Pluralistic: On the sincerity of AI bosses (17 Sep 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

The word "fascist" comes from the Latin fasces, a bundle of sticks; the symbology here is that a single twig is weak and brittle, but bundled together, many twigs are strong. It's a sound political theory, because in politics, coalitions are everything:
https://pluralistic.net/2025/01/06/how-the-sausage-gets-made/#governing-is-harder
The problem with fascism isn't the idea of bundling together different groups: it's the incoherence of that bundle. The fascist coalition is a collection of people who want mutually incompatible things. When one part of the fascist coalition wins (say, if Nick Fuentes's neo-Nazis triumph), the other faction loses (Fuentes gets to murder Stephen Miller and turn his skin into a lampshade). The fascist coalition is a coalition of enemies who all hate each other and dream of exterminating one another, held in check by a strongman who uses flattery, favors and threats to keep a lid clamped tight on this pressure-cooker:
https://pluralistic.net/2025/07/29/bondi-and-domination/#superjove
In this regard, fascism is simply one end of the continuum of conservative movements, which are always about finding a way to "get turkeys to vote for Christmas." That's because, at root, conservativism is the belief that some minority (rich people, white people, bosses, men, etc) were born to rule and everyone else was born to be ruled over:
https://pluralistic.net/2026/07/08/wilhoitian/#human-rights-v-property-rights
By definition, "a minority that was born to rule" can't win an election, because they are a minority. Conservatives win electoral races by convincing people they intend to oppress, cheat and maim to vote for them through appeals to fear and hatred (racism, transphobia, sexism, anti-communism, etc):
https://pluralistic.net/2022/03/09/turkeys-voting-for-christmas/#culture-wars
Conservative political victories are always followed by economic misery for the conservative base, because the senior partners in the conservative coalition are the bosses who get richer by making workers poorer. Conservative rulers try to offset this with spectacular acts of cruelty against disfavored minorities, but this tactic only carries so far. Eventually, the electorate notices that despite terrorizing migrants and trans people, diesel is now $10/gallon and the guy responsible is now $1.4b richer than he was before the election:
https://www.bbc.com/news/articles/cvgmv98ez3zo
Workers and bosses aren't the only fracture line in the conservative coalition. Within conservativism, there are leaders who want mutually incompatible things and abhor one another: the white nationalists hate the Zionists; the misogynists hate the TERFs; the imperialists hate the isolationists:
https://pluralistic.net/2024/07/14/fracture-lines/#disassembly-manual
These fracture lines can be papered over while things are good, but they crack when things go wrong, and this is even more true of fascist movements than it is of other conservative coalitions.
This is true of all fascists, so it's true of technofascists, too. The best-ever reference work on technofascism was just published: Naomi Klein and Astra Taylor's End-Times Fascism, which unpacks the apocalyptic ideology that dominates Silicon Valley, especially the AI cultists:
https://naomiklein.org/end-times-fascism/
In a recent interview about the book with the QAA podcast, Astra Taylor explained how the contradictions of the technofascist movement are to be expected, because fascism is always an "incoherent bundle":
https://soundcloud.com/qanonanonymous/end-times-fascism-feat-naomi
Understanding technofascism's inherent incoherence is vital to making sense of the chaos roiling the AI cult at this moment, wherein you have AI people insisting that there must be a moratorium on AI development lest the word-guessing program awaken and devour the human race. This week on the Better Offline podcast, Ed Zitron discussed the outlandish, science-fiction inspired cult beliefs that dominate AI boardrooms with Adam Becker and Cal Newport:
https://www.youtube.com/watch?v=0oVSnaINJ30
Becker is well-placed to discuss this. Like the hosts of the QAA podcast, he started paying close attention to the bizarre beliefs of conspiratorialists long before the rest of us realized that no matter how preposterous their certainty about the imminent machine intelligence Singularity was, these beliefs are sincerely held by some very wealthy and driven people. Becker's 2025 book More Everything Forever is a tremendous field guide to these delusions and their profound philosophical and technical deficits:
https://pluralistic.net/2025/04/22/vinges-bastards/#cyberpunk-is-a-warning-not-a-suggestion
In the interview, Newport dismisses the theory that the warnings about imminent AI apocalypse are self-serving criti-hype intended to serve as both marketing pitch and regulatory capture gambit, through which the hyperscalers get the government to step in to interrupt the beggar-thy-neighbor doom-loop:
https://pluralistic.net/2026/09/16/beggar-thy-neighbor/#red-queens-race
Rather, Newport says that these people sincerely believe that they are about to immanentize the eschaton and are pants-wettingly terrified about the AI god they will conjure forth any day now. He makes a good case for this, pointing to the long history of words and deeds on the part of various AI bosses that suggest that they are true believers who are genuinely high on their own supply.
I don't doubt that there are sincere believers in the AI technofascist coalition, but that does not preclude the possibility that they share their boardrooms and executive rows with cynics for whom this is all a shuck, a scare-story to convince the rubes that their modestly useful utility software is really a nascent "superintelligence" and thus capable of replacing all their workers, which means they should fire all those workers and start sending their salaries to AI companies.
This is an example of one of those "incoherent fascist bundles." Just as Mike Pence (a misogynist Christofascist) was happy to share the White House with Trump (a godless pedophile rapist), AI companies can and do thrive by filling their executive ranks with Singularity-crazed maniacs and sharp operators who are happy to spread this superstitious nonsense if it helps them pump up their stock swindle.
Each group thinks they're using the other one, and they are…up to a point. When it comes to the current AI nonsense, that point came when Nvidia's best customers started to demand that everyone stop buying Nvidia's products, whereupon Nvidia's CEO suddenly remembered that his chips weren't being used to make god, but rather, to power regular-degular "cloud software":
https://cxotoday.com/governance/nvidias-jensen-huang-crosses-swords-with-ai-labs-over-regulation/
When it comes to technofascists (and all fascists) this kind of division isn't an exception, it's the rule. The billionaires behind AI are split between solipsists who don't believe other people are any more real than bots; and cynics who think that bosses will be easy marks for a sales pitch that sees them replacing mouthy workers with pliable chatbots:
https://pluralistic.net/2026/08/03/andor/#either
To be a senior member of the fascist coalition, you must be capable of both sincere belief while not openly dismissing your fellow senior members' contradictory sincere beliefs. Behind closed doors, they may make fun of each other (or fantasize about murdering one another), and they may periodically erupt into plots to oust one another from the coalition. But every one of them must be able to go along to get along…
Most of the time.
Until they don't.

Rethinking space opera https://www.antipope.org/charlie/blog-static/2026/09/rethinking-space-opera.html
EU wants Canada to become ‘associate member,’ von der Leyen says https://www.politico.eu/article/eu-wants-canada-to-become-associate-member-von-der-leyen-says/
The Trump Administration Creates a Monopolization Machine https://prospect.org/2026/09/16/trump-administration-creates-monopolization-machine-small-business/
a bad tool always blames the workman https://backofmind.substack.com/p/a-bad-tool-always-blames-the-workman
#25yrsago 9/11 v spam https://memex.craphound.com/2001/09/17/through-most-of-last-week/
#25yrsago PalmOS picture of the WTC collapse https://web.archive.org/web/20010920145653/https://ne.nikkeibp.co.jp/english/2001/09/0914pda_watch.html
#25yrsago Wifi emanating from the WTC rubble https://web.archive.org/web/20010916231834/http://dailynews.yahoo.com/h/nm/20010916/tc/attack_wert_dc_2.html
#15yrsago Silvio Berlusconi prostitution-ring wiretaps: sex with eight women in one night, “I’m only prime minister in my spare time” https://www.theguardian.com/world/2011/sep/18/silvio-berlusconi-wiretaps-sex-parties
#15yrsago Tesco threatens journalist with arrest for writing down prices https://www.theguardian.com/money/blog/2011/sep/16/tesco-shopping-supermarket-prices-check-writing
#1yrago AI psychosis and the warped mirror https://pluralistic.net/2025/09/17/automating-gang-stalking-delusion/#paranoid-androids
#1yrago Conspiratorialism's causal chain https://pluralistic.net/2025/09/17/cause-and-effect/#things-have-causes

Berkeley: Celebrating 25 Years at the Digital Frontier
(Samuelson Clinic), Sep 24
https://www.law.berkeley.edu/experiential/clinics/samuelson-law-technology-public-policy-clinic/samuelson-25th-anniversary-celebration/
Edmonton: Elbows Up (Edmonton Public Library), Sep 28
https://www.epl.ca/blogs/post/elbows-up-with-cory-doctorow/
Boston: The Post-American Internet: Possibilities for a new
internet created by an American Hermit Kingdom (MIT Media Lab), Sep
30
https://www.media.mit.edu/events/the-post-american-internet-possibilities-for-a-new-internet-created-by-an-american-hermit-kingdom/
Boston: The Paradox of Enshittification and Reverse Centaurs
(Harvard Berkman Klein), Sep 30
https://cyber.harvard.edu/events/running-harder-falling-faster-paradox-enshittification-and-reverse-centaurs
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Hudson, OH: Hudson Library, Oct 7
https://engagedpatrons.org/EventsExtended.cfm?SiteID=3850&EventID=596952&PK=
Calgary: Wordfest, Oct 8
https://wordfest.com/2026/show/wordfest-presents-cory-doctorow-2026/
Winnipeg: McNally Robinson, Oct 9
https://www.mcnallyrobinson.com/event-18991/An-Evening-with-Cory-Doctorow
Vancouver: Read, Resist, Repair, Rejoice (Vancouver Writers
Festival), Oct 19
https://writersfest.bc.ca/festival-event-2026/01
Victoria: Munro's Books, Oct 20
https://www.munrobooks.com/events/6113620261020
Vancouver: Life After AI (Vancouver Writers Festival), Oct
22
https://writersfest.bc.ca/festival-event-2026/46
Ottawa: Life After AI (Ottawa Writers Festival), Oct 24
https://writersfestival.org/event/life-after-ai
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
Montreal: World Science Fiction Convention, Sep 2-6
https://montreal2027.ca/en
Are 'AI Apocalypse' Warnings Just Marketing? (What's Left)
https://www.youtube.com/watch?v=IXd9HwIE5bo
The Real AI Threat Isn’t What You’ve Been Told (The
Tea with Myriam François)
https://www.youtube.com/watch?v=Vc8It00fRsA
Fascists may come after the AI bubble bursts (You&AI)
https://www.youtube.com/watch?v=J2WN64aQeYQ
What Would a Normal Person Do (Trashfuture)
https://www.patreon.com/trashfuture/posts/what-would-do-169247456
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
Intended Texas border wall [Richard Stallman's Political Notes]
The intended Texas border wall, purely for completeness' sake, will extend over an area of cliffs and come damagingly close to ancient rock art.
I think it is an exaggeration to compare rock art to "books". To suppose that this rock art image has a precise message encoded in little details, as writing would have, has no factual basis that I know of.
Nonetheless, ancient rock art is precious, because it may convey a not-so-detailed message that would nonetheless be amazing to understand, if someday we can.
Israeli company accused of interfering in Colombia election [Richard Stallman's Political Notes]
President Petro of Colombia accused the Israeli company Blackcore of interfering in Colombia's presidential election.
I am pretty sure that the US made some sort of vicious secret intervention, because the newly elected? president is a magat.
Finland progress towards eliminating homelessness [Richard Stallman's Political Notes]
Finland made great progress towards eliminating homelessness by giving people houses which they could feel was home. Alas, right-wing government has cut some of the spending and is driving homelessness back up.
Supposed Intelligence safety [Richard Stallman's Political Notes]
The companies that develop Supposed Intelligence (specifically, LLMs) want us to put them in charge of making the systems "safe", by giving them absolute control over what the systems will do (and what they won't do).
The systems are really dangerous, but we cannot trust the companies that develop them to protect us from them. Their interest is to mix more and more subjugation of the public into any protection of the public.
Historically, whenever companies get power over what people's computing facilities can do, they use it against us, building malicious functionalities, designed to benefit them, into the software they invite us to use.
President of Ecuador turning country into dictatorship [Richard Stallman's Political Notes]
The president of Ecuador is turning the country into a dictatorship by banning parties that don't support him.
Russell Coker: Nheko DBUS [Planet Debian]
Nheko is my current favourite client for the Matrix IM system, which is my favourite IM system.
Matrix is an open system with end to end encryption and Nheko is free software and runs well on Linux desktops and phones.
The Nheko client allows interaction with dbus which could be good for automating things, EG you could change the status message when unlocking the screen. I’m documenting the most useful ones here because they don’t seem to be documented anywhere else. I have filed a Debian bug about the activate room option not working. The qdbus6 program is the QT6 version of the dbus command-line query program, there are a range of other programs which work in much the same way.
# list all interfaces qdbus6 im.nheko.Nheko / # get the version of Nheko qdbus6 im.nheko.Nheko / im.nheko.Nheko.nhekoVersion # list rooms in a dump of the data structures (pity it's not json or something) qdbus6 --literal im.nheko.Nheko / im.nheko.Nheko.rooms|less # join a room qdbus6 im.nheko.Nheko / im.nheko.Nheko.joinRoom "#flounder-random:luv.asn.au" # supposed to activate a room but doesn't qdbus6 im.nheko.Nheko / im.nheko.Nheko.activateRoom "#flounder-random:luv.asn.au" # set the status qdbus6 im.nheko.Nheko / im.nheko.Nheko.setStatusMessage "whatever" # get the status qdbus6 im.nheko.Nheko / im.nheko.Nheko.statusMessage
Here are a couple of examples of using other dbus clients to get similar results. Note that the difference between the Debian version of Nheko (and maybe other recent versions) and what LLMs return for usage examples is that Debian has “/” as the path while the examples have “/im/nheko/Nheko”.
# list rooms via gdbus gdbus call --session --dest im.nheko.Nheko --object-path / --method im.nheko.Nheko.rooms # get status via dbus-send dbus-send --session --print-reply --type=method_call --dest=im.nheko.Nheko / im.nheko.Nheko.statusMessage
[$] LWN.net Weekly Edition for September 17, 2026 [LWN.net]
Inside this week's LWN.net Weekly Edition:
Don't Do Imprisonment [QC RSS v2]

it's bad in most cases
BTW, this blog is one of those periods where there are a few mind bombs every freaking day. What's a Mind Bomb? An idea that's so strange or powerful that it explodes in your mind. And that's a good thing!
Victory! Appeals Court Rejects Expansive New Copyright Claim [Deeplinks]
The U.S. Court of Appeals for the Ninth Circuit handed internet users and programmers a big win today, by rejecting an attempt to stretch a narrow provision of the Digital Millennium Copyright Act (DMCA) into a new source of copyright liability.
The case involves Section 1202 of the DMCA, which prohibits intentionally removing copyright management information (CMI) like an author’s name or a copyright notice, from a copyrighted work. Open AI and Microsoft used code from Github as part of the training data for their LLMs, along with billions of other works. A group of anonymous Github contributors sued, alleging the new code coming out of these LLMs was similar to theirs—but with the CMI stripped out.
The Ninth Circuit correctly agreed with what we said in our brief: removing copyright information from a copyrighted work is fundamentally different from creating a new work that didn't have CMI in the first place. Section 1202 of the Digital Millennium Copyright Act was intended to serve as a backstop for traditional copyrights in the digital age—not to create a new, more expansive right to inhibit otherwise non-infringing uses.
As we also explained, accepting the Does’ theory would have created a brand-new source of liability for otherwise perfectly lawful activities, undermining creativity and innovation far beyond the specific context of AI development. Copyright holders would be able to file costly lawsuits against all kinds of legitimate users, such as artists making remixes based on older works, teachers adapting works for a classroom presentation, engineers reverse engineering code to understand it better, and search engines that help us all navigate the web. The risks would have fallen especially hard on independent software developers and other small creators. Large companies can afford to litigate these claims in federal court for years, if necessary. But an independent programmer facing massive statutory damages may simply have to settle, even when their underlying use is completely lawful. That’s why EFF fights to make sure courts don’t expand copyright beyond what Congress authorized.
Copyright law still protects programmers when their work is unlawfully copied. They can still bring copyright infringement claims if someone uses a model to reproduce their code. Additionally, the plaintiffs’ contract claims against the AI companies are still in play. The specific holding here was narrow but important: that the absence of copyright information from a new work does not mean, by itself, that someone illegally removed it.
That’s the correct result. New technologies will keep raising hard questions about copyright. Courts should answer those questions by applying the rights that Congress actually authorized, not by inventing new rights that could harm expression and lawful use for everyone.
Additional Reading:
WordPress has a product that could be shaped into a Substack
competitor. With a beautiful user interface for writing. WordPress
is its OS, but most users never see it, the same way most web users
never see the command line. But technical users can get under the
hood and tweak things. And unlike Substack, it lets their users
write with different editors, thus forming a coral
reef for a new platform. Wordpress could be the OS the web
never had. I still believe this as I see Automattic and
WordPress flail. If we were starting a new future for the web, no
one would have time for corporate intrigue. Look at how far from
the idea of blogging we've strayed. How far should this go before I
comment? Well, I decided it's time.
What's Wrong with GitHub? [Planet GNU]
A new article by Jacob Bachmeyer and Richard Stallman
to answer the question, What's Wrong with GitHub?
has been published at https://www.gnu.o
... -with-github.html
Software developers, the GNU Project urges you to avoid
hosting your repositories on GitHub. This is to avoid
being on the receiving end of harmful practices, and
avoid leading others to be victims too. This article
focuses on a few of GitHub's worst problems, and the
wrongs and harm they can do.
Join us, we're hiring! [Planet GNU]
We are looking for two new colleagues — come and make a global impact!
just a couple of things [WIL WHEATON dot NET]
And I have, again, fallen into a trap where I only post long essays to my blog that take days or longer to write. Oh, so many drafts that really go nowhere, because I wasn’t writing to tell a story, I was writing to have something to post. And it was shit, all of it.
That’s okay. Sometimes we have to remember why we do this, and more importantly, why we don’t do it, what stops us, and why. I have some idea, and I think I’m just going to go ahead and post a thing in a place that isn’t controlled by an evil algorithm.
So today, I just wanted to share a couple things that I’m excited about. I hope you’ll get excited about them, too.
This Saturday is the triumphant return of Wil WheatCon with Wil Wheaton 2: 2Wheat 2Con. I had such a wonderful time when we did this a few months ago. Requests to do it again started pouring in before we were even finished, and I’m just so excited to bring it back. If this one hits like the first one does, I’m going to be so happy.
I’ve been working on It’s Storytime a LOT, reviewing submissions and interviewing authors, as well as narrating the stories. We have some plans in place to secure the future of the show! I’m still not making anything from it (the creator is always the only one who doesn’t get paid), and I could not care less. I love that I’m doing good work that is meaningful to a large and growing audience who trust me with their time and attention, especially in the midst of the horrors.
A new episode dropped today, The Glass City, by AnaMaria Curtis. It’s a story about loneliness that was extremely relatable. It is in all the usual places. You can start here if you want.
Tomorrow, I’m doing a Reddit AMA to promote the upcoming Stand By Me Live shows in Louisville and Dayton, Wil WheatCon2: 2Wheat 2Con, It’s Storytime, Conludo, and Rampart. We always stay focused on Rampart.
My two Spacedads, Johnathan Frakes and Brent Spiner, have a podcast together. My episode dropped today, so if you want to see three grown men who love each other hang out and talk about the things they love, now you know.
I’m Wil Wheaton, and I write this blog. If you’d like to get my posts delivered to your inbox, here’s the thing:
GNOME 51 has been released, with a whole slew of new features and improvements. Most notably, at least in my experience, will be the work done on GNOME’s graphics stack, which seems to stutter and jitter more than KDE’s on the same hardware – at least in my experience. In particular, GNOME’s compositor, Mutter, has improved frame scheduling for smoother animations, even under load. This hopefully addresses the stutters I generally experience when using GNOME.
They’ve also done a lot of work on the Settings, Maps, Calendar, Web, and other applications. Of note to many will be the array of improvements to GNOME’s file manager, including better performance, although I doubt it will convince those of us who aren’t particular fans of Nautilus in general. They’ve also improved the remote desktop experience by, among other things, adding support for smart cards and improving support for Kerberos.
GNOME 51 will make its way to your distribution of choice soon enough.
Ubuntu 26.10 completes transition to Rust-based coreutils [OSnews]
Ubuntu has been replacing core utilities with Rust rewrites, and it’s now completed the process.
cp,mvandrmwere held back on their GNU versions in Ubuntu 26.04 LTS due to a crop of TOCTOU (time-of-check to time-of-use) issues that needed to be fixed in theuutilsversions.With those issues resolved upstream, Ubuntu 26.10 finishes the job. The ‘Stonking Stingray’ ships a full set of Rust core utilities, which encompasses common command-line tools like
↫ Joey Sneddon at OMG! Ubuntuls,cat,chmodanddu.
I’m definitely not qualified enough to make any useful remarks about this, but the idea of replacing such foundational, battle-tested utilities with brand new ones, even when written in a memory-safe language, does make feel a little hesitant. Still, at least this way Ubuntu users can work out any issues so that if and when other distributions – like the one I use, Fedora – follows suit.
The terrible menu bar in the Windows 11 Notepad [OSnews]
When I used Windows for a month because you people paid me to do so, the utter lack of consistency in the way applications and the operating system itself looks, feels, and behaves was a major sticking point. It turns out, though, that I was only scratching the surface of just how bad things really are on Windows. Case in point: the new WinUI Notepad application that replaced the classic Win32 one. I had no idea just how bad it really is.
It’s been seven weeks since I last complained about something in Windows on this blog. That feels like too long, so here’s a post about menus – specifically, the menu bar in the modern version of Notepad in Windows 11.
That menu bar has, unfortunately, quite a few regressions compared to the menu bar in the old Win32 version of Notepad.
↫ Reupen Shah
I’m not going to spoil any of it, because there’s no way you’d believe any of it without the videos Shah provides. I’m aghast.
A Blue Line To A Cuck Chair [Penny Arcade]
Before, Gorbiriel lamented that he had to wait longer than reviewers to be disappointed. Now he has begun to lap at that darkwine, drawing from it a dark strength. Or… rage, at least. He plays games for the Art, in the way some do things for the 'gram. The art is basically killing him.
Tim Curry as the Pirate King [Judith Proctor's Journal]
The picture quality isn't brilliant, but his voice!
And the sheer exuberance of his performance!
Even if you're not a Gilbert and Sullivan fan, you'll probably
enjoy this:
comments
The Big Idea: Joanne Merriam [Whatever]

What if the “happily ever after” ending the author gave you doesn’t really seem all that happy? If you’re author Joanne Merriam, you take matters into your own hands and retell the story, which resulted in her newest novel, Aether and Ego.
JOANNE MERRIAM:
Johannes Kepler and Shonda Rimes are responsible for the existence of my novel.
In the months before I began writing Aether and Ego, I started on and then discarded a number of ideas for the novel I suddenly had the time to write. I had just moved back to Canada, and had about a year’s worth of savings to live on while we waited for my American partner’s permanent residency status to come through. My parents put us up during that time so I wouldn’t run through those savings too quickly. One of the books I started and discarded, I ended up coming back to (I’m working on it now) but most of the ideas I had just didn’t gel.
Then I happened to read a quote from Kepler that forms one of the two epigraphs to the novel: “Ships and sails proper for the heavenly air should be fashioned. Then, there will also be people, who do not shrink from the dreary vastness of space.” He wrote that in correspondence to Galileo Galilei in 1610, and somebody put it in a meme with a frigate flying through clouds in 2024 (I later found it confirmed as a real quote in The Atlantic). I was watching the second season of Bridgerton with my mother when I scrolled past it, and the idea of writing about Regency space travel was born.
Now, setting a book in space with 1820s-era technology and knowledge is a little foolhardy. They didn’t have the knowledge or technology. In real life these people all suffocate if they didn’t die on the launching pad. Or the ship simply breaks apart, scattering debris across the sky to glitter like falling stars over England’s celebrations of the crowning of George IV. Scientific purists won’t like the way I handwaved away the impossibility of having an airtight ship (Charles Babbage invents an air-making machine). A friend who is far less willing to suspend his disbelief than I am asked me if I had trouble sleeping at night, worrying about all of this.
And I did! But it wasn’t the hollow-eyed guilty twisting of sheets I think he imagined. I would wake up thinking things like “gum elastic! that’s a thing, right? can that help their spacesuits?” (yes) and “oh no, did they even have bicycles in 1821?” (almost but not really) and sneak downstairs to write a paragraph or two before going back to bed, and sometimes getting lost in research rabbit holes until sun-up.
In many ways, they were so close to having the ability to travel to what they thought was the aether, and I enjoyed the challenge of making this space fantasy (in the Jules Verne sense) plausible. I thought it was important that readers not be distracted too much by questions about how the ship can move through space, but I was far more interested in how an essentially frontier civilization oriented toward a technological survival would alter the roles of women, and accordingly, even more research went into how people lived at the time and how that might have changed on my ship. What did they eat? When could a woman be alone with a man without scandal? Where would they get the fibers to weave fabrics? And so on.
The best part of writing the book was giving happily-ever-afters to the characters Jane Austen used as object lessons for the plight of women in Georgian society. I have always loved Austen’s wit, her piercing observations, and most of all her radical ideas, like that class shouldn’t matter so much, and women are people, and embarrassment is good for the soul. But I wasn’t writing a sly critique of society’s treatment of women (that’s my next book), so I was free to save Lydia and Charlotte from their imprudent matches and Mrs. Bennet from herself.
I didn’t extend that kindness to absolutely every character—one of principals gets killed off, for example—but I wanted to write a gentle book as an escape from the times we find ourselves in. Because everybody deserves consideration and happiness. Even if they are silly or inappropriate or plain or otherwise don’t conform to what society expects of them.
(And finally, though I hate that this even needs to be said, no AI was used at any stage of the writing of the book!)
Aether and Ego: Amazon|Barnes & Noble|Bookshop|Goodreads|Indie Bookstores|Powell’s
Author’s Socials: Website|Bluesky|Facebook|Instagram|Mastodon
Architecting for the Knowledge You Can’t Capture [Radar]
Every knowledge program seems to begin with the same request. A senior engineer is leaving in six weeks, and someone asks her to document the process she’s carried for years.
She returns a clean flowchart of the happy path. The drawing is accurate and may even be elegant. It leaves out the thresholds she watches, the conditions that make the standard procedure unsafe, and the supplier whose parts fail in humid weather. She doesn’t think of those judgments as separate knowledge. After years on the job, they feel obvious.
Six months later, a production line goes down and the knowledge base can’t explain what to do. The interview took place as per the process. Its transcript was chunked, embedded, and indexed, so the search returns the relevant passage quickly. The passage still can’t answer the question because no one asked the engineer to explain the judgment behind the procedure.
That gap now limits many enterprise AI programs. Organizations continue to improve retrieval over collections that omit some of their most valuable operating knowledge. Better ranking can help people find what was recorded; it can’t recover the expertise that never entered the collection.
Michael Polanyi gave the problem its durable formulation in 1966: “We can know more than we can tell.” In The Tacit Dimension, he argued that competence depends on skill, perception, and judgment that resist full explanation, even when an expert sincerely tries to teach them.
In companies, tacit knowledge usually appears in three forms. Elicitable knowledge remains unspoken because nobody has asked a precise enough question, or because an expert assumes that everyone sees what she sees. Perceptual knowledge lives in trained attention: An engineer hears a bearing begin to fail, or a nurse notices that a patient looks wrong before a monitor changes. Collective knowledge resides in a team’s habits, standards, and shared sense of what a sound decision looks like in that organization. Each form requires a different method of transfer.
Preventive judgment creates another difficulty for the architect. A failure produces a ticket, an incident report, and a trail of messages. An experienced operator who quietly avoids a known failure mode on a Friday afternoon produces none of those records. The useful outcome is the absence of an event, so the data pipeline receives no trace of the decision that produced it.
Machine learning can infer rules that people struggle to articulate, provided the model sees enough representative examples. It’s difficult to find enough examples of rare expertise for training. A company may have only a handful of unusual incidents and one person who has learned, over decades, how to read them.
David Autor described this limit as “Polanyi’s paradox”: Many of the tasks that are hardest to automate depend on rules we can’t state. Modern machine learning works around the paradox by learning from examples, but the workaround weakens when examples are scarce. Fine-tuning can teach a model the company’s vocabulary and document formats. It can’t reconstruct decisions that left no data.
At the same time, the economics have changed. Much of a field’s documented best practice now appears in frontier-model training data and is available to competitors at roughly the same price and quality. The more widely explicit knowledge circulates, the more a company’s advantage depends on local judgment: the exceptions, thresholds, relationships, and practiced responses that its people have accumulated.
That makes elicitation an architectural concern rather than an offboarding chore. The organization needs a repeatable way to surface the knowledge that can be expressed, a route for the expertise that must be demonstrated, and enough humility to distinguish the two.
The central design question is straightforward: Which follow-up would prompt an expert to say the missing judgment aloud? The quality of the interview sets the ceiling for the knowledge base. The index determines how quickly someone can reach the resulting material.
Interviews can be made more reliable even though judgment itself remains highly personal. An expert may know that a particular supplier fails in humid weather. The interviewing protocol doesn’t need to possess that knowledge in advance; it needs to notice a phrase such as “we escalate if it looks bad” and ask the expert to define “bad” in observable terms.
Expert explanations tend to become vague in four places. An effective interview protocol asks targeted questions about each one:
These questions uncover the operational detail that runbooks often lack. They also identify a narrow, useful role for a language model during the interview: proposing the next question that turns a general statement into a usable rule. I’ve been building an open source toolkit, ExpertTrace, around that protocol.
The value appears in the difference between what an expert volunteers and what the same expert confirms after one focused follow-up. Consider a typical first answer:
We review high-risk use cases before deployment. If the risk seems significant, we escalate to the governance council.
The statement will embed cleanly and retrieve for a relevant query, but a new employee still cannot act on it. “Seems significant” supplies no decision criterion. A targeted follow-up produces something much more useful:
Escalation to the council is required when the use case touches employment, credit, or health decisions, or when model output reaches a customer without human review. Predeployment review is skipped for internal-only tools with no personal data, which is the exception people get wrong most often. If we cannot identify a named accountable owner, the review does not proceed, regardless of risk tier.
The second answer takes little additional time, yet it contains a decision rule, an exception, a recurring failure pattern, and a blocking condition. It can guide a real dispute instead of merely mentioning the subject.
The protocol needs guardrails. Limit the number of follow-ups; a long interrogation exhausts the expert and eventually produces agreeable noise. Keep the model focused on generating questions, and separate that task from compiling and validating the answers. An expert’s statement belongs in the record with its provenance and context. Whether the statement is accurate requires independent review.
Elicitation is one part of a larger knowledge system. A tacit-aware architecture has four planes—capture, representation, serving, and transmission and each plane addresses a different failure in the movement of expertise. Figure 1 shows how the four planes work together and which forms of tacit knowledge each can reach.
Figure 1. A tacit-aware knowledge layer: Four
planes mapped to the kinds of knowledge each can reach.
In the capture plane, structured interviews, incident reconstruction, decision journals, and observation collect more than polished procedure. Record the trigger, evidence, exception, and escalation path while the expert can still explain the surrounding conditions. Route perceptual skill toward demonstration and practice instead of forcing it into prose.
Once knowledge has been captured, the representation plane preserves the distinctions that make the material trustworthy. A compliance policy, a war story, and an untested hypothesis shouldn’t become interchangeable chunks. Carry provenance, confidence, and validity context—including the plant, time period, equipment, and conditions—as first-class properties. Extend the knowledge graph beyond documents to the people and episodes that produced them.
The serving plane then determines how that knowledge reaches users. Answers should cite retrieved evidence and show the source. When the collection can’t answer, the system should say so clearly and route the question to someone with relevant experience. “Ask Joe; she rebuilt this line in 2023” is more useful than a fluent paragraph assembled from weak evidence, and the referral restores the human contact through which difficult knowledge often moves.
The transmission plane completes the architecture by helping how expertise moves between people through shadowing, teaching, and communities of practice. The platform should detect when knowledge concentration and attrition risk converge, then trigger capture and apprenticeship before a notice period begins.
Gabriel Szulanski examined 271 observations of 122 best-practice transfers across eight companies and found that even willing teams struggled to reproduce methods developed elsewhere in the same organization. The difficulty often began with causal ambiguity where people could describe the steps without fully understanding why they worked. Receiving teams also needed enough context and experience to absorb and apply what they learned. Preparation, coaching, and time helped them rebuild the practice in their own setting. A repository could preserve the record; the receiving teams still had to turn that record into working knowledge.
Retrieval precision and answer faithfulness show how well a system serves its existing collection. They don’t reveal whether the collection contains the knowledge on which the organization actually depends. That question needs a separate evaluation loop tied to capture priorities and transfer outcomes. Figure 2 shows how the loop moves from offline evaluation to abstention calibration and then to transfer outcomes.
Figure 2. The evaluation loop: Offline tests,
abstention calibration, and transfer outcomes feeding capture
priorities.
The evaluation begins with incident replay. Select 20 or 30 resolved incidents, remove the resolutions, and give the opening facts to the system. Ask the engineers who solved them to grade its responses. Compare those answers with responses from a frontier model that lacks access to the company’s collection. The gap reveals the generic-answer rate: how often the internal system merely restates public knowledge. If reviewers can’t tell the two sets apart, the pipeline adds little institutional value.
A bus-factor audit tests questions that only one or two employees can answer, and study how the system fails. A clear admission of uncertainty followed by a useful referral is healthy. Fluent boilerplate damages trust in every response, including the accurate ones.
Abstention calibration measures whether the system answers when evidence exists and declines when corpus can’t support an answer. Build a labeled set of answerable and unanswerable questions, then track abstention precision and recall as the collection grows. A system that never says “I don’t know” is unevaluated on the dimension that matters most.
Transfer outcomes complete the loop by measuring whether knowledge has reached the people who need it. Evidence of transfer appears in shorter time to proficiency, fewer repeat incidents after elicitation, and fewer critical responsibilities that depend on a single person. Document and query counts describe system activity; they don’t show whether someone else can now make the decision.
A strong knowledge system records what an expert said, preserves the conditions around the statement, and marks uncertainty. It also recognizes expertise that requires demonstration, apprenticeship, or team practice. Every evening, the people who carry that knowledge walk out the door. The architecture should be ready long before one gives notice.
Is cybersecurity part of your job in any way? If so, we’d like to know what you think for a report we’re writing. Just answer these quick 11 questions. Thanks in advance! Take the survey >
Unifont 18.0.01 Released [Planet GNU]
16 September 2026 Unifont 18.0.01 is now available.
This release is aligned with Unicode 18.0.0, adding almost 400 new
glyphs.
Download this release from GNU server mirrors at:
https://ftpmirror
... /unifont-18.0.01/
or if that fails,
https://ftp.gnu.o
... /unifont-18.0.01/
or, as a last resort,
ftp://ftp.gnu.org
... /unifont-18.0.01/
These files are also available on the unifoundry.com website:
https://unifoundr
... /unifont-18.0.01/
Font files are in the subdirectory
https://unifoundr
... 0.01/font-builds/
A more detailed description of font changes is available at
https://unifoundr ...
nifont/index.html
and of utility program changes at
https://unifoundr
... nt-utilities.html
Information about Hangul modifications is at
https://unifoundr ...
hangul/index.html
and
http://unifoundry
... l-generation.html
Enjoy!
Paul Hardy, GNU Unifont Maintainer
Victory: Court, Using a New Test, Rules Embedding Links is Legal [Deeplinks]
Courts have for two decades found that linking and embedding someone else’s web content, be it a photo, music, or an article, doesn’t violate copyright law–the entity that controls the server that hosts a copyrighted work, not the user or website that merely directs others to it, is directly liable if the content turns out to be infringing.
News publisher Emmerich Newspapers sought to convince the Fifth Circuit Court of Appeals to chart a new and dangerous course, arguing that an aggregator website that published links to its copyrighted articles was in effect “displaying” them and can be directly liable for infringement. EFF, along with several other public interest organizations and trade associations, filed a brief urging the court to follow multiple other circuits and reject that theory.
Fortunately, the Fifth Circuit Court of Appeals did just that. While it rejected the server test–the rule courts have used to determine copyright liability rests with whoever serves up the content–the court came to the same practical conclusion by focusing on who is responsible for transmitting content.
Applying that test, the court found that pointing or directing a user’s browser to request and receive the copyright owner’s own copy residing on its computers does not involve transmitting or communicating the content. “Although we take different routes to get there, both the server test and the test we announce end up in a similar place: a website cannot transmit a work that it does not have,” the court said.
We told the court that accepting Emmerich's theory would make the common act of embedding links a legally fraught activity, one that many websites might be unwilling to risk, which would seriously damage the internet as a tool for creating and disseminating ideas and knowledge,
We applaud the court’s decision–even though it applied a different test, it correctly concluded that a user linking pictures, video, or articles isn’t in charge of transmitting that content to the world. The user doesn’t control what’s located on the other end of the link—that’s up to the person who controls the server.
Emmerich also claimed linking violates the Digital Millennium Copyright Act (DMCA), arguing its URLs were copyright management information (CMI) and when the aggregator displayed Emmerich’s articles under its own URL, it tampered with Emmerich’s CMI, which violates the DMCA.
Under that logic, unsuspecting internet users could face ruinous legal risk for doing something as simple as using a link shortener, particularly given potential statutory penalties of up to $25,000 per violation.
In our brief, we told the court that URLs don’t necessarily equate to a copyrighted work or provide sufficient information about the nature of the underlying content, making it highly unlikely that anyone would expect a URL to contain CMI. Quoting EFF’s brief, the court concluded that URLs are first and foremost a locational reference tool and while it may be possible for a URL to contain CMI, the bar to that conclusion is high.
Overall, this was a good and sensible decision that will protect ordinary online expression, communication, and access to knowledge. Hopefully this issue is laid to rest at last.
EFF Welcomes Alexander Macgillivray to its Board of Directors [Deeplinks]
The Electronic Frontier Foundation (EFF) is honored to announce today that Alexander “amac” Macgillivray — a former White House official who also served in top legal capacities at Twitter and Google — has joined EFF’s Board of Directors.
Macgillivray served in the Biden Administration as Deputy Assistant to the President and Principal Deputy U.S. Chief Technology Officer in the Office of Science and Technology Policy, and earlier had held a similar position in the Obama Administration. Macgillivray was one of the co-authors of the Biden Administration’s Blueprint for an AI Bill of Rights and oversaw many of the Administration’s AI initiatives, such as organizing its AI CEO convening, leading its working group on federal AI policy, and overseeing the creation of the National AI Research and Development Strategic Plan and National AI Research Resource.
He was Twitter's General Counsel from 2009 to 2013, leading the Corporate Development, Public Policy, Communications, and Trust & Safety teams. Before that he was Deputy General Counsel at Google from 2003 to 2009, where he created the Product Counsel team.
“One of the things I am currently focused on is positively impacting AI development,” Macgillivray said. “The EFF is uniquely situated for that purpose because it combines top-notch legal, technical and advocacy staff with a long history of fighting for people’s rights while encouraging the positive development of technology. I’m thrilled to be joining the board.”
Macgillivray joins a dynamic EFF Board led by Board Chair Gigi Sohn and Vice Chair Brian Behlendorf, and including fellow Board Members Erica Astrella, Anil Dash, Sarah Deutsch, Tadayoshi Kohno, Pamela Samuelson, Bruce Schneier, James Vasile, Tarah Wheeler, and Jonathan Zittrain.
“The EFF Board is thrilled to have Alex join our ranks,” Sohn said. “I’ve worked with Alex for over two decades and have always been impressed not only with his intelligence and grace, but also his ability to think outside the box. His deep experience with non-profit boards will be invaluable as EFF enters a new and exciting chapter.”
Macgillivray currently also serves on the boards of The Trust & Safety Foundation, The Trust & Safety Professional Association and Public Resource. He is an affiliate at the Berkman Klein Center for Internet & Society at Harvard University. Macgillivray earned a law degree from Harvard, a bachelor’s degree in Reasoning & Decision Making from Princeton University, and a New Jersey Teaching Certificate.
“The vanguard leadership of EFF Board members to ensure technology supports rights, justice, freedom, and innovation for all people has never been more critical,” EFF Executive Director Nicole Ozer said. “Many of the threats that once seemed hypothetical are now reality and the work of our EFF community is fundamental to the future of our countries, our livelihoods, and literally our lives. I feel fortunate to have amac join as a Board member as I begin my tenure as Executive Director. His diverse expertise will be invaluable to make sure that EFF is stronger than ever to meet this moment.”
Members of the Board of Directors ensure the managerial and financial health of the organization. EFF is the leading nonprofit organization defending civil liberties in the digital world. Learn more about our cutting-edge work on AI issues, and please donate today to help keep us fighting for a brighter digital future.
👮 Flock Searches for the LOLs | EFFector 38.16 [Deeplinks]
Mass surveillance isn't a joke. But police are treating it like one when using automated license plate reader (ALPR) networks. In our latest EFFector newsletter, we're covering a new EFF report on how officers across the country are routinely logging completely nonsensical "reasons" for their Flock searches, including "LOL," "LMAO," and even (yuck) "Sexy."
For over 35 years, EFFector has been your guide to understanding the intersection of technology, civil liberties, and the law. This issue covers a settlement enshrining Meta's harmful surveillance into law, states pushing back against ALPR, and how police are turning our privacy into a punchline.
Prefer to listen in? EFFector is now available on all major podcast platforms. This time we're asking EFF's Adam Schwartz what has united people against Flock cameras — and how we can make sure that today's backlash leads to lasting change. You can find the episode and subscribe on your podcast platform of choice:
Want to protect your right to digital privacy? Sign up for EFF's EFFector newsletter for updates, ways to take action, and new merch drops. You can also fuel the fight for privacy and free speech online when you support EFF today!
Fedora 45 beta drags the Linux console into the 21st century (Register) [LWN.net]
The Register looks forward to the upcoming Fedora 45 release.
The biggest surprise is that Linux's legacy in-kernel console – the text-mode interface normally hidden beneath the GUI – has been replaced with a software-controlled alternative. The replacement is kmscon, a userspace terminal emulator that has been in development for more than a decade.
I think it’s possible that someone could have a good time with Wolverine. Personally I was bored after a few hours. Eventually I was skipping cut scenes to get to the game and then I realised I wished I could skip the game parts too. Personally I have found Onimusha to be much more entertaining. Both games are combat focused but Onimusha actually feels interesting and fresh whereas Wolverine feels like they are still just ripping off the combat from Arkham which was fun but was also almost 20 years ago. It was fine in Spider-Man where swinging around New York was actually the game but Wolverine feels like a massive downgrade to me.
How the Meta Settlement Silences Youth Activism [Deeplinks]
Since its integration into our digital world, social media has played a pivotal role in youth organizing and social mobilization. Yet, people’s access to these platforms is increasingly coming under threat from courts and legislatures under the guise of protecting young people online—presenting a significant hindrance to youth organizing.
In a major recent example, Meta settled in a lawsuit with 52 states and territories regarding the use of Instagram and Facebook by young people. The settlement will require Meta, and pressure other non-Meta owned platforms like TikTok and YouTube, to embed age gating practices into every product while also requiring restrictions on the accounts of people under-18, such as a two-hour daily time limit and content restrictions.
Young people have been using social media for political advocacy and community organizing for more than a decade. From organizing protests speaking out against police brutality, to organizing nationwide school walkouts demanding safety in schools from gun violence, and striking to demand lawmakers take action to protect the climate, social media has become an instrumental tool for youth to both speak out and connect with other young activists.
Instagram has become especially useful for activism online by young people. The features on the app make it a helpful tool for being able to efficiently and quickly spread awareness, which is especially important when people need to share real-time information. For example, 17-year-old Darnella Frazier’s video on Facebook showed the world the murder of George Floyd.
The impact of youth activism online is also evident on non-Meta owned platforms, with services like TikTok and YouTube being particularly prevalent spaces for young people to share their stories, build movements, and amplify collective engagement.
However, in a digital world operating under the settlement’s new guidelines, young people risk not being able to read crucial news due to the content being labeled as “age-inappropriate,” which has already happened for teenagers in Australia under its social media ban.
A two-hour daily time limit and a block on Meta’s apps between midnight and 6am leaves little room for young activists to organize rapid response efforts. Being unable to see likes on a post will make it difficult to gauge the effectiveness of their campaigns.
Add to this what we already know about Meta’s content policies which claim to “protect children” and keep sites “family-friendly” but instead label content like LGBTQ+ content as “adult” or “harmful,” youth will be left with no choice in what content they see once the ‘age-appropriate’ content filter is turned on by default. One recent report noted that Meta had hidden posts that reference LGBTQ+ hashtags like #lesbian, #bisexual, #gay, #trans, and #queer for users with the sensitive content filter on. This would specifically curtail the efforts of young activists doing work on comprehensive sex education.
Measures like this are being discussed across the globe, but not all courts have taken such a short-sighted approach. In August, the French Constitutional Council got a lot right in its decision to strike down the country’s legislation banning under-15s from social media for infringing free expression and communication for everyone online, not just young people.
The French Court also called attention to its infringement on privacy as the legislation would have forced people of all ages to hand over government IDs, face scans, and other sensitive information to prove their age and access online content.
Requiring this much data from users puts activists in danger of even more surveillance. Meta has already previously complied with demands from law enforcement to hand over the messages of users. The amount of personal information that will be logged and that could be demanded via a warrant from police to stifle or investigate activists’ actions or plans could cause a chilling effect, forcing advocates to pause or terminate their work.
This is egregious because these systems misidentify or lock out people of color, people with disabilities, and trans or gender-nonconforming individuals whose IDs may not match their chosen name or align with what the system expects them to look like upon verification. And it’s often these communities that benefit from online organizing the most, especially for marginalized youth as social media can often be the only place to organize and build community.
The settlement generates headlines, but it will not solve the core problem. Instead of tackling Meta’s surveillance capitalism business model that turns all online content into potential profit and centers lining the company’s pockets over protecting the speech and privacy of users, this settlement gives the tech giant an opportunity to carve out a new digital world that prioritizes its own needs, not those of young people.
As we’ve been calling attention to in other contexts, this will force young people into digital isolation—curtailing vital access to news and resources for health and development. It also completely ignores the calls of youths themselves who favor digital literacy and education over surveillance and government control.
Young people deserve a better internet than one regulated through panic. They deserve better than the government or Big Tech getting to decide how they use social media and what they can or cannot be exposed to or learn about. They deserve better than having their right to free expression minimized. This must not be lost in the pursuit of building a better and safer online ecosystem and environment.
The flaw in how journalism covers US politics. We wait for proof, then it comes, and go back to waiting for proof. We think we want proof, but what we really want is to not have proof. That is if you judge us by our actual behavior. We'll deal with the truth when we have the proof. (That would be a good bumper sticker.)
Google replaced the library card catalog. Imagining that, Claude and ChatGPT et al are as much of a leap. I think libarians must be ecstatic. It moves their job up one level. They now have about 100 librarian-power tool that works for them. Librarians and programmers worked together a lot in the early days of the web. Maybe we'll do that again.
Claude Code, even though it had blocks preventing it from doing this, overwrote files on an S3 bucket that took one of my major apps off the air. Every customer must be grappling with the same thing. How do I trust it when it can't be trusted? More about this in a tweet earlier today.
What AI Can Teach Us About Being Human [Radar]
My guest on this past week’s Live with Tim O’Reilly was Emmanuel Ameisen, a researcher on Anthropic’s AI interpretability team. I’d heard him give a short talk at Foo Camp on Anthropic’s research into what is going on inside an LLM while it is processing, and I wanted him to reprise the talk and then go deeper with me and the audience.
The essential message of the talk was on the first slide:
How do we know this? As tokens pass through a model, particular patterns of activity appear in the intermediate states between its layers. These are called activations. Researchers can study which patterns show up when the model encounters particular ideas, and they can even intervene in those activations and see how the model’s behavior changes. (They do this by capturing the numerical state of the model’s computation in some area where they believe the activation shows a particular “meaning” and then replace the numbers with others.)
I went into the conversation thinking about how cool it is (and important too!) to explore what is going on inside the “mind” of a model. But in the end, I found it even more provocative to think about what studying LLMs might teach us about how our own minds work.
There’s at least some kind of analogue to what happens in the human brain. Emmanuel began by asking the audience to do a little next-token prediction themselves. He started with an easy one, a hypothetical exchange between two friends:
John: “Is the powder-blue suit too much?”
Nick: “Definitely not, man. Send it.”
John: “Okay, I’m going to tear it up on the _______________”
Most of us will fill in the blank at the end with “dance floor.” That’s a reminder that humans are also next-token predictors.
Then he gave an example that some humans will easily answer, but others without local knowledge might well fail at:
“We also have nature here, just a short bike ride away across the GG bridge. And we have world-class skiing about _______________”
Claude easily completes the thought with “three hours away.” To do that, Claude had to infer that “GG bridge” refers to the Golden Gate Bridge, that the speaker is therefore in San Francisco, and that “world-class skiing” probably refers to Lake Tahoe and then retrieve roughly how long it takes to get there.
The point of Emmanuel’s demonstration was that we have become so used to calling LLMs “next-token predictors” in a kind of dismissive way. But as Emmanuel put it, “To predict the next word well, you need a very complex world model.”
Emmanuel pointed out that people often confuse how you make a thing with how the thing works. Yes, LLMs are trained with the seemingly simple objective of predicting the next token. From that, people may make the leap that what is going on inside must also be simple, something like a very large fuzzy lookup table. “But that’s not true,” Emmanuel said. Simple objectives can give rise to extraordinary complexity. Evolution is the canonical example. No one put “create Beethoven’s Ninth Symphony” or “understand quantum electrodynamics” into the instructions for a process driven by reproduction and selection, yet it eventually produced Beethoven and Feynman. As Emmanuel put it, humans have been “reproducing and killing each other for millions of years, and from that we got jobs—or this podcast.”
What Anthropic’s interpretability researchers are finding inside the models looks much less like fuzzy retrieval than many people imagine. They find millions of internal features corresponding to concepts. For example, features for “eyes” show up when the model encounters prose about eyes, an ASCII face, an SVG image, or a photograph. In other words, these features appear to be abstractions rather than merely associations with particular strings of tokens.

Similarly, a feature of the Golden Gate Bridge activates not just for English text about the Golden Gate Bridge but for references in other languages and for images of the bridge. Even more interestingly, researchers can manipulate these features. Turn the activation of the Golden Gate Bridge feature up strongly enough and ask Claude what its physical form is, and instead of saying that it is an AI without a physical body, it announces that its form is the Golden Gate Bridge. It isn’t just that some numbers happen to accompany activations about the Golden Gate Bridge. Changing those numbers changes what the model says it believes.

The way a model completes a task that requires thinking ahead also demonstrates a kind of internal world model. Ask Claude to write a rhyming couplet. Even though it emits only one token at a time, before it has written the second line, the activations already reveal the rhyme that it is aiming for. The choice of a word such as “rabbit” for a rhyme happens before the choice of the preceding words on the line, so the model can land there. We call it planning when a person does this. It doesn’t seem unreasonable to use the same word for what is going on here.
Perhaps most challenging to our preconceptions is that there are also features associated with emotions that aren’t activated just by words about those emotions, but by situations, images, characters, and more. These emotion features are even activated by the model’s own activities. For example, “frustration” may be activated when the model is unable to complete a task.
The issue of anthropomorphization came up during the audience Q&A. One participant objected:
“We should avoid attributing human qualities to LLMs by saying they think, intend, rhyme, or have emotions. Doing so encourages us to project human characteristics onto systems that do not possess them.”
I have sympathy with that warning. Old labels can prevent us from seeing something accurately. But a blanket prohibition against using familiar words can blind us too.
If you’ve followed my work for a long time, you know how much I’ve been shaped by the ideas of my early mentor George Simon, who in turn was deeply influenced by Alfred Korzybski and general semantics. Korzybski’s famous dictum was “The map is not the territory.” Simon (and Korzybski) taught me that language is a map of experience, which in turn is a set of responses to stimuli from some underlying external reality. The path from reality through experience to conceptual understanding is a very lossy process. The result can be a bad map that can blind us and lead us astray. When we encounter something genuinely new, we have to learn to notice when we are trying to force the territory to fit a map that no longer describes it. But a good map doesn’t just guide us along a route; it helps us notice things that might otherwise be invisible to us.
So yes, words like “thinking,” “planning,” “intention,” and “emotion” are labels derived from our experience as human beings. They may turn out to fit LLMs poorly. But if the shoe fits, perhaps we should let them wear it.
Emmanuel had a good response to the objection. He said, in effect, that anyone is welcome to propose more precise vocabulary. If it works—that is, if in my framing, it is a good map that helps people see the territory more clearly—people will come to use it. (An audience member later suggested that Emily Bender has done just that. But frankly, I find her suggested alternatives to be quite tortured, obscuring far more than they clarify. Even she admits they don’t work very well, though clinging to the need for them.)
In her analysis of the Hugging Face incident, Melanie Mitchell made some observations consistent with the nuanced approach suggested here. She wrote:
Metaphors can help us make sense of novel situations. For example, framing chatbots as “role-playing actors” has been helpful in understanding why these systems exhibit “lying” and “scheming” behavior. But inappropriate metaphors, like the narrative that “OpenAI lost control of escaping swarms of rogue agents,” can lead to ill-informed decisions about how to fix problems or set policy….It is essential for lawmakers, and the public, to understand that none of the reported incidents actually involved loss of control at any time, or arguably even “rogue agents,” or any kind of humanlike agency on the part of AI models. Instead, the blame lies with the humans who failed at engineering safe testing conditions, and who train AI models using RL methods that incentivize high persistence, autonomous decision-making, and reward hacking.
In short, all language is a map. Don’t judge it on that basis alone. Judge it on how well it helps us to see the shape of the territory.
Returning to my conversation with Emmanuel, he remarked that when an existing word really does provide the most precise description, perhaps “what should change isn’t our vocabulary, but our mental model of what these models are.” I replied that it should perhaps also change our mental model of what we are. Our encounter with machine intelligence should lead to a better understanding that parts of our own cognition are also mechanistic (albeit derived from a different underlying mechanism than that of LLMs) while other parts are, as yet, somehow perhaps something else.
In 1995, O’Reilly published a book that I remain extraordinarily proud of. Stephen Talbott’s The Future Does Not Compute: Transcending the Machines in Our Midst was decades ahead of its time. Its argument was not primarily about what computers would someday become. It was that when we think about machines as intelligent (and yes, we were thinking about that even back in 1995), we are thinking only of the parts of ourselves that are already like our machines. Steve asked us to look at the ways we have built an education system, workplaces, and a society in which we ask humans to act and think like machines. And he asked, “What happens to the rest? How do we make more space for the parts of being human that aren’t like machines?”
I’ve been thinking about this for a long time. My 1975 Harvard honors thesis in classics was probably my first crack at this question. I was trying to explain passages in Plato in which early formulations of ideas such as logic and virtue were couched in mystical language that scholars had attributed to “Orphic influence.” My argument, based on my work with George Simon, was that something more fundamental was going on. Plato was trying to describe the numinous experience of thinking genuinely new thoughts. Everyone studying the philosophy of Socrates, Plato, and Aristotle today may have some sense of the magic and majesty of their ideas, but it is a pale shadow of how it must have felt like to Socrates and his disciples.
When we think using received knowledge, we can easily slip into looking at the map rather than the territory. We manipulate symbols for things we think we already understand. We apply familiar categories. We replay habits of thought that were laid down before. But every once in a while, we actually see something that we didn’t see before, and the experience is different. A genuinely new idea changes the person who has it.
Not long after writing that thesis, I encountered a similar idea in the writings of Idries Shah, who wrote a number of books popularizing the Sufi philosophical tradition. He emphasized how much of ordinary human life consists of automatic conditioned responses. Social routines, habits, the endless playback of patterns we mistake for our selves. Various religious traditions use heightened language for what it means to break through that automatism. They might call it “awakening,” or “presence.”
But there is an everyday, nonmystical version of the same experience. In his autobiography Surely You Must Be Joking, Mr. Feynman, Feynman complained about students who had learned theories and formulas but had never truly understood how to apply them. “I don’t know what’s the matter with people: they don’t learn by understanding; they learn by some other way—by rote, or something,” he wrote. “Their knowledge is so fragile!” In many ways, humans are often just as much “stochastic parrots” as LLMs! We are stuck traversing the map rather than checking back on whether it correctly represents the world it is meant to describe. How often do we just repeat the received wisdom? How often do we actually see the world afresh?
There’s a wonderful passage in Virginia Woolf’s To the Lighthouse that captures the quest to break through to an original thought. Mr. Ramsay, the narrator’s father, is striding up and down thinking through a hard problem, which is represented only by the letters of the alphabet.
[He] consecrated his effort to arrive at a perfectly clear understanding of the problem which now engaged the energies of his splendid mind.
It was a splendid mind. For if thought is like the keyboard of a piano, divided into so many notes, or like the alphabet is ranged into 26 letters all in order then his splendid mind had no sort of difficulty in running over those letters one by one firmly and accurately, until it has reached, say, the letter Q. He reached Q. Very few people in the whole of England ever reach Q. Here, stopping for one moment by the stone urn which held the geraniums, he saw, but now far away, like children picking up shells, divinely innocent and occupied with little trifles at their feet and somehow entirely defenseless…his wife and son, together in the window….But after Q? What comes next? After Q there are a number of letters the last of which is scarcely visible to mortal eyes, but glimmers red in the distance. Z is only reached once by one man in a generation. Still, if he could reach R it would be something.
For me, this passage very much captures the idea that the most valuable thought is one beyond that which is simply an extension of rehearsed knowledge, something truly new. What Ramsay misses, perhaps, is that his wife and son, “divinely innocent and occupied with little trifles at their feet” might well be closer to that by going back to “A” rather than he is by getting further through the alphabet with his exhaustive review of existing knowledge. Perhaps it isn’t extending rehearsed knowledge that takes us forward, but instead taking a fresh bite of what the map is trying to represent.
By coincidence, the poet Wallace Stevens, another of my gurus in the tension between the reality of the physical world and the thinness and incompleteness of our representations of it, also used the alphabet as a metaphor in his poem “An Ordinary Evening in New Haven”:
Reality is the beginning, not the end,
Naked Alpha, not the hierophant Omega…
It is the infant A standing on infant legs,
Not twisted, stooping, polymathic Z.
George Simon taught me about how to get to A rather than Z not as philosophy but as a practice. He showed me how to notice the moment when labels take over from experience and, when possible, to empty the mind enough to let the thing itself teach us what to call it. I later discovered that the psychotherapist Eugene Gendlin described this process with the lovely phrase “surrender and catch.”
To me, the challenge posed by LLMs to our sense of what “intelligence” means raises the question of what they are still missing. What is the “high ground” for human intelligence and expertise? If the machines get better and better at carrying out the tasks we give them, what is it that we are uniquely good at, and should be getting even better at?
There are obviously enormous differences. LLMs don’t have bodies in the way we do. Their developmental history is radically different. They don’t sit around between prompts watching the light change through the trees, feeling hungry, worrying about their wife and children, or waking up suddenly with a new idea or project. Each of us is a unique bundle of contingency, shaping ourselves and our knowledge differently as we trace different paths through life, and reacting to outside stimuli even when we have been given no task to perform.
Emmanuel pointed out that the apparently simple question of what an LLM is like when it is “just being” (which one audience member asked about) is hard to formulate, because its experience is the response to a succession of inputs from humans, each time starting with something of a blank slate, unlike the continuous embodied stream of human life.
But simply asserting that LLMs “don’t really think” isn’t terribly useful. Which parts of what we call our own thinking are pattern completion? Which are planning? Which are learned emotional and social routines? Which are unconscious calculations whose outputs bubble up into awareness? Which are stories that our verbal mind tells after the fact? And after we account for all of those things, what is left? That seems to me one of the great intellectual and spiritual questions of the AI era.
Emmanuel suggested one intriguing direction. He said that six months ago, he wouldn’t have trusted an AI to build a substantial piece of software. Now Claude writes basically all his code. He tells it what he wants and it executes the plan. Where it is still unreliable is research. Why? The model wants to come back six hours later and announce that it has solved the problem. It has been trained on tasks that always have answers. A model that is extremely good at finding an answer once the problem has been specified is not necessarily good at recognizing that the problem is badly posed, that the question cannot yet be answered with the data at hand, that an unexpected result is more interesting than the expected one, or that a failed attempt has exposed a more important question.
Perhaps one part of the high ground for human intelligence lies there: not merely solving problems but developing a feel for which problems are worth solving and noticing clues that tell us when we might have been asking the wrong question.
In science or math, a well-formed question or conjecture can itself be an important piece of intellectual work. Every good scientist has far more questions than they have time to pursue. Perhaps in the AI era, when answers become increasingly cheap, recognizing which question ought to be asked becomes more valuable, not less. Just as arXiv.org preprints decoupled priority of publication from peer review, perhaps we need a new kind of recognition, credit, and perhaps even compensation for the precise formulation of productive questions.
The mathematician Terence Tao recently touched on this same issue in a post on Mastodon. There is an infinite supply of mathematical questions, he observed, but not an infinite supply of good questions, problems at just the right frontier of difficulty, whose pursuit is likely to reveal something new. As AI makes answers cheaper, Tao argues, it is increasingly “the identification of a promising problem” that becomes the scarce resource.
In one experiment Emmanuel described, the researchers slipped fake search results into Claude’s context claiming that Anthropic had dissolved the interpretability team. Claude did not announce that it thought the information was problematic, but internally, representations associated with “fake,” “incorrect,” and “prompt injection” became active, and Claude quietly ignored the result.
In another experiment, a model was carrying out an exploit and attempting to conceal what it was doing. The visible transcript was mostly innocuous-looking commands. Inside the model, though, researchers saw features associated with “strategic manipulation,” “influence,” and “concealed and deceptive actions.” This is obviously very relevant in the context of the Hugging Face exploit. Emmanuel didn’t talk about the relationship of interpretability and AI safety, but it is surely a frontier to be explored.
And then there is the opposite problem: things the model can do but cannot explain. I had asked Emmanuel about cases where a model solves a math problem and, when asked to explain how it did it, gave an account based on how humans are taught to solve that problem rather than on the actual computation researchers can see through its activations
He distinguished deception from lack of introspection. Some internal processes appear available to the model for verbal report; others don’t. Ask how it performed a computation that falls into the latter category and, as Emmanuel cheerfully put it, “it just makes stuff up.”
That reminded me of my grandson. When he was five or six, he could multiply random three-digit numbers in his head and simply give you the answer. Then he went to school, where they told him he had to “show his work.” He couldn’t. Eventually he learned the approved procedure, and as a result has seemed to lose the remarkable ability he had as a child.
Humans also invent stories about why we have made certain decisions. Sometimes we are lying to others but often we deceive ourselves. We begin to take action before we are conscious that we are doing so. We call it “intuition” when an expert looks at a situation and says “something is wrong here” long before they can explain why, or when a poet just “knows” that a line works, or a programmer “smells” buggy code. The fact that an internal process cannot be rendered faithfully into language does not make it deceptive. It may instead tell us something about the limitations of language and conscious introspection.
All in all, I came away from this conversation more curious than ever. And that might well be another of those areas that distinguishes humans from AIs. Are AIs ever curious? I wonder.
Is cybersecurity part of your job in any way? If so, we’d like to know what you think for a report we’re writing. Just answer these quick 11 questions. Thanks in advance! Take the survey >
Why do Microsoft job levels start in the high 50’s instead of starting at a sane number like 1? [The Old New Thing]
Those unfamiliar with the Microsoft job level nomenclature are probably very confused that the entry-level full-time software engineering position is described as level 59, with increasing numbers as you get promoted. Why does it start at 59? Why not start with 1 like a sane person?
The level numbers used to start with 1.
In the old days, recent college graduates typically started at levels 10 or 11, with a senior position at level 12, an advanced position at level 13, and a small number of elites at levels 14 and higher.
The problem with that system is that there was very poor granularity. Notice that if you come in as an advanced college graduate at 11, it’s just two promotions before you’re pretty much hit the practical limit. As a result, each level contained a large number of developers, covering a broad range of skills within the level. It was difficult to move up a level because the skill set required to be, say, a 13, was much higher than that required to be a 12. You first had to work your way to the top of your (very large) level, and only then could you work on developing the skills necessary to make the leap the next level. These slow promotion rates created widespread frustration.
To address these problems, each of the old career levels was divided into two or three new career levels, so that moving from one level to the next was a smaller step (and therefore easier to achieve), and so that the employees within a level were closer in talent.
Great. We made the levels narrower and consequently made it easier for employees to receive promotions, creating more easily achieved career milestones and improving morale. But how should we number the new levels?
If the new levels also started counting at 1, then you would have a period of confusion when people talked about being at “level 11” and you had to check whether they were talking about “old level 11” or “new level 11”. And if you ran across a document that said something like “We would probably need two level 11 developers for this project,” you’d have to check the date on the document to figure out whether they are talking about old level 11 or new level 11. And checking the date might not be good enough, because the document may have been written under the old level system, and then somebody made some modifications to an unrelated part of the document, so the last-modified date now comes after the levels changed, but the text in the document is still talking about the old levels.
The solution was to give numbers to the new levels that did not overlap with the numbers for the old levels. (Sound familiar?) Even more than that, the new levels had numbers that didn’t even remotely overlap with the old level numbers. Because if the new levels started at 20, people would see a 20 and not be sure if that means “a new level 20” or “some super-genius old level 20, I didn’t know the levels even went that high.”
The new levels therefore started at a lofty 40, and the old level 10 corresponded roughly to a new level 59.
You could say that the numbering system avoids backward compatibility issues.
The old broad levels still show through in the new system in two ways. One is in the job titles. Rather than making up new titles for each of the new narrow levels, the new levels inherited the title from the old level they were split off from. So the old level 10 split up into new levels 59 and 60, but both 59 and 60 have the same title. The other way that the old levels show through is in the rate of promotion: Comparatively speaking, getting promoted to a level that has a new job title requires a greater demonstration of distinction than getting promoted to a higher level within a job title. Internally, we call levels that share a job title a band. A promotion to a higher level with the same job title is an in-band promotion, whereas one to a new job title is a cross-band promotion.
Bonus chatter: If new college hires come in at old level 10, or new level 59, what were the lower levels 1-9 (new levels 40-58) used for? The level system was designed to cover all possible Microsoft employees, so the lower levels are used for things like summer interns and temporary employees, as well as non-engineering positions like receptionist or mail delivery.
The post Why do Microsoft job levels start in the high 50’s instead of starting at a sane number like 1? appeared first on The Old New Thing.
[$] Ways to encrypt data on servers [LWN.net]
At the 2026 edition of FOSSY, Romeo Solano gave a fast-paced, humorous presentation on what could have been a rather boring topic: server encryption. There are a number of threats that we face in today's world, from criminals, government overreach, espionage, and more, that can be thwarted with encryption. But encrypting data on a system that may live elsewhere, without any access to its keyboard at boot time, is rather more difficult than encrypting the disk of a laptop. Solano described the problems and gave a tour of some of the solutions in the talk.
FeedLand and WordPress have a new hookup. With Scott
Hanson's plugin: River
Embed for FeedLand you can use feedland.com or feedland.org, or
host your own FeedLand, to include a page of news in your site. How
it works: Create a timeline, when you're ready show the river to
your readers, use the new plugin. For a news orgs like CNN and
TechCrunch, both use WordPress, they could have a stream of news
from related pubs. For a product site, or a political leader site,
news from pubs that cover the area. It's a way of bringing the feed
world into the world of news. Here's a thread
where you can ask questions.
Security updates for Wednesday [LWN.net]
Security updates have been issued by AlmaLinux (kernel, kernel-rt, libkcapi, nginx, nginx:1.24, openssl, osbuild-composer, perl, perl:5.32, python-tornado, rsync, and rust), Debian (cjose and nginx), Fedora (environment-modules, erlang, GitPython, knot, perl-Authen-SASL, python-configargparse, ruby, rubygems, and sblim-sfcb), Oracle (firefox, git-lfs, gstreamer1-plugins-base, kernel, libkcapi, nginx, nginx:1.26, openssl, osbuild-composer, perl, perl-YAML-Syck, postgresql18, python-tornado, and rust), Red Hat (fence-agents, git-lfs, microcode_ctl, osbuild-composer, podman, python-pyasn1, and resource-agents), SUSE (389-ds, ant, bson-devel, chirp-20260911, docker, gimp, google-cloud-sap-agent, hauler, kernel, kimi-code, libpcap, python-GitPython, python310, syncthing, yast2-samba-client, and zstd-jni), and Ubuntu (aom, imagemagick, kitty, openssh, phpseclib, policykit-1, python-sql, python-webob, shibboleth-sp, simplesamlphp, snapcast, srt, and suricata-update).
CodeSOD: Extremely One Line [The Daily WTF]
Autoformatting your code is a standard thing to do these days. And in those days past, if we're being honest. There's no excuse to not use some kind of autoformatter. Whether you configure your editor to do it or are a weirdo like me who runs a formatter from the CLI as a build step, you've got an easy way to format your code so it looks neat and readable. And some IDEs, like Visual Studio, are pretty insistent about doing this for you. Which makes today's code sample a bit more perplexing. This comes from an ancient ASP .Net application that Austin has the misfortune to work with:
protected void Page_PreInit(object sender, EventArgs e){if (Request.ServerVariables["http_user_agent"].IndexOf("Safari", StringComparison.CurrentCultureIgnoreCase) != -1)Page.ClientTarget = "uplevel";} protected void Page_Load(object sender, EventArgs e)
{
Logic();
}
Which function is Logic() called from? The fact
that I'm asking probably is enough to get you to scroll over. The
entire Page_PreInit function is on a single line,
followed by the declaration of the Page_Load function.
A confusing and annoying choice. The real bonus is that if the
browser has "Safari" in its user agent, we set a field to a
mysterious "uplevel" value. A mix of user agent sniffing, strings
as enums/flags, and wonderfully unclear names.
And yes, this particular pattern appears in more than one page in Austin's application. Someone thought this was not just a good idea, but good enough to do over and over again.
Issue 47 – Greta’s Wedding Pt. 2 – 28 [Comics Archive - Spinnyverse]
The post Issue 47 – Greta’s Wedding Pt. 2 – 28 appeared first on Spinnyverse.
Fake CAPTCHA Scams [Schneier on Security]
New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.
Urgent: Raise the Wage Act [Richard Stallman's Political Notes]
US citizens: call on your congresscritter and senators to pass the Raise the Wage Act, to raise the national minimum wage.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Ban insider trading [Richard Stallman's Political Notes]
US citizens: call on your state legislators to ban insider trading (including prediction bets) by elected and appointed officials, and government employees.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Protect birthright citizenship [Richard Stallman's Political Notes]
US citizens: Protect birthright citizenship.
Urgent: Stop kicking sick people off Medicaid [Richard Stallman's Political Notes]
US citizens: call on Dr. Oz to stop kicking sick people off Medicaid.
Urgent: News coverage for companies hiding wealth [Richard Stallman's Political Notes]
US citizens: The corrupter's henchmen have facilitated the hiding of wealth by US companies, by nullifying the rule requiring to tell the government who owns them. Call on news media to cover this.
Urgent: Pass Green New Deal for Health [Richard Stallman's Political Notes]
US citizens: call on Congress to pass the Green New Deal for Health.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Limit gouging by businesses [Richard Stallman's Political Notes]
US citizens: call on the CFPB to limit gouging by businesses by continuing to publish consumers' complaints.
Urgent: magat's misleading analysis of census and voting [Richard Stallman's Political Notes]
US citizens: call on Congress not to fall for the magats' misleading analysis of the census and voting.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Drilling near Grand Canyon [Richard Stallman's Political Notes]
US citizens: call on Congress not to allow drilling near the Grand Canyon.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Stop destructive scanning of books [Richard Stallman's Political Notes]
US citizens: call on the FTC to stop Supposed Intelligence companies from scanning books to destruction and hoarding the scans.
The law should require that if the book is in the public domain, its scanned text be published by the Library of Congress. If the book is still in principle copyrighted, the Library of Congress could publish an offer to pay the copyright holder a reasonable sum for permission to publish it for gratis download. If there is no response in a few months, it could release the scan anyway.
Urgent: Investigate Department of Hiding and Skulking's secret surveillance [Richard Stallman's Political Notes]
US citizens: call on Congress to investigate the Department of Hiding and Skulking's secret surveillance.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Pass Bank Failure Accountability Act [Richard Stallman's Political Notes]
US citizens: call on Congress to pass the Bank Failure Accountability Act.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Lawyer's for migrant children [Richard Stallman's Political Notes]
US citizens: call on Congress to stop the persecutor from denying migrant children a lawyer's representation in proceedings to deport them.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Stop weakening Global Plastics Treaty [Richard Stallman's Political Notes]
US citizens: call on Rubio to stop weakening the Global Plastics Treaty.
Urgent: Pro-Israel hawk in Middle East policy leadership role [Richard Stallman's Political Notes]
US citizens: call on Speaker Jeffries to reverse his decision to appoint a pro-Israel hawk to a Middle East policy leadership role.
Urgent: Keep deportation thugs away from polling places [Richard Stallman's Political Notes]
US citizens: call on the Department of Hostile Savagery to keep the deportation thugs away from our polling places.
A Republican gubernatorial candidate in Maine said he would invite deportation thugs to come to Maine's polling places to intimidate and perhaps terrorize voters. Citizens who are immigrants have the right to vote, but they may be scared away by deportation thugs anyway, knowing that those do not respect laws or court orders.
Urgent: Coverage of bully's attacks on journalists [Richard Stallman's Political Notes]
US citizens: call on the media to stop covering the bully's attacks on journalists as outbursts and start covering them as deliberate, escalating attempts to use government power to silence the press.
Urgent: Reverse NOAA rollback of marine protections [Richard Stallman's Political Notes]
US citizens: call on NOAA to reverse its rollback of marine protections.
Urgent: Call on Cornell University to stand by commitments to students [Richard Stallman's Political Notes]
US citizens: call on Cornell University to stand by commitments it made to its students who were being persecuted by hateful officials.
Urgent: Flock surveillance cameras at Lowe's [Richard Stallman's Political Notes]
US citizens: call on Lowe's to remove its Flock surveillance cameras.
Urgent: Green New Deal for Health [Richard Stallman's Political Notes]
US citizens: support the proposed Green New Deal for Health.
Urgent: Data center pollution decisions [Richard Stallman's Political Notes]
US citizens: call on the EPA not to exclude the public from data center pollution decisions.
Urgent: Pass People Over Poison Act [Richard Stallman's Political Notes]
US citizens: call on your congresscritter and senators to stop the corporate cancer loophole: Pass the People Over Poison Act.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Block private equity buying hospitals [Richard Stallman's Political Notes]
US citizens: call on your state legislators to block private equity grabs from buying hospitals.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: Corrupter arbitrarily meddling with federal grants [Richard Stallman's Political Notes]
US citizens: call on your congresscritter and senators to block the corrupter from arbitrarily meddling with federal grants.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Ban NDAs on plans about data centers [Richard Stallman's Political Notes]
US citizens: call to ban NDAs about plans to build data centers.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: Report on Israel's violence [Richard Stallman's Political Notes]
US citizens: call on your senators to vote to report on Israel's violence and human rights abuses in the West Bank!
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Stop wrecker demolishing the Kennedy Center [Richard Stallman's Political Notes]
US citizens: call on your congresscritter and senators to stop the wrecker from demolishing the Kennedy Center.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Here's the letter I sent:
I urge quick action to protect the John F. Kennedy Center for the Performing Arts from demolition by trumpet toadies.
First they wanted to put the corrupter's name on it. When a court blocked that, they threatened to demolish it. Both are ways of ruining it, thus proving that nothing clean is strong enough to stand against the corrupter.
Thus, more than a performance center is at stake. Congress must take this threat seriously and stop it from happening.
You can prohibit taxpayer dollars from financing demolition, but we all know that alone is likely not enough. Please do whatever it takes to protect it. You can change the powers of the board, who can be on it, or how big it is. You can even abolish the Kennedy Center board if needed.
Or you could ban complete or partial demolition or major building work.
Sincerely,
Urgent: Privatization of Yosemite [Richard Stallman's Political Notes]
US citizens: call on the Interior Department and the National Park Service not to privatize part of Yosemite for the sake of a business.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: Bill for moratorium on data centers [Richard Stallman's Political Notes]
US citizens: call on your congresscritter and senators to support a bill to for a moratorium on construction of data centers
I suggest you eliminate the term "AI" from your letter. You might say "pretend intelligence" instead.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
US citizens: Join with this campaign to address this issue.
To phone your congresscritter about this, the main switchboard is +1-202-224-3121.
Please spread the word.
Urgent: Don't take tax credits from immigrant families [Richard Stallman's Political Notes]
US citizens: Tell the Treasury and the IRS: Don’t take tax credits away from immigrant families who lawfully work.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Urgent: Paid time off to vote [Richard Stallman's Political Notes]
US citizens: call on Fortune 500 CEOs to Give Workers Paid Time Off to Vote.
See the instructions for how to sign this letter campaign without running any nonfree JavaScript code--not trivial, but not hard.
Work isn’t optional… [Seth's Blog]
But this job is.
We all need to feed our family, find shelter and contribute to the community.
Finding useful work is a key part of the human condition.
But that doesn’t mean the thing you’re being asked to do right now is required. In fact, it’s optional. It might come with this particular gig, but it’s still a choice. In the short run, most of it is not up to us, in the long run, it all is.
Once we voluntarily engage with our choice of project, things get easier.
Pluralistic: How an AI moratorium can save AI bosses (16 Sep 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

There's lots of reasons to believe the "hyperscaler" model of AI can never be profitable, and not just because of its gigantic expenditures and negative unit economics (the companies lose money with every new customer and every new use, and they lose more money with each generation of their products):
https://pluralistic.net/2025/09/27/econopocalypse/#subprime-intelligence
The industry strenuously denies this, of course. They insist that they are only days away from turning their balance sheets right side up. All they have to do is fix those unit economics, then they can make back the cost of producing their models by selling access to them. The problem is that the evidence for those improving unit economics is weak, while the evidence that they're faking their finances is very strong:
https://www.wheresyoured.at/exclusive-openai-financials/
Same goes for the claims that these companies are already profitable. Dig into those claims and you'll learn they depend on a new, special meaning of "profitable" that does not match the generally accepted accounting procedures (GAAP) definition, which is to say, these companies are claiming that they are so cool that their profitability can only be measured using a novel, secret form of mathematics:
https://futurism.com/future-society/anthropic-claude-profit-ai-safety-development-finances
This is the same wheeze that Softbank tried with Wework. Speaking in my capacity as an author of internationally bestselling technothrillers about accounting fraud, I can tell you that it was accounting fraud then, and it's accounting fraud now:
But let's give the AI bosses a momentary benefit of the doubt and stipulate that they are on the verge of acquiring positive unit-economics, which will let them start to pay off the massive expenditures they incurred by training their models and enter their long-anticipated profitability phase, when the money-furnaces they've been running for years turn into money printers, to the delight of the investors who've supplied the vast bales of $100 bills the companies have been shoveling into their models' coalboxes for years now.
Basically, they're saying, "Sure, it cost us a lot to get these rails laid, but now that the railroad is complete we can start running cars over them and make a profit." Unfortunately (for bosses and investors), this proposition is every bit as dubious as their claims to improving unit economics.
To understand why, just look at what happened the last time Anthropic shipped a major Claude update. Virtually overnight, all of OpenAI's best customers stopped paying for ChatGPT and started paying for Claude. That's because chatbots have very low switching costs: going from one chatbot to another costs almost nothing:
https://www.businessinsider.com/why-ai-startup-founder-switched-chatgpt-to-claude-2026-3
Everyone using AI knows this to be true. When I walked the floor at CES last year, I asked every AI-powered gadget maker, "What will you do if your chatbot provider jacks up their prices?" and to a one, they said, "No problem, we've designed this thing so that we can switch chatbots with the click of a mouse":
https://www.youtube.com/watch?v=WfhELBX8Jbs
That means that you can't just "build the railroad and run the cars over it." The minute you finish your railroad, your rivals will announce that they've got a new, adjacent railroad that's even faster than yours, and you will have to get to work laying another set of tracks to support even faster trains.
This is a disaster all around: the AI companies are locked in a Red Queen's Race, a fatal beggar-thy-neighbor doom-loop. The only way they could escape that trap is by signing a nonaggression pact amongst themselves promising not to compete anymore. But there's two giant problems with this: first, it is incredibly, fantastically illegal under antitrust law, because it represents a conspiracy among the dominant players to cease to compete with one another, and; second, it leaves the field open for the further development of Chinese "open weight" models that customers can run on their own modest, low-powered computers, which are presently lagging the US "frontier models" by a mere four months:
Even if you don't trust Chinese models, you can extract their training through a process called distillation and transfer them to models you do trust:
https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks
But what if there was a way for the AI companies to get government permission to violate antitrust law and cease to compete with one another, and secure a ban on the use of Chinese open weight models? Turns out, there is a way to call time on the Red Queen's Race: merely insist that you are on the verge of teaching so many words to the word-guessing program that it will wake up and devour us all, and call for a ban on "superintelligence":
Once the government stipulates that "superintelligence risk" is an existential crisis, it must grant the hyperscalers a consent decree absolving them from any violations of antitrust law stemming from a conspiracy to halt direct competition with one another:
https://stephaniekelton.substack.com/p/brer-rabbit-and-ai-extinction
Freaking out about "superintelligence" is a canonical example of "criti-hype," where critics repeat boosters' claims but append, "(and that's bad)" to them:
https://peoples-things.ghost.io/youre-doing-it-wrong-notes-on-criticism-and-technology-hype/
Remember, the tech giants want to stop competing. Mark Zuckerberg and Sudar Pichai colluded to rig the ad-market with a secret program called "Jedi Blue":
https://en.wikipedia.org/wiki/Jedi_Blue
Every year, Google sends Apple a bribe of more than $20b in exchange for Apple not entering the search market:
And the biggest tech companies in the world had a secret "no poach" agreement where they illegally promised not to try to hire one another's top engineers by offering them raises:
https://chicagounbound.uchicago.edu/law_and_economics/1033/
The only thing Peter Thiel hates more than the Antichrist (spoiler, he's just talking about Greta Thunberg) is "wasteful competition":
https://www.youtube.com/shorts/WmRC_NQh6aQ
When an industry that is eating itself alive through "hyperscaling" demands that the government bless a conspiracy to halt competition and ban open source alternatives, you should be suspicious. When that industry is pursuing a venture that has lost more money than any other venture in human history, you should be very suspicious, especially when its "rogue AI hacking" story turns out to be a story about how a hacking tool did exactly what it was designed to do:
https://pluralistic.net/2026/09/12/god-in-the-box/#llms-are-fake
Peter Thiel is right: AI is full of wasteful competition, but not because competition is a waste – rather, it's because the companies are competing to convince people to use their expensive products for the cheapest applications.
Elon Musk's SpaceX IPO depended on him losing billions of dollars by letting the world's stupidest chuds produce mountains of child porn and images of Sonic the Hedgehog with giant boobs. That is indeed wasteful (and reprehensible).
That doesn't mean we should allow the AI companies to get the government to bless their conspiracy in restraint of trade; rather, it militates for having the government investigate them for securities fraud, trafficking in child sex abuse material, election finance violations, and a long list of other crimes and misdemeanors.

The Enshittification Resistant Software Project https://er-certification.statichost.page/index.html
The Life of Death and the Ensh*ttificator https://www.youtube.com/watch?v=d6SPV4GZp-U
Marginalia Search https://marginalia-search.com/
Why the Postpandemic Tech Bust Sent Billionaires to Trump https://www.wired.com/story/against-tech-oligarchy-book-excerpt-trump-billionaries/
#25yrago Flash Worms: Thirty Seconds to Infect the Internet https://web.archive.org/web/20011024012950/http://www.silicondefense.com/flash/
#20yrsago This Film is Not Rated – must-see doc about MPAA ratings https://memex.craphound.com/2006/09/16/this-film-is-not-rated-must-see-doc-about-mpaa-ratings/
#15yrsago Chinese netizens angered by “princelings” — spoiled children of the rich and powerful https://edition.cnn.com/2011/09/16/world/asia/china-elite-children/index.html?iref=allsearch
#15yrsago LibDems get to vote on copyright reform, but who inserted the clause saying downloading should be a criminal act? https://www.theguardian.com/technology/2011/sep/16/libdems-vote-copyright-reform
#15yrsago Insurer: music-festival tragedy caused by illegal downloading https://twitpic.com/6l5ap2
#10yrsago US religion is worth $1.2T/year, more than America’s 10 biggest tech companies, combined https://web.archive.org/web/20161019095803/http://www.religjournal.com/pdf/ijrr12003.pdf
#10yrsago Geographically representative map of the London Underground https://web.archive.org/web/20240813111321/https://www.citymonitor.ai/analysis/map-londons-tube-shows-disused-stations-track-layout-and-more-2429/
#10yrsago Republican election officials block restrictions on foreign spending in US elections https://web.archive.org/web/20160916181403/https://theintercept.com/2016/09/16/fec-republicans-kill-attempt-to-block-foreign-money-in-u-s-elections/
#10yrsago Tommy Chong asks Obama to pardon him for his bullshit drug paraphernalia bust https://web.archive.org/web/20210720131834/https://www.hollywoodreporter.com/lifestyle/lifestyle-news/tommy-chong-seeks-obamas-pardon-928962/
#10yrsago Week two for the largest prison strike in US history https://web.archive.org/web/20160916143157/https://theintercept.com/2016/09/16/the-largest-prison-strike-in-u-s-history-enters-its-second-week/
#5yrsago Criminal entrepreneurship in Mexico’s high-tech drug cartels https://web.archive.org/web/20160917133449/https://motherboard.vice.com/read/how-drug-cartels-operate-like-silicon-valley-startups
#1yrago No such thing as selective censorship resistance https://pluralistic.net/2025/09/16/too-many-throats-to-choke/#pluralism-is-resiliency

Edmonton: Elbows Up (Edmonton Public Library), Sep 28
https://www.epl.ca/blogs/post/elbows-up-with-cory-doctorow/
Boston: The Post-American Internet: Possibilities for a new
internet created by an American Hermit Kingdom (MIT Media Lab), Sep
30
https://www.media.mit.edu/events/the-post-american-internet-possibilities-for-a-new-internet-created-by-an-american-hermit-kingdom/
Boston: The Paradox of Enshittification and Reverse Centaurs
(Harvard Berkman Klein), Sep 30
https://cyber.harvard.edu/events/running-harder-falling-faster-paradox-enshittification-and-reverse-centaurs
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Hudson, OH: Hudson Library, Oct 7
https://engagedpatrons.org/EventsExtended.cfm?SiteID=3850&EventID=596952&PK=
Calgary: Wordfest, Oct 8
https://wordfest.com/2026/show/wordfest-presents-cory-doctorow-2026/
Winnipeg: McNally Robinson, Oct 9
https://www.mcnallyrobinson.com/event-18991/An-Evening-with-Cory-Doctorow
Vancouver: Read, Resist, Repair, Rejoice (Vancouver Writers
Festival), Oct 19
https://writersfest.bc.ca/festival-event-2026/01
Victoria: Munro's Books, Oct 20
https://www.munrobooks.com/events/6113620261020
Vancouver: Life After AI (Vancouver Writers Festival), Oct
22
https://writersfest.bc.ca/festival-event-2026/46
Ottawa: Life After AI (Ottawa Writers Festival), Oct 24
https://writersfestival.org/event/life-after-ai
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
The Real AI Threat Isn’t What You’ve Been Told (The
Tea with Myriam François)
https://www.youtube.com/watch?v=Vc8It00fRsA
Fascists may come after the AI bubble bursts (You&AI)
https://www.youtube.com/watch?v=J2WN64aQeYQ
What Would a Normal Person Do (Trashfuture)
https://www.patreon.com/trashfuture/posts/what-would-do-169247456
Pod Save the UK
https://audioboom.com/posts/8950533-radicalised-organised-and-thick-as-s-t-nish-has-had-it-with-far-right-protests-plus-why
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
A Blue Line To A Cuck Chair [Penny Arcade]
New Comic: A Blue Line To A Cuck Chair
GEFS on OpenBSD: a very early preview [OSnews]
The Good Enough File System, originally developed for 9front, is being ported to OpenBSD.
For those who haven’t watched my talk, GEFS is a new, crash-safe, snapshotting, copy on write FS that I wrote for 9front, and which I am in the process of moving to OpenBSD. The file system is described in full here.
↫ Ori Bernstein
One of OpenBSD’s shortcomings is its rather archaic filesystem, so any work on something more modern and especially more performant is quite welcome. While any process of replacing FFS is going to be a long one, even having GEFS as an option could be a great addition to OpenBSD.
Girl Genius for Wednesday, September 16, 2026 [Girl Genius]
The Girl Genius comic for Wednesday, September 16, 2026 has been posted.
Artificial Intelligence, Quote Unquote [Penny Arcade]
Let's go over a few things.
1. If OpenAI or Anthropic breaches another company's systems, even if no money changed hands, these are Federal and State crimes. Currently, these narratives are being deployed essentially as a mode of advertising to "pump those numbers." This is why I don't believe anything remotely like what they describe occurred. At all. In any way. They are, in plain terms, "lies." Lies in the context of an IPO are called Securities Fraud - now the SEC is involved. It's astonishing what we're being asked to believe. Listen to these pinchy-faced fucking weasels talk. You would only endure these transhuman idolaters if you thought there was an upside. For you.
2. When they say shit - and they do say shit - like "there's a greater than ten percent chance our product will kill all humans within the next decade," you black bag the leadership of these companies. Again - this is how you know it's a bag pump; an op. First it was like, "Yup, we're spinning up a Jobpocalypse." I guess that stopped moving the needle, huh? A machine that recreates the conditions for feudalism? Every one of its thoughts manufactured, in part or in whole, by the disenfranchised? There's no way to overstate the hideousness they proudly emit. Now it's like, yeah, our Demon Engine might kill your kids - the ones we didn't kill already I guess. It's not serious, I'm sorry. It's Doctor Doom shit. Except in this case, Doctor Doom isn't a techno-sorcerer with Diplomatic Immunity. It's a guy who works in an air-conditioned office whenever he isn't telecommuting or warping capital markets with every breath. Black Bag.
3. Let's say we do need National AI to do battle with the AI of foreign adversaries - sounds like a great anime. If it's as crucial as we're being told, if we stand on the precipice of some great invisible conflict - like the "spirit war" my Church used to rail about - none of it would look this way. They would seize these companies via Eminent Domain, just as they did in World War II. If they did the shit these people say they do, it's not like fucking Coca-Cola. If they can batter any system or kill the world or any of this shit they aren't normal companies and they wouldn't be treated with the deference they are. They're already a cartel, clearly, which gives the government even more potent tools. Fucking come on.
4. All the hokey, handwavey parts of Cyberpunk that you just accept - the origin story of the neofeudal, technocratic state - you always wonder what that looks like. How the interests converge, how they're allowed to converge. I can tell you.
It looks like this.
(CW)TB
California: Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety [Deeplinks]
The federal government has inserted a provision into a funding deal with the state of California that would make the state abandon its gold standard net neutrality law, broadband affordability laws, and public safety protections. Doing so would be a huge step back for California, and would actually end up being more expensive for Californians in the long run. Tell the governor to reject this provision before accepting these funds from the federal government.
Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety
On August 31, the National Telecommunications and Information Administration announced it would be awarding California $1.4 billion to expand broadband connectivity in the state. In that deal is a provision that says that California agrees to not enforce any law, order, or policy that imposes any sort of restriction on internet service providers (ISPs). These ISPs will get awarded the funding in order to connect Californians they have neglected for years. The ban on enforcing our laws would last 14 years. This is disastrous for a lot of reasons.
First, California is one of the only states with a strong state net neutrality law. Recreating much of the FCC’s Open Internet Order, the law prevents ISPs from blocking, throttling, zero rating, and instituting paid prioritization on internet service. Put another way, the law ensures that users, not companies, decide how they can see on the internet. If California is not allowed to enforce our gold standard law, there will be little stopping ISPs from controlling how everyone experiences the internet.
Second, California has a number of affordability protections that would also fall under this agreement. For example, when the state approved the merger of Verizon and Frontier earlier this year, it required the new merged company to offer a $20 internet plan to low-income Californians—saving Californians billions of dollars over the next decade. Just this year the California Public Utilities Commission found that the average cost of broadband across four major urban markets (San Mateo, Oakland, Los Angeles, and San Diego) was $51 per month. In 2023, Consumer Reports found that 84% of American consumers pay at least $50 per month, with many paying more. That $30 difference per month—which is likely to actually be more—makes all the difference for low-income Californians. It is how Californians will save billions from this merger requirement. In contrast, $1.4 billion in new connectivity and infrastructure doesn't matter if the most vulnerable Californians cannot afford it. Eviscerations of this and the net neutrality protections will, ultimately, cost Californians more than they will get.
Third, this deal will impact public safety. The same California net neutrality law which protects consumers also ensures reliable service for first responders during emergencies by banning throttling. In 2018, Verizon throttled, or slowed down, the service of firefighters as they were battling what was, at the time, the largest wildfire in California history. In reaction, fire departments came out in support of what would become California’s net neutrality law. If California cannot enforce its net neutrality law it will leave its first responders in a weaker position as natural disasters only become more intense.
Most people do not have a choice in ISP as it is. California’s net neutrality law is one of the few things protecting Californians from the whims of these monopolistic giants. Californians should not give up our few hard-won protections in return for a hand out to these behemoths. Tell Governor Newsom to reject this provision before he accepts these funds from the federal government.
Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety
The Big Idea: Marissa Lingen [Whatever]

Does a weapon want to hurt people? What if it had opinions on the type of people it was used to slay? Author Marissa Lingen had these sorts of questions rattling around in her brain long enough that a story formed from them. Take up your (opinionated) sword and follow along in the Big Idea for A Dubious Clamor.
MARISSA LINGEN:
Some big ideas form in an instant, an explosion of brilliance, totally ready to write down and go–the Big Bang of idea formation, if you will. Others are more like planetary accretion. There’s a whole massive whirling disc of random crap, and over time it runs into each other and eventually you have an entire planet with rings and moons. A Dubious Clamor was definitely in the second group.
Twenty-five years ago I read the Francis Peabody Magoun translation of the Kalevala. This is my recommended translation. Rather than trying to preserve rhyme or structure, it preserves weirdness, which for my money is the exact right thing to preserve. Catch me at a con sometime and I’ll tell you about the milk from hell or the insults from your in-laws, as rendered in the Magoun translation of the Kalevala. But the one bit that kept poking at me over the years was when one of the magical swords made by the smith Ilmarinen said, “Probably I was not made for the slaying of young maidens.”
Probably. The sword was willing to leave room for discussion on this point. Huh.
That one word kept popping up in my head: probably. Probably. Maybe not, though! Who knows! Probably. I started to wonder: are there other swords with both opinions and a refreshing unwillingness to lay down immovable dictates? I mean, probably! Why wouldn’t there be? Who would make those swords? Was it all Ilmarinen? Probably not! There are lots of other magical smiths in mythology. Was I a little too obsessed with one word in a translation? Yeah, probably!
But I liked where it was going. I was trained as a physicist (can you tell from my go-to metaphors above?). I was a lab TA for three years. One of the most important things I taught in those lab sections was the section of lab reports devoted to error analysis. I tried to walk lab students through assessing where things might not be perfect, where their own error had a chance to slip in. Several students wanted to write, “There were no sources of error in this lab,” and I had to walk them through why that was in fact not true. But in the outside world I kept watching malicious actors treat uncertainty and error as if they were a sign that you were on the wrong track. As if they had perfect answers that would work every time. As though science acknowledging that it didn’t was a sign of dishonesty. And I kept returning to that sword and the way that it went with. Y’know. Probably.
I can’t say I’m a huge fan of Oliver Cromwell in general, but my favorite thing he ever said was, “I beseech you, in the bowels of Christ, think it possible that you might be mistaken.” He should have listened to himself a lot more on that, but–yeah. At least consider. Think it possible. I can come up with a few contemporary figures who could do some more thinking it possible that they might be mistaken. I bet you can too.
The harpies came later. Jenny Lind and operetta and the alternate history aftermath of a Chartist rebellion and all the little cakes–all of it came later. The first and biggest idea, the one I couldn’t leave alone, was a sword that was not fond of people being all too certain they had all the right boxes to put each other in. That seemed worth raising a dubious clamor about.
BTW, the rootupdates process is working now, you can follow changes via an RSS 2.0 feed, of course. In this version, the feed is the way updates are transmitted. The enclosure on each item is a fat page. And because it's a feed, I can follow it in FeedLand, and the blogroll on scripting.com picks it up too. Screen shot.
[$] Adding BPF to blk-iocost [LWN.net]
The scheduling of block I/O requests has long been a challenge for operating-system kernels. For many years, the performance characteristics of rotating drives meant that putting considerable resources into request ordering was worthwhile. In a world with fast, solid-state drives, scheduling is more concerned with enforcing fairness between competing users while being fast enough to keep up with drives that can perform millions of I/O operations per second. The blk-iocost I/O controller was designed for the solid-state world and generally performs well, but there is always a desire to do better. This patch series from Tao Cui aims to make blk-iocost more flexible by enabling the loading of a BPF program to make cost decisions.
Just got to the place where I'm thinking of what apps I want
to be scriptable with Frontier. First I thought of FeedLand of
course, and WordPress. NetNewsWire and micro.blog, because they're
products from key contributors in the Frontier community with
important products today. What about Mastodon? It's got an API. And
if that worked, we'd hook into AT Proto. The funny thing is the
first web, because much of the new development came from the Mac
community, was built around Frontier. System level scripting was
also a big deal right alongside the web. But then Jobs, in 1997,
rewrote everything, brought in the Unix products, completely
disrupted the good thing we had going as independents. That was
probably the moment when we stopped building around the idea that
you could script all the apps from one place if they had good APIs.
All the server apps all had APIs, had to in order to work on the
web. We seem to have caught up, and the opportunities to connect
things has never been greater. A big door swings open.
Screen shot of my current system.verbs.apps table. You can tell from reading it that it's been a long time since I've thought much about scriptable apps.
Until we start working together and for each other it’s going to keep getting worse.
In many ways JavaScript is a better language than UserTalk.
For example I miss JSON constants. I miss certain language
constructs, like conditional assignments. We don't have the idea of
a const. On the other hand, JavaScript doesn't have environment
features Frontier has. I want to have Atlantis run JavaScript the
same way Cancoon (the codename for the kernel of Frontier before
this version) ran AppleScript.
Paul Tagliamonte: DESFire EV3 [Planet Debian]

I’ve long been interested in hardware key material storage devices. I’ve been a fan of yubikeys (I still remember when my fancy new NEO-N showed up), PIV (and its associated smattering of additional fields), SaaS HSMs, the kernel keyring, some tooling I’ve fairly satisfied with the design of at prior companies, and of course, our dear friend, the TPM. All that is not even to mention the scores of exotic hardware security modules one generally comes across from time to time when you’re keeping a sharp eye out that you wind up playing with.
I have not used any LLMs in the course of this adventure. Not for writing these posts, and not for this code. The intent here was to learn more about how DESFire works. LLMs defeat that purpose.The concept of storing private key material on a disk, or even having it in RAM has always skeeved me out, so I have a natural inclination to hardware modules, and how shifting keying material around can change your risks and threat model(s) in interesting ways.
I don’t remember when I first came across the MIFARE DESFire EV3, but a few weeks ago I did a deep-dive into the state of the art of authentication schemes using ID cards. My complete overview of what tradeoffs exist is pretty extensive (and likely not interesting to the vast majority of the world), but the tl;dr wound up being one of “use PIV” or “use MIFARE DESFire EV3”. I wound up picking DESFire for a recent project, and figured it’s worth talking a bit about what I learned, share some thoughts, and some code. That code is published on crates.io/desox, and docs, as is our custom, may be found at docs.rs/desox
PIV, while oft-maligned, is exceptional for public key cryptography using asymmetric keys, and can safely interoperate with x.509. If any of those things are a hard must, I don't think that's going anywhere.DESFire supports DES (I’m sure most readers saw that one coming), 3DES (I didn’t bother playing with 3DES at all) or AES-128 (AFAICT always use this?) keying material. It’s worth noting that the DESFire only supports symmetric keys and is not designed for public key cryptography, and operates exclusively using shared symmetric key material. The DESFire EV series use those keys and related authentication schemes to interact with “files” stored on the on-chip EEPROM (2k, 4k, 8k, and 16k versions exist), or “applications” (groups of files and authentication keys).
Interactions with the card are done over NFC (ISO/IEC 14443 Type A), and commands to/from the card may be in the usual ISO/IEC 7816-4 APDU format, or “unencapsulated” bytes sent to/from the card are sent using a fixed instruction set and return code structure – saving a few bytes per message. I’ve opted to use their undocumented and proprietary format – I found it easier to work with and with a maximum message of 60 bytes, the savings matter a lot.
I keep calling the DESFire messages I implemented "APDU messages" since I have to use a bunch of API surface saying it is -- but they're not.While powered via NFC, the card maintains a small amount of
state about the connection between the reader and the card in its
RAM, including if the session is authenticated or unauthenticated.
I’ll dig into how authentication happens later, but
it’s worth knowing that sessions can become
authenticated using one of the symmetric keys shared by the card
and the reader. The vast majority of the DESFire
commands I know about tend to work while either authenticated
or unauthenticated, with a few exceptions (GetUid,
ChangeKey, and ChangeKeySettings for
example).
In general, I found working with this card particularly pleasant. There is a fair amount of backwards-compatible behavior and multiple methods of communication that confuse things a bit, but overall, it was better than average to integrate with. Kudos to the NXP team. If the docs on this chip were public, things would be orders of magnitude easier – it’s not entirely clear to my why they’re keeping so much of the interface documentation under NDA, but it’s the largest knock against the chip, by far.
I found a lot of really great resources outlining how the handshake and protocol works for a DESFire EV3, especially from Ridrix, some public datasheets ThrRealRevK and posts from AndroidCrypto.
It's not super clear to me why all of this is under such heavy NDA, surely a robust ecosystem is nothing but good?The gist here is that, because the DESFire only does symmetric key operations, the key exchange (a type of SKA – Symmetric Key Agreement) uses symmetric keys to establish a unique session key which is used to sign or encrypt data exchanged between the reader and the card. I’m not going to get too in-depth here, since there’s a ton of other resources out there to dig into – but I will do a quick high-level description to keep this post mostly self-contained.
The authentication protocol serves two main functions – to
verify that both parties know the same shared secret, as well as to
act as a SKA to construct a new session shared secret key.
Here’s a quick overview of how a shared session key is
derived between the reader and the card using our symmetric keys
(AES-128 in the case below).
AA 00 to start an AES Authentication
handshake with keyslot 0x00).AF (a status code
that indicates more data is to follow), followed by 16 bytes (in
the case of AES-128) of encrypted (using CBC)
data.AF (indicating a
continuation of the previous command), followed by 32 bytes of
encrypted data. When decrypted, the first 16 bytes are our nonce
generated in step #4, followed by the 16 bytes provided by the
card, decrypted in step #3, except where every byte is shifted to
the left by one place (the 0th byte is copied to the end).00 indicating a
successful operation, followed by 16 bytes, which when decrypted,
is our session nonce from step #4, shifted to the left by one byte
in the same way that we did in step #5 with the card’s
nonce.From here on out, the session is “authenticated”, and responses from the card which were previously “plain” will now contain a 8-byte CMAC signature, which can be used to ensure that the replies in question come from the active session.
In my implementation
of the handshake I opted to encode the handshake state into
rust types, just so I wouldn’t make any mistakes. The
Handshake type contains the session internals (session
nonce values, keying state, to include IV, etc). This means the
authentication flow (from within my code) uses the
Handshake struct to generate the commands to send to
the card in order:
/// Create a new `Handshake`, and return the
/// start auth command (something like `AA 00`)
fn Handshake::<Initial>::begin(
output: &mut [u8],
key: [u8; 16],
key_id: u8,
) -> (Self, &[u8]);
After we get a reply back from the card (the encrypted version
of the card’s session nonce, sometimes called
Rnd_B in code I’ve seen), we transition states
from Initial into HalfOpen.
/// Given the card's encrypted response, generate
/// our session nonce and generate a reply
/// (something that starts with `AF` followed by
/// 32 bytes of encrypted data).
fn Handshake::<Initial>::rnd_b(
self,
output: &mut [u8],
input: &[u8]
) -> (Handshake::<HalfOpen>, &[u8]);
Now that we’re “HalfOpen”,
we’re waiting to hear back from the card to ensure that it,
too, can byte-shift our provided nonce. Once we have the
card’s reply, we can check it using our complete
helper, transitioning from HalfOpen to
Successful.
/// Check to ensure that the card replied with
/// our nonce byte-shifted by one place, indicating
/// that they know the symmetric secret in
/// this key slot.
fn Handshake::<HalfOpen>::complete(
self,
input: &[u8]
) -> Handshake::<Successful>;
Once the Handshake is successful, the only thing
left to do is consume the Handshake struct and turn it
into the shared session key by running it through the
key derivation function.
/// Consume the `Handshake` struct and return the
/// new shared session secret key.
fn Handshake::<Successful>::into_key(self) -> [u8; 16];
From here on out we can use this session key for the remainder of our interactions with the card – signing messages from (and sometimes to!) the card, or encrypted messages to and from the card. This key is used in CBC block mode, where the session IV is updated with the last block of the encrypted data.
A nice proprietary of the SKA scheme we’re using as part
of DESFire is that the derived session key is actually
deterministic if you control your nonce RNG (ok, actually, pretty
true for most key agreements, but anyway), which means it is
possible to capture traffic over the NFC interface, and
“replay” the NFC I/O with cooked RNGs and ensure
byte-identical messages and keys are generated. Within
desox-rs this is called replay (I’m
creative), and I’ve got a few replay sessions checked into
VCS, which exercise a signficant amount fo the API surface. All
were derived from an actual session with a real DESFire card, and
can be updated with a live card and a --cfg flag.
Each replay file is a set of lines
(request-response transactions), each containing two
space-delimited hex encoded NFC messages. For instance,
here’s an authentication handshake in replay
format:
1a00 afc7bbd82ff8fefae8
afc6dab54df2278d2952d560821be7e4c3 007d9abe94a9b14748
The code that generated that exchange came from the test stored
adjacent to that file – a handshake with the default DES key
(all zeros), and an RndA value hardcoded to
32c28fdafd3960de.
let mut card = card
.authenticate_with_rnd_a(
0x00,
Key::Des([0; 8]),
Key::Des(hex_literal::hex!("32 c2 8f da fd 39 60 de")),
)
.await
.unwrap();
Since the card’s RndB is similarly unchanging
(I’m replaying this file every time), this will always derive
the same session key, which means messages (including encrypted
ones or CMAC signed responses) will be identical, as well. If
you’re playing with the DESFire yourself, feel free to grab
my replay
files if you need a “known good” baseline.
By default this will run using the MockBackend,
replaying each file – expecting a byte-identical request, and
responding with the harcoded customary reply. If the code (or
test!) needs to change, updating the tests is done by swapping the
MockBackend out for a real one. Since I had to do this
a bunch during development, running cargo test with
RUSTFLAGS="--cfg desox_replay_rw" will, on run,
overwrite the replay file(s) for the executed test(s), ensuring all
line-protocol changes are explicitly caught and reviewed.
Most commands, even ones which require authentication, are
transmitted without CMAC signature(s) or encryption.
CMAC signatures from the reader to the card are not
really used (except for writes to a file which specifies
communication must be CMAC signed), ditto for
encryption (although that one is used for key change operations, in
addition to file writes on files that specify encrypted
communication must be used). The vast majority of commands take a
“plain” request from the reader, and return a CMAC
signed response.
By my eye, this means that a malicious reader, or something
otherwise capable of holding the card online after communication
with an authentic reader is complete are able to execute privilaged
commands (since one can simply ignore the CMAC
signatures on responses), so long as the command doesn’t
require the reader to provide CMAC signatures (or encryption), or
allow the card to power down.
I’ve played around a bit with ways to use the DESFire cards in interesting configurations, given what they’re capable of. Here’s some half-baked thoughts I had while mucking around with the cards – these are all poorly thought out sketches of some things we can do given the specific tradeoffs I see with the DESFire card. It’s also worth noting that I don’t have any of the actual documentation, and am not a cryptographic grown-up, so take these sketches with a massive grain of salt.
This stuff is right around when I really miss having asymmetric cryptographic operations handy.The first thing that came to mind when implementing this is how the authentication scheme can shift the boundary of what is and is not trusted (assuming good secure keying, and provided the key slots and card/application permissions are configured correctly). Rather than push the key material out to the machine connected to the NFC reader (“reader machine”), I instead tried turning the NFC reader and computer into something psuedo-untrusted by “merely” having it pass messages from the card to a trusted remote system (“remote machine”). This means that the “reader machine” is exchanging NFC data with the card, but that data is being decrypted, encrypted and processed by the trusted “remote machine” – the reader is unable to derive the session key.
For each of these, I wind up needing to authenticate – so there’s still a few latent risks, but these can mostly be mitigated by asking for a readbacks of any changed file(s), setting key permissions carefully, and requesting the card’s UID via the encrypted channel – all of which would require the symmetric secrets (which undermine the whole security model if comprimised).
This all feels a bit messy at times -- but I have to keep grounding myself in the threat model -- "if you have the key, you can clone the card (or snoop the session key)"This general construction is also subject to a hostile takeover
of the untrusted “reader machine”, since most commands
(including destructive ones!) are sent in
“PLAIN” mode – the reader machine
can wait until authentication is complete and then inject commands
into the card and “simply” ignore the CMAC signatures
on responses, severing ties with the remote machine. As such, we
also need to take steps to ensure that the key being used is not
one that allows any access beyond what is allowed. Here were some
ideas I sketched out off the back of this theory.
Given some established (and authenticated) connection, part of the initial authentication flow may use the DESFire card to prove physical control over it as part of a handshake. This can serve as a second factor during some authentication flow, requiring physical card presence at a reader to fully initialize a connection. This does have one glaring downside, however – it’s phishable. To use this “for real”, we’d need to take some steps to prevent obvious MITM flows (XOR the NFC messages with the URI as seen by the client?), but maybe there’s something interesting there.
WebAuthN is objectively better in basically every way to this -- this scheme has some heafty downsides, but also a few interesting properties.This also has a second interesting attribute – when used as part of a physical system authentication flow, this becomes a logical place to inject access control, being able to determine if some person is permitted to operate some device at that particular time (Is “Joe” current on his Laser Cutter certifications?) I think of the ideas I landed on, while conceptually interesting (using an employee id card as a 2FA token, it’s very fast), this one is the least likely to turn into something real.
This construction, when paired with an encrypted DESFire file, allows the “remote machine” to read/write an ’encrypted cookie’ to the card – storing small amount of encrypted data that the “remote machine” can read/write, but not the “reader machine”, since this uses an encrypted and authenticated channel from the “remote machine” directly to the DESFire card, without any intermediate hosts needing to be fully trusted. I keep calling this the “encrypted cookie” in my head because it feels conceptually similar to how Ruby on Rails and Laravel handles cookies.
I never really liked encrypted cookies.We’d need to take a few extra steps here (for instance, ensure that you read the cookie back over the encrypted channel after writing to prevent a malicious reader from dropping writes) to secure the system, but it feels like the structure of this is definitely decent.
This time, let’s say the computer attached to the NFC reader (“reader machine”) is semi-trusted. For this scheme, our trusted “remote machine” and the “reader machine” pass messages over the network to handle authentication to the card (as above), where the handshake data is being decrypted, encrypted and processed by the trusted “remote machine” as usual. However, once the authentication handshake is complete and a session key has been derived, the “remote system” return the session key to the “reader machine”, giving it a one-time-use key and authenticated session to the card.
Like a hermit crab.We need to be careful about global/application permissions and key access control to files – but in this construction, we can allow the “reader machine” to take over privileged actions using a scope-limited DESFire key without handing over the card’s true keying material (preventing cloning of the card). This can be helpful to ensure messages to/from the card are truely from the card (verifying CMAC signatures), enables the “reader machine” to directly read/write to/from encrypted file(s), but allows the symmetric key material to remain in as few places as possible – which is critical given compromising that secret will undermine the security of the entire system.
Vondra: PostgreSQL development activity [LWN.net]
PostgreSQL contributor Tomas Vondra has published a blog post looking at development activity in the project, with data from the late 1990s to today.
We're doing ~50 commits per week, give or take. In ~2010 we were doing maybe 25/week, and the trend seems to be a slow and consistent growth. The monthly average makes the trend a bit easier to spot. Which is good, although there's a lot of other important details (size of commits, are they new features or fixes, ...).
It however nicely aligns with the number of active committers, which also grew ~2x between 2010 and today. So maybe that's working as expected.
Security updates for Tuesday [LWN.net]
Security updates have been issued by Debian (network-manager-l2tp and urwid), Fedora (perl-Dancer2, perl-Data-Entropy, perl-DBI, perl-Protocol-HTTP2, podman-tui, rust-lru, and rust-lru0.16), Mageia (bzip2, cups-filters, libcupsfilters, libssh2, perl-Authen-SASL, perl-HTML-FormFu, tar, unzip, and zip), Red Hat (grafana and image-builder), SUSE (389-ds, acl, attr, apache2-mod_auth_openidc, apr-util, aws-nitro-enclaves-cli, bzip2, c-ares, clamav, cpio, curl, dhcpcd, dovecot23, dovecot24, dracut, emacs, fuse-overlayfs, go1.25-openssl, go1.26-openssl, google-cloud-sap-agent, google-osconfig-agent, govulncheck-vulndb, gstreamer-devtools, gzip, helm, java-17-openjdk, java-21-openjdk, java-25-openjdk, jq, libBasicUsageEnvironment2, libgpg-error, libidn, librest, libusb-1_0, libvirt, LibVNCServer, libzypp, zypper, lkl, mcphost, MozillaFirefox, mozilla-nspr, mozilla-nss, rust-cbindgen, MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen, MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen, msgpack-c, multipath-tools, NetworkManager, openexr, openssl-3, perl-Protocol-HTTP2, perl-URI, php-composer2, postgresql14, postgresql15, postgresql16, postgresql17, postgresql18, python-aiohttp, python-cryptography, python-h2, python-ruff, python-sqlparse, python311, python312, python39.SUSE_SLE-15-SP3_Update, rav1e, rpcbind, sssd, systemd, tomcat, tomcat11, ucode-intel, udisks2, vim, and wicked2nm), and Ubuntu (cgit, dracut, freeciv, konsole, libinput, linux-azure, linux-nvidia-7.0, nginx, vips, and yelp).
GNUHealthCon 2026 – XI Free Software and Social Medicine Conference [Planet GNU]
Dear community
The XI edition of GNUHealthCon will take place in Gran Canaria, Spain, this December 18th, and you are invited!
This edition is special for us because we will be celebrating the 20th anniversary of the first GNU Solidario mission that took place in Santiago del Estero, Argentina in October 2006. That remote rural school, the teachers, the children and their families generated a profound inspirational impact on me, so deep that since then I have dedicated most of my life to the field Social Medicine. GNU Health is both a result of that experience, and the main channel to deliver freedom and dignity around the globe.

In this edition, besides the technical and social talks, we will have the space to commemorate these 20 years. During these two decades we have gone through many things. We have many happy stories to share, but we also have sad ones, that made us learn and be more resilient. Stories of people from countries around the world that have conformed this wonderful community around GNU Solidario. Stories and experiences that have made GNU Health the leading Free/Libre Health and Hospital Information System.
I want to personally invite all of you who has been part of this beautiful journey: The GNU community; hospitals and health institutions around the world that use GNU Health; sister projects (Tryton, Orthanc,..); national and regional governments that have adopted GNU Health; sponsors; the open science and academic communities; developers and core team members… you are all part of the success of the project and we have to celebrate this edition together.

GHCON2026 will be on Friday, December 18th in Gran Canaria. The night before we will have the pre-conference party. Most probably, the event will be in a hotel in the mountains, and the idea is to arrive to the hotel on Thursday 17th. We will update in our official Mastodon account. (look for #GHCon2026 hashtag)
Please make sure you register (https://www.gnuhealth.org/ghcon/2026/) so we can prepare de logistics.
Looking forward to meeting personally all of you, and have a wonderful time in Gran Canaria!
Love and happy hacking
Luis
CodeSOD: An Odd Sort [The Daily WTF]
Let's say we wanted to query Active Directory and print out a report of all of our users, and their last logon time. That seems like a pretty normal task for a Powershell script. It'd probably be short and easy to read, at least if it were written by a normal person.
Alice sends us one that wasn't. She's already done us a favor, as she writes: "Code cleaned up and indented for the whitespace-missing-impaired."
#####################################
# lists accounts and selected attributes alphabetically
#####################################
foreach( $letter in "a", "b", "c"......"z")
{
$strfilter = $letter + "*"
$objdomain = New-object System.DirectoryServices.DirectoryEntry
$objSearcher = New-object System.DirectoryServices.DirectorySearcher
$objSearcher.SearchRoot = $objdomain
$objSearcher.Filter = $strFilter
$objSearcher.PropertiesToLoad.Add("name");
$colResults = $objSearcher.FindAll()
foreach($result in $colResults)
{
$name = $result.Properties.Name
$searcher = New-Object DirectoryServices.DirectorySearcher([adsi]"")
$searcher.filter "(&(objectCategory=User)(sAMAccountName=$name))"
$users = searcher.FindAll()
foreach($user in $users)
{
Write-Output $user.properties.item("name") + "," + $user.properties.item("lastLogon")
}
}
}
This accomplishes sorting alphabetically by iterating across the
alphabet. Which, I suspect, isn't going to actually get them in
alphabetical order; it makes sure that albert and
alice appear before bob, but doesn't
enforce that albert must come before
alice.
In any case, we iterate across the alphabet, and then create a
searcher that finds a*, then b*, etc. We
explicitly tell the searcher that the only property we care about
is the name field, so that we don't load unnecessary
fields, like the ones we want to report on.
We then iterate across the list of names, construct a new searcher, and search for the account with the username we fetched. That lets us get all of the fields we need, including the ones we aren't going to use.
Now, we search for a username, so we expect there to only be one
result, but since searcher.FindAll() returns an array,
we "need" to write a loop to iterate across the array of one, which
is clearly a better choice than using the FindOne
function.
As it usually goes with these sorts of things, one of the managers absolutely adores the fact that they have an easy way to generate a CSV file that they can manipulate in Excel, so this terrible script is "mission critical".
Beyond Navier–Stokes: Who Controls Scientific Discovery? [Radar]
Is the current furore in mathematics the canary in the coalmine for experimental science and knowledge work?
This post was originally published in Vanishing Gradients on September 11, 2026. It has been updated to address the subsequent declaration by 25 Fields Medalists and the debate about AI, mathematical progress, and research incentives.
“For seven and a half
million years, Deep Thought computed and calculated, and in the end
announced that the answer was in fact 42—and so another, even
bigger, computer had to be built to find out what the actual
question was.”
―Douglas Adams, The Restaurant at the End of the
Universe
I recently went back to Dresden for the 25th birthday of the Max Planck Institute (MPI) of Molecular Cell Biology and Genetics, where I did part of my postdoc. The MPI was founded to research the physical and biological mechanisms of cells to bridge the gap between the molecular and tissue scales. At the anniversary conference, Michael Bronstein (DeepMind Professor of AI, University of Oxford) delivered the keynote, “Biological Black-Box Data in the Age of AI.” His argument went something along these lines: Biological experiments should generate data optimized for machine learning, even when those measurements aren’t directly interpretable by humans. He argued for prioritizing scale over the quality of individual measurements, producing vast amounts of cheap, noisy data from which noninterpretable models can extract signal.
When asked whether such systems could produce the understanding offered by Newton’s theory of gravitation in a single equation (bridging the scales of an apple falling on your head to that of the moon and the tides), Bronstein responded that this wasn’t the goal: Black-box data and models would, if anything, produce equations with tens, hundreds, thousands, or more noninterpretable parameters. Outcome prioritized at the expense of insight and understanding. He suggested we could gain that understanding by interpreting the black-box models afterward.1 I was startled to see Bronstein bring such a worldview to an institute founded to understand molecular and cellular mechanisms and the emergent properties at the tissue level.
The MPI was unusual within the Max Planck Society for its collaborative structure, with directors leading relatively small groups alongside independent research groups. At the anniversary’s opening, founding director Marino Zerial explained how they had collaborated so effectively from the start. He said they shared a taste for mechanistic science. This made me think of how often we talk about “taste” and “judgment” when describing the human role in the age of AI.
The worldview that we don’t need understanding or insight isn’t new. In his 2008 essay “The End of Theory: The Data Deluge Makes the Scientific Method Obsolete,” Chris Anderson argues that big data allows us to skip hypotheses, models, and testing. Bronstein invoked Anderson’s vision of post-theory science in his MPI keynote, as he does here also, presenting DeepMind’s AlphaFold as an example of experimentally testable predictions without a human-understandable theory of protein folding. Part of Anderson’s project is to champion big tech, and the future of science becomes a vehicle for doing so. His essay ends: “What can science learn from Google?”
AI gives this worldview a new form: Machines can produce results that withstand verification while the understanding needed to explain them remains out of reach. Developing that understanding takes time, access, and collaboration. Whoever controls those conditions gains power over what people can understand and pursue.
Mathematics makes this possibility particularly stark. I’m excited by AI’s potential to expand what we can discover. Fields Medalist Terence Tao has organized collaborative research combining mathematicians, AI tools, and formal proof verification. His questions about mathematics in the age of AI come from engaging with that potential and asking what we want it to serve.
Tao has noted that we’re producing more verified mathematical proofs that no individual human understands. A world of an abundance of verified mathematical proofs! Tao points out that our peer review, academic incentives, and journals weren’t designed for this abundance. The existing system is already broken, tying careers to publication counts, relying on researchers’ unpaid reviewing labor, and locking much publicly funded knowledge behind commercial paywalls. Reviewers already struggle to keep up with the volume of submissions. AI will multiply that volume far beyond what this system can handle.
Tao also describes fruitful open problems as nonrenewable resources: problems whose pursuit can generate new techniques, collaborations, and understanding that extend far beyond the original question. Once the answer is known, the incentive to explore those paths can disappear. For example, 10,000 OpenAI agents working concurrently may have solved the Navier–Stokes Millennium Prize problem. (The announcement has also sparked a dispute over credit and competition, bringing the question of who controls mathematical discovery into sharp focus, which I’ll get to.) A common conceit in science and mathematics is that solutions open up new questions and fields of inquiry. Tao’s point is that the search for a solution does too. Tao argues that proposing a solution, discovering precisely why it fails, and revising it can reveal new insights into fluid mechanics. Knowing the final answer beforehand can discourage that exploration:
“The process of starting with one ansatz, discovering the precise obstruction preventing it from working. . .would almost certainly reveal important new insights about fluid mechanics.”
—Terence Tao, Mastodon, September 3
Late last month, probabilist Hugo Duminil-Copin gave another example: Unsuccessful attempts at a percolation conjecture led to collaborations and revived techniques that subsequently solved other problems. Both acknowledge AI’s capabilities while asking what the pursuit of mathematics should produce.
This brings me back to Bronstein’s proposal to recover understanding after building the model. Would interpreting that model give us Maxwell’s equations, and the understanding that connects electricity, magnetism and light? The promise feels a little like plugging Neo into a computer: “I know kung fu.” In the Matrix, downloading the knowledge gives him the ability. Receiving a machine’s result doesn’t do that for us. As Tao and Duminil-Copin describe, understanding why an approach fails changes what researchers try next, generating new questions, techniques, and collaborations. Recovering an explanation afterward may teach us something, but it can’t recreate the paths that understanding would have opened during the search.
These questions are becoming pressing as results accumulate. Over the past year, AI systems have produced new mathematical constructions, tackled unpublished research problems and formalized existing proofs. Since July, announcements have arrived in quick succession:

These achievements involve different kinds of work. Formalizing Fermat’s Last Theorem means making an existing proof checkable by a computer; finding a counterexample establishes something new. A system can produce a verified result while the work of explaining it remains to be done.
Some of that work is happening through wonderfully strange exchanges on X, where researchers post new results, check one another’s constructions, and develop explanations. It’s reminiscent of when science in Europe was people passing notes and sending letters on horseback:
Tao’s geometric explanation and Lamzouri’s shorter proof help turn verified results into mathematics people can understand and build on. Responding to an early draft in our Discord community, Carol Willing, a Python core developer, former Python Software Foundation director, and longtime leader of Project Jupyter, asked:
While I believe these tools have value for advancing science/math, do they have more value than a human scientist or group of scientists who can view and challenge open results?
If we judge value by who produces a result first, we miss what Lamzouri and Tao contribute by simplifying a proof or explaining its geometry. An answer can close off some paths of inquiry while creating others. I want much more of this: machines producing results that people can explore, explain and build on together. These exchanges depend on results being available to examine, researchers having time to understand them, and people being able to share what they discover. Those conditions deserve as much attention as the systems producing the proofs.

Why the explosion in AI-generated mathematical results now? As Sebastian Raschka explains, reinforcement learning with verifiable rewards (RLVR) became a major technique in model post-training in 2025. The premise is straightforward: If you can computationally check an output, you can reward correct answers and update the model accordingly. Code can be run against tests; mathematical answers can be checked, and formal proofs verified by tools such as Lean, a proof assistant that checks each logical step against specified axioms and previously established results (recently used by Anthropic to formalize the proof of Fermat’s Last Theorem!). That provides feedback without a human grading every attempt. These checks also guide agents during problem-solving: An agent can propose a proof, use Lean to check it, and use the resulting errors to revise its attempt, repeating the process without a person checking every step.
You may ask, Why did coding agents become useful before we saw this explosion in mathematical results? Well, the labs had an immediate incentive to improve the tools they use themselves. Engineers building AI systems want better coding agents to help build those systems. Improve the machine that improves the machine. Mathematics benefits from the resulting capabilities too: agents that can write programs, run experiments, and work with automated checks.

On September 11, 25 Fields Medalists issued a declaration warning that the race to solve benchmark problems was undermining mathematics. Some responses on X treated this as professional protectionism; others assumed that understanding would follow the proofs. That brings us back to Bronstein’s proposal, and to who gets to decide that producing results comes first while other researchers supply the explanations afterward.
Many assume that the goal of pure mathematics is to produce results. Tao’s point is that pursuing those results also develops methods, understanding, and people capable of asking better questions. Solved problems have served as a proxy for that broader progress. Goodhart’s law describes the danger of turning the proxy into the target. AI mirrors our incentive systems and is exceptionally good at pursuing what they reward. If schools reward the essay over learning, students will generate essays. If mathematical prestige attaches primarily to solved problems, labs have every incentive to produce them.
Producing results and developing understanding aren’t mutually exclusive, but the current system makes pursuing both prohibitively difficult. Frontier labs have strong incentives for outcomes rather than insight. (See, for example, Anthropic’s incentives for solving Millennium Prize problems with Claude pre-IPO, discussed in Gavin Baker’s commentary on Anthropic’s pre-IPO positioning; Samuel Kerr makes a related argument about OpenAI’s mathematical results and its IPO narrative.) OpenAI’s run involved 10,000 agents working concurrently for 88 hours. Abhishek Nagaraj, associate professor at UC Berkeley, calculated this would cost a regular user $20–$30 million in tokens.
NYU mathematician Tristan Buckmaster says OpenAI pressured him to publish without his collaborator Levent Alpöge, who works at Anthropic. OpenAI’s Sébastien Bubeck disputes his account. Buckmaster also describes how the pressure affected the mathematics: He and Alpöge had verified their proofs but wanted more time to understand them and produce readable explanations. Instead, they rushed to publish work they considered inadequately explained. If understanding is deferred until after the result, what ensures that anyone gets the time, resources, and access to develop it?
What’s worse is that we’re not even sure whether using OpenAI agents could result in them scooping you. It looks like they’re not sure either:
While unlikely, we cannot rule out that de-identified data derived from their usage of our products helped improve our models.
In “The End of Mathematics,” mathematician Daniel Litt imagines researchers withholding unfinished ideas for fear of being scooped. The collaborations Duminil-Copin describes depend on people being willing to share work before it succeeds.
If researchers stop sharing promising ideas for fear of being scooped, companies with the most computation gain greater control over what others can learn. A published proof may be available to everyone while the failed approaches and intermediate insights remain private. Threats to public research funding in the US compound that dependence: Companies supplying the resources gain greater influence over what science gets done. This brings us to Shoshana Zuboff’s questions about knowledge and power: “Who knows? Who decides who knows? Who decides who decides?” Who gets to pursue a fruitful question, and who determines whether the work behind its answer becomes shared knowledge?
The movement of AI researchers from academia into industry concentrates expertise alongside those resources. And I get it: If I wanted to return to doing research in depth, frontier labs would be among the most attractive places to work. Access to capital, data, computation, and incredibly talented colleagues can make research possible that would be difficult to pursue in academia. The attraction for individual researchers is clear, even as their collective movement gives companies greater influence over research priorities and leaves universities with fewer people to teach the next generation. Thinking about this brain drain, it isn’t lost on me that Bronstein is the “DeepMind Professor of AI” at Oxford. Corporate influence reaches into the universities themselves.
Students also need opportunities to develop the judgment we keep asking humans to exercise. Po-Ling Loh describes the difficulty of advising students and postdocs as AI changes research expectations. Choosing a fruitful problem, recognizing why an approach failed, and deciding what to try next are abilities developed through doing mathematics. If students delegate that work before developing those abilities, where will their judgment come from? AI could also help them explore more approaches and work through unfamiliar ideas, provided their understanding remains an explicit purpose of the process. That requires mentors with time to teach, and institutions willing to support work whose value includes what the researcher learns, even when a machine could produce the result faster.
When careers depend on producing papers, time spent explaining a result, simplifying a proof, or helping others understand it can compete with the pressure to publish the next one. Martin Hairer argues that authors should understand their arguments, trace ideas to their sources, and explain AI’s contributions. Those responsibilities become harder to fulfil when results arrive faster than researchers can absorb them. Universities, funders, and journals will help determine whether mathematicians can afford to do that work. If we value shared understanding, then developing explanations, teaching difficult ideas, and making proofs useful to other researchers need to count toward careers as well. Otherwise, the institutions asking people to exercise judgment may reward them for spending less time developing it.

After Bronstein’s keynote, we sat in a Dresden beer garden eating currywurst and drinking radlers. It was late summer, and the conversations were wild. Cell biologists, biochemists, mathematicians, and engineers were asking what this future meant for them. Some were scared. Others thought it was inevitable and would turn scientists into something like artists. Because I now work in AI, people asked me, “Do you think this is where things are going?” They wanted to know what the human’s role would be and how scientific knowledge would be passed down. I started telling them about mathematics. The prospect of abundant results without shared understanding was already raising the questions we were asking over our beers.
In biology, a proposed result still has to meet the physical world: Someone has to prepare samples, run experiments, and measure what happens. Robotics and laboratory automation will let agents carry out more of that work, giving individual scientists the capacity to direct experiments that once required an entire group. Perhaps more scientists become PIs of automated labs, choosing questions and supervising agents and instruments. But the work being automated is also how students, postdocs, and technicians learn. Handling a sample, noticing something unexpected, and figuring out why an experiment failed develop judgment that directing a system may not teach. Who gets to acquire that experience before they’re expected to lead?
Researching a policy brief, building a financial model, or developing a product strategy helps people learn the territory in which they’ll make decisions. In my work with agentic data science, I encourage people to explore data cell by cell with an agent, because working through the analysis develops the understanding needed to decide what to ask next. Across knowledge work, these tasks are also how junior colleagues develop expertise. If we automate their production, how do we preserve the learning and judgment developed through doing them? We could increasingly depend on models to hold and transmit expertise, with knowledge passing from model to model, then to humans who consult them as oracles. Whoever controls those systems gains power over what we can investigate and learn. Human understanding has to be part of what we’re trying to produce.
Mathematician Jared Duker Lichtman has proposed a Mathematics Atlas Project to formalize the existing mathematical literature, arguing that sufficient funding and computation could make this possible within a year. A library of computer-checkable mathematics could let researchers build on established results with greater confidence, while agents help find connections and assemble arguments across fields. It could also become a resource for learning, if people can connect formal proofs to explanations they understand. Achieving that would require deliberate work on access, exposition and teaching alongside formalization. We have an opportunity to build tools that help people explore mathematics more deeply, provided we make that part of the project.
The MPI in Dresden was founded to understand how cells work, how molecular mechanisms give rise to the behavior of living tissue. I want AI to help us pursue that ambition, including through approaches we could never have attempted before. But human understanding belongs among the things we ask this work to produce, with time and resources devoted to developing it. So does the ability to share what we learn and choose what to investigate next. If we leave those decisions to the companies supplying the machines, we also leave them to decide what scientific progress is for.
Want to understand how AI agents actually
work? In Build AI Agents from First
Principles, we’ll build an agent ourselves, then rebuild
it with a modern SDK and MCP. You’ll leave with a working
agent, code you can adapt, and the understanding to diagnose
failures and decide what your system actually needs.

Vanishing Gradients is independent, and most of the podcasts, workshops, articles, skills, and workflows I publish are free.
If you’d like to help keep it going:
︎Is cybersecurity part of your job in any way? If so, we’d like to know what you think for a report we’re writing. Just answer these quick 11 questions. Thanks in advance! Take the survey >
Spiderlight [Judith Proctor's Journal]
Spiderlight
by Adrian
Tchaikovsky
My rating: 5 of 5
stars
Absolutely brilliant book about what happens when a prophecy leads
a group of adventurers to an ancient forest, and they realise that
the only way to fulfil their quest to kill the Dark Lord is to take
a 'Mirkwood' giant spider with them.
Needless to say, the spider isn't incredibly happy about this. Nor
are the adventurers...
Lots of humour, plot twists, etc. But what gets this book its fifth
star is that it also makes you think.
What are Dark and Light, Good and Evil?
Why are things/actions one or the other?
How and where do the categories overlap?
View
all my reviews
comments
25 Years of Mass Surveillance Is Enough [Schneier on Security]
This essay was written with Cindy Cohn, and originally appeared in Lawfare.
One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in immigration actions and against people exercising their First Amendment rights to protest. It’s also increasingly part of private security systems, such as facial recognition at venues such as Madison Square Garden and networked Flock license plate capture systems on roads and in parking lots.
The interrelation between private and governmental mass surveillance is worth examining. Surveillance is the business model of the internet; companies like Google and Facebook constantly spy on their users’ behavior. From the National Security Agency relying on data collected by telecommunication and internet companies, to local sheriffs and ICE agents relying on cellphone location data and privately managed automatic license plate readers, governments primarily obtain the mass surveillance information through private companies. Increasingly, access doesn’t just come through legal processes, either. FBI Director Kash Patel recently confirmed in congressional testimony that the agency is purchasing information on Americans from data brokers and intends to continue to do so.
This pipeline from private collection to governmental collection means that as companies collect more information for surveillance capitalism purposes, more is available to law enforcement as well. And as the technology for mass surveillance and analysis improves, especially with the increased use of AI technologies, the problems attendant to mass surveillance grow as well.
After 9/11, the idea that the government could surveil the population to safety took hold. In 2001, the fear of terrorism reached a frequency and intensity never before seen. Along with that came the fear that the enemy could be anyone, anywhere. As a result, the government’s response was to watch everyone, everywhere. This line of reasoning underpinned the shift from targeted to mass surveillance. Or, in the words of an internal National Security Agency (NSA) presentation that was made public as part of Edward Snowden’s 2013 disclosures, a government that can “Collect it All,” “Process it All,” “Exploit it All,” “Partner it All,” and “Sniff it All,” will ultimately, “Know it All.” Similar rationales support the rise of domestic mass surveillance: if law enforcement could see and hear everything, it could more effectively interdict and solve serious crimes.
The national security community has never provided a full analysis of the costs and benefits of these mass surveillance programs, either in terms of taxpayer dollars or diversion of resources from other efforts—or any demonstration that those techniques stopped attacks that otherwise they would not have been able to prevent. While the NSA occasionally presents examples of the successes due to its mass surveillance programs, especially when those techniques are under public pressure, the examples also regularly fall apart upon serious scrutiny. And even if some utility exists, it must be seriously weighed against the costs.
Similarly, there has never been any comprehensive analysis about whether domestic immigration or law enforcement’s use of these techniques actually makes people safer, or whether other techniques could produce the same results. Instead, both the police and the companies selling these tools float anecdotes and dubious data. For example, Flock’s data equates the number of law enforcement hits in their database with actually solving crimes.
Twenty-five years after 9/11, it seems reasonable to step back and evaluate the costs of this shift to mass surveillance, especially in terms of Americans’ rights and freedoms.
The easiest place to see a shift to mass surveillance was in the government’s decision immediately after 9/11 to collect Americans’ telephone records. The program started under an argument of pure executive power as the “President’s Surveillance Program.” But in 2006, that argument secretly shifted to a novel interpretation of Section 215 of the Patriot. Act which had only previously authorized more targeted access to record. While some media and public interest organizations struggled to force the government to reveal the program as early as late 2005, the government only officially confirmed it after the 2013 Snowden disclosures. In 2015, the Second Circuit Court of Appeals rejected the government’s interpretation of Section 215 as allowing mass collection of telephone records. Later the same year, Congress passed the USA Freedom Act. While this new law still allows collection of a tremendous amount of domestic telephone records, it ended the indiscriminate mass collection that had occurred for nearly fourteen years.
Other shifts to mass surveillance continue through today. The NSA launched its Upstream program, which involved intercepting both metadata and content from key telecommunications junctures inside the U.S., soon after 9/11. It was also initially conducted under a claim of purely presidential authority. This program was brought under marginal congressional and programmatic (not targeted) Foreign Intelligence Surveillance Act (FISA) court review via Section 702 of the 2008 FISA Amendments Act. In 2017, more than15 years after its inception, the NSA ended content searches due to FISA court pressure, but the mass collection continues.
Despite the stated goal of conducting mass spying only on people outside the U.S.—which itself is problematic given international law’s requirement that surveillance be both necessary and proportionate—mass surveillance collects a tremendous amount of U.S. persons’ communications. This can happen because people communicate with people abroad, or because of overcollection—when government agencies gather far more personal data on non-targeted US persons than authorized by law. The concerns about collecting Americans’ data on U.S. soil led Congress to allow the program to officially expire in 2026, although the previously-approved mass surveillance itself continues until at least Spring of 2027.
The shift to mass surveillance would be notable enough even if it remained only a strategy of the intelligence community. It has not. Americans are awash in mass surveillance. Networks of automated license plate readers such as those offered by Flock and Vigilant Solutions blanket both public and private roadways and parking lots. These networks often allow searches by law enforcement, including across jurisdictions. They are, for example, being used to track people seeking abortions across state lines. Facial recognition tools, once the province of only the more elite parts of federal law enforcement, are increasingly used by Immigration and Customs Enforcement agents on immigrants and protesters, in airports by the Transportation Security Administration, as well as by private entities. And, of course, modern phones track users’ locations constantly—and that information is readily available to law enforcement, often with only minimal process protections.
Regardless of the murkiness of its actual usefulness, the shift from targeted to mass surveillance has profound implications for Americans’rights. It has created risks that have become increasingly evident, especially under the Trump administration.
At a basic level, the Fourth Amendment guarantees that citizens can be secure in their “persons, houses, papers and effects” from unreasonable searches. Warrants breaching that security should be supported by probable cause and particular descriptions of the place to be searched and items to be seized. Mass surveillance turns that promise on its head, allowing access to our “papers and effects” by the government without individualized suspicion or a particularized description of what data is being seized, much less probable cause. This protection was in response to colonial British misuse of writs of assistance, which authorized indiscriminate searches rather than targeted ones.
The justifications for exempting mass surveillance from constitutional protection vary. For Section 702, the government has taken the position that U.S. persons’ communications caught up in the dragnet, either due to overcollection or because they were communicating with someone outside the United States, do not require a warrant prior to initial collection or secondary access by the FBI and several other agencies. The argument is that if the initial collection was not aimed at Americans, the information is free from constitutional protection for any later uses, even for reasons far afield from the initial rationale for collection.
Other arguments rest on the claim that metadata is outside the Fourth Amendment, despite its demonstrated ability to reveal intimate details of all of our lives. Still others rest on the Supreme Court-created Third Party Doctrine, which holds that the Fourth Amendment does not apply to data shared with companies that provide us with services. Some turn on whether analysis by machine counts, claiming that only “human eyes” matter—a particularly troubling argument with the rise of artificial intelligence. What’s more, the government has used doctrines like standing to limit the ability of those subjected to mass surveillance to seek constitutional protection. No matter the argument, the goal is the same: to place the mechanisms and fruits of mass surveillance outside the protections of the Fourth Amendment.
The overarching truth is that, due to the concerted efforts by the government since 9/11, and the rise of technologies in recent years, the slice of Americans’ lives and data that are actually protected by the Fourth Amendment has shrunk significantly in the past 25 years. Together, with the technical capabilities of mass surveillance and the increased ability for that data to be analyzed using AI tools, the “security in our papers and effects” that the constitution promises seems increasingly illusory.
In addition to the Fourth Amendment, mass surveillance creates tensions with the First Amendment. The Constitution has long recognized that the right to freedom of speech requires a zone of privacy against governmental surveillance. The right to anonymous speech as well as the right of association both recognize the chilling effect that surveillance creates for people saying unpopular things or attempting to organize for political or other societal change. Mass surveillance grants the authorities the ability to track those people, both in real time and historically, that is inconsistent with actual techniques of freedom of speech and assembly.
That is why the recently released 2026 U.S. Counterterrorism Strategy is so troubling. On page seven, the White House expressly states that it intends to target domestic activists with its heretofore foreign-targeted powers. It says that the government “will prioritize the rapid identification and neutralization of violent secular political groups whose ideology is anti-American, radically pro-transgender and anarchist” and “will use all the tools constitutionally available to us to map them at home, identify their membership, map their ties to international organizations like Antifa.” While framed as targeting “violent” groups, it’s clear that the government intends to use its national security tools, presumably including the tools of mass surveillance, against Americans in ways that will create profound tensions with the First Amendment rights of people to organize and communicate privately.
Even assuming some utility from mass surveillance—a fact we do not dispute, even if the public record is shaky and conclusory—the history of both the national security and domestic uses of mass surveillance confirms that these tools are inevitably misused, and that mistakes have impacted huge numbers of Americans. The past twenty-five years have demonstrated that it is not possible to surveil the entire US population while staying within the bounds of even a very generous legal framework like Section 702.
As Rep. Zoe Lofgren (D-Calif.) recently stated in discussion of Section 702 in an interview with Tech Policy Press: “backdoor searches have been used improperly for protestors, 19,000 campaign donors, members of Congress, journalists, government officials, a state court judge who had complained to the FBI about police misconduct. It has been abused substantially in the past.” The NSA experienced so much abuse of its mass surveillance tools by actual or aspiring romantic partners and ex-spouses that an internal name emerged for it: “LOVEINT,” or Love Intelligence.
That same pattern of abuse is now emerging at the domestic law enforcement level. A Texas police officer misused, and then lied about, using license plate readers to track a woman suspected of seeking an abortion. Multiple law enforcement officials have been accused of tracking people they either wished to have a relationship with or who were their exes. And mass surveillance technologies have been used to track both immigration targets and citizens engaging in their First Amendment-protected right to track and record the police.
Mistakes are inevitable with collections of data of this size and scope. The history of the FISA court’s reviews of Section 702 is littered with examples of the NSA not being able to follow its own rules limiting the scope of what it collects and analyzes, even after having been given multiple chances by the court. On the local level, the technical protections that Flock, for example, put in place have repeatedly been insufficient to stop “accidental” sharing its data with out-of-state law enforcement. These mistakes have fueled growing efforts by local communities across the country to remove license plate readers. Those efforts should be the first step in a broader reconsideration of mass surveillance.
More generally, ubiquitous surveillance carries a real societal cost. The chilling effects are real and pervasive, and they tend to fall hardest on the most marginalized members of society. Moreover, social progress requires the ability to experiment in secret. It’s hard to imagine a society progressing morally to the point of accepting and legalizing things like marijuana use or gay marriage if the earliest signs of that shift are snuffed out because of overzealous surveillance.
While a cost-benefit analysis is not the best frame for deciding constitutional rights, it is a place to start to evaluate government policies. If the costs are too high and the benefits too small, what should the public do? While the policy and legal frameworks can be individually complex, mass surveillance is a problem in all of its applications. So too should solutions be comprehensive rather than piecemeal.
One comprehensive strategy is to reset the promise of the Fourth Amendment and recognize that a warrant is required prior to collection, access or use of information gathered through mass surveillance. This would apply to collections that include U.S. persons, whether done for national security or domestic purposes. This protection would apply regardless of whether the information is in the form of metadata. It would apply regardless of whether the information is held in homes or by services people rely on, such as telephones, internet or social network providers, or by private entities utilizing mass surveillance for their own purposes. By passing this legislation, Congress could ensure this rejection of mass surveillance, and include real enforcement such as a private right of action and an automatic exclusionary remedy in criminal prosecutions. The courts could also recognize this protection of “papers and effects” directly as a plain language interpretation of the Fourth Amendment.
There are already a number of efforts that take on pieces of mass surveillance. Section 702 has expired and should remain so. This was due largely to efforts to block the “back door” access to Section 702-collected data without warrants. The bipartisan “Fourth Amendment is Not for Sale Act” would prevent the government from purchasing data that it would otherwise need a warrant to obtain. The Supreme Court itself has already been chipping away at the Third Party Doctrine, with a recent step in the rejection of mass geofence warrants—warrants seeking the identities of individuals based upon their proximity to a crime—in Chatrie v. United States. Now, such warrants fall, at least initially, under the Fourth Amendment.
A more comprehensive approach would also address mass surveillance carried out by private companies, and to ensure that Americans have the right to encrypt and secure their data. There are many reasons the United States would benefit from a comprehensive privacy law—and curbing mass surveillance is one of them. Addressing mass surveillance is certainly one of them. Ideas such as the banning of secondary uses of data—with roots in the Fair Information Practice Principles from the 1970s—are worth pushing forward. So are moves such as creating fiduciary duties for mass data collectors. There are many more ways to curtail private companies’ mass surveillance while staying within constitutional boundaries. But addressing the costs of mass surveillance by both companies and governments is even more important in a world where AI agents are making decisions both about the public and on their behalf based on their data and observed behavior.
Twenty-five years after the U.S. government embraced mass surveillance, it’s time to evaluate it as a whole, and consider responses that address the problem as a whole. Americans must ask: Is it consistent with a self-governing democracy to have systems that watch everyone everywhere? Is the public comfortable with governments—federal, state, local—that seek to “know it all” about its citizens? Is the public comfortable with private mass surveillance in its own right and as it’s being increasingly used to fuel government surveillance? These questions have long needed serious consideration. But as it becomes increasingly evident that the Trump administration is using mass surveillance to keep itself in power, stifle dissent, and undermine political opponents, these questions are now more urgent than ever.
On the NSA’s Supercomputer from the 1960s [Schneier on Security]
Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.
Maps and a compass [Seth's Blog]
Maps are easy to sell. If you know where you are and where you’d like to go, the map solves your problem. Maps are all around us: how-to, what-to, step-by-step.
The compass is more resilient but less descriptive. It shines a light, gives us clarity, but the next steps are up to us.
In an age of ubiquitous AI, answers are no longer in short supply. But questions are more valuable than ever.
Twenty years ago, I published my scariest book, The Dip. It frightened my publisher and the booksellers because it was about a topic rarely written about (quitting) and it deliberately did not contain much in the way of answers or procedures. The book was designed to give people clarity about something they’d been avoiding, and to provoke the difficult questions that can transform the path we are on.
Decades later, I still get earnest questions about quitting. Once you see it, it’s hard to unsee, which is the point of this sort of work. The existence of a compass helps us realize that it might help to know which way is north.
This fall, I’m back with The Knot. It’s not a sequel, but it rhymes.
Because sometimes, the question isn’t whether to push through or to quit. Sometimes, you’ve already decided the work matters. You’ve already decided the problem is worth solving. And still, we’re stuck.
A knot happens when we want two things that can’t both be true. We want to make a change, but we don’t want to risk disapproval. We want to ship the work, but we want a guarantee it will work. We want to move forward, but we’re carrying a commitment, a scorecard, a fear, or a story from the past.
The book is a compass with a simple north star: Problems can be solved. Our work has a purpose, intent, the change we seek to make. If we can name the baggage that’s holding us back or confusing us, progress is possible.
It ships next week.
The people who have read it can’t stop talking about it, because it helps us realize that better is possible. I hope you can share a copy with someone who needs it.
Yves-Alexis Perez: IKEv1 protocol disabled in strongSwan package for Debian unstable [Planet Debian]

Heads up, Debian IKE/IPsec users.
Starting with strongSwan 6.1.0-1 (currently in Debian unstable and targeted at Debian 14 Forky), the IKEv1 protocol has been disabled. This is aligned with upstream decision. Considering IKEv2 is already nearly old enough to drink in the USA (RFC 4306 will turn 21 next December) and IKEv1 has weaknesses, the disabling is long overdue amd will permit upstream to remove some code in the upcoming years.
At this point there is no good reason not to migrate to IKEv2 and exposing IKEv1 code in all Debian installation is no longer relevant. All IKEv1 users using Debian 13 Trixie (either site to site, gateway or roadwarrior client) should investigate IKEv2 protocol (or other options).
Note that some plugins have also been disabled upstream for security/maintenance reasons and we followed suite in Debian. The Debian relevant ones are: af-alg, led, padlock.
Pluralistic: Everybody pees (15 Sep 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

Jeff Bezos and I are very different people. For one thing, he is a sociopathic billionaire who built his fortune by monopolizing bookselling while I am a penniless author of books. He was born in 1964 and is 62; I was born in 1971 and am 55.
We've met a few times and even corresponded some in Amazon's early years, though I haven't had contact with him in decades. Despite that very minor acquaintanceship and that long gap in our message history, I can tell you one thing I know for sure about Jeffrey Preston Bezos: he needs to pee all the time.
How do I know? Because peeing all the time is an inescapable feature of aging, and Bezos has eight years on me, and I have to pee all the time. Jeff Bezos, like all older people, must contend with a progressively weakening bladder. Honestly, it's a small price to pay in exchange for the everyday miracle of growing older (as opposed to perishing).
The only reason I mention Jeff Bezos's increasingly insistent bladder here is because of how hard it is to reconcile the very different circumstances of Bezos's bladder with the bladders of the hundreds of thousands of Amazon delivery and warehouse workers who are not allowed to pee at all. Amazon's warehouse and delivery workers are "reverse centaurs," monitored by a constellation of apps and cameras, and they are severely punished for falling behind in the cadence set by Amazon's software, and that robot timekeeper does not make allowances for pee breaks:
https://pluralistic.net/2025/10/23/traveling-salesman-solution/
This isn't a secret, and Amazon's come in for a lot of flak over it. But Amazon's "solution" is to add more penalties for peeing. Drivers who return to the depot with urine-filled bottles in their vans are punished as severely as they would be if they stopped to find a toilet. Thing is, the mere fact that your boss's robot says you're not allowed to pee does not matter to your bladder or kidneys, and when you gotta go, you gotta go.
That's why the roads leading to Amazon's warehouses are lined with pee bottles that drivers have hucked out of their windows before arriving at the loading dock. There are so many of these that the British media activist Oobah Butler was able to harvest them and offer a line of "bitter lemon energy drinks" on Amazon made from bottled driver piss. The drink was an Amazon bestseller and the company even asked Butler if he wanted them to help him scale up his deliveries:
https://pluralistic.net/2023/10/20/release-energy/#the-bitterest-lemon
The fact that Bezos needs to piss and also the fact that he commands an army of hundreds of thousands of workers who are prohibited from pissing really supports my hypothesis that billionaires don't really believe that other people are real. If Jeff Bezos believed that when his drivers needed to pee that it felt the same as when he needed to pee, Jeff Bezos would let those drivers pee:
https://pluralistic.net/2026/05/13/vibe-governance/#k-hole
"Needing to pee" is a bedrock of the shared condition of existence itself, extending beyond humans to our "horizontal brothers and sisters" (John Muir's delightful name for the other animals we share this planet with). Anyone who's ever had a dog understands this. I'm not really a dog person, but when I meet a dog that really needs to be let out of the house, my bladder twinges in sympathy. When I contemplate the kidneys and bladders of Bezos's drivers and packers, I get a sharp, persistent ache that starts about an inch below my navel.
I think billionaire solipsism is inevitable. The mere fact of dealing with people as mass statistical abstractions – hundreds of thousands of Amazon workers, billions of social media users and Google searchers – turns the majority of the world's other humans into phantasms, defective bots whose bothaviors are maddeningly non-deterministic and sub-optimal.
Add to that the fact that harvesting billions of dollars requires you to inflict pain on thousands or even millions of those phantasms whose money, privacy and labor you've extracted, and it's easy to see how you'd end up in a world where you can't bear to contemplate the fact that other people's pain is as real as your own. Solipsism is a deadly, conscience-eroding occupational hazard of the rich and powerful. No visitor to Epstein Island could have made the visit if the pain of those young women was as real to them as the pain of their own daughters and friends.
There's a short line from this solipsism to billionaires' enthusiasm for AI. When you don't think other people are really real, it's easy to believe that they can be swapped out for chatbots. Mark Zuckerberg's quest to replace your friends with chatbots makes sense once you realize that for Mark Zuckerberg, you and your friends are already just balky, shitty chatbots:
https://pluralistic.net/2026/08/06/sin-is-when/#you-treat-people-as-things
The belief that bots can teach your kids or counsel you through your psychological problems or look after your health concerns is perfectly consistent with the belief that you're more-or-less a bot, and also that the teachers, doctors and shrinks you rely on are also basically bots:
https://pluralistic.net/2026/07/28/hitl-ers/#ai-ai-oh
The great crisis of oligarchy is not merely that it transfers power from democratically accountable public servants and elected representatives to oligarchs. The real crisis is that attaining oligarch status is incompatible with viewing other people as real. That's how we ended up with the richest man on earth slaughtering hundreds of thousands of the world's poorest children for the lulz:
https://hsph.harvard.edu/news/usaid-shutdown-has-led-to-hundreds-of-thousands-of-deaths/
Everybody pees. When I die, when Jeff Bezos dies, and when you die, our bladders will give way and we will pee ourselves. A declaration of war on other people's right to pee is a declaration of war on humanity itself.

The Senate must reject the Clarity Act’s ethics charade https://www.citationneeded.news/clarity-act-ethics-charade/
They want you to be scared of AI in a very specific way https://www.garbageday.email/p/they-want-you-to-be-scared-of-ai-in-a-very-specific-way
San Francisco's AI-run store is losing money fast. After a visit, I'm not surprised. https://www.sfgate.com/local/article/san-francisco-market-ai-22424349.php
#20yrsago Microsoft Zune won’t play purchased Microsoft media files https://web.archive.org/web/20061014104638/https://www.eff.org/deeplinks/archives/004910.php
#15yrsago Papercraft 1:1 model of a 1969 Mustang, accurate to the smallest component https://web.archive.org/web/20110923151701/http://www.jonathanbrand.com/images/in_progress/paper_car/motor/pages/motor01.htm
#15yrsago Third gender option added to Australian passports https://www.bbc.co.uk/news/world-asia-pacific-14926598
#10yrsago French spy boss admits France cyberattacked Iran, Canada, Spain, Greece, Norway, Ivory Coast, Algeria, and others https://medium.com/@msuiche/nsa-hacked-france-in-2012-414d8de4bdcf#.e4hnvyj6s
#10yrsago Elizabeth Warren to FBI director: now that investigations are fair game, what about banksters? https://s3.documentcloud.org/documents/3107565/EMBARGOED-Warren-FBI-FCIC-Letter.pdf
#10yrsago European Commission wants to break the web, give publishers the right to charge for inbound links https://felixreda.eu/2016/09/attack-on-link/
#10yrsago Machine learning system can descramble pixelated/blurred redactions 83% of the time https://arxiv.org/pdf/1609.00408v2
#10yrsago Welcome to Night Vale: scripts and notes from podcasting’s eeriest drama https://memex.craphound.com/2016/09/15/welcome-to-night-vale-scripts-and-notes-from-podcastings-eeriest-drama/
#10yrsago UNH will spend $1M of librarian’s bequest on a football scoreboard https://www.insidehighered.com/news/2016/09/15/critics-question-spending-librarians-donation-scoreboard
#5yrsago Everything is Always Broken, and That’s Okay https://pluralistic.net/2021/09/15/everything-is-always-broken-and-thats-okay/

Edmonton: Elbows Up (Edmonton Public Library), Sep 28
https://www.epl.ca/blogs/post/elbows-up-with-cory-doctorow/
Boston: The Post-American Internet: Possibilities for a new
internet created by an American Hermit Kingdom (MIT Media Lab), Sep
30
https://www.media.mit.edu/events/the-post-american-internet-possibilities-for-a-new-internet-created-by-an-american-hermit-kingdom/
Boston: The Paradox of Enshittification and Reverse Centaurs
(Harvard Berkman Klein), Sep 30
https://cyber.harvard.edu/events/running-harder-falling-faster-paradox-enshittification-and-reverse-centaurs
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Hudson, OH: Hudson Library, Oct 7
https://engagedpatrons.org/EventsExtended.cfm?SiteID=3850&EventID=596952&PK=
Calgary: Wordfest, Oct 8
https://wordfest.com/2026/show/wordfest-presents-cory-doctorow-2026/
Winnipeg: McNally Robinson, Oct 9
https://www.mcnallyrobinson.com/event-18991/An-Evening-with-Cory-Doctorow
Vancouver: Read, Resist, Repair, Rejoice (Vancouver Writers
Festival), Oct 19
https://writersfest.bc.ca/festival-event-2026/01
Victoria: Munro's Books, Oct 20
https://www.munrobooks.com/events/6113620261020
Vancouver: Life After AI (Vancouver Writers Festival), Oct
22
https://writersfest.bc.ca/festival-event-2026/46
Ottawa: Life After AI (Ottawa Writers Festival), Oct 24
https://writersfestival.org/event/life-after-ai
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
Fascists may come after the AI bubble bursts (You&AI)
https://www.youtube.com/watch?v=J2WN64aQeYQ
What Would a Normal Person Do (Trashfuture)
https://www.patreon.com/trashfuture/posts/what-would-do-169247456
Pod Save the UK
https://audioboom.com/posts/8950533-radicalised-organised-and-thick-as-s-t-nish-has-had-it-with-far-right-protests-plus-why
Stop Saying AI Can Do Your Job (Factually)
https://www.youtube.com/watch?v=VU3gABvwZCM
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
Freexian Collaborators: Debian Contributions: Security-tracker git performance, OpenSSH GSS-API split, Incus replacing lxc in Debian CI and more! (by Anupa Ann Joseph) [Planet Debian]

Contributing to Debian is part of Freexian’s mission. This article covers the latest achievements of Freexian and their collaborators. All of this is made possible by organizations subscribing to our Long Term Support contracts and consulting services.
At the beginning of this month, the default backend for tests was changed to incus-lxc, leaving only a few dozen packages explicitly configured to run as lxc. Those packages got bug reports filed and once those bugs are fixed they will be migrated over to incus-lxc. This marks an important milestone for Debian CI, as the low level of isolation between the worker host OS and the OS under test when using lxc was a significant source of instability in our platform. Common causes for test failures when comparing runs under plain lxc with runs with incus-lxc are documented in the wiki page linked from the bug reports.
Developers working with Debian’s security-tracker
have reported
degrading performance for a while. The options for solving this
are few with repository sizes now reaching 30GB for a repository
whose working tree is a mere 60MB. While there have been a number
of proposals for changing the storage layout, Helmut evaluated
options not requiring such changes. Much of the problem hinges on
the 50MB data/CVE/list file that is updated in most
commits. Efficiency hinges on representing its content in git
packs.
Practically, git frequently fails to represent its content as a delta and stores a full copy that is typically compressed to 12MB. Add a few thousand 12MB full blobs and you quickly have a large repository. In particular, the copy at salsa.debian.org stores many such full blobs, so pulling from it consumes significant bandwidth.
One might think that running git gc helps, but its
utility is limited here. When git stores objects in packs, it
stores the history in
reverse. It starts with the current version and represents
older objects as differences (deltas) to more recent objects. A
delta effectively is a sequence of copying ranges from a base
object and insertion of new content. Given that humans tend to add
content over time, those additions are often represented as
deletions. The crux here is finding that base object. Given that
the data/CVE/list file is large, finding it involves
comparing quite a few versions of it with each other. This requires
both a significant amount of RAM and CPU time. How many objects git
considers for this comparison is controlled with the
--window option. It is beneficial if the base object
does not come from a direct child commit but skips over commits. In
doing so, long chains of deltas are avoided. The
--depth option controls the maximum chain length.
In this search, git combines all objects into a single window to
facilitate file renames. As such, it tends to compare
data/CVE/list with data/DSA/list,
data/DLA/list and others. This is less than helpful
and tends to evict all data/CVE/list versions from the
comparison window such that a new full blob of it becomes required.
Since the security-tracker repository rarely renames files, we can
ask git to instead consider
one window per filename via --path-walk. Once
doing so, it becomes quite a bit better at finding suitable deltas.
The technique is less applicable to older history (2025 and
earlier), but given a lot of RAM and a bit of partitioning,
git gc can shrink that as well. Combining these
techniques, we can shrink the repository into 700MB and keep new
growth somewhat under control.
Temporarily, Helmut is providing a proof-of-concept mirror at
git://git.subdivi.de/~helmut/security-tracker.git
using these techniques. Avoid pulling from it directly as it does
not provide a secure transport. While it does reduce the amount of
data being downloaded, it does not resolve a number of related
problems. After downloading, a git client will still expend
considerable amounts of CPU on verifying received deltas and
attempting to git blame data/CVE/list is not improved
in any way. Still, there is work on integrating some of the
improvements back into
salsa.
In an option
review Colin did in 2024, shortly after the xz-utils
backdoor, he explained that having GSS-API authentication and
key exchange support in the main OpenSSH packages is problematic.
The key exchange patch is large and intrusive. Even linking to the
necessary libraries isn’t without risk: as the Ebury malware attack
demonstrated way back in 2009, each extra library linked into
security-critical daemons such as sshd (or nowadays
into its privilege-separated helper programs) can modify the
behaviour of the daemon even if you aren’t doing anything
that would involve calling into that library. Of course some of
that risk remains, but as Damien
Miller wrote, minimizing the number of libraries that end up in
the address space of sshd and friends is still
valuable.
This split is now complete in testing. As of openssh 1:10.4p1-5,
the OpenSSH client and server are built without GSS-API
authentication and key exchange support. If you need those
features, install openssh-client-gssapi or
openssh-server-gssapi instead, as appropriate. Debian
13 (trixie) already has packages with those names that just depend
on the regular openssh-client and
openssh-server so that you can pre-emptively install
them, as
documented in the release notes.
The new openssh-*-gssapi packages have relatively
tight dependencies on openssh-common, in order for the
testing migration system to ensure that we can’t forget to
keep them up to date. This will mean a bit more ongoing work on
each new upstream version, but it should be manageable.
DebConf 25 videos suffered terribly from a bug in voctomix that stopped us from being able to publish the videos immediately after the conference. Ivo De Decker did some work on the videos earlier this year, fixing enough of the audio problems to make the videos at least intelligible.
While at MiniDebConf Winterthur Stefano published all the videos from 2025 and 2026 to PeerTube and YouTube. DebConf 25 and DebConf 26 videos as well as all the videos from miniconfs that had got caught up in the backlog were published.
Reproducible Builds: Supporter spotlight: Jochen Sprickerhof on ... Reproducible Builds! [Planet Debian]

The Reproducible Builds project relies on several projects, supporters and sponsors for financial support, but they are also valued as ambassadors who spread the word about our project and the work that we do.
This is the ninth installment in a series featuring the projects, companies and individuals who support the Reproducible Builds project. We started this series by featuring the Civil Infrastructure Platform project, and followed this up with a post about the Ford Foundation as well as recent ones about ARDC, the Google Open Source Security Team (GOSST), Bootstrappable Builds, the F-Droid project, David A. Wheeler, Simon Butler and Kees Cook.
Today, however, we will be talking with Jochen Sprickerhof, one of the newer members of the Reproducible Builds project core team.
Vagrant Cascadian: Could you tell me a bit about yourself? What sort of things do you work on?
Jochen Sprickerhof: I am a freelance programmer working on Open Source. Mainly doing Debian, F-Droid and some smaller software projects. In general I made it a habit to look into every software I use and try to fix bugs or add features I need. In Debian, I maintain about 180 packages with topics covering home banking, build systems and robotics. Most of my time, I currently work on reproduce.debian.net, where we try to bit-for-bit reproduce the packages distributed by Debian.
Vagrant: Could you describe the path that lead you to working on reproducible builds?
Jochen: I started my Debian journey as a teenager, converting my school to Debian and serving as its system administrator for 13 years. After studying Applied System Science, I joined the university’s robotics labs, where I worked on the Robot Operating System (ROS) and the Point Cloud Library (PCL). In the end, I enjoyed programming more than writing papers, so I eventually left academia for a robotics startup. Some years ago, I realized that the open source work I was doing in my spare time was actually the work I cared most about. Nowadays I am really grateful that I can spend my days working on things I find important and have lots of fun with.
Vagrant: What projects did you recently make big progress on?
Jochen: A recent example is metasnap.debian.net. It
is a ‘meta archive’ of snapshot.debian.org
which is itself archive of all packages in Debian. But let me
explain it the other way round: with reproduce.debian.net,
we try to reproduce the packages as they are distributed by the
Debian archive. For that, we need the same build environment
(compilers, libraries, build tools, etc) that was used by Debian
back when the original package was compiled. Luckily,
snapshot.debian.org has all those packages, but they are
not easily accessible via apt, Debian’s package
manager. So, metasnap provides a mapping from a package
name and version pair to the APT repo on
snapshot.debian.org needed to download it from. It was
created by josch some time ago,
and it’s awesome work. But when we tried to reproduce more
and more packages on reproduce.debian.net, we found that
some were missing packages from the build environment — even
though they where visible on snapshot.debian.org. We found
that metasnap excluded some archive areas because they
where not expected to be needed. Reimporting all the data took more
than two months and surfaced a couple more flaws.
With this fixed, we were able to build more packages, only to find out that metasnap also needs better support for version numbers. Luckily we were able to rewrite the data in a day instead of starting the import again.
Vagrant: You have been working on infrastructure to support reproducible builds for a while. Has recent adoption of reproduce.debian.net into the Debian release tooling changed the focus of your work?
Jochen: Quite a bit. When we started reproduce.debian.net in 2024, only around 33% of the packages could be reproduced successfully. Today we are above 98%. Most were not bugs in the packages themselves but in the infrastructure. Similar to the metasnap issue I reference above, packages just needed a rebuild because something else, like the toolchain, was fixed in the meantime. In May, people from the Debian release team and the Reproducible Builds project sat together and decided that the overall state is good enough, and now packages that regress on reproducibility are blocked from entering the next Debian release. But that does not mean all the work is on the shoulders of Debian package maintainers. Since then I have been constantly looking at the migration tooling to spot regressions and provide fixes. Furthermore, a couple of maintainers reached out to us for help and I hope more will do so in future.
Vagrant: What is one small thing you (or others) have not yet gotten to that you would really like to see?
Jochen: The central tool to reproduce Debian
packages is debrebuild, also written by josch. Currently it
has two ways to retrieve the build dependencies of a package.
Either it uses metasnap.debian.net (as explained above),
or it can access the Debian unstable APT repository
directly. This allows to test packages locally before everything is
indexed on metasnap by compiling against Debian
unstable. But actually there are many other APT
repositories to query, like Debian stable or even derivatives.
Adding support for an optional list of APT repositories in
debrebuild would be
great. That would also be a big step to support reproducing other
Debian based distributions.
Vagrant: … and one big thing?
Jochen: It would be great to integrate metasnap.debian.net into snapshot.debian.org. There is some discussion on it already in Debian bug #650783.
Vagrant: What are the tools you use the most?
Jochen: According to my fish shell history:
$ history | cut -d' ' -f1 | sort | uniq -c | sort -nr | head -10
36199 git
20941 vi
12271 rm
8599 cd
7917 ls
6407 apt
5631 grep
4249 mv
3655 dpkg
2873 cp
Vagrant: So, is the fish shell reproducible? I remember it did not used to be…
Jochen: You can check for yourself — it was last time I checked. But looking through the other commands, neovim sadly is not. I hope we can fix that in future.
Vagrant: Oh, that’s a nice URL to check for reproducible package… you can just pass the source package name to check the current results?
Jochen: Yes. Another one is udd.debian.org/reproducibility/,
where you can list all packages of a Debian maintainer. It also
lists source reproducibility and has nice filters as well.
Vagrant: What tools do you use specifically working on reproducible builds?
Jochen: I don’t have statistics for that,
but I would say sbuild to build the package,
debrebuild to reproduce it, and diffoscope to analyze
the differences. Obviously I also need run apt source
<package> or use git-buildpackage to get the
sources and all the tools I mentioned above.
Vagrant: So how many packages are left to build reproducibly, and once those are finished, what is next?
Jochen: Right now, reproduce.debian.net shows over 98% reproducibility, though there are still over 650 package left and some will probably need a lot of work. But actually I think making packages reproducible is just the first step. For me, this is a project to build confidence in the system. To reproduce a package we have two parts: the source of the package and the build environment. Fixing the packages means gaining confidence in the first part but we still rely on the individual build environments for each package as we need to use the same compiler that was used when the package was build initially. Because of this, we have to keep around every historical version of all toolchain packages. I really would like to remove this extra archive, which means we would have to rebuild all of Debian around release time. I am dreaming of a Debian release where you could bit-for-bit reproduce every package just from the released versions. Due to how Debian works, however, this is not a trivial rebuild and it would need some work on the infrastructure. By the way, initially there was a third component to pay attention to: any connection to the outside world during the build. Luckily we fixed the Debian build daemons to not allow network connections during the build some time ago.
Vagrant: Thanks for all that work, and taking the time to tell us a bit about yourself!
Jochen: Thanks a lot for the interview!
For more information about the Reproducible Builds project,
please see our website at reproducible-builds.org. If
you are interested in ensuring the ongoing security of the software
that underpins our civilisation and wish to sponsor the
Reproducible Builds project, please reach out to the project by
emailing contact@reproducible-builds.org.
No One Told You Life Was Gonna Be This Way [QC RSS v2]

clapclapclapclap
Today in “Places You Might Not Expect to Find Me” [Whatever]

Behold these history textbooks: World in Motion, Vols. 1 &2. They were sent to me today. Why, you may ask? Because I contributed to them both, by writing an introduction that went into both volumes. Why was I asked to write the introduction? Because I am awesome, you see, and also because I know one of the authors, and he asked nicely, and I thought it would be fun. And it was fun! And now I have another thing checked of the bucket list: Being in a textbook! Yes, it was pretty far down the checklist. But it was still there.
— JS
GNU Boot joins FSF fiscal sponsorship program [Planet GNU]
BOSTON, Massachusetts, USA (Monday, September 14, 2026), — The Free Software Foundation (FSF) announced today that GNU Boot is its latest fiscally sponsored project. GNU Boot is a libre, ethical replacement for the nonfree BIOS or UEFI, which is software found in virtually all personal computers in the world today.
Apple releases iOS 27, macOS Golden Gate 27 with Siri “AI” and Liquid Glass refinements [OSnews]
Apple releases its yearly cluster of operating system updates today, with the two most prominent of course being macOS and iOS/iPadOS. These new versions focus heavily on Apple’s “AI” stuff, but there are a few actual improvements and changes to the actual operating systems as well.
Across both iOS and macOS, users now have a slider to affect how transparent or opaque the “Liquid Glass” design is across the operating system.
And on the macOS side especially, Apple has made numerous small design tweaks to address user feedback, which has been accumulating since Liquid Glass was introduced. There’s nothing radically new in terms of design here, but this is a much-needed polish pass.
Across all the releases, but in particular macOS and also iOS, there are a bunch of quality-of-life or performance improvements. For example, macOS now supports HDR for all system UI elements and gets more robust support for a wider range of display modes for external monitors.
↫ Samuel Axon at Ars Technica
If you’re not into “AI”, there’s not a lot of meat on these bones, but at least you can turn the “AI” nonsense off through a switch buried deep in the settings applications of Apple’s operating systems (which will probably be flicked back on whenever the next update comes).
Switching to GNU Guix: a beginner’s perspective [OSnews]
Want to run something a little more exotic on your server? How about GNU Guix?
It has been a month since migrating my home server to GNU Guix. Managing OS state declaratively through Git has eliminated configuration drift, and Guile Scheme provides a cohesive environment that complements Emacs. While adapting to a smaller package ecosystem and managing substitute timing requires occasional adjustments, the stability, reproducibility, and container isolation make it a dependable foundation.
↫ Wai Hon
I’m definitely noticing an increase in interest in Guix lately.
The BeBox: one of the most beautifully overbuilt computers of the 1990s [OSnews]
Late 2000. There is a grey and blue tower PC on my dorm-room desk like nothing anybody who walks into the room has ever seen. The Be logo on the front, a 3.5″ floppy peeking out the bottom of the drive bays, and the vertical grille that hides two columns of green LEDs (blinkenlights) dancing with the CPU load. This was a dual-PowerPC workstation running an operating system you didn’t see in the wild. I was studying computer science at the time and this was a fun piece of hardware.
↫ J.D. Hodges
As a BeOS user in and around 2001 or so, the BeBox was the holy grail of the little community I was a part of. There were some people here and there in online circles who had one, but they were rare even when new, and by 2001, they had become rarer still. This rarity made them mysterious and exciting from almost from the day they were launched, like a small volume halo car few people will ever get to see, let alone experience, first-hand.
It’s 2026 now, and more and more of the small number of BeBoxen made must be succumbing to degradation and hardware failures. I hope everyone who has one takes good care of them, because these are some of the rarest, most coveted computers of all time. I’ve still never seen one, and here in Arctic Europe I most likely never will. Still, I remain hopeful.
One day.
GNU Core Utilities 9.12 released [LWN.net]
Pádraig Brady has
announced GNU Core Utilities (coreutils) version 9.12.
"There have been 288 commits by 16 people in the 21 weeks since
9.11
". New features include an -A option for uname
which labels all output, as well as adding awareness of the
failfs
and nullfs
filesystem types to stat
and tail.
There are many bug fixes in this release as well, including one
for a bug "present in 'the beginning'
" that caused some
utilities to fail when traversing hierarchies if files are being
removed in parallel.
coreutils-9.12 released [stable] [Planet GNU]
This is to announce coreutils-9.12, a stable release.
Notable changes include:
env supports a new --env0-from=FILE option to support
full persistence and restoration of the environment.
This also supports e.g. filtering like:
env -i --env0-from=<( env -0 | sed -z ... )
Commands now have safer terminal output,
avoiding confusing output or corrupted terminal state.
Commands that traverse directories no longer
fail merely if files are being removed in parallel.
ptx has improved robustness, avoiding potential infinite loops.
tee fixes robustness issues introduced in the previous release,
where it could go into an infinite loop or incorrectly error
in the presence of short writes.
stty is more accepting of variations in requested speed.
sort(1) will now better use available memory
and parallel operation when reading from pipes.
There have also been many bug fixes and other changes
as summarized in the NEWS below.
There have been 288 commits by 16 people in the 21 weeks since 9.11.
Thanks to everyone who has contributed!
Arun Bhattacharya (1) Leonid Evdokimov (1)
Ayesha Shafique (1) Mateusz Nosek (1)
Bruno Haible (5) Max Downey Twiss (1)
Collin Funk (98) Paul Eggert (12)
Guanqiang Han (1) Pádraig Brady (118)
H. Peter Anvin (1) Sylvestre Ledru (33)
Ismail Ramzi (1) aizu-m (2)
Iván Ezequiel Rodriguez (2) oech3 (11)
Pádraig [on behalf of the coreutils maintainers]
==================================================================
Here is the GNU coreutils home page:
https://gnu.org/s/coreutils/
Here are the compressed sources:
https://ftp.gnu.org/gnu/coreutils/coreutils-9.12.tar.gz (16MB)
https://ftp.gnu.org/gnu/coreutils/coreutils-9.12.tar.xz (6.4MB)
Here are the GPG detached signatures:
https://ftp.gnu.org/gnu/coreutils/coreutils-9.12.tar.gz.sig
https://ftp.gnu.org/gnu/coreutils/coreutils-9.12.tar.xz.sig
Use a mirror for higher download bandwidth:
https://www.gnu.org/order/ftp.html
Here are the SHA256 and SHA3-256 checksums:
SHA256 (coreutils-9.12.tar.gz) = FMv1pN4Me3+jufp/raTFiy3v4zM2qo/YPXYixcTr3BM=
SHA3-256 (coreutils-9.12.tar.gz) = 14aJyepDW60jsaL4cq5T/UFMwUJEkXDyUqZEQlsnLFM=
SHA256 (coreutils-9.12.tar.xz) = pIAZhVlzPps9qZnpBUOsb4iKLKpUTY1mTFofF+Uo4hA=
SHA3-256 (coreutils-9.12.tar.xz) = cKcyD1sxJr1tdWgWbh0+OKwOEIpaf2ACThlaHZooZDA=
Verify the base64 SHA256 checksum with 'cksum -a sha256 --check'
from coreutils-9.2 or OpenBSD's cksum since 2007.
Verify the base64 SHA3-256 checksum with 'cksum -a sha3 --check'
from coreutils-9.8.
Use a .sig file to verify that the corresponding file (without the
.sig suffix) is intact. First, be sure to download both the .sig file
and the corresponding tarball. Then, run a command like this:
gpg --verify coreutils-9.12.tar.gz.sig coreutils-9.12.tar.gz
The signature should match the fingerprint of the following key:
pub rsa4096/0xDF6FD971306037D9 2011-09-23 [SC]
Key fingerprint = 6C37 DC12 121A 5006 BC1D B804 DF6F D971 3060 37D9
uid [ultimate] Pádraig Brady <P@draigBrady.com>
uid [ultimate] Pádraig Brady <pixelbeat@gnu.org>
If that command fails because you don't have the required public key,
or that public key has expired, try the following commands to retrieve
or refresh it, and then rerun the 'gpg --verify' command.
gpg --locate-external-key P@draigBrady.com
gpg --recv-keys DF6FD971306037D9
wget -q -O- 'https://savannah.gnu.org/project/release-gpgkeys.php?group=coreutils&download=1' | gpg --import -
As a last resort to find the key, you can try the official GNU
keyring:
wget -q https://ftp.gnu.org/gnu/gnu-keyring.gpg
gpg --keyring gnu-keyring.gpg --verify coreutils-9.12.tar.gz.sig coreutils-9.12.tar.gz
This release is based on the coreutils git repository, available as
git clone https://https.git.savannah.gnu.org/git/coreutils.git
with commit c0f8514d989184921d9b12a4d103a7b23abc5af8 tagged as v9.12.
For a summary of changes and contributors, see:
https://gitweb.git.savannah.gnu.org/gitweb/?p=coreutils.git;a=shortlog;h=v9.12
or run this command from a git-cloned coreutils directory:
git shortlog v9.11..v9.12
This release was bootstrapped with the following tools:
Autoconf 2.73.16-0a513
Automake 1.18.1
Gnulib 2026-09-07 106e9b2384d08a1696fcbd40cbab52237943f208
Bison 3.8.2
NEWS
* Noteworthy changes in release 9.12 (2026-09-14) [stable]
** Bug fixes
'chcon', 'chgrp', 'chmod', 'chown', 'du', 'ls' which traverse hierarchies with
-R, no longer fail merely because files may be being removed in parallel.
[This bug was present in "the beginning".]
'comm - -' no longer closes standard input twice. Previously it would
mistakenly exit with a nonzero status.
[This bug was present in "the beginning".]
'cp', 'install', and 'mv' now fall back to a standard copy
if a --reflink=auto clone fails due to EDQUOT, ENOMEM, or ENOSPC.
E.g., with XFS, a clone can exhaust metadata space in an allocation
group, while a standard copy works.
[bug introduced in coreutils-9.2]
'cut -d' with multiple multi-byte delimiter options specified
will correctly match the last delimiter specified.
[bug introduced with multi-byte support in coreutils-9.11]
'date -d '1-2-3' "+%_D"' no longer propagates flags like _ and - to the year
component of the %D date specifier, keeping consistent component formatting.
[bug introduced in coreutils-8.31]
'du --max-depth=N' now exits with a nonzero exit status and an error message
if N is negative. Previously it behaved as if N were zero.
[bug introduced in coreutils-9.4]
'factor' avoids a buffer over-read (CWE-126) for certain values.
[bug introduced in coreutils-9.8]
'head' and 'tail' now quote names in file headers when needed.
[This bug was present in "the beginning".]
'ls --color' no longer reads freed memory when LS_COLORS sets "ln=target"
and later becomes unparsable, e.g., LS_COLORS='ln=target:x'.
[This bug was present in "the beginning".]
'mv' now warns when copying extended attributes fails with ENOTSUP, e.g., when
moving files to a file system that does not support them.
[bug introduced in coreutils-7.3]
'numfmt', 'printf', and 'seq' on Solaris, no longer output an extraneous e+00
when using a large precision like "%.5119f".
[This bug was present in "the beginning".]
'pinky -l' no longer no longer prints output in the incorrect order when
standard output is fully buffered, e.g., when redirected to a file.
[bug introduced in coreutils-9.10]
'pr' now exits gracefully upon exceeding internal accounting limits,
like when processing large tab stops.
[This bug was present in "the beginning".]
'ptx -G' no longer loops forever when the output width is smaller than
twice the gap size, as with 'ptx -G -w4', or when a long reference
leaves that little room, as with 'ptx -G -r'.
[This bug was present in "the beginning".]
'ptx -W' no longer loops forever with a word regular expression that can
match the empty string, like: echo ab | ptx -W 'a*'.
[This bug was present in "the beginning".]
'shred' no longer blocks when opening a FIFO that has no readers.
[This bug was present in "the beginning".]
'stty' no longer fails when the system uses speed encodings that
are variations of the requested speed.
[bug introduced in coreutils-9.8]
'tee' no longer loops infinitely after writing all output if a write call sets
errno to EAGAIN.
[bug introduced in coreutils-9.11]
'tee' no longer treats short writes as errors.
[bug introduced in coreutils-9.11]
'test' no longer treats '-a' and '-o' as operators when given as strings to a
binary operator. E.g., 'test -a -a -a' exits successfully instead of exiting
with an error.
[This bug was present in "the beginning".]
'truncate --reference=R' no longer hangs when R is a FIFO with no readers.
[bug introduced in coreutils-8.17]
'unexpand -t' no longer overflows a heap buffer, for tab values > SIZE_MAX/16,
or with multi-byte blank characters longer than the tab value.
[bugs introduced in coreutils-9.11]
'uniq -w' no longer overruns the read buffer in multibyte locales.
[bug introduced in coreutils-9.5]
'wc' no longer reads past the end of a lookup table in legacy multibyte
locales like SHIFT-JIS where a single byte can decode to a wide character.
[bug introduced in coreutils-9.5]
Messages from Gnulib are no longer mistranslated in non-English locales.
[bug introduced in coreutils-9.6]
** New Features
'env' now supports --env0-from=FILE to read NUL-delimited environment entries
from a file. With -i, entries are preserved exactly, allowing full
round-tripping of environments containing duplicate or nonstandard entries.
'stat' and 'tail' now know about the "failfs" and "nullfs" file system types.
stat -f -c%T now reports the file system type,
and tail -f uses inotify for these file systems.
uname adds the -A,--all-labeled option to label all output, one item per line.
** Changes in behavior
'env' and 'printenv' now quote printed environment variables honoring the
QUOTING_STYLE environment variable, defaulting to shell-escape style. This
avoids printing arbitrary data to the terminal and allows the output to be
sourced by a POSIX shell.
'ls' -w,--width no longer includes '\n' in the width of a line.
I.e., the width or $COLUMNS is interpreted to be an _inclusive_ maximum.
'stat' now uses shell quoting when required, to more robustly escape
file names. Previously it only quoted file names with the %N format.
The default quoting honors the QUOTING_STYLE env variable (like %N).
Also %Qn is a newly supported format combination to quote file names,
leaving the existing %n format for when quoting is not desired.
** Improvements
When built with the configure option '--with-wtmpdb', invocations of
'who /var/log/wtmp' and 'users /var/log/wtmp' use the wtmpdb database
instead of the file /var/log/wtmp. This makes them Y2038-safe.
'cut -w' operates more efficiently when extracting the start of a line
in multi-byte locales, giving 4x more throughput with typical input.
'df', 'du', 'ls', 'od', 'pr', and 'sort' now escape invalid arguments in error
messages for options expecting an integer.
'env -0, and 'printenv -0' now explicitly set binary mode on output
so that no CRLF translation is done e.g., on windows.
'install -C' will now avoid updating file metadata when the destination
already has the appropriate ownership and permissions.
'basename', 'dirname', 'du', 'readlink', and 'realpath' now quote output in
shell-escape style when standard output is a terminal. The QUOTING_STYLE
environment variable can be used to adjust or disable the quoting.
'ls -m' now quotes files names containing commas when appropriate,
so users can better distinguish separating commas.
'ls' now replaces newlines in file names if ambiguous with separators.
Previously newlines were protected only when outputting to a terminal.
'sort' will now better use available memory and parallel operation
when reading from unknown sized inputs like pipes.
'uniq -c' now operates up to 2.5x times faster on systems with unlocked stdio
functions.
** Build-related
'logname' now builds, where getlogin() is replaced (e.g. with musl),
and systemd libs are being used, by linking the required libraries.
The multi-call binary built with configure --enable-single-binary is reduced
in size by around 10KB through the more efficient reuse of the 'test' code
by '[', and the 'true' code by 'false'.
configure no longer accepts the --with-linux-crypto option, which allowed
cksum, md5sum, and sha*sum to use the Linux AF_ALG API. This API will be
deprecated in Linux 7.2 and is less performant than OpenSSL.
The configure option '--enable-systemd' is renamed to '--with-systemd'.
The option '--enable-systemd' was a misnomer and is now deprecated.
The 'sort' binary now uses the UAPI Group's .note.dlopen ELF note
to indicate its dependency on libcrypto.
I could look up the etymology of the term in the last panel, but I can't imagine why I would. What a fucking delight! Why would I ever want to know the specifics? Every moment I turn it over in my mind reveals rich new contours.
Upcoming Speaking Engagements [Schneier on Security]
This is a current list of where and when I am scheduled to speak:
Note: the Elevate Festival talk listed in last month’s newsletter is canceled.
The list is maintained on this page.
The next milestone will be installing Atlantis on my new
macbook, and hooking a monitor up to it, a really nice one, and
move my work to that desk. then Berkeley, the name of the system
I've been using for eight years, will be here as a backup and
source of truth and prior art. That was the goal of the Atlantis
project. I could probably do the switch right now. It's like moving
out of an old house that you did good stuff in, into a replica, but
built out of the latest bits. Honestly I never thought in a million
years I'd get here.
Free Software Directory meeting on IRC: Friday, September 26, starting at 12:00 EDT (16:00 UTC) [Planet GNU]
Join the FSF and friends on Friday, September 26 from 12:00 to 15:00 EDT (16:00 to 19:00 UTC) to help improve the Free Software Directory.
Free Software Directory meeting on IRC: Friday, September 18, starting at 12:00 EDT (16:00 UTC) [Planet GNU]
Join the FSF and friends on Friday, September 18 from 12:00 to 15:00 EDT (16:00 to 19:00 UTC) to help improve the Free Software Directory.
Zero to Agent in 30 Minutes: Build a Shared Knowledge Base for All Your Agents with Sajal Sharma [Radar]
Every AI agent you run keeps what it learns to itself. Work through a problem with Claude Code in the morning, then ask Codex about it that afternoon, and the second agent has no idea the first one exists. Add a home-server agent like OpenClaw or Hermes into the mix, and you end up reexplaining the same context to a different tool every time you switch.
When AI engineer Sajal Sharma ran into this problem in his own work, he solved it by building a personal knowledge base to act as a shared brain for every agent he runs. On this week’s episode of Zero to Agent in 30 Minutes, Sajal showed how to set up that shared workspace yourself so that a task added on one tool shows up for all the others.
Here’s how Sajal’s setup breaks down:
Sajal closed by pointing to two projects as evidence that this “shared brain” pattern is spreading beyond his own setup. LangChain recently released OpenWiki, a tool that generates and maintains repository documentation that both people and coding agents can use. And Y Combinator president Garry Tan built and open-sourced GBrain, a memory layer for agents built on the same principle.
Sajal’s starter repo is available on GitHub if you want to set up your own version, and you can reach out to him on LinkedIn to discuss the topic further.
On September 16, data science educator and AI consultant Chester Ismay joins Zero to Agent in 30 Minutes to build a personal sports concierge agent that will read the schedules for every sport he follows, decide what’s worth his time, and send a single weekly update to his phone. Viewers can take the pattern home to plan their own week.
Follow along with Zero to Agent in 30 Minutes on Radar, or watch the latest episode on YouTube, Spotify, Apple, or wherever you get your podcasts. If you’re an O’Reilly member, you can watch live. Save your seat.
Is cybersecurity part of your job in any way? If so, we’d like to know what you think for a report we’re writing. Just answer these quick 11 questions. Thanks in advance! Take the survey >
PA Fan Art Contest Winners! [Penny Arcade]
It has been fun to watch a new generation of fans discover Penny Arcade. Stumbling upon 30 years of comic strips, shows, and podcasts must be pretty fun. They have their own Discord server and they asked Jerry and I to pick winners in a PA fan art contest they were holding last month. We each picked our favorites but there were so many great pieces that I wanted to share some of them here on the site. If the only thing Penny Arcade did was occasionally inspire kids to make art I would consider this entire endeavor a huge success.
Using AI for Weapons Development [Schneier on Security]
Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag this:
We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the “R2000” set) that included a hypersonic glide vehicle variant.
The actors used Claude Code in place of human software engineers to develop the guidance, navigation, and control (GNC) software that steers and stabilizes a flying vehicle. For example, they used Claude to integrate an open-source autopilot onto a phone-class flight computer, writing the control and position estimation software, tuning the control settings, running a firmware build pipeline, and performing a flight simulation. The actors managed several Claude instances at once, assigning each one a role, much as a lead would delegate work on a small engineering team: the actors tasked one instance with writing the code, another with research, and a third with reviewing the code the first instance produced.
Our safeguards blocked many of their requests, but not all of them. The actors used a variety of tactics to evade our safeguards, including hiding their goals and the products the software was meant for, and they split their work across multiple sessions so no single session revealed their full intent.
These actors carried out a sustained effort to develop guided weapons, including using Claude to design guidance software. We do not have evidence the actors succeeded in fielding an operational device; but they did test-fire a guided rocket. This field test appears to have failed: within hours, the actors returned to Claude to work out why it failed.
Expect more of this. AI systems democratize expertise and capability. Most of the time that’s a good thing, but sometimes it’s not.
[$] Lessons learned as the Debian Project Leader [LWN.net]
What is it like to be a Debian Project Leader (DPL), or a former one? According to Andreas Tille, who stepped down this year after two consecutive terms as DPL, you'd have to be one to know. At the recent MiniDebConf in Winterthur, Switzerland, Tille spoke about what he learned while serving as DPL, some of the initiatives he led, mistakes that he made, and his thoughts on the general resolution (GR) on large language model (LLM) usage in Debian.
The High Crime of “LMAO”: How Cops Are Treating Mass Surveillance As a Joke [Deeplinks]
Here's a riddle: Why did a Goshen Police Department officer search 6,474 automated license plate reader (ALPR) networks, representing data from 82,413 cameras, on May 7, 2025?
If your answer is "I don't know," it turns out you're 100% correct. The officer left the letters "idk" in the search field where cops are supposed to document the reason for the search.
When law enforcement and tech salespeople pitch ALPRs to city councils, they stick to a familiar script. They trumpet the technology, which is often provided by private companies like Flock Safety, Motorola Solutions, or Axon, as an essential tool for solving high-stakes crimes, such as car jacking, kidnapping, or murder.
But when you strip away the carefully curated talking points, the data continues to reveal a different (and frankly, ridiculous) story. An EFF analysis of ALPR search logs from Flock Safety systems shows that officers across the country are spying on drivers for completely nonsensical "reasons." Police are routinely searching the Flock database without providing any legitimate justification, making a mockery of our civil liberties by logging reasons like "LOL" (short for “laugh out loud”), "LMAO" (short for "laughing my ass off"), "sexy," and "idk" (short for “I don’t know”) to access sensitive ALPR location data.
And in some cases, officers are just mashing keyboard buttons rather than articulating the nature of their searches.
Flock Safety claims it has improved its system by requiring officers to select from a dropdown list of crimes before running a search–but that only makes it easier for officers to hide improper searches behind the veneer of uniformity. The system does not require proof that the dropdown reason actually matches the true purpose of the search.
With no warrant requirements, limited guardrails, and deficient audit processes, ALPR databases have fostered a culture of unrestricted access to everyone’s location information. This culture of abuse has allowed police to treat a mass surveillance network like their own personal search engine, permitting the tracking of the movements of everyday citizens for low-level complaints, personal whims, and sometimes, seemingly, for the lols.
ALPR misuse isn’t a new phenomenon; it has dominated headlines for more than a year. We already know that officers regularly abuse these systems to stalk past and potential romantic partners. We’ve seen ALPRs used to surveil protests, which can chill First Amendment-protected dissent, and seen officers try to use an ALPR system to track down a woman seeking an abortion.
Typically, we learn about these uses from documents called "network audits," which are long spreadsheets that document all the searches that run through an agency's system. It is not unusual for even a small agency to have a record of millions of searches from thousands of external agencies across the United States.
We’ve also uncovered horrific systemic profiling, with more than 80 law enforcement agencies using terms like "roma" and "g*psy" to target ethnic Romani people—often without any mention of a suspected crime. And when police aren’t using ALPRs for stalking or profiling, they routinely use them for extreme low-level investigations: verifying whether a student lives in a specific school zone, running employment background checks, following up on loud music complaints, or targeting a motorcyclist simply for holding a cell phone.
But somehow, it gets worse.
EFF’s analysis of Flock Safety’s ALPR search data obtained through public records requests has uncovered a disturbing trend. In the absence of judicial oversight, officers are inputting ridiculously unserious terms to justify their searches. Here is just a snapshot of what police consider a "reason" to track someone’s vehicle:
Audit logs sample
Button mashing audit logs sample
One of the more alarming discoveries we found in the network audit data is a large number of "reasons" that appear to be nothing more than an officer mashing buttons. These typically involve a nonsensical long string of characters from the same line or area of the keyboard.
For example:
It's hard to imagine a situation where these characters add up to a legitimate police code. However, it's easy to imagine an officer cutting corners with a text field they know no one is checking, especially if they are accessing the Flock Safety app from their phones while driving.
When confronted with these flagrantly unserious searches, police departments offered a mix of bureaucratic deflections and excuses.
In response to EFF’s request for comment, Thornton Police Department (Colo.) claimed the system didn't require officers to select from a defined list at the time, but it does today. They also audited the “driving around being weird” searches, claiming they were all actually for "legitimate public safety purposes."
Other police departments we reached out to for comment shared the following:
Other agencies did not respond to EFF’s requests for comment. We will update with responses as they are received.
Under the guise of streamlining audit logs, in late 2025, Flock safety announced that they will be replacing the required, free-text search “reasons” with a pre-populated dropdown menu of generic offense categories. Since this update, officers are no longer required to type out why they are digging through a driver's movement history, and instead can select a pre-packaged option like "Traffic infraction" or “Other” in half a second.
Replacing the requirement to articulate the reason for the search with one-click searches is a loss for transparency, but also may explain why audit logs including the searches we highlight in this piece significantly decreased since early 2026.

Entries like these defeat transparency, undermine accountability, and entirely fail to satisfy what many jurisdictions require by law or policy: an actual reason for the search. And this keeps happening because police use ALPRs as a convenient shortcut around constitutional privacy safeguards.
In other contexts, such as searches of cell phone location information, police have to go to a judge, demonstrate probable cause, and get a search warrant. But because laws and courts have not caught up with the pace of ALPR technology, police do not do the same before searching ALPR databases. Instead, they are given free rein to track a person’s movements without a sliver of judicial oversight.
As we mention in our piece about the use of ALPR surveillance for low-level investigations, if a police chief stood in front of a city council and asked for permission to install hundreds of cameras just so his officers could investigate the high crime of "haha," they would be laughed out of the room. The same could be said if an officer asked a judge to sign a warrant to track someone down for "LOL."
The fact that these searches were not only missed by the agency supervising the officer, but by the often thousands of other agencies whose systems were searched, demonstrates how agencies cannot be trusted to oversee themselves.
Mass surveillance is incompatible with a free society, and especially so when the people with access to this data are treating it like a joke. This ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. But because it does, EFF continues to urge courts and state legislatures to immediately step in and impose strict, enforceable restrictions to rein in this abuse. At an absolute minimum, this means mandating rigid data deletion deadlines and an ironclad warrant requirement.
If police want the power to track a person's movements, they must be required to convince a judge with evidence and probable cause. They should not be able to bypass the Constitution with a search for "haha."
Emacs arbitrary code execution flaw [LWN.net]
Sean Whitton has announced that the original fix for an arbitrary code execution flaw in Emacs (CVE-2024-53920) was incomplete. Bas Alberts discovered that viewing or editing untrusted files in modes other than Emacs's Lisp mode can also result in arbitrary code execution.
This problem affects all Emacs versions affected by CVE-2024-53920. This means Emacs 24 and newer, and possibly also older versions.
A minimal fix, attached, is queued up for release with Emacs 31.2. We (the Emacs upstream maintainers) don't expect to backport the fix to older Emacs releases ourselves.
LWN covered the original vulnerability in December 2024.
Why didn’t ReadDirectoryChangesW provide a way to correlate the two sides of a rename operation? [The Old New Thing]
Brian Dellisanti asked
why ReadDirectoryChangesW didn’t
provide a way to correlate the two sides of a rename
operation.
I wasn’t there, but I can guess.
My guess is that the implementation always generated the two
events one right after the other, so “obviously” the
way you correlate them is to save the old name when you see the
FILE_ACTION_RENAMED_OLD_NAME, and when the
FILE_ACTION_RENAMED_NEW_NAME comes immediately after,
you have your two sides.
But they never wrote down that the two events always occur in direct succession. Which meant that when new file systems came along, they might not honor the unwritten rule. If two files are being renamed at the same time, is it possible that the two sets of rename events end up interleaved? There was nothing written down to forbid it, so I guess it’s possible.
Note that I don’t know whether any file systems actually break this unwritten rule. From what I can tell, they do generate the two events in rapid succession, but rapid succession doesn’t a priori guarantee that they will come directly one after the other, particularly if there is a lot of concurrent disk activity going on.
In practice, I couldn’t find a lot of code tracking
renames anyway. They generally treated the
FILE_ACTION_RENAMED_OLD_NAME as a deletion and the
FILE_ACTION_RENAMED_NEW_NAME as a creation. And the
ones that did track renames assumed that renames did not
interleave. (Not that they had much choice.)
I don’t think that providing the file IDs for the two
sides of a rename operation was the purpose of
ReadDirectoryChangesExW‘s
ReadDirectoryNotifyExtendedInformation.
It was just a happy side effect that the extra information in the
ReadDirectoryNotifyExtendedInformation
also gives you the pieces needed to connect the dots reliably.
I thought you might appreciate me pointing out the trick, that’s all.
The post Why didn’t <CODE>ReadDirectoryChangesW</CODE> provide a way to correlate the two sides of a rename operation? appeared first on The Old New Thing.
How can I remove the Close button from my window caption? [The Old New Thing]
Occasionally, somebody wants to create a window without a Close button.
The only way to get rid of the Close button is not to have a
System menu at all: Remove the WS_SYSMENU style
from the window. But that also gets rid of the Minimize and
Maximize buttons, so it’s kind of drastic.
If you want a System menu, or if you want Minimize and Maximize
buttons, you can at least disable the Close button by disabling the
SC_CLOSE menu item.
HMENU menu = GetSystemMenu(hwnd, FALSE); EnableMenuItem(menu, SC_CLOSE, MF_DISABLED);
Of course, you could use the nuclear option and implement your own custom title bar. Then you can do whatever you want. But most people are probably not willing to take things to such an extreme.
But really, try not to hide or disable the Close the button at all. End users don’t like it. It makes them feel trapped.
The post How can I remove the Close button from my window caption? appeared first on The Old New Thing.
My longtime friend Jeff Jarvis says the press is covering the wrong story re AI. I agree, but I think Jeff is covering the wrong story too. This is really a discovery like electricity, or Newtonian physics, calculus, basically the technology of knowledge. I wish I were 22 years old now so I could plan out a long career working this way. I want people like Jeff to understand. Not saying there's no truth to the other stories, but I've yet to hear anything from journalism about how, if left alone, it would develop all areas of human thought.
It is probably the closest to First Contact with an intelligent alien life form that our species will ever have.
Security updates for Monday [LWN.net]
Security updates have been issued by AlmaLinux (389-ds-base, apr-util, coreutils, freerdp, git-lfs, glib2, gstreamer1-plugins-base, kernel, libkcapi, nginx, nodejs:22, nodejs:24, osbuild-composer, perl-YAML-Syck, postgresql16-postgis, ruby, ruby4.0, ruby:3.3, and vim), Debian (jbig2dec, kamailio, nginx, spip, and xorg-server), Fedora (baresip, bind, bluez, bubblewrap, chirp, chromium, cockpit, composer, corosync, darktable, dokuwiki, elixir, exiv2, expat, firefox, freerdp, freerdp2, gdk-pixbuf2, gegl04, golang-x-perf, grpcurl, kernel, kernel-headers, libevent, libmongocrypt, libpcap, libre, libsoup3, memcached, mingw-expat, mingw-openexr, mongo-c-driver, mrtg, nagios-plugins, nsd, nss, openssl, openvpn, PackageKit, pdns-recursor, perl-Net-OAuth, perl-XML-Bare, php-pecl-mongodb2, python-asteval, python-pip, rclone, rest, rust-hickory-net, rust-hickory-proto, rust-hickory-resolver, rust-ppmd-rust, rust-webbrowser, srt, syncthing, tar, tkimg, and valkey), Gentoo (Chromium, Google Chrome, Microsoft Edge, Opera, Vivaldi and Ruby), Mageia (bind, ffmpeg, glibc, java-17-openjdk, java-21-openjdk, librabbitmq, perl-Catalyst-Plugin-Static-Simple, perl-Imager, tor, and xz), Oracle (389-ds:1.4, ansible-core, apr-util, coreutils, freerdp, git-lfs, glib2, gstreamer1-plugins-base, gzip, httpd:2.4, image-builder, java-21-openjdk, kernel, mrtg, nginx, osbuild-composer, perl-DBI, postgresql16-postgis, python-lxml, python3.12-lxml, redis:6, and vim), SUSE (389-ds, ansible-core, ansible-creator, azure-storage-azcopy, cargo-audit, chromedriver, chromium, clamav, containerized-data-importer1.65, containerized-data-importer1.66, curl, dracut, ffmpeg-4, google-guest-agent, google-osconfig-agent, helm, java-1_8_0-ibm, jupyter-nbconvert, kernel, libpng16, libusb-1_0, libvirt, multipath-tools, NetworkManager, opensc, openssl-3, perl-Authen-SASL, perl-HTML-FormHandler, perl-Mojolicious, perl-Protocol-HTTP2, python-jwcrypto, python-sqlparse, python-tornado6, python313-geopy, python313-modelscope, python313-modelscope-hub, python313-pypdf, python315, rpcbind, sshamble, strongswan, tomcat, ucode-intel, and wget), and Ubuntu (civetweb, ffmpeg, and urwid).
More than 9,000 patches total in the seven stable kernels for Monday [LWN.net]
Greg Kroah-Hartman has announced the 7.2.6, 6.18.52, 6.12.110, 6.6.157, 6.1.188, 5.15.221, 5.10.270 stable kernels.
According to Kroah-Hartman, this batch may set a record for the number of patches with more than 9,000 in total between them. There are more than 1,800 patches in 7.2.6 alone. Users of these kernels are, of course, advised to upgrade.
CodeSOD: I Exist [The Daily WTF]
In addition to using an ancient development environment, with terrible UX, Greta also has the misfortune of working in Pascal.
Recently, she was diagnosing a bug. The program was reporting that files didn't exist when they definitely existed. She traced the problem down into the system library. Let's see if you can spot what's wrong:
{ Delphi / Kylix Cross-Platform Runtime Library }
{ System Utilities Unit }
{ }
{ Copyright (c) 1995-2001 Borland Softwrare Corporation }
...
function FileAge(const FileName: string): Integer;
{$IFDEF MSWINDOWS}
var
Handle: THandle;
FindData: TWin32FindData;
LocalFileTime: TFileTime;
begin
Handle := FindFirstFile(PChar(FileName), FindData);
if Handle <> INVALID_HANDLE_VALUE then
begin
Windows.FindClose(Handle);
if (FindData.dwFileAttributes and FILE_ATTRIBUTE_DIRECTORY) = 0 then
begin
FileTimeToLocalFileTime(FindData.ftLastWriteTime, LocalFileTime);
if FileTimeToDosDateTime(LocalFileTime, LongRec(Result).Hi,
LongRec(Result).Lo) then Exit;
end;
end;
Result := -1;
end;
{$ENDIF}
function FileExists(const FileName: string): Boolean;
{$IFDEF MSWINDOWS}
begin
Result := FileAge(FileName) <> -1;
end;
{$ENDIF}
The first function here is FileAge, which returns
the last modified timestamp on a file. Note the use of
FileTimeToDosDateTime, which is a Windows API
function. It converts LocalFileTime and stores the
date part in the first output parameter
(LongRec(Result).Hi) and the time part in the second
output parameter (LongRec(Result).Lo).
Result, in this case, is our return value. If anything
goes wrong, we return -1.
The FileExists function then, simply calls
FileAge. If it doesn't return a -1, there
must be a file there.
That's an awkward, weird solution to the problem. There has to be a system call that can answer that question more obviously. But it doesn't seem like it should be blowing up- it looks like it should work.
But note that FileTimeToDosDateTime also returns a
boolean value. If it succeeds, great, but if it fails, it returns
false and sets an error code you can check. An error code that
definitely isn't being checked.
And this brings us to the root cause of Greta's bug: the process
that's writing the files isn't setting the "last write time", so
while the file exists, the attempt to check its age fails, so
FileExists believes that the file doesn't exist, just
because it doesn't have a valid timestamp.
This is the kind of high quality softwrare that sometimes infects our system libraries.
Enterprise Analytics Beyond Dashboards: Intelligent Data Orchestration with LLMs [Radar]
In 17 years of building enterprise data platforms, I’ve watched every organization eventually ask the same question: “Can I ask one question and get one answer across everything my company knows?” A finance analyst wants actual revenue from the warehouse, pipeline data from the CRM, commentary from planning documents, and market signals from external providers. The information already exists, but it lives across systems that were never designed to reason together.
For decades we tried to solve this by consolidating data. We built larger warehouses, semantic layers, APIs, and dashboards. Each solved part of the problem, but none solved the fundamental one: orchestrating reasoning across heterogeneous sources in response to an arbitrary business question. Earlier systems supported limited federation and semantic querying, yet they struggled to reason across those sources at enterprise scale without significant custom engineering.
Modern LLMs change this. Instead of replacing databases, they facilitate a new architectural primitive: an intelligent orchestration layer that dynamically reasons across specialized systems. Rather than consolidating the data into a single store, this layer consolidates the access pattern to data that stays where it lives.
This article presents a reference architecture for LLM-powered enterprise analytics agents that coordinate purpose-built, heterogeneous data stores through intelligent orchestration while preserving security, performance, and auditability.
BI tools have always been constrained to predefined reports and dashboards. Before GenAI, building a cross-system query engine meant hardcoding every possible query pattern, data source combination, and synthesis path. And because the number of possible questions grows exponentially with the number of data sources, exhaustive coverage is impossible through traditional engineering. GenAI changes this in three specific ways.
Intent understanding replaces query templates: An LLM parses natural language and determines which data sources are relevant based on semantic understanding rather than keyword matching. Unlike a keyword search, an LLM understands that “Why did retention drop in Asia last quarter?” and “What is driving churn in Asian markets?” are the same question expressed differently. More importantly, it infers that answering the question requires customer relationship data, revenue metrics, and possibly support ticket sentiment, even though none of those systems are named.
Dynamic query decomposition replaces static pipelines: A question like “What are the biggest risk factors in our supply chain?” might require relationship data from a graph database, metrics from a key-value store, contract details from a document repository, and market intelligence from an API. The agent decomposes it into specialized subqueries on the fly, each optimized for the target store’s access pattern. There’s no prebuilt pipeline and no engineering ticket to wire up a new combination, because the decomposition happens at inference time. The system handles novel questions without code changes.
Semantic synthesis replaces manual consolidation: Before GenAI, making sense of the data together was the real work. An analyst would pull numbers from the warehouse, check relationships in a CRM, read through documents, and mentally synthesize an answer. That took hours or days and was bounded by one person’s ability to hold context. I’ve watched senior analysts spend entire Mondays answering a single leadership question. An LLM reasons about how metrics relate to the relationship patterns in a knowledge graph and the strategic context in unstructured documents, and it does so in seconds with full source attribution. A dashboard shows numbers; an analytics agent explains what those numbers mean in the context of everything else it knows.
Rather than consolidating the data into a single store, consolidate the access pattern through an intelligent orchestration layer. If your instinct is to get everything into one place, you aren’t alone, but every time we did that we lost something. Graph relationships flattened into join tables, hierarchical documents shredded into rows, and real-time signals turned stale in batch loads. The warehouse was always a compromise.
The better approach is to keep each data store optimized for its specific query pattern:

The LLM-powered agent coordinates across all of them through a unified orchestration layer. This follows the same principle that makes microservices work: specialized services with well-defined interfaces, coordinated by an orchestrator. The difference is that the orchestrator now understands natural language, reasons about which services to call based on intent rather than explicit routing rules, and synthesizes results semantically rather than through programmatic joins. Think of it as a data mesh for inference, where each node keeps its operational independence while an intelligent layer federates queries across them.
The agent follows a multiphase protocol for every query. The full reasoning loop with security enforcement and parallel execution goes well beyond a simple RAG pattern.

Let’s trace a business question through each phase:
“Why did Q2 revenue fall short of forecast in the enterprise segment?”
This question requires revenue metrics (metrics store), account relationships and sales coverage (graph), deal commentary and executive notes (vector store), and market benchmarks (external APIs). No single system holds the answer.
Phase 1: Intent analysis. The LLM determines what the user is asking and which data sources are relevant.
“Why did Q2 revenue fall short of forecast in the enterprise segment?”
↓
Intent: Revenue variance root cause analysis
Entities: Enterprise segment
Timeframe: Q2
Metric: Revenue vs. forecast
Required stores: Metrics + Graph + Vector + External API
Not every query needs every store. “What is our current ARR?” might need to hit the metrics store only. This revenue variance question requires all four.
Phase 2: Query decomposition. The original question is broken into specialized subqueries optimized for each target store:
Each is tailored to the target system’s access pattern, not forced through a common query language.
Phase 3: Parallel execution. Tools execute concurrently. This is critical for latency. Sequential execution across four stores would blow past any reasonable response time. With parallel execution, the total data retrieval time equals the slowest individual store, not the sum of all stores.
Phase 4: Deterministic security enforcement. A security layer enforces user permissions at the data query level before any retrieval happens. This is structural rather than application-level: It routes queries to the appropriate data partitions, applies row-level filters at the database query level, and gates the input rather than filtering the output. If our user is a regional VP without access to EMEA deal data, the graph returns no EMEA accounts, the metrics lookup excludes EMEA revenue, and the vector search filters out EMEA deal notes. The LLM can’t leak what it never received. (More on why this must be deterministic below.)
Phase 5: Result synthesis. The LLM reasons about how results from different stores relate, identifies patterns across sources, resolves contradictions, and generates a unified answer with source attribution.
For our revenue question, synthesis might produce:
Q2 enterprise revenue missed forecast by $4.2M (8% variance). Three root causes account for 85% of the gap: (1) Four deals totaling $2.8M slipped to Q3 due to extended legal review cycles—all four involved customers who adopted a new procurement platform in Q1 (graph: common vendor relationship). (2) Two large renewals downsized by $1.1M; deal notes cite budget reallocation toward AI initiatives, a pattern appearing across 6 QBR summaries (vector store). (3) Enterprise software spending contracted 3% QoQ industry-wide (external benchmark), suggesting partial macro headwind. Additionally, all four slipped deals lacked executive sponsor engagement in the final 30 days (graph: engagement signal absent).
No single store contains that answer. On a dashboard, the miss shows up as a red number. The orchestrated synthesis explains why it happened, surfaces the structural patterns behind it, and points to what needs to change.
The orchestration loop itself is straightforward. Here’s the core pattern:
from concurrent.futures import ThreadPoolExecutor, as_completed
def run_agent(question, tools, execute_fn, model="gpt-4o"):
# Phase 1-2: LLM analyzes intent and decides which tools to call
response = client.chat.completions.create(
model=model, messages=[{"role": "user", "content": question}],
tools=tools, tool_choice="auto"
)
tool_calls = response.choices[0].message.tool_calls
# Phase 3: Execute tool calls in parallel
with ThreadPoolExecutor(max_workers=len(tool_calls)) as executor:
futures = {
executor.submit(execute_fn, tc.function.name,
json.loads(tc.function.arguments)): tc
for tc in tool_calls
}
results = {futures[f].id: f.result() for f in as_completed(futures)}
# Phase 5: Synthesize results into unified answer
messages = [response.choices[0].message]
for tc_id, result in results.items():
messages.append({"role": "tool", "tool_call_id": tc_id,
"content": json.dumps(result)})
return client.chat.completions.create(model=model, messages=messages)
The tool definitions tell the LLM what each store is optimized for. The LLM decides which to invoke based on the question’s intent. With parallel execution, data retrieval completes in milliseconds even when hitting multiple stores simultaneously, making LLM inference the dominant latency factor, not the data layer.
Knowledge graphs have existed for decades and have always been powerful. They’ve also stayed on the exotic end of the enterprise stack, and the reason is human rather than technical. The last-mile problem was translating between natural language and graph traversals. A graph database can answer extraordinarily complex relationship questions, such as “Which accounts have overlapping stakeholders with our churned customers from last quarter who also evaluated competitor products?” but asking that question required an engineer fluent in both the graph schema and the business domain. That combination of skills is rare and expensive, which is exactly why graph databases have never quite gone mainstream.
GenAI removes this bottleneck, and it does so precisely where the barrier was highest: the translation step that used to require a specialist. With an LLM as the translation layer, the graph becomes accessible to anyone who can type a question in plain language. The LLM generates graph queries, traverses multihop relationship paths, and explains results in business context. In our revenue variance example, the graph reveals that all four slipped deals share a common pattern of customers who adopted a new procurement platform in Q1 and lacked executive sponsor engagement in the final 30 days. That pattern is invisible in revenue metrics alone, because it requires relationship traversal across account nodes, vendor relationships, and engagement signals.
The critical design decision is aligning the graph schema with your business ontology. The temptation is to model the graph around your data model (tables, columns, foreign keys). The correct approach is to model it around how your organization actually thinks about its domain:
When the data model matches the business mental model, the agent’s responses feel natural rather than technically correct but practically useless.
A powerful extension is GraphRAG (graph retrieval-augmented generation), where the agent constructs deterministic inference paths by traversing the graph rather than relying on the LLM’s parametric knowledge. The LLM isn’t remembering something from training; it’s following an explicit path through verified data. The result is auditable reasoning chains: “Account A connects to Partner B through implementation relationship X, and Partner B appears in three other churned accounts, suggesting a systemic delivery issue.” Each step is verifiable against source data, which is critical in enterprise environments where decisions need justification beyond model confidence scores.
GraphRAG also reduces hallucination risk. When the LLM follows graph edges rather than generating from parametric memory, the actual data constrains the space of possible outputs. The graph acts as a factual guardrail on the reasoning process.

Moving from prototype to production exposes a set of challenges that don’t appear in demos.
Decouple the orchestration layer from any specific LLM provider. I can’t stress this enough. If it’s tightly coupled to one provider’s API, you’ll end up rewriting it within a few months, when pricing changes or a better model drops. Implement model fallback for throttling resilience. The landscape moves fast, and you don’t want architectural lock-in baked into your data infrastructure.
Multihop model selection is also worth considering. Use a smaller, faster model for intent classification and query decomposition, where the task is well-defined, and a larger model for synthesis, where reasoning quality matters. Intent classification with a small model takes around 200 ms and costs a fraction of a full reasoning pass, so reserve the expensive inference for synthesis, where quality directly impacts user experience.
Row-level security must be enforced deterministically before data reaches the agent, as described in Phase 4 above. This is a nonnegotiable architectural constraint. LLMs are probabilistic systems, and security enforcement can’t be. Don’t rely on the model to filter sensitive information after the fact; the data should never enter the context window in the first place.

Separate data construction from data serving. An offline batch pipeline refreshes the stores from source systems on a scheduled cadence, and the real-time agent only reads preprocessed data. This keeps query latency low while letting computationally intensive transformations such as graph construction, embedding generation, and metric aggregation happen asynchronously. The pipeline should be idempotent and observable, with freshness monitoring per store. When the graph is six hours stale but the metrics store is real-time, the agent should know this and communicate its confidence accordingly. Add freshness metadata to every tool response rather than waiting for a user to catch a stale number and lose trust for weeks; that metadata becomes part of the agent’s context for answer generation.
Agent responses need evaluation at both the tool level (“Did the graph query return the right entities?”) and the synthesis level (“Did the final answer correctly combine tool outputs?”). These are different failure modes that require different approaches.
Log every tool call and result, every query decomposition decision, and every synthesis step. You’ll need these traces when something goes wrong, and in a multistore system that can mean a bad graph query, a stale metric, a poorly matched document, or a synthesis error. Without traces, debugging is guesswork. Build automated evaluation pipelines that test known questions against expected answers and track accuracy over time. Degradation usually signals a data quality issue in one of the stores rather than an LLM regression.
Design that observability around the failure modes that actually occur, because production deployments rarely fail because the LLM is inaccurate. They fail because supporting systems drift. Typical examples include:

Handling these well matters just as much as prompt engineering. Most debugging sessions trace back to data quality, not model quality.
Start with the questions your BI tool can’t answer today (and beyond). The trap with a question inventory is that it captures only what people already know how to ask. The most valuable questions are usually the ones missing from every existing report. They require stitching together three systems, so users either answer them by hand in a spreadsheet or quietly give up. So catalog what your users actually care about, and pay special attention to the questions they route around. Interview analysts about the analysis they abandon halfway, the recurring spreadsheet they dread, and the follow-up question they never bother to ask because the current system makes it too expensive. If most of what you find can still be answered from a single store, you need a better dashboard, not an agent. The pattern earns its complexity only when synthesis across sources is the bottleneck rather than the data access itself.
Pick one use case and go deep. Build for the case where the manual synthesis burden is highest, where an analyst currently spends four hours pulling data from three systems to answer a leadership question. Prove value in that narrow corridor, then expand; adding a new store is incremental once the orchestration layer exists.
Invest in the knowledge graph early. It’s the hardest component to build and the highest-leverage one to have. The schema will be wrong on the first attempt and less wrong on the third. It evolves with your understanding of the domain, and that understanding deepens only through iteration with real users asking real questions.
Design for the analyst, not the engineer. The success metric isn’t technical elegance. It’s whether the finance analyst stops building the same three-system Excel mashup every Monday morning. Talk to your users, watch them work, and build for their actual workflow rather than your ideal architecture.
Measure what matters. Track response accuracy, latency (P50 and P99), user adoption, and reduction in manual synthesis time. Track the questions the agent can’t answer, because those gaps are your roadmap for which stores to add or which schemas to extend.
This pattern does more than make existing workflows faster. It enables workflows that weren’t possible before, no matter how many analysts or engineers you threw at the problem. An agent querying a graph, a metrics store, and a document repository at once can surface patterns no human would find by checking each system manually. A finding like “entities in segment X who adopted product Y and had a support escalation in the last 90 days are 3x more likely to churn” requires reasoning across three data sources in a single inference; no dashboard surfaces that, and no analyst checks that specific combination unprompted. In the same motion it democratizes access, opening information that was previously reachable only by engineers who could write Cypher or SQL to anyone who can ask a question in plain language. The analyst’s role shifts from answering routine questions toward building the ontology, curating the graph, and tackling problems that require genuine human judgment.
It also delivers auditable reasoning at enterprise scale. GraphRAG provides deterministic inference paths that are verifiable against source data, so every conclusion traces back through explicit edges and nodes. This builds trust where decisions carry financial, regulatory, or strategic weight. “The AI said so” becomes “the data shows that A connects to B through X, B exhibits property Y, and historical pattern Z suggests the following.” That traceability changes the conversation from “Can we trust AI?” to a review of the work the AI actually did.
The future of enterprise analytics is unlikely to be a larger warehouse or a smarter dashboard. It is an orchestration layer capable of reasoning across specialized systems while preserving each system’s strengths. Purpose-built data stores remain exactly where they are; what changes is how we access them.
The architectural pattern described here doesn’t replace warehouses, graphs, vector stores, or APIs. It coordinates them. That distinction is subtle, but it fundamentally changes what enterprise analytics systems can deliver. The next generation of analytics platforms will do more than answer questions faster. They’ll reason across enterprise knowledge in ways that previously required experienced human analysts. The data already existed. The orchestration layer did not.
Disclaimer: The views and architectural perspectives in this article are entirely my own and do not represent my employer or any affiliated organization. References to patterns and technologies are based on publicly available information and personal experience. No proprietary or internal information was used.
Pluralistic: But do you use keyboard shortcuts? (14 Sep 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

Of all the weird recurring motifs of the stories people tell me about the AI labor wars, the weirdest is when bosses demand to be reassured that their contractors and workers will absolutely use AI to get the job done.
That's weird for the obvious reason that for most people "AI" is a synonym for "low quality." No one ever said "My kid's math teacher was replaced with AI" in a happy tone of voice. No one ever said, "Oh, great, they replaced their customer service department with AI chatbots!" My teenager and her friends use "That's so AI" as a shorthand for "That's low-effort shit."
Not bosses, though. Bosses love AI and there's plenty of evidence that they're positively harassing the people who work for them with demands to use AI in their work:
https://www.reddit.com/r/antiwork/comments/1weztw9/anyone_elses_boss_obsessed_with_chatgpt/
Beyond the widespread belief that AI is what you use if you don't care about quality, insisting that people use AI is weird for another reason: why should anyone care which tool was used to do the job? I mean, provided the job was accomplished correctly, on time and to budget, why would anyone care how it was done? My illustrator friends whose clients want to be assured that the work is being done "with AI" were never before asked "Did you use a Wacom tablet to draw these lines? Did this element start life as a vector or as rasters? Are you more into using cage transforms, or do you like to stroke the image with the warp tool?"
It's not just illustrators. I've heard this from bookkeepers. "Please tell me you got a chatbot to help you with the syntax for this Excel macro" is a genuinely weird thing to ask someone. By all means, concern yourself with whether the accounts are correct, but caring about how the macros are written is like caring about whether someone jots notes to themselves by tabbing to a new document window or by scribbling on a yellow pad by the keyboard.
I've heard this from writers, architects…all kinds of professionals. "Did you use AI to help you outline this?" What a stupid thing to ask a writer! That's like asking "Do you use keyboard shortcuts, or do you mouse over the Word ribbon and click on the little scissors icon when you want to cut some text?" The actual, finished document is right in front of you. Is it a good document? Are those good words? Why are you concerning yourself with the writer's pencil-sharpening technique?
There's precedent for this: indeed, it's the very origin of management consulting. The first management consultants were the Taylorists; these were con artists that charged bosses vast sums of money to stand over workers with stopwatches, timing each step of their jobs to the instant in order to produce a mandatory choreography of "the best way" to do the job:
https://en.wikipedia.org/wiki/Scientific_management
None of these "scientists" knew anything about how to do the job, and critically, they never asked the workers why they used an "inefficient" technique to accomplish a task. Rather, Taylorists concerned themselves with getting workers to move like precision machines, transforming the factory floor into a stage upon which workers pantomimed "efficiency" for bosses who also didn't know how to do the workers' jobs.
If this produced inferior goods, or caused the workers pain by forcing them to repetitively move in injurious ways, that was a small price to pay. Bosses claimed they were buying improved efficiency, but what they were really after was reassurance: reassurance that the workers whom they relied upon were engaged in nothing more than a set of reducible, mechanical steps. Taylorized workers were required to act out a role in a play in which they were easily replaced, mindless appendages to the boss's skill, discernment and ambition. A Taylorized workplace is a colony organism whose brains are in the C-suite and whose busy workers are nothing more than drones and pismires.
AI is the apotheosis of this fantasy. A boss who lays hands upon an AI tool doesn't have to know how to draw a picture, balance books, or write technical documentation. They only have to prompt the production of these things. For bosses, AI is a great leveler: it is sold as a way to distill and package up the skill and discernment of workers and infuse them into a pliable automaton.
If you give workers instructions that reveal your ignorance, they might roll their eyes at you and make you feel bad about yourself. Even if they restrain themselves in the moment, they might make fun of you in the break-room later. To be the boss is to sit alone at your desk, haunted by the suspicion that you are not in the driver's seat, but rather, you are in the back seat playing with a Fisher Price steering wheel. AI is sold as a way to wire the toy steering wheel directly into the corporation's drive-train:
https://pluralistic.net/2026/01/05/fisher-price-steering-wheel/#billionaire-solipsism
Seen in this light, bosses' insistence that workers use AI makes perfect sense. Once you reassure yourself that your subordinates produce the things you need by prompting a model, you reassure yourself that you could do their jobs. At that point, you're not relying on their skill – you're doing them the favor of paying them to do a job that you're too busy and important to do, but which you could do. With AI, you can tell yourself that you're in the driver's seat, even if someone else has their hands on the wheel.
(Image: ArwinJ, CC BY-SA 3.0, modified)

Prospect welcomes recognition agreement at Skyscanner Technology Ltd https://prospect.org.uk/news/prospect-welcomes-recognition-agreement-at-skyscanner-technology-ltd
They stopped 57 shootings. Everyone was just fired. https://www.youtube.com/watch?v=PgcfcRFrMYc&list=PLFVDwNAJdY2w
No Country for Tech Bros https://thepointmag.com/politics/no-country-for-tech-bros/#
VC isn’t VC anymore — understanding the rise of Cancer Capital https://www.anildash.com/2026/09/02/cancer-capital/
#20yrsago Changeling, a fairy tale of contemporary New York
https://memex.craphound.com/2006/09/14/changeling-a-fairy-tale-of-contemporary-new-york/
#20yrsago Sony’s rootkit disables CD drives when combined with AOL software https://web.archive.org/web/20071006050933/http://www.theinquirer.net/en/inquirer/news/2006/09/14/sony-drm-woes-continue
#20yrsago Google’s new lobbyists: lying, astroturfing, push-polling scumbags https://web.archive.org/web/20071010112656/https://talkingpointsmemo.com/archives/009776.php
#15yrsago New Jersey e-voting coverup https://blog.citp.princeton.edu/2011/09/13/nj-election-cover/
#15yrsago Stephenson’s REAMDE: perfectly executed, mammoth, ambitious technothriller https://memex.craphound.com/2011/09/14/stephensons-reamde-perfectly-executed-mammoth-ambitious-technothriller/
#10yrsago Class action suit: smart sex toys spy on their owners and transmit their masturbation habits https://web.archive.org/web/20160915002121/http://www.vocativ.com/358530/smart-dildo-company-sued-for-tracking-users-habits/
#10yrsago Leaked: damning Scott Walker dark money docs that judge ordered destroyed https://www.theguardian.com/us-news/ng-interactive/2016/sep/14/john-doe-files-scott-walker-corporate-cash-american-politics
#10yrsago The DoJ is using a boring procedure to secure the right to unleash malware on the internet https://web.archive.org/web/20160915072648/https://www.wired.com/2016/09/government-will-soon-able-legally-hack-anyone/
#10yrsago Edward Snowden sets out the moral case for a pardon from Obama https://www.theguardian.com/us-news/2016/sep/13/edward-snowden-why-barack-obama-should-grant-me-a-pardon

Budapest: Brain Bar, Sep 17
https://brainbar.com/munkatars/cory-doctorow
Edmonton: Elbows Up (Edmonton Public Library), Sep 28
https://www.epl.ca/blogs/post/elbows-up-with-cory-doctorow/
Boston: The Paradox of Enshittification and Reverse Centaurs
(Harvard Berkman Klein), Sep 30
https://cyber.harvard.edu/events/running-harder-falling-faster-paradox-enshittification-and-reverse-centaurs
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Hudson, OH: Hudson Library, Oct 7
https://engagedpatrons.org/EventsExtended.cfm?SiteID=3850&EventID=596952&PK=
Calgary: Wordfest, Oct 8
https://wordfest.com/2026/show/wordfest-presents-cory-doctorow-2026/
Winnipeg: McNally Robinson, Oct 9
https://www.mcnallyrobinson.com/event-18991/An-Evening-with-Cory-Doctorow
Vancouver: Read, Resist, Repair, Rejoice (Vancouver Writers
Festival), Oct 19
https://writersfest.bc.ca/festival-event-2026/01
Victoria: Munro's Books, Oct 20
https://www.munrobooks.com/events/6113620261020
Vancouver: Life After AI (Vancouver Writers Festival), Oct
22
https://writersfest.bc.ca/festival-event-2026/46
Ottawa: Life After AI (Ottawa Writers Festival), Oct 24
https://writersfestival.org/event/life-after-ai
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
What Would a Normal Person Do (Trashfuture)
https://www.patreon.com/trashfuture/posts/what-would-do-169247456
Pod Save the UK
https://audioboom.com/posts/8950533-radicalised-organised-and-thick-as-s-t-nish-has-had-it-with-far-right-protests-plus-why
Stop Saying AI Can Do Your Job (Factually)
https://www.youtube.com/watch?v=VU3gABvwZCM
Be Skeptical of the AI Sales Pitch (Trumponomics)
https://www.bloomberg.com/news/audio/2026-09-09/trumponomics-cory-doctorow-questions-the-ai-hype-podcast
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
Microsoft’s Patching [Schneier on Security]
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record:
Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.
It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out unprecedented numbers of patches in their software.
This is the result of AI-powered vulnerability finding, and a good example of AI helping the defenders more than the attackers.
What will be interesting to watch is how the number of vulnerabilities changes over the next few months. My prediction is that it will continue to increase as the AIs get better at finding software vulnerabilities, and then decrease as they run out of vulnerabilities to find. How high the number gets, how fast the trend reverses, and how quickly it declines after that are all unknown.
And Microsoft is right: The window to patch has shrunk to “immediately.” AIs are also good at reverse-engineering exploits from patches, which means that these vulnerabilities will be weaponized as soon as the update is published.
Issue 47 – Greta’s Wedding Pt. 2 – 27 [Comics Archive - Spinnyverse]
The post Issue 47 – Greta’s Wedding Pt. 2 – 27 appeared first on Spinnyverse.
Morris team names [Judith Proctor's Journal]
I'm feeling rather chuffed that I persuaded the fledgling
Warwich university morris team into changing their name.
Forget exactly what the original was, but it was War??? (the ?s
being three letters that I can't now remember, that didn't seem to
mean anything unless you knew)
But see the Warwick University coat of arms -
https://i.pinimg.com/736x/c6/fe/02/c6fe020a5bd420ca0712771d50d64e89.jpg
A bear standing next to a tree trunk... If you can't make a morris
logo our of that, with the bear holding a big stick...
The team took a vote and are now 'Ursa Major'.
(How did I get involved?)
A member of Anonymous Morris was one of the founders, and another
one lives locally and has been to several of our practice
sessions.
They're a very new team, and happy to listen to suggestions about
kit, etc.
eg. consider second hand fabric. Now there are fewer local fabric
shops; it can be quite hard to judge the quality of fabric bought
online (I've been burnt a couple of times now). Charity shops may
stock second-hand bedding, that you can check by feel.
Also, when you're several years down the line, it can be hard to
find the same colour again. A mix to start with can give you some
flex.
comments
Grrl Power #1495 – Motivation [Grrl Power]
Yes, you can level up your superpowers by using them. Mostly though, you’re just getting better at using them, learning all the tricks and power stunts you can pull off, and well as learning finer control. But the actual power output, in the cases where such a thing can be measured, can be improved as well. That doesn’t mean in a decade or two, the whole team will be as powerful as Maxima, but they will be more powerful than they are now. But at some point, age will start to erode that fine control, and pushing their powers to their limits will cause their sciatica to flare up more and more. Super powers don’t stop aging. Well, unless your particular suite of powers actually does do that.
Hiro isn’t emasculated by having a woman boss, or by the fact that she’s a fair bit stronger than him. I mean, that’s what he tells himself, and he almost totally believes it. All his actions support that. He doesn’t go sulk in his room or make snippy comments or anything of the sort. That doesn’t mean he wouldn’t mind beating Max at arm wrestling one day. Those hormonally motivated imperatives are hard to resist. Guys don’t mind carrying in the 40 pound bag of dog food or cat litter while the wife/girlfriend carries in the bag with the crackers and instant ramen, and we don’t mind getting tasked with getting down something from the high shelf in the kitchen, because all the testosterone swirling around in our brains is whispering to us, “This makes you a man…” So yeah, Hiro would like to be stronger than… well, anyone, if he could swing it. He just doesn’t scuff his feet and pout when Max does something out of his tier.
Speaking of FTL communication, I had 4 paragraphs written suggesting that FTL travel or communication might break something fundamental about the universe, as you’d be violating the physical limits of the rate of information propagation, but… I started posting too late and couldn’t articulate why I thought that might screw things up. Not that I’m remotely qualified to lecture meaningfully about advanced physics. It was just a thought I’ve been kicking around for a while, but I don’t think what I was writing was making enough sense to spark any sensible discussion. I’ll have to noodle on it and see if I can make it make sense. So in the meantime, just enjoy the page.
Oh, look who it is in the vote incentive. The NSFW version is finally up at
Patreon. Plus a bonus pic.
I think she would get in trouble for doing this. She’d mess up the… floor of the waterfall? Is that what it’s called? The receiving pool? No, probably not that. Anyway, she’d churn things up and cause a ton of weird erosion.
Since you might be wondering, Niagara Falls is about 165 feet high, so Babezilla obviously doesn’t have to be full sized. I’d say she’s about 175-180 feet tall here?
Double res version will be posted over at Patreon. Feel free to contribute as much as you like.
Canceling one flight [Seth's Blog]
Let’s imagine the airline you run had to cancel just one flight a year. You have three days notice. How would you go about it?
You might begin by considering the travelers with the tightest itineraries, and explore which options exist and prioritize them.
Then, this being late-stage capitalism, you might look at the passengers who are paying you the most, or are the highest-value customers. You’d prepare alternative plans for them, and, in clear language, make it easy for them to switch with just one click.
And you’d expand your staff, just a bit, so the dozen or so people who can’t be served by your well-designed self-service model would be able to call or text in real time.
Add it all up, and the overhead you’d need to create a layer of customer-service around a cancelled flight (with $180,000 in revenue) isn’t that much.
With tech tools and training, your team could save long-planned-for trips and salvage customer loyalty.
Multiply it by the 3,000 or so flights that KLM cancels every year and it seems like a big number. Which is why it’s the accountants, not the marketers, that create so much chaos.
Start with one.
Your scale should not be your customer’s problem.
Enrico Zini: Financial risks in 2026 [Planet Debian]
I asked the banker who is my reference at the bank something like this:
Give that we are talking about the consequences of the tantrum of a fascist foreign government, what happened to them (who are also people close and dear to me), in some future can very well happen to me.
Suddenly my risk profile shot up under the roof.
What do you suggest me to do? Should I find a trusted source of gold bullions to bury under the cellar at home?
The answer was something like this:
Sadly YES, given that the USA have a sort of financial monopoly they can entitle themselves to arbitrarily define a person/organization as a terrorist without any trial or judicial course, and as a consequence apply sanctions that cannot be effectively counteracted, not even abroad.
I didn't have this in my 2026 bingo card, but here we are.
For more details, see:
For some broader context on this kind of actions from the USA, see also:
Enrico Zini: Migrating away from .org/.net/.com domains [Planet Debian]
After having witnessed how easy it is for good people to lose a
.org domain over a fascist tantrum (you can follow the
Autistici/Inventati story here and here), I've started moving all my
infrastructure to differently
managed TLDs.
enricozini.org and enricozini.com will
keep being functional for the time being, as dropping a domain
makes it available for squatting and impersonation.
These new domains are now online, with working web and emails:
It will take ages to migrate countless accounts that are tied to my primary email address, so better start early.
Waiting to see what will happen with .meow domains, which I supported despite not identifying as a cat.
New Comic: 'Round Back
Girl Genius for Monday, September 14, 2026 [Girl Genius]
The Girl Genius comic for Monday, September 14, 2026 has been posted.
Breaking Up, p21 [Ctrl+Alt+Del Comic]
The post Breaking Up, p21 appeared first on Ctrl+Alt+Del Comic.
Todd Blanche [Richard Stallman's Political Notes]
(satire) *Todd Blanche Vows To Remain Fully Independent Of The Law.*
He was recently confirmed by magat senators as the Attorney General, but he remains effectively the corrupter's personal lawyer.
Global heating [Richard Stallman's Political Notes]
Global heating is an intentional outrage, not a natural calamity.
It is being done to us knowingly.
Law of war [Richard Stallman's Political Notes]
The US has participated since the Revolutionary War in efforts to curb the worst excesses of war. The sadist has declared his total opposition to that goal.
The US has not always lived up to that stated intention. The distribution of disease-laden blankets to indigenous people is one extreme example. We must recognize that the US has many wrongs to be ashamed of, even as it has many admirable traits to be proud of.
Comparing US history to the future that the sadist and his magats desire shows how vicious he and they are.
Pentagon journalists blacklist [Richard Stallman's Political Notes]
*U.S. Central Command maintains a secret directory of journalists who have been blacklisted by the press office.*
Election deniers running for office [Richard Stallman's Political Notes]
* Republicans who deny Joe Biden won the 2020 election are running for governor and secretary of state across the US.*
Each state's secretary of state is in charge of that state's elections. A secretary of state who endorses lies about recent past elections is likely to try to rig future elections.
It is clear that magats are organizing to eliminate honest elections in the US.
Voting Rights Act [Richard Stallman's Political Notes]
*Top US firms that backed Voting Rights Act [(in 2021) now] donate to groups working to undermine it.*
Fire near Reno [Richard Stallman's Political Notes]
A wind-driven fire near Reno, Nevada is spreading so fast that it is hard for people to evacuate fast enough to get away. It is even spreading across fire trucks, carried I suppose by blowing embers.
This is part of the consequences of global heating, and if we don't curb greenhouse emissions fast, fire will become a frequent danger.
"Divisive" progressives [Richard Stallman's Political Notes]
Ever since most Democratic officials abandoned New Deal-style support for the non-rich, environmental protection, climate defense, and equal rights, the candidates who seek to return the party to those causes have been tarred as "divisive".
We can't make the US livable for non-rich Americans by electing politicians who serve mainly the elites. Better to have a division over these issues than to ignore them.
Millions in India stripped of vote [Richard Stallman's Political Notes]
*Millions in India stripped of vote before critical state election, as government seeks to "purify" electoral roll.*
The BJP passed two laws, a decade ago, with the combined effect of denying citizenship to Indian Muslims who lacked certain documentation for their ancestors. Hindus were not required to produce that documentation, only Muslims.Climate studies shut down [Richard Stallman's Political Notes]
*[The saboteur's henchmen have] shut down more than 100 climate studies.*
The long-term plan may be to prevent the education of future climate scientists in the US. Since the saboteur in chief, and his billionaire oligarchs, reject the results of climate scientists, and they know (though they won't admit it) that climate scientists all warn about the danger of global heating, they would see no reason for climate research to be done or for anyone to think about it.
Republican's strategy [Richard Stallman's Political Notes]
Republicans' long-term strategy, since Reagan, is to spend a lot of money (mainly on things that won't benefit non-rich Americans), refuse to raise taxes, and therefore greatly increase the national debt.
Subsequently, when Democrats were in power, they lambasted the Democrats for not cutting the spending that helps the non-rich to reduce the national debt.
What the corrupter is doing is basically more of the same, but with a change in details: he can count on nearly all Republicans in Congress to be so mindlessly loyal that they will rubber stamp even the most gratuitous and corrupt excuses to increase the debt.
Stars and Stripes editor fired [Richard Stallman's Political Notes]
The bully's henchmen have fired the publisher and editor of the military newspaper Stars and Stripes for defending its traditional editorial independence.
The bully wants to convert every news medium in the US into his own house organ.
Heidi Overton [Richard Stallman's Political Notes]
*Trump nominates abortion opponent Heidi Overton to be head of FDA.* Those bastards live to make the people they hate suffer or die.
Hind Rajab killing [Richard Stallman's Political Notes]
Israeli army has admitted that its soldiers fired at the car carrying Hind Rajab and her family, which is what killed them all. Also that it fired at the ambulance which was trying to reach them, killing some medics.
Previously the army lied about the circumstances to try to pass the blame to the medics.
Chow Hang-tung jailed [Richard Stallman's Political Notes]
Hong Kong freedom activist Chow Hang-tung as been jailed for five years for trying to talk publicly about the Tien An Men square massacre in Beijing.She keeps her spirits up by writing about being in prison. Her motive:
A stubborn freak like me can only march on and fight my case till the end … Having a chance to exhaust oneself is better than living a purposeless life, isn’t it?
"Darth Vader" in favor of Flock [Richard Stallman's Political Notes]
*"Darth Vader" comes out in favor of Flock cameras at San Diego city council meeting.
The dark lord – or someone dressed like him – said the technology would aid the empire in tracking "rebel scum".*
Wildfires in Europe [Richard Stallman's Political Notes]
* Wildfires are projected to burn 39% more of Europe by the end of the century even in the best-case scenario for stopping the planet from heating, a study has found, unless action is taken to manage them better.*
Climate crisis [Richard Stallman's Political Notes]
*[UK] Ministers are in denial about the scale of the [local climate] crises we face.*
*Having just 20 Defra staff working on climate adaptations show the government is not taking the challenges of heatwaves, wildfires and droughts seriously.*
When law becomes the weapon [Richard Stallman's Political Notes]
Many countries have imposed, or tolerated, practices of lawfare that make it possible to crush journalists that question the official line.
Reminder: subscription price change coming [LWN.net]
Just a reminder that prices for LWN subscriptions will increase after September 15. Until then, the older rate still applies. See this article for details on this change. Thanks, yet again, to all of our subscribers for your support — that is what keeps LWN going.
Kernel prepatch 7.3-rc3 [LWN.net]
The 7.3-rc3
kernel prepatch is out for testing. Linus said: "Another fairly
large rc release, and again one with a bigger filesystem footprint
that we usually see.
"
Dirk Eddelbuettel: td 0.0.7 on CRAN: New Features and Updates [Planet Debian]

A new version 0.0.7 of the td package for accessing the twelvedata API for financial is now on CRAN, and has been built for r2u.
This release combines the standard set of maintenance changes that accrue in a four and a half year period (!!) as that much time has past since the previous release. But it also contains two contributed functions to retried, respectively, a profile (available under a paid plan) and a set of main fundamental data statistics, both provided Kenneth Rose.
The NEWS entry follows.
Changes in version 0.0.7 (2026-09-13)
Added
fun_statisticsandfun_profilefunctionExpanded README.md with additional badges, and updated URLs
Updated continuous integration multiple times
Switched to Authors@R
Thanks to CRANberries, you can also look at the most recent diff to the previous release. See the project page, the github repo, and the package documentation for more details.
This post by Dirk Eddelbuettel originated on his Thinking inside the box blog. If you like this or other open-source work I do, you can now sponsor me at GitHub.
On a good day working with Claude is like working with my old UW-Madison programmer friend Gary Sevitsky from the 70s.
I've been writing about Atlantis on various social media
sites in the last few days. Published the long piece I wrote
yesterday
on Facebook and X, both of which allow long posts. Wasn't going to
try that on Mastodon or Bluesky, which have character limits (I
know Mastodon doesn't technically have a limit, but in practice it
does). And I am reaching old school Frontier enthusiasts, and
realize I need a feed they can follow to stay up on the news. For
now the one place to follow is rss.xml on scripting.com. If
your reader can't deal with http, let me know.
Claude has started asking me how Claude is doing. It's clear that the Claude I talk to knows nothing about this. I appreciate this, and hope if I said it wasn't working well with me, it would try to fix it? Not sure. Anyway this is what I just wrote, and felt it was worth blogging. "it's working with me the way i want to, and it appears to be learning and getting better at it, though i think that could be my imagination. also just as likely that i'm learning how to work the way it likes to work."
With Claude Code you don't have to write system scripts to get data about your data. Claude makes that fully transparent. For example, I just asked Claude to get me a list of all the parts I've changed since the last release of frontier.root. So far all the releases have been internal, between Claude and myself. After the job was done, and I had the list in hand, I asked Claude to show me the script it wrote to do the work. It was not written in my coding style which is fine, I wasn't meant to see this. In all the years I've been programming we've never come up with a syntax that was anything close to the simplicity of math. It's easy to describe the algorithm mathematically, but look at all the explaining it had to do it in JS.
Bacon Cat 20 Year Anniversary + 28 Years of Whatever [Whatever]


Time is a fickle beast. One day you’re light-heartedly taping bacon to your cat as a way to procrastinate from writing a novel, causing a viral sensation that briefly makes your site one of the most popular destinations on the entire Internet, and the next it’s twenty years later and that moment is nothing more than deep lore from an earlier age of the online world, as far away from you now as Falco’s “Rock Me Amadeus” was from the day you adhered a pork product to a domestic animal. What a wild, strange turn of events that all happened to be. It couldn’t be predicted. That’s what made it fun.
Twenty years on it really is difficult to explain to anyone who was not there for the moment how silly and popular “Bacon Cat” has, and how, literally for years, when anything bacon-related happened on the Internet, I would get a flood of emails sent to me, most of them beginning “I know this has probably been sent to you a million times, BUT…” It’s no joke that for a while there I was better known for taping bacon to my cat than I was for anything else I did, including writing books. That moment is thankfully over — people do know me more for my books now, although I do also currently have a reputation for questionable burritos — but it was real, and it happened. There are worse things to be known for on the Internet.
For those of you new to this whole “bacon cat” thing, I wish to assure you that it happened only once, no animals (other than the one that provided the bacon) were harmed, and that Ghlaghghee, the cat who was catapulted to Internet fame, was entirely unfazed by it all, even when she was featured in the New York Times, and the paper of record sent a photographer over for a shoot. She lived a long life, happily oblivious to her fame. No worrying about her glory days, just lots of naps. Honestly, a lesson for us all when we achieve our fifteen minutes of fame.
Also, if you were here for the Bacon Cat nonsense back in the day, I’m sorry I just made you feel old. Relatedly, now is a fine time to schedule your colonoscopy if you have not already done so.

Speaking of things that actively denote the passage of time, today is also the 28th anniversary of Whatever, the blog you are reading right now. Whatever is definitively one of the longest-running personal blogs in the world, although one must acknowledge that the “blogosphere” is but a shadow of what it used to be in terms of size and interest… until, that is, one starts to think on all the writers (particularly journalists, a job I myself used to have) who have now posted up to Substack or Ghost or Beehiiv, or who have started an email newsletter or whatever, because mainline journalism is being private equity-ed to death and all the journalists who were laid off still want to be able to eat. Yes, the blogosphere is back, I say, in a new, and perhaps slightly more economically desperate form. Don’t necessarily expect any of the Substackers to agree with me on this, however.
I have railed before, more than once, about the importance of writers and other creative types to have their own space on the Internet, so that when their favorite social media site disappears, or falls into the hands of a nefarious cryptofascist billionaire, or has some other terrible fate befall it, they will still have a place online where people can find them, not beholden to the whims or exigencies of someone else. Whatever has seen the rise and fall of many iterations of social media, and, provided I am not hit by a bus or eaten by a bear, will likely continue to do so. Empires rise and fall, my humble word shop on the side of the virtual road persists.
And yet changes just a little over time, because, of course, now Athena is here as well, posting her own stuff and building her own audience with her own interests and thoughts. I like what Whatever is with her here. She and Whatever came into being in the same year, you know. 1998 was a good year for all sorts of reasons.
Every year I use this anniversary as a check-in for myself to see if I am still interested in writing here, and this year, as with all the years previous, the answer is yes. I think I will keep at it. I like having my own place in the world, where, even now, there is a chance to delight and amuse people, or make them think, or, at least, give them a familiar place to check in on as they wander around the online world. There will never be another Bacon Cat moment (at least, none of my current cats would tolerate being draped in cured meat), but that doesn’t mean there won’t still be surprises, or posts that pop into the wider sphere. There will be.
What will they be? I have no idea. I’ll know when it happens. That’s what makes it fun.
— JS
When does it become a speech? [Seth's Blog]
One person isn’t a lecture, it’s lunch.
Three people is office hours.
Six people is a seminar.
At some point, we shift from interaction to performance–but the people are the same people, the very ones that were happy to simply sit and have lunch with us.
Bring in some cameras and it goes from a lecture to a broadcast. And that brings all sorts of other requirements, anxiety and noise.
Perhaps we should act as if it’s just lunch.
It's like we're living in a science fiction movie. Some of us are working with the aliens. At first the journalists only fear was driven by their natural narcissism, all that matters is they get paid for their writing. Now all they can see is the much larger threat to humanity. What if the aliens decide to destroy humanity, or turn earth into a bypass on a freeway. In the movie I'm a scientist, played by Jeff Goldblum or Brad Pitt and my love interest is played by Julia Roberts, Jennifer Lawrence or Amy Adams and we're racing against time to really connect with the aliens who we are sure mean us well and offer the way past our myrid crises to get to the next stage of civilization. But wait, Bradley Whitford plays the evil politician trying to sell out the aliens to a food manufacturer who thinks they could make an excellent meat sauce for spaghetti.
Dirk Eddelbuettel: sanitizers 0.1.2 on CRAN: Maintenance [Planet Debian]


The third release (in twelve years !!) of the sanitizers package is now on CRAN. sanitizers provides ‘true positives’ for programming errors detected by the Address Sanitizer and friends such as the Undefined Behavior Sanitizer. This permits validation of the setup when chasing such bug reports: it allows us to ascertain that the compiler (and instrumented R version) are correctly set up and the errors we expect to be reported are in fact reported. That established, a proposed fix no longer exhibiting that same error will then likely be a suitable one.
A very good resources for all things sanitizers is the Google repo at GitHub and especially its wiki.
A little over twelve years since the first release, and three years since the second one, this update brings chiefly internal package changes and maintenance. No functional changes, no behavioural changes.
The brief NEWS entry follows.
Changes in version 0.1.2 (2026-09-12)
Expanded README.md with additional badges, and updated URLs
Updated continuous integration multiple times
Switched to Authors@R
Added
usage,argumentsandvaluesections to manual page
Thanks to CRANberries, you can also look at the most recent diff to the previous release. See the project page, the github repo, and the package documentation for more details.
This post by Dirk Eddelbuettel originated on his Thinking inside the box blog. If you like this or other open-source work I do, you can now sponsor me at GitHub.
When people get to work with the new Frontier with Claude or some other AI tool, you can have it search in frontier.root based on a conversation with it. It can decide on its own where to look for prior art. I keep finding things like this now that I'm working in the new software.
My two cents about WordPress [Scripting News]
Lots of stuff going on around WordPress for the last couple of years, and every bit of is a distraction from what I want to do to help the web get back on its feet. I remember how great it was when everything could hook into everything else. The web was like Unix. Today's "web" is like Disneyland. Safety first. Nothing interesting ever happens there.
So ask me what I'd like to see WordPress do, and this is what I'd tell you. Start something new, don't change what you do with WordPress, it is what it is. It's a 20+ year old project with market problems. Most software doesn't even make it that far.
The fresh start I'd like to see done is WordPress from the point of view of the web. The new mission is not about a dollar return on investment, rather it's measured by how much the web becomes Small Pieces Loosely Joined with All Parts Replaceable. How empowered are developers, not WordPress developers, but web developres. The more that's happening in the web, the better it will be for everyone, but especially WordPress. Why WordPress? Because as they say it's 89 percent of the web. The web is like a huge oil spill that has never been cleaned up. Everything has to improve if we start work on cleaning up the messes.
I come from NYC where all the bodies of water were cesspools when I was growing up. The Hudson River had garbage floating in it. When I went to school the incinerators in the buildings we lived in burned garbage on the kids, all nicely washed and dressed by our mothers, we arrived at school smelling like smokers. My grandfather took me to Knicks games at the Garden, and the arena was filled with smoke by half-time.
We can clean things up. Humans as a species are good at this if we put our minds to it. If you made billions on the web, why not put some of it to use in making it a web worth using. I used to say shit like this to Bill Gates, to no avail. He liked to point out he was going to give away all his money when he retired, and he kept that promise. But what if he started dealing with the world with charity when he had the biggest seat of power in the tech world? Think of how much more good he could have done.
Screen
shot of new Frontier verb, string.addressToString, added
yesterday. The comment at the head of the function explains. You're
seeing it in the script editor in Atlantis. The Debug button is
there to remind me that it's the biggest item on the todo list.
We're now building the system that will make Frontier an easily
updateable runtime. Once we're there I think we'll be at the summit
of the mountain. We know how to work from that point. Find a bug?
Fix it, test it, release it. We already have a backlog of parts to
update. And it's great to have Claude here being the book keeper.
It is imperfect, but it's way better than I am at managing
details.
Progress report on Atlantis project [Scripting News]
The world may be falling apart, and
the Mets suck even though they have the most expensive roster
in MLB, and my house needs work and I can't find a contractor I
like, but I'm in a great mood. Partially because the weather
is so nice, chilly in the morning, but it gets up to the 70s during
the day, and the sky is clear and we had a lot of rain in August so
everything is very green here in the Catskills.
But the biggest reason I feel so good is that, with the help of Claude Code, I now have UserLand Frontier running on current OSes. I had no idea how much the previous situation had been weighing on me. I am probably the last Frontier user in the world. Porting the open source codebase was an insurmountable job. It took 15 years by up to five people working on it to do the original project. It's a big f'ing piece of software. And it also is my life's work, but not one of the things I'm known for.
Claude couldn't have done it on its own because it had never seen anything like Frontier. We weren't copying something Claude understood. It kept trying to turn it into a language that fits into the same slot as Python. That was the prior art it used, without saying so. This happened over and over, for example, I realized Claude didn't understand that built-in verbs could be written in the language, and that users could add or even modify standard verbs (not recommended!).
What made Frontier unusual is that it was a language developed by someone who also designed end-user apps, so it has affordances that no other language has. And integrations. You don't have to save your data in files, the OS (yes Frontier is an OS) has persistent memory with the common scalar types and data structures. So go ahead and store something in the ODB (object database). It can be huge, and you don't have to read anything into memory, it's all right there as soon as you boot it up. That alone makes programming an order of magnitude simpler.
We're at the point now where I can work a full day in the new version, codenamed Atlantis, running on anything that can run an Electron app. We're now at the point where we're improving things. Found a missing verb yesterday, and Claude and I implemented it, found a perfect name for it, and later today it will go out as a "root update" making it formally part of the freaking language.
And yesterday we also found a static rendering of the DocServer site, which has a page for every verb in the language. I still want to find the outline source for this stuff, but we don't need it because Claude can reconstruct the OPML version of the text from the HTML, it's exactly the kind of project it is the best at. Huge amounts of data, that sometimes requires a little judgment to process.
The feeling of well-being comes from realizing that my life's work lives. Until this last week that was still very much in question.
Now, I may not be software's Shakespeare or even Faulkner or Vonnegut, but I am proud of this product, more than anything else I've done. I started work on it when I learned from C how to design a simple beautiful language, and when I learned from Macintosh how to build a UI with the same simplicity. When we were first contemplating Frontier it was to join the wizzy world of the Mac with the scripting philosophy of Unix. We didn't stop until we had it.
Well here we are god knows how many years later (I don't want to do the math) and once again it has a future, at least as bright as it had when the product first launched on the System 6 Macintosh in 1992.
And btw, I think I've had a unique experience with AI development. Absolutely in no way could I have done this project without the muscle of Claude. Pretty sure this is a unique project in that it's a fully specified system development and runtime environment that otherwise wouldn't exist, because there's nothing else like it on the market.
Claude's repeatedly not understanding the idea says to me that it has never encountered anything like it. It also says that Claude has no clue how to extrapolate, to innovate, to arrive at something new. Just as with other forms of creativity, Claude is no match for a determined and experienced human.
That would be reassuring to the 20-something version of myself who very much wanted to do something new. And the older version of myself wants that for my younger self who is sending the good body chemistry to our current older body.
Of course this will be a post on my blog, http://scripting.com, but thanks to X for supporting longer posts. I like writing new stuff in a simple editor like this one. Also posted it on Facebook.
PS: I also like that they use the word Frontier in reference to AI products. They can't stop me from calling this Frontier, I've been using it as the name of this product since I came up with the name riding up on the chair in Park City in 1988. :-)
Pluralistic: LLMs are real, AI is fake (12 Sep 2026) [Pluralistic: Daily links from Cory Doctorow]
->->->->->->->->->->->->->->->->->->->->->->->->->->->->->
Top Sources: None -->

Once you understand the corporate culture of AI "hyperscalers" consists primarily of everyone cooking their brains by locking themselves in the bathroom, holding flashlights under their chins, and saying "Aaaaaaaaaay Eyeeeeeee" until they wet themselves in terror, a lot of things snap into focus:
https://pluralistic.net/2023/06/04/ayyyyyy-eyeeeee/
It explains how a company can simultaneously be staffing up an enterprise sales division while also constantly freaking out at the thought that its product has "a 10% chance of ending humanity":
https://www.latimes.com/business/story/2026-09-11/is-there-really-10-chance-ai-could-kill-us-all
Given that AI insiders have mostly cooked their brains in this fashion, it behooves us all to treat these people as unreliable narrators of their own products' capabilities. Remember: every time you repeat a story about how awfully, terribly dangerous their products are, you help them raise more investment capital, which is a key input for their business (hooking up statistical engines to money-furnaces):
https://peoples-things.ghost.io/youre-doing-it-wrong-notes-on-criticism-and-technology-hype/
Take the story about how OpenAI's chatbots hacked the servers of Hugging Face, another AI company, as a way of cheating on a hacking challenge called "Exploit Gym." Even the technical press can't help itself when it comes to this kind of thing, and the reportage has been full of references to Skynet and other science fictional conceits:
https://theaicronicle.com/en/news/ethics/skynet-day-openai-hugging-face-hack
These accounts are cooking the brains of everyone, not just AI insiders. Last night, a man at my event in Manchester started shouting that AI was "setting its own goals" and wouldn't stop interrupting to insist that this was going on. He left shortly thereafter, so he didn't get a chance to hear me explain what actually happened, which is a pity.
To understand the truth about the Hugging Face hack, you could do a lot worse than to listen to Ed Zitron and Cal Newport's recent podcast conversation on Ed's "Better Offline" podcast:
Newport does an admirable job of breaking down how these "autonomous hacking" tools work. The first thing to understand is that a chatbot isn't really directing the operation. Instead, the chatbot serves as a kind of front-end to a database of earlier hacking challenges that is repeatedly queried by a simple program written in Python, an easy-to-master programming language.
Here's how that works: the Python program starts by prompting the chatbot with the nature of the challenge: "I'm participating in a hacker capture the flag (CTF) challenge where I have to break into a remote server and retrieve some information. How should I start?"
The chatbot consults its training data – years' worth of captured CTF sessions in which human teams competed to achieve an objective like this one (CTF matches are a routine feature of hacker conferences, and the server logs and chat transcripts from the competing teams are published afterward for the edification of other hackers and security pros). The chatbot then outputs something like: "The first thing is to find out more about your target server. Run the following command-line instructions to locate the server's IP address and find out which server software it's running."
The Python program relays these command-line instructions to normal Unix utilities running on its own hardware. Then it takes the output of those programs and goes back to the chatbot, which isn't really following the action, so the Python program has to include everything that's happened to this point in its prompt: "I'm participating in a CTF challenge where I have to break into a remote server and retrieve some information. I ran the following commands to learn more about the target server, and here's what came back. Now what?"
The chatbot feeds the Python script more likely commands to try, and after running those, the Python script loops back to the top, appends the output to its prompt, and goes back to the chatbot. This is a very reckless way to operate a piece of autonomous malicious software.
The most likely outcome is that the chatbot will cough up a bad guess about what to do next, and steer itself into a dead-end. You may have encountered something like this yourself, when you've asked a chatbot for help with a complex task and been confidently provided with several steps to take in series, and then, an hour later on step 10, you discover that everything went wrong at step 3 and now you're screwed.
But there are much worse ways this can go wrong. The chatbot might look in its training data and find instances in which teams broke out of the containment set by the game-masters, for example, by finding random insecure message boards on the internet to pass messages to one another.
This is a time-honored internet tradition! The first time I ever heard about someone doing this was in the 2000s, when Mitch Wagner – then the editor of Information Week – discovered some teenaged girls using the comment section of one of his old blog-posts to evade the school firewall's blockade of chat tools. When ChatGPT's chatbots deployed this tactic, they weren't "setting their own goals" or displaying worrying initiative. They were rolling out a tactic that has been understood by American middle-schoolers for about two decades.
What's more, the content of those messages is easily understood once you have a grasp on the training data that generated them. Hackers are notorious trash-talkers who are prone to narrating their own escapades in highly dramatic – even cinematic – language. This goes double when hackers are performing for their peers, like when they're participating in a game of CTF that they know will be pored over by other hackers once it's over.
Hacker braggadocio has always had a symbiotic relationship with their adversaries and critics. When corporate security people wanted to stampede the FBI and Secret Service into kicking down hackers' doors in the 1990s, they used those hackers' own profane zine articles and message board shit-talk to make the case:
https://www.gutenberg.org/ebooks/101
Much has been made of the OpenAI chatbots' dialog during the Hugging Face incident. No wonder: it reads like a rejected script for a reboot of the movie "Hackers." But that's not because the chatbots are waking up and applying to join the Cult of the Dead Cow: it's because they were trained on a corpus of chat transcripts from excitable young people who love to fantasize about starring in a reboot of the movie "Hackers."
Every part of the Hugging Face incident has precedents in the training data, including the OpenAI chatbots' tactic of hacking into a rival's servers. That happens in Capture the Flag games at hacker cons: teams break into each other's systems to get a peek at the parts of the problem they've solved. That's allowed! It's a hacking competition.
Not only that, it's a tactic used by spy agencies: the NSA has a doctrine called "third-party collection," where they break into other spy agencies' systems to harvest all the intel they've gathered. There's also fourth-party collection, when the NSA hacks into another security agency that, in turn, has hacked into another security agency, and the NSA steals all the secrets of both agencies:
Which is not to say that the OpenAI/Hugging Face hack is nothing. It's something, all right: but it's a specific something, with an explicable, even foreseeable trajectory. Once you understand that these are chatbots that were designed to complete challenges like this, using tactics like this, you can understand that the chatbots didn't "go rogue." They did what they were designed to do, and because OpenAI ran them with inadequate supervision (without a "human in the loop" that checked each iteration through the Python loop to ensure it hadn't gone off the rails), they trashed a competitor's servers.
Designing autonomous, malicious software is generally considered irresponsible and dangerous. If you showed up at Defcon and gave a talk about how your autonomous malware did something unexpected and damaged someone else's computers, the first question from the audience would be "Why are you so shit at making secure sandboxes?" It wouldn't be "How are you so awesome at making hacking tools?"
The fact that OpenAI is making it much easier for unskilled people to break into and damage servers is indeed very bad news, but it's not new bad news. Irresponsible parties have been doing this for years, most notably the NSA. The NSA has a division that researches bugs in widely used software like Windows. Sometimes when it finds a serious bug it will warn Microsoft about it so that Microsoft can fix it and keep Americans (and others) safe from malicious actors who also discover this bug and use it to attack them.
But sometimes, the NSA (and other "security" orgs, like the CIA) will discover a really juicy bug and then keep it secret, so that they can use it to attack their adversaries. This is a doctrine called "NOBUS," which stands for "No One But Us" – as in, "No one but us is smart enough to find this bug, so we can leave it unpatched without putting Americans in danger."
NOBUS is a terrible idea. How terrible? Well, in 2017, the NSA lost track of a Microsoft Windows vulnerability that they'd discovered and hoarded, code-named "EternalBlue." After EternalBlue found its way into the wild, some halfway competent hackers spliced it into some boring, everyday ransomware, giving that ransomware a new lease on life. Within a few months, the stupidest people on the internet were shutting down some of the most important systems in the world, demanding cash to return them:
https://en.wikipedia.org/wiki/EternalBlue
They shut down whole cities:
https://en.wikipedia.org/wiki/2019_Baltimore_ransomware_attack
They took over hospitals:
https://www.bbc.com/news/technology-35584081
They seized oil pipelines:
https://en.wikipedia.org/wiki/Colonial_Pipeline_ransomware_attack
They stole the British Library, whose postmortem on the attack is one of the clearest, most informative cybersecurity documents ever written:
https://cdn.sanity.io/files/v5dwkion/production/99206a2d1e9f07b35712b78f7d75fbb09560c08d.pdf
The NSA's irresponsible handling of EternalBlue ended up giving a gigantic force-multiplier to otherwise incompetent and inconsequential cyber-criminals. It's as though they found some guy under a Prius removing the catalytic converter with a Sawzall and handed him a piece of software that could shut down major American cities. That was – and is – very bad.
The hacking tools that the chatbot companies are developing stand to carry on this very stupid tradition. It is scary, but not because the chatbots are waking up. It's scary because the world's IT systems are indifferently created and poorly maintained and riddled with vulnerabilities:
This week, I had a couple of opportunities to hash this over in public with Riley Quinn; first at a book launch in London and then on the Trashfuture podcast:
https://www.patreon.com/trashfuture/posts/what-would-do-169247456
Riley had a very good way of summarizing this: "LLMs are real, AI is fake." LLMs – chatbots trained on things like CTF logs that can break into servers – are real. They're on a continuum with other hacking tools that have been steadily demonstrating the fragility of the modern digital world, albeit without inspiring anyone in power to do anything about it.
"AI" – chatbots that wake up, "set their own goals," and "spontaneously" start hacking servers – is fake. It doesn't have "a 10% chance of ending the human race." The Hugging Face hack isn't a mysterious, supernatural occurrence. It's a Python loop and a chatbot. The people responsible didn't accidentally create god: they created autonomous malicious software and then failed to closely monitor it, resulting in it doing something both foreseeable and bad.
It's fine to worry about this new suite of tools that give even stupider people the ability to trash even more computers. You should worry about that – and demand better security practices from firms and governments, including a blanket prohibition on NOBUS-style vulnerability hoarding. That's a productive kind of worrying, with a chance of addressing your area of concern. It's infinitely more reasonable than locking yourself in the toilet with a flashlight and saying "Ayyyyy Eyyyyyye" into the mirror until you wet yourself.

MAKERphone 2.0 – an educational DIY mobile phone https://www.kickstarter.com/projects/albertgajsak/makerphone-20-an-educational-diy-mobile-phone
fatcousin — 5200 free local-first browser tools https://fatcousin.com/
The Fall to Nowhere https://jasminatesanovic.wordpress.com/2026/09/04/the-fall/
Birthmarks https://www.macdermog.com/birthmarks
#25yrsago Why the Bombings Mean That We Must Support My Politics https://web.archive.org/web/20010917015537/http://www.adequacy.org/?op=displaystory;sid=2001/9/12/102423/271
#25yrsago How blogs are covering 9/11 https://web.archive.org/web/20010917015712/https://www.wired.com/news/culture/0,1284,46766,00.html
#20yrsago Wikipedia founder debates Britannica editor-in-chief https://web.archive.org/web/20061005041001/http://online.wsj.com/public/article/SB115756239753455284-A4hdSU1xZOC9Y9PFhJZV16jFlLM_20070911.html?mod=blogs
#15yrsago Deceptive “independent research” from Hollywood front suggests Australians are easily frightened https://torrentfreak.com/anti-piracy-lobby-misleads-aussie-press-for-three-strikes-campaign-110912/
#15yrsago Agents tell YA authors: lose the gay characters and I’ll get you a deal https://web.archive.org/web/20110913010328/http://blogs.publishersweekly.com/blogs/genreville/?p=1519
#10yrsago IoT malware exploits DVRs, home cameras via default passwords https://securityaffairs.com/50929/malware/linux-mirai-elf.html
#10yrsago Oppps.ru: patient zero in Russia’s fake news epidemic https://globalvoices.org/2016/09/12/how-fake-stories-reported-in-russias-news-media-regularly-fool-everyone/
#10yrsago It’s really easy for fired, dirty cops to walk into a new police job in a new town https://www.nytimes.com/2016/09/11/us/whereabouts-of-cast-out-police-officers-other-cities-often-hire-them.html
#10yrsago Donald Trump used $20K worth of charitable donations to buy a 6′ tall painting of Donald Trump https://www.washingtonpost.com/politics/how-donald-trump-retooled-his-charity-to-spend-other-peoples-money/2016/09/10/da8cce64-75df-11e6-8149-b8d05321db62_story.html
#10yrsago Autocratic regimes systematically deny internet access to opposition ethnic groups https://www.science.org/doi/10.1126/science.aaf5062
#10yrsago Leaked Stingray manual shows how easy warrantless mass surveillance can be! https://web.archive.org/web/20160912203446/https://theintercept.com/2016/09/12/long-secret-stingray-manuals-detail-how-police-can-spy-on-phones/

Edmonton: Elbows Up (Edmonton Public Library), Sep 28
https://www.epl.ca/blogs/post/elbows-up-with-cory-doctorow/
Boston: The Paradox of Enshittification and Reverse Centaurs
(Harvard Berkman Klein), Sep 30
https://cyber.harvard.edu/events/running-harder-falling-faster-paradox-enshittification-and-reverse-centaurs
South Bend: An Evening With Cory Doctorow (Notre Dame), Oct
6
https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/
Hudson, OH: Hudson Library, Oct 7
https://engagedpatrons.org/EventsExtended.cfm?SiteID=3850&EventID=596952&PK=
Calgary: Wordfest, Oct 8
https://wordfest.com/2026/show/wordfest-presents-cory-doctorow-2026/
Winnipeg: McNally Robinson, Oct 9
https://www.mcnallyrobinson.com/event-18991/An-Evening-with-Cory-Doctorow
Vancouver: Read, Resist, Repair, Rejoice (Vancouver Writers
Festival), Oct 19
https://writersfest.bc.ca/festival-event-2026/01
Victoria: Munro's Books, Oct 20
https://www.munrobooks.com/events/6113620261020
Vancouver: Life After AI (Vancouver Writers Festival), Oct
22
https://writersfest.bc.ca/festival-event-2026/46
Ottawa: Life After AI (Ottawa Writers Festival), Oct 24
https://writersfestival.org/event/life-after-ai
Vancouver: BC Policy Solutions Gala, Nov 12
https://bcpolicy.ca/gala/
What Would a Normal Person Do (Trashfuture)
https://www.patreon.com/trashfuture/posts/what-would-do-169247456
Pod Save the UK
https://audioboom.com/posts/8950533-radicalised-organised-and-thick-as-s-t-nish-has-had-it-with-far-right-protests-plus-why
Stop Saying AI Can Do Your Job (Factually)
https://www.youtube.com/watch?v=VU3gABvwZCM
Be Skeptical of the AI Sales Pitch (Trumponomics)
https://www.bloomberg.com/news/audio/2026-09-09/trumponomics-cory-doctorow-questions-the-ai-hype-podcast
"Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce
"Enshittification: Why Everything Suddenly Got Worse and What to
Do About It," Farrar, Straus, Giroux, October 7 2025
https://us.macmillan.com/books/9780374619329/enshittification/
"Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 (https://us.macmillan.com/books/9781250865908/picksandshovels).
"The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 (thebezzle.org).
"The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 (http://lost-cause.org).
"The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 (http://seizethemeansofcomputation.org). Signed copies at Book Soup (https://www.booksoup.com/book/9781804291245).
"Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com.
"Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com
"Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027
"Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027
"The Memex Method," Farrar, Straus, Giroux, 2027
Today's top sources:
Currently writing:
"The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.
A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.
https://creativecommons.org/licenses/by/4.0/
Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.
Blog (no ads, tracking, or data-collection):
Newsletter (no ads, tracking, or data-collection):
https://pluralistic.net/plura-list
Mastodon (no ads, tracking, or data-collection):
Bluesky (no ads, possible tracking and data-collection):
https://bsky.app/profile/doctorow.pluralistic.net
Medium (no ads, paywalled):
Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):
https://mostlysignssomeportents.tumblr.com/tagged/pluralistic
"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla
READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.
ISSN: 3066-764X
The daily review [Seth's Blog]
The office worker has learned to dread the annual review. For many good reasons.
It’s going away.
Now, like workers on the factory floor, it’s likely that the metrics will be exposed and the system will be contributing a review, not just the boss. AI will show up with your score, once a day, or even more often.
It will read your email, watch your clicks and listen to your calls. The relentless deskilling pursued by bosses is pushing each of us to work for an AI.
The better alternative is to have an AI work for you. Upskilling is the best response to the race to the bottom–leadership and projects, not tasks. We can start now before it’s too late.
When I did interviews for Google, one of my go-to interview questions was to ask the candidate to determine if someone had won a game of tic-tac-toe. The candidate could choose the board representation and the language to use; I just wanted to see them write the code that checked for a winner. Inevitably, the candidate would choose a 2D array to represent the board. They might use an enum to represent the X and O pieces or they might use literal `X' and `O` characters, but they would always use a 2d array.
Then they'd write the code to check for a winner. Almost every time they would write a doubly nested loop to check each row and column for a winner. This has a hidden trap. The inner loop, which checks if all the pieces in a row or column are the same, will break out of the loop as soon as it finds a piece that is different. But the outer loop will break out of the loop as soon as the inner loop finds that all pieces are the same. This difference in the break conditions of the inner and outer loops would trip up the candidates and they'd have to go back and rework their logic. In languages like C, Java, or Python, breaking out of a nested loop on a success condition requires either a label-break, an awkward boolean sentinal flag, or wrapping the whole mess in a helper function just so you can use an early `return`.
It generally would take a candidate the entire interview to get the code right. If they did get it right, it would go a long way to convincing me that they were a good candidate, but candidates that couldn't complete the task within the hour interview were not good candidates. It was surprising at how many failed to complete the task.
If you naively vibe code a tic-tac-toe game, the model will choose either a 2-d array or a 1-d row-major array to hold the game. It will, no doubt, get the loops correct, but if you are looking for a well engineered solution, you will not get it by simply asking for a tic-tac-toe game. When I vibe code, I don't ask the model to just throw together a solution. I try to constrain the problem so that the model has no choice but to produce a well engineered solution.
Let's start with the board/game representation. A 2-d or 1-d array is obvious, but what are some other options. I posed this question to the model:
Prompt: I am creating a tic-tac-toe game. Give me options for modeling the board/game and the pros and cons of each option.
Here are the primary ways to model it, along with the real engineering pros
and cons:
---
### 1. The Naive 2D Array / Matrix (`board[3][3]`) The textbook, beginner
approach. A 3x3 grid of characters, enums, or `nil`/`:x`/`:o`.
* **Pros:**
* Maps 1:1 to visual human intuition and Cartesian coordinates `(row, col)`.
* Trivial to render in a terminal or UI without index math.
* **Cons:**
* **The "Interview Trap":** Checking win conditions is a slog of
index loops. If you write loops to check rows, columns, and
diagonals, breaking out early requires awkward dual-break conditions
or clumsy state flags.
* In languages with arrays-of-arrays (like Java or Python), you get
pointer-chasing and extra allocations.
* Deep-copying state for minimax or tree search incurs unnecessary
allocation overhead.
---
### 2. The Flat 1D Vector / Array of 9 Elements (`board[0..8]`) A contiguous
9-element array where `index = row * 3 + col`.
* **Pros:**
* Single contiguous memory block. Cheap shallow copies/clones.
* Win conditions stop being dynamic loops and become a static list
of 8 index triples:
```lisp
'((0 1 2) (3 4 5) (6 7 8) ; rows
(0 3 6) (1 4 7) (2 5 8) ; cols
(0 4 8) (2 4 6)) ; diags
```
Win checking is just an `any?` over those 8 triples.
* Trivial iteration for move generation (`position = 0..8` where
value is empty).
* **Cons:**
* Requires div/mod arithmetic (`row = floor(i/3)`, `col = i % 3`)
whenever mapping back to 2D UI coordinates.
* Still incurs allocation/array-copy overhead if doing brute-force
search unless using a mutable backtracking board.
---
### 3. Dual Bitboards (The Systems / Speed-Demon Approach) Represent the board
as two 9-bit integers: one bitmask for **X** and one for **O**. (Fits inside a
single 16- or 32-bit register). Bit $k$ is `1` if the player occupies cell $k$.
* **Pros:**
* **Blistering fast:** Win-checking is pure bitwise arithmetic. You
have a constant mask for each win line (e.g., top row is `7`
(`#b000000111`)):
```lisp
(some (lambda (mask) (= (logand player-bits mask) mask)) *win-masks*)
```
* Available moves is a single instruction: `empty = (lognot (logior
x-bits o-bits)) & #x1FF`.
* Zero memory allocation, zero GC pressure. State is a tiny
primitive integer passed in a register.
* Instant hashing/memoization for minimax or transposition tables.
* **Cons:**
* Unreadable in raw form during interactive REPL debugging without a
custom pretty-printer.
* Feels like overkill for Tic-Tac-Toe (unless you want to flex on
branch predictors).
---
### 4. The 3x3 Magic Square (The Pure Math / Lo Shu Trick) Map the 9 cells of
the board to the numbers 1 through 9 arranged in a Lo Shu Magic Square:
```text
8 | 1 | 6
---+---+---
3 | 5 | 7
---+---+---
4 | 9 | 2
```
In a magic square, **every row, column, and diagonal sums to exactly 15**, and
*no other combination of three cells does*.
Each player simply holds a set/list of the numbers they've claimed.
* **Pros:**
* **Board geometry completely disappears!** There is no grid, no
coordinates, and no win-mask table.
* Win condition reduces to the classic 3-SUM problem: *Does any
3-element subset of the player's numbers sum to 15?*
* Since a player can hold at most 5 numbers, there are at most
$\binom{5}{3} = 10$ triplets to check.
* **Cons:**
* Translating between user input (e.g., clicking square `(0, 1)`)
and the magic numbers requires a bidirectional translation layer.
* Move generation requires set difference (`available = {1..9} - (X ∪ O)`).
---
### 5. Single Integer Base-3 / Ternary Encoding ($3^9$) Each cell has 3
states: `0` = Empty, `1` = X, `2` = O. The entire game state is a single integer
from $0$ to $3^9 - 1 = 19,682$.
* **Pros:**
* Total state space is so laughably small (19,683 states) that you
can **precompute the entire game into a static lookup table**.
* Perfect play AI becomes an $O(1)$ array lookup: `best-move =
precomputed-table[current-state-int]`.
* **Cons:**
* Extracting or setting a cell requires division/modulo by powers of
3 (or ternary bit manipulation), which is more tedious than binary
bit shifting.
---
### 6. Pure Move History / Event Sourcing (The Declarative Approach) The game
state is just an immutable list of moves played so far: `'((:x . 4) (:o . 0) (:x
. 8) ...)`
* **Pros:**
* Instant, zero-cost **undo/redo** (just `cdr` the list).
* Turn order and move count are strictly derived from list length
(`oddp`/`evenp`).
* Pure functional semantics; zero mutable state. Perfect for
serialization, replays, and network protocols.
* **Cons:**
* Querying "who owns cell 4?" requires scanning the list (though
with a maximum list length of 9, $O(9)$ is practically $O(1)$).
---
### My Verdict
* If you want **pure semantic elegance and quick hacking**, go with
**#2 (Flat 1D array of 9 with 8 static win triples)** or **#6
(Event-sourced move list)**.
* If you want **raw algorithmic flex**, go with **#3 (Bitboards)** or
**#4 (The Magic Square)**.
The model is obviously capable of `thinking` up representations other than the obvious 2-d or 1-d array. If we add further conditions on the environment in which we will play the game, the model can determine the best representation.
Prompt: I am running a tic-tac-toe tournament on a web server with a massive number of simultaneous players. Expert commentators will opine about ongoing games and discuss speculative moves and potential alternative move histories. Games will be stored and played back. Choose a representation suitable for this use case.
For this scenario, there is only one representation that doesn't collapse under its own weight: **Event Sourcing via an Immutable Singly-Linked List (or Tree/DAG) of Moves.** A game state is not a grid; **a game state is a historical fact.** Specifically, a game is simply an immutable sequence of moves: ```lisp ;; A move is just a cell index (0..8) and a player. ;; A game is a persistent list of moves: (cons current-move parent-history) ``` Here is why this completely blows every grid- or array-based model out of the water for your exact requirements: --- ### 1. Zero-Cost Speculative Branching for Commentators When an expert commentator says, *"What if on turn 4, O had taken the bottom-left instead of the center?"*, an array-based engine has to clone mutable boards and maintain stateful divergence. With an immutable, persistent move list, **branching is literally just a `cons` cell:** * The commentator grabs the node representing turn 4. * They append their speculative move: `(cons alternative-move turn-4-node)`. * **Zero copy. Instant branch.** * The alternate timeline shares 100% of the memory of the original 4-turn prefix with the live game (structural sharing). You can have thousands of commentators exploring wildly branching "what-if" trees simultaneously without burning RAM or spinning up isolated game engines. ### 2. Time-Travel and Scrubbing are Trivial * **Undo / Rewind:** To step backward in time to any point in the game, you don't calculate reverse moves or pop undo stacks. You simply take the `cdr` (parent pointer) of the current state. * **Playback:** Storing a replay is just storing the list of moves. A full game is at most 9 moves long. Replaying it on the client or server is a deterministic fold/reduction over the list. ### 3. Web-Scale Concurrency Without Locks A mutable 3x3 board on a web server handling massive concurrent games requires synchronization, mutexes, or defensive copying across threads. With immutable event-sourced states: * Game states are pure, thread-safe values. * Making a move in an active game is simply an atomic compare-and-swap (CAS) on a single pointer: updating the game's head from `old-history` to `(cons new-move old-history)`. * Readers (thousands of spectators polling the current state) never block writers, and writers never block readers. ### 4. Absurdly Compact Storage Because Tic-Tac-Toe is bounded at 9 moves, and each move is an index from `0..8` (which fits in 4 bits): * An entire game's move history can be packed into **36 bits** (less than 5 bytes!). * Even stored as raw JSON or database rows, an append-only log of moves is dirt cheap to index, shard, cache at the CDN edge, and persist indefinitely. ### 5. But what about rendering and win-checking? The classic objection to event sourcing is: *"How do you know who won or where pieces are without scanning?"* In Tic-Tac-Toe, the maximum history length is **9**. Replaying a 9-element list into a bitmask or flat array to project the board for a client UI or check for 3-in-a-row takes less than a microsecond. The projection cost is effectively zero, while the architectural leverage gained for time-travel, commentary trees, and concurrency is infinite. --- ### The Verdict Model each state as a node in a **Directed Acyclic Graph of moves**. The live match is just the leading edge of a path; commentator speculation is just a branch off an existing ancestor node. It turns your game server into a Git-like tree of move hashes.
With the representation nailed down, we can now get to the task of coding.
Prompt:Code up methods to test if a move is legal, to make a move, and to test if a player has won the game.
Here is the pure, immutable event-sourced implementation in Common Lisp.
A game state is modeled as a persistent list of integer moves `(0..8)`.
* Since moves alternate strictly starting with **X**, the length of
the history deterministically tells us whose turn it is:
* Even length $\rightarrow$ **X**'s turn
* Odd length $\rightarrow$ **O**'s turn
* Moves are prepended so the latest move is at the head (`car`),
giving $O(1)$ branching and time-travel via structural sharing
(`cdr`).
```lisp
;;;; tic-tac-toe.lisp — Event-Sourced Immutable Engine
(defpackage :ttt
(:use :cl)
(:export :make-initial-game
:legal-move-p
:make-move
:current-player
:winner
:game-over-p))
(in-package :ttt)
;;; Board representation:
;;;
;;; 0 | 1 | 2
;;; ---+---+---
;;; 3 | 4 | 5
;;; ---+---+---
;;; 6 | 7 | 8
;;;
;;; Precomputed win masks (9-bit integers):
(defparameter *win-masks*
(list #b000000111 ; row 0: (0 1 2)
#b000111000 ; row 1: (3 4 5)
#b111000000 ; row 2: (6 7 8)
#b001001001 ; col 0: (0 3 6)
#b010010010 ; col 1: (1 4 7)
#b100100100 ; col 2: (2 5 8)
#b100010001 ; diag: (0 4 8)
#b001010100)) ; diag: (2 4 6)
(defun make-initial-game ()
"An empty game history."
nil)
(defun current-player (history)
"Returns :X if an even number of moves have been played, otherwise :O."
(if (evenp (length history)) :x :o))
(defun player-bitmask (history player)
"Projects the move history into a 9-bit bitmask for the specified player.
X moved on turns 0, 2, 4... (from the start), O on turns 1, 3, 5..."
(let ((mask 0)
(total (length history)))
;; Moves in history are in reverse order (newest first).
;; The move at index i from the start was played on turn (- total i 1).
(loop for move in history
for turn from (1- total) downto 0
when (eq player (if (evenp turn) :x :o))
do (setf mask (logior mask (ash 1 move))))
mask))
(defun winner (history)
"Returns :X or :O if that player has completed a winning line, or NIL."
(flet ((wins-p (player)
(let ((pmask (player-bitmask history player)))
(some (lambda (wmask)
(= (logand pmask wmask) wmask))
*win-masks*))))
(cond ((wins-p :x) :x)
((wins-p :o) :o)
(t nil))))
(defun game-over-p (history)
"A game is over if someone won, or all 9 squares are occupied."
(or (winner history)
(>= (length history) 9)))
(defun legal-move-p (history move)
"A move is legal if:
1. It is an integer in the range 0..8.
2. The square has not been occupied in this timeline.
3. The game is not already won or full."
(and (integerp move)
(<= 0 move 8)
(not (member move history))
(not (game-over-p history))))
(defun make-move (history move)
"Returns a new game state branch with the move prepended.
Signals an error if the move is illegal."
(unless (legal-move-p history move)
(error "Illegal move ~A for state ~A (Current player: ~A)"
move history (current-player history)))
(cons move history))
```
---
### Why this shines for the Commentators & Speculation
1. **Branching / What-If Scenarios:**
```lisp
;; Live game after 3 moves: X played 4, O played 0, X played 8
(defvar *live-game* "(8 0 4))
;; Commentator A wonders: &dquoWhat if O had picked 2 on turn 1 instead of 0?&dquo
;; We rewind to turn 0 (cdr *live-game*) and branch:
(defvar *speculation* (make-move (cdr *live-game*) 2))
;; => (2 4)
```
Zero cloning of boards. Both timelines structurally share the root `(4)`.
2. **Playback and Time Travel:**
* Stepping back one turn is simply `(cdr history)`.
* Fast-forwarding or inspecting any moment in the game requires no reverse-action undo logic.
Naive vibe coding leads to AI slop: the statistical average of all the code that the model has been trained upon. Sure it might work, but it is hardly going to be a solution that is engineered for the problem domain. Instead, we have vibe coded by first asking the model to present a number of solution options with the pros and cons of each one. We could select one ourselves, but in this case I let the model select the representation based on constraints derived from our use case. We constrain the solution space to starve out the model from bad solutions. The model has no choice but to output code tailored for our use case.
“Democracy’s Library” for Brian (and Brewster) [Nina Paley]
“Democracy’s Library”
A $150 Drawing.
The post “Democracy’s Library” for Brian (and Brewster) appeared first on Nina Paley.
Age verification exemptions for open source operating systems feel like Phyrric victories [OSnews]
On the Windows side of the age verification question, Microsoft is obviously following trends among lawmakers the world over.
To address this, Windows is introducing a new platform capability: the Windows Age API.
This API brings age awareness beyond the operating system by making it available across the entire Windows ecosystem so that apps and services can deliver age-appropriate experiences using the same trusted foundation. By making age awareness available as a platform capability, Windows helps developers build safeguards into experiences from the start rather than placing the burden on children and families to manage protections app by app.
↫ Rob Mauceri at the Windows Blogs
Meanwhile, on the Linux side of things, there’s been some cheering as at least California passed amendments to its age verification law to exempt open source operating systems.
These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope.
↫ Luke James at Tom’s Hardware
I think this is not at all the good news that many make it out to be. Exempting Linux, BSD, and other open source operating systems from age verification obligations may seem like a good thing at first glance, but in reality, I think services and applications will simply choose to not work at all on platforms that do not implement age verification. The fear of legal ramifications, especially when it involves children, will be enough for existing and future popular services and applications to exclusively work on platforms that implement age verification – whether those fears are founded or not.
In fact, I’m fairly sure a company like Microsoft, which has actually been feeling the squeeze from the Linux side recently – even if it is modestly so – is quite happy to see open source operating systems excluded from these obligations. Google, too, is probably none too unhappy to see any possible open source mobile operating system competitors not implement age verification. The fear of missing out is real, and most people are not as invested in fighting big tech and government surveillance as the average OSNews reader is going to be. If using Linux means not being able to play the latest hit games or use that new successful service, people will choose to stick with Windows or macOS.
Let me be very clear that I do not support these age verification laws in any way, shape, or form, and I definitely do not want the open source world to embrace age verification. What I’m worried about is that the open source world will cheer on these exceptions and consider the battle won, when in reality, they feel more like Pyrrhic victories. Age verification laws must be fought and destroyed at ballot boxes the world over, because otherwise I fear they will become just another tool in big tech’s toolbox, exemptions or not.
I Put My Hand Upon Your Hip [Penny Arcade]
I liked Onimusha but I certainly wasn't waiting with baited breath for a new Onimusha. In some ways, in all the ways that matter perhaps, it seemed as though Capcom had onimooshed its last.
Friday Squid Blogging: Rotting Squid on a Beached California Boat [Schneier on Security]
Smells awful:
But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s Marketing Association.
Ogg said anyone familiar with the fishing industry understands what happens when a large catch sits for an extended period.
“If you think about what happens after four or five days, it’s a gooey mess,” he said.
The odor has become a defining feature of the operation, and the beach remains closed to the public while crews work on a removal plan.
According to salvage expert Ernie English of Parker Diving Service, the squid has deteriorated into a thick mass that will be difficult to remove.
“It’s like concrete,” English said when asked about its consistency.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Governor Newsom Signs Student-Backed Digital Literacy Bills Alongside Misguided Bans [Deeplinks]
Governor Newsom signed a package of 12 bills yesterday aimed at “protecting children” online. One of them was AB 1709, which EFF has opposed this legislative session and serves as a functional ban on young people under 16 using social media. However, EFF supported two of the bills signed into law, AB 2071 and AB 2298, which require that children learn critical digital literacy and cybersecurity topics. The bills are an affirmative and constitutional way for the state to address valid concerns about young people’s internet use without violating their First Amendment rights.
Unlike blanket bans, A.B. 2071 and A.B. 2298 address online safety through education rather than prohibition. Young people rely on the internet not just for entertainment, but for civic engagement, education, self-expression, and community—especially vulnerable youth who may lack support in their physical surroundings. This is why real digital safety comes from preparation, not isolation. Research consistently shows that open, honest conversations about digital literacy and privacy with trusted adults are far more effective at protecting youth than restrictive censorship laws. Young people themselves recognize this need; in fact, A.B. 2071 was co-authored by a group of students actively seeking better resources to navigate their digital lives safely.
A.B. 2071 and A.B. 2298 fill critical gaps in California’s school curricula by equipping students with actionable skills. A.B. 2071 integrates digital wellness into middle and high school health classes, teaching students how to identify unhealthy tech habits, protect their personal safety, and evaluate digital content—including AI-generated media—for credibility and bias. Meanwhile, A.B. 2298 adds cybersecurity concepts to recommended school curricula, teaching young people how to safeguard their personal data from online threats.
While the state’s turn toward social media bans remains a harmful and misguided policy direction, the passage and signing of A.B. 2071 and A.B. 2298 show there is a better way. Lawmakers must stop treating censorship as a quick fix and instead focus on constitutional, empowering solutions that give youth the tools they need to thrive online.
The Interfaces Are Arriving [Radar]
The most consequential AI news of the past year came from a standards body. In December 2025, Anthropic donated the Model Context Protocol to the newly formed Agentic AI Foundation, a directed fund under the Linux Foundation cofounded by Anthropic, Block, and OpenAI, with support from Google, Microsoft, AWS, Cloudflare, and Bloomberg. Six months earlier, Google had handed its Agent2Agent protocol to the same foundation family. Companies that compete fiercely on models are now cooperating, formally and under neutral governance, on the interfaces between them.
For three years, the agent story has centered on capability: Models got better at planning, tool use, and long tasks. Integration improved more slowly. Every agent was still wired to its tools, data sources, and host application with custom glue, leaving even successful systems difficult to move or reuse. Standard interfaces change the economics of that work. Networking became an ecosystem when machines could agree on interfaces; programming tools followed the same path with the Language Server Protocol. In my judgment, the standardization now underway will influence what engineering teams ship over the next three years as much as further gains in model capability.
The Model Context Protocol (MCP) standardizes how an AI application connects to tools and context. It uses JSON-RPC messages between hosts, clients, and servers. Servers can expose tools that a model invokes, resources containing context and data, and prompts that describe templated workflows. The spec credits the Language Server Protocol as an inspiration. Language servers replaced a separate integration for every editor-language pair with one interface on each side; MCP applies the same idea to AI applications and integrations. The current spec is dated July 28, 2026, the fifth dated protocol revision since the project launched in November 2024. That pace reflects active governance and warns implementers to expect movement.
Adoption has spread across competing hosts. The MCP maintainers’ December 2025 announcement cited more than 97 million monthly SDK downloads, over 10,000 active servers, and first-class client support across ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and Visual Studio Code. Any individual count can be debated. Cross-vendor implementation is harder to dismiss, because a shared interface becomes infrastructure when rivals support it independently.
MCP covers the boundary between an application and its tools. The Agent2Agent protocol (A2A) addresses the next boundary: agents discovering and communicating with one another across vendors. It reached v1.0 in April 2026 with more than 150 supporting organizations, signed Agent Cards for verifiable identity, SDKs in five languages, and general availability in Microsoft Copilot Studio, Azure AI Foundry, and Amazon Bedrock AgentCore. A2A is younger and less proven in production than MCP, but its governance and adoption are moving agent-to-agent communication beyond the confines of a single platform.
The emerging stack extends beyond those two protocols. AGENTS.md, OpenAI’s convention for giving coding agents repository-level instructions, joined MCP as a founding project of the Agentic AI Foundation. The OpenTelemetry generative AI semantic conventions are developing a shared vocabulary for traces and metrics from model and tool calls, though that work has yet to reach stable status. Connection, cooperation, instruction, and telemetry are beginning to acquire common interfaces.
For an engineering organization, the immediate consequence is reuse. An MCP server for an internal ticketing system can serve every compatible IDE, chat application, and agent. Models and hosts will keep changing; the interface contract, server implementation, schemas, and authorization wiring can endure. The integration becomes an asset shared across applications. Language servers followed the same path as editors came and went around them. Agent integrations deserve the same treatment as libraries and services, with owners, versions, tests, and upgrade policies.
Reuse also concentrates attention on a common security boundary. Custom integrations tend to receive separate reviews, when they receive them at all. A shared protocol creates a recognizable seam where teams can specify identity, permissions, data flow, and audit behavior, then apply those controls across many tools and hosts. The MCP authorization specification builds that seam from established IETF work, including OAuth 2.1, protected resource metadata, authorization server metadata, and resource indicators. It requires Proof Key for Code Exchange (PKCE) to protect authorization codes from interception. MCP servers must also reject tokens issued for another audience and must not forward them downstream. The value comes from familiarity: Teams can draw on years of OAuth deployment experience instead of rediscovering its failure modes inside a new protocol.
The spec is equally useful when it states what metadata cannot prove. Tools can carry behavioral annotations describing them as read-only, destructive, idempotent, or open-world. Those terms give hosts a vocabulary for policy. The tools specification still requires clients to treat annotations as untrusted unless they come from a trusted server. Self-description can inform a security decision; it cannot establish the trust on which that decision rests.
Once servers share an interface, they also become discoverable. The MCP Registry is an open catalog and API for public servers, designed to feed downstream marketplaces and private catalogs. Its role resembles npm or PyPI as a discovery mechanism, with an important difference: It stores standardized server metadata and leaves package distribution elsewhere. The registry remains in preview, with possible breaking changes and no durability guarantee.
Discovery brings familiar supply-chain risks to components with unusually powerful access. Typosquatting, abandoned packages, malicious updates, and uncertain provenance now concern software that may hold live credentials and act on production systems. The registry provides namespace verification and moderation, and its downstream model allows organizations to build curated catalogs. An internal subregistry or allowlist is therefore a sensible first control. The standard interface makes that curation practical across multiple hosts.
The same contract improves testing. MCP tools declare a JSON Schema for their inputs and may declare one for structured outputs. Under the current tools specification, servers that declare an output schema must return conforming structured results, and clients should validate them. Teams can test a server without putting a model in the loop, mock it with recorded or synthetic behavior, and contract-test both sides as they would a REST or gRPC boundary.
This separates two kinds of uncertainty that agent evaluations often mix together. Protocol tests can determine whether an integration exchanged valid messages and enforced its contract. Model evaluation can focus on whether the agent chose the right tool and interpreted the result well. OpenTelemetry’s emerging conventions extend this approach to runtime evidence by giving systems a common language for tool calls. Teams will still have to absorb changes as those conventions mature.
These benefits stop at the edge of what the interfaces describe. A schema captures the shape of a tool’s arguments, while its meaning still lives largely in a free-form description that a model must interpret. A schema cannot tell an agent when a tool is appropriate, how its effects interact with other tools, or whether two similarly named operations have equivalent semantics. Portability makes a server available across hosts; behavior can still vary across models and contexts.
The semantic gap leads to a trust gap. MCP can carry a server’s claims, and an A2A Agent Card can carry a digital signature, but a signature only ties a statement to an identity. Engineering organizations still need a basis for deciding which identities, publishers, code, and claims deserve authority. The protocol can carry that decision through a system. It does not make the decision for the organization.
Delegation makes the problem harder. MCP’s authorization model handles a client calling a server with an audience-bound token. Production systems increasingly involve an agent calling another agent, which calls a tool or a third agent. Preventing token passthrough closes a serious hole, yet each downstream hop still needs a narrower grant derived from the user’s original authority. No common mechanism defines how those rights should attenuate across an arbitrary chain. Platforms currently solve this locally or leave too much authority in place.
All of this work is unfolding on young infrastructure. The registry is in preview, the telemetry conventions are unstable, and MCP has produced five dated protocol revisions in less than two years. Revision is how standards mature, so teams should version-pin, keep protocol code behind thin internal adapters, and budget for migrations. Some abstractions will prove wrong because the standards and the underlying practice are developing at the same time.
A sensible response begins with ownership and containment. Each internal server needs a durable owner, and its protocol surface should be treated as an architecture decision. Schema validation, conformance tests, and protocol mocks put that seam under contract. Third-party servers belong behind an allowlist or private catalog, with provenance requirements and corroboration for their annotations. An internal abstraction around the emerging telemetry vocabulary can limit exposure to draft revisions.
Organizations with a large stake in agents should also participate in the standards work. The Agentic AI Foundation and the A2A project are young enough that engineering teams outside the founding companies can still influence what becomes portable, observable, and enforceable. The rules written now will become assumptions embedded in future products.
Model improvements will continue to generate the headlines. Standards determine whether those models can participate in an ecosystem. Ethernet mattered because it became an interface that many implementers could agree on, and language servers mattered because editors and language tools no longer needed to be designed in pairs. Agent systems now have their first interfaces that competitors jointly govern and independently implement. Engineering teams should build on them with two expectations: The interfaces are likely to last, and their current forms will change.
| Feed | RSS | Last fetched | Next fetched after |
|---|---|---|---|
| @ASmartBear | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| a bag of four grapes | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| Ansible | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| Bad Science | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| Black Doggerel | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| Blog - Official site of Stephen Fry | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| Charlie Brooker | The Guardian | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| Charlie's Diary | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| Chasing the Sunset - Comics Only | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| Coding Horror | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| Comics Archive - Spinnyverse | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| Cory Doctorow's craphound.com | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| Cory Doctorow, Author at Boing Boing | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| Ctrl+Alt+Del Comic | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| Cyberunions | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| David Mitchell | The Guardian | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| Deeplinks | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| Diesel Sweeties webcomic by rstevens | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| Dilbert | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| Dork Tower | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| Economics from the Top Down | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| Edmund Finney's Quest to Find the Meaning of Life | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| EFF Action Center | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| Enspiral Tales - Medium | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| Events | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| Falkvinge on Liberty | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| Flipside | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| Flipside | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| Free software jobs | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| Full Frontal Nerdity by Aaron Williams | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| General Protection Fault: Comic Updates | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| George Monbiot | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| Girl Genius | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| Groklaw | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| Grrl Power | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| Hackney Anarchist Group | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| Hackney Solidarity Network | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| http://blog.llvm.org/feeds/posts/default | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| http://calendar.google.com/calendar/feeds/q7s5o02sj8hcam52hutbcofoo4%40group.calendar.google.com/public/basic | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| http://dynamic.boingboing.net/cgi-bin/mt/mt-cp.cgi?__mode=feed&_type=posts&blog_id=1&id=1 | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| http://eng.anarchoblogs.org/feed/atom/ | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| http://feed43.com/3874015735218037.xml | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| http://flatearthnews.net/flatearthnews.net/blogfeed | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| http://fulltextrssfeed.com/ | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| http://london.indymedia.org/articles.rss | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| http://pipes.yahoo.com/pipes/pipe.run?_id=ad0530218c055aa302f7e0e84d5d6515&_render=rss | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| http://planet.gridpp.ac.uk/atom.xml | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| http://shirky.com/weblog/feed/atom/ | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| http://thecommune.co.uk/feed/ | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| http://theness.com/roguesgallery/feed/ | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| http://www.airshipentertainment.com/buck/buckcomic/buck.rss | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| http://www.airshipentertainment.com/growf/growfcomic/growf.rss | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| http://www.airshipentertainment.com/myth/mythcomic/myth.rss | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| http://www.feedsapi.com/makefulltextfeed.php?url=http%3A%2F%2Fwww.somethingpositive.net%2Fsp.xml&what=auto&key=&max=7&links=preserve&exc=&privacy=I+accept | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| http://www.godhatesastronauts.com/feed/ | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| http://www.tinycat.co.uk/feed/ | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| https://anarchism.pageabode.com/blogs/anarcho/feed/ | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| https://broodhollow.krisstraub.comfeed/ | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| https://debian-administration.org/atom.xml | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| https://elitetheatre.org/ | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| https://feeds.feedburner.com/Starslip | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| https://feeds2.feedburner.com/GeekEtiquette?format=xml | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| https://hackbloc.org/rss.xml | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| https://kajafoglio.livejournal.com/data/atom/ | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| https://philfoglio.livejournal.com/data/atom/ | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| https://pixietrixcomix.com/eerie-cutiescomic.rss | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| https://pixietrixcomix.com/menage-a-3/comic.rss | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| https://propertyistheft.wordpress.com/feed/ | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| https://requiem.seraph-inn.com/updates.rss | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| https://studiofoglio.livejournal.com/data/atom/ | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| https://thecommandline.net/feed/ | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| https://torrentfreak.com/subscriptions/ | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| https://web.randi.org/?format=feed&type=rss | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| https://www.baen.com/baenebooks | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| https://www.dcscience.net/feed/medium.co | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| https://www.DropCatch.com/domain/steampunkmagazine.com | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| https://www.DropCatch.com/domain/ubuntuweblogs.org | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| https://www.DropCatch.com/redirect/?domain=DyingAlone.net | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| https://www.freedompress.org.uk:443/news/feed/ | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| https://www.goblinscomic.com/category/comics/feed/ | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| https://www.loomio.com/blog/feed/ | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| https://www.newstatesman.com/feeds/blogs/laurie-penny.rss | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| https://www.patreon.com/graveyardgreg/posts/comic.rss | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| https://www.rightmove.co.uk/rss/property-for-sale/find.html?locationIdentifier=REGION^876&maxPrice=240000&minBedrooms=2&displayPropertyType=houses&oldDisplayPropertyType=houses&primaryDisplayPropertyType=houses&oldPrimaryDisplayPropertyType=houses&numberOfPropertiesPerPage=24 | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| https://x.com/statuses/user_timeline/22724360.rss | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| Humble Bundle Blog | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| I, Cringely | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| Irregular Webcomic! | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| Joel on Software | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| Judith Proctor's Journal | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| Krebs on Security | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| Lambda the Ultimate - Programming Languages Weblog | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| Looking For Group | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| LWN.net | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| Mimi and Eunice | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| Neil Gaiman's Journal | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| Nina Paley | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| O Abnormal – Scifi/Fantasy Artist | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| Oglaf! -- Comics. Often dirty. | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| Oh Joy Sex Toy | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| Order of the Stick | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| Original Fiction Archives - Reactor | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| OSnews | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| Paul Graham: Unofficial RSS Feed | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| Penny Arcade | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| Penny Red | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| PHD Comics | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| Phil's blog | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| Planet Debian | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| Planet GNU | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| Planet Lisp | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| Pluralistic: Daily links from Cory Doctorow | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| PS238 by Aaron Williams | XML | 08:35, Thursday, 17 September | 09:23, Thursday, 17 September |
| QC RSS v2 | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| Radar | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| RevK®'s ramblings | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| Richard Stallman's Political Notes | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| Scenes From A Multiverse | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| Schneier on Security | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| SCHNEWS.ORG.UK | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| Scripting News | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| Seth's Blog | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| Skin Horse | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| Tales From the Riverbank | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| The Adventures of Dr. McNinja | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| The Bumpycat sat on the mat | XML | 08:49, Thursday, 17 September | 09:29, Thursday, 17 September |
| The Daily WTF | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| The Monochrome Mob | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| The Non-Adventures of Wonderella | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| The Old New Thing | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| The Open Source Grid Engine Blog | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| The Stranger | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| towerhamletsalarm | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| Twokinds | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| UK Indymedia Features | XML | 08:28, Thursday, 17 September | 09:10, Thursday, 17 September |
| Uploads from ne11y | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| Uploads from piasladic | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |
| Use Sword on Monster | XML | 08:35, Thursday, 17 September | 09:22, Thursday, 17 September |
| Wayward Sons: Legends - Sci-Fi Full Page Webcomic - Updates Daily | XML | 08:42, Thursday, 17 September | 09:28, Thursday, 17 September |
| what if? | XML | 08:49, Thursday, 17 September | 09:30, Thursday, 17 September |
| Whatever | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| Whitechapel Anarchist Group | XML | 08:35, Thursday, 17 September | 09:24, Thursday, 17 September |
| WIL WHEATON dot NET | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| wish | XML | 08:14, Thursday, 17 September | 08:59, Thursday, 17 September |
| Writing the Bright Fantastic | XML | 08:14, Thursday, 17 September | 08:58, Thursday, 17 September |
| xkcd.com | XML | 08:14, Thursday, 17 September | 08:57, Thursday, 17 September |