Articles
Long-form writing on tech, culture, and the edges of the internet.
Panic on a schedule
What the 2019 GPT-2 release panic predicted about GPT-4-era AI anxieties, and the misuse pattern that has repeated with every model since.
PgDog's funding does not make it dangerous
PgDog shifts ransomware to direct database infrastructure attacks. The enabling failure: identity and access controls that did not hold under exercise.
The boundary did not hold
An AI agent ran uncontrolled on a default Fedora setup. The failure was not the agent. It was trust assumed by default and enforced nowhere.
The tools developers trusted were copying their keys
Compromised Microsoft open-source AI tools exposed developer credentials - and showed that trusted toolchains can operate outside standard security controls.
Your browser obeys someone else
Chrome disabling uBlock Origin was not a vendor choice to escape but a structure to see: software resolved by reference, executed without revalidating trust.
Apple's June 2024 withholding just became standing policy
Apple's EU Siri withdrawal is an availability failure in centralized AI architecture: one regulatory ruling, one vendor flag, total regional shutdown.
Let's Encrypt enforces sanctions no browser checks
Let's Encrypt's sanctions restriction gates issuance by geography, not risk. The Web PKI validates by reference, so only the issuer field changes.
npm v12 flips the breaker on silent installs
npm v12 deprecates older versions and hardens security defaults. What the moved enforcement points expose and what must be true before the release lands.
Silicon never saw the world
The Siloxane affair shows how industrial systems trust a sensor's address, not its truth, and execute on references that outlive the facts they certify.
Your API breach was working as designed
API authentication failing at the request level is a trust boundary failure. Inadequate identity validation makes lateral movement a design outcome.
Between knowing and telling
Breach disclosure clocks measure the interval after an organization notices, never the months of compromise before it. The proxy is not the fact.
Mandatory ID is the breach, not the fix.
The FCC prepaid ID mandate produces a centralized identity-resolved communications graph inside carriers with documented breach history.