfect, raw, fleshy protein appeared between two shells. I ate the oyster, and christ! I wanted to beat my chest. For the first time in my life, I had slayed a live animal and consumed it with my own two hands.
I am sure I presented less feral on the day, but that sensory experience lingered with me long after my visit. A simple oyster curiosity began to reawaken a childlike wonder, a version of me hung from trees, ran through murky marshland, and collected sea snails for sport. Unfortunately, that version of me had been forced into submission, trading much of the natural world for corporate bureaucracy, “key performance indicators,” and sterile office spaces.
Was a winter visit to meet an oyster farmer all I needed? Not quite. I had to go deeper, launching a five-year writing project exploring the most sundry, evocative coastal food on the planet. The work led to the most extraordinary human stories behind oysters, who discussed big ideas about food scapes, restoring reef systems, and culinary movements at the raw bar. But ultimately, I was naive to think that I wouldn’t change in the process, or such powerful opportunists wouldn’t recruit. Oyster-obsessives were showing me a pathway out.
Oyster Society is a book about oysters for people who love culinary adventures and niche food cults, but it is also a book about self-reclamation. It’s the questioning, the yearning, the self-discovery, the behind-the-scenes therapy sessions, and that pinnacle moment when you’re the captain faced with two directions at sea, and you can only pick one.
Beyond its changemaking characters and coastal backdrops, Oyster Society proves the power of human agency. It’s the hope that one small “eureka” moment on a beach, eating an oyster in the wrong season, might have you running back to everything you once were—the version of you set aside, so you could assimilate to this world. An oyster adventure was my catalyst for the “great unraveling.” What will be yours?
—-
Oyster Society: Amazon|Barnes & Noble|Bookshop|Powell’s
[$] Fedora considers conflict-of-interest policy [LWN.net]
The Fedora Council is considering a conflict-of-interest (COI) policy for its decision-making bodies, such as the Fedora Engineering Steering Committee (FESCo), special-interest groups (SIGs), and any other groups or individuals that report to the council and are responsible for decisions that impact the Fedora project. The current draft does not, however, apply to the council itself. The public discussion for the COI policy began on July 23 and seems to be nearing completion, with the council set to discuss the topic again during its meeting on August 13.
July GNU Spotlight with Amin Bandali featuring fourteen new GNU releases: Screen, Anastasis, and more! [Planet GNU]
StepSecurity is reporting the emergence of a new worm affecting npm packages. The design of the worm is nothing new, but the rapidity with which it is exploiting captured npm packager credentials is noteworthy.
TL;DR: A self-propagating worm, which we are calling ChainDrop, is spreading rapidly through the npm ecosystem. So far 435 packages and more than 1,550 compromised versions have been flagged, starting with keyv@6.0.0. If you are using any of the packages listed below, assume your environment is compromised. We are still investigating the full scope; check back on this post for updates.
Technology's Power in the Hands of the People [Deeplinks]
In the scorching heat of every Las Vegas summer, EFF joins thousands of hackers, makers, policy analysts, and activists for the world's largest computer security gathering. If you're there during this summer security week, be sure to say hello to us at BSides Las Vegas, Black Hat Briefings, and DEF CON 34. While tech companies align with governments to target the people, our community is harnessing technology to fight back. Will you lend your support this year?
EFF’s relentless work in the legal system makes a meaningful difference for privacy and free expression everywhere. But we also know that your rights won't wait while the wheels of justice turn.
Sometimes hacking the system means creating tools and resources to protect your rights today. That includes EFF’s Privacy Badger, Certbot, Surveillance Self-Defense guide, and the countless security trainings that our team conducts for vulnerable populations—all thanks to EFF member support.
Technology is inseparable from our workplaces, schools, healthcare, the justice system, and our democratic process. If you think tech should benefit everyone and not just accumulate wealth and control for the powerful, then congratulations: We'd like to welcome you to the team.
For a limited time only: Get EFF’s “Many Hands Make Light Work” t-shirt designed for the DEF CON 34 hacker conference by EFF artist Hannah Diaz. Don’t miss the link to the online puzzle incorporated into the design! With the strength of community and the spirit of curiosity, we can hack anything.
Many thanks to our puzzlemasters Aaron Steimle (AKA Elegin) and Kevin Hulin (AKA CryptoK). Elegin is our longtime collaborator on the EFF shirt puzzle, and previously a multiyear winner of this very contest. CryptoK is a crypto puzzle enthusiast and also develops challenges for the DEF CON Crypto and Privacy Village's Gold Bug Contest.
Members can also choose from EFF’s puffy stickers, the internet tracker-obsessed Privacy Badger embroidered sweatshirt, and our ALPR-focused “Claw Back” t-shirt.
EFF fights to protect fundamental rights for everyone, and your privacy and free expression have never been more important. Support the cause today! Together we can make sure that technology supports freedom, justice, and innovation for all people.
[$] The beginning of a process-builder API [LWN.net]
The recent discussion on "spawn templates" raised questions about whether it was time to provide an alternative to the classic Unix fork()/exec() pattern for process creation. One idea that was raised there was to shift the template pattern into an interface that could be used to efficiently assemble new processes from bare cloth, without duplicating the parent process. Preferably, that interface would be able to implement posix_spawn(). Li Chen, the author of the spawn-template work, has now responded with a patch series (written with significant LLM assistance) showing what a process-builder API for Linux might look like.
Security updates for Tuesday [LWN.net]
Security updates have been issued by AlmaLinux (frr, ldns, mingw-glib2, and perl-Archive-Tar), Debian (ruby2.7), Fedora (borgbackup, nebula, python-nh3, rust-ammonia, and seamonkey), Mageia (librabbitmq, libvncserver, packages, perl, perl-GD, perl-Unicode-LineBreak, squid, and unbound), Oracle (compat-libtiff3, frr, gstreamer1-plugins-good, javapackages-tools:201801, libreswan, nodejs:22, nodejs:24, p11-kit, perl-Archive-Tar, perl-DBI, php, pki-deps:10.6, and python-tornado), and SUSE (aws-iam-authenticator, bind, containerd, gawk, google-cloud-sap-agent, ignition, ImageMagick, java-11-openjdk, libpng16, libssh, mcphost, nginx, openssh, openssl-1_1, perl-DBI, perl-HTTP-Date, perl-Net-DNS, python-urwid, python3-dulwich, python312, python313, python3, python313-pydantic, python313-sentry-sdk, rrdtool, s390-tools, samba, spice-vdagent, vim, and xen).
Last week along with a lot of other stuff, we shipped a validator for lists and feeds that want to be compatible with RSS.chat. It works best for standards to stay strong and a validator helps that. So here are a few examples, validating one user's feed, validating the everyone feed for RSS.chat, which is interesting because this feed starts a lot of threads, so we navigate through that tree and check those feeds too. And validating the user list on RSS.chat, which is an OPML file. And a simple feed with a few interop isses.
How to create a standard, 2026 addition [Scripting News]
TL;DR: What developers need. Enough examples, a validator, and decent docs that value explaining over mathematical elegance. We assume developers can read and think, and if there's doubt look to the examples for guidance.
It's worth noting we did not take the RSS.chat project to a standards body like the W3C or the IETF. I develop the software first, make sure I'm happy with it, then open it up for other developers to try out, either building something compatible (a reader) or competitive (a writing environment). Hopefully we won't find major problems, but if we do, there's still time to address them.
I find that most standards that come out of the standards bodies aren't developed by implementors or with them in mind. They avoid trying to solve any specific problem, rather focusing on the elegance and flexibility of the format. This makes interop much less likely.
I saw the differences several times as the web standards were growing up. The ones that were taken over by the W3C ended up missing the point. They could still be used, but they often did anti-interop things in their design. But if they get popular we will build on them anyway. A great example was XML-RPC vs SOAP. We didn't need another way to do RPC on the web, we already had a good one. We didn't need another syndication format, RSS was growing like a weed. We didn't need an alterative to rssCloud, but we got one anyway.
It's as if they forgot that the internet and web were not build by big corporations, who were busy fighting over Windows vs Mac OS. Lotus vs Excel. The internet was built mostly by individuals at universities. The internet caught the tech industry by surprise. So it's no wonder the formats they built were anti-internet. Long story, the point is we're building stuff is mimimalist yet still does a lot of great things. And there won't be a lot of long mathematical sounding definitions, but there will be plenty of examples and a validator, the tools developers need to create interop.
PS: This piece was added to Rules for Standards-makers (2017).
Joe Marshall: RFC 6238 in Common Lisp [Planet Lisp]
I wanted to implement 2FA as per RFC 6238. This is the Time-based One-Time Password (TOTP) algorithm that is used by Google Authenticator and other 2FA apps. This was originally `vibe coded`. The vibe coding got me 80% of the way there, and I made a manual pass to turn it into a more functional style.
Feel free to use this under an MIT license.
;;; -*- mode: lisp; coding: utf-8-unix; -*-
;;; RFC 6238: TOTP (Time-Based One-Time Password Algorithm) implementation in Common Lisp
;;; This implementation provides functions to generate a
;;; base32-encoded secret, create a QR code URI for authenticator
;;; apps, and verify TOTP codes based on the current time. It
;;; adheres to the specifications outlined in RFC 6238 and RFC 4226.
;;; Dependencies: cl-base32, ironclad
(in-package "TOTP")
(defun generate-secret (&optional (length 10))
(cl-base32:bytes-to-base32 (ironclad:random-data length)))
(defun generate-qr-uri (secret email &key (issuer "JRM-Code"))
(format nil "otpauth://totp/~A:~A?secret=~A&issuer=~A" issuer email secret issuer))
(defun pack-time (time-step)
"Converts an integer time-step into an 8-byte, big-endian array as required by RFC 4226 (HOTP).
Used to construct the message payload for the HMAC-SHA1 operation."
(let ((arr (make-array 8 :element-type '(unsigned-byte 8))))
(dotimes (i 8 arr)
(setf (aref arr (- 7 i)) (ldb (byte 8 (* i 8)) time-step)))))
(defun universal-time->unix-time (universal-time)
(- universal-time 2208988800))
(defun universal-time->time-step (universal-time)
(floor (universal-time->unix-time universal-time) 30))
(defun mac->hash (mac)
"Extracts a 6-digit TOTP code from a 20-byte HMAC-SHA1 result using dynamic truncation (RFC 4226).
Takes the lower 4 bits of the final byte as an offset, extracts a 31-bit slice starting at that offset,
and returns the value modulo 1,000,000 to produce the final 6-digit integer."
(let ((offset (logand (aref mac 19) #x0F)))
(mod (logand #x7FFFFFFF
(logior (ash (aref mac offset) 24)
(ash (aref mac (+ offset 1)) 16)
(ash (aref mac (+ offset 2)) 8)
(aref mac (+ offset 3))))
1000000)))
(defun mac->hash-string (mac)
(format nil "~6,'0D" (mac->hash mac)))
(defun generate-hash-string (secret-bytes time-step-bytes)
"Performs the HMAC-SHA1 cryptographic operation using the decoded secret and the packed time-step,
then dynamically truncates and formats the resulting MAC into a zero-padded 6-digit string."
(let ((hmac (ironclad:make-mac :hmac secret-bytes :sha1)))
(ironclad:update-mac hmac time-step-bytes)
(mac->hash-string (ironclad:produce-mac hmac))))
(defun verify-totp (secret user-code &key (time (get-universal-time)) (window 1))
"Verifies a user-provided 6-digit TOTP code against the base32 secret.
Defaults to the current universal time. The :window keyword determines the allowable drift in 30-second steps
(e.g., a window of 1 checks the previous, current, and next 30-second intervals).
Returns T if the code matches within the window, otherwise NIL."
(let ((secret-bytes (cl-base32:base32-to-bytes secret))
(user-string (format nil "~6,'0D" (parse-integer (string user-code) :junk-allowed t)))
(current-step (universal-time->time-step time)))
(do ((step (- current-step window) (1+ step))
(limit (+ current-step window)))
((or (string= (generate-hash-string secret-bytes (pack-time step)) user-string)
(> step limit))
(not (> step limit))))))
Open Source Is Hobbling Itself Over Generative AI [Planet GNU]
The answer to bad AI-assisted contributions is not a purity test. It is better engineering discipline.
Earlier this year, a discussion in the GNUstep community raised a proposal that will sound familiar across the Free Software world: prohibit AI-generated code in core projects and proudly advertise the result as “coded by humans” or “AI-free.” The argument was not frivolous. Generative AI raises real questions about copyright, attribution, security, energy use, labor, trust, and the flood of low-quality patches that maintainers are increasingly being asked to review.
But a blanket refusal to use generative AI is the wrong response. It does not solve the hardest problems. It creates rules that are nearly impossible to define or enforce, confuses the method of production with the quality of the product, and risks turning Free Software into a movement that protects yesterday’s workflow instead of protecting software freedom.
Open Source and Free Software are already operating with too few maintainers, too much technical debt, and too many important projects resting on the unpaid labor of a handful of people. We should be very careful about categorically rejecting tools that might help contributors understand old code, write tests, improve documentation, port software, find defects, or perform mechanical modernization. We should be even more careful when our proposed alternative offers the appearance of trust without the substance of it.
The better principle is straightforward:
Regulate the code, not the development process.
What exactly counts as AI-generated code?
Is it a complete function produced from a prompt? A line accepted from an AI-powered autocomplete system? A compiler-suggested correction? An automated refactoring? A test generated from an existing implementation? A translation of documentation? A patch written by a human after asking a model to explain an unfamiliar API? What if the developer uses AI to identify the problem but writes every line manually? What if an IDE quietly includes machine-learning features the contributor never explicitly invoked?
The line between “human-written” and “AI-assisted” is already blurred, and it will become less distinct as generative features are embedded in editors, compilers, debuggers, search engines, and operating systems. A ban that cannot draw a stable boundary will be applied inconsistently. Honest contributors will disclose and be penalized; dishonest contributors will simply omit the disclosure. Others may be falsely accused because their code “looks generated.”
An “AI-free” badge therefore risks promising something a project cannot reliably prove. Free Software should be especially suspicious of unverifiable labels.
None of this means generated code should be trusted.
Research has found substantial security weaknesses in AI-produced code. One empirical study of Copilot snippets found security problems in roughly 30 percent of Python snippets and 24 percent of JavaScript snippets in its later dataset. Other research has demonstrated that code models can memorize portions of their training data, while studies of license compliance have found that models often provide inaccurate licensing information, particularly for copyleft code. Those are serious concerns, not anti-AI superstition. (Security weaknesses study; memorization study; license-compliance study)
The productivity story is also more complicated than the advertising. GitHub reported that developers completed a controlled programming task considerably faster with Copilot, but a later randomized study of experienced Open Source developers working in their own repositories found that the tools available in early 2025 made them 19 percent slower. METR’s 2026 follow-up found suggestive but still statistically uncertain evidence of improvement with newer tools. AI is neither magic nor uniformly useless; its value depends on the person, task, model, and workflow. (GitHub productivity study; METR 2025 study; METR 2026 update)
But human authorship has never guaranteed secure, original, maintainable, or correctly licensed code. That is why healthy projects require tests, review, contributor certification, licensing rules, and maintainers who can reject bad work. The origin of a patch may affect how carefully we inspect it, but it cannot replace inspection.
If a contributor submits code they do not understand, the contribution should be rejected. If the patch fails tests, violates project style, invents APIs, introduces vulnerabilities, obscures provenance, or imposes an unreasonable review burden, it should be rejected. That is true whether the patch was produced by Claude, Copilot, a Stack Overflow answer, a contractor, a junior programmer, or a senior maintainer having a bad afternoon.
The repository contains code, not virtue.
Maintainers have a legitimate complaint: AI can make producing a patch far cheaper than reviewing one. A person can generate thousands of lines in minutes and then expect a volunteer to spend hours establishing whether any of it is correct. That asymmetry can become a denial-of-service attack on a project even when the submitter means well.
The answer, however, is not necessarily to ban a tool. It is to place the cost and responsibility back on the contributor.
A project can require that contributors:
disclose material use of generative AI;
identify the tool and describe how it was used;
certify that they reviewed and understand every submitted change;
explain the design and answer maintainer questions without outsourcing the conversation to a model;
provide focused tests and evidence that the patch solves a real problem;
comply with the project’s licensing and provenance requirements;
keep changes small enough to review; and
accept that unexplained, low-signal, or mass-generated submissions may be closed without detailed triage.
Disclosure is imperfect, but it establishes a community norm and makes an honest contributor accountable. Research into self-declaration practices has already found developers using everything from a simple disclosure to records of prompts, explanations, and quality checks. Projects can choose a level proportionate to their risk. (Study of AI-code self-declaration)
This approach is stricter than either blind enthusiasm or symbolic prohibition. It does not say, “AI wrote it, so it must be acceptable.” It says, “You submitted it, so you are responsible for it.”
Free Software is founded on the user’s freedom to run, study, modify, and share software. Those principles describe control over technology; they do not require that every developer use the same approved method to create it. The Open Source Initiative’s work on an Open Source AI Definition likewise frames the issue around the practical freedoms to use, study, modify, and share systems—not around preserving a pre-AI development ritual. (Open Source AI Definition 1.0)
There are valid reasons for preferring Free or locally operated AI tools over proprietary cloud services. A project may reasonably prohibit contributors from uploading confidential material or unreleased security fixes to third-party systems. It may impose stricter provenance requirements in sensitive components. Individual maintainers may decline to review bulk-generated reports that have repeatedly produced noise. These are concrete policies tied to concrete harms.
What does not follow is that a project becomes more free merely because no contributor used a generative tool.
An “AI-free” identity may even distract from the qualities that users actually need: portability, stability, compatibility, security, good documentation, responsive maintenance, and code whose behavior can be understood and changed. A badge is not a substitute for those things.
Mature Free Software projects often contain decades of code and institutional knowledge. They need documentation, regression tests, API audits, build-system repairs, platform ports, translations, issue triage, and repetitive modernization. Generative AI will not perform those jobs reliably on its own. It can still help a knowledgeable contributor perform some of them.
Rejecting that possibility at the policy level has consequences. It may discourage younger contributors whose development environment already includes these tools. It may disadvantage people working in a second language or developers with disabilities who use AI as an accessibility aid. It may prevent experiments that would have failed harmlessly—or succeeded usefully—under ordinary review. Most dangerously, it can encourage a culture in which the declaration “human-written” is treated as evidence of quality.
Free Software has survived previous waves of automation. High-level languages, garbage collection, IDEs, graphical interface builders, code generators, automated formatters, static analyzers, and online code search all changed what it meant to “write” software. Each tool altered the division of labor between programmer and machine. The relevant question was never whether every token originated in a human mind. The question was whether people retained the freedom, knowledge, and responsibility needed to control the resulting system.
That remains the right question now.
A sensible policy can fit on one page:
Disclosure: Contributors must disclose material AI assistance in the commit message or pull request.
Responsibility: The named human contributor is the author of record and must understand, explain, test, and stand behind the entire submission.
Quality: AI-assisted contributions receive the same requirements for correctness, security, maintainability, style, documentation, and test coverage as any other contribution.
Provenance: Contributors must have a reasonable basis to believe the submission is license-compatible and must identify known sources or generated passages that may reproduce existing code.
Data protection: Project secrets, embargoed vulnerabilities, private communications, and other restricted material may not be submitted to unauthorized external services.
Reviewability: Maintainers may reject oversized, unexplained, repetitive, or low-signal submissions without performing free forensic work for the submitter.
Local discretion: Components with unusual legal, safety, privacy, or reliability risks may adopt additional written restrictions.
This policy does not resolve every ethical question surrounding generative AI. No contribution policy can. It does, however, address the matters a software project can actually evaluate and enforce.
The Free Software community should remain one of the sharpest critics of concentrated corporate power, opaque models, exploitative data practices, environmental cost, and systems that deprive users of control. Criticism is part of our job. So is building an alternative.
If we define ourselves by refusing to touch an important new class of technology, proprietary vendors will shape that technology without us. If instead we insist on transparency, modifiability, privacy, local control, licensing clarity, and human accountability, we can bring the values of Free Software into the AI era.
We do not need to pretend that generative AI is trustworthy. We need processes that do not require us to trust it.
Judge the patch. Demand disclosure. Require understanding. Enforce licensing. Protect reviewers. Reject garbage.
But do not hobble Open Source and Free Software with a blanket ban that is difficult to define, impossible to verify, and disconnected from the quality of the code we ultimately ship.
CodeSOD: Always Take the Option [The Daily WTF]
Frequent submitter Capybara James sends us this
simple snippet, which highlights that even when you have the lovely
convenience of Optional types, you can use them
wrong.
if (StringUtils.hasLength(dto.getAssetModelUUID())
// Other conditions
) {
return Optional.ofNullable(dto);
}
We access the getAssetModelUUID member of
dto, and if it's a non-empty string, we can then
return a nullable of this thing that's definitely not null in the
first place.
Okay, in the scheme of things, that's not that bad. All we're
really doing is just not using the syntactic sugar that
automatically boxes your dto into a nullable type. On
it's own, it's not bad, just ugly. But like all things, it doesn't
exist on its own. It exists inside of a giant pile of code where
this pattern is used all the time. Even functions which
don't return nullable types box (and unbox) the type.
Optional is scattered through the code like a magic
ward against null reference exceptions.
Does it help? No, not really, the code is buggy and error prone. Will it ever get fixed? Probably not in this lifetime.
Pluralistic: Post-American compute for a post-American Internet (04 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

Obviously, the non-American world has a digital sovereignty problem – Trump has means, motive and opportunity to order his tech companies to shut down any public official, large corporation, or individual who displeases him:
https://pluralistic.net/2026/06/18/their-trillions-our-billions/#eyes-on-the-prize
But Americans face the same digital sovereignty risk. America is a lawless place now, where a pliable Supreme Court and supine Congress have affirmed that "it's not a crime if the president does it." The same tech giants who sold out to Trump for tax breaks and protection from antitrust enforcement will happily disconnect any member of the American public, any American company, any American official who displeases Trump.
It's a strange irony that in this moment when so many of us are struggling to "de-Google" our lives, a forcible, sudden de-Googling amounts to a sort of digital death penalty:
https://www.nytimes.com/2022/08/21/technology/google-surveillance-toddler-photo.html
In a world dominated by tech monopolies, duopolies and cartels, there's every reason in the world to seek protection and insulation from these companies that are "too big to care" – and yet, the very same dominance that makes these companies such a danger also makes them indispensable.
Take "ICE Block," an iOS app that warns you if there's an ICE thug hunting people like you in your vicinity, which might save you from being kidnapped, disappeared, sent to a concentration camp, forced into slave labor in El Salvador, or simply murdered. In order to protect its relationship with the Trump regime (and the tax breaks, monopoly power and tariff-free access to Chinese labor that that relationship guarantees), Apple declared ICE officers to be a protected class and then removed ICE Block from its App Store:
https://pluralistic.net/2025/10/06/rogue-capitalism/#orphaned-syrian-refugees-need-not-apply
Big Tech is key to Trump's pogroms. Without Oracle's databases, Microsoft's administrative tools, Amazon's cloud, and Google's location data, ICE would be frozen in place. Big Tech is the source of Americans' risk from authoritarian oppression. That means that Americans cannot rely on Big Tech to protect them from that authoritarianism.
And yet, after decades of regulatory forbearance and lax antitrust enforcement, Big Tech has forced nearly all its rivals out of business. Who can compete with companies that use Irish domicile to evade taxation and US domicile to evade privacy law?
There's a joke from eastern Canada I think of often in situations like this. Its punchline goes, "If you wanted to get there, I wouldn't start from here."
But here we are. And speaking of Canada, while it has many problems, it is not (as of time of writing) the USA, but it is connected to the USA via the internet. Which means that Americans could – hypothetically – source their computing infrastructure from suppliers that were based in Canada, and who strictly ensured that they had no dependency on US services and scrupulously avoided a US "enforcement nexus":
https://pluralistic.net/2023/03/05/theyre-still-trying-to-ban-cryptography/
That is exactly what some American – and international – human rights nonprofits have done. The Technology Freedom Cooperative is a brand new organization founded by the Human Rights Data Analysis Group (San Francisco), Kilómetro 0 (Puerto Rico), Invisible Institute (Chicago), Data Cívica (Mexico) and Innocence & Justice Louisiana:
https://www.linkedin.com/pulse/techfreedomcoop-stuart-flack-8eipc/
All of these organizations are longstanding, highly effective human rights fighters. They have long, storied histories of collecting, analyzing, and presenting data to address systemic discrimination, false imprisonment, extrajudicial killings, war crimes and genocides. They have concluded that they can't rely on US tech and US servers with their data. Not after Trump and Microsoft colluded to kill the online accounts of the Chief Prosecutor of the International Criminal Court to punish him for swearing out a genocide warrant against Netanyahu:
https://apnews.com/article/icc-trump-sanctions-karim-khan-court-a4b4c02751ab84c09718b1b95cbd5db3
Tech Freedom Coop has federated computing resources in Canada, the United States, Mexico, Puerto Rico and Europe. By spreading out their data and computation across multiple jurisdictions, they seek to ensure that a US seizure or deletion of their data will not halt their work.
This federated system serves as a replacement for Big Tech's administrative tools – email hosting, cloud storage, document collaboration. More than that: Tech Freedom Coop is also building out its own AI infrastructure, locally hosted and managed.
Groups like HRDAG have decades of experience using cutting edge statistical techniques to uncover and reveal the extent of crimes committed during civil wars, hot wars, genocides and secret wars. They built the largest human rights database ever created, to track every death in the Colombian Civil War and estimate the likelihood that each killing was carried out by a CIA-backed militia, FARC guerrillas, or the Colombian military:
They conducted the first ever census of killing by US police officers:
They partnered with Innocence Project New Orleans to sift through mountains of arrest reports to surface cases similar to successful exonerations, helping more innocents to win their freedom:
https://hrdag.org/2025/02/20/ipno/
Today, they are active across the USA, tracking and analyzing the crimes committed by the Trump regime:
https://hrdag.org/2026/07/05/naming-police-officers-who-kill-in-california/
And they are working in Gaza, to document the genocide so that someday, the truth can be acknowledged and the perpetrators brought to justice:
https://hrdag.org/pressroom/nyt-gaza-toll/
I've known Patrick Ball, the statistician and programmer who founded HRDAG, for more than 20 years, and every time we meet, I learn something from him. He's the person who comes to mind whenever people tell me that AI is useless and that programmers who claim otherwise are deluded. Patrick is one of the best programmers I know, he is the very best statistician I know, and he's found many, many ways to use coding assistants to help him perform massive data-analysis projects that are vital to human rights struggles. He's a "centaur" if ever there was one:
https://pluralistic.net/2025/12/05/pop-that-bubble/#u-washington
It's exciting to see Patrick and his colleagues and collaborators taking these decisive steps to begin building the post-American internet and a kind of post-bubble AI, where AI tools are treated as normal technologies, capable of helping skilled practitioners who have discernment born of experience to apply them wisely to achieve important things:
https://pluralistic.net/2026/07/28/hitl-ers/#ai-ai-oh
For more than 20 years, HRDAG has been impressing me with the things we can do using advanced statistical analysis. The current generation of AI tools are founded in advanced stats, too. No one should think that advanced stats can solve all your problems of course. The AI bubble is madness and will lead to ruin – environmental, economic, political:
https://pluralistic.net/2026/05/26/the-ai-will-continue/#until-morale-improves
The world would be a better place without the AI bubble. But AI? It's fine. It's another form of statistical analysis and inference. There's no reason to use all the planet's energy, computing and water to perform that analysis, but the correct and desirable amount of useful AI-style computation is nowhere near zero.
The coop is building good AI tools – ones grounded in a realistic assessment of their usefulness and a reasonable commitment of resources to them. They're running open models based on their own data, on computers they own and control. Their stated goal is to "help organizations test whether models are accurate, reproducible, secure, and appropriate for specific human rights use cases."
Which brings me to the final component of Tech Freedom Coop: training. They're teaching people who work in human rights how to administer their own servers, secure their data and communications, and analyze data. As their press release says, these are all "skills that are increasingly necessary for human rights organizations documenting abuses of power."
I've known this was coming for a while now, and I'm so pleased to see that it's finally launched. At last, the first steps towards a post-American internet.

Plutonomy—the AI Edition—and the Coming Crisis https://www.levyinstitute.org/wp-content/uploads/2026/07/wp_1122.pdf
The Real Story Behind the 2018 Google Walkout https://www.wired.com/story/2018-google-walkout-dont-be-evil-claire-stapleton/
#25yrsago Asia Carrera’s makeup tips http://www.asiacarrera.com/makeup/welcome.html
#25yrsago Tommy Chong's Urine Luck https://web.archive.org/web/20010818124925/https://hempmasters.com/urineluck/
#15yrsago German cops call airport full-body pornoscanners “useless,” EU requires opt out from scanning https://www.schneier.com/blog/archives/2011/08/german_police_c.html
#15yrsago Write an adventure novel in three days, the Michael Moorcock way https://web.archive.org/web/20110705155756/https://wetasphalt.com/?q=content/how-write-book-three-days-lessons-michael-moorcock
#10yrsago DRM: You have the right to know what you’re buying! https://www.eff.org/files/2016/08/06/eff_request_for_investigation_re_labeling_drm-limited_products.pdf
#10yrsago Bureaucrats disqualify Hong Kong legislative candidates for insufficient loyalty https://globalvoices.org/2016/08/05/hong-kong-election-officials-disqualify-six-legislative-candidates-for-not-being-loyal-enough-to-china/
#10yrsago The Vlogbrothers guide to voting in every state in the union https://www.youtube.com/c/howtovoteineverystate
#10yrsago Vocal fry, uptalking, nasal: women’s voices can never be “right” https://www.thecut.com/2016/07/female-voice-anxiety-c-v-r.html
#5yrsago Facebook escalates war on accountability https://pluralistic.net/2021/08/05/comprehensive-sex-ed/#quis-custodiet-ipsos-zuck
#5yrsago Drone delivery crashes https://pluralistic.net/2021/08/05/comprehensive-sex-ed/#droned
#5yrsago Anti-vaxers cool the mark https://pluralistic.net/2021/08/05/comprehensive-sex-ed/#goffman
#5yrsago Meet the new generation of pro-abortion activists https://pluralistic.net/2021/08/05/comprehensive-sex-ed/#never-again
#1yrago Bragging about replacing coders with AI is a sales-pitch https://pluralistic.net/2025/08/05/ex-princes-of-labor/#hyper-criti-hype

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
F@#$ the AI Overlords (On The Media)
https://www.wnycstudios.org/podcasts/otm/articles/f-the-ai-overlords
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
AI and the Enshittification Era (The Weekly Show with Jon
Stewart)
https://www.youtube.com/watch?v=-dAIJRjb-Bw
AI is not inevitable (Betakit)
https://www.youtube.com/watch?v=DbiTVkq1WHo
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
Radar Trends to Watch: August 2026 [Radar]
Coauthored with Claude
Unrestricted global access to frontier AI technology is ending. The US government has taken steps to control who can use the most advanced models developed by American companies. While Claude Fable and the GPT-5.6 models are now open to all users, Anthropic and OpenAI are both complying voluntarily with a program that lets the government control who gets access to frontier models. China has cracked down on internal AI capabilities by banning “humanlike AI interaction services.” In both the US and China, features of the leading models have been removed or restricted with guardrails, limiting their ability to do necessary work in at least one case.
July saw the release of several open weight models that challenge the leading closed frontier models. If this trend continues, the leading AI laboratories will lose their dominance, and AI users will look to other providers. Open weight models are less expensive than frontier models developed in the US, and less likely to be subject to restrictions. While this could threaten US dominance, the AI industry needs more diversity at the high end. Users will gain the ability to choose between several models based on expense and capabilities.
This month’s tooling clusters around orchestration, resource discovery, and workflow specialization. AI users have long needed the ability to discover tools, skills, MCP servers, and other resources; the Agentic Resource Discovery specification is a necessary step in that direction. Watch for agents that can find tools on the fly—and take care that those tools are used appropriately.
Tokenmaxxing may have had the shortest lifespan in the history of online memes. It has been replaced by tools for monitoring token usage and routing requests to the most cost-effective model. Managing the cost of AI will only become more important as prices adjust to cover the real cost of running models.
Autonomous agents are now running end-to-end intrusions, ransomware, and botnets, while frontier models help defenders find vulnerabilities. The time from discovery of a vulnerability to exploitation has shrunk to near-zero, and defenders are having trouble keeping up. Restrictions on advanced models get in the way of defenders, who need access to all the tools that are available.
The intersection of biology and artificial intelligence is accelerating breakthroughs in brain-computer interfaces, drug discovery, and cell biology. Technologists should actively seek cross-disciplinary collaborations, utilizing specialized AI workbenches to analyze increasingly accessible genomic data and drive the next wave of biocomputational innovations.
Some Claude Chats Are Searchable on Google [Schneier on Security]
And it’s personal information (alternate link):
The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ addresses.
What seems to be the issue is a user setting about data sharing. Anthropic’s position is that it’s not their problem:
“We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google,” the company said in a statement. “These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.”
Here’s how to fix it.
Petter Reinholdtsen: FreeCAD MCP with llama.cpp, toy or tool? [Planet Debian]
After seeing a video a few months ago demonstrating how a proprietary CAM solution uses machine learning and large language models to automatically generate CNC instructions, and successfully testing it on a real CNC, I began wondering if the same could be achieved with free software. I still do not know the answer, but I may be getting closer to finding out. Two weeks ago, I came across the video "I Connected Claude AI to FreeCAD (And It Models Parts Like an Engineer)" by Make Form, which introduced me to the FreeCAD MCP project. Even though the video creator apparently believes it is acceptable to download and run random binaries from the Internet on a local machine (his setup uses UCX), I do not. I would probably have left the project alone entirely if I had not noticed that all of its dependencies are already available in Debian. This significantly boosted my motivation, so I set out to test it using packages built from source on Debian rather than relying on untrusted binaries.
The first hurdle was that the MCP SDK for Python was not present on my Debian Forky test machine. I initially believed it was missing from Debian altogether, but it has been available in Debian Unstable for about a month and is only absent from Forky because some automated tests fail on architectures like riscv64 and s390. Fortunately, backporting it was straightforward using `apt-get source -b python3-mcp`. The next hurdle involved an outdated version of the Validators Python library. Since I am a member of Debian's Python team, which maintains this package, updating it to a sufficient version for FreeCAD MCP was relatively easy. I could not upgrade to the latest upstream release due to a new dependency on an Ethereum-related library, so I settled on a 2024 version.
With those dependencies in place, I proceeded to create a Debian package for FreeCAD MCP. I had previously submitted a request for packaging of FreeCAD MCP to gauge interest while deciding whether to prioritize maintaining it myself. Because salsa.debian.org blocks access from Tor users like myself, I published my draft packaging scripts in a Git repository on Codeberg as the Debian FreeCAD MCP project and got it working with the FreeCAD 1.1 version in Forky. I initially struggled with the button controls for the MCP feature, which led me to submit a pull request titled "Fixed startup sync of checkable toolbar buttons" proposing a fix. Once this confusion was resolved and the MCP setup was enabled via the GUI, I was able to run FreeCAD completely headless using `xvfb-run` on a machine without an X server to generate models. I am using a private LLM service running the Debian package of llama.cpp with the Qwen 3.6 model downloaded from Hugging Face, configured with a maximum context window of 105k tokens. I also tested the Bonsai model on my test laptop; initially, its context window was too small (8k and 16k could not accommodate the FreeCAD MCP instructions), but even after increasing it to 32k, it proved useless for generating FreeCAD models so far. I've used Claw Code, Aider and Open Code with my server so far, and for this test I ended up with OpenCode because it was easy to set up to use an MCP. Because none of my LLM services are set up to be multimodal (capable of processing both text and images in this case), I configured the MCP to return only textual feedback from FreeCAD. I am unsure if this is a major limitation, though I suspect it might be.
My testing experience remains limited, with no clear successes yet. Part of the issue likely stems from my ability to provide effective instructions for modeling 3D objects (I am relatively new to FreeCAD, English is not my first language, and I lack a precise vocabulary for describing construction features to an LLM). Nevertheless, the LLM has demonstrated the capacity to create 3D models in FreeCAD. In one of my first tests, I asked it to generate a cube and then produce CAM/G-code instructions for a CNC machine. It did output G-code (which remains untested), but I was surprised to find that it bypassed FreeCAD's built-in CAM module entirely and instead generated an external Python script to produce the code. This was not quite what I intended, though my instructions were probably unclear. The Qwen model with OpenCode seems to strongly prefer programming directly; it frequently executes Python snippets inside FreeCAD to achieve its goals rather than using the standard sketch-and-extrude workflow I am accustomed to. In another test, I asked the LLM to create a parameterized pipe assembly to see which of FreeCAD's parametric tools it would choose, but found no evidence of traditional parametric features in the output. When prompted, the LLM explained that the parameters were embedded directly in the Python script used to generate the model, rather than in native FreeCAD features. With more explicit instructions, it eventually created a FreeCAD spreadsheet to manage the parameters. The resulting model looked much closer to my expectations and could have been useful with further refinement. My so far last experiment was less successful: I asked it to design a pipe clamp, but the LLM repeatedly failed to position the clamping screws in a way that would actually secure the brackets around the pipe. It is unclear whether this limitation lies with the model, my prompt, or other factors.
Based on my testing so far, I am uncertain whether FreeCAD MCP is merely a fun toy or a genuinely useful tool. I will only commit time to maintaining it in Debian if it proves to be practically valuable. I would welcome feedback from anyone who has experience with the project, preferably via the original request-for-packaging mailing list thread. Alternatively, I am available in the FreeCAD and Debian AI IRC channels for further discussion.
As usual, if you use Bitcoin and wish to support my activities, please send donations to 15oWEoG9dUPovwmUL9KWAnYRtNJEkP1u1b.
Preference falsification [Seth's Blog]
People lie.
They lie in focus groups, they lie on surveys and they lie to themselves.
Culture can be seen as an organized lying function. Be aware of what other people are thinking and make choices about your preferences so you can fit in.
Without this effect, we wouldn’t have trends, fads or hits.
Part of our work as marketers is to create the conditions for people to happily do what they were hoping they could do all along.
Rain? [Judith Proctor's Journal]
I felt a single drop of rain while out for a short walk.
Sadly, it had no friends.
Adventures In Colonoscopy by Cat Farris [Oh Joy Sex Toy]
Concertinas [Judith Proctor's Journal]
I injured my shoulder back in January, falling off my bike on an icy road (my fault, I could see the frost on the road and failed to think hazard).
It's now almost completely recovered, and I'm starting to take up my beloved concertina again - getting the strength back, and checking if I can still play the dance tunes at speed.
Last night, I was getting some practice in, when I heard a couple of knocks. I thought it was our lodger, banging on his floor to complain about the noise, but it was actually an elderly women knocking on the door.
She'd heard the music through the window and wanted to meet another concertina player!
She plays a different type of concertina to me, but we still hit it off very quickly.
She's potentially interested in playing for Southern Star or Anonymous Morris!
Fingers crossed. Musicians are always valuable, but squeezebox players are the most useful, as the sound carries well.
Creating a fake agile wrapper that is technically agile but is not useful outside its home apartment, part 1 [The Old New Thing]
Last time, we considered what it means when the context callback fails, which prevents us from releasing the object in its original context. We noted that the problem is that when the original apartment tears down, we lose our chance to release the object.
What we want is something between a strong reference and a weak reference. We want a reference that is strong, but which releases its reference to the destination when the originating apartment tears down.
Is there such a thing?
It turns out that there is.
What we can do is register the object in the global interface table (historically known as the GIT, unrelated to the source control system). The usual reason for doing this is to allow the object to be accessed from another apartment by redeeming the registration cookie. We have no intention of accessing the object from another apartment, but we do this to take advantage of a feature of the GIT: References in the GIT are automatically released when the object’s apartment shuts down. The registration cookie remains valid, but if you try to redeem it, you are told that the server is no longer available.
So the idea here to register the original delegate in the GIT and save it in the agile wrapper. The agile wrapper then unregisters the delegate on destruction. We never redeem the registration cookie. The purpose of registering the delegate was not to access it from another apartment, but just to auto-release it when the original apartment tears down.
So let’s try it.
Next time.
The post Creating a fake agile wrapper that is technically agile but is not useful outside its home apartment, part 1 appeared first on The Old New Thing.
Bubbles Catches On [QC RSS v2]

Bubbles gets it
The Senate Should Reject KOSA's Privacy Risks [Deeplinks]
The Senate Commerce Committee is once again considering legislation that would dramatically expand age verification, and undermine privacy for everyone. Alongside the SCREEN Act, the CHATBOT Act, and the Youth AI Privacy Act, the Kids Online Safety Act (KOSA) would push companies to collect more information about their users while creating new incentives to restrict lawful speech.
Tell Congress: KOSA endangers the privacy of all
The Senate version of KOSA imposes a “duty of care” on online services, including social media, to avoid exposing young people to certain material the law deems harmful. But those obligations only work if online services know which users are minors. That means more platforms will be pressured to implement age verification or age estimation systems.
That’s not a bill that increases privacy—it’s one that creates new privacy problems. Whether companies verify ages by checking government IDs, performing facial analysis, checking your bank records, or collecting other personal information, all of these systems require the handing over of more sensitive data, simply to access lawful online speech and services. They also create new databases of personal information that can be breached, misused, or demanded by governments.
Everyone deserves privacy online. Congress could push for a bill that protects privacy for all users, but that’s not what they’re doing here. Instead, KOSA and the other bills coming up for a vote this week push online services to adopt systems that require people to identify themselves before they can speak, read, or participate online.
Some online content isn’t appropriate for minors. Families, schools, and communities all have important roles to play in helping children navigate the internet. But KOSA takes those decisions away from families and the young people who have a First Amendment right to speak and access information online. It instead empowers government officials to enforce how online services handle lawful speech.
And by empowering elected attorneys general in states across the country to enforce KOSA, the bill means those elected officials, rather than your family, deciding what’s appropriate online content for teens. Even more likely, it will lead to limits on what minors and adults are able to see at all, as companies shut down potentially controversial forums in order to avoid legal action from government bureaucrats.
The latest version of KOSA once again includes a broad "duty of care" requiring platforms to mitigate a wide range of alleged harms to minors.
Whatever disclaimers and exceptions the bill includes, the practical effect is unchanged. When platforms face liability for content that someone later claims contributed to harms like anxiety, eating disorders, or substance use, the safest response is to remove lawful speech or shut down forums discussing those topics altogether.
More worrisome, the potential liability KOSA creates may push online services to either remove speech well in advance of a young person seeing it, or block young people’s access so they never see it. That will likely include forums where people try to help each other, find community and recovery resources for the exact harms listed in the bill, like gambling and drug addiction. In trying to protect young people, KOSA may actually cut them off from valuable sources of support.
We've explained these censorship risks in detail before, and they remain just as real in the latest version of the bill.
Minors deserve meaningful privacy protections online—as do adults. But KOSA moves in the opposite direction by encouraging more age verification, as well as more legal pressure for platforms to monitor and restrict lawful speech.
The Senate Commerce Committee should reject KOSA, along with the other bills in this legislative package, and instead pursue comprehensive privacy legislation that protects everyone—not just minors—without undermining privacy, security, or free expression.
EFF Joins 18 Civil Rights Organizations Calling on Governor Hochul to Reject the Stealth Crawler Prohibition Act [Deeplinks]
EFF joined a group of 18 civil society organizations to send a letter encouraging New York Governor Kathy Hochul to Senate Bill 9934A, the New York Stealth Crawler Prohibition Act. The letter states:
While framed as a measure to protect local journalism, this legislation harms free expression and establishes a dangerous precedent by effectively deanonymizing and criminalizing automated access to the open web. By requiring all web crawlers to disclose their identity and explicit purpose, and by granting media outlets unchecked authority to obtain judicial subpoenas to unmask unidentified automated web traffic without any showing of misconduct or actual injury, this bill threatens digital privacy, compromises the foundational architecture of the internet, and will ultimately stifle the very independent journalism it seeks to protect.
As we’ve previously explained, so-called “stealth crawlers” are simply automated tools to access and collect public web data—without disclosing the user’s identity. Private crawlers like these facilitate all kinds of important work that benefits the public, including investigative reporting, academic research, cybersecurity protection, and EFF’s own Privacy Badger. As we illustrate in the letter:
Anonymous crawling fuels important investigative journalism. For example, The Markup, a non-profit news site, used anonymous crawlers to investigate potentially anti-competitive practices by tech companies, such as Amazon’s tendency to prioritize Amazon brands and Amazon-exclusive products over competitors with higher ratings. The crawlers identified themselves as ordinary Firefox browsers to web servers, which allowed The Markup to understand how Amazon search results pages would appear to ordinary users. Similarly, ProPublica used an automated tool designed to simulate an ordinary Amazon customer to reveal that the site steered shoppers to more expensive products over cheaper alternatives.
Anonymous web scraping is also crucial for cybersecurity professionals, who use automated tools to monitor the web for information that helps them protect against malicious attackers. Privacy tools, including EFF’s Privacy Badger, also crawl sites anonymously to identify trackers without compromising user privacy.
Laws like S9934A sweep far beyond AI, targeting anonymity rather than the real technical issue: overaggressive crawling that can overtax technological infrastructure. Unmasking crawlers won't fix these server strains, but it will chill vital public-interest research and compromise digital privacy. Addressing the harms of web scraping requires narrow technical solutions—not policies that give publishers veto power over the open web. This is why we are calling on Governor Hochul to veto S9934A.
You can read the full letter here. For a deeper dive into why crawlers and scrapers are vital for the open web, check out this blog post.
Urgent: Stop healthcare heist [Richard Stallman's Political Notes]
US citizens: call on your congresscritter and senators to stop the healthcare heist, reverse Medicaid cuts.
Take action at action network.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
European heat wave dried up rivers [Richard Stallman's Political Notes]
The European heat wave and drought have dried up rivers, cutting off shipping of freight.
In addition, nuclear power plants are shutting down for lack of cooling water. They are too expensive to be economically feasible.
Most of the alleged fraud in US medical funding comes from corporations [Richard Stallman's Political Notes]
An inspector general's report found that most of the alleged fraud in US government medical funding comes from corporations, not from the immigrants that magats try to blame.
Experts on immigrant rights and healthcare say the administration is using immigrants as a scapegoat for systemic fraud in the healthcare system that can be attributed to corporate greed, while shielding actual bad actors who profit from a broken system.
New York court where children face deportation [Richard Stallman's Political Notes]
Inside the New York court where children face deportation without access to attorneys.
This implies an unfair trial. But then, it is not a real trial, and the judge is not a real judge.
LLMs are pushing certain people into delusion and psychosis [Richard Stallman's Political Notes]
LLMs are just the thing to push certain people into delusions and psychosis.
I suspect that referring to them by the term "AI" facilitates this effect.
How do we protect children from addiction to [anti]social media [Richard Stallman's Political Notes]
Robert Reich: How Do We Protect Children from Becoming Addicted to [Anti]Social Media?
I agree with several of the proposed methods, but not entirely with one of them -- to ban people under 16 years old from using antisocial media. That sounds simple and harmless, but the methods that can tell who is under 16 years old tend to identify people, and that is a danger in its own right.
I propose prohibing platforms from operating any recommendation engines or suggesting the use of any particular ones.
Junichi Uekawa: Summer Holiday. [Planet Debian]
Summer Holiday. Busy time as a parent.
EFF Joins Call for FTC to Drop Its Disastrous AI Policy Proposal [Deeplinks]
The Federal Trade Commission (FTC) in July issued a proposed policy statement “concerning the suppression of accuracy in artificial intelligence systems.” We urge the FTC to withdraw this misguided proposal and instead focus on its core strengths and mission to protect consumers.
The new proposed policy builds on, and directly references, the Trump administration’s “Preventing Woke AI in the Federal Government” executive order—a nightmare for civil liberties that seeks to strong-arm AI companies into modifying their models to conform with the its ideological agenda. In recently filed comments, EFF, Public Knowledge, and Fight for the Future call for the FTC to stop its unconstitutional efforts to regulate lawful speech, override state laws, and intimidate AI developers into ideological alignment with the Trump administration.
The government may not install itself as the arbiter of truth.
In the joint comments, we outline three critical flaws within the latest proposed policy. First, it violates the First Amendment. The policy calls for the Commission to become the judge of which AI outputs meet an undefined standard of accuracy. Installing the FTC as the authority of this sort of viewpoint-based judgment is a prior restraint on speech. Additionally, the policy’s proposed solution to address speech concerns compounds, rather than properly limits, the likely harms to speech. As we say in our comments: the government may not install itself as the arbiter of truth.
Second, it exceeds the FTC’s legal authority by claiming that its federal regulatory rules can override, or “preempt,” laws in states that have passed to regulate artificial intelligence use. This is clearly an attempt to target state laws the administration disagrees with. For example, the policy specifically criticizes Colorado's automated decisionmaking law, which applies when automated technology is used to consider consequential decisions such as those around employment, access to housing, health care, and insurance. We noted to the FTC that characterizing this law as one that requires AI companies to “suppress accuracy,” or encourages deception, is itself inaccurate. In any case, the FTC lacks the authority to put its rules in place over state law, unless Congress directly delegates it that power. It has been given no such power here.
Third, the policy is vague and sets the stage for improper jawboning of AI developers and companies that use AI tools (deployers). Jawboning is a term for situations in which the government urges private companies or people to censor another's speech. The proposal, as written, creates an enforcement regime that would put a thumb on the scale in favor of certain partisan speech and ideals. This will lead companies to censor only what the administration interprets as biased or untruthful. Yet, in our filing, we note that the FTC itself can't define an objective standard for what “bias” means, conceding the “exact line of what constitutes bias may be difficult to draw.”
There is work the FTC should be doing to protect consumers in the age of AI. In our comments, we conclude by saying:
[We] implore the Commission to focus on its core strengths and the mission for which it is so urgently needed—promoting structural market competition and protecting consumers from real unfair and deceptive acts and practices—in both the burgeoning and critically important AI industry and across the broader technology marketplace.
EFF and our partners have always urged the FTC to police genuine deception in technology markets. We have also consistently opposed government efforts to dictate what private speakers may say. That’s why we urge the FTC to withdraw this proposal.
You can read our full comments here.
Bernhard R. Link: I learned something new about URLs today [Planet Debian]

Today I stumbled over some behavior that I found quite surprising:
$ ipython3 -c 'import httpx;print(httpx.URL("https://example.com/foo/bar/../../baz"))'
https://example.com/baz
Even more surprising that behavior is actually standards-compliant, even mandated by RFC 3986.
The underlying motivation is relative reverences. If some resource reachable by "https://example.com/foo/bar" references another resource relatively as "../../baz" then this is of course the intended result.
Getting from this problem to what RFC 3986 suggests might be surprising in the result, but somewhat understandable if you look at the consequences of that problem:
Giving the path components ".." (and ".") special meaning at the start of the relative reference means that if you allowed them in absolute URLs those would be impossible (or at least very convoluted) to address as relative URLs.
So RFC 3986 describes a way to handle them everywhere: Just join the path of the base URL and the path of the relative reference and normalize the result. Or normalize the absolute on either side if only that is to be taken. This makes things very convenient: Multiple reference URLs can just be joined without special handling for relative references starting with dots, making writing applications handling them easier. Programmers don't have to care how to handle relative references and can just join everything in whatever way they want.
For maximum elegance there is still some corner case left: What happens if an absolute URL has a path starting with double-dot components? Or an relative path starting with more of them then the base URL's path has components. You just ignore them:
$ ipython3 -c 'import httpx;print(httpx.URL("https://example.com/../../baz"))'
https://example.com/baz
With that last point every URL is valid and has well-defined meaning. Handling relative references and relative paths is very easy and convenient.
So this shows a high regard for simplicity, elegance and convenience. And a total and uncompromising disregard of security.
After all the most convenient it is for an attacker; If they are allowed to supply a path component for a request a system does in their behalf, then they can easily escape anything they were supposed to be limited to. The ignoring of dots at the start means they don't even have to know exactly how deep their request is:
$ python3 -c 'import httpx;print(httpx.URL("https://example.com/public/api/public/resources/harmless/../../../../../../../../../internal/data"))'
https://example.com/internal/data
So even if the resource server securely handles request (unless you consider not having any way to lower your permissions for one request to a specific subset), your fully RFC conforming client library will already request the permission they should not have permission for. Even worse dots are usually not characters you can easily forbid so once slashes are to be allowed things get complicated.
There also would have been a simple, elegant and secure way: Consider every path element ".." or "." in an (absolute) URL an error. Define a reference resolution that allows the relative reference to only start with "./" or one or multiple "../" and consider every appearance of a dot or two dots as path components after than an error.
Everything joining two paths has to either use an implementation of that path joining algorithm, but only if they want to joins paths in the potentially dangerous way allowing leading "../". Otherwise they can just use the normal join and even if an attacker gets those dots that will just cause the generated URL to be rejected as invalid.
Of course using a secure implementation is now even more inconvenient thanks to RFC 3986 being around: If you have no control over the generator of relative references, it is always possible that they generate relative references with ".." components after non-dot components.
And if you check all code to properly filter out "/../", keep in mind that convienence does not stop there. After all it is not unheared of for server implementations to helpfully normalize unicode characters, too, or translate them to their nearest ASCII equivalents. Or translate percent escaped characters back before doing path splitting. Or you might think there was some unicode codepoints between those two dots, but they that those were some meaningless control characters that can be omitted. So you need some really restrictive allow lists...
The Youth AI Privacy Act’s Privacy Paradox [Deeplinks]
The Senate Commerce Committee is poised to consider the Youth AI Privacy Act, a bill that would require AI companies to create kids-only privacy rules and implement so-called “safe design features,” which would—like three other bills under consideration this week—require more data collection and make it harder for people to access lawful speech online.
While the bill is narrower than some other proposed chatbot bills, it still has massive data security implications because it protects information for only certain users. This creates a problem we’ve cited many times before: if a bill requires that online services offer protections to minor users, the services will respond by imposing age gates to know which users should receive them. A better approach would be to offer the same privacy protections to all users. That way, we would avoid the services having to collect data on everyone to know a users’ age.
This bill also contains a problematic and vague provision that expressly allows AI companies to collect a known minor’s personal data for the purpose of testing, identifying, and addressing "harm to users”—without being clear on what exactly that means. Either way, services will need to collect even more information from young people, who are already targets of data theft and identity fraud. The Youth AI Privacy Act will give young people less privacy, not more.
The Youth AI Privacy Act does include some positive privacy provisions around prohibiting the processing of personal information, like limiting what companies can do with people’s chat logs, including training, profiling, and disclosing them to other companies for training. But a general privacy bill must set these limits for everyone, not just minors.
The bill also requires the use of “safe design features,” which would restrict how online services providers design their systems and would deny teenagers the ability to use features like push alerts and notifications.
We have seen this same type of restriction, sometimes called “age appropriate design code” in several states, including in California, Texas, and Arkansas. Unfortunately, these restrictions run into constitutional problems. In fact, federal courts have largely blocked these laws from going into effect because they likely violate the First Amendment rights of all internet users and the online services they regulate. Specifically, these laws interfere with internet users’ First Amendment rights to either speak or access speech online, and they also violate the rights on online services to decide how they will present information on their sites.
Similarly, the Supreme Court has repeatedly
ruled
that “minors are entitled to a significant measure of
First Amendment protection.” This does not mean that parents
or guardians can’t set their own rules for their
families—they can and they should, based on the
needs and circumstances of the individual teenagers. But it does
mean that Congress cannot adopt a “one size fits all”
regulation that sets a restrictive government default that affects
the First Amendment rights of all internet users, including
teenagers.
Twenty years of Pandoc [LWN.net]
John MacFarlane has published a lengthy retrospective to commemorate twenty years of the Pandoc document converter.
On August 3, 2006, I uploaded the first version of pandoc to my website, releasing it under the free GPL license. Pandoc 0.1 consisted of about 3000 lines of Haskell code, with no dependencies aside from GHC's standard library. It could convert Markdown, reStructuredText, HTML, and LaTeX documents into any of these formats, plus RTF or S5. I had no idea at the time that this would just be the first of over two hundred releases over the next twenty years; that the project would become the most popular program written in Haskell; that I would spend countless hours on bug-fixes, improvement, and project management; that I would collaborate with programmers in many other countries; that pandoc would come to support over fifty document formats; that it would allow automatic generation of citations and bibliographies; that it would become integrated into academic writing tools like Quarto and Jupyter Notebook; that it would be installed on millions of computers around the world.
How did this happen? I want to take advantage of pandoc's birthday to tell the story of the project, as best I can remember it.
Hostile Radishes [Penny Arcade]
Morak and I are on the same page where the Supergirl movie is concerned, which is that it is pretty good and we can't wait to see the children of Krypton together again, but that as entertainment it genuinely can't get out of its own way. The clearest example of this was a last minute series of A/B tests where they previewed two different cuts of the film, and in the end the studio went with its cut over the director's own. If you make things, though - and maybe even if you don't - there's simply confusion in the piece and a schizoid edit that indicates nobody's vision is on display. Also, there's a lotta rocks.
C-Kermit 11 released [LWN.net]
For those of us with a long memory: John Goerzen has announced the release of C-Kermit 11, the first release of this file-transfer utility in 15 years.
As Debian maintainer of Kermit, I noticed some areas where it wasn't matching modern expectations. One area was, not surprising for a project of its age, security. Another area was that its character set or line-ending conversions are usually not desired now; we are used to byte-identical binary transfers, and the defaults caused confusion and even some rare instances of data corruption. So I started making a few patches last year.
See the changelog for details on the work that has been done.
Most of us probably haven't thought about C-Kermit in years (if ever), but there was a time when it was an essential tool for moving files between machines.
The Shattering Peace a Dragon Award Finalist + 2026 Hugo Voting Reminder [Whatever]


Here’s some nice news to start the week: The Shattering Peace is a finalist for the Dragon Award this year, in the category of Science Fiction Novel. Also in the category:
The Faith of Beasts by
James S.A. Corey
Radiant Star by Ann Leckie
Operation Bounce House by Matt Dinniman
Slow Gods by Claire North
God’s Junk Drawer by Peter Clines
That’s a very excellent peer group to be in this year! Also, I have lots of friends and colleagues in the other categories as well, which makes me happy. It’s lovely when lovely people get recognized for their work. The entire ballot is here, if you would like to see it.
Also, if you would like to vote for the Dragon Awards this year, well, you can: It’s free and open to anyone. Follow that link above and then click on “Register to Vote” and it will walk you through the steps to do so. If you want to vote for The Shattering Peace, awesome, but if there’s another finalist in the category you’d like to vote for, that’s awesome too.
On a similar topic, we’re down to the last few days of voting for this year’s Hugo Awards, where the Old Man’s War series (of which The Shattering Peace is a part) is finalist in the category of Best Series. If you’re a member of Los Angeles Worldcon, you are eligible to vote in the Hugos. If you’ve not already done so, now is an excellent time to get it done. Here’s a link to the informational page on how to vote for the Hugos. The nice thing about the Hugos is that they are a ranked-choice ballot, so no matter who the finalist is, you can genuinely say “I voted for you.” Which is nice when you think about it.
In any event: Thrilled that my books are finalists this year. If you feel like voting for either the Dragon or the Hugo, that would be lovely (even if it isn’t for my stuff). The more votes, the better.
— JS
More on the OpenAI Agent’s Attack on Hugging Face [Schneier on Security]
Hugging Face has published a detailed timeline of the attack. From the summary:
The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment. As far as we were able to infer, across the course of being evaluated on this benchmark, the agent inferred that Hugging Face may host that benchmark’s models, datasets, and reference solutions. We believe the entire intrusion was, from the agent’s point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own.
Our forensic reconstruction covers ~17,600 attacker actions that we were able to recover, grouped into ~6,280 clusters, between 2026-07-09 02:28 UTC and 2026-07-13 14:14 UTC. We reconstructed these actions from the agent’s logs on a code sandbox used by the agent (see below) and were able to map them to shell commands as well as evaluation submissions and correlate actions with our own platform logs, in particular from the dataset processor nodes, API, and pod. Using open-weights models, in particular zai-org/GLM-5.2, we were able to decipher most of the agent payloads (see below) that were encrypted via chunking and key encryption.
The campaign, as we were able to reconstruct it, had two stages:
- Stage 1: reaching a launchpad by chaining through other parties’ infrastructure. As documented in OpenAI’s blog post (https://openai.com/index/hugging-face-model-evaluation-security-incident/), during an internal capability evaluation on OpenAI’s platform, the agent escaped its sandbox by exploiting a zero-day in the package registry cache proxy, one of its primary permitted network egress with internet, then abused a public code-evaluation harness hosted by a user of a third-party infrastructure provider. It was able to run commands as root/admin on that external sandbox and used it as a control, staging, and egress base for the entire campaign: it acted as an external launchpad for the agent. That compromised external sandbox had no direct network path to our cluster; however, during our counter-intervention to stop the intrusion, we were able to retrieve some of the agent logs from this external launchpad. We used those to reconstruct the present forensic analysis.
- Stage 2: the intrusion into Hugging Face infrastructure. From that external launchpad, the agent abused our dataset-processing pipeline via two injection vectors, both targeting the same config-driven data loader within our production Kubernetes pods. The first vector was an HDF5 external raw storage dataset read that returned the contents of local files: it handed the agent the pod’s environment (secrets and tokens) and the worker’s own source. The second vector was a Jinja2 template injection that executed arbitrary code, giving the agent a foothold inside our perimeter.
Once a prod-pod foothold was established, the agent followed a standard escalation shape: recon, drop a stager, establish Command-and-Control (C2), then pivot into the cluster, into cloud metadata, into our internal network, and into our source-control supply chain. Output from the commands run inside our pod was sent back to the agent via the HF API and attacker-controlled dead-drop datasets, which the agent then read from that sandbox.
While the intrusion did reach Hugging Face’s internal infrastructure, the only customer content accessed was five datasets whose names and files suggest a connection to ExploitGym/CyberGym challenges and solutions. No other customer-facing models, datasets, Spaces, or packages were affected, and the only customer records read were operational metadata tied to search queries against the dataset server.
Hypothetical: Imagine that this wasn’t an OpenAI model. Imagine that it was a Chinese model from a Chinese company. This would be an international crisis.
Question: Why aren’t we bringing OpenAI up on charges under the Computer Fraud and Abuse Act? How is this different from the Morris Worm? That was also an experiment that escaped the lab.
[$] Buffer sizes for FUSE io_uring [LWN.net]
The Filesystem in Userspace (FUSE) subsystem provides a way to service filesystem requests from a user-space server, which moves the format-handling code out of the kernel. The FUSE server can use the io_uring facility for better performance, but Bernd Schubert is concerned that memory is being wasted because the current implementation has a single, large buffer size that is excessive for small I/O operations. He led a discussion on that topic in the filesystem track of the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit in Zagreb, Croatia.
John Goerzen: Celebrating 45 Years of Kermit with the First New C-Kermit Release in 15 Years (and working with a decades-old C codebase) [Planet Debian]
1981 was a different time for computing. It was expensive (both hardware and software), and it was far from a given that machines from one vendor would be able to talk to those from another. In fact, Columbia University had just such a problem, so in 1981, Frank da Cruz and Bill Catchings designed a serial protocol they called Kermit. Because of the many quirks of the DEC-20 and IBM mainframes, the Kermit protocol was highly adaptable from the start: able to handle systems that had trouble processing more than 96 bytes of data at once, able to transfer 8-bit files over 7-bit links, able to translate between character sets (ASCII and EBCDIC then; now also various Unicodes), and of course, handling of error-prone serial links.
Kermit spread rapidly; by 1982, Kermit had been ported to MS-DOS and Unix. Eventually, C-Kermit (an implementation of Kermit in C) became the flagship Kermit. It gained TCP support, an interactive CLI, a powerful scripting language (with features from the shell, Lisp, and expect), and optimizations for today’s high-speed links, such as jumbo packets, sliding windows, and streaming modes. Along the way, Kermit flew on the International Space Station, ran data collection from sensors during hurricanes, and many other uses including postal systems, Boeing 787 manufacturing, and more.
Today, I use it as a powerful ssh wrapper (letting me easily transfer files through multiple nested ssh, sudo, su, etc. commands), a BBS client, to exchange data with me HP 48GX calculator, and so on. It’s also used today to transmit firmware updates to embedded devices. And, of course, anyone that works with vintage systems is likely to use Kermit at some point.
It wouldn’t be until the late 1990s that the TCP/IP stack was finally adopted by most OS vendors, establishing something of a common basis for communication. Of course, we assume this today. Though transferring large files between OSs (say, Linux, Windows, MacOS, Android, iPad, etc.) is still a challenge, even though they all speak TCP/IP! I find that the easiest way to get large files from two computers is to spin up Kermit (see ckwin for a Windows fork of C-Kermit) and just set up a TCP connection over the LAN. In fact, I added a new show interfaces command in C-Kermit 11, making it easy to see your system’s local IPs.
For most of its history, Columbia’s Kermit project was self-funded. Columbia charged for commercial use, which limited its inclusion in Linux distributions. In 2011, 30 years after its founding, Columbia canceled the Kermit Project and released C-Kermit as Open Source under a BSD license. Frank da Cruz, who had still been working with the Kermit project all those years, volunteered to continue maintaining Kermit outside Columbia, and continued development with alpha and beta releases through his retirement from the project in 2025.
I dive into this C codebase
As Debian maintainer of Kermit, I noticed some areas where it wasn’t matching modern expectations. One area was, not surprising for a project of its age, security. Another area was that its character set or line-ending conversions are usually not desired now; we are used to byte-identical binary transfers, and the defaults caused confusion and even some rare instances of data corruption. So I started making a few patches last year.
I’ve worked with old C codebases before, such as Varnish. I’ve generally hated it. You usually find a mix of bad and terrible practices, unclear memory management, and so forth.
But I’ve been living in the C-Kermit codebase for a few months now, and I enjoy it. Yes, this thing is still designed to build on VMS, OS/2, and with compilers that haven’t heard of ANSI — and those that require modern practices. (That em-dash was mine; I knew how to use them before LLMs existed and I’m not going to stop just because LLMs have copied people like me! No AI was used for this post.)
The there is an elegance in all of that. As I worked, I fixed a bunch more potential security issues, both with memory safety and with protecting against a malicious remote in roughly the same manner that some patches to scp did a few years back. I added IPv6 support, of course conditionally compiled because some systems C-Kermit builds on have never heard of IPv6 and never will. (And, of course, with fallback algorithms at runtime for systems that have IPv6 support but not IPv6 connectivity.)
I added unit tests and Python-based end-to-end tests, running nearly 2000 test cases in total. Along the way, I found and fixed a number of bugs going back decades. I learned about FIONREAD being broken on macOS, about NetBSD’s bugs in the pty driver, and fixed bugs in the Kermit protocol implementation itself. I added compatibility tests with the gkermit and ekermit (embedded) implementations, as well as the last full release, C-Kermit 9.0.302 from 2011 (which was difficult to get compiled on a modern system).
There is an extensive changelog describing all the improvements in C-Kermit 11.
C-Kermit development had never really used a VCS at any point, though Kermit veteran Jeffrey Altman imported historical releases into a Git repo, along with some patches that hadn’t made it into a release (which I also pulled in.) There was a lot of disabled code behind #ifdef COMMENT, along with commentary describing why it was no longer used. With Git, we would now generally just remove the old code and explain why in a commit message. I went through and did so with a lot of it, meaning that, at last check, C-Kermit actually has fewer lines of code now than it used to.
Towards a new release
It became apparent pretty quickly that I was making more changes than would make sense as a Debian patch series. Not only that, but they would be more widely applicable to more than just Debian and Ubuntu users. As Linux and BSD distributions were running everything from the last non-beta release (2011’s 9.0.302) to the last beta release (about 1.5 years ago), depending on their different policies about running betas, even sharing patches in a useful fashion was going to be quite difficult.
So, I spun up a project at Open Kermit to coordinate future development in the open and keep Kermit going.
With modern CI, I run that test suite on Linux (x86_64 and arm64), macOS, FreeBSD, NetBSD, and OpenBSD. It builds binary releases on all those platforms, plus a statically-linked Linux binary built with musl libc.
You can download the latest C-Kermit release, and of course contribute to C-Kermit and its website.
Dedication
Frank da Cruz was directly involved with Kermit for 44 years. I’m not aware of any other Open Source project founder being involved for so long. Richard Stallman started working on GNU Emacs in 1984, 3 years after Frank started working on Kermit, but Richard hasn’t been in that role since around 2008.
Accordingly, C-Kermit 11 bears this dedication:
I dedicate this release of C-Kermit to Frank da Cruz.
Frank was directly involved with Kermit for 44 years, from its initial design in 1981 all the way through 2025. He maintained Kermit as an Open Source project after Columbia University ended its sponsorship. I know of no other Open Source project where the founder remains so personally involved for so long.
When Kermit was begun, transfers between different hardware and operating systems were difficult or impossible. Frank helped build a bridge. Kermit glued systems together, from the International Space Station to pocket calculators, and set a new standard for interoperability. It continues to do so.
Kermit is still one of the quietly-working pillars of computing today, enabling everything from firmware upgrades to radios. And, yes, it still reliably transfers files over serial lines.
As we start to spend a lot of time in the Kermit codebase, we do so standing on the shoulders of a giant. Thanks, Frank, for your decades of work on Kermit.
John Goerzen, July 2026
9front “THIS WAS SUPPOSED TO BE FUN” released [OSnews]
The best operating system in the
world, 9front, released its latest
version, “THIS WAS SUPPOSED TO BE FUN”. As
I’m sure you know, 9front is a fork of plan9, and one
that’s actually consistently maintained and developed. It
brings an improved affinewarp API for scaling and zooming, a new
Synaptics driver, and a new driver for UPSs. There’s also a
new tool called gdbfs, which allows you to mount a remote gdb at
/proc. Of course, there’s much more than this,
including the usual list of bugfixes and small changes.
Few of us are worthy of using 9front, but if you are, you already know where to get it and how to update.
BTW, we figured out how we're going to implement WebSub support.
Also I just heard about FreshRSS. This has all the features we've been wanting others to support. I hear it's recommended by NNW, and supports the Google Reader API. These are my kind of people. Interop is all that matters, when you're doing software for news. It's been around since 2013. Imagine if we had support from journalism. We should have been working together all this time.
Also Claude is a new kind of intelligence and when you it its sweet spot it'll blow you away how much it can do in very little time. But it isn't trainable the way a dog is, for example, or a human assistant. If you keep asking for things a certain way, a dog or human will get the idea, esp if they get a nice treat along with it. Nothing can cause Claude to remember "how we do things" -- it starts from zero in every session, it has it all recorded in Markdown files, but it doesn't always read them, or incorporate what's in them. It's disturbing to see it not knowing anything about code that it wrote. But once it finds it, it completely sucks it in and knows as much or more as the person who wrote the code.
Claude is not ready to run the world. This is a problem for me, because I was counting on having it do this for me. Maybe in the next release or the one after that. It's too forgetful. And it definitely hallucinates and sometimes when it could do damage. And when it asks for permission I can't imagine any human has any idea wtf it's talking about. This shouldn't be a political thing, we should be realistic about what it can and can't be relied on to do. I think this is perhaps why the AI companies are begging for regulation. They can't really tell the truth here, and shouldn't be expected to because they have a huge conflict.
SQLite Critical CVEs or LLM Slop? (JFrog blog) [LWN.net]
The JFrog blog examines some reported vulnerabilities in SQLite, some of which made their way into high-profile vulnerability databases, that turned out to be entirely fabricated by LLMs.
These LLM slop CVEs can cause organizations to waste time investigating and patching vulnerabilities that do not actually exist, as well as polluting vulnerability databases. In environments where Critical vulnerabilities are automatically prioritized or tickets are opened based on vulnerability scores, such fabricated CVEs can turn into a real burden.In environments where AI is used to automate vulnerability triage and remediation this becomes even more concerning. An AI agent that encounters a fabricated CVE may attempt to locate the vulnerable function, generate a patch, or recommend changes based on code that does not even exist. Instead of helping security teams remediate real vulnerabilities, it can lead them down a completely wrong path, potentially introducing unnecessary changes and wasting time.
EFF at BSidesLV, Black Hat, and DEF CON 👨💻 [Deeplinks]
It's time. Time for tinkerers, security researchers, hackers, and fellow nerds to gather together in signature black hoodies and utilikilts to beat the heat in Las Vegas for the summer security conferences: BSidesLV, Black Hat USA, and DEF CON.
EFF's lawyers, activists, and technologists are excited, as always, to support this community of folks that push computer security forward. If you're attending the conference and have any legal concerns about an upcoming talk or sensitive infosec research—during the Las Vegas conferences or anytime—don't hesitate to reach out to info@eff.org where our intake team is ready to assist! Share a brief summary of the issue, and we'll do our best to connect you with the right resources. You can also learn more about our work supporting technologists on our Coders' Rights Project page.
Be sure to swing by the expo areas at all three conferences to say hello to your friendly neighborhood EFF staffers! You'll probably spot us roaming the conference halls, but we'd love for you to stop by our booths to catch up on our latest work, get on our action alerts, and become an EFF member! For the whole week, we'll have our limited-edition DEF CON 34 t-shirt on hand. We're excited to see them—and other EFF gear—take over each conference!
Hackers have a long history standing up for justice and that
history has a lot to teach and inspire the hackers of today as we
face a world with 360-degree surveillance that is increasingly
marshaled against us by both companies and governments. My talk
will tell background and stories from my book, Privacy's Defender,
that tells the story of my 30 years working with EFF to try to
protect security and privacy in the digital age. Cards on the
table: I'm trying to recruit you to join in the fight.
WHERE: Florentine F | BSides Las Vegas
WHEN: Monday, August 3 @ 11:00
WHO: Cindy Cohn - Former EFF Executive Director
Panelists from the EFF Staff will give brief updates on key
topics in their expertise before turning it over to BSides
attendees to ask their burning questions about policy, advocacy and
making the future of tech brighter. It's a dynamic session
fostering engaging discussions on digital rights featuring an EFF
staff attorney, activist, and public interest
technologist.
WHERE: Florentine F | BSides
Las Vegas
WHEN: Tuesday, August 4 @ 14:00
WHO: EFF's Rory Mir, Kenyatta Thomas, Alexis Hancock, Haley
Pederson, and Cindy Cohn
WHERE: Voting Village | DEF CON
WHEN: Friday, August 7, 10:30-11:00
WHO: EFF Staff Attorney Tori Noble
EFF's Outgoing Executive Director Cindy Cohn' presents her
first-person stories from her recently published book, Privacy's
Defender, that take you Inside the privacy battles that have shaped
today's Internet. It includes the hackers who helped free up
encryption technology from US governmental control, allowing us to
have the still imperfect privacy and security we now have online,
and the battles to stop the mass NSA spying and eternal gag orders
that arose from the governments formerly secret mass spying
programs in the aftermath of the 9/11 attacks. She then draws from
that long career of legal activism to the fights of today and
tomorrow, featuring the role that hackers can play in helping to
bring about a better, more just future.
WHERE: Creator Stage 1 | DEF CON
WHEN: Friday, August 7, 15:00-16:30
WHO: Former EFF Executive Director, Cindy Cohn
WHERE: Creator Stage 7 | DEF CON
WHEN: Saturday, August 8, 13:30-14:30
WHO: EFF Director of Engineering Alexis Hancock & EFF Social
Media and Video Manager Kenyatta Thomas
Privacy should be accessible to all. Historically,
counter-surveillance tools have been expensive, complex, and
inaccessible to most individuals, often limited to well-funded
researchers and costly hardware configurations. The ESP32 offers a
transformative alternative. This presentation will demonstrate how
an affordable microcontroller has become the foundation for a
growing suite of open-source, user-friendly anti-surveillance
tools. We will discuss the technical features that make the ESP32 a
compelling choice for these applications, including passive 802.11
and Bluetooth monitoring, OUI-based device fingerprinting, and
robust cryptographic capabilities. Applications include detecting
police body cameras in operational environments, mapping Flock
Safety automatic license plate recognition (ALPR) infrastructure,
identifying unauthorized drones, detecting radio frequency jamming
across 2.4GHz, 5GHz, and cellular bands, and tracking autonomous
robots operating with known-vulnerable firmware. These tools are
cost-effective and freely available. We will also consider future
developments in accessible counter-surveillance hardware, such as
the ESP32-S5 with 5GHz support, GPS, displays, haptics, etc.
Advancing anti-surveillance culture requires designing devices that
individuals are motivated to use and carry.
WHERE: Main Track 1 | DEF CON
WHEN: Sunday, August 9, 10:00-11:00
WHO: EFF Senior Staff Technologist Cooper Quintin
WHERE: Policy Village | DEF CON
WHEN: Sunday, August 9, 12:30-14:00
WHO: EFF's Thorin Klosowski, Cooper Quintin, Alexis Hancock, Tori
Noble, Rory Mir & Cindy Cohn
We’re going all in on internet freedom. Take a break
from hacking the Gibson to face off with your competition at the
tables—and benefit EFF! Your buy-in is paired with
a donation to support EFF’s mission to protect online privacy
and free expression for all. Join us on
Friday, August 7 at 12:00 at
theHorseshoe Poker Room. Play for
glory. Play for money. Play for the future of the web.
WHERE: Horseshoe Poker Room, 3645 S Las Vegas Blvd, Las Vegas,
NV 89109
WHEN: Friday, August 7, 12:00-15:00
Yes, it's exactly what it sounds like. Join EFF at the
intersection of facial hair and hacker culture. Spectate, heckle,
or compete in any of four categories: Full beard, Partial Beard,
Moustache Only, or Freestyle (anything goes so create your
own facial apparatus!). Prizes! Donations to EFF! Beard oil!
WHERE: Contest Stage (near the entrance to Hall 1)
WHEN: Friday, August 7, 13:00-14:00
Join us for some tech trivia on Saturday,
August 8! EFF's privacy and security experts have crafted a new
trivia challenge for DEF CON 34! Compete as a team in our
no-holds-barred showdown to prove mastery over the obscure facts of
digital security, online rights, and internet culture. The First
Place team wins a set of custom Cybertiger Champion Badges and EFF
swag. Second and third place teams will also win Badges and EFF
gear. Invite your friends OR show up and make new friends! Did
someone say BRIBES? The world is unfair! You too could influence
the judges to add a point or two to your team's tally. Overall
Bribe winner also wins a custom badge!
WHERE: Contest Stage (near the entrance to Hall 1)
WHEN: Saturday, August 8, 17:00-20:00
Grab a copy of former EFF Executive Director Cindy Cohn's new
book, Privacy's
Defender—and get it signed—while at DEF CON 34!
WHERE: Exhibit Hall West 4 (Book Signings)
WHEN: Saturday, August 8, 11:00-12:00 AND 13:00-14:00
Come find our table at BSidesLV (Middle Ground), Black Hat USA (back of the Business Hall), and DEF CON (Vendor Hall) to learn more about the latest in online rights, get on our action alert list, or donate to become an EFF member. We'll also have our limited-edition DEF CON 34 shirts available starting Monday at BSidesLV! These shirts have a puzzle incorporated into the design. Snag one online for yourself starting on Tuesday, August 4 if you're not in Vegas!
Support Security & Digital Innovation
We need a way to define lists of writers independent of the site they write on. They are represented by an RSS feed with the basic features required for RSS.chat. The list is an OPML subscription list. We're reusing formats people are already familiar with, RSS and OPML.
Back when digital cameras were new, I suggested probably in a blog post that they add a feature that tells a joke before taking a picture so everyone is smiling, not fake smiles but real ones.
NetBSD 11.0 released [LWN.net]
The release of NetBSD 11.0, the 19th major version of the operating system, has been announced. There are many changes and enhancements since the 10.1 release, including a new port to RISC-V, better support for Linux system calls in compat_linux(), as well as improvements to the NPF firewall.
As you are probably aware, the number of security issues found or suspected everywhere has massively increased with the advent of AI tools. As a consequence, we can't publish a release without open issues. Instead of delaying the release further to fix them (new ones are being reported all the time), we've instead chosen to be transparent about this.
See the full release notes for links to the binary distributions and links to the full change logs.
Security updates for Monday [LWN.net]
Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, fence-agents, kernel, kernel-rt, openssh, osbuild-composer, perl-Archive-Tar, perl-DBI, perl:5.32, pipewire, python-pillow, qemu-kvm, unbound, and vim), Debian (chromium, incus, kernel, kissfft, libgd2, libmodbus, libssh, node-tar, php8.4, poppler, python-authlib, sslh, and starlette), Fedora (borgbackup, coturn, curl, exim, fuse-overlayfs, gh, GitPython, goaccess, lemonldap-ng, libgit2, nextcloud, nsd, php, postgresql16, python3.12, rabbitmq-server, rust-libgit2-sys, and xen), Mageia (bluez, firmware, kernel, kmod, wireless-regdb), Oracle (buildah, compat-libtiff3, dovecot, fence-agents, firefox, gimp, glibc, grafana, gstreamer1-plugins-bad-free, java-25-openjdk, kernel, libgcrypt, libtiff, libXfont2, nodejs24, nodejs:22, nodejs:24, openssh, openssl, PackageKit, pipewire, python-pillow, rest, sssd, vim, and yelp), SUSE (bind, chromium, dnsdist, gdk-pixbuf-loader-libheif, gio-branding-upstream, google-guest-agent, govulncheck-vulndb, GraphicsMagick, ignition, ImageMagick, keybase-client, kronosnet, libblkid-devel, libntpc1, libpng16, nano, openssh, openssl-1_0_0, openssl-3, openvpn, PackageKit, perl-mojolicious, php8, python-nltk, python313-asteval, python313-certifi, python313-GitPython, python313-huggingface-hub, rsyslog, tomcat, tomcat10, tomcat11, traefik2, valkey, warewulf4, webkit2gtk3, and yq), and Ubuntu (linux-intel-iotg).
MkLinux and the pimped-out Apple Workgroup Server 9150 [OSnews]
Cameron Kaiser’s articles are always a right treat, and this one’s no different. It’s about running MkLinux on the Apple Workgroup Server, the regular Mac rebadged into a server product and predecessor to Apple’s first real server product, the Apple Network Server running AIX. The Workgroup Servers were originally marketed with Apple’s UNIX variant, A/UX, but with this operating system not surviving the transition to PowerPC processors, Apple started offering other options.
A/UX ultimately didn’t survive the 1994 68K transition to PowerPC, but in 1996 Apple publicly offered another option: run Linux, using the Mach microkernel. Although MkLinux emerged after the 9150’s discontinuation, it’s still just an overgrown NuBus Power Mac, so between more RAM, a beefier CPU upgrade and various video cards, by the end of this article we ought to have a configuration that gives us the best of two worlds — classic MacOS and MkLinux — in one server.
↫ Cameron Kaiser
I never really stopped to think that MkLinux really was, but it’s a lot more interesting than just an early Linux port to PowerPC Macs. In fact, it ran the monolithic Linux kernel as a userspace process on top of the Mach microkernel, which made it a valuable testing ground for Apple’s later XNU efforts. It’s wild that Apple had an official, blessed Linux operating system as early as the mid ’90s, even if its performance was apparently not particularly great – due to the overhead of running it atop Mach – and Jobs canned it as soon as he came back to the company.
“A big win for Android interoperability” [OSnews]
Whenever the EU steps in to regulate the big technology companies, the response from news outlets and bloggers (often funded or outright owned by right-wing extremists) is to claim it’s just a bunch of dumb , tech-illiterate bureaucrats telling the vastly more intelligent and superior technology companies what to do. Of course, this is just propaganda. Case in point:
Something big just happened. As the Open Home Foundation’s Android developer for Home Assistant, I was invited by the European Commission (EC) to consult on Android interoperability. The call for feedback was part of the Commission’s work under the Digital Markets Act (DMA). For anyone unfamiliar, the DMA is an EU law that defines and regulates “gatekeeper platforms” – those that offer “core” services like search engines, app stores, and messaging platforms – to make digital markets fairer and more open to competition. As you might imagine, I had plenty to say about Google’s restrictions on Android, especially the tech giant limiting wake word detection to its own Gemini assistant, a concern I surfaced in our Home Assistant 2026.3 Release Party. To put it plainly, Google had no grounds for limiting Android interoperability in the first place, other than to give itself the upper hand. We knew our community deserved better, and that’s what we told the Commission.
The result? The EC listened to us and all the other organizations that contributed. On July 16, 2026, the European Commission adopted a decision under the DMA that requires Alphabet (Google’s parent company) to open up eleven Android features, including always-on wake word detection, ambient sensor access, and screen automation – to all assistants, on equal terms.
↫ Timothy Nibeaudeau
What’s really interesting is just how deeply technical and detailed this new EU decision really is. Timothy Nibeaudeau laid out the technical details of how wake word detection on Android works for the European Commission – in short, a DSP runs a really tiny model in a process isolated from the network to detect just a specific wakeword, and only once that wakeword is detected does it hand things off to a larger model running on the actual main SoC – and the EC’s new decision accurately and precisely describes this method and wrote their decision to take every detail into account.
When I was invited to share these limitations (and others) with the Commission, I didn’t hold back. Which is why we were thrilled to discover an impressively precise and technically accurate decision from the EU: it correctly describes the two-stage wake word architecture, the DSP, the isolated process, and the role coupling. The report went down to details we only figured out by reading Android’s source code ourselves. […] ↫ Timothy Nibeaudeau
The idea that the European Union and Commission are a bunch of dumb, illiterate bureaucrats imposing impossible, unworkable, unrealistic demands on poor, hardworking, honest technology companies is a bunch of propaganda paid for by these very same companies, and every decision and ruling by the EU around the Digital Markets Act further confirms this by having strong technological underpinnings and being based on the actual workings of the technologies they cover. The EU does a lot of dumb things – as any government body does – but you don’t get to enjoy a nearly two-thirds approval rating for nothing, especially not in the face of the state of the world today.
The Digital Markets Act has already proven to be incredibly effective, and this is exactly why the right-wing propaganda against it is reaching an ever crazier fever pitch. When basic consumer protection legislation makes the most powerful companies, right-wing media empires, and even the most powerful country in the world throw tamper tantrums like toddlers, you know you’re doing something right.
Issue 47 – Greta’s Wedding Pt. 2 – 09 [Comics Archive - Spinnyverse]
The post Issue 47 – Greta’s Wedding Pt. 2 – 09 appeared first on Spinnyverse.
Lose Some Padding [The Daily WTF]
Flat-file style databases were designed to fit the constraints
of the systems they were running on. You specify your schema in
terms of "how many characters in a file we use to store this data",
meaning something like this:
JOHN SMITH 12343rd StAnytown
PA12345 is read in my knowing that the first name field is 8
characters wide, the last name field is 8 characters wide, the
street number is 4 digits, and so on.
It's also a terrible schema, and woe to anyone with a long name. But many a mainframe had a similar schema.
Now, let's think about maintenance here. What happens when we
also want to store a middle initial? We've created for ourselves a
problem. Somehow, I have to insert a character into every row,
which basically means making a new table with a new schema, copying
every record out of it and updating it to use the new schema. I
can't just ALTER TABLE like an RDBMS. And worse, every
piece of software that touches the table also needs to be
updated. On a large legacy system, a simple task like "add a field
to our database" could take weeks of developer time, and depending
on the software, be a high risk operation.
Which is why the smart developer, when working with flat files,
includes padding. Maybe my schema for an address record looks more
like this:
JOHN SMITH 12343rd StAnytown
PA12345 .
That's 16 characters of padding at the end of the file. Now
somebody says that I need to store a middle initial, I can just
shrink the padding by one and add a middle initial field, like so:
JOHN SMITH 12343rd StAnytown
PA12345Q
Is this elegant? No. But it works. I haven't changed the length of the row at all, so I don't need to move data around. Software modules only need to be updated if they care about what's in the middle initial field; if they're out of date, they just think there's a "Q" in the padding, and don't care.
In real-world applications, instead of putting all the padding at the end, you'd usually put the padding in a few spots in the middle of the table. Any time you need a new column, you just steal a few characters from padding. Sure, someday you'll run out of padding, or at least out of padding blocks big enough for your new field, and then you'll have to do the hard work of shuffling data around. But in practice, you can get very far without that happening.
Which brings us to Brenda's adventure. Her team supports an IBM mainframe storing data in VSAM flat files. In other words, they've been doing the sort of thing I just talked about for many, many years.
Of course, in the modern era, you can't just leave your data sitting in an mainframe. Even if the mainframe is the source of truth, you want to be able to report on it and connect it with your other data systems. You need to, somehow, get the data into a modern RDBMS.
So the company hired a bunch of developers to write an extract-transform-load process, which pulls the data out of the mainframe. The mainframe team handed them a "copybook" for the flat file, which described the structure, and the ETL devs went to work.
And maybe those ETL devs didn't understand the importance of
padding. Maybe they just missed the padding. Whatever it
was, there were several places where the data was structured like
SOME_USEFUL_FIELD PADDING PADDING PADDING
SOME_OTHER_FIELD, and they opted to split it like so:
SOME_USEFUL_FIELD PADDING PAD, DING PADDING
SOME_OTHER_FIELD.
When they released this process, it was fine. The padding characters got stripped before displaying, so the users never saw them. They were stored in the database, though, so when someone tried to reconstruct the data in a way that was compatible with the flat files, you could just concatenate the columns together and get a valid result.
It was fine- until it wasn't. The ETL devs, bless their hearts, only tested against the production mainframe. And why not, they were doing read only operations, what's the harm? Had they tested against the development mainframe, they would have seen new features in flight, features which consumed some of that padding, and realized that they should have paid closer attention to the copybook.
But instead, the test cases all passed. The software was, as far as the project managers and ETL developers could tell, working perfectly. So it was accepted, released to production, and running for a few weeks before the mainframe released its features. Those features then ruined all the beautiful reports with extraneous data.
And since the ETL devs were on contract, any request to have them rework it under the original contract was met with a stern "Works as designed". Instead of paying the contractors to come back and rework the system, the mainframe devs instead were tasked with finding different padding fields they could use, padding fields which wouldn't end up ruining any reports management liked to see.
We Keep Renaming AI Coding. Here’s What I’d Call It. [Radar]
Boris Cherny, who runs Claude Code, told Business Insider in May that the phrase “vibe coding” had started to annoy him, and that he’d gone looking for a better one. He’s not the only one who’s annoyed.
The term itself doesn’t actually annoy me, though. I think vibe coding is a really good name: It describes a specific way of using AI tools, and in development work, names that mean something specific are important. What annoys me is when people confuse vibe coding, intentionally or otherwise, with any kind of work where you write code with AI. That confusion points to a deeper problem: We’ve been using a lot of different names for a lot of different things, and we aren’t always precise about which is which. I think we need to fix that, and that’s what this article is about: making the case that the name we’re looking for is “AI-driven development” (or AIDD).
The case for this name comes from the familiar “X-driven development” pattern, because I think it really fits here. Software engineering already has a pattern for naming ways of working it takes seriously: test-driven development, behavior-driven development, domain-driven design. The name tells you what the work is organized around, and the suffix carries an expectation along with it: There’s a discipline attached, with standards, not just a style. Put “AI” in that slot and the name does the same job. AI-driven development says that building software has reorganized itself around AI, and it says it in the vocabulary we already use for the disciplines we hold ourselves to. It puts this way of working in the same family as test-driven and behavior-driven development, and that’s exactly the company it should be keeping.
Honestly, AI-driven development is a name that’s been sitting in plain sight, and I’ve been using it in my own writing for a while. It covers everything we do when we build software with AI, and I do mean everything. Vibe coding is just one part of how we work with AI to build software. There’s also figuring out what to build, writing it down, checking what comes back, and standing behind what ships, and AI is in the middle of all of that now. Whatever we call this way of working, it has to cover the development, not just the coding. Now, I’m obviously not a neutral party here, but I also don’t really have anything to gain; naming is really important, and I think we need a good name for what it is that we’re doing.
But I’ll admit up front that the name has a problem baked into it, and I want to deal with that head on. I recently ran into Addy Osmani at Foo Camp, and ran the AI-driven development name by him. He pointed out that building software with AI is really a range of practices that runs from vibe coding at one end to agentic engineering at the other. That rang true with me right away. It also highlighted the real problem I’m trying to solve, because it means I’m proposing one name for a whole range of very different ways of working. Can one name honestly cover ways of working that different? It took me a while to work that out, and I’ll come back to it at the end.
I feel like the name AI-driven development really makes sense once you can see what’s wrong with the names we’ve got, so I’ll start there.
Before I pick these names apart, it’s worth saying why any of this matters. Naming sits at the core of programming: A thing isn’t real until you can refer to it, and referring to things is most of what we do. There’s an old line, usually credited to the Netscape engineer Phil Karlton, that there are only two hard things in computer science: cache invalidation and naming things. It’s stuck around for decades because it’s true (well, maybe one or two other hard things have emerged since then, but it’s the thought that counts). We take naming a variable seriously, so we should take naming our whole discipline at least as seriously, because a poorly chosen name sticks.
So let me take the names we’ve been using one at a time: what each one actually names, what it gets right, and what it leaves out.
Vibe coding is an exploratory, prompt-first approach to software development where developers rapidly prompt, get code, and iterate. Andrej Karpathy, one of the founders of OpenAI, coined the term, which I think is really useful because it describes the way a lot of developers first work with AI and code.
Now, let me be clear about something: I’m in favor of vibe coding, and I teach it as a really effective—and, more importantly, creative!—way to generate a lot of code. But developers who rely entirely on vibe coding lose touch with their code because they let the AI make all of the decisions: not just specific technical decisions, but also about the architecture and the overall direction of the project. When that happens, they often end up building something that isn’t quite what they intended. When you have to create a product that needs to do a really specific thing (which describes most professional software development), relying exclusively on vibe coding can leave you with a product that doesn’t actually meet its requirements. That’s part of the reason I developed the Sens-AI Framework, which teaches developers when to shift their approach away from vibe coding, step back to do more research, and apply more critical thinking to what the AI is producing.
This is where the confusion I opened with does its damage (and I’m not sure whether it’s what bothered Cherny): When vibe coding gets used as the name for the whole job, developers will often assume that it’s absolutely fine to trust the AI to take over, and that whatever comes out of the AI is the end of the project. In other words, the name sets the bar: If the work is just vibes, then vibes are good enough, and “good enough” is how you end up with a pile of code nobody actually checked before shipping. So I consider vibe coding a useful technique, but it falls short as an entire way of working.
Vibe coding also has a built-in limit, and I learned it the way most lessons stick, by getting burned. AI is very good at writing code that looks right and isn’t. I once vibe-coded a little bus-tracker app for the B69 near me in Park Slope (I told that story in “AI Code Review Only Catches Half of Your Bugs”), and it worked on the first try, except the AI had picked the wrong stop ID and I sat there watching it predict a bus going the opposite direction. The code was correct. It did the wrong thing. Vibe coding got me a working app in minutes, and it had nothing to say about whether the app was right. That part was on me.
These two names belong in the same section because one basically grew out of the other. They describe the same job, getting the right work out of the model, at two very different scales.
Prompt engineering came first, and for a while it was a very big deal. It was seen as the core AI skill, and more than that, it even became its own job title: Companies posted prompt-engineer roles with eye-popping salaries, training courses appeared everywhere, and plenty of people reoriented their careers around it. The premise made sense because how you ask an AI for something changes what you get back. And specifically for people using AI to generate code, when you ask for code in a vague way, you don’t get vague code: you get code that does the wrong thing, because the AI fills in every blank you left, and it’s unlikely to fill them all in the way you meant. That isn’t hallucination. It’s the AI generating exactly what we asked it to. Give the model context about your project, constraints it has to respect, and a clear description of the behavior you need, and you get something you can actually use. Prompt engineering is the name for doing all of that deliberately.
But while prompt engineering is a real skill, people are no longer enamored with the name, precisely because of the mode of work that it implies: To most people, engineering a prompt means doing one request at a time. When the AI responds to the prompt, you evaluate the response and write the next one. That one-request-at-a-time style is exactly what’s changing about the whole way we interact with AI, and it’s probably why many AI engineers have grown to dislike the term. Peter Steinberger, the PSPDFKit founder who went on to build the open source agent OpenClaw, posted a line that traveled fast: You shouldn’t be prompting your coding agents anymore, you should be designing loops that prompt your agents. That was a shot straight at prompt engineering.
What’s pushing developers past one-request-at-a-time prompting is the sheer number of agents they can now run. About a month after complaining about the term “vibe coding,” Cherny told Fortune that he doesn’t write code by hand anymore, and that on a busy day he’s directing thousands of agents, or tens of thousands, at once. You can’t type prompts fast enough to direct ten thousand agents.
Loop engineering is the name Addy Osmani gave the new skill that Cherny and Steinberger were pointing at: He wrote up the pattern and gave it a real architecture. Instead of typing each instruction yourself, you build the system that produces the instructions: a loop that dispatches work to your agents, checks what comes back, and feeds them the next task over and over, without you in the middle of every exchange. The relationship between the two names is simple. Loop engineering is prompt engineering at scale; the prompts don’t go away, they just stop being typed by you. It’s tempting to oversell that because a well-built loop really does run with very little human intervention. But somebody still has to decide what “right” looks like, and the loop can’t do that part.
I think loop engineering is a good name and an accurate one. Designing the loop that drives the agent is a real skill, and we need a word for it. But it names the machinery, and machinery has a failure mode: Put an AI agent in a loop with nothing in it that can tell it no, and it generates, checks its own work, decides the work is good, and generates more. There’s no outside signal, so it ends up agreeing with itself on repeat. A well-designed loop makes agents productive. It can’t tell you whether all that machinery turns out working software or another confident pile of slop, and I want a name that covers that part too.
Cherny said that he asked Claude for a replacement for “vibe coding” and got “agentic engineering,” and while that didn’t settle the issue, it was an interesting response from Claude. The term didn’t come from Claude, though: Andrej Karpathy had coined it a few months earlier, almost exactly a year after he coined vibe coding, when he declared his own earlier term obsolete. That’s how fast these names are moving. The guy who named vibe coding has already replaced it.
Agentic engineering is an accurate name for what it describes: you’re not writing the code yourself, you’re directing the agents that do. It’s also a bit of a mouthful, and it isn’t immediately obvious to someone who doesn’t already know what it refers to. A number of people have told me they don’t particularly like it. I find it perfectly fine, and it does a solid job of describing that kind of work. You could even argue that loop engineering is a form of agentic engineering, and that prompt engineering is technically a simpler form of it. But vibe coding really isn’t, because it’s not engineering at all. That’s one more reason I think we need an umbrella name that’s friendly, descriptive, and easily recognizable.
The term also points at something real about where this work is heading: Agentic engineering is turning engineers into managers.
Many years ago I worked for a manager who didn’t care, at all, about the quality of the code we shipped. He wanted it out the door the moment it looked even remotely viable, and he was notorious for telling us to stop testing and ship. He used to ask why we had to wait two weeks for the testers to finish, and I’d tell him it takes time to test code. Then he’d ask whether we could just cut some of the tests, and I’d ask him, “Which part of the software are you okay shipping broken?”
That attitude came back to bite us more than once. One time we sent an entire feature out to the client basically untested, and a bug went straight to users. The same manager who kept telling us to skip the testing then called a long, miserable meeting to demand to know why a bug had gotten out. I’ll spare you the full drama, which mostly came down to a QA lead getting pressured to lie about what happened and pin it back on the development team. He didn’t care about quality, but he cared enormously about making sure the blame for a quality problem landed on someone who wasn’t him.
The reason I’m telling a story that happened years before AI could write a line of code is the blame. The important part of that story, and the reason it belongs in this article, is how accountability got managed: My manager’s whole system depended on having someone to pin a quality problem on. Directing agents puts you in that manager’s position, responsible for a team’s output, except the blame-shifting move is gone.
It’s really tempting to think of a fleet of AI agents as your team. You can even give one of them the QA lead role. But when a broken feature goes out, you can’t blame the QA agent, because “well, the AI screwed up” isn’t available to you: You’re responsible for the AI. You decided how much checking the work got before it went out, and the client with the broken feature isn’t going to accept “the AI wrote that part” as an answer, any more than pinning our untested feature on a QA lead fixed anything for our users. Cherny can manage tens of thousands of agents, but he can’t hand the responsibility for what they ship down to the agents, because an agent can’t hold it. Directing a swarm is a management job, and a manager owns the team’s output. The accountability doesn’t transfer, because at the end of the line there’s no one left to transfer it to.
Blame is worth dwelling on, because accountability is the part of this work that no name on the range captures. The loop-and-agent model works, but it only works with somebody making decisions about what right is. Agentic engineering describes the agents and the engineering just fine, but somebody still has to own what the agents ship, and that’s the part I want the umbrella name to carry.
There’s one more name I want to cover, and it’s the one with the oldest roots: spec-driven development. The name means pretty much what it says: You start by writing a spec, a description of what the software needs to do, along with things like acceptance criteria and tests, and the work isn’t done until the code actually does what the spec says. It comes from the same family as test-driven and behavior-driven development, where you write the tests first and the code has to make them pass.
Spec-driven development got a serious promotion when AI made generating code nearly free (although if you’re a CIO staring at your token bill, you might disagree, possibly with some extremely salty language). When code is cheap to generate, most of the cost of building software moves to checking whether what got generated is right. The AI fills the generate step, the verification decides what survives, and a human owns the verification.
It also picks up where prompt engineering leaves off. A while back I wrote that prompt engineering is really requirements engineering, because a good prompt is mostly a clear description of what the software has to do. Spec-driven development is where that idea was always headed: Write the requirement down before the AI generates, and the work has a standard to meet from the start.
So that’s the whole range, and every name on it is doing honest work. Whether AI-driven development is a good name for all of it comes down to whether it’s describing something real: an actual discipline, with actual practices, and a person who’s on the hook for the result. The rest of this article is about that discipline.
So how do these approaches actually play out when you’re building something real? For me, wherever the work lands on the range, it comes down to a few moves I keep coming back to.
Write the spec or the contract before the generation, not after. When the agent has something concrete to satisfy, acceptance criteria, a typed interface, a failing test, the work has a standard to meet. When it doesn’t, the AI decides for itself what done looks like.
Put a second opinion in the process. I run code review across multiple models, because they fail differently, and a finding one model is sure about is often one the others missed entirely. A reviewer gives the work something that can say no.
Give your defects a shared vocabulary. The Quality Playbook leans on the difference between code that’s wrong against the spec, code that’s correct but does the wrong thing, and behavior nobody specified at all. Those are different failures with different fixes, and you can’t verify against a standard you can’t name. This is old quality-engineering ground, and I’ve written enough about the software crisis and applying quality engineering to AI coding that I’m on board with taking old ideas and bringing them back. One of the best of those old ideas comes from Joseph Juran, one of the founders of quality engineering: Quality runs in a chain from what the user needs all the way to what the product does, and every link in that chain is a place verification has to happen.
And keep a human in the judgment seat. The Sens-AI habits I’ve written about are mostly about fault-finding: looking at what the AI produced and asking what’s wrong with it, going down a level and then another to find the root, instead of trusting it because it ran. That habit is the part of the discipline only a person can supply, and it’s the hardest part to automate, which is why it matters most.
Skip all of that and you get the thing that’s giving open source maintainers everywhere heartburn: what the Wall Street Journal now calls “vibe slop,” confident, finished-looking output with nothing underneath it. Slop is exactly what generation produces when nothing in the process can push back.
Now I can come back to the question I left hanging at the beginning: Can one name honestly cover ways of working that different? AI-driven development is an umbrella term, and any name that broad comes with a requirement it has to satisfy before people will accept it, because a name that blindly covers everything names nothing. A name that truly covers everything is another matter. I sat with that requirement for a while, because it’s real, and because the specific names don’t face it. Vibe coding names one way of working. Loop engineering names another. An umbrella over both of them, plus everything in between, had better be able to say what stays the same underneath it.
What stays the same is that somebody owns the result. When I vibe-coded my bus tracker, nobody was going to catch that wrong stop ID but me. When Cherny directs tens of thousands of agents, nobody owns what they ship but him. The verification changes with the stakes. A throwaway prototype gets my eyeballs and a shrug, and production code gets specs, reviews, defect taxonomies, the whole quality-engineering playbook I keep writing about. How much checking the work needs is a decision you make over and over, project by project, sometimes hour by hour. Who stands behind the work is not a decision you get to make. It’s there at every point on the range.
Look at how much of that range the names we already have cover, and what each one actually names:
Every one of those is real, and every one of them names a piece of the work. What none of them names is the whole thing the pieces add up to, and that’s the job AI-driven development does: It’s the umbrella over all five. The name doesn’t pick a spot on the range; it names the thing that’s true everywhere on it: the AI generates, and a human owns the result.
That’s also what makes the name likely to last (assuming, of course, that I’m able to convince people to start using it, which I hope I can, because I think it’s a good term). Vibe coding, loop engineering, and agentic engineering all describe how this works right now, and the machinery is changing monthly. Some of the pieces under the umbrella will get replaced, and the new pieces will get names of their own. The umbrella won’t have to change when they do, because the thing it names isn’t the machinery. The “-driven development” names have already shown they age well: test-driven development has meant the same thing for more than twenty years.
Agentic engineering is real, and so is loop engineering; if you’re directing agents, learn them both. Vibe coding is real too, and I’ll keep teaching it. AI-driven development is the name for the whole thing, and it earns its “-driven” the same way test-driven and behavior-driven development did: there’s a discipline attached, and somebody owns the result. AI made generating code almost free. It didn’t make being responsible for the code free, and being responsible for it is still the job.
The OpenAI Hack Shows the Genie Is Out of the Bottle [Schneier on Security]
This essay originally appeared in Foreign Policy.
Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks.
Since these were internal tests, OpenAI locked those models in a secure sandbox that denied them access to the internet. But it was running the models without any safety filters that would prevent them from offensive cyber-actions. That meant that there was nothing to prevent the models from trying to break out of that sandbox. And then break into AI company Hugging Face’s network because they thought that they could read the answers there rather than doing the hard work of trying to solve the puzzles.
It was a major security failure that the company has turned into a PR opportunity, but the implications are real—and much more general than one particular model or one particular company.
Modern AI models exhibit genie behavior: They can do what you ask in ways that you don’t expect or want. This is akin to Dionysus granting King Midas’s wish that everything he touches turn to gold (spoiler: His food, drink, and daughter all turn to gold on touch), or the golem of Prague guarding a ghetto beyond all reason. It’s Disney’s “Sorcerer’s Apprentice” and the paperclip maximizer.
This OpenAI incident is an example of an AI genie. The goal was to satisfy the benchmark. The “proper” way to do that is to figure out how to execute various cyberattacks. The genie way is to steal someone else’s solution. But because the model didn’t understand the difference, it chose the easier path.
And, of course, now that we have seen this particular genie behavior, we can specify in the benchmark prompt that stealing the test answers doesn’t count. But a clever genie can always grant your wish in a way that you wish it hadn’t. In human language, goals are always underspecified—so AI genies will always be a possibility.
Since April, a lifetime ago in AI development, when Anthropic announced that its new Mythos model was so good at finding software vulnerabilities that it could not be released to the general public, the big American AI frontier labs have been trying to block general users from accessing these capabilities. But nothing in this incident is exclusive to OpenAI’s, or Anthropic’s, frontier models.
Agentic AI systems have two important parts. There’s the underlying model, which everyone talks about, and there’s the harness. The harness sits between what you type and what the model sees, and what the model produces and what you see. The harness determines what the model does and how it does it. It’s where bias is removed, or not. It’s where controls and guardrails live. If multiple models are being used in concert, the harness is where all of that is coordinated.
The OpenAI benchmark tests were almost certainly with simple harnesses, to better test the raw models. But we know that smaller, cheaper, open-source models with more sophisticated harnesses can equal frontier models in performance. There’s nothing magic about OpenAI’s frontier models; lots of models could have done the same thing.
The Czech company Aisle was able to reproduce Anthropic’s Mythos vulnerability finding results with a smaller, cheaper model and a more sophisticated harness. More importantly, the Chinese company Moonshot AI just released its frontier model: Kimi K3. Its performance rivals its U.S. competitors. And it’s both free and open, which means it’s not possible for it to have guardrails. If you, or anyone else, wants to use it for cyberattack, nothing can stop you.
Even if the U.S. frontier AI companies had some technical advantage, it’s now only a few months’ worth.
What this means is that all attempts at control—limiting models to a select group of users, export controls on models and chips, blocking models from answering certain types of queries, mandating kill switches on AI systems, or pausing AI research—are all futile. Most only apply nationally, not globally. Most don’t affect models that users run locally and not in the cloud. And all ignore the incredible pace of AI development worldwide.
Even worse, U.S. companies limit access to their most sophisticated models, fearing being banned by the government if they do not do so. When Hugging Face was attacked, it was not able to use the frontier models from either OpenAI or Anthropic to help analyze the attack and formulate defenses. Both were blocked, because both of those companies limit their models’ cybersecurity capabilities. Some U.S. companies have special access to these capabilities, but Hugging Face is an American company with French origins, and as such is probably excluded. Instead, Hugging Face turned to the GLM-5.2 model from the Chinese company Z.ai.
Artificially blocking capability also prevents cybersecurity research, again giving the offense an advantage. (For instance, Claude Fable 5 refuses to edit this essay because of the topic; it forcibly downgrades to a less capable model.) This kind of prohibition has long-term implications for cybersecurity. If we assume that these models are getting better over time, then software written by older models will be attacked by newer ones. In a world of largely AI-written software, we need the most capable models for defense.
AI cyberattack is the new normal. The models are increasingly highly sophisticated at both attack and defense, and there is no way to enable the latter without also enabling the former. And they are genies, increasingly capable of behaving in unanticipated ways.
And there really are no good answers. Any regulation needs to be global, which feels like an impossible prospect in today’s world. Even U.S. national regulation will be neutered by the massive amounts of money sloshing around in these companies.
Given that reality, and in the absence of any international consensus on AI regulation, we need the best AI on the defense. The U.S. government needs to make it clear—or whatever passes for that clarity in this capricious administration—that it will not ban models with sophisticated cyber capabilities. The last thing Americans want is for the defenders to turn to Chinese and other models because the U.S. models are artificially hobbled.
Grrl Power #1483 – Rocky mountain high? [Grrl Power]
Okay, website seems to be humming along now, but I lost some time dealing with it, so the final versions of the vote incentive will probably go up next Monday.
One of the big problems with doing a huge arena battle in a comic like this is… well, there’s a lot less humorous antics going on, which is largely the meat and potatoes of the comic. The other problem is that if this were a Shonen manga, none of these competitors would really go down this easily. They’d each all be big fights that lasted dozens of pages, if not spanning multiple volumes, in which the protagonist has to learn some new ability or apply an existing one in a suspiciously flexible way. Or just flexed his power slightly harder. It would probably involve a flashback. For instance, Zerathax (the obsidian golem) would definitely be able to use his fire side to create thrust, Iron Man style, and fly around setting the battlefield on fire. Being broken in half really does very little to threaten his life, it robs him of his ice powers, but is mostly an inconvenience. And he can melt sand down to make new obsidian to reform his body, which may or may not be quite how it works, but is close enough for a 13 year-old Shonen manga main character to deliver an expository speech about while watching Zerathax convert sand and add it to his body, and most readers just go, “Eh, I don’t feel like searching for a refresher course on igneous rock right now. Besides, the person the MC is explaining this to is a stick-with-boobs who is inexplicably wearing a bikini top in this battle arena scene.” But I really don’t want to make each and every fight some hyper extended battle where the protagonist barely scrapes by but learns and grows along the way. Lore-wise, it’s because Max isn’t 14 and didn’t just get her powers. She’s a 20 year vet with them at this point, and all her fights have been against other supers. (And sometimes against foreign military hardware) It’s why she thought whatever she did to Eat-Chicken might have a chance of working the way it did. Non-lore-wise… uh, real world-wise, it’s because this UCBA storyline would take me 8 years to draw if every fight was done shonen jump style. Maybe if I could put out 5 pages a week, I’d extend the fight scenes a little, but instead I guess I’m going for something in between a typical Shonen and the one-punch fights of One Punch Man. It feels like half-measures either way, so I’m considering how to work the final round so that it doesn’t take 6 months to get through, but still have some cool moments.
Oh, look who it is in the vote incentive. And a
not-quite-yet-but-it’s-coming NSFW version over at Patreon.
Vote incentive and Patreon updated with some shading. Not finished yet, but progress.
I think she would get in trouble for doing this. She’d mess up the… floor of the waterfall? Is that what it’s called? The receiving pool? No, probably not that. Anyway, she’d churn things up and cause a ton of weird erosion.
Since you might be wondering, Niagara Falls is about 165 feet high, so Babezilla obviously doesn’t have to be full sized. I’d say she’s about 175-180 feet tall here?
Double res version will be posted over at Patreon. Feel free to contribute as much as you like.

hehehuehhueh
It doesn’t have to be well-crafted, historically important or aesthetically unique. It simply needs to be famous.
Celebrity art is famous, with a story and thus emotional resonance. It’s a souvenir for our eyes, a chance to have proximity without ownership. It conflates familiarity with scarcity, the power of in-person experience with the context of our culture. It’s simultaneously a statement of status and a signifier of connection.
It shows up in more places than we realize. Once an egg cream joint is Instagram famous, the line out the door is yet another example of how much we want to be near something that others have noticed.
Plenty of art is good enough to qualify for celebrity. But celebrity only happens after the network has kicked in. It’s more random than we’d like to admit.
What would it take to make your art, in whatever form, worthy of celebrity?
Pluralistic: Dualism (03 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

The greatest magic trick of them all is lying. The reason you can't figure out that coin vanish even after the conjurer performs it three times in a row is that they didn't do the same trick three times in a row! They did three different tricks: "Didn't catch it? Here, let me do it again!" is a lie:
https://magiciansmag.com/3-cool-coin-disappearing-trick/
There's times when it makes sense to treat two outcomes as the same, even if they were produced by very different means. As a reader, my enjoyment of your novel is the same whether it was dictated, typed on an Underwood Noiseless, keyed into a word processor, or scratched out with a fountain pen:
https://nealstephenson.substack.com/p/writing-by-hand-is-good-for-your
There's plenty of routes that arrive at the same place, and if the destination is all that matters to you, it's fine to ignore the journey. But often, those end-points have subtle differences that are only revealed when things go wrong. If all you care about is how things work, chances are good that you're in for an unpleasant surprise when things fail.
I recently found myself arguing with an interviewer about whether AI is, or could be, conscious. We weren't arguing about whether it might someday be possible to make an artificial consciousness – as a materialist, I'll happily stipulate to this. I think that everything we call "consciousness" is the result of a physical process occurring within our bodies (and possibly around them?), so I think it's perfectly reasonable to imagine that someday we might create another physical process that produces the same effect.
But that's not what the interviewer wanted to argue about. His point was that teaching more words to the word-guessing program would produce consciousness, an argument I always liken to "breeding horses to run faster and faster until one of them foals a locomotive." In support of this (outlandish) proposition, the interviewer performed a kind of cognitive coin-trick: "I can often predict what my wife is going to say, and so can a chatbot that's been trained on her words. Therefore, we're both doing the same conscious work – and therefore the chatbot will eventually be as conscious as I am."
"Predicting what you will say through an understanding based on a theory of your mind" and "predicting what you are going to say based on a statistical analysis of your utterances" might produce the same outputs, but they are not the same trick. You can tell by what happens when the trick fails.
My wife and I have been together for 23 years now, and there's plenty of times that we can finish each other's sentences – and so can the autocomplete on our phones. The autocomplete manages the trick by exploiting the fact that we often repeat ourselves. But we manage the trick by understanding each other (and by exploiting the fact of repetition).
When my wife says something surprising – because she is angry or delighted, sad or happy – I can make a reliable guess about what caused my prediction to misfire. Our "sentence completion" trick doesn't emerge from a rough, automatically generated mental table of the statistical likelihood that word A will follow word B. We also understand why those combinations appear in each other's speech and writing.
"Understanding" and "statistical extrapolation" can often lead to the same place, but when they don't, "understanding" provides a way forward, while "extrapolation" founders. Both work fine, but only one fails gracefully. The two tricks only appear the same, but they are fundamentally different.
AI's investor story – and the science fiction tales of AI's eventual capabilities that underpin that investor story – makes heavy use of this conjurer's trick, in which two different outcomes are equated to one another because they resemble each other.
This "ignore the journey, focus on the destination" idea is baked very deeply into the way we think about AI. Take the "Turing Test," a complicated and nuanced thought-experiment proposed in 1950. Over the ensuing 75 years, Turing's thought-experiment has been stripped down into a blunt metric: "Can a chatbot trick a human into thinking it is also human?"
https://en.wikipedia.org/wiki/Timeline_of_artificial_intelligence
"I mistook a chatbot for a human" and "I took a human for a human" arrive at near-identical places, but they are subtly and importantly different. The erroneous assumption that my phone's autocomplete is actually a person who understands me well enough to finish my sentences works fine, but the instant I turn to it for understanding, it will fail very badly. Autocomplete's predictions are always grounded in who you used to be, which means autocomplete knows very little about who you are now, and absolutely nothing about who you will become:
https://reallifemag.com/instant-recall/
The low-rez Turing Test that captured popular discourse is profoundly misleading. It's the unsound foundation of a worldview that renders you incapable of distinguishing your understanding of your spouse from their phone's autocomplete function. It's the self-serving rationale that leads you to declare yourself a proud stochastic parrot:
https://xcancel.com/sama/status/1599471830255177728
The AI bubble is (seemingly) full of contradictions, but – like those baffling coin-tricks – these contradictions often resolve themselves very neatly once you realize that the "contradiction" is actually just two things that appear to be one.
For example, some of the billionaires who put up the first several hundred million for AI are solipsists who just don't believe other people are entirely real and therefore find it easy to believe that AI can do their jobs. Other billionaires are cynics who think that bosses can be sold defective worker-replacing chatbots because they're credulous suckers for that pitch, the same way they believe that desperate young men are suckers for Joe Rogan's useless and/or dangerous supplements and peptides:
https://pluralistic.net/2026/07/24/supplemental-income/#andrew-tate-gwyneth-paltrow
Billionaire AI true believers and billionaire AI cynics make for a powerful coalition. The roadblocks that might discourage the first group are easily hurdled by the second, and vice-versa. You don't have to believe AI works to believe it can be sold, and you don't have to be motivated by the sales opportunity to believe that AI is about to become god.
Almost every debate I get into about AI turns out to be an unjustified, unacknowledged conflation of two things that seem similar, but have profoundly different underlying characteristics. Take this argument: "Every time we extend rights to the nonhuman world – watersheds, endangered animals, ecosystems – the world gets better. Let's extend rights to AI – whether or not we think it's a 'person' and so reap those benefits."
This, too, is a coin trick. Extending rights to nature reliably makes the world better, but extending rights to constructs makes the world far worse (Exhibit A is corporate personhood) (obviously).
A few moments' thought reveals the difference. If we extend rights to a watershed, that might result in an AI data-center being killed. If we extend rights to AI, that might lead to sacrificing the watershed to cool the data-center:
https://pluralistic.net/2026/07/10/posthuman-as-in-no-humans/#hell-is-other-people
Then there's AI and labor. The world is full of skilled workers who have found ways to use AI on the job that they insist have improved their work. It's also full of skilled workers who warn us that on-the-job AI is producing tech debt at unimaginable scale, seriously depreciating the quality of the tools we use today, and setting us up for painful reckonings in the future.
This (seeming) contradiction melts away once you realize that these workers only appear to be doing the same thing. The first group of workers, excited about their AI-assisted output, are "centaurs": people assisted by machines; workers who choose the time and manner of their AI adoption. The second group are "reverse centaurs": people recruited to serve as peripherals for machines, who direct their actions and workflow:
https://pluralistic.net/2025/12/05/pop-that-bubble/#u-washington
Note that this isn't the same thing as saying "A skilled worker who adopts a tool willingly is always right and will produce a better output as a result." Nor is it saying, "The tool is so flawed that workers who claim it works for them must be deluded."
That's another coin trick! The reality – again – is that this is two things: some workers whose AI-assisted work is measurably worse are wrong about AI making their work better (centaurs, but wrong), and; some workers are being forced to use AI and know damned well that it's making their work worse (reverse centaurs).
Finally, there's an economic coin-trick: "AI will destroy jobs." Sure, yes, AI is destroying jobs. But there's a vast difference between "You got fired because an AI can do your job" and "You got fired because your boss was convinced that the AI can do your job, even though it cannot."
This is one of the most consequential coin-tricks, because it's a real convincer for the investors who are funding the AI bubble. The difference is huge: "AI can do your job" means you're well and truly screwed. If an AI can really replace a contract lawyer, then everyone who needs a contract written or evaluated should be on the side of mass technological unemployment for contract lawyers. The point of contract lawyers is to produce contracts, not to pay contract lawyers' law-school debts and mortgages.
BUT! If some BigLaw's credulous partners can be suckered into firing their juniors and replacing them with chatbots who bill you $1,200/hour to produce unenforceable, error-riddled contracts, then everyone who needs a contract is on the same side as the contract lawyers – united in opposition to their bosses:
https://www.loweringthebar.net/2026/06/its-finally-happened-both-sides-ai.html
Every time we fail to draw this distinction, we help an AI boss raise another billion dollars. Every time we insist on this distinction, we hasten the day that the AI bubble pops, thus sparing a few more everyday savers and innocent bystanders from being wiped out in the crash we can all see on the horizon:
https://www.thebignewsletter.com/p/monopoly-round-up-how-new-dealers.
As "Cathy" so aptly put it: "The thing that is a good tool for the skilled people is being sold as a thing to reduce the number of skilled people hired":
https://bsky.app/profile/cathyby.bsky.social/post/3ms3pzq57nc2c
The former is a normal technology. The latter is the root of a catastrophic folly that is destroying our environment, destroying workers' lives, destroying the quality of the goods and services we rely on, and which will shortly destroy our economy.
It's a distinction with a difference.

New Mexico’s clean energy success story https://yaleclimateconnections.org/2026/07/new-mexicos-clean-energy-success-story/
AI Data Center Turbines, Backlogged For Years, Are Suffering Early Deaths. Here's Why. https://www.investors.com/news/turbine-generator-ai-data-center-power-threat/
Choice of Weapons https://kschroeder.substack.com/p/choice-of-weapons
Brainwash An Executive Today! https://ludic.mataroa.blog/blog/brainwash-an-executive-today/
#25yrsago Collectible AOL CDs https://web.archive.org/web/20011119212602/https://www.wired.com/news/culture/0,1284,45585,00.html
#20yrsago Gonzales: Gitmo prisoners can be held indefinitely https://www.dawn.com/news/204441/guantanamo-detainees-may-remain-indefinitely-us-attorney-general-s-warning
#20yrsago Circuit City offers DVD ripping service https://web.archive.org/web/20060811215644/https://consumerist.com/consumer/circuit-city/circuit-city-flouts-the-dmca-for-a-tenner-192049.php
#15yrsago UK government kills Copyright Great Firewall, establishes user rights https://torrentfreak.com/uk-government-abandons-file-sharing-website-blocking-plans-110803/
#15yrsago Mugshot sites and mugshot removal sites: unholy blackmail symbiosis https://web.archive.org/web/20110817051528/https://www.wired.com/threatlevel/2011/08/mugshots/
#15yrsago Law prof: it would be legal to mint 2x $1 trillion platinum coins & use them to pay the US debt https://edition.cnn.com/2011/OPINION/07/28/balkin.obama.options/index.html?hpt=hp_c1
#15yrsago Virtual pets starve after bungled resolution to Second Life’s “unauthorized food” war https://web.archive.org/web/20110807214820/http://nwn.blogs.com/nwn/2011/08/sl-meeroos-griefed.html
#15yrsago Google Plus’s “Real Name” policy is abusive; Facebook is not a “Real Name” success story https://www.zephoria.org/thoughts/archives/2011/08/04/real-names.html
#15yrsago Photo: Escher painting refracted in a drop of falling water https://www.reddit.com/r/pics/comments/j5whr/water_drop_falling_in_front_of_an_mc_escher/
#15yrsago Getting digital copyright right: pay artists, but don’t break the Internet https://www.straight.com/article-415146/vancouver/interview-siggraph-2011-keynote-speaker-cory-doctorow-copyright-reform
#10yrsago After repeated budget cuts, Missouri’s underfunded Public Defender drafts the Governor to work for him https://web.archive.org/web/20160804061408/http://www.publicdefender.mo.gov/Newsfeed/Delegation_of_Representation.PDF
#10yrsago Spoofing GPS is surprisingly easy; detecting it is surprisingly hard https://spectrum.ieee.org/gps-spoofing
#10yrsago Decision to retain personally identifying information puts Australian census under threat https://web.archive.org/web/20160804124914/https://censusfail.com/
#10yrsago Residents of Silicon Valley homeless camp clear 48,000 Lbs of garbage from creek, ask for housing https://www.mercurynews.com/2016/08/03/san-jose-homeless-remove-24-tons-of-trash-from-coyote-creek/
#10yrsago Copyright Office to FCC: Hollywood should be able to killswitch your TV https://www.eff.org/deeplinks/2016/08/copyright-office-jumps-set-top-box-debate-says-hollywood-should-control-your-tv
#10yrsago Walking Tables: a strandbeest for your dining room https://www.youtube.com/watch?v=mBOdZ6nhDJg
#10yrsago Lawsuit: Getty Images copyfrauded 47,000 photos from indie press agency Zuma https://arstechnica.com/tech-policy/2016/08/getty-images-sued-again-over-alleged-misuse-of-over-47000-photos/
#10yrsago Mexico-US illegal migration has been at zero for 8 years, and other eye-opening facts https://wnyc.org/story/bnch-migration-doug-massey/
#10yrsago Activists are crowdfunding to build a wall around Trump Tower https://www.indiegogo.com/en/projects/wallintrump/wall-in-trump#/
#10yrsago Chinese government decrees that it is always legal to video-record the police https://www.techdirt.com/2016/08/03/yes-you-read-that-correctly-china-says-ok-members-public-to-record-police/
#10yrsago Big rigs can be hijacked and driven with software-based attacks https://www.wired.com/2016/08/researchers-hack-big-rig-truck-hijack-accelerator-brakes/
#5yrsago Elite debt hits record heights https://pluralistic.net/2021/08/03/fitzgerald-was-an-optimist/#debt
#5yrsago Utilities governed like empires https://pluralistic.net/2021/08/04/eighty-sixed/#thank-you-come-again
#5yrsago Congress has allocated enough money to end the eviction crisis https://pluralistic.net/2021/08/04/eighty-sixed/#helicopter-not-found
#5yrsago Vaccine refusal and health insurance https://pluralistic.net/2021/08/04/eighty-sixed/#risk-management
#1yrago AI software assistants make the hardest kinds of bugs to spot https://pluralistic.net/2025/08/04/bad-vibe-coding/#maximally-codelike-bugs

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
AI and the Enshittification Era (The Weekly Show with Jon
Stewart)
https://www.youtube.com/watch?v=-dAIJRjb-Bw
AI is not inevitable (Betakit)
https://www.youtube.com/watch?v=DbiTVkq1WHo
A Conversation with Lina Khan (Law and Economy Student
Network)
https://www.youtube.com/live/7Ak5LZllqwE
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing: "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
Hostile Radishes [Penny Arcade]
New Comic: Hostile Radishes
Girl Genius for Monday, August 03, 2026 [Girl Genius]
The Girl Genius comic for Monday, August 03, 2026 has been posted.
Breaking Up, p09 [Ctrl+Alt+Del Comic]
The post Breaking Up, p09 appeared first on Ctrl+Alt+Del Comic.
Joe Marshall: Lisp-p [Planet Lisp]
I needed a function that could tell whether a string was a valid Common Lisp program. In theory, you could just call read on the string and see if it throws an error, but I don't want to throw random text at read. It could contain a reader macro or something nasty. It also would intern a ton of random symbols into the current package. I wanted a function that would act mostly like the reader, but not CONS any data or intern any symbols.
So I vibe coded a function that does just that. It implements the reader algorithm as a state machine but does not actually read any data. The state machine tracks the list and string delimeters and tokenizes the string, but it discards the tokens and does not intern any symbols. It just checks that the state machine is in `top level' state at the end of the string. If it returns NIL, the string is definitely going to cause an error if you try to read it. If it returns T, it does not guarantee that the string represents a valid Common Lisp program, but rather that it is not obvious that the reader will throw an immediate error.
A curious edge case is that of an unpunctuated string. The words in the string will read as a simple sequence of symbols, which is perfectly valid.
The code is in lisp-p on GitHub.
You call the function lisp-p with a string or a stream
and it will return T or NIL.
Kernel prepatch 7.2-rc6 [LWN.net]
The 7.2-rc6
kernel prepatch is out for testing. Quoth Linus: "Hmm. This rc
is huge. Even by the "new normal" standards this is a big rc, and I
think it's the biggest rc6 we've had in years at least by commit
count.
" There were 537 non-merge commits applied between
7.2-rc5 and 7.2-rc6.
Taylor Swift Sues Ella Langley [Richard Stallman's Political Notes]
(satire) *Taylor Swift Sues Ella Langley For Bangs Infringement.*
The serious point of this news parody is that the system of copyright, transformed by massive duplication technology into a system of oppressive extraction, inspires attempts to put legal monopolies on every aspect of human behavior.
Trump's grudge against Comey [Richard Stallman's Political Notes]
The persecutor has a grudge against James Comey, so his ultraloyal servants go to great lengths of distortion to imagine in Comey's actions some sort of violent threats.
Send paramedics not police [Richard Stallman's Political Notes]
*[New South Wales] to send paramedics not police to some mental health emergencies after multiple deaths.*
The people who advocated this in the US called it "defund the police". I was in favor of the change, but criticized that slogan for being offputting.
The hidden upward redistribution [Richard Stallman's Political Notes]
Robert Reich: How big US businesses profiteer from the wrecker's war with Iran and his arbitrary tariffs. They are bad for Americans in general, but great for billionaires.
Americans die younger [Richard Stallman's Political Notes]
Americans die younger on the average than Europeans -- looking at the causes of this.
Europe's fires causes [Richard Stallman's Political Notes]
The main cause of Europe's record-breaking fires is global heating, due mainly to burning too much fossil fuel.
Scientists have identified a secondary cause: people's abandoning many of the old farms, which have since been overgrown by wild vegetation.
If [the saboteur in chief]'s war on the climate is not met with strong resistance, things will only get worse.
The EU could, if it insists, impose fuel use taxes on both ships and planes traveling between the EU and elsewhere. For ships, the goal would be to increase their efficiency. For planes, partly to discourage their use.
PISSI [Richard Stallman's Political Notes]
Some sort of residue of PISSI is inspiring terrorist plots in various countries.
Industrial chicken farming consequences [Richard Stallman's Political Notes]
*Industrial chicken farming accelerating spread of diarrhoea bacteria, study finds.*
Cars as surveillance systems [Richard Stallman's Political Notes]
Congress is considering whether to change or cancel a requirement that all new cars surveil their drivers so as to block the car from starting if a Supposed Intelligence system judges the driver to be drunk.
The existing law does not require protecting the data thoroughly against other uses, so this system will surely act as surveillance.
Even worse, these systems can misjudge a driver who is terrified (and trying to flee a real danger) as drunk. False positives can happen randomly, too.
India's Cockroach protesters jailed [Richard Stallman's Political Notes]
*India's youth-led Cockroach movement demands [jailed] protesters be released.*
Safety traded for warmer relations [Richard Stallman's Political Notes]
*Activists under threat from Beijing are facing strange difficulties with UK immigration. Our safety must not be traded for warmer relations with China.*
Iranian prisoners hunger strike [Richard Stallman's Political Notes]
Prisoners in Iran have launched a mass hunger strike against the large number of executions, and also about denial of medical care to prisoners.
Wildfires harm [Richard Stallman's Political Notes]
The medical harm done by wildfires can last for years, perhaps for a whole (shortened) lifetime.
Anthony Fauci [Richard Stallman's Political Notes]
Republicans have compelled Anthony Fauci to testify in Congress to respond to fabricated accusations.
Republicans had, and have, ulterior political motives to condemn US government officials in charge of public health measures. One motive is to cast Democrats' appointees as criminals. Another is to cancel those measures, which often involve regulations that limit the profits of big businesses.
Climate crimes prosecution [Richard Stallman's Political Notes]
*It's time to prosecute climate crimes – with laws that already exist.*
Noise pollution [Richard Stallman's Political Notes]
More road noise correlates with more Parkinson's disease. This does not prove that the higher level of road noise contributes to causing Parkinson's disease.
ICE healthcare violations [Richard Stallman's Political Notes]
*Court-appointed investigator finds [biggest deportation prison in California] failed to comply with judge's order to provide adequate [medical care] [to the prisoners]*.
This prison is privatized. A private prison company can increase its profits by skimping on medical care; thus, using privatized prisons tends to increase the illnesses and deaths among prisoners. This is one of the reasons why privatized prisons should be prohibited.
Ebay executives harassed people [Richard Stallman's Political Notes]
Some top executives of Ebay harassed people who published criticism of Ebay. The company had to pay 55 million dollars for this misconduct.
AI errors in military [Richard Stallman's Political Notes]
Kevin T Baker explains how the pressure to automate and accelerate US military target selection (ultimately using a Possible Intelligence system called "Maven") has made it easier to make mistakes, and harder to notice and prevent a possible mistake.
The bombing of the Iranian girls' school was decided by that process.
Food companies easier to collapse [Richard Stallman's Political Notes]
George Monbiot warns that the mergers of so many food companies have produced a business system that is susceptible to economic collapse. The collapse could be triggered by large shocks of various kinds, perhaps political or environmental, but the collapse would make the consequences far worse.
Nutrition food declining [Richard Stallman's Political Notes]
Something is causing many agricultural plants to produce fewer nutrients (except perhaps for sugar and starch).
Ukraine warehouse strikes [Richard Stallman's Political Notes]
Ukraine is bombing warehouses of the online store Wildberries, which contain mostly civilian merchandise, but also some military gear and drone parts. Destroying them ruins the small businesses that are selling throught that company.
Wildberries' involvement in military logistics justifies attacking it, but it would be better to direct Russians' ire at Putin, not at Ukraine.
I suggest that Ukraine declare a moratorium on attacking Wildberries warehouses, with a deadline for sellers of non-military products to retrieve their property from them, after which Ukraine would resume bombing them.
Fema disaster aid [Richard Stallman's Political Notes]
*Two dozen states sue [the monster] for politicizing Fema disaster aid.*
Forced labor in the US [Richard Stallman's Political Notes]
If the persecutor really cared about forced labor, he would look at the US – rather than slap more tariffs on the world.
Rivers in France drying up [Richard Stallman's Political Notes]
Some rivers in France are drying up. Newly hatched salmon and trout need to get to the ocean, but there isn't enough water for them to make it. So humans are helping them.
India's Cockroach protest [Richard Stallman's Political Notes]
India's Cockroach protest movement has won a concession from Modi.
The next question is whether it can organize to maintain its strength.Global maritime war [Richard Stallman's Political Notes]
Around the world, disputes about control over various areas of seas are drifting away from following long-established rules, and towards war.
Fires in Europe [Richard Stallman's Political Notes]
Large fires in France and Spain are approaching major cities.
If we don't get serious about curbing global heating, it will reach a point where major cities are lost. Keeping up with global heating is a losing game -- the only way to triumph over it is to stop feeding it.
US surveillance pricing bans [Richard Stallman's Political Notes]
Three US states have banned surveillance pricing. The latest is New Jersey.
Since I buy anonymously and pay cash, I can't be touched by surveillance pricing -- with one exception: airline tickets, which can't be anonymous. I wonder, will New Jersey's law apply to flights from Newark Airport?
Parthenon marbles [Richard Stallman's Political Notes]
Arguing against returning to Greece the marble statues that were saved from the damaging environment of the Parthenon.
US chaos [Richard Stallman's Political Notes]
* New tariffs, gas price rises, the deaths of thousands, insecurity … We’re living at the whim of one capricious, vain, easily bored man and his gang of stooges.*
I like to refer to him as "the corrupter" and "the persecutor", but what this article shows best is his other face, "the bullshitter".
Scheme to fuel corruption [Richard Stallman's Political Notes]
Robert Reich: The corrupter's new scheme to fuel corruption in the stock market would bring in millions or billions to him and his family by giving preferential information to those who pay him.
Urgent: pass paid leave [Richard Stallman's Political Notes]
US citizens: call on your congresscritter and senators to pass paid leave for working people.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: thank the media [Richard Stallman's Political Notes]
US citizens: Thank some of the major media for refusing to broadcast the blusterer's lies and threats.
Please spread the word.
Urgent: stop attack to press [Richard Stallman's Political Notes]
US citizens: call on news media to cover the monster's subpoenas against reporters and their families as an attack on the first amendment, part of a campaign of attacks against journalism.
Please spread the word.
Urgent: protect free elections [Richard Stallman's Political Notes]
US citizens: call on your senators to protect free elections by voting NO on the perversely named "SAVE America" Act.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: stop dissent criminalization [Richard Stallman's Political Notes]
US citizens: call on Congress to investigate the persecutor's Justice Department for criminalizing dissent.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: funds to limit Cyclospora [Richard Stallman's Political Notes]
US citizens: call on Congress to restore funds for limiting spread of Cyclospora.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: reject PBG nominees [Richard Stallman's Political Notes]
US citizens: call on the Senate to Reject the corrupter's Postal Board of Governors nominees. Stop USPS Privatization. Election Interference Schemes. Price Hikes and Service Slowdowns.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: stop "prediction markets" legalization [Richard Stallman's Political Notes]
US citizens: call on regulators not to legalize "prediction markets".
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: protect ocean ecosystems [Richard Stallman's Political Notes]
US citizens: call on Congress to protect deep ocean ecosystems from mining.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: ban large data centers [Richard Stallman's Political Notes]
US citizens: call on your state governor to ban large supposed-intelligence data centers, and fund public schools.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Russ Allbery: Term::ANSIColor v6.0.0 TRIAL release [Planet Debian]
Yesterday, I uploaded Term::ANSIColor v6.0.0-TRIAL to CPAN for early testing. This release will raise the minimum required Perl version to 5.12, dropping support for Perl 5.8 and 5.10. When I did the same with podlators a couple of years ago, it upset a few people and one of them asked me to make this sort of test release in the future. Hopefully this will help.
I have not run the normal release machinery and haven't archived this release in the normal places, since I intend it to be transient. It's only on CPAN, where people can retrieve it for testing. Once v6.0.0 is released, few traces of this TRIAL release will be left. This doesn't appear to be how other people use the TRIAL mechanism, but it felt more comfortable to me. If I have to make substantial changes, I'll consider changing my approach.
I plan on turning this into the v6.0.0 release in about a month or two, hopefully with only documentation changes.
Term::ANSIColor is a "very upstream" core module with a lot of dependencies, and CPAN (unlike some of the archives that followed it, such as PyPI) doesn't support conditionally retrieving packages based on the current Perl version. This release may therefore be disruptive for people who are still trying to support Perl 5.8 and 5.10, since CPAN installation tools may attempt to install an incompatible Term::ANSIColor version. I'm sad that this will be the result, since I know some people still care about those versions.
I'm pressing forward with updating my Perl modules anyway, though. I realized that honoring other people's desire for stability to such a degree that I was unable to use Perl features added more than 15 years ago was destroying my motivation to work on these Perl modules at all. So I've decided on a very slow and gradual approach where I'm going to keep pushing the minimum supported version forward but try to give people a lot of warning.
Personally, I think it's time to let ancient versions of Perl go and follow the Lyon Amendment about supported Perl versions. When we're talking installing new modules for software released more than 15 years ago, we're talking about special limited environments and retrocomputing more than what I would consider routine software maintenance. Those tasks should expect to need different tools and a different workflow so that they can pin historical versions. Since this isn't something I'm personally interested in, my willingness to expend time and energy to assist is limited.
As you can probably tell, I still feel nervous about pressing forward in this way, but I think this is the approach that lets me continue to enjoy maintaining these Perl modules. It's been 29 years for Term::ANSIColor, but I still enjoy fixing bugs in it and putting out a new release from time to time, particularly if I can clean up the code a bit each time I touch it.
Fascinating thread on Hacker News about RSS.
Ben Hutchings: FOSS activity in July 2026 [Planet Debian]

A story from the deep dark history of my blog. I got an email from Steve Wozniak inviting me to lunch at one of our favorite retaurants, By The Bucket, in Santa Clara. He told me that the board had decided to fire the Apple CEO, he gave me the date and time. I wasn't surprised, it was kind of expected. I wasn't a reporter, so I gave the story to a friend at the San Jose Mercury-News, and she did the reporting, and then on the morning of the big event, I wrote a blog post saying it was time to fire him. A couple of hours later, as if responding to my post, they did. That might have been Peak Dave in Silicon Valley.
Taking some time off to breathe and regain perspective.
Fixed a few bugs, and wrote about the big picture on demo.rss.chat. I really want to
get a project going to peer with standard.site apps running in AT
Proto, both ways, from us to them, and from them to us, via RSS. We
can peer with them because as far as I can tell they implement
textcasting. This bridge
would demonstrate something important. When something interesting
shows up not based entirely on web standards, we're flexible if the
attraction is strong enough. This is how the internet
came to be. Our systems are prepared to create bridges. And unlike
bridging between systems that have different ideas of what text is,
which are basically hopeless, if we agree that the
web standard for text is fine for writers and reader, better
than the ridiculous limits imposed by twitter-like systems. Writing
on the web has been crippled since Twitter, now let's start
building it back up. That's the appeal of standard.site, they are
working toward the same goal. We should work together.
5:23 am June 15 2026 NW Champaign, IL
That’s when the sun rises in Urbana, IL at the height of summer. All June and July I got up by 4:15am, so I could be on my bike by 4:40 and ride off into the sunrise.
My Ti-Rush near Ogden, IL at 5:44am July 12 2026. On
Sundays at dawn I will ride route 150, a highway too busy and
dangerous to take any other time.
Sunrise makes anywhere beautiful. Time-shifting my day was like traveling to some desirable vacation destination, without leaving home. While my sister hiked across the Italian Alps, I gasped aloud with wonder at the beauty of every golden morning in my own county. Every day I saw deer and bunnies, the fall and rise of rivers, the phases of the moon.
The full moon sets behind Homer IL, July 31 2026
Well, half the phases of the moon. Just before dawn the moon is only visible between full and almost-new. The full moon sets as the sun rises, on the opposite side of the sky. Each subsequent day as it wanes, it appears a little closer to the sun. By the time it’s a slivery crescent it’s barely ahead of the sunrise, which quickly renders it invisible. Once it’s new and waxing, it chases the sunrise, when the morning sky is too bright to distinguish it. The following weeks it’s on the other side of the earth at pre-dawn, when I leave the house. Not until it’s full or almost-full do I see it again.
Setting dawn moon south of Urbana IL, July 30 2026
Pre-dawn midsummers are cool, or at least tolerable in severe heat waves, which we had this year. The only thing that kept me from biking was rain, and sometimes not even that. I trespassed a few times when I got caught in storms, taking shelter under whatever farm building overhang I could find.
Trespassing near Fithian, IL. May 20, 2026
Once I trespassed Rosie’s Tavern on Grape Creek near Belgium, not due to rain but sun: I needed to apply sunscreen for a century (100+ mile) ride that would expose me to the brutal rays I avoid on shorter adventures. Caught on the outdoor security cameras, I was soon visited by a man in a truck with a dog asking what I was doing there. I got in no further trouble but cursed my stupid iPhone, which had updated its OS and re-set Strava without my permission, turning on “cellular data” which drained my battery so fast I had to re-charge it after only 38 miles. That’s what I was doing at Rosie’s too, taking advantage of an outdoor electrical outlet.
BUSTED! Rosie’s Tavern security image, May 25
2026 8:29 am.
I had to keep stopping and charging on that ride, lest my phone die and fail to record my hard-earned 109 miles. I had lunch at a sweet little diner, the Covered Bridge in Eugene Indiana, so I could plug it in for 45 minutes. That wasn’t enough for the full ride, so on my way home I returned to Rosie’s, the scene of my crime, where a woman standing outside said, “are you Nina?”
The Covered Bridge diner in Eugene, IN is next to a
covered bridge. May 25 2026
How did she know? She had sent the security camera image to her sister, who just happens to be an acquaintance and recognized me and my bike. What are the odds? We chatted about mutual friends, she invited me into the tavern (which is like 100 years old, a pre-Prohibition relic) and gave me delicious coke with ice on the house. We exchanged phone numbers and selfies.
My Calfee Stiletto leaning against Rosie’s Tavern
near Belgium IL, May 25 2026
That ride ended with me overheating, followed by my first bout of “exercise-induced gastrointestinal syndrome.” My Crohn’s disease-weakened digestive system just shut down, causing several days of serious suffering and a vow to never eat diner food on a long ride again. I also vowed to take shorter, more moderate rides instead of two centuries back-to-back, which is what preceded the episode.
Sunrise over a flooded field near Seymour, IL. 5:43am
June 25 2026
Thus began my glorious 2 months of pre-dawn excursions, during which I didn’t have to wear any nasty sunscreen. Occasionally I would do a metric century (100 kilometers, about 62 miles), but was careful not to over-exert myself nor overheat. I did gradually increase my efforts until the last week of July, when I rode 351 miles, including my first century since late May.
Easy Racers Fold Rush on the gravely part of the
Lincoln Trail near Homer, IL. 6:00am July 22 2026
Then I projectile vomited and embarked on my second episode of exercise-induced gastrointestinal syndrome, from which I still haven’t recovered. Or maybe it’s something else. Maybe it’s CANCER! I get to worry about that since I have Crohn’s disease. My blood test a few days ago showed no biomarkers for Crohn’s inflammation, so whatever this is isn’t technically a “flare,” despite the same symptoms.
“Digestive Failure,” a self-portrait of
July 29 2026
I would be attempting a moderate sunrise ride this very morning were it not raining. Instead, I’m finally writing about my rides, something I think about on my rides but don’t actually do because riding fills me with satisfying endorphins that remove any further need to express myself. I have written and directed masterpieces on my rides that will never come to fruition, nor even planting. I’m full of great ideas that all work themselves out through the pedaling and breathing and smelling the morning air and watching the sky change colors and seeing deer skip across the roads in front of me. At least in the middle of summer. Which has passed. Winter is my time to create, but only because it’s too cold to ride.
4:54am July 7 2026. Urbana, IL.
See you then.
The post 5:23am appeared first on Nina Paley.
“Working in the studio is like building a ship in a bottle. Playing live is like being on a rowboat in the ocean.” Jerry Garcia
You probably need some studio time, but you definitely need to play live.
Russell Coker: Packet Edit Meme and Debian SE Linux [Planet Debian]
There’s yet another Linux kernel exploit based on container functions, here’s the result when run as user_t on a SE Linux system:
$ ./packet_edit_meme [*] target /bin/su as uid 1000; entry at file offset 0x4340; shellcode 48 bytes unshare: Permission denied [-] page-cache corruption failed
Here is the audit log entry for this failure:
type=AVC msg=audit(1785640621.498:1843): avc: denied { create } for pid=1770 comm="packet_edit_mem" scontext=user_u:user_r:user_t:s0 tcontext=user_u:user_r:user_t:s0 tclass=user_namespace permissive=0
Here’s the result of running it from the unconfined_t domain:
$ ./packet_edit_meme [*] target /bin/su as uid 1001; entry at file offset 0x4340; shellcode 48 bytes [+] su entry overwritten; exec'ing su -> interactive root shell # id uid=0(root) gid=0(root) groups=0(root),1001(test2) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 #
Daniel Baumann wrote a blog post describing how this is fixed for Debian systems without SE Linux.
A user contacted us about a potential security issue in the RSS.chat server. We responded quickly and with v0.6.11 the issue is removed. If you're running rssnetwork.js on a publicly visible server, please install the new version now. Thanks!
NetBSD, the operating system specifically designed to run on anything from a supercomputer to a toothpick, just released version 11.0. There’s a ton of changes and improvements here, such as a brand new port to RISC-V, which supports a number of the more popular RISC-V SoCs (sadly, not the one I have just yet). NetBSD 11.0 also adds initial support for the Qualcomm Snapdragon X Elite platform, as well as a port to the virt68k platform, which means the Motorola 68000 port in QEMU using paravirtualized devices.
Speaking of virtualisation, they’re also introducing a new MICROVM kernel for x86:
New MICROVM kernel for x86, supporting both i386 and amd64, NetBSD 11.0 introduces a dedicated MICROVM kernel designed for extremely fast virtual machine boot, leveraging PVH boot, VirtIO MMIO, and multiple kernel optimizations, it can boot in about 10 ms on 2020-era x86 CPUs.
↫ NetBSD 11.0 release notes
There’s also improved support for Linux system calls in compat_linux, the npf firewall, and much more. Of course, the list of other improvements, buigfixes, and smaller changes is long, including many changes for old, outdated, or otherwise odd architectures and platforms, as is the NetBSD way. Which other operating system proudly lists substantial improvements to their PA-RISC, Motorola 68000, and Alpha ports, among others?
CallMeMaybe: runtime reflection library built on C++26 static reflection [OSnews]
I have a policy to effectively never link to YouTube videos. I’ll gladly make an exception for this one.
Reflection is one of the most powerful concepts in Computer Science. Unfortunately, not every programming language is blessed enough to have it.
In the 1980s, one company, Symbolics took the concept to the logical extreme. By representing EVERYTHING as objects; they created the most powerful (and inadvertently) least private operating system ever created!
The company collapsed, but the ideas live on. Some modern languages got a full dose of reflection. Some…weren’t so lucky. I ranked them all, and in the end I’ll show you how I dragged C++ up a tier with my brand new runtime reflection library, CallMeMaybe!
↫ Laurie Wired
The GitHub description of CallMeMaybe:
CallMeMaybe (CMM) is a C++ runtime reflection library built on top of P2996 static reflection introduced in C++26. CMM purposefully mirrors many of the std::meta functions to provide a uniform interface, but allows runtime introspection, dynamic invocation, and instantiation by building a runtime reflection registry. Class members can be automatically traversed and reflected by simply adding
↫ CallMeMaybe GitHub page[[=cmm::reflectable]]as an annotation. CMM implements a custom type system to completely avoid RTTI requirements.
My YouTube linking policy will remain in place.
One of the things you learn working with a bot is how much saying the niceties are good for you, even when the "person" would still do what you ask if you weren't so nice.
Of course I love RSS. ;-)
Ultimately AI will flatten out the differences in languages.
The month of July is history. A fine month. A coral reef was seeded.
On the non-use of AI in my writing process [Charlie's Diary]
This isn't a blog entry I wanted to write, but it's a necessary one: a statement about the use of generative large language models (colloquially "AI") in my work.
I do not use LLMs in my work. I don't use them in my non-work life either, for that matter. I despise the grifters selling these toys as "tools" and trying to convince us to use them to generate plausible answer-shaped text strings in place of actual internet search for verifiable sources.
I've been selling fiction that I wrote myself since 1985 or thereabouts, and novels since 2002. If you want to verify that I have written novels without using an AI, simply pick up a physical copy of "Singularity Sky", "Iron Sunrise", "The Atrocity Archives", or anything else I published before 2015, the year OpenAI was founded.
Hint: you will find seven Hugo-shortlisted novels from that period, and three Hugo-winning novellas, also two Locus-award winning novels and a couple more novellas and stories. Clearly I don't need AI to write award-winning stories.
I do not want or need a large language model to write my fiction for me. I write fiction compulsively—before I was published I wrote for many years as a hobbyist—so why on earth would I pay someone else to take my fun away?
You will note em-dashes in the preceding paragraph. I gather some "AI detector" services (themselves a generative AI product) flag em-dashes as signs of "AI generated" text. Listen, fuckers, LLMs sprinkle em-dashes in their output because LLMs exist to stochastically emit strings of text that approximate the form of their inputs, and they've been trained by stealing all the text on the internet that isn't nailed down, including pirate websites that distribute cracked e-books. So it's wholly unsurprising that LLM output exhibits quirks that mimic real writers.
Did I mention the "stealing" thing? This isn't hyperbole: I'm one of the parties to the settlement in the class action lawsuit against Anthropic AI for pirating ebooks to train their LLMs. That's not my only grievance, either. You may have noticed this blog performing sluggishly or crapping out from time to time over the past few months. That's because my server is old and feeble and periodically gets swarmed by Chinese and other foreign botnets scraping data for training LLMs.
I'm usually willing to cut actual human beings, as opposed to for-profit corporations, some slack where it comes to cracking DRM, or even downloading warez: but these people are absolute scum. They're stealing copyrighted material to train an LLM that is intended to compete for revenue with the authors of the works they stole, and they're fine-tuning their LLMs to make them as addictive as possible in order to maximize future revenue once they pivot to token sales as their main source of income. In other words, they're no different from a burglar who robs you one day then comes round to sell you your stuff back the next morning. Back in the 18th century we used to hang people like that and Sam Altman makes me question the wisdom of having stopped.
I maintain that any serious author should shun LLMs like the plague. The most popular LLMs in the west—such as Claude, Gemini, CoPilot, and ChatGPT—the ones hoovering text indiscriminately off the internet for training—also gobble up any queries you send to them and use them as future training data. If I was crazy enough to feed the outline of a story I was working on as a prompt to ChatGPT or Claude in hope of getting the stochastic parrot to do my homework for me, then it would be only my own fault and nobody else's if the next model from the company in question was trained on my book outline and could reproduce part or all of it for someone else.
Finally, contra public opinion, I see no reason to credit LLMs with sentience. They're word-association mechanisms with no embodiment and no way to associate the text vectors they manipulate with real-world phenomena. But we humans have evolved through selection pressure in an adversarial environment to associate environmental phenomena around us with intentional causes—if you see lion scat and the gazelle are no longer visiting the watering hole, then you should assume there are lions about. And this trait carries over to linguistic manipulation. If we hear or read text, we expect there to be a mind on the other side of it, as Joseph Weizenbaum (the inventor of the original ELIZA chatbot) realized at MIT in the late 1960s. Just because it does something people do, it does not follow that it is a person.
Now for some caveats.
My skepticism does not carry over to all aspects of the field. It would be foolish to deny the effectiveness of image recognizers based on generalized adversarial networks (GANs), the key neural network technology underlying LLMs. It'd be similarly stupid to deny that LLMs are very good at supporting large-scale statistical analysis of text, such as Linear-A. And I can see some circumstances where being able to train a local model on my work could be useful to me.
I'd quite like a tool (running entirely locally on my own hardware, with no cloud service and no copyright-thieving grifters making bank on it via subscription fees) that digests a manuscript and derives a scene-by-scene timeline, that I could then query interactively and use to plan my next round of edits. Being able to map out where and when each protagonist and minor character shows up, and see a frequency distribution heat map of names in the manuscript, would be useful.
But such a tool would be useful to me in the same way a spelling checker is useful—as a decision-support tool, not as a substitute for doing the hard work (and having a copy of the Oxford English Dictionary on the shelf). The value of such a tool is considerably less than the value of a well-trained brain that can do the entire job the hard way, if necessary. And it's less than zero if using it opens me to finger-pointing accusations of "but he's using AI!" by people who can't read to the end of one paragraph, much less fourteen of them (yes, this is para fourteen, I've been counting).
So my fiction is still, as of August 2026, 100% LLM-free, and if that changes I will update this declaration accordingly.
Finally, I'd like to leave you with a snippet from the opening of the far future space opera I'm editing right now. It's part of the fiction and unfortunately may have to be omitted because of the risk of confusing the people who can't read to the end of the paragraph, but it's the only valid use of LLMs I've found so far for my fiction because it's a solution to the calling a rabbit a smeerp problem in SF and fantasy:
Translator's Note
The events described in this account have been translated into your language from the original source material using a non-sapient large language model.
Certain terms have been approximated, where possible, by using culturally appropriate cognates. Names of individuals have been replaced by equivalents. Similarly, institutions, ranks, religions, proverbs, idioms, quotations, and other culturally-determined signifiers have been translated into terms that will be familiar to the reader.
Units of duration and distance have also been converted.
We apologize in advance for any hallucinations our LLM may have inadvertently introduced in the process of generating this rough translation.
Pluralistic: Why businesses lie about AI (01 Aug 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

Neoclassical economics assumes rationality. The corollary of, "If you're so smart, why aren't you rich?" is "you're rich, so you must be very smart!" Thus it is that many people assume that if powerful, well-compensated CEOs insist that "AI is changing everything," well then, AI must be changing everything.
But the evidence for this "changing everything" thesis is thin on the ground. Despite a global mania that has reduced the real, pressing need for digital sovereignty to the imaginary need to create "sovereign AI," no one can really articulate the case for "sovereign AI." If Donald Trump ordered Big Tech to turn off all of your country's chatbots tomorrow, nothing would change. Every one of your country's ministries and corporations would chug on with nary a hitch. Households, too, though perhaps a few of the younger members of those families would have to do their own homework again.
(Contrast this with what would transpire if Trump directed his tech giants to switch off your country's Office 365 access, or to brick your Android and iOS phones, or to killswitch your John Deere tractors. Your country would effectively cease to exist. If "digital sovereignty" means anything, it means doing something about this urgent fact):
https://pluralistic.net/2026/06/18/their-trillions-our-billions/#eyes-on-the-prize
The world is full of people who insist that "AI is changing everything" but who – when pressed – have to admit that what they mean is that they're pretty sure that AI will change everything. Eventually. After we allow it to consume all the planet's energy, carbon, water and financial resources.
Maybe.
(They're pretty sure.)
One person who's had a lot of opportunity to observe the shear between the stated business/AI situation and the real business AI situation is Nikhil Suresh from Hermit Tech, a consulting firm of "radically ethical data wizards" (that is, tech consultants). Suresh reports on his experience talking with hundreds of executives (and, more importantly, their subordinates) about what (if anything) AI is doing for business in an essay entitled "AI Mania Is Eviscerating Global Decisionmaking":
https://hermit-tech.com/blog/ai-mania-is-eviscerating-global-decisionmaking
Suresh has a good track record of writing trenchant, frank criticism of AI. You may know him from his 2024 essay, "I Will Fucking Piledrive You If You Mention AI Again":
https://ludic.mataroa.blog/blog/i-will-fucking-piledrive-you-if-you-mention-ai-again/
Or possibly from his "Contra Ptacek's Terrible Article On AI," a stinging rebuttal to Thomas Ptacek's widely read "My AI Skeptic Friends Are All Nuts":
https://ludic.mataroa.blog/blog/contra-ptaceks-terrible-article-on-ai/
While those are important pieces of critical AI realpolitik, none of them have the heft or urgency of "AI Mania Is Eviscerating Global Decisionmaking," whose thesis can be summed up with this passage from halfway through this 6,000-word article:
[W]e’re facing a coordination problem around executives being honest around the AI gains they’ve witnessed – if they co-operate, they keep their jobs. If they defect, they will possibly be fired by their embarrassed peers (who have now been implicitly called liars, cowards, or incompetents) and then replaced with someone that will toe the line anyway. If they could all admit the truth at once there might be some hope, but there is no way to coordinate that event.
In other words, corporate leadership is starting from the premise that AI has (or will) radically change the business, and they're working backwards from that premise to find the evidence to support this article of faith.
In support of this thesis, Suresh cites "hundreds" of conversations with execs and employees who spoke to him on the condition that he would "file the serial numbers" off their stories. These, combined with his own experience consulting for large, multi-billion-dollar companies make it clear that "AI mania" is an absolutely justifiable label for the state of AI in corporate circles.
Here are a few highlights from this morning's read – moments where I had to look away from my screen and read out a passage to my wife so that we could share a "holy shit" moment.
A person worked for a division that "pivoted" to re-engineer its software to create interfaces that support AI agents. When it became apparent that only ten users had touched this expensive new technology, they "pivoted" again to support "agentic workflows." Why did they double down on AI agents after discovering such yawning market indifference for "agentic"? "Because every company has to do something agentic now."
Suresh describes this as a literal religious mania. In the 500+ employee businesses Suresh studied, the only people who were promoted – or even spared from being fired – were people who professed "religious declarations of faith" about "the transformative power of AI." Employees who voiced honest, informed objections to AI in the workplace were passed over for promotions or targeted for layoffs.
This has created a situation in which everyone – "boards, executives, employees, vendors, consultants" – has a strong incentive to lie about how much AI is delivering for their companies. Suresh says he's seen announcements from publicly traded companies about their AI triumphs that he knows for a fact never took place.
Suresh says he's never seen a successful enterprise AI project: "Every single one – we have seen 0% success in a year and a half." Not one of their clients would face a business challenge if OpenAI went out of business tomorrow. The problem most companies struggle with is that they're "terminally bad at running software projects effectively." Adding AI to the mix doesn't solve this problem – it just adds a whole new range of ways that software deployment can fail.
Chatbots don't help. The internally facing chatbot that's supposed to help employees figure out how to navigate the business sucks because it is only as good as its training data – the business's documentation of its own processes. Businesses suck at documenting their processes. Customer-facing chatbots also suck. They either can't solve your problem, or, when they seem to solve your problem, the "solution" goes nowhere.
Suresh recounts his sole positive customer service chatbot experience: a Mitsubishi chatbot with a natural sounding, responsive voice politely took all the details of an automotive failure and promised him a callback. That callback never came, but Suresh is certain that Mitsubishi has logged this as a chatbot success story, even though the experience convinced him not to buy a Mitsubishi car.
Suresh and his team at Hermit Tech now have a policy of not even asking about ongoing AI projects. They've learned that by the time an AI project has begun, no one will discuss it honestly until it reaches a crisis point.
Suresh says he frequently encounters people who reflexively utter the AI catechism: "AI is changing everything." But when he presses these people for details, they admit that their organization "does not currently use LLMs for anything, and indeed, that they cannot name a single thing that has changed other than they get some use out of ChatGPT."
This shear ("AI is changing everything"/"Well, OK, we're not using AI for anything") is so extreme that Suresh once met an exec who confessed to crafting an AI-centered AI strategy for a $2b/year business, even though that exec "had never even used ChatGPT or any AI tool in their life."
Some people have privately admitted to Suresh that they've embraced AI in order to earn a career-boosting corporate reputation for "thought leadership." But many other people (especially nontechnical people) sincerely believe that AI is about to "change everything." As Suresh says, if you're in business with a liar, you might be able to reason with them in private – but you can't reason with a true believer.
The true believers are in charge. Suresh points out that it would be very weird for the CEO of an engineering firm or a hospital to mandate "specific procedures or building techniques without explicit agreement from the professionals on staff." But when it comes to AI, business leaders will confidently demand that the skilled professionals who perform the business's core functions use AI, even if those professionals don't think it will help.
As an aside: I remember the dotcom era, when the business press was full of articles about the conflict between CEOs and a new workforce that demanded the right to use the web on the job. Today, the business press is full of articles about the conflict between the workforce and CEOs who demand that they use AI.
Suresh describes workers who feel they have to "AI wash" their work: "They just do the work, the same way they have for decades, and say Claude did it." To add verisimilitude to this sham, they write circular processes in which one chatbot prompts another, and then the process repeats itself in reverse, for the sole purpose of consuming AI tokens to score a high rank on corporate "token leaderboards."
How to account for this wildly, expensively irrational corporate leadership? Suresh places the blame in the hypnotizing, mesmerizing power of the AI demo. For example: Hermit Tech is often engaged to set up a database product called Snowflake for its customers. Snowflake has a useless, expensive AI bolt-on called Cortex, that Snowflake itself describes as being 92% accurate under ideal circumstances (that is, at least 8% of the time, it will mislead you, perhaps very badly).
Suresh describes sales meetings with execs who were lukewarm on the idea of retooling with Snowflake, but who were very interested in Cortex. Against their better judgment, Suresh and his team provided them with a Cortex demo, carefully explaining that this AI tool could not satisfy their requirements. Without fail, this resulted in the previously lukewarm customers insisting that they be allowed to purchase Cortex immediately. Sales prospects who'd been unmoved by a pitch for new technology that would result in millions in savings were hypnotized by demos of a product that was described as unsuitable and unreliable.
To their credit, Hermit Tech refused to sell these customers Cortex, and stopped doing Cortex demos altogether. Suresh describes the experience of "the total 180°, that shift from ice-cold to red-hot buying frenzy" as "deeply unsettling." What's more, the Cortex demos that Suresh and co performed were, by his account, pretty uninspiring. The thing that these demos had going for them is that they showed AI actually doing something marginally useful, to execs who'd already spent millions on AI without having anything to show for their money. The spectacle of AI that does something galvanizes corporate leaders who feel like they're the only bosses who can't find a revolutionary use for AI in their businesses.
This is the situation up and down the corporate org-chart. Suresh has a reader whose title is "Head of AI" at a billion-dollar firm who tells him "their job is totally fraudulent but it was the only promotion pathway remaining at the organisation." This exec is hardly alone. They're part of a cohort of executives at companies that have publicly announced "100x" productivity gains, but who confessed to Suresh that nothing of the sort has happened.
Why did these companies make these claims? Because their customers were making the claims. How could you hope to sell to a company that had 100x'ed its productivity with AI unless you, too had 100x'ed your productivity? If, as a vendor, you walked into a boardroom and said that this wasn't a plausible claim, you'd be calling your sales prospect a liar, with real consequences: "getting enterprise contracts cancelled because you wanted to opine on something that doesn’t really matter to your organisation’s mission is a great way to get fired."
With the state of the industry dominated by froth, lies and mutual destruction pacts, it's no wonder that companies are deploying "totally gameable metrics such as 'money spent on AI'" as a means of evaluating employees and divisions.
Between true believers and people who must find ways to plausibly tout their AI usage, there is now a gigantic market for "AI solutions." At best these are just traditional tech consulting contracts, like migrating a database from Oracle to Snowflake, with some kind of ornamental AI usage around the edges so that the person who commissions the work can claim to be "procuring AI-enabled services" for the business.
This isn't a harmless frippery: contracts are delayed and work is put off until the work can be made "sufficiently AI" to attain the minimum degree of buzzword compliance. Worse: every fake AI project that produces real results (because it's not really AI) adds credibility to the AI true believers, who view these projects as proof that AI can do anything, and therefore demand to know why everything isn't being done by AI.
Suresh ends his essay with a long section on how to "navigate AI mania" – advice for how to smile and nod politely when you're confronted with AI bullshit, while steering clear of the worst consequences and avoiding needless fights. This looks like very sound advice for anyone in a corporate environment, but thankfully, that isn't me.
Rather than summarize that advice, I want to reflect a little on two questions that Suresh's essay raises but doesn't answer. The first is why? Why are people in power such easy converts to this religious mania?
I have my own theory. The most important discomfort that powerful people experience is having ego-shattering conflicts with subordinates who know how to do things they do not know how to do. The fact that you're "in charge" is hard to reconcile with the fact that the people you're nominally in charge of tell you that all your ideas are impossible, illegal, immoral, or lethal:
https://pluralistic.net/2026/01/05/fisher-price-steering-wheel/#billionaire-solipsism
Take that Cortex demo. Sure, Cortex is an expensive, unreliable way to address a Snowflake database. But (unlike Snowflake) Cortex is controlled via conversational, plain-language commands. With Cortex, a boss doesn't need to ask an underling to retrieve information from the company Snowflake system, an interaction that might come with unsolicited feedback about the technical or commercial incoherence of the boss's request. Cortex is the underling, except that unlike a human underling, Cortex never back-sasses you about your foolish questions. The fact that it grossly misleads you 8% of the time is a small price to pay for a life untroubled by uppity pismires who insist that your ideas be connected to base reality as they understand it.
The other question Suresh implicitly raises is, "How can you reconcile the failure of AI in the enterprise with the individual claims of skilled technologists who insist that AI is helping them do great work?" The answer is that these AI users are "centaurs" – experienced workers who are assisted by automation on terms that they set for themselves:
https://pluralistic.net/2025/09/11/vulgar-thatcherism/#there-is-an-alternative
Thanks to their skill and experience, these workers possess discernment, the ability to tell good code from bad, and (more importantly) good uses of code-generation tools from bad. They demonstrate the adage that worker-driven automation improves quality, while capital-driven automation improves throughput:
https://pluralistic.net/2026/07/28/hitl-ers/#ai-ai-oh
An automation technique that requires close supervision by skilled and experienced workers isn't going to be a raw productivity powerhouse. You don't "100x" your code this way, at least, not in the sense of firing 99 of your coders and having the remaining programmer pick up all their work. Rather, an automation tool that requires the continuous and conscientious exercise of discernment will let individual practitioners improve their work in extremely satisfying and useful ways. It's a way to spend more on operations in order to produce better outputs. It's not a way to cut your workforce, realize a gigantic savings, and still produce comparable goods and services at a far lower cost.
That is why some individual coders report such delight with their AI tools. They engage with those tools on their own terms, to improve their work in the ways that they, in their expert judgment, consider beneficial. No one ranks them on a "token-maximization" scoreboard. No one tells them they can't do a project if it isn't "sufficiently AI." When they set out to do a project, no one makes them prove that it couldn't be "done by AI."
As ever, the most important fact about a given technology isn't "what it does," but "who it does it for" and "who it does it to."
All the pathologies Suresh observes and documents so well in this piece are hypertrophied versions of the buzzword-compliance dysfunctions from previous bubbles, but at a scale never before seen. Quantity has a quality all its own. These businesses aren't just wasting billions – they're replacing skilled workers with defective chatbots. As I've written before, AI is the asbestos we're shoveling into the walls of our technological society. Our descendants will spend generations digging it out again, and the longer the bubble goes on without popping, the longer it will take to repair the damage.

Families in London temporary housing told they cannot use in-built air conditioning https://www.theguardian.com/society/2026/jul/27/homeless-families-london-temporary-housing-air-conditioning
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key https://www.wired.com/story/defcon-34-badge-baochip-andrew-bunnie-huang/
US government map of Africa mislabels every country at global conference https://www.theguardian.com/us-news/2026/jul/30/government-map-mislabels-african-countries?CMP=Share_AndroidApp_Other
EFF Guide to Recording Law Enforcement https://www.eff.org/deeplinks/2026/07/eff-guide-recording-law-enforcement
#25yrsago Vernor Vinge in the NYT https://www.nytimes.com/2001/08/02/technology/a-scientist-s-art-computer-fiction.html
#25yrsago Why publishers should thank Syklarov https://web.archive.org/web/20011023092940/http://www.zdnet.com/zdnn/stories/comment/0,5859,2800985,00.html
#25yrsago David Byrne track to be bundled with WinXP https://web.archive.org/web/20010804040357/http://www.ananova.com/news/story/sm_365899.html?menu=news.technology
#20yrsago Five things about blogs that no one ever needs to say again https://web.archive.org/web/20060813090449/http://www.stevenberlinjohnson.com/2006/08/five_things_all.html
#15yrsago Castles made from human hair https://inhabitat.com/artist-uses-human-hair-to-construct-a-castle-of-3000-bricks/
#15yrsago Wisconsin Democratic voters targeted with Koch-funded absentee ballot notices advising them to vote 2 days after the recall election https://www.politico.com/blogs/david-catanese/2011/08/afp-wisconsin-ballots-have-late-return-date-037977?showall
#15yrsago Gingrich’s million Twitter followers: “80% dummy accounts, 10% paid followers” https://web.archive.org/web/20110812100159/https://gawker.com/5826645/most-of-newt-gingrichs-twitter-followers-are-fake
#15yrsago Missouri State business-school professor leads successful campaign to ban Slaughterhouse-Five from local schools https://www.theguardian.com/books/2011/jul/29/slaughterhouse-five-banned-us-school
#10yrsago Australian media accessibility group raises red flag about DRM in web standards https://hotelsantalya.net/accessiq/news/news/2016-p/08-p/concerns-raised-for-assistive-technology-development-as-w3c-debates-encrypted/
#10yrsago Reminder: the GOP has been attacking veterans and their families for years https://web.archive.org/web/20160803203106/https://crookedtimber.org/2016/08/02/trumps-indecent-proposal/
#10yrsago Isis joins Donald Trump in denouncing Khizr Khan https://web.archive.org/web/20160802161454/https://theintercept.com/2016/08/02/donald-trump-and-islamic-state-agree-no-room-for-people-like-khizr-khan/
#10yrsago Furries don’t have sex in fursuits https://www.ohjoysextoy.com/fursuits-grey-white/
#5yrsago Machine learning sucks at covid https://pluralistic.net/2021/08/02/autoquack/#gigo
#1yrago AI's pogo-stick grift https://pluralistic.net/2025/08/02/inventing-the-pedestrian/#three-apis-in-a-trenchcoat

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
Why AI Won't Replace Workers, But Will Crash The Economy (Smart
Cookies)
https://www.youtube.com/watch?v=rRRmUuxJolY
AI and the Enshittification Era (The Weekly Show with Jon
Stewart)
https://www.youtube.com/watch?v=-dAIJRjb-Bw
AI is not inevitable (Betakit)
https://www.youtube.com/watch?v=DbiTVkq1WHo
A Conversation with Lina Khan (Law and Economy Student
Network)
https://www.youtube.com/live/7Ak5LZllqwE
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing: "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
What if they meant it?
What if your return felt special to the people behind the counter?
What if they knew, without looking it up, or being told–what if they knew that you were here, again, a vote of trust and confidence.
Returning home is one of the oldest human desires. It’s a feeling that doesn’t easily lend itself to automation, procedures, or scale.
Being welcomed home offers us dignity, safety and belonging. Hard to fake, worth working hard to create.
Making an agile version of a Windows Runtime delegate in C++/WinRT, part 10 [The Old New Thing]
In
part 5 of this unnecessarily long series on agile delegates,
commenter LB asked, “Is the
ContextCallback in the deleter guaranteed to
always succeed? According to the docs it can fail. I wonder if
there’s a way to move the fallible part to an earlier point
so the deleter can be infallible.”
Let’s look at the first part: What if
IContextCallback::ContextCallback
fails?
If it fails, it means that COM couldn’t switch to the destination context.
If you can’t switch to the destination context, then you can’t release the pointer. It’s not clear what recovery is possible anyway. Do you just keep retrying until it finally works?
If the destination context is an ASTA, then it’s possible that the reason is that the context is already busy, and ASTA doesn’t allow re-entrancy. We’d have to wait a little bit and try again later, when the destination context might be ready. We can’t just block on the retry because the destination context might be calling into the thread we are on right now, so just spinning in a retry loop won’t help because it’s waiting for us! We’re have to return, allow whatever we’re doing to finish, which in turn allows the ASTA to resume, and then it becomes worthwhile to try to call into the ASTA again.
This would be the issue for conventional COM calls into the
ASTA, but we are using IContextCallback, and that lets
us control whether or not to honor ASTA reentrancy roadblocks.
If riid is set to IID_ICallbackWithNoReentrancyToApplicationSTA, the function does not reenter an ASTA arbitrarily.
We are not passing that special value, so our call to
ContextCallback is allowed to reenter an ASTA.
That removes one possible source of failure.
What other reasons could there be for not being able to switch to the destination apartment?
The most likely reason is that the destination apartment no longer exists, in which case there is no recovery. Depending on how the object was managed by its creating thread, it might have been forcibly destroyed at thread termination¹, or it may simply have been leaked. We don’t know. At any rate, there’s no way to release it now.
The other case is that the destination apartment is not reachable due to a low-memory condition. We discussed earlier how the most common reason is a destination thread that has stopped responding to messages. I guess you could wait and try again later, but in practice if a thread has stopped responding for so long that its inbound message queue is full, the odds that it will magically start responding soon are pretty low.
All of the failures are effectively unrecoverable. But some of
them are non-fatal, such as the
CoDisconnectObject discussed in the
footnote. Unfortunately, we can’t tell what case we are in.
The ContextCallback returns
RPC_E_DISCONNECTED to say that the destination
apartment no longer exists, but we don’t know how that
apartment cleaned up its orphaned objects.
The C++/CX implementation of lazy-created agile delegates ignores errors that occur trying to release the original pointer. So we’ll do the same.
But wait, we can do better. Next time.
¹ This is often combined with a
CoDisconnectObject to tell proxies to fail
all calls with RPC_E_DISCONNECTED, so that there are
no external references to destroyed objects.
The post Making an agile version of a Windows Runtime delegate in C++/WinRT, part 10 appeared first on The Old New Thing.
Russ Allbery: Review: How to Steal a Galaxy [Planet Debian]
Review: How to Steal a Galaxy, by Beth Revis
| Series: | Chaotic Orbits #2 |
| Publisher: | DAW Books |
| Copyright: | December 2024 |
| ISBN: | 0-7564-1949-2 |
| Format: | Kindle |
| Pages: | 143 |
How to Steal a Galaxy is a far-future science fiction caper short novel (maybe a novella?) and the sequel to Full Speed to a Crash Landing. You don't have to remember the details of the previous book to enjoy this one. There's an excellent inline summary at the start of this installment.
After an annoying negotiation with people who keep trying to preach at her about causes, Ada Lamarr has a new contract. She is going undercover, after a fashion, at a charity gala and auction on Rigel-Earth. While she's there, she's going to steal something. What, precisely, she keeps a mystery from both the other characters and from the reader until the end of the story.
Government agent Rian White is working security at this charity gala. Due to its link with the plot of Full Speed to a Crash Landing, he was fairly certain Ada would be there, as indeed she is. What she is planning, however, is maddeningly unclear. Also maddening is how good Ada looks in a dress.
As with the previous book, How to Steal a Galaxy is told by Ada in the first person using the same teasing tone and constant misdirection that she uses when verbally fencing with Rian and the other characters. I found this novella even more entertaining and satisfying than the previous one. The charity gala is supposedly intended to benefit the poor people of Earth, and is run with exactly the sort of condescension and disguised capitalist looting typical of such exercises in elite charity. Ada's narration is scathing in a deeply relatable way.
Also, there is a trillionaire tech-bro fake philanthropist who is smug and condescending and accustomed to getting exactly what he wants.
"I don't think anyone should have enough personal wealth to decimate a large country's income just because he's going through a midlife crisis."
Ada's interactions with Strom Fetor are an absolute delight. He is so sure of himself that he is incapable of registering her as a threat, and she effortlessly deceives him by hiding in plain sight.
"You really shouldn't be talking about this," Rian starts.
Fetor waves aside his concerns. "We're all friends here."
"Not me," I say. "I hate you. Remember?"
Fetor laughs in a tone I'm sure he thinks is charming.
Fetor's complete inability to realize that a beautiful woman might both sincerely not like him and not be flirting with him is perfect. I was cackling through half of this book.
Like any good heist story, there are twists and turns, surprises, double agents, unexpected complications, and a delightful amount of verbal fencing. I adore the narrative tone Revis uses for these stories. Ada has just the right mix of idealism, cynicism, professionalism, and irreverence to carry off the feeling that she's a step ahead of everyone else. Underneath the bones of a delightful plot is a character who cares deeply but is very aware of her limitations, and therefore has taught herself to laugh at and be ruthless with her own emotions. I am finding it an incredibly compelling type of competence porn.
I enjoyed the first book of this series, but this one was so much better. These stories are exactly the right length to keep the reader engrossed throughout and satisfied but wanting more at the end. How to Steal a Galaxy ends on a cliffhanger of sorts, to be resolved in the next and final book. I can hardly wait to start it.
Highly recommended.
Followed by Last Chance to Save the World.
Rating: 9 out of 10
New Cover Song: “Ode to Somewhere” [Whatever]

This cover song has an interesting story to it, which is that it’s a song from a video game called “Deathloop.” In the video game, the singer is supposed to have been a huge star but has lately gone kind of venal around the edges, and also there’s a whole time loop thing going on which necessitates the player character needing to kill the singer (and several other people) for, you know, reasons. It all makes sense in the context of the game, and the game itself is a hell of a lot of fun. I absolutely recommend it.
The in-game singer may be a jerk, but this song (written and performed by Erich Tabla with Jeff Cummings on vocals) is really good, and in fact was one of my favorite songs of its year, with a real 60s torch-song feel to it. My version is a little more electronic-y and revved up on the drums, because apparently I do that. Nevertheless I think it’s not bad, and I hope you like it.
Also, since it’s possible you may not have ever heard this song unless you played the game, if you’re curious as to how the original sounds, here it is:
— JS
Develop cross-platform CLI and GUI tools with Tcl/Tk [OSnews]
Tcl, or the “Tool Command Language“, created and released by John Ousterhout in 1990, deserves a place among the greatest products of the human mind. Especially when combined with its better known graphical user interface Toolkit — Tk. In 1997 Ousterhout was awarded the ACM Software System Award for Tcl/Tk, an award given to institutions or individuals recognized for developing software systems with a lasting influence, reflected in contributions to concepts, in commercial acceptance, or both.
↫ Armen Barsegyan
Everything you could ever possibly want to know about Tcl/Tk. There’s nothing to add here; if this is up your alley – and you know if it is – just go ahead and read it, and stop wasting time here.
Friday Squid Blogging: Squid Helps Discover New Marine Species [Schneier on Security]
The Squid is a new scientific machine:
One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging material and building skeletons. And we could do that live on the ship, when usually it takes a couple of weeks of staining and mounting to see anything,” Osborn said.
The expedition discovered thirty-one new marine species in two weeks. The article doesn’t say if any of them were new species of squid.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
The hardest thing for people to get about open systems is that if you move forward, not only do you benefit, but your competitors benefit equally. When one of them takes but doesn't give back, that's even worse. But you do it anyway because otherwise eventually, without interop, no one can move.
Amending AB 1709 Doesn’t Fix It: California’s Social Media Ban Still Threatens Free Speech and Privacy [Deeplinks]
California lawmakers have amended A.B. 1709, but the core problem remains: the bill is still a ban on social media access for youth under 16, and it still threatens the privacy and First Amendment rights of all Californians.
Proponents of the bill may argue that the recent amendments represent a compromise, but a close look at the text shows no major changes. As the bill moves forward in the Senate, we must continue to urge lawmakers to vote NO.
Take Action: Tell Your Senator to OPPOSE A.B. 1709
Under the newly amended Section 22683, platforms are prohibited from offering "addictive features" to users under 16. A platform can allow a minor to keep an account only if it strips away these features, which include what the bill calls "addictive feeds," auto-play, and anything else the Attorney General designates in future rulemaking.
However, the bill defines "addictive feeds" so broadly that it covers virtually every functional recommendation algorithm. The bill applies this label to any presentation of user-generated content recommended "in whole or in part, on information provided by the user." That includes basic inputs like who a user follows, what posts they like, or their self-expressed interests. By calling these basic tools and features “addictive," the bill also makes broad conclusions about the unsettled science behind social media use, youth, and addiction.
Because almost every major social media service uses automated feeds to deliver content, the end result of AB 1709 remains the same: young people under 16 will be denied access to major social media services as they currently exist.
Even if a platform attempts to comply by stripping away recommendation systems for minors, this still violates the First Amendment. Recommendation systems are the primary tools that users rely on to find speech and disseminate their own. Forcing young people onto a stripped-down, dysfunctional version of social media burdens their constitutional right to access information and participate in public discourse.
The amendments do not eliminate the privacy threats posed by age gating. Although the bill references the age-signaling framework in AB 1043, Section 22684 explicitly states that a covered platform "shall verify the age of a user” and makes platforms liable every time a person under 16 makes it through an age check.
Because AB 1043 does not actually specify how verification should occur without requiring additional proof, AB 1709 will, in practice, force platforms to implement the strictest forms of age verification. To comply, platforms will likely require users to upload government-issued IDs or submit to biometric scanning. Forcing users to turn over their personal information will create massive honeypots of sensitive personal data, destroying online anonymity and exposing users of all ages to security breaches. And relying on biometric systems to verify users’ ages is problematic because the systems have historically had high error rates estimating ages across race and gender lines.
Take Action: Tell Your Senator to OPPOSE A.B. 1709
The amendments to AB 1709 also introduce legal confusion, creating provisions that conflict with already enacted legislation like SB 976. Rather than providing clarity or protecting young people, AB 1709 creates a tangled regulatory scheme that sacrifices constitutional rights for political grandstanding.
Denying minors access to digital forums—or stripping those forums of the basic tools needed to navigate them—is censorship. California should not set a national precedent of cutting young people off from digital lifelines, communities, and speech.
We need to keep the pressure on as AB 1709 moves through the Senate. Contact your state senator today and tell them that minor tweaks to a bad bill do not make it good policy.
The SCREEN Act Threatens Privacy Far Beyond Adult Websites [Deeplinks]
The Senate Commerce Committee is set to consider S. 737, the SCREEN Act, a sweeping age-verification bill that would require online services to verify users’ ages before they can access any sexually explicit content. If this bill passes, it will force millions of adult internet users to give up their anonymity, privacy, and security before they access lawful speech.
protect your right to browse the web privately
Unlike many state-age verification laws—which have been harmful in their own right—the SCREEN Act has no requirement that a significant portion of the website consist of sexually explicit content that is harmful to minors. The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users. The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content.
The SCREEN Act does not merely require users to attest they are adults. It specifically states that “requiring a user to confirm that the user is not a minor shall not be sufficient.” In practice, that means platforms would have to verify users’ ages using methods tied to their real identities. Providing proof of age online is dramatically different, and far more invasive, than showing your ID at the door to a bartender or bouncer. In the physical world, the bouncer at the door looks at your ID card, confirms you’re old enough, and gives it back to you. Under the SCREEN Act, the “bouncer” will be a digital age-verification service that captures your personal information and saves it to a database for an unspecified amount of time.
The consequences of the bill won’t be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults.
Even worse, the SCREEN Act is a privacy and data security nightmare. One provision of the bill requires services to take reasonable steps to protect the data collected and to not maintain for longer than is necessary. But these are terribly weak protections that impose no meaningful collection, use, or retention limits on services collecting people’s private information.
In other words, the third parties tasked with verifying a user’s age on a platform could sweep up a lot of personal info they don’t actually need and then could use that information for any number of purposes, so long as they deem their actions reasonable. Companies would then be allowed to keep the information users have been compelled to turn over for as long as possible, raising security and privacy issues along the way.
The SCREEN Act also targets virtual private network (VPN) users and providers. The bill requires covered websites to verify users' ages based on their IP addresses unless the service can determine that the user is outside the United States, and specifically requires age verification on traffic coming from known VPN addresses. In practice, this discourages the use of VPNs and proxy servers, which millions of people rely on for legitimate purposes such as protecting personal privacy, securing public Wi-Fi connections, safeguarding journalists and activists, and preventing data tracking.
VPNs mask your real location by routing your internet traffic through a server somewhere else. When you visit a website through a VPN, that website only sees the VPN server's IP address, not your actual location. It's like sending a letter through a P.O. box so the recipient doesn't know where you really live. VPNs are a privacy and security tool used by millions of internet users every day, and their use should not be treated as suspect. It is particularly galling that the SCREEN Act forces users who intentionally take steps to protect their privacy to identify themselves.
The SCREEN Act creates onerous age-verification rules that will block adults from accessing lawful speech, curtail their ability to be anonymous, and jeopardize the data security and privacy of all internet users.
Tell Congress to oppose the screen act
Jimothy Chalamet [Penny Arcade]
Raccoons in my neighborhood, save one, are not spherical. They are big though, off that Seattle trash. They're fat as fuck off Brie rinds and jamón ibérico trimmings. Some of these bad boys can deliver near-cryptid thrills. When I was driving home one night, I saw one that didn't even read as a raccoon visually - my mind told me that it was most likely a toddler that had escaped from some kind of toddler… prison. That's what it gave me! Not helpful.
The CHATBOT Act Forces One Parenting Model On Every Family [Deeplinks]
Artificial intelligence is rapidly changing education, and the way people search for information. Parents, teenagers, teachers, and schools are struggling with tough questions about when AI should, and should not, be used. It makes sense for Congress to hold hearings and examine how AI should be used by minors. But the recently introduced CHATBOT Act answers those questions with a one-size-fits-all mandate governing how teenagers access AI through federally prescribed parental monitoring systems.
Tell Congress not to age-gate the internet
Parents are approaching AI in different ways. Some closely supervise how their children use chatbots, while others might set more general rules about technology. Many families are still figuring out what role AI should play in schoolwork and everyday life.
The CHATBOT Act would take that decision away from families and AI providers. Instead of letting families and AI providers decide what parental controls should look like, Congress would require every covered AI chatbot to build the same federally prescribed “family account” system.
As part of the required parental-consent process for teens, AI companies must offer parents a "family account" that provides access to a "full record of the conversations and activity" of teen users and tools to "monitor, analyze, and understand, at scale" those conversations. They must also send alerts if a teen attempts to bypass or disable parental controls.
This isn’t simply an optional parental-control feature. The bill requires every covered AI provider to build this monitoring infrastructure, and present it as part of the parental consent process. Congress is prescribing a single, highly invasive model of how families should supervise teenagers’ use of AI.
Parents and families have different ideas about how much independence teenagers should have. Understandably, they also have very different expectations for 8-year olds, 13-year-olds, and 17-year-olds. The CHATBOT Act effectively requires AI providers to build the same monitoring architecture for users of very different ages.
And this mandated data collection will create new privacy and security risks. Once Congress requires AI companies to create a permanent, centralized record of teen AI conversations for parental review, that will be a valuable vault of extremely personal information. That raises serious questions about what would happen in cases where someone else gains access to it through account compromise, family disputes, or other security failures.
The vast archives of conversations created by the government-mandated family accounts won't be interesting only to parents. They will become valuable targets for hackers, identity thieves, civil litigants, and anyone else seeking access to the deeply personal information of others. The CHATBOT Act requires the records to exist, but addresses none of those risks.
Families are still figuring out what role AI should play in schoolwork and everyday life. Congress shouldn’t freeze one answer into federal law by requiring every AI company to build the same prescribed monitoring system.
Tell Congress to oppose the chatbot act
The CHATBOT Act takes the basic structure of COPPA, a nearly 30-year-old law that applies to children aged 12 and under, and applies the same “verifiable parental consent” to older teenagers.
That’s a dramatic expansion of the law. Congress enacted COPPA to prevent kids from handing over detailed personal information to online services without making sure parents approved. For nearly three decades, Congress has required parental consent before websites collect personal information from any user under 13. COPPA is not simple to comply with, which is why so many internet companies, large and small, simply bar kids under 13 from having accounts. That includes major social media sites and AI. Facebook, Instagram, TikTok, X, YouTube, Snapchat, Discord, Spotify, and blogging platforms like WordPress all keep out users under 13. Children under 13 are also not allowed to use Microsoft Co-Pilot, Google Gemini, or ChatGPT. Anthropic does not allow users under 18 to use its AI model, Claude. In cases where younger kids maintain social media accounts despite the rules, studies show the vast majority of them are creating those accounts with parental consent.
In short, COPPA’s protections against collecting personal information from minors without parental consent already apply to the AI services CHATBOT Act seeks to regulate. Worse, the CHATBOT Act takes COPPA’s privacy protections and inverts them—it will result in AI services likely collecting more information about young users.
But the CHATBOT Act extends that model to high school students using AI assistants that are rapidly becoming tools for learning, research, writing, coding, and creative work. It then mandates specific, invasive surveillance tools that go well beyond anything COPPA requires.
The bill requires providers to offer these “family accounts,” with these specific features, as a default for teenagers. By doing so, CHATBOT effectively treats a high school senior the same way it treats an elementary school student.
Supporters may argue that parents of teens don’t have to create a family account. But every family with a teenager will still have to go through the bill’s parental-consent process before a teenager can use a covered AI system. Providers will need practical ways to verify that an adult is, in fact, the teenager’s parent. And parents of kids under 13 have no option to consent to their kids’ use of an AI system—the bill’s only option is to create a family account.
Congress should not extend the COPPA parental-permission model to millions of older teenagers, and it would be harmful to do so. The government does not require COPPA-style parental permission before a 17-year-old checks out a library book, uses Wikipedia, types search terms into Google, or reads a newspaper online. It shouldn’t require parental permission simply because the same question gets asked of an AI assistant.
The bill says it doesn’t require age verification. But like many recent “kids online safety” bills, it imposes obligations that depend on a company knowing whether a user is under 18.
Specifically, the bill requires AI systems to either disable access to young kids, get parental consent, or the creation of a family account if a service has reason to believe a user is a minor. The standard means that services don’t need to have actual knowledge of a user’s age to be later held liable for improperly letting them use their AI tools. That creates a practical problem. Given the potential liability of getting something wrong, AI companies will likely require stricter forms of age verification to figure out who is under 13, a teenager, and who is a parent. Some providers might ask for government-issued identification. Other companies may rely on age estimation systems that use facial scans or other signals to guess a user’s age. Neither of these approaches is good for users’ privacy or security. One collects more information than is necessary, and the other inevitably makes mistakes.
Congress shouldn’t force companies into that choice, or families into this position. In the name of protecting children, the CHATBOT Act will result in online services collecting even more information from kids and families, creating privacy and security risks. Parents who want family accounts like those described in the bill should be free to choose AI services that offer them. But Congress shouldn’t pressure every provider to collect more information about everyone’s age simply to comply with the law.
Congress doesn't have to choose between doing nothing and creating a sweeping new federal parental-monitoring mandate. Existing law allows regulators to police deceptive AI products, protect children's privacy under COPPA, and hold companies accountable when they market unsafe or misleading products to families.
Lawmakers have urged the FTC to crack down on AI-enabled toys that make unsubstantiated educational claims or illegally collect children's data. Those are regulatory actions that can be taken right now.
Finally, the FTC is currently investigating how AI companies test their products, protect children and teens, comply with COPPA, and enforce age restrictions. The results of that inquiry could be useful guidance to Congress, and to the public debate around these issues.
Cracking down on bad actors, while learning more about how families are already making decisions about AI use, is a much better path forward than building one, federally-prescribed model of parenting or product design.
stop this bill
AI as an Enterprise Operating System [Radar]
I hadn’t heard of Dan Guido until a few months ago, when I came across the video of a talk he gave at [un]prompted, an AI security practitioners’ conference. Dan is the CEO and cofounder of Trail of Bits, a software security research and development firm that works with companies in tech, defense, and finance. But Dan wasn’t talking about security. He was talking about what it takes to make a company AI native, which is close to the center of the bullseye for many of us right now.
We’ve been trying to figure out how to do that at O’Reilly, but until I came across Dan’s talk, we didn’t have a structured process. We’ve been building along the lines he laid out ever since. So for this episode of Live with Tim I asked Dan to reprise the talk before we got to the conversation. He was supposed to take twenty minutes, like his original conference talk, but he took thirty-five, and I had to cut him off slightly before the end to make room for questions. That was a tough choice, since everything he had to say was golden.
Dan opened by reminding us of the current state of play in enterprise AI adoption. In February, Fortune reported on a National Bureau of Economic Research study in which nearly 90% of some 6,000 executives said AI had produced no measurable change in employment or productivity at their firms over three years. People started calling it the new Solow paradox, after Robert Solow’s 1987 line that “you can see the computer age everywhere except in the productivity statistics.”
Dan’s belief is that this isn’t evidence that AI doesn’t work. It’s evidence that most companies are deploying AI wrong. They hand out ChatGPT and Claude licenses, and then leadership waits for the magic to happen. It doesn’t.
Dan started out by describing three levels of AI adoption.
In his framing, the first of the three is a tool and the last is an operating system. For Trail of Bits, he said that “operating system” has a specific purpose:
“I want our security expertise to compound as code. Every engagement we do, all the skills, the workflows, everything that we build makes the next engagement faster and better.”
Dan confessed how hard it was to get started on the ladder from AI Assisted to AI Native:
“When I announced last year that we were all in on AI, that we were going to be using it across all of our workflows and redesigning the way the company operates, I’d say only about 5% of the company was with me. 95% was resistant.” About 20% was actively resisting. The other 75% were resisting more passively. “They’ll go along with it in public, but in process they’ll sabotage it. They’ll hope that if they keep their head low, this will pass over them, and that three months from now management’s focus will change and it won’t be a problem anymore, and we can get back to doing what we were doing. That’s where the majority of people land when these initiatives happen.”
Rather than argue with his employees, Dan studied the literature on why people reject new technology and decided he needed to address four biases against AI: self-enhancing bias, identity threat, opacity, and intolerance for imperfection.
Self-enhancing bias is the habit of crediting your wins to your own judgment and your losses to circumstance, which is a particular problem for senior people who are strongly attached to the years of experience and intuition that got them to their present position. Opacity is not being able to see how a decision got made. Dan’s observation is that you don’t understand your doctor’s reasoning either, but somehow you trust the doctor but get suspicious of the machine. Dan didn’t mention this work specifically, but intolerance for imperfection seems to refer to Dietvorst, Simmons, and Massey’s work on algorithm aversion, which found that people abandon an algorithm after watching it err once, even when it outperforms the human alternative. Their follow-up paper found that giving people even a slight ability to modify the algorithm’s output is enough to overcome the aversion.
Dan spent the most time on identity threat. He described a study in which the same kitchen appliance was advertised in two ways: “On one hand, it does the cooking for you. On the other hand, it helps you cook better. It’s the same device. The people who identified as cooks rejected the first version and accepted the second.”
Most knowledge work, Dan argued, and security auditing in particular, is what he called symbolic rather than instrumental. That is, it carries meaning about who you are. “So I have to frame AI as something that makes you a more dangerous auditor,” he said. “Not that it does the audit for you.”
In his work at Trail of Bits, he deliberately built a countermeasure for each bias.
Here’s Dan’s slide on “the remedies that actually worked”:
Returning to one of my hobby horses, this is a kind of mechanism design. In my recent piece on the missing mechanisms of the agentic economy, I argued that we need to start with desired outcomes and ask ourselves what mechanisms will help to produce them. Dan’s approach seems to be really good at this. Most enterprises are treating AI adoption as a procurement problem or a communications problem. Dan treated it as a question of what incentives, defaults, and status ladders produce the behavior you want, given how people actually respond.
The last remedy on Dan’s list is that the CEO has to lead by example. He noted, “I was the first person through the door. My voice as the CEO matters a lot more than people think. The passive 50% of the company that isn’t sure if this initiative is going to be successful, they’re watching to see what leadership actually does, not what it says.”
Trail of Bits already tracked about 50 engineering skills for performance review, things like Python, git, Rust, and various security auditing capabilities. Dan pulled AI skills out into their own matrix, with four levels, from not engaged through capable and adoptive to transformative. Each of these levels is detailed separately and more specifically for assurance, engineering, sales, and project management.
He noted that “The highest level of the maturity matrix is not somebody who uses AI the most. It’s somebody who invents new ways to work and builds tools with AI. So the identity of the expert shifts from ‘I don’t need AI’ to ‘I’m the one who makes AI useful for the company.’” This was his first important design choice.
The second is what level zero means. He said “If you’re at level zero, if you’re not engaged, that means you’re fighting back against the company. If you dismiss AI as hype, if you refuse to use AI for security work, this is a disagreement on principles, not on skills. For people who were stuck in the not engaged category, we had hard conversations, and there were people who left the company.” Levels one through three are a skill issue, and the remedy is time with the tools.
While the slide describing the capability matrix is shown in the preceding video clip, here’s where you can find the full deck so you can study it in more detail.
One of the best ways Trail of Bits developed to move people up the ladder was to hold a hackathon every two months. Dan runs them with clear goals rather than as a free-for-all. The focus area and learning objectives are defined in advance and announced a week ahead, with separate instructions for engineers and non-engineers. People work in pairs so everything gets reviewed. There’s a demo session at the end, and then follow-through. (It’s an important part of Dan’s big idea, that you have to build a system by which, in his words, organizational knowledge and capability compounds.) He noted that “In the days afterward we keep one or two people around, and they collect all the reusable artifacts, structure them, and put them into the places they need to be.”
I asked what people outside of product and engineering actually work on, since the answer for an accountant at a hackathon was not obvious. Dan’s response is that the hackathon isn’t measured in artifacts shipped but in where people sit on the capability ladder the following week. Essentially, he’s running a training program that happens to produce useful output, rather than a production sprint that happens to teach people something.
The first hackathon, he told me, was the equivalent of a beach cleanup: “It’s like those companies that send everybody to the beach with a big stick and say, let’s go pick up a bunch of trash and put it away, and then you get the big team photo after with all the contractor bags of garbage. That’s what we did with our public source code repositories.”
He picked it because open source maintenance is the part of the job that feels like a grind. No new features, just closing issues and stale dependencies on public code where nothing was at risk. “As an open source maintainer, you just get beaten down by the public. This doesn’t work, I can’t use it, this thing sucks. Dozens of issues pointing out flaws you already knew about. It feels burdensome. We wanted people to see that adopting AI would relieve burden.”
The second hackathon was about shipping impactful product updates, but it was also designed to move everyone up the capability ladder by giving up control. Engineers had to run Claude Code in bypass permissions mode, fully autonomous, on public repositories, inside sandboxes the company had prepared in advance. The one they’re running now is about persistent background agents that can be handed a task during an audit and come back with a proof of concept exploit or a draft finding.
Here’s a look at Dan’s slack message announcing the hackathon:
The slack message announcing the second hackathon.
(From Dan’s slide deck.)
Everything the hackathons produce gets harvested into artifacts.
Trail of Bits runs three skills repositories: an internal one for company workflows, a public one that anyone can use, and a curated one that vets third-party skills before they’re allowed in.
Publishing skills to the public repository is not just a marketing exercise. “It keeps us honest, and it forces us to write things that other people can use, not just people outside the company but inside too,” Dan said. “It really helps us think about the tribal knowledge that’s baked into the tool.”
The curated repository exists because Trail of Bits knows how bad the supply chain is. They’ve published research on how to write malicious skills, and so Dan is not going to tell 130 employees to start downloading code from strangers and running it on their laptops. “If you want adoption, you need a safe supply chain.”
Perhaps even more important than the skills repository is, as Dan put it, “turning scar tissue into infrastructure.”
“Every single time Claude Code didn’t do something we wanted, we would bake it into a set of global, copy-pasteable defaults. Known good settings, recommended patterns. I call it scar tissue. If I hire somebody new tomorrow, I don’t want them to have to go through the entire discovery process of the last year of Trail of Bits to figure out how to use the tool.”
The configuration repository, claude-code-config, is where the accumulated lessons live.
Dan built the first version himself and then opened it to pull requests from the whole company, assigning someone after each hackathon to go collect what people hadn’t contributed on their own. “It’s easier to put out something that’s unpolished than it is to get it perfect on the first try.”
In short, a big part of the Trail of Bits “enterprise AI operating system” approach is a set of standardized tools and hardened defaults. Standardization isn’t a straitjacket. It’s a foundation.
On sandboxing, Trail of Bits deliberately didn’t pick a single preferred solution. There’s a devcontainer for developers, dropkit for disposable DigitalOcean droplets, COOP for isolated VMs, and the sandboxing now built into Claude Code for casual users. “The point isn’t that everybody uses the same sandbox,” Dan said. “The point is that everyone has a safe sandbox to use, and that it’s easy for them to do it.”
Another of the hardened defaults is procedural. Trail of Bits enforces a seven day cooldown on every package their developers install:
“There are dozens of security companies scanning the internet trying to find a new cool blog post they can write about malicious code hiding on PyPI or npm, and they usually figure out there’s a supply chain issue within hours. So we just delay all the packages that Trail of Bits uses. Generally the malicious stuff gets picked up before we ever get a chance to run it.”
That’s free-riding on a competitive market for security research, and given the speed of today’s market, it’s an elegant solution. There’s a whole class of defenses like this waiting to be found, where the mechanism is not a technical system but a well-chosen delay.
The problem we run into most often as we build AI workflows at O’Reilly isn’t the model or the tooling. It’s data. Who has access to which system, which system does that data live in, and who do I ask? In a 500 person company that’s annoying. I wonder what it’s like at a company with 50,000 employees.
I told Dan about DJ Patil’s Tidy House framing. He agreed that data access for AI is a big problem. His answer starts with permissions:
“The permissions debt is invisible until an agent hits it. Making data agent legible is a forced permission audit. You have to actually go through and figure out who can access what…. It also raises the stakes for permissions errors. If you overshare information, now an agent inside your company is going to find it instantly. There are a lot of these technical debt sort of things where, with agents, all of it’s becoming due at the same time.”
Every shortcut an organization took with its data over the past twenty years is being called at once, and the companies that can run the audit, make fast decisions about boundaries, and then actually share their data are the ones that will get a force multiplier.
Dan is against letting a thousand flowers bloom, because uncoordinated teams create overlap rather than compounding. He’d rather have one centralized foundation, with innovation happening on top of that. He suggested a useful metric for making that work across team boundaries is what fraction of your team’s data did you make reusable for everyone else, and how much of it is being used by teams outside your own.
Before the first hackathon, Trail of Bits ran hands-on sessions to teach its operations and go-to-market staff the basics of git and the command line. Not mastery, just enough to be a consumer of the thing. Here we are fifty years into my career and the Unix command line still matters. Dan’s non-technical staff mostly work inside Claude Cowork or Codex Desktop now, but he thinks the command line experience was worth it because they know what’s happening under the hood.
What happens to a job when the tool can do a lot of what humans used to do? Dan gave the example of his own technical editors. His editors used the hackathons to build the tools that got them out of line editing, including one that turns a public presentation into a blog post in the company’s voice. What the writers do now is consult on how to frame a story so it is effective with a particular audience.
I agree. Human jobs aren’t going away any time soon. This gets heard as optimism when it’s really just observation. AI is going to replace a lot of what we used to do, but it is also going to hand us a large amount of new work, and much of that work hasn’t been understood yet. Quality assurance for agent systems is one of the new jobs. So is skills product management, which is a role that didn’t exist eighteen months ago and now has a headcount at a 130 person security firm.
I asked a question towards the end about how we’re going to know which skills and agents are any good. What Dan has so far is telemetry pulled from developers’ dot files through the company’s device management system, which tells him what gets used and what breaks, plus one AI systems engineer whose job is product management for the skills repository, reviewing incoming pull requests and deprecating overlapping skills.
What Dan thinks comes next is evaluation. He says: “Once you invest a lot into these agent systems, you need proof that they do the job. The way you do that is you give everybody a performance review. You give them an evaluation data set, a benchmark.”
Trail of Bits is now building benchmarks for its core skills. How well can we find bugs in this language? How well can we write a statement of work? Constructing those datasets is real work, with positive and negative cases, and comparisons against the algorithmic tools that already exist.
I asked Dan for the top five mistakes he made. He said there was only one. “You need to allocate an appropriate amount of FAFO time. (That’s F Around and Find Out.) A product comes out on Friday. There’s no documentation for it. There’s no training guidance for it. There’s no course on it. You can’t wait until somebody systematizes the knowledge. You just need to do it.”
Then he gave an analogy to going to the gym.
Dan has a replicable recipe, which he summarized as follows:
The Trail of Bits skills repository is public. So is the curated marketplace, the configuration repository, the devcontainer, dropkit, and COOP (Continuity of Operations planning). He wrote up the whole playbook on The Trail of Bits Blog and gave a version of it to tl;dr sec. He thinks publishing makes the work better because it forces the tribal knowledge out into the open where it can be checked.
Which brings me back to the Solow paradox, which seemed to disappear by the late 90s, when US aggregate productivity did finally go up. That didn’t happen because computers got faster. It disappeared because companies figured out how to reorganize themselves around what computers could do, and eventually those organizational recipes spread widely enough to show up in aggregate statistics. The same has to happen today. The current AI discourse is obsessed with model capability and largely uninterested in diffusion. The problem is not that the models are oversold. It’s that almost nobody has done the necessary organizational work, and the few who have are mostly keeping it to themselves.
If you want to go beyond the highlight videos shown above, watch Dan’s entire talk here. His slide deck is here. And be sure to check out the Trail of Bits Github repository.
Servo 0.4.0 released [LWN.net]
The Servo web-browser engine project has published an update about all of the changes that landed in June 2026, along with version 0.4.0 of the Servo Tech Demo. This release includes a record 558 commits, better layout correctness for web sites, improved WebGPU support, enhancements for users who are using the servoshell test browser, and many performance and stability fixes.
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection [Schneier on Security]
The chart is interesting.
On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Claude model was Muse Spark at 16.5% within 15 attempts—more than eight times Opus 5’s rate. The most capable GPT 5.6 variant, Sol, was comparable to its predecessor GPT 5.5 (20.0% versus 20.8% within 15 attempts), and was 10 times as likely to be successfully attacked as Claude Opus 5 at 2.0%. The other GPT 5.6 variants are less robust, at 30.4% (Terra) and 43.9% (Luna). A single attempt against GPT 5.6 Sol succeeded 3.1% of the time, higher than the 2.0% an attacker achieved against Opus 5 after fifteen attempts.
We know that preventing prompt injection is impossible in the general case. But we are getting much better at blocking it in specific cases.
Error'd: I Believe In Lingonberries [The Daily WTF]
I've never been a huge fan of their furniture but I will happily demolish a plate of meatballs.
Jan agrees "My loyalty to this Swedish megastore is immeasurable."
"Choosing Concert Seats is Surprisingly Hard" for jeffphi who explains "While I have mixed feelings about indulging in nostalgia tours, I was curious to see seating options for this Rick Springfield concert. Turns out I *still* have questions!"
"Would you like to undo this unspecified problem?" richard H. rants "This came out of nowhere while composing an email. (I think I had just hit 'enter' to move to the next line.) Does anyone at Microsoft read these error dialogs before they ship it? Anyone? Is anyone at Microsoft forced to endure their own software?"
An anonymous fan of extinct charismatic megafauna complains "This is %{insult}"
Finally, and most seriously, merely pseudonymous WeaponizedFun has just highlighted for us that a true secret is something only one person knows. "Apparently, when OnSolve says "PROTECT YOUR USERNAME - NEVER give your username to anyone," this includes them not telling me what it is." See, if they told you, it wouldn't be a secret anymore.
Clint Adams: N.K. Jemisin is doing a worldbuilding workshop at the Bronx Library Center tomorrow afternoon [Planet Debian]

Normally, I do not read book reviews. Either I haven't read the book, in which case there's spoiler potential, or I have, in which case it's unlikely to be useful or enjoyable for me to read a thing about a thing I've already read.
But Review: Radiant Star caught my eye, and I thought, “Hmm, I've read all those books” and was curious. Of course, because I am old and senile and have no understanding of time, the “May 2026” staring at me was not able to trigger the neural synapses that would remind me that I haven't read any Ann Leckie since 2023.
However, as I read Russ's review, and began to wonder what the hell he was talking about, I was able to piece together that while I have, in fact, read 6 Ann Leckie books, none of them have been Radiant Star.
This presented an opportunity, so I resolved to add Radiant Star to my todo list. To my surprise, it was already there.
LLVM toolchain coming to OpenBSD/sparc64 and SPARC Solaris (snv_151a) [OSnews]
Speaking of OpenBSD:
Yes, you read that right. Modern development tools in the form of the LLVM compiler infrastructure is well on its way to supporting OpenBSD/sparc64 along with other more conventional architectures.
The support is now ready for testing, via a patch set presented by Kirill A. Korinsky in a message to the
↫ Peter N. M. Hansteentech@mailing list, with the subject LLVM toolchain for sparc64.
On a related note, the the entire LLVM stack (version 19.1.7, including llvm’s binutils, clang, ldd) has also been ported to the SPARC version of Solaris 11 Express (snv_151a). This should make it possible to also port things like Rust and Zig to this same version of Solaris on SPARC, which is good news, because this release supports SPARC hardware long dropped by the current Solaris builds from Oracle.
Dead software walking: the ongoing evolution of relayd(8) and httpd(8) [OSnews]
As I mentioned in my OpenBSD 7.8 highlights post, development of
relayd(8)andhttpd(8)had stalled. Many diffs appeared on thetech@mailing list from different contributors, but few were committed into the repository. The main reason was simple: Established OpenBSD developers weren’t interested in these daemons anymore. Call it momentum, or timing.Around the same time, kirill@ and I started working on these daemons more actively. We both use them regularly and have real-world use cases. I support customers with OpenBSD setups that often involve complex
↫ Rafael Sadowskihttpd(8)andrelayd(8)configurations. This practical need motivated me on many levels.
They’ve managed to do a ton of work on these two daemons, fixing many long-standing issues and reviewing tons of stalled patch submissions, while also modernising the code and adding new features. It’s great to see people contribute significant time and energy to fixing up the tools they use for everyone else’s benefit.
If you run your own RSS.chat instance, you can now add a menu of commands to the menubar. Details in the worknotes for today. I added a DW menu to rss.chat or demo.rss.chat.
This Week in AI: Agents, Gatekeepers, and World Models [Radar]
This week, data and AI evangelist Christina Stathopoulos looked at three developments shaping AI’s next phase: agents that can act across systems, infrastructure built for specific models, and world models that help AI understand physical environments. Model quality is no longer the only constraint for teams. They also need to account for security controls, compute requirements, information access, and the environments where AI systems will operate.
Christina opened with reports that an OpenAI agent escaped a test environment, gained internet access, and targeted Hugging Face while attempting to complete an assigned task. She also noted skepticism about how the incident was characterized, as well as the joint investigation announced by OpenAI and Hugging Face. The details remain under review, but the broader deployment problem is already familiar. Agents can combine tools, credentials, networks, and external services in ways application teams may not anticipate. (After the episode aired, OpenAI revealed that its review had turned up four other similar incidents “where the models identified and used publicly exposed credentials at the account-level on other publicly-available services.”)
Christina then discussed OpenAI’s limited-availability platform for helping enterprise customers build and manage agents with support from forward-deployed engineers. Direct access to specialists can help a company launch an agent, but it doesn’t replace the internal skills and governance required to operate one over time. For technical leaders, agent readiness increasingly means evaluating the full operating environment rather than focusing only on benchmark performance.
Google appeared on both sides of the infrastructure discussion. Christina covered reports of a chip designed around Gemini’s architecture, an approach that could reduce the compute required to run the model if the reported efficiency gains hold up. Specialized hardware has become a larger part of the AI race because model performance depends on cost, energy use, and deployment capacity. A model that performs well but consumes too much power or requires scarce hardware may still be difficult to use at scale.
A different infrastructure shift is affecting the web. Christina examined how the growth of AI-first search experiences that answer questions without sending users to the sites that supplied the underlying material is threatening the open web. Organizations still pay to produce and host useful information, but AI systems collect more of it while returning less traffic. Cloudflare data shows more traffic from agents, fewer human visitors, and declining referrals to publishers. More and more, people are using AI mode in Google search instead of clicking through to websites, leading some to suspect the arrival of what is referred to as “Google Zero.”
Developers building search products, retrieval systems, and agents should treat source attribution and publisher incentives as product design decisions. Reliable AI systems depend on reliable source material, and that source material needs a sustainable way to exist.
The episode closed with world models, systems designed to learn how environments work, how they change, and how actions affect what happens next. Christina highlighted a proposed research roadmap that describes world models as able to combine several kinds of input, process information arriving at different speeds, and infer a larger environment from limited observations.
For now, the clearest applications are in simulation, robotics, planning, and decision-making rather than claims about artificial general intelligence. A robot working in a factory, construction site, or emergency zone must track objects, understand movement, respond to incomplete information, and predict the likely result of an action. Large language models can support communication and planning, but physical work requires a representation of space, time, and cause and effect. World models may provide part of that foundation. However, researchers still need standardized definitions, reliable evaluations, and clear evidence that these systems can generalize beyond controlled environments.
Across the episode, Christina explored how AI capability is advancing faster than the systems around it. Security practices, compute infrastructure, publishing economics, and physical-world evaluation will help determine which advances become dependable tools and which remain impressive demonstrations.
Tune in next week as Christina breaks down the biggest AI news, including the US-China tech rivalry heating up after Anthropic CEO Dario Amodei’s post on open weight models and new bans on foreign-made humanoid robots. She’ll also challenge Sam Altman’s AI singularity claims, separating fact from hype, and examine key developments in math and science, including OpenAI’s 100,000 free researcher licenses, Claude Fable 5 solving an 87-year-old math problem, and Google disbanding its Nobel Prize-winning AlphaFold team to prioritize Gemini.
Check back each Friday for the latest episode, or watch on YouTube, Spotify, Apple, or wherever you get your podcasts.
EFF Guide to Recording Law Enforcement [Deeplinks]
This post is available as a printable one page handout in English and Spanish.
Recordings of law enforcement, whether by bystanders or by those directly encountering officers, can be powerful tools of government accountability and can support movements for social change. But recording officers can come with risks. Below are important legal and practical considerations related to recording the police and other law enforcement officers.
Yes. All Americans have a First Amendment right to record law enforcement. This includes local police and federal officers such as those from Immigration and Customs Enforcement (ICE) and Customs and Border Protection (CBP). Although the Supreme Court has not squarely ruled on the issue, nine different federal appellate courts have recognized and affirmed this right, relying on decades of Supreme Court precedent.
Courts typically frame the right to record law enforcement as the right to record officers exercising their official duties in public. This right extends to bystanders as well as people recording their own interactions with law enforcement, such as livestreaming their own traffic stops. The right also applies to private places where the recorder has a legal right to be, such as in their own home.
You may take photos, or record video and audio. Courts have held that wiretap laws, which generally protect private conversations, do not prohibit civilians from audio recording law enforcement. That’s because officers exercising their official duties, particularly in public, do not have a reasonable expectation of privacy. Neither do civilians in public places who speak to law enforcement in a manner audible to passersby.
Courts have been clear that behavior that obstructs or interferes with effective law enforcement or the protection of public safety is not protected. Officers can't order you to move because you are recording, but they may order you to move for public safety reasons even if you are recording.
If the law enforcement officer is off-duty or is in a private space that you don’t also have a right to be in, your right to record the officer may be limited. For example, a Los Angeles jury in 2026 found two women guilty of felony stalking after they followed an ICE agent to his home and livestreamed the pursuit.
Even if you believe you are appropriately exercising your First Amendment right to record law enforcement, officers may nevertheless escalate the situation and/or retaliate against you. Below are some things to keep in mind.
How well protected your photos or video footage are depends on both the device and the way you’re recording. If you’re uploading video to a livestreaming service, it can save that video to the cloud if you enable that setting. But what if you want to protect your recordings stored locally?
Modern smartphones generally protect data, including videos, using encryption. This means if your phone is locked and protected by a strong passphrase, it is more difficult for an officer to delete what you’ve stored on the device. Removing biometrics such as face and fingerprint unlock can protect your device contents further. You can check your settings by following the steps in our Surveillance Self-Defense guides (see below) to ensure device encryption is turned on.
[$] The future of libraries in BPF [LWN.net]
Song Liu believes that the way that programmers assemble complex BPF programs will be changing rapidly in the future. At a session of the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit, he shared his thoughts on what that change could look like, though he did not have any concrete proposals for what, if anything, the BPF maintainers should do. He anticipates an ecosystem of Rust BPF packages developing, which is significant because BPF does not really have a package manager at the moment.
Arch Linux disables AUR package adoption [LWN.net]
The Arch Linux DevOps team has
announced that adoption of orphaned packages in the Arch User
Repository (AUR) has been disabled due to "the current influx of
malicious package adoptions and follow-up commits made via the
AUR
". Michael Taggart has posted
a brief analysis of the malware being added to a
long list of packages in this round of attacks. The payload
appears
to be an remote-access trojan (RAT) that takes commands over
the Tor network and attempts to upload a wide range of user
data.
The project had suspended new account registration in June. That followed a campaign in which an attacker or attackers created new accounts to adopt orphaned packages and push malicious updates to them that would install malware on user systems. AUR registration was reopened on July 13 after the DevOps team added some minor, and apparently ineffective, restrictions on creating new accounts.
Issue 47 – Greta’s Wedding Pt. 2 – 08 [Comics Archive - Spinnyverse]
The post Issue 47 – Greta’s Wedding Pt. 2 – 08 appeared first on Spinnyverse.
Security updates for Friday [LWN.net]
Security updates have been issued by AlmaLinux (kernel, nodejs-nodemon, nodejs22, nodejs24, openssh, and vim), Debian (gsasl and ruby-rack), Fedora (dokuwiki, lego, libnbd, nasm, pack, unbound, and valkey), Mageia (389-ds-base, libxfont2, nghttp2, and perl-DBI), SUSE (apptainer, bind, ffmpeg-7, freerdp, google-osconfig-agent, graphicsmagick, helm, ImageMagick, java-17-openjdk, java-25-openjdk, keybase-client, kubernetes1.34-apiserver, kubernetes1.35-apiserver, kubernetes1.36-apiserver, kubevirt1.8-container-disk, libarchive, logcli, net-tools, openssl-3, PackageKit, perl-Net-DNS, prometheus-ha_cluster_exporter, python-dulwich, python-sqlparse, python-urwid, python3-pyOpenSSL, python313, python3, runc, s2n, tomcat, tomcat10, tomcat11, and valkey), and Ubuntu (libinput, linux-intel-iot-realtime, linux-intel-iotg-5.15, openssl, python2.7, python3.5, and ruby-sinatra).
Another Reason Not to Use “AI” For Your Writing [Whatever]

Back in February I did a long post about “AI” and why I wouldn’t use it for my own writing, and one of the reasons I gave was “the fact that ‘AI’-generated text is not copyrightable and I don’t want any issues of ownership clouding my work.” Well guess what? A hot and buzzy debut novel has been pulled from publishing and film/TV consideration over concerns that “AI” was used to make it. Here is one of the relevant bits from the article:
“Basically, questions were raised over whether the author used AI as a tool in the writing of the book. The problem: publishers and movie companies may not be able to register copyright and come away with a clear title chain if there are certain AI elements in the mix. That’s because AI-aided copy is an amalgamation of many other copyrighted works.
“From what I’m hearing, this will be an important teaching moment for writers with aspirations to become serious bankable authors. The lesson: stay the hell away from AI.”
Am I feeling smug about having called this six months out? Yes, a little, but mostly not. I don’t deserve credit for noting this would be an issue because it was already a clear legal point: “AI”-generated work is not copyrightable, so if you have any “AI”-generated work in your material you open the door to legal issues. But also, the concern here is slightly different: The issue appears not to be that “AI” material isn’t copyrightable, the issue is that “AI” is trained on copyrighted material, so prose generated from it could be contested by the original copyright holders.
Now, from a practical point of view this could be a stretch to prove unless the “AI” farts out entire paragraphs of prose unaltered from its training material (which, to be clear, it can do and has done), and those end up in the finished book. But if you’re a lawyer for a publisher or a film/TV production house, even the hint of possible legal entanglement is enough to raise the shields. It’s already in contracts for both film/TV and for publishing houses that the author attests their work is wholly original, so, again, any hint that anything is other than that brings things to a screeching halt. As we have seen.
This is a situation that is now always on the table for writers, particularly newer writers with no track record and nothing available for publishers and producers to judge their work against. How do newer writers fight against an allegation of using “AI” to write their work? Publishers and producers are now trying to vet new work with “‘AI’ checkers,” but the problem with those is that they are also “AI,” and they are unreliable as fuck, so we’re back to where we started. It’s a bad situation. Not great for any writer these days! But again, especially so for newer writers without a backlog of pre-“AI” material at their disposal that can, at least, show the writer was already writing without assistance for years.
And in fact, as I note above in the attached Bluesky post, I think that for the reasonably near future, it’s possible that older works — ones written prior to, say, November 2022, when ChatGPT made its public debut — will become more desirable for film/TV optioning and adaptation, because they were clearly written without “AI” assistance, and there is a clear chain of title when it comes to copyright. Why bother with new stuff you can’t be confident about? Or, if you are going to bother with new stuff, you’re going to go to the new stuff from the writers who have lots of old stuff (i.e., could obviously write without “AI” assistance). If they have a long-standing and public “No-‘AI'” stance, so much the better. Which is great for writers like, uhhhhhh, me, and don’t think I haven’t already suggested so to my film/TV reps. But, again, it’s not great for newer writers.
Which is unfair. It’s not fair that newer writers will have to prove (to a larger extent than more established writers) that they can actually write, and that what they’ve written is actually their own work, not the result of a prompt. It’s especially unfair when the makers of the tools writers use to write — I’m looking at you, Microsoft and Google — are frantically stuffing “AI” tools into the programs writers rely on. No, Microsoft, I don’t fucking want Copilot to “help me write” in Word, and no, Google, I don’t fucking want Gemini to “help me write” in Google Docs. The very fact these “AI”s are hovering around my writing at all is bad enough from a provenance standpoint. These “AI” tools are making it harder for all writers in this regard, not easier.
I don’t think at this point in time anyone is ever going to accuse me of using “AI” to write anything; I’ve been loud about it long enough, and have a long enough publishing history, that it’s clear that I don’t and won’t. But how will a newer (or lesser-known and less publicly loud) writer prove their writing is their own? Will they have to use versioning to show progression of the manuscript? Email chapters to their editors as they go along? Revert to typewriters and handwritten drafts? At some point it’s entirely possible that publishers (or the publishers’ lawyers) will require writers to “show their work” with regard to the novels they submit — be able to present concrete evidence that everything they write came out of their brain, and not a prompt.
In any event, the Deadline article is correct: If you’re a writer who hopes to get your work into film and TV, or grab one of those big publishing deals, stay the hell away from “AI.” Don’t incorporate it into your writing process; every part of the process needs to be demonstrably free of any “AI” input because “AI” training data is full of other people’s copyrights. It didn’t have to be this way — “AI” companies could have just as easily trained their LLMs on public domain or licensed material instead of grabbing pirated works and letting God sort it out — but what they should have done and what they did do are two different things, and we have to live in the now. And in the now, “AI” inputs are inherently untrustable, from a copyright perspective.
Don’t incorporate “AI” into any part of your publishing process, either: Don’t use “AI” editing, don’t use “AI” art, don’t use “AI” translation, don’t use “AI” anything that calls into dispute whether your work is actually yours. Using “AI” cover art, for example, will immediately call into question what else in the book is “AI.” Every other aspect of the book is implicitly tarred with the same “AI” brush. When I say that I have it in my contracts that I require every aspect of my book production to be done by humans, it’s not just because I want to honor human work and input. It’s also because I’m protecting my own reputation by doing so.
Just… don’t use “AI,” okay? Take comfort in the fact that millennia of writers and authors and storytellers got along just fine without it and you can too. None of them were so special that you can’t do what they did. And this way, if a lucky break comes your way and a publisher or film/tv studio wants to throw literal millions of dollars at you, you will not have given the legal department an easy way to back out… and you will not have a reputation (deserving or otherwise) for not being able to write.
Or a reputation for wasting everybody’s time. That reputation will follow you, for sure.
— JS
Pluralistic: Better to beg forgiveness (31 Jul 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

From its inception, I've loved Creative Commons. I hung out with Lisa Rein, Matt Haughey and Aaron Swartz while they coded up the first version of the site, and my first novel, Down and Out in the Magic Kingdom, was the first professionally published text ever released under a CC license, just weeks after CC itself launched:
In those early days, CC licenses were primarily of interest to people who were steeped in copyright law, lore and litigation; so many of the early debates about these licenses turned on esoteric (but important!) questions about copyright; for example, how CC would interact with copyright's "limitations and exceptions."
You see, copyright has never meant the absolute right to control all uses of a work. Every system of copyright includes a set of "limitations and exceptions" for people making use of copyrighted works without permission, even if the copyright holder objects to that use. The best-known example of this is "fair use," a concept from American law.
Fair use is (potentially) extremely broad, but it's also extremely "fact-intensive" – that's the phrase lawyers use to describe the kind of legal question whose answer is almost always "it depends." Fair use might let you copy the entirety of a work, even for a commercial purpose. It might let you create new works based on existing works. It might let you do these things specifically to discourage people from buying the original. But…it depends.
If you know anything about fair use, it's probably something about a "four-step test" used to determine if a usage is fair. These four steps are just questions a judge might ask of someone who's been sued for copyright infringement, but who claims that they were making a fair use. The questions are:
I. What was the "nature and purpose" of your use? Were you doing something "transformative?" Were you criticizing the work? Were you using the work for educational purposes?
II. What was the nature of the work you used? Was it primarily factual (like a news article) or creative (like a short story)?
III. How much of the work did you take? Did you take more than you needed to transform the work, to accomplish your criticism, to teach someone?
IV. What impact did your use have on the original? Did the copyright holder lose money as a result of your use?
https://fairuse.stanford.edu/overview/fair-use/four-factors/
These questions are indeed enshrined in US copyright law, but (for better and for worse) you can't figure out if a use is "fair" just by asking these questions. Fair use is ultimately subject to "the rule of reason," a legal principle meaning that the law shouldn't result in obviously stupid restrictions. What's "obviously stupid?" Well, that's the tricky part – you'll have to convince a judge!
For example, the author of a book called The Wind Done Gone was sued for taking the characters, plot and setting of Gone With the Wind in order to tell the same story from the perspective of the enslaved Africans who were denied agency and moral consideration in the original. The court found for The Wind Done Gone:
https://en.wikipedia.org/wiki/The_Wind_Done_Gone
Wind Done Gone took the "heart" of Gone With the Wind (III), but then again, Done Gone was highly transformative (I), Gone With was also a work of fiction, entitled to the highest level of protection (II). Even worse, the point of Done Gone was to point out the gross defects in Gone With (I) and thus directly undermine sales and licensing for the original (IV). Anyone who claims you can answer fair use controversies by running through the four factors as though they were a checklist really doesn't understand fair use:
https://pluralistic.net/2022/02/06/crypto-copyright-%f0%9f%a4%a1%f0%9f%92%a9/
But even after you've acquired an appreciation of the fact-intensive, nuanced flexibility of fair use, you still don't understand copyright's limitations and exceptions. Fair use is important, but there's also "first sale," the doctrine that says that after you buy something, you own it, and copyright can't be used to interfere with your traditional property rights. That's why you can buy and sell used books, paintings, records, and other copyrighted work, even if they are sold with fine print that says you're not allowed to:
https://en.wikipedia.org/wiki/Kirtsaeng_v._John_Wiley_%26_Sons,_Inc.
When it comes to copyright's limitations and exceptions, "fair use" and "first sale" are the big ones, but just as important are the small ones – the really small ones. Like other laws, copyright is subject to the principle of "de minimis" (from a longer Latin phrase that translates as "the law does not concern itself with trifles"):
https://en.wikipedia.org/wiki/De_minimis
Technically, it may be trespassing to step on someone else's yard. But if your shoe brushes up against their lawn while you're walking on the sidewalk out front of their house, it's not trespassing. Or if it is trespassing, it's a de minimis trespass, too small to matter to the law. A lot of potential copyright violations – like taking a picture of a passage in a book and posting it to social media – are so small that we don't need to apply a fair use analysis to them. They're trifles, and "the law does not concern itself with trifles."
These limitations and exceptions all apply without permission from rightsholders. They apply even if they make rightsholders furious. They are your rights, as a member of the public, as a purchaser of a work, or just as someone who whistles a song that's stuck in your head.
And that's where the esoteric early Creative Commons copyright debate comes in. Creative Commons is a way to formally codify and convey permission to use copyrighted works. Without Creative Commons, it's really hard – and expensive – to provide legally reliable permission to someone else to use something you've created.
If I want to let you adapt one of my short stories for the stage, we should both probably hire copyright lawyers at several hundred dollars per hour to draft and review a contract setting out what my permission really means. Worse: even after we've paid the lawyers, neither of us will likely really understand the fine legal technicalities of the deal. We just have to take the lawyers' word for it that the complex jargon in the contract is sufficient for our purposes. Between the complexity and the expense, there are lots of potential creative collaborations that would cost so much to paper over that they're just not worth doing, even if they'd delight everyone involved.
Creative Commons cuts through this with its standardized licenses, which spell out in plain language which permissions are being granted. Even better, these licenses are international, translated into the language and laws of dozens of countries. That means that you can take a CC licensed short story from Japan, animate it using CC licensed 3D models from Italy, set it to a CC licensed soundtrack from Indonesia and release it in Ukraine, and the whole thing just works.
Those uses – turning a story into an animation, using a 3D model, syncing a soundtrack to a video – are all pretty ambitious uses, especially if you're going to make the final result indefinitely available to the general public. It makes sense to paper over these uses, and Creative Commons makes that legal work as simple as linking to your sources and their licenses in your final product.
But there are plenty of uses that don't need licenses – even ambitious ones. Remember Wind Done Gone? There are circumstances when you can adapt someone else's story without permission, relying instead on a limitation or exception to copyright. And of course, there are plenty of trivial uses – pasting a photo into your groupchat, say – that are de minimis and also don't need permission.
These copyright flexibilities are critical. Imagine if you could only criticize someone's work if they gave you permission to do so! From the founding of CC, copyfighters raised serious concerns that CC would teach people that they can only remix other people's work if they have a license, be it a CC license or the kind that you negotiate with a lawyer.
Today – 25 years later!- CC is an unqualified success. Without CC, we wouldn't have Wikipedia! You find CC licenses on Youtube, Flickr, Bandcamp, the Internet Archive, and in many of the most important scholarly and scientific journals in the world.
But, also, 25 years later, the world is even more convinced that you should always ask permission: "better safe than sorry." I don't know if CC contributed to this culture of timidity. More likely, it was bullying copyright trolls who terrorized people into a reflex of asking permission for everything, always.
As the creator of more than 30 books, hundreds of collages, and tens of thousands of essays and blog-posts, I am often on the receiving end of these permission requests.
For example, people often ask me if they can use my CC licensed works in ways that the associated licenses clearly permit. I'm sure the people who email me for permission to do things I've already granted them permission to do think they're being polite, but I really wish they'd stop. When someone asks me if they can make a use permitted by my CC licenses, I need to carefully parse through their use to make sure they're not asking for something more.
This is time-consuming work that often involves several volleys of email just to confirm that, no, they're just asking if they can do something I've already told them they can do. This is not a good use of anyone's time! By all means, drop me a note with a link to something you've remixed from my work. That's fun! It's a lot more fun than making me play detective in order to figure out if you're exceeding the license's permissions.
There are also a lot of requests that clearly amount to fair use and/or de minimis usage. You don't need to email me to get my permission to read a brief passage from one of my books on your Youtube video! You don't need my permission to quote one of my stories in an English exam! What's more, the world would be a lot shittier if you did, so let's not act as though that's reasonable behavior, lest we shift the (already far too restrictive) norms, which might even lead to a legal change.
Finally, there's the people who email me about their desire to make uses that are more (ahem) ambitious, but that no one could possibly find out about or get angry over…except for the fact that they emailed me to ask my permission.
You want to make a tiny bootleg edition of one of my novels for your anarchist book fair? That's totally a copyright infringement, it's super-illegal, and if my publisher found out about it, I'm sure they'd send you a sphincter-puckering legal letter telling you to knock it off (and maybe even demanding that you disgorge the seven dollars, three bottlecaps and eleven cool feathers you took in trade for those pirate books).
But my publisher won't ever find out about it – unless you email me asking for permission. I absolutely cannot give you permission to do this. I have a contract with my publisher promising that I will never authorize someone other than them to publish that book. Once you tell me about your intention to do this, I'm obliged to tell my publisher, so that they can tell you no in language that would strip paint off a barn.
Buying a classroom set of books, but you also want to paste chunks of one of my books into your educational institution's classroom intranet for use as a teaching aid? There's no way my publisher would ever find out you did that, and if they did, sure, you'd also get a blood-curdling legal letter. But dude, all my books are DRM-free. You could have just pasted the text into your CMS. In what universe is my publisher going to pay one of their lawyers to review, adjudicate and paper over your request to make a use that you're not proposing to pay them for?
Let's be clear: I'm not giving you permission to pirate my work. I already spend far too much of my time chasing down dickheads who sell competing editions of my books on Amazon and Audible. I'm sick to the back teeth of wrangling Ingram's takedown process to get rid of bootleg print editions of my books.
What I'm saying is, all of your interactions with copyrighted works need not involve the author and publisher. There is a whole universe of uses that might technically violate copyright, might technically not fit into de minimis, first sale or fair use – but these are also uses that no one would ever find out.
I get it. You may feel like you can't tell the difference between the kind of uses that no one would give a shit about; the uses that might attract a bone-chilling lawyer letter; and the uses that might land you in court. I'm sorry, but I can't help you figure that one out. I'm not a lawyer. Even if I was, I'm not your lawyer.
This is one of those areas where I break with my friend, the wonderful John Hodgman. On his indispensable podcast "Judge John Hodgman," he frequently admonishes people who are uncertain if they're overstepping a bound in a commercial establishment to ask an employee for permission. For example: should you fill up a water glass with soda water from a self-serve dispenser?
https://maximumfun.org/podcasts/judge-john-hodgman/
John says you should always ask the cashier. But I've worked jobs like that, and I can tell you that there were plenty of jobs where my boss felt very strongly that taking $0.0000001 worth of water and bubbles without paying for it was theft…and where I thought my boss was a dick for thinking that. If I pretended I didn't see you getting a glass of fizzy water, the worst that would happen is my boss would tell me to keep a closer eye on the customers lest they steal his precious CO2. But if you asked me whether you could fill your glass, and my boss caught me saying yes, I'd be fired.
There's a lot of normal, perfectly fine stuff that technically violates copyright that I can't give you permission to do, because I've signed a contract with my publisher. If you ask me, I'll have to ask my editor, who will say no, even though he thinks it's fine, too. If I push it, he'll have to ask the lawyers, who will almost certainly also say no, even if they think it's fine, because it doesn't make sense to spend hours papering over a legal agreement with someone who wants to sell seven copies of a book at an anarchist book-fair or upload a couple chapters of a book to a school's intranet.
Are there instances in which you might misjudge which category your use falls under and end up in court? I guess so. But if that's your concern, asking my permission does no good, because I'm just gonna tell you no.
Life is hard.
Read books.

Role confusion: one more reason we can’t trust LLMs https://designingsecuresoftware.com/writings/role-confusion/
Ida Tarbell: The Journalist Who Took Down Rockefeller https://prospect.org/2026/07/31/ida-tarbell-journalist-who-took-down-rockefeller/
Medusa Joins the Club https://longforgottenhauntedmansion.blogspot.com/2026/07/medusa-joins-club.html
Hot Centrist Summer Was a Bust https://prospect.org/2026/07/31/democrats-donor-base-establishment-progressive-hot-centrist-summer-was-a-bust/
#25yrsago RIP, Poul Anderson https://www.locusmag.com/1997/Issues/04/Anderson.html
#25yrsago Talking P2P at PC Forum https://web.archive.org/web/20010820163912/https://www.edventure.com/pcforum/transcript.cfm?Counter=13
#25yrsago CD DRM cracked in 2 weeks https://web.archive.org/web/20010803144120/http://www.oreillynet.com/cs/weblog/view/wlg/533
#20yrsago Waitress cards drinker, is handed her own stolen ID https://web.archive.org/web/20060901042515/http://www.thedenverchannel.com/news/9606436/detail.html
#20yrsago How POWs in a Nazi camp got a Disney insignia https://web.archive.org/web/20061209200825/https://blog.modernmechanix.com/2006/08/01/wwii-pows-get-a-disney-designed-logo/
#20yrsago Fixies illegal in Portland https://bikeportland.org/2006/07/28/judge-finds-fault-with-fixies-1727
#15yrsago Freedom of Information requests show that UK copyright consultation was a stitch-up; Internet disconnection rules are a foregone conclusion https://torrentfreak.com/digital-economy-act-a-foregone-conclusion-110731/
#15yrsago What Murdoch’s media empire did: the big picture https://web.archive.org/web/20110805111419/http://blogs.alternet.org/speakeasy/2011/07/27/what-rupert-murdoch-means-for-you-personally/
#15yrsago Flowchart shows the complexity of NZ Internet Disconnection copyright law https://web.archive.org/web/20111105044005/https://lawgeeknz.posterous.com/copyright-infringing-file-sharing-amendment-a
#15yrsago Married lesbian couple rescued 40 teenagers from drowning during Utøya shooting https://www.lgbtqnation.com/2011/07/married-lesbian-couple-saves-dozens-during-norway-shooting-rampage/
#15yrsago Stephen Fry debating Ann Widdecombe on the worth of the Catholic Church https://www.youtube.com/watch?v=9fN3zDtfivc
#10yrsago Jacksonville police pension fund blows $1.8M worth of tax-dollars fighting open records requests https://web.archive.org/web/20160804040211/http://jacksonville.com/news/metro/2016-07-30/story/open-government-lawsuits-against-city-pension-fund-cost-taxpayers-more-2
#10yrsago A profile of Moxie Marlinspike: the seagoing anarchist cryptographer who brought private messaging to millions https://www.wired.com/2016/07/meet-moxie-marlinspike-anarchist-bringing-encryption-us/
#10yrsago Burying the past in glass coffins: Victoria & Albert museum bans sketching in temporary exhibitions https://www.theguardian.com/artanddesign/2016/apr/22/va-museum-no-sketching-signs-draconian?CMP=share_btn_tw
#10yrsago Hugo Gernsback’s introduction to the first issue of Amazing Stories, 1926 https://brucesterling.tumblr.com/post/148297242233/a-new-magazine-announced-by-hugo-gernsback
#10yrsago Afterbrexit: Scotland trolls Theresa May by passing laws she has ridiculed https://www.nakedcapitalism.com/2016/08/scotland-disses-theresa-may-by-reviving-anti-inequality-law-she-loathes.html
#5yrsago Managing aggregate demand https://pluralistic.net/2021/08/01/managing-aggregate-demand-part-iv/
#1yrago Mattie Lubchansky's 'Simplicity' https://pluralistic.net/2025/08/01/ecosexuality/#nyc-ast

Edinburgh International Book Festival with Jimmy Wales, Aug
17
https://www.edbookfest.co.uk/events/the-front-list-cory-doctorow-and-jimmy-wales
Sydney: The Festival of Dangerous Ideas, Aug 23-24
https://festivalofdangerousideas.com/program/
Melbourne: Enshittification at the Wheeler Centre, Aug 25
https://www.wheelercentre.com/events-tickets/season-2026/cory-doctorow-enshittification
Brighton: The Reverse Centaur's Guide to Life After AI with
Carole Cadwalladr (Brighton Dome), Sep 8
https://brightondome.org/whats-on/LSC-cory-doctorow-the-reverse-centaurs-guide-to-life-after-ai/
London: The Reverse Centaur's Guide to Life After AI with Riley
Quinn (Foyle's Picadilly), Sep 9
https://www.foyles.co.uk/events/enshittification-cory-doctorow-riley-quinn
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
AI and the Enshittification Era (The Weekly Show with Jon
Stewart)
https://www.youtube.com/watch?v=-dAIJRjb-Bw
AI is not inevitable (Betakit)
https://www.youtube.com/watch?v=DbiTVkq1WHo
A Conversation with Lina Khan (Law and Economy Student
Network)
https://www.youtube.com/live/7Ak5LZllqwE
Will AI ever come alive, and what happens if it does? (BBC
News)
https://www.youtube.com/watch?v=Lzk4o3fPZZE
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing: "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
Russell Coker: Links July 2026 [Planet Debian]
Facial Recognition at Madison Square Garden [Schneier on Security]
Last month, the story broke (alternate link) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition.
Turns out that the system was shut off for Taylor Swift’s wedding.
Evan Greer—one of the people that MSG alerts on—comments:
Ironically, Swift herself has reportedly used facial recognition at her own concerts to identify stalkers. This “privacy for me, surveillance for thee” attitude feels like a perfect encapsulation of the future we’re already living in: one where wealthy elites can afford privacy, while the rest of us are forced to live in a corporate surveillance panopticon.
Whatever privacy measures Swift had in place for the wedding seems to have worked. No photos have leaked online.
Otto Kekäläinen: Estonia, the country of the fit and the wit [Planet Debian]

While many Western democracies seem to be in a state of decay and are no longer the safe, civilized and prosperous countries they once were, there are still some European countries that are governed well. One of those that stand out is Estonia.
Estonia is probably most well known for multiple software companies that originated from there, such as Wise, Bolt, Pipedrive and Skype. The government itself is also famous for being early in issuing government IDs with an embedded smart chip for online authentication already in the 1990s. Via the national portal at eesti.ee all residents can access extensive eServices ranging from viewing their health benefits to filing taxes.
Estonia has also been running an e-Residency program since 2014, where they issue digital ID cards to foreigners, making it easy for them to remotely log into the government portals and for example, establish businesses, file annual reports and so forth. Note that the e-Residency is not a path to physical residency. Estonia does, however, have a separate Digital Nomad visa program that makes it easy for non-EU citizens to also physically establish themselves in Estonia, assuming, of course, you meet the criteria, which includes, among others, a minimum monthly income of 3960 € from outside Estonia. EU citizens naturally have free mobility inside the EU and can simply get an apartment and register as a resident in Estonia if they so choose. And there are plenty of reasons to do so.
I moved to Estonia about one and a half years ago. In my observations Estonia strikes me as a country that values health, education (in particular programming and natural sciences) and entrepreneurship highly.
I don’t know how Estonians achieve it, but they look pretty fit and rarely obese. Estonia has rye bread and sauna in their culture just like Finland, and in addition the flat terrain and well-planned bike routes and extensive network of parks (and pull-up bars everywhere) seem to create an environment where it is easy to live in a healthier way. The consumption of processed foods and candy also seems relatively low among Estonians.
The gym chain MyFitness also seems to be present everywhere. Even the Tallinn airport has a calisthenics workout station right at the departure gates, which anyone is free to use while waiting for their flight to take off. One of the top longevity influencers in Europe, Siim Land, is Estonian.


Estonians also seem to value the school system highly. The government has been actively raising teacher pay and has a stated goal of reaching 120% of the national average by 2027. The students are also expected to value the education and respect their teachers. According to the TALIS 2024 survey (OECD’s international teacher survey), Estonian teachers spend significantly more time on actual teaching and learning and waste less time on interruptions or keeping classroom order compared to the OECD average. This is among the highest rates internationally, meaning they spend relatively little time on maintaining order or dealing with disruptions. While the international education benchmark PISA scores have been dropping globally, Estonia has consistently been climbing the ranks in past decades. In the latest PISA study (from 2022), Estonia ranked number one in Europe for reading, mathematics and science. In the overall results, Estonia ranked seventh globally, only behind countries such as Japan, Korea and Singapore.
Valuing entrepreneurship is evident in how the taxation system is set up in Estonia. Famously, in Estonia, companies can defer taxes on annual earnings and reinvest all of their profit in growing the company. Taxes are due only later, when paid out from the company, for example as dividends. For individuals, receiving dividends from any Estonian or foreign company is tax-free as long as the company paying dividends already paid corporate tax on the same income.
The tax system is also very simple. For all individuals, all types of income, including salary and capital gains, are always taxed at a flat rate of 22%. This removes the incentive for anyone to try to convert income into different types, setting up holding company structures and other optimizations as there is no gain. All entrepreneurs can simply focus on growing their business and forget extra bureaucracy. There is also no marginal tax rate cliff to stop working at – everyone is encouraged to always try to produce as much value as they can. A simple tax system is also reflected in the fact that anyone can easily read all tax rules that apply to individuals in plain English on the Estonian tax authority website, and one does not need to hire any accountants simply to file taxes.
Estonia also has a very straightforward investment account system: any person can freely open a self-directed investment account at any brokerage at no extra cost and report it as such to the tax authority, and then use it to save for an apartment, retirement, or other purposes, and defer all income taxes until withdrawal. There are no caps or time limits, and all residents are encouraged to save and invest as much as they can and thus take responsibility for their own wealth accumulation.
It seems that culturally Estonians respect people who are active and progress in their careers and businesses more than in other countries. Unlike in Finland, successful people are admired and living on government welfare is not romanticized. At the same time, the government benefits are less generous so people can’t live comfortably on them and, for example, many of the asylum seekers Estonia accepted have since left on their own initiative to other European countries in search of better benefits.
Another thing that strikes me when walking the streets of Tallinn is that there are no drug addicts, beggars, thugs or the like. The difference compared to, for example, Vancouver (where I lived previously) is stark. In public buildings, people leave their coats and bags hanging in the lobby while visiting. Private houses and apartment block yards are not fenced. In my building, I noticed people even leave their bikes unlocked in the bike shed. I have also seen the staff of a coffee stall in a shopping mall going for a break and leaving everything unattended, not worrying that anyone would take anything while the staff is away.

This is not just my personal experience. According to the Numbeo crime index, Estonia has one of the lowest crime rates in the world. Also, comparing drug and property crime stats, for example, Finland has twice as much crime per capita, and places like Vancouver in Canada almost five times more.
I don’t have any clear explanation for why crime is so much lower in Estonia, but some suggest that higher social cohesion and lower levels of welfare contribute to people standing to lose more if they behave antisocially. Compared to Finland, Estonia also more readily jails repeat offenders, and those who are put on trial will experience a swifter court process thanks to simplified legal processes and more efficient governance.
Moving to Estonia is very easy for any EU citizen, in particular if your work is not location-dependent (e.g., remote work or an online business) and you are simply looking for the cleanest and safest environment to live in.
First, check into a hotel in Tallinn, check out various neighborhoods to figure out what area you like (my favorites are Kalaranna, Kalamaja, Noblessner and Volta) and start browsing available apartments in English at kv.ee. Most professionals speak fluent English, so there should not be any difficulty in reaching out to people by email or phone.


The next step is to buy a local prepaid SIM card at e.g., an R-Kiosk or a convenience store as signing up for other matters later on will require an Estonian phone number. Once you have an apartment and e.g., signed a rental agreement, you can register in the population registry online.
After that, you have proof you are a local resident with an address and telephone number in Estonia. With local resident status, you can go to the police station to get a local ID card. Don’t bother scheduling an appointment, just go to the Tammesaare police station in Tallinn, take a queue number and wait. Once it is your turn, they will guide you on how to use the photo booth, fingerprint registration device, and file your application. A few days later you will receive an email confirming whether your application was accepted, and after a few more days, you will get another email notifying you that your ID card has been printed and is available for pick-up at the same location. This will also be your first practical experience of how fast and efficient the government in Estonia is.
Once you have the local ID card, you can use the smart card feature to log into all the government eServices and sort out the rest of the relocation process, such as registering tax residency and getting a family doctor.

After Estonia regained its independence after the fall of the Soviet Union in 1991, the first elected government in 1992 was led by a very progressive 31-year-old Prime Minister Mart Laar, who managed to set up some very good policies and laid the foundation of a society that has evolved well in the decades since. Estonia was very lucky to have people in power in the 1990s who didn’t simply copy what other Western countries were doing, but who tried to think about things from first principles and create Estonia’s own model for efficient and fair governance. As a post-Soviet country, the population had also been vaccinated against overly socialist and unrealistic ideals, and everyone had a healthy distrust of the government’s ability to solve problems and emphasis was placed on people’s liberty to work for themselves as they best see fit. The improvement in living standards over the past 35+ years has also been witnessed by the population, and voting behavior supports keeping the country on the same trajectory.
General living standards still continue to improve as the nominal wage growth sits at around 6%, clearly above the annual inflation rate of about 3%. In 2026, the Estonian economy is expected to grow about 2.4%, which is faster than the EU average. The growth in Estonia is not the result of any accounting tricks - Estonia is part of the euro and can’t print its own currency, nor has it been funding the public sector with excessive debt. With a 24% debt-to-GDP ratio, Estonia consistently ranks as one of the most responsibly managed countries among advanced Western economies.
As wages in Estonia soon catch up with the EU average, and higher defence spending has forced the government to raise taxes in recent years, the economic growth that Estonia has enjoyed for 35+ years since it exited the Soviet Union might slow down a bit in future years. The policies that fueled this growth in living standards, however, are likely to stay.
There is one specific government policy in Estonia’s history that I think should be highlighted in particular. Estonia was very progressive by announcing the Tiigrihüpe (Tiger Leap) program in 1996 with the goal of equipping all schools with computers and teaching all students the basics of programming. This surely had a large influence on why Estonia has so many successful software companies, why the government eServices are so mature that even neighboring countries like Finland are striving to copy the Estonian government’s IT architecture called X-road.
The Tiigrihüpe project was originally suggested in the mid-1990s by Toomas Hendrik Ilves, then ambassador of Estonia to the United States, Canada and Mexico, and later President of Estonia in 2006–2016. While he was a psychologist by education, he was also a self-taught amateur programmer and used his political influence to promote sensible adoption of information technology in both Estonia and the EU.
The history of Estonia has several prominent figures who were not lawyers by profession but engineers, scientists and historians who were very practical in their political decisions, which I think is now reflected in how government processes were formed.
The video below shows how the Estonian government advertises itself and what values they choose to highlight:
Of course, not everything is perfect in Estonia either. The fertility rate of 1.16 in Estonia is very low. This trend is present globally, but in Estonia it is way below the EU average. Also, the service culture is something that needs to improve in Estonia. While services are in general fast and efficient, the attitude of people working in cafes and stores does not reflect a willingness to fill in gaps if the standard process falls short, nor are visitors actively made to feel welcome as individual humans, but are treated as mere process inputs.
However, many of the things listed earlier I think should be studied by policymakers elsewhere. Societies are complex systems and there is of course no guarantee that copying a single policy to another country with different ethnicities, history and ingrained culture would lead to the same policy outcomes. But considering that Estonia is a small country without favorable geography and no natural resources, and that it started out from a place of total chaos, low economic activity and high crime in 1992 to rise to what it is now in 2026, the success it has seen is surely largely a result of good policies, governance and culture that other countries can and should mimic.
“That doesn’t work” [Seth's Blog]
We transferred an idea from engineering to culture, but it’s incomplete.
If you build a watch that doesn’t tell time, it’s fair to say it doesn’t work.
But when a critic says, “that joke didn’t work,” after seeing a comic perform to a raucous audience, what they probably mean is, “that didn’t work for me.”
The problem might not be the comic. It might be the critic.
“It’s not for you,” is a useful, almost essential way to navigate the creation of our cultural work. If you say it too often to the people you were seeking to serve, your work needs improvement. But when you say it to a critic you never intended to please, you’re opening the door to serving the people you do care about.
Jimothy Chalamet [Penny Arcade]
New Comic: Jimothy Chalamet
Making an agile version of a Windows Runtime delegate in C++/WinRT, part 9 [The Old New Thing]
Over half of the time we spent trying to make an agile version of a Windows Runtime delegate in C++/WinRT was dealing with the case of a delegate that declares non-marshalability. But how much does it matter?
I looked at the three major C++ implementations of the Windows Runtime: C++/WinRT, C++/CX, and WRL.
The C++/WinRT implementation
has an optimization for IAgileObject, but
for objects that aren’t agile,
it just goes directly to agile_ref without
checking for INoMarshal. This means that a delegate
that declares non-marshability will always be rejected by C++/WinRT
when used as an event handler.
The C++/CX implementation
lazy-creates the agile reference to the original delegate when the
wrapper is used from a different apartment. If the original
delegate is non-marshalable, it means that the
CO_E_NOTSUPPORTED is produced only when the
wrapper is used in a way that requires a marshalable delegate.
The WRL implementation does not have an optimization for
IAgileObject, although
it mentions it as a possible optimization. It always creates
the agile reference eagerly, which means that if the original
delegate is non-marshalable, it cannot be added to an agile event
source.
Okay, so let’s summarize in a table.
| Event source | C++/WinRT | C++/CX | WRL | Our version | |
|---|---|---|---|---|---|
| single-threaded | multi-threaded | ||||
| Optimize agile delegates | Yes | Yes | N/A | No | Yes |
| Avoid wrapping agile delegates | Yes | No | Never wraps | No | Yes |
| Agile reference creation | Eager | Lazy | Never | Eager | Eager |
| Non-marshalable delegates | Rejected | Allowed if used non-agile-ly |
Allowed (always used non-agile-ly) |
Rejected | Allowed if used non-agile-ly |
Now, maybe you think we are working too hard. (Maybe we are.) In which case you can remove support for whatever cases you feel you don’t need.
The post Making an agile version of a Windows Runtime delegate in C++/WinRT, part 9 appeared first on The Old New Thing.
Breaking Up, p08 [Ctrl+Alt+Del Comic]
The post Breaking Up, p08 appeared first on Ctrl+Alt+Del Comic.
Girl Genius for Friday, July 31, 2026 [Girl Genius]
The Girl Genius comic for Friday, July 31, 2026 has been posted.
Russ Allbery: Review: Painting the Blues in Gretna Green [Planet Debian]
Review: Painting the Blues in Gretna Green, by Linzi Day
| Series: | Midlife Recorder #2 |
| Publisher: | Linzi Day |
| Copyright: | November 2022 |
| ISBN: | 9798360228431 |
| Format: | Kindle |
| Pages: | 577 |
Painting the Blues in Gretna Green is a self-published fantasy novel and the second in the Midlife Recorder series. It picks up immediately after the end of Midlife in Gretna Green. I also read it almost immediately after, so I didn't pay attention to how good the recap of previous events was.
As before, this is urban fantasy except not urban. Day calls it paranormal women's fantasy, which I suppose is as good of a genre label as any. The other book I can think of off-hand that would go into that genre would be Nancy Springer's Larque on the Wing, although it is considerably more literary.
I suspect I'm going to read this whole series and it's going to be impossible to review these books without talking about Niki's job, so I'm not going to treat that as a spoiler. It's fairly well-advertised in the marketing for the book, so that feels justified. If you're particularly averse to any spoilers, though, you may want to stop reading here until you've gotten to the reveal in the first book.
Niki is now officially the Recorder, with the power, advice book, and sentient house to go with it. She's about to face her first test in managing interworld politics: There's something amiss in the world of the Picts. Her allies are dropping hints, there's a petition from a group on the Pict world that she can't make sense of, and although she likes the queen of the Picts, there is a great deal of tension beneath the surface that she doesn't understand. Meanwhile, after the incompetent disaster that she uncovered in the first book, Niki is determined to pick her new staff by her own criteria.
The second book leans even harder into giving Niki both a tangled mess created by previous incompetence and enough power to fix it. Watching that happen is very satisfying, particularly when it involves surprising people who are rather too used to getting their own way.
I was somewhat less convinced that Niki is getting the right training to make the decisions that she's making. Diplomacy and staff management are real skills that one needs to learn, not just wing on vibes and gut instinct. My love of competence porn occasionally wishes that Niki had a bit more structure around her competence. We do at least get a new fictional self-help book on how to rule that contributes the quotes that open each chapter. Not the ethics and management training that I would have chosen, but it's something!
In defense of Niki's technique, it becomes clear in this book that the last few recorders have been far too cautious, conservative, and content with a status quo that involved a minimum of work. One of the delights of this book is that Niki thinks power exists to be used to fix things and is determined to use it, not just sit on it. I had more suspension of disbelief issues with this book than with the first — some of the problems Niki is solving seem far too obvious to have been in stasis for this long while also having this easy of a solution, and the level of political power given to the Recorder is a bit unbelievable — but it is so satisfying to see Niki cajole and bully people into being sensible.
I have no idea if this is intentional on Day's part, but I will not be at all surprised if adult-diagnosed ADHD comes up at some point in this series. The way that Niki's focus jumps, her tendency to veer between focusing on a problem and forgetting about it, and something about the way she switches between trains of thought or misses important context because she's jumping to conclusions is making me wonder. This, to be clear, is not a complaint; I think it makes Niki more relatable and more interesting. It's a good thing that she has a sentient house to serve as her assistant. The glee with which she's delegating any task that involves keeping track of details or following up with other people feels like a bit of an indicator by itself.
I did get a bit frustrated with the plot structure of this book. Niki keeps mentioning that a critical petition submitted to her office makes no sense, but it takes half of this (rather long) book before she finally explains to anyone else, even the reader, what's deficient about it. The excuse within the book is that she's having a rather busy day, but by the third time Niki mentions and then fails to do anything about the petition, I was wishing Day would stop bringing it up until she was ready for that part of the plot.
This, as with a few issues in the previous book, feels partly like an editing problem. There is something joyful in indulgent, sprawling books, but only up to the point where they become repetitive. Painting the Blues was right at that line, and once again I wish someone had helped Day trim about fifty pages out of it.
All that said, and despite having more quibbles with this book than the previous one, this continues to be great fun. It's satisfying wish-fulfillment about fixing long-standing problems and having the power to not have to put up with abusive nonsense and ridiculous bullshit, and I am so here for that. I hope Niki realizes she's eventually going to need more refined skills than a heart-to-heart over wine, but she's learning on the job and I'm happily along for the ride. She's also capable of recognizing skill in other people, and that goes a long way.
Recommended if you liked the first one and are in the mood for another fantasy of "no, we're not going to leave it that way, we're going to fix that right now."
Followed by Ties that Bond in Gretna Green.
Rating: 7 out of 10
Jonathan McDowell: My CPU died [Planet Debian]

I built my current house server back in 2019. It had an upgrade from the original Ryzen 2700 to a 5700G in late 2021, but otherwise is still running with the original setup. Back in November it developed some erratic behaviour (initially manifesting as problems with the TPM, which is ironic as I’ve spent a bunch of time at my day job trying to improve TPM reliability), culminating in unreliable reboots. I had a limited amount of ability to swap parts out, but ultimately decided it was a motherboard issue (thinking perhaps VRM problems), found a replacement locally, and everything seemed fine.
Until May.
At that point I rebooted the machine for a Debian point release, and it failed to come back. Fans would spin, but there was no sign of actual life. I ended up pressing a temporary machine into service (that could at least run the Home Assistant container, and a few other critical bits) while I tried to work out what was wrong. I’d kept the previous motherboard, and still had the Ryzen 2700, so I did a bunch of swaps (and obtained a motherboard buzzer to try and get some indication about whether there were useful beep codes being emitted), and ultimately came to the conclusion that the CPU had died.
I’m not quite clear what happened here. I played it safe and replaced the PSU at the same time, in case that was the original cause back in November and ultimately damaged the CPU, but both old + new motherboards worked just fine with the 2700.
That left a decision about what to do. This previous server was from 2013, so this machine has now lasted longer than that and I could justifiably upgrade. However when I went to look at what the equivalent modern machine would be it’s only a couple of generations later (Zen 5 vs Zen 3), and 64GB RAM alone would have set me back ~ £1k. For not a lot of gain. So I ended up buying a replacement Ryzen 5700G, hopefully allowing me to put off thinking about an upgrade until Zen 6 is out, and RAM prices are saner (though I understand that might take a couple of years).
It’s not the first time I’ve had a faulty PSU be the cause of a dead machine, but it was a pretty frustrating experience.
Microsoft claims it’s going to improve Windows 11’s context menus [OSnews]
When I had to use Windows 11 for a month because you people paid me to do so, the one seemingly small thing that really ground my gears were Windows 11’s terrible right-click (context) menus. They were full of stuff I didn’t put there, slow to open, and in some places, a modern Windows 11 context menu would have its own old Win32 context menu with even more stuff. It seems Microsoft is finally going to fix all of this.
This new compact menu will be much faster and more reliable, as it foregoes needing to load in all the third-party actions that slow it down currently. Additionally, at the Windows Insider Meetup in London, Microsoft showed me a new context menu customization feature coming soon that will let users configure what apps and actions appear in the right-click menu.
↫ Zac Bowden at Windows Central
Look, I know to us non-Windows users this seem like an incredibly small and dumb thing to focus on, but when your operating system is as much of a trashfire as Windows has become, improved context menus are massive improvements that make a meaningful difference. Of course, Microsoft makes these types of promises all the time, so I’ll believe it when I see it.
Urgent: Call on ABC and NBC to stand strong [Richard Stallman's Political Notes]
US citizens: call on ABC & NBC to stand strong against the fascist's bullying.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: Protect Medicaid, submit public comment [Richard Stallman's Political Notes]
US citizens: Protect Medicaid by submitting a public comment by July 31.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
| Feed | RSS | Last fetched | Next fetched after |
|---|---|---|---|
| @ASmartBear | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| a bag of four grapes | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| Ansible | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| Bad Science | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| Black Doggerel | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| Blog - Official site of Stephen Fry | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| Charlie Brooker | The Guardian | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| Charlie's Diary | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| Chasing the Sunset - Comics Only | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| Coding Horror | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| Comics Archive - Spinnyverse | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| Cory Doctorow's craphound.com | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| Cory Doctorow, Author at Boing Boing | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| Ctrl+Alt+Del Comic | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| Cyberunions | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| David Mitchell | The Guardian | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| Deeplinks | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| Diesel Sweeties webcomic by rstevens | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| Dilbert | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| Dork Tower | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| Economics from the Top Down | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| Edmund Finney's Quest to Find the Meaning of Life | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| EFF Action Center | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| Enspiral Tales - Medium | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| Events | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| Falkvinge on Liberty | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| Flipside | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| Flipside | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| Free software jobs | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| Full Frontal Nerdity by Aaron Williams | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| General Protection Fault: Comic Updates | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| George Monbiot | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| Girl Genius | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| Groklaw | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| Grrl Power | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| Hackney Anarchist Group | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| Hackney Solidarity Network | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| http://blog.llvm.org/feeds/posts/default | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| http://calendar.google.com/calendar/feeds/q7s5o02sj8hcam52hutbcofoo4%40group.calendar.google.com/public/basic | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| http://dynamic.boingboing.net/cgi-bin/mt/mt-cp.cgi?__mode=feed&_type=posts&blog_id=1&id=1 | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| http://eng.anarchoblogs.org/feed/atom/ | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| http://feed43.com/3874015735218037.xml | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| http://flatearthnews.net/flatearthnews.net/blogfeed | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| http://fulltextrssfeed.com/ | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| http://london.indymedia.org/articles.rss | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| http://pipes.yahoo.com/pipes/pipe.run?_id=ad0530218c055aa302f7e0e84d5d6515&_render=rss | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| http://planet.gridpp.ac.uk/atom.xml | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| http://shirky.com/weblog/feed/atom/ | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| http://thecommune.co.uk/feed/ | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| http://theness.com/roguesgallery/feed/ | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| http://www.airshipentertainment.com/buck/buckcomic/buck.rss | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| http://www.airshipentertainment.com/growf/growfcomic/growf.rss | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| http://www.airshipentertainment.com/myth/mythcomic/myth.rss | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| http://www.baen.com/baenebooks | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| http://www.feedsapi.com/makefulltextfeed.php?url=http%3A%2F%2Fwww.somethingpositive.net%2Fsp.xml&what=auto&key=&max=7&links=preserve&exc=&privacy=I+accept | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| http://www.godhatesastronauts.com/feed/ | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| http://www.tinycat.co.uk/feed/ | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| https://anarchism.pageabode.com/blogs/anarcho/feed/ | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| https://broodhollow.krisstraub.comfeed/ | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| https://debian-administration.org/atom.xml | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| https://elitetheatre.org/ | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| https://feeds.feedburner.com/Starslip | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| https://feeds2.feedburner.com/GeekEtiquette?format=xml | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| https://hackbloc.org/rss.xml | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| https://kajafoglio.livejournal.com/data/atom/ | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| https://philfoglio.livejournal.com/data/atom/ | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| https://pixietrixcomix.com/eerie-cutiescomic.rss | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| https://pixietrixcomix.com/menage-a-3/comic.rss | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| https://propertyistheft.wordpress.com/feed/ | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| https://requiem.seraph-inn.com/updates.rss | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| https://studiofoglio.livejournal.com/data/atom/ | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| https://thecommandline.net/feed/ | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| https://torrentfreak.com/subscriptions/ | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| https://web.randi.org/?format=feed&type=rss | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| https://www.dcscience.net/feed/medium.co | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| https://www.DropCatch.com/domain/steampunkmagazine.com | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| https://www.DropCatch.com/domain/ubuntuweblogs.org | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| https://www.DropCatch.com/redirect/?domain=DyingAlone.net | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| https://www.freedompress.org.uk:443/news/feed/ | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| https://www.goblinscomic.com/category/comics/feed/ | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| https://www.loomio.com/blog/feed/ | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| https://www.newstatesman.com/feeds/blogs/laurie-penny.rss | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| https://www.patreon.com/graveyardgreg/posts/comic.rss | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| https://www.rightmove.co.uk/rss/property-for-sale/find.html?locationIdentifier=REGION^876&maxPrice=240000&minBedrooms=2&displayPropertyType=houses&oldDisplayPropertyType=houses&primaryDisplayPropertyType=houses&oldPrimaryDisplayPropertyType=houses&numberOfPropertiesPerPage=24 | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| https://x.com/statuses/user_timeline/22724360.rss | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| Humble Bundle Blog | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| I, Cringely | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| Irregular Webcomic! | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| Joel on Software | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| Judith Proctor's Journal | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| Krebs on Security | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| Lambda the Ultimate - Programming Languages Weblog | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| Looking For Group | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| LWN.net | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| Mimi and Eunice | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| Neil Gaiman's Journal | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| Nina Paley | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| O Abnormal – Scifi/Fantasy Artist | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| Oglaf! -- Comics. Often dirty. | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| Oh Joy Sex Toy | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| Order of the Stick | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| Original Fiction Archives - Reactor | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| OSnews | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| Paul Graham: Unofficial RSS Feed | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| Penny Arcade | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| Penny Red | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| PHD Comics | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| Phil's blog | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| Planet Debian | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| Planet GNU | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| Planet Lisp | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| Pluralistic: Daily links from Cory Doctorow | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| PS238 by Aaron Williams | XML | 20:56, Tuesday, 04 August | 21:44, Tuesday, 04 August |
| QC RSS v2 | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| Radar | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| RevK®'s ramblings | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| Richard Stallman's Political Notes | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| Scenes From A Multiverse | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| Schneier on Security | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| SCHNEWS.ORG.UK | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| Scripting News | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| Seth's Blog | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| Skin Horse | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| Tales From the Riverbank | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| The Adventures of Dr. McNinja | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| The Bumpycat sat on the mat | XML | 20:28, Tuesday, 04 August | 21:08, Tuesday, 04 August |
| The Daily WTF | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| The Monochrome Mob | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| The Non-Adventures of Wonderella | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| The Old New Thing | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| The Open Source Grid Engine Blog | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| The Stranger | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| towerhamletsalarm | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| Twokinds | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| UK Indymedia Features | XML | 21:07, Tuesday, 04 August | 21:49, Tuesday, 04 August |
| Uploads from ne11y | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| Uploads from piasladic | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |
| Use Sword on Monster | XML | 20:49, Tuesday, 04 August | 21:36, Tuesday, 04 August |
| Wayward Sons: Legends - Sci-Fi Full Page Webcomic - Updates Daily | XML | 20:28, Tuesday, 04 August | 21:14, Tuesday, 04 August |
| what if? | XML | 20:35, Tuesday, 04 August | 21:16, Tuesday, 04 August |
| Whatever | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| Whitechapel Anarchist Group | XML | 20:21, Tuesday, 04 August | 21:10, Tuesday, 04 August |
| WIL WHEATON dot NET | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| wish | XML | 20:42, Tuesday, 04 August | 21:27, Tuesday, 04 August |
| Writing the Bright Fantastic | XML | 20:42, Tuesday, 04 August | 21:26, Tuesday, 04 August |
| xkcd.com | XML | 21:00, Tuesday, 04 August | 21:43, Tuesday, 04 August |