RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Your three memory vendors are one vendor
supply chain securitythird-party risk

Your three memory vendors are one vendor

A US lawsuit alleging memory price fixing by Samsung, SK Hynix, and Micron exposes an unverified control: supplier independence assumed, never validated.

7 min read
1.3 million IPs hit LWN in two hours
scraper attacklayer 7 ddos

1.3 million IPs hit LWN in two hours

LWN.net is absorbing a 1.3-million-IP Layer 7 scraper flood. Why per-IP defenses fail, what web telemetry shows, and what shifts the cost back to the client.

6 min read
A meditation app shipped a switch statement as AI
LLM engineeringAI architecture

A meditation app shipped a switch statement as AI

Whether a product 'really uses AI' is unanswerable and beside the point. What predicts reliability is system design: validated inputs, constrained outputs, fallbacks.

10 min read
Access is the breach
EU chat controlencryption backdoor

Access is the breach

The EU chat control mandate concentrates standing access to private messaging into a single point of compromise that no implementation quality can fix.

7 min read
Age verification does not verify age
KIDS Actage verification

Age verification does not verify age

The KIDS Act conditions access on collecting identity artifacts, converting every covered service into a standing target the control itself does not protect.

9 min read
An hour-old account drops forty working exploits
vulnerability responsesystems architecture

An hour-old account drops forty working exploits

A coordinated dump of forty anonymous 0-days breaks your triage queue, not your servers. Engineer response throughput and pre-authorized action before the burst.

10 min read
I reverse-engineered a 2002 GameCube before doing it legally
reverse engineeringbinary analysis

I reverse-engineered a 2002 GameCube before doing it legally

Decomp Academy turns matching decompilation into a teachable, verifiable skill, which exposes why compiled opacity was never a real security control.

8 min read
Mirai's hardcoded logins still answer on 554
IoT securitysupply chain

Mirai's hardcoded logins still answer on 554

Open webcams indexed by Shodan and Censys are not a privacy footnote - they map insecure OEM firmware, exposed services, and supply chain risk.

6 min read
Mythos AI cleared for distribution, no validation report
ai-securityjailbreak

Mythos AI cleared for distribution, no validation report

REDLINE breaks down the security risk in releasing Mythos AI to trusted US organizations: not the model, the missing adversarial validation and zero prompt-level telemetry.

7 min read
Springer Nature unpinned two papers, no log
supply chain securitydata integrity

Springer Nature unpinned two papers, no log

Springer Nature removed two Max Planck studies. The real exposure is a research supply chain with no integrity log - the same trust gap as CI/CD poisoning.

7 min read
The breach was the network working as intended
lateral movementidentity security

The breach was the network working as intended

The 2015 Polish S incident: lateral movement from inherited permissions and automated escalation, where access was granted by position not verified at use.

8 min read
The camera on the pole has a login screen
credential stuffingidentity controls

The camera on the pole has a login screen

Flock cameras are credentialed endpoints inside a trust boundary. The exposure is not surveillance. It is credential stuffing against a standardized fleet.

7 min read