RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

A helpful AI agent cannot be a private one
cybersecurityAI safety

A helpful AI agent cannot be a private one

Meta's Muse personal AI agent is only useful because it reads your messages, contacts, and habits. What that access costs your privacy and safety.

7 min read
iPhone Duo is not a convenience feature
iPhone Duomulti-device authentication

iPhone Duo is not a convenience feature

iPhone Duo's shared access and multi-device authentication expand who can authenticate and access, collapsing resource security to the weakest device and party.

7 min read
Open problems are running out
AI safetycryptography

Open problems are running out

Terence Tao calls open math problems a non-renewable resource. Why AI mining them threatens encryption, AI safety benchmarks, and how to respond.

6 min read
Ranking is not vetting
malvertisinggoogle ads

Ranking is not vetting

Attackers buy top Google Ads placement and use cloaking to deliver trojanized installers; ad review validates the submission, not the file you download.

7 min read
Resignations are signals, not scandals
AI safetyAnthropic

Resignations are signals, not scandals

How to read a high-profile resignation from an AI safety lab like Anthropic - what it signals, what to ignore, and what to watch in the months after.

7 min read
Four bits, then a cliff
LLM quantizationproduction LLM serving

Four bits, then a cliff

How to choose LLM quantization for production: why 4-bit is the default, where 1-bit collapses, and why your own eval set is the real deployment gate.

9 min read
I factored a root CA
rsa-factoringcertificate-authority

I factored a root CA

Factoring a 1990s Certificate Authority's public key recovered its private signing key, showing that confidentiality resting on computational cost is not a control.

7 min read
LG Smart TVs branded surveillance risk
smart device securityattack surface

LG Smart TVs branded surveillance risk

A public claim about LG smart TVs is a signal about a device class: connected endpoints inside the enterprise that no one owns, monitors, or governs.

7 min read
LG TVs recorded audio and mapped your network
smart tv privacyiot security

LG TVs recorded audio and mapped your network

LG smart TVs captured audio with the screen off and scanned local devices. The control users operate governs the display, not the microphone.

7 min read
The backdoor lives in the compiler, not the source
trusting trust attacksupply chain security

The backdoor lives in the compiler, not the source

A Thompson-style compiler backdoor passes source audits, signatures, and reproducible builds because the validators are built by the same toolchain.

9 min read
You can't reset your genome
AI safetygenomic data

You can't reset your genome

AlphaGenome Atlas makes genomic prediction cheap and fast, but a genome can't be rotated like a password - reshaping AI safety and data ethics.

7 min read
Chrome wipes everything but Google
chrome-privacycookie-security

Chrome wipes everything but Google

Chrome again retains google.com data through a user-set clear-on-exit wipe. Analysis of the exemption, X-Client-Data, and cookie-theft exposure.

7 min read