RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

CISA pushed passwords to a public repo
credential exposuregithub security

CISA pushed passwords to a public repo

A top cyberdefense agency published credentials in a public GitHub repository. A control analysis of what failed and what must now be true.

7 min read
Cloudflare's CISO spent two weeks breaking Mythos
AI securityLLM agents

Cloudflare's CISO spent two weeks breaking Mythos

Cloudflare's CISO red-teamed Anthropic's Mythos LLM. The findings on harness design, memory persistence, and tool allowlists matter more than the model itself.

6 min read
Discord's E2EE doesn't make your calls private
discordend-to-end encryption

Discord's E2EE doesn't make your calls private

Discord rolled out E2EE on voice and video calls. What the control covers, what it does not, and where attackers will redirect effort.

7 min read
Entra ID trades your credential for a token
cloud securityidentity and access

Entra ID trades your credential for a token

Microsoft Entra ID resolves trust at sign-in and honors bearer tokens on reference, not verification, which is how one compromised login becomes a cloud breach.

9 min read
Forge guardrails took an 8B model from 53% to 99%
AI safetyguardrails

Forge guardrails took an 8B model from 53% to 99%

A Show HN post says Forge guardrails took an 8B model from 53% to 99% on agentic tasks. Here's what that means for security and reliability.

7 min read
GitHub breached. Scope unknown.
github breachplatform security

GitHub breached. Scope unknown.

GitHub disclosed an internal data breach with no mechanism stated. Operator analysis of confirmed facts, structural exposure, and required tenant action.

6 min read
How GCC 4.3 deleted a NULL check in 2009
C programmingundefined behavior

How GCC 4.3 deleted a NULL check in 2009

How undefined behavior in C lets compilers delete safety checks, why it drives most memory-safety CVEs, and what it means for AI-generated code.

7 min read
March 2019 changed who reads binaries
reverse engineeringAI safety

March 2019 changed who reads binaries

Free disassemblers and decompilers changed who can audit binaries. The defender, attacker, and AI safety implications are now playing out in practice.

6 min read
Microsoft issued a login code no one requested
identity riskphishing

Microsoft issued a login code no one requested

A single-use Microsoft code arriving unrequested is evidence an identity boundary acted without its owner - a control that must be verified, not trusted.

9 min read
SMS 2FA was never authentication
passkeysauthentication

SMS 2FA was never authentication

Microsoft is replacing SMS one-time codes with passkeys. M. Hale defines what failed, why it failed, and where the boundary still leaks.

7 min read
The 2021 bucket that sat open for nine years
cybersecuritydata exposure

The 2021 bucket that sat open for nine years

Abandoned files, forgotten buckets, and stale subdomains are the cheapest way attackers get in. Here is how to find yours before they do.

6 min read
The breach isn't the leak. It's the leaker.
board governancecredential exposure

The breach isn't the leak. It's the leaker.

A board-level reading of a U.S. cybersecurity agency credential exposure on GitHub, framed as runtime control failure and institutional risk.

9 min read