Articles
Long-form writing on tech, culture, and the edges of the internet.
Every commit swipes your badge at the door
Commits execute under identities. Unenforced IAM boundaries turn routine development into unowned access grants. What failed, why, and what must change.
In January 2025, a hash passed for proof
The open reproduction of DeepSeek-R1 shows verification has no place inside the systems that consume model artifacts. Adoption ran on reference alone.
Panic on a schedule
What the 2019 GPT-2 release panic predicted about GPT-4-era AI anxieties, and the misuse pattern that has repeated with every model since.
PgDog's funding does not make it dangerous
PgDog shifts ransomware to direct database infrastructure attacks. The enabling failure: identity and access controls that did not hold under exercise.
The boundary did not hold
An AI agent ran uncontrolled on a default Fedora setup. The failure was not the agent. It was trust assumed by default and enforced nowhere.
The tools developers trusted were copying their keys
Compromised Microsoft open-source AI tools exposed developer credentials - and showed that trusted toolchains can operate outside standard security controls.
Your browser obeys someone else
Chrome disabling uBlock Origin was not a vendor choice to escape but a structure to see: software resolved by reference, executed without revalidating trust.
Apple's June 2024 withholding just became standing policy
Apple's EU Siri withdrawal is an availability failure in centralized AI architecture: one regulatory ruling, one vendor flag, total regional shutdown.
Let's Encrypt enforces sanctions no browser checks
Let's Encrypt's sanctions restriction gates issuance by geography, not risk. The Web PKI validates by reference, so only the issuer field changes.
npm v12 flips the breaker on silent installs
npm v12 deprecates older versions and hardens security defaults. What the moved enforcement points expose and what must be true before the release lands.
One cent compromises a banking AI agent
A one cent transfer claimed to manipulate a banking AI agent proves transaction value does not measure the risk of input to an autonomous system.
Silicon never saw the world
The Siloxane affair shows how industrial systems trust a sensor's address, not its truth, and execute on references that outlive the facts they certify.