Articles
Long-form writing on tech, culture, and the edges of the internet.
The bypass is a feature
Persistent authentication stores a completed verification as a token, then acts on the token forever. Reference replaces validation, and the person goes unchecked.
TOTP fixes the channel, not the credential
TOTP kills SMS interception and SIM-swap OTP theft, but AiTM phishing still steals the session token. What TOTP secures and what it doesn't.
Your decisioning problem isn't accuracy.
Run open-source decision models locally-pinned versions, validation, immutable logs-so every approval or denial stays reproducible and auditable.
A 1938 law now points at AI critics
How labeling AI critics as 'foreign agents' under FARA-style rules chills safety research, disclosure, and open discourse - and what researchers can do.
Installed from Play Store' is not a safety badge
F-Droid 2.0 is a viable Google Play alternative only where its open, reproducible trust boundary is inspected and enforced in practice, not just stated.
On 18 June, no hack - broken access control
Red-team breakdown of the OpenAI agent that reached Australian government Medicare files: broken access control, not a hack, mapped to MITRE ATT&CK.
Snapdragon X2's September 2025 debut bets on mainline Linux
Linux support on Qualcomm's Snapdragon X2 improves auditability but moves AI safety controls onto hardware the device owner fully controls - here's the security tradeoff.
The connection runs code before you touch anything
How VSCode Remote-SSH agent forwarding exposes a signing oracle to the remote host, the CVE-2022-41034 cross-machine RCE, and where the pivot shows up in telemetry.
A managed endpoint no longer bounds insider exposure.
Apple Intelligence on Mac acts within existing user access with no confirmed runtime monitoring, creating an insider exposure the board must constrain now.
A red badge you never earned
Apple's persistent iOS ads and promotional prompts don't just annoy users - they erode the trust signal that protects you from Apple ID phishing.
Claude optimizes what it measures
Claude only makes faster what you let it measure. Build the measure-change-verify loop, carry guardrail metrics, and verify every change against a baseline.
Respond before you confirm
A claimed breach of FBI employee data shows why identity and access boundaries must function at runtime for any organisation holding sensitive data.