RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Cypherpunk frees the key schedule twice
use-after-freecryptographic-libraries

Cypherpunk frees the key schedule twice

UAF in the Cypherpunk Library's context teardown - CWE-416, heap reuse, sandbox-free RCE path, and why EDR misses the corruption stage.

6 min read
Massachusetts bans precise geolocation sales
privacy legislationlocation data

Massachusetts bans precise geolocation sales

Massachusetts banned the sale of precise location data. The statute kills a commercial attack vector and creates real telemetry gaps for defenders.

6 min read
Motorola bricked your routers
vendor riskthird-party governance

Motorola bricked your routers

A board-level read on the Motorola router event: vendor authority over fielded equipment is a primary risk vector, and silence is the visible control failure.

9 min read
NovaMind reframes breach disclosure as system design
incident responsebreach disclosure

NovaMind reframes breach disclosure as system design

After a thousand breaches, the gap between compromise and disclosure is widening. The fix is treating disclosure as a pipeline, not a crisis.

9 min read
Pentagon raises Israel espionage threat to highest level
board governancecounterintelligence risk

Pentagon raises Israel espionage threat to highest level

The Pentagon's elevated Israeli espionage threat exposes how access controls built on allied trust drift silently from current risk posture.

7 min read
Texas data centers failed the voltage test
identity-boundaryaccess-control

Texas data centers failed the voltage test

Texas grid voltage failures at data center and crypto sites expose the same admission-without-enforcement gap every identity boundary already has.

7 min read
The integration is the attack surface
supply-chain-securityMITRE-ATTCK

The integration is the attack surface

Pentagon raised Israeli collection risk to top tier. The technical exposure is supply chain privilege inherited from vendor software, not espionage.

7 min read
Your AI features are now your attack surface
AI governanceidentity and access management

Your AI features are now your attack surface

Meta has confirmed over 1,000 Instagram accounts were compromised through abuse of its AI chatbot - a board-level view of the control failure.

9 min read
Your living room TV is harvesting credentials
smart-tv-securitycredential-harvesting

Your living room TV is harvesting credentials

Smart TVs are operating as nodes in the AIScrap credential harvesting operation. Permissive defaults permit it. Unpatched firmware does not remediate it.

6 min read
Claude Code deleted our deploy pipeline
claude-codeagentic-engineering

Claude Code deleted our deploy pipeline

Why semantic code understanding for Claude Code agents needs an entity index on top of git, not an LSP. Receipts from 90 days of production edits.

6 min read
CVE-2023-2163 is now a config file away
eBPFkernel-security

CVE-2023-2163 is now a config file away

Zeroserve exposes eBPF program loading through an HTTP scripting surface. The kernel verifier becomes the trust boundary for every web request.

6 min read
IOCCC 2025 ships glibc tcache poisoning primitives
IOCCC 2025memory corruption

IOCCC 2025 ships glibc tcache poisoning primitives

The 29th IOCCC's 2025 winners distill heap metadata corruption, tcache poisoning, and type confusion into legal C - the same primitives behind modern CVEs.

6 min read