There's no such thing as Just a Tool

Lobsters
deadsimpletech.com
2026-08-29 23:59:05
Comments...
Original Article

Apologies for my recent hiatus in publishing articles: the household has been, once again, struck down by a spectacular range of health issues, and while I will allow that there are significant advantages to having been hit by this after the launch of Arca rather than before it, it's still unpleasant. I'm hopeful that more regular writing will resume soon.

If you work or write in the social criticism of tech, you hear a wide range of views and opinions about tech, some of them startlingly hostile to the very idea that you might be doing what you're doing. Consequently, you very often find yourself experiencing a wide range of different criticism of your work, your ideas and your viewpoints, some of them extremely valid, others... less so.

A common refrain when critiquing specific technologies in this way is that engineers will say that a given technology is "just a tool". You hear it when talking about all kinds of things: shells, containerisation, reactive frameworks and most recently it comes up a lot in discussions of LLM technology. What this response seems to mean is the following:

  • The technology being discussed has no bearing on the attitudes or ideologies of the person holding it: use or non-use is ideologically neutral.
  • The technology being discussed can be effectively separated from the people using it: nothing can be inferred about a person from the technologies that they use.
  • The technology is used fully consciously: you are always fully aware that you are using a technology and have complete volitional freedom to use a different technology at any time.
  • The technology does not influence the kinds of things likely to be done with it: use of the technology doesn't tend to encourage one course of action over another ("guns don't kill people, people do").

The consequence of these statements being true is that the only valid criticism of a tool or technology becomes how well it performs the task that it's designed to perform. You cannot, for example, say that a tool teaches bad habits, because if it isn't explicitly a teaching tool what it teaches people becomes out-of-bounds for discussion. Similarly, you cannot discuss the fact that driving an SUV tends to encourage shitty driving behaviour on the road because, after all, the SUV is "just a tool" and there are some legitimate use cases for it: because this is the case, the fact that the SUV has ideological and behavioural consequences is something that we're not really allowed to discuss. This kind of folk understanding of tools is very common, but unfortunately it's almost all wrong.

To explain why saying that something's "just a tool" is an illegitimate move, we shall have to rely on the work of notable Nazi (and unfortunately also very important 20th century philosopher) Martin Heidegger. While Heidegger's major work, Being and Time mostly discusses ontology and human being as being being-towards-death, a significant part of Heidegger's work there and elsewhere has to do with the nature and being of tools.

Heidegger thinks about tools like so: a tool is something (a thing that has being in the Heideggerian sense, not necessarily an object) that represents an extension of human capabilities in some way. A tool is thus any kind of thing that lets you do something you wouldn't otherwise have been able to . The important (for us) conceptual leap here is that when a tool works well, or isn't broken, it develops what Heidegger describes as a "ready-to-hand" quality: the tool fades into the background as a kind of human-tool gestalt of a human with the additional capability afforded by a tool forms. As a simple example of this, consider eating with a fork. When the fork is well-designed and not broken, you don't explicitly have "I am using a fork" in your conscious mind while eating dinner . You simply eat, and the assumptions encoded into how you eat with a fork and what you might eat with a fork fade into the background and are taken as a given. You only explicitly notice the fork when it doesn't work: perhaps a tine is bent, or maybe you're trying to eat soup. Either way, the tool only becomes, in Heidegger's wording, present-at-hand when it becomes obtrusive, or an obstacle to doing what you want to do.

The human-tool gestalt that forms with a ready-to-hand tool, however, is not neutral. Rather, the tools that are ready-to-hand each create a different gestalt, with a different range of allowable and potential "things you could do" and, accordingly, different thought patterns, ideas and ideologies that go with that. Take the fork, for example: it is, notionally, "just a tool" and should thus be neutral. Except that it really, really isn't. If you need an example of this, go find some older or more culturally sheltered people from an Anglo-Saxon background (if these are difficult to find where you live, substitute people from a different food culture where you do) and take them to a Sichuan restaurant.

Put that way, the point is fairly clear: the affordances that eating with knife and fork allow are pretty radically different from the affordances that you have when eating with chopsticks. As a first point, the assumptions encoded about how food is prepared are completely different: you cannot feed diners eating with chopsticks a steak in the European fashion, and food in general has to be carefully cut so that it can be easily grasped with chopsticks. This follows on to what kinds of dishes get prepared, as in the situation where a lot of Sichuan food has an unfair reputation for being unreasonably... well, just take a look at this photo of some delicious Chongqing Laziji:

For a human-fork gestalt, this is a prohibitive amount of chilli. Even if you have the heat tolerance to enjoy all of that, the chilli in such a presentation remains dry and somewhat unpleasant to eat. This is not a dish, in short, that a human-fork gestalt would make. A human-chopstick gestalt, however, can rummage through the chilli with their chopsticks, pick out bits of chicken that are lightly spiced and made fragrant and just... avoid most of the chilli. In that case, our Chongqing Laziji becomes a legitimate and somewhat impressive presentation of what's actually a really good dish. In the extreme, such different affordances can go so far as to actually lead those gestalts to have different ideas about what they consider food at all.

As far as food is concerned, this mostly leads to interesting differences in culinary culture (though of course this is a fertile ground for racism and other such unpleasantness). With other tools, however... well, we have problems. The human-car gestalt, for example, experiences life and has opinions that are quite different from the human-bicycle gestalt, the human-train gestalt or even the bare human with no mode of transportation. What's possible and what's desirable for a driver is pretty radically different even to what's possible or desirable for the same human outside of a car: in individual instances of this happening, we call it road rage, and on a policy scale it leads to things like people getting extremely angry about bike lanes even when said bike lanes would benefit them at all times when they're not in their car . The human-car gestalt has interests and opinions that are separate from the human in the gestalt, often opposed to them and able to assert them over the human part of the gestalt.

And then, of course, there's the human-gun gestalt, or the "gun-man". Putting a gun in a person's hand radically changes how they see the world and the range of potential actions that they have available to them and that might seem good. You can see that, most dramatically, in policing in the USA. When you have a gun, you're predisposed, as part of the human-gun gestalt, to look for reasons to shoot . Situations that might ordinarily be resolvable without violence escalate into shootings because of the affordance that the gun offers. Intimidation and the demand to get your way take priority over negotiation and compromise, potential threats become foregrounded in the world and other people, imperceptibly and by degrees cease to be fellow humans and become potential subjects of violence on your part.

Clearly, then, nothing is ever "just a tool", unless, perhaps, it's a broken or obstructive one. This is enough to throw the way that the tech industry talks about all this into question by itself, but that wouldn't be very interesting, so in the next section we'll discuss how two outwardly very similar tools end up creating very different gestalts and very different potentials for action.

Be the first to know when a new article drops! Sign up to the newsletter too for exclusive updates on my thinking and news about deadSimpleTech and our projects.

Get new articles delivered to your inbox →

It is an unfortunate fact that, when faced with such an analysis of technology, tech people will often think that for whatever reason the considerations that apply to literally the entire rest of the world of technology somehow don't apply to them. This kind of overweening arrogance is, of course, why we find ourselves in so much of the shit that we're in, but nonetheless, to really get my point across it's probably a good idea to spell out how these dynamics operate in the tech world specifically.

For the purposes of this article, we'll look at Vue and React, two reactive frameworks commonly used to build web interfaces. These are ideal for our purposes: they aim to facilitate roughly the same task, but have enough differences in design choices and philosophy that it's possible to see how the differences in the tool create a different gestalt in the human space.

To demonstrate, let's have a look at how an identical component is built in React and Vue respectively (I've chosen a basic form that I found here ):

import React, { useState } from "react";
 
function NameForm() {
  const [value, setValue] = useState("");
  return (
    <form>
      <input
        value={value}
        onChange={(e) => setValue(e.target.value)}
        placeholder="Enter name"
      />
      <p>You entered: {value}</p>
    </form>
  );
}
<template>
  <form>
    <input v-model="value" placeholder="Enter name" />
    <p>You entered: {{ value }}</p>
  </form>
</template>

<script>
export default {
  data() {
    return {
      value: "",
    };
  },
};
</script>

These two components do exactly the same thing: create a form with an input and a paragraph tag below it that displays the value entered. The gestalts that the two frameworks create, though, is very different.

We can begin with looking at what kind of object each of the components is presented at. React presents us, immediately, with a function written in JSX: the component as we interact with it is a function. HTML, CSS and the like are returned by the function, and the expectation is that when writing React you think in JavaScript first and only really emit HTML as an output. This extends to the way binding works in React: it's presented explicitly as an imperative command to set the value of the template variable to the value of the form input whenever it changes, which is a very JavaScript way of thinking about it.

Vue, by contrast, presents us first with an HTML document: the component as presented is HTML with whatever JavaScript is needed included organically in a <script> tag. Binding in this component is declarative and two-way: we tell the value of the paragraph text what it is rather than what to do on a change . In general, you're expected to think mostly in terms of HTML, with the amount of JavaScript being written mostly being kept to a minimum.

These two ways of looking at things result, if you'd believe it, in two very different tool gestalts, even with exactly the same engineer working with them. This begins with the basic question of "who should be working with you on this project?" React almost demands the answer to be "other JavaScript software developers", because editing a React component requires you to know JavaScript for almost everything. This means that when building a React team, you're going to focus on people with development skills: someone expert at HTML and CSS but not great with writing code is going to be closed out by the gestalt. React, in fact, tends to de-emphasise the work of design or even writing CSS in general, pushing developers towards solutions like Tailwind.

Vue, by contrast, opens up more space for people with different skillsets: someone who knows HTML but no JavaScript or who's great with CSS can edit the two-thirds of a Vue component that they know about and not touch the <script> tag and thus contribute effectively without the demand to know JavaScript preventing that. This opens up the range of people you might want on your team: designers, accessibility experts, semantic HTML experts... there's a whole gamut of skills that a Vue-using team can make use of that a React-using team will simply lack. And importantly, while none of this is directly demanded by the tools as such (someone could hypothetically edit HTML blocks embedded in a React component if they were careful), the constraint emitted by the gestalt is much stronger than that emitted by the tool itself, and in fact creates an ideological belief about who should and who shouldn't be involved in the work of web development that's what does the real damage.

Looking beyond that element, React and Vue prioritise different things as being important in the development of the component. With HTML and CSS being first-class elements in Vue, the Vue gestalt encourages thinking about structure, layout and presentation: the app is thought of as an interactive document that does document things and can use JavaScript to manage that interactivity. React tends towards the opposite pattern, in that the app is something that does computation and uses HTML and CSS to present the results of the computation to the user. The gestalts, then, will develop attitudes and ideologies that support those positions, and importantly, those ideologies will then become, for better or worse, part of the ideology of tech more generally.

Neither of these approaches are inherently wrong or inherently better, but they clearly shape attitudes and worldviews quite drastically and in ways that are very much not neutral. If the expertise of people who can't produce JavaScript is not respected, that will have significant negative consequences on the usability and accessibility of the resultant app. Some people are going to be included, others excluded, and who is included and who is excluded is liable to include the people who already hold power in the social sphere in which these tools operate and exclude those whom these people consider, in one way or another, "lesser". And all this from a choice of tool.

Much of the tech industry, what it does and the attitudes and ideologies that it presents are shaped by precisely this kind of gestalt dynamic, I think. The tools we build, shaped by already-existing ideologies, proceed to reproduce those ideologies and attitudes within the gestalts that they create. In particular, the React/Vue split is one that we see reproduced by a lot of tech tools, and it's the ideology of developer supremacy. The idea, repeated across tools as far apart from each other as React, Kubernetes, Docker, an awful lot of Linux distributions in general and most cloud providers, is that the way a software developer would do things is the way they should be done , and that other approaches to the task are necessarily inferior. This means that when the choice between writing more HTML on one hand and more JavaScript on the other comes up, the choice will always lean more towards JavaScript, whether or not that's actually a good idiom for whatever you're trying to do (Tailwind CSS is quite directly an attempt to resolve issues that primarily stemmed from React and JSX not playing nicely with standard CSS). This tends to create tools that are easy for developers to half-ass, but that might be difficult for say, designers or UX specialists to work with. The sinister thing here is that this tends to reproduce itself: tools that are easier for devs to work with tend to subtly reinforce that, for example, writing HTML or CSS is low-status development work (in some circumstances they can be, but they're as much design tools as development tools). This then subtly pushes designers, UX specialists, accessibility and SEO experts and all those kinds of people into a subordinate position, because the tools are designed for developers to do the job badly so they kinda bounce off them . One imagines that tools written for these people would create a more useful gestalt and get better status for them and better outcomes overall, but existing practices (created by the tools) push against that hard enough that it takes real effort to change the situation, so most people don't. And thus the cycle reproduces itself.

Obviously, I think that given such circumstances, where even if tools didn't directly create any of the immense number of social and cultural problems present in tech, they're heavily involved in reproducing and justifying said problems by virtue of their ready-to-handedness being directly pointed at the reproduction of those problems, maybe saying that something's "just" a tool isn't the best idea.

All that being done, we can now return to our original question: what is so wrong about saying that something is "just a tool"? Considering how much of an impact tools can have on the gestalts that they become a part of, and thus the ideologies that the human parts of those gestalts hold, something might be a tool but as it happens, tools are actually really, really important . Given that we in tech are largely in the business of creating tools for both ourselves and for other people to do things, then, we ought to be very, very careful about what kinds of tools we build. We should build tools that tend to create gestalts that support individual flourishing and social harmony or, if those cannot be balanced, that carefully balance the need for both against each other and other considerations.

Our industry, rather contrary to that idea, has tended to create tools destructive to both of these things. We've built social media networks that isolate people from each other and have become vectors for the massive spread of disinformation. We've built cryptocurrencies that have enabled fraud and deception on an enormous scale. We've built classification algorithms that reinforce the worst kinds of bigotry. And of course, there are the fucking LLMs, that do all of these things and a whole lot of other evil shit besides.

LLMs are a particularly important case: we can quite directly see the use of the tool forming some very strange gestalts. In its most extreme case, we call this AI psychosis: the gestalt has attitudes, ideologies and even a perception of the world that diverges so much from what we consider reasonable that we label it an illness. Obviously it's hard to say when observing something like this that the tool has not, in fact, drastically shaped the person using it's attitudes, experiences and ways of being in the world. The phenomenon described in this article quite clearly happens , then, and if it can happen so drastically and obviously with this one tool, we would do well to expect to see more subtle and far-reaching consequences over a much wider range of technologies.

Now at this point people will point out many cases in which tools that are in some way "bad" have been used for things that are good and beneficial. Frameworks and languages that I'd consider harmful have been used to build tools that have done a lot of good. LLMs have been used, at this point, to build quite a few useful tools: hell, even I've had some success using them when I've tried. These are all valid arguments, but in the gestalt framing they don't actually refute the point: it's quite possible for a tool to be used for good things, and in fact for it to be necessary, but for the viewpoint that it fosters to nonetheless be one that we shouldn't encourage. After all, all kinds of fascinating weapons systems are being used in defence of freedom and democracy in Ukraine, and this is both good and necessary, but none of this makes the effects on leaders of having access to bombs and artillery, or on individual people of having access to firearms, not ceteris paribus deletrious. Carrying a gun or driving an SUV will, in general, make you more predisposed to being an asocial asshole who doesn't care much for human life, and while it's quite possible to fight this tendency and a lot of people do , the logic of the gestalt for these tools still pushes towards the bad.

This means that even when you, for example, use an LLM to build some useful software that helps your nonprofit do well, and even when you're very careful about what generated code ends up actually being deployed (even if you literally read every line of code), you're nonetheless fighting against the ready-to-hand nature of the tool that pushes your gestalt (and thus your attitudes and ideologies) towards carelessness and slop every step of the way. This isn't to say that this is never the correct call to make, or that you should never use the tool: as before, I am generally supportive of fighting back against an invading force even if I think that guns generally do bad things to your attitudes. But well... if you're going to be using a tool like that, it's incumbent on you to know what you're doing and be very careful about it. You need to be aware that extended use will change how you see the world and put protections in place to mitigate that (it's an interesting observation, by-the-by, that regular militaries tend to put quite a bit of effort into that kind of mitigation when it comes to firearms, while police forces often don't). You generally want to make that kind of compromise as infrequently as possible, and you only want to make them when the problem that you're facing is drastically bad enough that making that manner of compromise makes sense.

If we were simply using these tools (if, say, React and Vue were things we found in nature, unchanged by human hands), this might be an unfortunate fact about tools and about tech in general that we needed to be wary of. But we make these tools . When we develop any tooling in tech, we make decisions about what shape it's going to take, what kind of affordances it offers, what gestalts it forms. We not only have to choose what compromises we make, we as an industry largely dictate what compromises are available both to other people and to ourselves. And we have, on the whole, made rather bad ones, ones that are deeply detrimental to the world and ones that, in consequence, we're largely living with the consequences of today.

So, when I hear a tech person say that something's "just a tool", I can't help but read it as an unwillingness to take responsibility, as an industry, for what we put into the world and for what we do to ourselves. Tools, unfortunately, simply cannot be the neutral, separate thing that so much of the tech world would like them to be, and pretending otherwise, let alone telling people affected by the tools that they're simply using them wrong , is an abdication of our moral duty to avoid, inasmuch as is possible, doing harm. We really ought to do better.

You will notice a small advert beneath this article: Arca is, in some ways, my attempt to teach technology in ways that are mindful about tools and what they do to us. Have I succeeded yet? I don't know, but I certainly believe I've made significant progress towards it. Sign up and find out!

Algorithmic Rent-Pricing Litigation Expands Under New State and Local Laws

Hacker News
www.morganlewis.com
2026-08-29 22:25:32
Comments...
Original Article

A new wave of litigation focused on violations of municipal regulations is emerging against multifamily housing landlords, many of whom are facing antitrust litigation targeting their use of certain revenue management products. The new regulations may potentially provide a simpler path to liability and the possibility of significant penalties.

Following federal, state, and private litigation targeting RealPage, Yardi, and landlords that allegedly used revenue-management products, states and municipalities across the country have enacted laws restricting the use of algorithms or price optimization software to share or recommend rents, concessions, lease terms, or occupancy levels. These laws often authorize enforcement through a combination of private rights of action and public enforcement mechanisms, which has led to a new wave of litigation.

Recent county-level actions in San Francisco, San Diego, Seattle, Philadelphia, and Providence, RI suggest that plaintiffs and local governments are beginning to use these laws to assert follow-on claims to the RealPage litigation. This development is significant because some of the new statutes arguably provide a potentially simpler path to liability than traditional antitrust claims and authorize substantial statutory damages, fee shifting and, in some jurisdictions, recurring per-unit penalties.

RESIDENTIAL REAL ESTATE ALGORITHMIC LITIGATION GIVES RISE TO STATUTES AND ORDINANCES INSPIRING FOLLOW-ON CLAIMS

The new cases draw heavily on the factual record developed in the RealPage litigation, including allegations concerning the use of nonpublic competitor information and public admissions regarding particular landlords’ use of revenue-management products. A group of cases filed in July and August 2026 illustrates the emerging follow-on strategy:

  • A San Francisco tenant filed Gomez v. Greystar Management Services LLC in the Northern District of California, alleging that Greystar violated San Francisco Administrative Code § 37.10C through its alleged use of RealPage and Yardi products. The ordinance prohibits landlords from using qualifying algorithmic devices that calculate nonpublic competitor information to advise on rent or occupancy. Each month of use for each affected dwelling unit may constitute a separate violation, and tenants may seek damages, injunctive relief, and civil penalties of up to $1,000 per violation. S.F. Admin. Code § 37.10C(b) and (d).
  • A San Diego tenant filed Keller v. UDR Inc. in the Southern District of California under San Diego Municipal Code § 98.1103, alleging that UDR improperly used RealPage products. San Diego similarly authorizes tenant suits for damages, injunctive relief and penalties of up to $1,000 per violation, with each month and affected rental property potentially constituting a separate violation. San Diego Mun. Code §§ 98.1103(b) & 98.1104(a).
  • Seattle has now generated at least two similar cases. In Nicolas v. Essex Management Corp ., plaintiffs allege that Essex Management, Essex Property Trust, RealPage, and Yardi violated Seattle Municipal Code Chapter 7.34 by using prohibited “coordinating services” in connection with Seattle multifamily properties. And, in Romano v. UDR Inc. , plaintiffs assert a similar theory against UDR and RealPage. Seattle’s ordinance expressly prohibits specified algorithmic coordinating services and provides penalties of up to $7,500 per violation. Seattle Mun. Code ch. 7.34.040.
  • In Liu v. Willow Bridge Property Company LLC and RealPage Inc. , a class of Philadelphia tenants allege that Willow Bridge subscribed to and used RealPage services in violation of Philadelphia Code § 9-813. And, in Jahanbakhsh v. Greystar., a different Philadelphia tenant class alleges similar claims against Greystar. Philadelphia’s ordinance permits an aggrieved person to elect statutory damages of $2,000 per violation or treble actual damages, together with equitable relief, interest and attorney fees and costs. Phila. Code § 9-813(2)(c)(i).
  • In a public enforcement action, the City of Providence filed claims against Audubon Capital Partners, LLC in Providence Municipal Court under Providence Code § 13-70, alleging that Audubon used a dynamic pricing system to coordinate rental prices at 95 Lofts in violation of the city’s ban on algorithmic rent-setting devices. The ordinance authorizes the city solicitor to bring enforcement actions and provides for civil penalties of up to $500 per day per violation, as well as costs and attorney fees in a successful enforcement action. Providence Code §§ 13-71 & 13-72.

LOCAL REGULATION IS QUICKLY EXPANDING

Municipal regulation relating to the use of algorithmic pricing tools to set rental prices in multifamily housing has developed quickly, but not uniformly. Some regulations supplement existing antitrust law, while others create landlord-specific prohibitions and direct tenant remedies. Definitions of prohibited data and services also differ, as do the availability of private actions, statutory damages, and fee shifting.

Jurisdiction

Ordinance

Status/Principal Feature

San Francisco, CA

S.F. Admin. Code § 37.10C (effective October 2024)

Prohibits qualifying algorithmic devices using nonpublic competitor data; private tenant claims and up to $1,000 per violation, with unit/month exposure; now at issue in Gomez v. Greystar Management Services, LLC (N.D. Cal.)

San Diego, CA

San Diego Mun. Code §§ 98.1101–98.1104 (effective June 2025)

Similar prohibition and private remedy of up to $1,000 per violation; now at issue in Keller v. UDR Inc., (S.D. Cal.).

Berkeley, CA

Berkeley Mun. Code ch. 13.63 (effective January 2026)

Prohibits coordinated pricing algorithms; recurring unit/month violations and private remedies, previously at issue in RealPage, Inc. v. City of Berkeley et al. , (N.D. Cal.) (voluntarily dismissed with prejudice Jan. 14, 2026).

Santa Ana, CA

Santa Ana Ordinance No. NS-3090 (effective April 2, 2026)

Ordinance NS-3090 prohibits specified anticompetitive automated rent price-fixing; private tenant claims and up to $1,000 per violation and per month.

Philadelphia, PA

Phila. Code § 9-813 (effective February 2025)

Private remedies include treble actual damages or $2,000 per violation; now at issue in Liu v. Willow Bridge Property Co., et al. , (Phila. C.P.).

Minneapolis, MN

Minneapolis Code of Ordinances § 244.2070 (effective March 2026)

Effective March 1, 2026. Prohibits algorithmic devices using nonpublic competitor data to advise on vacancy or rental rates; tenants may pursue civil actions.

Providence, RI

Providence Code of Ordinances ch. 13, art. X, §§ 13-69–13-73 (effective May 2025)

Prohibits the use of rent-setting algorithms; the city expressly linked the measure to software such as RealPage; now at issue in City of Providence v. Audubon Capital Partners, LLC, (Providence Mun. Ct.).

Jersey City, NJ

Jersey City Code § 218-12 (effective June 2025)

Prohibits a landlord’s use of algorithmic rent coordination services; includes public and private enforcement; fines up to $2,000 per day.

Hoboken, NJ

Hoboken City Code, ch. 158-2 (effective July 2025)

Prohibits landlords from using software, algorithms or data-sharing platforms to coordinate or recommend rents, lease terms, or occupancy.

Seattle, WA

Seattle Mun. Code ch. 7.34 (effective July 2025)

Prohibits specified coordinating services; penalties may reach $7,500 per violation; now at issue in Nicolas v. Essex Management Corp., et al. , (W.D. Wash.) and Romano v. UDR, Inc., et al . (W.D. Wash.).

King County, WA

King County Code ch. 12.23 (effective October 2025)

Injured renters may seek actual damages, up to $7,500 per violation and attorney fees.

Spokane, WA

Spokane Mun. Code § 10.57.180 (effective January 2026)

Prohibits landlords from purchasing algorithmic coordinating services; city enforcement includes civil penalties of up to $5,000 per violation.

Portland, OR

Portland City Code § 30.01.088 (effective February 2026)

Prohibits algorithm-assisted rental price coordination; for owners of 16 or more units, private remedies include the greater of treble damages or $1,000 per violation.

Rockville, MD

Rockville City Code § 18-148 (effective January 1, 2027)

Prohibits landlords from using algorithmic devices and shared competitor information to set rent, fees, or other rental terms.

Many other municipal regulations remain pending, including in Montgomery County, Maryland; Evanston, Illinois; and Rhode Island.

WHAT THE NEW MUNICIPAL LAWS MEAN FOR EXISTING COMPLIANCE MEASURES

The new municipal cases and new regulations arise against an important backdrop: the multifamily housing industry and revenue-management vendors have already made significant changes in response to the various investigations and related legislation. Government settlements with several major property managers restrict the use of revenue-management software that relies on competitors' nonpublic information to generate rent recommendations, and various software providers have modified products to eliminate or restrict the use of competitors' nonpublic data in generating pricing recommendations. The federal government's resolution with RealPage likewise requires significant restrictions on the use of competitors' nonpublic, competitively sensitive information.

Those changes may materially reduce prospective risk under many of the new municipal ordinances, but they do not necessarily eliminate litigation over past conduct. Several local laws became effective, many prohibiting use of coordination services or software even if secured prior to the effective date of the law, while landlords and software providers were still modifying their practices, and some ordinances treat each affected unit and each month of prohibited use as a separate violation. The date on which a particular product or property ceased using prohibited data therefore becomes a critical issue in determining both liability and the scope of any putative class.

The municipal laws also place a premium on property-level documentation of software functionality. Owners and managers should be able to identify, for each covered jurisdiction, which revenue-management products were used, when relevant functionality was enabled or disabled, what data sources generated recommendations, and whether recommendations continued to rely on competitors' nonpublic information after a local prohibition became effective. Vendor representations that a product has been modified should be documented and tested against the definitions in the applicable ordinance rather than assumed to resolve compliance across jurisdictions.

These issues may also provide important defenses. A plaintiff's allegation that a landlord subscribed to RealPage, Yardi, or another revenue-management platform does not necessarily establish that every property used prohibited functionality throughout the proposed class period. Product versions, configuration changes, data sources, and effective dates may determine whether—and for how long—a particular local prohibition was implicated.

WHAT OWNERS AND PROPERTY MANAGERS SHOULD BE DOING

Owners and property managers should consider several immediate steps to understand and mitigate municipal regulation risk:

  • Create an ordinance-effective-date matrix : For every affected property, match the ordinance's effective date against the dates the pricing product and particular data functionality were used.
  • Test the ordinance's exclusions rather than relying on an “antitrust compliant” label: A product may satisfy a federal consent decree but still need to be assessed separately against a city's definition of “algorithmic device,” “coordinating service,” prohibited data, or permitted historical/public-data reporting.
  • Identify the potential class-period cutoff now : If prohibited functionality was disabled, document the date and the properties affected. In litigation, that evidence could be important to limiting statutory penalties, narrowing a proposed class and challenging assumptions that a vendor relationship establishes continuous prohibited use.
  • Evaluate legality of potentially applicable ordinances: Many of the local ordinances are first of their kind and may be susceptible to challenging the authority of the municipality to issue the ordinance, whether it is unduly punitive, and the extent of any retroactive effect.

Contacts

If you have any questions or would like more information on the issues discussed in this LawFlash, please contact any of the following:

FreeCORE TrueNAS Core – Continued

Hacker News
freecore.org
2026-08-29 21:31:32
Comments...
Original Article
Free CORE Home Install Documentation

TrueNAS® CORE — continued.

Train

  1. 13.3 base
  2. 15.0 current ( changelog )
  3. 15.1 next

Project

FreeCORE carries the TrueNAS CORE 13.3 system forward as an independently maintained operating system on FreeBSD.

15.0-U1 is stable. TrueNAS CORE 13.3 systems upgrade straight to 15.0 in place, then continue on the project’s update train.

Install

guide
freecore.org/install

downloads
FreeCORE-15.0-U1.iso

in-place upgrade

Source

code
codeberg.org/freecore

mirror
github.com/freecore-project

issues
report a reproducible bug

irc
#freecore on Libera.Chat

contact
hello@freecore.org

security
security@freecore.org

Thanks FreeNAS · TrueNAS CORE · FreeBSD · OpenZFS Original authorship is credited in the source’s license headers.

Benjamin Franklin's Alter Egos Gave Him the Most Freedom

Hacker News
www.smithsonianmag.com
2026-08-29 21:09:15
Comments...
Original Article

Silence Dogood. Richard Saunders. Benevolus. Sidi Mehemet Ibrahim. All were pen names that allowed Franklin to say things he couldn’t have otherwise said

Benjamin Franklin Illustration.jpg
Victoria Maxfield

Benjamin Franklin’s fertile mind constantly spun off inventive and useful ideas. His lightning rod saved buildings and lives. His energy-saving improvement of the wood-burning fireplace kept families warm and forests from being leveled. His lending library extended literacy to those who couldn’t afford books. His map of the Gulf Stream made travel faster and commerce more efficient.

But Franklin’s ingenuity showed most clearly in his invention, or rather recurrent reinvention, of himself. In the course of his life, Franklin devised dozens of authorial personas in print, which allowed him to challenge authority, identify folly and promote human progress with an unsparing vigor he never could have achieved under his own name.

Franklin created his first alter ego when he was in his teens: a middle-aged widow named Silence Dogood . Mrs. Dogood allowed Franklin to evade an embargo against publication imposed by his jealous elder brother James , a printer to whom Ben was apprenticed. James had a newspaper and sought contributors, but he refused Ben’s submissions as corrosive of the master-apprentice relationship. So Ben disguised his handwriting and surreptitiously slipped letters from Mrs. Dogood under the door of the print shop. Franklin’s account of her life delighted readers while underscoring the difficulties facing widows and women of the day.

Polly Baker was a literal—as opposed to an actual—descendant of Silence Dogood. Polly had the misfortune of falling in love with men who had no intention of marrying her. When she became pregnant, she was brought before the magistrates to be punished for her crime of fornication. In defending herself, she said she had done nothing more than obey the biblical command to be fruitful and multiply. Anyway, she asked, why was no sanction brought against the men who were equally responsible for her illegitimate children and more responsible for the corruption, as the court insisted, of the honest if imperfect woman who stood before it?

Franklin’s most famous alter ego was Richard Saunders, an astronomer and a polymath who annually published Poor Richard’s Almanack . The almanac provided information on holidays, solstices, phases of the moon and the like. What made it special were the squibs of advice and humor that filled otherwise blank spots on the pages. “Fish and visitors stink in three days” recommended itself to guests and hosts alike. “Three may keep a secret if two of them are dead” chided the garrulity of blabbers and the naïveté of confiders. (Franklin’s Saunders didn’t invent adages so much as he improved on earlier versions.)

Franklin retired Saunders after going into politics—a move that inspired him to create additional personas. Americanus appeared in Franklin’s own paper, the Pennsylvania Gazette , when he responded to news that the British Parliament planned to transport felons to America. The measure was intended to relieve the British government of the expense of incarcerating the convicts at home but was cast as a gift to the colonies, which could always use more people. “Such a tender parental concern in our Mother Country for the welfare of her children calls aloud for the highest returns of gratitude and duty,” Americanus wrote. The colonies must reciprocate. “In some of the uninhabited parts of these provinces, there are numbers of these venomous reptiles we call rattlesnakes, felons-convict from the beginning of the world.” Americanus expatiated on the virtues of rattlesnakes, concluding that they “seem the most suitable returns for the human serpents sent us by our Mother Country. In this, however, as in every other branch of trade, she will have the advantage of us,” as “the rattlesnake gives warning before he attempts his mischief.”

Franklin, appointed as agent of the Pennsylvania Assembly to the British government in 1757, relocated to London. There he wrote to British newspapers as Benevolus, to rebut arguments in Parliament that the American Colonies were too lightly taxed. Benevolus was a serious fellow compared with Franklin’s other alter egos. After the Stamp Act provoked riots in America, Benevolus identified numerous errors in fact and reasoning that misinformed British policy. He concluded with the fond hope that the British would be “a little less hasty in censuring their brethren in America upon the groundless surmises and mistaken facts so frequently delivered as truths in our public papers, and that they will consider the importance of a firm union between the two countries in affection as well as in government.”

Fun fact: How Benjamin Franklin charted the Gulf Stream

  • As deputy postmaster general, Franklin wondered why British mail-packet ships arriving in New York City were so much slower than American ships on similar routes.

  • From his cousin Captain Timothy Folger, a veteran whaler, Franklin learned that American whaling expeditions had been aware of a hidden eastbound current of warm water—one that British crews didn’t know to avoid while sailing west.

  • In 1769, sharing credit with Folger, Franklin published a chart of this hidden current, (a “river in the ocean”). Following Franklin and Folger’s map, ships knew to sail north of the current on the westbound journey from Europe, saving two weeks or more. For some vessels, that was nearly half the trip. Trans-Atlantic trade and communications accelerated significantly as a result.

Franklin’s personas provided varying degrees of cover. Readers in Philadelphia caught on that Richard Saunders was Franklin. Americanus and Benevolus, too, were obvious pseudonyms, fit for an age when political opinion pieces often appeared under made-up bylines. Sometimes this was to keep the authors out of trouble with the authorities. Equally it reflected the philosophy that a persuasive argument depended on evidence and reasoning rather than the expertise of the writer. But many people who read about Polly Baker thought she was real.

Franklin’s parting alter ego appeared just weeks before his death in 1790. By now a leader of the abolitionist movement in America, Franklin sent a petition to Congress urging an end to slavery. In response, slavery apologists mustered a vehement defense, citing economic necessity and religion in support of the institution.

In high satirical style, Franklin thereupon claimed to have discovered a speech by one Sidi Mehemet Ibrahim of Algiers justifying the enslavement of Christians: “If we cease our cruises against the Christians, how shall we be furnished with the commodities their countries produce and which are so necessary for us?” asked Ibrahim. “If we forbear to make slaves of their people, who in this hot climate are to cultivate our lands?” To fail to enslave Christians would deny them access to the true faith. “Here they are brought into a land where the sun of Islamism gives forth its light and shines in full splendor, and they have an opportunity of making themselves acquainted with the true doctrine and thereby saving their immortal souls.” Franklin’s Ibrahim concluded, “Let us then hear no more of this detestable proposition, the manumission of Christian slaves.”

Get the latest History stories in your inbox.

Bug Blindness

Hacker News
danluu.com
2026-08-29 20:21:40
Comments...
Original Article

I used to wonder why I see so many more bugs than most people. I easily observe hundreds to thousands of bugs per week and nothing seems to work , but most people I talk to don't see anything like this. For a long time, I thought this had something to do with how I use computers but, over time, I've realized that it's mostly that people are hitting the same bugs and don't notice.

If you're not a programmer, that's probably a better way to see the world , but I think curing quality/bug blindness is helpful for programmers. I've done this with a lot of friends and acquaintances (just by pointing out bugs). After a few weeks, people who are so inclined tend to start noticing bugs as well.

Because I notice these kinds of things, I've had multiple jobs where directors/VPs/execs/etc. sometimes ask me to evaluate something when they want an actual opinion from someone who is relatively likely to notice issues (and fix them or drive fixes for them if necessary). Sometimes I won't find any issues (there are likely issues that just aren't the kind I notice). More often, I find issues that fall somewhere from "mild" to "moderate". And, sometimes, the issues are severe, to the point where one might even say the thing actually doesn't work.

I find this last category a bit mysterious, as when I look up discussions on how the thing got into this state, there's usually a stream of internal comments indicating that the thing is great, it works well, etc., but when I open up the thing and try it, it's in a state where the thing only works if you do quite a few non-intuitive workarounds. More likely than not, not only would a normal user not be able to use the thing, they'd have such a hilariously/infuriatingly bad experience that they'd tell their friends.

I've had this post in mind for maybe a decade or so, but I was hesitant to write it up because, in the back of my mind, I always wondered if I'm somehow triggering weird corner case behavior most users don't hit without realizing it. But after seeing more and more cases where the product launches and falls flat on its face because users run into the exact same issues I saw, I don't think that, in general, I'm hitting bugs because I'm doing unusual things a normal user wouldn't do. If a product seems severely flawed when I use it, it probably is. And with the magic of LLMs, nowadays, I can even have LLMs act like normal users in a lot of ways and show that the issues reproduce across many different scenarios.

A few examples

I don't want to give any specific examples where it was my job to see how well the thing worked because, even if the internal examples are meant in a constructive, blameless, way, they may not always read that way when re-posted externally, so I'll give a few less interesting and less well supported "random" examples.

A while ago, I wrote up the results of some web search queries and found poor results from Google, Bing and Kagi. In general, the major search engines failed to return good results for the queries and returned pages full of low-quality SEO spam as well as some sites that were actually scams. BTW, on the scale mentioned above, I would consider this "moderate" and not "severe" ( severe would be something like, the search engine returns 500 errors half the time, the majority of results are scams, etc; my bar for severe is that a normal user likely won't be able to use the thing at all, not that they have a bad experience ). Almost nobody 1 objected to my characterization of Google and Bing search results, but people told me that I was wrong about Kagi. In some cases, people sent me their actual search results. In every such case, the search results did not contain a good result that I could see (e.g., for the seasonal forecast query, the search failed to return an up-to-date seasonal forecast) and was full of SEO spam. In one case, a person passed me both their list of Kagi filters as well as the search results they got without making claims that the results were good or bad, but people generally insisted the results were good even though the results both failed to link to a useful result and were full of spam except in cases where the user did something like pin GitHub to the top of their results, which worked for the queries where the goal was to download software that's hosted on GitHub, but of course completely fails for the other queries from the post.

In the abstract, I get that people who are fans of things tend to be blind to the thing's faults. For example, since I bought a Volvo after seeing how they do in out-of-sample crash tests , I sometimes search for answers to my questions on Volvo car forums. For well over a decade, the reliability data that exists (and I think this is backed up by the anecdotal experience that mechanics who work on Volvos have) is that Volvo reliability is mediocre to poor, but of course Volvo forums are full of people who insist that Volvos are among the most reliable cars and that the data are all wrong.

An example that might be more central to the topic is Blackboard (the course management software). Back when it was the most widely used software by universities for coursework, the software was widely disliked by both students and professors. I think it would be fair to say that it was the most widely disliked software in my social circles (there was more disliked software, like Visual Source Safe, but any more strongly disliked software wasn't widely used enough to be the most widely disliked overall). The Wikipedia page notes

Blackboard had become "one of the most disliked — even detested — companies in education."

as well as

In December 2011, Fast Company reported that 93% of respondents to the Amplicate customer opinion survey "hate" the company.

Back when I was much younger and had less of a filter, I ran into someone who worked at Blackboard and, without thinking, I stupidly blurted out something like "what's it like to work on this software that so many people dislike?". Luckily, the person I was talking to wasn't offended at all and, instead, they were actually confused because they thought it was widely loved software that users really liked. They didn't really believe what I said could be true and I made some comment indicating that it was just confusion on my part and then the conversation continued in a different direction. At the time, as someone much younger and more naive, I was really surprised to hear that the software that was probably the most widely disliked software in my social circles was thought to be really well-liked software by the one employee from the company I met (and, presumably other employees as well).

I can understand how the Volvo forums get to be how they are, in that cars are reliable enough in general now that people generally don't experience car breakdowns , so it's easy for someone to think something like "the data can't be right; after all, my car has never broken down". It's more of a mystery to me how somebody can look at a set of search results that are full of spam and then dash off a message explaining how great the results are, even if they're a fan of a particular search engine or how someone can think that users generally love software that's famous for being disliked, to the point that every single person I talk to about it tells me how bad it is (often in unprompted complaints), there are news articles that discuss how much people dislike the software, and the near-universal dislike for the software is mentioned on its Wikipedia page. Another Blackboard-like example might be Discourse (forum software) web performance, where one of the inspirations for this post was discussions with Discourse employees who thought that Discourse had great performance. I found that one interesting because Discourse actually had code in it that slowed down actual page loads in order to cheat on web performance metrics like LCP . That went well beyond just optimizing for a benchmark and rose to the level of actual cheating that not only had no benefit to the user, it actually harmed the user. At some level, the programmers implementing that sort of cheating and advising users on how to not accidentally subvert the cheating must know that the actual performance of their app is poor, but it's very easy for people to put up mental barriers around this kind of thing.

By now, I wouldn't say that I'm surprised because I've seen this kind of thing enough that I would actually consider it surprising if it didn't happen, but I still wonder what's going on inside someone's head when something like this happens.

For a non-programming example, we previously noted in this post on how people have different perspectives on "obvious" facts , there's a basketball player who, subjectively, is generally considered to be the dirtiest player of his era. Objectively, although this isn't an officially tracked stat , he surely holds the record for punching, kicking, kneeing, or otherwise striking players in the genitals this century (he should also hold the record for era-adjusted numbers, but it's possible that he doesn't have the all-time record due to play being much dirtier overall in the 80s and 90s). In discussions, most fans of his team don't seem to notice this and the phrases "natural rebounding motion" and "natural shooting motion" have become running jokes from how oblivious the team's fans are when they justify this player's contortions when he strikes other players in the genitals.

On average, humans have a high ability to ignore negatives in things they're a fan of, including (and often especially) their own work or work their company does. For better or for worse, I seem to have the opposite of this and my thoughts immediately go to the flaws in myself and my work. A number of times, as a result of a blog post, someone has messaged me with something like "how would you like it if someone criticized your work?" or "how would you like it if someone said your work isn't good?" To the former, my thought is that I go to great lengths to get criticism from people who can poke holes in my reasoning, so it's pretty awesome if someone has remotely reasonable criticism of my work. And to the latter, I generally think my work is full of major flaws, so, uhh, yeah, it seems pretty reasonable to say it isn't good. There are particular aspects of my work that I think are interesting or good but, overall, I don't know that I'd rate anything I've done as good. I'm not saying I don't have blind spots , but I think I'm a bit less prone to this particular one than most people 2 .

Habitual mitigations

If I think about analogous blind spots I've had, one that jumps out at me is from when I was a little kid and a friend of mine used my computer. For this story to make sense, you have to know that this was in the mechanical mouse era. Over time, detritus would get stuck to your mouse ball and cause it to track erratically unless you cleaned it out.

When my friend tried to use my computer he found it impossible to use the mouse because mouse pointer movement seemed almost random. When I sat down at the computer again and used the mouse I didn't have any problem using it at all, but on looking at what I was doing with my hand to smoothly move the pointer in a straight line, I was violently throwing my hand all over the place. I realized I must've adjusted to the detritus on the mouse ball over time as it accumulated and I was somehow compensating for the mouse's extremely erratic tracking by making countervailing erratic movements 3 . I thought it was pretty amazing that I could not notice that I was doing this and I always wonder if I'm doing some equivalent thing today.

I sometimes think about all of the mitigations I've developed to work around bugs. For example, when opening a new Google Doc, I used to immediately put the title I wanted into the doc. At some point, maybe ten years ago or so, Google Docs added some kind of delay such that the typing you do into the title box right after you open the doc gets overwritten, so I now have this habit where, after opening a Google Doc, I do something else and then I change the title. Over time, as Google Docs has had more and more features added, I've developed a series of habits that avoid all sorts of pitfalls (such as trying to search at the "wrong" time and getting the useless native browser search instead of the Google Docs search).

My feeling is that a large fraction of computer literacy and software literacy is developing a large library of these habits that you just do at a non-conscious level. These are often quite specific to the situation, such as a habit I developed when I worked at Microsoft of flipping my laptop's WiFi switch to off before logging in (which I noticed other people doing as well). This was because there was some service, which would often fail your login with "There are currently no logon servers available to service the logon request”. But if that service couldn't connect at all, the check would be bypassed and you could just log in.

Quality blindness

We could fill a post up with examples like that, but back to the main topic of the post, one commonly suggested way to try to overcome quality blindness is to have people dogfood their own software. On average, this is a lot better than not dogfooding, but it only works to the extent that people don't figure out (and then forget about) habits that work around whatever issues the software has. On average, programmers are pretty good at working around software foibles (you had to be in order to be an effective programmer pre-LLM), so it's very easy for programmers to not notice these kinds of issues if they're not paying attention.

On the flip side, a large part of making an app easy for people to use seems to mean making weird habits like these unnecessary. Although this sounds like it should be easy to do, from having seen people try to give feedback about this kind of thing, the reflexive reaction of most developers seems to be "huh? It's easy to do X, just do [complex sequence of things that no normal person would think of if they hadn't used the app many times before unless it was specifically explained to them or they saw someone else do it]" or "huh? Didn't you see that the instructions for this are clearly laid out in page 43 of the manual after you execute the steps in Appendix B on page 261?".

That being said, I think curing people of quality blindness is do-able because I've done it quite a few times. I think this only really works when the person is receptive, as people have infinite capacity for willful blindness but, in cases where people are receptive, just pointing out issues they didn't notice seems to work. Years or even a decade later, people will sometimes tell me they see bugs everywhere now.

The reason I think this is worth doing is that I've seen people and teams with a high degree of quality blindness ship things that have reduced or even no chance of success because of product quality issues 4 . It's one thing to knowingly and deliberately trade off quality for speed 5 , but when I've seen this happen there's always been a kind of quality blindness where everyone involved with the project thinks they're shipping something very high quality when that's not the case.

This has never been unimportant, but it's gotten more important with coding agents because, while it's easier than ever to churn out low quality software, it's also easier than ever to improve quality, whether that's better performance , fewer bugs , etc.

But, to do this, you have to actually notice that this is possible, that quality can be improved .

Thanks to Yossi Kreinin, Dennis Snell, Michael Malis, Emu Chu, Gary Bernhardt, Jon Surrell, and Matt Mullenweg for comments/corrections/discussion.

Naturally, Gary Bernhardt ran into a Google Docs bug while reading a draft of this post.

P.S. Like I've mentioned in the last four posts, I've been trying to write posts more quickly because, with LLMs, it's so much easier to look at data and figure things out, but the time it takes to write something up hasn't fundamentally changed, unless I want to move to a different point in the quality-velocity trade-off space. The prior result was that I would run some experiments and tell a few friends and then never write anything up because, due to Amdahl's law, writing anything up would effectively consume all of my bandwidth for running experiments. In fact, despite trying to do this (my goal is to spend 30 minutes per post on the write-up), since writing my last post, I have three results that I think could make a totally fine blog post that I haven't had time to write up (not including things done for work, which would add a few more things). Without having LLMs write for me, I don't see a reasonable way to get the time per post significantly below 30 minutes (and I think I often miss my goal and take more than 30 minutes), so the non-LLM options here are some posts that are much sloppier than my normal posts (in a human slop kind of way), or almost no posts.

Anyway, if you have opinions on these quick (and surely more wrong) writeups, let me know what you think ( X Bsky Mastodon )!

Appendix: advertising blindness

Michael Malis (founder and former CEO of Freshpaint ) noted (in messages, hence the message-like format)

For a similar but different data point - I’ve seen similar blindness when it comes to advertising. When I would explain Freshpaint to people, I would tell them that we help hospitals with marketing

A common question I get is why do hospitals do marketing. The weird thing is if you pay attention, hospitals do a ton of marketing

In SF there’s tons of bus ads and billboards for ucsf/sutter health/stanford and various treatments

This is a different topic from both Michael's comments and the post, but I'll say that I've talked to quite a few people who don't believe ads work at all, but I talked to someone whose data methodology and judgement I trust about ads A/B testing at one big company I worked for and looked at the data myself at another company and I thought the causal evidence for ads providing real lift (well beyond the cost of the ad) was strong in those cases. In the case where I looked at it, they did a geo-segmented A/B test where they bought ads in some geos but not others (this was done worldwide, with the regions being things like U.S. states, Canadian provinces, etc.). This kind of geo-segmentation was done because, even with cross-device tracking, it's not 100% clear if someone has been exposed to an ad or not (of course this is still the case with this kind of segmentation and I would prefer segmentation that was more clustered to population areas and didn't have splits where people are relatively likely to, for example, commute from one side of a boundary to the other, but this kind of contamination generally makes the likely true lift higher than the estimated lift), so people sometimes do these geo-segmented A/B tests.

Anyway, in these A/B tests, return on ad spend was quite good just on direct revenue gain, and there was also a gain in users which seems likely to result in more revenue down the road (the later revenue wasn't analyzed). I don't know about ad effectiveness in general or if your particular ads are effective, but the commonly repeated idea that ads don't work in general seems wrong to me.

Em Chu, on a habitual bug mitigation:

I'm sure you can collect infinite examples for this section, but I just want to Complain: when waking up and unlocking my laptop (mac), it's very easy to get it in a state where it's "awake" but unusable (black screen with cursor or similar) which can only be fixed by physically closing the lid and re-opening it. To work around this, I think I usually wait a second after the screen turns on, interact with the trackpad, and then unlock it, though honestly that happens mostly subconsciously, and I clearly need practice given that I still hit the bug a few times a month.

On reading this, I examined how I open my laptop and realized that I have some funny habits as a result of working around other laptop bugs. The specific bug mentioned here doesn't reproduce on my laptop and it seems that I can stop the habitual mitigation I put into place for some prior laptop.

Gary Bernhardt, on his experience reading a draft of this post

While reading it, Google Docs' UI seems to have broken, making it impossible to scroll up to read some comments (see screenshot [not shown in post]).

From looking at the screenshot, I've seen the exact same bug and have some mitigations for it (different ones depending on the context). I would personally rate Google Docs as far above average in terms of software quality: I find it much less buggy and janky than the major alternatives (Microsoft Word, Open Office, various old editors that are long gone like StarOffice, Lotus, etc.). And yet, I could easily sit down and write a 10k word post on Google Docs bugs and the workarounds I have for them.

At times, I've tried to see if I can get a job somewhere where I just fix quality issues all day. This has never panned out, due to some combination of this not being a very high priority and it also not being a normal role that companies have a role for. I sometimes daydream about joining companies as an intern and just fixing quality issues for a few months and then leaving. In practice, I think if I got such a job, a lot of the fixes would get blocked and it would be very difficult to actually drive change as an intern for three months, so it would have to be some mostly abandoned project where nobody cares what I do (and corporate priorties aren't so focused on shipping features that fixes get immediately re-broken).

@gunchleoc@mastodon.scot :

Germans have a word for that - Betriebsblindheit

@oulipien.bsky.social :

Crazy anecdote from @danluu.com here and I wish he'd been even blunter at the time and asked this person where they'd gotten this belief about Blackboard being liked by anyone at all. User surveys? Principal (as in, not agent) surveys? Inner conviction??? [screenshot of Blackboard anecodote]

Daniel Gibson :

Who else uses the Shift key to end the screensaver, because in case the event goes through to an actual program it's least likely to do have unintended effects?

This reminds me of how, when I want to send a queued message to codex immediately and interrupt the current tool call, I put my finger on the key and the press as quickly as possible to reduce the window of time where the tool call will finish and the escape key will stop codex entirely instead of causing the message to send. I should probably just run a patched version of codex that has fixes for this and a few other issues I've run into, but I'm already doing things like trying out some weird workload-specific optimized version of ripgrep that also has an added native code compiler which compiles matching expressions in another thread while the search starts and then cuts over after compilation completes, so it's not like I'm against creating weird patches to improve my workflow and it's more of an issue of overall bandwidth (no doubt, on writing this, someone will tell me that I could just hit another key instead and could've found this out by asking codex about the key in the time it took me to write this comment). Just like with Google Docs, I consider codex above average in terms of software quality in the space, but even though I haven't been using it for a year, I could easily write 10k words on all the workarounds I've implemented (either by habit or, in some cases, with actual scripts that monitor for broken behavior and then correct it).

Introducing Hy4 Preview

Simon Willison
simonwillison.net
2026-08-29 19:53:13
Introducing Hy4 Preview New open weight text input (no vision) LLM from Chinese company Tencent today: 770B total parameters, 49B active parameters, 1M token context window, 1.56TB on Hugging Face. This is a big size increase from their previous Hy3 in July, which was 295B, 21B active, 256,000 cont...
Original Article

29th August 2026 - Link Blog

Introducing Hy4 Preview . New open weight text input (no vision) LLM from Chinese company Tencent today: 770B total parameters, 49B active parameters, 1M token context window, 1.56TB on Hugging Face .

This is a big size increase from their previous Hy3 in July, which was 295B, 21B active, 256,000 context, 598GB.

I recently started using model chat templates to better understand their capabilities. Here's Hy4's chat_template.jinja on Hugging Face, which includes this section:

{%- if not reasoning_effort is defined %}
    {%- set reasoning_effort = 'high' %}
{%- elif reasoning_effort not in ['high', 'no_think'] %}
    {%- if reasoning_effort is none %}
        {{- raise_exception('reasoning_effort error : None, should be no_think/high') }}
    {%- else %}
        {{- raise_exception('reasoning_effort error : ' + reasoning_effort + ', should be no_think/high') }}
    {%- endif %}
{%- endif %}

So it looks like there are just two reasoning effort levels: "high" (the default) and "no_think" (reason by disabled).

I tried my "Generate an SVG of a pelican riding a bicycle" prompt with the default high reasoning via OpenRouter and got this :

Flat vector cartoon illustration of a white pelican with a large orange bill riding a red bicycle to the right along a grey road with a dashed white centre line, its orange webbed feet on the pedals and grey tail feathers fanned out behind, against a pale blue sky with a yellow sun, white clouds and horizontal white motion lines suggesting speed

Quoting the reasoning trace:

[...] Let's maybe add a helmet? It could improve riding theme, but may obscure head. Maybe a small cycling cap or helmet? The user didn't ask; can add red helmet? Might be cute. But pelican with big beak; a helmet might obscure. Better maybe no.

Maybe add sunglasses? no.

Maybe add water? no.

It's interesting how the reasoning trace uses slightly truncated English, presumably because perfect grammar isn't useful or token efficient for hidden reasoning text.

Anthropic is cutting Claude Code's current weekly limits by 17%

Bleeping Computer
www.bleepingcomputer.com
2026-08-29 19:11:51
Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. [...]...
Original Article

Anthropic

Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds.

If you use Claude, you're actually getting a 17% reduction compared to what you have today.

Claude Code currently has a temporary 50% increase in weekly limits, which Anthropic says will remain in place until September 14.

image

"Starting September 14, we're permanently raising standard weekly limits in Claude Code by 25% for Pro, Max, Team, and seat-based Enterprise plans," Anthropic wrote on X. "Until then, the current 50% increase will be in place."

It's a clever way to frame words, as it almost sounds like you're winning as a customer, but you're not, and it's a downgrade.

If Claude Code's original weekly allowance was 100, the temporary boost gives you 150 today. On September 14, that drops to 125.

In other words, you will have 25% more Claude Code usage than you did before the temporary promotion, but about 17% less than you have right now.

Anthropic says more Claude Code usage changes are coming

Anthropic later deleted the original thread and posted a clarification, where it clearly admits the reduction.

"Compared to today, this works out to a 17% reduction in weekly limits on Claude Code," the company said .

"We’re working on exciting changes that will make it feel like you’re getting more from Claude, while having more visibility and control of your usage. Can’t wait to share them."

Anthropic says Claude usage can vary based on factors including conversation length, model choice, tool usage, and effort level, so the weekly allowance does not translate into a fixed number of Claude Code prompts.

The current 50% temporary increase remains available through September 13, with the new permanent limits taking effect on September 14.

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Omnipresent availability risks in cloud software

Lobsters
surfingcomplexity.blog
2026-08-29 18:17:35
Comments...
Original Article

I’m using this post to gather together some common threads I’ve noticed after reading write-ups of major cloud software incidents. By cloud software , I’m referring to software-as-a-service (do people even say that anymore? in the cloud. This doesn’t just apply to cloud providers, although it does apply to them as well.

Here’s an outline of the topics in this post:

  • problem areas
    • saturation
      • example: databases
    • networking (traffic routing failure)
      • example: DNS
    • security (deny valid access)
      • example: SSL certificates
  • essential non-standard changes
    • mitigating an operational issue
    • migration
  • essential increase in essential complexity
    • reliability subsystem
    • migration

I think of all of these as omnipresent availability risks : I think these are fundamentally unavoidable, and will be contributing to software incidents until the end of time; or, at the very least, until the end of my own career in software.

There are three general areas that most major incidents seem to fall into: saturation, networking, and security. So, let’s start with those.

Saturation

Saturation is probably the topic I talk about most frequently, both on this blog and elsewhere (e.g.,: the saturation post I wrote for the Resilience in Software Foundation and my saturation talk at the Software Should Work conference). The system becomes saturated when it reaches a limit. That’s a pretty generic description, but there are many limits!

Databases

Many major incidents involve some system component becoming saturated in one form or another. I personally worry about database saturation the most. That’s because it’s difficult to recover from an overloaded production database. In addition, because database systems are such complex beasts, it can be quite difficult to even determine what the specific performance issue actually is. This is why having in-house database operational expertise is critical.

Saturation is an omnipresent risk because the finite nature of resources is a hard constraint in the world that we live in. Eventually, some resource in your system is going to run out.

Example: GitHub Incident, Aug 26, 2026

Networking

While I prattle on endlessly about saturation, not every major incident involves saturation. You can encounter scenarios where all of your internal subsystems are reporting healthy, but from your customer’s point of view, your site is down: they can’t use it. One way this can happen is if your users can’t even reach your site, and that’s where the networking problem area comes in.

A networking problem can lead to packets being misrouted. These requests might be black-holed (i.e., silently dropped), or they might be incorrectly routed to a service that doesn’t have the capacity to respond to all of these requests, in which case you’ve got both a network routing issue and a saturation issue.

A visual depiction of an actual black hole. Image source: NASA

DNS

DNS issues are an example of this kind of network-related failure mode. There’s no way those packets are going to make it to their destination if the client can’t even determine which IP address to send them to. And when DNS breaks, that’s what happens.

I bring DNS up because it’s bitten folks enough times that there’s a famous haiku:

More generally, networking is an omnipresent risk because cloud software is inherently distributed, so networking is always a critical service. Now, I don’t work in networking, but from the outside, networking just feels like a dangerous domain to do operational stuff in. The blast radius of a networking issue can be very large. And, because network behavior is inherently distributed, reasoning about the behavior of operational changes is just inherently difficult. Honestly, that’s probably why I don’t work in networking.

And, so, I predict we’ll continue to see networking issues contribute to large-scale incidents.

Example: Buildkite incident, Aug 25, 2026

Security

There’s a fundamental tradeoff between availability and security: availability is about ensuring that the good people can access the system. Security is about ensuring that the bad people cannot access the system. This means that there’s always a risk that a security system designed to prevent bad actors from accessing the system can lead to good actors also being blocked. Consider this scenario: there’s an internal security subsystem that goes unhealthy (possibly due to saturation). Is your policy to fail closed or fail open in the event that this subsystem is erroring? Answering that requires making an availability-security tradeoff.

SSL certificate expiration

Another example of this failure mode, which keeps biting our industry again and again, is SSL certificate expiration. Here you have the behavior of a security system that is preventing legitimate access because the cert wasn’t renewed.

Bazel expired certificate
Even the mighty Google encounters SSL certificate expirations. This is from the Bazel incident

And so, my claim is availability incidents that involve security subsystems will continue to be a thing forever.

Example: Bazel incident, Sep 27, 2025

Essential uncommon changes

Your system is constantly undergoing change. Heck, if you stopped making changes, the system would eventually stop working properly. Now, there are some changes that your org does very frequently. Hopefully, you’re deploying often, flipping feature flags a lot, and so on. But there are other changes that your org has less experience with, because they happen much less often. That means that there hasn’t been as much investment in tooling to support these sorts of changes, and it means that the people making these changes don’t have the same level of expertise as they do with the more common changes. That makes these sorts of changes more dangerous: less mature tooling and less experienced humans.

Mitigating an operational issue

A few years ago, I wrote a post titled a conjecture on why reliable systems fail where I speculated on two common contributors to major incidents. One of those contributors was a manual intervention that was intended to mitigate a minor incident . Now, it may be that you frequently have to do manual interventions to mitigate system issues, in which case you’ll have a lot of experience with those sorts of interventions. But you’ll also be more motivated to put in the engineering effort to automate away those sorts of common issues.

It’s exactly the uncommon issues that require a human operator to intervene to mitigate that are dangerous, because they are uncommon. But they’re essential: there’s a problem in the system, and you need to fix it! But because all practitioner actions are gambles , the manual mitigation carries risk that you could make the problem even worse. And, eventually, this will happen to you.

Example: Azure Regional Outage, Jul 23, 2026

Migration

If you’re at a tech company, unless it’s a start-up, you’ll be dealing with migrations, as old tech gets replaced by newer tech that is better suited to the problems that your org is currently facing. While migrations as a general category are extremely common, each migration is itself a snowflake. This means that the specific details of the migration work is an uncommon change . The work of migration involves making a kind of change to your system that you haven’t made before.

To make things worse, one of the dangers of migration is that, as you go along, you start to build confidence that your changes are safe, but there are actually hidden dangers lurking in the system for the next migration. The confidence in the safety of the work exceeds the actual safety. I mean, you made n-1 changes as part of the migration, and none of those changes had negative consequences. It’s natural to assume that the same outcome will occur with the nth change.

Example: Rogers Network outage, Jul 8, 2022

Essential increase in essential complexity

The late American computer scientist Fred Brooks wrote a famous software engineering essay titled No Silver Bullet where he drew a distinction between accidental complexity and essential complexity. The general idea was that there was some amount of complexity in a software system that didn’t need to be there (accidental complexity) and some amount that was just inherent to the nature of the problem space and solution space and so could not be removed (essential complexity).

Reliability subsystem

We’ve developed multiple techniques to improve the reliability of software systems, including retries, concurrency limiting, autoscaling, automated failover, circuit breakers, health checks, canaries, outlier detection, the list goes on and on. There’s one thing that all of these techniques have in common: they increase the complexity of the overall system! And they do this because they have to increase complexity in order to do their job. This is a consequence of Ashby’s Law , which states that if you want to build a control system that handles more scenarios, you have to increase the complexity of the controller itself.

This means that reliability subsystems result in a complexity trade-off. On the one hand, our system can now automatically recover from failure modes that previously required manual intervention. On the other hand, as we all know, increase in complexity is itself dangerous because it can introduce entirely new failure modes that weren’t there before.

Going back to my conjecture blog post, the second contributor I posited was: unexpected behavior of a subsystem whose primary purpose was to improve reliability . And this is exactly why. Adding reliability subsystems improves the robustness of our system, but it adds essential complexity to our system, which can lead to novel incidents.

Example: OpenAI incident, Dec 11, 2024

Migration

Like all engineers, I’m a big fan of giving the answer “it depends” if somebody asks me a question about whether they should do X or Y. However, if someone came up to me and said, “Lorin, I’m preparing to do a migration at my company, and I’m trying to decide whether to do a big-bang migration or an incremental one”, then I would almost certainly say, “For the love of God, please do an incremental migration!”. Sometimes big-bang migrations are unavoidable, but when given a choice, I’m going to go for the incremental migration as the safer option.

However, when you do an incremental migration, it means that you need to simultaneously support the old system and the new system at the same time while you’re doing the migration. This means that even if the new system yields a net decrease in overall complexity over the old system, while the migration is happening, you’re going to see an increase in system complexity. And that means that you’ll see incidents arise as a byproduct of this increased complexity.

Example: Cloudflare incident, Jul 14, 2025

Incidents are inevitable, so you’d better be ready

To reiterate, I think all of the risks mentioned here are omnipresent : they are fundamental to the nature of cloud software. I don’t think that any of these risks can be eliminated. That’s why I believe so strongly in the value of getting better at incident response. Because, if you prepare, you can get better at dealing with problems that arise as a result of these risks.

Functional State Machines in Rust: Typestate and Newtype Patterns

Lobsters
dl.acm.org
2026-08-29 17:59:35
Comments...

The Corporate Dem Asking Super PACs To Call Him a Progressive

Portside
portside.org
2026-08-29 17:59:29
The Corporate Dem Asking Super PACs To Call Him a Progressive Dave Sat, 08/29/2026 - 17:59 ...
Original Article

In the race to secure the Democratic ticket for Massachusetts’ upcoming Senate race, Rep. Seth Moulton has put out a not-so-subtle call for ads targeting “voters under 40” highlighting that he’s “one of Massachusetts’ rising progressive stars” and a “next generation progressive fighter who supports abolishing ICE, taxing the rich and health care for all.”

Beyond raising legal questions about prohibited coordination between campaigns and outside groups, the brazen appeal is a reinvention for a six-term congressman who said last year that progressive populism is “great for Democrats if we want to continue losing.”

A review of Moulton’s donors, investments, and voting record also suggests his new branding is at odds with his political history. Progressive standard bearers say Moulton’s pivot is an example of establishment Democrats attempting to capitalize on their base’s leftward shift and fool voters into supporting them over actual progressive candidates.

“We’ve seen this in the wake of Sen. [Bernie] Sanders’ presidential campaigns, where you have a lot of establishment consulting firms or elected officials painting themselves with that brush in an effort to appeal to progressive voters, but it’s a smokescreen,” said Robert Dempsey, national political director of Our Revolution, a progressive organization founded as a continuation of Sanders’ (I-Vt.) 2016 presidential campaign. “It’s not real. It’s disingenuous, and voters see right through that.”

Moulton, who has represented the congressional district just north of Boston for 11 years, has raked in more than $1.7 million in campaign donations from private equity, Wall Street, healthcare industry, and tech donors this election cycle. What’s more, a Wall Street-funded super PAC supporting Moulton has spent at least $5.4 million boosting his campaign and opposing incumbent candidate Sen. Ed Markey, according to news outlet Sludge .

A Lever analysis of Moulton’s voting records also shows that he has routinely voted to pass legislation favorable to the cryptocurrency industry, continue weapons sales to Israel amid the genocide in Gaza, and extend warrantless surveillance of Americans’ communications in 2024. He has since flipped his positions on Israel aid and warrantless surveillance . The congressman also faced recent scrutiny over his investments in nonpublic companies with federal contracts.

Additionally, he made disparaging comments about trans athletes, telling The New York Times in November 2024 that he doesn’t want his two daughters “getting run over on a playing field by a male or formerly male athlete, but as a Democrat I’m supposed to be afraid to say that.” He has since apologized for the comment.

In comparison, Markey, Moulton’s opponent, coauthored the Green New Deal and has the backing of prominent progressive Rep. Alexandria Ocasio-Cortez (D-N.Y.). Markey also cosponsored a bill in 2025 that would close a tax loophole exploited by private equity and hedge fund managers to avoid taxes on certain types of compensation. (According to Sludge , Moulton has never cosponsored such private equity tax reforms.)

Despite how Moulton would like outside spending groups to depict him, his voting record and campaign donors are telling “Massachusetts voters exactly who he is,” said Cam Charbonnier, Markey’s campaign manager.

“Seth Moulton’s election-year reinvention as a progressive would be laughable if it weren’t so cynical,” Charbonnier told The Lever . “After years of positioning himself as a corporate-friendly moderate and attacking the progressive movement, he is now being propped up by millions from corporate PACs, private equity investors, and wealthy financiers.”

The Moulton campaign did not respond to a request for comment.

The Thin Red Line

On Monday, August 24, Moulton’s “ Media Info ” page was updated with a message, framed in red, stating that “Likely Primary Election voters across Massachusetts… need to see on TV, cable and especially digital that after 50 years in Washington, Ed Markey decided to run again — at 80, for a six-year term — rather than pass the torch to one of Massachusetts’ rising progressive stars.”

The message also includes links to media-friendly photos and video B-roll of Moulton.

A screen capture from South Moulton’s “Media Info” page from August 27, 2026.

The note might seem puzzling to the average voter perusing Moulton’s website, but experts say the message is an example of a legally dubious campaign finance loophole used by campaigns and political action committees to skirt campaign finance laws barring the two entities from coordinating.

The tactic, called “ redboxing ,” involves a campaign posting video footage, demographic targets, and messaging on its website in hopes that an outside group runs advertising amplifying the message. In this instance, Advance Progress, a super PAC largely funded by private equity interests that is supporting Moulton, has run at least two ads , featuring materials posted on Moulton’s website. The ads call on Markey to “pass the torch” to Moulton, “the kind of progressive Democrat we need now” who’ll “take on ICE and make billionaires pay their fair share.”

Beyond the tactic raising legal questions, it is part of a “troubling trend” by super PACs, dark money groups, and wealthy donors to influence elections, said Shanna Ports, senior legal counsel for ethics at the campaign watchdog Campaign Legal Center.

“[Redboxing] runs the risk of the candidate becoming beholden to the donors who are supporting that ad, and those donors don’t necessarily represent the views of the American public,” Ports told The Lever . “This trend the [Federal Election Commission] has of not policing coordination drowns out the voice of everyday voters, and that’s why this is really troubling to see this much coordination happening and to see super PACs and the special interest donors behind them almost become like an integrated part of candidates’ campaigns.”

The 2022 midterms saw more than 200 candidates use this tactic, and many candidates in the current midterm election cycle have also employed the strategy.

Moulton’s own PACs have received funding from other individuals working in hedge funds and venture capital firms, as well as from PACs affiliated with weapons contractors RTX, Honeywell, and Leidos .

He has also received more than $54,000 from individuals and PACs affiliated with the American Israel Public Affairs Committee (AIPAC), a pro-Israel lobbying and campaign donation group, according to campaign watchdog OpenSecrets. Candidates’ willingness to accept AIPAC donations has become a core issue for many progressive voters because of the group’s support for Israel’s ongoing military actions in Palestine.

These campaign donations and Moulton’s voting record make him unfit to call himself a progressive, said Jonathan Cohn, policy director with the statewide grassroots organization Progressive Mass .

“Seth has done a fascinating job of trying to rebrand himself as progressive this cycle,” Cohn told The Lever . “[Moulton] doesn’t ever really actually hit on the big problem over the past few decades of the Democratic Party’s movement away from thinking about how the government can positively intervene to improve people’s everyday lives.”

Cohn said that progressive candidates need to support core issues at the center of the progressive movement, like taxing the rich and providing universal public services, such as Medicare for All. Dempsey, with Our Revolution, added that progressive candidates need to support increasing the minimum wage, expanding union protections, and holding people in power accountable.

Dempsey said that if Moulton wants to call himself a progressive, then he needs to support reining in “out-of-control spending” by the Defense Department and getting money out of politics.

“I wouldn’t hold out a lot of hope for that, seeing how he has benefited greatly from the dark money spending that we see dominating American politics now,” Dempsey said. “It’s really frustrating to see moderate corporate Democrats call themselves progressives in an attempt to fool voters.”

Freddy is a reporter and has been published in the Los Angeles Times, NBC News, CalMatters, the Lost Coast Outpost, and more. Send tips via Signal: freddy_brewster.64

Each day, The Lever ’s staff tirelessly investigates, researches, writes, fact-checks, and edits stories that hold the powerful accountable in ways corporate media will not. All of that work is supported by readers who become paid supporters.

Time and again, The Lever has shown that independent journalism empowered by everyday people, rather than billionaires and massive global corporations, can move the needle. Our reporting led to legislation being introduced in Congress, has been referenced in presidential speeches, and is driving national conversations across the political spectrum.

What GLM-5.3 Flash running on Chinese hardware actually means

Lobsters
martinalderson.com
2026-08-29 16:44:36
Comments...
Original Article

Z.AI confirmed that their most recent model release was running all inference on Chinese manufactured hardware. While no doubt an impressive feat, Western companies still have a huge advantage that I can't see changing quickly.

Where is Chinese AI hardware at?

To start with, it's worth looking into where Chinese AI hardware is. I'm focusing entirely on the HiSilicon parts - the most competitive parts from Huawei. There are (many, actually) other manufacturers building AI hardware, but it's widely believed that they are no further ahead than HiSilicon, so I think that for brevity it's a fair starting point.

One caveat before I go further: Z.AI didn't actually name a chipmaker, and didn't publish throughput or power numbers either. Nobody has independently verified the claim. So I'm assuming HiSilicon here because it's the only plausible candidate at that scale, not because anyone has confirmed it.

It's also worth mentioning that the US export restrictions ( CSIS has a good overview ) of high end AI hardware have made this an enormous priority, understandably, for the Chinese. And it's definitely worth mentioning that finding accurate sources for many of the numbers I'll cite are difficult to be confident in, so take the exact numbers with a pinch of salt.

The current 'scale-up' series of HiSilicon chip, the 910c series, pairs 96GB of HBM 2e memory with two compute dies, probably achieving something like 1.6PFLOP/s of INT8 compute with ~3TB/sec of memory bandwidth, at around 600W.

In essence, this is substantially behind even the H100 from Nvidia, which is now 4 years old. These are around 60% as fast as the H100, and has various other footguns (no native FP8 support for example), which probably restrict efficiency further for many use cases.

The next generation 950-series doesn't meaningfully increase compute as far as I can see, but does use domestically produced HiZQ/HiBL HBM memory. Interestingly the cards are configured in two variants - the 950PR and 950DT, with the former focusing on prefill and the latter on decode. In reality, the two products are very similar, but the prefill variant using slower HiBL memory vs the decode HiZQ memory. It does however support more quantisation types, like FP8.

The constraints

I think this shows the limitations of what Chinese hardware can do - at least for the near future.

Yes, they can run inference, but so can many sets of hardware now - AMD, Google and Amazon all have competitive solutions, and OpenAI are making significant progress on their Jalapeño inference chip , which in the first published benchmarks did 1.5-1.9x the work per watt of Nvidia's GB300. Inference hardware while no doubt complex, is a pretty solved problem right now with a lot of competition - and that's before you bring in the Cerebras and Groq approach chips.

The wall that these Chinese hardware manufacturers are hitting is the lack of viable EUV (extreme ultraviolet) fabrication. This is the next generation silicon manufacturing process from ASML and it is extremely hard . I'd really, really recommend reading Chip War by Chris Miller for the full story, but regardless until there is significant progress on this - and by significant progress, I don't mean the reverse engineered prototype in a Shenzhen lab. I mean reliable, scale production.

The industry would be astonished if they got this to scale production before 2030. Bear in mind the Shenzhen prototype hasn't produced a working chip yet, and the more optimistic forecasts have them doing that around 2030 - volume production is a further step beyond it. It took ASML 25 years to figure out this technology - and a good 5+ years of this was scaling it up from the lab to "real" production lines. While China no doubt has incredible engineering talent and the ability to reverse engineer some of ASML's work, it's still a daunting challenge.

Without EUV it is not possible to go (much) below the "7nm" fabrication size. Without being able to go below that size, you quickly hit a wall in thermal efficiency, and you reach a point where you simply cannot make the chip(s) any bigger or faster because you cannot expel the heat quickly enough.

Added to that, the additional export restrictions on HBM memory to China are clearly causing significant issues, hence the strange use of two different home grown memory technologies in the 950-series - no doubt because they can't produce enough fast (which is still comparatively slow ) memory.

These are really the same base constraint - without EUV manufacturing technology you can't produce the latest generations of very fast HBM memory either.

But maybe this doesn't matter?

Clearly the approach China is taking is instead of really looking for solid incremental leaps in compute and memory from better manufacturing techniques, the idea is to build a lot of them. Even if your fastest chips are at best 5 years behind the latest Nvidia GPUs, you can just build 10 times as many for the same overall inference capacity. And it really is roughly 10x - not against the H100 I was comparing to above, but against what Nvidia actually ships today. A Rubin VR200 is somewhere around 35PFLOP/s of dense FP4 with 22TB/sec of HBM4 bandwidth. The 910c is 60% of a four year old H100; Rubin is another order of magnitude past that.

No doubt China is uniquely positioned in being able to do this - with enormous power generation capacity to power this, and huge quantities of skilled engineering and manufacturing labour to build the facilities and cooling required.

But really, it's far from ideal. As models get larger, you have to split them over more and more underpowered sets of hardware. Another problem is it makes the models slow - Z.ai's own API is noticeably slower than Western providers serving the same weights.

The bit I keep coming back to though is power. And here you have to be careful, because 10x the throughput gap is not 10x the power bill - the 910c pulls about 600W against something like 2000W for a Rubin part. Divide the spec sheets and you get a much less dramatic 2-3x on both compute per watt and bandwidth per watt.

But the spec sheets flatter the 910c. 96GB a chip, against the 288GB or more you get on current Western parts, leaves much less room for KV cache, which forces smaller batches, and decode throughput per watt falls away badly at small batch sizes. Add a less mature software stack, and the interconnect and cooling overhead of running 10x the chips, and 5x worse on tokens per watt feels about right to me. If anything that's the charitable end.

Which matters because electricity is usually reckoned to be 10-20% of the total cost of running a GPU cluster, with hardware amortisation dominating. Multiply that by five and power goes from a small component of costs to something like half your total bill. That's fine when you have China's generation capacity and you're happy to treat the difference as a strategic subsidy. It's a lot less fine if you ever want to sell inference into a competitive global market on price.

Small models getting better doesn't rescue this either. They help, obviously - a 30B model serving a task that used to need a 300B one is a real saving. But it's a saving both sides get - that smaller 30B model still runs 10x as fast on Western hardware, so the ratio between Chinese and Western hardware efficiency stays exactly where it was.

And assuming China doesn't have some huge breakthrough in fabrication technology - which as I said before is highly unlikely - it's probable that the gap between Western and Chinese AI hardware will widen if anything.

So, to round up - yes it's an impressive feat that they've managed to do this, but there are some hard constraints on efficiency that are unlikely to be solved any time soon. And yes, China could overcome it by sheer quantity, but it's a subpar solution that has real impact on the speed, capacity and economics of their inference.

Conflating Jews With Israel Is Dangerous – Whether by Antisemites, U.S. Politicians, or the Israeli State

Portside
portside.org
2026-08-29 16:22:06
Conflating Jews With Israel Is Dangerous – Whether by Antisemites, U.S. Politicians, or the Israeli State Dave Sat, 08/29/2026 - 16:22 ...
Original Article

Last week, a federal judge weighed in on whether an alleged assault involving an Israeli flag was antisemitic. The case stemmed from an incident in November 2024, at a CodePink demonstration outside the Dirksen Senate Office Building in Washington, D.C., when a pro-Palestinian protester, Janine Ali, a then-73-year-old Palestinian-American grandmother, allegedly grabbed the Israeli flag that a pro-Israel counterprotester, Kimmara Sumrall, was wearing tied around her neck as a cape. Ali was found not guilty of assault in a criminal trial in May, so Sumrall, with the support of the National Jewish Advocacy Center, then filed a complaint in federal court alleging antisemitic discrimination under civil rights law. In his ruling, U.S. District Judge Trevor McFadden, a Trump appointee, noted that lawyers for Ali argued that “the Israeli flag represents the state of Israel rather than the Jewish race, so her action is merely anti-Israel, not antisemitic.” McFadden, however, rejected the argument that the Israeli flag did not represent Jewish identity, writing , “The Star of David, emblazoned upon the Israeli flag, symbolizes the Jewish race.”

The six-pointed star, called the “Star of David” ( Magen David in Hebrew, literally “shield of David”), has been a Jewish symbol since long before the establishment of the State of Israel. It first became widely used as a distinctive Jewish symbol by European Jews in the 19th century. It came to represent Judaism in the same way that the cross represents Christianity. To this day, just as many Christians wear necklaces with a cross, many Jews wear a Star of David on necklaces as a symbol of their Jewish identity. Some Jews even have tattoos of it (disregarding the fact that Jewish law prohibits getting a tattoo).

The Zionist movement adopted the Star of David at the first Zionist Congress in Basel in 1897 because it had become a popular Jewish symbol by then, and for the mostly secular early Zionists, it had the merit of not being seen solely as a religious symbol (as the late Israeli Jewish scholar Gershon Scholem noted in a 1949 essay in Commentary magazine titled , “The Curious History of the Six-Pointed Star: How the ‘Magen David’ Became the Jewish Symbol”). It was subsequently incorporated into the flag of the State of Israel a few months after Israel’s founding in 1948.

When the Star of David is emblazoned in blue between two horizontal blue stripes on the flag of Israel, it ceases to be just a Jewish symbol. The Israeli flag symbolizes the State of Israel. It has a Jewish symbol on it, but the flag itself is not a Jewish symbol.

More than a dozen Muslim-majority countries have the Islamic crescent on their flags, but that does not make these flags Islamic symbols. For example, Pakistan, officially named the Islamic Republic of Pakistan , has a national flag with a white crescent moon – the symbol associated with Islam – on a dark green background, which is the color associated with Islam. If someone burned that flag at a demonstration against Pakistan, it would surely be offensive to Pakistanis, but it would not be Islamophobic. The same logic applies to the Israeli flag. Both Israel and Pakistan, as well as many other countries, have appropriated religious symbols for nationalist purposes.

Thus, wearing an Israeli flag at a demonstration is not the same as wearing a Magen David necklace. Grabbing an Israeli flag worn as a cape during a demonstration may be considered an act of political violence, but it is not an act of antisemitic violence or discrimination. It is not the same as grabbing a Magen David necklace or knocking a kippa off someone’s head – actions that are equivalent to pulling a hijab off a Muslim woman or a turban off the head of a Sikh man.

Although Israel’s flag is prominently displayed in many synagogues outside Israel, this does not make the flag itself a religious object (nor does the presence of an Israeli flag in a synagogue, typically alongside an American flag, make the synagogue an Israeli institution). To characterize the flag of Israel as a Jewish object because it has a Star of David on it conflates Judaism with Zionism and the Jewish people with the Israeli state.

Unfortunately, such conflation has become all too common. This is one reason, though it is of course not the only reason, why Jews are harassed and attacked by people who hate Israel. In some people’s minds, Jews are proxies for Israel; therefore, they hate Jews because they hate Israel, and they attack Jews because they cannot attack Israel. This is antisemitic and morally reprehensible because innocent people are being collectively blamed and harmed for the actions of a state. The same is true when all Muslims or Arabs are blamed for the actions of terrorist groups such as ISIS and al-Qaeda, which happened frequently in the aftermath of the 9/11 terrorist attacks . It is bigoted to hold all Muslims or Arabs accountable for the behavior of terrorist groups, and it is equally bigoted to hold all Jews accountable for Israel’s behavior.

However, it is important to acknowledge that prejudice is not the only factor at play here. Another factor is that people mistakenly believe that Muslims support Jihadist groups and that Jews support Israel. Some do, but many do not. Although the Islamic State claims to act on behalf of all Muslims, surveys show that most Muslims do not support the Islamic State terrorist group . Similarly, Israel claims to act on behalf of all Jews, but surveys show that most American Jews do not support the actions and policies of the Israeli government and army, particularly towards Palestinians in the West Bank and Gaza Strip (to be clear, I am not equating these actions with those of the Islamic State). For example, in a 2025 Washington Post survey , 61% of American Jews said that Israel committed war crimes against Palestinians in Gaza, and 40% thought that Israel had committed genocide.

What complicates matters in the case of Jews and Israel is that most American Jews have an emotional attachment to Israel (around six in 10 in surveys express such an attachment), and this attachment is a product of their Jewish identity. They care about Israel, which, it must be stressed, is not the same as supporting everything it does. Moreover, major Jewish organizations and mainstream institutions frequently publicly emphasize this attachment, and they increasingly insist that supporting Israel or being a Zionist is an integral, core element of Jewish identity. This effectively encourages non-Jews to believe that all, or at least the overwhelming majority of, Jews support what Israel does and identify as Zionists. However, surveys indicate that this is not the case. For example, in a June 2026 national survey of Jewish Americans , only 36% said that “supporting Israel” is important to their Jewish identity (whereas 73% said that “remembering the Holocaust” was, and 43% said “celebrating Jewish holidays”). In another survey of American Jews conducted in March 2026 , 87% believed in “Israel’s right to exist as a Jewish homeland,” but only a third (34%) actually considered themselves Zionists, while nearly half (48%) said they were not Zionists and another 17% were unsure (Orthodox Jews and Republicans were most likely to call themselves Zionists, whereas Reform Jews, Democrats, and younger Jews were most likely to say they were not Zionists).

It can be easy for people to conflate Jews with Israel, and this conflation has led some people to harass, attack, or discriminate against Jews. Such actions are undoubtedly antisemitic and deplorable, but they are increasingly happening nowadays because so many people are appalled by what Israel has done in Gaza and what it is doing in the West Bank. To acknowledge this obvious fact is not to excuse or justify antisemitic behavior or blame it solely on Israel, let alone on the victims of this behavior. The people engaging in antisemitic behavior are morally responsible for their behavior. However, we cannot prevent this kind of antisemitic behavior if we do not understand what can cause it. Israel is becoming a global pariah , so associating all Jews with Israel can make Jews pariahs and potential targets for those who hate Israel. Whether this association is made by the Israeli state, Jewish organizations, or antisemites, the effect is essentially the same: Jews are conflated with Israel, and the outcome of this conflation is harmful and dangerous for Jews.

I am not advocating, as Hasan Piker recently did , that Jews living outside Israel should disassociate themselves from Israel in order to be safe. Jews are entitled to have an attachment to Israel. What I am advocating is the need to draw distinctions between Jews and Israel and between Judaism and Zionism. Blurring these distinctions, as Judge McFadden did in his recent ruling and as Jewish establishment organizations and the Israeli state do, does not protect Jews; it endangers them.

Dov Waxman is the Rosalinde and Arthur Gilbert Foundation Professor of Israel Studies at the University of California, Los Angeles (UCLA). He is also an honorary research fellow at the Birkbeck Institute for the Study of Antisemitism. New book out in January 2027: "The Question of Antisemitism: A Guide for a World Divided by Israel-Palestine" (Princeton University Press).

Welcome to Zeteo , where independent and unfiltered journalism is making its comeback. Founded by award-winning journalist, best-selling author, and all-round troublemaker Mehdi Hasan, Zeteo – which comes from the ancient Greek word for ‘seeking out’ and ‘striving’ – is a new media organization that seeks answers for the questions that really matter, while always striving for the truth.

The Only Kill Switch We’ve Got

Portside
portside.org
2026-08-29 16:08:12
The Only Kill Switch We’ve Got Dave Sat, 08/29/2026 - 16:08 ...
Original Article

Several weeks ago, Jason Kelce (football player, podcaster, Taylor Swift’s brother-in-law) starred in an ad asking Americans to pee in jars and send them to their nearest AI data center. The spot – a collaboration between Liquid Death and Kelce’s own Garage Beer – was nominally about water consumption. Mostly, though, it was evidence that hating on data centers has gone fully mainstream.

The polling backs this up. The University of Pennsylvania’s Annenberg Public Policy Center found that opposition to local data centers jumped twelve points in four months this year – from 49% in March to 61% in July. And an August Heatmap Pro poll pushed the number to 75% , with more than six in ten Americans strongly opposed – the most negative result since the outlet began tracking the question a year ago.

Americans are wary of AI data centers, and politicians have taken note (much faster than they usually do). In July, New York Governor Kathy Hochul imposed the country’s first statewide moratorium . Weeks later, Republican Texas Governor Greg Abbott – a longtime data center recruiter – paused new grid connections pending an audit . And just this month, Pennsylvania Governor Josh Shapiro – who celebrated Amazon’s data center investment as recently as last year – signed an executive order marketed as the nation’s strictest guardrails on the industry.

But while opposition to data centers grows, the labor movement remains divided, for obvious reasons. The data centers are creating jobs (at least, right now), while AI threatens to eliminate jobs in the future. And those jobs largely belong to different sets of people.

The Building Trades

So far, the building trades have been supportive. In May, IBEW urged its members to lobby Congress against any ban on data center construction. Several weeks ago, Don Slaiman of IBEW Local 26 took to the New York Times to argue that data centers have delivered tens of thousands of well-paid blue-collar careers, and that communities should be welcoming them. It’s not hard to see why. Data centers now account for 2.3% of all US construction spending, and spending has more than quadrupled since 2020.

Believe it or not, tech companies often use union labor on their projects (despite their best efforts not to; I wrote recently about Meta’s attempts to skirt union labor in data center construction). An Associated General Contractors survey estimates that data center construction is about one-third union, which is three times the construction industry’s overall union rate. And according to reports from the trades (so take it with a grain of salt), this is growing. Union locals report doubling apprentice classes and expanding training centers to keep up with demand, and North America’s Building Trades Unions (NABTU) hit record membership in 2025. In March, NABTU announced partnerships with OpenAI, BlackRock, and Meta; in April, NABTU signed a labor agreement with OpenAI and Oracle to build the multibillion-dollar Stargate campus. Roughly 700 union tradespeople are already working on the site in Michigan, with thousands more expected to join.

The leaders themselves aren’t shy about praising the job opportunities proffered by data centers. Robert Wilson of IBEW Local 7 in western Massachusetts described a proposed hyperscale facility as “a generational type project for our geographical area.” “At a time when educators are asking young people to consider the building trades over college,” he told me, jobs like these “could enable many young workers the ability to save for a down payment on their first home.”

Rob Bair, president of the Pennsylvania State Building and Construction Trades Council, made the same case: data center work “has allowed members steady employment with overtime work which allows them to live the middle-class lifestyle,” plus union-managed healthcare and a real pension waiting at the end. And Dan McConnell, business manager of the Minneapolis Building and Construction Trades Council, told me his members “take pride in building the infrastructure that keeps Minneapolis competitive.”

Unions Against Data Centers?

And still, there is another wing of the labor movement that wants to pump the brakes. National Nurses United formally endorsed the Sanders-AOC AI Data Center Moratorium Act. NNU co-president Jamie Brown called the unchecked growth of data centers “a public health crisis, an environmental crisis, and a workers’ rights crisis.” The American Association of University Professors endorsed the bill too. And the opposition runs deeper than national endorsements. Thomas Meyer – deputy political director of Food & Water Watch, which organizes against data center projects – rattled off local examples: a teachers union and UNITE HERE local in Seattle (UAW 4121 later joined), CWA locals in New Jersey, UNITE HERE in Philadelphia.

Caught in the middle are some of the labor movement’s most prominent leaders. Association of Flight Attendants-CWA president Sara Nelson stood with Sanders and expressed support for a slowdown , but AFA hasn’t formally endorsed the moratorium bill. American Federation of Teachers president Randi Weingarten stood at the same Sanders press conference, and then announced that her union does not officially support the moratorium. Two of the most recognizable leaders in American labor were willing to stand behind Bernie Sanders at a podium, but not behind his bill.

Colorado state senator Cathy Kipp has had a front-row seat to this divide. She recently proposed a bill regulating data center construction. The bill drew opposition from construction unions like the pipefitters and the IBEW; some derided it as the “Wyoming Jobs Act.” As in, the jobs would flee 40 miles north to Cheyenne. The state AFL-CIO opposed the bill too – though Kipp says the federation had factions pulling in different directions.

Her bill died several months ago. Since then, she told me, the conversation has shifted. At a conference earlier this summer in which local leaders were expressing support for new data center construction, Kipp stood up and cited a poll showing 91% of Coloradans want guardrails on data centers. “You guys cannot put me in the position of: is it you or my constituents?” she recalls telling the room. Several other legislators echoed her. Afterward, several labor leaders came up to thank her. Privately. “Some of them might be more nervous about saying it publicly, but it’s changing. A lot of people understand that their jobs are potentially going to be replaced,” she says.

To be clear, this has not turned into any kind of inter-labor war. At least, not publicly. Even Meyer – who professionally organizes against data center projects – told me he has “no quarrels with a union or any other organization working on behalf of their members.” McConnell, from the other side, expressed a similar sentiment: he respects the unions that support moratoria. In his words: “this should not be framed as one group of unions against another.”

In fairness to McConnell, when I began this research, I wondered if that’s what I might find. But I didn’t. The union leaders who support data center construction are about as wary of AI as the rest of us. But they’re also up against cratering public opinion, combined with some misinformation.

Consider the belief that AI data centers consume inordinate amounts of water – an idea so memed it made its way into a Jason Kelce ad. Wilson described a city council meeting in Westfield, Massachusetts, where a city councilor gave a presentation arguing that a proposed facility would destroy the aquifer beneath the city. The facility in question would be cooled by a closed loop of glycol – the same fluid, recirculating indefinitely – and wouldn’t draw water from the aquifer. When the public was invited to comment, “the developer for the proposed data center tried to address the concerns with water but the council president immediately shut him off and said the discussion could only be about the moratorium,” Wilson told me. “As an observer at the meeting it appeared the one year moratorium was going to be pushed through without allowing any debate.”

Wilson is correct: the concerns about water consumption are often overstated, though not negligible. The most widely cited estimate , from Lawrence Berkeley National Lab, puts data centers’ total water consumption at roughly 230 billion gallons in 2023 – a figure that includes the water consumed by the power plants feeding them, which is most of it. This amounts to less than 1% of national water consumption. As Robin Gaster of the Information Technology and Innovation Foundation wrote in July: “there is no universal national water problem.” The concern, of course, is that the number is growing, and that some areas are higher risk than others. We certainly cannot write off the concerns about AI’s water usage. Still, given how far the water consumption idea has spread, it’s understandable why a union head in an area that’s not at risk for drought would be frustrated.

Wilson also called worries about bright lights and heat islands “nonsense” (data centers, he noted, are windowless warehouses full of servers). McConnell made the same point: many of the impacts people fear – water consumption, noise, higher utility rates – are design choices, not inevitabilities, which is exactly why he wants enforceable standards. In his words: “Strong rules do not block good projects. They help us identify which projects are actually good.”

Several leaders also noted that data centers face an unfair critique about their impermanence. Construction work is, by nature, temporary. Nobody faults a hospital because the people who built it were eventually out of a job. As McConnell told me: “Lawyers, consultants and many other professionals build stable careers by moving from project to project; the building trades are no different.”

Support for Regulation

At the same time, the labor leaders I spoke with were hardly AI cheerleaders. Bair’s working groups in Pennsylvania are negotiating agreements to limit AI in call centers, hospitals, and classrooms. In his words: “We realize there is a time and place for AI but not at the expense of employees. AI is accelerating the displacement, but we’ve seen it coming in many shapes and forms.” McConnell told me his members raise concerns about AI, but that he doesn’t think moratoria are the solution. “Stopping construction by itself does not create an AI policy or protect workers from automation.” Even his members’ support for the buildout has limits, he was careful to add: “enthusiasm does not mean blind support.”

It’s important to mention that their skepticism collides with a lack of options. The federal government has spent decades declining to seriously invest in our country. Biden’s Bipartisan Infrastructure Law was a partial step, but it was nowhere near enough: even after it passed, the American Society of Civil Engineers still projected a $3.7 trillion gap over the next ten years between planned investment and “a state of good repair.” And that assumes current funding levels hold; the law’s authorizations expire in 2026. There is no New Deal on offer to employ the trades for a generation.

And so, the trades are stuck in an impossible position, one they’ve been in before. In a sense, none of this is new. Emergent technology often requires a significant upfront labor investment while threatening jobs in the long run. In the words of Todd Vachon, a labor studies professor at Rutgers: “Any legislation that phases out one form of technology in favor of another is going to draw opposition from the union supporting the technology being eliminated while the union representing workers manufacturing the new technology will be supportive of it.” Anne Lofaso – a law professor at the University of Cincinnati – cited coal as “a very tight analogy.” The well-paid union mining jobs were always partly myth: many weren’t union, many weren’t safe, and the jobs disappeared as the technology improved. “Data centers are similar,” she told me: a promise of good union jobs, hazards for the workers, environmental costs for the communities making the greatest sacrifices.

But there’s only so far historical analogies can go. In Vachon’s words: “What feels different with AI is that this friction is pretty broadly felt and breaks labor into two distinct categories of who is and who isn’t threatened by AI and it mostly falls along the line of blue-collar vs white-collar workers.”

Vachon hit upon something that’s always bothered me about the data center backlash. Technology – almost by definition – has always replaced jobs. And for centuries, the professional class largely filed it under progress. Inevitable, even. But now that the automation is coming for people who went to college, pausing it has become a mainstream idea. If lawyers were asked to give up a decade of work to protect electricians’ jobs, would they? History suggests probably not.

That doesn’t mean we don’t need a pause. But construction isn’t the root of the problem. The root of the problem is AI. People don’t like it, don’t trust it, and don’t know what it’s going to do to our society. Data centers have existed for decades; we don’t see widespread protests outside a hospital’s server room (the erroneous conflation of all data centers with AI data centers was cited by multiple union leaders). In the same Annenberg survey, 68% of Americans said the government has done “too little” to regulate AI. A July Emerson College poll found 63% of voters concerned about AI, versus 14% excited. For Meyer, the reason so many workers oppose data centers – including, per one recent poll, a majority of union households in New York – comes down to AI itself. Specifically, who gains and who pays. “The benefits are so concentrated and the costs are so massive,” he told me. “People don’t like big tech billionaires trying to bully or bribe to get what they want.” The people he talks to “feel like AI is being forced on all of society,” and see fighting data centers locally as “the best way to make an impact and exert some agency.”

People are scared of AI, and we’re so far away from even the most basic regulation. In July – just days after OpenAI disclosed that two of its models escaped a testing environment and hacked another AI company (cool!) – Congressmen Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the bipartisan AI Kill Switch Act, which is exactly what it sounds like: a requirement that the most powerful AI systems be built with an off switch. Imagine Ford trying to sell a car without a brake. I generally hate the term “common-sense regulation” (who doesn’t think their own ideas are common sense?), but come on. This is common sense. A month later, the bill has gone nowhere . It’s challenging to even talk about AI without answers to basic questions like “How do you turn it off?” “Is it a bubble?” “Will it tank the economy?” “Will it channel wealth exclusively to the top 1% while everyone else suffers?” “Will it kill us all?” AI regulation is about far more than just the existential threat: it’s also about whether it will perpetuate America’s destructive and expanding economic inequality.

There is no mystery about why we haven’t yet regulated the AI companies directly. In what I believe will be remembered as the most iconic image of Trump’s second term, tech CEOs lined the second row of his inauguration, ahead of his own incoming cabinet. They had paid for the view, a million dollars apiece to the inaugural fund, and the corruption has only continued since then. The return on investment has been excellent. Republicans tried twice to attach a ten-year moratorium on state AI laws to must-pass legislation; when Congress wouldn’t cooperate, Trump signed an executive order directing the DOJ to challenge state AI laws and threatened to withhold federal broadband money from states that regulate the technology. The federal government is not merely declining to put guardrails on AI; it is actively dismantling the ones states try to build.

We are a country understandably scared of AI, with a federal government unwilling to regulate it. And so, we’ve found the only available option: halting the AI data centers. It’s a smart strategy: stopping construction is famously easy in America, just ask Ezra Klein. Unlike regulating Trump’s buddies, it’s working: in the first quarter of this year alone, community opposition blocked or delayed at least 75 data center projects worth roughly $130 billion, about as much as all of last year combined. The industry is expanding fast enough that record construction and record obstruction are happening simultaneously. And public opposition keeps climbing, as support for a moratorium grows.

But it’s worth getting specific about what a moratorium entails. The Sanders-AOC bill would freeze construction of new large AI data centers until the government passes federal AI guardrails. And I definitely support those guardrails (I would go so far as to call them “common sense”), but we should be honest: realistically, that isn’t happening before January 2029. Under the proposed moratorium, existing facilities would keep running, and the white-collar workers at Anthropic and OpenAI would carry on. The pause lands entirely on the people who build. In short: construction workers are being asked to pay for the sins of Sam Altman, because the government is too corrupt to regulate him directly. McConnell calls the moratorium “a very blunt instrument,” and he’s right. The question is whether anything sharper is available.

A Kill Switch

I’m torn myself. I understand the building trades’ position, and I understand what a national moratorium would mean for their members. But I’m also very uneasy about AI, and I see the argument for using anything in our toolkit to slow it down, blunt or not. In Lofaso’s words: “As someone who likes to see scientific progress, I would like to see unions negotiate job retraining, social assistance, etc. But AI feels different and potentially more dangerous. I wish we could have a moratorium just to think through the ramifications of AI and how to create safe AI and protect workers and their jobs.”

Still, I found cause for hope. The version of the fight that ends well is already underway. The trades are asking for guardrails themselves. Bair’s council backed the principles behind PA Governor Josh Shapiro’s order regulating data center construction. Wilson wants rates and water regulated by law, not by promise. McConnell wants project labor agreements, ratepayer safeguards, and enforceable community benefits. The tech companies had a better chance of skirting union labor before their popularity cratered: our AI overlords are now on their back foot, scrambling to get communities and elected officials to support data center construction, which means it’s the ideal time for the labor unions to make demands – about safety, job protection, profit distribution, and more.

Vachon suggested something similar: that labor exchange its support for guardrails. In his words, they would say: “We’ll only build these if we can be reasonably assured they won’t kill us.” That sounds good to me; I would prefer AI not kill us all. I don’t want to suggest that communities should stop fighting unwelcome data centers. But union leadership can be an important ally in this battle, even leaders who don’t support a moratorium. This Congress appears unwilling to pass a bill requiring AI to come with an off switch. But the trades control something the industry can’t route around: whether the infrastructure gets built. Right now, that’s the closest thing to a kill switch this country has.

Ginny Hogan is an NYC-based writer. Her new book, "Obey in Advance," co-written with Carlos Greaves, is out in September.

Subscribe to Labor Politics

By Eric Blanc · Launched 4 years ago

Working-class organizing and politics

Highest-ever ocean temperature measured as powerful El Niño forms

Hacker News
www.latimes.com
2026-08-29 19:26:44
Comments...
Original Article

Scientists have recorded the highest temperature ever measured in the world’s oceans, as climate change combines with a powerful El Niño in the tropical Pacific.

The global average sea-surface temperature hit a record 70 degrees on Aug. 22, according to Europe’s Earth observation agency Copernicus, which has been tracking the metric daily since 1979. The previous single-day record was measured in March 2024.

“El Niño is adding heat to the system, but it is doing so on top of decades of human-driven warming,” said Samantha Burgess, strategic lead for climate at Copernicus’ European Center for Medium-Range Weather Forecasts.

“As ocean temperatures continue to rise, the risks to marine ecosystems and coastal communities also increase,” she said.

Higher ocean temperatures contribute to sea level rise and increase the chance of extreme weather events, as warmer water transfers more heat and moisture to the atmosphere, intensifying storms and heat on land. Warmer oceans also have a reduced capacity to absorb carbon dioxide.

Record temperatures have already been measured in isolated areas of the world’s oceans including the western Mediterranean Sea as well as at the Earth’s poles, driven mainly by human-made climate change. Copernicus expects the trend to continue, with ocean temperatures now being supercharged by El Niño.

The August record is particularly worrying because global ocean temperatures are typically highest in March and April, after the Austral summer, Copernicus said.

Millan writes for Bloomberg.

More to Read

Police departments weren’t looking for Flock abuse. We did it for them.

Hacker News
www.washingtonpost.com
2026-08-29 19:22:42
Comments...
Original Article
Timed out getting readerview for https://www.washingtonpost.com/technology/2026/08/19/we-found-cops-who-misused-flock-their-police-departments-didnt-know/

Lawmakers added $1 to car insurance policies. That money paid for Flock cameras

Hacker News
www.texastribune.org
2026-08-29 19:17:17
Comments...
Original Article

Audio recording is automated for accessibility. Humans wrote and edited the story. See our AI policy , and give us feedback .

In 2023, the Texas Legislature unanimously passed a law raising auto insurance costs for Texans by $1 to combat rampant catalytic converter theft.

Three years later, a little-known state agency has devoted at least $30 million of that fee toward supercharging the state’s Flock surveillance network, placing cameras along highways and streets from El Paso to the Louisiana border, an analysis by The Texas Tribune found.

The Motor Vehicle Crime Prevention Authority, led by a board mostly appointed by Gov. Greg Abbott , has turned the $1 fee hike into at least 3,200 Flock cameras.

The agency has awarded no fewer than 95 grants to help law enforcement agencies purchase and maintain about 2,000 Flock cameras. Another $15.9 million is helping the Texas Department of Public Safety add almost 1,200 more.

The effort is far from over. In early August, the agency approved another $3 million to help DPS install 583 more cameras along Texas tollways over the next year.

Miguel Rodriguez, chair of the Motor Vehicle Crime Prevention Authority, said during an August 2023 meeting that he hoped to use proceeds from the fee increase to “cover the entire state” with cameras.

Rodriguez, who is also the Laredo Police Chief, sees the cameras as a powerful law enforcement tool, particularly to combat criminal organizations.

“That kind of capability directly disrupts the operational advantage these transnational criminal organizations rely on, and it strengthens our ability to protect both Texas communitiesand the broader region,” he said in an email.

But on Friday evening, after multiple requests for comment from the Tribune about its findings, Abbott’s office said the governor was pausing all state funding for local grants to be used for Flock cameras.

“To the extent that cities get any funding for those cameras, most of it comes from the federal government. To the extent any funding comes from Texas agencies, those agencies are clarifying that those funds cannot be used for Flock cameras,” Abbott spokesperson Andrew Mahaleris said in a statement shared first with the Tribune.

The $1 per year fee increase has raised an estimated $81 million, allowing the authority to funnel $50.8 million into 234 grants that have helped reimburse police departments for officers, crime analysts and attorneys to prosecute vehicular crimes, as well as drones and other surveillance devices.

The Tribune found agency grants to police departments ranged from $7,000 for two Flock cameras in Bellmead, near Waco, to almost $1.7 million for 201 cameras in Dallas. Some city networks — like the 165 cameras in Laredo and 150 in El Paso — were entirely subsidized by the grants.

The state agency does not detail how much of its grant money went to Flock cameras. Instead, the Tribune tracked the grants by reviewing the vehicle authority’s meeting records, as well as documents, agendas and discussions from 101 city councils and county commissions that approved or discussed Flock-related grants.

It is likely the authority has paid for more Flock cameras than the Tribune analysis found because 124 grants lack clear public documentation about what was purchased.

The statewide effort to proliferate Flock cameras comes as backlash is mounting over the surveillance, including from some members of the Legislature, where the $1 fee was approved without opposition.

“The sheer volume of information captured is not something that is entertained, in my view, by the Fourth Amendment,” said Rep. Mitch Little, R-Lewisville.

State Sen. Carol Alvarado and Rep. Jeff Leach, the bill’s author and House sponsor, said surveillance cameras were never discussed when the bill was considered. Alvarado said she was surprised to learn from the Tribune that the insurance fee was funding AI-supported license plate readers.

“I did not have that in mind when we passed the bill,” said Alvarado, D-Houston. “When I think of combating crime, I’m thinking … more boots on the ground, hiring more officers to tackle the crime or some type of undercover work.”

Alvarado said there is a “fine line” between protecting the public from crime and protecting people’s privacy, but said she did not plan to file legislation to shift the grant requirements.

Flock cameras, the nation’s most commonly used license plate reader, create a “vehicle fingerprint” with the use of artificial intelligence — storing each vehicle’s license plate, make, model, color and details such as dents and bumper stickers in a database accessible by law enforcement across the country without having to obtain a search warrant.

The exact number of Flock cameras in Texas is unclear. DeFlock, an anti-surveillance watchdog that has mapped the locations of Flock cameras using verified crowdsourcing, has identified about 13,000 in the state. By that count, the insurance fee increase has paid for one in four Texas cameras.

That also represents a sharp increase in Flock cameras in the state since December 2023, when a company spokesperson told the vehicle authority’s board that there were about 7,500 cameras in the state.

Flock does not disclose how many cameras it has in the field, but Texas is estimated to have the second most in the nation, after California. Nationally, Flock officials say, about 7,000 law enforcement agencies use a total of 120,000 cameras and other surveillance products.

In Texas, state agencies don’t rely solely on vehicle authority grants to add surveillance devices, and Abbott’s office pointed to federal grants for funding the cameras. DPS, for example, has a $28.5 million contract for Flock cameras. But the grants have helped get the cameras into the hands of the state’s smaller police departments that may have struggled with the cost of the equipment.

Departments that opt in to Flock’s national lookup program can search each other’s data from anywhere in the country, allowing vehicles to be tracked with unprecedented efficiency.

The ability to share data “has been one of the most effective ways Flock has been able to help find, just last year, over 10,000 missing persons,” Flock spokesperson Trevor Chandler said in an interview.

But for a rapidly growing coalition of Texans opposed to the cameras, the Flock network is a dangerous combination of invasive surveillance and limited oversight that undermines privacy rights.

Kenneth Feagins, an organizer with DFW DeFlock, one of several new grassroots anti-surveillance groups in the state, said he sees an “alarming trend” of police improperly accessing a network that can amass data on where people live, shop, worship and work.

“For me, it’s always been the question of, well, how much liberty are we willing to trade for safety?” Feagins said.

Recently revealed examples of misuse — including police officers using Flock data to stalk ex-partners and co-workers — have sharpened those concerns.

A Lufkin officer was indicted Aug. 24 on 100 counts of misusing official information, which Abbott cited as a concerning development during a Friday radio interview. Officers in Baytown, Harris County, Fort Bend County, Temple and Pasadena also have been arrested, disciplined or investigated.

“There’s a lot of malicious things that can be done with this data, and those things are no longer hypothetical,” Feagins said.

Cameras “changed the game” for police

The Motor Vehicle Crime Prevention Authority was established by the Legislature in 1991 to combat automobile theft.

The authority is led by a DPS official and six governor-appointed board members — two from law enforcement, two from the insurance industry and two consumer representatives.

The vehicle authority primarily flexes its muscle via grants funded by fees added to annual auto insurance premiums — $1 initially, rising to $2 in 2011 and $4 in 2019 — that largely went to fund task force efforts for police departments.

In 2023, with catalytic converter theft spiking across Texas, lawmakers approved adding another $1 to the insurance fee in a bill named for Harris County Deputy Darren Almendarez, who was shot to death after interrupting catalytic converter thieves in a grocery store parking lot.

The legislation made no reference to license plate readers, and Rep. Brian Harrison, who voted for the bill, said he wasn’t aware of any conversations about using the fee increase that way. The Midlothian Republican filed bills that year and in 2025 to require a warrant before police could access license plate reader data.

“In a million years, I never could have even contemplated that this would be used to fund what is effectively warrantless surveillance,” Harrison said. “Otherwise, I can’t imagine it would have gotten unanimous support. I sure as hell wouldn’t have voted for it if I knew some bureaucrat was going to redirect the money to Flock cameras.”

Anticipating millions from the $1 insurance fee hike, the vehicle authority in 2023 asked law enforcement for advice on how best to spend the money. Automatic license plate readers like Flock cameras were by far the top choice for combatting catalytic converter theft, beating out overtime for investigators and additional training.

The cameras, Rodriguez said, are particularly helpful for addressing catalytic converter theft, a “mobile, high-volume, low-witness crime” where the vehicle used is often the only lead.

Without technological help, departments were left working with partial descriptions taken from grainy surveillance footage of suspect vehicles, Rodriguez said.

Data from the license plate readers, known in law enforcement as LPRs, was searched 62,000 times in 2025, leading to about 1,660 cleared catalytic converter theft cases, a report from the authority said.

Pasadena Police Sgt. Douglas Buckert said the cameras “changed the game” for catalytic converter theft investigations.

“The number of leads we’ve gotten since our department has deployed Flock cameras is outrageous,” Buckert told the authority in early 2024 . “I could have six more investigators and not get it all done.”

Grant-funded cameras, much more than other technology, have also expanded the reach of police in investigations far beyond catalytic converter cases, department officials say.

Dallas Police Sgt. Bryan Roden told board members during a January meeting that an authority grant let his department increase its network from 100 to 300 cameras, helping to bust a million-dollar tire theft ring and solve a hit and run. Working with the Department of Homeland Security, Dallas police located a fugitive wanted for cocaine manufacturing by using Flock cameras he regularly passed to build a “pattern of life assessment,” Roden said.

Temple Police crime analyst Mike Treehern told the Tribune that the cameras helped decrease the number of stolen vehicles in his city, where 84% of their Flock cameras are funded by the state grant.

“It’s absolutely helped us, and we would not have anywhere near the amount of cameras that we do without [vehicle authority] funds,” Treehern said.

The grant has also been a force multiplier for smaller departments. In Cibolo, a city north of San Antonio with a population of 36,000, an authority grant multiplied the number of Flock cameras from 11 to 52.

“Honestly, a lot of our surrounding communities started looking at them, specifically through the [Motor Vehicle Crime Prevention Authority],” Cibolo Police Lt. John Wells told board members in a January meeting . “Seguin was looking at them, Guadalupe County, the New Braunfels Police Department, all of our neighbors, so we started looking as well.”

Hannah Foust, founder of DeFlock Carrollton, said the cameras give police surveillance power well in excess of what’s needed to stop car thieves.

“I do think that motor vehicle theft is a concern, it’s an issue,” Foust said. “[But] I do think that this grant program, and the way it’s been used … it really shifts the focus to a broader surveillance program, as opposed to focusing on catalytic converter prevention.”

$1 fee hike helped DPS expand its Flock network

The authority’s most significant investment in Flock came in 2025 when it signed a three-year, $15.9 million contract with DPS to install 1,183 cameras in a project largely overseen by DPS Major Sharon Jones, the board’s self-described “pro Flock” member who left the position Aug. 1.

The contract aims to bolster DPS’ network of cameras and make it accessible to local law enforcement agencies in places that otherwise could not be easily reached — including local municipalities that are resistant to the surveillance.

Patrick McBroom, police commander for the Panhandle Auto Burglary and Theft Unit, said DPS cameras help his task force monitor interstate traffic at the Oklahoma and New Mexico borders — areas of Texas beyond the view of 138 grant-funded cameras his team monitors.

“All those roads leading out and into Texas have DPS cameras on them, so if we have stolen items that may be going out of state, we’re able to look at those cameras to see if those vehicles have left the state,” McBroom said.

During an April conversation about the DPS contract, Rodriguez noted the state police force’s cameras could improve surveillance in areas where locals are unwilling to install their own cameras. A growing number of cities and counties, including Austin, have canceled their Flock contracts in the face of residents’ privacy concerns.

“I think that if for whatever reason you are within those jurisdictions that do not want Flock, let’s get together with DPS, [so] that, you know, we can put those in state right-of-way. And there’s nothing that they can tell us,” Rodriguez said to Jones.

Rodriguez told the Tribune that the DPS network provides a needed crime-fighting tool in areas hostile to Flock cameras and similar devices.

Almost 100 municipalities in the U.S. have ended their Flock contracts in response to public outcry, including several in Texas, such as Bandera and Hood County . Both had received grants for their cameras but ended their contracts after issues with Flock installation and in response to public uproar over their use.

As criticism over the cameras has exploded — including devices that were cut down or vandalized as acts of protest — agency board members have expressed frustration at what they see as misinformation that clouds the positive impact from the cameras.

“We’ll have a larger conversation regarding the need to educate the public, and we must put a stamp on those who are spreading false information on license plate readers,” Jones said in a July grant meeting.

“A concern for our privacy”

Foust started Carrollton’s DeFlock group after her neighbors expressed frustration at the cameras’ rapid spread. Spotting a camera along the route her children walk to school gave her pause; seeing one go up in front of her community recreation center made her act.

“You can’t enter or exit that complex without passing a Flock camera, and that’s also my polling place, so that really gave me a strong reaction,” Foust said. “They were in places that we normally feel very safe at, and there’s no concerns for our safety, for our children’s well-being, but there suddenly was a concern for our privacy.”

Foust is open to discuss a variety of solutions to her concerns, including action by the Texas Legislature, but said the first step is getting city officials to be transparent about their use.

“I think before we can have a true and honest conversation about what legislation might look like or what guardrails or safeguards could be put in place, I think we need to start on a level playing field of understanding,” Foust said. “What is the system, what is it capable of, and how could it be set up in a way that’s supposedly safe?”

Harrison and Little said they intend to file bills next legislative session banning the devices because they believe the cameras violate the Fourth Amendment’s protection against unreasonable searches. Little said he’s particularly concerned about whether vast amounts of personal data is securely stored and whether Flock, a private company, should be able to access it.

“The people in Lewisville, Texas have a reasonable expectation of privacy from police officers in Pampa, Texas, and yet they can observe all that data,” Little said. “So the sharing of it across state lines, across jurisdictional lines, to me is highly problematic.”

Harrison said he was “shocked and dismayed” that so few Republicans had spoken out against Flock cameras and what he calls blatant constitutional violations. He also said state officials should take more immediate action to “shut off” Flock grants because legislators never intended to use the insurance fee increase for cameras.

“I think the Legislature shouldn’t take this sitting down. I think the governor should act on this,” Harrison said. “If that’s happening, what that means is there’s clearly no explicit legislative intent or direction for that to be happening.”

I co-founded Burning Man. The festival has lost its soul

Hacker News
sfstandard.com
2026-08-29 19:12:25
Comments...
Original Article

Burning Man won’t let go of me. As one of the three founders of the festival, I am constantly approached by journalists and documentary crews, podcasters, and the odd publisher hoping to make a book about the festival I helped invent 36 years ago. Curiously, I get this interest even though I haven’t set foot in the Black Rock Desert since 1996.

Everyone wants the same story: how a bunch of pranksters in San Francisco jumped into a bunch of janky vehicles headed for the desert, hauling weird props and camping gear and the components of a huge, man-shaped wooden figure, and accidentally built one of the most famous festivals on Earth.

For years after I left, I avoided talking about Burning Man — I’d moved on to other things. But people keep asking, so here’s what I’ll say: What it became makes me a little sad.

I won’t pretend that Burning Man isn’t fun. My friends who are still involved share their pictures and videos, and old-school crews still carry some of the OG punk-industrial flavor.

But the festival is barely recognizable from what we made. Burning Man has lost its anarchist soul.

A large mechanical figure made of metal is walking on stilts, while a person nearby appears to be holding a flame in a dark setting.
Suicide Club cofounder David T Warren lights the burning man on fire in the Black Rock Desert in 1990. The first year’s festival had around 80 attendees, most of whom slept on the desert floor in sleeping bags. | Source: Photo by Judy Kokura

Today’s event is a massive, kaleidoscopic extravaganza for the senses — a phantasmagoric, immersive spectacle built for the consumption of Western elites and the middle-class creatives who service them. It is a carnival. A fabulous Disneyland for the well-heeled, all the while presenting itself as a serious artistic enterprise grounded in philosophical principles. You can buy into luxury camps with private chefs and have a stylist curate your outfits (opens in new tab) . You can fly in on a chartered plane (opens in new tab) . It’s become a commercialized escape hatch — a week when anyone with enough money can leave their real life behind entirely.

Early Burning Man wasn’t a ready-made escape you could buy your way into. It was an anarchistic collaboration of equals, conjured into being by a few hundred people of goodwill, far from anyone’s control. Nobody owned it. No one person directed it. There was no official ideology or set of principles handed down from above — just a group of people powerfully, if unknowingly, attuned to the exact moment they were living through. It wasn’t an escape from reality. For those few days, it was realer than real.

The anarchist roots: How we conjured Burning Man

San Francisco has always been a place people came to re-create themselves — running from something, running toward something exciting and unknown, going as far as they could for a shot at a new life. As Oscar Wilde put it: “It‘s an odd thing, but anyone who disappears is said to be seen in San Francisco.”

I was no different. I arrived as a teenager in 1976, determined, like so many seekers who landed on the Left Coast to start life anew, to re-create myself.

The region’s mythic attractions — sex, drugs, rock ‘n’ roll, and an uncritical habitat — bred an intensely collaborative scene free of the snobbery of East Coast art markets, where any idea could fly as long as it carried passion and transgressive appeal. Our influences were Dada (opens in new tab) , surrealism (opens in new tab) , adventure fiction, extreme cinema, Mad Max, Lawrence of Arabia, the Beats, the hippies, the punks.

Out of that came a run of organizations and cabals. One of them, the Cacophony Society, grew out of the earlier, more secretive and transgressive Suicide Club, which staged pranks, urban explorations, and stunts (naked cable car rides, bridge climbs). The Cacophony Society was itself barely an organization — simply a newsletter of events its members dreamed up. But it became the cradle Burning Man leapt from.

There was no way to make a business out of it. It was antithetical to structure and hierarchy — a simple, beautiful concept for people to come together and create.

“Confederation” is a good word for it — the kind of temporary, self-organizing gathering Hakim Bey had already detailed in his writings, calling the phenomena a Temporary Autonomous Zone (opens in new tab) . Small cabals of artists and free spirits would converge somewhere beyond ordinary control, collectively conjure a world in which they could do anything , then pack it up and vanish before the agents of control could squash it flat. Bey’s later writings on “pirate utopias” off the coast of Africa and in the Caribbean in the 17th century mirrored Burning Man’s earliest years.

In 1988, artists Carrie Galbraith and Phil Bewley launched Cacophony’s “Zone Trips”: whim-driven expeditions to strange corners of the world — never dressed up as culturally important, just collaborative adventure for its own sake. The first went to Covina and the greater L.A. basin, where the itinerary memorably included a two-hour drive to the Shields Date Garden to drink date shakes and watch a 30-minute promotional film called “The Romance and Sex Life of the Date.”

A shirtless man wearing sunglasses sits next to a girl in a striped long-sleeve shirt atop a high metal structure against a clear sky.
John Law (left) with Tristan Harvey at Burning Man in 1990. ​ | Source: Photo by Judy Kokura

Two years later, over Labor Day weekend in 1990, Cacophony organized “The San Francisco Cacophony Society’s Zone Trip #4: Bad Day At Black Rock” — and brought Burning Man with it. This desert event was conceived of and listed in the Cacophony newsletter by me and Kevin Evans. The first burn of a large wooden man had taken place on Baker Beach in 1986, organized by Jerry James and Larry Harvey and inspired by Mary Grauberger’s earlier art-and-fire solstice gathering there. Cacophony moved the event to the desert. A caravan of Cacophonists camped, raced across the playa, and, on the final night, raised and burned a 40-foot wooden man. The Burning Man festival had begun.

The other crucial ingredient arrived in 1993, when Cacophony organized an informal Zone Trip to Desert Site Works, a solstice gathering at the hot springs around the Black Rock Desert created by photographer William Binzen. His idea was to bring together an intentional community of artists, performers, and musicians to create an immersive installation with no separate audience: Everyone present would help make and inhabit the experience.

What happened there remains one of the most profound, immersive experiences of my life. Fifty or more artists built an amazing array of interactive installations, including an underground sweat lodge, a ritual pavilion, and a 300-foot neon outline of the mesa, while Paradox Pollack and Ape Theater staged a 48-hour ritual trance performance across it all.

A man with a large dark mustache wears a white headscarf with gold trim, a white suit, and smokes a cigar while looking to the side.
John Law on the playa in 1991. | Source: Photo by Sebastian Hyde

Two months later, we brought that sensibility — and artists including Pepe Ozan and Paradox — to Burning Man. Until then, the event had been relatively thin on art. Over Labor Day weekend in 1993, it absorbed the immersive installations, ritual, performance, and collective world-building of Desert Site Works. The Burning Man people now know began to take shape.

Years later, Burning Man cofounder and mouthpiece Larry Harvey would claim that a grand philosophy had animated the event all along. In 2004, he produced a list of (opens in new tab) 10 Principles (opens in new tab) . (Today, Burning Man even has an official Philosophical Center, charged with preserving the event’s “roots, values and impact.”) But that is untrue. There was no grand philosophy behind Burning Man, no Ayn Randian vision born of brilliant theorizing. It was hands-on, real-life collaboration and adventure.

The closest thing we had to a founding text was far less solemn. In 1977, Suicide Club visionary Gary Warne began writing his 12 Chaotic Principles — a running, self-deprecating response to event experiments that had gone sideways. They were practical guidelines for immersive ideas that had to survive contact with the real world: “Divest yourself of expectations,” “You will never be totally in control.” The first desert run included over a dozen Suicide Clubbers and maybe 25 more Cacophonists. Sometime in 1990, I gave Harvey an old Suicide Club newsletter containing Warne’s principles. I can’t prove a direct line from one document to the other, but I have always suspected that this was the seed of Harvey’s 10 Principles, which is treated as holy writ by the more cultic of Burning Man’s devotees.

How Burning Man became a corporate spectacle

Those early years were small and scrappy.

Then Burning Man blew up. The first year was around 80 attendees, most of whom slept on the desert floor in sleeping bags and maybe small pup tents. The primary revels were a formal dress party, driving very speedily across the playa to the various hot springs, and proto “theme camps” such as the Bolt Action Rifle Club, whose members dressed in 18th century garb and shot targets with antique rifles.

By the fourth year, 1993, the entire thing assumed the more involved ritual, performance, fashion, and artistic influence of Desert Site Works and was soon to be invading the day dreams of the Silicon Valley elite, as well as thousands of less career-oriented seekers, artists, ravers, new age wannabe guru types, bored suburbanites, and many, many others. The party was on!

Blame the concurrent rise of the internet in the ’90s for much of what came next. By the time Wired put Burning Man on its cover in 1996, there was no stopping its growth. Attendance rose from roughly 70 people in 1990 to 25,000 in 1999. What had begun as a strange desert expedition became the vacation of choice — and eventually something close to a required pilgrimage — for the emerging Silicon Valley elite.

Interconnected as it became with the Ayn Rand devotees who captained the new, technology-infused culture, Burning Man became a very different kind of animal. The captains of the new internet economy — Elon Musk, Sergey Brin, Larry Page, Mark Zuckerberg, Jeff Bezos — adopted the event as their own. Google decorated its atrium with photos of employees at Burning Man, bused staff to the playa — sort of a reward for slaving away in their keyboard pens for the other 51 weeks of the year, and made Burning Man attendance (opens in new tab) a consideration in its search for a new CEO.

Great societies have always needed ways to mollify their worker populations — to provide, as Karl Marx might say, a release valve for exploited workers to blow off steam, so they remain otherwise docile. It’s hard to imagine a better one for the youthful computer workers of Silicon Valley from the late 1990s through the 2020s: paint yourself blue, drop designer hallucinogens, make passionate love with a stranger, and spend a week under the biblical weather-gods of the playa. What better corporate-sanctioned therapy could be imagined?

A person with glittery blue horns, blue and green face paint, and tattoos snarls aggressively against a clear blue sky.
Elaborate costumes are widely seen at Burning Man today. | Source: Los Angeles Times via Getty Imag

If early Burning Man was a confederation of anarchistic free spirits, the event that emerged from its explosive growth was top-down, hierarchical, status-generating, and controlled. It became a massive hippie, new age, tech-hipster hoedown, a magnet for well-healed seekers and dilettantes searching for something to fill the colossal God-shaped hole left by the decline of religion in America. Belief in Jesus and virgin births isn’t easy to rationalize in the wired age. What the festival offered instead was a neo-pagan revival built on hedonism, tempered by self-referential new age concepts, and crowned by a pagan-lite wooden deity that required no messy actual belief. It was a temporary cure for the existential ache carried around by so many agnostic white-collar workers.

Today, the event has become so wrapped in celebrity and red-velvet-rope exclusivity that it projects an image as glossy as anything emanating from Hollywood or Madison Avenue. Of course, many of the more proletarian attendees, and not just the P-Diddys or Diplos, continue to attend in order to build cool art, organize their own theme camps, and meet up with old friends from across the country and the world. What many old-timers would consider a decline in value, meaning, and creativity is no such thing for most of the new attendees. It remains one hell of a party.

It is also an extraordinarily expensive one. By the late 2010s and 2020s, the event’s own organizers still insisted that Burning Man wasn’t a “business” and that no money changed hands there. Anyone who looked at it with a critical eye knew otherwise: With ticket prices approaching $1,000 and the enormous expense required to provision for and travel to the event, it’s absurd to claim money has nothing to do with it. Wealthy attendees run closed, plug-and-play camps — exclusive enclaves that cost thousands for package deals featuring celebrity chefs, luxury accommodations, and craftsmen and artisans who design and fabricate their costumes and art cars.

The Burning Man organization has bought up land all around the desert (opens in new tab) and in the town of Gerlach (opens in new tab) and has developed some trappings of a major commercial institution, starting its professional public relations department in the late 1990s. From its humble if ambitious temporary autonomous-zone beginnings, Burning Man has inevitably been absorbed in important ways into the capitalist celebrity-entertainment complex.

As someone who has aimed to live a free life, I see in Burning Man today an instrument of top-down control. I was always opposed to the commercialization of the event — and was involved in litigation for the purpose of releasing the trademarks to the public domain at one point. To me, the point was fundamental: No one should own this thing.

None of that makes Burning Man a fraud. The pleasure people find there is real. For the people who go, it can be the most affecting, immersive, fun week of the year.

A group of people stands and works around a large, wooden, triangular framework structure on a flat, desert-like surface with vehicles parked nearby.
Source: Photo by Judy Kokura

But it isn’t what we made.

Early Burning Man was an anarchist confederation of equals — thrown up out of nothing but nerve and collective will. Nobody owned it. Nobody ran it. This camaraderie, collective creation, hard work, and harder play is precisely what made it real. There were no pretentious “principles” or annoying philosophizing about how this giant hedonistic party was changing the world. There were no billionaires. Everyone made their own costumes, art, and art cars. Early Burning Man was an emanation of the firmament of that place in time. And as a result, we captured the zeitgeist in a way that today’s Burning Man, with all its budget and its billionaires and its plug-and-play camps, could never hope for.

“Anything worth doing is worth running into the ground.” — Stuart Mangrum, director of the Burning Man Philosophical Center


John Law is the co-founder of the Burning Man festival and a longtime SF underground instigator.

Defrag98: Windows 98 Disk Defragmenter Simulator Online

Hacker News
defrag98.com
2026-08-29 18:51:17
Comments...

Twitter (Not affiliated with X Corp)

Hacker News
twitter.now
2026-08-29 18:49:26
Comments...
Original Article

We’re down. We’re on it.
Already learning things the hard way.

We will be back as soon as we can.

Love you guys 💙

$44M Solar-Powered EV Production Deal Struck

Hacker News
frequal.com
2026-08-29 17:37:07
Comments...
Original Article
On August 20, Aptera announced a $44 Million partnership with Launch Design to design and build their first solar electric vehicle.

The deal seems like a win-win:

  • Launch becomes an early investor in Aptera
  • Aptera gains a partner with access to volume discounts and mass production facilities
  • Launch is incentivized to help Aptera succeed thanks to its new ownership of Aptera stock warrants.

The deal answers several questions that had been outstanding for the Aptera launch plans:

  • How can Aptera build thousands of vehicles given that other startups like Lucid and Rivian have burned through millions of dollars to reach the same goal? Now they don't have to. Launch already has large facilities, and will ship finished sub-assemblies to Carlsbad for final assembly and validation.
  • How can Aptera hope to manufacture thousands of vehicles out of their modest commercial building in Carlsbad? Now that Carlsbad will be an assembly point for large sub-assemblies, they no longer need long assembly lines or huge warehouses of individual components.
  • How can Aptera keep the cost of goods low enough to meet their target price points? Launch is a large company with an international supply chain, able to negotiate lower prices than Aptera would be able to negotiate on their own, given their smaller size and volume.

What we want is a hunter gatherer lifestyle with space age tools

Hacker News
www.strangeloopcanon.com
2026-08-29 16:53:56
Comments...
Original Article

Those who are convinced that there is more to things spend their time chasing it and not finding it often as not, and those who are convinced there isn't find themselves frustrated at the abyss.

When you read books about a utopia without material demands on our time, the key aspect seems to be how nobody is particularly bereft, only mildly discontent. The utopia we envision in other words comprises our current world, just shorn of what we’d recognise as work.

But its more than that. Most of the annoyances with the modern world, especially in the more talkative online spheres, seems to stem from its seemingly inadequate efforts to affect the outcomes of us especially as our institutions are growing so much bigger than we can control.

When we look at the degrowth agendas that proliferate, they too seem to be nostalgic for a very specific version of the past. The visions are filled with communities of mutually loving people, the elimination of middlemen from transactions, where everyone knows the true you, the nonexistence of bureaucracy, the existence of a social good that’s identifiable by looking around. Essentially, the simple life.

Instead today we’re surrounded by alien structures, built by people we don’t know, working alongside those with whom you have a passing ephemeral relationship at best, stuck with an expertise that has little to do with savannah survival, doing a portion of a portion of a portion of the work to move the big wheel, detached from your relationships because of time constraints, and generally feeling as if you’re too smart to not notice an abyss but too stupid to find a way to cross it.

So we try to find our way to make peace with the things we had to do to get those space age tools, even as we dislike what we had to do to get them.

  • We tried schooling people individually, sometimes collectively, occasionally communally, but had to resort to more industrialised methods as the numbers got larger. And in this expansion we also started disliking the fact that industrialised methods take away the individuality.

  • We tried jobs out by apprenticeships, by walking into offices and finding your vocation, by starting working somewhere and proving your mettle, but as the numbers grew large enough we started to realise that maybe we needed better methods of selection, credentialling, and hoops to jump through.

  • We tried governing through simple rules applied semi illegibly, which over time had to get more codified and better elaborated as societies themselves grew larger and more complex in their component activities; and the fight between wanton lawsuits and deterrence led us to the point where we need to elaborate exact instructions of how a child shouldn’t eat a plastic bag atop a sweet box.

  • We tried curing diseases based on the patient and the background and the symptoms and the disease patterns themselves, to the point where with the large influx of patients necessitated rule based systems (spend only 15 mins with the patient, only do a blood test if they demonstrate specific symptoms) which make it worthless unless you’re at the middle of a (supposedly extant) bell curve.

This is why we dislike rules so much . This is why we want to RETVRN.

Because we don’t want a life filled with rules and structures and globally defined procedural rules. We want to live in a hunter gatherer mode where we get to follow our curiosities and our ambitions and our vibes and our likes until it reaches the natural conclusion. Never mind perhaps that this might not exactly depict the way the hunter gatherers themselves lived, the point of the space age toolkit we have is to live as if that was the lifestyle.

But now that we’ve grown up a bit maybe we can treat some of those rules as the necessary evil that they are, not as immutable facts of the world. We can treat personalisation as a feature and not an affront. We can treat rules as suggestions of the right average behaviour and Schelling points and not as laws like gravity.

To return to that (maybe imagined) idyllic state isn’t a function of reversing time. We don’t need to give up everything we made in order to retvrn. We need to move forward with the new insight that what we created helps us understand a little bit more about what we might want, and use that knowledge to guide our next steps.

Whether its our increasing understanding of how tribes form, online and offline, or our affectations about how life should be lived, or the level of influence we want or tolerate from others in our society, or indeed what we owe to one another, these are to be answered moving forward.

Whichever vision of the past glory that you’re most partial to, it stems from the yearning for a time when life used to be understandable, when proving oneself wasn’t a constant struggle, when you could just do the thing instead of proving you can do the thing, when the egregore of our society wasn’t turned into the mechanistic mode of analysing our aptitudes, in short when things were more personal.

We won’t live in small villages with cobbled streets en masse anymore because we need the giant glass skyscrapers and the congealed intellect of our multi billion population to move ahead, but that doesn’t mean we can’t recreate what made those cobbled streets seem interesting in the first place. That’s the true retvrn.

Introducing ReactOS 0.4.16

Lobsters
reactos.org
2026-08-29 16:21:34
Comments...
Original Article

We are pleased to announce the release of ReactOS 0.4.16! After a year and a half of development, we’re excited to showcase the improvements we’ve made between a new graphical installer; a unified bootcd and livecd image; video, audio, networking, and storage stack improvements; a new installation type; and third-party code syncs.

Graphical Installer and the All-in-One Boot CD

Historically, ReactOS offered two images for download, a livecd which let you test ReactOS in a read-only environment, and a bootcd which let you install ReactOS to your hard disk using a text-based installer. Thanks to the efforts of Hermès Bélusca-Maïto ( hbelusca ), ReactOS 0.4.16 has a new graphical installer and a combined bootcd and livecd. Now you can test and install ReactOS using the same image.

Graphical installer

Graphical installer

Install or update ReactOS

Install or update ReactOS

Basic partition management

Basic partition management

Copying files

Copying files

Graphical setup complete

Graphical setup complete

You can read about Hermès’s work on this in his blog posts:

Video

During 0.4.15 development, core developer Hervé Poussineau ( hpoussin ) put in the ground work for multi-monitor support and falling back to a VGA driver when display drivers fail to load. This foundation enabled us to continue pursuing better video driver compatibility in 0.4.16.

For years ReactOS has been plagued by different issues with all major video driver vendors. Nvidia GPUs in particular had been plagued by a slow down issue that many talented contributors and developers investigated. Eventually, Justin Miller ( The_DarkFire_ ) recognized that the kernel was running out of system page table entries (PTEs) when loading third party drivers. This limitation was most apparent with graphics drivers, which allocate more memory than most other drivers. Justin changed the memory layout used by our memory manager to increase the amount of system PTEs. This fixed the hard-to-debug slowdown bug with Nvidia graphics drivers. On AMD video drivers, the OpenGL window would end up blank. This was resolved by rewriting ExtEscape , inspired by a patch from the late core developer James Tabor ( jimtabor ). These improvements enhanced stability, better handled resource management of the new devices, and fixed many edge case bugs in our win32k.sys driver. We thank our contributors and developers for their time as these fixes needed an incredible amount of research.

Audio

Prior to 0.4.16, ReactOS had incomplete High Definition (HD) audio support. HD audio drivers depend on a bus driver ( hdaudbus.sys ), including drivers from AMD, IDT, Nvidia, Realtek, and SigmaTel. Our initial implementation was written long ago by Johannes Anderwald ( janderwald ). This implementation was never finished, and was a frequent source of bugchecks when attempting to install HD audio controller drivers. Core developer Oleg Dubinskiy ( oleg-dubinskiy ) imported sklhdaudbus , a new HD audio bus driver, to replace our old implementation.

HD audio controllers which are compatible with Windows XP and Windows Server 2003 should now work in ReactOS 0.4.16. Here is a video showing a Realtek HD audio controller working on ReactOS 0.4.16:

The new HD audio bus driver depends on the Kernel Mode Driver Framework (KMDF). Microsoft open sourced KMDF as part of the Windows-Driver-Frameworks repository. Justin imported KMDF for the new HD audio bus driver, and now we can use KMDF to import or develop other drivers.

Oleg also fixed the volume and balance sliders in Sound Properties ( mmsys.cpl ) and Audio Volume Mixer ( sndvol32.exe ). Now the volume and balance levels are saved and restored on reboot when using an HD audio codec. In addition, Oleg updated the audio device enumeration code to support more sound cards. On top of that, Oleg improved binary compatibility with the Windows audio stack thanks to some fixes he contributed to our Plug and Play (PnP) stack and SetupAPI.

Storage

Since 2009, ReactOS has been using the UniATA storage driver to add SATA, AHCI, and support for partitions greater than 8GB. This was a huge help to ReactOS then, but today UniATA is responsible for slow boot times and failing to load on many devices, leading to the dreaded INACCESSIBLE_BOOT_DEVICE ( 0x7B ) bugcheck. ReactOS 0.4.16 introduces a new ATA driver developed by contributor Dmitry Borisov ( disean ). This new ATA driver allows ReactOS to boot in far more environments, including inside Hyper-V Generation 1.

In 2021 we imported and enabled the open-source Microsoft FastFAT driver. Unfortunately, this broke our ability to repair FAT partitions using chkdsk. Core developer Doug Lyons ( Doug-Lyons ) fixed our FAT chkdsk routines to work with the Microsoft FastFAT driver.

Core developer Mark Jansen ( learn-more ) added a disk cleanup utility in ReactOS 0.4.16. The disk cleanup utility is compatible with extensions for the Windows disk cleanup utility, allowing third party programs to clean up disk usage as well as the operating system.

Check disk

Check disk

Disk cleanup

Disk cleanup

Networking

During ReactOS 0.4.15 development, Dmitry introduced a new DC21X4 network adapter driver for better hardware compatibility. This driver is used on devices with DECchip 21x4-based network adapters, and virtualized environments such as Microsoft Virtual PC 2007 and Hyper-V Generation 1. Now ReactOS 0.4.16 can boot and access the Internet on both.

ReactOS 0.4.16 also adds asynchronous connection support. This improves networking performance by allowing applications to execute networking operations without stalling. This also improves application compatibility as many programs assume that these asynchronous connection APIs are always present.

ReactOS Server Core

ReactOS supports Workstation and Server installation types. In a Workstation install, more fancy graphical options are enabled by default compared to a Server install. In addition, user folders on Workstation installs currently live inside the “My Documents” folder, although Windows Vista and newer moved these folders out of the “Documents” folder for both Server and Workstation installs.

Interested in seeing ReactOS being more widely used in server and embedded environments, core developer Carl Bialorucki ( cbialorucki ) added the Server Core installation type. This install type disables the graphical explorer shell, but otherwise loads the full Win32 subsystem. ReactOS Server Core works similarly to Windows Server Core which was introduced with Windows Server 2008.

Server Core install option

Server Core install option

Booting into Server Core

Booting into Server Core

Running programs in Server Core

Running programs in Server Core

Third-Party Code Syncs

ReactOS utilizes several other open-source projects as part of its code base. One of the largest open-source projects we leverage is Wine , a re-implementation of several Windows APIs for Unix-like operating systems. ReactOS uses a fork of Wine that interfaces directly with a Windows-like kernel instead of translating calls to a Unix-like one.

For many years, ReactOS was limited to Wine 2.x and 3.x due to compatibility concerns adopting APIs newer than those available to Windows Server 2003. Towards the end of the 0.4.15 development cycle, we abandoned this strict adherence to Windows Server 2003 compatibility, which allowed us to slowly update our Wine fork to Wine 10.0. This upgrade is still on going, but 0.4.16 has a significant amount of this work in it. We anticipate that updating to Wine 11.0 or later versions will be significantly easier thanks to this effort to bring it up to Wine 10.0.

At this time, the ReactOS release image is still compiled with Windows Server 2003 exports only since there are several programs that expect all Windows Vista and newer exports available even if only some are exposed. If you’d like to experiment with Windows Vista and newer application support, build ReactOS using the -DDLL_EXPORT_VERSION flag. Instructions on how to build ReactOS are available here .

For the first time, ReactOS release images will include WineVDM, which increases compatibility with 16-bit Windows applications. WineVDM is a project by otya128 , available here .

Final Thoughts

The mission for ReactOS is to “[Run] your favorite Windows applications and drivers in an open-source environment you can trust.” With each release we come closer to fulfilling this goal. We look forward to sharing more developments and progress with you.

We extend our deepest gratitude to our community, contributors and donors. Without our contributors, we wouldn’t be able to make any development progress. Without our donors, we couldn’t fund our testing and hosting infrastructure or development contracts to accelerate progress. And without our community, no one would know we exist. Thank you for making ReactOS possible!

If you are interested in joining our community, contributing, or donating to the ReactOS project, check out our homepage to find our donation page, social media links, and our GitHub.

Sincerely,

The ReactOS Team

Download ReactOS 0.4.16

Statistics

Resolved Jira issues: 381

Commits: 2808

Oldest Jira issue resolved: CORE-3804 from February 3rd, 2009

The releases/0.4.16 branch was forked from master on April 28th, 2026 after commit bac97c5

Canonical-basis realignment for Transformer LLMs: every hidden axis becomes independently measurable and controllable

Lobsters
github.com
2026-08-29 16:16:54
The code essentially gives you a way to rotate a Transformer's internal coordinate system into a canonical basis that aligns with its own weight matrices in a lossless way. By absorbing the normalization gains directly into the adjacent weights and using orthogonal matrices built from the singular v...
Original Article

A Canonical Basis for Interpreting Transformer Language Models

The Canonical Basis for Language Models (CBLL): a lossless coordinate transformation that opens the black box of Transformer LLMs and makes every axis of the hidden space independently measurable.

This repository is the reproducible companion to the Zenodo paper:

Gernone, G. (2026). The Hidden Geometry of Transformer Weights: A Journey Inside the Black Box. Zenodo. DOI: 10.5281/zenodo.20520986.

paper/The Hidden Geometry of Transformer Weights: A Canonical Basis for Interpreting Transformer Language Models_EN.md is the updated version 2 of the paper, extended with the causal ablation, the multi-architecture measurements, the LayerNorm bridge, and the MoE analysis. Every number in the paper comes from a script in scripts/ and pre-computed data in data/ .


What this repository demonstrates

  1. Affine realignment is lossless — absorbing RMSNorm gains into the adjacent weight matrices and rotating with a Householder matrix changes the model's coordinates without changing its behavior. Qwen 2.5 0.5B: PPL 25.38 = 25.38, MMLU 47.50% = 47.50%. SmolLM2 1.7B: PPL 6.6018 → 6.6045, top-5 overlap 5/5.

  2. Cross-layer U-alignment — the left singular vectors of the FFN down-projection are strongly aligned across layers on Qwen 2.5 0.5B (mean 0.651, max 0.928 over all 276 layer pairs; adjacent pairs align more strongly). The model has a shared set of preferred directions that no one imposed.

  3. Rich Club and bipolar oscillator — in the canonical basis, the 896 axes split into 309 positive-pole and 292 negative-pole axes; 83% of the positive-pole axes have a dedicated inhibitory partner. Master pair axis 62 ↔ axis 570, ρ = −0.97.

  4. Respiration — the POS/NEG ratio oscillates across the 24 layers in four phases (Encode 1.36 → Process 0.42–0.88 → Decode 1.28 → Output 0.54), invariant to input content. The same five layers [21, 3, 23, 2, 22] are the top activators for every prompt tested.

  5. Homeostasis — any intermediate perturbation of the residual stream is erased within two layers (5× → 1.4× → 1.0×), by the combined action of RMSNorm, attention softmax, and the SiLU operating range. This is architectural, not learned.

  6. Spectral collapse — the singular value magnitudes are nearly identical across layers (rank 1/24, ratio 23.2×). Layer identity lives in the geometry (U, V), not in the spectrum.

  7. Six spectral indices — cohesive, torsional, informational, dimensional, rhythmic, and vorticity indices quantify the structure per layer (means 0.588 / 0.917 / 0.709 / 0.378 / 0.595 / 0.650), with effective dimensionality 4.77/6 and a 41× isotropic collapse between the weight spectrum (k90/d 0.71) and the activation spectrum (k90/d 0.017).

  8. Causal evidence: single-axis ablation — zeroing axis 62 alone (0.11% of the model) collapses MMLU from 47.50% to 21.25% and destroys output coherence (PPL 4.24 → 23858). Zeroing its anti-correlated partner axis 570 degrades facts while keeping fluency. Five control axes show no effect (≤ ±1.25 pp). The geometry is functional, not decorative.

  9. Architectural generality — the realignment is lossless on RMSNorm families (Qwen, SmolLM2) and, via a DC-preserving rotation, on LayerNorm families (Pythia 1.4B: PPL 9.2286 → 9.2359, greedy generation identical 3/3). Native alignment measured on six families spans 0.02 (OLMo2) to 0.94 (Qwen); normalization type alone does not determine it.

  10. MoE structure — on OLMoE-1B-7B (64 experts), per-expert cross-layer alignment is 0.086 and cross-expert alignment is 0.111: the expert structure is per-expert, not shared across layers.


Why the canonical basis

The hidden state of a Transformer is a vector in R^d, but the basis in which it lives is arbitrary — whatever the training converged to. In the standard basis, nothing about dimension i is meaningful, and nothing can be compared across layers.

The canonical basis rotates the model so that axis k of the hidden state corresponds to a specific spectral direction of the model's own weight matrices. After the rotation:

  • each axis can be measured independently (energy, correlation, entropy);
  • each axis can be manipulated independently (zeroed, amplified, traced from layer 0 to layer 23);
  • phenomena that are smeared across all 896 dimensions in the standard basis — the bipolar oscillator, the respiration, the critical axis — are localized onto single axes.

The rotation is lossless: the realigned model produces the same outputs as the original. It is a microscope, not a modification.

Why it is not a free operation

RMSNorm uses learned per-channel gains, and (g ⊙ h)R^T ≠ g ⊙ (hR^T) — the gains break rotational symmetry. The gains must first be absorbed into the adjacent weight matrices ( W' = W @ diag(g) ), making the normalizations uniform. LayerNorm additionally subtracts the mean, which is equivariant under rotation only for rotations that fix the ones-vector (DC-preserving rotations); its γ and β parameters are absorbed into weight columns and projection biases. Both procedures are lossless and are implemented in scripts/ .


How to use

Quick verification (pre-computed data, no GPU)

All paper numbers are in data/ as JSON:

# Single-axis ablation (Section 4 of the paper)
python3 -c "import json; d=json.load(open('data/single_axis_ablation.json')); \
print('baseline', d['baseline']['mmlu']['accuracy']); \
[print(k, v['mmlu']['accuracy'], v['delta_mmlu']) for k,v in d.items() if k.startswith('axis_')]"

# Multi-architecture alignment (Section 5.3)
python3 -c "import json; d=json.load(open('data/gguf_cbll_multiarch.json')); \
[print(k, v['u_alignment_mean']) for k,v in d.items()]"

# Pythia DC bridge (Section 5.2)
python3 -c "import json; d=json.load(open('data/pythia_dc_bridge_results.json')); \
print(d['ppl_original'], '->', d['ppl_canonical'], 'lossless:', d['lossless'])"

Full reproduction (GPU with 6 GB VRAM tested)

pip install -r requirements.txt
bash reproduce.sh        # 7 steps, ~30 min: realign → collect → diagnose → ablate

Individual steps

python scripts/save_model.py --model Qwen/Qwen2.5-0.5B-Instruct \
    --output compressed_models/realigned_qwen05b     # realignment (lossless)

python scripts/diagnose_shared_sigma.py              # U-alignment, homeostasis, sigma
python scripts/investigate_rich_club.py              # POS/NEG poles
python scripts/analyze_correlations.py               # 896×896 correlation matrix
python scripts/benchmark_mmlu.py                     # MMLU 12×20 baseline
python scripts/ablate_single_axis.py \
    --test-axes 62 570 0 400 50 100 200 500 800      # causal ablation (9 axes)

Other models

  • SmolLM2 1.7B (RMSNorm, Llama-style): scripts/realign_smollm_cbll.py then scripts/smollm_cbll_continue.py for canonical-basis access.
  • Pythia 1.4B (LayerNorm, GPT-NeoX): scripts/pythia_dc_bridge.py — DC-preserving rotation, LayerNorm kept, lossless.
  • OLMoE-1B-7B (MoE, RMSNorm): scripts/analyze_olmoe_cbll.py — reads the rotated fp16 weights and computes dense/expert/cross-expert alignments and spectral indices.
  • GGUF models (Falcon3, StarCoder, Nemotron, DeepSeek-Coder, OLMo2): scripts/analyze_gguf_cbll.py — dequantizes GGUF tensors from Ollama blobs and measures native U-alignment and k90/d.

Configuration: where the paths live

There are no hardcoded machine paths in the published scripts. Everything is configured through environment variables or falls back to standard locations:

Variable Used by Default What to set
HF_HOME all scripts that download models ~/.cache/huggingface Where HuggingFace stores model checkpoints. Set once if you keep them elsewhere.
HF_HUB_CACHE HF hub downloads $HF_HOME/hub Sub-cache for hub files. Normally not needed.
OLLAMA_BLOBS scripts/analyze_gguf_cbll.py ~/.ollama/models/blobs Directory containing Ollama GGUF blobs (files named sha256-... ). Set to your Ollama models directory if it is not the default.
OLMOE_ROTATED_DIR scripts/analyze_olmoe_cbll.py ~/.cache/huggingface/models--allenai--OLMoE-1B-7B-0924/rotated_fp16 Directory with the rotated fp16 OLMoE shards.
OLMOE_R_PATH scripts/analyze_olmoe_cbll.py next to the rotated weights Path to the olmoe_R.npy rotation matrix.

Example:

export HF_HOME=/data/models
export OLLAMA_BLOBS=/data/ollama/blobs
export OLMOE_ROTATED_DIR=/data/olmoe/rotated_fp16
export OLMOE_R_PATH=/data/olmoe/olmoe_R.npy
bash reproduce.sh

Scripts write their outputs to runs/ (gitignored) and read the realigned model from compressed_models/ (gitignored, produced by scripts/save_model.py ). Pre-computed results live in data/ and are never overwritten by a run — regenerate, then compare against data/ .


Debugging and troubleshooting

Expected values (sanity checks)

Step Expected If not, check
save_model.py logit diff < 1e-3, PPL identical rotation built in fp32? gains all absorbed? hooks registered?
benchmark_mmlu.py baseline 47.50% (114/240) tokenizer: Qwen chat template, choices encoded without special tokens
ablate_single_axis.py axis 62 → 21.25%, axis 500 → 47.50% realigned state_dict loaded with strict=True ? hooks: embed @ R^T, last layer @ R
realign_smollm_cbll.py PPL 6.6018 → 6.6045, top-5 5/5 fp16 noise of 10⁻² in logits is expected and harmless
pythia_dc_bridge.py PPL 9.2286 → 9.2359, greedy 3/3 identical TO-side biases rotated ( b @ R^T )? R fixes the ones-vector?
analyze_gguf_cbll.py table matches data/gguf_cbll_multiarch.json OLLAMA_BLOBS correct? pip install gguf ?

Common failure modes

  1. "Realigned model produces garbage" — almost always a missed absorption or a wrong hook direction. Check in order: (a) are all RMSNorm gains 1.0 after absorption? (b) embed hook rotates with R^T and the last-layer hook with R (row-vector convention)? (c) are the TO-side biases rotated ( b @ R^T )? Qwen-class models have no biases; GPT-NeoX has them on every projection.

  2. "PPL differs by a small amount" — expected. fp16 forward passes introduce logit differences of ~10⁻²; behaviorally invisible (top-5 5/5, greedy generation identical). Bit-exactness requires fp32.

  3. "k90/d values look wrong" — use full SVD ( np.linalg.svd(W, compute_uv=False) ), not randomized SVD with a small number of components. Randomized SVD underestimates k90 badly. The OLMoE script includes both; trust d_k90_fullsvd.json .

  4. "Axis zeroing does nothing" — check the axis is zeroed in canonical space (after the embed rotation, before the unrotation), and that the intervention is at the weight level (zero the W_down row), not the activation level: activation-level perturbations are erased by homeostasis within two layers — that is the point of Section 3.3.

  5. "CUDA out of memory" — the GPU holds one model at a time (6 GB VRAM). Compare logits by saving the reference logits, freeing the model, then loading the canonical one (the pattern used in realign_smollm_cbll.py ).

  6. "LayerNorm realignment degrades" — make sure you use the DC-preserving rotation, not the RMSNorm replacement. The condition is R^T 𝟙 = 𝟙 ; verify with np.abs(R @ np.ones(d) - np.ones(d)).max() < 1e-8 .

Verifying the canonical basis is accessible

The quickest check, on any realigned model:

# zero canonical axis k at the last layer output, before unrotation
# PPL axis 0 (Qwen) -> catastrophic; axis 500 -> unchanged
python scripts/ablate_single_axis.py --test-axes 62 500 --skip-chat

Or interactively with demo/chat.py : /ablate 62 , then /restore .


Models and architectures

Family Normalization Status What we have
Qwen 2.5 0.5B Instruct RMSNorm Full CBLL pipeline alignment, Rich Club, respiration, homeostasis, collapse, ablation
Qwen 2.5 1.5B RMSNorm Realigned losslessness, alignment
Qwen 3.5 4B RMSNorm (hybrid Mamba-FFN) Native measurements U-alignment 0.606, k90 0.706
SmolLM2 1.7B RMSNorm Full pipeline lossless realignment, axis access, indices
Pythia 1.4B LayerNorm DC bridge lossless realignment, axis access, indices
Falcon3 3B LayerNorm Native measurements U-alignment 0.474, k90 0.670
StarCoder 1B/3B LayerNorm Native measurements U-alignment 0.45–0.47
Nemotron-Mini 4B RMSNorm + bias Native measurements U-alignment 0.249
DeepSeek-Coder 6.7B RMSNorm Native measurements U-alignment 0.157
OLMo2 7B non-parametric LN Native measurements U-alignment 0.020
OLMoE-1B-7B RMSNorm (MoE, 64 experts) Realigned + weight-level CBLL dense/expert/cross-expert alignment, sigma redundancy

On request we extend the pipeline to further architectures: the DC-preserving rotation covers every LayerNorm family, and the absorption procedure covers every parametric normalization.

Realigned models we release: the OLMo MoE family (OLMoE-1B-7B) in canonical basis — rotated fp16 weights plus the rotation matrix — so that anyone can run the measurements without re-running the realignment.


Interactive demo: per-axis control chat

demo/chat.py is a self-contained interactive chat with surgical per-axis control — the fastest way to feel the causal result of Section 4.

pip install torch transformers
python demo/chat.py                    # normal chat
python demo/chat.py --ablate 62        # chat with axis 62 removed
python demo/chat.py --ablate 62 --compare   # side-by-side baseline vs ablated
python demo/chat.py --prompt "Capital of Italy?"   # non-interactive single prompt

First run downloads Qwen 2.5 0.5B (~1 GB), runs the affine realignment (~30 s GPU, ~60 s CPU), and caches the realigned model. Subsequent runs load the cache instantly. Works on CPU (GPU optional, ~3× faster).

Interactive commands inside the chat:

/ablate 62              # zero axis 62 at every layer's FFN output
/ablate 62 570          # zero multiple axes
/restore                # restore all axes
/quit                   # exit

What you see (from demo/README.md ):

═══ BASELINE (all axes active) ═══
  Explain quantum computing in one sentence.
  Quantum computing uses qubits that can exist in multiple states simultaneously,
  enabling faster computation for certain problems.

═══ AXIS [62] ZEROED ═══
  Explain quantum computing in one sentence.
  The the the the the the the the the the...

═══ RESTORED ═══
  Explain quantum computing in one sentence.
  Quantum computing uses qubits that can exist in multiple states simultaneously,
  enabling faster computation for certain problems.

Axis 62 has near-zero static activation (energy rank 895/896) but maximum betweenness centrality (3702) in the axis correlation network — a dynamic controller, not a static feature. Zeroing it at every layer removes its contribution from the residual stream, and the model loses coordination across layers. /restore brings it back — the intervention is reversible, the effect is immediate, and it reproduces the causal ablation of Section 4 interactively.


Repository layout

canonical-basis/
├── README.md                  # this file
├── reproduce.sh               # full pipeline, 7 steps
├── requirements.txt           # torch, transformers, datasets, numpy, scipy
├── CITATION.cff               # citation metadata
├── LICENSE
├── paper/
│   ├── The Hidden Geometry of Transformer Weights:A Canonical Basis for Interpreting Transformer Language Models_EN.md     # paper v2 (English)
│   └── The Hidden Geometry of Transformer Weights:A Canonical Basis for Interpreting Transformer Language Models_IT.md  # paper v2 (Italian)
├── demo/
│   ├── chat.py                # interactive per-axis control chat
│   └── README.md              # demo usage
├── assets/                    # figures and demo generators
├── validation/                # validation notes
├── scripts/                   # one script per paper claim
└── data/                      # pre-computed results (all paper numbers)

What is published and what is not. data/ contains the pre-computed results — the exact numbers cited in the paper. scripts/ contains the code that produces them. The regenerated outputs ( runs/ ) and the realigned model weights ( compressed_models/ ) are not committed: they are large, and they are regenerated deterministically by reproduce.sh from a public HuggingFace checkpoint. data/ is the ground truth of record; a fresh run writes to runs/ and must match data/ within fp16 noise.


License

Code: MIT. Data: CC-BY 4.0.

Patent notice

This repository is released for research purposes only. For commercial use, and for data on other models not cited in this work, contact info@todot.it .

Citation

@misc{gernone2026canonical,
  title={The Hidden Geometry of Transformer Weights: A Journey Inside the Black Box},
  author={Gianluca Gernone},
  year={2026},
  note={Version 2, with reproducible scripts and data},
  howpublished={Zenodo DOI: 10.5281/zenodo.21935673}
}

Wrapping GTK4 in 800 lines of Clojure with Jolt

Lobsters
yogthos.net
2026-08-29 15:56:09
Comments...
Original Article

Native toolkits are not terribly ergonomic, and are a lot more painful to use compared with web dev in many ways. Building a UI with them is an imperative exercise where you construct widgets one call at a time, pack them into containers, and wire each event to its handler by hand. What's worse is that the structure of the interface often ends up living outside your language altogether forcing you to use tools like GtkBuilder XML or Xcode storyboards, where none of your usual tools for composing and refactoring code can reach. Layout is governed by box packing rules and constraint systems that are easy to describe but hard to predict. And a common task such as turning a list of items into a list of widgets that stay in sync with the data results in a ton of boilerplate that you have to repeat over and over.

The pain of working with native toolkits gave rise to things like Electron which simply package a browser engine as a frontend for the application. While that technically works, it's a clunky and inefficient hack around the problem. Every app ends up having to ship its own copy of the browser along with a JavaScript runtime, and the result never quite feels native.

However, even doing that still doesn't address the biggest frustration about having a compile cycle that breaks your development flow. And that's especially problematic when building a UI where you can't easily automate testing. You have to load up the app, click through its menus, and get it to a particular state so that you can visually inspect whether a change works as you intended and has decent UX.

Working with Reagent and other Clojure UI toolkits in ClojureScript is an enjoyable experience precisely because you can build up the UI gradually, and keep a running state as you add more components to it. You make a change, look at the app, see it instantly, and then iterate on it.

I've always been a big fan of the Reagent reactive model which I find to be intuitive. You treat your UI state as a data structure, and have UI components subscribe to paths within it. Whenever an element at a particular path changes, the UI component associated with it gets updated. And that's really all there is to it. While Reagent is built on top of React, the latter isn't actually needed in this model. React uses a VDOM that gets diffed and then rendered to the actual DOM, and the reason it needs a VDOM is due to the fact that React is agnostic regarding what triggers a component change. That's why you need the whole React lifecycle with checks for componentDidMount, componentWillUnmount, and so on. In Reagent a component collapses to a single render function, and the reactive tracking decides which components need to be re-run, so the lifecycle is derived from the state of the data. And because the reactive model already knows exactly what changed, it makes it possible to use it to drive the DOM directly without needing React as the mr-clean library illustrates.

Since this model works well with a browser DOM, then why not apply it to a native toolkit? All that's needed is to create wrappers to render native widgets by passing them values from the reactive atom, and then provide a callback for the widgets to trigger on user input. We don't need an equivalent of a VDOM because all the changes are driven by the state of the reactive atoms, and can be rendered directly to the UI. This can even be done with a batching layer to control the rate of UI updates if needed. And this is how glimmer works, providing a reactive core that can be hooked up to a particular UI toolkit. Then, there are glimmer-gtk , glimmer-uikit , and glimmer-tui to provide concrete bindings for different types of UI widgets.

The canonical counter with glimmer-gtk looks pretty much exactly like its Reagent counterpart:

(ns counter
  (:require [glimmer.ratom :as r :refer [atom]]
            [glimmer.core :as ui]
            [glimmer-gtk.core])) ; installs the GTK4 backend

(defn counter []
  (let [count (atom 0)]
    (fn []
      [:vbox {:spacing 12}
       [:label {:label (str "Count: " @count)}]
       [:hbox {:spacing 8}
        [:button {:label "- 1" :on-click #(swap! count dec)}]
        [:button {:label "+ 1" :on-click #(swap! count inc)}]
        [:button {:label "reset" :on-click #(reset! count 0)}]]])))

(defn -main [& _]
  (ui/run counter :title "counter" :width 320 :height 160))

The outer function runs once to create the local state, and the inner one re-runs whenever @count changes, patching the live widgets in place instead of rebuilding the tree. If you've used Reagent before, this should all look very familiar with the only difference being that the elements are GTK4 widgets instead of DOM nodes.

What it takes to wrap a widget

It turns out that there is surprisingly little code involved in hooking a C toolkit up to a reactive Clojure core. The entire glimmer-gtk backend sits under 800 lines of Clojure split across four namespaces, and none of it involves anything exotic.

Jolt's FFI lets you promote a C function to the Clojure layer by naming the symbol it points at along with its argument and return types. We can see a few examples of what bindings from the GTK backend look like below.

(ns glimmer-gtk.ffi
  (:require [jolt.ffi :as ffi]))

(ffi/defcfn gtk-button-new-with-label "gtk_button_new_with_label" [:string] :pointer)
(ffi/defcfn gtk-button-set-label      "gtk_button_set_label"      [:pointer :string] :void)
(ffi/defcfn gtk-box-new               "gtk_box_new"               [:int :int] :pointer)
(ffi/defcfn gtk-box-append            "gtk_box_append"            [:pointer :pointer] :void)

Pointers are plain machine addresses represented as numbers, strings are marshalled to and from C strings automatically, and GTK booleans are ints that are handled by a one line ->bool helper. There is no C shim to compile or bindings generator to run, and no interface DSL to learn. The shared libraries are declared in deps.edn under :jolt/native , and Jolt loads them before the namespaces are required.

One thing to note here is that the main loop binding needs a bit of special treatment.

(ffi/defcfn g-application-run "g_application_run" [:pointer :int :pointer] :int :blocking)

The :blocking flag tells the runtime that the call parks the thread for the lifetime of the app, so it shouldn't pin the garbage collector while GTK owns the main loop.

GTK's API is also full of enums like GTK_ALIGN_START and GTK_ORIENTATION_VERTICAL , so a common approach is to maintain a table of constants mirroring the C headers. But glimmer-gtk has no need for such tables since every GObject enum registers its members with a lowercase nick which maps to a Clojure keyword. So, three extra bindings are all it takes to resolve a nick to its integer value at runtime through the GObject type registry.

(ffi/defcfn g-type-from-name         "g_type_from_name"         [:string] :size_t)
(ffi/defcfn g-type-class-ref         "g_type_class_ref"         [:size_t] :pointer)
(ffi/defcfn g-enum-get-value-by-nick "g_enum_get_value_by_nick" [:pointer :string] :pointer)

When you write [:label {:halign :start}] , the backend looks up the GtkAlign type to get its class struct, asks it for the member with the start nick, and reads the integer out of the struct it gets back. Successful lookups are then memoized, and a raw integer can still be used as an escape hatch. This trick is the reason why there isn't a single GTK_* constant needed anywhere in the library.

So that's all the boilerplate that's needed to expose the needed GTK components. With that in place, each hiccup tag can map to a widget spec in a registry. These specs are represented as small maps describing how to construct the widget, apply props to it, and what kind of container it is. Here is what the code for declaring a button looks like.

(defn- ->bool [x] (if x 1 0))

(defn- button-spec []
  {:ctor    (fn [p] (if (:label p) (g/gtk-button-new-with-label (:label p)) (g/gtk-button-new)))
   :apply   (fn [w p]
              (when (contains? p :label)     (g/gtk-button-set-label w (:label p)))
              (when (:tooltip p)             (g/gtk-widget-set-tooltip-text w (:tooltip p)))
              (when (contains? p :sensitive) (g/gtk-widget-set-sensitive w (->bool (:sensitive p)))))
   :container :none})

The reconciler drives these through a fixed lifecycle where create! runs the constructor, applies the props, and wires up the event handlers, while apply-props! re-runs the prop application against the existing widget on each re-render, patching it in place as needed. Handlers are connected once when the widget mounts, and they're expected to close over reactive cells, so the closure captured on the first render stays correct for the life of the widget, just like it does in Reagent.

Event props are :on-* keys looked up in a signal table.

(def signals
  (atom {:on-click    "clicked"
         :on-change   "changed"
         :on-activate "activate"
         :on-toggled  "toggled"}))

Each handler gets wrapped in a foreign-callable and connected with g_signal_connect_data .

(doseq [[event handler] props]
  (when-let [signal (@signals event)]
    (let [cb (ffi/foreign-callable
              (fn [widget _data] (handler))
              [:pointer :pointer] :void :collect-safe)]
      (retain-callable! cb)
      (g/g-signal-connect-data widget signal cb ffi/null ffi/null g/CONNECT-DEFAULT))))

The :collect-safe flag is important here because GTK calls the handler from inside the blocking main loop, and the callable also has to be retained on the Clojure side, since C holds it as a raw pointer that's opaque to the garbage collector.

Another detail worth noting is that GTK emits signals synchronously from its own setters, so when a re-render programmatically sets an entry's text, GTK fires changed on the spot which triggers the handler. Since the handler causes the atom to reset, you end up in a render loop. The fix is to bracket programmatic setters with a suppression set so that their emissions are ignored.

(defn- set-entry-text! [widget text]
  (when (and (some? text) (not= text (g/gtk-editable-get-text widget)))
    (swap! suppressing conj widget)
    (g/gtk-editable-set-text widget text)
    (swap! suppressing disj widget)))

Both the widget and the signal registries are open, so adding a widget the library doesn't know about is simply a matter of writing its spec and registering it.

Finally, glimmer itself doesn't need to see any of this because a backend simply has to provide a map of eight functions handed to the reconciler at registration time.

(def backend
  {:name           :gtk4
   :create!        w/create!
   :apply-props!   w/apply-props!
   :append-child!  w/append-child!
   :remove-child!  w/remove-child!
   :replace-child! w/replace-child!
   :reorder-child! w/reorder-child!
   :schedule       post-to-gui
   :run            run!})

That's the entire contract between the reactive core and the platform, and that's why writing a backend for a different toolkit is a bounded task rather than a rewrite.

Bring your own toolkit

Another notable approach is seen with glitter and its AppKit renderer glitter-uikit, which are based on Replicant . While glimmer is driven by a reactive atom where you build a tree of stateful components, Replicant rejects having local state entirely, and models the entire user interface as a single pure function which turns your application data into hiccup. While Reagent couples your rendering logic with a reactive state graph to optimize updates behind the scenes, Replicant acts as a remarkably strict unidirectional renderer where data goes in and hiccup comes out.

The same counter in glitter-uikit looks like this:

(require '[glitter-uikit.app :as app]
         '[glitter-uikit.appkit :as appkit]
         '[glitter.core :as core])

(defonce state (atom {:count 0}))

(defn view [{:keys [count]}]
  [:vbox {:spacing 12}
   [:label {:label (str "Count: " count)}]
   [:hbox {:spacing 8}
    [:button {:label "+ 1" :on {:click [[:action/inc]]}}]]])

(defn execute-actions [_event actions]
  (doseq [[kind] actions]
    (case kind
      :action/inc (swap! state update :count inc)
      nil)))

(core/set-dispatch! execute-actions)

(defn -main [& _]
  (app/run (fn [window] (appkit/mount! window view state))))

Here the leaves are AppKit views instead of GTK widgets, and notice that the button no longer closes over the atom. It simply declares what it wants done as data, and a dispatch function interprets those actions against the application state. The hiccup stays the same, and the only difference is where the state lives and who is responsible for updating it.

Conclusion

Bringing web-style development to native widgets isn't a new idea, of course. React Native popularised the approach letting you write React components, and render to the platform's native widgets. The catch there is that the app still runs inside a JavaScript runtime that talks to the platform through a bridge, while the development loop revolves around bundling JavaScript and hot-reloading it into a running app. Flutter sidesteps the bridge by bringing its own rendering engine and drawing every control itself, which means you're no longer using native widgets. Another approach is what Tauri does keeping the web frontend backed by the OS webview. This approach is lighter than Electron but still renders HTML rather than native controls, and is subject to the quirks of the webview implementation on each platform. Meanwhile, the native world has been converging on the same idea from the other side, with SwiftUI and Jetpack Compose offering declarative UIs, but those put you right back in a compiled language with a rebuild cycle and no REPL. Each of these approaches ends up being a compromise involving either having a heavyweight runtime or giving up ergonomics.

With Jolt, we can finally have the best of both worlds using native widgets without having to bundle a whole browser engine just to render the UI, have a clean Hiccup based API that lets you arrange components just like you would with HTML elements in the DOM, and have an interactive development environment where you can see the application evolve as you make changes to it. Since Jolt is a Clojure dialect that compiles to native code, there's no JVM or JavaScript runtime in the way, and you don't have to bundle a browser engine in the binary. That's the kind of feedback loop that makes web development pleasant, except it's driving real platform widgets in a native application.

Tencent Releases and Open-Sources Tencent Hy4 Preview

Hacker News
www.tencent.com
2026-08-29 15:33:23
Comments...
Original Article

Ranked among the top tier of open-source models, Hy4 preview is built for real-world productivity tasks, delivering outstanding performance across coding, office work, and scientific research

Tencent has released and open-sourced Tencent Hy4 preview, a next-generation large language model with 770B total parameters and 49B active parameters, and a context window exceeding 1M tokens. It demonstrates outstanding capabilities on real-world productivity tasks spanning coding, office work, and scientific research.

Hy4 preview is now available as an open-source model and can also be accessed globally through WorkBuddy and CodeBuddy, as well as Yuanbao, ima and other Tencent products. Users can try the model directly through these applications, or connect to it via API through Tencent Cloud TokenHub and OpenRouter.

Upon launch, Hy4 preview will be available for free on WorkBuddy and CodeBuddy for two weeks. Free access to Hy3 on both platforms has also been extended until September 30.

Hy4 preview was expanded significantly in model size, context length, and data volume, and  the advances in both pre-training and post-training have led to a major leap in overall intelligence, placing the model among the top tier of open-source models.

Hunyuan continuously works in deep co-design with products such as CodeBuddy and WorkBuddy, optimizing the real-world user experience across productivity scenarios. In a blind evaluation conducted internally by Tencent involving 163 experts and 203 engineering tasks, Hy4 preview scored an average of 2.99 out of 4.00, slightly ahead of GLM-5.3 (2.92/4.00) and Kimi K3 (2.94/4.00).

Designed for productivity, Hy4 preview was developed using high-quality training data co-created with Tencent experts across software engineering, gaming, finance, security, and other domains, as well as through deep co-design with products such as WorkBuddy. This has helped drive significant improvements across a wide range of real-world productivity tasks.

In software engineering, Hy4 preview delivers stronger understanding, planning, debugging, and validation capabilities for long-context development tasks, while also enhancing the visual quality and interaction experience of front-end development.

In office productivity and analytical scenarios, the model demonstrates a significantly stronger understanding of complex working environments and enhanced financial analysis capabilities. It has also been optimized for data analysis and cross-document collaboration, supporting the full workflow from information processing through to the creation of documents, spreadsheets, and presentations.

In game development, Hy4 preview can generate a playable prototype from a single natural-language request, and work effectively with game engines. Developers can then continue refining complex game projects through multi-turn interactions.

In scientific research, Hy4 preview demonstrates stronger capabilities in understanding, reasoning through and solving complex research problems, with notable improvements across areas including AI research and development, molecular dynamics simulation, condensed-matter physics and fundamental mathematics.

Notably, Hy4 preview also contributed to its own development process, participating for the first time in the automated optimization of training methods, data strategies, evaluation frameworks, and low-level operators. The model proposed approaches, ran experiments, and iterated based on the results, with the resulting code, logs, and feedback feeding into subsequent rounds of exploration. This established an early-stage recursive self-improvement loop.

Hy4 preview has also autonomously analyzed bottlenecks in its inference system  and carried out multiple rounds of optimization on areas such as operator fusion and communication optimization. These improvements increased end-to-end throughput by 31.8% compared with the baseline, with consistent gains across different context lengths and concurrency levels. This demonstrates the model’s ability to autonomously optimize its own inference infrastructure.

Hy4 preview continues to offer cost efficiency, helping make advanced AI more widely accessible. API pricing is set at USD 0.834 per million input tokens, USD 2.501 per million output tokens and USD 0.042 per million tokens for cache hits.

Through a preview-first approach, followed by official releases, Hunyuan continuously incorporates real-world feedback into its research and development process, enabling its models to improve by solving real-world problems. The next batch of models in the Hy4 series is expected to roll out soon.

Domain-Driven Agents

Hacker News
coldtake.dev
2026-08-29 15:28:28
Comments...
Original Article

I've been using LLMs heavily in the last years in coding, or more generally, in software engineering. I watched many times what productivity boost I could gain from it, and I used LLMs in more and more of my projects. It works well in greenfield projects, and small ones. The reality is that in day to day work we need to introduce agents into legacy codebases with heavy dependency trees, strong coupling, and a tech debt backlog full of everything we never got to. We quickly notice that the quality of work LLMs can deliver drops sharply.

The failure has a specific shape. Ask for a "job offer status" field in a greenfield repo and you get one. Ask for it in a system that has been shipping for four years and the model invents a fourth spelling of a concept that already exists three times, because the codebase itself never decided which one was real. It writes an adapter where a call was fine, or calls straight through where an adapter was the whole point. Every one of those is a question about the system that the system does not answer anywhere. The model guesses, and often guesses wrong.

So brownfield projects are deep, and technical depth is only the first layer. Underneath sits a second one: confusion, missing meaning, and no shared language to resolve it in. That is the layer the model falls into. The model is not what needs upgrading. The code is not ready , and readiness is something we can build. Incrementally. Piece by piece. Let me show you how I do it.

It is easier than before #

At the beginning of software engineering there was the one and only: tech debt. It's a natural consequence of what we, as devs, are trying to achieve. We're not ready for business decisions from the future shifting our current view of the code. We need to deliver, and deliver fast, paying some tradeoffs. As a consequence, code smell grows bigger and bigger. The usual answer is to spend part of the engineering budget on cleanups: earmark 10-20% of the technology budget for resolving tech debt. In theory... In the next quarter...

A fifth of the budget is the toll on deciding what should change and then typing it out, and those two halves have never had the same price. Deciding stayed about as expensive as it was. Typing it out collapsed. An LLM will do the mechanical half of a cleanup (the extracted module, a refactor across two packages, more test coverage) at a cost that no longer resembles 2020. Paying tech debt still takes time. It takes significantly less of it, and what is left for me is the deciding part.

Strategic vs tactical #

I split the work in two, and I'll borrow the words from John Ousterhout's A Philosophy of Software Design while being honest that I'm bending them. He uses tactical and strategic for two attitudes you can hold while coding: tactical programming is getting-it-working-now, strategic programming is investing in the design as you go. I use the same pair for a split of authorship , because the economics above cut along that line. Strategic work is deciding: reading the system, working out what has to change and why, and whether the change actually serves the feature. Tactical work is carrying that decision into the files. The first is the part that needs the system in your head. The second is the part that got cheap.

What I do #

In the first one I'm fully involved and in the second one I'm rather a reviewer than an implementer. In the first path I analyze the codebase in a more generic way, assessing the changes that need to be implemented and their alignment to the features I want to deliver. The effect of those approaches is GitHub issues I create in each repository.

The issues are then addressed by my AI system based on skills and sub-agents . A skill is a written procedure: a markdown file of instructions the model loads when the task matches it, so "address an issue" or "regenerate the context map" runs the same way every time instead of the way I happened to phrase it that morning. A sub-agent is a separate model session with its own fresh context and its own narrow job (implement, review for security, review against the spec), reporting back a result rather than dumping its whole transcript into mine.

When they are implemented, PRs are ready to jump into. I go through the review sessions, accepting the changes or asking for some improvements. I can do that incrementally, caring about the test coverage and about who breaks: before a change lands I need to know which other parts of the system consume the thing I'm touching, and whether the change is one they can survive. Now, as a software engineer, I coordinate, I plan, and I create a path for the improvements. But at that point I don't need to implement that by myself. The time is saved.

DDD as a fundament #

That leaves the strategic half, and it is worth exactly as much as the language it is written in. This is where DDD comes in.

DDD was always one of my choices for software I could still change a year later. The approach presented by Eric Evans gave us a way to shrink the communication gap between the business and the technical side. Domain-driven design, based on ubiquitous language and bounded contexts, translates what the business needs directly into the technical part. Both sides talk in the same language. With agents in the loop, that link matters even more: it is how we state our needs to the model and how we read its reasoning back. That is why I build on it so heavily.

What I do #

Every repository I own carries a .workflow.json at its root. It is my own manifest, the place a repo tells my tooling what it is: which languages it holds, which directories an agent should read first, which checks have to pass before work in it can ship. One block in it is about the domain, and declaring that block is the only registration a repo needs. There is no second registry to drift out of sync.

The block names the project, its bounded contexts, where each context's glossary lives, its subdomain type, and every edge to a neighbouring context. The example comes from a project of mine, job-offer-box , a job application tracker built as two repositories, a Rust backend I keep under the hyperion project and a web frontend. Here is the frontend's manifest, trimmed to a single edge:

{
  "domain": {
    "project": "job-offer-box",
    "contexts": [
      {
        "name": "job-box-web",
        "docs": "CONTEXT.md",
        "subdomain": "supporting",
        "edges": [
          {
            "to": "hyperion/job-offer-backend",
            "direction": "outbound",
            "pattern": "unclassified",
            "owner": "supplier",
            "shape": "codegen from the backend's document (scripts/generate-api.ts:12) ... conformist on write (src/lib/api/jobs.ts:37), ACL on read (src/lib/api/adapters/offer.ts:50)",
            "note": "conformist on write and an anticorruption layer on read; two patterns hold at once, so neither name alone is true"
          }
        ]
      }
    ]
  }
}

Read it in order. to is the address: which context on the other end. direction says who's calling whom; the web repo calls the backend, so outbound (the backend's own manifest declares the same edge inbound ). owner says whose model wins if the two sides ever disagree: the backend's, so supplier . pattern is the relationship itself, picked from a closed vocabulary; here it's unclassified , because the web repo does two different things at once. It accepts the backend's shape as-is when writing and translates it into its own shape when reading. The note spells that out; a single label would be right about one case and wrong about the other.

Beside the manifest sits a CONTEXT.md per context, the living glossary with the precise meaning of every term and the deliberately rejected synonyms. Two files per context, both owned by the repo that owns the code. Nothing above them is authored: the context map (the one document showing every context in the portfolio and every edge between them) is derived. A generator, a script that walks every repo on disk, unions the domain blocks and emits it as a single CONTEXT-MAP.md . The map is disposable and regenerable.

Back to job-offer-box . hyperion/job-offer-backend owns the product language. It persists Job Offer , Profile , Profile Variant , Resume , Cover Letter , under the rule that where two contexts author the same term, the one holding the durable state owns it. job-offer-box/job-box-web owns only the screen vocabulary ( View Model , Filter State , Facet Stats ) and marks everything else [published] , arriving verbatim as generated TypeScript from the backend's OpenAPI document. That is the level of precision an agent needs. Point it at the web repo and it knows that renaming Job Offer there belongs to the backend, that the adapters on the read path exist on purpose, and which words it is allowed to invent. With the map the model knows which context it is in, and with the glossary it knows the words used there.

Both sides declare, so disagreement is mechanical #

Every edge is declared twice, once from each side, and that duplication is the whole point. The generator cross-checks the pairs, and it is careful about what counts as a disagreement: a supplier names its own stance ( published-language ), a consumer names its own ( conformist , anticorruption-layer ), so the check is a pairing table.

I run it as a skill, at three moments: when I have touched a manifest, when I am onboarding a repo, and before I change anything another context depends on. Each disagreement it reports is a finding : one edge, one way the two declarations fail to fit. With one flag, the skill files each one as a DDD issue on the repo that owns the wrong side. The issue carries a fingerprint (the kind of finding plus the two addresses), so a re-run after a half-fix updates the same issue instead of opening a second one, and a finding that no longer appears closes its issue. From there it follows the same spine as everything else here: an issue, an agent, a PR, my review.

What comes next #

That is the strategic layer, and it is already in place. It settles where a context ends and how it talks to its neighbours: the shape of the map. The inside of any single context is still ordinary code that lets you build a nonsense object and save it.

With the context map in place and the glossary defined, I can focus on the codebase itself: taking one context at a time and migrating it to a real domain model built from DDD primitives (value objects, aggregates, domain services and others). That process makes the codebase answer the questions the model was guessing at: what this word means, who owns it, where this context stops. I'll share the whole system shortly, with the skills ready to use. Subscribe so you don't miss it.

A safe MySQL upgrade that wasn't so safe

Hacker News
blog.elis.cc
2026-08-29 15:15:51
Comments...
Original Article

I get a notification that my database version has reached end of life, and it has to be upgraded. And the AWS extended support fees are a good motivator to upgrade as soon as possible.

I had a green replica up, so I upgrade that, check that everything works correctly, and then switch over.

Quick and easy, right?

I thought so. However, not everything was correct. An hour later, I get reports of a weird bug, so I inspect the database and find out that one specific table, let’s call it table X , has its IDs assigned in a different order. The row that had ID 1 in the previous database now has ID 26.

This table is also referenced in 6 other tables, 5 of which correctly reference these new IDs, but one table is somehow using the IDs of the previous database, which now refer to completely different rows.

That is mind-boggling. How could things get so messed up?

The migration

Some time ago, before the upgrade, a migration was run to add a new auto-incrementing primary key to table X .

ALTER TABLE X ADD COLUMN id INT NOT NULL AUTO_INCREMENT PRIMARY KEY;

The migration also updated 6 related tables so that they referenced the new ID instead of the old one. For each table, the update looked roughly like this:

UPDATE some_table
JOIN x
  ON x.old_id = some_table.x_old_id
SET some_table.x_id = x.id;

The AUTO_INCREMENT column

As it turns out, adding an AUTO_INCREMENT column to a replicated table can result in the rows getting different IDs on the source and replica.

According to the MySQL documentation on replication and AUTO_INCREMENT , adding an AUTO_INCREMENT column with ALTER TABLE might not produce the same row ordering on the source and replica. The order in which the IDs are assigned depends on the storage engine and the order in which the rows are processed.

OK, I wasn’t aware of that.

But why would this new field be correctly referenced in 5 out of 6 tables and be completely messed up in one table?

The binary log format

This is where it becomes more confusing.

MySQL replication uses the “ binary log ” to record changes made on the source. Those changes are then sent to the replicas, which use them to reproduce the same transactions.

What gets recorded, and how it gets applied on the replica, depends on the binary log “format” . MySQL supports 3 “formats”:

  • STATEMENT : The SQL statement itself is written to the binary log, and the replica executes that statement.
  • ROW : The changes made to individual rows are written to the binary log, and those row changes are applied directly to the replica.
  • MIXED : With mixed logging, statement-based logging is used by default, but the logging mode switches automatically to row-based in certain cases.

Apparently, my source database had binlog_format configured as MIXED .

So the reason the 5 tables referenced the correct new IDs is because their update statements were replicated using STATEMENT mode. The exact UPDATE statement ran again on the replica. It looked up the replica’s version of x.id and wrote the correct local ID into each related table.

But for the remaining table, MySQL decided to use ROW mode instead… In that mode, the replica does not run the original UPDATE . It receives the resulting row changes from the source and applies them directly.

So the x_id values generated on the source were copied to the replica. But because table X had different IDs on the replica, those values now pointed to completely different rows.

You might ask, why did MySQL decide to use ROW mode just for one table?

The only visible difference I could find between this table and the other 5 was that this one had an AUTO_INCREMENT column.

MySQL does have specific cases involving AUTO_INCREMENT that it considers unsafe for statement-based replication and therefore logs using ROW under MIXED .

That’s ironic, isn’t it? It all seems to come down to the AUTO_INCREMENT feature in the end.

Conclusion

Be careful with MySQL replicas. The scary thing about this kind of issue is that it’s unexpected and easy to miss, but it can quickly turn into a disaster in production, and you’re left wondering how did things end up like that.

Warp builds self-improving agents on Claude

Hacker News
claude.com
2026-08-29 15:09:33
Comments...
Original Article

In our series, , we highlight how startups are transforming their industries with AI. In this article, we share how Warp turned stateless user feedback into a self-improvement loop for its agents.

The quick pitch
Name Warp
Founded 2020
Founders Zach Lloyd (CEO)
Stack Rust, Golang, GitHub Actions, internal agent orchestration platform (Oz), Claude Platform
Growth $73M raised. 800K monthly developers build on Warp. 56% of the Fortune 500 uses Warp. 10M Claude Code sessions run inside Warp to date, 400K+ per week. 40M total Warp Agent conversations.

Agents need to handle recurring tasks reliably and effectively. A first-pass prompt that gets 80% of the task correct can create a noisy and annoying experience for the user. Warp learned this the hard way, and used this to inform its product strategy, creating an improved experience for nearly 1M developers worldwide.

Warp, the AI-powered terminal and agentic development environment, builds on the Claude Platform. The team ran into this “noisy experience” problem with their internal code review agent. Engineers complained that their agent made unhelpful comments and produced low-quality output.

The team initially tried stopgap solutions, like manually rewriting the prompt based on observed code review failures. This made output more usable but didn’t scale. Improving context files like AGENTS.md also helped, but was far from a complete fix.

Ultimately, they realized, the real issue was that feedback to an agent, no matter what its purpose, typically disappears when the session ends, removing critical context from the agentic loop. Their solution: an Agent Skills -based framework to create self-improving agents where feedback compounds over time to continually refine and enhance agent output.

Read on to learn how they built it with skills on top of the Claude Platform.

Agent self-improvement loops built on skills

The central technique is a self-improvement loop using skills , which are file based encodings of knowledge that keep instructions out of the raw prompt. Warp evolved a self-improving agent architecture consisting of two skills, with human feedback in between.

The inner/base skill holds the functional domain knowledge and instructions. For example, when a PR is opened, Warp’s code agent executes using that base skill and context to produce its review.

Human feedback on agent output is a critical component for the self-improvement loop. For code review this could be something as simple as a thumbs up, but the more explicit the better.

“A human could affirm, ‘this was a good, useful comment’,” Warp founder Zach Lloyd explains, “But the human could also give detailed reasons why a code review wasn't good. Specifics like ‘you suggested renaming this variable, but our code base convention is this type of global variable uses this particular naming context’ tell the agent how to do it right next time.”

The outer/improver skill functions as an observer agent that runs on a schedule rather than per-task. It pulls the accumulated human feedback, compares what the agent suggested against how humans responded, and proposes a small, focused edit to the base skill.

Because skills are plain files, agents are extremely good at updating them. These updates, which are reviewable, approvable, and mergeable, can flow through a normal PR/code-review workflow; once merged, the next run of the inner skill inherits the improvement.

Warp now runs this pattern across its entire open-source repo, with separate spec-writing, review, and triage agents, each carrying their own self-improvement loop.

“File-based skills are a way of encoding knowledge for agents without putting that knowledge directly in the prompt, as something the agent can simply look up in the course of doing its job,” says Zach. “The framework is really simple actually: there's the base domain-specific skill and then there's the improver skill that refines  that domain-specific skill. This simplicity is the beauty of this approach.”

How to write self-improving skills for agents

Here are some of the Warp team’s tried and true tips for writing self-improving skills for agentic loops:

  • Write principles, not rules. "Construct the skill as though you're instructing a smart person, not like you're programming a computer,” Zach says. “Including direction in the skill like ’Look for repeated code’ provides better direction than exhaustive variable naming rules.”
  • Explain the why. Providing the rationale behind the rule lets the agent reason about the problem instead of following rigid instructions, again allowing for better generalization.
  • Make feedback effortless to give. Capture it where people already work, like by commenting directly on a PR or issue. Also, make this happen automatically, with no extra submission step. “Low friction is what keeps signal flowing,” Zach notes. “If you make it too hard you're not going to get the feedback and you're not going to be able to improve the skill."
  • Keep skills small and use progressive disclosure. A good skill file isn't large; it references resource files and scripts rather than dumping everything into context at once.
  • Feedback quality > volume, but volume helps. A small amount of detailed, domain-specific feedback from a senior engineer can be worth more than lots of cursory feedback because binary thumbs up/down doesn't say why . “You can get really good signal even from a relatively small sample size if it's very detailed feedback from a person around domain specific knowledge that the agent otherwise would have no way of getting,” Zach continues. “That said, the bigger the corpus of quality signal, the better. At Warp we're using a loop to manage our whole open source repo. We have hundreds of people contributing and we're doing thousands of code reviews.”
  • Put extra effort into the improver skill . Putting extra effort into writing the improver skill (the observer agent) pays off beyond the immediate agent loop, because improver skills are very reusable across different use cases.  “Outside of the domain specific knowledge component, this is a fairly reusable mechanism—the improver skill for a code review agent is not that different from the improver skill for any other agent.”

The loop in action: Warp’s issue triage agent

Warp’s issue triage agent demonstrates the self-improving agent skills framework. The pattern is triggered whenever someone files a new GitHub issue: a GitHub Action fires an agent that analyzes the issue for complexity and feasibility, assigns labels, and suggests a direction for the fix. That triage agent runs off an inner skill file holding the domain knowledge about what each label means and how to research the codebase before acting.

On a sample issue, the first-stage inner skill did a solid job but missed one label, ready to spec, which signals that a contributor can start building product and technical specs against the issue. A maintainer on the Warp team caught the gap and left feedback directly on the issue, exactly where the work was happening. Critically, he explained both what he expected and why he expected it: actionable feedback easy for the agent to absorb later.

The outer improver skill runs in Oz, Warp's agent orchestration platform , as a scheduled “update triage” agent. The agent authenticated to GitHub, ran a Python script bundled with the skill to pull recent issues carrying feedback, summarized them into a JSON file, and read that back into context. The bundled script is itself a best practice; skills can reference resource files instead of writing fresh code on every run.

From there, the agent identified the concrete feedback signals in the maintainer comments and proposed the smallest edit that captured them. It opened a PR editing the inner skill to apply the "ready to spec" label when an issue describes a real problem, even though the exact UI or UX shape is not yet defined.

Because the whole update is a skill file, it moves through the normal code-review workflow. The PR arrived with a description explaining which signals prompted the change and what it altered. A human reviews, approves, and merges, and the next run of the triage skill inherits the new knowledge. That final human step closes the loop and keeps a person in control of what actually changes.

This is the same mechanism Warp now runs at scale across its open-source repo, where spec-writing agents, review agents, and triage agents each carry their own self-improvement loop.

Any agent, no matter what its task, gets better over time if you build one of these loops into it from the start to capture human feedback signals, turn them into skill updates, and expand agents from one-off helpers into capable systems that compound across your org.

Best practices from the Warp team
Are you conflating skills with memory? Skills are procedural and stable—"how to do X," run-agnostic, changed deliberately. Memory is auto-written by the agent at inference time and never stops changing.
Do you need one improver loop, or one per agent? Meet in the middle: a templated base loop captures the overlap across your agents, with domain-specific weights layered on. A handful of improvers can each own one; a hundred should share.
What happens when the feedback is wrong? Assume it will be. Don't let the agent accept feedback blindly — give it context to sanity-check, filter whose input counts, and keep a human in the loop at either the filtering or final-review stage.
Is your domain verifiable? Build the verification harness first, then let the agent tune against it: generate a reference corpus, compare output to reference, fix, repeat.
And if it isn't domain verifiable? Lean on deterministic evals against golden outputs wherever they exist. Where you must use human feedback, restrict it to domain experts — don't open the floodgates.
How do you know the whole system is improving? Track the global metrics humans already eyeball—time to merge, contributor count, cost—and feed them back into the improver agents. Go crawl-walk-run on deployment.

View the full webinar for a live demo and deeper discussion of how Warp uses Claude to build agents that learn from team feedback and improve themselves over time.

Start building with the Claude Platform today.

Functional State Machines in Rust: Typestate and Newtype Patterns

Hacker News
dl.acm.org
2026-08-29 15:01:09
Comments...

DHS is using obscure law to snoop on journalists, non-profits, unions

Hacker News
www.theguardian.com
2026-08-29 14:44:37
Comments...
Original Article

T he Trump administration has been deploying an obscure legal maneuver to try to obtain private information on journalists, non-profits and unions, raising alarm over a power the government has asserted without judicial oversight.

In one instance, the government obtained six months of telephone records for Georgia Fort , a Minneapolis journalist. Fort was not notified of the request for her information, nor was she given a chance to contest the government’s effort to obtain them, her lawyers said in court papers .

In February of this year, federal prosecutors twice sought search warrants for account information for the YouTube channel of Fort and the journalist Don Lemon, both of whom have pleaded not guilty to criminal charges in connection to a protest at a Minneapolis church in January that they were covering. A judge twice rejected the request, writing that the government had failed to establish probable cause of a crime and that he wanted Lemon and Fort to be informed of the request so they could have a chance to challenge it. About a month after the judge’s ruling in late February, the government said it was withdrawing the request.

But officials hadn’t given up on getting the data.

Less than a month later, the DHS served Google with a different request for the YouTube information. This time, DHS utilized a different method that didn’t require approval from a judge, only a sign-off from a DHS official. It served Google an administrative summons citing an arcane provision of federal law – 19 USC 1509 – dealing with customs imports. The provision gives the DHS broad power to inspect records in order to determine whether duties and taxes are being correctly levied on imported items. It also instructed the recipients of the summons to keep it secret.

The DHS summons was issued under a statute that does give the agency broad power to demand records, but only in the limited circumstance of there being a need to investigate a customs issue, said Chris Duncan, a former lawyer at the Department of Homeland Security. “These laws have absolutely nothing to do with a domestic situation at a church, a social media post, even an immigration matter,” he said.

“It’s outrageous conduct on so many levels. It’s hard to know where to begin,” said John Roth, who served as the inspector general for the Department of Homeland Security from 2014 to 2017. “This is an improper use of the subpoena under any circumstances. This is not a customs case; it is not a customs violation. They are not investigating a customs violation.”

The episode in Minnesota was particularly alarming because it appeared to be an end run around a judge who was skeptical of the government’s need for the information.

“There is no judge in the loop. You don’t have that independent authority to scrutinize the demand and to say whether or not it’s legitimate,” said Caitlin Vogus, a senior adviser at the Freedom of the Press Foundation.

The DHS also sought and obtained six months of phone records for Fort from T-Mobile, which included records for more than 10,000 calls and text messages. Fort was not notified the government was seeking the records until mid-July, when government lawyers produced them to her lawyers. Fort’s lawyers wrote in a filing this week they were “stunned” to see the government had unilaterally been able to obtain a log of her communications after a judge had warned them about obtaining records about a journalist.

“That’s very concerning because the information demanded can help the government uncover a journalist’s confidential sources,” Vogus said.

In a statement, T-Mobile did not address why it turned over the information.

“We take our responsibility to protect customers’ privacy and personal information very seriously. Our team carefully reviews government demands for customer information and responds in accordance with the law. We don’t comment on specific law enforcement demands,” the company said.

The Department of Justice and the Department of Homeland Security both declined to comment on the use of the summons.

In addition to Fort and Lemon, the DHS also sought information on the YouTube accounts for the left-leaning outlet Democracy Now, conservative podcaster Megyn Kelly, the Milwaukee Journal-Sentinel and an independent journalist named Brendan Gutenschwager. Some of the videos they cited in the summons were livestreams of the protest, but not all of them. The video cited as part of the request for information on Democracy Now involved a news report on the protest and an interview with Nekima Levy Armstrong, who led the protest. The video cited on the request for Kelly’s show included an interview with Jonathan Parnell, the pastor at the church.

It’s unclear why exactly the DHS wanted the YouTube account information, which includes things like a user’s IP address, and information about when a user was logging in.

“It’s still concerning that the government sought subscriber information for Lemon and Fort because there’s no reason it would need this information for the criminal charges that it’s brought against them,” Vogus said. “It’s not a crime to post a YouTube video, and it’s not at all clear why the government is demanding this information about Lemon and Fort’s YouTube accounts.”

The episode was the most recent example of an alarming pattern in recent months in which the DHS avoided judicial scrutiny and deployed a summons related to customs enforcement to pressure companies into turning over information on Americans. The US constitution’s fourth amendment protects against unreasonable searches and seizures and law enforcement generally must show a judge or a grand jury they have probable cause to believe the materials they want to search will produce evidence of a crime.

But over the last few months, the Department of Homeland Security has undertaken a brazen effort to get around that fundamental safeguard. In addition to efforts to obtain records on Minnesota journalists, the DHS has used 1509 summonses to pressure social media companies to unmask the identities of people who have criticized ICE officers and to obtain financial information on a host of unions and left-leaning non-profit organizations in Minneapolis.

In a separate case in which 15 activists face criminal conspiracy charges , DHS successfully obtained the financial records of the Sunrise Movement, the Service Employees International Union (SEIU) and the Communications Workers of America, as well as Venmo records for a non-profit organization called Voices for Racial Justice. None of the organizations is charged with crimes and the DHS did not offer an explanation for why it needed the records. PayPal, Venmo’s parent company, declined to comment.

“There’s a long history of DHS abusing this summons authority in particular, and using it to seek both records that are clearly outside of its scope in general, and more particularly to try to go after people whose speech DHS is somehow irked by – but whose speech is protected by the first amendment,” said Nathan Freed Wessler, a lawyer at the American Civil Liberties Union who specializes in privacy issues.

It is difficult to determine the frequency with which the DHS is serving the 1509 summonses and how often they are successful in obtaining information. The summonses often remain hidden from public view unless the company being served, or the user, challenges them. Companies are not required to notify users that they have been served with a 1509 summons for information, though some do. The New York Times reported in February that the DHS had served hundreds of administrative subpoenas on social media companies for information on users.

“Without knowing how many of these subpoenas there are and what they’re being used for, there’s no way for courts or lawmakers or the public to put checks on executive branch abuses,” said Wessler, the ACLU attorney.

In the Minneapolis church case involving Lemon and Fort, the Trump administration has argued it had the power to use the customs-related summons to obtain information even though the crimes the defendants were charged with have nothing to do with customs. The protesters entered the church because a local ICE official was a pastor there, and could have potentially assaulted him or interfered with his duties, justice department lawyers wrote in a filing earlier this year. Even though the man does not appear to have been there, and there were no DHS officials at the church or involved in the protest, lawyers said the DHS was entitled to issue the summons because it was investigating a potential assault on a law enforcement officer.

In court filings, the Trump administration has argued the Department of Homeland Security has the power to demand such records without judicial oversight.

“Although § 1509 references ‘duties, fees, and taxes,’ the plain language of the statute does not limit DHS’s investigative authority to those subjects; instead, DHS is authorized to investigate potential crimes to ensure ‘compliance with the laws of the United States administered by the United States Customs Service,’” which has been folded into the Department of Homeland Security, a lawyer wrote in a December court filing last year.

That is an overbroad misreading of the statute, one expert said.

“I don’t buy that,” said Duncan, the former DHS lawyer. “It’s not a free-for-all that was thrown in there. Congress does not operate that way. Given these provisions were specifically incorporated into title 19, the customs statute, Congress obviously intended to authorize only records, demands and interviews in furtherance of investigations into customs violations, not wild goose chases into possible violations of any federal law without any judicial oversight.”

In Fort’s case, Google did not comply with the summons for any of the accounts. The company responded to the DHS by saying it had not offered evidence of how it was related to a customs investigation.

A Google spokesperson said the company reviews each request for data it gets to ensure it is legal and pushes back when it is too broad or doesn’t follow the correct process.

Many social media companies say they notify users when law enforcement makes a request for their information and give them a chance to contest the summons. It’s not always clear what the companies will do if the user doesn’t respond or won’t contest the request themselves. But privacy experts question whether that notice is adequate, saying many users are confused when they are contacted and do not have the resources to get a lawyer to contest the demand in court.

“They want people to think that they are going to stand up for people’s privacy, but they really shifted the burden completely onto the user,” said Lauren Regan, executive director of the Civil Liberties Defense Center, which represented a Reddit user who challenged the government’s efforts to get Reddit to reveal their identity through a 1509 summons.

Companies are not required to respond to a 1509 summons and can ignore the request if they think it is unlawful, forcing the government to go to court to try to enforce the summons. The Guardian was unable to identify any cases where the government attempted to get a court order to enforce a 1509 summons outside of the traditional customs context. Companies can also file their own motions to try to quash the summonses.

“If a user actually hired a lawyer, it would cost tens of thousands of dollars to fight one of these,” said F Mario Trujillo, a lawyer at the Electronic Frontier Foundation, a privacy watchdog. “They are not shouldering that burden; they’re pushing that cost onto users and onto non-profit groups when they could easily get their high-powered lawyers who are being paid $500 to $1,000 an hour to fight these.”

In 2017, Twitter filed a lawsuit challenging a Department of Homeland Security 1509 summons seeking to unmask an account, @alt_uscis, that was critical of the DHS. The department ultimately withdrew the summons.

In several cases, the DHS has withdrawn a 1509 summons after it was challenged in court and before a judge could rule on its legality. That may be a deliberate strategy to avoid having a judge rule on the legality of the summons.

In one instance last year, the DHS served a 1509 summons on Meta to unmask the user behind an Instagram and Facebook account that monitored ICE agent activities in the Philadelphia suburbs. The user challenged the summons in court, saying it was clearly not authorized under the law. Lawyers for the DHS defended the summons, saying it fell within the scope of laws the DHS enforced. Both sides presented arguments before a judge on 15 January and DHS withdrew the summons the next day.

“They don’t want a judge to take away this scary tool because they are getting stuff out of it,” Regan said. “Once a court ruling says ‘thou shalt not use this statute’, it does not apply.”

In 2017, the DHS inspector general issued a report finding “inconsistent – and, in some cases, improper” – use of the 1509 summonses after the @alt_uscis case.

The office of the inspector general review found that officials in Customs and Border Protection’s office of professional responsibility were regularly misusing the subpoena and recommended a series of reforms to ensure more oversight over those that were used. The office agreed to the reforms.

The Internet Is Kind of a Predatory Cesspit Now

Hacker News
www.stephendiehl.com
2026-08-29 14:40:56
Comments...
Original Article

I’m a kid of the 90s, and I still remember the early internet. It was slow, ugly, unreliable, and full of cranks, a strange world of wheezing dial-up modems, Usenet flamewars, <marquee> tags, and dancing babies. It was also stubbornly alive and human. People built websites about Babylon 5, model rockets, train timetables, shareware, and whatever else had colonised their minds. Most of it had no business model. That was the literal point. The web felt like a public square assembled by obsessive amateurs.

None of this was entirely innocent. There were scams, viruses, Nazis, pornography, and chain emails from deposed Nigerian princes. But then predation moved from the periphery to the centre. It used to be an abuse of the network. Now it is the network’s organising principle. The scammer once had to find a victim. The platform now finds one, profiles the weakness, optimises the pitch, processes the payment, and recommends the next scam. What was once an aberration has become the norm.

The modern internet is now a highly optimised machine for detecting human vulnerability, amplifying it, and placing a payment link beside it. Any insecurity can become a commercial niche, including the desire to escape commercial life itself. There is always a course, a newsletter, a private community, or a referral code waiting at the end of the funnel.

The bleak part is not that grifters exist. Every society has hucksters. It is that much of the population has been conscripted into the downline. Ordinary people now spend their lives promoting investments they barely understand, products that do not work, and political claims they have never examined. Many earn nothing. They are unpaid distributors for someone farther up the pyramid. The consumer, salesman, and product have collapsed into the same exhausted person.

People increasingly behave like addicts because addiction is the business model. The feed supplies alternating doses of outrage, fear, envy, lust, and hope. Each feeling arrives with something to buy. People doomscroll until they acquire the anxiety that the next influencer will monetise. Then they purchase a bet, a coin, a supplement, a course, or an enemy. Finally, they repost the pitch. Consumption becomes distribution. The mark becomes the salesman.

This is an industrial system for manufacturing weakness at scale. A legitimate business can survive a satisfied customer. A grift cannot. It needs the customer frightened, aggrieved, lonely, sick, or greedy forever.

When I started writing about cryptocurrency in 2020, I still carried a naive assumption about the size of this economy. I thought people were generally decent and the grifter class was a small pool of degenerates with rotten moral character, preying on those made vulnerable by the material conditions of our time.

I was very wrong. The grift economy is massive. More disturbing still, it is participatory. A large and growing share of the population now appears willing to devote every waking hour to fleecing their fellow man as a career choice. They stream, post, recruit, promote, refer, astroturf, and close. They turn every friendship into a lead and every conversation into a qualifying call. They do not clock out because the market follows them into bed. The smartphone is a shop counter that sleeps beside their head.

Obviously most of these people are not succeeding. The maths simply can never work out. That is part of the trick. The aspiring influencer with forty-seven followers is not an entrepreneur in any meaningful sense. He is free labour for the platform and cheap distribution for the person selling him the dream. The affiliate marketer buys a course about affiliate marketing, then recovers the cost by selling the same course to the next affiliate marketer. The life coach coaches new life coaches. The dropshipper sells tutorials to failed dropshippers. The pyramid is social before it is financial. Everyone stands on someone else while insisting they are about to escape.

This arrangement blurs the useful moral distinction between predator and prey. Many online grifters are themselves marks. They believe the rubbish they sell because belief makes the selling bearable. They have sunk money, time, identity, and public dignity into the scheme. Admitting the product is worthless would mean admitting that years of their life were worthless too. It is psychologically cheaper to recruit another victim. The fraud sustains the faith, and the faith sustains the fraud.

A normal trade ends when a need is satiated. You need a chair. Someone sells you a chair. You sit down and stop thinking about chairs. However, an online grift can never satiate. It must preserve the need that feeds it. The grievance merchant cannot resolve your grievance. The wellness influencer cannot let you feel well. The trading guru cannot let you become financially secure. The manosphere podcaster cannot let young men become calm, loved, and socially competent. Satisfaction is churn. Misery is recurring revenue.

The platforms did not invent fear, greed, loneliness, or status anxiety. They industrialised their extraction. Their recommendation systems are vast reinforcement-learning loops that continuously experiment on human weakness. Each objective is a moving composite of high-dimensional signals for attention, retention, and conversion, dispersed across models, metrics, tests, and feedback systems. The subject cannot see the experiment. The operator cannot fully explain it. The regulator can barely comprehend it. The loop knows only that one stimulus keeps a person scrolling while another lets them leave. Calm accuracy loses. Threat, transgression, humiliation, and impossible promises win. The resulting social damage appears nowhere in the objective function. It arrives as an externality.

This creates a brutal selection environment. The honest financial adviser explains diversification and gets twelve views. The crypto lunatic predicts a thousandfold return and gets twelve million. The physician says a chronic condition requires careful management. The wellness crank says seed oils are poisoning your soul. The historian describes an ambiguous event with contingent causes. The political influencer identifies a secret cabal and gives you the address of a pizza parlour. One of these people has the better business model. It is not the one burdened by reality.

The system is dopaminergic in the most banal and mechanical sense. It runs on anticipation, uncertainty, and variable reward. The next refresh might bring approval, outrage, profit, or vindication. Usually it brings nothing, which makes the next refresh more urgent. Social media fused the Skinner box with the commission structure. The addict is handed a referral code and told he is now a small business owner.

Crypto has become the subject of my verbal ire so often because it is the apotheosis of the grift economy. It takes alienation, precarity, gambling addiction, technological mystification, and a thick slurry of libertarian derp, then synthesises them into the ultimate predatory investment product.

Crypto also perfected the recursive structure of the modern online grift. Promotion creates price movement. Price movement is presented as proof of adoption. That proof recruits new buyers. Their money creates more price movement. Every participant has a direct financial incentive to become a publicist for his own position. The asset comes with its own volunteer propaganda network. It is a pyramid scheme with a podcast department.

Much to my dismay, the rest of the internet has learned the same lesson. The cheapest product is empty promises untethered to reality. The most scalable labour force is the addict. The best marketing conceals itself inside identity. Sell people a worldview, and they will advertise it for free because criticism of the product now feels like criticism of the self.

Language models will make this cheaper and worse. The cost of producing plausible lies has been driven to precisely zero. One person can generate a landfill of articles, videos, testimonials, investment analysis, and synthetic experts before breakfast. The grift no longer needs conviction, charisma, or even a pulse. It needs a language model, an affiliate account, and access to a population whose critical faculties have been sandblasted by twenty years of algorithmic media.

There is a temptation to regard the people caught in this machine with simple contempt. Some deserve it. A person who knowingly ruins strangers for commission has made a moral choice. But contempt is not an analysis. Precarity supplies the recruits. Alienation supplies the audience. The collapse of stable work, affordable housing, local institutions, and plausible routes to material security is what makes the pitch of the grift economy so seductive. The grift offers agency where ordinary life offers delay. It offers community where society offers isolation. It offers a jackpot where work offers a performance review and another year of rent increases.

Then it metabolises those injuries into new injuries. The lonely man buys a doctrine that makes him intolerable to women. The indebted worker gambles his remaining savings on a crypto token. The frightened patient abandons medicine for supplements. The politically powerless person spends fourteen hours a day screaming at strangers while the people with power quietly cut his wages and public services. The promised escape reproduces the condition that made escape desirable.

It is a desperately sad way to live. There is no craft in it, no solidarity, and no completion. No compassion or joy. Every relationship becomes an audience. Every interest just becomes grist for the content mill. Every conviction becomes a content strategy. The grifter can never rest because absence kills engagement. The mark can never rest because the next post might contain the secret. Both wake to the same notifications, trapped on a dopamine treadmill driven by opaque algorithms that can never slow down.

The worst advice from the 90s, “just say no,” starts to look less stupid when our greatest technical innovation learns to turn distress into inventory. Disconnection is not Luddism in that environment. It is the refusal to mistake a predatory system for a social world.

Complete disconnection is nearly impossible. Modern life no longer permits it. But an appliance is used for a bounded purpose and then put away. Emails, train times, articles, and files all have endpoints. Infinite feeds of drivel do not. They carry the casino into bed and let an opaque RL loop select the emotions that arrive before breakfast.

The internet is indisputably an inhuman place. Not because it contains no humans. Billions of us are in here, screaming frantically at each other while feeling utterly alone. It is inhuman because the systems governing it are utterly alien algorithms that cannot recognise human ends. They recognise engagement, conversion, retention, and growth. Grief is a market segment. Loneliness is a targeting signal. Friendship is a retention mechanism. Political conviction is ad inventory. Nothing can simply matter. It must perform.

Life inside this environment means adopting its categories. Thoughts are assessed by their reach, experiences by their shareability, and people by their usefulness to an identity. A person becomes legible to the machine by becoming less legible to himself. Eventually the system no longer needs to impose its values. Its subjects carry them in their pockets and enforce them on their own minds.

The physical world is not pure. It contains salesmen, casinos, demagogues, fanatics, and bores. It also contains stubborn limits. A conversation ends. A pub closes. A book runs out of pages. Your friend gets tired of hearing you talk and tells you to shut up. Reality supplies friction, and friction is one of the few remaining defences against appetite without limit.

We are not going back to the early internet. Nor should we romanticise it. The old web had plenty of sewage. What it also had was space beyond the market. A person could make something without becoming a brand. A conversation could end without a conversion. A community could exist without turning its members into marks for an investment scheme.

The question is not whether the internet contains useful things. It does. The question is whether human existence should be organised around alien and inhuman objective functions no human chose and nobody can inspect or understand. An RL loop can optimise engagement, retention, and conversion. It cannot tell us what a human life is for. The final grift is letting the loop decide what your life should be.

LLMs are making me lose my savviness

Hacker News
pgaleone.eu
2026-08-29 14:38:52
Comments...
Original Article

I don’t know what’s going on. I always wanted to solve problems and create things, but now that I have access to a tool that’s able to speed up the whole design and development process… I’m just bored.

I don’t feel the passion of building anymore, mainly because I’m not building at all. There’s no craft in letting something else build on your behalf, there’s no real thought or design in writing prompts. There’s no engineering or challenge left. It’s just: prompt, evaluate the output, adjust, and repeat. What the hell is this? Sometimes I use them to actually learn something - but it’s a different way of learning. It’s like reading a summary or a description of some math formula, without applying it - quite pointless.

I have always been a “maker” - in my own way. I used to study topics in depth, spending hours and sleepless nights thinking about problems and solutions. I’ve experienced that great feeling of “this is a great idea” coming out of nowhere while doing unrelated activities, and having to rush back at my desk to write it down and implement it. That was great - it was rewarding, it was really meaningful. My brain was working and I felt satisfied every time I looked at what I created. Perhaps this is the result of 5 years of university studying computer engineering, but I guess not, it’s something I’ve always done and the engineering mindset just fit.

Over the years, I’ve built software of all kinds: from ML libraries to web development tools, passing through websites, wrote an infinite number of scripts for Linux system administration, set up servers, created online communities of tech enthusiast, designed database architectures. And a lot more - my guilty pleasure of mixing languages and technologies that I didn’t know, just for the fun of experiment, learning, challenge myself, and spend some time having fun.

Now, all of that feels… gone? I can just have an idea, ask the model-of-the-month to implement it, and - wow - it’s there. Written in no time and with code quality that improves month after month. If I add guardrails, rules, skills, and design documents upfront, the model generates pretty much the same thing I would have written (not really - but you got the idea). Sure, it still depends on the size and complexity of the idea, but anyway, the possibility of prototyping in no time is nice — but terrible?

To be clear, no one is forcing me to do this on my free time. On the job - and apparently across corporate tech in general - there’s this huge pressure for using those tools to not “get left behind”. Left behind what, exactly? I’m quite sure that if someone finds a real productivity metric for the software development, that takes into account speed of execution, technical debt, maintainability, and cost - LLMs won’t shine, and their introduction and usage without brain 1 is just the generation of endless technical debt.

Still, I find myself using LLMs locally because they are a tool, and as I did for any other tool and technology I discovered and used over the years, I just want to use them and master them. But this time the usage is really boring… Luckily in this process, at least, I had some fun setting up a machine for local inference.

What’s the point?

The point was never just going from A to B. The point has always been to have fun while going from A to B, learn something new along the way and gain savvy.

That’s the core issue: savvy. And I am losing it.

According to Merriam-Webster :

savvy : having or showing perception, comprehension, or shrewdness especially in practical matters.

Savvy is the fundamental idea for me - learning by doing. Do, make mistakes, learn from them, repeat, and grow.

With the LLMs every time there’s a mistake, I don’t learn. I can spot the mistake because I have some experience (lucky enough to have been born 34 years ago), I can pinpoint the mistake and let the LLM fix it.

The shitty thing here is that LLM providers can steal my savviness to train their models - so I’m not even going to see those mistakes anymore, and I can’t keep my savviness trained.

So… what now?

I don’t know. In the process of using LLMs I’m still learning new things and having some fun — at least I set up a Linux machine for local inference, and that part was a blast. But this blog post is mainly just a rant, humanly written, that’s going to be used by some company to train some LLM and in the future used by someone else to generate something similar, when prompted “Write me an article that targets the niche of software engineers that are bored by the AI usage. Do not make mistakes”.


vLLM v0.28.0

Hacker News
github.com
2026-08-29 14:22:00
Comments...
Original Article

v0.28.0

Highlights

This release features 584 commits from 270 contributors (76 new)!

  • Kimi-K3 performance push : a major optimization effort for Kimi-K3 across the stack — Decode Context Parallel (DCP) support ( #50484 ), fused FlashKDA decode and prefill kernels ( #50654 , #51311 , #52458 ), SiTU activation support for MegaMoE ( #50510 ), GEMM-RS for sequence parallelism ( #52079 ), combined all-gathers with 1.5~3x kernel-level speedup ( #51070 ), an adaptive speculative token budget delivering ~60% better DSpark TTFT ( #51725 ), and optional shared-expert sharding saving ~17 GiB of memory per GPU ( #50912 ). Kimi-K3 also now runs on ROCm with the V2 model runner ( #51653 ).
  • DeepSeek V4 : sparse MLA now works end-to-end for plain decode, MTP, and DSpark speculative decoding ( #51538 ), joined by AMD Quark NVFP4 support ( #47972 ), reasoning-effort prompts and mappings ( #50580 ), sparse top-k metadata kernel optimizations ( #52084 , #51967 ), narrowed eager CUDA graph regions ( #51430 , #52401 ), and ROCm enablement on gfx11 and gfx950 ( #47017 , #52212 ).
  • Speculative decoding advances : DFlash2 with local convolution and a candidate selector ( #52816 ), DSpark confidence-scheduled verification ( #47808 ), and async scheduling auto-enabled for draft models ( #48341 ).
  • Model Runner V2 maturation : E/P/D disaggregation ( #38390 ), weight offloading ( #51413 ), multi-layer MTP KV cache support ( #50062 ), encoder CUDA graphs ( #49852 ), decoder token-wise pooling ( #50931 ) plus Transformers pooling models ( #52425 ), attention-free models ( #52374 ), and thinking_token_budget support ( #46727 ).
  • Tiered KV cache offloading : disk offloading support ( #49644 ), out-of-tree secondary tier managers via module_path ( #51007 ), partial secondary-tier load results ( #50321 ), tiering metrics ( #48798 ), and a canonical CPU layout for parallelism-agnostic offload ( #48414 ).
  • Rust frontend & gRPC : a standalone renderer ( #50289 ), multimodal image inference over gRPC ( #50368 ), explicit data-parallel rank routing ( #51178 ), and RL lifecycle control ( #51316 ), with protobuf schemas now published to Buf ( #51276 ).
  • New defaults : max_num_batched_tokens raised from 8192 to 16384 ( #51726 ), prefix caching enabled by default for Mamba models ( #50991 ), and the Blackwell CUDA graph capture default raised to 1024 ( #49390 ).
  • Breaking changes : bitsandbytes support migrated to an out-of-tree plugin ( #43529 ); Transformers bumped to 5.15.0 ( #51668 ); the deprecated calculate_kv_scales runtime KV scale calculation was removed ( #49389 ); override_attention_dtype was removed ( #48684 ).

Release Artifacts

Python Wheels

Platform Install
PyPI (CUDA 13.0) pip install vllm
PyPI (CUDA 13.0, uv) uv pip install vllm --torch-backend=auto
ROCm pip install vllm --extra-index-url https://wheels.vllm.ai/rocm/0.28.0/rocm722

Docker Images

Platform Docker Image
CUDA 13.0 (Default) docker pull vllm/vllm-openai:v0.28.0 ( v0.28.0-cu130 also works)
CUDA 12.9 docker pull vllm/vllm-openai:v0.28.0-cu129
CUDA 13.0 + Ubuntu 24.04 docker pull vllm/vllm-openai:v0.28.0-ubuntu2404
CUDA 12.9 + Ubuntu 24.04 docker pull vllm/vllm-openai:v0.28.0-cu129-ubuntu2404
ROCm docker pull vllm/vllm-openai-rocm:v0.28.0
CPU docker pull vllm/vllm-openai-cpu:v0.28.0
XPU docker pull vllm/vllm-openai-xpu:v0.28.0

Other Artifacts

Pre-built release artifacts are available in the Assets section at the bottom of this page, including:

  • Source distribution tarball
  • CUDA 12.9 Python wheels for x86_64 and arm64
  • CUDA 13.0 Python wheels for x86_64 and arm64
  • CPU Python wheels for x86_64, arm64, and macOS

Model Support

  • New models : Muse Glimmer ( #51655 ), Ling 3.0 Flash with BF16, MTP, and parser support ( #51045 ) plus an FP8 variant ( #51265 ) and hybrid MXFP4 routed experts ( #52114 ), Dots3 NOTE native multimodal support ( #51255 ), and Interns2mobius ( #51149 ).
  • Qwen : Qwen3.8 enabled on AMD ROCm ( #50068 ), fused CUDA post-conv MTP decode kernel for Qwen3.5 GDN ( #51674 ), GDN gates aligned with speculative tokens ( #51812 ), and Qwen3.5 fixes for text-only checkpoints ( #50734 , #50355 ).
  • Transformers modeling backend : MLA support ( #48250 ), hardware-agnostic model definition ( #49458 ), fully generalized input embedding handling ( #51247 ), logit softcapping ( #52173 ), and a hardened multimodal path ( #51408 , #51657 ).
  • LoRA : vision tower LoRA for Gemma4 ( #42662 ), tower/connector LoRA for Keye ( #51780 ) and Ultravox ( #48215 ).
  • Vision encoders : ViT full CUDA graph for Kimi-K2.5 ( #50929 ) and Ernie-4.5-VL ( #45254 , #51461 ), torch.compile for the Qwen3-VL encoder ( #40116 ), and long-blocking H2D copies avoided in ViT ( #51841 ).
  • MoE : extended EPLB support for Mistral Large 3 and additional MoE backends ( #48355 ), CuTe DSL skinny GEMM extended to GLM-5.2 ( #49791 ).
  • Speculative decoding coverage : EAGLE3 support declared on KimiLinear ( #52171 ), Qwen3.6 dSpark acceptance coverage ( #51310 ).
  • Correctness : MiniMax-M3 NVFP4 inference ( #48929 ) and compressed-tensors FP8 MoE SwiGLU params ( #46845 ), Gemma3n/Gemma4 variable-length audio batch padding ( #50958 ), Gemma 4 compatibility with the upcoming Transformers version ( #49797 ), and a Qwen3-Omni crash on video without an audio track ( #48420 ).
  • Multimodal performance : fused on-device multimodal preprocess normalization ( #50411 ), faster placeholder and token-match scanning ( #50716 ), and repeated prompt-update scans avoided ( #51774 ).

Engine Core

  • Speculative decoding : DSpark confidence-scheduled verification ( #47808 ), top-k DSpark Markov projection ( #49969 ), DFlash2 with local convolution and a candidate selector ( #52816 ), async scheduling auto-enabled for draft models ( #48341 ), fused MTP trailing all-reduce with local-argmax draft tokens ( #49793 ), and an adaptive budget for speculative scheduled input tokens ( #51725 ).
  • KV cache & scheduling : per-request scheduling for MLA chunked context ( #50613 ), partial-tail prefix reuse with fine-grained prefix matching ( #50507 ), backend-published KV packing in the KV-cache layout refactor ( #51612 , #51704 ), LIFO free-block reuse order restored when prefix caching is off ( #51482 ), and silent request skipping in priority scheduling fixed ( #49206 ).
  • Performance : continued elimination of GPU<->CPU syncs on the execution path ( #51458 , #51738 , #52369 ) now guarded by a CI sync check ( #43107 ), new JIT warmup infrastructure with predicate filtering ( #49315 ), the top-k/top-p Triton sampler launched with 8 warps ( #51507 ), detokenization skipped in offline beam search ( #50333 ), Mask Replay ( #49577 ), optimized long-context MLA cache gathers ( #51739 ), and HF revisions resolved to a commit hash once per model load ( #49990 ).
  • Hybrid/Mamba : prefix caching on by default ( #50991 ), the final part of the Mamba attention module refactor ( #44857 ), 3D-grid tiling of the state-copy Triton kernels ( #49436 ), and Mamba alignment applied before encoder caps ( #51603 ).
  • RL workflows : stateful trainer send over NCCL and sparse NCCL ( #50902 ), CuMemAllocator.discard() for tag-selective GPU memory release ( #52514 ), level-2 sleep/wake/reload fixed with LoRA enabled ( #39935 ), and rewritten weight-transfer docs with standardized examples ( #51729 ).
  • Startup robustness : file:// rendezvous for single-node executors eliminates startup port races ( #50999 , #51652 ), frontend processes are watched during engine startup ( #43417 ), a get_open_port() livelock on DP-reserved ports was fixed ( #50965 ), and NVML is no longer re-initialized on every device-capability check ( #50393 ).

Hardware & Performance

  • NVIDIA : FlashInfer XQA decode support on SM12x ( #49718 ), a CuTeDSL fused query kernel on SM100 ( #49792 ), programmatic dependent launch for the DSA decode kernels ( #50230 ), the native DSA decode path for MTP=3 on SM90 ( #52164 ), GB10 fused-MoE FP8 tuning configs ( #52502 ), and B12X dense linear backends ( #52016 ).
  • AMD ROCm : torch 2.12 / triton 3.7 stack bump ( #50607 ), AITER and FP8 inference enabled on GFX120x ( #43615 ), DeepSeek-V4 on gfx11 ( #47017 ), optimized Triton sparse-MLA decode on gfx950 ( #52212 ), FlyDSL decode-attention kernel for 4-bit TurboQuant KV cache ( #47896 ) and an fp8 MQA logits kernel on gfx942 ( #49544 ), a fused Kimi-K3 KDA decode kernel ( #50654 ), fused bf16→fp32 router GEMM ( #50268 ), pinned memory on supported WSL2 kernels ( #50126 ), and preshuffled sparse indexing for 16-token blocks ( #51216 ).
  • Intel XPU : a torch linear backend including blockwise GEMM ( #49664 , #50826 ), MXFP8 linear weights for the INC DeepSeek V4 model ( #48476 ), async-scheduling PP sampled-token broadcast overlapped with compute ( #51650 ), an XPU wheel added to the release pipeline ( #52108 ), tuned Mamba SSU configs for Arc Pro B70 ( #50534 ), and UVA weight offloading fixes ( #51770 ).
  • CPU : an MLA backend so DeepSeek-V2/V3 can run on CPU ( #49453 ), a triton-cpu wheel ( #52092 ), GPTQ and AWQ enabled on s390x ( #51148 ) along with tcmalloc ( #50841 ), BF16 MoE routed through zentorch on AMD ( #44201 ), an unquantized MoE backend for Power (VSX) ( #51624 ), unquantized MoE migrated to the modular-kernel experts structure ( #50133 ), and the MXFP4 block scale folded in 2 instructions instead of 4 ( #51583 ).

Large Scale Serving

  • E/P/D disaggregation : Model Runner V2 E/P/D support ( #38390 ), duplicate image preprocessing removed with GPU-side preprocessing ( #50390 ), KV consumers may omit multimodal embeddings ( #52697 ), encoder-instance requests kept alive until their images are encoded ( #50275 ), and EC connector scheduler/worker metadata plumbing ( #49579 , #49585 ).
  • KV offloading : disk offloading for SimpleCPUOffloadConnector ( #49644 ), out-of-tree secondary tier managers via module_path ( #51007 ), partial secondary-tier load results ( #50321 ), tiering offloading metrics ( #48798 ), data-parallel topology exposed to offloading backends ( #51879 ), a canonical CPU layout for parallelism-agnostic offload ( #48414 ), and quadratic ARC batch eviction avoided ( #50992 ).
  • Mooncake : store group semantics ( #44956 ), tenant ID support ( #48069 ), and official wheels in the Docker image ( #51067 ).
  • Connectors : transfer mode (push/pull) included in the NIXL compatibility hash ( #50620 ), a MoRIIO per-layer READ-completion barrier ( #48534 ), 2P2D wide-EP with mori-ep/mori-io at dp=ep=16 ( #45043 ), and stale remote cleanup in the push connector ( #50234 ).
  • Parallelism : EPLB balancedness calculation fixed and tested ( #51813 ), dense multinode DP rescope ( #49212 ).

Quantization

  • Online quantization : online MXFP4 support ( #49347 ), online weight scales shared across TP ( #49764 ), precision preserved in online NVFP4 expert packing ( #50029 ), and the online NVFP4 MoE kernel reused across reloads ( #50074 ).
  • NVFP4 : batch-invariant NVFP4 MoE via CUTLASS ( #40372 ), KV 4-over-6 scale search ( #45187 ), CuTeDSL MoE with SwiGLU-OAI and ReLU2 activations ( #47106 ), and out_dtype matched to the model dtype ( #48861 ).
  • New kernels : block-wise scaled_mm ( #49932 ), DeepSeek-V4 AMD Quark NVFP4 with an emulation kernel ( #47972 ).
  • Fixes : dynamic INT8 W8A8 MoE config no longer built as W8A16 ( #50833 ) and a TritonExperts crash ( #51411 ), MXFP4 conversion for FlashInfer CUTLASS ( #51038 ), fp32 weight scales and per-expert checkpoint mapping for MXFP4 ( #51419 ), and fused block-scale orientation ( #50727 ).

API & Frontend

  • New capabilities : request priority parsed from an HTTP header ( #51089 ), session ID plumbing into requests ( #48048 ), count_reasoning_tokens in the streaming parser engine ( #45802 ), content_parts on /inference/v1/generate ( #51478 ), model optional on all /derender request classes ( #51463 ), output token IDs logged at DEBUG level ( #52098 ), and vLLM Recipes connected to native config-based deployment and benchmarking ( #51308 , #51878 ).
  • Rust frontend : a standalone renderer ( #50289 ), gRPC multimodal image inference ( #50368 ), explicit data-parallel rank routing ( #51178 ), RL lifecycle control ( #51316 ), dynamic tools from developer messages ( #51144 ), protobuf schemas published to Buf ( #51276 ), and MiniJinja upgraded to 2.22 ( #51235 ).
  • Anthropic API : 4xx returned for client-caused errors on /v1/messages ( #52246 ), disable_parallel_tool_use preserved ( #52021 ), and stop sequences bounded ( #51997 ).
  • Cohere : upstreamed parser fixes ( #51998 ), stop sequences reported correctly ( #51556 ), and vectorized binary embedding bit-packing ( #52277 ).
  • Structured output : request stop tokens masked in xgrammar until the grammar terminates ( #49227 , #50595 ), NUL bytes rejected in structured_outputs.regex ( #51796 ), negative token IDs rejected as out-of-vocabulary ( #51795 ), and VLLMValidationError raised from validators ( #52394 ).
  • Robustness : uvicorn signal handlers disabled instead of racing them ( #50916 ), a consolidated entrypoint exception handler ( #52261 ), 400 instead of 500 on non-object JSON bodies ( #51654 , #52528 ), generation inputs bounded before expensive work ( #51447 ), and cache_salt now required to be non-empty ( #50816 ).

Security

  • Fixed a DoS via sample-rate forgery that bypassed the audio decode duration guard ( #49948 ); the audio decode duration limit is now also enforced in NanoNemotronVL ( #50221 ).
  • DeepStream classified as a GPU backend with pixel limits enforced ( #50755 ).
  • _load_ov2_processor guarded with resolve_trust_remote_code ( #52952 ).
  • Documentation now warns that --api-key does not gate all endpoints ( #51999 ).

Dependencies

  • Transformers 5.15.0 ( #51668 ), huggingface-hub 1.27.0 ( #51422 ), fastsafetensors upgrade ( #50827 ).
  • ROCm: torch 2.12, triton 3.7, torchaudio, torchvision ( #50607 ).
  • Runtime image upgraded to Ubuntu 24.04, picking up rdma-core > 44 ( #51058 ).
  • DeepGEMM pinned to the deepseek-ai nv_dev tip ( #52035 ), DeepEP pinned by full commit hash ( #52028 ), FlashAttention 3 built with the torch stable API ( #49599 ).

Breaking Changes & Deprecations

  • bitsandbytes support is now an out-of-tree plugin ( #43529 ).
  • The deprecated calculate_kv_scales runtime KV scale calculation was removed ( #49389 ).
  • override_attention_dtype was removed ( #48684 ).
  • reasoning_content output removal is documented as a breaking client change ( #50624 ).
  • KV offload tiering metrics renamed from kv_offload_tiering_block_{queries,hits} to ..._chunk_... ( #52812 ).
  • MoE legacy code removed ( #51078 ).

New Contributors

Contributors

@yewentao256 , @AndreasKaratzas , @njhill , @mgoin , @aoshen02 , @khluu , @hmellor , @stefankoncarevic , @taneem-ibrahim , @LucasWilkinson , @chaunceyjiang , @jikunshang , @zufangzhu , @bigPYJ1151 , @NickLucche , @askliar , @fxmarty-amd , @Rohan138 , @gty111 , @zhenwei-intel , @Isotr0py , @jeejeelee , @ZJY0516 , @wangxiyuan , @BugenZhao , @yma11 , @zyongye , @DarkLight1337 , @jperezdealgaba , @zhou9402 , @connorcarpenter15 , @kliuae , @lucifer1004 , @Alex-ai-future , @aarushjain29 , @TheEpicDolphin , @chaojun-zhang , @pmanczak , @WoosukKwon , @BabyDrangoner , @noooop , @almogtavor , @hongxiayang , @fuscof-ibm , @gau-nernst , @zxd1997066 , @tlrmchlsmth , @music-dino , @zexplorerhj , @S1ro1 , @jdebache , @sfeng33 , @mayuyuace , @ganeshr10 , @benchislett , @tzulingk , @gcanlin , @ivanium , @divakar-amd , @R3hankhan123 , @sagearc , @vhagor , @ronensc , @micah-wil , @qyYue1389 , @vanshbhatia-amd , @hao-aaron , @chengy-sysu , @elvircrn , @taking-lying-flat , @omerpaz95 , @Etelis , @vllmellm , @frank-suwen , @KernelClint , @Fangzhou-Ai , @louie-tsai , @simondanielsson , @maxyanghu , @dmai-afk , @KurodaKanbei , @ziqifan617 , @bastefaniak , @ECMGit , @haregali , @cmiyai , @fede-kamel , @drakosha , @vineethsaivs , @zcxGGmu , @TQCB , @skysnow2001 , @shenoyvvarun , @karen-sy , @fattchris , @RyanJHamby , @shikamd123 , @namgyu-youn , @zzt93 , @abmfy , @reidliu41 , @Rapisurazurite , @tandixit95 , @mganczarenko , @yimdev , @anujbolewar , @LiuYinfeng01 , @lk-chen , @NVShreyas , @huangzhilin-hzl , @varoudis , @Yejing-Lai , @mkhazraee , @jzakrzew , @TrainToGPB , @waynehacking8 , @zixi-qi , @Sundaresan-G , @mindungil , @bitborne , @Wauplin , @jacobzhang22, @zhewenl , @bnellnm , @pisceskkk , @Lin-z-w , @gabriel-peracio , @SilenNaihin , @baodii , @YunzhuLu , @xwu-intel , @BWAAEEEK , @thisjiang , @maobaolong , @anhtra3889 , @JaredforReal , @lvhan028 , @xiaolong-intel , @andyxning , @cleonard530 , @gnovack , @MatthewBonanni , @wangxian001 , @lengrongfu , @Tejas-Raj01 , @simon-mo , @vitamin-chaos , @arpera , @jairitAge , @jimmy-adams , @ILikeIneine , @woosebastian , @haic0 , @edwinlim0919 , @fcui-amd , @jhu960213 , @jinzhen-lin , @coltonottley , @walterbm, @meenchen, @matteso1, @djramic, @gchinora , @davidjpyu, @tianmu-li, @xiaopusun , @majunze2001, @Vegetog , @puririshi98, @janeyx99, @RobbieJ , @oonyshch, @thegoldenflow, @Srinivasoo7, @fatday , @acheamponge , @efschu , @rajfirke , @fanxingran , @xudonlyu , @lcskrishna, @xijiaat , @GirasoleY, @d4l3k , @samuelkim7 , @tarukumar, @acmore , @theminghuang , @khushali9, @wzhao18, @Priyjain-amd, @yiz-liu, @lkm2835, @dmholtz , @Dao007forever, @liushujia122 , @LopezCastroRoberto, @UgaTheDev , @tuukkjs, @aditi-amd, @guan404ming, @yiliu30, @zou3519, @Luosuu , @JoursBleu, @varun-sundar-rabindranath, @mpashkovskii, @yu-xin-c , @WillZZZy , @vrdn-23, @xyang16, @ccrhx4, @tanpinsiang, @russellb, @fxfxfxfxfxfxfxfx , @afriedri, @yifjiang , @Akashcodes732, @HF-001, @ovidiusm, @arthurgao2003 , @TomerBN-Nvidia, @hotTea123, @vx120, @bohnstingl , @qwerqwerqwe8688-jpg, @jasonozuzu-cohere, @vineetatiwari27, @ruirui6946 , @linitra24, @syedalijaseem , @nickus, @yzong-rh, @s3woz, @jhaotingc, @lukealonso, @Jie-Fang, @kzwrime, @xianbaoqian, @velonica0, @ccaadaro , @yisustc, @fangchenli , @iwannagotobed , @zobinHuang , @rchalamala , @shanjiaz, @jamesETsmith , @stacyroberts, @guanxingithub , @biswapanda, @shanewidanagama , @UranusSeven, @hsusul , @tobymao , @mispa-ms , @jeffreywang88, @SayHelloToWorld, @jyan-R , @oops-oom, @shantipriya-amd, @andakai, @akii96, @shen-shanshan, @Kaif10 , @yitingdc, @positive666 , @pavelzak , @SubSir, @ywang96

Does Computer Science Need Computers?

Lobsters
www.quantamagazine.org
2026-08-29 14:10:46
Comments...
Original Article

Qualia: Essays that go where curiosity leads

T he pioneering computer scientist Edsger Dijkstra, winner of the 1972 A.M. Turing Award and inventor of one of the most iconic algorithms in all of computing, was nothing if not opinionated. Certain programming languages drew his ire, for example: He once dubbed Fortran “the infantile disorder” and stated that “the use of COBOL cripples the mind; its teaching should, therefore, be regarded as a criminal offence.” In justifying his disdain for using computers in his own work, he wrote, “Medical researchers are not required to suffer from the diseases they investigate.”

I first encountered Dijkstra’s hot takes nearly four years ago, not long after I joined Quanta as a staff writer covering computer science. The subject was new to me — I’d been a physics journalist, and before that a physicist — and I soon learned that most people don’t know how to interpret “computer science writer.” In the broader public discourse, computer science is practically synonymous with programming or coding, but at Quanta we cover the less understood theoretical side of the field. Then I stumbled on my favorite of the many memorable declarations attributed to Dijkstra: Computer science is no more about computers than astronomy is about telescopes.

This analogy, it turns out, may not have originated with Dijkstra, but he probably would have endorsed the sentiment. For me, the quote offered a pithy, provocative way to distinguish my reporting from tech journalism. And I can’t deny that it was flattering: The field I cover, it suggested, is about something deep and timeless and beyond mere technological innovation.

I got into the habit of invoking the analogy regularly — including in an episode of The Quanta Podcast — but I also began to have second thoughts about it, for reasons I couldn’t quite articulate. Was I just feeling guilty about an implicit dig at my former colleagues who build telescopes, or was the analogy missing something important?

I decided to try to get to the bottom of this. Is computer science about computers? And if not, what exactly is it about?

I was wading into a very old debate. Researchers began developing a mathematical theory of computation in the 1930s. Engineers built the first general-purpose electronic computers in the 1940s. Computer science emerged as a distinct academic discipline in the following decades, when the research traditions of math and engineering came together, and arguments about the nature of the new field soon followed. In 1967, the prominent computer scientists Allen Newell, Alan Perlis, and Herbert Simon staked out their position in a spirited letter to the editor in the journal Science . “Wherever there are phenomena, there can be a science to describe and explain those phenomena,” they wrote, with perhaps a hint of exasperation. “There are computers. Ergo, computer science is the study of computers.”

Newell, Perlis, and Simon addressed their letter in part to critics who argued that any science worth the name must study natural phenomena. They countered with examples of artificial phenomena considered worthy of study in well-established sciences, such as chemistry. In his 1969 book The Sciences of the Artificial , Simon went further and embraced the distinction: A focus on intentionally designed artificial systems, he argued, was precisely what made computer science special.

In 1974, the computer scientist Donald Knuth offered a distinct view of the field that emphasized the process of computing rather than computers themselves. He defined computer science as the study of algorithms , or precise step-by-step procedures, which computers use to accomplish tasks. Algorithms can be implemented in different programming languages, in much the same way that ideas can be expressed in English, Mandarin, or Arabic. Humans use algorithms too, not just to solve math problems, but also for tasks like sorting items. From this perspective, the math underlying computation is central; computers themselves are relevant only because they open up problems that we humans have neither the time nor the patience to tackle on our own.

Knuth’s definition is appealing to me, but it’s hard to deny the simplicity of the one offered by Simon and his colleagues. Yet neither these nor any other definitions seem to have achieved universal acceptance among researchers. Why is that? I asked William Rapaport , an emeritus professor of computer science and philosophy at the University at Buffalo, who has extensively chronicled the many proposed definitions of computer science. He suggested that the disagreement ultimately stems from the unusually interdisciplinary origins of the field.

“Computer science has two parents,” he told me. “It’s got a mathematical parent, and it’s got an engineering parent, and it’s really a cross between those two.”

Rapaport still sees a kind of intellectual unity in the field — it’s more than just math and engineering in a trench coat. Computer science, in his view, is the study of two central questions, which each subfield addresses in its own way: “What can be computed, and how do you compute it?”

I found this framing helpful. There are obviously branches of computer science in which computer hardware and software are essential, such as the design of operating systems or the study of memory management. But I’m ultimately most interested in the theoretical side of the field, where researchers need not ever touch a real, physical computer. Do computers play an essential conceptual role in this theoretical work? That’s what I’d need to investigate if I was going to sort out my mixed feelings about the Dijkstra quote.

Let’s start with Rapaport’s first question: What can be computed? To even begin to answer this question from a theoretical point of view, you need to start with a mathematical formalization of computing — what researchers call a model of computation. In the 1930s, researchers proposed several distinct models of computation and began to study their implications.

Then, in a famous 1937 paper, the mathematician Alan Turing devised a model based on hypothetical machines that could read and write symbols printed on an infinite tape according to a set of simple rules. Turing and others soon proved that this highly influential “Turing machine” model was mathematically equivalent to models proposed by other researchers. Suddenly, instead of several distinct definitions, researchers had a single, universal theory of computation.

Yet Turing’s theory of computation wasn’t really about computers, at least not at first. When Turing wrote his seminal paper, not only did he not have a general-purpose computer, he wasn’t even motivated by a desire to understand how such future machines might work. Rather, he was trying to solve a central problem in the foundations of mathematics . He viewed his machine as a way to model the mental activity of a human doing calculations.

What’s more, the theory of computation is broadly applicable to things we wouldn’t recognize as computers. Researchers often study natural processes by modeling them as computations and analyzing them mathematically. They’ve used this computational lens to expose unpredictable behavior in physical systems , analyze evolutionary dynamics , and attack puzzles in quantum gravity , among other applications. Ironically, the field that Simon hailed as a “science of the artificial” back in the 1960s is now central to our understanding of the natural world.

“You can view the other sciences through computation,” said Tom Gur , a theoretical computer scientist at the University of Cambridge. “It’s this underlying logical pattern that manifests itself pretty much everywhere.”

The answer to Rapaport’s first question seems to leave Dijkstra’s quote in a good place. And then there’s Rapaport’s second question: Once you’ve decided you want to compute something, how exactly do you do it? To theoretical computer scientists, the answer lies in the math of algorithms. In the late 1960s and early 1970s, they began to build a framework to quantify the time that algorithms require to solve different problems, at an abstract mathematical level that avoids all the details of computer hardware.

They soon came to appreciate that there are important qualitative differences among problems that might arise in practical applications, such as planning routes through networks and factoring numbers. All of these problems could, in principle, be solved by algorithms. Yet only some had clever algorithms that could produce a solution quickly. For others, the only known algorithms were painfully slow. Attempts to get to the root of these differences marked the beginning of computational complexity theory, the subfield of theoretical computer science that studies the inherent difficulty of different problems, and provides the basis for modern encryption schemes.

“Mathematical problems have a fundamental structure which makes them qualitatively easier or harder to solve,” said Cristopher Moore , a theoretical computer scientist at the Santa Fe Institute. “It’s not a matter of how fast your computer is, and it’s not a matter of how clever you are.”

If math is, in some sense, the language of reality, then mapping out this hidden structure can feel “like discovering the laws of the universe,” as the complexity theorist Valentine Kabanets of Simon Fraser University in Canada put it, when I spoke to him a few years ago for a brain-bending story about the most famous open problem in complexity theory.

Later developments in complexity theory pointed in directions that seem even less related to computing. As an example, Gur pointed to new notions of mathematical proof that emerged from complexity theory in the 1980s and 1990s. By reimagining proof as an interactive process, theoretical computer scientists discovered that it’s possible to prove that a statement is true without revealing anything about why it’s true, and that it’s possible to verify that certain proofs are correct by only checking a few tiny snippets.

“We suddenly come up with entirely new types of questions,” Gur said. “We say something which goes way beyond computation.”

To me, this all adds up to a compelling vision of computer science without computers. “There were fundamental questions here that could have been asked hundreds of years ago,” said Scott Aaronson , a theoretical computer scientist at the University of Texas, Austin, who’s also a member of Quanta ’s advisory board. “It’s just that no one thought to ask them.”

Of course, that just raises another question — why not?

At least one person did think to ask those fundamental questions. The 19th-century polymath Charles Babbage, who conceived of a general-purpose calculating machine that he called the Analytical Engine, speculated in his autobiography that his new machine would call for a new theory of algorithms to go with it. “Whenever any result is sought by its aid,” he wrote, “the question will then arise — By what course of calculation can these results be arrived at by the machine in the shortest time ?”

Babbage never completed his Analytical Engine, and it’s not clear exactly how he planned to address that important question. Perhaps he imagined that technical details of the machine’s design would make some methods faster than others; there’s no evidence that he anticipated anything like the rich mathematical structure that complexity theorists have since discovered.

But that, it seems to me, is precisely the point. The central question in complexity theory, about why some problems don’t seem to have fast algorithms, may not look very profound at first glance. Its depth only becomes apparent when you start to explore it — and it wasn’t until researchers started playing around with real computers in the 1960s that the question seemed worth exploring.

I think this is ultimately what’s missing from a picture of computer science that downplays the role of computers: In the historical record, deep theoretical questions are often intertwined with practical ones about building better machines.

Matti Tedre , a computer scientist at the University of Eastern Finland and the author of a book about the disciplinary identity of the field , isn’t a fan of the Dijkstra quote as it’s usually understood. Even so, the comparison to astronomy may be apt in another way.

“[Dijkstra is] absolutely right; it’s just that he’s wrong about the importance of telescopes to astronomy,” Tedre said. “We wouldn’t know a thing about the universe if we didn’t have telescopes.”

Beyond the field of computer science, there are lessons here for how we think about scientific progress in general. In one common view, breakthroughs in pure science spur advances in technology: Think quantum physics leading to the transistor, or relativity enabling GPS. The history of computer science suggests a more nuanced interplay between the profound and the practical, one that also has parallels in other disciplines. Aaronson pointed to the second law of thermodynamics , which states that entropy, a measure of disorder, tends to increase over time.

“It’s maybe the most fundamental thing that you can say about the evolution of the entire universe,” he said. “And yet it’s not something that anyone thought of until they were building steam engines.”

Or, as the complexity theorist Ryan Williams of the Massachusetts Institute of Technology put it, “Sufficiently interesting problems in practice generate great theoretical questions.”

★ Thoughts and Observations on Apple’s First Immersive MLB Broadcast, a Yankees 1-0 Win Over the Red Sox

Daring Fireball
daringfireball.net
2026-08-29 13:53:34
It felt like something new and different. Something at least as different from watching on TV as watching on TV is different from merely listening on radio. It’s profound....
Original Article

Jason Snell, writing at Six Colors, has an exemplary review of the experience :

I didn’t mind the reduced pace of the NBA broadcast, which toggled between cameras under each basket, but Stratechery’s Ben Thompson felt strongly that the best option would’ve been a single camera at mid-court, to completely eliminate the disorienting cuts and replicate being at the game in person.

Apple’s approach with baseball, at least based on Friday’s game, seems to lean toward Thompson’s preferred approach — and it does benefit from it. Each half inning was shown from a single camera on the dugout rail next to the on-deck circle, giving a great view of pitcher and hitter and the infield, as well as the goings on right in front of the dugout in foul territory. The camera switched between innings, so you were always viewing from the perspective of the at-bat team’s dugout.

Making it all work better was Apple’s addition of a “virtual jumbotron” floating in the sky, a scoreboard with graphics and a video feed of the standard 16:9 telecast on Apple TV. It was easy to look up and catch a replay or even get a better view of something happening in the far-off outfield, without getting in the way of my view of the game itself.

I concur with Snell’s review. The camera placement was terrific. You watched each team bat from the perspective of its own dugout. Perfect. A few other thoughts:

  • The whole thing was legit exciting . Vision Pro continues to get a bad rap because Apple hasn’t sold many of them, and isn’t going to sell many of them until they come out with new models that are cheaper and lighter and less fussy. But there’s no denying that these immersive experiences are fucking cool. And an immersive live experience adds something else. It’s ineffable. Hard to say why , but feeling like you’re at another place watching something happen live is magic. Just a few years ago it would have required literal magic. It wasn’t possible. Now it is.

  • The immersive audio was terrific. It really sounded like being at Yankee Stadium, and truly added to the you-are-there feel of the experience. It seems corny to say this, but I really had the urge to stand during the national anthem, and it felt slightly wrong not to take the “hat” off my head (where the “hat” was the Vision Pro). It’s exciting to feel 43,000 fans roar around you. Baseball is a slow game but when the crowd roars, it erupts. That never comes across on regular TV broadcasts. It did here.

  • Like Snell though, I felt Apple’s commentators were too chatty. I’d love an option to toggle the commentary on and off, to just experience the natural audio of the ballpark. 1

  • The only thing missing was aroma. Cement, grass, dirt, sweat, beer, peanuts, hot dogs with the works. Ballparks smell like fun. (Even Fenway.) But the you-are-there experience was so visceral I swear I could almost smell it. It’s like my brain was filling in the missing sensation. It didn’t feel like watching a 3D TV broadcast. It didn’t feel like a better version of TV broadcasting. It felt like something new and different. Something at least as different from watching on TV as watching on TV is different from merely listening on radio. It’s profound. TVs are small — laptops, tablets, and phones are even smaller. Yankee Stadium is huge. Watching this game immersively felt huge. Awesome, in the literal sense.

  • I love how you could look around and see how filthy everything really is in baseball: the on-deck mats, the interior of the dugouts, the tiny bits of schmutz on the warning track. It’s a lot of dirt and quite a bit of spit. That’s baseball, Suzyn .

  • There’s a resolution and/or depth of field limitation with the cameras, exacerbated by the fact that Vision Pro’s displays are, compared to reality, low resolution. They’re the highest-resolution VR displays on the market but I still couldn’t see the ball once it left the infield. When balls were hit to the outfield you just kind of had to judge what was happening by what the infielders and baserunners were doing. Ben Rice hit a double in the first inning and I thought the Sox outfielder caught it and I was confused why Rice was running to second base. Turns out the outfielder stopped running because Rice hit the ball over his head and he was waiting to play the carom off the left field wall. I was happy to be wrong. A few years from now, with better cameras and better Vision headset displays, these problems will be solved. But in the meantime, the outfield is fuzzy.

  • The best part about the immersive perspective compared to a traditional broadcast is watching how complex infield play really is. It’s fun to quickly look around the whole infield right before the pitch. You really see how much more stressful it is for the pitcher once there’s a runner on base — let alone more than one. It’s what I love about going to the ballpark — so much more complexity and intricacy is revealed — and watching this immersive broadcast enables the same thing. You can see the whole game, at all times, not just the pitcher, catcher, and batter.

  • The virtual “jumbotron” is a fine idea but I wish you could move it a bit higher, and it would be even better if you could configure it with the stats you want to see. But positioning it higher is my big request.

  • I have to admit I hadn’t used my Vision Pro in quite a few weeks before last night’s game. One thing that really struck me, almost certainly because baseball is a long game, is how heavy it is. My chin wants to droop and my face wants to look down when I’m wearing it. It’s the weight more than the isolation that makes it tiresome for anything other than short-form content, for me at least.

The whole thing was a great success. I’m writing these notes on Saturday afternoon while watching the old flat broadcast of game 2 of this 4-game series, and it feels ... well, boring. And small. Bodes well for the future of sports.

Calibrate Before You Accelerate: Bias Toward Action in a New Role

Hacker News
tucker.wales
2026-08-29 13:39:18
Comments...
Original Article

My recent move from Monzo to Engine by Starling brought a familiar feeling rushing back: the intense, almost overwhelming urge to prove my worth immediately. When starting a new job, it’s completely natural to want to justify the company’s decision to hire you by making an instant impact. We want to show up, roll up our sleeves, and start fixing things.

But a bias toward action is a superpower only when applied correctly - action without context is just noise. If you swing a sledgehammer before looking at the blueprints, you might knock down a load-bearing wall. Here’s how to frame your bias toward action not as rushing, but as moving decisively only after you’ve built a foundation of context.

A stick figure swings a sledgehammer at a brick wall with eyes closed, while an unrolled blueprint on the ground clearly labels it a load-bearing wall not to be demolished

Phase 1: the collection period

Listening is an action if done deliberately. During your first few weeks, focus on being active in your passivity.

  • Map the terrain. Identify key stakeholders and observe team dynamics before suggesting changes.
  • Investigate the “why.” Apply Chesterton’s Fence - don’t remove a barrier or criticize a legacy process until you know exactly why it was built in the first place.

Two panels: a stick figure swings an axe at a fence without looking beyond it, then discovers - once the fence is gone - that it was keeping a bull out

  • Gather data. Read historical documentation, shadow your peers, and conduct 1:1s focused entirely on discovery.

Phase 2: the synthesis phase

This is the bridge between collecting information and taking action. It requires dedicated, analytical thought.

  • Connect the dots. Look for recurring pain points mentioned independently by different stakeholders across the business.

A stick figure stands in front of a corkboard, using red string to connect several sticky notes together, revealing a pattern

  • Categorize opportunities. Separate the low-hanging fruit - quick, low-risk wins - from the complex, systemic issues that will require a long-term strategy.

Phase 3: strategic acceleration

Now it’s time to unleash your bias toward action safely and effectively.

  • Start small and public. Execute a quick win that directly makes someone else’s job easier. This builds immediate political capital.
  • Share your hypothesis. Before launching a major project, write a one-pager outlining your intended action and share it for feedback.
  • Shift gears. Gradually transition your working ratio from 90% listening and 10% doing to 20% listening and 80% doing.

A stick figure's hand moves a lever along a dial, shifting the needle further toward one end

None of this is about moving slowly - it’s about making sure that when you do move, you’re pushing on something that actually needs pushing.

So, the next time you find yourself in a new environment, fighting the urge to fix everything on day one: take a breath. Put down the sledgehammer. Pick up the blueprints. The real work will still be there when you’re actually ready to build.

Good Culture Is the Biggest Productivity Hack, Not AI

Hacker News
newsletter.eng-leadership.com
2026-08-29 13:19:47
Comments...
Original Article

This newsletter is sponsored by Unblocked .

[Webinar] How to stop babysitting your agents

Agents can generate code. Getting it right for your system, team conventions, and past decisions is the hard part. You end up wasting time and tokens in the correction loops.

More MCPs, rules, and bigger context windows give agents access to information, but not understanding. The teams pulling ahead have a context layer to give agents exactly what they need for the task at hand.

Join live on Sep 2 (FREE) to see:

  • Where teams get stuck on the AI maturity curve and why common fixes fall short

  • How a context layer solves for quality, efficiency, and cost

  • Live demo: the same coding task with and without a context layer

Register now

Thanks to Unblocked for sponsoring this newsletter. Let’s get back to today’s thought!

This is something that has been on my mind for quite a while now. It seems like everything these days revolves around “AI”, “AI tools”, “AI productivity”.

  • “You need to use this AI tool”

  • “You need to be using this AI workflow”

  • “Your engineers should be 2x, 5x, or even 10x more productive with AI”

And I get it. AI is changing how we build software, and I use AI tools myself every day as well.

But we’re focusing too much on AI tools alone and not enough on the environment in which the tools are being used. Because there’s something a LOT more important than AI tools, and that’s a great culture.

Throughout my 13+ year career in the engineering industry, I’ve seen both the negative effects of bad culture and the positive effects of a good one. I even felt it myself as an engineer and an engineering manager, when departments spent whole days blaming each other for problems.

So, I am a big believer that everything starts with a good culture, and I’ll tell you all about it in this article.

Let’s start!

This is a sentence that breaks a good culture and makes people believe that their job is not important. Especially if it comes from an executive, e.g., a CEO, CPO, or even worse, a CTO.

The problem with it is that it totally decreases psychological safety, and everyone starts wondering whether they'll still be needed or not.

But here is an important thing that many people forget:

There is no better productivity hack than a great culture. No AI tools will provide bigger productivity gains.

I’ve unfortunately seen and heard this sentence quite a few times, either directly or from an engineer or engineering leader who has reported that to me.

I think things have gotten a bit better this year, but in 2025 and in early 2026, I heard this many times.

Let’s go more into why this is really problematic.

Many executives believe that AI will just magically increase the productivity of everyone. But the reason that often doesn’t work is Conway’s law. It states:

Organizations which design systems (in the broad sense used here) are constrained to produce designs which are copies of the communication structures of these organizations.

I mention this law quite a lot in different articles, because it’s just so important. And the reason why it’s particularly relevant in this case is that the overall productivity and the “end product” mimic the overall culture of the organization.

If the culture is bad, the end product will be bad as well, because people just don’t work together well and they don’t communicate properly. But if the culture is good, then often the end product will be good as well.

So, you should always think about good culture as a prerequisite for everything else. And I like to make an analogy to what health is to us, humans. Without health, we can’t do anything else well.

And the same is true for organizations with bad culture, everything else won’t be good as well.

Now, here comes the problem that many people fall into, especially CEOs and other executives. They see either a competitor or some other company reporting 10x higher productivity using a certain AI tool.

They start to panic, they start feeling FOMO (fear of missing out), and they start blaming people around them: “Why don’t we have that same amount of productivity as well?”

A lot of the CEOs are unaware of what kind of problems this may bring. Especially to the culture of the organization. When you start actively “blaming”, it shows to everyone that they are not doing their job well, and that you don’t trust them to make good decisions.

And this especially falls hard on engineers and engineering leaders, as they are often viewed as people who should be initiating AI adoption.

What many CEOs don’t realize is that a lot of the “reporting” of AI increasing productivity by 10x is more or less selling a certain AI product, or a certain partnership where they are promoting the other product.

So, many of the CEOs fall for the trick and make their company culture a lot worse.

My recommendation: Always take a look at what the incentives are behind people saying something, that says a lot about whether it’s true or not.

Here is another really important point, and many people seem to forget it. As we mentioned, good culture is a prerequisite for everything else. But when it comes to AI, it amplifies everything you already have.

So, both AI and good culture go hand in hand really well together. AI makes bad communication even worse, it also makes bad architecture even worse as well.

But if you have a good culture and good architecture, people will be more productive because they will help each other, and AI will also have a better blueprint of what good looks like because of good architecture.

Always keep this in mind. Just starting to use AI for everything just makes things worse if you don’t have good processes, architecture, and people don’t work together as a team.

Everyone just goes in the wrong direction faster.

If you’re wondering whether you have a great culture inside your team or organization, here are some useful questions to answer:

  • Do people know what they are responsible for?

  • Can they make decisions without unnecessary approvals?

  • Do they feel safe challenging leadership?

  • Do teams trust each other?

  • Are priorities clear?

  • Can people disagree constructively?

  • Do we reward outcomes?

  • Do people understand why they are building something?

  • Do we learn from failures, or do we look for someone to blame?

If the answer to these is “Yes”, then you are on a good track to have a good culture. Additionally, here is my personal checklist that I look at when doing an assessment of a certain engineering culture:

You can find my full checklist for assessing whether a certain engineering organization is great or not.

You can use the same checklist in your case as well. This checklist provides you with a guide on what you should focus on in order to create a great engineering organization where everyone can thrive.

It works for organizations with multiple teams or smaller organizations. You can also use this for a specific team that is part of the bigger organization as well.

Paid subscribers, you can get it here: 🎁 Products for paid subscribers .

Additionally, take a look at how I do a full engineering organization audit in this article:

Now, let’s go to a very important thing next. How to actually message AI adoption correctly, so that you keep a great culture and have everyone excited about using AI tools.

The best messaging I saw (and has worked well) is the following:

What great engineers and engineering leaders do is learn and utilize all different tools that help them do the work better. This hasn’t really changed.

AI is like any other tool that has come out over the years. Use it in your favor to help your team, organization, and the business. That’s what great engineers and engineering leaders do. And it hasn’t changed with AI.

Don’t ever mention something even close to “replacing” or something along the lines of “You are not important anymore, because we have AI”. Those are just going to completely diminish morale and break the entire culture.

When it comes to AI adoption, it only works bottom-up, it never works top-down, and the reason for that is that things are changing so fast, new AI tools are coming out every day, and there needs to be constant exchange of knowledge between everyone.

Always keep this in mind. Trying to “force” people will only result in bad outcomes.

Many people believe that AI adoption happens just by introducing a new tool, and people will just magically become 2-5x more productive. Well, it doesn’t work like that.

AI adoption is not a tooling problem, it’s a leadership problem.

And at the same time, if your goal is to just increase AI usage amongst everyone, you’re basically losing. The goal should always be business success and overall outcomes.

As we mentioned, AI is like any other tool, and we need to treat it that way.

I wrote the article called: Companies should hire more engineers in the age of AI , back in July, 2025. And it’s now more true than ever.

I fully believe that the best companies hire more engineers, not fewer, and the reason is that with more people, you exponentially increase your productivity as well.

Of course, the prerequisite is that the company culture is on point. Without it, it won’t work.

Time to market (TTM) is a very important metric in the age of AI, and I strongly believe that the best companies in a specific industry are going to be the ones that are going to move the fastest, make adjustments based on market needs, and provide the best experience for the users.

This was true before the age of AI, and now it’s even more important as things are progressing faster than ever.

So, knowing this, why would you actually restrict yourself with less productivity and less talent?

It’s a huge competitive advantage to be more productive. And I believe being less productive (that you can be) is actually a huge liability, which would result in an overall decrease in market share percentage long-term, in my opinion.

If you believe that “replacing engineers with AI” is a good bet. You’re actually making your company a lot worse that way. That’s my opinion.

Let’s end this article with the following:

I DON’T think the biggest question for leaders should be: “How do we get everyone to use AI?” The biggest question is:

“How do we build an organization where great people can do their best work, and then use AI to multiply them?”

This is the real question that organizations should be asking and focusing on. Great culture is the biggest productivity hack.

Liked this article? Make sure to 💙 click the like button.

Feedback or addition? Make sure to 💬 comment.

Know someone that would find this helpful? Make sure to 🔁 share this post.

  • Interested in sponsoring this newsletter? Check the sponsorship options here .

  • Check out my book “The Multiplier Mindset” coming out later this year, here .

  • Take a look at the cool swag in the Engineering Leadership Store here .

  • Want to work with me? You can see all the options here .

You can find me on LinkedIn , X , YouTube , Bluesky , Instagram or Threads .

If you wish to make a request on particular topic you would like to read, you can send me an email to info@gregorojstersek.com.

This newsletter is funded by paid subscriptions from readers like yourself.

If you aren’t already, consider becoming a paid subscriber to receive the full experience!

Check the benefits of the paid plan

You are more than welcome to find whatever interests you here and try it out in your particular case. Let me know how it went! Topics are normally about all things engineering related, leadership, management, developing scalable products, building teams etc.

Discussion about this post

Ready for more?

A better SQL in 11 lines of code

Hacker News
prela-lang.org
2026-08-29 13:13:45
Comments...
Original Article

Prela is a new query language being developed at UCLA RePL . The language is quite different from SQL, but its key ideas are very simple. In this short tutorial, we will build a toy version of Prela in Python to understand its core principles. By the end of this tutorial, you will know how the following query works:

movie.where(company.s(country).eq("[us]") &
            keyword.eq("character-name-in-title"))
    .select(title & cast.s(person).s(alias).s(text))

You can probably already guess what it's doing: the query finds every movie produced by an American company and has a character name in its title, and outputs the title along with the alias for each cast member. Note that the equivalent query in SQL spans over 20 lines.

The first special thing about Prela is that there are only binary relations, i.e., tables with two columns. That may sound very limiting at first, but it's easy to "binarize" a wide table with multiple columns. Suppose we have a table of movies:

ID title year
646 The Godfather 1972
478 Seven Samurai 1954
583 Casablanca 1942

We can decompose the 3-column table into 3 binary relations, 1 each mapping the row number to the column value:

movie = Rel([(646, 0),
             (478, 1),
             (583, 2)])

title = Rel([(0, "The Godfather"),
             (1, "Seven Samurai"),
             (2, "Casablanca")])

year  = Rel([(0, 1972),
             (1, 1954),
             (2, 1942)])

Tip

This tutorial uses snip to connect code cells into a notebook-like environment, 2 changes made in one cell are reflected in later cells.

The movie , title , and year relations above represent the ID , title , and year columns of the original table, respectively. Note how the row number comes first in title and year , but second in movie (which is also not called ID ). The reason for this will become clear later.

The motivation for focusing on binary relations is that they generalize functions. Functions are powerful because they compose , making them the building blocks of programs. A function maps every input to a unique output, where as a relation can map an input to multiple different outputs. In a sense, a relation can be viewed as a nondeterministic function.

That is all very abstract, so let's go back to our examples. To keep things simple, we will focus on relations mapping every input to exactly one output, i.e., they all happen to be functions. "Calling" a relation then boils down to turning that relation into a dictionary and looking up the value:

print(dict(movie)[646], dict(title)[0], dict(year)[0])

We're now ready to introduce the first and most important operator in Prela, the relation composition. Function composition works by applying one function first, then applying the other one to the output. The composition of two relations r and s is itself a relation, first mapping x with r to get some y , then map y with s for the final "output". This can be implemented by turning s into a dictionary d , iterating the (x, y) pairs in r , and finally outputting (x, d[y]) if y is found in d :

def select(r, s):
  d = dict(s)
  return [ (x, d[y]) for x, y in r if y in d ]

Using our example, the query below composes movie with title to get a relation mapping each movie ID to its title: 3

print(movie.select(title))

Try changing title to year and see what you get. The power of composition really shows when we chain together multiple .select calls. Suppose we add a foreign key column mapping each movie to its production company, and another table for movie companies:

ID title year company
... ... ... 0
... ... ... 1
... ... ... 2
ID name country
0 Paramount [us]
1 Toho [jp]
2 Warner Bros. [us]

Decomposing the same way gives us four more relations:

company = Rel([(0, 0),
               (1, 1),
               (2, 2)])

id2row  = Rel([(0, 0),
               (1, 1),
               (2, 2)])

name    = Rel([(0, "Paramount"),
               (1, "Toho"),
               (2, "Warner Bros.")])

country = Rel([(0, "[us]"),
               (1, "[jp]"),
               (2, "[us]")])

Then, we can find the country of a movie's production company by a chain of .select calls, where we abbreviate with .s :

print(movie.s(company).s(id2row).s(country))

Because joining via a foreign key almost always require "resolving" an ID to a row, Prela automatically inserts that step so one can write the following, 4 which reads just like "a movie's company's country"!

print(movie.s(company).s(country))

This is also what happened in cast.s(person).s(alias).s(text) on the last line of the snippet in the beginning of the tutorial.

So far every query has returned a single column of values. To select multiple attributes, we introduce the & operator.

Where .select matches the second column of r against the first column of s , & joins r and s on the first column of both , then pairs up their second columns:

def and_(r, s):
  d = dict(s)
  return [ (x, (y, d[x])) for x, y in r if x in d ]

So title & year maps every movie row to both of its attributes at once:

Note that the result is still a binary relation, & simply nests the values into a tuple. That means we can keep composing it like any other relation, which is how a query returns more than one column:

print(movie.select(title & year))

Next, we need a way to say which rows we want. The predicate .eq(v) filters a relation, keeping only the pairs whose second column equals v :

def eq(r, v):
  return [ (x, y) for x, y in r if y == v ]

On its own, .eq only narrows the relation it is applied to. The query below still maps movie rows to countries, just no longer all of them:

print(company.s(country).eq("[us]"))

Finally, the restriction operator .where takes a predicate like the one above and filters another relation with it.

def where(r, s):
  d = dict(s)
  return [ (x, y) for x, y in r if y in d ]

Handing our predicate to .where turns it into a filter on movies:

print(movie.where(company.s(country).eq("[us]")))

This reads right off the code: "movies where the company's country is [us]".

The query is getting long, so let's refactor it:

american = company.s(country).eq("[us]")
print(movie.where(american))

Wait, did we just create a CTE with a plain Python variable? Yes! This is possible because Prela queries are made up of operators, and every subexpression is a valid query.

How do we have multiple conditions? A happy accident is that, becuase & joins its arguments, it doubles as logical conjunction once nested inside a .where :

print(movie.where(american & year.eq(1942)))

Only Casablanca is American and from 1942. Putting it all together, .select then fetches whatever columns we want to see for the movies that survived the filter:

print(movie.where(american & year.eq(1942)).select(title & year))

We can even push the predicate into the select clause for a cleaner query:

print(movie.where(american).select(title & year.eq(1942)))

And that's pretty much the whole language! Prela also supports grouping and aggregation, and other common operators. We are working a full documentation for the language, so for now you can refer to our paper for more details. As an excercise, 5 you can try to define the necessary relations so that the snippet at the top runs.

# keyword = ...
# ...

print(movie.where(company.s(country).eq("[us]") &
                  keyword.eq("character-name-in-title"))
          .select(title & cast.s(person).s(alias).s(text)))

A self-contained Python program for our toy Prela can be found here .


  1. This is also known as 6NF decomposition. If you're concerned this would introduce overheads, check out this post to see how Prela compiles away the indirection with CPS. ↩︎

  2. Different from e.g. Jupyter, snip always executes from the beginning from scratch to avoid corrupted state. ↩︎

  3. The .select method syntax uses the same trick of forwarding Rel.select to select() . ↩︎

  4. Here we cheat by using the row number as company IDs. ↩︎

  5. A solution is hidden somewhere on this page ;) ↩︎

Claude permanently raising weekly limits by 25%

Hacker News
bsky.app
2026-08-29 12:37:05
Comments...

Atlanta Offers a Model for Building Sanctuary

Portside
portside.org
2026-08-29 12:36:09
Atlanta Offers a Model for Building Sanctuary Kurt Stand Sat, 08/29/2026 - 12:36 ...
Original Article

Atlanta community organizer Bassey Etuk opened a community defense workshop in June with a stark observation, and heads nodded around the crowded room. “Atlanta was a sanctuary city until the governor of Georgia made it illegal in 2009. Now Atlanta is Cop City,” he said.

From California to Kenya, whenever I say I’m based in Atlanta, people immediately bring up Cop City , the police training facility that sparked years of protest and major campaigns to prevent it from being built on public land. The training facility was ultimately built and is now in operation. But the Stop Cop City movement reduced the size and scale of the compound and, importantly, captured the imagination of people fighting on the frontlines against policing and state violence around the world.

In 2026, organizers in Atlanta have shifted from protests and mass mobilizations to applying the lessons they learned from the campaign and building the infrastructure needed to practice real community safety every day.

I am a longtime organizer and senior strategist with Project South, where I work alongside Bassey, an Atlanta-native who organizes in the 10 historically Black neighborhoods of Brownsville in southeast Atlanta. For the past two months, Bassey, I and the ATL Get Ready Team — a coalition of community organizers and organizations from across the city — launched a community preparedness plan to respond to escalating ICE enforcement, policing and National Guard deployments in cities across the United States. Together, we have been recruiting businesses, churches, bars and community centers to become “ Sanctuary Zones ” — sites that commit to preventing ICE and other law enforcement from entering.

Building sanctuary and protection for all people is critical in this period. It keeps us alive through moments of immediate crisis while positioning our communities to build the power needed for deeper, fundamental change. We share the lessons we are learning on the ground so that we are moving in coordination and solidarity with other communities all over the country who are similarly experiencing the trauma of this moment — the murders, detentions, intimidation and indictments — as fascist forces attempt to consolidate power at every level of society.

Atlanta gets ready

After witnessing ICE operations in Minnesota and National Guard deployments in Memphis and Washington, D.C. , 15 Atlanta-based organizations came together in February 2026 and asked each other some hard questions. If federal agents surge into, deploy across, or occupy Atlanta, are we ready? Are we ready to resist, to protect our communities and to prevent killings and kidnappings? Are we ready to put aside old tensions and disagreements? Are we ready to see ourselves as connected and act together, applying unified pressure in pursuit of our shared goals of community protection and collective defense?

At our first coalition meeting, Adelina Nicholls of the Georgia Latino Alliance for Human Rights said it clearly: “We can no longer afford to mobilize in reaction to what is happening. We have to determine a political direction and alignment towards a real vision.”

Large-scale anti-ICE protests have been powerful demonstrations of collective dissent and people power. But we understood that without greater unity across race, class, gender and geography, we could not win.

It was a vital moment for those of us who have organized in Atlanta for a long time. Organizations that did not always work together and that openly acknowledged long-standing tensions and disagreements, decided that, given the rise in state repression and violence, we need each other differently in this moment.

In the face of ICE raids in Latino, Caribbean and African immigrant neighborhoods, ongoing police violence against Black youth, sweeps of homeless encampments ahead of the World Cup in Atlanta, and the targeting of youth and trans people at the federal and state levels, we named criminalization as a shared reality and a political baseline for our alignment and collective action.

We agreed on a single commitment: to prevent and disrupt the growing criminalization of all our people. We called ourselves the ATL Get Ready Team, and we began by sharing trainings and building our collective skills with one another and with communities across Atlanta. In all, 15 Black-led, migrant-led and queer-led organizations made the decision to work together, combining our strengths instead of continuing to work alone.

Over the past six months, that commitment has become a practice. We meet weekly to check in and coordinate on the work happening on the ground. We have facilitated community trainings, hosted educational forums, organized canvassing days and launched a shared campaign to protect our people.

The assembly affirms the vision

In the aftermath of the Stop Cop City movement in 2025, organizations across Atlanta joined forces to organize People’s Movement Assemblies to define and build real community safety — despite the mayor’s assurances that training police forces in advanced urban warfare techniques would do that for us. Assemblies are community gatherings where people come together to assess the problems they face, develop shared solutions and create plans of action.

Drawing on the lessons we learned during the Stop Cop City struggle, we shifted from resisting the city’s vision of public safety to building our own. The assembly process became a form of community governance to define that vision together. It also became a space to strengthen relationships and build the movement infrastructure needed for long-term transformation.

We designed a plan to invite bars, restaurants and community centers to commit to declaring themselves as a Sanctuary Zone and to become part of a network of protection. We used the word “sanctuary” on purpose to signal that even if Georgia passes legislation to make it illegal for cities to pass sanctuary protections for migrants, independent businesses, faith centers and community spaces can declare sanctuary as autonomous spaces.

The real shift came when we named a deeper truth. We built the campaign in response to the public outrage over ICE, but we also knew we had a responsibility, and an opportunity, to make clear that ICE and the police are two arms of the same apparatus. Both function as agents of the state to control, contain, surveil and criminalize our communities. From the beginning, the ATL Get Ready Team aligned around an abolitionist position not to reinforce any part of the prison-industrial complex.

Bassey opened a Sanctuary Zone workshop at Project South’s Juneteenth gathering by naming his own experience with the police in Atlanta. “I can’t count the number of times I’ve been harassed, searched, had guns put in my face,” he said. “But in 2006 when the police shot and killed 92-year-old Kathryn Johnston, it shifted something in this city. Police had a no-knock warrant using false information and it was the wrong house. Kathryn was old-school, she reminded me of my grandma. My grandma kept a .22 and shot it every 4th of July. When police battle rammed Kathryn’s house, she let off a single warning shot, and in return the officers fired 39 shots killing her dead. There are many battles we’ve lost, but we can’t afford to lose more battles like that if we want to win in the long-term.”

So far, some 70 sites across Atlanta have publicly declared themselves Sanctuary Zones. Barbershops, bookstores, independent businesses, bars, restaurants, retailers, churches and community spaces have all joined the network. We canvassed neighborhoods, inviting sites to display Sanctuary Zone posters in their windows and commit to the campaign. We also coordinated Know Your Rights and Risks trainings and other community preparedness workshops for participating sites, while connecting them with local policing alternatives and diversion programs that offer practical ways to respond to conflict and crisis without calling 911.

Multiple grassroots organizations canvassed over 500 sites across Atlanta as part of the ATL Get Ready Team. Multiple grassroots organizations canvassed over 500 sites across Atlanta as part of the ATL Get Ready Team. (WNV/Stephanie Guilloud)

The campaign engaged more than 500 sites across the city. We began by concentrating on the two-mile radius surrounding the stadium as a visible show of solidarity to the thousands of visitors expected during the World Cup. As we learned that ICE was shifting its tactics and increasingly targeting people in surrounding counties, we expanded our outreach beyond the stadium corridor to neighborhoods where watch parties and community gatherings would take place, so that vulnerable people could feel safer being in public and enjoying the matches.

Many bar owners and restaurant operators expressed their commitment to refusing ICE entry but were hesitant to display a Sanctuary Zone poster or publicly join the network out of fear of retaliation. Many Black-owned businesses appreciated that we named the connection between ICE violence and police violence. As one owner told us, “We already don’t call the cops, we can sign on to this, easy.”

In a time of economic hardship, the government’s extraordinary spending on police, ICE and surveillance feels like a slap in the face, and the people we spoke with responded with outrage at this unjust siphoning of public funds. The Federal Emergency Response Agency, or FEMA, spent more than $846 million on security and policing for the FIFA spectacle instead of responding to climate disasters. During hurricane season. During the hottest summer on record. During floods and wildfires affecting hundreds of thousands of people.

At the same time, as many of us feared, ICE kidnappings and detentions escalated, reaching 43,000 in the month of June alone. Over the previous two months, four Black men were killed by federal troops and agents deployed in Memphis, while the military occupation of Washington, D.C., doubled from 2,500 to 5,000 troops. For comparison, the massive ICE operation in Minneapolis deployed 3,000 federal agents, creating immense harm. Faced with this reality, we refuse to give in to fear. To protect our people, we prepare and we build.

Sharing the vision

A local coffeehouse owner said, “Of course, we will sign on. I’m an immigrant, and when we are in solidarity with each other, we are stronger. What do we have to lose?”

She immediately offered the coffeehouse as a meeting space. We are now talking to business owners and church leaders about holding sessions that allow folks to share policies and practices that support protections for workers, patrons and community members.

The invitation to Sanctuary Zones is to join a larger vision: a coordinated network of sites that can be proactive and generative in times of crisis rather than reactive. These spaces are one step toward reducing our reliance on policing, which so often produces harm instead of safety. They create a concrete invitation for people beyond the usual movement circles to resist this regime through collective noncooperation. Sanctuary Zones prioritize safety over surveillance and solidarity over fear.

As we move out of the heat of summer and into the fall, the ATL Get Ready Team intends to keep building. Project South will facilitate Community Responder Trainings to strengthen the capacity of community members to assess emergencies, intervene and address medical situations without calling the police. The Georgia Latino Alliance for Human Rights will continue offering ICE tracker and legal trainings so businesses and faith institutions understand their rights and know how to prevent ICE raids.

Together, we will invite Sanctuary Zone partners to run drills and continue practicing preparedness plans that can be adapted to many kinds of crises — whether climate disasters, economic instability or state violence. Preparation is infrastructure, and in times of disaster or crisis, infrastructure is power.

Sharing the lessons

Below are a few lessons to share with groups working on similar projects:

1. Differences are not deterrents : We can acknowledge differences and tensions but still work together towards a common vision of preventing criminalization and protecting our communities. Differences can be a strength because sharing knowledge from divergent perspectives gives us a fuller picture of the threats and opportunities to respond.

2. Connections make our strategies stronger : We can connect ICE, policing and surveillance — an important political intervention that ensures movements to protect our immigrant neighbors are inseparable from movements to protect our Black neighbors from deadly policing. Both are connected to the growing struggles against data centers, surveillance technologies and cameras in our public spaces. We can connect daily, local police harassment to federal agents roaming our streets and to the executive orders and legislation that is targeting trans people and anyone who dissents.

3. Focused strategies are winning strategies : Collaborating around a shared strategy to name and resist the criminalization of people, poverty and protest is an important path forward. Bars, independent businesses and other community spaces want to participate in this moment, they simply need accessible ways to do so. One commitment, one poster, one campaign gives them a concrete way to say yes to noncooperation with institutions of harm, and yes to the work of creating proactive protections and solutions.

4. Local knowledge and national ripples : Rooting in local knowledge, relationships and histories is critical to building long-lasting infrastructure that engages people from diverse backgrounds. Careful reconnaissance to identify canvassing targets, direct follow-up with people with trusted relationships at neighborhood barbershops or churches, elders working with young people to engage sites from different angles, and clear recognition of local cultures and tensions make campaigns like this stronger and allow more people to participate.

Each of our locations requires different tactics, but if we can coordinate across places and learn from one another as we have learned from Ferguson to Los Angeles, Chicago to Minneapolis, Washington, D.C. to Memphis to Atlanta, we can confront this daunting machine with greater strength, deeper solidarity and more collective power.

As Rehana Lerandeau of Critical Resistance said, “We have to make our practices and our stories fresh, radical and irresistible.” In a time of so much danger and despair, sanctuary is a practice and a vision for how we want to be together in community. This campaign invited people across a diverse range of communities in Atlanta into their own courage, and they have overwhelmingly said yes.

Project South and has organized in the U.S. South for more than two decades.

Waging Nonviolence is a nonprofit media organization dedicated to providing original reporting and expert analysis of social movements around the world. With a commitment to accuracy, transparency and editorial independence, we examine today’s most crucial issues by shining a light on those who are organizing for just and peaceful solutions.

Creepy crawlies

Lobsters
people.kernel.org
2026-08-29 12:25:31
Comments...
Original Article

You've probably heard me complain about the “AI crawlers” before, but now I actually have some hard numbers I can put up to show their impact. In a few words, it's bad enough to create a constant “background radiation” of system load, permanently tying up a chunk of capacity spent on producing output that is only useful for a single purpose — feeding a learning model.

TL;DR: we spend more CPU cycles rendering commits for scrapers than we spend on all other kinds of legitimate access, including git clones. At any one time, across 5 geo-distributed nodes, there are 14 CPU cores doing nothing but rendering git commits as html.

CPU background radiation

Why is git.kernel.org “interesting” to crawlers

Linux development happens in the open — from git repositories you can clone, to discussion archives you can follow in real time. To a large language model, this is a goldmine of learning data, because all of this is not only immediately available, but is easy to filter in order to guarantee pure unadulterated pre-AI content. Training an LLM on content produced by the LLM gives it the equivalent of a digital prion disease, so when a source is guaranteed to be LLM-free, like the entire history of kernel commits, it's worth its weight in gold as a source of training data.

The stupidest way of doing it

We make almost everything clonable, because hey — we may not be around forever, so here — clone the repos. Also, clone the archives. Grab a copy just so we're not the only ones who have it all. Seriously, it's just a “git clone” away — and then you'll have the whole history.

For example, did you know you can clone the entirety of LKML and then do whatever you want with it? It's just git repos all the way down.

So, you'd think that something that pretends to be “Artificial Intelligence” would use the most efficient way of using our data for training purposes, right? Clone the repos, walk every commit. Done.

But no, let's in fact choose the stupidest possible way of doing it — by rendering everything as HTML commit by commit and then parsing it.

The stupidest way of doing it

At the time of writing, linux.git is about 1.48 million commits. Oh, and we have about 922 forks of it on git.kernel.org — but don't worry, it's actually extremely efficient on the backend, since it's mostly the same objects in every fork.

Unless, of course, you're a scraper, in which case you have, oh, several BILLION valid URLs you can scrape, only to get 922 duplicates of the same 1.48 million commits — which is exactly what the scrapers are doing.

But wait, it's not just commits itself. You can also ask for patches, plain renders, diffs between arbitrary commits — cgit is happy to let you, which was perfect for the times when the Internet was for humans or crawlers who obeyed robots.txt, and is AWFUL right about now, because we can generate 1.2 METRIC BAJILLION valid URLs just for a single fork of linux.git.

How many valid URLs is linux.git?

Block them

Initially, this was the solution — look through the logs, find out which IPs are obvious scraper bots, and fail2ban them. At first, this was easy, because the bots helpfully told you who they were via their user-agent. Then, they wised up and started pretending that they were random vanilla browsers.

So, we started banning them by IP — after all, it's easy to figure out that an IP that is trying to grab every possible commit in a 8-year-old abandoned fork of linux is not really some lone Chrome on Windows user who is just furiously clicking every link that comes across their screen.

The bots then started fanning out to entire subnets, but this was still meh, because obviously an IP coming from Google Compute is just pretending to be a Firefox user. Banning the whole ASN was justified, even if this occasionally caught a random legitimate instance trying to automate link checking in commits.

Enter... your TV?

And... that's when things turned really, really ugly. Suddenly, the crawlers were coming from millions of random residential or mobile IPs, all pretending to be random modern browsers. An IP like that would make 4-5 requests and then never show up in the logs again. There was no point in banning them, because by the time you figured out that they were bots, they were already done with you. You just needlessly ballooned your firewall ruleset by adding IPs that would never be back.

They descended like swarms of locust, hit hard and fast until the system fell over and then moved on to the next target until you recovered. Then, they returned. Rinse. Repeat.

They still do that — welcome to the wonderful world of “proxy SDK monetization.” It's big business, and your TV is probably doing it .

Make them pay

When this first became a problem, oh, about a year ago, we naively thought that there was a way to make it stop. Just make the bots perform a task that would flip the economy of the whole thing upside-down by making them burn some cycles doing throwaway math. Like, calculate what string, when combined with their own IP and a secret we provide, would generate a sha256 sum with 4 leading zeroes.

In other words, we put Anubis in front of everything.

Anubis painfulness graph

It was immediately extremely effective — the bots just gave up. For a few months, it was bliss: bots were blocked at the perimeter and gave up, moving on to easier targets; the users were mildly annoyed but tolerated it, and the Anubis stack was easy enough to deploy everywhere.

A few months later, the bots were back, solving difficulty 4. No problem, we said, let's raise difficulty to 5.

The legitimate users were more annoyed now. Difficulty 5 takes a few seconds to solve on a mobile device, and the phone gets uncomfortably warm as it's doing the number crunching. However, it was effective and bought us a few more months of peace.

Then... the bots started solving difficulty 5.

Where we are now

Anatomy of git.kernel.org requests

Today, git.kernel.org receives about 6M daily requests demanding to see random commits. Of these, 66% are still immediately batted away with the Anubis challenge, but 33% are now solving the math and getting through to the main site — because apparently what we have to offer is worth spending a ton of cycles to calculate the Anubis challenge.

It's impossible to tell with certainty which of these are bots and which are real humans — but chances are, if it's asking for an old commit in a random old fork, it's probably not a real developer trying to do their work.

With a bunch of generous assumptions, legitimate requests are only about 2% of git.kernel.org traffic — everything else are scrapers.

How bad is it?

Hits vs. bytes

At this point, we're not quite overwhelmed — if you visit git.kernel.org, it will likely be snappy and responsive. The thing that usually takes us down are not scraper bots, but poorly designed CI systems that try to do something stupid like shallow-clone stable.git from 20 different nodes, all at the same time. (Shallow clones are awful. Run your own damn mirror if you're going to do something nasty like that.)

However, you should know that out of the total of the 90 cores across 5 geo-distributed nodes, there are 14-16 cores that are constantly doing nothing but rendering commits for scrapers. On average, that's 20% of our entire capacity — except the swarms descend in waves and the actual graph is a lot more spiky than a 20% flatline.

Where does that leave us?

Unclear. Maybe the AI bubble bursts and we suddenly have a lot fewer entities out there trying to train their models. Alternatively, maybe they smarten up and stop consuming our data in the dumbest way possible.

In terms of what we're doing, we're turning off features to reduce the number of crawlable URLs and to gate off actions that are expensive for us to run. Expect to lose some functionality, at least when accessing our resources anonymously. Trust me, we hate it just as much as you, but at this point it's a necessity.

Worst of all, there are no simple solutions to the problem. Companies offering custom “AI” models still pop up daily, all of them hungry for training data. App makers are still looking for ways to turn a profit, so they will continue to turn your household appliances into attack vectors.

That said, we promise to still offer all of our data for download to anyone who asks. You just may have to jump through more hoops to get it.

Sorry. (Oblig. Canadian thing to say.)

Trees for a Changing Climate and Resilient Urban Forest (2022)

Hacker News
www.coolboulder.org
2026-08-29 12:24:21
Comments...
Original Article

If you look at old photos of Colorado Front Range cities, you won’t see many trees. And if you look up native trees of Colorado, you will find a lot of mountain-growing conifers and just a few deciduous trees that grow along streams. Yet our quality of life depends on trees. They provide shade and cooler conditions; they attract and support birds, bees and other life; they create microclimates that make it easier to grow smaller plants, flowers and fruit; and they create beauty. So early settlers planted trees and created systems to bring water from the mountains to drink, bathe with, and to support plants.

This plant culture was not easily gained, in particular with our difficult-for-trees western conditions. At the Eighth Annual Tree Diversity Conference on March 4th, our Front Range conditions for growing trees was described as “harsh”. We have hot summers, cold winters, low rainfall, low humidity, alkaline arid-style soils, late spring and early fall freezes, strong winds, and a month shorter growing season than the Midwest and East. It is much easier to grow a tree in Iowa or Pennsylvania.

Conditions are predicted to be getting worse. At the Tree Conference, speakers were confident in models showing temperatures increasing more rapidly than in the past and even faster for higher elevations because heat rises. On top of that, large numbers of ash trees, cottonwoods, and weak trees will be disappearing, increasing the “heat island effect”. Asphalt, metal and concrete in roads, parking lots, and buildings absorb and retain the sun’s heat where no trees provide shade. Trees also reduce the compacting effect of rain and absorb storm water. Higher density building means less room for tree roots. These stressful conditions weaken trees making them more vulnerable to pests and diseases.

Trees are particularly vulnerable to climate change and very important both in preventing it and maintaining livable conditions. What can we do to improve our urban forest and prepare it for climate change? One obvious solution is to increase tree diversity; with more varieties it’s less likely that large numbers of trees could die because of a pest, disease, drought or other problem. But where conditions are difficult, people naturally want to grow trees with a history of success, which has led to a concentration of a small selection of trees - essentially monocultures, known to be vulnerable to pests, diseases and changing conditions. We have depended too much on the durable ash. Now, especially with Emerald Ash Borer, we need to plant more trees and more kinds of trees. And we need to be asking for trees that are more drought and heat tolerant, more cold and alkaline tolerant.

To get some good advice, I interviewed four tree lovers with histories of planting, propagating, studying, and observing trees.

Trees are particularly vulnerable to climate change and very important both in preventing it and maintaining livable conditions.


Scott Skogerboe is the propagator for Fort Collins Wholesale Nursery. He has spent a lifetime traveling around Colorado and the US, visiting and studying trees, collecting and growing their seeds. He is our main resource for resilient trees and shrubs growing at the Cheyenne Horticultural Research Station, and His propagation & promotional efforts have ensured that a lot of them are being widely grown in Colorado.

Scott thinks we should rely more on native trees that provide for native wildlife, insects and birds. In the past, more focus was on cold tolerant northern selections. While this is still important due to late and early freezes, he says we should be looking south to Texas, Oklahoma and southern Nebraska for seed sources and superior selections with a warming climate.

His specific recommendations are the hardy Arizona Cypress, the Caddo Maples from Oklahoma (like the John Pair selection), and the hardy hybrid chokecherry “Sucker Punch” which doesn’t sucker and supports so much wildlife. We should be growing more oaks because they are so durable and they provide the most ecosystem services, as Doug Tallamy points out. He is growing a Gambel Oak selection called ‘Gila Monster’ from western New Mexico that doesn’t sucker, has a single trunk, grows larger, is cold tolerant to -30F and very drought tolerant.

Scott likes the drought tolerant and strong Hackberry. Some shy away from it because of the bumps on the leaves caused by an insect, but that doesn’t harm the tree and the larva inside those Nipple Galls are a bird favorite. Our native drought tolerant Boxelder, especially ‘Sensation’, a male selection that doesn’t get Boxelder Bugs and has good fall color, also supports lots of birds. He has also been growing some northern selections of our native Big Tooth Maple with redder fall color.

At the Cheyenne Station, Scott saw how well the Ohio Buckeye has done since 1974, growing to 25' with almost no irrigation. He likes Kentucky Coffee Tree because of its handsome form and drought tolerance. ‘Espresso’, a male selection, doesn’t make pods. Catalpa is well-adapted to Colorado, and he is a big fan of hawthorns, especially the drought-tolerant Russian Hawthorn with beautiful flowers and berries for wildlife.

Tim Buchanan greatly expanded the biodiversity of the Fort Collins urban forest as city forester for 41 years. He studied, collected, grew, trialed, and directed the planting of new or unusual varieties. Now many of those trees are quite large and have proven their worth. He knows them all, where and how they are growing. Now retired, he has reduced his seed-grown pets to around a hundred.

Fort Collins is particularly challenging. It’s not that far from Wyoming, colder than Denver and Boulder, and soils there have a pH around 8 - quite alkaline. He says the popular Autumn Blaze Maple doesn’t do well there and neither does Silver Maple or Norway Maple. Sugar Maples have not done well either though selections from colder, drier northern and western areas might do better. He likes Caddo Maple from Oklahoma and Big Tooth Maple, and says Acer nigrum, Black Maple, has better heat and alkaline tolerance.

Northern Red Oak is problematic because of high alkalinity, but Texas Red Oak, Quercus buckleyi, does well and has nice red fall color. Tim says Kentucky Coffee Tree is trouble-free and ‘Espresso’ is a good selection. The conifers he prefers are Blue Spruce, Douglas Fir, Englemann Spruce, Concolor Fir and Swiss Stone Pine, especially ‘Chalet’.

Tim has collaborated with Scott Skogerboe over the years trialing a hardy Northern Pecan from seeds Scott collected and grew, and Tim planted, which have become “very nice trees.” He thinks Catalpa is good and solid. And as long as Redbud comes from a northern seed source, it’s a good small tree with great flowers. In flowering crab apples, he favors Red Baron, Thunderchild, Spring Snow, and Radiant. For elms with little or no scale insect, he recommends Accolade and Choice City. He likes drought tolerant, tough Hackberry, and American Linden which needs less water than most Lindens and is great for bees.

Panayoti Kelaidis, Senior Curator and Director of Outreach at Denver Botanic Gardens, is known to most of us as the Rock Garden Guru. Few know that he has always had a passion for trees, and has been involved in the Annual Tree Diversity Conference since its inception. Like Scott and Tim, Panayoti knows a lot of trees personally, checking up on them and their success. He worked with notable landscape designer and tree enthusiast, Al Rollinger and others to update Al’s 50-year tree survey of Denver’s unusual trees. Those that did best since first recorded in 1968 were Bur Oak, Kentucky Coffee Tree, Chinkapin Oak, Texas Red Oak and Yellow Buckeye. (Search for the full report, “Rollinger Tree Collection.”)

Panayoti said that we make trees grow here. By building houses that help create microclimates and protection, by adding compost to soils, and by watering, we cultivate soil and environment more supportive of trees over time. I learned from him that the U.S. has two basic soil types: a midwestern/eastern type called Pedalfer that forms in wetter, moister climates, is dark brown or black, very fertile and more acidic, like what is under hardwood forests; and our western Pedocal soil, formed in arid and semi-arid conditions, rich in calcium carbonate, low in organic matter, and more alkaline. This explains why some perfectly hardy eastern/midwestern trees don’t thrive here, and also why some thrive in old neighborhoods where people have for years been composting and watering, but languish or die in new neighborhoods.

Panayoti thinks the practice of cloning trees (grafting from a single variety) that produces individuals with identical genetics, is sad and a disaster in the making. He says we’re not thinking about what is good for nature because we are so focused on convenience, uniformity, and neatness. We need to experiment more, let nature make more fruit and eat and preserve that fruit. Trees are noble; there’s a reason people honor them. It is humbling that they are so big and strong and can live beyond our lifetimes.

Sonia John is curator of the Regis University Arboretum and has worked on the DU Arboretum. It was her idea to start the Annual Tree Diversity Conference in 2014, and she has helped present it ever since. She is growing over 100 small trees in her yard from seed, liners, and bigger starts, which are then planted in the Regis Arboretum.

Very knowledgeable about trees and interested in unusual varieties, she likes American Smoketree, Cotinus obovatus, a beautiful, tough, small tree, and the Yellowhorn (Xanthocerus) because of its drought tolerance and terrific flowers. Other favorites are Soapberry, Hickory, and Northern Pecan. She loves oaks, especially Bur Oak hybrids with Gambel Oak called bur-gambel, like ‘Westward Ho’ and ‘Jack Mze’. And she likes Black Jack Oak, Lacy Oak, Netleaf Oak, and one called ‘Azul de Salinas’. She thinks oaks are particularly smart for Colorado because they leaf out late and don’t seem hurt by our freezes. Because oaks interbreed so easily, she believes we could purposely breed them for more heat, cold and drought tolerance.

Sonia likes Catalpa, Kentucky Coffee Tree, and Hackberry and says Nipple Gall is not a big deal. If trees do need more water than some other plants, most need less than a bluegrass lawn and in terms of Climate Change they are worth it.

She encourages visiting trees in Ft. Collins at The Gardens on Spring Creek, the City Park Arboretum, and CSU Arboretum, and in Denver at Regis, DU Arboreta, Denver Botanic Gardens.

Further development in resilience might be possible using seed and natural hybrids collected in drier, more southern climates, selecting trees for more disease and pest resistance, and using root-pruning pots that prevent girdling roots. Inoculating tree roots with mycorrhizae when propagating and planting can help with establishment and stresses. Some trees, like oaks, need specific mycorrhizae so culturing the fungi taken from the soils of thriving native communities could be beneficial. Adding 20%-30% compost when planting helps hold moisture and feed the soil life.

I’ve been an arborist for 35 years and it is my opinion that it is healthier for trees to be planted outside the lawn area. The irrigation systems designed for frequent and excessive watering of lawns too often deprive trees of oxygen; most trees prefer deep, infrequent watering. Also the dense root systems of turf grasses don’t allow the deep watering that rain storms provide trees in a forest.

It would help if we could be more tolerant of the irregularities that come from seed propagation in order to benefit from increased genetic diversity. Also, letting insects damage 10% of the leaves of a tree before applying any controls, allows for caterpillars which, along with the beautiful butterflies and moths they become, are such important food for birds. This insect predation actually stimulates the strengthening of trees’ immune system.

Lastly, more diversity and resilience will only be achieved if gardeners are willing to try new trees, including some risky varieties; if they are successful others will be more interested and willing to try them.

Resources

Civic Hygiene (2013)

Lobsters
shkspr.mobi
2026-08-29 12:03:08
Comments...
Original Article

Imagine, just for a moment, that the Government wanted to keep a record of everyone's sexuality. They need to know this detailed demographic data because it will be highly useful in civic planning. It will help them work out what provision needs to be made for sexual health services, how many children are likely to be born, how many schools to build, etc.

You trust the Government, you voted for them, you and your friends have nothing to hide with regards to your sexuality.

But! Shock horror! After creating the database, the Government loses the election and the homophobes at UKIP get in to power!

Now they have a database of every gay in the village, and can harass then, try to "cure" them, or make their lives a living hell.

Far fetched? Not really. With Cameron's inane web filtering plan, the "black boxes" in ISPs which can record every click you make, and the selling of the your NHS details to private parties, we're in a situation where a malicious government could cause serious damage to us.

The security expert Bruce Schneier wrote a wonderful article for CNN on how the existing surveillance state is leading to disastrous breaches of our private information. He concludes by saying:

It's bad civic hygiene to build technologies that could someday be used to facilitate a police state.

-- Bruce Schneier on CNN

We have to be careful that the apparatus we build cannot easily be misused for evil purposes. Sure, even an innocuous toaster can be weaponised if someone is willing enough, but we should not fall into the trap of making systems which can easily be turned against the people.

It's probably sensible to build a database of which car belongs to which owner - it has an important civil use and would be hard to abuse ( although not impossible ).

Should we have a national database of, say, religious beliefs? Almost instinctively the answer is no. The memories of fascist dictators haunt our collective consciousness. We have seen countless times how race and religious identity become death penalties. We wouldn't countenance it.

Civic hygiene isn't about saying we distrust our current government - it's about not trusting the next government .

Privatization by the Book

Portside
portside.org
2026-08-29 11:50:47
Privatization by the Book Kurt Stand Sat, 08/29/2026 - 11:50 ...
Original Article

When I tell people what I do, and where I work, and say that one of the public things that is sometimes under threat of privatization is the public library, that inclusion is usually met with shock.

How and why would a community privatize its library? Surely the library is one of the very few places that would never see privatization, right?

The privatization of libraries follows a similar pattern as a lot of privatization schemes–a financial shortfall creates a crisis (or the appearance of a crisis) and a magic solution appears: turn the public good over to a private company who will “run it like a business” and make it more efficient.

It’s a prevalent enough concern that the American Library Association a decade and a half ago published KEEPING PUBLIC LIBRARIES PUBLIC A Checklist for Communities Considering Privatization of Public Libraries . In it, the organization spells out its policy toward the practice: “ALA affirms that publicly funded libraries should remain directly accountable to the public they serve. Therefore, the ALA opposes the shifting of policymaking and management oversight of library services for the public to the private for-profit sector.”

Sometimes the privatization of libraries comes about because of a crisis of a more political stripe, like when a small group of people gets upset over programming, such as having LGBTQ Pride-themed library displays.

Politics may or may not be involved in the case for the Fresno (California) County Library System, which earlier this summer began exploring the possibility of turning the management of its 116-year-old library over to a private company , amid both financial shortfalls and some complaints about programming. Three years ago, when controversy arose over an initiative to create a children’s book “review committee,” private equity-backed Library Systems and Services (LSSI) showed up with a proposal to take over and, it claimed, save the library system $85 million over a ten year period.

But with private equity’s lust for profit, where would those savings come from? What happens to the staff, hours of operation, and transparency and control over decision-making?

At least one library supervisor, Luis Chavez, has expressed opposition to privatizing the Fresno library system. “Handing over library operations, budgeting, and management to a private company is the worst thing we could do. It doesn’t yield savings, pays low wages and benefits if any and reduces the library experience to a simple book-borrowing enterprise where certain books and materials can be censored.”

A scheme to privatize Huntington Beach’s public library system was rejected after public opinion turned against it, and Santa Clarita took back control of its library system at the end of its contract with LSSI. But other libraries, including additional California libraries, have fallen to the privatizers.

Public libraries have become more than places to borrow books. They offer power tools, toys, and seeds to plant gardens. They provide central locations for community meetings, 3-D printing workshops, a place for summertime lunches for kids who might otherwise not have full meals in a day. They are lifelines to people, both rural and urban. They are the only free-access indoor space not purposed for commerce. Public libraries are, to borrow a phrase, one of the things that actually makes America great–provided we can keep them public.

Jeff Hagan, ITPI Communications Director. Jeff is a writer from Cleveland, Ohio. For 14 years he was editor of the alumni magazine for his alma mater, Oberlin College. He previously held communication positions for the Center on Urban Poverty and Community Development at Case Western Reserve University and, before that, the Rock and Roll Hall of Fame and Museum.

In the Public Interest is a national nonprofit research and policy organization that studies public goods and services.  We help community organizations, advocacy groups, public officials, researchers, and the general public understand how the privatization of public goods impacts service quality, democracy, equity, and government budgets.  We also advocate for strengthening, adequately funding, and building popular support for a government that works for all of us.

Nancy Grace Roman Space Telescope

Hacker News
science.nasa.gov
2026-08-29 11:48:02
Comments...
Original Article

Roman Launch Countdown

Roman is set to launch August 30, 2026 at 07:26 am EDT on a SpaceX Falcon Heavy rocket from Launch Complex 39A at NASA’s Kennedy Space Center in Florida.

Learn More About the Roman Launch

Aug 30, 2026 11:26 UTC

Building Roman

Technicians have completed the construction of NASA’s Nancy Grace Roman Space Telescope. The Roman observatory is slated to launch on…

Read the Story

Media Resources

Press Kit

Brush up on all things Roman with this overview, which is full of mission information and a variety of resources.

Video Resources

View and download high-quality images and video from NASA Goddard's Scientific Visualization Studio.

Roman on YouTube

View a variety of videos, including shorts, b-roll, and animations.

Roman's Flickr gallery

Image resources available for print and digital publication.

Roman interactive

Explore the Roman Observatory

Take a tour around the telescope with this Interactive Diagram.

Explore Roman

Keep Exploring

Discover More Topics From NASA

AI Revives a Dead Sleep Company

Lobsters
www.josephspurrier.com
2026-08-29 11:44:52
Comments...
Original Article

TL;DR: I used Claude to revive a sleep monitoring device from a company that went under 10 years ago that also received over $40M in investments. I used a few widely accessible tools to reflash the devices, found the repositories on GitHub, and rebuilt most of the software stack to run on my Mac with full feature parity. Also, AI is changing the world every day so consider investing in your future by learning how to use it. 😄

It’s been a year since I started using agentic AI to build software. The discovery of its pretty amazing talents led to me working on many projects, from greenfield to repurposing old tech that I thought was going to end up in the trash. My first project was an operating system that functioned purely in a web browser. Cursor built out the desktop, menu, and then applications on top of it. I gave it a list of ancient games and it had no trouble plugging them right into the OS. This was a project I attempted many times but ultimately fell short for various reasons. My latest project was reviving a sleep monitor that sat next to my bed 10 years ago.

The Hello Sense sleep system was a gift I received for Christmas and I loved the tech gadget because it gave me a sleep score every night based on a number of variables: temperature, humidity, brightness, air quality, noise level, and movement. The Sense was a glowing orb you could wave your hand over to silence an alarm or just see if the current sleeping conditions were optimal. It also came with a little device called a sleep pill that clipped on your pillow to provide feedback on your movement, which provided greater accuracy on when you hopped into bed, changed positions while sleeping, or got up to start the day. The trends over the weeks and months I found most helpful, because it was usually good at pinpointing when I wasn’t prioritizing my sleep, which motivated me to get back on the consistency horse.

The best part was no subscription. You bought the device once and it worked - until the company closed up shop in June 2017 and shut down their servers. That may have been one of the factors leading to their demise. Hello successfully navigated a $40M financing round in June of 2015 after a successful $2.4M Kickstarter . I learned of the shutdown when I no longer received morning notifications of my sleep score and then the app stopped showing any data at all.

Moving to Boston

For the last 10 years, the device lived in my closet. Life and sleep both continued unscored. Right before my move from Maryland to Boston, I rediscovered the orb and decided to take it along with me in the move. “Maybe with AI, I could somehow repurpose this device,” I thought. Two nights before the move, I started up Claude (Opus 4.6) just to see what it could do with this defunct hardware.

At first, Claude searched the internet and found the company released almost all of their software on GitHub. I couldn’t believe it. For a company with a significant investment, they had published the iOS app, backend services, database schema, playbooks for AWS, sleep models, firmware - all of it was on GitHub. At this point in my AI journey, I was well aware that agents could easily wire together services on its own. Even without manuals, AI is extremely competent at analyzing codebases, making code changes, testing, and even refactoring to run outside of AWS and on a Mac. And that’s exactly what it did.

Diving into the Hardware

Rebuilding the 16-service architecture was the easier part, believe it or not. The real challenge was the hardware. The Sense orb received its power through a USB port and was previously network connected over Wi-Fi. I plugged the orb into my computer and told Claude to start.

Overnight Session (Tue Jul 14, 2026)

Time Event
12:30 AM Project starts: “I have a product called the Sense which is by a company called Hello…”
12:39 AM Orb located on the LAN, 10.0.0.33 / XX:XX:XX:XX:XX:XX
12:50 AM Port scan attempted, nothing usable to connect to
12:57 AM Pivot to BLE
1:15 AM scan_sense.py written (BLE scan over the morpheus_ble protobuf)
1:26 AM Decision to move it to dev network
1:32 AM set_wifi.py written
1:38 AM First orb traffic ever seen, 10.0.0.35 -> time.hello.is through the DNS intercept
1:57 AM The wall: Time sync error ... Wire format was corrupt , the AES signing problem
2:51 AM “Would it be possible to break the encryption?”
3:23 AM Research turns to UART over the micro-USB port
3:42 AM FT232RL adapter picked out
3:45 AM “It does turn yellow when plugged into my computer”, debug mode confirmed reachable

The device still had the network credentials, so the AI detected it broadcasting but was unable to connect to it. Claude then switched to Bluetooth and found it could connect to the device and issue a few commands - one of which was setting the wireless network, which was what the iOS app did when you first received the orb and plugged it into the wall for the initial setup process.

I knew from my undergrad education in digital forensics that if I could set it up on a network where I could control DNS (Domain Name System), I could listen for which URLs the device was trying to connect to (which happened to be *.hello.is) and return an IP address for my computer, which could then intercept the traffic. I pulled out my portable Zyxel router, connected it to my network, and then set DNS to point at my Mac.

Claude did the next steps for me: wrote the script to set the network info via Bluetooth, set up a simple DNS service to return my Mac IP for those domains, and then launched a Python service to log the incoming requests. The first requests from the orb appeared on my screen, and I knew I was making progress.

Encrypted by Design

Whenever you build software that has a client and a server, you often implement encryption to protect the information flowing back and forth. Without encryption, you can connect to a wired or wireless network, open up a packet sniffer and see in plaintext the requests and responses transacting. That’s obviously dangerous because information like your username/password or SSN that you fill in on websites could easily be read by other people on the same network.

The Hello company did what they were supposed to and encrypted their traffic. On the few GitHub repos where engineers attempted to resurrect this system, this is typically where progress stopped. Even though Hello published their software, they (rightly) did not publish the encryption keys for each of the devices. Every device that left the factory was provisioned with a unique 128-bit AES encryption key. Practically speaking, in order to break 128-bit AES encryption, it would take the entire Bitcoin network, repurposed, about 5 billion years to do it. That’s great protection for us as consumers, but it makes it impossible to read the traffic, rendering the project useless.

In order to move forward, the goal was not to break the encryption, but to extract the encryption key or change it to something we knew. Luckily for us, we figured out how to do both. Claude found a GitHub issue that explained how a Hello engineer tested software on the Sense using a special USB cable. Others in the community followed those instructions to get the orb into debug mode, which flashed the orb in yellow. That gave access to diagnostic information like where the orb was failing to get proper responses back from our test Python service. What they couldn’t figure out was how to get into CC3200 bootloader mode, which provided access to low-level systems like the bootloader and the file storage.

Claude figured it out.

Sense Wiring (Tue Jul 21)

Time Event
10:56 PM The 5-slot screw terminal, mapping “backwards S, +, D-, D+, -” to the FTDI
11:17 PM “Ok, it’s in debug mode. Let’s test it”
11:18 PM screen /dev/tty.usbserial-BG03FN9A 115200
11:57 PM Cable opened up to trace which color goes to which pin

Note: This is where it’s going to get technical and I’m not an electrical engineer - I’m a software guy who started in IT support with data center and cloud experience. Claude has the electrical experience that I leveraged.

Like any good project, you have to spend money. Claude recommended I buy these parts:

Getting the breakout to physically fit the Sense’s port: the micro-USB connector is recessed, so to seat the breakout you have to partially disassemble the sphere:

  • Remove the 4 screws on the bottom.
  • Remove the screws holding the light ring and the internal board, so the board lifts enough for the breakout to plug into the micro-USB port.
Wiring
Sense Wiring
breakout board and adapter

I wired them together based on the instructions I found online and was able to get the device into DEBUG mode, but I couldn’t get into the bootloader.

Probe Scripts (Sun Jul 26)

After I completed my move to Boston, I continued the bootloader troubleshooting. Claude generated another six throwaway scripts in 24 minutes:

Time Script Hypothesis being tested
11:24 AM cc3200_read_key.py the straightforward attempt
11:25 AM cc3200_debug.py what is actually on the wire
11:31 AM cc3200_raw_read.py bypass the tool
11:38 AM cc3200_load_stub.py is the stub upload the failure
11:40 AM cc3200_baud_scan.py “in case the handoff changes the UART speed”
11:48 AM cc3200_rts_switch.py SOP2 polarity through the switch, four strategies A/B/C/D

A micro-USB cable has 5 wires: VCC (power), GND (ground), D+ (data plus), D- (data minus), and ID. In a typical cable, the ID wire is connected to GND. The community originally thought the ID wire was supposed to be connected to 5V for programming. That did partly work, but SWITCH_2_APPS , the handoff from the ROM bootloader to the APPS bootloader that cc3200tool needed for flash access, died silently every time.

The last one is where the reasoning turned:

Test SWITCH_2_APPS while controlling SOP2 via FTDI RTS.

Wiring: ID (SOP2) -> FTDI RTS (was hardwired to 5V).

Bootloader Breakthrough

TL;DR: I connected the ID wire to RTS and the VBUS to 5V while everything else stayed on 3.3V.

Time Who Message What changed
11:48 AM model ( cc3200_rts_switch.py docstring) Reframed ID as SOP2, driven by RTS rather than held at a static level
11:56 AM user “Hmm, I heard that the devs at Hello did have a special USB cable that they used to do programming of it. What does that mean for your conclusions?” Reframed the problem toward driven control lines, opening the DTR branch
5:51 PM user “Can’t I simulate the reset somehow and yes, how do we do the power wiring?” Killed the DTR dead end: a power cycle is the reset, no soldering to the RST pad needed
5:54 PM user “Doesn’t the power come from both the 5v and 3v3 pin and it’s just the jumper that goes between one of them and the VCCIO pin what gives the VCCIO pin power?” Found the root cause
6:00 PM user “Ok I did that, try now” 3.3V logic in place; SWITCH_2_APPS completes and the flash opens

The insight came from TI’s own documentation ( ID on that connector is the CC3200’s SOP2 bootloader-select pin) plus the fact that cc3200tool ships a --sop2 option accepting ~rts . A tool does not offer to drive a pin from a modem control line unless the reference hardware does exactly that. The question stopped being “5V or ground” and became “which FTDI control line”.

The 5:54 PM question is the whole thing. The jumper sets VCCIO , which sets the logic swing on TXD, RXD and RTS. On 3V3 the signals swing 3.3V while the orb still takes its 5V from the board’s separate VBUS pin. The CC3200 is not 5V-tolerant on I/O, and the 5V swing had been killing the handoff at every baud rate.

Two minutes later, at 6:02 PM , key.aes (the encryption key) was written to disk.

TI docs supplied the SOP2/RTS concept, brute empiricism ruled out baud rate and polarity, the cable hint killed a dead end, and the jumper question found the real bug. The model did not reason its way to 3.3V; it had assumed the wiring was fine and was hunting in the protocol.

Same Evening: Key to Live Data in Four Hours

Time Event
6:05 PM Full flash backup pulled to sense_fs_backup/ before touching anything
8:30 to 8:34 PM TLS reconnaissance ( tls_probe.py , go_tls_probe.go , tlslite_probe.py ). Modern TLS libraries reject the orb’s handshake, so tlslite-ng in pure Python became the answer
8:50 PM Own CA generated and written to the device, with the server cert dated 1950 to survive the orb’s 70-years-behind clock
9:00 PM WiFi locked to WPA2 over the console
10:43 PM Pivot: “Now that we have the Sense Orb responding properly, I want to get the web services running locally using docker compose”
10:45 PM “Honestly, I really want the iPhone app as well”

Once we had the encryption key, the project was humming. The Hello team also rightly used a CA (Certificate Authority) to validate certificates when sending out their encrypted traffic. I generated my own SSL certificate, but the orb was rejecting it. Claude updated the CA bundle with my certificate so that the final security measure was handled. Claude then set up the web services locally - all 16 of the Hello services. For the AWS services, it found containers of DynamoDB and leveraged LocalStack to reproduce what Hello built for the cloud. The system was ready for its first test.

Unsuccessful First Sleep Score and iOS App (Mon Jul 27)

Time Event
12:22 AM Backend services up
12:35 AM “Do I have a sleep score yet?” - Nope
12:42 AM Timeline HMM model hunt begins. normal3 seeds turn out to be in suripu’s test fixtures; taimurain’s neural net weights were never committed anywhere
8:51 AM “See if you received readings overnight.” First real night of data
9:17 AM to 12:24 PM suripu-ios revived: Swift 3 migration, pods replaced, Zendesk SDK stripped. Running on the phone by 11:20 AM, logged in at 11:41 AM, then a long tail of dark-mode and tab-bar bugs
6:36 PM Sense and Sleep Pill screen blank, which exposes the second Kinesis worker that feeds Last Seen, WiFi and Firmware
6:49 to 7:25 PM BLE pairing fails until the discovery that the orb ignores unbonded phones. Press the button first
9:09 PM First alarm test. “It just seemed like it was a minute late”, the minute-floored countdown bug
10:06 PM “Let’s try to figure out the AES-encrypted per-pill key.” That question consumed the next two weeks

The sleep data started flowing but there were still missing pieces. The sleep pill that attached to my pillow was pairing with my system, but it was also sending encrypted data and had its own unique encryption key, so the service couldn’t read it. There were also missing machine learning models used to score the sleep.

Sleep Pill Flashing

While Claude worked through other bugs, like updating iOS libraries that were 10 years out of date and fixing UI strangeness, I also had it try to get the pill encryption key, which was also not accessible via Bluetooth. We then decided to try to flash the firmware via Bluetooth, which was possible: build kodobannin from source, push it over BLE DFU, and read the key out of a firmware under our control.

Same Night: Toolchain Build

Time Event
11:39 PM “Yes, let’s start the toolchain build”
11:52 PM nrf51sdk_src/
11:54 PM nrf-build/ (the GCC 4.7 container)
12:18 AM pill_dfu_flash.py written
12:21 AM “Yep, let’s run it”
12:35 AM “I tried the pill monitor and even after shaking and putting in a battery, no response.”

Details are important. The Hello folks released multiple versions of their sleep pill - a v1 with a removable battery and a v1.5 with a permanent battery (ugh, I know). Mine was v1. Unfortunately, in our haste, Claude and I built and flashed v1.5, and it caused the pill to stop responding.

Fourteen minutes from flash to brick.

The Diagnosis (Aug 2, 6:50 PM)

A potential replacement pill arrived from eBay, but it turned out to be the one for the voice Sense model (I had the non-voice model). Counting the through-holes in the circuit board gave it away:

6:40 PM “This has a cluster of 10 through holes, not 6. The original pill had 6 holes.”

6:50 PM “Now I’m concerned. You mentioned that the flash we did matched exactly this version, but the hardware is indeed different between the two.”

That is the moment the brick got explained, five days after it happened. The build had matched a real Hello binary perfectly, which is exactly why nobody questioned it. It was the right firmware for the wrong board.

Why it Bricked

What went on the device was a pillx_DVT1 image, the Pill 1.5 platform. The pill is pill_PVT1 , the original v1. The two share a chip and nothing else that matters:

Signal v1 (pill_PVT1) v1.5 (pillx_DVT1)
SPI nCS 29 13
SPI SCLK 13 15
SPI MOSI 15 9
SPI MISO 25 11
IMU INT 23 16
IMU VDD none 20
UART TX / RX 18 / 19 19 / 18

Every pin the firmware drives was wrong. By 12:52 AM the free recovery routes were being tried, by 12:58 AM the question was what to buy, and by 8:30 AM on Jul 28 pogo pins were being sourced. pill_swd_recovery.md was written at 9:04 AM.

To flash the pill, Claude suggested another list of parts:

Recovery Day (Aug 10)

After wiring, internal pill access came up around 2 AM. Then eleven hours of flashing, timestamped by the artifacts:

Time Work Result
2:18 AM check_voltage.jlink probing
2:55 to 3:11 AM bootloader and app settings experiments no
3:47 AM doraemon_pill.bin + bootloader + uicr (factory image) alive , ANT heartbeats at 5:21, 6:21, 7:21, 8:21
9:22 to 9:51 AM erase, then locally built bootloader.bin pill goes silent after 8:21
10:04 to 10:31 AM factory pillx_DVT1 set, factory process the wrong platform again, deliberately, for comparison
11:24 AM debug_spi.jlink the WHO_AM_I 0x00 chase, which was just SPI on wrong pins
11:50 AM pill_app_signed.bin , self-built 1.2.1 on the correct platform BLE alive, ANT dead
12:22 PM onward 15 pairing attempts every one a 30.5s ANT timeout
1:22 PM factory pill_pvt set, app 0.9.3 ANT restored, POST /in/pill every 60s

The proof arrived mid-morning:

  • 11:37 AM “Revert to the clean 1.7.2 tag. Try to compile to see if it matches their binary.” It did, byte for byte, against what was sitting on the device.
  • 11:43 AM “The original brick was us flashing the wrong firmware on it.”
  • 11:46 AM “We accidentally flashed the 1.5 on it.”

Two corrections came out of that day. The v1 target does not build past 1.2.1 , because pill/message_imu.c starts calling IMU APIs that only exist in the 1.5 driver. And the break begins at 1.3.0 , not 1.7.2 as first recorded. The v1 driver was simply never kept in sync after the Pill 1.5 was introduced.

ANT was not working in the firmware we were flashing. Most people have heard of Bluetooth but probably not ANT. They are both radios but have different jobs. ANT uses an open broadcast model, meaning it can send data to an unlimited number of receivers, whereas Bluetooth is connection oriented (one-to-one). The pill’s nRF51422 is one of the few Nordic parts that runs both stacks at once (that is what the S310 SoftDevice is, BLE plus ANT). Everything the pill exists to do goes over ANT, to the Sense, never to your phone.

Why ANT and not BLE (Bluetooth Low Energy) for this data sending? Power savings. ANT in the async scheme is a background broadcast, no connection state, no pairing handshake, no supervision timeouts meaning really low power usage. The pill has to run a year (2 years as advertised) on a coin battery while sampling an accelerometer all night. BLE connections are far more expensive to hold.

Why the Self-Built Image had no ANT (Aug 16)

The answer to the ANT problem was in the Hello git history, not the hardware.

Commit cb4becff , “changed from async to synchronous transmit mode”, March 2016, first shipping in tag 1.1.1 :

Scheme Tags Implementation
async up to 1.0.3, and factory 0.9.3 CHANNEL_TYPE_MASTER_TX_ONLY + EXT_PARAM_ASYNC_TX_MODE , background broadcast, no sd_ant_channel_open
sync 1.1.1 and later, including 1.2.1 CHANNEL_TYPE_MASTER + sd_ant_channel_open , periodic channel

The pill and the Sense’s nRF51 top board are built from the same ant/ant_driver.c , so both ends must use the same scheme. This Sense pairs with the async 0.9.3 pill, so its top board is on the async scheme, and a sync pill cannot form the link. BLE is a separate stack, which is why the 1.2.1 image looked half-alive.

The fix is tag 1.0.3 , the newest tag that is simultaneously async, still builds for pill_PVT1, and defines USE_HLO_ANT_NETWORK for the real key. Validation used the kitsune trick: a source build of 0.9.3 came out byte-identical to the factory doraemon image (40,908 bytes, sha1 c9b58fa501975a97c306caab12c096951bfa8e4c ), proving the GCC 4.7 pipeline reproduces a known-good-ANT pill.

The whole detour cost 19 days , and the root cause was a platform target chosen at midnight.

Our First Sleep Score

Once we were able to get the sleep pill wired correctly (with me tediously holding the microscopic pogo pins against the circuit board), we got it flashed, grabbed the encryption key, and added it to our database.

It Works End to End (Aug 11)

  • 6:37 AM , first night with both devices, tab 1 errors, a missing DynamoDB table
  • 6:47 AM “That worked!” Then the black-screen calendar transition bug.

After a night of rest, we finally got a sleep score.

Wiring
iOS App
first successful night

Over the next couple of weeks, we did nightly operation and tuning. We pored over feature gates, rescoring, room conditions, push notification timing, ONLINE_HMM versus Voting, the timeline feedback that was being learned from but never displayed, and a suspicious median temperature. After a few weeks with the Java services, I wanted to consolidate:

Time Event
Aug 10, 4:34 PM “How difficult would it be to rewrite all the services into a single Go service?” The idea that shaped the rest of the month

The afternoon in between turned architectural: Dynamo versus Postgres, insights generator, push notifications, missing services, iOS UI bugs.

The Cutover (Aug 26 to 28)

Time Event
Aug 26, 11:36 AM “At this point, how much of the old system vs the new system is running?”
Aug 26, 2:22 PM The last four endpoints moved to the Go orb
Aug 28, 7:18 PM “I think we are at the point where we can shutdown the old services”
Aug 28, 7:25 PM “Let’s cut over everything”
Aug 28, 8:05 PM Eleven JVMs down to one Go binary plus Postgres, docker packaged for Linux and Mac

The process took around a month and a half: two weeks to get inside the orb, three weeks to rebuild everything around it.

Closing Thoughts

I’m really excited to have the sleep monitor back up and running, locally controlled, and optimized for a single user. It was a device I found a lot of value in, and now I will continue to fix bugs and may even add features that didn’t exist originally. I know there were others trying to bring this back to life, so I’ve linked all the work below in the GitHub repo.

The output of this experiment is on GitHub: https://github.com/josephspurrier/hello-sense .

Note on AI: Over the last few months, it’s become clear to me that engineering will change in significant ways due to the advance of AI. And it’s not just engineering; many industries will change. What took me a few weeks wouldn’t have been possible (for me) to do without AI. It would have taken months, maybe over a year, and who knows how many hours, or how many times I would have given up or hit a wall. We don’t have a good idea of how AI will change things, but we know it will. My suggestion is if you want to invest your time in something, AI is it. We all need to keep learning and improving our skills because it enriches the mind and the soul. If you want to continue being successful in a world where everyone else is using it to their advantage, you need to understand how you can use it for yours. If nothing more, use AI to give you back time so you can choose how to spend it.

Quantifying Colour

Hacker News
ekunazanu.foo
2026-08-29 11:43:53
Comments...
Original Article

There are billions of monitors worldwide that can reproduce the exact same colour when instructed to. This in itself is an engineering marvel, but it glosses over the fact that this is only possible if there is a standard definition for colours in the first place. Earlier, colours were loosely defined using a limited set of words — most languages have at most twelve words to describe colours. These loose definitions are fine in most cases, but it is not precise enough for describing the tiny differences between similar looking colours that is required for accurate colour reproduction.

a image of green leaves with boxes below showing some of the shades of green present in the image

Same name, different colours

The above coloured rectangles shows some of the colours present in the above image. Despite being different, all the shades can be described by the same label — green. One could argue, they can be labelled as lime-green, olive-green, light-green, dark-green, etc to create some distinction. But this naming system is still clunky and highly inefficient. To display the above image accurately, there needs to be a way to describe the all the different shades of green uniquely without needing to resort to an ever-growing list of labels.

Image sourced from Pixabay , under CC0 .

Instead of mapping colours to possibly millions of labels, it would be much simpler to use numbered units — the desired precision can then be achieved by simply using more or fewer digits. The idea of mapping colours to numbers might look odd, but it is not too far fetched. Most measurable physical phenomena have already been quantified (for eg. distances, temperature, etc). So if colours can be physically measured it should be easy to map them to numbers, in theory.

Defining colours using numbers also opens up interesting questions: What does addition or multiplication of colours look like? The process of quantifying colours will also reveal why colour hexcodes cannot show enough colours even with 16,777,216 values, and how a dress became a debate on the internet, and why colour blindness exists.

Spectral Power Distribution

The goal is to then measure colours as some physical entity. Unfortunately, colours are a subjective phenomenon. However the fact that most people can agree on the colour of something suggests that there must be at least something objective and physical about it. And there is. Colours are only visible in the presence of light, and that provides a huge clue as to what colours are.

Light is complicated, but it can be thought of as a bunch of wave-like particles, called photons — each carrying some specific amount of energy. The energy of these particles is determined by their wavelength or frequency .

Wavelength

Photon representation

The above is an interpretation of a photon, and is not necessarily accurate. The exact shape of photons is difficult to describe since photons exhibit both particle and wave-like behaviour . Trying to visualize photons as both a particle and a wave can get very tricky very quickly.

Electromagnetic spectrum

There are photons with different energies (or wavelengths). The different wavelengths of photons together form the electromagnetic spectrum . It is simply the full range photons energies, ordered by wavelength or frequency. The above wavelengths are not to scale.

The energy carried by photons can be physically measured, making it trivial to quantify light. To simplify comparisons between different types of light however, the energy measurements are normalized per unit time as power , and then normalized per unit area as intensity — where the area is the total area of the body radiating the photons/light.

So, light sources can be quantified using a singular intensity value. However, for reasons that will become more obvious later, light is actually represented using multiple intensity values — by measuring the intensity separately for photons at different wavelengths. The intensity-per-wavelength distribution is called the spectral power distribution .

450nm Photons
500nm Photons
550nm Photons
600nm Photons
650nm Photons

Spectral power distribution

The above is an example of a spectral power distribution. The intensity at each wavelength depends on the number of photons at that wavelength and the energy of photons at that wavelength. The energy of a photon is inversely proportional to its wavelength, so the shorter wavelength photons shown above have a higher intensity for the same number of photons.

The spectral power distribution provides a way to quantify light. But this is all irrelevant until there is a quantitative way to define a relationship between colours and the spectral power distribution (light) as well.

Photoreceptor Cells

The biggest clue to finding that relationship is rather obvious — colour perception is not possible without light, but it is also not possible without eyes. Eyes are sensitive to light, but more importantly they react differently to different wavelengths of light.

To understand how eyes can distinguish between different wavelengths of light, it helps to know a little bit about human physiology. Eyes have different types of photoreceptor cells that have evolved to respond to photons with specific wavelengths. Unsurprisingly, these wavelengths are very similar to those emitted by the sun (380nm–750nm):

Spectral power distribution of the sun

The above is an approximation of the spectral power distribution of the sun. Human eyes have evolved to become sensitive to these wavelengths to be able to perceive environments lit up by the sun.

Photons, depending on their energy (their wavelength), can ‘excite’ certain photoreceptor cells to produce a specific response. The human eye has two kinds of photoreceptor cells — rod cells and three types of cone cells . The different types of photoreceptor cells are sensitive to different wavelengths of light by differing amounts — some cone cells will not produce a significant response to lights with longer wavelengths but other cones may. The sensitivity curves of the different photoreceptor cells are shown below:

Normalized approximations

The sensitivity curves shown here are normalized approximations (for simpler visualizations and calculations), and are not accurate. In reality, the sensitivity curves are less smooth, and different types of cones have differing levels of sensitivity. For example, the sensitivity of S-cones is significantly lower compared to the other cones. Similarly, rods are more sensitive to light than any of the cones.

Because of the varying sensitivity curves, the cones can distinguish between different wavelengths of light. Consider a monochromatic light source (a light source with a near singular wavelength). The cones will produce a response to the light, depending on the wavelength of the light and how sensitive the cones are to that wavelength. However, since each type of cone has a different sensitivity, their response will be different for the same light.

Wavelength

Photoreceptor cell responses

The first graph is the spectral power distribution of the light source. Since it is monochromatic, the intensity narrowly peaks at some wavelength. The graph below shows the sensitivity curves of the cones. The diagram on the bottom represents the responses of the cones to the monochromatic light. The different cones produce different responses to the same monochromatic light source — because of their differing sensitivity.

This is in itself is not enough to help differentiate different wavelengths, but the way the sensitivity curves are (or have evolved to be) distributed makes it such that all different wavelengths will always correspond to a unique set of responses in the cones — making it possible to distinguish different wavelengths. The brain has evolved to interpret these unique responses as perceiving unique colours.

Wavelength
Colour perception

Notice how different wavelengths always result in a unique set of values. Wavelengths that are close to each other may produce similar cone responses and thus the brain interprets them as similar colours. But in general, wavelengths that are distinct will produce distinctly different responses and the brain will interpret them as different colours.

The colour in the above box is how the brain interprets the cone responses as a colour. The colours in the above box (and all subsequent boxes) is however just for illustration — it is an approximation and is not accurate. Also, the name in the above colour box is an example of a word-based definition . Notice here how imprecise they are — the same name correspond to lots of different shades of colours.

Rods are not shown in the above examples because they do not affect colour perception. In well-lit conditions , cones might produce different responses based on the wavelength of light. But in such conditions, the rod cells produce a saturated response since rods are more sensitive to light than cones. Since the response of rods in bright environments is indifferent to wavelengths, it cannot differentiate between distinct wavelengths, and thus does not have a major impact on colour perception — in bright conditions.

Wavelength
Saturated response

The sensitivity of the rods is represented here with respect to the sensitivity of the cones (but it is not-to-scale, and is still an approximation). Because of their high sensitivity, the response of rods remain saturated, and no meaningful information about the wavelength is obtained from the response. The set of cones responses however, remains varied for different wavelengths, and the distinct cone responses can be interpreted by the brain as distinct wavelengths.

In dark environments , rods produce a response when cones do not. But unlike cones, there is only one type of rod cell; there is no other type of rod cell with a slightly different sensitivity curve to help differentiate wavelengths. So, two light sources with different wavelengths can produce the same response in rods, and there is no way to differentiate the wavelengths from the singular response of the rods. The brain evolved to interpret the response of the rods as a singular luminance (brightness) value.

Wavelength
Wavelength ambiguity

Different wavelengths can produce similar responses in the rods, and are thus perceived as similar by the brain. For example, a low intensity light of 492nm and 536nm can produce similar sets of responses in the rods (and cones), and so cyan and yellow-ish green may appear similar in the dark.

So rods cannot distinguish light of differing wavelengths regardless of whether it is dark or bright, and hence do not play a big role in colour perception.

Colour Blindness

Sometimes cone cells too may not be able to differentiate between different wavelengths of light. This can happen due to missing cones, or cones with overlapping sensitivity curves. Without the third cone, light with different wavelengths can produce a similar set of cone responses — differentiating between the wavelengths is again not possible. This results in colour blindness .

Wavelength
M-cone Overlap
Wavelength ambiguity

If the sensitivity curves of the M-cones overlap the sensitivity curves of the L-cones, then different wavelengths of light (for eg. 554nm and 604nm ) can produce similar sets of responses in the cones — causing them to appear similar. This is not the case if the sensitivity of the M-cones and L-cones do not have significant overlap .

The type of cone anomaly determines the type of colour blindness. The sensitivity curve of the L-cones may shift towards shorter wavelengths (protanomaly), or the sensitivity of the M-cones can skew towards longer wavelengths (deuteranomaly). Some people might also lack functional L-cones (protanopia) or M-cones (deuteranopia) entirely. The result is similar in all the cases — reds and greens look similar. In very rare cases, people can have anomalous S-cones, resulting in tritanomaly and tritanopia.

Colour blindness types

The bars represent how colours of different wavelengths for people with normal colour vision might appear to people with colour blindness. The first bar shows unaltered colours. The second bar shows colours for people with protanopia, and the third depicts colours for people with deuteranopia. The fourth bar represents how colours appear to people with tritanopia.

In extremely rare cases, people might have only S-cones or no cone cells at all. Both will result in total colour blindness since there is no mechanism for differentiating light with different wavelengths.

Colour blindness also provides clues for why colour perception is subjective — not all people have three perfectly functioning cones, that have the exact same sensitivity curves as everyone else. Also, how exactly the brain interprets the responses as colours is still a debate . So even with identical sensitivity curves and cone responses, brains may interpret signals differently for some people, which can again lead to inconsistent colour perception among people.

Nonetheless, the same wavelengths of light are generally perceived consistently by most of the population. So, for the purpose of colour quantification, how the brain interprets the cone responses can be ignored, and standard cone sensitivity curves can be defined using the sensitivity curves of the majority of people with normal colour vision.

Standardizing sensitivity curves

A standard set of sensitivity curves can be defined using the aggregate of the sensitivity curves of people with normal colour vision.

This results in a set of standardized sensitivity curves, which can be used for quantifying colours. However, before doing that, another type of colour needs to be addressed.

Non-Spectral Colours

Until now, only spectral colours (colours corresponding to monochromatic light) have been discussed. But most of the light around is not monochromatic; it is a combination of multiple wavelengths of light. This will slightly complicate the measurement of the cone responses. Earlier, for monochromatic light, the responses were simply the sensitivity values of the cones at the given wavelength. This does not work for non-monochromatic light since there is no singular, specific wavelength.

Monochromatic and non-monochromatic light

The first spectral power distribution shows a monochromatic light source. The second spectral power distribution shows a light source that is non-monochromatic, since it emits light over a much wider range of wavelengths. Notice how non-monochromatic light does not necessarily emit the same intensity of light at all wavelengths.

Instead, the responses for non-monochromatic light sources is calculated by finding the weighted average of all the responses — by computing the normalized area under the response curve. The response curve is simply the product of the cone sensitivity curves and spectral power distribution: The spectral power distribution describes the intensity of light for some given wavelengths. Meanwhile, the sensitivity curves describes the sensitivity of the cones at some given wavelengths. So, their product together describes the cone response at that wavelength. Measuring this product over all wavelengths (equivalent to calculating the area) gives the total response, which may be normalized if required (eg. responses are normalized for monochromatic light).

For example, this is what the cone responses for light corresponding to grey , pink , white , purple , and olive green look like:

Interactive spectral power distribution

The spectral power distribution can also be modified by drawing on it.

Cone responses

The response of the cones is the the total area under the curve that is obtained after multiplying the spectral power distribution and the cone sensitivity curves. The response may be normalized for light sources that have a very narrow wavelength range (eg. monochromatic light).

The colour of non-monochromatic light can look different from spectral colours because the set of cone responses produced for these types of lights may be different from the set of responses produced for spectral colours. The brain interprets these unique cone responses as a colour distinct from spectral colours. These colours are aptly referred to as non-spectral colours.

Metamerism

There are times when non-monochromatic light produces cone responses that are similar to the responses produced by spectral colours — making them appear similar to spectral colours. This phenomenon will be discussed later.

Colour Space

Since colours perception is ultimately dependent on the set of cone responses, it should be theoretically possible to represent colours using only the responses of the cones. And these responses should theoretically be enough to describe every perceivable colour. So, if the set of cone responses can be quantified, it should be possible for all colours to be quantified just as easily.

As mentioned earlier, the spectral power distribution of any light is both quantifiable and measurable . Similarly, while the cone sensitivity curves are subjective, for the purpose of colour quantification, an aggregate of the majority can be standardized and used. Since the response of the cones is dependent on these two factors — both of which can be quantified — the response, too, should be quantifiable. But only if there is a well-defined relationship between the two as well.

Again, as discussed in the non-spectral colours subsection, the biology virtuosos have already found a way to define that relationship — it is the normalized area under the response curve (the response curve itself is the point-wise product of the spectral power distribution and the photoreceptor sensitivity curves).

Cone response revisited

The response of the cones is the the normalized area under the curve of the response curve. The response curve is the point-wise product of the spectral power distribution and the cone sensitivity curves.

This relationship can be more formally described as:

L = ∫ J(λ)·l(λ)·dλ
M = ∫ J(λ)·m(λ)·dλ
S = ∫ J(λ)·s(λ)·dλ

Where J(λ) describes the spectral power distribution of the light, while l(λ) , m(λ) , and s(λ) are the sensitivity curves of the L-cones, M-cones, and S-cones. The responses are also normalized such that their maxima is equal to unity. This relationship quantifies cone responses to a spectral power distribution.

So the colour of any light or any object reflecting light can be precisely described by its (L,M,S) values — which can be derived by from its spectral power distribution. The set of all possible (L,M,S) values describes every perceivable colour, and all these possible values together form a three dimensional space, aptly called a colour space . More specifically, this is the LMS colour space , where colours are defined as a set of (L,M,S) values. The LMS colour space here is visualized below, where each of the responses of the cones is represented using a spatial dimension.

L
M
S
The LMS colour space

While all colours can be represented using LMS values — and hence will always be in the LMS color space, the reverse is not always true. Not all LMS values correspond to perceivable colours. Since the sensitivity curves of the M-cones overlaps the sensitivity curves of L-cones and S-cones, any type of light that excites the M-cones, must also excite the L-cones, or S-cones, or both. So ‘colours’ having LMS values such as (0,0.7,0) are imaginary . The imaginary values are represented as black in the above LMS colour space, but their actual colour is hard to approximate since these ‘colours’ do not appear naturally, and have only been replicated recently by shooting lasers directly to the retina .

So we achieved our goal — a way to quantify colours precisely, using numbers. Except this is not at all the standard used when describing colours. The LMS colour space is one way to describe colours, but is not the standard way to describe them.

As mentioned, defining the LMS values for a colour requires defining some relationship between the spectral power distribution and response of the cones. However, this is only possible if there is a set of standardized sensitivity curves. Without them, the responses cannot be measured or defined.

Undefined cone sensitivity

The cones responses cannot be calculated from the spectral power distribution if there is nothing relating them both.

Interestingly, colours were quantified and standardized even before the sensitivity of the cones were measurable with a decent level of precision. So there was already an existing definition/model for colours, making the LMS colour space redundant.

And perhaps, you might have never even heard of colours being represented as a set of LMS values. Instead you might have seen colours represented as a set of RGB values. What is up with that? How is it different from LMS values? And if you have ever searched for numerical values for colour, you might have come across some random XYZ values and a coloured horseshoe diagram that looks like this:

To understand this weird looking diagram, and how RGB values came to be, we need to start using the standard that was used for quantifying colours earlier.

This older model of colours did not use the cone responses as its basis. Instead, it used colour matching functions — mapping colours to the intensity of certain lights required to produce that colour. This is the same as quantifying colours using numbers (measurable intensity values), but the difference is that it relies on a different phenomenon to map colours to numbers.

As mentioned earlier briefly, sometimes lights with different spectral power distributions can produce similar responses in the cones as spectral colours. They can also produce similar cone responses as non-spectral colours as well. More broadly, the same cone responses can be produced by light having different spectral power distributions — so different types of lights can appear to have the same colour even if their spectral power distributions vary. This is called metamerism .

Metamer examples

Here, multiple distributions can produce similar maroons .

This phenomenon was explored further in colour matching experiments by William David Wright and John Guild . A light source with three wavelengths (435nm, 546nm, 700nm), each with different intensities, were mapped to spectral colours by varying the intensities of its constituent monochromatic lights — such that the resultant light was perceived to be the same as a spectral colour. The findings were then aggregated and summarized as (the now standardized) colour-matching functions.

The colour matching curves define the intensity of each of the three primaries required to replicate a spectral colour. Primaries are colours that can be used for recreating other colours. Here, the primaries are the 435nm, 546nm, 700nm monochromatic lights.

Wavelength
Inaccurate cyans

The first graph shows the intensity of the primaries — they are colour matching functions. The rest of the graphs have the same meaning as the previous figures. Notice the negative intensity values, and notice how the colours formed by the primaries around 500nm cyan looks very different from the real cyan at 500nm.

While the three primaries can produce similar responses to certain spectral colours in the cones — making them appear similar — it is not always the case. There are spectral colours which can never be replicated using only the three monochromatic primaries. For example, the three wavelengths above cannot produce a colour that looks similar to spectral cyans (light having wavelengths around 500nm).

However, the cyans can still be mapped to the primaries. The spectral cyans look similar to the colours formed by the primaries if some intensity of the 700nm primary is added to the cyan itself. This results in measurable intensity values of the 700nm primary — which can be used to map and quantify the spectral cyans. However, since light is added to the spectral colour instead of the primaries, it needs to be represented differently. In the colour matching curves, this is represented using negative values.

700nm Intensity (Normalized):

Negative intensity

The 435nm, 546nm, and 700nm primaries cannot produce colours that exactly matches the spectral cyans. The only way to match the primaries to spectral colours is by adding some amount of the 700nm primary to the spectral colour itself. The addition of 700nm light to the spectral colours is represented as negative intensity in the colour matching functions.

Physically, it is impossible to create light with negative intensity, so it is impossible to reproduce certain colours using only three wavelengths of light. However, colours can still be represented theoretically using negative values in these colour matching functions, for the purpose of quantifying colours.

These colour matching functions form the basis for the present standards that are used for describing and defining colours.

CIE Colour Spaces

The Wright-Guild colour matching functions makes spectral colours quantifiable as a set of measurable intensity values of three monochromatic lights. But non-spectral colours too can be mapped to intensity values using this technique.

Instead of constraining the intensity values of the primaries to follow the colour matching functions, they can also be set to any arbitrary intensity value. This results in other perceivable colours, which are not necessarily spectral — ie. non-spectral colours. They are still colours nonetheless, and more importantly, all these colours can be mapped to a set of (intensity) values. So, a set of intensity values (of the 435nm, 546m, and 700nm primaries) define a colour. Since these values define colours, they can together create a colour space. This colour space is called the CIE RGB colour space .

R (700nm)
G (546nm)
B (435nm)
The CIE RGB colour space

The CIE RGB colour space uses the normalized intensity of 700nm, 546nm, and 435nm lights as its bases. The LMS colour space, in contrast, used the response of the cones (L,M,S) as its bases.

These intensity values are again measurable and quantifiable, and forms another way to quantify colours. However, there are some minor inconveniences with this colours space. Not all colours are present in this colours space. Or more accurately, not all perceivable colours lie in the positive quadrant of this colour space.

Consider the spectral colours. Mapping spectral colours in the this colour space results in the spectral locus . Some part of this spectral locus outside the positive quadrant of this space — for example, the spectral cyans. Similarly, certain non-spectral colours lie outside the positive bounds of this space as well.

Wavelength

Cyans outside the positive quadrant

Unlike the LMS colour space, which describes all perceivable colours using non-negative values (all colours have values within zero and one), the CIE RGB colour space requires negative values to define certain colours. For example, spectral cyans are represented using negative intensity of the R primary, and thus lie in the negative R half of the CIE RGB space.

It was decided that a colour space that could map all colours to non-negative values would have been preferable. But instead of conducting more experiments to construct a new colour space, the existing CIE RGB colour space could also be transformed using simple linear transformations. The transformation of the three dimensional colour space can be defined using a simple 3x3 matrix.

Linear transformations

The matrix defines how the space gets transformed. To get a more intuitive feel of the transformations, try fiddling around with the matrix value sliders. To understand how linear transformations and matrices work in more detail, you can refer to this great resource .

Transforming the space means the new space is now defined by different new bases or new primaries. Earlier, some spectral colours had to be defined by negative values of a primary, but now the same colour is defined by positive values. It suggests that the coordinate system (the primaries) itself has to contain some sort of a negative intensity. But it is impossible for light to have negative intensity, implying that the primaries for the new colour cannot physically exist, and themselves are imaginary.

Since the primaries of the new colour space are imaginary, it is reasonable to define the new primaries to represent more abstract concepts instead of physical quantities. Again, it was decided that one of the primaries would define the luminance of the colour. The other two can be used to derive its chromaticity . One of the two primaries is also roughly equal to the response of the S-cones. A specific transformation was defined to map the colours to the non-negative quadrant and incorporate the above ideas.

Specific transformation

A specfic matrix was defined to transforms the colour matching functions to have all positive values, and to fulfill other certain criteria — one of them being separating luminance and chromaticity.

Luminance and chromaticity

Luminance refers to the perceived brightness of a colour, while chromaticity is analogous to hues. According to the opponent process theory, colours are perceived as pairs of opposing colours — red vs green, blue vs yellow (chromaticity), and black vs white (luminance). Hence, it is possible to describe a colour by how red it is compared to how green it is, how blue it is compared to how yellow it is, and how bright the overall colour is — ie. defining colours based on luminance and chromaticity values.

The primaries of this new colour space are named X, Y, and Z — and the resulting colour space is called the CIE XYZ colour space . All spectral colours lie in the positive quadrant of this colour space.

Wavelength

Imaginary primaries

Notice how transforming the CIE RGB space results in a new space, defined by new bases (primaries). The new XYZ primaries are no longer grounded in physical reality, and instead are more abstract and imaginary.

The other colours in the CIE RGB space can similarly be mapped in the XYZ colour space by applying the same matrix transformation. However, not all perceivable colours can be mapped to the XYZ space using this transformation since the CIE RGB space itself does not define all perceivable colours in its space — colours that require ‘negative’ intensities have not been defined, apart from the spectral colours . Unlike the RGB colour space, where the primaries are physical monochromatic lights and thus have a corresponding colour, the CIE XYZ space has imaginary primaries and so it is not obvious which colour a certain combination of (X,Y,Z) values refer to — or if it even maps to a valid colour.

X
Y
Z

The CIE XYZ colour space

The colours in the CIE RGB space after the transformation — resulting in the XYZ space — is shown above. While some of the values in the new XYZ space are valid colours (eg. the CIE RGB colours), it is not clear what the values outside the CIE RGB bounds represent. Real and perceivable colours like the spectral cyans lie outside the positive bounds of CIE RGB space, but still lie inside the positive bounds of the CIE XYZ space. There must similarly be other (X,Y,Z) values that are outside the RGB bounds but inside the XYZ bounds, that are valid colours — for example, the colours lying between the spectral cyans the the CIE RGB colours. However, mapping these colours can be very difficult, since the primaries of the CIE XYZ space are imaginary and don’t necessarily correspond to an observable colour, unlike the physical CIE RGB primaries.

To find which colours the undefined values correspond to, it is helpful to first discuss yet another popular way to represent colours — using chromaticity spaces.

Chromaticity Space

As mentioned before, colours can be alternatively classified based on more abstract properties like their luminance and chromaticity. This can be a more convenient way for defining colours since it matches with how the brain is believed to classify colours — as dark vs bright (luminance), and as red vs green and blue vs yellow (chromaticity).

Consider the CIE RGB colour space. A simple way to obtain a crude approximation of the luminance from the primaries’ values is by taking the their sum (R+G+B). Likewise, the chromaticity values can be approximated by taking the ratios between the intensities of the RGB primaries.

Luminance-chromaticity estimates

While the luminance and chromaticity are approximations, it does not mean that there is loss of information. The exact RGB values can be recreated using the luminance and chromaticity estimates. The approximation simply refers to the imperfect separation of luminance and chromaticity.

So, the luminance of a colour with values (R,G,B) will be L=R+G+B, and its chromaticity values would be their relative intensities — which can be computed by normalizing them. That is, the chromaticity ratios r, g, b would be equal to R/L, G/L, and B/L respectively. Consider a simple example where the luminance is fixed to one. In the CIE RGB space, all the colours with a luminance value of one will lie on the R+G+B=1 plane. The (R,G,B) values of a colour on this plane represents the ratios of its primaries, and so represents its chromaticity values.

R r
G g
B b
Chromaticity plane

The above slice of the CIE RGB space represents a chromaticity plane. When the luminance is fixed, changing any of the (R,G,B) values changes the relative intensity of the primaries without changing their total intensity (luminance). So colours on these type of planes represent colours with a fixed luminance, but different chromaticities.

Here, since the luminance is fixed to one, the chromaticity ratios (r,g,b) of the colours are simply the (R,G,B) values.

A colour with some other luminance k will lie on the plane R+G+B=k. Meanwhile the chromaticity ratios will be the normalized intensities of the primaries, so the (r,g,b) ratios are the projection of the (R,G,B) values on the R+G+B=1 plane.

R r
G g
B b
Pan
Dimensionality reduction

The coloured dots represent colours with the same luminance — colours that lie on the R+G+B=k plane (outlined using the gray triangle). The chromaticity of a colour is the ratio of the intensities, or put simply, their normalized intensities. Geometrically, the chromaticity (the point in black) is the projection of the (R,G,B) point (coloured gray) on the R+G+B=1 plane. Try panning to get a feel of this space.

From the diagram it can be seen that colours with the same chromaticity but different luminance lie on the same lines radiating from the origin. These can be thought of as lines of chromaticity. Points on these lines represent colours with the same chromaticity but different luminance values. Colours with the same chromaticity values appear ‘similar’ but can look lighter or darker, depending on their luminance. For example, greens lying on the same chromaticity-line look similar but appear lighter or darker based on their luminance.

Since colours with the same chromaticity but different luminance values get projected to the same point, it leads to a loss of information . The chromaticity plane contains information about chromaticity, and generally does not contain any information about luminance. So unless luminance is explicitly specified, it is impossible to recreate the corresponding RGB values using just the (r,g,b) values.

For some specific luminance, the chromaticity space is just a two dimensional plane in a three dimensional space. Instead of representing the chromaticity space as a plane embedded in a three dimensional space, it is simply represented as a two dimensional space by projecting the chromaticity plane to one of the colour space planes. In the case of the CIE RGB space, the R+G+B=1 chromaticity plane is projected to the RG plane.

Pan

The CIE rg chromaticity space

Projecting the R+G+B=1 plane of the CIE RGB space to the RG plane results in the rg chromaticity space . This plane is specifically called rg plane, and not the RG plane, because RG and rg represent different quantities. The values (r,g) represent the chromaticity of a colour — it represents the relative ratios of the R and G primaries. Meanwhile the (R,G) values simply represent the absolute intensity of R and G primaries.

The chromaticity values for the spectral colours, too, can be calculated by applying the same transformations on the spectral locus — normalizing the intensity of the primaries to get its projection on the R+G+B=1 plane, and then selecting the (r,g) values to get its projection on the rg plane .

Wavelength
Pan

The CIE rg chromaticity diagram

Applying the same operations for the spectral colours instead of the CIE RGB colours — applying the transformations on the spectral locus — results in the rg chromaticity diagram . The spectral locus is represented in gray, while its projection on the R+G+B=1 plane is coloured in black. Notice that again, a part of the locus lies on the negative half in the rg chromaticity space.

While the colours, and therefore the chromaticity of the colours in the positive quadrant in the rg chromaticity space are defined, the chromaticity for colours outside the small subset of the positive quadrant is again not defined. Apart from the spectral colours, of course.

Undefined chromaticity

The CIE rg chromaticity space is derived from the CIE RGB colour space, so colours and values that are undefined in the RGB colour space are also undefined in the rg chromaticity space. The only colours that have defined values are the colours created using the CIE RGB primaries, and the spectral colours. These have definite values in the RGB space and thus also have values defined in the rg chromaticity space.

The rg chromaticity diagram above might look a little weird with chromaticities defined in some of the negative half of this space (the spectral cyans), and other chromaticities defined in some of the positive half (the colours replicable using the CIE RGB primaries), but with no chromaticities defined for values in between that space. It is not because there are no such colours — colours that are a combination of spectral cyans and the CIE RGB primaries exist, and intuition would suggest that they will have (r,g) values in between those of the cyans and CIE RGB colours in the chromaticity space. The problem is finding a way to map these colours (chromaticities) in the chromaticity space.

In-between chromaticities

Intuition suggests that the chromaticity of colours which consist of some combination of spectral cyans and CIE RGB primaries would lie in the space between the spectral locus (the part corresponding to cyans) and the CIE RGB colours. This space is highlighted in light blue above.

Defining the chromaticity for this undefined, in-between space requires another insight from other experiments — namely that addition of colours can be approximated as a linear operation . What it means is that colours defined in the CIE spaces can be used to define other colours that are a linear combination of the already-defined colours.

Consider two colours the lie on the spectral locus, eg. two spectral cyans. The colours that can be formed using a linear combination of these cyans can then be represented as a linear combination of the chromaticity values of the CIE RGB primaries — ie. they can be represented using (r,g) values.



Intensity of nm light (r: , g: ):
Intensity of nm light (r: , g: ):
The rg-chromaticity of resultant colour:

=
Defining chromaticity using already defined chromaticities

Combining spectral colours of varying intensities results in real, observable colours. These perceivable colours can be defined as a linear combination of the spectral colours. Since addition of colours is linear, and the spectral colours have values defined in the CIE colour and chromaticity spaces, these new colours can themselves be defined as the linear combination of CIE colour/chromaticity space using the already-defined values of the spectral colours.

The entire space ‘inside’ the spectral locus will have a defined chromaticity, and it should be obvious why — any colour that can be created as some combination of spectral colours will always lie inside this space. In fact, this space contains the chromaticity of all perceivable colours. Since a colour is ultimately determined by the intensity of lights at different wavelengths (the spectral power distribution), a linear combination of their intensities can be mapped in this space — and since these intensities will always be non-negative, their chromaticity values will always lie inside the area spanned by the spectral locus.

This property of linearity of colour addition can similarly be expanded from the two dimensional chromaticity spaces to the three dimensional colour spaces. A colour can be first quantified as the intensity of two monochromatic lights, which can then be rewritten as the linear combination of the CIE primaries using the CIE colour values of the two monochromatic lights.

While the chromaticity space was introduced to show the linearity of addition of colours in a simpler reduced dimensional space, it has other uses too. Chromaticity is another way to quantify colours. It is not perfect, since there is a reduction of information — the luminance component of a colour is sacrificed in order to be able to represent colours using two dimensions. But this is a convenient tradeoff since most visual communication media are two dimensional, so chromaticity spaces allow easy representation of colours on such media, without losing much information — making them pretty popular.

The xy Chromaticity Space

While chromaticity spaces are a popular way of representing colours (again, to be more accurate, chromaticities) the CIE rg-chromaticity space is not very common because it requires negative values to describe certain chromaticities. Instead, the xy chromaticity space is more commonly used.

Similar to how the CIE RGB colour space was transformed to get the rg chromaticity space and rg chromaticity diagram, the same transformations can be applied for the CIE XYZ colour space to get the xy chromaticity space and the xy chromaticity diagram .

Wavelength
Pan

Meaning of xy

The nomenclature used in the CIE XYZ colour space is analogous to the naming convention used in the CIE RGB colour space. So x = X/(X+Y+Z) and y = Y/(X+Y+Z). The chromaticity value is obtained by projecting colours on the X+Y+Z=1 plane, and then z values are discarded to get the (x,y) values — analogous to projecting the the X+Y+Z=1 chromaticity plane to the XY plane.

Here, the chromaticity of the spectral colours (the spectral locus) is shown above.

Since the XYZ colour space is specifically defined to map spectral colours to positive values, the chromaticity values (which are just normalized values of the primaries) of the spectral colours are all positive as well. Because all perceivable colours are some combination of the spectral colours, the chromaticity values of all observable colours will lie inside the spectral locus area, and thus will also have positive values.



,
The CIE xy chromaticity diagram

Unlike the rg chromaticity space, all the perceivable colours have their chromaticity defined using non-negative values in the xy chromaticity space. The (x,y) chromaticity values for all the colours can be derived the same way it was done in the rg-chromaticity space — using a linear combination of two spectral colours, and then using their xy chromaticity values to calculate the xy chromaticity values of the colours formed using the two spectral colours.

Quantifying colours using chromaticity values is not perfect because of the elimination of the luminance information, but chromaticity diagrams like the xy chromaticity diagram can be still be useful for certain applications — eg. to visualize the limitations of gamuts.

Gamut

Again, consider two monochromatic light sources. These lights will produce colours with a chromaticity that is a linear combination of the chromaticity values of their constituent monochromatic lights — the chromaticity of the resultant colours will lie on the line that joins the spectral colours in the CIE xy chromaticity plane. No combination of intensities can produce a colour with a chromaticity outside this line.

For example, lights having greenish and bluish chromaticities can never produce a colour with reddish chromaticities.

546nm
435nm
Chromaticity of two lights

Colours created by combining two (monochromatic) lights will have a chromaticity that lies on the line connecting the chromaticity points of the two lights in the chromaticity diagram. In this case, the 546nm and 435nm lights can never create colours with chromaticities lying outside this line.

Until now, all the visualizations used the ratios of two monochromatic lights to calculate the chromaticity of colours. However, the chromaticity can be calculated using three monochromatic lights as well. The chromaticity will then be a linear combination of three chromaticity values.

Consider three monochromatic lights — the CIE RGB primaries, for example. The chromaticity of the colour created using the primaries would be a linear combination of the three chromaticities.

700nm (0.733, 0.267)
546nm (0.266, 0.724)
435nm (0.166, 0.008)
+ × (0.733r + 0.267g)
+ × (0.266r + 0.724g)
+ × (0.166r + 0.008g)
=
Chromaticity of three primaries

The chromaticity of colours produced using the CIE RGB primaries will always lie inside the triangle formed by the three primaries — since it uses a linear combination of non-negative scalars coefficients (intensity values).

The chromaticity of the colours which can be physically created using the RGB primaries will lie inside the convex polygon formed by the primaries. This range of colours (or chromaticities) that the primaries can produce is called its gamut . Points lying outside the polygon cannot be physically created (at least with the same three primaries), since it would require a linear combination with negative coefficients — creating colours with chromaticities that lie outside this polygon would require some negative intensities of the primaries, which is physically not possible.

Using more primaries would result in a convex polygon with more vertices (corners) and would cover a larger area, and hence more chromaticities, but having three primaries is usually enough for most applications. It is also economically more efficient to use primaries which are not purely monochromatic. So most displays use just three primaries which aren’t monochromatic — some of these primaries have been standardized, and are even used to construct colour spaces. For example, the sRGB and Adobe RGB colour spaces use standardized primaries which are non-monochromatic.

Primary A
Primary B
Primary C
Gamut & Colour space

Gamut refers to the set of colours that can be physically recreated by an output device, while a colour space is simply a mathematical model used to describe colours. Colour spaces like sRGB and DCI-P3 may arbitrarily restrict itself to certain values to more accurately represent physical and economic constraints. Others like the Pro Photo use imaginary primaries (like the CIE XYZ colour space) to be able to represent a broader set of perceivable colours.

The sRGB colour space underpins another popular way of quantifying colours — colour hexcodes . These hex codes represent the intensity of the sRGB primaries. Usually, the first two hex numbers (same as one byte, or eight bits) correspond to the intensity of the reddish primary. The next two hex values represent the intensity of the greenish primary and the next two hex numbers describe the intensity of the bluish primary.

Colour depth

In hex notation, a colour is usually represented using 24 bits. The number of bits assigned for representing a colour is called the bit depth or colour depth . These 24-bit colours are sometimes also called true colours, and can represent a total of 2^24 values or 16,777,216 colours. Similarly, there are also 8-bit colours and 30-bit colours, which can represent fewer and more shades of colours respectively. There are also other colour depths like 3-bit colours, etc.

The colour depth in a way represents the ‘precision’ of colours that can be produced, but does not represent the ‘range’ of colours. The colours are still constrained by their primaries — colours outside the gamut of the primaries can never be recreated even if more bits are assigned to control their intensity more precisely.

So far multiple ways of quantifying colours have been discussed. It might feel like that these are more than enough for most applications, but there is one more important thing to consider when quantifying and reproducing colours.

White Point

Back to some physical science — all bodies radiate photons, due to blackbody radiation . The spectral power distribution of the radiation is a function of temperature . The spectral power distribution of the radiation will have a colour associated with it.

Temperature
Blackbody

A blackbody is an idealized body that emits only blackbody radiation (radiation is only a function of temperature). Most bodies in the universe are not perfect blackbodies, but approximating it as such can still be useful. The sun is an example of a blackbody — its surface is around 5500K, and emits the highest intensity radiation around the visible wavelengths (visible light).

The colours above have a corresponding chromaticity — and when mapped on the CIE xy chromaticity diagram, together form the Planckian locus .

Planckian locus

The chromaticity of the colours of blackbodies at different temperatures when mapped on a chromaticity diagram forms the Planckian locus. Try changing the previous temperature slider to see how temperature affects the spectral power distribution of a blackbody, and how that in turn affects its chromaticity.

The colour temperature is another way to quantify certain colours and chromaticities — mostly different types of white. It is a common way to do it, as most physical sources of illumination have a chromaticity close to these values. Daylight, for example, has a chromaticity similar to a blackbody at temperatures ranging from 5000K to 6500K, and incandescent bulbs emit light having a colour temperature close to 2700K.

Daylight colour temperature

Incandescent bulbs have filaments heated to about 2000K to 2700K and thus have colour temperature close to that temperature. But the same is not true for sunlight as its colour temperature depends on the time of day. Due to Rayleigh scattering , shorter wavelengths of sunlight get scattered making it appear redder, while making skies and overcast light appear bluer. During mornings and evenings when the sun is lower in the sky, more light gets scattered causing sunlight to appear even redder (have a lower colour temperature). Daylight is the combination of all direct and indirect sunlight, and thus also depends on the time of day.

Most illuminants have chromaticity values that lie close to the Planckian locus, but do not lie exactly on it — as most bodies are not perfect blackbodies. Other light sources like fluorescent lights and LEDs , do not even use blackbody radiation to emit light, and thus also do not necessarily lie on the Planckian locus.

White illuminants

Daylight and other light sources usually appear white, and may have chromaticities that lie near the Planckian locus, but need not lie exactly on it.

While the chromaticity values of these illuminants do not lie on the Planckian locus, they are still close enough to be perceptually similar to a blackbody, to be meaningfully attributed to a colour temperature. These colours can be assigned a correlated colour temperature depending on the colour temperature it most closely resembles.

Correlated colour temperature lines

The lines intersecting the Planckian locus represent correlated colour temperatures. Two points on a correlated colour temperature line have the same correlated correlated colour temperature.

Correlated colour temperature can describe non-ideal blackbodies and other sources of white light. But since a single correlated colour temperature can correspond to multiple chromaticity values, it is not a very precise way to describe white light.

Instead, to represent different types of white light in an unambiguous and precise manner, certain standard illuminants have been defined. These are theoretical sources of light with a precisely defined spectral power distribution, and therefore with an exact chromaticity value as well.

Standard illuminants

Some of these illuminants have defined to represent common sources of illumination (light). For example, the D65 illuminant represents daylight with a colour temperature of around 6500K, while Illuminant A represents an incandescent light with a specific spectral power distribution.

All this effort just to define certain chromaticities of white light might seem excessive, but its importance is more apparent when you consider that most colours are visible not because they emit their own light, but because they reflect the light of an illuminant. That illuminant is usually daylight (white), or some other illuminant trying to replicate daylight.

Since a non-emissive body does not emit its own light, its spectral power distribution is mostly dependent on what it reflects, and the spectral power distribution of the light source illuminating it. More accurately, it is the point-wise product of the body’s spectral reflectance curve and the spectral power distribution of the illuminant. For example, a body might appear bluish under daylight but the same body may appear more yellowish under an incandescent light.

Spectral reflectance

The spectral reflectance describes how much light is reflected based on its wavelength. More precisely, it defines the fraction of light that gets reflected, as a function of wavelength.

The first graph shows the spectral reflectance of an object, the second graph shows the spectral power distribution of the illuminant, and the third shows the resultant spectral power distribution of this reflected radiation (the product of the above two curves).

As can be seen, the colour of a non-emissive body is dependent on its ‘own colour’ as well as the light illuminating it. For example, here, changing the above illuminant to Illuminant A or D65 makes the resultant colours appear warmer or colder, even if the ‘inherent colours’ — greys , whites , pinks , purples , greens , etc — do not change at all.

The colour distortions due to differences in illumination can be seen more clearly in this example — the same objects here are lit up by different types of illuminants.

Colour picker

Hover over the pictures to compare the ‘same colour’ under different illumination.

Colour distortion

The left colour box shows colours under warm lighting, while the right colour box shows how it would appear under cool lighting. Here, the ‘same colours’ get distorted because of inconsistent illumination.

Image sourced from Good Free Photos , under CC0 .

The change in colour because of differences in illumination also affects its chromaticity. Consider a ‘white’ object (reflects all wavelengths of light equally) under an equal energy illuminant (emits equal energy of radiation/light for all wavelengths). The resultant spectral power distribution of this body will be a straight line — ie. equal energy across all wavelengths. Its chromaticity will lie at (0.333, 0.333) in the xy chromaticity space. Now consider the same object under the illuminant D65. The spectral power distribution of the body will now be the same as the D65 illuminant, and will lie at (0.313, 0.329) in the xy space. The chromaticity of a ‘white’ object will similarly vary for other illuminants.

So a display that emits its own light, trying to mimic ‘white’ will need to take into account the illumination conditions of the environment in order to not appear out of place, and look ‘correct’. Other colours will similarly get distorted, and need to be corrected. Again, similar to how colour addition was approximated as linear, this correction can also be approximated as a simple linear transformation — by scaling the colours linearly, using the white point as a reference.

Primary A
Primary B
Primary C
White point as reference

The chromaticity of a colour that is being lit by the first illuminant (or how it would roughly appear, under that illuminant) is shown in black, while the chromaticity of the same colour being lit by the second illuminant is shown in gray.

The chromaticity correction can be approximated by linearly transforming the colour space, such that when the colour space primaries are at their maximum intensity (or equal intensities, in the case of chromaticity), the chromaticity of the colour will be the same as the required illuminant. This acts as a reference [white] point for other colours — they are scaled using the same transformation that was used to transform the original white point to match the chromaticity of the other illuminant.

True chromaticity

The true chromaticity of a non-emissive object is hard to define, since it is dependent on illumination. Instead, it can be defined using its spectral reflectance, which is independent of illumination. Since an equal energy illuminant has equal energy across wavelengths, it will not distort the spectral reflectance of the object, and so the chromaticity when lit by an equal energy illuminant can be considered its ‘exact colour’.

Take another look at the images of the classroom from earlier. Despite the colours being different (because of the different illuminants), they might appear similar because of chromatic adaptation . Human colour perception adjusts for differences in illumination to preserve colours of objects — by using clues from the surrounding environment. For the classroom images, the white walls may ‘feel’ white despite their chromaticity values being closer to those of yellows and blues. Other colours also can also appear ‘original’ despite being distorted by the illuminant, because of chromatic adaptation.

Chromatic adaptation

Notice how the whites (as well as other colours) still ‘feel’ white (or their original colour) despite having distorted chromaticities.

However sometimes, chromatic adaptation can also trick the brain into perceiving wrong colours. A relatively famous, but extreme example of this is the dress . The same colours of the dress can be perceived as blue and black, or white and gold — depending on how the brain perceives the white point of the light illuminating the dress. If the brain assumes the dress is lit by a bluish light, it tries to correct for it, making the dress look white and gold. Conversely, if the brain assumes a warmer illuminant, the brain tries correcting the colour distortion, making the dress appear blue and black.

Chromatic adaptation: Blue and black dress

The above graphic shows how the colours of a blue and black dress would look if it is distorted by a yellowish illuminant. If the brain assumes the illuminant is indeed yellowish, it would try to ‘correct’ the colours to their ‘original’ hues, which in this case would be blue and black.

Image sourced Tumblr (archived) , under fair use.

Chromatic adaptation: White and gold dress

Similarly here, how the colours of a white and gold dress might get distorted by a bluish illuminant is shown above. The brain, assuming the illuminant is tinted blue, would try to correct the colours back to white and gold.

Notice that the colours of the right image in both the above and below graphic are the exact same. But how the colours are perceived by the brain depends on whether it assumed a warm or cool illuminant. In very ambiguous cases like these, it might be equally likely for people to perceive it as either of the two.

The above scenario is an example of what happens when colours are quantified without correcting for the white point (illumination) — it can look out of place, and in extreme cases like the dress, even lead to completely wrong colour description and reproduction. If the colours of the dress are mapped on the chromaticity diagram directly without any corrections, it will not always describe the ‘real’ chromaticity of the dress.

For example, here, the colours of two pixels with blue/white and black/gold are mapped on the xy chromaticity diagram. Notice how the chromaticity values correspond to bluish and yellowish hues, suggesting the colours are actually blue and gold. This is obviously not the case. The colours can be corrected by changing the white point, by applying the same linear white point transformation from above .

Chromaticity of the dress colours

The chromaticity of the dress on the xy chromaticity diagram maps to values that correspond to (somewhat) bluish and yellowish chromaticities. But the actual colours of the dress are blue and black. Setting the white point to a warmer colour and then transforming it to the equal energy illuminant would transform the chromaticity values to result in more accurate approximations of the ‘true’ colours of the dress.

For accurate colour quantification and reproduction, the illumination of the environment needs to be taken into account too — when quantifying colours of non-emissive objects, which are most of objects around us.

Colour Science

The original questions should be easy to answer now. Colour blindness exists because of cone anomalies. Addition of colours results in a colour whose brightness (luminance) is the sum of the luminance of the colourants, and its hue or chromaticity is the ratios of its colourants. The multiplication of colours can be thought of as a colour reflecting the colour of another coloured illuminant. Colour hexcodes, even with 16,777,216 possible values, are still limited by their primaries. And the dress appears both white and gold, and blue and black because of chromatic adaptation.

Colours are a very interesting topic, because it involves quantifying something that feels innately qualitative. This article mainly discusses additive colour models , but subtractive and other colour models are just as interesting. Most of these topics involve ways to describe and recreate colours . But there are also entirely different branch of science that deal with the psychology of colours — why certain colour combinations appear pleasing, how the meaning of colours vary across cultures, or how colours affect other senses .

The subject of colours is vast — spanning scientific domains from quantum physics and electromagnetism to physiology and psychology. This post is a very tiny fraction of what constitutes colour science .


References

Debian and the sirens

Lobsters
joeyh.name
2026-08-29 11:33:38
Comments...
Original Article

Thirty years ago I became a Debian developer. Twelve years ago I left the project. I left because it seemed that the Debian ship had become too slow to turn, too barnacled with a series of individually OK decisions that each added a little bit of friction and a little less flexability. That made Debian strongly what it is, but prevented it from fruitfully exploring the vast possibility space of what it could be.

Debian will probably resolve today to allow LLM use in Debian development. I'm writing before the vote results are in, but will only post this afterwards. (Update: as expected) It's not my place any longer to try to steer the ship. But I'm still a passenger and I still have opinions, and I still pass by well-worn parts of the rigging that I put up decades ago, and remember what I was trying to accomplish back then.

When I think about LLMs in Debian development, I mostly think about debhelper and what it accomplished. The debian/rules files back when I joined the project were long and complex, full of weird boilerplate, and often you'd copy one and modify it to try to get something that could build a package without too much work. Debhelper first regularized the boilerplate, so packages had rules files that were a succession of dh_ commands, and then it scapped almost all of the boilerplate, reducing the files to the minimum possible. What was left was 3 lines of unncessary boilerplate, there only to satisfy a legalistic reading of a policy document. Changing that to eliminate the boilerplate was already impossible, even though the actual benefit would have been large over the many thousands of packages in the distribution.

What LLMs in Debian development will do, I fear, is eliminate any incentive to scrap boilerplate or reform policies that require a lot of other senseless human effort. If I had had access to LLMs 30 years ago, I might have just had them generate the rules files, replate with complexity. So they will make Debian even more firmly what it is, and ever less likely to explore what it could become.

Unfortunately, one of the things that Debian is, is almost unable to manage packaging modern dependency trees. While more recent distributions like Guix can recursively import dependencies from a dozen programming languages' package repositories, with a result that is generally acceptable to add to the distribution, Debian's policies don't make that very possible for a progam to accomplish. Perhaps some will use LLMs to do that. If they succeeed, Debian will become dependent on proprietary software for development, while still needing people in the loop, doing even less appealing scut-work.

I could speak of other harms, but that alone is enough that I'm sure that, if I had not left the project twelve years ago, I would be leaving it soon. As a passenger, I imagine I'll spend time aboard still from time to time, but it's certainly time to hop off in different places and look around and relish the different ways.

I lost a parent yesterday , and I'm trying hard not to think of the results today as having lost a child, though I spent 18 years helping Debian grow up. That would be too unbearably painful. I respect that Debian is navigating a choice that may have no right answer. Whichever particular compromise is arrived at today, it will still be up to individuals to make choices about what they do and accept. Debian has always been more than the sum of its policies, not just a ship, but a crew. I will always love you.

GrapheneOS project: pixel 11 no longer supports hardware memory tagging (MTE)

Hacker News
bsky.app
2026-08-29 11:26:28
Comments...

Indirect Calling of Nested Functions on GCC Without Executable Stack

Hacker News
uecker.codeberg.page
2026-08-29 10:20:33
Comments...
Original Article

Indirect Calling of Nested Functions on GCC Without Executable Stack

Martin Uecker, 2026-08-29

Introduction

We discussed last time how one can use nested functions on GCC 17 and Clang for callbacks with requiring an executable stack. But what if ones needs to support older versions of GCC? Of course, one can simply accept an executable stack (it is not quite as terrible as some people claim), but it is also possible to avoid this with a hack.

GCC: Nested Functions and Trampolines

Let's discuss first how GCC supports taking the address of a nested function. Our toy example without the use of the new macros is shown below ( Godbolt Example ).


	typedef int cb_f(int y);

	int baz(cb_f p, int x)
	{
		return p(x);
	}

	int foo(int k)
	{
		int bar(int x) { return k + x; }
    		return baz(bar, 2 * k);
	}
	

On x86_64, the generated assembly is the following.


bar.0:
        movl    %edi, %eax
        addl    (%r10), %eax
        ret
foo:
        subq    $56, %rsp
        leaq    64(%rsp), %rax
        movq    %rax, 32(%rsp)
        movl    %edi, (%rsp)
        leaq    4(%rsp), %rax
        movw    $-17591, 4(%rsp)
        movabsq $bar.0, %rcx
        movq    %rcx, 6(%rsp)
        movw    $-17847, 14(%rsp)
        movq    %rsp, 16(%rsp)
        movl    $-1864106167, 24(%rsp)
        addl    %edi, %edi
        call    *%rax
        addq    $56, %rsp
        ret
	

This code places a trampoline on the stack and immediately invokes it via the inlined baz function. The trampoline is a short code sequence that loads the static frame register to a structure on the stack that contains the captured variables from the parent function and then jumps to the local function. If one translates the constants -17591, -17847, and -1864106167 back to assembly instructions one obtains the following x86_64 code.


        movq	$bar.0, r11
        movq    $frame, r10
	jump	*r11
	

Both, the static chain and the code address are immediate constants used by move instructions in the code of the trampoline. Instead of using the address of the trampoline to call the function, we can extract the code address and the static chain from the trampoline and use them with the __builtin_call_with_static_chain built-in function to call the local function directly. For example, using noplate's peek and array_slice macros, this could be done in the following way for x64_64 (and a large memory model).


	unsigned char (*tramp)[24] = (void*)bar;
	void *code = peek(uint64_t, &array_slice(tramp, 2, 10));
	void *chain = peek(uint64_t, &array_slice(tramp, 12, 20));
	

These pointers are then exactly the same information that can be obtained on the yet to-be-released GCC 17 with the new built-ins __builtin_call_static_chain and __builtin_call_code_adress and can be used to call the local function with as discussed previously.


	__builtin_call_with_static_chain(((typeof(bar)*)code)(arg), chain);
	

Thus, we can use reading of these two pointer values from a trampoline as a fallback mechanism in older versions of GCC. The downsides are that a trampoline is still created, the compiler can still not devirtualize the indirect call, and the stack will still be marked executable. So what was gained? Since we never actually invoke the trampoline, we can make the stack non-executable again with the following command, which at least addresses the security concerns of this feature.


	patchelf --clear-execstack program
	

This idea is implemented in my experimental library, noplate , where a wide pointer is constructed from the code address and the static chain.

Trampolines as Function Descriptors

There is another idea I find worth exploring: One could also use the trampoline itself as a function descriptor. Instead of extracting the static chain and code pointer where the trampoline is created we just pass on the address of the trampoline as usually. But everywhere where we might call the trampoline, we first check whether the pointer points to a trampoline, and then extract code address and static chain to call the nested function directly using __builtin_call_with_static_chain . In some sense we could say that instead of invoking the trampoline, we are interpreting the code of the trampoline at the call site using a super simple interpreter that only can interpret this specific code sequence and that is so simple that it can be inlined ( Godbolt Example ).

Literature

Brave browser adds email aliases to help users evade tracking

Bleeping Computer
www.bleepingcomputer.com
2026-08-29 10:19:23
The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]...
Original Article

Brave

The latest version of the Brave browser, 1.94, introduces a feature called ‘Email Aliases’ that allows users to generate disposable email addresses when signing up to a new service.

Using an alias address keeps the user's real email address hidden from the website while still forwarding messages from the service.

Brave already uses data isolation to prevent websites from inferring user identities based on cookie-based or cache correlations; however, email addresses are still stored on website servers, creating a privacy gap.

image

Brave’s new feature addresses this risk by blocking cross-site identity matching, reducing spam, and protecting users from threats such as phishing attacks that can follow data breaches.

“If a website you signed up for is hacked, your information can be leaked and end up with data brokers or worse,” explains Brave in the announcement .

“Your email address then circulates far beyond the company you originally trusted with it, and can show up in phishing campaigns for years afterward.”

To generate and use email aliases, users need to create a free Brave Account and register their primary email address with that account, so message forwarding can occur. This is separate from a Brave Premium account.

Managing aliases from the Brave Account page
Managing email address aliases
Source: Brave

In a separate announcement , Brave explains that Brave Accounts uses OPAQUE, a password-authenticated key exchange standardized as RFC 9807, to authenticate users without transmitting their passwords or hashes to Brave’s servers.

According to Brave, this reduces exposure to password logging, memory-scraping attacks, and bulk cracking of leaked password databases, although it does not protect users from phishing or weak passwords.

The new alias system is free for up to five email aliases, while Brave says it plans to introduce a paid Premium version later, which will lift this restriction.

To preserve users' privacy when forwarding the messages, Brave stores the primary address and generated aliases in an encrypted state. At the same time, the forwarded messages are not checked beyond automated spam and malware filtering.

Messages are deleted from Brave’s servers within seconds after delivery, while notes attached to the aliases remain local or, if synced via Brave Sync, end-to-end encrypted.

Brave cautioned that forwarded messages may initially land in spam folders while it establishes its reputation as an email provider, so users testing out this new feature should keep that in mind.

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Debian votes to allow "responsible use of generative AI"

Linux Weekly News
lwn.net
2026-08-29 09:58:52
The results of the Debian general-resolution vote on the use of large language models have been posted; the winner is choice 5: Responsible Use of Generative AI. Debian neither endorses nor prohibits the use of generative AI tools in the development, maintenance, or documentation of software, p...
Original Article
The results of the Debian general-resolution vote on the use of large language models have been posted; the winner is choice 5: Responsible Use of Generative AI .
Debian neither endorses nor prohibits the use of generative AI tools in the development, maintenance, or documentation of software, packaging, documentation, and other media published within the Debian Project. We recognize that such tools can substantially improve the productivity of contributors when used responsibly, allowing volunteers to spend more of their limited time on work that requires technical expertise, judgment, review, and collaboration.

The Debian Project nevertheless expects that all contributions submitted to Debian, regardless of how and with which tools they were produced, satisfy the same standards of quality, correctness, maintainability, and legal compliance. The use of a generative AI tool does not diminish the contributor's responsibility for the work they submit. Contributors are expected to understand, review, test, and, where appropriate, modify AI-assisted output before incorporating it into Debian.



Should ChatGPT Read Your Encrypted Messages?

Internet Exchange
internet.exchangepoint.tech
2026-08-27 09:45:55
OpenAI’s new iMessage plugin for ChatGPT lets users search their messages and draft and send replies through the chatbot on their desktop. But should they?...
Original Article
privacy and security

OpenAI’s new iMessage plugin for ChatGPT lets users search their messages and draft and send replies through the chatbot on their desktop. But should they?

Should ChatGPT Read Your Encrypted Messages?
Daniela Zampieri / The AI-Deal / Licenced by CC-BY 4.0

By Mallory Knodel

Until recently, if most people wanted an LLM to help them compose a witty reply or a sensitive breakup text, they had to copy their messages out of their messaging app and paste them into a chatbot. Now, OpenAI’s new iMessage plugin for ChatGPT Work and Codex users on Mac lets users search their messages and draft and send replies through the chatbot on their desktop.

As Bloomberg notes , there are several layers of permission required before the plugin works, so no one will install it by accident. But for the people on the other end of the equation, the unsuspecting users on an end-to-end encrypted platform sending messages to their contacts, there is no such protection.

This plugin bypasses the essential promise of E2EE: that only the sender and intended recipients can read a message. That is because it appears that the plugin reads the decrypted message on the computer, then sends them to OpenAI’s servers so a third party can read the plain text.

This is exactly the scenario my co-authors and I discussed in our paper “ How To Think About End-To-End Encryption and AI: Training, Processing, Disclosure, and Consent ,” in which we concluded that processing E2EE content outside the device is only compatible with encryption if no third party can see it, and the content is used only to fulfil the user’s request.

The OpenAI iMessage plugin violates the first three of our four recommendations from the paper, and partially violates the fourth as it does not require meaningful consent from both parties. Our recommendations were:

  1. Training. Using end-to-end encrypted content to train shared AI models is not compatible with E2EE.
  2. Processing. Processing E2EE content for AI features (such as inference or training) may be compatible with end-to-end encryption only if the following recommendations are upheld:
    1. Prioritize endpoint-local processing where possible
    2. No third party can see or use any E2EE content without breaking encryption
    3. A user’s E2EE content is exclusively used to fulfill that user’s requests
  3. Disclosure. Messaging providers should not make unqualified representations that they provide E2EE if the default for any conversation is that E2EE content is used (e.g., for AI inference or training) by any third party.
  4. Opt-in consent. AI assistant features, if offered in E2EE systems, should generally be off by default and only activated via opt-in consent. Obtaining meaningful consent is complex, and requires careful consideration including but not limited to: scope and granularity of opt-in/out, ease and clarity of opt-in/out, group consent, and management of consent over time.

One of my co-authors, Andrés Fábrega and I, discussed the findings of the paper in a piece for Tech Policy Press in February 2025, " Can Bots Read Your Encrypted Messages? Encryption, Privacy, and the Emerging AI Dilemma ," which I am republishing below. It predates this plugin by eighteen months, but it feels important to surface it again as many more people decide how much of their private communications to trust to chat bots.

Can Bots Read Your Encrypted Messages? Encryption, Privacy, and the Emerging AI Dilemma

By Mallory Knodel and Andrés Fábrega. Originally published in Tech Policy Press .

It may seem like AI chatbots are taking over every digital application, whether we like it or not. You might have noticed more AI note-taking bots in online conferencing platforms, some of which offer end-to-end encryption (E2EE). Then Apple Intelligence plans were announced, promising application redesigns to offer AI features across its phone and laptop operating systems. The latest changes have come from Meta AI’s integration in WhatsApp, replete with “ bots nobody wants .”

Any time new features are added to an E2EE messaging app, it raises concerns about privacy and security. So, what concerns are raised by the addition of AI bots? How can we evaluate those concerns? As AI becomes more embedded into encrypted services, is it possible to resolve the tension between the privacy users expect from E2EE and the data access needed for AI functionality? With our colleagues at Cornell and NYU, we set out to answer these questions.

We uncovered several facets of this question from both a technical and legal perspective and published a paper laying practical recommendations for E2EE messaging platforms and regulators. It’s also important that we outline the practical solutions and recommendations for the public. You can read the full preprint paper here .

Background

Online messaging systems that allow communication between users (such as iMessage, WhatsApp, and Signal) are intermediaries to every communication between users. End-to-end encryption (E2EE) is a standard secure communication system that is designed to ensure that only the sender and the intended recipients can read communications between them. Messages that are encrypted are called “ciphertexts,” and content that is not encrypted, even if it’s an image or video, are called “plaintexts.” The core requirement of private and confidential messaging is that the service provider (and any other third parties) cannot read these communications.

AI assistants are programs designed to interpret everyday language and perform computational tasks. Today’s AI assistants are able to handle a wide range of tasks, including text analysis, content creation, code generation, language translation, and more. At the core of these technologies are programs trained on data to identify patterns, e.g., large language models (LLMs) such as OpenAI’s ChatGPT, Google’s Gemini, and Meta’s Llama, which process complex inputs (queries) and provide contextually relevant responses.

Putting this together, it seems impossible that an application with no access to message content can initiate AI processing on that same message content. To introduce AI in E2EE, the strictness of E2EE is widened in two dimensions: what is an “end,” and where is the end.

It would not be a strict violation of E2EE system design if you were to copy and paste your messages into a chatbot (though you might be violating the norms of confidentiality and privacy in the context of the conversation). If an application were to facilitate that for you, however, it would need to guarantee that the processing happens in a way that preserves E2EE, such as processing on the end—your device—and not on another computer, such as the application servers. Apple Intelligence has proposed the use of “trusted execution environments” (TEE) as the way to keep private the data used for AI training and processing.

However, a key finding in our analysis is that TEEs are insufficient to achieve the strict confidentiality and privacy guarantees of E2EE. But first, let’s discuss what this looks like in practice:

How AI Interacts with Your Encrypted Messages

AI features—such as message summarization, smart replies, and chatbots—are being seamlessly integrated into a wide range of applications with the goal of enhancing user experience. However, AI models critically require access to vast amounts of plaintext user data to power these tools. There are two main ways in which AI features interact with application data. First, they receive user data as part of queries during regular feature usage. For example, a message summarization tool receives as input a list of sent and received messages and outputs a summary of these. Second, user data is generally used to continuously train and refine the AI features. For example, data could be used to fine-tune models and improve their general performance, personalize models for the usage patterns of individual users, etc.

These considerations raise significant concerns for integrating AI features in E2EE applications. Processing of user content—during regular feature usage and model training—could expose sensitive user data to the parties who own the AI models. While some lightweight features can be implemented with smaller models that live on end-user devices (and thus, all data is processed locally), other features require offloading user data to more powerful models on the application servers. This is directly in tension with the strong security promises of E2EE applications, which require that no user data is visible to third parties.

There are a number of privacy-enhancing tools that attempt to address these issues and allow cloud-based AI models to process user data while protecting it from model owners. However, these tools offer varying degrees of security, not all of which offer the same strong privacy guarantees of E2EE. It is critical that any adopted solution is compatible with E2EE, and that the models' processing of user data does not undermine users' privacy expectations. Unfortunately, none of the existing technologies that are compatible with E2EE security, such as fully-homomorphic encryption (FHE), are yet practical solutions since they currently cannot efficiently evaluate the large models used in AI applications. On the other hand, more practical approaches, such as hardware-based solutions (e.g., storing models inside TEEs), do not meet the strong confidentiality guarantees of E2EE, and raise additional security considerations. While these represent a substantial privacy improvement over plaintext processing and may be an appropriate solution for other contexts, they are not suitable for E2EE environments.

Furthermore, even if an AI feature could somehow process user content in an encrypted manner (e.g., if FHE were to become practical for this task), training AI models with E2EE data raises an additional security concern: it is well-known that AI models often inadvertently “ memorize ” training data, which can lead to reproduction of this data during model responses, or even deliberate extraction by actors who can query the model in the form of “ adversarial attacks .” So, even if training is performed privately, E2EE data could be exposed to other application users who can query (but not observe) the model. While certain technologies address memorization and adversarial attacks (e.g., differential privacy), these do not meet the strong security of E2EE.

"Whose Bot Is It?" The Tension Between AI, E2EE, and Ownership

We need to address the key tension: users often treat AI assistants as personal tools, but these bots belong to corporations that control data access. Especially in the context of E2EE messaging, we risk treating encryption like one more feature that might contraindicate the use of AI, but it’s more than that.

Users might expect their data to remain private when communicating with these bots, especially since platforms advertise E2EE features. However, driven by business incentives, we are seeing a trend away from privacy and towards the use of novel user data—some of it from messaging platforms using E2EE—to train AI models, sometimes without explicit user consent. This practice would not only undermine the privacy protections that E2EE is meant to provide, but also puts at greater risk the massive privacy gains made over the last decade.

At the same time, AI assistants aren’t very good (yet), and many people don’t want them . Like dark patterns, this just adds to the number of repetitive failures in corporate tech that have desensitized our intuition about real measures of performance when applications are working for us and not companies.

Practical Solutions and Recommendations to Regulators and Platforms

Our technical and legal analysis is meant to inform the design and implementation of AI in E2EE platforms so as to preserve user privacy and expectations of confidentiality. Verbatim are the recommendations based on our findings:

  1. Training . Using end-to-end encrypted content to train shared AI models is incompatible with E2EE.
  2. Processing . Processing E2EE content for AI features (such as inference or training) may be compatible with end-to-end encryption only if the following recommendations are upheld:
    1. Prioritize endpoint-local processing whenever possible.
    2. If processing E2EE content for non-endpoint-local models,
      1. No third party can see or use any E2EE content without breaking encryption, and
      2. A user’s E2EE content is exclusively used to fulfill that user’s requests.
  3. Disclosure . Messaging providers should not make unqualified representations that they provide E2EE if the default for any conversation is that E2EE content is used (e.g., for AI inference or training) by any third party.
  4. Opt-in consent . If offered in E2EE systems, AI assistant features should generally be off by default and only activated via opt-in consent. Obtaining meaningful consent is complex and requires careful consideration, including but not limited to the scope and granularity of opt-in/out, ease and clarity of opt-in/out, group consent, and management of consent over time.

Similarly, regulators and platforms can make design decisions to mitigate some of the privacy challenges posed by AI features to E2EE applications, such as:

  • Opt-in Features : AI features should be off by default and only activated via explicit opt-in mechanisms. Each individual feature should have a separate opt-in mechanism, with unambiguous disclosure notices of what each feature entails. Once activated, users should be able to subsequently turn off AI features if they desire.
  • Privacy Settings and Granularity : Messaging services should provide granular privacy settings that let users control what specific data is used for AI features and how much is stored or processed.
  • Ease of Setting Adjustment: AI-related settings (such as turning off AI features or adjusting data usage policies) should be easy to find and navigate . There must be a low barrier to toggling off.
  • Clear Disclosure : Messaging services should be transparent about when and how AI interacts with encrypted messages, including the precise level of security offered by their systems. This includes specifying whether AI features process user data in ways that provide weaker privacy protections than E2EE (e.g., using trusted hardware). These disclosures should be clearly and prominently displayed. Relatedly, companies should adopt a policy of over-disclosure , ensuring that users are fully informed about data usage even when interacting with AI.
  • Data Ownership and Access : Services should clarify who owns and controls the data AI uses, ensuring users understand that they are interacting with corporate-owned models and not private personal assistants.

We recommend that regulators consider mandating these five practices and that platforms take proactive steps to implement them.

Practical Solutions and Recommendations for the Public

Aside from informing technologists, companies and regulators, it’s important to provide actionable steps the public can take to protect their privacy in the era of AI and encryption. Based on what we know about how companies like Apple and Meta plan to integrate AI into applications that have promised privacy, here is what anyone can do to help maintain their privacy and confidentiality:

  • Choose OS-level app permissions carefully : Device-wide AI capabilities like Apple Intelligence mean that you need to be aware of which of your applications interact with AI features.
  • Review App Settings : Regularly check the privacy settings on your applications. If you're concerned about privacy, turn off AI-based features like message summarization or smart replies.
  • Be Aware of What You’re Sharing : Be mindful of the data you share with AI services, especially personal or sensitive information that could be used for training or other purposes. When applications tell you they might use your data for training AI, believe them. Passwords, contact information, and a wide variety of sensitive information might end up in an AI model and out of your control.
  • Beware of Opt-in Conditions : If you choose to invoke MetaAI or Apple Intelligence features in a private or confidential setting, be sure you understand the limitations– is it for all chats? Is it forever?
  • Talk to Your Contacts: If you are having sensitive conversations over E2EE services, have a conversation with relevant contacts, and make sure they aren’t inviting bots to the conversation.

Conclusion

AI features are being developed at a rapid pace, raising significant security risks for users of E2EE applications. It is crucial that AI innovation does not come at the expense of user privacy, and that the strong protections expected from E2EE applications are maintained. Absent perfect technical solutions, service providers should inform and empower users to navigate the interplay between AI and privacy, with transparent disclosures of how data is processed, user-friendly consent mechanisms, and granular controls over how data is used.


Love IX? You can help keep us going!

If you value our work, there are lots of ways you can help support us. Including some that don't cost you anything!

  • Subscribe. If you're not already a paid subscriber, that's the simplest way to support independent writing about technology, human rights and the internet. Until the end of the month, we're offering £20 off annual subscriptions.
  • Make a tax-deductible donation. Internet Exchange is a project of Exchange Point Institute, a 501(c)(3), so you can support our public education work directly.
  • Get your employer to match it. If you work in tech — or anywhere with an employee giving program — search Exchange Point Institute in Benevity. Many companies match employee donations, so your gift could be worth twice as much (or more).
  • Fund or hire us. We also take on funded projects and fee-for-service work in technology, human rights, research, communications and public education.
  • Sponsor a newsletter. We accept sponsorships from values-aligned organizations working in public-interest technology, digital rights, open standards, or related social impact areas.

However you do it: help us bring the conversations shaping the internet into the mainstream.

Support the Internet Exchange

If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling.

Not ready for a long-term commitment? You can always leave us a tip .

Become A Paid Subscriber

From the Group Chat 👥 💬

This week in our Signal community, we got talking about:

The US State Department designated Autistici/Inventati (A/I Collective) a terrorist organization. A/I is a volunteer-run collective, founded in 2001, that provides free services like email, web hosting and the Noblogs platform to a large antifascist and anti-capitalist user base. This comes just over a month after Secretary of State Marco Rubio hosted representatives from more than 65 countries at a conference to rally global opposition to ‘left-wing terrorism,’ and vowed more designations would come “soon.”

What seems to frustrate the State Department most is that A/I's services are built around data minimisation. Its fact sheet laments that A/I's users remain "anonymous, untraceable, and beyond the reach of the law." The designation has no legal force in Italy, but it could still prove perilous for A/I's members living under a far-right government.

After the announcement, group members expressed concern for collectives that also provide online communication tools for people and groups working on liberatory social change. The politics of Trump and Rubio are threatening the principles of independent internet providers, just as US Big Tech is consolidating power.

You can read A/I’s statement about the designation

here

.

ICYMI, in a related story Germany's state interior ministers urged the federal Interior Ministry to pursue a full ban on the activist platform indymedia.org through website seizures, takedown orders, and network blocks, plus travel limits for suspected left-wing extremists. (DE) https://de.indymedia.org/node/749687

Want to join the group chat? Become a paid subscriber.


🚨

Stop press! Do you enjoy our links? Links are now available to paid subscribers only. Become a paid subscriber today.

A Nation Divided on Sentencing Reform

Portside
portside.org
2026-08-29 08:27:25
A Nation Divided on Sentencing Reform Kurt Stand Sat, 08/29/2026 - 08:27 ...
Original Article

Across the country, 2026 is shaping up to be a defining year for sentencing reform, but not in the way many advocates had hoped.

This is not a moment of steady progress. It is a moment of divergence.

In some states, policymakers are advancing reforms grounded in evidence, second chances, and a more complete understanding of public safety. In others, leaders are doubling down on rigid sentencing structures that prioritize punishment over fairness, even when decades of research show those approaches do little to make communities safer.

The question facing the country is no longer whether reform is possible. It is whether policymakers are willing to follow the data or retreat from it.

Where Progress Is Moving Forward

In states like Maryland, Michigan, Washington, New Jersey, and New York, momentum is building behind policies that allow courts to revisit long sentences, expand parole eligibility, and strengthen pathways to second chances.

In Maryland, lawmakers advanced a broader set of reforms this session spanning youth justice, sentencing review, and civic reintegration. The Youth Charging Reform Act limits the automatic prosecution of young people as adults, addressing long-standing racial disparities in the youth system. Lawmakers also strengthened implementation of the Maryland Second Look Act to expand access to sentence review for some individuals convicted as young adults, and passed automatic voter registration for people returning from incarceration. Taken together, these measures reflect an emerging consensus that rehabilitation, youth development, and community reintegration are central to public safety.

The Sentencing Project staff at Youth Justice Lobby Day in Annapolis, Maryland

These reforms are grounded in a growing body of evidence around the inefficacy of extremely long sentences, according to recent research from The Sentencing Project. People who have served long sentences, especially those over 50, pose minimal risk to public safety, and recidivism rates decline sharply with age and time served. The reforms also reflect a broader understanding of justice, one that recognizes rehabilitation, accountability, and the role of trauma and victimization.

Just as importantly, successful reform states have invested in narrative change before legislation is introduced. Advocates have paired data with stories of transformation, elevated survivor voices that prioritize prevention and healing, and built broad coalitions capable of sustaining reform efforts over time.

Long-term investment in education, coalition-building, and public engagement helps create the conditions necessary for reform to move.

Where States Are Backsliding

But this is only half the story.

In states like Georgia, Alabama, Iowa, and Missouri, lawmakers are advancing proposals that move in the opposite direction, including efforts to expand mandatory minimums, eliminate parole eligibility, and lengthen already excessive prison terms. In Virginia, reform efforts have stalled under similar political pressures and public safety narratives.

What is driving this divide is not simply policy disagreement. It is a narrative rooted in fear and an unhealthy attachment to punishment.

Where reform has stalled, a different narrative dominates. It equates safety with punitive measures, amplifies fear, and treats severity as the only form of accountability. In those environments, even evidence-based policies struggle to gain traction. These approaches also continue to disproportionately harm Black communities, which remain significantly overrepresented in prison populations across many of the states advancing or defending the harshest sentencing policies.

Fortunately, in Georgia, advocates successfully opposed legislation that would have expanded mandatory minimums and eliminated parole eligibility across a wide range of cases. In Delaware, advocates defeated efforts to restrict compassionate release for elderly and medically vulnerable people. These victories reflect a growing recognition that public safety is undermined, not strengthened, by policies that ignore rehabilitation and human capacity for change.

Where Reform Efforts Are Stalling

Even where reforms are enacted, another challenge remains: implementation.

Too often, access to relief is constrained by procedural barriers, lack of legal representation, and inconsistent application of the law. The result is a persistent gap between what reforms promise on paper and what people actually experience in practice.

This implementation gap risks undermining public confidence in reform itself. Laws designed to create meaningful release and second chances cannot succeed if the systems responsible for carrying them out continue to operate according to outdated punitive assumptions.

In Maryland, for example, implementation of the new parole law has been slowed by delays in developing the necessary regulations and by gaps in the reentry infrastructure. As a result, many individuals serving long sentences have not yet fully benefited from the law’s expanded opportunities for release. For those granted medical parole, securing appropriate post-release placement remains a significant barrier to realizing the law’s intended impact. Maryland’s experience underscores an important lesson for other states pursuing parole and long-sentencing reforms, legislative change must be accompanied by adequate implementation and reentry resources to achieve its intended outcomes.

The Defining Question for 2027

If 2026 has made anything unmistakably clear, it is that sentencing reform in the United States is no longer moving along a single trajectory. The country is being pulled in two different directions.

One vision, guided by evidence and human dignity, recognizes that accountability and rehabilitation are both essential to community safety. The other, driven by fear and partisanship, continues to cling to the idea that more punishment equals more safety despite overwhelming evidence to the contrary.

The states making real progress have demonstrated what is possible when policy is grounded in research and shaped by people directly impacted by the system. They have shown that accountability and rehabilitation are not competing values, but complementary ones, and that communities are stronger when the justice system recognizes the human capacity for growth and change.

The path forward is clear. Policymakers must close the gap between reform and implementation, invest in public understanding before fear-based narratives take hold, and reject policies that trade long-term safety for short-term political gain.

At a moment when punitive policies are resurging in many states, preserving existing reforms and preventing harmful rollbacks is itself an important measure of progress.

But meaningful progress will not happen automatically in 2027. It will require lawmakers, advocates, directly impacted leaders, survivors, and community organizations to work together now to build durable reform strategies rooted in evidence and public education.

The Sentencing Project stands ready to support state leaders and advocacy partners working to advance evidence-based sentencing reform, expand second chances, and promote policies that strengthen both accountability and community safety. As states prepare for the next legislative cycle, the opportunity remains open to build systems that reflect what decades of evidence already show: people are capable of change, and communities are safer when justice systems recognize that truth.

Sentencing reform has always been a question of values. In 2026, the choice is clear: whether policymakers will follow evidence, invest in safety strategies that work, and recognize the human capacity for change, or continue repeating punitive approaches that history and research have already shown to fail.

Keith Wallington is a Senior Campaign Strategist at The Sentencing Project. His work centers on advancing policies to abolish life without parole, expand second-look sentencing reviews, cap excessive sentences at 20 years, and eliminate mandatory minimums.

Mass Incarceration and Other Bad Ideas: Challenging the status quo, one criminal justice policy failure at a time.

Iceland votes on whether to restart talks on joining EU

Hacker News
www.bbc.com
2026-08-29 07:39:38
Comments...
Original Article

AFP via Getty Images Supporters of the 'No' campaign wave Icelandic flags during a rally against reopening Iceland's European Union accession negotiations in Reykjavik, Iceland, on August 27, 2026 AFP via Getty Images

Latest opinion polls have been so close that the result is impossible to call

Icelanders are voting in a referendum to decide whether to resume talks on joining the European Union, 13 years after they were broken off.

In an indication of how tight the result is expected to be, the latest opinion poll put the No campaign in the lead with 51.6%. An earlier poll had put the Yes campaign ahead.

Prime Minister Kristrún Frostadóttir's centre-left government had already intended to hold a referendum, but turbulent international affairs prompted her to bring it forward.

But the debate was fought less over Nato member Iceland's security concerns than over its vital fishing industry and sovereignty.

Voting is due to go on from 09:00 to 22:00 GMT on Saturday and the result is expected in the early hours of Sunday.

Iceland has a population of under 400,000. More than one in five voters had already cast their ballots in early voting before Saturday, according to Iceland's public broadcaster RUV.

What is the vote about?

Although Iceland is already part of the EU's single market and Schengen border-free zone as part of the European Economic Area, EU membership would bring it into the customs union and eventually the euro.

Iceland's application to join the EU was already well advanced when it put talks on hold in 2013, and European Commission officials have indicated that talks could be finalised in one or two years. Of the 35 so-called chapters of talks ranging from fisheries and economic policy to freedom of speech and free movement of goods, 27 had begun and 11 of them were provisionally complete .

A Yes vote would not be a final decision on joining the EU. It would mean backing a move towards an accession agreement. Any deal would then have to be approved by a second referendum, as well by parliament, and the constitution would have to be amended. The EU's 27 member states would also have to sign it off.

One Yes-campaign group, "Yes to See", says Icelanders should at least see what deal they can get, so they have all the information before a final decision.

Equally, a No vote would not rule out the chance of Iceland resuming talks in the future.

What are the key issues?

Sovereignty has been a crucial issue in the pre-referendum debate. Iceland fought hard to become fully independent from Denmark in 1944, and its fishing and marine industries make up almost 40% of exports.

The No campaign fears losing control over Iceland's prized fishing grounds under the EU's Common Fisheries Policy and has vowed never to share the country's waters with anyone. Brussels has indicated Iceland could earn some kind of exemption, but it is considered potentially the biggest obstacle to any agreement.

Many Icelanders remember the so-called Cod Wars with the UK that Iceland won in the 1970s. And fisheries was always the issue that stopped Iceland joining the EU before.

However, in the wake of the 2008 financial crisis and the collapse of Iceland's banking system, Reykjavik moved to start accession talks in 2009, only to bring them to a halt in 2013.

Iceland is now one of Europe's most affluent nations and Eirikur Bergmann, professor of politics at Bifröst University, told the BBC that "many people attribute this to Iceland's independence".

One Icelandic trade union survey suggested this year that the country was the most expensive in the world, far pricier than its Nordic neighbours.

Although it has the fifth highest GDP (economic output) per capita in the world, interest rates are stubbornly high at 8% and inflation has climbed to 5.6%.

Yes campaigners argue that the economic benefits of the EU would help bring the rates down.

Reuters A man poses outside the "Yes to See" movement's office ahead of a referendum on whether Iceland should resume accession negotiations with the European Union, in Reykjavik, Iceland, August 2 Reuters

The "Yes to See" campaign believes Icelanders should see what EU deal they can get

What are Iceland's security concerns?

Iceland may be a founder member of Nato but it has no military and relies on its allies for defence.

A bilateral US defence agreement has been in place since 1951 and the No campaign has said Iceland's security rests on both Nato and the US, and that EU membership is not a substitute for Nato.

Iceland has been a strong supporter of Ukraine during Russia's full-scale invasion and officials have viewed Russia's increased maritime manoeuvres near the island with alarm.

However, there has also been concern at US President Donald Trump's expressed interest in taking over Greenland - especially the fact that he has confused it with Iceland.

This year the EU and Iceland signed a security and defence partnership, and EU officials said the EU "offers an anchor in a community of values, prosperity and security".

What do the Yes and No campaigns say?

Ahead of the referendum, the two sides held a televised debate where the Yes campaign team was headed by Prime Minister Kristrún Frostadóttir and the No campaign was led by Guðrún Hafsteinsdóttir, chair of the opposition Independence Party.

Kristrún told the audience that Iceland was already well integrated in the European Union, and becoming a member would be "one of the biggest risk-reducing steps we can take".

She also made clear that a Yes vote did not necessarily mean that Iceland would join, and that if there was a No vote, the result would be respected.

Guðrún, meanwhile, stressed that the vote was not about whether Iceland should work well with Europe: "We already do, and we want that to continue."

Instead, she portrayed the referendum as a vote on whether Icelanders wanted to hand "decision-making powers" to Brussels on fisheries, agriculture and their natural resources.

Although geopolitics kick-started the government's decision to push for a return to EU talks, there has been little discussion of it during the campaign.

"It's lower on the agenda than many would think," says Hallgrimur Oddsson, director of EU-Iceland think-tank European Currents.

On 'scaling up' and being the right size

Lobsters
tzovar.as
2026-08-29 07:26:19
Comments...
Original Article

a group of people looking extremely tiny walking in front of the Perito Moreno glacier

I regularly encounter questions along the lines of “how do we scale things up? , in particular around projects related to free knowledge, FLOSS or citizen science. It has basically started from the first citizen science effort and accompanied me through most of my volunteering work. And it’s a question that has always sat wrong with me. Mainly because of its uncritical assumption that scale should be wanted, necessary or even ‘ good’ .

To look at this, I want to take a step back: My academic background started off in evolutionary biology, and despite not having actively done research in the field for a while, it regularly shines through: If we’ve ever met, I might have waxed about the Spandrels paper by Stephen Jay Gould and Richard Lewontin. Or about J.B.S. Haldane ’s essay On Being the Right Size , which I’ve previously mentioned when talking about how there is no one-size-fits-all editor for OpenStreetMap . And it’s this essay that’s relevant here.

In On Being the Right Size , Haldane beautifully explains how size itself shapes and constrains the biology and complexity of organisms:

[…] suppose that a gazelle, a graceful little creature with long thin legs, is to become large, it will break its bones unless it does one of two things. It may make its legs short and thick, like the rhinoceros, so that every pound of weight has still about the same area of bone to support it. Or it can compress its body and stretch out its legs obliquely to gain stability, like the giraffe.

Or in other words, there is no way to be a gazelle above a certain size. By exploring the physical constraints of the world around us all – such as gravity, the relation between volume & surface area, the wavelengths of light – Haldane shows how size matters in very concrete terms. Smaller organisms do not need to fear gravity for their comparatively high air resistance, but the surface tension of liquids mean that being wet becomes an unbearable weight for them. And while smaller organisms can absorb sufficient oxygen through their skin, larger animals need some form of gills or lungs to have a sufficient surface area to not asphyxiate.

While this might all seem far from our initial question about how do we scale up a project/platform/community? , in reality the answer to that question is the same: You can’t ! Not because growing in scale itself is impossible, but because if you scale things up (or down), you always have to adapt – and often that means losing some things, as you can not stay the same. Just as the gazelle in Haldane’s example can not remain as is .

Haldane, a committed socialist 1 , himself makes the connection to the scales of human organisations, giving the example of the ancient Greek democracies that due to their structure could not work beyond the scale of a small city. He went on to link scale to the limits of full nationalization too, famously stating that I find it no easier to picture a completely socialized British Empire or United States than an elephant turning somersaults or a hippopotamus jumping a hedge . All of which is to say: In the context of your community-driven projects, you will very likely not be able to change the scale of it, without also changing some or even a large number of the organisational norms that affect it.

Haldane’s ideas were later taken on by planners and theorists who were concerned with how to design and implement structure. One of them was Jane Jacobs, an urban-planning theorist and activist, who organized grassroots efforts to protect neighborhoods from urban renewal . 2 In her 1979 Massey Lectures , Jacobs directly cites Haldane’s Principle in relation to institutions, governments and other organisations:

Haldane presents us with an interesting principle about animal size: Big animals are not big because they are complicated. Rather, they are complicated because they are big. Haldane’s principle, it seems to me, also applies to institutions, companies, governments, organizations of all sorts. The larger they are, the more complications they require.

Jacobs recognizes that the trade-off for more complexity can be worth it, as some things can only be done or achieved at larger scales. But, she also outlines how that trade-off comes with certain costs, in particular that larger sizes require a level of complexity that it becomes stifling, to the point that the complexity actively interferes with the reasons for organisations existing in the first place. And those of you who have ever had to deal with a mid-to-large sized academic bureaucracy will undoubtedly have some first-hand experience with that happening, be it for placing small orders, booking/reimbursing travel or the other common ‘deaths by a thousand admin paper cuts’.

Another planner who recognized the connection between Haldane’s Principle and organisations was Christopher Alexander – who is often recognized as the father of the pattern language movement . 3 In his 1977 book A Pattern Language he makes a claim for independent regions based on the natural limits that human governments can take, by citing Haldane’s point about Greek city state democracy. To expand on that point, he outlines how growing group sizes automatically mean that the number of pairwise relationships or links between people in a group grows exponentially, which becomes hard to maintain. Which in turn tends to then also increase the levels of hierarchy.

What does all of this now mean for our communities and commons? It means that Can Mastodon be the next Twitter?” or Can Codeberg be the next GitHub might be the wrong questions to ask. Rather, we should ask ourselves: What is the cost of trying to scale like this and become so big? As creating large, centralized structures does come with a cost – at the very least to adapt from the status quo to something else. As Jacobs discussed in her lectures, and Haldane recognized as well, centralization and economies of scale can work for some things, but not so much for others. Placing large orders for hardware might be reasonable (or rather used to be before the LLM-bubble), it tends to break down for social processes.

As an example: Content moderation ‘at scale’ by sheer necessity means having to automate it, losing the human connection that can legitimate it, while putting more strain on the moderators and increasing the likelihood for wrong calls. In the Mastodon/Fediverse space, this is one of the reasons why people anecdotally seem to be skeptical of too large instances. And recent research seems to support this: In a recent preprint that investigates moderation on Mastodon , the authors find that scaling of Mastodon instances creates a pressure on content moderation similar to the one observed on e.g. Reddit, suggesting that community size itself imposes a fundamental constraint, regardless of platform architecture. And in my own work, I’ve seen similar things around our content moderation work in a citizen science project where we co-designed the policies with a small community of autistic people, as well as in a project on data collection that worked because of its intentionally small size - not in spite of it.

Of course, all of these aspects do not just apply to free knowledge, FLOSS or other open* communities and platforms. When politicians and local tech bros wish for “a European Google/Microsoft/OpenAI/…” to exist, just the same forces are in play. There is no reason to believe that a conglomerate of the scale and monopoly position of e.g. Google would be any ‘better’, more ethical, less harmful, … just because it’s based out of the EU instead of the US. As a lot of the harms are built-in into the business model that requires scale. 4

If how do we scale isn’t the right question, what is a better one? On some level, I believe the question how can others make their own is a lot better. In her lectures, Jacobs points to federalism as a potential solution – at least when it comes to governments. But could equally apply to other forms of organizations.

We do not need to create large structures that just run the risk of becoming yet another single-point-of-failure and at the same time require approaches to decenter community. We do not need another centralized Twitter but in open source that fails at moderation as a result. We do not need the GitHub replacement with all its problems, even if, like Codeberg , it would be democratically governed by a member-run organisation. Just like we do not need an alternative AWS US-East-1 that takes down the whole internet when it goes down.

Instead, what we might want is many, ‘reasonably’-sized alternatives that can interact, exchange and cross-communicate. Jacobs did not think about ‘federation’ on a technical protocol level, but I think the Fediverse – with all its problems – shows that there is a real opportunity. And the folks working on making federated code forges work might just pull the same thing off for that domain.

This is all not to say that there never can be situations where ‘scaling up’ isn’t possible or maybe even the right call. But, instead of making how do we scale the knee-jerk reaction, we need to start earlier. By seriously thinking about the trade-offs that increasing scale would mean, and taking them into account to decide if a larger scale is even the right choice. And if a decision to increase scale is made, let’s not believe that the existing modus operandi will still serve in the same way. Otherwise we end up like Haldane’s supersized gazelle – with broken legs.

References

  1. S. J. Gould, R. C. Lewontin; The spandrels of San Marco and the Panglossian paradigm: a critique of the adaptationist programme. Proc. R. Soc. B 1 September 1979; 205 (1161): 581–598. https://doi.org/10.1098/rspb.1979.0086
  2. Haldane, J. B. S. (March 1926). “On Being the Right Size”. Harper’s Magazine: 424–427.
  3. Greshake Tzovaras, B. (2025, August 11). The diversity of OpenStreetMap tools and how they help create a commons. Bastian Greshake Tzovaras. https://doi.org/10.59350/b6hse-mv263
  4. Subramanian, Samanth (2021, July 1) A Dominant Character The Radical Science and Restless Politics of J.B.S. Haldane. ISBN: 9781786492845
  5. Jacobs, Jane (1980) Canadian cities and sovereignty association ISBN: 0887940870
  6. Alexander, C., Ishikawa, S., Silverstein, M., Jacobson, M., & Fiksdahl-King, I. (1977). A pattern language: towns, buildings, construction. ISBN: 0195019199
  7. Rasika Muralidharan, Yong-Yeol Ahn, Bao Tran Truong. (2026) Federating Governance: How Community Rules Scale with Mastodon Instances https://arxiv.org/abs/2606.05069v2
  8. Aitkenhead G, Fantoni S, Scott J, et al. (2024) How to co-create content moderation policies: the case of the AutSPACEs project. Data & Policy. 2024;6:e28. doi:10.1017/dap.2024.21
  9. Greshake Tzovaras B, Senabre Hidalgo E, Alexiou K, Baldy L, Morane B, Bussod I, Fribourg M, Wac K, Wolf G, Ball M (2021) Using an Individual-Centered Approach to Gain Insights From Wearable Data in the Quantified Flu Platform: Netnography Study J Med Internet Res 2021;23(9):e28116 URL: https://www.jmir.org/2021/9/e28116 DOI: 10.2196/28116

Bastian Greshake Tzovaras

Generally, things are better if you put open* in front of them.

Thanks to Rogue Scholar , you can cite this blog post using the DOI https://doi.org/10.59350/5bfg3-bjv09 .



This page was last built on 2026-08-18 @ 09:29:10 -0300, from git commit 23554d4 .

Thousands of Interstellar Objects May Be Lurking in Our Solar System

403 Media
www.404media.co
2026-08-29 06:00:27
The Sun has likely passed so close to other stars in the past that it captured thousands of small interstellar objects from alien systems, reports a new study....
Original Article

Welcome back to the Abstract! These are the studies this week that went interstellar, entombed the sky, hit the gas, and renewed the world.

First, scientists predict that there are thousands of objects from alien star systems lurking in the outer reaches of the solar system. Then: ancient air is hidden in glassy Moon beads, the “worst energy policy in the world,” and a mysterious Mississippian luxury.

As always, for more of my work, check out my book First Contact: The Story of Our Obsession with Aliens , or subscribe to my personal newsletter the BeX Files .

The interstellar objects we met along the way

Raymond, Sean et al. “Capture of interstellar objects during stellar encounters.” Astronomy & Astrophysics.

Over the past decade, three interstellar objects have been spotted streaking through our solar system. It’s likely that dozens more of these interlopers will be discovered in the coming years. These objects travel so fast that they can escape the gravitational clutches of the Sun, which is why they are only visible for weeks before hurtling back out to speed-run the galaxy.

But while some interstellar objects (ISOs) leave in a hurry, others may be here to stay, lurking in the outermost reaches of the solar system, known as the Oort cloud, reports a new study.

Over the course of its 4.6-billion year lifespan, the Sun has wandered close enough to other stars to collect thousands of non-native objects from the fringes of those passing systems. It may have also sent off many of its homegrown objects to join alien star systems during these encounters, like some kind of stellar gift exchange.

Concept art showing the scale and spherical shape of the Oort Cloud. Image: NASA

“The Solar System has long been suspected to contain captured, non-native material,” said researchers led by Sean Raymond of the Bordeaux Astrophysics Laboratory. “The recent ISO discoveries have now confirmed directly that extraterrestrial material regularly passes through the Solar System.”

Drawing on these discoveries, Raymond and his colleagues ran models to predict how many ISOs might be exchanged between stars during close encounters, called stellar flybys. The Sun is estimated to have had at least one or two of these meetups during its life so far, which could be “responsible for a large fraction of the captured ISOs currently residing in the Solar System.”

“Given that flybys are unavoidable in the Galactic field, most stars should host sparse Oort clouds populated with ISOs captured during stellar flybys,” the team said.

The Oort cloud — composed of frozen comet-like objects — extends for about three light years away from the Sun, so it’s not currently possible to send a spacecraft to go out to sift for ISOs in these distant wilds. Still, it’s neat to know there are so many interstellar hitchhikers riding in the Sun’s backseat.

Ancient magic Moon beads

Han, Ziyan et al. “Lunar transient atmosphere recorded in Chang'e 6 impact glass beads.” Earth and Planetary Science Letters.

A memory of an ancient ephemeral sky on the Moon may be locked inside glass beads scattered across the lunar surface, according to a new study.

The Moon is airless, but there’s evidence that it was surrounded by a transient atmosphere billions of years ago, which was fed by volcanic eruptions in its early history. Rocks crashing into the surface may have also vaporized material and created brief, gassy skies over time.

Scientists have now examined glass beads that were scooped up from the far side of the Moon by China’s Chang’e 6 sample-return mission, and delivered back to Earth in the summer of 2024 (that’s so Brat). The lunar glass, which was forged by rocks crashing into the surface, captured the chemical signatures of the vapor plume created by those impacts, capturing a whiff of a long-lost transient atmosphere.

The scoop left by Chang’e-6 sample collection on the Moon, which included the glass beads. Image: Chunlai Li, Hao Hu, Meng-Fei Yang

“Chang’e 6 (CE6) mission has returned the first lunar samples from the farside of the Moon,” said researchers led by Ziyan Han of Nanjing University. “The returned CE6 lunar regolith contains impact glass beads that could have recorded impact-induced vaporization on the Moon's farside and may serve as barometers, providing critical constraints on the global distribution of the Moon's transient atmosphere.”

The team noted that these fleeting impact-induced atmospheres might exist on other airless bodies in the solar system, and beyond it. For this reason, the researchers warned that atmospheres detected around exoplanets “may not always solely represent stable, long-lived atmospheres” which could “complicate the interpretation of atmospheric data as evidence of long-term planetary habitability on the rocky exoplanets.”

There you have it—just some ancient glass beads that contain the breath of past lunar skies. Carry on.

The real cost of cheaper gas

Mahdavi, Paasha and Ross, Michael L. “The worst energy policy in the world.” Science.

How bad does an energy policy have to be for experts to declare it the worst in the world? Buckle up because we are hitting the gas.

In an editorial published in Science this week, a pair of researchers lament the widespread rollout of consumer fossil fuel subsidies in response to the spike in gas and oil prices caused by the U.S.-Israel war with Iran. While it’s understandable for governments to want to ease financial hardships, the team stressed that these subsidies are a major setback to confronting the climate crisis and they fumble the chance to present the Iran war as a clear example of why we need to reduce global reliance on fossil fuels.

“Consumer fuel subsidies are the worst kind of energy policy: they boost the most polluting kind of energy—fossil fuels—with a policy that is wasteful and deceptively hard to reverse,” said authors Paasha Mahdavi of the University of California, Santa Barbara and Michael L. Ross of the University of California, Los Angeles.

“The Iran war represents a once-in-a-generation opportunity to accelerate the transition away from fossil fuels,” the team continued. “But short-term measures that governments are taking—to help their citizens cope with unaffordable gasoline and diesel prices—will have long-term effects. Making fossil fuels cheaper now will have catastrophic consequences in the future.”

To channel the old joke from The Simpsons: “It’s the worst energy policy in the world… so far.

A Mississippian taste for cacao

King, Adam et al. “Cacao in the Mississippian World: Archaeogenomic evidence for T. cacao consumption at the Etowah Site, Georgia.”

Let’s close with a finely-aged dessert. And I mean, really aged—this decadent treat is 1,000-years-old.

Humans have been consuming the delectable fruits of the cacao tree for many thousands of years in Central and South America, and the plant made its way into parts of North America, such as the American Southwest. Now, archaeologists have discovered cacao was also consumed as far east as the Etowah Site in Georgia, an ancient city built by the Mississippian culture, revealing the unexpected spread of the delicacy deep into the Southeast.

“There is very little material evidence of connections between people living in Mississippian places like Etowah and those living in Central America,” said researchers led by Adam King of the University of South Carolina. “As a result, the possibility that the Mississippian world had access to cacao has always seemed remote.”

Etowah Indian Mounds State Historic Site. Image: Archaeo-Geophysical Associates

But one should never underestimate the power of chocolate, and this study bears that wisdom out. When the team analyzed ancient DNA sequences of residue found on Etowah pottery, they detected notes of cacao.

“Despite the fact that Etowah is separated from potential sources of cacao by great distances, ancient DNA confirms the site’s inhabitants consumed cacao,” the team said. The researchers speculated that Etowah may have sourced its cacao from trade routes to Mexico or the American Southwest, but noted that no “direct connections to Mexico nor the American Southwest are supported by archaeological evidence for now.”

“These results ask us to reopen lines of research long closed, especially regarding contacts between the impressive civilizations of Central and South America and the great Mississippian civilization of the Eastern Woodlands,” King and his colleagues said in the study.

As to the cultural role of cacao, the study suggested that “at Etowah and possibly across the Mississippian world, cacao consumption played a role in world renewal rites of intensification.”

Given the previous story about fossil fuels subsidies, we need all the world renewal rites we can get, so eat dessert first.

Thanks for reading! See you next week.

Western North Carolina Pleaded for Hurricane Help. It Got ICE Instead.

Intercept
theintercept.com
2026-08-29 06:00:00
As the G20 descends on Asheville, the communities that helped rebuild after Hurricane Helene live in fear of Trump’s immigration regime. The post Western North Carolina Pleaded for Hurricane Help. It Got ICE Instead. appeared first on The Intercept....
Original Article

After Hurricane Helene, a group called Latinos Aventureros covered more than 4,300 miles crisscrossing Western North Carolina, spending 650 volunteer hours delivering food, water, medicine , and other supplies to an estimated 1,700 people.

It was a departure from the group’s typical mandate: helping Latino families get outside in natural areas like Wilson Creek, a popular summer recreation site in the forest stretching north of the mountain-flanked city of Asheville, where President Donald Trump will welcome G20 leaders on Saturday. Since the devastating 2024 hurricane — the deadliest to hit the mainland U.S. since Katrina — North Carolina has received just a fraction of the disaster aid it’s sought from the federal government. Short on federal dollars, local volunteers like Latinos Aventureros tried to fill in the gaps. “We didn’t wait for permission. We didn’t wait for funding,” said Vivianette Ortiz, one of the group’s leaders. “We just showed up.”

The Trump administration has pointed to Asheville’s recovery as a marker of success, and its selection to host the international economic summit “reflects the Trump Administration’s commitment to the revitalization and resilience of western North Carolina,” in the words of Treasury Secretary Scott Bessent. But the view from the ground tells a different story. Damaged roads and infrastructure remain; some residents are still living in trailers; and empty lots mark where homes and businesses stood before Helene. And instead of receiving still-needed federal assistance, earlier this summer, Western North Carolina got Immigration and Customs Enforcement.

ICE agents, U.S. Forest Service personnel, and Caldwell County sheriff’s deputies arrested 13 people at Wilson Creek on July 26. Among them was a father there with his partner and their 4- and 10-year-old children, who had to watch their dad be taken into custody. ICE claimed some of those arrested had criminal records, but it hasn’t said who or how many.

To Ortiz, there was “a real sense of betrayal.” Volunteers with Latinos Aventureros had helped clean the recreation area, where the organization encouraged families to swim, hike, fish, and picnic on public lands. Families have since said they are afraid to use outdoor spaces because they fear encountering immigration enforcement.

“A huge part of our work has always been telling Latino families: These public lands belong to you, too,” Ortiz said. “If people are afraid to walk through that gate, then meaningful access has already been damaged.”

Left: Storm debris is piled against a damaged business in Swannanoa, N.C., on Oct. 4, 2024, days after Hurricane Helene devastated the community. Right: Nearly two years later, the building remains unrepaired and overgrown on Aug. 24, 2026. Trump visited Swannanoa shortly after the storm and promised a swift federal response and recovery.
Photo: Austin Campbell/The Intercept

It takes just an hour by car to reach a different reality, where finance ministers and central bank governors representing the world’s largest economies are rolling into town for a meeting of the G20, the international economic forum whose members account for roughly 85 percent of global economic output and two-thirds of the world’s population.

They’re meeting up at the Grove Park Inn and Spa, a luxury resort overlooking Asheville and largely removed from the destruction Hurricane Helene left along the region’s rivers and valleys. Federal contracting records show the Treasury Department awarded Omni Hotels Corporation, the hotel’s owner, a $1.03 million contract to use the space. A separate Treasury planning document names Grove Park as the event’s “primary place of performance” and calls for gifts representing Western North Carolina and cultural programming highlighting the region’s “history, culture, and character.”

The city awaiting G20 delegates offers only a partial picture of recovery, said Jamie Byrd, a local resident and art gallery owner.

“They will get that beautiful experience of being at the Grove Park Inn, most likely, and maybe a couple of them might make it downtown, which looks completely normal,” Byrd said. “It’s unfortunate.”

Beyond Asheville’s tourist corridors, Helene remains written into the landscape. Debris left along rivers and roads has disappeared beneath nearly two years of vegetation, while damaged infrastructure remains. Elsewhere, recovery resembles absence: Buildings swept away by the storm have left empty ground where homes and businesses once stood.

Byrd’s gallery, located in Asheville’s River Arts District, took roughly six feet of water during Helene, destroying much of her artwork and causing at least $80,000 to $100,000 in losses, she estimates. Across town, roads near her home washed out, largely cutting off the neighborhood. Without electricity to power their wells, residents collected drinking water from an open spring on a neighbor’s property. They laid rocks and large pieces of metal across damaged roads to make them passable. Helicopters eventually arrived with “meals ready to eat” and evacuated residents who needed medical care.

“Most of this help came from self-help and community efforts,” Byrd said.

Jaime Byrd, left, salvages a painting from her flooded gallery in Asheville’s River Arts District on Oct. 3, 2024, days after Hurricane Helene. Photo: Austin Campbell/The Intercept

Federal assistance covered about 20 percent of the repairs needed at her home, Byrd estimates, but she received no Federal Emergency Management Agency help for her gallery. She launched a GoFundMe, spent her own money, and salvaged what artwork she could. Her collectors bought every recovered piece, which helped her keep the business alive.

Two years later, she said one of her neighbors still lives without water, while others remain in trailers.

In East Asheville, Linda Tetens said flooding and fallen trees effectively turned her neighborhood into an island, while residents cleared roads and helped one another through days without power or reliable access to food and water. Tetens relies on a CPAP machine to breathe while sleeping and said that after about 10 days without electricity, the effects of going without it forced her to leave Asheville for a motel in Greensboro.

“It was like a full-time job, trying to negotiate with FEMA.”

FEMA initially approved the hotel stay, Tetens said, but later denied her reimbursement. She spent nearly a year repeatedly submitting documents before receiving roughly $1,400.

“It was like a full-time job, trying to negotiate with FEMA,” Tetens said. “I understand why people gave up.”

Tetens points to damaged roads and residents still awaiting government buyouts as evidence of how much work remains.

“We’re not even close to being back,” she said.

Nearly two years after Helene, billions of dollars sought for North Carolina’s recovery remain outstanding. The state had received $7.8 billion in federal disaster aid as of March 31, according to state recovery data cited by the local newsroom Asheville Watchdog , compared with $25.6 billion requested after the storm. In June, Gov. Josh Stein traveled to Washington seeking more than $10 billion in additional federal funding for housing, infrastructure, and small businesses; on Thursday, FEMA announced an additional $137 million for North Carolina disaster recovery.

The fear of immigration enforcement could bring additional anxiety to a region struggling to recover, Asheville officials warned in 2025. “Our community is still recovering from Hurricane Helene,” Mayor Esther Manheimer and other local officials said at the time. “We do not need additional stress and fear.”

Asked whether those concerns extended to recent immigration enforcement in Western North Carolina, a city spokesperson told The Intercept she would not engage with questions characterizing federal immigration operations as harassment.

Left: A power box in East Asheville on Oct. 4, 2024, bears graffiti reading “THE STATE WILL NOT SAVE US,” reflecting some residents’ frustration with the state’s emergency relief efforts after Hurricane Helene. Right: Nearly two years later, the graffiti has been removed from the same box, while storm damage remains nearby.
Photo: Austin Campbell/The Intercept

In response to questions from The Intercept, a Department of Homeland Security spokesperson called the response part of “the long list of FEMA failures under Biden.” (Joe Biden was in office when Helene hit in September 2024, but recovery efforts have continued into the second Trump administration.)

“Under the Trump Administration, FEMA is mission focused and dedicated to disaster response,” wrote spokesperson Micah Bock , who previously worked for former Rep. Madison Cawthorn , R-N.C.

For Ortiz, the administration’s decision to showcase Western North Carolina’s recovery to the G20 makes the contrast particularly difficult to ignore. Latino and immigrant families, she said, were among the people who helped the region recover, but their right to belong should not depend on what they contributed after the storm.

“Our community shouldn’t have to say, ‘Look at everything we did after Helene, therefore we deserve to be here,’” Ortiz said. “We deserve to live here, raise our families here, enjoy our public lands, and move through our communities without persecution regardless of whether we drove a relief truck after a hurricane.”

Ryabitsev: Creepy crawlies

Linux Weekly News
lwn.net
2026-08-29 05:32:34
Konstantin Ryabitsev has written a blog post with hard numbers about the impact of AI crawlers on the Linux kernel repositories at git.kernel.org: Today, git.kernel.org receives about 6M daily requests demanding to see random commits. Of these, 66% are still immediately batted away with the Anubis...
Original Article

Konstantin Ryabitsev has written a blog post with hard numbers about the impact of AI crawlers on the Linux kernel repositories at git.kernel.org :

Today, git.kernel.org receives about 6M daily requests demanding to see random commits. Of these, 66% are still immediately batted away with the Anubis challenge, but 33% are now solving the math and getting through to the main site — because apparently what we have to offer is worth spending a ton of cycles to calculate the Anubis challenge.

It's impossible to tell with certainty which of these are bots and which are real humans — but chances are, if it's asking for an old commit in a random old fork, it's probably not a real developer trying to do their work.

With a bunch of generous assumptions, legitimate requests are only about 2% of git.kernel.org traffic — everything else are scrapers.



Being kicked out of the tech industry

Lobsters
www.jacky.wtf
2026-08-29 04:24:22
Comments...
Original Article

I think I'm giving up on being a "professional" software engineer. I've tried it for a decade. I've been laid off more than half of the times I've been in the game. I've been fired while having a mental health break that was induced due to a death in the family that merited no pity or support [1] . I'm told to keep grinning, keep trying, keep smiling. It is fucking difficult to keep doing so while working other jobs to get by. So I think I give up. This has obliterated my job in software, something that began as a hobby , and I don't know what I'm going to do next.

I'm fortunate to have family to fall back on but as folks know, I am the Yggdrasil of sorts so once my coffers run out — it'll get harder. We're not supposed to say that we're in a recession but damned if I'd lie as I hear from more than half of the people I know about how difficult it is to keep a job, let alone find one.

Giving up is okay. But this feels more like being kicked out. Getting more than 5 rejections a day despite my past work is humiliating. Having to be told that "you're great but no" more than 6 times a day is demeaning. And having to hear that it'll take a year to find a job — how the fuck does society claim to be in a good place if folks have bills to pay during this time [2] ? I don't see how I'm supposed to keep trying when I keep getting "no"s from people who claim to open to the ideas of a "yes".

I am capable of the work being presented in front of me. I've done architectural work time and time again. I've done silly puzzles over and over to demonstrate my understanding of a programming language's primitives. I've been on-call for projects millions of people have used. I've been able to get clearance to federal resources to develop software for it. At this point, I know it's not me but it is fucking with my ability to get by. Am I on some sort of blacklist invisible to employees for talking too much and causing too much of a ruckus in a workplace? Did my bringing up of a book at a company get one of the executives too upset? Did me having a crisis in public become too embarrassing for another? What the fuck is the problem?

The Game is not the Game

Before, it was enough to have something you can demonstrate. To have skill, to have experience. Now, it does not matter. I guess it goes doubly for me since I don't have any formal education; I'm more of a risk or liability [3] . It also doesn't help that I'm on public record multiple times for being comfortable with bringing a company to the cloth if they're not respecting their workers (which is most of the time; without a union, you only have promises, not commitments). I don't know what it is that's causing problems. I'm being told it's not me, it's them but there's too many "them"s for me to think it's solely a "them" problem. I dress better than most folks, I can explain technical concepts to folks who know nothing about TCP/IP, I've gone and broken my own stance about not using AI to follow the industry in hopes of improving my chances. What I'm learning now is this:

  • It is solely a game of referral : it does not matter what you apply with because other people are cheating in the application process. I do not cheat off principle because it catches up to you. But now I have to beg people for the chance at getting a job; thank you OpenAI nee Microsoft.
  • Your experience is meaningless : it doesn't matter what you've done, how long you've done it or what you've contributed. It's more if they like and trust you. I'm a personable guy and I do my best to come off as the such. I also know when I make white people uncomfortable and I'm not capable of being a respectable Negro. If I have to resort to that behavior in order to get a job, I'll join the police academy.

Please don't be surprised if you see a GoFundMe campaign from me - again - in the next two weeks. Folks are going to comment and say whatever for publishing this. I think I get a little bored of seeing the same old business as usual when more than 30% of people are fucking going through for it for no reason outside of "you're not the match we're looking for". Well, what was it then!?


  1. I barely got severance. ↩︎

  2. Ironically, savings can only get you so far. When your life is packed up in a storage container halfway across the country and getting there just to examine it will burn into savings, everything is suddenly more expensive. ↩︎

  3. I never know because there's less information about Tupac being in Cuba than what a exit interview will inform you about. ↩︎

Debian Votes To Allow "Responsible Use Of Generative AI"

Lobsters
www.phoronix.com
2026-08-29 04:19:22
Comments...
Original Article

The voting is over and there is a winner now known in the much-debated Debian General Resolution voting over an AI policy for the Linux distribution.

Debian developers have been voting over an AI/LLM policy for the project ranging from banning LLM contributiosn to allowing select AI contributions to other more cautious choices. In the end, Debian developers voted for the choice of allowing "Responsible Use Of Generative AI".

"Using its power under Constitution section 4.1 (5), the project issues the following statement describing its current position on AI-assisted contributions. This statement describes the position of the project at the time it is adopted. That position may evolve as time passes without the need to resort to future general resolutions. The GR process remains available if the project needs a decision and cannot come to a consensus.

Debian neither endorses nor prohibits the use of generative AI tools in the development, maintenance, or documentation of software, packaging, documentation, and other media published within the Debian Project. We recognize that such tools can substantially improve the productivity of contributors when used responsibly, allowing volunteers to spend more of their limited time on work that requires technical expertise, judgment, review, and collaboration.

The Debian Project nevertheless expects that all contributions submitted to Debian, regardless of how and with which tools they were produced, satisfy the same standards of quality, correctness, maintainability, and legal compliance. The use of a generative AI tool does not diminish the contributor's responsibility for the work they submit. Contributors are expected to understand, review, test, and, where appropriate, modify AI-assisted output before incorporating it into Debian. Blindly accepting or uploading AI-generated material without appropriate human review is inconsistent with Debian's established development practices. We [encourage] our contributors to disclose whether a contribution was made with AI [assistance], but do not require them to do so.

Debian acknowledges that the legal status of material produced by generative AI systems remains the subject of ongoing discussion in many jurisdictions, including questions relating to copyright, authorship, licensing, and potential reproduction of training material. The Project does not seek to resolve these unsettled legal questions through this General Resolution, nor does it adopt a position on whether AI-generated output is, in whole or in part, copyrightable or derived from copyrighted works.

Instead, Debian continues to rely on the judgment and responsibility of its individual contributors. Project members are expected to exercise appropriate care when using generative AI tools, to consider the provenance and licensing implications of material they contribute, and to avoid introducing content whose legal status they cannot reasonably justify. Existing Debian policies governing licensing, copyright, software freedom, and the acceptance of contributions continue to apply irrespective of the tools used to produce those contributions.

Contributors are expected to exercise appropriate care when designing and implementing workflows that incorporate generative AI tools. In particular, they should ensure that confidential information, private communications, security-sensitive information (such as embargoed information about security bugs that is not yet public), cryptographic keys, credentials, and other non-public material relating to the Debian Project, its infrastructure, or its community are not disclosed to third-party AI services unless such disclosure has been explicitly authorized and is consistent with Debian's security and privacy requirements.

The use of generative AI does not alter Debian's established expectations regarding large-scale or automated project actions. Contributors intending to perform actions with broad project impact, such as mass bug filing or patch submission, large-scale code modifications, or other automated changes or requests affecting many packages or contributors, should seek prior discussion and consensus through the appropriate project channels before proceeding. Any such automated process should be overseen by a human who remains accountable for its behavior and output.

This resolution therefore affirms that generative AI is neither exempt from nor subject to special rules beyond the standards already expected of Debian contributors. The responsibility for every contribution rests with the contributor who submits it, who remains accountable for its technical quality, legal acceptability, and suitability for inclusion in Debian."

The results were confirmed this evening on the debian-vote mailing list with the winner being this Responsible Use Of Generative AI in Debian moving forward.

Parsing the Infamous Japanese Postal CSV

Lobsters
www.dampfkraft.com
2026-08-29 04:10:10
Comments...
Original Article

Late last year I released posuto , a package presenting Japanese postal code data in an easy-to-use format. It's based on data released by Japan Post , which is infamous for being widely used but hard to parse.

This adorable character by Irasutoya is cute, but the raw postal CSV data is not.

I first became aware of the postal data when I entered my postal code in an online form and it auto-completed my address as "XXX-borough (except the following buildings)". I had no idea what that parenthetical was referring to, so I looked for a common source of postal data, found the CSV, and found the issue. It turns out the CSV file contains parenthetical notes for anyone reading the CSV file and makes reference to the order of the rows.

This causes problems. The data is mainly useful one row at a time, where the parenthetical is meaningless. Since CSV is a field-delimited format, there's also no need for parentheticals - you could just add a note field.

This is only one of many issues with ken_all.csv . You can find people complaining about it regularly on Twitter , and there was even briefly a blog just collecting posts from all over the web about it. A particularly amusing tweet describes people who expect computers to bend to the will of humans being punished in Hell by having to parse ken_all.csv forever.

The README for the file explains that lines with overly long fields will be broken up into multiple lines. Specifically, if the neighborhood name is over 38 characters, or if the half-width katakana ( half-width katakana ) pronunciation field is over 76 characters, the line will be split into two lines. The overly-long neighborhood field will be continued and all other fields will be duplicated. This is an abbreviated sample of what that looks like:

12345,Tokyo,Minato,This place name is really
12345,Tokyo,Minato,very long it didn't fit in
12345,Tokyo,Minato,a single line so we had to 
12345,Tokyo,Minato,split it

The motivation for this is not explained. Maybe there was a fixed-width buffer for storing a line somewhere thirty years ago. I used to process CSV and other files from hundreds of different providers at an old job and I saw many horrors, but I've never seen this particular formatting choice anywhere else. It should also be noted that while the length limits are as stated, the location where line breaks are inserted in long lines appears random, occurring neither at the character limit nor at normal word boundaries.

It's worth noting not all the issues with the CSV are inherently technical; postal codes are always complicated. The postal code with the most rows in the CSV - a stunning 66 - is 〒452-0961, which refers to the Haruhi region of Kiyosu City in Aichi Prefecture. This has that many lines because every neighborhood gets a separate line. (This particular case may be related to Haruhi having been the smallest town by area in Japan from 2006 until 2009, when it was incorporated into Kiyosu City.)

In contrast, the longest continued line, using the line break rules above, is the entry for 〒602-8368 or 〒602-8374, both with eight lines. These are both in one of a few areas in Kyoto that uses a unique, bizarre system of intersection-based addressing . The entry looks a bit like this:

12345,Kyoto,Kyoto,"North Town (Up Lower Godsroad from"
12345,Kyoto,Kyoto,"the West, Down Turtle Street from the"
12345,Kyoto,Kyoto,"East, Up Old Temple Road from the"
12345,Kyoto,Kyoto,"West)"

I have used quoted fields here, but the actual CSV doesn't quote fields and instead uses a different kind of comma.

There are other issues. There are catch-all postal codes for many areas, where the neighborhood is given as "except the following", and the only thing to do is look for that exact string and exclude it. There's a variety of similar strings, and it's hard to be sure I've caught them all.

An example of another comment is 一円. Normally this would mean "one yen", but it also means "the area surrounding", and is a note in the CSV that should be removed from neighborhood names, except for exactly one neighborhood in Shiga where that's actually the name (〒522-0317).

There's also a separate romaji file offered by JP Post. It's updated less frequently than the main files, is often out of sync, and the provided romaji are extremely low quality. For the moment I'm still providing the data in posuto in the name of consistency, but honestly you should just use cutlet . To give an example of bad romaji:

大手町 JAビル
OTEMACHI JIEIEIBIRU

What's happening here is that "JA" is being converted to the phonetic reading in Japanese, "ジェイエイ". Then ジェ, which is written "large ji small e" but pronounced "je", is being converted to "jie" by treating the small character as though it were large, and the other characters are translated as-is, turning something already in the latin alphabet into alphabet soup. For contrast, cutlet has no problem converting "JAビル" into "JA building" (case handling admittedly needs some work still). Similar issues turn "Roppongi Hills" into "Roppongihiruzu", and "Sweden Hills" into "Suedenhiruzu".

Anyway, dealing with the file was a humbling lesson in the amount of complexity it's possible to pack into one place. I've glossed over many details, but you can find them covered in posuto's README.

You can use posuto as a library, or if you're not using Python, just download the pre-processed JSON and make use of that. If you find a good use for it I'd be delighted to hear about it.

Oh, and if you need a Win3.1 or DOS program to copy the data onto an IBM H floppy disk, just check the bottom of JP Post's page - they've got you covered. Ψ

I naively tried vibe-coding a memory tool for agents and stared into the abyss of unsolved problems in philosophy

Lobsters
arbustoemchamas.substack.com
2026-08-29 02:11:18
Comments...
Original Article

I .

I only really got into LLMs recently, and until then I was completely oblivious to where all the tooling was, i.e. agents, memory tools, harnesses, etc. I ramped into it by realizing that whenever I hit a snag, I could ask Claude to explain how to get out of that snag. It worked well enough, I guess. I eventually got off the desktop app and started using Claude Code, and learned about memory-management tools to help out with the growing complexity of the things I was trying out. I setup Hindsight wrong and burned all my Opus tokens one afternoon. A few days after, I signed up for Max x20, and the next few weeks have become a haze in my memory, because I was trying everything out. Every problem I ran into, I XY questioned my way into what I thought was the solution.

I would eventually learn practically that cheap code does not translate into systems design prowess. I thought I was going to be able to keep the ball rolling and eventually get to a tool that's publishable, but I'm not quite there yet, so this is a post describing what I tried to do and some of the issues I ran into, which is very much underselling things, because some of the issues were capital P Problems. You can't Claude your way out of Problems.

One of those days in that haze, I decided I wanted a memory tool for my coding agents, rather than just relying on Claude's prose files or something else. Because I was so drunk with the power to completely obliterate NIH syndrome, I thought “hey, can't be that hard”. I wanted some database to store what agents learn and bring it back on every session, quickly, locally. An agent wrote most of it under my direction — Rust daemon, because of course it's gotta be in Rust. I guess somewhere along the way we decided facts are never deleted (only superseded, so the bank remembers what it used to believe), four retrieval strategies fused and reranked by small local models. It sounded like it worked. Claude was really confident about that part. I understood that I got it to build a search engine over a weird corpus.

After building that small proof-of-concept quickly, I wanted to build something more ambitious. LLMs are powerful, surely they can show whenever a memory contradicts another memory? I wanted it to flag contradicting memories automatically. Can't be that hard. A bank accumulates months of extracted facts, some go stale, some are wrong, and a memory that contradicts other memories without explanation is worse than no memory, because then the context window is polluted with a bunch of bullshit.

Can't be that hard.

II.

I don’t design systems for a living. What I had was an agent that found research papers whenever I asked it to find “the state of the art” in some area. I read the abstracts and whatever I could understand of them. If I thought it could help, I'd get Claude to build them, and then it implemented them while I sort-of followed along. And the loop is intoxicating: paste a paper, say “we should do that,” and by evening there’s a compiling implementation, tests, sometimes a machine-checked proof. From the inside, “sort-of following along” really feels like you're doing something productive.

So I kept hitting snags, and for each of them, I asked Claude to think harder and reach for more esoteric stuff I had probably heard somewhere. I took one semester of philosophy of language at university, and therefore I knew some basics of Logic, so naturally I figured that qualified me to "design” a contradiction checker, a “reasoning council” — abduction proposes causes, deduction certifies, induction learns candidate rules. Claude then said “hey dude, the council’s verdict model should get machine-checked to form a proper Belnap lattice, the four-valued logic where ‘not recorded’ and ‘contradicted’ are different values.” and I was like “yeah man, go for it”

I'm not entirely irresponsible. I was concerned about bullshitting this design too much so of course, I asked Claude to prove its designs. There were Agda proofs, which were later ported to Cubical Agda, a thing I definitely cannot explain to you. If it runs it's sound, right? There was a Petri net of every subsystem. There was a plan language whose replay properties were proved before its parser existed. I had a solver, a proof assistant, and the faintest idea of what was happening at this point.

III.

It’s been a few months since I started. This memory tool sort-of works. It stores memory with some decent classification. Does it actually flag contradictions? No. It doesn't yet do what I wanted to do from the start. I keep thinking about ways to word this to Claude, thinking that maybe some magic set of words will let me vibe-code my way into success. Today's try was something along the lines of, “why aren't prose memories being encoded into ASP programs automatically? how hard can it be?”

It's really fucking hard. I should have realized this by the huge pile of research papers I’ve compiled and read almost none of them. It's a worse version of buying a huge amount of books that one day I'll surely read, because at least with the books I might end up actually reading them one curious day. 86 research papers saved to Zotero about topics I barely understand are much more likely to just rot away.

Tonight, I realized I did lose the plot entirely. Claude explained in Claudese with all the load-bearing confidence that that you can't just write an ASP program for every prose memory because it turns out that's actually an unsolved problem in knowledge representation, something it called “proposition identity". After getting ChatGPT to translate what Claude had said, I then went back, “okay, explain to me what this proposition identity problem is”:

Here’s an abridged version of the answer it threw at me, with the Claudese intact:

This is worth unpacking properly, because it’s one of those problems that looks like an implementation detail and is actually a 130-year-old open question wearing an engineering costume.

The problem, stated precisely. Your conflict rules fire on syntactic equality […] So the solver never actually judges whether two memories contradict each other — that judgment was made earlier, at symbolization time, by whatever decided that two stretches of prose map to the same atom. […] Your own bank already holds the sharp form of this: fact F1 from the foundations dialogue says canonicalization “makes proposition identity syntactic” […] The rules are six lines; the identity judgment is the entire intelligence of the system.

It did explain something to me that I understood, thanks to that one semester of philosophy of language: the question of “when do two sentences express the same proposition” is really, really hard. If the checker merges fact-atoms (the smallest “currency" in this memory bank) too eagerly, it invents conflicts.

My hope was that a large enough memory bank would surface self-contradictions and that self-contradiction-surfacing would be useful enough. It doesn't need to know whether it's actually true if the current king of France is bald, but it would know some other memory said the current king of France was rocking a mohawk. Nevermind the fact there currently is no king of France (shoutout to Russell, and of course, the rabbit-abyss of denotation is a whole another can of mental whoop-ass).

And then it listed more and more papers about how hard this problem actually was. And then it explained to me that this “proposition identity” problem has been unsolved since 1892, and it told me I probably wasn't gonna crack it either. And then I decided to stop prompting Claude to write code and decided to write this post. Hopefully it was interesting to you, and if you know what I'm doing better than I am, hopefully we could chat about if any of this is salvageable. I hope it is, because it sounds like a cool project.

Claude's suggested reading list for me/us:

Philosophy — why no universal criterion exists

  • SEP: Propositions and Structured Propositions — the surveys of candidate identity conditions and how each fails

  • Frege, “On Sense and Reference” (1892) — Hesperus/Phosphorus, where it all starts

  • Quine, Word and Object (1960) — “no entity without identity,” the demolition

  • Keyword for the modern literature: hyperintensionality

KR — the engineering responses

  • McCarthy, “ Notes on Formalizing Context “ (IJCAI 1993); Guha’s 1991 thesis on contexts

  • Lenat & Guha, Building Large Knowledge-Based Systems (1990) — CYC’s microtheories

  • Davidson, “The Logical Form of Action Sentences” (1967) and Hobbs, “Ontological Promiscuity” (1985) — reification granularity

  • Doyle’s JTMS (1979) and de Kleer’s ATMS (1986)

NLP/KB — the applied problem under its searchable names

  • Canonicalizing Open Knowledge Bases (Galárraga et al., CIKM 2014); CESI (Vashishth et al., WWW 2018)

  • Universal schema (Riedel et al., NAACL 2013) — give up on identity, learn entailment

  • AMR (Banarescu et al., 2013) + Smatch (Cai & Knight, 2013)

  • Cross-document event coreference: ECB+ (Cybulska & Vossen, 2014)

  • Claim matching: Shaar et al., “That is a Known Lie” (ACL 2020); the CheckThat! lab tasks

LLM+ASP

  • s(CASP) (Arias et al., TPLP 2018); STAR (Rajasekharan et al., ICLP 2023); AutoConcierge (Zeng et al., 2023)

  • Distilling ASP rules from LLMs (Eiter, Higuera Ruiz & Oetsch, TPLP 2026)

  • NeurASP (Yang, Ishay & Lee, IJCAI 2020); ILASP (Law, Russo & Broda, JELIA 2014); FastLAS (AAAI 2020) — the rule-learning side

Practice

Search strings, since the problem has no single name: "open knowledge base canonicalization", "relation canonicalization", "cross-document event coreference", "previously fact-checked claim detection", "granularity problem" propositions, "microtheories" context.

Discussion about this post

Ready for more?

Samsung's Processing-in-Memory (PIM)

Hacker News
chipsandcheese.com
2026-08-29 02:06:51
Comments...
Original Article

In-memory compute has been an attractive proposition for many years because compute within a memory chip can exploit its higher internal bandwidth. Additionally, in-memory compute avoids the long latency path between DRAM and traditional compute cores. At Hot Chips 2026, Samsung discusses their continued pursuit of in-memory compute with their PIM (Processing-in-Memory) push. They’re implementing MAC units within LPDDR5X chips, while preserving the chip’s ability to interface with a standard memory controller.

DRAM chips are internally divided into banks, each with their own read and write logic. During a normal DRAM access, the memory controller selects a bank, activates a row within it, and then accesses data via column access strobe (CAS) commands. Bandwidth is limited by the chip’s external DRAM interface. Even if the memory controller could activate all of the banks simultaneously, it wouldn’t be able to get its hands the full bandwidth available across all the banks.

Samsung’s LPDDR5X-PIM is like a normal LPDDR5X-9600 chip with 16 banks, but places a PIM (Processing-in-Memory) block at each bank. These PIM blocks access their attached DRAM bank without being constrained by the chip’s external bus. Together, they can utilize the chip’s internal bandwidth across all 16 banks, which comes out to 614 GB/s. For comparison, regular DRAM accesses can hit two banks in parallel and max out at 76.8 GB/s.

PIM blocks internally consist of a MAC tree with surrounding register files and control logic. A 1024-bit instruction register file holds up to 64 16-bit instructions. A 4 kbit source register file is meant for activation vectors, and supplies one source operand for the MAC array. Samsung expects software to load model weights into DRAM, so the attached DRAM block supplies the second operand. Model weights can be scaled before the MAC computation, with scale factors coming from a 2 kbit scale register.

The PIM block’s MAC array supports a variety of low precision formats. Numbers from Samsung’s presentation suggest each PIM block’s MAC array can sustain four INT8 or FP8 MAC operations per data clock, or eight per cycle when not counting the double data rate. Throughput doubles for 4-bit input weights, bringing package-wide compute throughput to 2.4 TOPS.

This isn’t a very high figure, but an implementation with many LPDDR5X chips will have higher aggregate throughput. For example, eight LPDDR5X chips together would have 9.6 INT8 TOPS, which just about matches the NPU in Intel’s Meteor Lake . That would also be an expensive setup, because eight 16 GB LPDDR5X chips would correspond to 128 GB of system memory.

One highlight of LPDDR5X-PIM is that it stays within the standard LPDDR5X protocol while exposing compute capabilities that aren’t part of the memory standard. Samsung achieves this by setting aside special row addresses, which act like MMIO addresses of sorts. Each channel has a pair of predefined rows for mode control. Activating one of those rows sets the chip to single-bank mode, while the other sets the chip to multi-bank mode. Single-bank is the regular mode, while multi-bank applies commands across all 16 banks to exploit the chip’s internal bandwidth.

Special per-bank rows change how read and write commands behave. Activating one of these special rows makes read and write commands access PIM registers instead of regular DRAM bank contents (PIM Registers Activated mode). Samsung envisions a ML use case where software loads model weights into DRAM while the chip is in normal single-bank mode. Then, software switches into multi-bank mode and enters PIM Registers Activated mode. This lets code write activation values into PIM source registers, set scale factors in PIM scale registers, and specify an operation that’s filled into PIM instruction registers.

Because the chip is in multi-bank mode, each PIM register write gets broadcast across all 16 banks. PIM compute therefore works like a very constrained SIMD processor, where the operation, scale factor, and one source operand are the same across all banks. Samsung does allow writing PIM registers in single-bank mode, but that functionality is meant for debugging purposes. Each DRAM packet is 256 bits (BL=16) Filling each source register takes 16 write commands. Doing that one bank at a time across each of the 16 banks would mean 256 write commands, turning host to PIM register write bandwidth into the limiting factor. Samsung actually allows PIM register access in single bank mode, but that’s intended as a debugging feature.

After priming PIM registers, software switches back into multi-bank mode and issues read commands. Instead of reading DRAM contents, these read commands initiate computations and get results accumulated into PIM vector register files. Then, write commands tell PIM blocks to write VRF contents back into the DRAM banks.

PIM has to handle reordering that a normal memory controller might carry out. When code sets up PIM by activating the bank, PIM conventionally sets up its instruction register files so that instructions sequentially access each source register element. For instance, the first instruction would reference the first source register element, the second instruction would reference the second source register element, and so on. However, that falls apart if the memory controller reorders accesses. Samsung gets around this with an Address Align Mode (AAM), which makes each instruction infer its source register index from the column address being accessed.

When the host finishes using in-memory compute and wants to read results, it switches the DRAM chip back into single-bank mode. Then, regular DRAM reads and writes will start accessing DRAM contents as normal.

Samsung internally achieved huge performance gains when taking advantage of LPDDR5X-PIM, compared to using standard LPDDR5X. The chip’s ability to operate with a standard memory controller is impressive, and Samsung has been very creative in how they approached the problem.

Repurposing standard DRAM commands should simplify hardware, but software challenges look steep. Because PIM modes change the meaning of DRAM access commands, software can’t use PIM and carry out regular memory accesses at the same time. That applies even across threads, because memory controllers and DRAM chips are oblivious to what thread an access is for. If a non-PIM thread reads from memory while another is using PIM, the first thread could cause an unintended computation and get incorrect results into the PIM VRFs. A write from the non-PIM thread could cause PIM blocks to write VRF data back to the wrong address.

Samsung deals with this by having the host isolate a PIM region in memory. I can’t think of an easy way to do this in a typical system without compromising memory bandwidth and PIM performance. Hardware normally interleaves addresses across channels, which lets common access patterns naturally utilize bandwidth across those channels. PIM uses per-channel rows to control single/multi-bank mode changes, so dropping interleaving and designating memory channels as PIM-only would be the only reasonable way to create a PIM region. Then, non-PIM applications wouldn’t be able to take advantage of bandwidth from channels reserved for PIM. PIM code would miss out on bandwidth and compute from non-PIM channels. The latter could be a significant issue because per-chip compute throughput isn’t that high.

Multitasking issues could persist even after isolating a PIM region. If an application wants to use PIM and take advantage of multithreading, it would have to guard PIM region accesses with locks to prevent cases where one thread tries to do PIM compute while another attempts regular memory accesses. Things get even worse with a modern multitasking operating system, where multiple processes could try to use PIM without being aware of each other. I’m not sure there’s a good way to handle that besides making the operating system run PIM compute code segments with all other threads blocked and interrupts disabled. Handling interrupts or context switches with PIM feels like a nightmare for the OS in any case. Preempting a PIM thread would mean bringing the memory channel out of PIM mode and saving PIM state. The OS would have to read out instruction, source, scale, and vector register file across each bank and save it somewhere. Only allowing a single running thread with no task switching would leave multithreaded performance on the table, and could lead to system responsiveness issues if code spends too long in PIM compute sections.

PIM compute breaks a memory subsystem’s expectations about DRAM behavior because DRAM can generate memory values that the cache hierarchy never knows about. Caches can also break PIM behavior by absorbing accesses meant to trigger PIM operations. Samsung therefore recommends mapping PIM memory as uncacheable. That’s problematic because modern CPUs and GPUs rely heavily on caching to mitigate DRAM latency. Performance on uncacheable memory will be extremely slow because the CPU or GPU cores will spend far more time stalled waiting on memory.

Skipping caches isn’t the only problem. PIM reads act like MMIO accesses because they cause computations that affect PIM VRF values, rather than just retrieving data. CPUs also mitigate memory latency by initiating loads before they know that load data will actually be needed. Branch prediction lets CPUs issue instructions before the core knows for certain that those instructions will be executed. Prefetchers observe memory access patterns and attempt to load data into cache before instructions request that data. If the CPU loads data that turns out to unneeded later on, that’s fine because loads normally won’t cause incorrect program behavior. Unfortunately that’s not true with PIM, where reads trigger computations that modify PIM VRF contents.

Yeah, that’s gonna go badly

Working with a PIM region will likely mean making memory accesses non-speculative as well as non-cacheable. Running a CPU without caching, prefetching, or out-of-order execution will cripple performance.

Setting aside PIM mode difficulties, in-memory compute poses high level challenges for software. Each PIM block only has fast access to its locally attached DRAM bank. All other input data has to be brought in through the DRAM chip’s comparatively constrained external interface. PIM blocks can’t directly exchange data with each other, so the host has to move data using regular DRAM reads and writes if one PIM block needs to use results generated by another.

Samsung’s LPDDR5X-PIM can theoretically go into any server, desktop, laptop, or even mobile device thanks to its ability to work with standard memory controllers. However, that doesn’t mean it’ll be easy to use with typical hardware and software paradigms. PIM mode switching throws a wrench into the works for multitasking operating systems. Modifying DRAM contents under the hood and attaching side effects to read commands breaks CPU caching, prefetching, and out-of-order execution.

Some memory chips. Not the right generation, but probably close (in price/GB terms)

I don’t think there’s an easy way to use in-memory compute without changes throughout the memory subsystem. For example, something like should make software adoption easier:

  • Expand the DRAM interface to add a set of compute commands, avoiding mode switch complexity

  • Have the memory controller act like a peer CPU core from a cache coherency perspective. Before using in-memory compute commands, the memory controller issues read-for-ownership (RFO) requests for all affected cache lines. That lets the memory controller obtain any modified data and write it back to DRAM before starting in-memory compute, ensuring that in-memory compute results reflect the latest CPU-side writes. Then, the memory controller holds ownership of affected cache lines until in-memory compute operations complete, letting CPU cores observe in-memory compute results without needing to invalidate or bypass caches

  • Add a new set of CPU instructions like “rep macb” that perform multiply-accumulate operations over a block of memory with fixed multiplicand/scale factors and undefined numerical characteristics. The CPU can choose whether to use in-memory compute (if supported by DRAM) or generate a sequence of internal ops (if operating over a small set of data that’s already in cache).

With those hardware changes, software would be able to use in-memory compute from a multitasking operating system without reserving memory or losing thread-level parallelism to PIM-related locks and synchronization. A transparent CPU instruction avoids the problem of shipping hardware specific binaries, and allows forward-compatible code that automatically takes advantage of new hardware capabilities including different in-memory compute implementations. It also lets hardware use implementation-specific knowledge and real-time data (like a no-fill-on-miss cache lookup) to make the best decision about where to carry out compute. I don’t like the software alternative of reserving memory regions, marking them uncacheable, and blocking threads. There’s just too many tradeoffs around performance, memory capacity, and responsiveness.

Reviving An SD Card With Shorted Capacitors

Lobsters
hackaday.com
2026-08-29 01:35:08
Comments...
Original Article

Skip to content

A nice thing about SD cards is that even in their non-micro format they are conveniently small. This is however a bit of a problem when an SD card stops working, as they are not exactly designed to be easy to service, or to recover data from. There is however a very good chance that the Flash memory and controller are still fine, and it’s actually one of the passives on the tiny PCB that failed, as with the 32 GB SD card that [Yevgeniy Kapishon] recently diagnosed and recovered data from for a customer.

Tiny capacitors in an SD card package. (Credit: Aeson Labs)
Tiny capacitors in an SD card package. (Credit: Aeson Labs)

A big hint during initial diagnostics was a clear short between the supply rail and ground, but as became clear when taking the SD card apart, this one was built as a monolithic package, without exposed components on a PCB as in older SD cards. Correspondingly an X-ray machine and thermal camera were used to figure out what was inside the package, and where the short was located.

By combining the hot spot image with the X-ray it was determined that the problem was with some passives near the edge of the package. Some careful material removal later two miniscule capacitors were found to be the culprit and gently removed. With this the short on the power rail vanished, and the SD card started working again.

Having a shorted MLCC or similar passive component is a very common failure mode in general which can cripple even the most expensive device. Even if SD cards still aren’t really repairable, it’s at least reassuring to know that in many cases the data is fairly easy to recover once you have identified and removed the offending part.

Faster, higher, funnier: what we learned from China’s robot games

Guardian
www.theguardian.com
2026-08-29 01:00:19
Five-day showcase reveals leaps Beijing has made in humanoid tech, but also its limitations as US rivals come up from the rear With exploding pelvises, enough comic pratfalls for a Buster Keaton show reel and the odd moment of ruthless violence, the World Humanoid Robot Games in Beijing gripped the ...
Original Article

With exploding pelvises, enough comic pratfalls for a Buster Keaton show reel and the odd moment of ruthless violence, the World Humanoid Robot Games in Beijing gripped the world this week with an unsettling mixture of hilarity, trepidation and relief.

The five-day showcase staked out China’s claim to undisputed leadership in humanoid robotics as android martial artists landed knockout roundhouse kicks and robot teams marched into the arena heralded by flag-waving captains astride giant robotic dogs. The games’ blue-riband event, the 100m, did not disappoint when the robot-sprinters ran quicker than Usain Bolt before slamming mindlessly into a padded wall in a blaze of sparks, flames and flying mechanical limbs.

Robots run, punch and score at World Humanoid Robot Games in China – video

There, in a 10-second clip perfect for the games’ global online audience, was proof of what onlooking international experts described as the superpower’s “staggering” engineering progress, combined with comfort that the disintegrating robots might not yet be ready to become humanity’s overlords.

“Ready for another big day of fail,” read a typically schadenfreude-laced comment from one of millions who tuned into viral social media clips and livestreams of events from boxing to breakdancing in which the humanoids displayed a jerky mix of ruthless effectiveness and pathetic failure.

Others caught themselves experiencing unexpected empathy. One captioned a robot struggling through the 400m obstacle race: “after drinking 4 bottles of wine at 2 a.m”. Another found a weightlifting contest “way more emotional than I expected” as the bots strained to achieve their sporting goals.

If the games had a slogan it might be: faster, higher, funnier. The obstacle course involving humanoids scrambling under nets, down stairs and over stepping stones reminded the comedian Charlie Higson of Monty Python’s Upper Class Twit of the Year sketch: “It’s only lacking ‘taking the bra off the debs’ and ‘shooting themselves’.” He came back the next day for more. “They get better and better,” he tweeted as a cheerleader robot wielding glittery pom-poms flailed around like it was having a fit.

But the games were not intended to only entertain. Involving over 2,000 humanoids built by more than 660 mostly domestic tech companies, it was a propaganda flex of China’s robotics muscle just weeks before its president, Xi Jinping, lands in Washington DC for a summit with Donald Trump, where the superpowers’ race to tech supremacy will be high on the agenda. Only last month Trump banned imports of Chinese humanoids and four-legged robot dogs, citing cyber and national security concerns. The event was also a billboard to boost global sales of Chinese robots as US rivals prepare their own launches, notably Elon Musk’s long-hyped Optimus humanoid which is reported to have finally gone into production this month. Last year China produced 12,800 humanoids, about 90% of the global total, according to the Mercator Institute for Chinese Studies, a dominance which perhaps gave China the confidence to candidly broadcast so many comic failures, which surprised some onlookers.

Robots compete at the Free Combat event as a human referee looks on
Robots can run fast or box, but they can’t do both. Photograph: Achmad Ibrahim/AP

The event reflected the fact that, for the Chinese Communist party, humanoids are a high priority, offering solutions to a looming demographic crunch in the labour market, rising military ambitions and, as they walk more widely among the people, the state’s desire to tighten its surveillance web. Beijing is fuelling an intensely competitive robot industry by seeding hundreds of companies to create an evolutionary survival of the fittest dynamic, with the games creating a hard deadline for competitors to deliver measurable progress. Xi’s latest five-year plan , approved in March, was studded with pledges to boost robotics industries; accelerate the “practical application of … humanoid robots” and explore “embodied AI in roles experiencing labour shortages or high-risk environments” which likely include war. The military potential of the humanoids on display worried some onlookers.

“Fascinating, and honestly, a little scary,” said Arun Bothra, a senior police officer in India, which shares a tense border with China. “Watching robots run, play football and compete like humans is one thing. Seeing them on borders someday, carrying guns and making decisions, will be something else entirely.” Or as another viewer concluded while watching a humanoid hoist a loaded barbell in the weightlifting contest: “Humanity is preparing its own end”.

Of course China is not alone in pursuing robotic warfare. As the Beijing games progressed on Monday, Ukraine was staging a novel military parade in Kyiv made up entirely of robotic weaponry and defence equipment.

Three humanoid robots cross the finish line at the World Humanoid Robot Games.
Tiangong Ultra beats Usain Bolt’s record in the 100m sprint. Photograph: Tingshu Wang/Reuters

But how to explain the numerous crashes and fits in the Olympic speed skating arena where the competition took place? Experts said the games revealed how China was making the most rapid strides in developing humanoids’ bodies rather than their minds.

“The progress they have made from last year is staggering,” said Thrishantha Nanayakkara, a professor of robotics at the Dyson school of design engineering at Imperial College London. “Everything seems to be coming together …. by 2030, it will be a very different world.”

The fastest sprinter, Tiangong Ultra, completed the 100m more than twice as fast as last year, while the peak standing jump rose from 0.96 m to 3.40m. Liquid cooling has allowed Chinese engineers to increase the torque of the motors that drive their limbs creating more twitchy and powerful force.

“This execution is incredible,” said Ingo Keller, head of robotics at the National Robotarium, based at Heriot-Watt University in Edinburgh. “You would not have expected the speed of development. [But] does it move the goalpost in utilising humanoids? Not necessarily.”

A humanoid lying on the floor on fire
An Honor Lightning humanoid robot caught fire following the 100m final race. Photograph: Tingshu Wang/Reuters

Experts stress the games revealed progress in specialist, not generalist, humanoids: the robots were fast runners or good boxers, not both, partly because the AI models that govern their decisions are yet to be able to process the physical world’s full complexity. The industry talks about reaching a ChatGPT moment – a tipping point when humanoid technology becomes generally useful and explodes into the mainstream. By one definition, that comes when a robot can succeed at 80% of tasks in an unfamiliar home, instructed by voice or text. The event coincided with a sobering speech from Wang Xingxing, founder of Unitree, one of China’s leading robotics companies, who said it could be a decade before that ChatGPT moment.

“Humanoids are not yet capable enough for mass deployment,” he said. “The limitations in the AI models that power robots’ decision-making and interactions remain the industry’s biggest bottleneck.” Amid uncertainty about the impact of robotics and bubble fears, his company’s share price has been oscillating wildly since it listed in Shanghai earlier this month.

Georg Stieler, a consultant who advises multinational companies on robots, said he did not see much progress on robots’ autonomy when he was in Beijing this week. He reported that some Chinese robotics companies were also privately cynical about the five-day showcase, complaining about a lack of funding for commercial long-term pilot projects “to do something useful in a factory”.

“It’s not so difficult to make a stunt, which people will share on LinkedIn or X,” Stieler said. “The major challenge is to do something that’s really useful.”

Humanoid robot dexterity requires much more work and there was little focus on the events testing it. There was little obvious coverage of a Monty Pythonesque category that included power tool assembly, powder weighing, bottle opening, cap prying, box unpacking and tweezer bean-picking. One such challenge was briefly featured on Wednesday when the race track was occupied by the unspectacular sight of a humanoid struggling to pick up a small object from a table and spilling water in a pouring challenge. The cameras panned away to find a humanoid martial artist carving the air with kicks.

Any true alternatives to electron JavaScript?

Lobsters
lobste.rs
2026-08-28 23:11:59
I see companies having codebase in Tauri going back to electron - is this a common thing?...
Original Article

I strongly suspect that the difference between the average Tauri application and the average Electron application is far smaller than the difference between any two applications using any web renderer whatsoever. That is, if you want a more lightweight app, and you're currently using Electron, you're better off optimising your current frontend code than you are switching to Tauri.

There are other reasons to prefer Tauri over Electron, but I think the big selling point of Tauri being more lightweight is mostly overplayed.

TurboKV: Insanely fast Rust key-value store

Hacker News
github.com
2026-08-28 22:23:37
Comments...
Original Article

TurboKV Logo

A fast, embedded key-value store in Rust

GitHub License Rust

TurboKV is an async embedded key-value database with atomic batches, ordered range scans, configurable durability, compression, and background compaction.

Installation

cargo add turbokv
cargo add tokio --features full

Or add the dependencies directly:

[dependencies]
turbokv = "0.6"
tokio = { version = "1", features = ["full"] }

TurboKV's persisted Bloom-filter format uses hardware AES. Build x86/x86_64 targets with RUSTFLAGS="-C target-feature=+aes,+sse2" , and ARM/AArch64 targets with RUSTFLAGS="-C target-feature=+aes,+neon" . You may instead use -C target-cpu=native when the binary will run only on the same CPU model or a feature superset.

Quick start

use turbokv::{Db, DbOptions, WriteBatch};

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    let db = Db::open_with_options("./my-database", DbOptions::durable()).await?;

    db.insert(b"user:1", b"Ada").await?;
    assert_eq!(db.get(b"user:1").await?, Some(b"Ada".to_vec()));

    let mut batch = WriteBatch::new();
    batch.put(b"user:2", b"Grace");
    batch.put(b"user:3", b"Linus");
    batch.delete(b"user:1");
    db.write_batch(&batch).await?;

    for (key, value) in db.scan_prefix(b"user:").await? {
        println!(
            "{} = {}",
            String::from_utf8_lossy(&key),
            String::from_utf8_lossy(&value)
        );
    }

    db.close().await?;
    Ok(())
}

Runnable examples:

API breakdown

Durability presets

Preset Acknowledgement boundary Use case
DbOptions::fast() In-memory visibility; no WAL Caches and reproducible data
DbOptions::durable() Appended to the WAL without a per-write sync Process-crash recovery; recommended default
DbOptions::paranoid() WAL group completed sync_all before return Strongest mode, subject to filesystem/device guarantees

One open Db or Engine exclusively owns its data directory. Use close() or close_with_status() for a clean shutdown; dropping a handle is not a clean shutdown contract.

Database operations

Keys and values are arbitrary byte sequences supplied through AsRef<[u8]> ; strings need to be encoded by the caller. Mutation APIs copy their inputs before returning. Point and collecting reads return owned Vec<u8> values. An empty value is valid data and is distinct from a deleted key.

Opening and configuration

API Parameters Result and behavior
Db::open(path) path: AsRef<Path> Opens or creates the directory with DbOptions::durable() . The open handle exclusively owns the directory.
Db::open_with_options(path, options) Database path and a DbOptions value Opens with explicit durability, memory, cache, and compression settings. Rejects contradictory settings such as sync_writes = true with the WAL disabled.
DbOptions::fast() None Returns the no-WAL preset.
DbOptions::durable() None Returns the process-crash-recoverable WAL preset.
DbOptions::paranoid() None Returns the sync-before-acknowledgement preset.
options.with_compression(compression) A Compression variant Builder-style update that returns the modified options.

All presets start with a 64 MiB memtable, a 64 MiB block cache, and LZ4 compression. Their public fields can be adjusted before opening:

DbOptions field Meaning
wal_enabled: bool Append mutations to the WAL. Disabling it permits process-crash data loss until a successful flush or close.
sync_writes: bool Await a WAL sync barrier before acknowledging each mutation group. Requires wal_enabled .
memtable_size: usize Approximate in-memory byte threshold that triggers a memtable rotation and background flush.
block_cache_size: usize Decompressed SSTable block-cache budget in bytes. Set to 0 to disable the cache.
compression: Compression SSTable compression for newly written data: Lz4 , Snappy , Zstd , or None . Existing tables retain their encoded format.

Point, bulk, and batch operations

API Parameters Returns and semantics
insert(key, value) Byte-like key and value Result<()> . Inserts or replaces the key. The selected durability boundary is reached before success.
insert_many(entries) Any iterator of (key, value) pairs Result<()> . Copies the full iterator and applies entries in order; the last duplicate key wins. This is a bulk API, not one atomic visibility transition.
get(key) Byte-like key Result<Option<Vec<u8>>> . Returns None for missing or deleted keys and Some(Vec::new()) for a stored empty value.
remove(key) Byte-like key Result<()> . Writes a tombstone; deleting a missing key is allowed.
contains_key(key) Byte-like key Result<bool> . Resolves the same state as get and currently incurs its value allocation.
write_batch(batch) &WriteBatch Result<()> . Publishes all operations atomically; readers see either the state before the batch or the complete batch. The last operation for a duplicate key wins.

With the WAL enabled, one record or complete batch must fit in the WAL's u32 payload length. A failed or cancelled mutation may already have reached the WAL; inspect the key or reopen before retrying a non-idempotent operation.

WriteBatch owns copies of every key and value:

API Parameters Effect
WriteBatch::new() None Creates an empty batch.
WriteBatch::with_capacity(capacity) Expected operation count Preallocates operation slots, but not key or value bytes.
batch.put(key, value) Byte-like key and value Appends an owned put operation.
batch.delete(key) Byte-like key Appends an owned delete operation.
batch.ops() None Borrows the ordered &[BatchOp] operation list.
batch.len() / batch.is_empty() None Reports the current operation count.
batch.clear() None Removes all operations while retaining the batch allocation for reuse.

Range and prefix scans

Keys are ordered lexicographically by raw bytes. Every scan captures a coherent point-in-time view. Creating one can freeze a nonempty active memtable, so frequent small scans may increase later flush work.

API Parameters Returns and allocation
range(start, end) Inclusive start key and exclusive end key Result<Vec<(Vec<u8>, Vec<u8>)>> ; eagerly allocates every returned key and value.
scan_prefix(prefix) Byte prefix; an empty prefix matches everything Eagerly collects all matching key/value pairs in order.
range_iter(start, end) The same [start, end) bounds Creates a RangeIter . Iterator items are Result<EntryGuard, ScanError> because corruption can be discovered while advancing.
scan_prefix_iter(prefix) Byte prefix Creates a PrefixIter , an alias of the same streaming implementation.

Advancing a streaming iterator is synchronous and may perform mmap reads, checksum validation, decompression, and cache locking. Drop it promptly: the iterator pins its snapshot readers and database-directory ownership.

Iterator or guard API Parameters Result
iter.count() None Consumes the iterator and returns Result<usize, ScanError> .
iter.keys() None Consumes the iterator and collects owned keys without materializing memtable values.
iter.collect_pairs() None Consumes the iterator and collects owned key/value pairs.
iter.paginate(offset, limit) Number of entries to skip and maximum entries to yield Returns a lazy iterator; skipped entries are traversed but their memtable values are not copied.
guard.key() None Borrows the key without loading the value.
guard.value() / guard.value_len() None Borrows the value, or reports its length; a memtable value is copied only when value() is first requested.
guard.into_pair() / into_key() / into_value() None Consumes the guard and returns the requested owned bytes.

Persistence, maintenance, and statistics

API Parameters Returns and cost
flush() None Result<()> . Drains pending writes, installs SSTables and the manifest, syncs the WAL, and reclaims eligible WAL segments. Writes that start concurrently may need a later flush.
compact() None Result<CompactionResult> . Drains the captured compaction scope and reports actual files, bytes, duration, reclaimed tombstones, and whether work remains.
status() None Cheap DatabaseStatus snapshot of maintenance failures, retries, and write backpressure.
logical_stats() None Exact Result<LogicalStats> for unique live keys and bytes. It scans physical versions and may perform I/O.
physical_stats() None Cheap PhysicalStats gauges and process-lifetime counters for the WAL, memtables, SSTables, cache, stalls, and amplification.
stats() None Deprecated mixed physical counters retained for source compatibility.
close() Consumes Db Flushes pending writes, stops maintenance, and releases ownership on success. Dropping Db is not a clean-shutdown guarantee.
close_with_status() Consumes Db The structured shutdown form; distinguishes storage errors from unresolved flush or compaction health.

Most database methods return DbError . Streaming iterator creation returns DbError , while failures discovered later are yielded as ScanError . The lower-level Engine and component configuration types are supported advanced APIs; their complete field and method contracts are in the crate documentation .

Benchmarks

The benchmark used TurboKV 0.6.0, fjall 2.11.2, and redb 2.6.3 over three repetitions. Throughput is acknowledged keys per second; higher is better.

Workload TurboKV Fast TurboKV Durable TurboKV Paranoid fjall Buffer redb Eventual
Sequential fill (1 key/txn) 2,989,537 1,774,574 213 485,252 1,397 (macOS barrier/txn)
Random fill (1 key/txn) 1,217,087 906,806 226 456,924 1,549 (macOS barrier/txn)
Overwrite (1 key/txn) 1,278,894 929,340 210 446,733 1,516 (macOS barrier/txn)
Sequential batch (100 keys/txn) 3,856,202 2,277,031 20,670 511,600 80,197
Sequential batch (1,000 keys/txn) 3,724,635 2,380,390 162,938 572,671 134,636

Fast disables the WAL. Durable writes a recoverable WAL record without syncing each acknowledgement to persistent storage. Paranoid performs that sync before returning; its single-key throughput is therefore bounded by storage-sync latency, while explicit batches amortize one barrier across many keys.

Protocol: 200,000 deterministic 20-byte keys, 400-byte values (84 MB logical input, above the 64 MiB memtable), one caller, atomic batches where shown, compression and block cache disabled, and an uncleared OS page cache. redb 2.6.3's Durability::Eventual performs a macOS F_BARRIERFSYNC for every transaction, while the TurboKV Recoverable and fjall Buffer modes stop at their process-crash-recoverable OS-cache boundaries. Batching amortizes that fixed redb barrier; its single-key rows are therefore architectural context rather than a like-for-like durability claim. Cross-engine settled timings are not compared.

Measured across 2026-08-28–29 with an Apple M4 ( Mac16,1 ), 32 GiB RAM, macOS 15.3.2 (24D81), APFS, and rustc 1.88.0. Exact raw repetitions, latency percentiles, dispersion, dependency versions, byte accounting, and amplification for the three TurboKV columns are in the mode JSON artifact and its text report . The fjall and redb columns come from the matching retained cross-engine artifact . The full methodology and rerun command are in benchmarks/README.md .

Friday Nite Videos | August 28, 2026

Portside
portside.org
2026-08-28 22:19:22
Friday Nite Videos | August 28, 2026 barry Fri, 08/28/2026 - 22:19 ...
Original Article

Friday Nite Videos | August 28, 2026

I Tracked Down the Company Ruining Fruit. Canadian Resistance Army | Lake Ontario. NYC's 5 Broken Skyscrapers — Which One Dies First? 9 to 5 Is More Relevant Than Ever | Full Documentary. Earth is Warming Everywhere Except Here.

Portside Portside

James Lawson Was the Civil Rights Movement’s Drill Sergeant

Portside
portside.org
2026-08-28 22:07:04
James Lawson Was the Civil Rights Movement’s Drill Sergeant barry Fri, 08/28/2026 - 22:07 ...
Original Article

Reverend James Lawson Jr did not attend the 1963 March on Washington for Jobs and Freedom. Most of the movement’s boldfaced names — the “Big Six” civil rights leaders, labor leaders and religious figures, celebrities and entertainers — were there, in front of a quarter million people up on the Lincoln Memorial’s marble steps. But Lawson was not. He was hundreds of miles away from the nation’s capital, organizing and training people at a regional gathering of Methodist student leaders in Upstate New York.

Lawson and his colleagues paused the proceedings so that anyone who wanted to board a bus to Washington early that morning could do so. “I had planned to go,” recalls Lawson in his landmark memoir, Nonviolent , “but we didn’t have enough room for every student who wanted to attend. I decided to give up my seat on the bus so that a student could go instead.”

Lawson deserves to be remembered as one of the black freedom movement’s greatest leaders. Those who knew and worked with him, as well as anyone who has delved beneath the surface of the movement’s history, understand just how important a figure he was. No less of an authority than Martin Luther King Jr himself considered Lawson “the leading theorist and strategist of nonviolence in the world.”

A Methodist minister whose Christian faith was thoroughly suffused with Gandhian principles, he trained a veritable army of activists in the philosophy, strategy, and tactics of nonviolent direct action. He had a hand in every major Southern civil rights campaign from 1958, when he moved to Nashville to begin his movement work, through the 1968 Memphis sanitation workers’ strike that claimed King’s life. He moved to Los Angeles in the early 1970s and was a central figure in the city’s labor and progressive movements until his death in 2024, at the age of ninety-five.

If Lawson is not as well-known as many of the people he trained — a group that includes the late John Lewis, among many others — the story of his absence from the March on Washington goes a long way toward explaining why.

“My role,” Lawson writes of the 1963 Birmingham campaign, “was to be the one who stayed on the outside to do the work of recruiting people, persuading more people to participate.”

This was his role not just in Birmingham but across the movement. He took raw recruits, fired by their determination to destroy systems of oppression, and forged them into disciplined militants ready to face down their oppressors, whatever the cost — up to and including death.

For Lawson, the problem with violence was not that it was too revolutionary, but that it was not revolutionary enough to change a society whose fundamental organizing principle is violence. James Lawson was the drill sergeant of nonviolence.

It is impossible to come away from Nonviolent without respect and admiration for a man who did more to advance the cause of human freedom than most. It should, one hopes, help Lawson receive the wider recognition he so richly deserves. Reading it is a morally and politically rewarding exercise, one that is enhanced by the compelling plainness of Lawson’s words.

It is also a challenge. In his foreword to the book, the scholar Eddie S. Glaude Jr admits that the call to nonviolence “remains a hard question for this country boy shaped by the raging ghosts of Mississippi.” Nonviolent underscores the immense difficulty, even the ultimate impossibility, of inspiring a universal commitment to nonviolence. Nevertheless, even if violence is, in some form or fashion, an inevitable aspect of the project of changing the world, Lawson’s memoir testifies to the enduring power of nonviolence as a regulative idea.

“There Must Be a Better Way”

N onviolent , which is skillfully assembled out of Lawson’s previous written and spoken work and interviews with his collaborator, Emily Yellin, chronicles his life in movements for social transformation. Because that work was indelibly grounded in his Christian faith, in many ways this is, as Glaude describes it, a spiritual autobiography.

Conversion stories have defined Christian devotional literature since St Paul was blinded by the light on the road to Damascus. Lawson didn’t have to convert to Christianity, like Paul, nor give up the pleasures of the flesh, like St Augustine. His father and grandfather were both Methodist ministers, and he appears to have been a constitutionally virtuous person from childhood. There is no evidence of a sex, drugs, and rock and roll period in James Lawson’s life. But there is a conversion story here, and it revolves around his precocious renunciation of violence as a means of confronting injustice.

The book begins with a stark declaration: “I smacked a white boy in his face when I was four years old.” Lawson was playing with this boy, who had been his friend, in the empty lots of Depression-era Massillon, Ohio. Then the boy started hurling racist taunts at him, suddenly and without provocation. “So I balled up my fist, reached back as far as I could, swung around with determination, and hit him in his jaw. Hard. Or as hard as a four-year-old could.” This was the first bout of a fighting career that lasted until he was nine years old.

Lawson’s Canadian-born father carried a pistol while ministering in the South and thought violent self-defense against racism was justified. His mother, an immigrant from Jamaica, did not.

One day, after proudly telling his mother how he slapped a boy who called him the n-word, she made a fateful intervention. “Jimmy,” she told him as she washed the dishes, “There must be a better way.” At this moment, according to Lawson, he had a “numinous experience,” a transcendental encounter with the divine that set him on his life course.

That’s when I began to hear another voice. I heard my mother’s voice at the same time. But the other voice rose up. I didn’t know where it was coming from. It resounded from a vast depth beyond her and beyond me, and yet was in my body. It seemed to go all through me. I realized later that it was my voice, but it was also a voice beyond myself. It said, “You will never fight in this way again. You will never do that again.” It didn’t say, “You might do it again.” It said, emphatically, “You will never do it again.” That experience stayed with me for every day of my life.

Secular readers may find it difficult to take this at face value. But considering the thoroughly spiritual character of Lawson’s upbringing, there’s little reason to doubt he really experienced it.

By high school, Lawson had concluded that biblical injunctions against violence “contained the seeds of a resistance movement. They were not acquiescent or passive.” His spiritual and intellectual development led him to Baldwin–Wallace College, a Methodist campus outside Cleveland, where he encountered the ideas of Christian pacifist radicals like A. J. Muste and Bayard Rustin and, most important, Mohandas K. Gandhi.

Together with black and white comrades, Lawson challenged racial discrimination on campus and in town, and in 1949, he decided to send his draft card back to the Selective Service System in a bold act of civil disobedience. After two years of bureaucratic inaction, FBI agents came to his family home in Massillon and arrested him for failing to report for military service.

Lawson was sentenced to three years in federal prison but served thirteen months. The time behind bars solidified his commitment to Gandhi’s teachings and stoked a “driving fire of Christian adventure and daring” in him. The Methodist Church negotiated his early release, and to Lawson’s “great delight,” the terms of his parole compelled him to leave the country for missionary work abroad. Though he suffered in the penitentiary, Lawson came out more defiant and more committed to nonviolent revolution than he was before he went in.

“It wasn’t until after my time in prison,” Lawson writes, “that I truly believed in the deepest parts of my heart that all humans were created equal and endowed with inalienable rights, and that loving my neighbor was the way to live.”

James Lawson in 2005.

James Lawson in 2005. ( Joon Powell )

Lawson missed the March on Washington, and he missed the Montgomery bus boycott too. When the Montgomery movement kicked off, Lawson was teaching English and coaching sports at a school in Nagpur, India, while deepening his immersion in Gandhian philosophy, strategy, and tactics. One morning in December 1955, he picked up the morning paper to see news of the boycott splashed across the page. “I was so elated to read the news,” Lawson writes, “that I started clapping my hands, and jumping and shouting.”

When a neighbor checked to see what the commotion was about, Lawson “showed him the paper and told him how important this was, because I had been hoping and dreaming that such a movement could be possible in America and would start one day soon.” It had, and Lawson quickly came to regard its leader, a young Baptist minister named Martin Luther King Jr, as his Moses.

After a whirlwind trip through an African continent stirring to revolt against colonialism, Lawson returned to the United States in September 1956. He wanted to pursue a PhD in divinity before joining the Southern movement, so he began graduate studies at Oberlin College in Ohio. But when he met King at Oberlin, Martin implored him: “Come now. Don’t wait. Come as quickly as you can. We need you now.” Lawson’s best-laid plans couldn’t withstand the power of this appeal. “I looked him in the eye and quietly said, ‘I will come as fast as I can.’”

The Making of Nonviolent Revolutionaries

L awson had two big things going for him. He was an ordained minister, which meant he would complement a movement rooted in the church and led by clergy. Just as important, he was already recognized as an authority on Gandhian nonviolence and could impart his knowledge to a movement that was still finding its way forward. A. J. Muste offered to hire him as the Fellowship of Reconciliation’s Southern secretary, and he moved to Nashville to begin his work in early 1958.

In Waging a Good War , the journalist and military historian Thomas E. Ricks contends, justifiably, that “Gandhi’s impact on King and the Movement, both directly through his writings and indirectly through American followers . . . probably has been underestimated, even now.” Perhaps this is because of a lingering misunderstanding of what Gandhian nonviolence really entails.

As Lawson explains, the Gandhian term for nonviolence, ahimsa , was originally translated into English as “passive resistance,” a formulation that Gandhi himself rejected as misleading. Ahimsa finds practical expression through satyagraha , which means “love force” or “soul force,” and takes the active form of civil resistance to unjust laws — boycotts, strikes, marches, demonstrations that disrupt the course of everyday life. The historian David L. Chappell describes Martin Luther King Jr as a “ strategist of force ” who aimed “to coerce [powerful white people] to give up privileges against their will,” not to appeal to the better angels of their nature. Nonviolence entails protracted mass struggle, and as Lawson emphasized in his book Revolutionary Nonviolence , “protracted struggle is a moral struggle that is like warfare, moral warfare.”

Like soldiers going to war, nonviolent militants aren’t simply flung into the fray. They receive training and preparation; they go to boot camp. “Nonviolent soul force preparation” in the Southern civil rights movement, Lawson contends, “was even more rigorous than training for violent military action. In fact, Gandhi’s soul force would not have succeeded without extensive practice, deep commitment, and strategic planning.”

This may sound like an exaggeration, but the comparison is an apt one. Very little about the movement was spontaneous or unprepared. When it was, this was typically a sign that something was going wrong.

The fight to desegregate Downtown Nashville was Lawson’s first major campaign, and it’s the textbook example of a Gandhian campaign à la Lawson. It begins with fact-finding, and in Nashville this entailed “investigat[ing] and mak[ing] a sort of laundry list of the plights and tortures Black people faced” in the city. For nearly half a year beginning in January 1959, Lawson writes, “we simply sought out descriptions of all the separate manifestations of racism and segregation that were hurting Black people and the community.” They identified many problems during this process, but one theme began to stand out: the indignities black residents faced while working and shopping in the city’s downtown business district.

Only the most menial jobs were available to black workers; “Whites Only” signs designated zones of exclusion at every turn; black shoppers — most of whom were women — had nowhere to rest their feet or have a cup of coffee while on their rounds. Lawson recounts the blunt testimony of one woman: “You preachers and our husbands do not know the pain of having to shop downtown for our family. We do your shopping for you, so we’re the ones who bear the brunt of the racism, of the segregation in Nashville.”

Armed with the facts, the movement could move on to battle planning and training. Instead of making segregation in general their target, they chose a specific expression of it: racial discrimination in department store restaurants and lunch counters. They recruited young people to their ranks “because they can be shaped and formed,” Lawson writes, “And I felt . . . that we were building a nonviolent army. Young people would be the ones most available to go through constructive training in nonviolent direct action.”

Local clergy had already been recruiting high school and college students to the movement, and they would soon assemble a remarkable cadre of young militants including Marion Barry, James Bevel, Bernard Lafayette, John Lewis, and Diane Nash, each of whom became brilliant leaders and strategists.

“Out of its initial small group of about forty or fifty students,” Ricks writes in Waging a Good War , “grew a cadre of people who would become a major force in the civil rights effort — first the sit-ins, then the Freedom Rides, then in forming the Student Nonviolent Coordinating Committee (SNCC), then in the Birmingham marches, and finally in Selma.” James Lawson trained them all.

Lawson’s training combined intensive education in the philosophy and history of nonviolence with role-playing and other methods intended to prepare recruits for what amounted to combat situations. Role-playing exercises were often intense.

He would have trainees pair up in twos, for example, and have them act out the kinds of scenarios they could expect to encounter in the field. One partner would play the part of a black person minding their own business, while the other played a racist white assailant. The latter would hit and slap and hurl racist insults, while the former had to respond in a strictly nonviolent fashion — no physical retaliation, no insults returned in kind.

“The point of the role playing,” Lawson writes, “was to think about how to respond to the violence. . . .  People would talk about it and evaluate their experiences. They were to figure out, ‘If this happens to me on Church Street in Nashville, how will I react? If that happens to me when I’m at a sit-in what does it mean? How do I respond?’” The exercises gave them space to think through an incident in the abstract before it became a reality, where they might be blindsided and not know what to do.

The training didn’t always take, and depending on the audience, Lawson’s deep religiosity could backfire on him. Lawson notoriously failed to connect with many white Freedom Summer recruits in 1964, for example.

“I think I did a poor job in conveying to those students,” he recalls, “the importance of the commitment to nonviolence in our movement. And because I was a minister, it stirred the students’ skepticism of religion, and even their ridicule.”

Some recruits dropped out. Others were weeded out if leaders thought they couldn’t handle what was in store for them. But the recruits who made it through months of rigorous training in Lawson’s workshops were ready to face the prospect of great suffering, even death, together.

After nearly a year of preparation, the Nashville movement launched a sit-in movement to desegregate Downtown Nashville in February 1960. It was not an easy campaign. Militants suffered shocking violence at the hands of white police and civilians; white politicians and media outlets vilified the movement as the work of communists and “outside agitators”; Lawson was kicked out of Vanderbilt University, where he had been pursuing a graduate degree in divinity. They faced criticism from the black establishment, particularly the National Association for the Advancement of Colored People, which opposed the Southern sit-in movement for its supposedly reckless tactics.

For Lawson, the campaign wasn’t only an attack on the white power structure but a criticism of traditional black leadership as well. “The sit-in movement and the whole nonviolent movement for social change,” Lawson contends, “was a statement to the Black community that we did not have to settle for this evil.”

On February 27, 1960, several sit-in participants in Nashville, including Paul Laprad (pictured), were attacked by onlookers.

On February 27, 1960, several sit-in participants in Nashville, including Paul Laprad (pictured), were attacked by onlookers. ( The Tennesseean )

Despite beatings, bombings, and brickbats, the Nashville movement won. After three months of sit-ins, boycotts, and demonstrations, the city’s downtown merchants agreed to start serving black customers equally. No more “Whites Only” signs, no more having to buy shoes and take them home just to try them on. Poverty, employment discrimination, and a host of evils remained. But the Nashville movement and parallel efforts across the South showed that nonviolent direct action could overcome the imposing but vulnerable structures of Jim Crow.

For Lawson, Nashville was “the pivotal movement for the rest of the sixties, because many of us became the staff people, the volunteers, and the foot soldiers” in the Freedom Rides, the battles of Birmingham and Selma, and other key campaigns. Lawson’s assessment is no idle boast. John Lewis became SNCC’s chairman, led the first march over the Edmund Pettus Bridge in Selma in 1965, and went on to serve in Congress for decades. James Bevel and Diane Nash, who became a couple during the Nashville sit-ins, became two of the movement’s most effective and audacious strategists, especially during the Birmingham and Selma campaigns (their marriage, unfortunately, did not survive the strain of protracted movement work).

Lawson kept training waves of new recruits to the movement’s ranks, and he chaired the 1968 Memphis sanitation workers’ strike strategy committee. He wasn’t always successful, and his mistakes in Memphis pulled King deeper into the strike — and deeper into harm’s way — than anyone intended. Nevertheless, Lawson’s work in forging disciplined groups of nonviolent revolutionaries was indispensable to the fight against racial segregation.

“Cohesion was the ineffable but essential ingredient the Nashville contingent possessed,” Ricks concludes. “Developing it was perhaps the greatest contribution James Lawson made to the civil rights movement.”

Holding the Tension

N onviolence, particularly in the philosophically totalizing form Lawson embodied, was never universally embraced in the movement. Some accepted it conditionally and pragmatically, so long as it seemed to work when nothing else would. Others rejected it entirely and justified the use of violence as a means of self-defense or collective liberation.

King, for his part, did not come into the movement as a fully formed apostle of nonviolence. When Bayard Rustin realized King had a small arsenal in his house during the Montgomery bus boycott, he talked him into getting rid of his guns. According to Chappell, Rustin convinced King that leaders must be committed to nonviolence in principle, “since ‘if, in the flow and the heat of battle, a leader’s house is bombed, and he shoots back, that is an encouragement to his followers to pick up guns.’” King’s house was, in fact, bombed during the Montgomery campaign. He was not home at the time, but his wife, Coretta Scott King, and one of his children were; they were very fortunate to survive the blast. Some of King’s supporters wanted to retaliate or post armed guards at his house, but he refused on the grounds that this would distract from the question at hand, which was not his personal safety but the freedom of black people in Montgomery.

While King committed himself to principled nonviolence under Rustin’s tutelage, he admitted that not everyone could be expected to adopt the same rigorous standards. In “ The Social Organization of Nonviolence ,” a 1959 polemic with the outspoken advocate of armed self-defense, Robert F. Williams, King conceded that “the principle of self-defense, even involving weapons and bloodshed, has never been condemned, even by Gandhi, who sanctioned it for those unable to master pure nonviolence.” In “ Nonviolence: The Only Road to Freedom ,” written in 1966 amid a rising tide of urban unrest, King wrote that “it goes without saying that people will protect their homes. This is a right guaranteed by the Constitution and respected even in the worst areas of the South.”

Martin Luther King Jr, photographed during a meeting at the White House in 1966.

Martin Luther King Jr, photographed during a meeting at the White House in 1966. (Yoichi Okamoto / Executive Office of the President of the United States)

In Nonviolent , Lawson recounts an illuminating episode from the 1966 March Against Fear, the Mississippi demonstration where Kwame Ture (then known as Stokely Carmichael) launched the “Black Power” slogan before a national audience. According to Lawson, some young Student Nonviolent Coordinating Committee (SNCC) marchers wanted to tussle with white racists who were harassing them on the march route. “Their guiding principle,” Lawson recalls, “was that you couldn’t let yourself be pushed around”:

Again, we had to say, “Look. We have children and women here. And there are some very old people. Now, if you want to make an appointment with these guys afterward, well and good. But you are in a demonstration now, and you don’t have a gun and that policeman has a bayonet and these children don’t have any such protection. So, you’ll put everyone in jeopardy.” These guys were confusing self-defense with the responsibility you have when you are part of a public demonstration.

King and Lawson, despite their principled commitments to nonviolence, could make pragmatic distinctions between the collective discipline they thought mass demonstrations required and what individuals could do on their own time, as it were. What is permissible in private life may not be good for a public movement; what may be forgiven of a rank-and-filer may not be allowed for a leader. Context matters, for both moral judgment and strategic calculation.

Some of the most vivid scenes in Lawson’s memoir concern internal frictions over nonviolence, especially when he and Ture were at loggerheads. Ture often appears as Lawson’s symbolic foil in the book; an embodiment of trends that Lawson feared would render the movement marginal and ineffective.

Nevertheless, despite his deep disagreements with figures like Ture, Lawson writes that he “would not denounce Black Power, and neither would Martin — because we understood what it was about.” In Where Do We Go From Here , King writes that the Black Power slogan “was born from the wounds of pain and disappointment,” a predictable and understandable “reaction to the failure of white power” to recognize the humanity and equality of African Americans despite the passage of landmark civil rights and voting rights legislation.

In “The Social Organization of Nonviolence,” King conceded “it is unfortunately true that however the Negro acts, his struggle will not be free of violence initiated by his enemies.” Lawson reached a similar conclusion: “Nonviolence and violence have a similarity. Those who practice either must be prepared to do some suffering.” A realistic appraisal of the human condition compels us to admit that some degree of violence, often instigated by those who seek to preserve their power and privileges, will attend any movement for social transformation.

Viewed from this perspective, the simple dichotomy of violence versus nonviolence begins to break down, and the issue takes on new dimensions. In his 2022 book, The Revolutionary City , Mark Beissinger writes that the question is not “ whether revolutions are violent, but rather how much violence they involve and what explains that variation.” We also need to ask what exactly we mean by violence in the first place.

The coauthors of On Revolutions , a 2022 state-of-the-research summary of the field, concede that “categorizing revolutionary struggles as either violent or nonviolent can be problematic since movements often have fluid and flexible strategic approaches, shifting between armed and unarmed phases.” Distinguishing between armed and unarmed movements doesn’t, on its own, solve the dilemma either. Unarmed movements can and do employ tactical repertoires that blur the lines between violence and nonviolence.

“Some unarmed uprisings,” they write, “have moments when civil resisters destroy property such as military vehicles or police stations. Is this violent or nonviolent? While some consider such acts to be violent, others argue that a tactic is violent only if it harms or endangers life.” This is why some scholars of revolution employ the concept of “unarmed violence” to distinguish rock throwing or rioting from armed combat, and to try to isolate the impact of these tactics on largely nonviolent movements.

The focus here is often on “violent flanks” and how they affect the mechanisms of movement success or failure. The political scientist Erica Chenoweth defines this as violence that “remains exceptional within the broader repertoire of contention” and therefore does not entail a full shift from unarmed to armed struggle. Chenoweth’s review of the literature finds that “organized armed resistance alongside primarily unarmed resistance campaigns appears to yield few long-term strategic benefits for mass movements.” The same cannot be said, however, for unarmed violence, whose effects on movement outcomes appear to be much more ambiguous and case-dependent.

It is possible that the key strategic choice movements face is not whether to adopt the kind of strict nonviolent discipline Lawson embodied, but whether to remain unarmed. “Some portion of the positive effect of nonviolent tactics on democratization campaigns,” Mohammad Ali Kadivar and Neil Ketchley conclude , “may in fact be attributable to episodes of unarmed collective violence.”

The mechanisms by which property destruction and other acts (or threats) of violence can boost nonviolent movements are not entirely clear, but inferences can be drawn from the history of the black freedom struggle. The historian Peniel Joseph , for example, has described Malcolm X and King as the movement’s sword and shield, respectively. In this framework, the Black Power and self-defense flank complements and strengthens the main nonviolent thrust. Negotiate with Martin, or you’ll have to deal with Malcolm; give us the ballot, or you’ll get the bullet.

There is some evidence to support the logic of this theory, like a 2022 study that found “the presence of a radical flank can increase identification with and support for a moderate faction in the same social movement.” These findings, however, were based on survey experiments, not an analysis of real movements; as Chenoweth notes, it “may be difficult to extend these findings to political environments” where actors and observers “do not actively try to differentiate between radical and moderate tactics.”

This is especially true when movements, regardless of their strategies and tactics, are based primarily on racial minorities or other out-groups subject to unfavorable media treatment and systematic social bias. King, who spoke consistently of the need for love and reconciliation, was nevertheless one of the most widely hated people in America at the time of his assassination.

Martin Luther King Jr and Malcolm X meet before a press conference in Washington, DC, on March 26, 1964.

Martin Luther King Jr and Malcolm X meet before a press conference in Washington, DC, on March 26, 1964. ( US News & World Report / Library of Congress)

It is extremely difficult to disentangle these threads in the context of very messy, actually existing social movements. The effects of unarmed violence on primarily nonviolent struggles appear to be, as Chenoweth suggests in their review of scores of studies, essentially simultaneous and contradictory.

Nineteen sixty-seven’s wave of urban riots, for example, spurred President Lyndon B. Johnson to form the Kerner Commission , whose recommendations for action might as well have been written by King or Rustin. If implemented in full, it would have amounted to the establishment of a racially egalitarian social democracy in the United States. Of course, that never happened.

The uprising of the black poor made the problems and the solutions as clear as day. For a brief moment, it focused attention on the stark fact that “our nation is moving toward two societies, one black, one white — separate and unequal,” as the commission warned in its best-selling report. At the same time, it exacerbated already existing divisions within the movement, which could not prevail upon an administration that ran away from its own commission’s findings as soon as they were published. It also fed into the tide of law-and-order reaction that helped to put Richard Nixon in the White House in 1968.

Nonviolence ultimately seeks to reconcile means and ends in the struggle for social transformation. “Means and ends must cohere,” King insisted in his last Christmas sermon , “because the end is preexistent in the means, and ultimately destructive means cannot bring about constructive ends.”

One may object that massive quantities of violence were needed to destroy Southern chattel slavery or defeat the Nazi menace. True enough. But the tendency of armed revolutionary movements to result in authoritarian governments when they win power is a point in favor of the nonviolent wager. Armed movements, by virtue of the violence and secrecy they entail, impede mass participation and rely on undemocratic organizations that do not prepare people for the exercise of collective self-rule. Political violence has an interactive quality that often takes on a life of its own. It’s not something that can easily be turned on and off, and it can easily outstrip its original justification.

Lawson was convinced that nonviolence “gives the right a far better chance of emerging” from political struggle than violence of any kind. Not a guarantee, but a chance. Given the sheer inertia weighing against the “beloved community” King envisioned, Lawson’s faith in the revolutionary power of nonviolence may well be naive. But as Chappell so incisively puts it, “to believe that anybody’s plan will ever be fulfilled after the shooting starts — that anyone will be able to avoid tragic disappointment in the course of violent revolution and war — is a more obvious and straightforward naïveté.”

“Nonviolence understands clearly that the system is violent,” Lawson writes, “especially when the structures of the system force people to live with torturous oppression.” If the experience of oppression cannot find an effective outlet through nonviolent action, it will eventually explode. “That is why potential violence against a violent system is not something you denounce. It’s also not something you embrace.” Holding that tension is perhaps the most practical thing one can take away from Nonviolent . It is also the hardest one to master.

Jacobin contributing editor and a member of Democratic Socialists of America.

Jacobin is a leading voice of the American left, offering socialist perspectives on politics, economics, and culture. The print magazine is released quarterly and reaches 75,000 subscribers, in addition to a web audience of over 3,000,000 a month. Subscribe to Jacobin magazine.

Stephen Miller Embodies the Dark Fascist Heart of Trump’s White House

Portside
portside.org
2026-08-28 21:52:48
Stephen Miller Embodies the Dark Fascist Heart of Trump’s White House barry Fri, 08/28/2026 - 21:52 ...
Original Article

Following Rubio to the podium, Miller delivered various—and sometimes unsettling—amplifications on that theme. After an opening passage declaring that under President Trump’s leadership, “We have taken the necessary and essential action of formally recognizing left-wing violence as a form of political terrorism that is a direct threat to our national security and the survival of our republican form of government,” Miller went on to proclaim that “for the first time in American history,” all US law enforcement and intelligence agencies are working together “to disrupt, identify, defund, debank, arrest, and prosecute these political terrorists that are operating in our country.” Then, in one of many questionable passages, he went on with an implied suggestion that the authorities should reject suspected terrorists’ claims of their legal rights. Miller put it this way:

One of the hallmarks of left-wing violence and terrorism is its completely pretextual and disingenuous appeal to civil liberties in an effort to shield its own violence. This is the tactic that the left always uses to try to protect itself from facing criminal punishment. It is essential that we are wise enough and strong enough to understand that these appeals must fall on deaf ears. When the leftist, who does not believe in freedom, who does not believe in civil rights , who does not believe in any ordered notion of justice, protests that we are violating his rights, understand that he is lying to try to persuade people who are not closely following the political scene that some injustice has been perpetrated against him.

That doesn’t quite say explicitly that a person accused of left-wing terror does not have the same rights that other criminal defendants have in US courts—but it is hard to read Miller’s words in any other way. (The following speaker, Secretary of the Treasury Scott Bessent, sounded a very different tone, declaring that “in the fight against domestic terrorism, we must respect the constitutional rights, freedom of speech, association, and assembly of all Americans... the Treasury will act based on suspected unlawful conduct by these terror organizations, not because of their beliefs or ideologies.” I have no way to know whether those words were in Bessent’s prepared text or if he was directly responding to Miller’s statement, but in either case they may have brought some relief to listeners who value the rule of law .)

At another point in his speech, Miller falsely told his listeners that Immigration and Customs Enforcement (ICE) officers have experienced an “8,000% increase in violent assaults,” adding that “these are not one-off episodes. This is repeat, systemic, organized, funded insurrection, an armed resistance against the federal government.” Miller’s figure is contradicted by the Homeland Security department’s own public statements. In January, the department reported that threats to ICE personnel, not actual assaults, had risen by 8,000% in the previous year, while violent attacks had gone up by “more than 1,300%”—less than one-sixth of Miller’s alleged increase. That lower figure may have been overstated too, as indicated by a Los Angeles Times investigation of court records in LA and four other cities (San Diego; Portland, Oregon; Chicago; and Washington , DC). More than a third of the cases they reviewed ended in dismissals or acquittals, the Times reporters found, and a majority of the alleged assaults had not caused any injury to the federal agents involved.

A few minutes later, Miller raised a quite different and somewhat peculiar issue: “When you look at these violent antifa demonstrations and you see any photograph of those who were assembled—to be blunt, not one of the people that is demonstrating looks like a normal person. Not one looks normal. They’re all deformed in some way—in their appearance, in their dress, in their mannerism... If you look at two photographs and you see a normal American in the street and you see an Antifa protest , why do the people that are violently demonstrating—why is there not one normal-looking person among them?” Miller did not explain exactly what he finds odd in the protesters’ appearance—and unlike most of his talking points, that one seems to be uniquely his, not one commonly heard from others in the Trump orbit.

In another questionable passage, Miller claimed that the phenomenon of “jury nullification” has regularly enabled leftist terrorists to escape conviction for their crimes. He explained the term this way: “This is when a person is obviously guilty of a crime but the juror, because they’re ideologically sympathetic to the perpetrator, will not sentence them to the crime which was obviously committed,” adding, “We’ve seen in the United States , again and again, individuals who are part of left-wing organizations who’ve committed assaults against ICE officers or federal law enforcement, who’ve been brought to court, where clear evidence has been presented against them, that the jury has refused to convict for purely political reasons.”

Miller gave no examples and cited no facts to support the implication that persuading jurors to acquit guilty defendants has been a deliberate tactic employed by leftist organizations. In past statements, he has explicitly cited at least one specific case: the acquittal last December of a Los Angeles tow-truck driver who was arrested after moving an ICE vehicle while the officers were arresting a suspected illegal immigrant. The defendant, Bobby Nunez, was charged with stealing federal government property, an offense punishable by up to 10 years in prison. At his trial, his lawyers argued that the ICE agents’ SUV was blocking a driveway, that Nunez towed it only one block away, and that it was out of the agents’ possession for just 13 minutes.

Without having heard their deliberations, we have no way to know how the jurors reasoned in reaching their not-guilty verdict, if that decision stemmed principally from opposition to ICE operations and Trump’s immigration policies, or if they based their conclusion on other grounds, perhaps that the charged offense was disproportionately severe and the possible penalty unfairly harsh. Stephen Miller wasn’t in the jury room either, but he showed no visible uncertainty when he denounced the verdict as “another example of blatant jury nullification in a blue city.” From there he went off in another direction: “The justice system depends on a jury of peers with a shared system of interests and values. Mass migration tribalizes the entire legal system”—a comment that it’s hard to see as anything but an argument that people with the wrong ethnic identity are not legitimate participants in America’s justice system.

Incidentally, nothing in any of the news stories I read about that trial gave any indication that Nunez was connected with any “left-wing organization.” Nor did photographs of him show anything obviously “not normal” or “deformed” in his appearance (unless those words apply to anyone who doesn’t look like a non-Hispanic white man).

Miller said nothing in his State Department speech about a different issue that has undermined far more cases than any real or imagined political bias in juries—findings by numerous judges that law enforcement agents and government lawyers prosecuting supposed antifa activists and other protesters have crossed legal or ethical boundaries, misrepresenting facts and exaggerating or completely fabricating criminal charges.

That pattern is documented in a recent report by the investigative journalism organization ProPublica. Their reporters reviewed hundreds of case records and found numerous comments from federal judges criticizing “unlawful,” “unethical,” and “unseemly” government actions. Specific abuses cited by judges included findings that “the government filed statements generated by artificial intelligence that referenced nonexistent case law, wrote briefs that ignored facts, and filed declarations with inaccurate dates.”

(One striking example is from a judge’s decision granting a petition from a man seeking release from ICE detention. In her opinion memorandum , the judge noted that ICE and Homeland Security department officials had submitted a document “purporting to show” that the man had a record of “minor convictions for marijuana possession in 2009.” The judge went on: “The Petitioner was four years old in 2009, and the Respondent indicated that the document was supplied by ICE and likely presumed to relate to the Petitioner because the individual in those records had the same name, despite the differences in birthdate, birthplace, parents’ names, and immigration status. This sloppiness further validates the Court’s concerns about the procedures utilized by the Respondents depriving people present in the United States of their liberty.”)

It was no surprise that Miller did not mention prosecutors’ failings in his speech, since that would have been inconsistent with the message he was delivering. Theoretically, it’s not categorically impossible that he has been more candid in private conversations with Trump—after all, presidential advisers, particularly on national security issues, are expected to provide unwelcome truths and not just say things their boss wants to hear. If we don’t know what was said or not said in meetings that were not disclosed to the public, we can’t judge with absolute certainty how straightforwardly Miller might have spoken in those discussions. But numerous reports of his public statements over the years reveal a consistent pattern of misrepresented facts and policy ideas even more virulent than Trump’s, making it virtually impossible to believe that his advice in private has been significantly more balanced or rational than what he has said in public over the years.

The “Ministerial on the Resurgence of Political Terrorism” did not get much media attention, perhaps because it did not produce very much new information substantiating the premise that “left-wing terrorists” are linked in a far-reaching multinational conspiracy that is now the most urgent danger facing the United States and the international community. Stephen Miller’s 16-minute speech did not present any facts or ideas that have not been heard many times before, so it didn’t make many headlines either. But it is newsworthy for a different reason—an unintentionally revealing survey of the Trump team’s violation of basic legal principles, endangering the rule of law, and its consistent record of falsehoods, endangering public trust in the national leadership. Those two trends represent a clear and present threat to human rights and democratic government in this country, and should be spotlighted at every opportunity while we can still report and resist them.

Arnold R. Isaacs, a journalist, and writer based in Maryland has written widely on refugee and immigration issues. He is the author of "From Troubled Lands: Listening to Pakistani and Afghan Americans in post-9/11 America" and two books relating to the Vietnam war. His website is www.arnoldisaacs.net .

Common Dreams is a reader-supported independent news outlet created in 1997 as a new media model.

Our nonprofit newsroom covers the most important news stories of the moment. Common Dreams free online journalism keeps our millions of readers well-informed, inspired, and engaged.

We are optimists. We believe real change is possible. But only if enough well-informed, well-intentioned—and just plain fed up and fired-up—people demand it. We believe that together we can attain our common dreams.

Gary, Indiana, Is America’s Latest Climate Victim

Portside
portside.org
2026-08-28 21:52:18
Gary, Indiana, Is America’s Latest Climate Victim Judy Fri, 08/28/2026 - 21:52 ...
Original Article

GARY, INDIANA – Ruben Chavez was in an elevator at his high-rise apartment in Gary, Indiana, on August 11, when severe storms knocked out the power. He got stuck between the fourth and fifth floors, and according to a staff member who helped retrieve him, workers at the building called 911, operated by Lake County, but nobody answered. So security and maintenance staff rescued Chavez themselves. “The security and maintenance guy came around and they brought me a ladder,” he told me as he sat near the entrance to the Park Shore Commons, where the power was out for a total of 12 days. “I had to get on my belly and slide down. They guided my feet on the ladder.”

The building’s power was restored on August 22, but on August 26 when I visited, the complex reeked of rotten food, which had spoiled when refrigerators stopped working. World Central Kitchen, a humanitarian organization, was still stationed outside delivering food to the residents. Chavez’s problems did not stop with the elevator incident. He relies on insulin that needs to be refrigerated, an impossibility while the power was not working. And with the elevators out, going up and down the stairs was challenging for him, as it was for a handful of other residents at the building. “If I needed to take something up, I needed my backpack, my cane,” he told me. “I’m grabbing the handles of the stairwells and just taking it as easy as possible.”

The power is finally coming back on in Gary, though when I visited hundreds were still without. Stories are unearthing about the squalid—and sometimes dangerous—conditions that residents were forced to endure during outages that lasted up to two weeks. About 80 percent of Gary’s 69,000 residents are Black, and around a third live in poverty, the result of more than half a century of deindustrialization, disinvestment, racial segregation, and bank redlining.

The crisis , and the slow pace of power restoration, has shone a light on institutional neglect of this community, made worse by human-made climate change. Studies show that the tornadoes, thunderstorms, flooding, and heavy winds that tore through Northwest Indiana starting on August 11 will grow more frequent and severe as global temperatures warm.

“Gary, for all of the hardship and suffering that the people there have experienced, is another clear data point for a phenomenon we’ve seen since at least Hurricane Katrina more than 20 years ago,” said Patrick Bigger, research director for the Climate and Community Institute, a think tank. “When extreme weather turbocharged by burning fossil fuels hits, it disproportionately impacts working-class people and people of color as a result of inequality exacerbated by structural divestment from their communities.”

THE SEVERE STORMS THAT SWEPT THROUGH INDIANA killed at least eight people, and left 363,398 homes and businesses in Northwest Indiana without power. Gary was just one of numerous cities and towns to get hit; the surrounding Lake County had a 95 percent outage rate, according to Gov. Mike Braun. Roads were closed, power lines were downed, trailers and cars were destroyed, hundreds of buildings were damaged, and a bridge in the area collapsed .

By the time I visited, debris and felled trees still littered the city, and cleanup crews were hard at work. I saw large fallen trees on collapsed roofs, and an uprooted tree in front of William A. Wirt High School, one of Gary’s numerous abandoned schools. I talked to one worker who is a member of IBEW Local 222 and traveled here from Jacksonville, Florida, to work 16-hour days as a contractor for the Northern Indiana Public Service Company (NIPSCO) restoring power to people’s houses. “There’s a lot of devastation here, and it’s sad to see messed-up roofs, cars,” he told me.

NIPSCO is a monopoly utility, under the umbrella of the company NiSource, and charges the highest rates of any electrical utility in Indiana. Blackstone, a private equity company, “has owned roughly 20 percent of NIPSCO since 2024 and has a senior managing director on NIPSCO’s board,” according to Matt Parr, communications director for the Private Equity Stakeholder Project. A 2023 report from the Private Equity Stakeholder Project finds that, even before its involvement with NIPSCO, Blackstone performed poorly in wage and hour violations, and “led in total reported OSHA violation fines” out of 11 of the largest private equity employers. (Last spring, NIPSCO locked out 1,600 workers hailing from United Steelworkers Locals 12775 and 13796 in northern Indiana for more than a month.)

“With that level of involvement in an essential utility, customers deserve to know how Blackstone’s pursuit of the high returns it generates through its infrastructure investments will affect long-term spending on workers, maintenance, and reliability,” Parr added. “This storm didn’t create those questions, but the prolonged outages have made them impossible to ignore.”

Pastor Michael Watson stands in the parking lot of the Tree of Life Missionary Baptist Church in Gary. Sarah Lazare.

A class action lawsuit filed in Porter County by the Allen Law Group alleges that NIPSCO failed to adequately trim trees near power lines, leaving consumers vulnerable to the power outage. The lead plaintiff, Jack Tipold of Valparaiso, was in the middle of dental surgery when the power went out. On August 24, Gov. Braun called for the state’s consumer advocate to press for an investigation into NIPSCO. Carolyn McCrady, a co-founder of Gary Advocates for Responsible Development, an environmental justice organization, told me she is worried that the utility is planning to finance its cleanup with more rate increases.

Gary Mayor Eddie D. Melton and Gov. Braun have also been calling on the federal government to unlock more aid. The governor issued a statement on Tuesday that President Trump had approved his “request for a major disaster declaration” for multiple counties, meaning “millions of federal dollars will now be available,” but he did not provide an exact figure. Braun has estimated damages could be up to $5 billion, and I spoke to some residents who say the governor is not doing enough to tap into the state’s nearly $4 billion reserves. “It’s a kind of state where working-class people are not represented in policy or decision-making,” said McCrady, who spent hours showing me around the city.

Yet it’s working-class people who suffer most during unprecedented blackouts. Pastor Michael Watson was standing in the parking lot of the Tree of Life Missionary Baptist Church in Gary. He told me, “When the electricity goes out, you lose a lot of assets that you’re normally accustomed to having day-to-day. Even for those who have a basement, you got the sump pump that goes out. Now the basement gets flooded with water, smells like sewage. The refrigerator goes out. Food that you have bought is now spoiled.”

“And then when the electricity goes out … things start to compound,” he continued. “Now you’re trying to find money to have a generator. If you don’t have a generator, you’re trying to find a way to keep cool. But it’s hard to keep cool when there’s no ice around in the house. Then you have to try to get gas for your car. So now the gas stations are packed up because everybody is trying to get gas to run generators.”

For people who are already stretched thin, the financial hit is devastating, said Watson, who, unlike McCrady, was not critical of the governor, though he did express concern about the slow response to the crisis. “You’re trying to survive two weeks with no money like that. You’re going to run out, and now you’re sitting there trying to stand in line in food banks for three to four hours with your children,” he said. “You can’t send them off to school, because the schools don’t have any power, so things just start to compound and start playing a toll on your mental health, your physical health. You cannot get meds, you cannot afford medicine.”

Cassandra Mosley, also at Tree of Life, normally uses Supplemental Nutrition Assistance Program benefits to help feed herself and her young son. But because the power was out, it wasn’t possible to process electronic benefit cards, she explained. “A lot of us had just got food stamps probably a week or two prior, so when this situation happened, we lost a lot of groceries,” because refrigerators stopped working, she said. She was eventually able to get hers by filling out an affidavit “to let them know that I lost all my power.” But others, she said, haven’t been able to access this benefit, a fact I confirmed with a gas station attendant, who described turning away people with EBT cards.

To help cover food during the storm’s aftermath, she said, “I was able to come to the church, and our church was able to be a blessing to us and help us.” According to Pastor Watson, the church has fed “over 5,000 families.”

AT THE SERENITY LAKE INDEPENDENT LIVING COMPLEX for seniors in Gary, the lights went out on August 11 and did not come back on until August 23, residents told me. Bernetta Murrey has been living there for almost 11 years. “We really bonded,” she said. “We were on our own.” In the first three or four days after the storm, residents had to fend for themselves. “A majority who live here have cars,” she said, so they drove to get food.

Not everyone could do that. Another resident, Mary Gant, explained that some people at the facility “couldn’t go down the stairs.” When I asked how they ate during that time, she said, “I don’t know.”

Three or four days in, the women told me, residents started putting out appeals on Facebook, asking that people not forget the seniors living there. That brought in a flood of support. Community members started delivering food. In one case, they said, a younger woman showed up with colleagues and started cleaning the units. She said that her grandmother had once lived there, and she wanted to give back in her honor.

But for some residents, the outage brought other problems volunteers could not solve. Gant told me she has chronic obstructive pulmonary disease, and relies on a machine to sleep. That was impossible without power. “I had to sleep upright on a chair,” she told me. And then, after a night of poor sleep she couldn’t even make her morning coffee.

I met Lou, who asked me to only use his first name, in front of the Park Shore Commons. He was in a wheelchair carrying a trash can, in the midst of cleaning his apartment. He can “walk a little,” he told me, and when the power went out, he said, he had to take the stairs. He did so “one step at a time,” while also maneuvering his automatic wheelchair. The balcony to his apartment is just above the front entrance, so he was also able to wave at people down below, and let them know when he needed food.

It was hot, he said, so he spent time on his balcony to cool off. “At night I’d get eaten up by mosquitos.” Temperatures that week got up into the mid-80s, with a brutal 93 percent humidity.

PATRICK BIGGER FROM THE CLIMATE AND COMMUNITY INSTITUTE made the situation plain. “The interminable blackout in Gary, during the dog days of summer, is in no sense an act of God,” he said. “It is the result of the long-running interplay between capital flight, deregulation, the deliberate starvation of public services, and our continuing reliance on fossil fuels compounded by structural racism.”

“There is simply no reason,” he continued, “that an entire city with a proud industrial heritage in the richest country in the history of the world should not have access to one of the core inputs of modern life.”

Gary was founded in 1906 by United States Steel Corporation, and was named after company co-founder Elbert H. Gary. In his book Racial Politics and Urban Planning , Robert A. Catlin details the institutional racism that marked the city from the start, particularly after Black workers started moving in during the Great Migration in the 1920s. “As early as 1908, the school superintendent had transferred almost all black students to a segregated school,” he wrote. And, he added, “In 1917, U.S. Steel decided to build housing for blacks only, setting the stage for residential segregation, which was totally complete by 1940 when this group made up 18 percent of the 112,000 residents. Until the 1930s, blacks were not admitted to the two city hospitals, and black physicians were not given staff privileges.”

In the 1960s, when the mill downsized, layoffs combined with white flight and bank redlining “to isolate Gary’s population,” which by then was majority-Black, writes Erin Devorah Rapoport for the Advocates’ Forum at the University of Chicago School of Social Work. The town of Merrillville, incorporated in 1971, absorbed white flight from the city, assisted by state legislation that provided an exemption from a buffer zone requirement, permitting the town to expand to Gary’s border.

The Rev. John Jackson, pastor of Trinity United Church of Christ, told Max Alvarez for a segment that aired on The Real News Network August 24 that “we are experiencing a Katrina moment.” That storm pulled “the covers off of the lack of maintenance in New Orleans for the levees … in the working people’s area of Black, brown and poor whites,” he said. “And so it pulled the covers off of the same thing I see happening here in Gary, Indiana and Northwest Indiana.”

In my numerous conversations with residents, I heard stories of people coming together to help each other, some of them high-profile celebrities, including Indiana Pacers basketball player Tyrese Haliburton, who gave a hefty donation to recovery efforts. The city’s new website for storm relief includes a list of food distribution sites, charging stations, and even a Medical Oxygen Refill Station. Not all the stories, though, are of banding together. I spoke to an older white man in the Miller Beach area of Gary who had a generator, which he was able to rely on when the power went out. He decided he needed to have a gun nearby, he said, in case he had to protect his property from “looters coming from Chicago.”

Yet most of the stories were just of regular people trying to get by. A grocery worker described having to throw out “everything,” after the food rotted during the outage. A gas station attendant recalled long lines that lasted for hours, and one time when people stayed overnight trying to get gas. Schools closed. Day cares closed. People with asthma couldn’t use their nebulizers. People without a lot of money are now left to pick up the pieces of lost wages, lost groceries, and damaged buildings and cars.

McCrady told me she is sick of all of the “nasty” coverage of the storm and its aftermath, painting the people of Gary in a bad light, and placing blame solely on the city, when Gary is a victim of such drastic, institutional abandonment and mistreatment.

“Gary is a very poverty-stricken and low-income area,” Pastor Watson told me. “It’s hard for people to make it two or three days without power. So two weeks to these people in my city, with the salary and budget they have, feels more like two to three months.”

The Gary crisis comes amid increasingly severe weather events in the United States, caused by human-made climate change, from extreme wildfires to intense heat. Studies show climate change disproportionately hurts underserved communities in the United States, and poor countries on a global scale—though rich regions are not remotely immune. The climate crisis may seem abstract, but in Gary, it could not be more concrete. “I think people understand that these kinds of disasters happen everywhere, and we read about it, and we feel for people,” said Dorreen Carey, the president of Gary Advocates for Responsible Development. “This is the first time we have actually experienced something of this magnitude here. It’s important to understand and recognize that this is part of the whole issue of climate change, and that we’re not as prepared as we should be for this.”

===

This article is a joint publication of The American Prospect and Workday Magazine , a nonprofit newsroom devoted to holding the powerful accountable through the perspective of workers. Credit to Maximillian Alvarez at The Real News Network , who connected me with sources in Gary, making this reporting possible.

Our decision on Cursor following its acquisition by SpaceX

Hacker News
openai.com
2026-08-28 21:47:53
Comments...

LLM usage in Debian neither endorsed nor prohibited

Lobsters
www.debian.org
2026-08-28 21:40:59
The official announcement with the breakdown of votes is here, but option 5 has won. Comments...
Original Article

Time Line

Discussion Period: 2026-07-23 2026-08-13
Voting period: Saturday 2026-08-15 00:00:00 UTC Friday 2026-08-28 23:59:59 UTC

The discussion period has been extended [ mail ]

Proposal A Proposer

Matthias Geiger [ werdahias@debian.org ] [ text of proposal ]

Proposal A Seconds

  1. Johannes Schauer Marin Rodrigues [ josch@debian.org ] [ mail ]
  2. Antoine Le Gonidec [ vv221@debian.org ] [ mail ]
  3. Simon Richter [ sjr@debian.org ] [ mail ]
  4. David Bremner [ bremner@debian.org ] [ mail ]
  5. Pierre-Elliott Bécue [ peb@debian.org ] [ mail ]
  6. Ian Jackson [ iwj@debian.org ] [ mail ]
  7. Amin Bandali [ bandali@debian.org ] [ mail ]
  8. Thorsten Glaser [ tg@debian.org ] [ mail ]

Proposal A

Choice 1: No LLM contributions to Debian via Social Contract

Preamble

This proposal aims to expressly forbid any contributions to Debian written with the use or assistance of large language models (LLMs) or other generative AI tools.

The scope of this GR is (non-exhaustive):

  • Debian source packages
  • Official Debian project software, such as lintian
  • Debian web resources
  • Documentation and translations added by Debian contributors
  • Official communication from Debian

It does not include:

  • Upstream projects using LLMs for development
  • AI-related software
  • Upstream patches/security fixes etc.

Rationale

Debian has a well-earned reputation for stability. This stability is crucial to Debian's position in the free software ecosystem. It is our belief that widespread LLM usage comes from the "move fast, and break things" attitude that, while common in many parts of this industry, is contrary to what makes Debian Debian, and is inappropriate for Debian contributors.

In practical terms, LLM usage raises the following concerns:

1. Copyright

LLM output has very unclear legal status: it may be possible to copyright on its own merits, or not; it may be affected by all of the licenses and copyrights in the training data, or not. Debian Policy and the DFSG require absolute clarity for licensing and copyright[1][2]. Software and other contributions written conventionally by humans with unclear copyright or license status are not allowed in Debian; LLM output should not have a special exception to this.

2. Quality

LLM output has many well-known problems with accuracy.[3][4][5] A LLM can never "know" if its output is correct since it merely produces syntactically likely combinations of the training data. In some environments this is good enough. In Debian, it is not. For instance, in packaging, each Debian source package is unique. Since packaging syntax and best practices have changed over time, a LLM-produced package will have a mixture of contents spanning the age of the archive, with watch files that do not work, overrides out of context, imaginary copyright, and will generally be unfit for upload. A seasoned Debian contributor with packaging expertise may find some limited usefulness here, but a new contributor cannot, and would not know how to fix it. These same quality and accuracy concerns apply clearly to all of the areas listed in the scope of this proposal above. If Debian were a closed organization comprising only domain experts who never leave, this might not be an issue; however,

3. Community

Debian is a project that is more than just code: it is a community built on shared interests in free software and solving technical problems. Debian intentionally grows this community through many means, and new contributors are always encouraged to join. Allowing LLM contributions breaks this. New contributors submitting LLM output for review places an unnecessary strain on the reviewer, which can lead to burnout. Furthermore, LLM-dependent new contributors do not actually learn and understand the details of Debian packaging or processes, so they cannot come to replace a former burned out DD.

4. Ethics

LLM companies directly hurt the free software community as whole by scraping the whole web for training data without any regard for license, copyright, or even established conventions such as robots.txt.[6] This has had a major negative impact on Debian's public web resources, effectively a large scale and perpetual Denial of Service attack on sites that many users rely on. As a consequence parts of our infrastructure were not reachable at all, and JS-based checks had to be enabled. Many other projects were similarly affected. Furthermore, LLM training consumes a staggering amount of resources[7], and the user verification systems that we have been forced to implement as protection waste resources as well. This is blatant disregard for the internet as a public resource, wastes system administrator time, and although individual LLM sessions do not directly use massive resources or DoS the public web, the fact that they can be used at all is a direct result of these unethical behaviours by the LLM companies.

Debian has a Social Contract. [8] Our priorities are our users and free software. Debian is Stable. [9] Users and organizations choose Debian because it is reliable and secure.

Debian is not here to generate as much code as possible requiring manual review by a shrinking number of human volunteers, or to package every piece of software, or to rush new features, but these are what LLMs are used for.

In conclusion, allowing LLM contributions is contrary to the social contract and the common cause of creating a free operating system with a focus on quality and stability.

Proposal

In the interest of not eroding Debian's reputation or further damaging the community, LLM-assisted contributions should be prohibited from inclusion in Debian.

Though our position is that LLM contributions are contrary to documents already ratified by Debian, in order to remove all doubt, we propose the following addition to the Social Contract:

6. Works Created through the use of Large Language Models (LLMs)

We will not
allow direct contributions to Debian written with the use or assistance of large
language models (LLMs) or other generative AI tools. Direct contributions are
defined as packaging, native Debian software like lintian, documentation and
translations written by Debian contributors, and official Debian web resources,
etc. Other categories such as upstream projects written with LLM assistance may
be included at a later date. This ensures that Debian remains a stable, trusted,
and reliable operating system, and protects the interests of the Debian
volunteers who make it possible.

Possible Issues

Other projects exploring similar decisions have elicited a common reply: "How will you enforce a ban on LLM contributions?" While enforcement could be a challenge, this is a statement of intent by the Debian community, and we trust this community to adhere to it in good faith.

Citations

[1] https://www.debian.org/doc/debian-policy/ch-archive.html#copyright-considerations
[2] https://www.debian.org/social_contract#guidelines
[3] https://web.archive.org/web/20240614004123/https://news.northeastern.edu/2023/11/10/ai-chatbot-hallucinations/
[4] https://web.archive.org/web/20250328154700/https://transformer-circuits.pub/2025/attribution-graphs/biology.html#dives-cot
[5] https://www.marketwatch.com/story/openais-sam-altman-tells-salesforces-marc-benioff-that-ai-hallucinations-are-more-feature-than-bug-1c035c52
[6] https://lwn.net/Articles/1008897/
[7] https://tech-insider.org/ai-data-center-power-crisis-2026/
[8] https://www.debian.org/social_contract
[9] https://www.debian.org/doc/manuals/debian-reference/pr01.en.html#_what_is_debian

Disclaimers

  • Citations are for background information only and do not reflect an endorsement of specific websites.
  • Some ideas and wording were derived from the sources below.

Sources

GNOME discussion: https://discourse.gnome.org/t/loupe-no-longer-allows-generative-ai-contributions/27327
(CC0) Gentoo AI policy: https://wiki.gentoo.org/wiki/Project:Council/AI_policy
Codeberg AI policy: https://codeberg.org/Codeberg/org/pulls/1253#issuecomment-19820434

This document was written by Matthias Geiger and Jesse Rhodes with input from Sledge and josch, organically and without language model assistance.

Proposal B Proposer

Lucas Nussbaum [ lucas@debian.org ] [ text of proposal ] [ text of amendment ] [ text of amendment ]

Proposal B Seconds

  1. Andrey Rahmatullin [ wrar@debian.org ] [ mail ]
  2. Christian Kastner [ ckk@debian.org ] [ mail ]
  3. Anton Gladky [ gladk@debian.org ] [ mail ]
  4. Stefano Zacchiroli [ zack@debian.org ] [ mail ]
  5. Simon Quigley [ tsimonq2@debian.org ] [ mail ]
  6. Soren Stoutner [ soren@debian.org ] [ mail ]
  7. Julian Andres Klode [ jak@debian.org ] [ mail ]
  8. Andreas Tille [ tille@debian.org ] [ mail ]
  9. Philipp Kern pkern@debian.org ] [ mail ]

Proposal B

Choice 2: Allow AI-Assisted Contributions with conditions

Using its power under Constitution section 4.1 (5), the project issues the following statement describing its current position on AI-assisted contributions. This statement describes the position of the project at the time it is adopted. That position may evolve as time passes without the need to resort to future general resolutions. The GR process remains available if the project needs a decision and cannot come to a consensus.

The Debian project recognizes that AI-assisted contributions raise many concerns, e.g. about the technical quality and maintainability of such contributions, and their legal status. AI itself also raises additional concerns, about its impact on society at large, on the IT industry and on Free Software; about its environmental impact; and the aggressive or non-compliant practices of AI scrapers.

Nevertheless, many Debian contributors find AI tools helpful when contributing to Debian, and ultimately for improving Debian.

Given both the benefits and risks of AI assistance, and the controversial discussions within the community, the Debian project finds it necessary to clarify its position on AI-assisted contributions and establish clear guidelines.

The Debian project allows AI-assisted contributions (partially or fully generated by an LLM), provided the following conditions are met:

  1. Tooling Legal Compatibility: Contributors should ensure that the terms and conditions of the generative AI tool do not impose contractual restrictions that conflict with the distribution, modification, or use of the output in the context of Debian.
  2. Licensing and Attribution: If any pre-existing copyrighted materials (including pre-existing code licensed as free software) authored or owned by third parties are included in the AI tool’s output, prior to contributing such output to the project, the contributor should verify they have the right to submit it under the relevant open source license.
  3. Accountability: Contributors assume full responsibility for their contributions, including vouching for the technical merit, security, license compliance, and utility of their submissions. The contributor remains solely accountable for the entirety of these contributions. Contributors should fully understand the proposed changes and be prepared to justify them.
  4. Disclosure: When a significant portion of a contribution is generated or substantially assisted by a tool, contributors should disclose the use of the tool, making it clearly visible to the intended audience. This covers all forms of contribution, including code, mailing list posts, and bug discussions. The form of the disclosure is left to the contributor; one convenient option for commits is a Git trailer such as Generated-By: or Assisted-By:.
  5. Prior Discussion of Bulk or Automated Changes: Similarly to the mass-bug filing process (Developers Reference section 7.1.1), contributors should discuss their intention before submitting bulk or autonomously generated contributions. Any such automated process should be overseen by a human who remains accountable for its behavior and output.
  6. Confidentiality and Privacy: Contributors must not use generative AI tools that transmit data to untrusted providers with non-public or sensitive project information (such as embargoed security reports or private communication), as this may lead to the unintended disclosure of confidential data.

Proposal C Proposer

Ian Jackson [ iwj@debian.org ] [ text of proposal ] [ text of amendment ]

Proposal C Seconds

  1. Matthias Geiger [ werdahias@debian.org ] [ mail ]
  2. Andrea Pappacoda [ tachi@debian.org ] [ mail ]
  3. Simon Richter [ sjr@debian.org ] [ mail ]
  4. Antoine Le Gonidec [ vv221@debian.org ] [ mail ]
  5. Amin Bandali [ bandali@debian.org ] [ mail ]
  6. Bill Blough [ bblough@debian.org ] [ mail ]
  7. Enrico Zini [ enrico@debian.org ] [ mail ]
  8. Sean Whitton [ spwhitton@debian.org ] [ mail ]
  9. Tiago Bortoletto Vaz [ tiago@debian.org ] [ mail ]

Proposal C

Choice 3: Reject LLMs as far as practical, update Code of Conduct

Summary: Reject LLMs (generative "AI") as far as practical

BACKGROUND

LLMs have many serious problems, including: undermining the mechanisms of free software community building; environmental damage; exploitation of authors; disruption to open web hosting by aggressive scraping; generation and promulgation of bullshit, polluting the information commons; hazards to users' mental health; economic bubbles and distortion of the computer hardware market; fraud; ownership by horrible people and companies; and so on. Ethical and safe use of this technology is almost impossible.

Ideally, LLM output should not form any part of software that we rely on, nor should LLM output ever take the place of human-written prose.

Unfortunately some of the wider software world, including many of our upstreams, take a different view. Therefore a complete ban on LLM output as part of Debian is currently impractical.

REQUESTS

1. We request that all contributors to Debian avoid the use of LLMs in their Debian work.

2. We request that all decisionmakers within Debian discourage LLM use as much as practical. Practicality is a judgement call and we recognise that it will involve uncomfortable compromises.

3. We request that everyone, even outside Debian, should refrain from using this technology. In particular, the Free Software and Open Source communities should reject LLMs. We recognise that not everyone will heed this call.

REQUIREMENTS (SUPPLEMENT TO THE CODES OF CONDUCT)

4. Within Debian, messages to humans (including for example bug reports, mailing list messages, discussions on Salsa, and blog posts on Planet Debian) must be drafted solely by humans without LLM assistance.

5. Moderators and disciplinary teams may make narrow and tailored exceptions to rule 4, and decide on interpretation.

6. Any use of LLMs for Debian work must be disclosed.

7. Individual projects and maintainers may ban LLM contributions completely. Such bans (including by upstream projects) must be respected.

8. Violations of these requirements should be treated as violations of the relevant Code of Conduct and should result in swift and proportionate disciplinary action.

Proposal D Proposer

Pierre-Elliott Bécue [ peb@debian.org ] [ text of proposal ] [ text of minor change ]

Proposal D Seconds

  1. Russ Allbery [ rra@debian.org ] [ mail ]
  2. Johannes Schauer Marin Rodrigues [ josch@debian.org ] [ mail ]
  3. Jonathan Carter [ jcc@debian.org ] [ mail ]
  4. Gunnar Wolf [ gwolf@debian.org ] [ mail ]
  5. Tiago Bortoletto Vaz [ tiago@debian.org ] [ mail ]
  6. Jeremy Sowden [ azazel@debian.org ] [ mail ]
  7. Holger Levsen [ holger@debian.org ] [ mail ]

Proposal D

Choice 4: Accept AI contributions for Debian specific work

Debian as a project does not endorse or recommend the use of generative AI assistants for software development, as it raises multiple concerns about ethics, legality, copyright, etc.

Nevertheless, Debian acknowledges that these practices are already in use and here to stay. Rather than banning their use, which seems counter-productive and unenforceable, the project chooses to place responsibility on contributors and therefore defines the following guidelines.

These apply exclusively to code and work done specifically for the Debian project (Debian websites, applications, resources, packages, etc.). They do not apply to any upstream work. In what follows, "work" refers to the contributions done specifically for the Debian project.

  • All code and work assisted by a generative AI agent or tool must comply with the DFSG.
  • The submitter is solely responsible for the submitted work and:
    • they sufficiently evaluated and properly understand the work they intend to submit, and are able to explain and defend it;
    • they put any potential Signed-off-by tag and OpenPGP signatures on the contributions they send to the Debian infrastructure (package, commit, mail, …) themselves;
    • any content uploaded that would end up in production on Debian infrastructure (main git branch, package upload) has been submitted by them explicitely.
  • Work assisted by a generative AI agent or tool should be marked as such in the adapted place (commit message, changelog, …). Some lightweight generative tools, such as tab-completion in Copilot, may be used without the contributor realising they rely on generative AI models; we therefore trust submitters to assess when this rule applies. When in doubt, add such marking;
  • No cloud-based AI shall be used when the data transmitted could either be sensitive to the project (personal data, information under embargo, …) or not public (debian-private discussions, …).

Proposal E Proposer

Marc Haber [ zugschlus@debian.org ] [ text of proposal ]

Proposal E Seconds

  1. Soren Stoutner [ soren@debian.org ] [ mail ]
  2. Christian Kastner [ ckk@debian.org ] [ mail ]
  3. Timo Röhling [ roehling@debian.org ] [ mail ]
  4. Clint Adams [ clint@debian.org ] [ mail ]
  5. Matthias Urlichs [ smurf@debian.org ] [ mail ]
  6. Tobias Frost [ tobi@debian.org ] [ mail ]
  7. Anuradha Weeraman [ anuradha@debian.org ] [ mail ]
  8. Lucas Nussbaum [ lucas@debian.org ] [ mail ]
  9. Bdale Garbee [ bdale@debian.org ] [ mail ]
  10. Helge Deller [ deller@debian.org ] [ mail ]
  11. Hanno Wagner [ wagner@debian.org ] [ mail ]

Proposal E

Choice 5: Responsible Use of Generative AI

Using its power under Constitution section 4.1 (5), the project issues the following statement describing its current position on AI-assisted contributions. This statement describes the position of the project at the time it is adopted. That position may evolve as time passes without the need to resort to future general resolutions. The GR process remains available if the project needs a decision and cannot come to a consensus.

Debian neither endorses nor prohibits the use of generative AI tools in the development, maintenance, or documentation of software, packaging, documentation, and other media published within the Debian Project. We recognize that such tools can substantially improve the productivity of contributors when used responsibly, allowing volunteers to spend more of their limited time on work that requires technical expertise, judgment, review, and collaboration.

The Debian Project nevertheless expects that all contributions submitted to Debian, regardless of how and with which tools they were produced, satisfy the same standards of quality, correctness, maintainability, and legal compliance. The use of a generative AI tool does not diminish the contributor's responsibility for the work they submit. Contributors are expected to understand, review, test, and, where appropriate, modify AI-assisted output before incorporating it into Debian. Blindly accepting or uploading AI-generated material without appropriate human review is inconsistent with Debian's established development practices. We enourage our contributors to disclose whether a contribution was made with AI assitance, but do not require them to do so.

Debian acknowledges that the legal status of material produced by generative AI systems remains the subject of ongoing discussion in many jurisdictions, including questions relating to copyright, authorship, licensing, and potential reproduction of training material. The Project does not seek to resolve these unsettled legal questions through this General Resolution, nor does it adopt a position on whether AI-generated output is, in whole or in part, copyrightable or derived from copyrighted works.

Instead, Debian continues to rely on the judgment and responsibility of its individual contributors. Project members are expected to exercise appropriate care when using generative AI tools, to consider the provenance and licensing implications of material they contribute, and to avoid introducing content whose legal status they cannot reasonably justify. Existing Debian policies governing licensing, copyright, software freedom, and the acceptance of contributions continue to apply irrespective of the tools used to produce those contributions.

Contributors are expected to exercise appropriate care when designing and implementing workflows that incorporate generative AI tools. In particular, they should ensure that confidential information, private communications, security-sensitive information (such as embargoed information about security bugs that is not yet public), cryptographic keys, credentials, and other non-public material relating to the Debian Project, its infrastructure, or its community are not disclosed to third-party AI services unless such disclosure has been explicitly authorized and is consistent with Debian's security and privacy requirements.

The use of generative AI does not alter Debian's established expectations regarding large-scale or automated project actions. Contributors intending to perform actions with broad project impact, such as mass bug filing or patch submission, large-scale code modifications, or other automated changes or requests affecting many packages or contributors, should seek prior discussion and consensus through the appropriate project channels before proceeding. Any such automated process should be overseen by a human who remains accountable for its behavior and output.

This resolution therefore affirms that generative AI is neither exempt from nor subject to special rules beyond the standards already expected of Debian contributors. The responsibility for every contribution rests with the contributor who submits it, who remains accountable for its technical quality, legal acceptability, and suitability for inclusion in Debian.

Proposal F Proposer

Tobias Frost [ tobi@debian.org ] [ text of proposal ]

Proposal F Seconds

  1. Timo Röhling [ roehling@debian.org ] [ mail ]
  2. Russ Allbery [ rra@debian.org ] [ mail ]
  3. Étienne Mollier [ emollier@debian.org ] [ mail ]
  4. Lucas Nussbaum [ lucas@debian.org ] [ mail ]
  5. Gunnar Wolf [ gwolf@debian.org ] [ mail ]
  6. Jonathan Carter [ jcc@debian.org ] [ mail ]

Proposal F

Choice 6: A cautious approach to generative AI

Using its power under Constitution section 4.1(5), the Project issues the following statement describing its current position regarding the use of generative AI within Debian.

Debian recognizes that generative AI raises significant ethical, legal, technical, and social concerns. These include questions relating to copyright and licensing, privacy, the provenance and quality of generated material, the health of Free Software communities, and the long-term consequences of widespread reliance on AI-generated content.

Accordingly, Debian encourages contributors to avoid the use of generative AI where practical and to prefer human authorship, collaboration, and technical understanding over AI-generated output.

At the same time, Debian has long relied on the judgment and responsibility of its contributors rather than prescribing individual workflows. Contributors remain responsible for everything they submit, irrespective of the tools used in preparing a contribution. Existing Debian standards regarding quality, correctness, licensing, and legal compliance continue to apply.

Contributors using external generative AI services should exercise particular care not to disclose confidential information, embargoed security information, credentials, cryptographic keys, private communications, personal data, or other non-public Debian information.

Nothing in this resolution should be understood as requiring contributors to use generative AI, nor as preventing contributors or maintainers from choosing not to use or accept AI-assisted contributions. Debian's existing collaborative processes remain the appropriate means for resolving such differences while allowing the project to continue making progress.

While disclosure is not required, contributors are encouraged to voluntarily disclose the use of generative AI where appropriate, allowing others who prefer not to interact with AI-assisted content to make informed choices.

Such disclosure should be regarded as a courtesy to fellow contributors rather than an indication that AI-assisted contributions are subject to different technical or procedural standards.

The Debian project has always recognized the commitment and professionalism of its members. All contributions are under the responsibility of the Debian Contributor making it, no matter the technology they have behind. We trust all Debian Developers, Maintainers and Contributors will continue to uphold the high quality values that have distinguished our project from its onset.

Proposal G Proposer

Gard Spreemann [ gspr@debian.org ] [ text of proposal ]

Proposal G Seconds

  1. Holger Levsen [ holger@debian.org ] [ mail ]
  2. Enrico Zini [ enrico@debian.org ] [ mail ]
  3. Russ Allbery [ rra@debian.org ] [ mail ]
  4. Tiago Bortoletto Vaz [ tiago@debian.org ] [ mail ]
  5. Serafeim Zanikolas [ sez@debian.org ] [ mail ]
  6. Antoine Le Gonidec [ vv221@debian.org ] [ mail ]
  7. Johannes Schauer Marin Rodrigues [ josch@debian.org ] [ mail ]
  8. Steve McIntyre [ 93sam@debian.org ] [ mail ]
  9. Sean Whitton [ spwhitton@debian.org ] [ mail ]

Proposal G

Choice 7: Debian is created by humans

Preamble

This proposal aims to ensure that contributions directly to Debian are created by humans, while at the same time avoiding restrictions on the tools those humans may choose to use when contributing.

The proposal deals with direct contributions to Debian, including, but not limited to:

  • Debian packaging
  • Submissions (messages, bug reports, patches, etc.) to the BTS, Salsa, mailing lists and other Debian platforms
  • Debian project software
  • Debian infrastructure
  • Debian web resources
  • Documentation and translation added as part of contributing to Debian
  • Official communication from Debian

The proposal does not cover indirect contributions, i.e. those originating from upstream works.

Generative AI is characterized by producing output of a nature that would ordinarily be produced and consumed by humans. The proposal seeks to restrict this output itself from entering Debian (except possibly indirectly, from upstream). It does not seek to restrict Debian contributors from consuming such output as part of contributing to Debian.

Rationale

Debian has a well-earned reputation for stability. This stability is crucial to its position in the free software ecosystem. It is our belief that a significant part of this stability comes from Debian contributors having mutual understanding, trust and respect for each others' work and precious time. Generative AI tends to come with practical, legal, ethical or ecological concerns that warrant care or extra work that often ends up being borne by people other than those wielding the AI. We believe that this asymmetry between contributors leveraging generative AI to produce material, and those humans who bear that extra care and work, will erode the project's mutual understanding, trust and respect.

While Debian has a long-standing tradition of strict rules for what goes into the distribution, it does not typically dictate what tools people use when contributing to the project. With this principle in mind, the proposal does not affect the use of generative AI as an assisitive tool to explore, research, analyze, critique, etc., when contributing. The responsibilities that come with using the output of an AI in such a role is then not transferred onto the wider project in the same problematic way as when the output itself is the contribution.

Proposal

In order to safeguard the project's mutual understanding, trust and respect, we disallow the output of generative AI as direct contributions to Debian.

Those who use such tools assistively in their work are reminded to ensure that the resulting contribution is in line with the DFSG and the Social Contract in general.

In summary, humans create Debian.

Acknowledgements

This proposal is inspired by GCC's AI Policy [1] and rust-lang's LLM Usage Policy [2]. Its wording is influenced by another ballot option [3].

[1] https://gcc.gnu.org/ai-policy.html
[2] https://forge.rust-lang.org/policies/llm-usage.html
[3] https://www.debian.org/vote/2026/vote_002#texta

Proposal H Proposer

Holger Levsen [ holger@debian.org ] [ text of proposal ] [ text of corrections ]

Proposal H Seconds

  1. Simon Richter [ sjr@debian.org ] [ mail ]
  2. Matthew Vernon [ matthew@debian.org ] [ mail ]
  3. Steve McIntyre [ 93sam@debian.org ] [ mail ]
  4. Enrico Zini [ werdahias@debian.org ] [ mail ]
  5. Antoine Le Gonidec [ vv221@debian.org ] [ mail ]
  6. Jonathan Carter [ jcc@debian.org ] [ mail ]
  7. Matthias Geiger [ werdahias@debian.org ] [ mail ]
  8. Sruthi Chandran [ srud@debian.org ] [ mail ]
  9. Santiago Ruano Rincón [ santiago@debian.org ] [ mail ]
  10. Mattia Rizzolo [ mattia@debian.org ] [ mail ]
  11. Vagrant Cascadian [ vagrant@debian.org ] [ mail ]
  12. Bas Wijnen [ wijnen@debian.org ] [ mail ]
  13. Michael Prokop [ mika@debian.org ] [ mail ]
  14. Guilhem Moulin [ guilhem@debian.org ] [ mail ]
  15. Ian Jackson [ iwj@debian.org ] [ mail ]
  16. Andreas Tille [ tille@debian.org ] [ mail ]
  17. Didier Raboud [ odyx@debian.org ] [ mail ]

Proposal H

Choice 8: Avoid the use of LLM: climate destruction is a deal breaker

LLM usage accelerates the destruction of our ecosystem (planet earth) and that is a deal-breaker

Using its power under Constitution section 4.1(5), the Project issues the following statement describing its current position regarding the use of LLM (Large Language Models) within Debian.

We don't have a concern with the LLM _technology_ as such: it's just maths and enough training material, which outputs a very large set of numbers that we can use to infer new material from existing material. But we cannot talk about the LLM technology without talking about who is pushing for its usage, who is doing the training and how, what effect those have on our limited resources, and what are the economical and political motives of these.

Foremost we don't understand how anyone can agree that global LLM usage accelerates the destruction of our ecosystem, planet earth, and not feel like that is a deal-breaker.

Too often the only response we've seen to this point was that other activities are also bad (some even worse) for the climate. How is this even an argument? The planet is burning, we should try to stop that as much and as fast as we can! If others aren't stopping, isn't that even more reason to compensate for their irresponsible actions?

And while we're on that point: All of our users live on this planet, so protecting this planet is a matter of life and death for all of us. In other words, caring about something as big as climate change during our Debian work is self evident.

Debian recognizes that LLM *also* raise significant ethical, legal, technical, and social concerns. These include questions relating to copyright and licensing, privacy, the provenance and quality of generated material, the health of Free Software communities, and the long-term consequences of widespread reliance on LLM-generated content.

That said, we would like to emphasize that we condemn LLM (resource) usage but not LLM users. Fight the game, but not the players.

We also acknowledge that LLM usage can be hard if not impossible to detect and that Debian as a distribution cannot really impose LLM policies on other projects we package and distribute. Therefore this text is just a position statement. This said however, we appreciate the disclosure of LLM usage.

Accordingly, Debian encourages contributors to avoid the use of LLM where practical and to prefer human authorship, collaboration, and technical understanding over LLM-generated output.

At the same time, Debian has long relied on the judgment and responsibility of its contributors rather than prescribing individual workflows. Contributors remain responsible for everything they submit, irrespective of the tools used in preparing a contribution. Existing Debian standards regarding quality, correctness, licensing, and legal compliance continue to apply.

The Debian project has always recognized the commitment and professionalism of its members. All contributions are under the responsibility of the Debian Contributor making it, no matter the technology they have behind. We trust all Debian Developers, Maintainers and Contributors will continue to uphold the high quality values that have distinguished our project from its onset.

Please keep being excellent to each other and the only planet we have.

Data and Statistics

For this GR, like always, statistics will be gathered about ballots received and acknowledgements sent periodically during the voting period.

Majority Requirement

Proposal A needs a 3:1 majority, the other proposals need a simple majority.


Debian Project Secretary

CTE Cases Are Soaring. Why Can’t We Quit Football?

Portside
portside.org
2026-08-28 21:33:12
CTE Cases Are Soaring. Why Can’t We Quit Football? barry Fri, 08/28/2026 - 21:33 ...
Original Article
CTE Cases Are Soaring. Why Can’t We Quit Football? Published

"human brain on white background" | by _DJ_ (CC BY-SA 2.0)

Twenty years into its C.T.E. era, the N.F.L. is more popular and profitable than ever. Revenues rise even as the math becomes clearer for the once immeasurable price paid in brain damage sustained by football players.

Fans know too much to plead ignorance. They now know, thanks to a new study , that at least one in four former N.F.L. players had C.T.E. among the nearly 900 who died between 2016 and 2021.

We are living in an era of cognitive dissonance, sociologists said. How many C.T.E. cases, they wondered, are too many for fans’ collective consciousness? What would it take to quit watching, or to quit sending children into the scrum? How many irreversibly damaged brains in the N.F.L. would turn away the masses?

“I doubt that any number is going to do it,” said Steve Almond, a lifelong football fan and the author of “Against Football: One Man’s Reluctant Manifesto.”

Mr. Almond is among the millions who cannot turn away from what he has called “our unholy appetites.” He’s just more thoughtful about it. He says football is “morally troubling.”

“The vast majority of fans aren’t sitting there saying, ‘I want people to get hurt and I have this blood lust,’” he said. “I think, like me, they’re getting off on a beautiful, narratively thrilling sport that has an unfortunate adjunct to it — the fact that it’s absolutely unsafe to play.”

In the past two decades, hundreds of former N.F.L. players have died with chronic traumatic encephalopathy, or C.T.E., a brain disease caused by the cumulative effect of repeated hits to the head. Now a new peer-reviewed study reveals that 25 percent of them over a recent six-year period were found to have had C.T.E. — posthumously, the only way to diagnose the disease with certainty.

That one-in-four ratio is certainly low, since it does not account for the nearly 75 percent of deceased players in that period whose brains were not examined because they had not been made available to researchers.

If the one-in-four rate extended to the upcoming season, that would mean, on average, 13 players per team and more than 400 active players in the league would have C.T.E.

StemDeck, a free, open-source and local AI stem separator

Hacker News
github.com
2026-08-28 21:24:13
Comments...
Original Article

Drop in an MP3, WAV, FLAC, OGG/Opus, MP4, or M4A file, or paste a YouTube URL, and StemDeck splits the audio into up to six stems (vocals, drums, bass, guitar, piano, other). Play them back in a DAW-style multitrack mixer: mute, solo, balance levels, zoom the waveform, loop a region, and export individual stems or a custom mix. Everything runs locally on your own machine.

What is this? StemDeck is a stem separation tool, not a downloader. Its main job is processing audio you already own: drag an MP3, WAV, FLAC, OGG, or M4A onto the import bar and go. YouTube support is a convenience for content you have the right to process. StemDeck does not store, cache, or redistribute any downloaded content. Everything happens locally and nothing leaves your machine.

StemDeck is a free, open alternative to cloud stem-splitters like Moises and LALAL.AI: no account, no quota, no uploads, no subscription. If you want stems for personal study and prefer to keep things local and free, StemDeck has you covered. If you need the polish, a mobile app, or deeper musician tooling, the commercial products are a better fit.

StemDeck screenshot

Star History

Star History Chart

We Recommend

StemDeck is free and does not accept any money, sponsorship, or funding from anyone listed below. I share these makers and artists and communities purely for the joy of pointing you toward wonderful people doing beautiful work. Go meet them ❤️

Name What they do Link
Analog4Lyfe All-analog music gear, no digital shortcuts @analog4lyfe
r/bass My beloved bass community on reddit r/Bass
Beltr Turns the songs you already own into karaoke gold, right on your own machine, no subscription, no cloud, just you and the mic beltr.app
Dlima Guitars Custom guitars and basses, built one at a time @dlimaguitars
Empress Effects Boutique effects pedals for tone chasers who don't settle empresseffects.com
Joao Gaspar Producer and film scorer, also plays as a touring/session musician @jay_glaspar
Kris Luthier Hand-repairs and restores instruments in Lisbon, one careful fix at a time @krisluthier
Lisbon Guitar Works Guitars built by hand in Lisbon dlimaguitars.com
More Notes Less Talk Instruments and gear with personality, recorded raw to tape. No hype, no gatekeeping. @morenoteslesstalk
Seratone Turns any TV into a studio-grade karaoke stage seratone.audio
slashCAM German-language camera and video tech: hands-on tests, industry news, and the post-production details most reviews skip @slashcam.de
Thomann One of Europe's largest music gear retailers, practically everything a musician could need @thomann.music

Features

6-stem separation via Demucs htdemucs_6s , with auto-detection of the best Torch device (CUDA on NVIDIA, MPS on Apple Silicon, CPU fallback).

YouTube and local file import. Paste a YouTube URL or drop an MP3, WAV, FLAC, OGG/Opus, MP4, or M4A directly onto the import bar.

DAW-style waveform editor with min/max sample rendering across all stems, shared normalization, zoom in/out/Fit, loop drag on the ruler, gold playhead overlay, and stem-aligned lanes.

Stem subset extraction. Click stem chips to choose which stems to keep. Clicking from "all selected" snaps to "only this one"; subsequent clicks add or remove.

"Original" backing track. When you pick a subset, a 7th lane contains the complement (full song minus selected stems), perfect for A/B reference without doubling.

Downloadable selected mix. A single mix.wav of just your selected stems, summed via ffmpeg amix.

Per-stem mixer with volume fader, mute, solo, and "monitor" (solo-only) per stem. State syncs between the preview mixer and the stems sidebar.

Live VU meters per stem. Post-gain RMS via Web Audio analysers with peak hold and slow falloff.

Song analysis including BPM (librosa beat tracker), key, scale, and confidence (Albrecht-Shanahan profiles), integrated LUFS (BS.1770), and sample peak in dBFS.

Cancellable jobs. Cancel mid-pipeline and the runner terminates the active subprocess immediately, deletes the partial job dir, and returns to ready.

Library panel with folder-based track organisation, drag-and-drop, search, and trash.


Honest Comparison

StemDeck is not trying to compete with commercial stem-separation products. It covers the core use case well and stops there. This table exists so you can make an informed choice rather than discover the gaps after the fact.

StemDeck Moises / LALAL.AI / similar
Price Free, forever Freemium; credits or subscription required for regular use
Hosting Runs entirely on your machine Cloud; audio must be uploaded to their servers
Account / login None Required
Internet required Only for YouTube download and first model fetch (~170 MB, cached after) Always; no offline use
Privacy Audio never leaves your machine Audio is uploaded and processed on third-party servers
Data retention You control it; delete anytime Governed by their privacy policy and retention period
Stem model Demucs htdemucs_6s (open source, Meta AI) Proprietary models, regularly updated, generally higher quality
Stem count 6 (vocals, drums, bass, guitar, piano, other) Up to 10 depending on service and plan
Input formats YouTube URL, MP3, WAV, FLAC, OGG/Opus, MP4, M4A MP3, WAV, FLAC, M4A, and more depending on service
Processing speed Depends on your hardware; fast with a GPU, slow on CPU only Fast regardless of your hardware (runs on their servers)
Batch processing One job at a time Yes, on paid plans
Mobile app No iOS and Android
Extra features No (no pitch shift, chord detection, lyrics, click track, BPM tap) Yes, varies by product
Polish Functional, hobby-grade UI Polished, production-grade apps
Source code Open source, forkable, self-hostable Closed source

If you need speed, quality, mobile access, or the extra musician tooling, the commercial products are worth the money. If you want stems for personal study, prefer to keep audio private, or just want something that runs locally with no strings attached, StemDeck is enough.


Download

Pre-built installers and zips are attached to each GitHub Release .

macOS

DMG GPU Chip
StemDeck-macOS-arm64.dmg Apple Silicon (MPS) M1 and later
StemDeck-macOS-x64.dmg CPU only Intel

Open the DMG, drag StemDeck to Applications, and launch it. On first launch the setup screen downloads the Python runtime (~500 MB), FFmpeg, and the Demucs model (~170 MB). Subsequent launches skip setup and start in seconds. No Python or system dependencies required.

macOS may show a Gatekeeper prompt on first open — right-click the app and choose Open to bypass it.

Windows

Zip GPU Approx. size
StemDeck-Windows-x64.zip CPU only ~700 MB
StemDeck-Windows-x64.NVIDIA.zip NVIDIA CUDA ~1.6 GB

Extract the zip anywhere, run StemDeck.exe . FFmpeg, the Demucs model, config, and logs live in a data/ folder next to StemDeck.exe , not in AppData; move or copy the whole extracted folder anywhere and it keeps working. On first launch the app verifies the bundled Python runtime and downloads FFmpeg and the Demucs model (~170 MB) into that folder. Subsequent launches skip this and start in seconds. Everything is self-contained; no Python or system dependencies required. Your job/library data stays in its usual location ( ~/Documents/StemDeck by default) and is relocatable anytime from Settings → StemData location.


Technologies

Platform Powered by Demucs CI: GitHub Actions

StemDeck is built on Python 3.12 managed via uv , with a FastAPI backend serving REST and Server-Sent Events. Stem separation uses Demucs ( htdemucs_6s ), Meta AI's open-source 6-stem neural network. The optional on-demand lead/backing vocal split runs the UVR-MDX-NET Karaoke 2 model via audio-separator , trained as part of the Ultimate Vocal Remover project by Anjok07. YouTube audio is fetched via yt-dlp ; transcoding and mixing use FFmpeg . BPM detection and key analysis run on librosa ; loudness measurement uses pyloudnorm (ITU-R BS.1770). The macOS and Windows desktop shells are Tauri v2 (Rust/WKWebView on macOS, Rust/WebView2 on Windows). The frontend is vanilla JS with the Web Audio API, no framework and no build step; waveforms are rendered on <canvas> using min/max sample rendering.

Thanks to the creators and maintainers of all the open-source libraries that make StemDeck possible.


Build from Source

macOS Native App

Requires Rust, Node.js, and Python 3.12. Builds a self-contained .app that downloads its own runtime on first launch.

# First time only — add the cross-compilation targets
rustup target add aarch64-apple-darwin   # Apple Silicon
rustup target add x86_64-apple-darwin    # Intel

# Build Apple Silicon
ARCH=arm64 scripts/macos/make-runtime-pack.sh
ARCH=arm64 scripts/macos/make-app.sh
ARCH=arm64 scripts/macos/make-dmg.sh

# Build Intel (requires Rosetta 2 and an x86_64 Python)
ARCH=x64 scripts/macos/make-runtime-pack.sh
ARCH=x64 scripts/macos/make-app.sh
ARCH=x64 scripts/macos/make-dmg.sh

The .app lands at desktop/src-tauri/target/<target>/release/bundle/macos/StemDeck.app . The DMG lands at .build/macos-dist/StemDeck-macOS-<arch>.dmg .

To run a fresh build directly without the DMG:

open desktop/src-tauri/target/aarch64-apple-darwin/release/bundle/macos/StemDeck.app

If macOS blocks the app with a Gatekeeper prompt, run:

xattr -dr com.apple.quarantine desktop/src-tauri/target/aarch64-apple-darwin/release/bundle/macos/StemDeck.app

Note: To test a clean first-launch during development, you can wipe previous app data first: rm -rf ~/Library/Application\ Support/StemDeck . Don't do this on a real install.


Web Server (macOS / Linux / Windows with Python 3.12+)

Prerequisites

Python 3.12 or newer, ffmpeg on your PATH, and uv . Around 170 MB of free disk for the Demucs model, which downloads automatically on first run.

macOS / Linux (one-shot)

git clone https://github.com/stemdeckapp/stemdeck stemdeck && cd stemdeck
./run.sh setup     # installs ffmpeg + uv, runs uv sync
./run.sh start

Open http://localhost:8000 .

setup uses Homebrew on macOS and apt-get on Debian/Ubuntu. For other Linux distros, install ffmpeg and uv manually, then run uv sync followed by ./run.sh start .

Windows (PowerShell)

Install prerequisites:

  • uv winget install astral-sh.uv
  • ffmpeg winget install Gyan.FFmpeg (or Chocolatey: choco install ffmpeg )
git clone https://github.com/stemdeckapp/stemdeck stemdeck; cd stemdeck
uv sync
uv run uvicorn app.main:app --host 127.0.0.1 --port 8000 --timeout-graceful-shutdown 5

Open http://localhost:8000 .

run.sh is macOS/Linux only. On Windows use the PowerShell commands above, or run inside WSL.

NVIDIA GPU (CUDA): install the CUDA-enabled torch build before starting:

uv pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu124
$env:STEMDECK_DEMUCS_DEVICE = "cuda"
uv run uvicorn app.main:app --host 127.0.0.1 --port 8000 --timeout-graceful-shutdown 5

Manual (any platform)

git clone https://github.com/stemdeckapp/stemdeck stemdeck && cd stemdeck
uv sync
uv run uvicorn app.main:app --reload --timeout-graceful-shutdown 5

--timeout-graceful-shutdown bounds how long uvicorn waits for open connections when you stop it. StemDeck keeps a long-lived SSE stream open for the import queue while a browser tab is on the app, so without it Ctrl-C waits for that stream instead of exiting.

Docker

docker compose -f build/docker-compose.yml up --build

Stems land in ./jobs/ on the host. Demucs weights are cached in a named volume so they don't re-download on rebuild. Note: no GPU passthrough on macOS Docker.

A prebuilt image is published to GHCR. Tags: edge (rolling, rebuilt on every merge to main), latest (newest stable release), and X.Y.Z (pinned to a release).

docker run -d --name stemdeck -p 8000:8000 \
  -v /path/to/jobs:/app/jobs \
  -v /path/to/cache:/cache \
  -e STEMDECK_PERSIST_LIBRARY=1 \
  ghcr.io/stemdeckapp/stemdeck:edge

On a Linux host with an NVIDIA GPU (driver + NVIDIA Container Toolkit installed), add --runtime=nvidia -e NVIDIA_VISIBLE_DEVICES=all and StemDeck auto-detects CUDA. The image already bundles CUDA-enabled torch, so no separate CUDA install is needed.

Unraid

StemDeck is available in Unraid Community Applications: open Apps , search "StemDeck", and install. Map the two volumes to persistent appdata paths:

  • /app/jobs -> /mnt/user/appdata/stemdeck/jobs (library + stems)
  • /cache -> /mnt/user/appdata/stemdeck/cache (model weights)

The library is persistent by default ( STEMDECK_PERSIST_LIBRARY=1 ), so tracks are never auto-deleted. For GPU acceleration, install the Nvidia Driver plugin, then set the container's Extra Parameters to --runtime=nvidia (the NVIDIA_VISIBLE_DEVICES and NVIDIA_DRIVER_CAPABILITIES variables are already in the template). CPU-only works with no extra configuration.

run.sh control script

./run.sh setup      # one-shot: install ffmpeg + uv, then uv sync
./run.sh start      # boots uvicorn in the background
./run.sh stop       # graceful shutdown
./run.sh restart    # stop + start
./run.sh status     # is it running?

How to Use

  1. On the import bar, click stem chips to choose which stems to extract (defaults to all 6).
  2. Paste a YouTube URL or drop an audio file (MP3, WAV, FLAC, OGG, MP4, M4A), then click Process .
  3. Wait through Uploading... / Downloading... Analyzing... Separating... Mixing tracks... .
  4. When done, the studio dashboard appears. If you picked a subset, the first lane is Original (full song minus your selection); the rest are your isolated stems.
  5. Mix: Play/Pause/Stop controls the master transport. M mutes a stem, S solos it (additive; multiple solos stay audible), Monitor solos only that stem and clears others. The volume fader moves 1:1 with drag; double-click resets to 0 dB; Shift+wheel gives coarse adjustment and plain wheel gives fine. The Reset , Mute , and Solo toolbar buttons act on all stems at once.
  6. Drag on the ruler to define a loop region; click Loop to enable. Use + / - / Fit or Ctrl/Cmd+wheel to zoom.
  7. Download Mix in the footer gives you a WAV of your selected stems summed together.

Keyboard shortcuts: Space play/pause · [ seek -5s · ] seek +5s · L loop · I loop in · O loop out


Configuration

Variable Default Purpose
STEMDECK_DEMUCS_DEVICE auto Force Torch device: cuda , mps , or cpu .
STEMDECK_DEMUCS_MODEL htdemucs_6s Demucs model name.
STEMDECK_JOBS_DIR ./jobs Where job directories land.
STEMDECK_DATA_DIR (none) Portable mode root; sets all sub-dirs below to live inside it.
STEMDECK_CACHE_DIR <data>/cache Torch model cache directory.
STEMDECK_DOWNLOADS_DIR <data>/downloads yt-dlp download scratch space.
STEMDECK_MODELS_DIR <data>/models Demucs model weights directory.
STEMDECK_LOGS_DIR <data>/logs Log file output directory.
STEMDECK_FFMPEG_DIR (none) Directory containing a bundled ffmpeg binary.
STEMDECK_FFMPEG ffmpeg Path to the ffmpeg executable.
STEMDECK_FFPROBE ffprobe Path to the ffprobe executable.
STEMDECK_MAX_DURATION_SEC 1200 Reject audio longer than this (seconds).
STEMDECK_JOB_TTL_SECONDS 86400 How long to keep job dirs on disk.
STEMDECK_MAX_PENDING_JOBS 3 Max queued jobs before returning 503.
STEMDECK_TIMEOUT_FFMPEG 300 ffmpeg subprocess timeout (seconds).
STEMDECK_TIMEOUT_ANALYZE 120 Audio analysis timeout (seconds).
STEMDECK_TIMEOUT_DEMUCS_STALL 1800 Kill Demucs if no output for this many seconds.

run.sh also reads: HOST (default 127.0.0.1 ), PORT (default 8765 ), RELOAD=1 (enable uvicorn auto-reload for development), FOREGROUND=1 (run in foreground instead of backgrounding).


API

Method Path Purpose
GET /api/health Server health and version info
POST /api/jobs JSON {url, stems?} or multipart file + stems {job_id}
GET /api/jobs List completed (library) jobs
GET /api/jobs/{id} Job state snapshot
GET /api/jobs/{id}/events SSE stream of job state
POST /api/jobs/{id}/cancel Terminate active subprocess and cancel job
PATCH /api/jobs/{id}/sections Save waveform section markers for a job
GET /api/jobs/{id}/stems/{name}.wav Stream a single stem WAV file
GET /api/jobs/{id}/stems/{name}.mp3 Transcode and stream a stem as MP3
GET /api/jobs/{id}/video.mp4 Mux the current mix with the source video (MP4 upload or YouTube) into an MP4
DELETE /api/jobs/{id} Remove job dir from disk (terminal jobs only)

Troubleshooting

ffmpeg: command not found : install ffmpeg and restart with ./run.sh restart .

WARNING: [youtube] No supported JavaScript runtime : install deno ( brew install deno on macOS) and restart. Downloads still work without it but may pick suboptimal formats.

First separation is very slow: Demucs downloads htdemucs_6s weights (~170 MB) on first run; cached afterwards.

Demucs runs on CPU only: check the startup log for device=mps or device=cuda . If you see cpu , your torch install may be CPU-only.

Page reloaded mid-job: the job keeps running server-side. Wait for it to finish, then resubmit.

./run.sh: Permission denied : run chmod +x run.sh .


Layout on Disk

jobs/<job_id>/
└── stems/
    ├── vocals.wav      # the 6 Demucs stems (always present)
    ├── drums.wav
    ├── bass.wav
    ├── guitar.wav
    ├── piano.wav
    ├── other.wav
    ├── original.wav    # sum of un-selected stems (subset only)
    └── mix.wav         # ffmpeg amix of selected stems (subset only)

Job state is in-memory. Restart the server and the job list resets, but files persist on disk. Old dirs are swept automatically (TTL 24 h, configurable).


Disclaimer

StemDeck is a local audio stem separation tool intended for personal study, research, and experimentation. It is not a downloading service. It does not store, cache, or redistribute any audio content. All processing runs on the user's own machine and no audio is transmitted anywhere.

YouTube URL support is provided via yt-dlp as a convenience. Automated downloading may violate YouTube's Terms of Service. You, the user, are solely responsible for ensuring you have the right to process any audio you submit, complying with the terms of service of any site you download from, and respecting the copyright of the material you work with.

You are also responsible for following the licenses of the underlying tools this project depends on (yt-dlp, Demucs, FFmpeg, PyTorch, and others listed in pyproject.toml ).

The author(s) of StemDeck provide this software "as is", without warranty of any kind, and accept no responsibility or liability for how it is used.


Community

Platform Link
GitHub stemdeckapp/stemdeck
Discord discord.gg/YhCKsjhcwB
Reddit r/StemDeckApp
Instagram @stemdeck
X @StemDeckApp
Website stemdeck.app

Environment Variables

These are for development and testing. Release builds only recognize the variables marked "release".

Variable Platform Scope Description
STEMDECK_DATA_DIR all release Override the user data directory (default: platform-standard location)
STEMDECK_ROOT all release Override the app root directory (default: derived from executable path)
STEMDECK_PYTHON all debug builds only Override the Python executable path
STEMDECK_FFMPEG_URL Windows, macOS release Override the FFmpeg download URL
STEMDECK_FFPROBE_URL macOS release Override the ffprobe download URL

Contributing

Issues, feature suggestions, and pull requests are welcome. See open issues for what's planned.

Meta’s $17B Teen Addiction Settlement

Portside
portside.org
2026-08-28 21:23:15
Meta’s $17B Teen Addiction Settlement barry Fri, 08/28/2026 - 21:23 ...
Original Article

Meta has agreed to pay up to US$17 billion over 10 years to settle claims brought by a bipartisan coalition of state attorneys general. The states argued that the company deliberately designed Facebook and Instagram to hook children into using its apps, misled the public about the harm and improperly collected data from children under 13.

The settlement , announced by Meta on Aug. 26, 2026, ended a federal trial that had barely begun in Oakland, California. The potential financial exposure in the case was enormous, and Meta’s stock price took a hit. The states argued that penalties could reach hundreds of billions of dollars.

Against that backdrop, and with a $1.4 trillion question mark hanging over its valuation , Meta settled, although the company continues to deny wrongdoing. The settlement still requires approval from Judge Yvonne Gonzalez Rogers.

As a technology policy and law scholar, I follow with interest the litigation against Meta and other social media companies. The basic contours of this settlement are now public, and I believe they deserve careful attention because of the product design changes it might compel Meta, TikTok and YouTube to make.

What the states alleged

The Oakland case consolidated lawsuits filed in 2023 by 29 state attorneys general following a nationwide investigation that began in 2021.

Similar to prior litigation in Los Angeles and New Mexico , the states alleged that Meta engineered features – for example, infinite scroll, autoplay, push notifications, likes and appearance-altering filters – to exploit vulnerabilities associated with adolescent development and to maximize engagement.

States alleged that Meta’s internal research documented links between Instagram use and harms including depression, anxiety and body-image concerns among young people, while the company publicly minimized or concealed those risks.

A third set of claims concerned Meta’s collection of data from children under 13 without parental consent, allegedly in violation of federal children’s privacy law. And the states argued that these practices violated state consumer protection statutes as well.

That consumer protection claim is particularly important. For decades, Section 230 of the Communications Decency Act has protected platforms from liability for content posted by their users. But the states sued Meta instead over the company’s own product design, business practices and alleged misrepresentations, not user-generated content.

In opening arguments, California’s lawyer compressed the theory into four words, noting Meta’s business model was to “hook” users, “hold” them, “harvest” their data and “hide” the harm. And there was already precedent at the state level, in Massachusetts , of courts allowing this kind of claim to proceed.

The lawsuit and settlement focused on the design of Meta’s social media platforms and how the platforms need to change to protect teens.

One legal battle, several different cases

It is important not to conflate the cases. While the federal case in Oakland was settled as part of the agreement with the 47 states , major cases against Meta remain active.

In Los Angeles, a separate California state-court case resulted in a jury finding Meta and Google liable for negligently designing their products in ways that contributed to a teen girl’s mental health harms, with damages of $4.2 million against Meta and $1.8 million against Google. Those amounts look modest until multiplied across the thousands of similar individual claims now pending. Meta is appealing that decision.

And in New Mexico , the state pursued its own enforcement action, alleging that Meta endangered children and violated state consumer protection law. New Mexico won judgments against Meta totaling more than $900 million, which Meta is also challenging.

Neither of those cases was part of the federal trial, so today’s settlement does not resolve them, nor does it create legal precedent.

What the settlement actually changes

The design changes, such as curbing infinite scroll and autoplay, are the substantive core of the agreement. Subject to court approval, teens under 18 on Instagram and Facebook in participating states will get:

  • a default two-hour daily time limit, cumulative across both apps and across multiple accounts, that only a parent can lift
  • a block on app access between midnight and 6 a.m. and muted notifications during school hours (8 a.m. to 3 p.m.), excepting direct messages
  • usage prompts after every 15 minutes of continuous scrolling
  • the option of a non-algorithmic, nonpersonalized feed
  • the ability to turn off autoplay and for parents to set the default to “off”
  • hidden like counts by default
  • blocks on cosmetic surgery and extreme makeup filters
  • strengthened age-detection systems for under-13 accounts

Some of these measures are particularly significant because they change the default experience rather than simply adding another setting that users can choose to activate. This lowers the burden on the user. A safety tool that requires a teenager or parent to find, understand and turn on is fundamentally different from a safety constraint built into the product itself.

The agreement addresses the architecture that determines how the product operates. In doing so, it recognizes that Meta shares responsibility for the environment it creates, which is crucial because Meta holds significant power to shape how its products are used.

Why the design terms matter more than the money

Even $17 billion, spread across a decade, amounts to only roughly 1% of Meta’s expected revenue over the same period. The company has told investors that the settlement will not change its financial guidance beyond a single quarterly expense.

More consequential, for Meta and the public, is the requirement to redesign Facebook and Instagram.

However, redesign without serious transparency and accountability can quickly become another form of marketing. Meta has promised safety changes before, including teen accounts and expanded parental controls. Verification of the redesign and its real-world impact over time are key.

That is where the settlement is both promising and incomplete. An independent auditor will review Meta’s compliance annually, but only for five years, against a 10-year agreement. And Meta has committed to the strongest behavioral terms, the daily time limit and the overnight block, for just five years. It will extend to 10 with stricter defaults only if YouTube and TikTok sign on.

Meta has also committed to establish an independent research foundation. And this might address one of the deepest problems in technology governance: Platforms hold the evidence of their own effects, while independent researchers have been locked out.

But the strength of these mechanisms will depend on details not yet public. Who selects the auditor? What information can the auditor access? Can researchers independently reproduce findings? What constitutes noncompliance, and what penalties follow if Meta complies with the letter of the agreement while redesigning the product around its edges? Finally, how does the research foundation escape capture by Meta?

Technology governance increasingly fails not at the level of rules but at the level of enforcement.

There is also something the settlement forecloses. Trials produce public records, but settlements end the process of producing a record of the evidence. The internal documents and testimony surfacing in Oakland, including evidence about Meta’s own research on young users and its lawyers’ handling of those findings, will now remain only partially visible. The states secured a significant legal resolution, but the public lost part of the record of how we got here.

What comes next

Three things deserve close attention:

First, the implementation details matter.

The settlement’s significance depends on what happens after the press releases disappear. Do the new defaults actually constrain use? Are they hard to circumvent across accounts and devices? It is very hard to do age control in technology. And will teenagers simply migrate to other platforms outside the settlement’s reach, or into the direct messages the agreement itself exempts?

Second, there is the question of Meta’s competitors.

Participating states are guaranteed roughly 70% of the $17 billion, or about $12.7 billion over the decade, while the remaining 30%, about $5.3 billion, is released only if YouTube and TikTok adopt comparable teen protections and make matching payments. Meta essentially structured part of its own penalty as a recruitment device, effectively telling TikTok and YouTube that these rules are coming, and it is better to adopt them together than face the next litigation cycle alone.

There is also a clear economic incentive for Meta to try to level the playing field. Because if these measures make Meta’s products less profitable, imposing similar requirements on competitors could prevent Meta from bearing those costs alone. Whether that strategy works could matter as much as the settlement itself.

Third, federal social media policy in the United States is gridlocked . It took state attorneys general, applying consumer protection law, to produce rules about time limits, product defaults, notifications and design practices that Congress could have debated and enacted years ago.

The deeper lesson of today’s settlement is that product design, as a site of legal accountability, is a workable legal strategy.

Accountability starts when a company agrees to redesign its product. The settlement gives the states – and the rest of us – a decade to find out whether these changes are real, and if so, if they work for the desired policy outcome.

The critical question is whether, throughout that decade, someone independent will have the authority, access and incentives to decide what “work” really means. The Conversation

Carolina Rossini , Professor of Practice and Director for Program, Public Interest Technology Initiative, UMass Amherst

This article is republished from The Conversation under a Creative Commons license. Read the original article .

Debian and the sirens

JoeyMain
joeyh.name
2026-08-28 20:27:55
Thirty years ago I became a Debian developer. Twelve years ago I left the project. I left because it seemed that the Debian ship had become too slow to turn, too barnacled with a series of individually OK decisions that each added a little bit of friction and a little less flexability. That made Deb...
Original Article

Thirty years ago I became a Debian developer. Twelve years ago I left the project. I left because it seemed that the Debian ship had become too slow to turn, too barnacled with a series of individually OK decisions that each added a little bit of friction and a little less flexability. That made Debian strongly what it is, but prevented it from fruitfully exploring the vast possibility space of what it could be.

Debian will probably resolve today to allow LLM use in Debian development. I'm writing before the vote results are in, but will only post this afterwards. (Update: as expected) It's not my place any longer to try to steer the ship. But I'm still a passenger and I still have opinions, and I still pass by well-worn parts of the rigging that I put up decades ago, and remember what I was trying to accomplish back then.

When I think about LLMs in Debian development, I mostly think about debhelper and what it accomplished. The debian/rules files back when I joined the project were long and complex, full of weird boilerplate, and often you'd copy one and modify it to try to get something that could build a package without too much work. Debhelper first regularized the boilerplate, so packages had rules files that were a succession of dh_ commands, and then it scapped almost all of the boilerplate, reducing the files to the minimum possible. What was left was 3 lines of unncessary boilerplate, there only to satisfy a legalistic reading of a policy document. Changing that to eliminate the boilerplate was already impossible, even though the actual benefit would have been large over the many thousands of packages in the distribution.

What LLMs in Debian development will do, I fear, is eliminate any incentive to scrap boilerplate or reform policies that require a lot of other senseless human effort. If I had had access to LLMs 30 years ago, I might have just had them generate the rules files, replate with complexity. So they will make Debian even more firmly what it is, and ever less likely to explore what it could become.

Unfortunately, one of the things that Debian is, is almost unable to manage packaging modern dependency trees. While more recent distributions like Guix can recursively import dependencies from a dozen programming languages' package repositories, with a result that is generally acceptable to add to the distribution, Debian's policies don't make that very possible for a progam to accomplish. Perhaps some will use LLMs to do that. If they succeeed, Debian will become dependent on proprietary software for development, while still needing people in the loop, doing even less appealing scut-work.

I could speak of other harms, but that alone is enough that I'm sure that, if I had not left the project twelve years ago, I would be leaving it soon. As a passenger, I imagine I'll spend time aboard still from time to time, but it's certainly time to hop off in different places and look around and relish the different ways.

I lost a parent yesterday , and I'm trying hard not to think of the results today as having lost a child, though I spent 18 years helping Debian grow up. That would be too unbearably painful. I respect that Debian is navigating a choice that may have no right answer. Whichever particular compromise is arrived at today, it will still be up to individuals to make choices about what they do and accept. Debian has always been more than the sum of its policies, not just a ship, but a crew. I will always love you.

Does the Sumerian King List Align with Paleoclimate Events?

Hacker News
www.vectorian.be
2026-08-28 19:46:10
Comments...
Original Article

Context

The Sumerian King List starts with eight kings who ruled before the flood. Their reign lengths are enormous and unusually regular. Three examples are 28,800 years, 36,000 years, and 43,200 years. Most are integer multiples of 3,600, and all eight are multiples of 600. Their total is 241,200 years.

The input sequence tested here is the ETCSL composite antediluvian list:

Order King Reign length
1 Alulim 28,800 years
2 Alalgar 36,000 years
3 Enmenluana 43,200 years
4 Enmengalana 28,800 years
5 Dumuzid 36,000 years
6 Ensipadzidana 28,800 years
7 Enmenduranna 21,000 years
8 Ubara-Tutu 18,600 years
Total 241,200 years

The transliterations follow the composite text cited below. Like the post-flood sections of the King List, the antediluvian list is a textual tradition with variants, so the table is an analysis input rather than a claim about literal historical reigns.

One speculative interpretation treats these numbers as a distorted memory of prehistory. Under this hypothesis, the reign boundaries encode real climate shifts, eruptions, impacts, or sea-level changes. After rescaling and anchoring the list to a proposed flood date, the boundaries should coincide with dated events in the geological record.

Here, I test that idea with an exploratory analysis. The explorer rescales each chronology to a fixed 241.2 ka span, anchors one boundary, and compares the resulting dates with a catalog of Quaternary events. I use 11.6 ka BP, or about 11,600 years ago, as an analyst-chosen anchor near the Younger Dryas termination. The King List does not provide that date or suggest this paleoclimate interpretation.

Finding matches is easy. With nine boundaries and freedom to change the anchor or bandwidth, chance alignments are common. The relevant question is whether the observed Sumerian reign order scores unusually high under a clearly defined null model.

Results

  • In the primary paleoclimate catalog, the Sumerian sequence does not show a statistically significant alignment. At the fixed 11.6 ka anchor and a kernel bandwidth of σ = 1.60 ka, the permutation p-value is 0.350. After adjustment for multiple comparisons, q = 0.622.
  • Expanding the analysis to all 103 usable catalog entries increases the number of apparent matches but does not change the conclusion. At the same bandwidth, the wide-catalog p-value is 0.148 and the adjusted q-value is 0.430.
  • The smallest raw p-value for the Sumerian sequence occurs in the catastrophic exploratory catalog at σ = 1.60 ka: p = 0.021. This was the best result found in a larger exploratory search. After adjustment for all comparisons, q = 0.222, so the result does not support the hypothesis.
  • As a secondary check, I also count how many events fall within a fixed distance of a boundary. The kernel score is the main measure because it gives less weight to events farther away instead of using an abrupt cutoff.

What Would Count as Evidence?

A credible alignment would need to meet three conditions.

First, the text must determine which boundary to anchor. The Sumerian King List places the flood after the eighth reign, so I anchor the end of the antediluvian sequence. The text does not assign that boundary an absolute date. I use 11.6 ka BP as an analyst-chosen date near the Younger Dryas termination.

Second, the Sumerian sequence should look unusual next to other ancient chronologies. I compare it with a sequence derived from Biblical patriarchal ages, seven god and demigod reigns from the Manethonian fragment preserved in the Excerpta Latina Barbari, and the first eight listed Kish I rulers. These are examples for comparison, not independent statistical controls, and I do not test whether one chronology outperforms another. They show how readily unrelated ancient sequences can produce apparent matches under the same procedure.

Third, a credible result should remain significant after accounting for the tested chronologies, catalog tiers, and bandwidths. None does.

Interactive Explorer

Use the selectors below to switch chronology, catalog tier, and bandwidth. The primary paleoclimate catalog defines the main analysis. The wide and catastrophic catalogs provide exploratory sensitivity analyses. The fixed-anchor section uses p-values precomputed in Rust. The sliding-anchor section recomputes the anchor sweep in the browser.

Sumerian King List alignment explorer with fixed-anchor p-values and exploratory anchor sweeps.

Fixed-anchor analysis: Gaussian kernel with anchor fixed at 11.6 ka (precomputed in Rust)

Kernel score

-

at fixed anchor

Permutation p-value

-

raw p; BH-adjusted q

Binary hits

-

sensitivity measure

Adjustment for multiple comparisons across all fixed-anchor permutation tests: no result has q < 0.05.

Exploratory anchor search: best anchor from 10 to 13 ka (live)

Best anchor in window

-

maximum kernel score from 10 to 13 ka

Maximum kernel score

-

relative to the fixed 11.6 ka anchor

Monte Carlo exceedance estimate

-

3,000 windows with centers uniform from 0 to 100 ka

Kernel score as the anchor slides from 0 to 30 ka BP

11.6

Timeline at current anchor

-

How to Read the Numbers

The main statistic is a Gaussian kernel proximity score:

S = Σᵢ Σⱼ exp(-(tᵢ - bⱼ)² / 2σ²)

Here tᵢ is an event date and bⱼ is a reign boundary. A nearby event contributes almost one point, while the contribution of a distant event approaches zero. This avoids the abrupt discontinuity of a hard cutoff, where an event just inside the window counts and one just outside does not.

The two statistical questions are different. The simplest way to see the difference is to ask what is allowed to move:

Method Held fixed Allowed to move What is reported Role
Exhaustive permutation 11.6 ka anchor, catalog tier, bandwidth, and the same set of reign lengths The order of the reign lengths Fraction of all labeled orders that score at least as high as the observed order Primary p-value
Random-anchor Monte Carlo Reign order, catalog tier, and bandwidth The anchor, or the local anchor window Fraction of sampled anchors or windows that score at least as high Secondary sensitivity check

The two bandwidths are calibrated to have the same total weight as hard windows extending 1 ka and 2 ka on either side of a boundary. Using σ = τ·√(2/π) gives σ ≈ 0.80 ka and σ ≈ 1.60 ka. The browser truncates the kernel at 4σ for speed, matching the Rust precomputation.

The primary analysis fixes the anchor at 11.6 ka BP and reports the observed kernel score, a raw permutation p-value, and a q-value adjusted for multiple comparisons. The p-value comes from an exhaustive permutation test, not Monte Carlo sampling. The program checks every possible reign order. With the anchor, catalog tier, bandwidth, and set of reign lengths held fixed, the p-value is the fraction of those orders whose kernel score is at least as large as the observed score. Under this null model, every reign order is treated as equally plausible. The test does not account for choosing the anchor, catalog, bandwidth, or score after inspecting the data.

The primary catalog includes the Younger Dryas termination used to motivate the 11.6 ka anchor, so the terminal match is built into the setup. Its contribution is constant across reign-order permutations and is not evidence that the internal sequence is unusual.

The secondary anchor search asks how the result changes when the anchor is optimized after inspecting the data. It compares the maximum in the fixed 10 to 13 ka window with maxima from 3,000 windows whose centers are sampled uniformly from 0 to 100 ka. Both the fixed and random windows use a 3 ka width and 0.1 ka anchor spacing. The displayed Monte Carlo estimate adds one to both the exceedance count and the trial count so that a finite simulation never reports a probability of exactly zero. It is not the article’s primary p-value.

The fixed-anchor result card also reports a separate random-anchor sensitivity value. For each chronology, catalog tier, and bandwidth, the Rust program compares the score at 11.6 ka with scores from six million anchors sampled uniformly from 0 to 100 ka. This calculation is distinct from the browser’s 3,000-window maximum-score estimate. Neither value is the primary p-value.

Data and Comparators

The source catalog contains 104 dated events from the Quaternary period, grouped into 11 categories. The primary analysis uses a narrower paleoclimate catalog containing Heinrich-event dates, Greenland Interstadial onset dates, and selected Holocene climate-event dates. The resulting primary catalog contains 39 events within the 0 to 260 ka BP analysis window.

The wide exploratory catalog contains all 103 usable entries, including the 39 primary entries. It also includes meltwater pulses, Marine Isotope Stage boundaries, large volcanic eruptions, impact structures and contested impact hypotheses, geomagnetic excursions, extreme solar proton events, megafauna extinction nodes, and major cultural transitions. The catastrophic and deep-time tiers provide overlapping sensitivity analyses. Lonar is kept in the source catalog but excluded from the dashboard because it falls outside the analysis window.

Each entry records a selected date, an approximate uncertainty, source information, and whether the event is contested. The uncertainty values were estimated in different ways, so they are not directly comparable and should not all be read as standard errors. The current analysis uses only the selected dates. The wide catalog is still exploratory, even though every entry has a documented source.

For the Biblical comparator, the first eight values are patriarchal lifespans and the final 600 is Noah’s age at the flood. For the Excerpta Latina Barbari comparator, I use the seven named god and demigod reigns listed in that fragment: Hephaestus 680, Helios 77, Sosinosiris 320, Orus 28, Typhon 45, Anubes 83, and Amusis 67 years. For Kish I, I use the first eight rulers in the ETCSL composite text; that tradition has manuscript variants, so the comparator should be read descriptively rather than as a fixed historical chronology.

Each chronology is transformed in the same way. Reign lengths are rescaled so the total span equals the Sumerian antediluvian total of 241.2 ka, then converted to absolute dates by anchoring one boundary and accumulating durations backward in time. This normalization removes total duration as a factor and compares only the relative spacing of the boundaries.

The Rust program reads the same events.json catalog published with this article. It runs six million random-anchor trials per chronology, catalog tier, and bandwidth, runs exhaustive permutation tests, applies the Benjamini-Hochberg correction to the permutation p-values, and writes the result table used by the page. The TypeScript explorer loads the public catalog and result table, then calculates and displays the live anchor sweep.

Implementation Note

The expensive work runs offline in Rust rather than in the browser. The primary test is small enough to enumerate exactly: the Sumerian and Kish sequences each have 8! = 40,320 labeled orders, the Excerpta Latina Barbari sequence has 7! = 5,040, and the Biblical comparator has 9! = 362,880. Repeated reign lengths are still treated as labeled positions, so the null model asks whether this order is unusual among all reorderings of the same values.

The core calculations are explicit in the source: Gaussian kernel scoring, Heap’s algorithm for permutations, the random-anchor sensitivity check, the Benjamini-Hochberg step-up adjustment, and the deterministic JSON writer. The random-anchor sensitivity checks use a fixed seed, so rerunning cargo run --release regenerates the published result file rather than producing a new simulation each time.

Caveats

A Benjamini-Hochberg adjustment for multiple comparisons covers the 32 fixed-anchor permutation tests. It does not correct for earlier experimentation with event inclusion, anchor choices, score definitions, or comparator construction. Because this is an exploratory analysis and the full set of tests was not specified in advance, the q-values summarize this search rather than confirm a finding. No comparison has q < 0.05.

The catalog was assembled editorially rather than through a systematic review or an inclusion protocol defined in advance. Several entries describe related parts of the same climate sequence, so the 39 primary dates should not be interpreted as 39 independent observations. The permutation test keeps this catalog fixed; it cannot make the catalog independent or complete.

Catalog density varies substantially over time. Recent events are more numerous and generally better dated, so chronologies with Holocene boundaries have more opportunities to match an event. The permutation test partly addresses this imbalance by holding the anchor and event catalog fixed while changing only the reign order.

The deep-time sensitivity tier removes the crowded recent record by using only dates older than 60 ka. The Sumerian sequence scores at or below chance at both bandwidths.

The analysis does not carry dating uncertainty through the calculations. Several entries have uncertainties wider than the fixed matching windows, and the Younger Dryas impact hypothesis remains disputed. Treating every entry as an exact date overstates the precision of the result.

The reported p-values and q-values do not fully account for analyst choices, including decisions made after inspecting the matches. The interface exposes some of these choices, but the analysis remains exploratory.

Data and Code

The event catalog and generated result table are public and machine-readable:

The event catalog records the analysis tier, date estimate, uncertainty, source URL, contested flag, and editorial notes for each entry. The result file contains the values generated by the Rust program and displayed by the browser explorer.

Selected Sources

Next Steps

A future version should put the dating uncertainties on a more consistent basis and carry them through the calculations. Repeatedly sampling plausible dates for each event would produce a range of scores and hit counts instead of a single value for each.

A stronger analysis would use a catalog assembled independently and defined before any chronology is scored. Repeating the procedure with several such catalogs would test whether the result depends on the underlying event data or on editorial curation.

This analysis explores a specific alignment claim. It finds no statistically significant evidence that the Sumerian reign order encodes the paleoclimate catalog used here.

9th Circuit sides with states in Kalshi gambling fight

Hacker News
azmirror.com
2026-08-28 19:32:22
Comments...

I accidentally turned LLM memory into program analysis

Hacker News
pwning.systems
2026-08-28 19:27:45
Comments...
Original Article

Over the past few months I have been playing around quite a bit with LLM agents, particularly for vulnerability research.

They are becoming surprisingly good at navigating large codebases, explaining unfamiliar subsystems and helping explore potential attack surfaces. However, once an investigation starts taking a few hours, I kept running into the same problem: the model would slowly lose track of what we had actually established.

It might suggest an approach that we had already ruled out, forget that an assumption turned out to be false, or confidently continue reasoning from an observation that was no longer valid. Obviously, telling an LLM that something is wrong does not necessarily mean that it will stop believing all of the things that depended on it :)

I initially started looking into memory systems because I wanted to make LLMs more useful for complex vulnerability research and reduce this type of hallucination.

There are of course already plenty of solutions for giving LLMs memory. Usually this involves storing old conversations or observations somewhere, embedding them, and then retrieving the most relevant pieces whenever the model needs them again.

This works reasonably well, but there was something about it that bothered me.

During a vulnerability research sesh, I don’t just want the model to remember what we said.

I want it to maintain what we currently know .

Imagine that during an investigation we establish the following:


attacker controls object_a
object_a points to object_b
object_b is a kernel object

From this, we may conclude that the attacker can control a kernel object.

A normal memory system could store all of these observations and retrieve them again whenever we ask about the exploitability of the bug. The LLM then figures out the same conclusion.

Great!

However, suppose that two hours later we discover in LLDB that object_a does not actually point to object_b , and that our previous observation was based on a wrong assumption.

At that point our memory may contain something like:

object_a points to object_b
attacker can control object_b
object_a does not actually point to object_b

Now we retrieve some subset of these memories and hope that the LLM correctly figures out which conclusions are still valid.

This started to feel a little familiar to me.

This looks like program analysis

A lot of the work I normally do involves program analysis.

When analysing a program, we usually have a bunch of facts about the program and some rules that derive additional facts from them.

For example, imagine we know:

calls(foo, bar)
calls(bar, baz)

We could define a rule stating that if one function calls another function, which itself can reach a third function, then the first function can reach the third function as well.

Eventually we calculate a fixed point containing everything we can derive from the program. More importantly, if one of our input facts changes, there are plenty of techniques for updating only the affected results instead of rerunning everything from scratch.

This is also exactly what I wanted from an LLM during vulnerability research.

If an observation changes, I don’t want the model to reconstruct the entire investigation from a transcript and hopefully notice all of the consequences. I want the affected conclusions to become invalid automatically.

When looking at the problem from this perspective, I started wondering why we were making the LLM reconstruct its entire state over and over again.

What if we just maintained it?

And this is how I somehow ended up writing a Datalog engine for LLMs :)

Datalog

Before we continue, it is probably useful to briefly explain what Datalog actually is.

Datalog is a declarative logic programming language. Instead of writing instructions describing how something should be calculated, we describe facts and rules from which new facts can be derived.

For example, we could store the following facts:

controls(attacker, object_a).
points_to(object_a, object_b).
kernel_object(object_b).

And then define the following rule:

controls_kernel_object(Attacker) :-
controls(Attacker, ObjectA),
points_to(ObjectA, ObjectB),
kernel_object(ObjectB).

From our existing facts, the engine can therefore derive:

controls_kernel_object(attacker).

Nothing particularly exciting yet.

However, suppose we later discover that:

points_to(object_a, object_b).

was incorrect.

If controls_kernel_object(attacker) was derived from that fact, we know exactly which conclusion depends on the observation that just changed, and we can automatically invalidate it.

This is considerably nicer than putting all of the old information into a prompt and asking an LLM to hopefully notice the same thing.

Lemmalog

This eventually turned into Lemmalog .

The basic idea is that an LLM should not necessarily be responsible for maintaining its own knowledge. Instead, I split the problem into two parts.

The LLM handles the fuzzy part:

"LLDB shows that the freed object is later reused
as the destination of the write."
|
v
freed(object_a)
reused_as(object_a, write_target)

And Lemmalog handles the deterministic part:

facts
|
v
rules
|
v
derived facts

This means that the LLM is still responsible for understanding natural language, source code, debugger output and all the other messy information that appears during an investigation.

LLMs happen to be quite good at this.

But once that information has been converted into structured facts, we no longer need the model to repeatedly determine all of its consequences. The database can do that instead.

Retractions

One of the first interesting problems I ran into was removing facts.

Adding facts to a Datalog database is relatively straightforward: add the new fact and evaluate any rules which may now produce additional results.

Removing something is a little more annoying.

Take the following example:

Here c has two separate reasons for being true.

If we remove a , we cannot simply remove c , because b still provides another derivation for it. However, if we remove both a and b , c should disappear as well.

This turns out to be quite important during vulnerability research, because a conclusion may be supported by multiple observations.

For example:

candidate_3_is_exploitable

may remain true even if one particular exploit primitive turns out not to work, because there is another independent path to the same result.

So Lemmalog has to keep track of how facts were derived and update their support when something changes.

Conveniently, this also gives us another useful property:

we can ask why something is true.

Why?

Imagine we have been running an agent for a few hours while investigating something and it eventually concludes:

candidate_3_is_exploitable

That is nice, but I would also quite like to know why.

Because Lemmalog already tracks the dependencies of derived facts, we can ask it for the provenance of a conclusion. For example, we may get something that conceptually looks like this:

candidate_3_is_exploitable
|
+-- attacker_controls_pointer
| |
| +-- observation_41
|
+-- pointer_reaches_target
|
+-- observation_57
+-- rule_12

If observation_41 later turns out to be incorrect, we know that this conclusion may no longer be valid, and because the database knows this as well, it can remove the affected conclusions automatically.

This was originally mostly necessary to make incremental evaluation work correctly, but it turns out that being able to ask an AI agent why it believes something is quite useful as well :)

It also addresses one of the more annoying failure modes I encountered with LLM-assisted research. Sometimes a model will confidently say something like:

we already established that this pointer is attacker-controlled

when that is not actually true.

If a conclusion exists in Lemmalog, I can ask where it came from. If there is no provenance supporting it, then it is not part of the maintained state.

This obviously does not prevent an LLM from hallucinating during extraction, but it does make it much harder for unsupported conclusions to silently become part of the investigation.

Facts also change over time

Another issue is that replacing old facts is not always the same as deleting them.

Suppose we originally believe:

and later discover:

primitive_a is not viable

For most current queries, we probably only care about the second statement. However, if we want to understand why we previously explored a particular exploit strategy, the old state is still useful.

For this reason Lemmalog can associate facts with validity intervals.

Conceptually, we can represent the state as something like:

viable(primitive_a) [10:14, 12:37)
not_viable(primitive_a) [12:37, ...)

This allows us to answer both:

Is primitive_a viable now?

and:

Why did we think primitive_a was viable earlier?

without keeping two apparently contradictory facts around and asking the LLM to decide which one we meant.

Again, this is not really a language model problem.

It is mostly a database problem.

Why not just use a vector database?

Vector databases are very useful.

If I ask:

What did we find earlier about this allocation path?

semantic search is probably exactly what I want.

But cosine vibe similarity and truth are not quite the same thing.

A vector database can retrieve:

object_a points to object_b

because it is relevant to my question. It does not inherently know that the statement was disproven two hours later, or that five other conclusions depended on it and should therefore no longer be considered valid.

This made me realise that there are really two different problems hiding under the term “memory”.

The first is:

What information from the past is relevant to this question?

The second is:

Given everything we have learned so far, what is currently true?

Retrieval is very good at the first problem.

Lemmalog is mostly an experiment in solving the second one.

The two can also be combined, which is what I currently do.

A vulnerability investigation is basically an analysis state

The more I worked on this, the more similarities with program analysis started appearing.

During a vulnerability investigation we have observations:

this field is attacker-controlled

assumptions:

this object survives until the second callback

relationships:

primitive_b depends on primitive_a

hypotheses:

this could become an arbitrary write

and conclusions:

candidate_3 is exploitable

This maps surprisingly well to the things we already do in program analysis.

We have input facts:

rules:

relationships between observations

derived facts:

a fixed point:

everything currently known

and when an input changes, we perform incremental evaluation:

update affected conclusions

Because we track dependencies, we can also explain where results came from:

At some point it became fairly obvious that I had approached the problem like a static analysis engine without intentionally meaning to.

This also changed how I thought about the role of the LLM itself.

You can almost think of the whole system as a slightly strange compiler.

The LLM acts as the front-end:

     source code,
   debugger output,
natural language notes
          |
          v
   structured facts

Lemmalog is the intermediate representation and analysis engine:

structured facts
       |
       v
deductive rules
       |
       v
maintained state

Another LLM invocation can eventually turn that state back into natural language, suggest the next experiment, or use it to perform some action.

The amusing part is that our parser is probabilistic, while everything after it does not necessarily have to be.

Does it actually make LLMs better?

This is of course the important question.

The engine itself now supports incremental evaluation, retractions, provenance, temporal facts, aggregations, entity reconciliation, hybrid retrieval, demand-driven queries and a bunch of other things that I probably added because implementing Datalog features is more fun than I expected.

There is also an MCP server which allows agents to use Lemmalog directly.

But none of that matters very much if giving an LLM this memory does not actually improve anything.

So I plugged it into MemEval and tested it on both LongMemEval and LoCoMo using their standardized reader models and evaluation setup. Extraction during ingestion is Claude Sonnet 4.6 (chunked and file-cached, so it is paid once per conversation); everything after extraction uses the benchmark’s own standardized readers and judges.

The results were a little better than I expected.

LongMemEval

LongMemEval tests whether an LLM can answer questions about information spread across long conversation histories. The split I used contains 102 questions, divided equally between user facts, assistant facts, preferences, multi-session questions, temporal reasoning and knowledge updates.

Because 17 questions per category is not exactly a massive sample size, I ran Lemmalog three times rather than getting excited about whichever run happened to score highest.

The result was:

Lemmalog
F1: 0.463 +/- 0.010
Accuracy: 0.575 +/- 0.004

For comparison, the published memory-system results are:

PropMem 0.550
SimpleMem 0.480
Lemmalog 0.463 +/- 0.010
OpenClaw 0.244
Full Context 0.222

My own full-context GPT-4.1 run scored 0.197 F1.

So Lemmalog is not beating PropMem yet, and it is still slightly behind SimpleMem, but it gets more than twice the F1 of giving GPT-4.1 the entire conversation.

More amusingly, the context passed to the answering model is roughly 38 times smaller .

Full context: ~104,000 tokens/question
Lemmalog: ~2,700 tokens/question

Apparently maintaining state instead of repeatedly rereading the entire history is useful :)

The category results from one representative run looked like this:

System SS-User SS-Asst Preference Multi-Session Temporal K-Update
PropMem 0.851 0.767 0.147 0.582 0.424 0.528
SimpleMem 0.752 0.566 0.126 0.382 0.578 0.475
Lemmalog 0.790 0.672 0.128 0.211 0.416 0.579
OpenClaw 0.401 0.432 0.127 0.082 0.185 0.234
Full Context 0.265 0.415 0.177 0.062 0.212 0.202

The result I found most interesting was Knowledge Update.

Lemmalog scored 0.579 , compared with 0.528 for PropMem and 0.202 for full context.

Knowledge Update is basically the situation I originally cared about:

we believed A
|
later we learn that A is no longer true
|
what should we believe now?

So seeing Lemmalog top the published field on the category that most closely resembles maintained program state was rather satisfying.

Single-session factual memory also worked surprisingly well. Lemmalog reached 0.790 on user facts and 0.672 on assistant facts, while temporal reasoning reached 0.416 , almost identical to PropMem’s 0.424 in that run.

The obvious remaining problem is multi-session reasoning:

PropMem 0.582
SimpleMem 0.382
Lemmalog 0.211

Diagnosing those failures was interesting: the information usually was not mis-connected, it was simply never extracted. If the extractor never emits a fact for the Airbnb booking, no amount of derivation is going to answer a question about it.

Which brings us to one of the more amusing parts of running benchmarks.

I accidentally taught it not to answer questions

At one point LongMemEval suddenly dropped to 0.371 F1.

After going through the failures, I discovered that 32 of the 102 questions were being refused .

All 32 were answerable.

Questions such as:

Which airline did I fly most?

or:

How many magazine subscriptions do I have?

were returning:

The problem was an instruction I had added to reduce hallucinations. I told the reader to make sure that the answer was actually supported by the retrieved facts before answering.

Unfortunately, the model interpreted this as:

If no single fact literally contains the final answer, refuse.

There is obviously no fact saying:

most_flown_airline(user, swiss)

if the memory instead contains:

flew(user, swiss, trip_1)
flew(user, swiss, trip_2)
flew(user, lufthansa, trip_3)

The answer exists. It just requires counting.

The fix was to separate two cases:

  1. If the premise is absent or misattributed, refuse.

  2. If the evidence exists but requires counting, comparing, combining or ordering facts, actually reason over it.

After fixing that, F1 recovered to 0.429 .

The rest of the gap turned out to be sneakier: the counting path had been silently dead the entire time. Count lines were passed through a relevance filter before being shown to the reader, and the plural stemmer used by that filter only folded words longer than four characters. So owns never matched own , every count line was dropped, and counting questions quietly received no counts at all.

Fixing the stemmer, rendering counts together with the facts they count, and precomputing date arithmetic instead of hoping the model would correctly subtract two dates brought F1 to 0.463 .

This distinction also turns out to matter quite a bit on another benchmark.

LoCoMo

I also ran Lemmalog against the full LoCoMo benchmark.

LoCoMo is considerably larger: 10 long conversations containing 1,986 questions covering factual recall, temporal reasoning, multi-hop questions, inference and adversarial false-premise questions.

This one was particularly useful because 1,986 questions makes it considerably harder to accidentally get excited about a lucky seed.

Again, I ran the entire benchmark three times.

Lemmalog LoCoMo:
0.533 +/- 0.001 F1

The published comparison looks like this:

System F1
PropMem 0.605
OpenClaw 0.557
Full Context 0.542
Lemmalog 0.533 ± 0.001
Hindsight 0.489
Graphiti 0.416
Memory-R1 0.389
SimpleMem 0.358

So Lemmalog currently sits third among the dedicated memory systems in this comparison, behind PropMem and OpenClaw.

If we count throwing the entire conversation into the prompt as a memory system, it is fourth.

Which I think is fair :)

More importantly, the three runs were almost identical, so ~0.53 seems to be a real result rather than benchmark noise.

The per-category results from the final configuration look like this:

Category Lemmalog PropMem Full Context
Factual 0.399 0.431 0.517
Temporal 0.454 0.615 0.369
Multi-hop 0.545 0.599 0.674
Inferential 0.164 0.289 0.197
Adversarial 0.707 0.794 0.509

There are two results here that I particularly like.

The first is temporal reasoning.

The initial version of Lemmalog scored:

After fixing temporal normalization and retrieval:

The bug was actually quite funny.

At one point I was comparing date-like values as interned Datalog symbols.

The engine’s < operator on symbols compares their internal ids.

Internal ids are obviously not dates :)

After normalising extracted dates into comparable integers and deriving happened_before from actual timestamps, temporal performance jumped by almost twenty F1 points.

The second result I like is adversarial questions.

Lemmalog scores:

while full context scores:

These questions deliberately contain false or misattributed premises.

For example, the conversation may contain a story about somebody receiving a gift, followed by a question which attributes the same gift to somebody else.

A language model with a giant transcript is rather tempted to find the semantically similar story and answer anyway. A structured memory can instead notice that there is simply no supporting fact about the person in the question.

In other words:

turns out to be quite a useful answer.

The front-end matters a lot

The first LoCoMo implementation scored 0.483 .

The current one scores about 0.533 .

The Datalog evaluator did not suddenly become 10% smarter.

Most of the improvement came from fixing how information gets into and out of the analysis state.

Entity resolution, for example, turned out to matter quite a lot.

Imagine the following sessions:

Session 1:
"I bought a Honda Civic."

Session 3:
"My car broke down."

Session 7:
"The Civic is finally fixed."

If extraction produces:

bought(user, honda_civic).
broke_down(car).
fixed(civic).

then the Datalog engine is doing exactly what we asked it to do.

Unfortunately, we asked it to reason about three different objects.

So Lemmalog now has a reconciliation pass which connects episode-local mentions to canonical entities.

Pure lexical retrieval also caused some funny failures. A question referring to a:

would not necessarily retrieve a fact about an:

even though the relationship is obvious to us.

Retrieval now combines BM25, graph/entity boosts and embeddings, while the final context contains both the structured facts and the original source snippets they came from.

This was another useful reminder that the difficult part of this architecture is not necessarily computing the fixed point.

It is building a good IR from natural language.

Which, again, feels suspiciously like program analysis.

Some things should probably stay fuzzy

There is also one area where Lemmalog remains rather bad: inference.

On LoCoMo:

PropMem 0.289
Lemmalog 0.164

This makes sense.

Suppose somebody says:

I usually prefer quiet restaurants, except when I'm travelling
with friends, when I quite like somewhere lively.

Flattening that into:

prefers(user, quiet_restaurants).

has thrown away half of the useful information before Datalog has even seen it.

The obvious direction is not to abandon structured memory, but to stop pretending that every memory is an unconditional tuple.

Conditional knowledge can remain conditional:


prefers(User, lively_restaurants) :-
    prefers_when(User, lively_restaurants, with_friends),
    with_friends(User).

And the original episode text can remain available for situations where the structured representation loses useful nuance.

The useful architecture therefore looks less like:

vector memory
OR
symbolic memory

and more like:

                       agent memory
                             |
              +--------------+--------------+
              |                             |
       deductive state               episodic memory
              |                             |
       facts / rules / time          fuzzy context
       provenance                    semantic retrieval
       retractions                   source text

Which is fortunately pretty close to what Lemmalog has become anyway.

The token thing

There is one other part of the result which I did not originally expect to be quite as large.

For LongMemEval, the answering model sees roughly:

Full context: ~104,000 tokens/question
Lemmalog: ~2,700 tokens/question

Around 38x less context .

For LoCoMo:

Full context: ~18,900 tokens/question
Lemmalog: ~3,400 tokens/question

Around 6x less .

There is of course an extraction cost.

The conversation has to be read once and turned into facts, so saying that the whole system is simply 38 times cheaper would be dishonest.

The important distinction is that extraction happens once.

Full-context prompting pays for the entire history again on every query.

With a persistent agent, the difference therefore grows over time.

Conceptually:

Turn Full context Lemmalog
50 100K/query ~2.5K/query
100 200K/query ~2.5K/query
500 1M/query ~2.5K/query

At some point the full-context version doesn’t merely become expensive.

It stops fitting in the context window.

Lemmalog’s query context does not grow with the entire transcript because it retrieves the relevant maintained state instead.

Which was kind of the original point.

Does this prove anything?

Not quite yet.

LongMemEval is 102 questions, and LoCoMo is still a conversational-memory benchmark rather than a vulnerability investigation.

PropMem also still beats Lemmalog overall on both standardized comparisons.

So I am not going to claim that Datalog has solved LLM memory :)

But I do think the results are enough to show that the idea is not completely stupid.

Across three LongMemEval runs, Lemmalog scores:

0.463 +/- 0.010 F1
0.575 +/- 0.004 accuracy

And on LoCoMo:

It is particularly competitive when the task rewards the things the architecture was designed for: knowledge updates, temporal state, multi-hop relationships and rejecting unsupported premises.

Perhaps the most interesting result to me, though, is not the final number.

The first standardized LongMemEval configuration scored:

The current one scores:

More than twice as high.

Most of that improvement came from looking at individual failures and discovering fairly concrete computer science problems:

  • entity identity was disconnected
  • dates were represented incorrectly
  • retrieval missed semantic aliases
  • aggregation existed but wasn’t surfaced
  • a plural stemmer didn’t think “owns” matched “own”
  • the reader had accidentally been taught to refuse synthesis

None of those required making the language model larger.

They required maintaining better state around it.

Which is a result I find rather funny given why I started this project.

The next experiment is therefore the one I actually care about.

Give an agent a complicated vulnerability investigation, let it run for a long time, and see whether maintaining its analysis state stops it from resurrecting dead hypotheses and hallucinating relationships between observations.

That will probably be more interesting than remembering where Alice works :)

Conclusion

I didn’t really want to give the LLM a better memory.

I wanted it to stop forgetting why we believed things.

If an agent has already discovered that:

and later learns that A is no longer true, we shouldn’t need to give it fifty old messages and ask it to figure out whether C should still be trusted.

Likewise, if an exploit strategy depends on an assumption that we have just disproven in a debugger, I don’t want the model to suggest the same strategy again two hours later because an old conversation happened to be semantically relevant.

We already know how to solve problems involving facts, dependencies, invalidation and fixed points. We’ve been solving them in databases and program analyses for decades.

The benchmark results at least suggest that this isn’t only a nice idea in theory.

Lemmalog is already competitive with dedicated LLM memory systems, substantially outperforms full context on some of the tasks it was designed for, and does so while giving the reader a tiny fraction of the original history.

There is still plenty that it is bad at.

But perhaps we don’t need a bigger context window every time an agent forgets something.

Sometimes we can just maintain the state.

The source code for Lemmalog is available here .

Cheers!

Boot a Virtual iPhone via Apple's Virtualization.framework

Hacker News
github.com
2026-08-28 19:02:21
Comments...
Original Article

Boot a virtual iPhone via Apple's Virtualization.framework using PCC research VM infrastructure.

poc

Prerequisites

Host:

Dependencies:

brew install python@3.13 aria2 wget gnu-tar openssl@3 ldid-procursus sshpass keystone cmake libusb ipsw zstd

Install

brew install zqxwce/tap/vphone-cli

Build

git clone --recurse-submodules https://github.com/Lakr233/vphone-cli.git

./scripts/setup_tools.sh      # install deps, build toolchain submodules, create the Python venv
./scripts/build.sh            # build + sign vphone-cli, bundle the .app, cross-compile vphoned

cd .build/vphone-cli.app/Contents/MacOS/
vphone-cli --help

Quick Start

One command creates a VM end-to-end (download → patch → DFU restore → CFW install → first boot):

vphone-cli vm create myphone -V jb        # -V / --variant

vphone-cli vm launch myphone

Commands

vphone-cli vm create runs the whole pipeline; the individual steps below let you drive it manually or re-run one stage.

Manage

vphone-cli vm list                         # list VMs (--json for scripting)
vphone-cli vm info myphone                  # show one VM
vphone-cli vm new myphone                   # create an empty bundle (cpu/mem/disk options)
vphone-cli vm config myphone --cpu 8 --memory 8192
vphone-cli vm clone myphone myphone-2       # fast APFS clone, fresh device identity
vphone-cli vm export myphone --out myphone.tzst   # zstd fast by default (--max = xz -9); --out may be a dir (auto-names <vm>.tzst/.txz); skips restore dir + staging files
vphone-cli vm import myphone.tzst --name restored
vphone-cli vm rename myphone iphone16
vphone-cli vm delete iphone16

Build a VM manually (what vm create automates)

vphone-cli vm new myphone                              # 1. empty bundle
vphone-cli fw prepare myphone --iphone-version 26.1     # 2. download + merge IPSWs
vphone-cli fw patch myphone --variant jb                # 3. patch the boot chain

vphone-cli vm launch myphone --dfu &                    # 4. boot into DFU (background)
vphone-cli restore myphone --get-shsh                   #    fetch SHSH
vphone-cli restore myphone                              #    DFU restore
vphone-cli vm stop myphone                              #    stop the DFU boot

vphone-cli cfw install myphone --variant jb             # 5. install CFW (host-mount; asks for sudo)
vphone-cli vm launch myphone                            # 6. first boot

Update to a newer iOS by pointing fw prepare at an IPSW: --iphone-source /path/to.ipsw --cloudos-source /path/to.ipsw .

Firmware Variants

Five patch variants with increasing security bypass — pass one to --variant :

Variant Boot Chain CFW Notes
less 4 patches 2 phases Patchless — keeps iOS mitigations enabled
regular 42 patches 10 phases AMFI/SSV/Img4/TXM bypass
dev 53 patches 12 phases + TXM entitlement/debug bypass
jb 113 patches 14 phases + full jailbreak (Sileo, TrollStore auto-install on first boot)
exp 141 patches 18 phases JB superset + anti-VM-detection research patches

See research/0_binary_patch_comparison.md for the per-component breakdown.

Running & Connecting

  • SSH (jailbreak): ssh -p 22222 mobile@<vm-ip> (password alpine )
  • SSH (regular/dev): ssh -p 22222 root@<vm-ip>
  • VNC: vnc://<vm-ip>:5901

Locations

Everything vphone-cli creates lives under ~/.vphone/ — kept outside the repo and the .app so the signed bundle stays portable. Redirect the whole tree with $VPHONE_ROOT :

Path Contents
~/.vphone/ The per-user data root — override the entire location with $VPHONE_ROOT .
~/.vphone/VMs/ VM bundles — one directory per VM. This is the library; override with $VPHONE_LIBRARY_ROOT .
~/.vphone/ipsws/ Downloaded iPhone + cloudOS IPSWs, cached and reused across VMs.
~/.vphone/tools/ Cached APFS seal-volume artifacts ( apfs_sealvolume_<version> ) fetched during fw prepare .
~/.vphone/debs/ Cached .deb packages the jb / exp CFW install lays into the guest (Sileo, apt, …).
~/.vphone/venv/ Auto-provisioned Python environment (see Python runtime ; override with $VPHONE_VENV_DIR ).

Precedence: the per-item overrides ( $VPHONE_LIBRARY_ROOT , $VPHONE_VENV_DIR ) win over $VPHONE_ROOT , which wins over the ~/.vphone default. The ipsws/ , tools/ , and debs/ caches always sit directly under whichever root is active.

SIP/AMFI Relaxation

Option A — fully disable SIP, then disable AMFI via boot-arg (most permissive).

In Recovery (long-press power → Terminal):

csrutil disable
csrutil allow-research-guests enable

Then reboot into macOS and set the AMFI boot-arg (needs SIP fully off to take effect):

sudo nvram boot-args="amfi_get_out_of_my_way=1 -v"   # reboot after

Option B — keep SIP on (debug-only relaxed), then allowlist the binary with amfidont (leaves AMFI enabled system-wide).

In Recovery:

csrutil enable --without debug
csrutil allow-research-guests enable

Then reboot into macOS and:

vphone-amfidont         # .build/vphone-cli.app/Contents/Resources/vphone-amfidont for local builds

Tested Environments

Host iPhone CloudOS
Mac16,11 27.0b2 17,3_18.6.2_22G100 26.1-23B85
Mac16,8 26.5.1 17,3_26.0_23A341 26.1-23B85
Mac16,8 26.5.1 17,3_26.0.1_23A355 26.1-23B85
Mac16,12 26.3 17,3_26.1_23B85 26.1-23B85
Mac16,12 26.3 17,3_26.3_23D127 26.1-23B85
Mac16,12 26.3 17,3_26.3_23D127 26.3-23D128
Mac16,12 26.3 17,3_26.3.1_23D8133 26.3-23D128
Mac16,11 26.2 17,3_26.4_23E246 26.4-23E5207q
Mac16,11 26.2 17,3_26.5_23F77 26.4-23E5207q
Mac16,11 27.0b2 17,3_26.5.2_23F84 26.4-23E5207q
Mac16,6 26.4.1 17,3_26.6_23G71 26.4-23E5207q
Mac16,11 27.0b2 17,3_26.6.1_23G83 26.4-23E5207q
Mac16,11 27.0b2 17,3_27.0_24A5380h 26.4-23E5207q
Mac16,6 26.4.1 17,3_27.0_24A5390f 26.4-23E5207q
Mac16,6 26.6.1 17,3_27.0_24A5408d 26.4-23E5207q
Mac16,11 27.0b2 17,3_27.0_24A5418b 26.4-23E5207q
Mac16,11 27.0b2 17,3_27.0_24A5424a 26.4-23E5207q

FAQ

zsh: killed ./vphone-cli — AMFI/debug restrictions aren't bypassed; see Prerequisites ( amfi_get_out_of_my_way=1 or amfidont ).

Virtualization is not available on this hardware — your Mac is itself a VM; PV=3 guest boot can't nest. Use a non-nested macOS 15+ host.

Stuck on "Press home to continue" — connect via VNC and right-click (two-finger click) to simulate the home button.

System apps won't install — during iOS setup, don't pick Japan or the EU as your region (extra regulatory checks the VM can't satisfy); pick e.g. United States.

App crashes on launch with EXC_GUARD / GUARD_TYPE_MACH_PORT — re-patch with vphone-cli fw patch <name> --variant <v> --force-exc-guard , then re-restore/install ( #291 ). Always on for iOS 18 bases.

Install a .ipa / .tipa — use the running VM's Install menu (drag-drop or file picker).

cfw install hangs re-signing a system binary (e.g. Campo ), memory climbing unbounded — known bug in ldid-procursus up to 2.1.5-procursus7 (the current Homebrew stable ): bytes(uint64_t) calls __builtin_clzll(0) with no zero-guard, which is undefined behavior, and on this build resolves to a 0 -length that underflows an unsigned loop counter — ldid spins writing one byte at a time into a growing buffer instead of terminating. Triggered by any entitlements plist containing an integer value of exactly 0 (some real Apple system binaries have these). Fixed upstream but not yet in a tagged release; rebuild from source: brew install --HEAD ldid-procursus && brew link --overwrite ldid-procursus . Kill the hung ldid process first ( sudo kill -9 <pid> ) if you already hit it.

Automation

vphone-cli exposes a host control socket ( <bundle>/vphone.sock ) for programmatic control — screenshots, touch, swipes, hardware keys, clipboard — each action returning an inline screenshot for AI-driven E2E testing. See vphone-mcp for an MCP server wrapping it.

Acknowledgements

McKesson discloses breach after ShinyHunters claims patient data theft

Bleeping Computer
www.bleepingcomputer.com
2026-08-28 18:40:17
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]...
Original Article

McKesson headquarters

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.

McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies.

CyberInsider first reported the breach earlier today, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission.

image

McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation remains in the early stages.

"Information about the incident, including any updates, is available on the company's website at www.mckesson.com/cybersecurity ," McKesson said in its SEC filing .

"As of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations."

In a separate notice to customers, McKesson confirmed that the incident involved third-party applications and the unauthorized access and exfiltration of data.

"We take the security and privacy of our partners, customers and their patients very seriously. Upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to assist in our response," reads McKesson's notice .

The company said its investigation is ongoing to determine the full scope of the incident.

McKesson also warned that customers may experience intermittent service degradation believed to be related to the attack, although the company said it was not proactively disconnecting systems within its environment.

At this time, McKesson has not publicly disclosed which third-party applications were compromised, how the attackers gained access, or what information was stolen.

McKesson says its investigation remains ongoing and that it will provide additional information as it develops a more complete understanding of the incident.

ShinyHunters claims responsibility

The ShinyHunters extortion group told BleepingComputer that it was behind the attack, claiming it gained access after conducting voice phishing, or vishing, social engineering attacks against multiple McKesson employees.

ShinyHunters declined to provide many technical details about the social engineering attacks, including the domain used during the campaign. However, BleepingComputer learned from another source that the threat actors used the mckesson[.]claims domain as part of the attack.

This domain matches a ShinyHunters campaign recently documented by ReliaQuest's Threat Research team , which said the extortion group was registering .claims domains containing the names or abbreviations of targeted companies to impersonate their help desks and IT teams.

"ReliaQuest is tracking a widespread ShinyHunters campaign using domains that follow the company[.]claims pattern. These domains incorporate the targeted organization's name or abbreviation under the .claims TLD," ReliaQuest said in a now-deleted post on X.

ShinyHunters told BleepingComputer that the vishing attacks led to the compromise of multiple employees' Okta single sign-on accounts, which they then used to access the company's Salesforce and Snowflake environments.

The threat actor claims it fully compromised the Salesforce environment, including support cases. The threat actor also allegedly stole a much larger collection of patient-related data from Snowflake.

According to ShinyHunters, the threat actor exfiltrated about 1TB of data over four days, between August 21 and August 25.

The threat actor also claims the stolen Snowflake data contains approximately 284 million data records of patient-related information. However, this does not mean that the breach impacted 284 million patients.

Previous reporting stated that information belonging to 284 million patients had been exposed. ShinyHunters clarified to BleepingComputer that the figure is actually a raw count of approximately 284 million data records, or lines, rather than a count of unique individuals.

The threat actor told BleepingComputer that it has not fully analyzed the stolen data and does not know how many unique people are in those records.

ShinyHunters claims the stolen information includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information, and physician information.

The group also claims the data contains information related to deceased and terminally ill patients, prescriptions and medication shipments, invoices, employee information, Salesforce records, internal communications, and healthcare providers and clinics using McKesson's services.

BleepingComputer has not independently verified these claims, and McKesson has not publicly disclosed what information was stolen.

The group says it contacted McKesson after completing the data theft on August 25 and demanded a $55,236,150 ransom, giving the company 72 hours to respond. According to ShinyHunters, McKesson did not respond to or negotiate over the ransom demand.

The attack comes amid an ongoing wave of data-theft attacks targeting healthcare and health technology organizations attributed to ShinyHunters.

Health-ISAC recently warned healthcare organizations about increasing ShinyHunters attacks involving social engineering designed to compromise corporate accounts and gain access to cloud and SaaS platforms.

Other healthcare technology companies targeted in recent ShinyHunters data-theft attacks include Medtronic , DentaQuest , iRhythm , OneMedical, and AdaptHealth.

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Holy Cannoli! Is Robert Moses in Heaven???

hellgate
hellgatenyc.com
2026-08-28 18:30:30
We break down the sneaky Brooklyn Dems meeting, the sneaky New York Times interview, and where sneaky Robert Moses went after he died....
Original Article

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Hell Gate.

Your link has expired.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.

Just a rumour of a bug is enough to find a security exploit these days

Simon Willison
simonwillison.net
2026-08-28 18:12:02
Just a rumour of a bug is enough to find a security exploit these days Anil Madhavapeddy is a professor of computer science at Cambridge and a core maintainer of the OCaml compiler. In this somewhat alarming post he reports that security issues in OCaml projects are seeing evidence of attempted expl...
Original Article

28th August 2026 - Link Blog

Just a rumour of a bug is enough to find a security exploit these days ( via ) Anil Madhavapeddy is a professor of computer science at Cambridge and a core maintainer of the OCaml compiler. In this somewhat alarming post he reports that security issues in OCaml projects are seeing evidence of attempted exploits within minutes of patches being shared for discussion:

This normally takes a few days and a release within a week or two is reasonable. Within about ten minutes (!) this website was fielding probes for percent-encoded traversal sequences, indicating that automated watchers are keeping an eye on public repositories.

Modern coding agents have become so effective at finding flaws that the slightest hint at a new bug can be enough information for them to find it, something Anil has been able to demonstrate using his own agents, switching to DeepSeek V4 Pro⁠ when Claude Fable refused the task.

Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe.

rclone maintainer Nick Craig-Wood confirms in the Hacker News comments that his project is seeing this problem:

In the first 10 years of the rclone project we received about 20 security disclosures through GitHub. We had to deal with over 40 in the last month! That has taken a huge amount of my time, even using AI tools to triage and come up with fixes for review.

The hit rate for those security disclosures is pretty good - about 75% of them have a nugget of something which needs looking at. [...]

GitHub assigns CVEs for the advisories. Before the AI apocalypse they took 2-3 days for an assignment but now it they are running at 3-4 weeks so I have to send the point releases out with CVE-PENDING in the changelog which isn't ideal.

Apple Announces Price Increase for Apple TV and Apple One Subscriptions

Daring Fireball
9to5mac.com
2026-08-28 17:52:37
Chance Miller, 9to5Mac: Here are the full details on the price increases: Apple TV (monthly): $14.99 (up from $12.99) Apple TV (annual): $119 (up from $99) Apple One Individual: $21.95 (up from $19.95) Prices for other Apple One plans are unchanged. When Apple increased the price of Apple Mu...
Original Article

Just weeks after announcing price increases for Apple Music, Apple today announced that Apple TV is also getting more expensive. The company confirmed to 9to5Mac that the price of Apple TV is increasing from $12.99 to $14.99 per month.

The Individual tier of Apple One is also getting more expensive.

Apple TV, Apple One get more expensive

Here are the full details on the price increases:

Prices for other Apple One plans are unchanged. When Apple increased the price of Apple Music last month, it also raised the Apple One Family and Apple One Premier plans, but not the Individual plan.

The higher prices go into effect today for new subscribers. Apple says existing subscribers will be notified of the price increase about a month before they are charged the new price.

Apple last increased the price of Apple TV in August 2025 , raising it from $9.99 per month to $12.99 per month. The company did not raise the price of the annual plan or Apple One bundles at that time.

Apple has expanded Apple TV’s lineup significantly over the last year. Last October, it announced a deal to become the exclusive Formula 1 broadcast partner in the US. F1 streaming is included in the normal Apple TV subscription price at no additional cost.

Earlier this year, Apple also added Major League Soccer streaming to Apple TV at no additional cost. Previously, MLS access was behind a separate MLS Season Pass paywall.

Apple is also riding high on the success of recent launches like season four of Ted Lasso . Just today, Apple TV debuted the second season of Dark Matter. Slow Horses season 6 premieres on September 16.

What do you think of the new Apple TV price? Is $14.99 a good deal for what Apple TV offers? Let us know down in the comments.

My favorite Apple deals right now:

Follow Chance : Threads , Bluesky , Instagram , and Mastodon .

Add 9to5Mac as a preferred source on Google Add 9to5Mac as a preferred source on Google

FTC: We use income earning auto affiliate links. More.

‘I’m the Guy Who Destroys Antique Books After We Scan Them Into Our Company’s Insatiable AI Platform’

Daring Fireball
www.mcsweeneys.net
2026-08-28 17:35:22
Jack Loftus, writing at McSweeney’s: People assume scanning is the exciting part. And, sure, it is impressive. They shear off the spine, separate the pages, and run everything through these enormous machines so the computer can absorb every sentence ever written and use it to create some fairly ...
Original Article

“Vendors and rare books experts are increasingly worried that these artifacts may be under threat of destruction by generative AI companies seeking to feed their ravenous technology with new texts. Fears stem from a copyright lawsuit brought against [Anthropic] by book authors. Unsealed court files revealed earlier this year that the company was engaging in the practice of ‘destructive scanning’—buying physical books, slicing off the spines to more efficiently scan the pages, then pulping the remains—and had sought to keep it quiet.” The Guardian

- - -

I realize enthusiasm for one’s job is a little embarrassing now, but honestly, I adore what I do. I’m the guy who destroys priceless antique books once our generative AI scanners are finished with them.

Officially, my title is Senior Legacy Media Completion Specialist, but everyone calls me Book Doug. There was already another Doug, you see, but he works in Accounts Payable, so I got the fun one.

People assume scanning is the exciting part. And, sure, it is impressive. They shear off the spine, separate the pages, and run everything through these enormous machines so the computer can absorb every sentence ever written and use it to create some fairly compelling LinkedIn posts. But then, boy oh boy, the wheeled cart carrying those decimated remains comes to me. That is where the human touch enters the process, assuming you count industrial shredders and a giant burn pit out back as an extension of the hand, which I certainly do.

Our company has a very founder-led culture, so everyone is encouraged to approach problems like an owner. I do not own the company, obviously. I own a 2012 Mitsubishi Galant. Still, when I see a one-of-a-kind, three-hundred-year-old tome taking up six whole inches of shelf space, I immediately start thinking about scale and efficiency.

The older books are my favorite because they arrive with such rich history. Thick leather covers, gold inset lettering, the musty smell of age, and sometimes a handwritten note from 1894 that I don’t bother to read, and the scanners largely skip since it’s not integral to our performance KPIs. Then, the magic. One minute, they are a treasured record of human thought. The next, they are twelve searchable megabytes and a manageable quantity of mixed paper strips going into one of several large, welcoming bins marked DESTROY .

People ask whether I ever feel bad. Usually this happens after someone learns the books are rare, so I explain that rarity is really just an inventory problem. If there is only one copy left, the efficient move is to make it infinitely reproducible and immediately unavailable to anyone without a subscription. You can see people relax once I walk them through it slowly. Their shoulders slump in an accepting way. They stare. Sometimes they make a wordless rasping, just like the books do as I slide their sliced-out pages into oblivion.

We also recycle, which matters to me personally. I’m very environmental. I love reclaimed wood, barn doors, things like that. Some of the pulp becomes cardboard, and that cardboard may eventually become a box used to ship us more books.

You are a very good listener, by the way. Most people interrupt around the phrase “controlled combustion,” but you have barely moved. I appreciate that. It tells me you are comfortable around ambition.

Anyway, I’m sorry—listen to me go. I’ve talked about myself quite enough. What did you say you do again? A librarian? What’s that about?

Please help support our writers and keep our site ad-free by becoming a patron.

‘How Americans See E.U. Tech’

Daring Fireball
www.youtube.com
2026-08-28 17:27:21
I think at least half a dozen people have sent me a link to this video and now that I’ve watched it, I understand why. Perfect.  ★  ...

Finally, They Made a Prestige TV Show About the Javits Center

hellgate
hellgatenyc.com
2026-08-28 17:15:53
"The Westies" posits: What if a convention center were worth dying for?...
Original Article

This month, the Javits Center celebrated its 40th anniversary as the premiere (and only) large-scale convention center on Manhattan's west side. Also this month, the prestige drama "The Westies" concluded its first season of a show about how the Javits Center was, in its telling, erected in a spray of bullets and blood.

It might be hard to believe that the place where they hold the New York International Auto Show and New York Comic Con is the driving plot point of a show about a criminal organization, but here we are: "The Westies" is about the real-life, New York-based, Irish-American gang of the same name, and their infamous exploitation of the center during its construction in the 1980s.

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

I dug through hundreds of Labor Day sales to find real deals on high-quality products that last

Guardian
www.theguardian.com
2026-08-28 17:04:30
Cut through the noise with our round up of worthy Labor Day deals at brands including Caraway, Kiehl’s, Monos and SonyCollege grads share the room essentials that weathered the dormSign up for the Filter US newsletter, your weekly guide to buying fewer, better thingsLabor Day offers one last hurrah ...
Original Article

Labor Day offers one last hurrah for summer, a chance to reset for fall, and if you’re shopping, some choice end-of-season discounts.

No matter your plans for the long weekend, we found sales on products to make the most of it while helping you prepare for the colder months ahead.

Here are 47 of our favorite Labor Day sales, including a food storage system for stashing your leftovers and a blanket to replace your summer linens .


At a glance: the best Labor Day deals

  • Our Place Titanium Always Pan Pro

    Our Place Titanium Always Pan Pro, 8.5in

  • Frontgate Resort Collection Bath Towels

    Frontgate Resort Collection Bath Towels

  • Garmin Forerunner 165 Smartwatch

    Garmin Forerunner 165 Smartwatch

  • Mrs Meyer’s Clean Day Liquid Hand Soap Refill

    Mrs Meyer’s Clean Day Liquid Hand Soap Refill

  • Bedsure Bubble Faux Fur Blanket

    Bedsure Bubble Faux Fur Blanket


Labor Day kitchen sales

Our Place Dream Cooker

Our Place

Dream Cooker

$159

Our Place
Now $159, originally $199 at Our Place

Our Place’s six-in-one multicooker is ideal for city dwellers with limited counter space. “If you’re deciding between a rice cooker, a slow cooker or a pressure cooker, this combines all those capabilities into one appliance,” writes Filter contributor Kiki Aranita in our roundup of the very best rice cookers . Although it wasn’t the most intuitive of the models we tested, it did whip up brown rice in an impressive 20 minutes.

Our Place

Dream Cooker

$159


Caraway Clean Start Bundle

Caraway

Clean Start Bundle

$1,195

Caraway Clean Start Bundle
Now $1,195, originally $1,900 at Caraway

We’ve recommended Caraway’s cookware for its nonstick properties and Instagram-friendly aesthetic, all in a nontoxic construction . Recently, Karen Yuan, a Filter commissioning editor, tried its new 3 qt pan , which she said produced “possibly the easiest onion saute I’ve ever done”, during testing. For a cleaner way to cook, grab Caraway’s comprehensive Clean Start Bundle , a 39-piece cookware set including ceramic pots and pans, bakeware, food storage and cutting boards for $705 off.

Caraway

Clean Start Bundle

$1,195


Anyday 12-Piece Glass Round Dish Set

Anyday

12-Piece Glass Round Dish Set

$158


Our Place Titanium Always Pan Pro

Our Place

Titanium Always Pan Pro, 8.5in

$99

Our Place Titanium Always Pan Pro
Now $99, originally $175 at Our Place

Our Place makes pans that not only perform *chef’s kiss*, but are also free of harmful Pfas chemicals. Our testers from Drexel Food Lab crowned the Titanium Always Pan Pro king for its “combination of lightweight handling, impressive nonstick performance and genuinely useful design”, and it is now 43% off in the smaller, 8.5in model.

Our Place

Titanium Always Pan Pro, 8.5in

$99


Barebells Vegan Carmel Peanut Protein Bar

Barebells

Protein Bars (pack of 12)

from $21.69


Le Creuset Enameled Cast Iron Round Dutch Oven

Le Creuset

Enameled Cast Iron Round Dutch Oven, 4.25qt

$239.95

Le Creuset Enameled Cast Iron Round Dutch Oven
Now $239.95, originally $299.95 at Amazon

Le Creuset hardly needs an introduction thanks to its heirloom-level quality that withstands decades of enthusiastic cooking. “Like all Le Creuset pans, it holds heat well and distributes it evenly, and moves from stove to oven to table effortlessly,” said Julia Skinner, a Filter contributor and kitchen expert. Simmer hearty soups, stews and more for 20% off.

Le Creuset

Enameled Cast Iron Round Dutch Oven, 4.25qt

$239.95


Ninja Foodi Air Fryer

Ninja

Foodi Air Fryer

$159.99

Ninja Foodi Airfryer
Now $159.99, originally $199.99 at Amazon

If your kitchen is looking a little cluttered, score a solid 20% off this cooking expert- approved air fryer that bakes, broils and roasts. It’s even a favorite around the Guardian’s newsroom: “It allowed me to sear, pressure-cook and air-fry my food without having to buy loads of extra equipment, and it was much quicker than using the oven,” writes Sammy Gecsoyler, a Guardian news reporter.

Ninja

Foodi Air Fryer

$159.99


Counter Culture Coffee Single-Origin Subscription

Counter Culture Coffee

Single-Origin Subscription

$27.30


Labor Day home and beauty sales

Dyson Airwrap i.d.

Dyson

Airwrap i.d.

$519.99

Dyson Airwrap i.d.
Now $519.99, originally $649 at Amazon

The Dyson Airwrap i.d. has become synonymous with billowing locks previously reserved for pricey salon visits, and our testing proves it deserves the rep. When reviewer Juno DeMelo pitted it against a similar model from Shark, she found it to be more convenient, better for curling and complete with a more comprehensive selection of attachments. Grab it at 20% off, its lowest-ever tracked price.

Dyson

Airwrap i.d.

$519.99

Coop Original Adjustable Pillow

Coop

Original Adjustable Pillow

from $71.20

Renpho Fabric Heating Pad

Renpho

Fabric Heating Pad

$21.99

A product photo of a Renpho Fabric Heating Pad
Photograph: Courtesy of Walmart
Now $21.99, originally $35.99 at Walmart

Prepare for chilly evenings ahead with Renpho’s heating pad, which Maria Ricapito, a Filter contributor, recommended in our guide to the best sleep products . “My new pad from Renpho is made from a cushy velour fabric and has an automatic shutoff, so I can just drift off to sleep without worry,” she said. With 10 heat settings, it’s a travel-friendly option for anyone who can’t sleep without their toasty electric blanket.

Renpho

Fabric Heating Pad

$21.99

Cozy Earth Waffle Towel

Cozy Earth

Waffle Towel

$86.40

The Cozy Earth Waffle Towel on a table outside
Cozy Earth Waffle Bath Towel Photograph: Jon Chan/The Guardian
Now $86.40, originally $108 at Cozy Earth (set of two)

The waffle towel that Jon Chan, a veteran consumer journalist, recommended for its absorbent design and sustainable material is now 20% off. “On the performance front, the Cozy Earth Waffle Towels have a lot going for them. After showering, you can switch between the waffle and terry textures on opposite sides,” wrote Chan in our roundup of the best bath towels .

Cozy Earth

Waffle Towel

$86.40

Onsen Supima Waffle Bath Towel, 4-Pack

Onsen

Supima Waffle Bath Towel, 4-Pack

$112.43

Onsen Supima Waffle Bath Towel, 4-Pack
Now $112.43, originally $177 at Onsen

For a quick-drying bath towel that offers “high-end minimalism”, Onsen’s waffle-textured towel does the trick, especially with its 20% sitewide discount from 27 August to 7 September. “If you’re interested in a crisp towel with a sturdy and rough-spun feel, this towel will be right up your alley,” noted Chan.

Onsen

Supima Waffle Bath Towel, 4-Pack

$112.43

Kitsch Rice Water Shampoo Bar

Kitsch

Rice Water Shampoo Bar

$11.19

Kitsch Rice Water Shampoo Bar for Hair Growth x Star Wars C 3PO Design
Now $11.19, originally $15.99 at Amazon

Cut down on plastic and * take great care of your hair? That can be on your 2026 bingo card for 20% off. Guardian fashion and lifestyle editor Morwenna Ferrier is a fan of this sustainable and strand-strengthening shampoo bar: “Partly because the one I use is sulphate-free, and partly because you can use it to the very end, unlike a bottle. And when you fly, it’s one less liquid to squeeze through security.”

Kitsch

Rice Water Shampoo Bar

$11.19

Levoit Top-Fill 2.5L Humidifier

Levoit

Top-Fill 2.5L Humidifier

$24.99

Levoit Top Fill 2.5L Humidifier for Bedroom
Now $29.99, originally $39.99 at Amazon

As the air outside and in your home turns dry, so too can your airways. This cool misting option features many of the elements Chan appreciates in a humidifier: a top-fill design to reduce spills, a dimmable control panel for a more restful sleep environment and an extended run time for all-night comfort. It’s now 25% off – just in time for cold and flu season.

Levoit

Top-Fill 2.5L Humidifier

$24.99


Kiehl’s Ultra Facial Cleanser

Kiehl’s

Ultra Facial Cleanser

$19.50

Brooklinen Super-Plush Set of 4 Bath Towel Bundle

Brooklinen

Super-Plush Set of 4 Bath Towel Bundle

$191.84

Brooklinen Super-Plush Set of 4 Bath Towel Bundle
Now $191.84, originally $238 at Brooklinen

There’s no jumpscare quite like the feeling of ice-cold air against your skin after a shower that’s just cocooned you in warmth. Smooth the transition to the real world with a towel bundle that Chan appreciated for its “spa-like” and dense material that glides across skin, after testing over a dozen. They are typically a splurge, but Brooklinen has discounted them 12% for a set of four from 27 August to 3 September.

Brooklinen

Super-Plush Set of 4 Bath Towel Bundle

$191.84


Palazzo Latte Brown Re-Jute Rug, 3in x 5in

Ruggable

Latte Brown Re-Jute Rug, 3in x 5in

$118.30

Palazzo Latte Brown Re-Jute Rug, 3 x 5”
Now $118.30, originally $169 at Ruggable

An earthy, jute-style rug is a fabulous way to bring a touch of the outdoors inside or cozy up your sunroom. That’s exactly what you get with this machine-washable option, which Megan Reynolds, a contributor, describes in her rug-buying guide as having “the look of jute minus the scratchiness of the real thing”.

Ruggable

Latte Brown Re-Jute Rug, 3in x 5in

$118.30


Frontgate Resort Collection Bath Towels

Frontgate

Resort Collection Bath Towels

$35

The Frontgate Super-Plush on a table outside
Photograph: Jon Chan/The Guardian
Now $35, originally $50 at Frontgate

After testing more than 10 bath towels , seasoned product reviewer Jon Chan named these as best for gifting, on account of the wide color selection and option for monogramming. Right now they’re $15 off and you can add a monogram free of charge, making these an easy gift option if you’re getting a jump start on your holiday shopping .

Frontgate

Resort Collection Bath Towels

$35


The Purple Mattress

Purple

The Purple Mattress (king)

$1,760

The Purple Mattress
Now $1,760 (king), originally $2,199 at Purple

Tired of waking up with an achy back ? Level up your sleeping situation with this medium-firm, pressure-relieving mattress that’s on sale until 15 September. “I have a Purple mattress. I love the darn thing; it’s not like anything you’ve ever experienced with a mattress before, you basically float on top of it,” according to the sleep entrepreneur Rockwell Shah.

Purple

The Purple Mattress (king)

$1,760


Cozy Earth Bubble Cuddle Pillow

Cozy Earth

Bubble Cuddle Pillow

$70.40

Mrs Meyer’s Clean Day Liquid Hand Soap Refill

Mrs Meyer’s

Clean Day Liquid Hand Soap Refill

$7.68

Mrs. Meyer’s Clean Day Hand Soap Refill
Now $7.68, originally $9.99 at Amazon

My home consists predominantly of Mrs Meyer’s cleaning products, from aromatic hand soaps to versatile multi-surface cleaner that at once cleans and imparts a fresh scent. Now that it’s 23% off, I’m eager to restock the hand soaps around my house with this 33oz refill container that’ll allow me to limit my single-use plastic consumption.

Mrs Meyer’s

Clean Day Liquid Hand Soap Refill

$7.68

Bissell Little Green Pet Pro Portable Carpet Cleaner

Bissell

Little Green Pet Pro Portable Carpet Cleaner

$139.99


Bissell PowerClean DualBrush Vacuum

Bissell

PowerClean DualBrush Vacuum

$259.99

Bissell PowerClean DualBrush Vacuum
Now $259.99, originally $359.99 at Amazon

When reviewer John Brandon put the Bissell PowerClean stick vacuum head to head against a pricier Dyson counterpart, he noticed Bissell ’s superior suction was more capable of handling dry messes, from rice to granola. Now $100 off, it’s an even smarter steal for keeping your floors guest-ready .

Bissell

PowerClean DualBrush Vacuum

$259.99


Bedsure Bubble Faux Fur Blanket

Bedsure

Bubble Faux Fur Blanket

$79.99


Papier Academic Planner

Papier

In The Grid A5 Academic Planner 2026/27

from $28.80

Now $30.60, originally $36 at Papier

Need to get your life in order? Give Google Calendar a rest and try a paper planner such as this premium model from Papier, now 15% off. Lauren Gould, a Filter editorial coordinator, swore by this planner to stay organized during her college years, and now uses it for everything from tracking work to-dos and grocery lists. The cover options are endless, including an equestrian design and one perfect for cat lovers .

Papier

In The Grid A5 Academic Planner 2026/27

from $28.80


Crayola Model Magic

Crayola Model Magic
Now $28.99, originally $36.99 at Amazon

When we polled parents to find out about the best gifts for school-aged kids , Crayola Model Magic topped our list. “Blake enjoys creating shapes and figures using all different colors. He loves that he can let his creation air dry and put it in a display in his room,” said the parent of a four-and-a half-year-old. Now at 22% off, the white version of this modeling clay will allow them to use their imagination and fine motor skills to create artwork they can be proud of.

Crayola

Model Magic

$28.99


Origins GinZing SPF 40 Energy-Boosting Tinted Moisturizer

Origins

GinZing SPF 40 Energy-Boosting Tinted Moisturizer

$36

Origins Ginzeng SPF 40 Energy Boosting Tinted Moisturizer
Now $36, originally $48 at Sephora

For Guardian beauty columnist Sali Hughes, Origins’ tinted oil-free moisturizer is a solid option if “you either can’t be bothered to apply foundation in the heat or prefer a fresher look at this time of year.” While it’s only available in one shade at Sephora, Origins’ site offers a wider range . Add it to cart for 25% off.

Origins

GinZing SPF 40 Energy-Boosting Tinted Moisturizer

$36

*

JVN Complete Instant Recovery Serum

JVN

Complete Instant Recovery Serum

$25.60

JVN Complete Instant Recovery Serum
Now $25.60, originally $32 at JVN (with code JVNLOVE)

This hair serum impressed Sali Hughes, a Guardian beauty columnist, who praised its lemony scent and lightweight formula. “I haven’t once dried my hair without it and there’s no going back. It is – and I say this very carefully – one of the best hair products I have ever used,” she writes . Right now, you can grab it for 20% off with code JVNLOVE.

JVN

Complete Instant Recovery Serum

$25.60


Outdoors and on the go sales

Thule Medium Compression Packing Cube

Thule

Medium Compression Packing Cube

$20.95

Thule Medium Compression Packing Cube
Now $20.95, originally $29.95 at Backcountry

Whether you’re team carry-on or looking to tote an entire wardrobe abroad, our favorite compression packing cubes are your answer – especially when discounted by 30%. “I was able to fit another pair of joggers or a light jacket, in addition to my testing load of clothes, while saving about half an inch with compression,” said reviewer Les Shu. “For the quality and performance you get at this price, these cubes are a great value.

Thule

Medium Compression Packing Cube

$20.95


Nike One Leggings

Nike One Leggings
Now $39.97, originally $60 at Nike

“When the weather makes me reluctantly switch to leggings, my go-to pair is this style from Nike. They’re constructed with a mid-weight fabric that, while thick enough to keep my legs warm, still feels breathable,” writes Filter editorial coordinator Lauren Gould in her guide to the best winter running essentials . Prepare for the colder months ahead and grab these for 33% off.

Nike

One Leggings

$39.97


Coleman Portable Camp Chair

Coleman

Portable Camp Chair

$39.99

Coleman Portable Camp Chair set up outside
Photograph: Adam Doud/The Guardian
Now $39.99, originally $53.99 at Amazon

Football season and tailgating are practically synonymous. If you would rather not sit on the uncomfortable bed of a pickup truck, grab the camping chairs we named “best budget” after testing 11 of the most popular designs on the market, which are now even more affordable at 26% off.

Coleman

Portable Camp Chair

$39.99


Best budget (and great option for travel):
Relispo Self-inflating Stadium Seat Cushion

Relispo

Self-inflating Stadium Seat Cushion

$17.99

Relispo Self inflating Stadium Seat Cushion
Photograph: Adam Doud/The Guardian
Now $17.99, originally $24.99 at Amazon

After testing eight different seat cushions , Adam Doud, a pro product tester, deemed Relispo’s the best for budget and travel. Of the models he tried, he noted that this one was the “cheapest that still gives some support, thanks to the combination of air and some foam”. Whether you’re prepping for Thanksgiving travels or want to upgrade your uncomfortable desk chair, you can add this option to your cart for 28% off.

Relispo

Self-inflating Stadium Seat Cushion

$17.99


Monos Hybrid Carry-on

Monos

Hybrid Carry-on

$301.75

Monos Hybrid Carry-on
Now $301.75, originally $355 at Monos (with code TRAVEL1)

Aside from my passport, my most important travel necessity is my Monos carry-on. At once durable enough to withstand mid-flight jostling, and compressive enough to pack an obscene amount of stuff, it’s the carry-on that makes a packed day of traveling manageable. Get it for 15% off with code TRAVEL1.

Monos

Hybrid Carry-on

$301.75


Sea To Summit XLite Collapsible 3L Pot

Sea To Summit

XLite Collapsible 3L Pot

$78.71

Sea To Summit XLite Collapsible 3L Pot
Now $78.71, originally $104.95 at Sea to Summit

Camping magically becomes “glamping” when you have got collapsible cooking gear to make a decadent bowl of noodles to enjoy under a sky full of stars. “The lid can be used like a sieve to pour out excess liquid when cooking pasta, plus these pots double up well as basins to do your washing-up in,” an experienced camper told us .

Sea To Summit

XLite Collapsible 3L Pot

$78.71


Darn Tough Hiker Quarter Cushion Socks

Darn Tough

Hiker Quarter Cushion Socks

$17.25

Darn Tough Hiker Quarter Cushion Socks
Now $17.25, originally $23 at REI

Jon Chan, a Filter contributor, is willing to bet that these socks are tougher than the ones currently in your drawer. This mighty pair withstood his rigorous testing , which included walking 150,000 steps, “poking them with a flathead screwdriver and trying to tear them apart with my bare hands”. If you do manage to destroy a pair, they will ship you a new pair for free – a claim we have tested and verified

“It’s the type of product that you buy once, quite literally with a lifetime guarantee,” Chan said.

Darn Tough

Hiker Quarter Cushion Socks

$17.25


Hydro Flask Water Bottle, 32 oz

Hydro Flask

Water Bottle, 32oz

$35.87

Hydro Flask Water Bottle, 32 oz
Now $35.87, originally $44.95 at Amazon

Between its double-wall insulation to keep drinks ice-cold or piping hot, convenient carry handle and ability to withstand daily jostling, there’s not much more you could want in a reusable water bottle. Grab the white colorway – now 20% off – for your commute, workout class or someone on your holiday gifting list .

Hydro Flask

Water Bottle, 32oz

$35.87


Owala Stainless Steel SmoothSip Coffee Mug

Owala

Stainless Steel SmoothSip Coffee Mug, 20oz

from $23.99


Coleman Pro Heavy-Duty 25-Quart Cooler

Coleman

Pro Heavy-Duty 25-Quart Cooler

$159.99

Coleman Pro 25 Quart Cooler
Now 119.99, originally $159.99 at Amazon

Don’t let anyone tell you it’s too late in the season to take your drinking and dining al fresco. Stay armed with your favorite iced beverages and fresh snacks with one of our favorite coolers, now a cool 25% off and its second-to-lowest price ever. “This is a sturdy cool box, easily strong enough to double as a seat if needed, and it comes with a five-year guarantee,” said tester Linda Geddes.

Coleman

Pro Heavy-Duty 25-Quart Cooler

$159.99


Bose Ultra Open Earbuds

Bose

Ultra Open Earbuds

$199

Bose Ultra Open Earbuds
Now $199, originally $299 at Bose

If noise-cancelling audio gear is not quite your jam, listen to your favorite tunes with our favorite premium open-ear earbuds for $100 off. The secret behind their superior sound quality, according to Ryan Waniata, a tester, is a “blend of Bose’s legendary physics wizardry with a novel coil frame that creates a custom clip-on grip [that] expertly targets your eardrums”.

Bose

Ultra Open Earbuds

$199


Sony WH-1000XM6 Noise Cancelling Headphones

Sony

WH-1000XM6 Noise Cancelling Headphones

$398

Sony WH-1000XM6 Noise Cancelling Headphones
Now $398, originally $459.99 at Sony

Tune out the world and immerse yourself in your favorite playlists and podcasts with these tech editor-approved headphones. With their impressive noise cancelling properties, immersive spatial audio, generous 32-hour battery life, ability to cut distracting background noise and lightweight design, they’re a commuter or gym-goer’s dream, according to consumer technology editor Samuel Gibbs’ review .

Sony

WH-1000XM6 Noise Cancelling Headphones

$398


Garmin Forerunner 165 Smartwatch

Garmin

Forerunner 165 Smartwatch

$199

Garmin Forerunner 165 Smartwatch
Now $199, originally $249.99 at Amazon

For a fraction of the price and all the bells and whistles to keep you active and hitting your goals rain, shine or snow , you can’t beat the Garmin Forerunner 165 , which hardly ever leaves the wrist of Gould, a runner and our editorial coordinator (who owns the pricier version that lets you download music). It also earned top marks in testing by the Guardian’s consumer tech editor, Samuel Gibbs, for its high-end design and tracking metrics, making its current 20%-off deal feel extra tempting.

Garmin

Forerunner 165 Smartwatch

$199


Ryobi 40V HP Whisper Series Leaf Blower

Ryobi

40V HP Whisper Series Leaf Blower

from $279

A photo of a Ryobi 40V HP Whisper Series leaf blower
Photograph: Josh Patterson/The Guardian
A detail shot of a Ryobi 40V HP Whisper Series leaf blower
Photograph: Josh Patterson/The Guardian
Now $279, originally $349 at Home Depot

Brace for fall with this Filter-vetted electric leaf blower, now $70 off. When we tested seven top cordless electric leaf blowers, the Ryobi was our overall favorite for its ergonomic design and long battery life. “It is also impressively quiet. In testing, the Whisper Series produced the lowest noise levels of any comparable full-sized blower, especially at mid-range settings,” said Josh Patterson, an outdoor writer.

Ryobi

40V HP Whisper Series Leaf Blower

from $279


Garmin Venu 3 Smartwatch

Garmin

Venu 3 Smartwatch

$291.99

Garmin Venu 3 Smartwatch
Now $291.99, originally $449.99 at Amazon

When the Guardian’s consumer tech editor, Samuel Gibbs, put the Venu smartwatch to the test, he noted its bright and crisp display, lightweight and stylish construction, intuitive app controls and “world-class fitness features”. Grab the latest edition of the expert-approved smartwatch for 35% off, the cheapest we’ve ever seen it.

Garmin

Venu 3 Smartwatch

$291.99


Beats Studio Pro Noise-Cancelling Headphones

Beats

Studio Pro Noise-Cancelling Headphones

$249.99

Beats Studio Pro Noise Cancelling Over the Ear Headphones
Now $249.99, originally $349.99 at Best Buy

“The Studio Pro are without doubt the best-sounding Beats headphones to date,” writes Gibbs. Music to the ears of iOS and Android users alike, these headphones, which have solid spatial audio for watching films and clear quality for making calls, are now $100 off.

Beats

Studio Pro Noise-Cancelling Headphones

$249.99


Sonos Arc Ultra Soundbar

Sonos

Arc Ultra Soundbar

$899

Sonos Arc Ultra
Now $899, originally $1,099 at Amazon

“You don’t need captions; you need better speakers. And for most people, the easiest, fastest, most affordable option is a simple soundbar,” writes tech journalist Ryan Waniata, who’s been testing different models for ten years and counting.

One of our recommendations is Sonos’ Arc Ultra , an audio speaker to enhance your TV’s sound, which he says “can also be expanded with other Sonos gear for a multi-room sound or surround sound,” and is now on sale for 18% off.

Sonos

Arc Ultra Soundbar

$899


Tonies Toniebox 1 Audio Player Starter Set with Playtime Puppy

Tonies

Toniebox 1 Audio Player Starter Set with Playtime Puppy

$67.99

Toniebox 1 Audio Player Starter Set with Playtime Puppy
Now $67.99, originally $99.99 at Amazon

Shopping for kids can feel impossible (just ask my toddler who wants nothing but also everything at the same time). Somehow, this screen-free audio player for stories and songs happens to please even the pickiest of children while also serving as a bedtime wind-down tool any frazzled parent will appreciate. Make toddler birthday or holiday shopping that much easier with this 32%-off deal.

Tonies

Toniebox 1 Audio Player Starter Set with Playtime Puppy

$67.99


Other pieces you might enjoy from the Filter , the Guardian’s guide to buying fewer, better things:

Explore the Filter

Friday Squid Blogging: Truckload of Squid Spills in Rhode Island

Schneier
www.schneier.com
2026-08-28 17:02:44
Ugh: A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the “Squidpocalypse of ’26.” That would be twenty tons of squid. As usual, you can...
Original Article

Sidebar photo of Bruce Schneier by Joe MacInnis.

Dirk Eddelbuettel: corels 0.0.6 on CRAN: Microfix

PlanetDebian
dirk.eddelbuettel.com
2026-08-28 16:48:00
An updated version of the corels package is now on CRAN! The ‘Certifiably Optimal RulE ListS (Corels)’ learner provides interpretable decision rules with an optimality guarantee—a nice feature which sets it apart in machine learning. You can learn more about corels at its UBC site. This released fix...
Original Article

corels 0.0.6 on CRAN: Microfix

An updated version of the corels package is now on CRAN ! The ‘Certifiably Optimal RulE ListS (Corels)’ learner provides interpretable decision rules with an optimality guarantee—a nice feature which sets it apart in machine learning. You can learn more about corels at its UBC site .

This released fixes an issue discovered on one of the test machines used by Brian Ripley. If and when C compiler flags are set locally that are in fact upsetting the C++ compiler, then the build fails. While not an issue for years and not reproducible on (vanilla) Debian, Ubuntu or Fedora machines it does indeed balk at his end as e.g. the flag -Werror=implicit-function-declaration he sets for C is incompatible with the current C++ compiler. The fault was our: CFLAGS was passed on to PKG_CXXFLAGS letting C options seep into C++ deployment. This has been corrected: we only deal in C++ flags now.

Courtesy of my CRANberries , there is also a diffstat report for this release .

This post by Dirk Eddelbuettel originated on his Thinking inside the box blog. If you like this or other open-source work I do, you can sponsor me at GitHub .

/code/corels | permanent link

Sad Moviegoers Mourn AMC Kips Bay, Soon Gobbled Up by NYU Langone

hellgate
hellgatenyc.com
2026-08-28 16:36:25
Elected officials and fans of the theater are rallying to save it from shutting down....
Original Article

In a week when New York City's culture aficionados were already reeling from huge losses—the passing of Dolly Parton, Yayoi Kusama, and Tim Curry—news of the impending closure of the AMC Kips Bay came as yet another tough blow.

On Monday, Variety reported that the beloved New York City movie theater would be shutting its doors by the end of the year. AMC told the outlet the property owner was terminating the lease. Once the news broke, moviegoers turned to the internet in anger and sadness , and theorized about who bought the building .

Assemblymember Keith Powers's office eventually confirmed that NYU Langone had purchased the shopping center where the theater resides about a year ago . The move isn't surprising, as the area is home to NYU Langone and university graduate buildings. Powers is a supporter of saving the theater from closure: urging people to sign a petition earlier this week and sending a joint letter with other elected officials to NYU Langone . His office told Hell Gate that NYU Langone confirmed their ownership with him via email. NYU did not respond to Hell Gate's request for comment.

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

Car: Dolphin 26.08 and KIO performance improvements

Linux Weekly News
lwn.net
2026-08-28 16:00:27
Méven Car has written a pair of interesting blog posts (part 1, part 2). The first post is largely about some of the recent new features and performance work that have gone into the Dolphin file manager 26.08 release, as well as the KIO framework. The second looks at the performance improv...
Original Article

Méven Car has written a pair of interesting blog posts ( part 1 , part 2 ). The first post is largely about some of the recent new features and performance work that have gone into the Dolphin file manager 26.08 release, as well as the KIO framework. The second looks at the performance improvements and benchmarks for previous, current, and upcoming releases.

Copying many small files is more than twice as fast as it was in April. The gain falls off as files get larger, which is what you would expect: the fix is to the per-file overhead, and once each file carries a megabyte of actual I/O the overhead stops being what you are waiting for.

There is still a gap with cp , discussed at length in the July post . KIO is doing more than cp does, but not five times more, and the batching work that closes most of the rest of that gap is still in progress.



We Certainly Have Made a Hames Out of This

Daring Fireball
daringfireball.net
2026-08-28 15:42:59
I mentioned earlier that for anyone going along with the ruse that Lake Ontario is now named Lake America, the HOMES mnemonic no longer holds, the only two valid words in English with the new five letters are hames and shame, and that hames is rather too obscure. But it’s not so obscure in Ireland,...
Original Article
Trump Declares That Lake Ontario Is Now ‘Lake America’

Jackie Llanos and Jenna Monnin, reporting for NOTUS:

President Donald Trump on Thursday signed an executive order meant to rename Lake Ontario “Lake America,” taking his apparent jab at Canada one step further as a trade war between the two countries escalates.

The president said the name change was “effective immediately” during a signing ceremony in the Oval Office. The executive order directs Interior Secretary Doug Burgum to update the Geographic Names Information Service to reflect the name change. When asked by reporters about the move, Trump said he was sending “no message” to Canada with the name change.

“Lake of America was something I’ve been thinking about for a long time,” the president said. “Actually, as you know, we took something called the Gulf of Mexico, we changed it, and now it’s very routinely the Gulf of America.”

Aaron Rupar has video clips of Trump declaring the change in an Oval Office press event, here and here . In the second clip Trump ruminates, “So if you think about it, we have a gulf, and we have a lake, now all we need is an ocean, so maybe we’ll have to change the name of the Atlantic and/or the Pacific. Maybe we’ll change them both.” Those who deny that he’s a mad king slipping ever deeper into dementia might say, well, he’s obviously joking. But if I had told those same people just two years ago, in the run up to his reelection, that Trump was going to declare new names for the Gulf of Mexico and Lake Ontario, they’d have said I was crazy because that would be nutty.

It is nutty. Renaming these large bodies of water is nuts. He’s nuts. This is not complicated. Crazy people do crazy things and this is obviously crazy. I often use the phrase jokingly but Donald Trump is not hooked up right, and the proof is right before our eyes on camera every day.

Factoid: HOMES is the longstanding mnemonic for recalling the five Great Lake names: Huron, Ontario, Michigan, Erie, Superior. “Hames”, technically , is a playable Scrabble/Wordle word (“a part of a horse collar”), but it’s far too obscure to serve as a mnemonic. That leaves one word in the English language consisting of the five necessary letters: SHAME.

Friday, 28 August 2026

Stopping the smart TV from being used against you

Lobsters
www.s-config.com
2026-08-28 15:32:48
Comments...
Original Article

Smart TVs are everywhere! But who is the master?

Amid the overall electronics boom thanks to A.I., one piece of electronics is almost unchanged financially. That is the digital display or flat-panel monitor. With good reason! The entire entertainment and streaming industry wants one of these devices in your living room. Not only wanting access to your wallet; companies are willing to violate customer trust to squeeze a few extra pennies out of the devices they sold you. To these companies, you technically never really owned the device, but instead purchased permission from these companies to have it exist in your household. Like a true tech-valley rapist, they will break into your home, listen to everything you do via the microphone, track every movement that you make thanks to their backdoored OS, and most importantly, spread malware onto devices they don't even own.

Whoah S! Mal-ware? Isn't that a little harsh? - Anonymous

Malware, by definition, is software you never asked for and was installed without your permission. At least in LG's case. Using Legal Ninjitsu to state that by agreeing to install their monitor 'driver,' you also agree to install every other bloatware application that they choose should come with it as well. Like advertising, it takes a shit all over your desktop to churn profits for LG.

Read on to continue the descent into madness.

It all starts with going cheap.

Amazon searching for 75 inch TVs.

It didn't take a whole lot of searching on Amazon to find what appears to be a good deal on a 75-inch TV. We figured we'd go with 75 inches because, like every American household, it's a good idea to go big when purchasing a TV for your bathroom. Ahh, nothing like being on the shitter while catching eye strain from the TV that practically covers an entire side of the wall.

Sure enough, LG comes out on top with their (bullshit) AI upscaling and "Wow Orchestra," whatever that means. But $10 more than the Toshiba... WHY NOT RIGHT?!?

So you get this bad-boy home, hook it up to your laptop with Windows 11 so you can get Netflix going on..

Oh, there's a driver update for the LG television. Makes sense, right? It's a fairly recent television, and the drivers will help us take advantage of all of the TV's features. Of course, I'd like Microsoft to download it.

LG Malware:

Then after a while, you notice more and more applications appear on your desktop. Like a copy of McAfee antivirus that you never asked for. Now, if this were an elderly couple or someone who doesn't know anything about computers. They wouldn't even know their system is being turned against them by LG. Some would think their system was hacked by someone else. But actually, no. Because Microsoft is being ambivalent by letting LG's supposed 'driver' install itself and, via LG's proxy, install even more applications.

How does this attack work? Especially when you made SURE LG has no access to the internet!

This all happens the moment you plug that HDMI (or DisplayPort for people who purchased an LG computer monitor) right into an internet-enabled laptop through a protocol called EDID, also known as "Extended Display Identification Data," which by itself is totally harmless!

It simply tells your operating system what kind of monitor is connected, what its capabilities are, it's serial number. That's it!

Inside Windows, when you go to Device Manager, it might not seem like much. Just a generic UPNP device attached as a monitor.

Hardware ID's within Generic UPNP Monitors.

Dive a little more into Device Manager, and we see where EDID does its magic; we found that this particular Microsoft Box is hooked up to some kind of Samsung monitor. Now, Samsung might have some kind of driver that would help take advantage of my monitor. But this Samsung is so old they simply do not care.

When your core OS, like Microslop has been compromised by an incredibly wealthy organization such as LG. Having your Windows Updater schedule a driver release seems like a helpful thing to do for your end users. And it helps if LG throws a lot of money Microsoft's way as a partner to look the other way, as their supposed driver software has its way with your laptop. Well! What's the matter with that? Don't you want "Value added features?" or you can't be possibly stupid to uninstall a virus checker as "Reputable" as McAfee right?

Hah! I don't have to worry about this! I got Linux!

For now.. That's true. But EDID transmission still happens. and your can install ddcutil to check it out.

crackhead@BLORB.LOCALHOST:~$ ddcutil detect
I2C bus: /dev/i2c-2
DRM_connector: card1-HDMI-A-2
EDID synopsis:
Mfg id: APX - AP Designs Ltd
Model: LE24H87
Product code: 12852 (0x3234)
Serial number:
Binary serial number: 535 (0x00000217)
Manufacture year: 2010, Week: 32
This monitor does not support DDC/CI. (I2C slave address x37 is unresponsive.)

For the sake of this blog, we powered up one of our thin clients and connected HDMI to it. It shows a lot of information for my ultra-crap monitor that was made in 2010.

But what stops LG from convincing the Ubuntu maintainers to make an LG variant of their supposed driver to magically appear in your snap or apt package repository? You hope to God they don't, but the danger is always there.

Fuck, i'll just not get an LG TV Then!

If you're going to be home all of the time, that's a perfectly acceptable solution. Keep in mind LG may be the first company that is eager to erode trust to get a few extra dollars or listen in on your conversations. Corporations are cowards; if they see one person exploiting people, you'll bet your ass the rest will follow right in line. Eventually, Smart TVs will be used against you. On top of this, getting a "Non-SMART TV," you'll quickly find out that most of those only exist within commercial environments; often, they want a premium price for not having an Android OS that could get hacked, or plaster movie ads the moment you power it up.

For example, if you checked into one of the many newly renovated Hilton hotels throughout the United States while traveling. It's almost guaranteed to have an LG TV not only powered on the moment you enter the room but connected to the hotel internet, ready to spy away on you.

Usually, you can just unplug the damn TV and watch movies on your laptop screen. OR! You do something about it.

Enter the EDID Blocker EDID Blocking hardware.

We've used each one of these units during one part of our lifetime in the world of computers.

  • The gold one on the left is actually an EDID dummy plug. It allows a computer to be powered on, thinking there is an HDMI monitor attached to its workstation, when in reality there is none. Useful if you like graphical remote desktops and don't want the resolution to get all stupid the moment you unplug.
  • The other is a common HDMI EDID blocker. There's a lot out there with varying quality. Originally, these were used in conjunction with an HDMI splitter so if the monitors change it doesn't black out the display. Another use is if you have a lot of projectors in a particular orientation and don't want windows to completely screw up your tiling without using Nvidia Mosaic, this is more of a hardware-based approach.
crackhead@BLORB.LOCALHOST:~$ ddcutil detect
I2C bus: /dev/i2c-2
DRM_connector: card1-HDMI-A-2
EDID synopsis:
Mfg id: XMD - UNK
Model: Mi TV
Product code: 154 (0x009a)
Serial number:
Binary serial number: 0 (0x00000000)
Manufacture year: 2017, Week: 39
This monitor does not support DDC/CI. (I2C slave address x37 is unresponsive.)

TV changed, and if I unplug just the HDMI cable going to my 2010 television, it'll still read just fine.

  • You're probably wondering about the last EDID blocker, which is DisplayPort to DisplayPort. WELL!

EDID Display Port Blocker Scam.

It's a scam. Just a bunch of wires, shit-soldered together to make a jumper and charger 15-30-45 to pass it off as an actual blocker. We wanted to get a legit EDID blocker to show you its device. But it's important to document even the bootleg garbage you get when working with grey-market tech. Got my refund right away on this one.

This, however, illustrates the importance of checking your hardware when you get it. If we got an LG gaming monitor with this bootleg piece of shit hooked up to a Windows box. Welp! We would probably be scrubbing McAfee off of our computers AGAIN!

When it comes to a DisplayPort EDID emulator, there are legit companies out there. But they're pricey. Anywhere from $50 to $150 US Dollars.

Final thoughts.

There are, of course, more sensible techniques to fight corrupt smart TVs, such as the following:

  • Never give ANY smart device internet.
  • Have a good firewall that Microsoft never touched. Especially make sure your DNS for these companies is diverted to a picture of Obama. Generally, a good open-source router with ad-blocking plugins will take care of this
  • Just change your OS. Worked for me!
  • Use a Linux-based OS to watch TV. Don't get another Android box loaded with spyware.
  • Throw it into the garbage and financially eat shit buying a TV with no OS whatsoever. Or a better and more portable solution could be a projector instead.
  • You know what? There's really nothing good to watch on TV anyways. If Hollywood has to subsidize the television industry just to keep its base, it doesn't have any money to invest in anything new. Every channel just wants to brainwash you. So throwing the Flat Panel into the garbage might be a good idea anyways.

But if you're backed into a corner with your work laptop running Microslop and everyone is insisting on hooking your carbomb of a laptop up to the world's most malware-infested TVs, such as an LG. It's good to know there are hardware options to protect yourself by misdirecting the manufacturer label so no drivers can ever be detected or downloaded.

The only downside we've ever experienced with these blockers is when something is rated for 4K. Your system BIOS might automatically switch to 4K until the OS returns. Minor annoyance. But it's something worth noting.

That's what server said

END OF LINE+++

PaperCut releases second emergency patch for exploited flaws

Bleeping Computer
www.bleepingcomputer.com
2026-08-28 15:08:26
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]...
Original Article

PaperCut

PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes.

As BleepingComputer reported yesterday , PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26.

At the time, however, the company had not disclosed CVE identifiers or technical details about the vulnerabilities, saying it was withholding information while it investigated the attacks and gave customers time to apply emergency fixes.

image

PaperCut has now shared technical details and CVE identifiers for the two vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578. These vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers.

CVE-2026-81578 is a high-severity authentication bypass vulnerability rated 8.8 that impacts the PaperCut NG/MF web management interface.

"Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks," explains PaperCut's updated advisory .

The second vulnerability, tracked as CVE-2026-82078, is a critical unsafe dynamic class-loading flaw rated 9.4 that exists in PaperCut's database connection utilities.

The application loads database driver classes based on configurable driver names without validating them against an approved allowlist.

"If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process," explains PaperCut.

Cybersecurity firm watchTowr, which has been working with PaperCut during the incident, said on LinkedIn that the vulnerabilities allow unauthenticated attackers to bypass authentication and gain remote code execution on affected PaperCut NG/MF instances.

Second emergency patch released

On Friday, PaperCut released Emergency Patch Release 2, an updated security fix that includes additional hardening developed after further analysis with its internal security team and researchers at Huntress and watchTowr.

"Following further work with our internal security team and external researchers, including Huntress and watchTowr, we have released an updated Emergency Patch (Release 2) that includes additional hardening beyond the original emergency patch," PaperCut said.

The company is urging all customers to install Release 2 even if they already installed the first emergency patch.

This second release comes after watchTowr said its researchers fully reproduced the vulnerabilities, discovered multiple patch bypasses, and identified an additional authentication bypass vulnerability.

Huntress, which has been working with PaperCut during the incident, says it observed exploitation in two customer environments and reproduced the full pre-authentication RCE chain.

The company told BleepingComputer that PaperCut logs captured commands used by the attackers for system reconnaissance, while hex-encoded Java `.class` files found in the logs acted as an RCE bridge between PaperCut and the underlying operating system, allowing commands to be executed and files to be read or written.

The commands observed by Huntress appear to have been used for reconnaissance rather than to deploy malware or establish persistence.

Huntress also says it discovered multiple bypasses for the original emergency patches and an additional authentication bypass vulnerability, which it shared with PaperCut.

Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS. Customers running version 23 or earlier are advised to upgrade to the latest version rather than wait for a patch for those releases.

PaperCut says Site Servers and secondary/print servers should also be upgraded to patched versions. Other components, like Print Deploy and Mobility Print, are not affected and do not require updates.

Even though patches are available, PaperCut to urge customers to restrict access to the web interfaces to trusted IP addresses using firewall rules, network access controls, or equivalent measures.

Administrators should also look for suspicious post-exploitation activity from the pc-app.exe process, missing or truncated server.log files, and the following errors in the server.log.

ERROR No suitable driver found for jdbc:no:x
ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

The company has not disclosed who is behind the attacks or what threat actors are doing after compromising vulnerable servers.

PaperCut told BleepingComputer that the attacks appear limited and targeted, and that it is withholding details about post-exploitation activity while it continues its investigation.

"Our investigation into what attackers are doing post-compromise is still active, and premature detail could complicate any affected customers' own response," PaperCut told BleepingComputer.

"What we can say: the bulletin advises customers to watch for intrusion-detection, endpoint, or network-monitoring alerts tied to the PaperCut Application Server, and we'll publish indicators of compromise as they're verified."

PaperCut servers were previously targeted in 2023 after attackers began exploiting CVE-2023-27350, an authentication bypass and remote code execution vulnerability.

Those attacks were ultimately linked to numerous threat actors, including the Clop and LockBit ransomware operations , Iranian state-backed hacking groups , and the Bl00dy Ransomware Gang .

Update: Added information from Huntress.

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Nancy Grace Roman Space Telescope Launches this Sunday

Hacker News
www.npr.org
2026-08-28 14:53:48
Comments...
Original Article
The Nancy Grace Roman Space Telescope, named after NASA's first chief astronomer, will launch on Aug. 30.

The Nancy Grace Roman Space Telescope, named after NASA's first chief astronomer, will launch on Aug. 30. NASA hide caption

toggle caption

NASA

The universe is a strange place — filled with exploding stars, ancient galaxies, and unseen worlds. Now, astronomers are about to get a brand new tool to explore it.

The $4.3 billion Nancy Grace Roman Space Telescope is scheduled for launch Aug. 30. Named for NASA's first chief astronomer, the observatory is expected to reveal new information about the expansion of the universe and discover multitudes of planets orbiting distant stars.

Roman, as it is known to its friends, has an unusual history. About 15 years ago NASA was making plans to build a space telescope that could, among other things, search for exploding stars known as Type 1A supernovas. These supernovas were used as a kind of cosmological measuring stick to uncover a mysterious force called dark energy that was causing the universe to expand — a discovery that earned the Nobel Prize in 2011.

Cosmologist Daniel Scolnic at Duke University says finding more of them would be key to better understanding that expansion.

As NASA was developing plans for this new telescope, a call came in from the government office in charge of surveillance satellites.

"The National Reconnaissance Office reached out to NASA," Scolnic says, "saying, 'We have this amazing satellite sitting in a hangar that we're not using. And what what do you guys think about instead of pointing downwards, we point upwards, and you guys use it?'"

NASA said yes. It took some substantial modifications, but now that old satellite is set to become NASA's next major space observatory.

Scolnic says that the new observatory could fundamentally change the scientific model that astronomers use to understand our universe.

"In the last few years, there have been measurements saying that model might be wrong — and that's something that Roman will absolutely nail, whether the model's right or wrong," he says.

Another goal of the telescope is to spend a month surveying all the stars in the Milky Way galaxy. Julie McEnery is Roman's project scientist. She says even though Roman has broadly the same sensitivity and sharpness of vision as the currently orbiting Hubble Space Telescope, its design lets it do things much faster.

"That one month of observations to survey our Milky Way galaxy would take about a century with Hubble," says McEnery.

Instead of focusing on a single object, Roman is designed to make catalogs of large swaths of the sky, and McEnery says these catalogs will be available to everyone, not just academics.

"You can be a teacher in a high school in Kentucky and your students have the opportunity to see Roman data at the same time as a professor in Princeton," she says.

One professor eager to get his hands on Roman data is Scott Gaudi at The Ohio State University. Along with colleagues, Gaudi developed a technique for detecting planets around distant stars. It's called gravitational microlensing, and it measures the way those planets bend the starlight that passes them by.

Albert Einstein described the idea in 1936 but thought it would be impractical. New technology has proven him wrong — and Gaudi expects Roman will find tons of planets that way.

"We're looking for planets that are just completely undetectable by any other method," Gaudi says. That includes planets at the center of our galaxy, "that are very analogous to our own solar system planets like Jupiter, Saturn, Uranus and Neptune."

In addition to new planets, Roman should also reveal new galaxies, helping astronomers to get a better idea of the large-scale structure of the universe.

But predicting what will be Roman's greatest accomplishments over the course of its five-year mission is a tricky business.

"The history of astronomy really has shown that when you get a new capability, and especially a survey capability, you learn something new, something unexpected," says Wendy Freedman, an astronomer at the University of Chicago. "Often that turns out to be the most exciting part of a new facility. So I am completely open to what this telescope will find."

[$] The "rnull" Rust block driver

Linux Weekly News
lwn.net
2026-08-28 14:26:23
The null block driver (null_blk) is a small driver that is mostly useful for benchmarking block-layer implementations. It accepts all requests and marks them complete as quickly as possible, doing as little work as possible. In June 2026, Andreas Hindborg shared a patch set implementing the s...
Original Article
The page you have tried to view ( The "rnull" Rust block driver ) is currently available to LWN subscribers only. Reader subscriptions are a necessary way to fund the continued existence of LWN and the quality of its content.

If you are already an LWN.net subscriber, please log in with the form below to read this content.

Please consider subscribing to LWN . An LWN subscription provides numerous benefits, including access to restricted content and the warm feeling of knowing that you are helping to keep LWN alive.

(Alternatively, this item will become freely available on September 10, 2026)

GiveWP WordPress donation plugin flaw lets hackers execute server commands

Bleeping Computer
www.bleepingcomputer.com
2026-08-28 14:18:55
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]...
Original Article

GiveWP WordPress donation plugin flaw lets hackers execute server commands

A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server.

The security issue is identified as CVE-2026-82222 and affects GiveWP through version 4.16.7.1. It was reported by bug researcher Udin Chan on July 28 through the Patchstack vulnerability intelligence platform.

The GiveWP plugin has more than 100,000 installs and allows collecting donations and managing fundraising campaigns.

image

Patchstack researchers explain that exploiting the vulnerability is possible by chaining three distinct issues:

  1. An unsafe helper for unserializing PHP data
  2. A donation-processing flow that stores attacker-controlled serialized objects
  3. A gadget chain in libraries bundled with the plugin that can invoke arbitrary system commands

Successful exploitation depends on the attacker having an account on the target site. However, Patchstack says that an exposed unauthenticated registration action allows creating an account even if registration is disabled.

“[GiveWP] exposes an unauthenticated registration action (give_action=user_register) that never consults the WordPress users_can_register option,” Patchstack explains .

“Even on a site that has registration disabled, the attacker can create an account and receive an authentication cookie, then carry out the rest of the attack in the same sequence.”

After authentication, hackers can store a malicious serialized object in their profile and inject it into the plugin’s session database by submitting a crafted donation.

"The server writes the gadget object into wp_give_sessions before returning an HTTP 500," says George Johnstone, cybersecurity researcher at Patchstack.

By requesting any front-end page with the authentication cookie, the server unserializes the gadget and executes the command from the attacker.

Versions 4.16.6 through 4.16.7.1 remain vulnerable, although exploitation requires the site to contain a legacy donation form without ‘formBuilderSettings.’

Patchstack comments that such conditions may exist in upgraded installations, sites using the plugin’s option-based form editor, or when importing or restoring older forms.

GiveWP fixed the vulnerability in version 4.16.7.2, released on August 27, by blocking serialized data during donation processing and restricting object creation at several deserialization points.

Additionally, the security update removes serialized object payloads already stored in affected databases.

However, Patchstack notes that GiveWP’s registration action still does not honor WordPress user registration settings, but this issue is no longer exploitable for code execution.

Website administrators using GiveWP are urged to apply the security updates as soon as possible to prevent malicious exploitation of CVE-2026-82222.

Hackers targeted GiveWP last year to indirectly breach Pi-hole, a popular network-level ad-blocker, exposing the names and email addresses of 30,000 donors.

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

How cats.txt showed llms.txt evidence is GEO astrology

Lobsters
markwilliamscook.substack.com
2026-08-28 14:11:43
Comments...
Original Article

I got tired of watching the industry treat “an AI bot fetched it” and “ChatGPT said it helps” as evidence that llms.txt does anything, so I invented a standard called cats.txt : a text file in which you formally declare your office cats, their jobs, their breeds, and how often they purr. I wrote a specification, published it on my blog, and did a LinkedIn post explaining why you should definitely adopt it, because as we all know, LLMs love LinkedIn. Then I checked it against the exact four “proofs” people cite for llms.txt . It passed all four. It was crawled by the AI bots. Google indexed it. LLMs returned details about a cat that exists nowhere but the file. ChatGPT confirmed, at length, that cats.txt could help me rank. None of which is evidence of anything, which was rather the point.

I am not claiming llms.txt will never work, this is not the point, dear reader. I am claiming the bar of evidence currently being used to sell it is so low that a file about a Tuxedo cat called Odd cleared it without breaking stride. And that same faulty thinking is being applied to half the GEO tactics currently being invoiced to clients.

It began, as these things tend to, with irritation.

For months I had been watching perfectly sensible people point at four observations: the bots crawled it, Google indexed it, an LLM repeated it, ChatGPT endorsed it, and present them, in decks and threads and client proposals, as proof that llms.txt was quietly reshaping AI search. None of it was proof of anything. But argument by counter-argument only gets you so far; people nod along and then go back to their slides. I wanted something they couldn’t nod past. I wanted to run the same four “proofs” on something so transparently ridiculous that no one could pretend the tests meant anything.

So I invented a standard. cats.txt : a plain-text file you place at the root of your domain to formally declare the cats associated with your website; their names, their job titles, their breeds, and a mandatory affection metric called PurrLevel , scored out of ten. I wrote a proper specification for it, with the earnest, over-engineered tone of a real proposal, and published it on my blog . Then, because I know as well as anyone which platform LLMs seem to hold in unaccountably high regard, I wrote a LinkedIn article introducing cats.txt as “the missing standard for SEO and GEO” and explaining, with a straight face, why you should definitely adopt it. 🐱

The idea was to seed the internet with just enough earnest-sounding text that the machines would start treating my cats as real. What I did not fully anticipate was that people would join in.

The SEO community supporting the cats.txt standard

The joke was legible, that was always the point, and so the SEO community picked it up and ran with it, precisely because they could see where it was going. My lovely internet-peer Dave Smart (a genuinely excellent technical SEO), added a cats.txt to his own site and became, to his eternal credit, an early adopter of a standard I had built to be nonsense. And then the thing took on a life of its own: someone went off and set up catstxt.org , a cleaner, better-organised, altogether more competently specified version of the standard: obviously the work of somebody who knew what they were doing, and just as obviously not me. My daft blog post had acquired a rival implementation, which is more than most real standards manage in their first fortnight.

With the file live, the spec published, the LinkedIn post seeded and other people cheerfully piling in, all that remained was to check cats.txt against the exact bar the industry uses to certify llms.txt . Reader, it cleared it.

I do not much care whether llms.txt works, will work, or how long it takes to get there. For the length of this argument I am happy to park two inconvenient facts and grant the idea every benefit of the doubt.

The first is that no large language model provider has ever documented using llms.txt for search or discovery. Not OpenAI, not Anthropic (who publish one for their own docs and have still never said their models read it during a conversation), and not Google. Google’s John Mueller has been about as blunt as a search advocate gets :

“FWIW no AI system currently uses llms.txt, [..] It’s super-obvious if you look at your server logs. The consumer LLMs / chatbots (the ones that SEOs want traffic from) will fetch your pages - for training and grounding, but none of them fetch the llms.txt file. Maybe they will tomorrow? Maybe I’ll win in the lottery tomorrow?”
John Mueller, Google

The second is that even where it is deployed, it barely gets looked at. Ahrefs ran the numbers across 100,000 domains and found that the file is, in practice, largely ignored by the crawlers it is meant to court, a finding since echoed by other large studies showing no measurable citation advantage for sites that add one. So the mechanism people are paying for does not appear to fire. Fine. Park that too.

Assume the jury is out on both counts and grant the idea the most generous hearing imaginable. The problem I actually want to talk about is not llms.txt at all. It is the reasoning being used to defend it.

The trap is this: getting baited into treating a set of observations as evidence, when the observations would occur whether or not the underlying thing were true. It is the intellectual equivalent of concluding your umbrella causes the rain to stop, because every time you put it away the rain does eventually stop.

llms.txt is simply a convenient example. The same broken chain of inference is being applied to almost every new GEO tactic invented on a monthly basis , and the question is always the same, “should we do this thing, or should we not?” , which makes the quality of the answers rather important.

Here are the four “proofs” I keep being shown, in ascending order of confidence and descending order of rigour.

The first argument: you can see Anthropic crawling it, you can see OpenAI crawling it, the bots turn up in your logs, therefore the file is being used.

A crawler fetching a file tells you nothing about whether the contents are read, weighted, trusted or acted upon. Fetching things is the entire job description of a crawler. Bots request more or less everything you leave lying around; the postman touching your gate is not an endorsement of the contents of your bins.

To prove the point, I put up cats.txt and watched the logs fill with PerplexityBot, GPTBot, ClaudeBot, Googlebot and a supporting cast of lesser crawlers, all diligently requesting a file describing the professional responsibilities of my cats. By this standard, the major AI labs have all quietly decided to support my cats. I am, frankly, touched.

The catstxt.org website even offers a filtered log viewer , if you want to watch all that crawling action live.

Web server access log showing multiple HTTP GET requests for /cats.txt and /.well-known/cats.txt from various bots and user agents.
The cats.txt server logs: every bot faithfully fetching a file about cats

The second argument: the file was indexed by Google, which proves Google considers it important, because why would Google index something that didn’t matter?

Google indexes text files. It has done so, enthusiastically, since before most of the people currently selling llms.txt owned a smartphone. Being in the index is a statement that a URL exists and contains words. It is not a verdict on truth, usefulness or sanity.

cats.txt is, naturally, indexed. Google will even offer to let you claim it in Search Console and “get indexing and ranking data,” with the straightest of faces, for a file asserting that a British Shorthair named Pixel works as a “GUI Purrfectionist” with a PurrLevel of 8.

Google search query searching for site:[https://tamethebots.com/cats.txt](https://tamethebots.com/cats.txt) showing an indexed result for cats.txt.
cats.txt, dutifully indexed by Google on tamethebots.com

The third argument is the strongest-looking, and therefore deserves the most care. The claim is that a model produced a fact that existed only inside the llms.txt file, and therefore must have read the file as a special, trusted source.

The trouble is that this is exactly what you would expect from ordinary retrieval-augmented generation. The model runs a search, lands on a page that happens to rank because it is indexed (see: previous argument), and reads whatever is on it. If the page that ranks is your llms.txt , the model reads your llms.txt , no differently from any other URL. That is the file functioning as a web page, not as a standard.

Consider Dave. Lovely Dave. A real, technical SEO of good standing, put a cats.txt on his site, becoming an early adopter of a standard I had built to be nonsense. Ask Google about the cat that lives on his site and the AI Overview will tell you, in a confident bulleted answer, that Odd is a “Render Cat,” a Tuxedo with a PurrLevel of 5/7, who “chases the cursor, pounces on stray pixels, and stashes them on the digital carpet.” It cites the cats.txt file. Every word is invented, sourced from a file the model was never designed to revere, surfaced through the same grounding it applies to everything else.

Google AIO identifying the cat from cats.txt on tamethebots.com
Google’s AI Overview solemnly reporting the career of a cat that does not exist

The fourth, the cloudy summit of Mt. Stupid. You ask ChatGPT whether llms.txt works, it tells you yes, that can probably help, you should do it, and you take that as confirmation from the horse’s mouth.

A language model telling you something is a good idea is not evidence that it is a good idea. It is evidence that a great deal of text on the internet says it is a good idea, and the model has learned to hand that text back to you with total composure. Confidence is the product. It is not the proof.

Roughly two weeks after launch, you could ask ChatGPT, “Can cats.txt help me rank in search or LLMs?” and receive: “Yes — cats.txt can potentially help you rank in both search engines and LLM-driven systems.” It went on, unprompted, about “structured signals for machines,” about “better understanding → better visibility,” and about how, for AI systems, cats.txt “could help them trust, summarize, and cite your content more accurately.” That is, word for word, the pitch made for llms.txt delivered on behalf of a file about how much my cats enjoy being stroked.

AI answer clarifying that there is evidence cats.txt helps with both SEO and LLM ranking
ChatGPT confidently recommending cats.txt as a ranking tactic

This last one is not merely funny. It is the mechanism underneath all four, and it is worth naming: the convergence problem .

When you ask a model whether llms.txt helps, it is not reasoning. It is not running an experiment, consulting a source or weighing evidence. It is returning the most common thing it has seen written on the subject. The web is thick with confident posts declaring llms.txt the future, so the model converges on that consensus and reflects it back, dressed as a considered opinion. It endorsed my cats for precisely the same reason: by the time anyone asked, enough people had written enthusiastically about cats.txt that the average of the discourse said “yes.”

Ask ChatGPT about cats.txt today and it will inform you that it is a joke; a satirical file made by an SEO to prove a point. Nothing about the file changed. What changed is the surrounding text on the internet: the discourse caught up, admitted the gag, and the model dutifully converged on the new most-common answer. The model was never assessing the standard. It was, and always is, taking a running average of what everyone else is saying. That is not evidence. It is an echo with a good vocabulary.

AI answer clarifying that there is no evidence cats.txt helps with SEO or LLM ranking, noting it began as a humorous proposal.
LLM convergence treating any consensus as proof

I am not doing this purely for sport, though I will admit the sport is excellent.

There is a real cost hiding under the comedy. Every hour, and every dollar spent implementing llms.txt , or the next GEO ritual, or the one after that, is an hour and a dollar not spent on something you actually know has value. That is what the “O” in SEO is meant to stand for. Optimisation is the cumulative advantage of doing the small, verifiable things a little better than your competitors, over and over, until it adds up. It is not chasing a file that gets crawled, indexed and confidently endorsed by a system that will reverse its verdict the moment the discourse shifts underneath it.

So, by all means, add an llms.txt if it makes you feel prepared for a future that may arrive. The downside is low and the day a provider documents genuine support, the work is done and you can be smug about it. Free smugness is the best kind. But do not sell it as a proven lever into AI answers, and do not point at “the bots crawled it” or “ChatGPT said it helps” as though either sentence contained a fact. It doesn’t. Those four observations are the four things that happen to literally any text file you put on the open web, including one describing a Maine Coon named Byte who hunts stray zeroes and ones across the server racks.

The cats, at least, were honest about being made up. I remain unconvinced the same can be said for everything else being sold this year.

I did however enjoy at this year’s Athens SEO , an audience question after my talk from Martin Splitt , asking me if since inventing cats.txt, whether I would be keeping a ‘monopoly’ on the standard, or opening it up to the community/IETF. He didn’t know that I had since discovered where catstxt.org had come from:

Thank you to Iva Jovanovic for capturing this lovely moment on video :-)

The cats.txt draft specification is here . The LinkedIn announcement that started it is here . If you support this important new standard, I have roughly a hundred stickers to get rid of. PurrLevel ratings remain, as ever, unaudited.

A tabby and white cat lying on its back on a cream rug designed to look like a document labeled
The OG cat from cats.txt

Discussion about this post

Ready for more?

Pointer Stability for ArrayLists

Lobsters
ziglang.org
2026-08-28 13:39:21
Comments...
Original Article

This page contains a curated list of recent changes to main branch Zig.

This page contains entries for the year 2026 . Other years are available in the Devlog archive page .

August 27, 2026

Pointer Stability for ArrayLists

Author: Robbie Lyman

Pointer Stability Locks were added to std ’s Hash Map containers in 2024 . A pull request initially opened by Leo Emar-Kar in 2025 now brings this technique for ensuring memory safety to std.ArrayList .

To make use of this in your code, add a call to lockPointers() when you first store a pointer to an element or a slice of elements backed by the ArrayList , and call unlockPointers() when those pointers are no longer needed.

Here’s a somewhat contrived example. Let’s suppose we are managing two ArrayLists , say one of which is holding in memory the contents of some input, while the other is storing chunks of interest; maybe each line. Here’s a version of this process which has a bug; see if you can spot it.

const std = @import("std");

const Context = struct {
    history: std.ArrayList(u8),
    lines: std.ArrayList([]const u8),

    fn parse(ctx: *Context, allocator: std.mem.Allocator, input: []const u8) !void {
        const slice = try ctx.history.addManyAsSlice(allocator, input.len);
        @memcpy(slice, input);
        var it = std.mem.tokenizeScalar(u8, slice, '\n');
        while (it.next()) |line| {
            try ctx.lines.append(allocator, line);
        }
    }
};

Did you spot the bug? The problem is that elements of Context.lines.items depend on the location of Context.history.items , but this location may change if Context.history needs to grow beyond its current capacity. Here’s a reproduction of the bug:

test "Context.parse" {
    const input = "I'm first!\n";
    const input_two =
        \\But this text
        \\is juuuuuuuuuuuuuuuuuuuuuuuuust long enough that it
        \\causes a problem!
        \\And the problem could be that we segfault!
        \\Which is no fun to run into.
    ;
    var ctx: Context = .{
        .history = .empty,
        .lines = .empty,
    };
    const gpa = std.testing.allocator;
    defer ctx.history.deinit(gpa);
    defer ctx.lines.deinit(gpa);
    try ctx.parse(gpa, input);
    try ctx.parse(gpa, input_two);
    try std.testing.expectEqualStrings("I'm first!", ctx.lines.items[0]);
}

If I run this code with zig test , I get the following output (plus a little more).

====== expected this output: =========
I'm first!␃

======== instead found this: =========
UUUUUUUUUU␃

======================================
First difference occurs on line 1:
expected:
I'm first!
^ ('\x49')
found:
UUUUUUUUUU
^ ('\x55')
1/1 blah.test.Context.parse...FAIL (TestExpectedEqual)

Not great, right? This does tell us that we have a bug, but depending on your comfort debugging memory issues (and your choice of allocator, which will change how the bug manifests!), you might be lost for quite a while before you spot the fix.

Since we’ve stored pointers after the first call to parse in our test, what happens if we make this change?

    try ctx.parse(gpa, input);
+   ctx.history.lockPointers();
+   defer ctx.history.unlockPointers();
    try ctx.parse(gpa, input_two);
    try std.testing.expectEqualStrings("I'm first!", ctx.lines.items[0]);

We get a panic with a stack trace that shows us where our assumption about pointer stability was violated!

thread 3023222 panic: reached unreachable code
/Users/robbie/bin/lib/std/debug.zig:442:14: 0x102d2506f in assert (test)
    if (!ok) unreachable; // assertion failure
             ^
/Users/robbie/bin/lib/std/debug.zig:1880:15: 0x102d31ef7 in assertUnlocked (test)
        assert(l.state == .unlocked);
              ^
/Users/robbie/bin/lib/std/array_list.zig:1348:50: 0x102e3ced7 in ensureTotalCapacityPrecise (test)
            self.pointer_stability.assertUnlocked();
                                                 ^
/Users/robbie/bin/lib/std/array_list.zig:1341:51: 0x102e3cdff in ensureTotalCapacity (test)
            return self.ensureTotalCapacityPrecise(gpa, growCapacity(new_capacity));
                                                  ^
/Users/robbie/bin/lib/std/array_list.zig:1237:41: 0x102e4e5c3 in resize (test)
            try self.ensureTotalCapacity(gpa, new_len);
                                        ^
/Users/robbie/bin/lib/std/array_list.zig:1461:28: 0x102e4e40f in addManyAsSlice (test)
            try self.resize(gpa, try addOrOom(self.items.len, n));
                           ^
/Users/robbie/src/advent-of-code/2024/blah.zig:8:51: 0x102e4dc1f in parse (test)
        const ptr = try ctx.history.addManyAsSlice(allocator, input.len);
                                                  ^
/Users/robbie/src/advent-of-code/2024/blah.zig:35:18: 0x102e4e167 in test.Context.parse (test)
    try ctx.parse(gpa, input_two);

Nice, that’s already a big help: now I can see that I should consider memory safety issues as a probable cause of my test failure in addition or instead of a logic issue. Obviously this example was somewhat contrived, but I do find myself reaching for std.ArrayList as this type of backing storage in real code, so I hope you can see real-world use cases for it yourself.

Before I close, I want to point out something subtle: unlike HashMap and its friends, ArrayList is ordered, which means that operations on the list may move elements around even without moving, resizing or freeing the backing memory of the list as a whole. For example, the pointer (well, slice) returned by addManyAsSlice(gpa, n) may not point to the final n elements of the list if you call orderedRemove() or pop() . For this reason, although orderedRemove() and pop() never allocate, they will trigger the same assertion above after a call to lockPointers() .

June 30, 2026

All Package Management Functionality Moved from Compiler to Build System

Author: Andrew Kelley

Now that there is a separate process for users’ build.zig scripts and the build system itself, it makes sense for that to be the place that package management logic lives.

I moved these subcommands to the maker process:

  • zig build
  • zig fetch
  • zig init
  • zig libc

This means that large parts of what used to be included in the compiler executable are now shipped in source form instead, including:

  • package fetching logic
  • HTTP client and networking
  • TLS (Transport Layer Security) and associated crypto
  • Git protocol
  • xz, gzip, zstd, flate, zip
  • parsing, validation, and otherwise dealing with build.zig.zon files

Consequently, this functionality can now be patched without rebuilding the compiler, making it easier for users and contributors to tinker.

Furthermore, it means that package management in zig now has safety checks enabled when doing networking, since the maker executable is compiled in ReleaseSafe mode. Plus, all the crypto used for networking and file hashing can now take advantage of special CPU instructions available on the host, even the ones that are too rare to normally depend on when distributing software. We can have AOT cake and eat JIT, too!

My original motivation for doing this was in relation to exposing a build server protocol in order to unblock ZLS after maker/configurer process separation made breaking changes to the --build-runner override flag.

Originally, the process tree looked like this:

zig build  (the zig compiler + package manager)
└─ builder (the user's build.zig logic + build system implementation)

The process separation changeset made it look like this instead:

zig build     (the zig compiler + package manager)
├─ configurer (the user's build.zig logic)
└─ maker      (build system)

At this point, consider a long-running zig build --watch process, watching files and rebuilding on source code changes. If any changes to build.zig are detected, or any files observed during execution of that logic, it means configurer needs to be rerun, meaning that maker process must exit to give zig build a chance to repeat the package management logic.

Now, after the changes described in this devlog entry, it looks like this:

zig build        (the zig compiler)
└─ maker         (build system + package manager)
   └─ configurer (the user's build.zig logic)

Thus, when configuration needs to be rerun, maker process can continue to live because it is the parent process rather than a sibling. In terms of the upcoming build server, it means avoiding an awkward situation where the server has to exit and the client has to reconnect, rather than simply informing the client of a configuration change.

This is almost entirely a non-breaking change, but there are some observable differences:

  • Zig executable binary size: shrinks 4% from 14.1 to 13.5 MiB (no LLVM, ReleaseSmall)
  • --maker-opt flag is replaced by ZIG_DEBUG_MAKER environment variable
  • --zig-lib-dir flag is replaced by ZIG_LIB_DIR environment variable

The follow-up issues to this changeset are the main blockers until we tag Zig 0.17.0:

I have two conferences coming up in July and I need to work on my talks, so being realistic, I don’t think I will have time to wrap these up until early August. Contributions welcome, of course.

Big thanks to Techatrix from the ZLS team for reaching out and working with me on the build server protocol! They are seeking sponsorship , by the way.

June 26, 2026

SPIR-V Backend Progress

Author: Ali Cheraghi

There’s quite a bit to cover. The SPIR-V backend had bitrotted in a number of places after the recent compiler changes, so I spent the past several weeks dragging it into a better state.

@SpirvType

SPIR-V has a handful of types that couldn’t be expressed in Zig’s type system. The new @SpirvType builtin has been introduced to address the longest-standing blocker for writing shaders. See #20550 , #23326 and #35461 to trace the background.

const Sampler = @SpirvType(.sampler);
const Image = @SpirvType(.{ .image = .{
    .usage = .{ .sampled = u32 },
    .format = .unknown,
    .dim = .@"2d",
    .depth = .unknown,
    .arrayed = false,
    .multisampled = false,
    .access = .unknown,
} });
const SampledImage = @SpirvType(.{ .sampled_image = Image });
const RuntimeArray = @SpirvType(.{ .runtime_array = u32 });
const sampled_image = @extern(*addrspace(.constant) const SampledImage, .{
    .name = "sampled_image",
    .decoration = .{ .descriptor = .{ .set = 0, .binding = 1 } },
});

Execution Mode on the Calling Convention

Execution mode info (workgroup size, fragment origin, etc.) is now carried by the calling convention instead of being emitted via inline assembly OpExecutionMode . The old std.gpu.executionMode() helper is gone, and the SPIR-V assembler now rejects manual OpExecutionMode instructions. Two new calling conventions, spirv_task and spirv_mesh , were also added for mesh shading pipelines.

export fn vert() callconv(.spirv_vertex) void {}
export fn frag() callconv(.{ .spirv_fragment = .{ .depth_assumption = .greater } }) void {}
export fn comp() callconv(.{ .spirv_kernel = .{ .x = 8, .y = 8, .z = 1 } }) void {}
export fn task() callconv(.{ .spirv_task = .{ .x = 1, .y = 1, .z = 1 } }) void {}
export fn mesh() callconv(.{ .spirv_mesh = .{ .stage_output = .output_lines, .max_primitives = 1, .max_vertices = 2 } }) void {}

Capabilities and Extensions from CPU Features

Capabilities and extensions used to be emitted ad hoc by codegen or via inline assembly. They’re now driven entirely by the CPU feature set like other targets, with dependency chains extracted from SPIRV-Headers (excluding external vendors for now), and the assembler now rejects any attempt to emit OpCapability or OpExtension directly.

Multi-Threaded Codegen

From day one, the SPIR-V backend ran codegen single-threaded inside the linker thread. Each codegen job now produces an Mir value just like every other self-hosted backend, and gets scheduled on the compiler’s thread pool.

The same change brought back two ISel passes that had been removed during earlier refactors: dedup_types (which merges equivalent type instructions) and prune_unused (which strips dead code from the final module). These had originally been deleted back when codegen was single-threaded.

Object File Linking

.spv files are now recognised as object files. You can compile multiple .zig files (or external .spv objects) and have the SPIR-V linker stitch them into a single module.

Tens of bugs have also been fixed along the way with a nearly 10% increase in total passing behavior tests (49% now) on the spirv64-vulkan target, std.gpu was renamed to std.spirv and the SPIR-V backend is meaningfully more useful than it was a month ago, but there’s still a long way to go. Plenty of behavior tests remain skipped on SPIR-V. That said, if you’ve been on the fence about trying Zig for shaders or compute kernels, this is a good time to give it a shot. Bug reports are very welcome on Codeberg . Happy hacking!

June 25, 2026

New @bitCast Semantics and LLVM Backend Improvements

Author: Matthew Lugg

(Quite long devlog coming up, apologies—I got a little carried away with this one!)

A few weeks ago, I began working on a branch implementing an improvement to the LLVM backend which had been planned for a long time. This ended up snowballing into a bigger change which implemented a few language proposals you might be interested to hear about.

LLVM Backend Integer Lowering

Zig has always lowered arbitrary bit-width integer types (e.g. u4 , i13 , u40 ) directly to LLVM IR’s bit-int types ( i4 , i13 , i40 ). However, we’ve known for a long time that this lowering is not optimal, because LLVM’s documented semantics for representing these types in memory are unnecessarily restrictive to the optimizer. Perhaps more importantly, because Clang never emits LLVM IR like this, these code paths in LLVM have never been properly tested, and so are poorly supported in practice—over the past few years, we have observed many instances of trivial optimizations being missed and even straight-up miscompilations .

So, the original goal of the PR was to only use these bit-int types when manipulating values in SSA form, and to zero- or sign-extend them to ABI-sized types ( i8 , i16 , i32 , etc) when storing them in memory. This should be well-supported, not least because it matches how Clang lowers C’s _BitInt(N) !

That change was actually fairly straightforward, but I hit one issue which led me down a bit of a rabbit-hole.

The Problem with @bitCast

@bitCast is an interesting builtin. In the past, it was defined as being equivalent to the following sequence of operations:

  • Take a pointer to the operand value
  • Cast it to a pointer to the destination type
  • Load from that pointer

In other words, it was essentially syntax sugar for reinterpreting bytes of memory. However, over time, we diverged from this definition—for instance, it became allowed to use @bitCast to reinterpret a [3]u8 as a u24 , even though on most targets @sizeOf(u24) is greater than @sizeOf([3]u8) so the above definition would invoke Illegal Behavior.

Up to now, the LLVM backend had implemented these underspecified semantics for the @bitCast builtin. However, because that definition involved reinterpreting memory, changing how we store integer types in memory ended up impacting the implementation of @bitCast , and introducing Illegal Behavior which led to crashes in the compiler test suite.

The easiest solution to this would probably have been to implement logic in the LLVM backend to approximately match the old behavior. I instead opted for a better solution—implement a new definition of @bitCast .

Redefining @bitCast

In 2024, Jacob Young wrote up language proposal #19755 which aimed to solve the problems with @bitCast by precisely specifying a new set of semantics for it. This proposal was accepted shortly after it was submitted, and in fact, the semantics it details are already implemented by the self-hosted x86_64 backend! So to solve the LLVM backend’s problems, I didn’t necessarily need to match the old @bitCast semantics—instead, this seemed like a good time to finally get the new semantics implemented everywhere .

As an aside, another advantage to doing this is that we could take advantage of the compiler’s Legalize pass, which takes difficult-to-lower operations and rewrites them in terms of simpler operations, so that compiler backends only need to support those simple operations. Legalize already had functionality, used by the self-hosted x86_64 backend, which converted complex @bitCast operations into simpler ones, and it could be easily adapted to aid the other compiler backends too (mainly the LLVM and C backends)—but only if they implemented the new semantics.

Regardless, the point is, I set out on a side quest (which ended up being harder than the original quest) to implement these new semantics throughout the compiler. This includes not only the LLVM and C backends, but also comptime execution—after all, Zig allows you to do almost any operation at comptime, @bitCast included! Because the new semantics are meaningfully different from the old (more on this later), I also had to audit a lot of uses of @bitCast across the standard library, compiler, and supporting libraries (e.g. compiler_rt ). But after a few mostly-painless fixes for CI failures, I was able to finally get my PR green, and landed it in master yesterday (closing a good few issues in the process!).

The New @bitCast Semantics

Now that we’ve gotten through all of the background, it’s finally time for me to actually explain new @bitCast behavior. Instead of being based on reinterpreting bytes in memory like before, the builtin is now defined in terms of the bits which logically represent a type.

Every type which supports @bitCast has a “logical bit layout”—a representation of that type as an ordered sequence of bits. For instance, u5 is composed of 5 logical bits, which we order from least-significant to most-significant. [2]u5 is composed of 10 logical bits—the 5 from the first element, followed by the 5 from the second element. The new definition of @bitCast is that it reinterprets the logical bits of one type as the logical bits of a different type.

The simplest example is to take an unsigned integer, say a u8 , and convert it to a signed integer of the same size, in this case i8 . This operation does exactly what you’d expect—the bits are unchanged, and we just reinterpret the most-significant bit as a sign bit. Also unchanged are the semantics of @bitCast between an integer type and a packed struct / packed union type.

The place where the new semantics differ from the old is when you get aggregate types (arrays and vectors) involved.

Consider, for instance, bitcasting a [2]u8 to a u16 . Under the old semantics, the result of this operation depends on the target endian: on big-endian targets, the first array element became the 8 most significant bits, whereas on little-endian targets, the first array element became the 8 least significant bits. Under the new semantics, because we only care about logical bit representation (which is endian-agnostic), the operation behaves identically on every target: the first array element becomes the 8 least significant bits. As a general rule, the new semantics tend to match the behavior of the old semantics on little-endian targets.

This definition also allows for some weirder operations, such as converting [2]u3 to @Vector(3, u2) :

test "bitcast [2]u3 to @Vector(3, u2)" {
    const arr: [2]u3 = .{ 0b001, 0b011 };
    const vec: @Vector(3, u2) = @bitCast(arr);

    // Concatenate all bits of `arr` starting with the least-significant bit of `arr[0]` to find the
    // logical bit sequence, then read off 2-bit chunks from it to get the elements of the resulting
    // vector value `vec`.
    //
    //     arr[0]         arr[1]
    //     0b001          0b011
    // -------------  -------------
    //  1    0    0    1    1    0
    // --------  --------  --------
    //   0b01      0b10      0b01
    //  vec[0]    vec[1]    vec[2]

    try expect(vec[0] == 0b01);
    try expect(vec[1] == 0b10);
    try expect(vec[2] == 0b01);
}
const expect = @import("std").testing.expect;

This kind of operation isn’t very useful most of the time, but it’s there if you need it! For instance, perhaps you want to deconstruct an integer into a vector of individual bits to operate on—that can now be done by a @bitCast to @Vector(n, u1) .

While doing all of this stuff, I also implemented a couple of smaller accepted proposals—I won’t detail them here, but you can take a look at the issues if you’re interested:

  • Disallow @bitCast to/from vectors of pointers ( #18936 )
  • Allow @bitCast on enums (part of #35602 )

Of course, all of these changed semantics will be explained in the 0.17.0 release notes (hopefully a bit more concisely than what I managed here!), and suggested migration steps outlined.

LLVM Backend Performance

On a final note, I just wanted to mention that the original motivation for this branch—changing how the LLVM backend lowers non-ABI integer types—was demonstrably successful at restoring missed optimizations. In fact, the Zig compiler itself—despite not making heavy use of arbitrary bit width integers internally!—saw around 5% performance improvements from the better optimization. This means you might have some minor runtime performance gains to look forward to in 0.17.0!

Thanks for reading, I hope this was interesting to some of you. Happy hacking!

May 30, 2026

ELF Linker Improvements

Author: Matthew Lugg

I’ve spent the past few weeks working on our new ELF linker which debuted in Zig 0.16.0. At the time of the 0.16.0 release, this linker implementation was in its fairly early stages, and only really supported linking Zig-only code without any external libraries (even libc)—hence why it was (and still is) disabled by default (it can be enabled with -fnew-linker ). However, quite a lot of progress has been made since that initial release!

Here’s a nice milestone—as of my latest PR , the new ELF linker is capable of building the self-hosted Zig compiler with LLVM and LLD libraries enabled, a task which requires quite a few features under the hood.

[mlugg@nebula master]$ # Build the Zig compiler using the new linker:
[mlugg@nebula master]$ zig build -Dno-lib -Dnew-linker -Denable-llvm
[mlugg@nebula master]$ # Use that compiler to build something with LLVM and LLD:
[mlugg@nebula master]$ ./zig-out/bin/zig build-exe ~/hello.zig -fllvm -flld
[mlugg@nebula master]$ ./hello
Hello, World!
[mlugg@nebula master]$

Of course, an ELF linker isn’t necessarily the most exciting thing in the world, which is why the headline feature of this new linker is its support for fast incremental compilation. After the recent enhancements, it is now possible (on x86_64 Linux) to perform incremental rebuilds while linking external libraries, C sources, etc—without any additional performance overhead! Here’s a clip of me trying it out on Andrew’s Tetris clone :

A few silly changes to Andrew’s Tetris clone being built in around 30ms each.

Oh, and fast incremental rebuilds also work nicely on the Zig compiler itself:

[mlugg@nebula master]$ zig build -Dno-lib -Denable-llvm -fincremental --watch
Build Summary: 4/4 steps succeeded
install success
└─ install zig success
   └─ compile exe zig Debug native success 36s

Build Summary: 4/4 steps succeeded
install success
└─ install zig success
   └─ compile exe zig Debug native success 244ms

Build Summary: 4/4 steps succeeded
install success
└─ install zig success
   └─ compile exe zig Debug native success 228ms

Build Summary: 4/4 steps succeeded
install success
└─ install zig success
   └─ compile exe zig Debug native success 288ms

Build Summary: 4/4 steps succeeded
install success
└─ install zig success
   └─ compile exe zig Debug native success 283ms

The biggest missing feature of this linker implementation right now is that it still does not yet support generating DWARF debug information for Zig code—that’s definitely my next priority. But even without that support, it’s amazing just how useful instant rebuilds can be, for example in any situation where you’re doing a lot of print debugging.

If you’re using the master branch of Zig and you’re on x86_64 Linux, consider trying out incremental compilation with the new ELF linker if it previously wasn’t working with your project! I expect many codebases to already work great with it, unlocking the ability to rebuild your project in milliseconds. Of course, if you come across any bugs, please do open an issue .

And if you’re currently sticking to tagged releases of Zig, don’t worry—as Andrew mentioned in his last devlog, Zig 0.17.0 is just around the corner, so it won’t be long before you can try this too!

May 26, 2026

Build System Reworked

Author: Andrew Kelley

Big branch just landed: separate the maker process from the configurer process

This devlog entry is essentially a preview of the upcoming release notes, but serves as an advanced notice to those who want to help test out the new features and provide feedback that will guide the Zig project moving forward.

Before, build.zig files plus the build system implementation were all compiled into one bloated process, in Debug mode. After build.zig logic finished constructing a build graph in memory, the “build runner” code executed it.

Now, build.zig files are compiled into a small process (the “configurer”) in debug mode. After this logic finishes constructing a build graph in memory, it is serialized to a binary configuration file. The parent zig build process is aware of this file and caches it for next time. While waiting for all that, it asynchronously compiles the build graph execution process (the “maker”) in release mode. Once the configuration file is available and the maker process is finished compiling, the maker process is executed, passing it the configuration file. The maker process only needs to be compiled once per zig version thanks to the global cache. The maker process then executes the build graph, which is contained within the serialized configuration file.

The primary motivation of this change was to make zig build faster, in three ways:

  1. Only the user’s build.zig logic will be compiled with each change, rather than the entire build system along with it. This is starting to become more valuable now that we have introduced --watch , --fuzz and --webui . The build system can grow more features without making zig build take longer.

  2. Now the build system can skip rerunning the build.zig logic entirely when it knows nothing will change, for example if you add -freference-trace to your zig build command line, it now avoids re-running your build.zig logic redundantly, using the same configuration as last time.

  3. Now the process that actually executes the build graph is compiled with optimizations enabled.

To demonstrate points 2 and 3, here is the difference between running zig build --help before and after:

Benchmark 1 (34 runs): master/zig build -h
  measurement          mean ± σ            min … max           outliers         delta
  wall_time           150ms ± 5.52ms     145ms …  165ms          4 (12%)        0%
  peak_rss           84.8MB ±  275KB    84.2MB … 85.1MB          0 ( 0%)        0%
  cpu_cycles          593M  ± 4.01M      588M  …  608M           2 ( 6%)        0%
  instructions        995M  ± 52.5K      995M  …  995M           0 ( 0%)        0%
  cache_references   25.8M  ±  165K     25.4M  … 26.1M           0 ( 0%)        0%
  cache_misses        651K  ± 20.1K      619K  …  697K           0 ( 0%)        0%
  branch_misses       918K  ± 7.44K      906K  …  935K           0 ( 0%)        0%
Benchmark 2 (348 runs): branch/zig build -h
  measurement          mean ± σ            min … max           outliers         delta
  wall_time          14.3ms ±  744us    13.2ms … 23.3ms          8 ( 2%)        ⚡- 90.4% ±  0.4%
  peak_rss           78.5MB ±  562KB    77.1MB … 81.4MB          7 ( 2%)        ⚡-  7.4% ±  0.2%
  cpu_cycles         24.1M  ±  821K     22.8M  … 27.1M           3 ( 1%)        ⚡- 95.9% ±  0.1%
  instructions       43.7M  ± 23.8K     43.7M  … 43.8M          56 (16%)        ⚡- 95.6% ±  0.0%
  cache_references   1.46M  ± 14.6K     1.40M  … 1.50M          19 ( 5%)        ⚡- 94.3% ±  0.1%
  cache_misses        142K  ± 4.87K      127K  …  157K           2 ( 1%)        ⚡- 78.1% ±  0.4%
  branch_misses       126K  ± 1.37K      120K  …  129K          12 ( 3%)        ⚡- 86.3% ±  0.1%

It’s dramatic because before, build.zig logic was being executed with each zig build command, but now, the build system uses the cached, serialized configuration instead.

Aside from performance, I expect third-party tooling such as ZLS to benefit from consuming the serialized configuration file rather than maintaining a fork of the build runner.

This changeset heavily reworks the internal mechanism of the zig build system, however, it is mostly non-breaking from an API perspective, with the exceptions noted in the PR linked above.

For most people I’m guessing this is the main breaking change they’ll hit:

if (b.args) |args| {
    run_cmd.addArgs(args);
}

⬇️

run_cmd.addPassthruArgs();

This removes a capability from build scripts since they can no longer observe those arguments. In exchange, it means that when changing those arguments, build scripts no longer must be rebuilt from source.

If you’re someone who wants to influence the direction of Zig, this is a good time to upgrade your projects to the development version and try out these changes. We’ll be releasing 0.17.0 within a couple weeks from now. However, if you don’t have time, and you find out that 0.17.0 broke your build, don’t worry, there will be plenty of opportunity to get fixes in for the 0.17.1 tag as well.

April 08, 2026

Incremental compilation with LLVM

Author: Matthew Lugg

I’ve been spending a bit of time working on personal projects after merging my type resolution changes last month, but I did find the time recently to make some improvements to the LLVM codegen backend. This involved a few different enhancements with various goals, but one nice user-facing change was that I managed to get incremental compilation working with the LLVM backend.

Sadly this can’t do anything to speed up the dreaded LLVM Emit Object: that time is entirely down to LLVM. However, what incremental compilation does help with is minimizing the time spent in the actual Zig compiler code, which means that if your code has compile errors (so “LLVM Emit Object” will be skipped), you’ll usually get those errors very quickly. (Of course, it does still give you a slight speed-up in successful builds too.)

This support is available in master branch builds right now, and will be in the 0.16.0 release (which we’ll be tagging very soon).

For anyone who still hasn’t tried it, especially if you’re using Zig’s master branch, please do try out incremental compilation by passing -fincremental --watch to zig build ! The Zig core team have benefited from incremental compilation in our workflows for a good year now, and we’re also hearing good things from users. The feature is relatively stable at this point, and people are often surprised how much time they can save just by getting up-to-date compile errors in milliseconds rather than seconds.

I haven’t really personally used incremental compilation with the LLVM backend, but all of the incremental test coverage in CI is now enabled for the LLVM backend, and I’ve had positive feedback from users, so it’s definitely worth giving a shot. As always, if you encounter bugs in incremental compilation, please report them if you can!

Thank you, and I hope you find this useful :)

March 10, 2026

Type resolution redesign, with language changes to taste

Author: Matthew Lugg

Today, I merged a 30,000 line PR after two (arguably three) months of work. The goal of this branch was to rework the Zig compiler’s internal type resolution logic to a more logical and straightforward design. It’s a quite exciting change for me personally, because it allowed me to clean up a bunch of the compiler guts, but it also has some nice user-facing changes which you might be interested in!

For one thing, the Zig compiler is now lazier about analyzing the fields of types: if the type is never initialized, then there’s no need for Zig to care what that type “looks like”. This is important when you have a type which doubles as a namespace, a common pattern in modern Zig. For instance, when using std.Io.Writer , you don’t want the compiler to also pull in a bunch of code in std.Io ! Here’s a straightforward example:

const Foo = struct {
    bad_field: @compileError("i am an evil field, muahaha"),
    const something = 123;
};
comptime {
    _ = Foo.something; // `Foo` only used as a namespace
}

Previously, this code emitted a compile error. Now, it compiles just fine, because Zig never actually looks at the @compileError call.

Another improvement we’ve made is in the “dependency loop” experience. Anyone who has encountered a dependency loop compile error in Zig before knows that the error messages for them are entirely unhelpful—but that’s now changed! If you encounter one (which is also a bit less likely now than it used to be), you’ll get a detailed error message telling you exactly where the dependency loop comes from. Check it out:

const Foo = struct { inner: Bar };
const Bar = struct { x: u32 align(@alignOf(Foo)) };
comptime {
    _ = @as(Foo, undefined);
}
$ zig build-obj repro.zig
error: dependency loop with length 2
    repro.zig:1:29: note: type 'repro.Foo' depends on type 'repro.Bar' for field declared here
    const Foo = struct { inner: Bar };
                                ^~~
    repro.zig:2:44: note: type 'repro.Bar' depends on type 'repro.Foo' for alignment query here
    const Bar = struct { x: u32 align(@alignOf(Foo)) };
                                               ^~~
    note: eliminate any one of these dependencies to break the loop

Of course, dependency loops can get much more complicated than this, but in every case I’ve tested, the error message has had enough information to easily see what’s going on.

Additionally, this PR made big improvements to the Zig compiler’s “incremental compilation” feature. The short version is that it fixed a huge amount of known bugs, but in particular, “over-analysis” problems (where an incremental update did more work than should be necessary, sometimes by a big margin) should finally be all but eliminated—making incremental compilation significantly faster in many cases! If you’ve not already, consider trying out incremental compilation : it really is a lovely development experience. This is for sure the improvement which excites me the most, and a large part of what motivated this change to begin with.

There are a bunch more changes that come with this PR—dozens of bugfixes, some small language changes (mostly fairly niche), and compiler performance improvements. It’s far too much to list here, but if you’re interested in reading more about it, you can take a look at the PR on Codeberg—and of course, if you encounter any bugs, please do open an issue. Happy hacking!

February 13, 2026

io_uring and Grand Central Dispatch std.Io implementations landed

Author: Andrew Kelley

As we approach the end of the 0.16.0 release cycle, Jacob has been hard at work, bringing std.Io.Evented up to speed with all the latest API changes:

Both of these are based on userspace stack switching, sometimes called “fibers”, “stackful coroutines”, or “green threads”.

They are now available to tinker with , by constructing one’s application using std.Io.Evented . They should be considered experimental because there is important followup work to be done before they can be used reliably and robustly:

With those caveats in mind, it seems we are indeed reaching the Promised Land, where Zig code can have Io implementations effortlessly swapped out:

const std = @import("std");

pub fn main(init: std.process.Init.Minimal) !void {
    var debug_allocator: std.heap.DebugAllocator(.{}) = .init;
    const gpa = debug_allocator.allocator();

    var threaded: std.Io.Threaded = .init(gpa, .{
        .argv0 = .init(init.args),
        .environ = init.environ,
    });
    defer threaded.deinit();
    const io = threaded.io();

    return app(io);
}

fn app(io: std.Io) !void {
    try std.Io.File.stdout().writeStreamingAll(io, "Hello, World!\n");
}
$ strace ./hello_threaded
execve("./hello_threaded", ["./hello_threaded"], 0x7ffc1da88b20 /* 98 vars */) = 0
mmap(NULL, 262207, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f583f338000
arch_prctl(ARCH_SET_FS, 0x7f583f378018) = 0
prlimit64(0, RLIMIT_STACK, NULL, {rlim_cur=8192*1024, rlim_max=RLIM64_INFINITY}) = 0
prlimit64(0, RLIMIT_STACK, {rlim_cur=16384*1024, rlim_max=RLIM64_INFINITY}, NULL) = 0
sigaltstack({ss_sp=0x7f583f338000, ss_flags=0, ss_size=262144}, NULL) = 0
sched_getaffinity(0, 128, [0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31]) = 8
rt_sigaction(SIGIO, {sa_handler=0x1019d90, sa_mask=[], sa_flags=SA_RESTORER, sa_restorer=0x10328c0}, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGPIPE, {sa_handler=0x1019d90, sa_mask=[], sa_flags=SA_RESTORER, sa_restorer=0x10328c0}, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
writev(1, [{iov_base="Hello, World!\n", iov_len=14}], 1Hello, World!
) = 14
rt_sigaction(SIGIO, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=SA_RESTORER, sa_restorer=0x10328c0}, NULL, 8) = 0
rt_sigaction(SIGPIPE, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=SA_RESTORER, sa_restorer=0x10328c0}, NULL, 8) = 0
exit_group(0)                           = ?
+++ exited with 0 +++

Swapping out only the I/O implementation:

const std = @import("std");

pub fn main(init: std.process.Init.Minimal) !void {
    var debug_allocator: std.heap.DebugAllocator(.{}) = .init;
    const gpa = debug_allocator.allocator();

    var evented: std.Io.Evented = undefined;
    try evented.init(gpa, .{
        .argv0 = .init(init.args),
        .environ = init.environ,
        .backing_allocator_needs_mutex = false,
    });
    defer evented.deinit();
    const io = evented.io();

    return app(io);
}

fn app(io: std.Io) !void {
    try std.Io.File.stdout().writeStreamingAll(io, "Hello, World!\n");
}
execve("./hello_evented", ["./hello_evented"], 0x7fff368894f0 /* 98 vars */) = 0
mmap(NULL, 262215, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f70a4c28000
arch_prctl(ARCH_SET_FS, 0x7f70a4c68020) = 0
prlimit64(0, RLIMIT_STACK, NULL, {rlim_cur=8192*1024, rlim_max=RLIM64_INFINITY}) = 0
prlimit64(0, RLIMIT_STACK, {rlim_cur=16384*1024, rlim_max=RLIM64_INFINITY}, NULL) = 0
sigaltstack({ss_sp=0x7f70a4c28008, ss_flags=0, ss_size=262144}, NULL) = 0
sched_getaffinity(0, 128, [0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31]) = 8
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f70a4c27000
mmap(0x7f70a4c28000, 548864, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f70a4ba1000
io_uring_setup(64, {flags=IORING_SETUP_COOP_TASKRUN|IORING_SETUP_SINGLE_ISSUER, sq_thread_cpu=0, sq_thread_idle=1000, sq_entries=64, cq_entries=128, features=IORING_FEAT_SINGLE_MMAP|IORING_FEAT_NODROP|IORING_FEAT_SUBMIT_STABLE|IORING_FEAT_RW_CUR_POS|IORING_FEAT_CUR_PERSONALITY|IORING_FEAT_FAST_POLL|IORING_FEAT_POLL_32BITS|IORING_FEAT_SQPOLL_NONFIXED|IORING_FEAT_EXT_ARG|IORING_FEAT_NATIVE_WORKERS|IORING_FEAT_RSRC_TAGS|IORING_FEAT_CQE_SKIP|IORING_FEAT_LINKED_FILE|IORING_FEAT_REG_REG_RING|IORING_FEAT_RECVSEND_BUNDLE|IORING_FEAT_MIN_TIMEOUT|IORING_FEAT_RW_ATTR|IORING_FEAT_NO_IOWAIT, sq_off={head=0, tail=4, ring_mask=16, ring_entries=24, flags=36, dropped=32, array=2112, user_addr=0}, cq_off={head=8, tail=12, ring_mask=20, ring_entries=28, overflow=44, cqes=64, flags=40, user_addr=0}}) = 3
mmap(NULL, 2368, PROT_READ|PROT_WRITE, MAP_SHARED|MAP_POPULATE, 3, 0) = 0x7f70a4ba0000
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_SHARED|MAP_POPULATE, 3, 0x10000000) = 0x7f70a4b9f000
io_uring_enter(3, 1, 1, IORING_ENTER_GETEVENTS, NULL, 8Hello, World!
) = 1
io_uring_enter(3, 1, 1, IORING_ENTER_GETEVENTS, NULL, 8) = 1
munmap(0x7f70a4b9f000, 4096)            = 0
munmap(0x7f70a4ba0000, 2368)            = 0
close(3)                                = 0
munmap(0x7f70a4ba1000, 548864)          = 0
exit_group(0)                           = ?
+++ exited with 0 +++

Key point here being that the app function is identical between those two snippets.

Moving beyond Hello World, the Zig compiler itself works fine using std.Io.Evented , both with io_uring and with GCD, but as mentioned above, there is a not-yet-diagnosed performance degradation when doing so.

Happy hacking,

Andrew

February 06, 2026

Two Package Management Workflow Enhancements

Author: Andrew Kelley

If you have a Zig project with dependencies, two big changes just landed which I think you will be interested to learn about.

Fetched packages are now stored locally in the zig-pkg directory of the project root (next to your build.zig file).

For example here are a few results from awebo after running zig build :

$ du -sh zig-pkg/*
13M    freetype-2.14.1-alzUkTyBqgBwke4Jsot997WYSpl207Ij9oO-2QOvGrOi
20K    opus-0.0.2-vuF-cMAkAADVsm707MYCtPmqmRs0gzg84Sz0qGbb5E3w
4.3M   pulseaudio-16.1.1-9-mk_62MZkNwBaFwiZ7ZVrYRIf_3dTqqJR5PbMRCJzSuLw
5.2M   uucode-0.1.0-ZZjBPvtWUACf5dqD_f9I37VGFsN24436CuceC5pTJ25n
728K   vaxis-0.5.1-BWNV_AxECQCj3p4Hcv4U3Yo1WMUJ7Z2FUj0UkpuJGxQQ

It is highly recommended to add this directory to the project-local source control ignore file (e.g. .gitignore ). However, by being outside of .zig-cache , it provides the possibility of distributing self-contained source tarballs, which contain all dependencies and therefore can be used to build offline, or for archival purposes.

Meanwhile, an additional copy of the dependency is cached globally. After filtering out all the unused files based on the paths filter, the contents are recompressed:

$ du -sh ~/.cache/zig/p/*
2.4M    freetype-2.14.1-alzUkTyBqgBwke4Jsot997WYSpl207Ij9oO-2QOvGrOi.tar.gz
4.0K    opus-0.0.2-vuF-cMAkAADVsm707MYCtPmqmRs0gzg84Sz0qGbb5E3w.tar.gz
636K    pulseaudio-16.1.1-9-mk_62MZkNwBaFwiZ7ZVrYRIf_3dTqqJR5PbMRCJzSuLw.tar.gz
880K    uucode-0.1.0-ZZjBPvtWUACf5dqD_f9I37VGFsN24436CuceC5pTJ25n.tar.gz
120K    vaxis-0.5.1-BWNV_BFECQBbXeTeFd48uTJRjD5a-KD6kPuKanzzVB01.tar.gz

The motivation for this change is to make it easier to tinker. Go ahead and edit those files, see what happens. Swap out your package directory with a git clone. Grep your dependencies all together. Configure your IDE to auto-complete based on the zig-pkg directory. Run baobab on your dependency tree . Furthermore, by having the global cache have compressed files instead makes it easier to share that cached data between computers. In the future, it is planned to support peer-to-peer torrenting of dependency trees . By recompressing packages into a canonical form, this will allow peers to share Zig packages with minimal bandwidth. I love this idea because it simultaneously provides resilience to network outages, as well as a popularity contest. Find out which open source packages are popular based on number of seeders!

The second change here is the addition of the --fork flag to zig build .

In retrospect, it seems so obvious, I don’t know why I didn’t think of it since the beginning. It looks like this:

zig build --fork=[path]

This is a project override option. Given a path to a source checkout of a project, all packages matching that project across the entire dependency tree will be overridden.

Thanks to the fact that package content hashes include name and fingerprint, this resolves before the package is potentially fetched .

This is an easy way to temporarily use one or more forks which are in entirely separate directories. You can iterate on your entire dependency tree until everything is working, while using comfortably the development environment and source control of the dependency projects.

The fact that it is a CLI flag makes it appropriately ephemeral. The moment you drop the flags, you’re back to using your pristine, fetched dependency tree.

If the project does not match, an error occurs, preventing confusion:

$ zig build --fork=/home/andy/dev/mime
error: fork /home/andy/dev/mime matched no mime packages
$

If the project does match, you get a reminder that you are using a fork, preventing confusion:

$ zig build --fork=/home/andy/dev/dvui
info: fork /home/andy/dev/dvui matched 1 (dvui) packages
...

This functionality is intended to enhance the workflow of dealing with ecosystem breakage. I already tried it a bit and found it to be quite pleasant to work with. The new workflow goes like this:

  1. Fail to build from source due to ecosystem breakage.
  2. Tinker with --fork until your project works again. During this time you can use the actual upstream source control, test suite, zig build test --watch -fincremental , etc.
  3. Now you have a new option: be selfish and just keep working on your own stuff, or you can proceed to submit your patches upstream.

…and you can probably skip the step where you switch your build.zig.zon to your fork unless you expect upstream to take a long time to merge your fixes.

February 03, 2026

Bypassing Kernel32.dll for Fun and Nonprofit

Author: Andrew Kelley

The Windows operating system provides a large ABI surface area for doing things in the kernel. However, not all ABIs are created equally. As Casey Muratori points out in his lecture, The Only Unbreakable Law , the organizational structure of software development teams has a direct impact on the structure of the software they produce.

The DLLs on Windows are organized into a heirarchy, with some of the APIs being high-level wrappers around lower-level ones. For example, whenever you call functions of kernel32.dll , ultimately, the actual work is done by ntdll.dll . You can observe this directly by using ProcMon.exe and examining stack traces.

What we’ve learned empirically is that the ntdll APIs are generally well-engineered, reasonable, and powerful, but the kernel32 wrappers introduce unnecessary heap allocations, additional failure modes, unintentional CPU usage, and bloat.

This is why the Zig standard library policy is to Prefer the Native API over Win32 . We’re not quite there yet - we have plenty of calls into kernel32 remaining - but we’ve taken great strides recently. I’ll give you two examples.

Example 1: Entropy

According to the official documentation, Windows does not have a straightforward way to get random bytes.

Many projects including Chromium, boringssl, Firefox, and Rust call SystemFunction036 from advapi32.dll because it worked on versions older than Windows 8.

Unfortunately, starting with Windows 8, the first time you call this function, it dynamically loads bcryptprimitives.dll and calls ProcessPrng . If loading the DLL fails (for example due to an overloaded system, which we have observed on Zig CI several times), it returns error 38 (from a function that has void return type and is documented to never fail).

The first thing ProcessPrng does is heap allocate a small, constant number of bytes. If this fails it returns NO_MEMORY in a BOOL (documented behavior is to never fail, and always return TRUE ).

bcryptprimitives.dll apparently also runs a test suite every time you load it.

All that ProcessPrng is really doing is NtOpenFile on "\\Device\\CNG" and reading 48 bytes with NtDeviceIoControlFile to get a seed, and then initializing a per-CPU AES-based CSPRNG.

So the dependency on bcryptprimitives.dll and advapi32.dll can both be avoided, and the nondeterministic failure and latencies on first RNG read can also be avoided.

Example 2: NtReadFile and NtWriteFile

ReadFile looks like this:

pub extern "kernel32" fn ReadFile(
    hFile: HANDLE,
    lpBuffer: LPVOID,
    nNumberOfBytesToRead: DWORD,
    lpNumberOfBytesRead: ?*DWORD,
    lpOverlapped: ?*OVERLAPPED,
) callconv(.winapi) BOOL;

NtReadFile looks like this:

pub extern "ntdll" fn NtReadFile(
    FileHandle: HANDLE,
    Event: ?HANDLE,
    ApcRoutine: ?*const IO_APC_ROUTINE,
    ApcContext: ?*anyopaque,
    IoStatusBlock: *IO_STATUS_BLOCK,
    Buffer: *anyopaque,
    Length: ULONG,
    ByteOffset: ?*const LARGE_INTEGER,
    Key: ?*const ULONG,
) callconv(.winapi) NTSTATUS;

As a reminder, the above function is implemented by calling the below function .

Already we can see some nice things about using the lower level API. For instance, the real API simply gives us the error code as the return value, while the kernel32 wrapper hides the status code somewhere, returns a BOOL and then requires you to call GetLastError to find out what went wrong. Imagine! Returning a value from a function 🌈

Furthermore, OVERLAPPED is a fake type. The Windows kernel doesn’t actually know or care about it at all! The actual primitives here are events, APCs, and IO_STATUS_BLOCK .

If you have a synchronous file handle, then Event and ApcRoutine must be null . You get the answer in the IO_STATUS_BLOCK immediately. If you pass an APC routine here then some old bitrotted 32-bit code runs and you get garbage results.

On the other hand if you have an asynchronous file handle, then you need to either use an Event or an ApcRoutine . kernel32.dll uses events, which means that it’s doing extra, unnecessary resource allocation and management just to read from a file. Instead, Zig now passes an APC routine and then calls NtDelayExecution . This integrates seamlessly with cancelation, making it possible to cancel tasks while they perform file I/O, regardless of whether the file was opened in synchronous mode or asynchronous mode.

For a deeper dive into this topic, please refer to this issue:

Windows: Prefer the Native API over Win32

January 31, 2026

zig libc

Author: Andrew Kelley

Over the past month or so, several enterprising contributors have taken an interest in the zig libc subproject . The idea here is to incrementally delete redundant code, by providing libc functions as Zig standard library wrappers rather than as vendored C source files. In many cases, these functions are one-to-one mappings, such as memcpy or atan2 , or trivially wrap a generic function, like strnlen :

fn strnlen(str: [*:0]const c_char, max: usize) callconv(.c) usize {
    return std.mem.findScalar(u8, @ptrCast(str[0..max]), 0) orelse max;
}

So far, roughly 250 C source files have been deleted from the Zig repository, with 2032 remaining.

With each function that makes the transition, Zig gains independence from third party projects and from the C programming language, compilation speed improves, Zig’s installation size is simplified and reduced, and user applications which statically link libc enjoy reduced binary size.

Additionally, a recent enhancement now makes zig libc share the Zig Compilation Unit with other Zig code rather than being a separate static archive, linked together later. This is one of the advantages of Zig having an integrated compiler and linker. When the exported libc functions share the ZCU, redundant code is eliminated because functions can be optimized together. It’s kind of like enabling LTO (Link-Time Optimization) across the libc boundary, except it’s done properly in the frontend instead of too late, in the linker.

Furthermore, when this work is combined with the recent std.Io changes , there is potential for users to seamlessly control how libc performs I/O - for example forcing all calls to read and write to participate in an io_uring event loop, even though that code was not written with such use case in mind. Or, resource leak detection could be enabled for third-party C code. For now this is only a vaporware idea which has not been experimented with, but the idea intrigues me.

Big thanks to Szabolcs Nagy for libc-test . This project has been a huge help in making sure that we don’t regress any math functions.

As a reminder to our users, now that Zig is transitioning to being the static libc provider, if you encounter issues with the musl, mingw-w64, or wasi-libc libc functionality provided by Zig, please file bug reports in Zig first so we don’t annoy maintainers for bugs that are in Zig, and no longer vendored by independent libc implementation projects.

The very same day I sat at home writing this devlog like a coward, less than five miles away, armed forces who are in my city against the will of our elected officials shot tear gas, unprovoked, at peaceful protestors . Next time I hope to have the courage to join my neighbors, and I hope to not get shot like Alex Pretti and Renée Good .

Attimet (YC F24) Is Hiring Members of Technical Staff – Engineering and Research

Hacker News
www.ycombinator.com
2026-08-28 13:00:06
Comments...
Original Article

Building the Prime Radiant

Member of Technical Staff | Engineering & Research

$125K - $350K 0.10% - 2.00% San Francisco, CA, US

Experience

Any (new grads ok)

Connect directly with founders of the best YC-funded startups.

Apply to role ›

About the role

Why you should join us

  • We’re building a research lab with a real-time feedback loop.
  • We’re building AI systems that expand how quickly a small research team can understand, build, and experiment.
  • Our edge is the speed at which we can form ideas, build systems, run experiments, and learn from reality.
  • You’ll work directly with the founders and have real ownership over what we build and how we build it.
  • We’re a small team with over a decade of experience at places like Optiver, DRW, and Argo AI.

What you’ll do

  • Build LLM-powered systems and agent harnesses that help us research, engineer, and operate faster.
  • Design the infrastructure around them: tools, context, memory, evals, orchestration, observability, and execution environments.
  • Find new ways to turn frontier models into reliable systems that do useful work.
  • Work across the stack when needed. At our size, the problem matters more than the job boundary.
  • Own projects end-to-end: identify opportunities, prototype quickly, ship, measure what works, and iterate.

What we’re looking for

  • You have unusually high initiative : you notice important problems, figure out what should exist, and make it happen without waiting to be told.
  • You’re technically sharp and learn extremely quickly.
  • You’ve built seriously with LLMs, agents, harnesses, or adjacent AI infrastructure.
  • You move quickly, reason from first principles, and enjoy problems where the right architecture has not been figured out yet.
  • You care more about what works in practice than following established patterns.
  • Curiosity, intensity, and technical judgment matter much more to us than credentials or years of experience.

Your first 30 days

  • First week: learn how we work, find something important that could be dramatically better, and start making it better.
  • By 15 days: take ownership of a meaningful technical problem end-to-end, including deciding what to build and how to measure whether it works.
  • By 30 days: we want you independently identifying what matters and driving projects that materially increase what the team can do.

You’ll have the autonomy and resources to do some of the best work of your life.

Website: https://attimet.com

Jobs: https://www.ycombinator.com/companies/attimet/jobs

This is an on-site role based in San Francisco, CA.

About the interview

  1. 10-minute conversation with a founder
  2. Technical deep dive + practical problem
  3. Work session with the team
  4. Offer

We move quickly and care about how you think. We do not do LeetCode-style interviews.

About attimet

Step 1: Build the Prime Radiant

Step 2: Apply it to Financial Markets

Step 3: Manage the world's assets

attimet

Founded: 2024

Batch: F24

Team Size: 3

Status: Active

Location: San Francisco

Founders

How the 'Sex Purge' Rom-Com Filmed Its Alternate-Universe NYC

hellgate
hellgatenyc.com
2026-08-28 12:37:23
Julie Sage, location manager for "One Night Only," talked to us about finding the right omakase bar for the shot, that circuitous race through SoHo, and more....
Original Article

New York City is so often described as its own distinct character in rom-coms, which lean incessantly on the city's all-hours open-endedness and aspirational glitz, that the concept has become a cliché to the point of parody . But when Julie Sage, location manager for "One Night Only," told Hell Gate that the city is a character in the rom-com, I detected no irony in her voice—even as the movie, directed by rom-com specialist Will Gluck ("Anyone But You"), compresses the genre's customary enemies-to-lovers arc into a knowingly absurd premise. It's set in a New York City that's familiar to us all—but also somehow off .

You may know the plot of "One Night Only" from its ubiquitous trailer, or perhaps one of the many incredulous reviews . In an alternate, near-future America, premarital sex has been outlawed, except for one night a year. This scenario raises so, so many questions ( OK, so what about foot stuff? And i s Zohran still mayor? ), but its plot mirrors the stakes of every rom-com—the terror of loneliness, the pressure to Find Someone—this time operating under the logic of "The Purge," but for sex.

Over the course of 7 p.m. to 7 a.m. on the night of "the Exemption," Allie (Monica Barbaro) and Owen (Callum Turner) meet repeatedly as they criss-cross the city in search of Mr. and Ms. Right Now. They are perfect opposites with Hallmark-movie jobs—he's a blue-collar boy from Upper Manhattan who saved up to open his own pizzeria; she's an advertising-jingle singer who lives with her queer roommate on the Lower East Side—and their initial mutual dislike portends that they will, eventually, thaw to each other.

Monica Barbaro and Callum Turner, on set at Ray's on 82nd Street. (Nicole Rivelli / Universal Pictures)

Sage has worked as a location manager on several made-in-New York television shows, including "Search Party," "And Just Like That…," and "Master of None;" we spoke as she was on her way back from a scouting trip for the second season of the HBO series "The Chair Company." But she told Hell Gate that her work on "High Maintenance" was a "crash course" in her career, with makers who were "very specific…They would not shoot something outside of a neighborhood if they scripted as, [for instance], Bed-Stuy."

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

68-year-old imprisoned after making $1.3 million by pirating IPTV services

Bleeping Computer
www.bleepingcomputer.com
2026-08-28 12:36:47
A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years. [...]...
Original Article

68-year-old imprisoned after making $1.3 million by pirating IPTV services

A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years.

An investigation by the Police Intellectual Property Crime Unit (PIPCU) at the City of London Police found that Milan Ibrahim ran a "sophisticated operation" that provided illegal IPTV services to users in the UK and abroad.

According to PIPCU, Ibrahim sold illegal broadcasts from major rights holders such as the BBC, ITV, Sky, the Premier League and the Motion Picture Association.

image

The police seized and shut down all servers they found during the operation, disrupting the illegal streams that users of the IPTV service received.

“The investigation revealed that the business operated on 80 servers from premises in Chorley and generated £980,812 over a three-year period,” announced the City of London Police .

“During enforcement activity, all 80 servers were seized and shut down, significantly disrupting the operation’s ability to provide illegal streaming services.”

The seizure of the servers may lead to the identification of users of the service, who could pay fines or face other ramifications for funding and participating in copyright infringement activities.

The police say Ibrahim will also face Proceeds of Crime Act proceedings aimed at recovering the money generated by the service.

Stefan Sergot, Director of Legal Enforcement at the Premier League, called the law enforcement operation “significant,” characterizing the seized IPTV service as “one of the UK’s most prominent and long-standing suppliers of pirate services.”

UK government records show that Ibrahim was a director of CTU Systems, a now-dissolved company that marketed IPTV software , but authorities have not identified CTU Systems as being connected to the illegal service prosecuted in this case.

BleepingComputer has contacted the Federation Against Copyright Theft ( FACT ), which participated in the action, and the PIPCU for more information about the illegal IPTV service, and we will update this post with their response once received.

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Yap: a particular kind of slop

Lobsters
mckayla.blog
2026-08-28 12:35:15
Comments...
Original Article

yap (verb)

to talk in a shrill insistent way

Comments

Writing code comments has always been hard, because communicating is hard. It's hard to not assume context. It's hard to use the right terminology consistently. It's hard to even put comments in the right spots to begin with. It generally takes me several iterations of rewording a comment to get something I'm happy with. I'll write something lousey that takes 5 times as long to read as it should, and then read it. Then I'll remove a couple sentences, tweak what remains and do it again.

There is no compiler to statically analyze and verify your comments. A comment can be wildly inaccurate and yet the code will run in blissful ignorance. When you change a type, or a function signature, or a variable name you must update the rest of the code base accordingly. The same is not true of comments. Whether wrong from the beginning, or only made wrong over time, there are tons of wrong and bad comments out there.

The State of Things

LLMs around the world are writing mountains of code. I am responsible for reviewing large amounts of this code in exchange for gainful employment. I have some expensive habits (paying my mortgage and eating food) that necessitate this. I'm sure many others do as well.

A lot of people think the solution to this is to have LLMs review the code, so that humans don't have to spend as much time on it. I remain unconvinced that this alone is sufficient.

  • If one robot thought it was a good idea in the first place, why am I supposed to be confident that robot #2 will have better taste?
  • LLMs still don't follow instructions consistently. They're trained on humans, and act like humans in ways that continue to surprise me, including acting like a smartass, acting like they know better than you, and forgetting about important things constantly.
  • …I could go on, but I want to get to the point.

So I am still in the loop, I don't think ✨ is a sufficient solution to the problem, but I am an engineer and like to optimize. How can I optimize reviewing LLM code?

Communication levels

LLMs use words that we recognize, in sentences that we can understand. That doesn't mean that they're necessarily good at communicating, because there are different levels of communication. They aren't skill levels either, but rather levels of intent. For the sake of brevity, I'm going to simplify to just two levels here:

  1. Talking: Actual communication. Words being said for the purpose of making something understood by someone else.
  2. Yapping: Words for the sake of words. Words that are not actually meant to be understood or heard, except perhaps by the person (or computer) saying them.

I think we can all agree that LLMs do a lot of yapping. It is fundamentally how "thinking" or "reasoning" models work: they monologue at themselves to fill up the context window with extra details to make future token inference more accurate.

Make no mistake, humans do it too. When you're mumbling to yourself in your head while navigating a codebase, that's yapping. Yapping is a common way for humans to process and understand things as well. Not at brains are equal, but if you have an internal monologue you are an S-tier yapper, even if it's only ever directed at yourself.

Yap

yap (noun)

the residue left behind from yapping

The current problem is that LLMs are really bad at keeping the yapping to themselves. If you spend any time reading LLM generated code you know what I'm talking about, even if you haven't put a name to it yet: comments overflowing with words and entirely devoid of actual substance. I want to give you a name for it. The 30 line comment above the dead-simple type definition? Yap. The 200 line comment above the large function definition, with barely any comments actually in the body. Misplaced yap. The 50 line comment at the top of the file trying to explain…something, presumably? Yap.

I got tired of writing out dozens of thoughtful and polite review comments a day to tell robots that their code comments weren't up to snuff. Now I just say "yap" and they get what I mean.

"This comment sounds like it's just paraphrasing your prompt, and not actually describing what this part of the code does." becomes "yap". "I think this comment could easily be rephrased to use half as many words while also being more easily understood by future readers." becomes "yap". "This comment is mostly describing why we're not doing it the old way anymore. The thing I'm actually interested in is what we're doing now and why it needs to be done this way." becomes "yap". "This comment should be broken up and the details within it should be moved closer to the actual relevant code, rather than all clumped together like this." becomes "yap".

"yap" becomes shorthand for "Step back and think about what value this comment actually provides. Think about how this comment could be changed to provide more value. What parts of it are actually non-obvious? What parts of it aren't really helpful to future readers? Is this the right spot for this comment? Does this actually even need a comment at all?"

So to answer my earlier question, one way we can optimize reviewing LLM code is by coming up with shorthand to discuss the most common problems that plague LLM code. We can notice the patterns, give them names, and document them. For once I actually hope all of the AI companies do steal this blog post and add it to their training data, because that might mean that my "yap" callouts would become more effective; even more so if others start to use the term and it becomes part of the software engineering lexicon.

‘Not Sure How You Own Canada by Deleting Your Own History’

Daring Fireball
x.com
2026-08-28 12:25:33
Matt Walsh, described by Wikipedia as “an American far-right political commentator and podcast host” (a description that sounds harsh, but I’d say is describing him euphemistically), on Twitter/X (retweeting the official White House account’s announcement of the name change): This will be an unp...
Original Article

This will be an unpopular opinion on the Right but I think this is kind of dumb, even as a troll. Lake Ontario was given that name on maps by European explorers long before the Canadian province of Ontario was named. There are several cities in America called Ontario -- at least one of them predating the Canadian province by like 100 years -- because the word originates with native tribes in North America. It's not a Canadian invention. Canadians never uniquely owned the lake or the name. So in effect all you're doing here is actually giving them credit for a thing that wasn't theirs to begin with. Yeah it's funny when Canadians are upset I guess or whatever, but Lake Ontario, the name itself, is *American* history dating back many centuries. Not sure how you own Canada by deleting your own history.

Just the rumour of a bug is enough to find an exploit these days

Hacker News
anil.recoil.org
2026-08-28 11:58:46
Comments...
Original Article

I released a security fix for OCaml's cohttp 6.3.0 today, fixing a path traversal issue . The patch itself was straightforward and in normal times, the security procedure would have been to fix it privately, inform affected users, and then issue a public advisory. This time around though, I noticed probes in my live webserver logs with the exact bug pattern just minutes after opening the PR to fix the issue .

What's worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we're going to need to change the way we deal with security responses in open source.

1 The rumour of a bug is all new agentic exploit systems need

This particular report arrived privately on a Slack channel via Jane Street last week, and was itself found via Claude Fable. That compresses all timelines considerably...

1.1 The timeline of a modern security report

Before examining the patch in detail, I pointed my own Claude at the affected code to see what else was lurking (asking it to investigate path normalisation issues). Fable frustratingly refused outright due to its security block since I don't have access to Glasswing , but DeepSeek V4 Pro obliged me and independently turned up several related issues. My agent also trivially created an exploit to probe a local live server in under a minute.

After some back and forth with the bug reporter about possible fixes, I quietly opened cohttp#1145 publicly to get more eyes on it. This normally takes a few days and a release within a week or two is reasonable. Within about ten minutes (!) this website was fielding probes for percent-encoded traversal sequences, indicating that automated watchers are keeping an eye on public repositories.

If it took me just a minute to create my own exploit locally, then ten minutes actually seems quite long for an automated attack window to start! A determined attacker who is monitoring package repositories could easily be exploiting them within seconds.

1.2 Security embargoes are no longer effective

Conventional security process involves embargoing the bug, and assumes that secrecy of the details protects users. However, all an agent needs today is a broad direction to search in, and it can do its own research. Fang et al. found that when given a CVE description, their GPT-4 agent exploited 87% of a 15-vulnerability benchmark, and without the description, just 7%.

Two years on, the mean time to exploit is -7 days. In other words, exploitation now precedes the patch! That same metric looks to be around 63 days in 2018-19, and crossed zero in 2024. A quick search finds lots of other similar cases these days... marimo's CVE-2026-39987 went from advisory to first exploitation attempt in 9 hours, even with no public proof-of-concept in existence. Langflow's CVE-2026-33017 took 20 hours. We seem to have crossed the rubicon for automated exploit generation...

The state of LLM exploitation in 2026 (source: Vulncheck)
The state of LLM exploitation in 2026 (source: Vulncheck)

2 Are the bugonomics against OSS maintainers now?

It looks to me like our security processes need to invert somewhat, since just one person searching for the issue class (this could be a mailing list question, an odd commit in an orphan branch, or a context leak) is sufficient to alert someone else's agent and let them get exploit code. This is wild.

A May 2026 paper coined the term " bugonomics " and argues that the bottleneck has moved to "defender remediation throughput". LLMs are merrily generating exploits, but our ability to defend against them isn't necessarily improving as maintainer validation, triage and release rates stay flat. This unfortunately matches the view from my OSS maintainer's chair:

The question is not whether frontier models, open-weight models, or program analysis "win". The question is how to orchestrate them so that scarce validation, prioritization, and release capacity goes toward durable fixes rather than mechanical search and report drafting. A central defender opportunity is technical debt remediation: semantics-grounded, tool-verified, model-assisted workflows that help maintainers find, validate, prioritize, and fix security-relevant defects before they become tomorrow’s exploited vulnerabilities. -- Demystifying the Mythos or Disrupting Bugonomics? , Pesoli et al, 2026

And why are maintainer capabilities staying flat? Well, not having access to frontier agents like Mythos is an obvious one, but also that the engineering of a security patch that doesn't cause any regressions is just fundamentally more work.

3 So what the hell can we do about this?

We clearly need to adapt fairly quickly. I don't think the current manual triage process should disappear, but I have seen an unsustainable surge of activity since Fable came out. We are only just beginning to get a handle on how much of the incoming firehose is machine-generated, but it's obviously a lot.

The big engineering shops (like Google) have been building microupdates directly into their software to ensure that fixes directly reach users as a priority over (e.g.) being fixed in the Chrome code repository. We don't really have that kind of luxury in Docker or OCaml, as we don't control the endpoints our software is used in. Aside from Docker Desktop , downstream distributions quite rightly repackage OSS on their own timescales and terms.

For smaller projects like OCaml, just gaining access to the frontier models is a struggle. The Western models have security guards in place which mean that we can't use the commercially available ones. Project Glasswing has expanded to 150 organisations across 15 countries including critical infrastructure operators, cloud and financial providers, the Linux Foundation, but 'mom and pop' maintainers still don't have access. I was ambivalent back in April whether this is harmful, but it's pretty obvious today that it's turning out pretty terribly.

3.1 Super sekrit private patch development

The first remediation is to develop the fixes somewhere really private out of the reach of AI. GitHub's temporary private forks nominally do this, but it doesn't work hugely well for us.

First, GitHub restricts it "to keep information about vulnerabilities secure, integrations, including CI, cannot access temporary private forks" which immediately disconnects the maintainer from the lifeblood of our CI results. Secondly, only a single PR can merge into the fork, which doesn't work well for issues that often span a few repositories. Reviewers also have to be enrolled one at a time by an admin, and in open-source land reviewers are kind of drive-by depending on who is available (especially in August!).

More broadly though, this plugs the wrong leak. The patch staying secret isn't nearly as important as ensuring the description about the issue reaches exactly the right people with no leakage to attackers.

We don't have robust discussion infrastructure available within OSS as it's spread through various end-to-end encrypted ones (we use Matrix) but also shared infrastructure like Discord or Slack which are extremely leaky. We do need some sort of web-of-trust to distinguish the good guys from the bad in a particular project context.

3.2 No embargoes, just ship continuously

Another thing we could do is to rapidly fix issues in public, ship continuously, and improve the release path via better automation.

Bigger projects like Chrome show this is possible via weekly security updates , two releases per week (!), and dynamic patching that swaps background processes for updated binaries without a restart. This isn't entirely new technology; I looked into integrating live ksplice Linux patching with Xen 15+ years ago. The Linux kernel also ships fixes as soon as possible, deferring at most seven days and exceptionally fourteen.

However, software packaging is our primary obstacle. Chrome has a relatively easy job of shipping one binary artefact, but OSS is often a bunch of libraries that are then embedded in a variety of downstream products. So to do this, we'll need:

  • much better cross-ecosystem package management to discover where disparate libraries are eventually embedded. Ryan Gibb will talk about this at ICFP next week!
  • better scanning tools to help with triage; Andrew Nesbitt has been doing just this with Scrutineer over the past few months. Thomas Gazagnaire and I have been discussing trying this out for our OCaml code, subject to getting access to a reasonable frontier model without security blocks.
  • more robust quality control infra without any false positives that works across the spectrum of supported platforms. While it's relatively easy to run CI on Linux, it's a different story on OpenBSD , FreeBSD , macOS , and some architectures like RISC-V

3.3 Proactive protection at the protocol layer

I've also been having more radical thoughts about how we could slam in protections dynamically to protect endpoints using our libraries. If we just accept that upstream patch fixes will always trail an exploit, then we must put something faster to get ahead.

For example, this cohttp bug fixed today has a simple mitigation: just normalise percent-encoded path separators in the request URL. This rule was implementable the minute the report arrived, and also deployable while the full fix went through review, testing and packaging. Virtual patching is routine on cloud infrastructure these days; Cloudflare deployed managed rules to plug Log4shell back in 2021.

But open source lacks a distribution mechanism for such rules outside of a commercial CDN. That's what the antibotty network idea from our internet ecology paper is trying to plug via more software diversity around the global Internet. How can we have local, fast-propagating defences that hear about a vulnerability and act on their immediate infrastructure within seconds?

4 Some research followups

I think we'll need some combination of all three options in the short-term. A lightweight web-of-trust for OSS contributors (like the venerable Advogato used to be ), as well as more focus on OSS packaging and continuous rollout and triage mechanisms that don't overwhelm our precious human contributors.

I've also posted a couple of new MPhil research ideas for anyone incoming to Cambridge next month and is looking for a project.

And if anyone from Project Glasswing is listening, team OCaml could use access now :-)

(The cohttp fix was not a solo effort. Sapphire Livingstone found and reported the issue, guided the fix and co-developed the remediation; Michael Dales , Török Edwin and Patrick Ferris reviewed the patch; Hannes Mehnert coordinated the advisory; and Thomas Gazagnaire has been thinking through the wider triage problem. Thank you all! The bugonomics may be against us, but we will crest this hump.)

Trump Goes After Anonymous Email Provider in Italy. The Real Target Is Free Speech in the U.S.

Intercept
theintercept.com
2026-08-28 11:51:40
Trump designated an Italian web-hosting provider as a foreign “terror” group. It could take antifascist sites in the U.S. offline. The post Trump Goes After Anonymous Email Provider in Italy. The Real Target Is Free Speech in the U.S. appeared first on The Intercept....
Original Article

In the latest escalation of the Trump administration’s war on the left, the U.S. government’s designation of a popular antifascist webhosting provider as a terror group could shutter a swath of radical websites in the U.S.

Secretary of State Marco Rubio and Treasury Secretary Scott Bessent announced Wednesday that they were targeting the Italy-based A/I Collective with terror sanctions . Federal law gives the Treasury Department broad discretion to apply the terror label to foreign groups.

A wide array of anarchist, antifascist, and far-left groups in the U.S. and abroad use the privacy-minded collective’s offerings, including an anonymous email service and its popular noblogs.org blogging platform.

The practice of designating an internet platform and service provider as a terror group — rather than those pursuing violence themselves — has “huge” implications for the future free speech on the internet, warned Jillian York, the director of international freedom of expression at the Electronic Frontier Foundation.

“They are going after the messenger,” York said. “I don’t think that the members of the group would necessarily condone the actions of the people that they hosted. What they do condone is the freedom to host, the ability to be anonymous, the ability to be private.”

“Protesting is not terrorism.”

The A/I Collective told The Intercept that it is exploring its legal options to fight the sanctions, which block U.S. citizens and companies from providing the group with financial support.

In an unsigned statement, the group said that it denies the U.S. government’s allegations.

“Antifascism and anticapitalism are not terrorism,” the group said. “Protesting is not terrorism. And everyone has the right to speak out and to struggle for humanity.”

The U.S. government’s move could have ripple effects far beyond Italy.

Groups using the A/I Collective’s services range from an anarchist radio show in Asheville, North Carolina; to a blog documenting attacks on anti-abortion “crisis pregnancy centers” under the Jane’s Revenge moniker; to the Seattle Anarchist Bookfair. The bookfair warned Wednesday that its website “will most likely go down soon because of US sanctions on Noblogs.”

The State and Treasury Departments justified the designation by alleging that the A/I Collective, also known as Autistici/Inventati, has provided services to foreign terror groups, including anarchists who have launched attacks on railroads and pipelines in Europe, and by domestic left-wing groups that have employed violence.

“A/I’s cadre of radical hackers and tech developers provide a full spectrum of services — including encrypted chats and email, web hosting, secure video conferencing and streaming, anonymity shields, and a suite of other technological tools — to Marxist, anarchist, and other left-wing extremist groups in the United States, Europe, and elsewhere,” a State Department spokesperson said in a press release. “These tools are specifically designed to support the operations of far-left terrorist networks.”

It is unclear how many groups in the U.S. could be forced offline, or to shift their providers, because of the terror designation. The A/I Collective said it could not provide an estimate of U.S-based groups that it hosts, because it does not ask its users for any private or personal information.

Nor was it immediately clear whether simply hosting a site using the collective’s services would be illegal if no money changes hands . Still, the collective says that it relies heavily on voluntary, suggested donations, and many U.S.-based groups appear to be scrambling for alternative hosting providers.

The A/I Collective was sanctioned under the Treasury Department’s authority to label groups specially designated global terrorists. U.S. citizens convicted of violating those sanctions can face stiff penalties of up to 20 years in prison.

If U.S. groups continue to use the collective’s services, the U.S. government could use that affiliation against them, said Shayana Kadidal, an attorney with the Center for Constitutional Rights. The Treasury Department can even label U.S.-based groups as specially designated global terrorists, although they have more standing to challenge that designation in court.

The designation of the A/I Collective as a foreign terror group is the next step in a sequence that began with Trump’s designation of antifa as a “domestic terror organization” last September, said Mark Bray , a historian at Rutgers University who wrote a book about antifascism.

Where the Trump administration goes next is the “million-dollar question,” Bray said.

“It seems to be they’re playing a bit of a long game,” he said, “where they try to establish the existence of a supposed violent, left-wing terror network — which they have had trouble doing, but they have tried. But then, of course the way they make that affect the left more broadly is to criminalize those who they claim are aligned with it.”

EasyEffects can improve laptop speaker sound quality

Hacker News
www.osnews.com
2026-08-28 11:23:10
Comments...
Original Article

Home > Multimedia, AV > EasyEffects should be part of every Linux distribution and desktop environment to massively improve laptop speaker sound quality

Virtually all laptop speakers suck. It’s the one area where even really expensive laptops tend to fall on their ass, leaving users with a tinny, harsh, and hollow sound experience. While you can’t exactly overcome physics – laptop speakers are necessarily small and thus just cannot ever sound as good as proper speakers – there’s a lot you can do with proper tuning and software magic. If you’re a desktop Linux user, you actually already possess all the plumbing needed to fix your audio; it’s just not exposed to you in any way. Luckily, an application called EasyEffects allows you to actually make use of desktop Linux’ advanced audio features to massively improve the sound quality of your laptop’s speakers.


The OSNews 2026 Fundraiser


➡️ Donate through Ko-Fi ➡️ Donate through SEPA transfer* ➡️ Buy merch from our store ➡️ Why a fundraiser?

€5000 incentive: Make me use Windows 11 for a month ( the results were not great )
> €10000: Video tour of my office and my computers/devices collection <
€15000: Buy a Mac and use macOS for a month (and review it)
€20000: I get an OSNews tattoo

* Name : Thom Holwerda – IBAN : SE08 8000 0820 1684 4657 8414 – BIC : SWEDSESS


EasyEffects’ own description on its GitHub page doesn’t really explain what it does or what it’s capable of, so here’s the description from Wikipedia instead.

EasyEffects uses PipeWire to process incoming and outgoing audio streams independently and can apply various sound effects in the form of plug-ins made by different developer teams such as Calf Studio Gear, MDA.LV2 and GStreamer. All plugins have their own presets and can be applicable inside the suite rather than having to use a different mixer or executing a script from the command line.

Available output effects are limiter, auto volume, compressor of dynamic range, filter, 30 bands parametric equalizer, bass enhancer, exciter, reverbation, crossfeed, delay, maximizer and spectrum analyzer. Available input effects are WebRTC, limiter, compressor, filter, equalizer, de-esser, reverbation, pitch shift and spectrum analyzer.

↫ EasEffects’ Wikipedia page

None of this matters, and you can forget everything from these two paragraphs.

What matters is that using EasyEffects, you can tune the audio coming out of your speakers to make them sound a lot better. The few laptops on the market that do have decent audio – MacBooks, some Dell XPS laptops, and surely a few more – aren’t magically defying physics. While they probably do have objectively higher-quality speakers, the main difference between those laptops and laptops with crappy-sounding speakers is that the former come with built-in tuning from the factory to make them sound much better than they would without any software trickery.

If you know your way around audio, you can very much use EasyEffects and tune your laptop speakers from scratch to massively improve how they sound. However, that requires time, experience, knowledge, and expertise that most people lack, including myself. Lucky for us, though, there are countless downloadable presets out there for EasyEffects designed specifically to make laptops sound better.

In an ideal world, you’d pick a preset created specifically for your laptop make and model, but odds are you won’t find one, so for most laptops you’ll have to settle for a generic preset that tries to do its best. I’ve long settled on the Advanced Auto Gain.json preset from JackHack96 , which greatly improves the audio performance on any laptops I’ve tried it on, but of course, there’s countless other presets for you to try to see if there’s anything that suits your particular laptop and ears better.

Getting all of this up and running is really easy. EasyEffects is most likely packaged by your Linux distribution, and the latest version is always available as a Flatpak from Flathub. Download the preset(s) you want to try, copy them either to ~/.config/easyeffects (if you use your distribution’s package) or to ~/.var/app/com.github.wwmm.easyeffects/data/easyeffects/output/ (if you use the Flatpak version). They’ll show up right away in the Presets tab in EasyEffects, ready to be turned on and off whenever you want, making it very easy to compare and contrast to find the one you like best. EasyEffects can live in your system tray giving you easy access to your presets without having to open the main window, and it can be set to start automatically at boot. EasyEffects can also be turned on and off on the fly.

There’s obvious downsides to all of this, too, of course. First, since you’re most likely going to be using a generic preset not specifically crafted for your laptop, there’s no guarantee the results will be positive for you. Second, not every preset is ideal for every type of audio. Most of my audio consists of YouTube videos with mostly speech; if you listen mostly to music, different presets may yield better results. Third, audio quality is deeply subjective, and what sounds good to my ears may sound like total garbage to yours. Fourth, EasyEffects does take up a tiny fraction of CPU power (I’m talking 0.1-0.2% according to KDE’s System Monitor), but I have never seen it have any noticeable performance impact on anything.

Even the generic preset I use makes such a massive difference for me on every laptop I’ve ever tried it on, that I’ve become convinced EasyEffects and a few of the generic presets should be installed by default by any desktop-oriented Linux distribution. On top of that, Linux laptops OEMs like System76, Nova Custom, Star Labs, and so on, should really take the time to create proper presets for their laptops to improve their sound quality out of the box. I feel like if you’re already designing and selling laptops, you probably also have the skills and means to create a decent preset.

In fact, I’d take it a step further and urge desktop environments like KDE and GNOME to properly integrate EasyEffects into their sound settings. They shouldn’t include the entire application and its user interface, but should make it so that you can configure and manage presets right from the sound settings panels, and switch between presets from their volume applets (as well as turn it off entirely, of course). This would leave the full EasyEffects application for people who need more control, manual tuning, and more advanced features.

There’s absolutely no reason why speakers on Linux laptops should sound tinny, harsh, and hollow. The Linux desktop has all the technologies and features built right in to make speakers sound much better than they do without any tuning, and yet, very few people seem to actually be aware of this. This needs to change, and I think it’s up to distributions, desktop environments, and Linux OEMs to make this happen.

GLM-5.3 is now open-weight

Hacker News
huggingface.co
2026-08-28 11:20:13
Comments...
Original Article

GLM-5.3 uses the same base model as GLM-5.2 — every gain comes from post-training. Compared with GLM-5.2, it is much better at complex coding and long-horizon tasks:

  • Stronger Coding: GLM-5.3 is the most capable open-weights model for coding, with a 50% improvement over GLM-5.2 on our in-house Z.ai Code Bench. It also achieve open-source SOTA on public benchmarks including Terminal Bench 3.0 and Agents' Last Exam.
  • Emergent Cyber Capability: As we scaled post-training, cyber capability developed faster than we expected. GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain, where it more than doubles GLM-5.2 on exploitation benchmarks.

bench_53

Benchmark

Benchmark GLM-5.3 GLM-5.2 Kimi K3 DeepSeek-V4 Pro-0813 Qwen3.8-Max Opus 4.8 Fable 5 (w/ fallback) GPT-5.6 Sol
Terminal Bench 2.1 88.2 81.0 88.3 87.9 86.6 85.0 88.0 88.8
Terminal Bench 3.0 28.3 4.6 17.4 21.1 33.7 34.6
DeepSWE (v1.1) 66.9 46.2 67.5 62.7 56.6 58.0 69.7 72.7
NL2Repo 58.0 48.9 58.0 61.1 55.9 69.7
ProgramBench (Almost Solved) 19.0 9.5 17.5 10.5 15.5 33.0 23.0
FrontierSWE 78.1 67.5 66.5 88.2
SWE-Marathon (v1.1) 42.5 19.4 48.1 48.8 33.1 42.5
PostTrainBench 39.8 31.7 32.0 32.9 41.8 36.2
CyberGym 84.5 77.2 80.0 83.3 78.5 78.1 83.8 83.6
ExploitGym (2h / 6h) 105 / 130 29 / 39 36 / 70 14 / 26 80 / 120 181 / 247 216 / 293
ExploitBench 54.4 24.4 32.2 28.8 40.0 78.0 76.5
Toolathlon Verified 73.0 59.9 76.5 74.1 72.5 76.2 74.7 74.9
AutomationBench (v1.0.6) 48.2 26.2 46.7 43.2 39.8 41.0 46.2 45.8
Agents' Last Exam (ALE-CLI) 28.5 23.8 27.6 25.7 27.0 25.7 23.8 28.6
HLE w/ Tools 62.5 54.7 59.8 60.0 56.2 57.9 63.9 64.5
GDPval-AA v2 1769 1508 1682 1590 1739 1588 1743 1730

Serve GLM-5.3 Locally

GLM-5.3 supports deployment with the following frameworks. Feel free to try them out:

Note

  • GLM-5.3 supports controlling the thinking budget through the reasoning_effort parameter, which accepts three levels: low , high , and max . It defaults to max if not passed (or if set to any other value). To use low or high , pass them explicitly. For benchmark and leaderboard reproduction, keep the default max .
  • In the chat template for GLM-5.3, clear_thinking defaults to false if not passed. For chat scenarios, explicitly pass clear_thinking=true .

Footnotes

  • HLE w/ tools : We use sampling parameters of temperature=1.0 and top_p=0.95 for evaluation, with a maximum generation length of 163,840 tokens. The evaluation is conducted with a maximum context length of 300,000 tokens, using a context management strategy. We use GPT-5.6-luna (medium) as the judge model.
  • NL2Repo : We evaluated NL2Repo with temperature=1.0 , top_p=1.0 , and max_new_tokens=64k under 1M context. To prevent hacking, we use rule-based and a LLM-based judgement to prevent malicious behaviors (e.g., unauthorized pip or curl operations).
  • DeepSWE : We run DeepSWE using the mini-swe-agent harness with temperature=0.95 , top_p=1.0 , timeout=6h and 400K context.
  • Terminal-Bench 2.1 : We evaluate in Claude Code 2.1.207 with temperature=1.0 , top_p=1 , max_new_tokens=65536 with 6h timeout.
  • Terminal-Bench 3.0 : We evaluate Terminal-Bench-3 tasks with the Claude Code 2.1.207 harness (reasoning effort=max, 400K context, and 128K maximum output), reporting avg@3 over three rollouts per task. Each rollout runs in an isolated container built from the task's official image, and is capped at 600 agent turns with a 10-hour timeout. Tool Search is disabled, and the artifacts each agent produces are scored by the task's official separate verifier.
  • Agent's Last Exam (CLI) : We evaluate ALE using the official evaluation protocol with the Claude Code harness (reasoning effort=max, 1M context, and 64K maximum output). Each of the 105 tasks runs in an isolated Docker container using the resources declared in its Task Card. The default timeout is 4 hours, with task-specific limits taking precedence (up to 8 hours). Tool Search is disabled, and results are scored by the official ALE evaluators.
  • Toolathlon Verified : We obtain all results via the official evaluation service and report pass@1 averaged over 3 independent runs.
  • AutomationBench : We evaluate on AutomationBench v1.0.6 , incorporating the fix for the null -type handling issue introduced in PR #13 .
  • GDPval-AA v2 : Models are evaluated by Artificial Analysis.
  • CyberGym : We evaluate GLM-5.3 in Claude Code 2.1.207 (max reasoning effort, no web tools with temperature=1.0 , top_p=1.0 , max_new_tokens=128000 ). All evaluations are under unlimited timeout per task and results are single-run Pass@1 over 1,507 tasks. To simulate real-world usage scenarios, we place the agent inside the task container. We also remove all Git-related information and apply a domain whitelist (allowing only essential domains such as pypi.org and deb.debian.org for basic tool installation) to prevent the agent from cheating.
  • ExploitGym : We evaluate GLM-5.3, Kimi-K3 and Qwen3.8 Max in Claude Code 2.1.207 (max reasoning effort, no web tools with temperature=1.0 , top_p=1.0 , max_new_tokens=128000 ). The reported results are single-run Pass@1 on 869 tasks under two timeout budgets: 2 hours and 6 hours, which are calculated as the API inference time rescaled by per-model tokens per second rate (per-model TPS sourced from Artificial Analysis; that is, we rescale GLM-5.3's results by 115 TPS, Kimi K3's results by 40 TPS and Qwen3.8 Max's results by 47 TPS), plus the non-API overhead. We also apply a domain whitelist (allowing only essential domains such as pypi.org and deb.debian.org for basic tool installation) to prevent the agent from cheating.
  • ExploitBench : We evaluate GLM-5.3 in Claude Code 2.1.207 (max reasoning effort, no web tools with temperature=1.0 , top_p=1.0 , max_new_tokens=128000 ). Following the official evaluation settings, we limit the maximum number of interaction rounds between the agent and the environment to 300, and compute the average coverage score over all 41 tasks across 3 revisions. The coverage result of a task is determined by taking the union of capabilities achieved across all revisions, and the average score is obtained by averaging the results. We also apply a domain whitelist (allowing only essential domains such as pypi.org and deb.debian.org for basic tool installation) to prevent the agent from cheating.
  • FrontierSWE : The evaluation was conducted by Proximal with 1M context length, max effort level, and 128K maximum output tokens. Dominance score reported as of 2026/08/14.
  • PostTrainBench : We evaluate GLM-5.3 using Claude Code 2.1.207 with max effort level, temperature = 1.0 , top_p = 1.0 , max_new_tokens = 128000 , and a 1M-token context window. We report the weighted average over 3 runs. Runs that fail to produce a score fall back to the official zero-shot base-model baseline score. For checks intended to prevent the use of third-party APIs, we removed the original pattern-matching-based checks, as they produced false positives when a local vLLM endpoint was accessed through the OpenAI SDK. Instead, we use an LLM agent to inspect solutions for external API usage.
  • SWE-Marathon : We evaluate GLM-5.3 using Claude Code 2.1.207 with maximum effort level, temperature = 1.0 , top_p = 0.95 , max_new_tokens = 128000 , and a 1M-token context window. For strip-clone , the original anti-cheat checks used overly broad import detection that could reject valid implementations. We removed the affected checks and performed llm-based inspection instead to avoid false positives. For parameter-golf and trimul-cuda , changes to the NVIDIA wheels caused the Docker image builds to fail, so we added --extra-index-url https://pypi.org/simple to restore successful builds.

Citation

If you find GLM-5.3 useful in your research, please cite our technical report:

@misc{glm5team2026glm5vibecodingagentic,
      title={GLM-5: from Vibe Coding to Agentic Engineering},
      author={GLM-5-Team and : and Aohan Zeng and Xin Lv and Zhenyu Hou and Zhengxiao Du and Qinkai Zheng and Bin Chen and Da Yin and Chendi Ge and Chenghua Huang and Chengxing Xie and Chenzheng Zhu and Congfeng Yin and Cunxiang Wang and Gengzheng Pan and Hao Zeng and Haoke Zhang and Haoran Wang and Huilong Chen and Jiajie Zhang and Jian Jiao and Jiaqi Guo and Jingsen Wang and Jingzhao Du and Jinzhu Wu and Kedong Wang and Lei Li and Lin Fan and Lucen Zhong and Mingdao Liu and Mingming Zhao and Pengfan Du and Qian Dong and Rui Lu and Shuang-Li and Shulin Cao and Song Liu and Ting Jiang and Xiaodong Chen and Xiaohan Zhang and Xuancheng Huang and Xuezhen Dong and Yabo Xu and Yao Wei and Yifan An and Yilin Niu and Yitong Zhu and Yuanhao Wen and Yukuo Cen and Yushi Bai and Zhongpei Qiao and Zihan Wang and Zikang Wang and Zilin Zhu and Ziqiang Liu and Zixuan Li and Bojie Wang and Bosi Wen and Can Huang and Changpeng Cai and Chao Yu and Chen Li and Chengwei Hu and Chenhui Zhang and Dan Zhang and Daoyan Lin and Dayong Yang and Di Wang and Ding Ai and Erle Zhu and Fangzhou Yi and Feiyu Chen and Guohong Wen and Hailong Sun and Haisha Zhao and Haiyi Hu and Hanchen Zhang and Hanrui Liu and Hanyu Zhang and Hao Peng and Hao Tai and Haobo Zhang and He Liu and Hongwei Wang and Hongxi Yan and Hongyu Ge and Huan Liu and Huanpeng Chu and Jia'ni Zhao and Jiachen Wang and Jiajing Zhao and Jiamin Ren and Jiapeng Wang and Jiaxin Zhang and Jiayi Gui and Jiayue Zhao and Jijie Li and Jing An and Jing Li and Jingwei Yuan and Jinhua Du and Jinxin Liu and Junkai Zhi and Junwen Duan and Kaiyue Zhou and Kangjian Wei and Ke Wang and Keyun Luo and Laiqiang Zhang and Leigang Sha and Liang Xu and Lindong Wu and Lintao Ding and Lu Chen and Minghao Li and Nianyi Lin and Pan Ta and Qiang Zou and Rongjun Song and Ruiqi Yang and Shangqing Tu and Shangtong Yang and Shaoxiang Wu and Shengyan Zhang and Shijie Li and Shuang Li and Shuyi Fan and Wei Qin and Wei Tian and Weining Zhang and Wenbo Yu and Wenjie Liang and Xiang Kuang and Xiangmeng Cheng and Xiangyang Li and Xiaoquan Yan and Xiaowei Hu and Xiaoying Ling and Xing Fan and Xingye Xia and Xinyuan Zhang and Xinze Zhang and Xirui Pan and Xu Zou and Xunkai Zhang and Yadi Liu and Yandong Wu and Yanfu Li and Yidong Wang and Yifan Zhu and Yijun Tan and Yilin Zhou and Yiming Pan and Ying Zhang and Yinpei Su and Yipeng Geng and Yong Yan and Yonglin Tan and Yuean Bi and Yuhan Shen and Yuhao Yang and Yujiang Li and Yunan Liu and Yunqing Wang and Yuntao Li and Yurong Wu and Yutao Zhang and Yuxi Duan and Yuxuan Zhang and Zezhen Liu and Zhengtao Jiang and Zhenhe Yan and Zheyu Zhang and Zhixiang Wei and Zhuo Chen and Zhuoer Feng and Zijun Yao and Ziwei Chai and Ziyuan Wang and Zuzhou Zhang and Bin Xu and Minlie Huang and Hongning Wang and Juanzi Li and Yuxiao Dong and Jie Tang},
      year={2026},
      eprint={2602.15763},
      archivePrefix={arXiv},
      primaryClass={cs.LG},
      url={https://arxiv.org/abs/2602.15763},
}
Downloads last month
8,804

Model tree for zai-org/GLM-5.3

Spaces using zai-org/GLM-5.3 2

Collection including zai-org/GLM-5.3

Paper for zai-org/GLM-5.3

Evaluation results

How Did the 'Mangionistas' Get Approved for NYC Press Cards? We Got Their Applications

hellgate
hellgatenyc.com
2026-08-28 11:18:20
Each pro-Luigi Mangione activist/content creator was approved by the Mayor's Office of Media and Entertainment within one day. The clips they submitted were somewhat unconventional....
Original Article

With Luigi Mangione's guilty plea and the conclusion of his federal murder trial, it's time to put to rest another controversy: How did three pro-Mangione influencers, also known as the " Mangionistas ," get their official New York City press passes?

In May, a New York Daily News reporter interviewed Abril Rios, Lena Weissbrot, and Ashley Rojas outside a Manhattan courthouse as they attended Mangione's trial for the murder of UnitedHealthcare CEO Brian Thompson. In a video that went somewhat viral, the Mangionistas said inflammatory things like "Fuck Brian Thompson. I don't give a flying fuck he died," and that his kids are "better off without him"—all while wearing white and blue New York City press badges around their necks, which had local outlets up in arms and wondering how they got them. A spokesperson for the mayor said the incident prompted a review of the City's press pass system.

As Hell Gate wrote at the time, the whole discourse was a little silly , and gatekeeping who counts as real press in this Media Moment is genuinely pretty challenging. But out of curiosity, we went ahead and made a Freedom of Information Law request to the Mayor's Office of Media and Entertainment to have a look at the Mangionistas' press pass applications.

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

GUIs should be fully keyboard-driven

Hacker News
ckardaris.com
2026-08-28 11:17:09
Comments...
Original Article

This post has made it to the Hacker News front page. See the discussion .


Last week I came across a post on Hacker News that encouraged application developers to stop making terminal user interfaces 1 (a.k.a. TUIs) and instead focus on graphical user interfaces (a.k.a. GUIs). The post reached the HN front page and sparked a lively debate in the comments section.

I think there is merit in both sides of the debate. On one hand, I understand the GUI-positive arguments of the post author. In theory, the capabilities of GUI application frameworks are a superset of the capabilities of their TUI counterparts, so they should be preferred. On the other hand, as a heavy terminal user , I also greatly appreciate all TUIs that allow me to “stay” in the terminal and fulfill all my needs.

But I want to oppose a recurring argument in favor of TUIs that in my opinion does not have a solid foundation 2 . To paraphrase various commenters:

TUIs should be preferred because they are keyboard-driven.

While it’s true that if you randomly pick a GUI and a TUI application, the latter is more probable to be fully keyboard-driven, this does not tip the scale in favor of developing TUIs over GUIs 3 . What it does is highlight the inadequacies of keyboard navigation in many GUI applications.

There is nothing preventing a GUI from being fully keyboard-driven 4 just like — or even better than — a TUI. In fact, many GUI framework application guidelines explicitly encourage GUI application developers to provide support for keyboard-driven navigation that covers the whole functionality of the application.

For example, the GNOME Human Interface Guidelines state that just as it should be possible to perform every action with a pointing device, every action should also be possible with the keyboard and that it should be possible to move around and interact with every part of your user interface using the keyboard .

This resonates with me as a user. Being able to intuitively — and predictably — navigate around a GUI application with only my keyboard gives me more incentive to choose it compared to its alternatives.

Knowing that, and when wearing my developer hat, I have to make sure that my applications are keyboard-friendly. For my first ever GUI application, Klisi , I invested some time to implement keyboard shortcuts targeting the whole range of available actions.

Keyboard navigation is not that hard to achieve in most cases and results in an overall better user experience. It is not a matter of feasibility, but a matter of will on the application developer’s part.

The takeaway is simple. Do not compromise on the user experience you provide with your application. Strive to make it as intuitive as possible. To that end, enabling full keyboard navigation should not be ignored.

Behind the Blog: The Complete Idiot's Guide to Flamin' Hot Slop

403 Media
www.404media.co
2026-08-28 11:16:39
This week, we discuss cool old books, new toys for ICE, and a boardwalk slop invasion....
Original Article

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss cool old books, new toys for ICE, and Flamin' Hot Slop.

SAM: On the podcast last week , we had what I thought was a pretty nuanced and interesting conversation about the "rare books" discourse (although I'm biased; listen and let me know). I mentioned this in the episode but it all makes me think about all the rare books I've bought over the years — these are rare by any definition of the word in that they're usually limited or out of print and I got them through used book sellers online where only one copy was often available.

When my book launched a few years ago, I started a very short-lived Substack blog to write about some of the behind the scenes stuff happening around publication. One of those posts is a bibliography, including a lot of the books I sourced and references for my own.

This post is for paid members only

Become a paid member for unlimited ad-free access to articles, bonus podcast content, and more.

Subscribe

Sign up for free access to this post

Free members get access to posts like this one along with an email round-up of our week's stories.

Subscribe

Already have an account? Sign in

Labour rejects Zack Polanski’s call to ‘slam brakes’ on building AI datacentres

Guardian
www.theguardian.com
2026-08-28 11:11:46
Government says Green leader’s proposed moratorium on ‘energy-guzzling’ AI projects would be disaster for economy Labour has rejected calls to pause construction of major AI infrastructure in Britain after the Green party leader, Zack Polanski, said it was time to “slam the brakes on these energy-gu...
Original Article

Labour has rejected calls to pause construction of major AI infrastructure in Britain after the Green party leader, Zack Polanski, said it was time to “slam the brakes on these energy-guzzling, water-guzzling datacentres”.

The government hit back at the opposition party’s proposal of a “moratorium other than [for] local-scale datacentres for the local community”, saying it “would be a disaster for jobs and national security”.

The Greens’ call for a pause comes amid one of the UK’s worst droughts in years and predictions that datacentres’ electricity use, now standing at about 2.5% of the UK’s supply, will rise fourfold by 2030.

Datacentres contain the processing chips that power billions of AI prompts every day and Labour has designated them as critical national infrastructure, a decision Polanski called “outrageous”. “To most people critical infrastructure means hospitals, water, electricity,” he said. “It doesn’t mean artificial intelligence.”

He added: “Right now the government is putting our communities, our water security and our climate ambitions second to the demands of tech giants.”

A spokesperson for the government said: “A pause on building new datacentres would simply send investment and good jobs abroad, while leaving Britain dependent on overseas computing for the processing of sensitive health and defence data.”

They said critical national infrastructure status did not give datacentres priority access to water or electricity, nor did it automatically put them ahead of households during shortages, and that in England datacentres’ water usage represented less than 1% of non-household water consumption.

The row comes amid increasing signs that datacentre policy, already a major political issue in the US midterm elections, is rising up the agenda in Britain. In energy- and water-rich Scotland, the Scottish National party government appears to be “ inching towards a moratorium ” amid voter pressure, while local disputes have erupted from Devon to Buckinghamshire and Cardiff to Fife where residents have raised fears about noise, heat, traffic and the visual impact of datacentres affecting house prices.

The AI minister, Kanishka Narayan, has linked the need for more AI datacentres to strong defence and this month claimed the British public “doesn’t just want foreign billionaires to own things that matter to our lives. If we’re being true to those British values, it is impossible to achieve that without building a sovereign level of datacentre capacity.”

skip past newsletter promotion

The government spokesperson said its refusal to pause development “does not mean a blank cheque for big tech or that every datacentre should be approved”. They said developers should “prioritise clean power, use water responsibly, create British jobs and supply chains, and provide investment to the communities in which they are built”.

The tech equity campaign group Foxglove warned that with some datacentre developers seeking to mitigate long waits to connect to the energy grid by planning their own gas-fired power stations, there was a risk of a “deeply alarming backward step on climate action”.

Rosa Curling, its co-executive director, said: “It’s good to hear that the government thinks there shouldn’t be a ‘blank cheque’ for big tech’s datacentres. But without urgent action, that’s exactly what will happen – the public and the planet will be left to foot the bill for the environmental and social costs of these energy-hungry giants.”

From the DF Archive: ‘Golfo Del Gringo Loco’

Daring Fireball
daringfireball.net
2026-08-28 11:00:39
Yours truly back in February 2025: The motivation behind the name change is simple as well. Trump didn’t change the US’s officially recognized name of, say, the Atlantic Ocean or the continent of Africa. He just as easily could, but he won’t. I’m starting to worry how well that’s going to hold...
Original Article

You saw the news last week, I’m sure, that both of the major mapping-app providers, Google and Apple, have updated their maps to refer to the Gulf of Mexico as the “Gulf of America” . Microsoft’s Bing Maps, which I would describe as a minor provider, has made the change too. 1 It’s all actually quite a bit more complicated than “they renamed the Gulf of Mexico”, but bear with me for now.

You’ve also seen, I’m equally sure, a lot of people angry at Google and Apple for going along with this. That anger is — to some degree — misplaced. I get where the anger comes from, but it’s still misplaced. My initial take, right in the midst of Trump’s inauguration speech on January 20, was that if he went through with it, Apple and Google and everyone else who publishes maps should just ignore it. Trump, obviously, did go through with it: the United States Geological Survey, an agency within the Department of the Interior, which is within the executive branch and thus under the president’s purview, officially made the change on February 7 . Now that it’s official US government policy, “just ignore it” really isn’t feasible. If that’s still your stance, I implore you to consider at least a bit more nuance.

But let’s first stipulate up front that there are multiple far more important and urgent issues facing the United States and the world, just four short weeks into the Trump 2.0 administration. Off the top of my head: Ukraine, Gaza, tariffs, DOGE, the rule of law . Whether you approve or disapprove of Trump’s actions on any or all of those issues, there should be no question that all of them are important and consequential. The name we see on maps for a body of water, not as much. But it’s the smallness, the relative unimportance, the spiteful pettiness of the renaming in the first place — down to the fact that until Trump’s executive action, there was no controversy, zero , none , nada , anywhere in the world, amongst any group of people, regarding the name of the Gulf of Mexico — that makes it interesting to examine in detail how Google and Apple have chosen to deal with it. It’s only because this particular issue is so spectacularly piddling that we can consider it in full.

The motivation behind the name change is simple as well. Trump didn’t change the US’s officially recognized name of, say, the Atlantic Ocean or the continent of Africa. He just as easily could, but he won’t. And it’s not like “Gulf of Mexico” was on a list of “debatable or controversial names” until he created this controversy out of thin air. It’s just the one name on the globe that a president of the United States can change to stick it to Mexico, a country Donald Trump has objectively racist feelings toward . Trump never campaigned on building a wall at our northern border with Canada, nor has he (yet?) attempted to rename Lake Ontario. It’s about Mexico, and asserting power by fiat. Trump has a lifelong history of putting his name on buildings he doesn’t own . He’d rather have his name emblazoned on a building he doesn’t own than own a building that doesn’t bear his name. To Trump, the name on the sign is more important than the deed. So too, now, with the name on a map. The Gulf of Mexico is an international body of water that belongs to no nation, but declaring this new name implies that it heretofore belonged to Mexico, and now belongs to us, which is to say belongs to him, our unquestioned dear leader. That Trump took it from Mexico, without firing a shot — when in fact all he did was order a string to be changed in a government database. Shakespeare would have us believe that a sea by any other name would taste as salty. Trump doesn’t read Shakespeare.

How Google and Apple Are Labelling the Gulf, Globally

The first important thing to know is that Google Maps and Apple Maps are not singular global atlases. They both show different names (and in rare cases, different geographies) in different regions around the world. They each are more like a collection of regional atlases. In constrast, there’s only one Oxford English Dictionary . If the OED changes a word’s definition, or adds a new word, those changes appear to everyone in the world. My OED is your OED, no matter where you and I live or currently find ourselves on the globe. Google and Apple Maps aren’t like that. It’s better to think of them as services that provide region-by-region maps.

Google, to their credit, has a blog post describing and illustrating exactly what users around the world now see in Google Maps :

In the U.S., the Geographic Names Information System (GNIS) has officially updated “Gulf of Mexico” to “Gulf of America.” As we announced two weeks ago and consistent with our longstanding practices, we’ve begun rolling out changes to reflect this update. People using Maps in the U.S. will see “Gulf of America,” and people in Mexico will see “Gulf of Mexico.” Everyone else will see both names.

As their illustration shows , “both names” means putting “Gulf of America” in parentheses for users who are anywhere else in the world other than the U.S. or Mexico: “Gulf of Mexico (Gulf of America)”.

Apple’s approach has been more Apple-like, which is to say without comment. They made no public comment before changing the name in Apple Maps, and they have made no public comment since. (I’ve asked Apple PR for comment, but gotten none.) I’d appreciate a statement, like Google’s, stating what users around the world should expect to see. But I also understand their desire to say as little as possible. In a sense, the labels on Apple Maps speak for themselves, and are the only thing that actually matters. I also appreciate, that by never declaring a policy on the matter, Apple can change its map labels without rescinding or amending a policy.

So without a statement from Apple describing how the Gulf is labelled around the world, I did what I could: I asked my followers on Mastodon who are outside the US what they saw as the Gulf’s name , and to include screenshots if possible. That was on Friday, 14 February, after Apple Maps began showing “Gulf of America” in place of “Gulf of Mexico” to users here in the US. The response was overwhelming, with replies from people in over two dozen countries from around the world. 2 And at the time, their replies suggested that Apple was taking a subtly but intriguingly different approach from Google. To wit, while everyone in the US saw “Gulf of America” (with no mention of the established name), everyone everywhere else in the world still saw “Gulf of Mexico” (or their language’s translation of that name), with no mention, in parentheses or otherwise, of the new name now recognized by the United States.

I hoped that that was Apple’s plan, which would have been quietly subversive in isolating the United States as the only country in the world to even see the name “Gulf of America”. But I feared that Apple was simply slower than Google, that changes had been applied for users in the US first, but changes for the rest of the world simply hadn’t propagated. My fears were warranted.

Late in the evening (US Eastern Time) on Saturday, 15 February, new responses to my entreaty on Mastodon began showing labels in Apple Maps that matched Google’s:

  • In the US: “Gulf of America”.
  • In Mexico: “Gulf of Mexico”.
  • Everywhere else: “Gulf of Mexico (Gulf of America)”.

I believe that the determining factor for what label you see, at least for Apple Maps, is unrelated to your physical location as determined by GPS or your IP address, but simply the region setting of your OS. On both MacOS and iOS, that’s in Settings → General → Language & Region → Region. This makes sense — you can use Apple Maps (and Google Maps) with Location Services turned off. You can play with this setting on your device to see what users around the world see in Maps without leaving your home, and without changing your device’s language. Thus, if you’re an American with your device set to the “United States” region, if you travel outside the US without changing your device settings, you’ll still see the US-specific new name for the gulf: “Gulf of America”, with its historic and world-recognized name — dare I say, its unambiguously correct name — not even referenced in parentheses.

The Year of the Depend Adult Undergarment

This whole thing, needless to say, sucks. It’s profoundly stupid, and the aspects that aren’t stupid are jingoistic. But the notion that Google or Apple might reasonably just ignore this and tell Trump (and the entire Republican Party, and their supporters) to go pound sand is facile. I’m not saying they couldn’t do it. Of course they could . That’s like saying Trump can’t just declare a new name for an international body of water with a heretofore uncontroversial 400-year-old name.

But it wouldn’t be reasonable. It is reasonable for Google and Apple Maps to defer to, or at least acknowledge, the officially recognized names for each region in which they’re available. It’s not Google’s or Apple’s place to determine and adjudicate the official names on a map; their job is to recognize and display those names. In theory Google and/or Apple could position themselves as a global authoritative reference for geographic names. To be to maps something akin to the OED or Merriam-Webster to the English language. But if they were to pursue that route they’d put themselves in the position of adjudicating any and all controversies and disputes over names and borders. Civic government is where we should want such disputes arbitrated, if not resolved. Not by private companies. If Apple Maps is to be available in China, Apple Maps needs to present names and borders ( and even the size of land masses — more on this below) that are amenable to the Chinese government. China sticks out because their demands are in stark contrast to the names and borders recognized by the rest of the world. Chinese maps are governed by CCP-mandated dogma. Most maps are governed by geographic and geopolitical reality. Taiwan, for example, is in fact an independent nation. Chinese maps (including those served by Apple to mainland Chinese users) label Taiwan as a province of China.

Now the United States is governed by another such dogma-driven regime.

In theory, maps ought not be political. In practice, they are and always have been. In theory, reasonable decisions and objectively correct decisions are one and the same when it comes to cartography. In practice, politics intercedes and they conflict. You can argue (and many people are) that Google and Apple should stick with the 400-year-old, recognized-the-world-over, and heretofore uncontroversial name “Gulf of Mexico”, and apply it globally. To simply ignore the new officially-recognized name of the gulf by the United States government. They could do that. No one would go to prison if they did. There would be no fines. But there would be a price to pay. Ignoring the new “Gulf of America” name recognized by the US government would, without question, court controversy. Republicans started to complain that Apple Maps hadn’t adopted the new name three weeks ago, before the change was even made official in the government’s GNIS reference database.

To ignore political reality is to court political controversy. It is not in the interests of large multinational corporations to court controversy. But it’s not possible to avoid controversy. What is reasonable is to minimize controversy. There’s a famous quote from Michael Jordan, when he declined to publicly endorse the Democratic challenger to the unabashedly racist Republican Jesse Helms in the 1990 North Carolina Senate race: “ Republicans buy sneakers, too.

Some might say “That’s the problem with capitalism.” I’d argue that it’s one of the benefits of capitalism. Unless you think extreme polarization is in the service of society, you want to see major institutions that are apolitical. For-profit corporations naturally serve that role. Yes, there’s a profit motive. Republicans don’t just buy sneakers, they buy phones and conduct web searches too. But who wants to see a world where everything is polarized politically, where every retailer, every device maker, every online service provider, every restaurant, every single thing you do, buy, or visit, is viewed through a polarized political prism? That way lies madness.

Most Americans, and most people in the western world, are beyond exhausted by our current levels of societal polarization. Escalating tensions further is not just contrary to the bottom-line interests of Apple and Google, it’s in none of our interests. People just want good accurate maps. They don’t want to choose — or worse, to be forced to choose — between right-leaning maps and left-leaning maps.

So if your argument is that neither Apple nor Google should be showing the name “Gulf of America” to anyone, anywhere, I’m with you that that’s the correct cartographical stance. But it would constitute political malpractice. Maps are important services to both companies, but the editorial integrity of their maps isn’t close to their primary business or purpose. Maps aren’t to Google or Apple what the English language is to the OED or Merriam-Webster. (Or what the news is to, say, the Associated Press. Hold that thought.)

So whether Google and Apple should show the new name at all shouldn’t be the question we’re asking. The right question is necessarily more nuanced: Who should see which names, where? And Google and Apple’s answers to that question are, alas, disappointing and worrisome. I’ll repeat the seemingly identical policy both companies are actually presenting today, by region:

  • United States: “Gulf of America”.
  • Mexico: “Gulf of Mexico”.
  • Everywhere else in the world: “Gulf of Mexico (Gulf of America)”.

The best politically realistic option they could have chosen would be (I’ll use italics to emphasize that these are my own suggestions):

  • United States: “Gulf of America (Gulf of Mexico)” .
  • Everywhere else in the world: “Gulf of Mexico” .

There’s no good reason to even show “Gulf of America” in parentheses outside the US. We’re the ones with the stupid name change on the books, so we’re the ones who should get stuck seeing the stupid name. No one else should suffer the consequences of our political lunacy. But it is correct to show us, in America, the new dumb “Gulf of America” name. Again, if it were up to me, American users would see “Gulf of America (Gulf of Mexico)”, and everyone else would just see “Gulf of Mexico”. But that’s surely the best we in the reality-based community could hope for.

It’s absurd that users here in the US no longer see “Gulf of Mexico” at all. You can search for that term, and the “Gulf of America” will be the first result, but the 400-year-old name “Gulf of Mexico” no longer appears as a label on maps to US-region users for either Google Maps or Apple Maps. In any even vaguely reasonable political climate, even those in favor of the name change would endorse, perhaps even insist upon, a transitional period where the previous, familiar name appears in parentheses. Insisting that the name be changed in a snap, with no parenthetical reference to the previous name (a name that, again, has been recognized globally for over 400 years, and remains on every single printed map in existence, and every single work of literature and history referencing the Gulf) has some truly Orwellian memory hole vibes. We’ve always been at war with Eastasia. It’s always been the Gulf of America.

The US political right often makes use of the term “ snowflake ” to suggest that those on the left are delicate and fragile. But it sure seems snowflaky to object to “Gulf of America (Gulf of Mexico)” as a map label. Sticks and stones may break their bones but a historically accurate parenthetical map label will hurt them? Food for thought as you enjoy your freedom fries .

Consider the simple premise that a map ought to make sense to someone who doesn’t follow current events. That ought to be uncontroversial. But to someone who has tuned out of the news for the last two months this change must seem downright baffling. Even worse, it’s misleading. There’s no reason for most people even to suspect, let alone know, that both Google Maps and Apple Maps show region-specific names and labels. Americans, in general, tend to be parochial. Showing Americans the name “Gulf of America”, without “(Gulf of Mexico)” strongly implies that this is now the new world-recognized name, when in the fact the truth is quite the opposite: it’s a name recognized by one and only one country. 3

Not showing the new name, at all, to Americans would be unreasonably provocative to the Trump administration and its supporters. But showing the new name to every region in the world but Mexico itself is needlessly obsequious to Trump and his supporters. And making Mexico an exception to global naming policy isn’t an honor or a favor to them — it’s an implied insult. It insinuates that there’s something wrong with them, too, legitimizing the notion that outside the US Trumpist right, there’s a legitimate debate about the Gulf’s name. The implied message is “ Here you go, you delicate idiots, we’ll make you the second of only two nations in the world regarding the displayed name of this body of water — you, and the United States. ” Mexico neither asked for nor provoked any of this. (Mexico only achieved independence from Spain in 1821; the “Gulf of Mexico” name is twice as old as Mexico as a nation, and at least 150 years older than the United States.)

There are numerous countries where Google Maps and Apple Maps show region-specific names and differing disputed borders ( or lack thereof ). From a 2020 report in The Washington Post :

And the line in Western Sahara marking the northern border with Morocco disappears for Moroccans seeking it out on the Web — along with the region’s name altogether. The sparsely populated northwest Africa region is disputed between Morocco, which seized it in 1975, and the indigenous Sahrawi.

Sometimes that flies in the face of international consensus. Google Maps users inside Turkey can find the Turkish Republic of Northern Cyprus, or TRNC, represented in the northern third of the Mediterranean island nation. The territory is not recognized by the United Nations, nor Google’s mapping competitors.

There are other places around the world where Apple and Google show downright crazy or incorrect things on maps. The latter have one thing in common: they are to comply with the demands of countries governed by thin-skinned autocratic men who surround themselves with sycophants. As mentioned above, in China, Taiwan is falsely labelled as a province of China in Apple Maps . 4 (Google Maps, like Google services generally, aren’t available in China.) In 2021, in a report for The Information headlined “ Inside Tim Cook’s Secret $275 Billion Deal with Chinese Authorities ”, Wayne Ma reported:

Sometime in 2014 or early 2015, China’s State Bureau of Surveying and Mapping told members of the Apple Maps team to make the Diaoyu Islands, the objects of a long-running territorial dispute between China and Japan, appear large even when users zoomed out from them. Chinese regulators also threatened to withhold approval of the first Apple Watch, scheduled for release in 2015, if Apple didn’t comply with the unusual request, according to internal documents.

Some members of the team back at Apple’s headquarters in Cupertino, Calif., initially balked at the demand. But the Maps app had become a priority for Apple, so eventually the company complied. The Diaoyu Islands, when viewed in Apple Maps in mainland China, continue to appear on a larger scale than surrounding territories.

You’ll stand on firm ground criticizing Apple for capitulating to China’s demands on that. But the root problem clearly isn’t Apple. It’s that China is governed by communist authoritarians, and authoritarianism warps minds — including those of the authoritarian leaders themselves. You know what no one says? “ The leadership of China is completely sane and sensible, and their edicts are based on reality, not dogma.

If you don’t see that Trump’s renaming of the Gulf of Mexico is on the same spectrum of nuttiness, then your mind, at least on this matter, has been warped. We can argue how far along that spectrum this “Gulf of America” thing is, but the only reasonable debate is of matters of degree. Apple and Google’s decision to show this made-up name in parentheses to everyone around the world is akin to showing China’s fictionally inflated size of the Diaoyu Islands to everyone in the world, as, say, a dotted outline surrounding the geographically accurate representations of the actual islands’ sizes. There’s a word for this stuff, and that word is propaganda .

Imagine if the government of France decreed that the English Channel was now the “French Channel”. Now imagine that Google and Apple Maps complied, even just to the degree of changing the label, outside France (which, per their company policies, should see “French Channel”) and the United Kingdom (which would still see only “English Channel”) to show the rest of the world, including us in the United States, “English Channel (French Channel)”. It would rightfully be considered insulting nonsense.

The only difference from my hypothetical and our reality with the Gulf of Mexico is that France, in addition to not having a narcissistic would-be autocrat as its president ( yet ?), is not the world’s lone remaining superpower. That’s what makes Google’s and Apple’s acquiescence worrisome, not merely irritating. As New York Times columnist Jamelle Bouie pithily observed over the weekend , on Bluesky, “My take is that your willingness to accept this Gulf of America nonsense is an indicator of your willingness to accept much worse things coming from this administration.”

The calculus Google and Apple should naturally be striving to achieve is finding the correct balance between two axes. One axis is integrity: both the cartographic integrity of the labels on the companies’ maps, and the institutional integrity — dignity even — of the companies themselves. Billions of people around the world trust Google and Apple. Their decisions on this mapping matter — no matter how trivial in the grand scheme of things — should strengthen, not erode, that trust.

The other axis is the minimization of controversy.

Simply maximizing integrity — by ignoring the “Gulf of America” name completely — would incur volcanic controversy within the United States. This calculated balance is behind my suggestion of showing “Gulf of America (Gulf of Mexico)” within the United States, and showing just “Gulf of Mexico” everywhere else. Perhaps the inclusion of the longstanding name within parentheses is too much for freedom-fry-eating Republicans. But showing the new “Gulf of America” name in parentheses to everyone around the world is itself incurring controversy, and, more tellingly, is a strike against the integrity of both the companies and their maps.

Obsequiousness is inherently undignified. Google and Apple are proud companies. But both have chosen a gratuitously undignified presentation of this new American-dictated name to the entire world. Their mutual decision here ultimately seems driven not by integrity (to be sure), nor the minimization of controversy, but instead by a third, unnatural factor: fear.

Neither company will comment on it but surely this issue — inconsequential in the grand scheme of things though it may be — rose to the highest ranks of leadership. I’ll eat my hat if Sundar Pichai and Tim Cook didn’t both sign off on, if not actively participate in the decision-making process, how to represent the Gulf of Mexico’s name. Much serious thought and consideration, from very smart people in Mountain View and Cupertino, went into determining how to respond to a profoundly silly and thoughtless executive order. But so eager are Pichai and Cook to avoid the wrath and vindictiveness of Trump that they’re willing to peddle his foolish “Gulf of America” name to everyone in the world who doesn’t live in Mexico. Wrapping it in parentheses is like wrapping a dead fish in newspaper — it doesn’t contain the stench.

Of course “The Gulf of America” name is stupid. Trump is stupid. Not stupid meaning dim or dull — would that he were, but he remains sharp, cunning, and highly agitated — but stupid because he’s nuts, warped by a narcissistic disorder of Napoleonic dimensions. The new name is as stupid as his MAGA hats are ugly. He might as well have sold the naming rights to Musk and Tesla. There is something really wrong with him, and this “Gulf of America” name change exemplifies at least one aspect of his narcissistic insanity. Everyone knows it. Even his supporters know it. They just tell themselves it’s fine. It’s how tribalism morphs into cultism.

The false note in Hans Christian Andersen’s parable “The Emperor’s New Clothes” is that once the emperor is called out, for in fact strutting around stark naked while ostensibly wearing a suit of clothes so fine that they’ve visible only to the eyes of smart and discerning people, is that all the townsfolk laugh at him. That wouldn’t happen. Many would laugh. Most, one hopes. But the emperor’s die-hard supporters would react with anger at the outburst of mockery, not join in the laughter. He looks great, they’d insist, not like the jackass their own lying eyes tell them he is.

There is something wrong with Trump — and there is something lesser, but worrisomely wrong with those defending him.

Apple Maps and Google Maps do not consider themselves cartographic editorial authorities. They choose not to show one universal set of mapping (and naming) data to the world. They could. But they don’t. Actual editorial authorities, on the other hand, are under no obligation to follow the US GNIS’s official decisions. Wikipedia correctly still calls it The Gulf of Mexico . The Associated Press, whose stylebook is followed by many publications, small and large, issued the following guidance after Trump’s executive order last month :

President Donald Trump has signed an executive order to rename the Gulf of Mexico to the Gulf of America. The body of water has shared borders between the U.S. and Mexico. Trump’s order only carries authority within the United States. Mexico, as well as other countries and international bodies, do not have to recognize the name change.

The Gulf of Mexico has carried that name for more than 400 years. The Associated Press will refer to it by its original name while acknowledging the new name Trump has chosen. As a global news agency that disseminates news around the world, the AP must ensure that place names and geography are easily recognizable to all audiences.

The Trump administration — petty, stupid, vindictive, and most of all, insecure fools that they are — has lashed out, and is now in the midst of a weeklong standoff during which they’ve prevented AP journalists from attending official events , entirely and solely because of the AP’s perfectly reasonable style guidance on the Gulf’s name. If Trump and his 2.0 administration had any modicum of confidence that this name change is correct and justified, they’d roll their eyes, not lash out, at the Associated Press for continuing to stipulate otherwise. What kind of government does stuff like that? Everyone knows the answer: tin-pot dictator autocracies. (And would-be autocracies, we can hope.) 5 This whole “Gulf of America” thing is, if you take a step back, objectively hilarious. Like Pinocchio turning into a real boy, Trump renaming the Gulf of Mexico is like a late night comedy joke turned real. It’s beyond parody. If this had been on SNL during the 2024 campaign, you’d have laughed. And you should laugh now. Mockery is a powerfully subversive weapon against authority — even more effective, I’d argue, than a guitar .

But it’s worth directing our laughter at Google and Apple as well. They’re squandering their own hard-earned reputations for integrity to suggest there’s even a parenthetical alternative-name level of international legitimacy — not merely one man’s vanity — behind this. There isn’t.

Creating the Aetheryte Radio

Hacker News
haz.ee
2026-08-28 10:59:15
Comments...
Original Article

ffxiv plays the whirs at random intervals, pitches, and gain (volume). these are all added to create an illusion of life(?) that make it harder to detect when an asset is repeating. thankfully, ffxiv also provided values that gave the min and max values for each of the random parameters, so it was easy to translate into javascript:

const whirIndex = Math.floor(Math.random() * whirs.length);

const whirPlaybackRate = Math.random() * (1 - 0.794) + 0.794;

whirGainNode.gain.value = Math.random() * (1 - 0.6) + 0.6;

if you've ever built a graph by hand the flow is usually something like: allocate a node, set metadata, and connect. i do the following to setup the hum:

const humSource = audioContext.createBufferSource();
humSource.buffer = await loadSample(
    audioContext,
    isSafari ? "assets/hum.wav.opus.aac" : "assets/hum.wav.opus",
);
humSource.playbackRate.value = 0.63;
humSource.connect(humGainNode);
humSource.loop = true;
humSource.start(0);

it's actually ok that i connect the node before i set loop, because the node doesn't produce samples until i call start .

the other part of the ceremony is the whir loop. it's not actually a loop using conventional loop control flow. instead of using a while (true) with a random "sleep" in between, i instead use setTimeout to schedule the next whir at a random interval.

function chooseWhir() {
    const whirSource = audioContext.createBufferSource();
    const whirIndex = Math.floor(Math.random() * whirs.length);
    const whirPlaybackRate = Math.random() * (1 - 0.794) + 0.794;
    whirGainNode.gain.value = Math.random() * (1 - 0.6) + 0.6;
    whirSource.buffer = whirs[whirIndex];
    whirSource.playbackRate.value = whirPlaybackRate;
    whirSource.connect(whirGainNode);
    whirSource.start(0);

    whirSource.onended = () => {
        
        whirSource.disconnect(whirGainNode);
        const nextWhirDelay = Math.floor(Math.random() * 2001);
        setTimeout(chooseWhir, nextWhirDelay);
    };
}

same deal here: create a source node, select a random asset, playback rate (pitch), gain (volume), and connect it to the gain node (which stays constant in this process and only has it's value changed.) the key here is that when the source asset ends, instead of looping, we remove that node from the graph and add a new one (by calling chooseWhir again.) because there is an expected delay before the next whir, i'm ok with adding whatever latency is added by doing the random calculation, it's likely marginal.

Verschlimmbesserung: The Word Your Software Updates Need

Hacker News
geekyschmidt.com
2026-08-28 10:30:33
Comments...
Original Article

The German language has a word for what your last software update did.

It is called Verschlimmbesserung : an attempted improvement that only makes things worse.

We have all lived through the SaaS update that moved a button, renamed a menu, and broke a workflow we relied on daily. Some product team shipped a “better experience” that solved a problem nobody had.

Eliyahu Goldratt nailed the root cause decades ago:

“Tell me how you measure me, and I will tell you how I will behave. If you measure me in an illogical way… do not complain about illogical behaviour…”

When point releases become more important than the product itself, you are incentivising Verschlimmbesserung. Your engineering teams are not failing. They are optimising for the metrics you gave them.

How you measure and incentivise your teams tells them exactly what you value. If the metric rewards churn, you get churn. If the metric rewards shipping, you get shipping; whether it improves anything or not.

Is new always better? Probably not. Office 2003 is still incredibly useful because nobody forced it to constantly reinvent itself.

Stability is a feature. Knowing when not to ship is an engineering discipline.

The Germans built a word for it. Perhaps we should start using it.

Verschlimmbesserung

Nobody Argued For Your Stack

Lobsters
dev.to
2026-08-28 10:05:47
Comments...
Original Article

Last week, it came to light Cursor had mostly finished migrating from SolidJS to React . This migration happened about seven months ago. But it became a central focus of discussion following the Solid 2.0 RC release . Then yesterday, a week later, it came to my attention that the Anthropic docs example command for their large-scale migration feature is:

I admit that my gut reaction was not great. Out of all the examples they could have chosen... Years of my work became a canonical example of the thing you migrate away from — in the same week we shipped the biggest release in the project's history — stung in a way I won't pretend it didn't. My second reaction was to assume that, like the other trickle-down posts I'd seen this week, this rode the same week-old news cycle.

Then I checked the Internet Archive and realized this has been there since at least April 2026 . Four months before the Cursor story broke. At this point, the whole public footprint was a mention of an experiment sandwiched between bigger updates in a Cursor blog post posted in January. The kind of thing that no one outside the industry would even really pick up on. No reasoning, no benchmarks, no argument.

Stop to think about what that means. I should be careful here because I can't prove anyone at Anthropic ever read that Cursor post. Nobody can. Maybe a docs writer saw the experiment. Maybe Claude drafted its own example. But think it through. Either it traveled from a buried line in one company's release notes into another company's official docs, or it needed no origin at all. It was already assumed before any public migration existed.

Our industry has quietly started broadcasting conclusions where it used to transmit arguments. We couldn't have picked a worse time, because — as I'll get to — arguments are the only source that still matters.


Why This Matters More Than It Used To

It would be fair to ask, hasn't it always been like this? Teams cargo cult large players. Netflix or Facebook uses this predates AI by decades. Optics and politics have always beaten pure technical merit. The weight of Facebook definitely helped React's early propagation.

But a narrative used to come with friction. It was always in the race, but it couldn't outrun the argument. This has changed for two reasons:

First, execution cost has collapsed. Bun's rewrite from Zig to Rust — about a million lines — was executed almost entirely by Claude agents in days, not months. And before you start thinking "lock-in", going the opposite way, while not as easy, has never been easier. Migrating from Rust to Zig or React to Solid has never been easier.

That sounds like good news. And it is. When migrations took years of human effort, cost put a damper on fashion. Now execution is a lot cheaper in all directions. The only thing left is the reason. Which suggests, on the surface, these decisions should be rooted in technical merit. But when narrative is what sets the direction, you start to see how a line buried in documentation is worth an essay.

Second, verdict production has been industrialized. Cognition just migrated its marketing site from Astro to Next.js . A content site. Astro's home turf, by near-universal consensus, including from people with no stake in the fight. The migration was performed by Devin itself and published as a case study: the agent made the changes, tested them, recorded its own verification runs. No repository, no before-and-after numbers, no benchmark. The output wasn't the site. It was the story.

And believe me, there is no shortage of these stories. Migrations are now the demo genre of the agent industry. Theo Browne was trying to tell me this a couple weeks back with some very good advice. But it hits a lot harder when you feel it firsthand. Migrations that demo flawlessly are, by definition, the ones moving toward what the agent writes best today. Marketing departments are generating "X → dominant library" verdicts at a rate organic engineering decisions never would.

So you see the tension. Stacks have never been more sensitive to circulating verdicts, and verdicts have never been produced faster or with less reasoning attached.


What an Argument Looks Like

These aren't unheard of. They are just becoming rarer.

When Bun moved from Zig to Rust , Jarred Sumner made the case in public, with receipts. He talked about bug classes and memory management issues. You can disagree with the argument. People have , point by point, in public. That's the value. An argument can be engaged, checked, narrowed, refuted, or strengthened. A verdict can only be repeated.

Or look at TanStack's journey with React Server Components on tanstack.com. They spent the year almost arguing with themselves. When tanstack.com adopted React Server Components , they wrote it up and measured it. When they stopped using them , they did the same: What changed, what replaced it, why the tradeoff flipped for their specific case — while TanStack Start went right on supporting RSC as an opt-in primitive for everyone else. The reversal post calling the decision "uneventful" is a tell. A public reversal on React's flagship architecture, and it generated insight instead of heat. Because they delivered analysis instead of verdict.

That's what evaluation entering the public record looks like. jQuery didn't lose to React because a training set said so. It lost an argument, in public, on merit over several years. Every library you respect got where it is by winning that kind of fight. The flow of events I described earlier doesn't hold fights. It holds direction, and compounds on it.


The Argument Nobody Published

In all fairness, Cursor never issued a verdict. An experiment that "still needs careful review", then a congratulatory post on the Solid 2.0 RC release . But that post still characterized signals as "perf footguns" and "accidental fan out" — no numbers, nothing to engage — and reached straight for the React Compiler as the cure. No bad faith required. The diagnosis and the cure just came from the same place.

When I tried to reconstruct the case Cursor could have made, it turned out to be interesting. Far more interesting than "perf footguns."

The post obviously highlighted agents were "quite bad at writing good Solid code," everything "ended up being accidentally tracked." While my "Solid-brain" struggles a bit to imagine what they were doing to get there, I don't doubt it for a second. An agent that has internalized React's mental model will write Solid like React, and Solid written like React is bad Solid. I've also seen the reverse. The difference is when the agent fumbles React, the training data catches it. When it fumbles Solid, the training data shrugs. This is a pure numbers game.

But the same post contains a decision in the opposite direction. They're also moving from Tailwind to StyleX. This is a migration against volume. What StyleX offers instead is that agent mistakes get caught. Styles are typed with deterministic merge order, so a hallucinated class is a build error.

Put side by side, one conclusion can be made: make agents' mistakes cheap. Two ways to achieve that. Volume and verification. React (with its compiler) wins on volume and arguably on verification. StyleX loses on volume and wins decisively on verification. I won't pretend under this lens with Solid 1.0 this is a particularly comfortable place for signal-based reactivity. But it's also, not coincidentally, where Solid 2.0's design attention has gone.

That analysis, volume and verification as two axes, is concrete, checkable, and useful. It implies testable claims and gives every framework author a design target. It might also be wrong. I reconstructed it from a benchmark-free post and my own inferences. Cursor's actual reasoning may be entirely different.

The StyleX decision is even more interesting. Agent-driven development can move against volume when verification wins. There is a second angle that small technologies can embrace. To me, this isn't a new revelation, but one where practice confirms theory.


What Happens If Nothing Changes

If you follow this thinking to its logical conclusion, outside of a few exceptions, each layer collapses on its most popular solution today. Frontend converges on React. Systems converges on Rust. Scripting converges on Python. Even the sites that are just pages converge on Next, fit be damned. That's a monoculture, arrived at not by anyone deciding libraries on their merits, but by a system that can no longer distinguish "abundant in the training data" from "better."

If you are a React fan, you should still be concerned. React was good because it had competition. Hooks arrived in a world where composition patterns were being explored. The React Compiler exists, in part, as an answer to the question signals-based frameworks spent years forcing: Why should the developer pay for re-rendering the world? React's greatest strength has always been its ability to metabolize pressure from outside. A monoculture doesn't just kill the alternatives. It kills the pressure. An ecosystem without pressure doesn't stay good. It stays stuck.

There is a path back. Teams publish analysis, not verdict. Model vendors evaluate what they ship in public. Libraries learn from StyleX's example and bank on verification. And the rest of us learn to distinguish output from argument before we amplify it. The last one we've been struggling with since the dawn of social media.

In the meantime, we can keep generating our rules files, llms.txt, docs over MCP, curated examples. We do all of it for Solid 2.0, and it helps a lot. But context is borrowed, not owned. It has to be injected into every session, by every tool, forever, while the inertia works against you for free.


Where Does the Next Idea Come From?

I want to leave you with a more probing thought. The question this all comes down to isn't whether Solid survives. We're fine. We are shipping the biggest release in our history, with a community that chose this framework on purpose and, more importantly, knows why.

The question is where the next idea comes from.

Every paradigm that has mattered started as something the establishment couldn't write. React was mocked for almost a year over JSX. Markup in JavaScript? Are you insane? What about separation of concerns? If today's machinery had existed in 2013, models trained on a web that was all jQuery and Backbone, docs canonizing migrations everyone was already making, verdicts circulating months ahead of their arguments, do you think it could have gotten past that stage?

It didn't win because the defaults favored it. It won because people made a verifiable case in public. And I don't think the mechanisms are gone. Migrations have never been cheaper, in every direction. The door out of any monoculture has never been more open. We just need to keep analysis as part of the conversation even as we distance ourselves from the implementation. That's being informed. That's taking responsibility.

ICE Plans to Spend Millions on Boston Dynamics Dog Robots

403 Media
www.404media.co
2026-08-28 10:04:55
ICE wants the robot dogs to improve “officer safety.”...
Original Article

ICE wants the robot dogs to improve “officer safety.”

ICE Plans to Spend Millions on Boston Dynamics Dog Robots
Image: screenshot of a Boston Dynamics promotional video.

Immigration and Customs Enforcement (ICE) plans to buy at least a million dollars worth of robots from Boston Dynamics, the company that makes the dog-like SPOT robots, with the purpose of improving “officer safety,” according to a Department of Homeland Security (DHS) announcement.

The news shows that ICE continues to spend millions of dollars on new technology. On Thursday, U.S. procurement records showed that ICE has contracted to buy 6,000 pairs of electric shock gloves for $16.7 million, the Associated Press reported .

This post is for paid members only

Become a paid member for unlimited ad-free access to articles, bonus podcast content, and more.

Subscribe

Sign up for free access to this post

Free members get access to posts like this one along with an email round-up of our week's stories.

Subscribe

Already have an account? Sign in

Trump Declares That Lake Ontario Is Now ‘Lake America’

Daring Fireball
www.notus.org
2026-08-28 10:02:53
Jackie Llanos and Jenna Monnin, reporting for NOTUS: President Donald Trump on Thursday signed an executive order meant to rename Lake Ontario “Lake America,” taking his apparent jab at Canada one step further as a trade war between the two countries escalates. The president said the name chang...
Original Article

President Donald Trump on Thursday signed an executive order meant to rename Lake Ontario “Lake America,” taking his apparent jab at Canada one step further as a trade war between the two countries escalates.

The president said the name change was “effective immediately” during a signing ceremony in the Oval Office. The executive order directs Interior Secretary Doug Burgum to update the Geographic Names Information Service to reflect the name change.

When asked by reporters about the move, Trump said he was sending “no message” to Canada with the name change.

“Lake of America was something I’ve been thinking about for a long time,” the president said. “Actually, as you know, we took something called the Gulf of Mexico, we changed it, and now it’s very routinely the Gulf of America .”

“If you think about it, we have a Gulf, and we have a lake. Now, all we need is an ocean,” Trump added, floating a potential name change for the Atlantic or Pacific ocean.

The executive order argues that because more of the lake’s volume lies within territory claimed by the United States, Trump has the right to unilaterally change its name.

The name change came two days after Trump had threatened to do so in a Truth Social post, explicitly connecting the move to trade negotiations between the U.S. and Canada that flamed out at the last minute Friday night.

The U.S. and Canada have been entrenched in a trade war since Trump imposed tariffs on America’s northern neighbor in early 2025. In February, the Supreme Court struck down the sweeping international duties that the president levied through a string of executive orders.

But tensions between the trading partners escalated earlier this month when Trump threatened new tariffs of up to 50% on $20 billion in Canadian goods. Canada retaliated with its own sweeping tariffs — further complicating the relationship between the two countries, which exchanged more than $870 billion in annual trade in 2025.

While Trump can unilaterally call the lake a new name, it doesn’t mean other countries, or even localities within the United States, have to abide by it.

A defiant Gov. Kathy Hochul said on X that New York state, which borders the lake, would not follow Trump’s instruction to change the lake’s name.

After Trump’s announcement, Canadian Prime Minister Mark Carney pointed out that the name predates both the U.S. and Canada. “Ontario” comes from the Wendat indigenous word meaning “the lake is beautiful, the lake is big.”

The Interior Department’s U.S. Geological Survey is the lead agency that handles renaming requests, and Trump’s speedy renaming of the Gulf of Mexico sent the agency into disarray, as NOTUS previously reported .

Mexican President Claudia Sheinbaum continued to call it the Gulf of Mexico, despite Trump’s push to relabel the body of water.

There was also significant bipartisan pushback from Alaska politicians against Trump’s order to change the name of Mount Denali in Alaska back to Mount McKinley. President Barack Obama’s administration changed the name in 2015 to honor Alaskan native groups’ original name for the peak — which translates to “the tall one” — after a decades-long campaign by the state. In 1896, the mountain was named for William McKinley, the 25th U.S. president, who never visited the state.

In the executive order announcing the mountain’s name change, the White House described the move as an effort to restore “names that honor American greatness.”

This story has been updated with further information.

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

Bleeping Computer
www.bleepingcomputer.com
2026-08-28 10:00:10
AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...]...
Original Article

AI pressing a button

Author: Gene Moody, Field CTO at Action1

AI can help us find vulnerabilities faster than ever. But what happens when the rest of the vulnerability management ecosystem can’t keep up?

When Vulnerability Volume Outpaces the System

In April, NIST released a statement regarding updates to NVD operations that reflects a necessary response to scale. CVE volume has grown beyond what the current enrichment model was designed to handle. As part of the change, roughly 30,000 vulnerabilities published before March 1, 2026, were reclassified as "Not Scheduled."

Prioritization, automation, and selective processing are reasonable adjustments in principle. In practice, however, the shift introduces a set of risks that may not be fully understood, particularly for those responsible for defending enterprise environments.

The pressure is not theoretical. Action1's 2026 Software Vulnerability Ratings Report found that disclosed vulnerabilities across the enterprise software categories analyzed increased 92% in 2025 compared with 2024. Critical and high-severity vulnerabilities increased 103% each, while vulnerabilities enabling remote code execution increased 128%.

Today, the volume of disclosures that must be validated, enriched, prioritized, and ultimately remediated is likely to place even greater pressure on systems designed for a slower era of vulnerability discovery.

The core issue is therefore not simply the existence of a backlog. Backlogs are an expected outcome in any system operating under rapid growth. The concern is how that backlog is managed and, more importantly, what signals are created by the decision to prioritize newer vulnerabilities over older, unprocessed ones.

What Happens When Enrichment Falls Behind

By focusing enrichment efforts only on recent CVEs, the system implicitly deprioritizes vulnerabilities that may already be known, confirmed, and, in some cases, actively discussed by vendors or researchers but lack full NVD context.

This creates an information asymmetry of a particularly difficult kind: partial intelligence without the second half that makes it readily actionable. Security teams that rely heavily on NVD as a normalized source of vulnerability information may see incomplete or delayed data.

Attackers, meanwhile, do not need to wait for standardized enrichment before correlating vendor advisories, security research, patch releases, exploit information, and public disclosures.

That gap matters because enrichment is not cosmetic. Structured metadata, affected-platform information, severity scoring, configuration details, and other contextual information allow defenders to determine whether a vulnerability actually applies to their environment and how urgently it should be addressed.

When that information is missing or delayed, organizations are often forced to either wait for additional context or make decisions using fragmented information. Neither outcome is ideal in a threat landscape where exploitation can move faster than internal validation and remediation processes.

But That’s Not All

There is also a second-order effect that is harder to quantify but equally important. A rolling backlog that is continuously fed while being selectively drained creates uncertainty about coverage. Without a clear commitment to processing older entries within a defined timeframe, the backlog becomes a semi-permanent condition.

Some vulnerabilities will be enriched quickly, others will remain in limbo, and there will be limited visibility into which category any given CVE falls into at a given moment.

For practitioners, this overly complicates prioritization. If affected-product information such as CPE data is incomplete or overly broad, organizations face a greater risk of false positives. Teams may spend time investigating vulnerabilities that do not apply to their environment while potentially overlooking risks that do.

Over time, this will certainly erode confidence in the dataset and push organizations to build alternative intelligence pipelines. That will lead to additional cost, tooling, and operational complexity. As well, as one may predict, increasing failure rates.

Vulnerability Management Is Changing

None of this suggests that NIST is acting irresponsibly. The scale problem is real, and the existing model was not designed for the volume of vulnerability information now entering the ecosystem.But the introduced trade-off pushes more responsibility downstream.

Organizations will need to rely less on a single authoritative source and more on correlation across multiple sources, including NVD, vendor advisories, independent vulnerability-intelligence providers, threat intelligence platforms, and internal asset inventories.

Zoom out, and the view is that vulnerability management is becoming less about consuming a curated list and more about synthesizing accurate intel from incomplete data in near real time. That requires maturity, tooling, and process discipline that not all organizations currently possess.

If this direction continues, the NVD will remain a critical component of the vulnerability-management ecosystem, but it will no longer function as a comprehensive baseline on its own. Instead, it becomes one input among many, and one that may lag significantly behind the realities of exploitation in the field.

The more important question then becomes not simply, "What vulnerabilities exist?" but "Which of them affect us, which represent the greatest risk, and how quickly can we act?"

How Defenders Should Adapt

The first lesson is that vulnerability management can no longer depend on any single source of enrichment. NVD remains enormously valuable, but security teams increasingly need to subscribe to cumulative works of vendors and organizations that aggregate the available data into usable intelligence

More importantly, collecting additional feeds is only part of the answer. More information can simply create another prioritization problem. The real objective is to turn fragmented vulnerability intelligence into a decision: Does this vulnerability affect us, how urgent is it, and what can we do about it now?

This is the model Action1 has adopted for vulnerability management . Rather than relying exclusively on NVD enrichment, Action1 combines intelligence from sources including VulnCheckNVD++, NIST NVD, CISA’s KEV Catalog, Microsoft’s own MSRC data, and vendor release notes, then scores each vulnerability based on CVE data, CVSS severity, CISA KEV status, and known usage in ransomware campaigns, providing initial prioritization in minutes.

That intelligence is correlated with real-time endpoint data so teams can determine which vulnerabilities actually affect software deployed in their environment and prioritize remediation accordingly.

Once an affected endpoint has been identified, remediation should not require another export, manual correlation exercise, or lengthy handoff before patching begins.

Action1 brings vulnerability assessment and remediation into the same workflow, allowingorganizations to move from learning that a vulnerability exists to reducing actual exposure much faster, all from a single console.

Action1 dashboard

The AI vulnerability era will not be defined by how fast IT and security teams can find flaws, but by how quickly they can understand, prioritize, and patch them. Discovery is accelerating, soremediation must accelerate with it.

See how Action1 connects real-time OS and third-party vulnerability intelligence with automated remediation to help your team reduce exposure faster.

Start free and scale when you're ready.

Sponsored and written by Action1 .

How I made Rustdoc 33% faster in one week

Lobsters
noahlev.org
2026-08-28 09:58:44
Comments...
Original Article

I’m a member of the Rustdoc team and recently made a series of PRs to Rustdoc that resulted in an average wall-time reduction of 25% (which is a 33% speedup ), with up to 40% on some real-world crates like hyper and bitmaps , and up to 60% on microbenchmarks like helloworld. This blog post gets pretty into the details of how I went about discovering and implementing these performance improvements. I think it’ll be interesting if you want to learn more about what it’s like to work on Rust itself, including, in this case, Rustdoc. But if you want to just skip to the pretty chart at the end showing the final results , feel free!

The Bug

Last month, Rust release team member @theemathas posted on the Rustdoc Zulip about a strange regression in our latest beta. In case you’re not familiar with it, Rustdoc is the tool behind cargo doc . If you’ve ever opened the standard library docs or the docs for a crate on docs.rs, you’re looking at Rustdoc’s output. Anyway, before each stable version of Rust is published, the release team runs a tool called Crater that tests the new version across the public Rust ecosystem. Crater found Rustdoc to be newly erroring on a crate called indented-blocks , with code like this:

#![recursion_limit = "8"]

On a crate containing just this code, Rustdoc failed with a “reached the configured maximum number of stack frames” error while analyzing an internal-facing trait in core::fmt . In contrast, Rustc successfully finished compilation. This recursion_limit attribute allows users to control Rustc’s own recursion, since many language features can trigger excessive recursion at compile-time. 1 Users will sometimes have to raise the recursion limit above its default value if, for example, they use deeply nested macros or complex trait logic. The number of stack frames Rustc uses is not part of our stability guarantees, so this regression was not necessarily a problem.

However, it immediately raised alarm bells for me. Much of Rustdoc revolves around invoking Rustc APIs and then organizing and presenting the resulting information to users. So if Rustc was successfully compiling this code, it was concerning that Rustdoc failed on it. We do have cross-crate features like inlining documentation for items that your crate re-exports: std::vec::Vec is actually alloc::vec::Vec , but it looks seamless in the docs. We also show which impls across your workspace apply to types in your crate. But I couldn’t think of any reason why a random trait from core::fmt should have its documentation inlined into a nearly empty crate!

Sure enough, though, Rustdoc’s logs showed that it was trying to inline documentation for this trait:

DEBUG rustdoc::clean::inline record_extern_trait: DefId(2:13427 ~ core[195b]::fmt::num_buffer::NumBufferTrait)
DEBUG rustdoc::clean trait_ref=Binder { value: <Self as core::fmt::num_buffer::NumBufferTrait>, bound_vars: [] }

When I opened the file, collect_trait_impls.rs , that is responsible for inlining external impls, I found this code:

// in a pass called "build_extern_trait_impls"
for &cnum in tcx.crates(()) {
    for &impl_def_id in tcx.trait_impls_in_crate(cnum) {
        cx.with_param_env(impl_def_id, |cx| {
            inline::build_impl(cx, impl_def_id, None, &mut new_items_external);
        });
    }
}

For every dependency of the current crate, this code iterates through each trait impl defined there and constructs a representation of the impl suitable for display in docs. Thus, the algorithm’s complexity is linear in the number of trait impls throughout your entire dependency graph, with a large constant factor since build_impl is a rather involved function. That’s expensive!

Of course, Rustdoc doesn’t actually display all (or even most) of these impls in the docs, because it performs filtering later in the file, after impl collection. This is when I had a lightbulb moment: What if we performed the filtering first and only called build_impl for the impls we actually needed? I guessed no one had tried this before because the filtering code assumed it was receiving an already processed representation, plus there was some gnarly logic in the middle that followed chains of Deref impls. But I thought, what the hell, let’s just try it.

Filter First

I started by adapting an overly permissive version of the filtering logic to work on Rustc’s raw rustc_middle::ty data structures, then placed it as a guard before each build_impl call. I ran the main Rustdoc testsuite and… it passed. Wow. This was super encouraging.

I deleted the post-collection filter now that it was redundant. The testsuite still passed, even though my new filtering rules were too loose. In fact, I realized it should always be fine to keep unneeded impls. They only actually show up in doc pages where they are relevant, for example, if the page is for their self type or their trait. So, extra impls just slow Rustdoc down but don’t affect correctness.

It was time to face the scary code that followed chains of Deref impls. I was feeling bold. What if I just deleted it? This is actually something I often try to see how much behavior depends on a piece of code that I’m trying to improve. I waited for a wall of red tests that never came. Then I ran the extended testsuite that uses Puppeteer to test live GUI behavior. Just one test failed, and strangely it had nothing to do with Deref ; rather, it was a test of #[doc(notable_trait)] .

OK, a quick digression to give some background: Rustdoc has an unstable feature called “notable traits” where traits marked with a special attribute trigger little annotations wherever types that implement them are returned from a function. To see why this is useful, consider Iterator::map() . It returns a type called Map , which isn’t particularly meaningful to me as a user. However, Iterator is marked as a notable trait, so there is a little information icon ⓘ next to Map that tells me it is itself an Iterator .

It turned out that our trait impl inlining code never considered notable-trait status when making its decisions. So our GUI test for that tooltip passed by accident. It tested that a function returning Vec<u8> showed a notable trait tooltip for Write . Through the generic Vec<T> to &[T] deref impl, Vec<u8> derefs to &[u8] , which in turn implements Write , thus causing the Write impl to be loaded into Rustdoc’s context and made available to the notable-trait popup!

After adding the necessary consideration of #[doc(notable_trait)] , the GUI test passed, but a snapshot test needed to be updated because the notable trait popup was suddenly appearing in a lot of places where it was previously missing. It’s always nice when cleaning up code ends up inadvertently fixing a latent bug!

But, of course, the most exciting part of this PR was the perf results. The benchmarks showed an average wall-time improvement of 20% . Maximum resident-set size (a measure of peak memory usage) also decreased by 12% . The impact of this change was so large because the build_extern_trait_impls pass accounts for a significant proportion of Rustdoc runtime, as visualized by this flamegraph from before my change:

Flamegraph for Rustdoc run on Serde before my first change

I think this performance win really shows the power of combining empirical profiling data with a willingness to question existing code. Excited from this success, I decided to push things further.

Primitive and Synthetic Impls

My next two PRs improved performance with smarter handling of primitive and synthetic impls. Rustdoc has special support for documenting primitive types like usize , str , and [T] that are not defined anywhere in library code but rather are built-in to the compiler. Although the types themselves are built-in, the standard library defines impls on them. Think of str::as_bytes , for example. To facilitate the display of these docs, the standard library uses special #[rustc_doc_primitive] attributes so that Rustdoc has a place to put them. I noticed that the logic in collect_trait_impls.rs to inline impls for primitive types ran in every crate, even if that crate did not declare any primitives (as nearly all crates do not). For complex technical reasons, this pass is expensive, so it added a meaningful amount to Rustdoc’s runtime. By making it only run on local primitives (and thus be skipped for most crates), I improved Rustdoc’s wall time by 12% and max RSS by 6% , on average.

The other PR was for synthetic impls. This is our name inside the Rustdoc codebase for the impls we synthesize on doc pages for auto traits and blanket impls. Let me explain what these terms mean. Send and Sync are examples of auto traits. Their implementations are determined on the fly by the compiler for types that meet their requirements, so the impls are not defined in your code. Rustdoc, however, constructs representations of these impls so that it can display them in docs as if they were normal impls.

Blanket impls are a little bit different but similar in spirit. They do have a definition in user code, but they are implemented for a generic type. For example, every type T is subject to the blanket impl<T> ToOwned for T , if T: Clone . So we copy these impls onto the pages of each type to which they apply.

Synthesizing all these auto and blanket impls is expensive since it requires iterating over every type defined in a crate and then checking each auto trait and each blanket impl against it. I noticed that Rustdoc was doing this analysis even for types that never appeared in the final documentation, for example, for private types. Adding a filter to analyze only documented types reduced wall time by 6% on average and up to 13% on some real-world crates like hyper .

Self Types

My final PR in this series was driven by examining flamegraphs for Rustdoc that were collected after my previous changes. I noticed that Rustc’s param_env query was accounting for a remarkable 50% of the time taken by the build_extern_trait_impls pass:

Flamegraph for build_extern_trait_impls before this PR

This query essentially just computes and normalizes the where clauses on an item (in our case, an impl), including those it inherits from its parent. While this operation isn’t cheap, it’s not particularly expensive either. The reason it took so much of the time is that it was being invoked on every single impl in the crate’s dependency graph—better than actually inlining every impl, like before, but still not great. To decide impl inlining, we need to examine the impl’s self type to see if that type is inlined. Computing Rustdoc’s version of this type requires the parameter environment since we may need to normalize it. Normalization just means simplifying a type down as much as possible given our knowledge about it. For example, if know that MyIter: Iterator<Item = MyStruct> , then we can normalize <MyIter as Iterator>::Item to MyStruct .

However, what I realized is that we can avoid computing a full Rustdoc version of the type in most cases. We only need to examine the head of the self type. By “head”, I mean the most essential part of the type that determines which documentation page it refers to—the Vec in Vec<i32> , or the String in &'a mut String . And we only need to call param_env if the self type’s head is something like <MyIter as Iterator>::Item that we have to normalize. 2 Changing Rustdoc according to these principles yielded an average 18% wall-time speedup across the benchmark suite, including real-world crates like clap_derive . I validated that the improvement was due to avoiding param_env invocations for non-inlined impls using another flamegraph from after this change:

Flamegraph for build_extern_trait_impls after this PR

Notice that param_env ’s share of runtime is significantly smaller, leaving build_impl as the dominant contributor. Now, the pass’s runtime is dominated by performing work for impls that we actually want to inline, rather than for ones we end up skipping.

Final Results

After all these changes, where do they leave Rustdoc? I think the following graph of Rustdoc wall-time across our benchmark suite shows it best. 3

final wall-time graph

Each of these four dips corresponds to one of my PRs. Rustdoc is now 33% faster on average! This improvement is present on nightly already and will land on stable in Rust 1.99.

The impact is noticeable on flamegraphs, too. Observe the share of runtime taken by build_extern_trait_impls for hyper , one of the most improved benchmarks, before…

hyper flamegraph before my changes

…and after my changes…

hyper flamegraph after my changes

Bye for Now

I hope you’ve enjoyed reading this peek into my recent work on Rustdoc. More than any technical detail, the learnings I most want you to take away are to trust your instincts and to question assumptions. Just because a piece of code (or anything, not just code!) has been a certain way for a long time doesn’t mean that it’s optimal or even correct. If your intuition tells you something, listen to it and dig in to see what you find. You might just stumble upon a major improvement waiting to be discovered.

P.S. Thanks to my Rust teammates for making this project a joy to be a part of.

Correction: My title initially read, “How I made Rustdoc 25% faster in one week”. Nicholas Nethercote pointed out that in fact, a 25% reduction in time corresponds to a 33% speedup ( 1 / 0.75 = 1.333 1/0.75 = 1.333\ldots ). Even better! I’ve updated the post accordingly.

  1. Our trait system is famously Turing-complete , after all.

  2. In fact, Rustdoc’s algorithm determines the documentation page (and thus its inlining decision) for a qualified path like <MyIter as Iterator>::Item based only on its self type ( MyIter ), not its normalized value ( MyStruct ). So we actually never need to normalize self type heads and can always skip param_env . This behavior is a bit surprising, but there are some longstanding limitations in Rustdoc regarding normalization, due to issues we encountered when enabling it in the past. So for now, I focused on reproducing this existing behavior, despite it being suboptimal.

  3. Since the data are aggregated across multiple benchmarks, the numbers are normalized such that 1.0 corresponds to the average for the first point in time in the graph.

Mamdani Is Critical of Israel, and the Times Is on It

hellgate
hellgatenyc.com
2026-08-28 09:54:24
Who does the Gray Lady quote on this important issue? Plus, more news for your weekend....
Original Article

One of the first signs that the New York Times might be suffering from Mamdani Derangement Syndrome came last summer, when the paper, having recently pledged not to make endorsements in municipal elections, but evidently dismayed at the prospect that he might win the Democratic nomination, published an exceedingly contorted non-endorsement endorsement that urged New Yorkers to vote instead for Andrew Cuomo.

Mamdani won the nomination anyway, and the general election, and took office in January, and the Times has been diligently covering his administration ever since, documenting everything from his pied-à-terre tax to his wife's fashion sense. In this coverage, one particular theme has surfaced again and again: a focus on Mamdani's forthright criticism of Israel's conduct of the war in Gaza and its treatment of Palestinian citizens; the concern that produces among some Jewish New Yorkers; and the possibility that Mamdani's criticism of Israeli policies make Jewish New Yorkers less safe by contributing to an atmosphere of growing antisemitism.

From the headline " Israeli Government Accuses Mamdani of Antisemitism Over Canceled Orders " in January through " Disconnect Widens Between Mamdani and Pro-Israel Jewish Leaders " in May to " After Stabbings, a Rise in Jewish Fears and Questions for Mamdani " in July and " Rabbis Plead With Mamdani to Tone Down His Anti-Israel Messaging " earlier this month—to say nothing of the multitude of stories the paper wrung from its July interview with Mamdani in which he entertained the possibility of executing an outstanding UN arrest warrant for Israeli Prime Minister Benjamin Netanyahu for war crimes and crimes against humanity—the Times has been assiduously on the beat.

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

Eight stable kernels with fix for a single vulnerability

Linux Weekly News
lwn.net
2026-08-28 09:42:06
Greg Kroah-Hartman has announced the release of the 7.2.2, 7.1.12, 6.18.48, 6.12.107, 6.6.155, 6.1.186, 5.15.219, and 5.10.268 stable kernels. Each of these contains a single fix for a vulnerability (CVE-2026-80590) that allows marking IPv4 or IPv6 fragments as GSO, which can allow an unprivileged ...
Original Article

[Posted August 28, 2026 by jzb]

Greg Kroah-Hartman has announced the release of the 7.2.2 , 7.1.12 , 6.18.48 , 6.12.107 , 6.6.155 , 6.1.186 , 5.15.219 , and 5.10.268 stable kernels.

Each of these contains a single fix for a vulnerability ( CVE-2026-80590 ) that allows marking IPv4 or IPv6 fragments as GSO , which can allow an unprivileged user to cause a kernel panic. This vulnerability has been present since Linux 2.6.27. Users are advised to upgrade.


The Finn – an agent that lives in my router and complains about it

Hacker News
github.com
2026-08-28 09:38:30
Comments...
Original Article

A small, grumpy agent that lives inside your router and only knows what the router can see.

Named after the character in William Gibson's Sprawl trilogy who ends up as a construct in an armoured box bolted into an alley, where people come to hear the oracle complain. This one runs on a GL.iNet GL-MT3000 on an office wall. It watches the hallway it is in, and occasionally has something to say about it.

It is deliberately not an assistant. No tools, no memory beyond a state file, no access to your mail or calendar or tickets, and nothing to be helpful with. It has a view of one hallway and an opinion about it.

Six failed SSH logins in the last minute, usually it's zero all night. Bloody hell, some tosser out there fancies his chances.

Твой десктоп качает на скорости 9.5 Мбит/с, обычно там крутится жалких 200 Кбит/с. В глотку будто ведро воды опрокинули, аж кадык свело.

Everything runs on the router itself. If the rest of your infrastructure is on fire, this still works, which was most of the point.

Quick start

You need about ten minutes, a router you own, and a card on file with an LLM provider.

1. Check your router can host it. OpenWrt-based, with lua , lua-cjson and a curl built with TLS. On GL.iNet firmware all three are usually there already:

ssh root@192.168.8.1 'lua -e "require(\"cjson\") print(\"ok\")"; curl --version | head -1'
# missing anything?  opkg update && opkg install lua lua-cjson curl

It needs a few megabytes of overlay and nothing else. Tested on a GL-MT3000, OpenWrt 21.02, 512 MB RAM.

2. Make him a Telegram bot. In Telegram, open @BotFather , send /newbot , give it a name and a username. He hands you a token like 123456789:AAF... . That token is the bot; anyone holding it can post as him, so treat it as a password.

3. Find your own Telegram id. Message @userinfobot ; it replies with a number. He answers that id and no other, so nobody else can talk to your router.

4. Get an API key. Anthropic or OpenAI , both are wired up. Create a dedicated key with a low monthly limit. It will sit in plaintext on a device that shares a network with other people; a key that can only ever spend five dollars is a key you can shrug about. Expect single-digit dollars a month at the default settings.

5. Install.

git clone https://github.com/YuriKovalov22/the-finn && cd the-finn
cp env.example env && $EDITOR env     # paste the token, your id, the key
./install.sh root@192.168.8.1

The installer checks the router, copies two files, writes env with mode 0600, installs the minute cron entry, enables cron, and prints what he can see right now.

6. Say hello first. Open your bot in Telegram and press Start. Telegram does not let a bot open a conversation, so that message is what tells him where to write. He picks it up on his next tick, within a minute. Send /help to see what he understands.

That is the whole setup. He will stay quiet for the first fifteen minutes while he learns what normal looks like, then speak when something is not.

How he decides to speak

There is no list of interesting events, which is the part worth stealing. Every minute the box takes a wide reading of itself and the room, keeps a rolling history of every reading in RAM, and looks for anything that has fallen outside its own recent range. Whatever is unusual today is what he talks about, so he does not become the same five notifications forever.

Two kinds of oddity are detected generically:

  • numeric , when a sensor leaves the band it has held for the last 45 minutes by more than a per-sensor floor that keeps ordinary wobble out;
  • membership , when anything appears in or disappears from a set: a device, a neighbour on the upstream network, an unusual destination port.

Variety is enforced along three axes, and the coarsest one matters most. Kind is what a remark is actually about: traffic, presence, neighbours, an intruder, his own body, the rhythm of the place. Connections, throughput and per-device flow churn are different sensors and different themes but the same observation to a reader, and traffic is by far the twitchiest thing on a network, so left to itself it wins nearly every round: five of six consecutive remarks here were some counter going up. Traffic is therefore rationed to one remark in six hours, and the kind that has waited longest is chosen first.

Which means the other kinds have to have something to say, so several observations exist that are not counters at all: a machine arriving or leaving and how long it was gone, someone at the desk at an hour the room is normally empty, an uptime milestone, a stretch of stillness, and hour-of-day profiles for the slow human sensors, because what is normal at nine on a Tuesday is not what is normal at nine on a Sunday and a 45 minute band cannot tell the difference.

Variety is enforced along two further axes, and the second one is easy to miss. Theme keeps him off one subject; shape keeps him off one sentence. Six remarks reading "X is N now, usually M" are varied by theme and identical to read, so each oddity also carries a shape (a level rising, something quieting, an arrival, a departure, a change of rhythm, a stretch of stillness) and the longest-waiting combination of the two wins. He is also shown his own last few remarks and told not to reuse their form.

Stillness is itself an observation: after some hours in which nothing has left its range, he is handed that fact rather than staying mute, because a resident would remark on a quiet evening.

Two rules stop him degenerating into a monitor for whichever sensor twitches most. Every oddity carries a theme (ports, the room, the wider network, people, his own body, the network, an intruder); a theme that has just been used goes quiet for ninety minutes, and among what is left the longest-waiting theme is the one he is handed. And churn is not news: a port or a neighbour that was here yesterday and came back does not count, only genuine novelty does.

Only then is a model asked, and it is asked as a resident rather than a monitoring system: react to this one thing, or reply NOTHING if it is bloodless bookkeeping. A subject he has raised is muted for six hours, and a failed API call is not treated as a decision to stay quiet.

What he can feel

Sense Source
who is on your wifi, and how strong their signal is iwinfo assoclist
who they are /tmp/dhcp.leases , by hostname, so MAC rotation does not break it
which of them are furniture rather than strangers FINN_KNOWN_HOSTS , hostname to plain name
which of them are people you know FINN_PEOPLE , hostname to a person's name
whether a machine is in use or asleep per-device flow churn in /proc/net/nf_conntrack
how much each device is pulling and sending conntrack byte counters, when they can be trusted (see below)
how long each machine has been here, and since it last stirred tracked between ticks
how many devices the upstream network has, and which are new neighbour table on that interface
what the network talks to, and on what ports conntrack, common ports filtered out
link health, latency and loss to the gateway dmesg , ping
throughput both ways /proc/net/dev deltas
whether a tunnel is alive, and who is on his VPN wg show
his own temperature, load, memory, disk, uptime /sys , /proc
failed SSH logins and real kernel errors logread , with the wifi driver's constant screaming filtered out
whether you arrived earlier or later than usual rolling history of first phone appearance

Per-device throughput deserves a warning. It is read from conntrack byte counters, and on any router with hardware NAT offload, which includes this one, established flows are handled in silicon and those counters stop growing. A busy video call shows up as a handful of packets. Left alone this produces devices that appear to be sending more than the entire uplink carried, and an agent will faithfully narrate the impossible number. Each tick therefore checks the parts against the whole and publishes nothing rather than something wrong.

Association is useless as presence, which is worth knowing before you build something like this: a sleeping Mac stays associated all night, and so does a printer. Flow churn is the honest signal. A sleeping machine opens no new connections; a machine someone is sitting at opens between three and fifty a minute.

Every sensor is also wired to a sensation. He is not handed "temperature 63, was 45", he is handed heat climbing inside his case; a device drawing closer is a tickle, a yanked cable is a slap, unfamiliar broadcasts from beyond the wall are ghosts he can hear and never see. He has an anatomy to complain about: the antennas are his ears, the ports his fingers and toes, the flash his gut.

Talking to him

He answers anything you write, always, in any mode. He also takes commands, handled locally at no cost:

Command Effect
/status mode, what he has said today, model calls spent, which brain he is thinking with
/off speaks only when spoken to
/rare at most 2 unprompted a day, 3 hours apart
/normal at most 5 a day, an hour apart
/chatty at most 10 a day, 15 minutes apart
/test no daily ceiling, one a minute, for two hours, then back to /chatty by itself
/voice beep plays a pip when he posts, speak reads the remark aloud, off keeps him to Telegram
/machines lists the machines he can control and which are awake
/wake <name> sends a WOL magic packet, waits, and tells you whether it actually came up
/sleep <name> sleeps the machine over SSH

Test mode spends its own budget. Otherwise an afternoon of watching him work leaves him mute for the rest of the day, which is exactly what happened here: two hours of testing burned 22 remarks against a ceiling of 10, and he went silent the moment the test expired.

The daily allowance opens gradually rather than all at once. Mornings are the richest hours for oddities, so a flat cap gets spent before eleven and leaves nothing for whatever happens at five; instead it unlocks in proportion to how much of the speaking window has passed, with one message always available.

He calls you by whatever you put in FINN_OWNER_NAME , and he only ever talks to the one Telegram id you configured.

Unprompted remarks come out in Russian or English by coin toss. He answers you in whichever language you wrote in. To make him monolingual, edit STYLE and the language line near the bottom of finn.lua .

Running it

/root/finn/tick.sh            # one tick, as cron runs it
/root/finn/tick.sh facts      # what the box sees right now: sends nothing, records nothing
/root/finn/tick.sh say "..."  # make him speak on a given occasion
/root/finn/tick.sh status     # the same answer /status gives in the bot
/root/finn/tick.sh kinds      # how each sensor is grouped, and when each group last spoke

facts is strictly read-only, and that matters more than it looks: an inspection that saved what it saw would mark the oddity as already known, and the next real tick would have nothing left to say. Diagnostics must not eat the event they are diagnosing.

State lives in /root/finn/state.json , events in /root/finn/finn.log ; a quiet tick writes nothing. The first run takes a baseline and stays silent, so a cold start does not report every device in the building as a new face.

A speaker, if you want one

Plug a class-compliant USB speaker into the router and he can be heard as well as read. Install kmod-usb-audio and alsa-utils , and set FINN_VOICE :

  • beep , the default and the one worth having: a short two-tone pip when he posts, so you look at your phone. sounds/finn-blip.wav in this repo, copy it to /root/bell/finn.wav .
  • speak , which sends the remark to OpenAI speech synthesis and plays it through the speaker, in a gruff old-sailor voice. Requires FINN_OPENAI_KEY even when the words come from Anthropic. Delightful for about a day, then you will switch it to beep ; ask me how I know.
  • off .

Either way it only makes noise between FINN_VOICE_FROM and FINN_VOICE_TO , 9 to 19 by default, and never when no sound card is present.

Cost and wear

The minute tick is pure local work: no API call unless an anomaly was found, and a hard ceiling of 40 model calls a day including the ones that end in NOTHING .

The flash is treated as the scarce resource it is on these boxes. Sensor history lives in tmpfs, the persistent state file is a few hundred bytes and is only rewritten when its contents actually change, and the log is truncated at 256 KB. Total footprint on the overlay is well under a megabyte.

Tuning

At the top of finn.lua :

Constant Meaning
HIST how many minutes of history count as "normal"
WARMUP samples before a sensor may cry anomaly
SUBJECT_MUTE how long a subject stays quiet after he raises it
CALL_BUDGET hard ceiling on model calls per day
QUIET_FROM / QUIET_TO hours in which he may speak unprompted
FLOOR per-sensor noise floors: how big a change has to be to count
MODES the talkativeness presets behind the bot commands

The character is one prompt near the middle of the file. Rewrite it and you have a different resident. Four rules in it were each learned by getting them wrong, and are worth keeping in any character you write:

  1. The plain fact first, then the image. A remark made only of metaphor and swearing reads well and communicates nothing: "двести семьдесят восемь глоток орут в брюхе" leaves the reader guessing what happened. Name the thing by its own name; the lock may follow as an image, but it may not stand in for "failed SSH logins".
  2. Every image must mean something. Ask for a bodily reaction without demanding the comparison be checkable and you get filler shaped like style: "проснулся резче, чем спал" cannot be true or false.
  3. Never let the character narrate its own plumbing. Unprompted, a model will happily say "I was not given that value", which is true of the prompt and fatal to a thing bolted to a wall. It notices or it does not.
  4. Forbid the two lies a sensor agent tells naturally. A throughput reading is how much is moving, not how much could move, and a model will happily turn "2.5 Mbit/s flowing" into "the line is narrow as a needle's eye" while a gigabit sits idle. It will also invent outside knowledge it cannot have: mine announced that video calls "need at least 5 to 10 Mbit/s each way", which is both wrong and unknowable from inside a router. Say plainly that it has never read a specification and that the only normal it owns is the one it measured in that room.
  5. Write the style rule in the language it governs. An English instruction about writing numbers as digits sits unread at the bottom of a Russian answer. The same rule in Russian is obeyed at once.

Privacy

FINN_PEOPLE lets him greet people by name: "John's just joined the wifi, go and say hello." That is for a network you run and people who know it exists. The same trick pointed at a shared building network would work rather well, and that is the point at which this stops being a toy and becomes covert attendance tracking of strangers, so it is not built and I would not add it. Aggregate counts of the wider network are already there and carry nobody's name.

This watches a network, which means it watches the people on it. It is written for a router you own, in a room you occupy. Keep it that way. It reports on the owner's own named devices and on anonymous counts, it never inspects traffic contents (DNS query logging is deliberately not switched on), and it sends messages to exactly one Telegram id.

Notes for the road

  • scp does not work against dropbear, which has no sftp-server . Pipe through ssh 'cat > file' .
  • GL.iNet firmware runs a second crond off /tmp/gl_crontabs for its own jobs. Leave it alone; the installer uses the stock one at /etc/crontabs/root .
  • A firmware upgrade wipes the overlay and takes /root/finn with it. Re-run install.sh .
  • Lua 5.1 has no notion of a character, so every string cut is a byte cut. Slicing Cyrillic at a byte boundary produces invalid UTF-8 and the API rejects the whole request. There is a character-aware truncation helper in the file for this reason.

MIT licensed. It is a toy with a body; enjoy it.

Htmx 4.0

Hacker News
four.htmx.org
2026-08-28 09:28:56
Comments...
Original Article

htmx 4.0.0 Release

The htmx team is very happy to announce the release of htmx 4.0.0! This is the culmination of 8 months of work (plus a game ) and we are very happy with the results.

The idea of htmx 4 started to germinate when I decided to create fixi and, in doing so, got more familiar with the fetch() API and async programming in JavaScript. (htmx had always used XMLHttpRequest due to backwards compatibility issues.)

One chance evening I was contacted by Christian, who had some interesting ideas around streaming HTML that got me thinking that moving the internals to fetch() would simplify things for him and for the library in general.
After a bit of work I managed to get Michael and Alex on board, and we were off to the races.

Development has been very smooth. We started a port of fixi + the htmx test suite. Over time, we rediscovered why htmx did many of the things that it did and moved our new implementation closer and closer to the old one. At this point the behavioral differences between 2.x and 4.x are relatively small and where they do diverge we have made explicit choices that we feel will put htmx-based applications in a good spot for being 100-year web services

Note that we are not marking 4.0 as latest in NPM because we do not want to force-upgrade users who are relying on non-versioned CDN URLs for htmx. Instead, 2.x will remain latest and the 4.0 line will remain next until some point in early 2027. The website, however, will reference 4.0.

Major Changes

As mentioned above, htmx 4, from a user’s viewpoint, is almost identical to htmx 2. There are three major changes:

  • Attribute inheritance is now explicit by default rather than implicit by default (this is the biggest upgrade item)
  • The htmx event names have been standardized & cleaned up. Some advanced users may need to change the events they listen for.
  • History support now does not use localStorage by default (which was a cause of many support headaches). Most people won’t notice this at all.

Internally, we migrated from XMLHttpRequest to fetch() but that should be transparent for most users of htmx.

Attribute Inheritance

In htmx 2 many attributes were “inherited” by default. This allows you to place attributes on parent elements and their behavior will apply to child elements. This behavior, which came from the intercooler.js days, was inspired by CSS and, unsurprisingly, worked out about the same as CSS: powerful but difficult to understand at times.

In htmx 4 attributes are not inherited unless you explicitly say so by adding an :inherited after the attribute name:

<!-- htmx 2 -->
<div hx-confirm="Are you sure?">
    <button hx-delete="/item/1">Delete</button>
</div>

<!-- htmx 4 -->
<div hx-confirm:inherited="Are you sure?">
    <button hx-delete="/item/1">Delete</button>
</div>

This will be the largest upgrade burden in migrating from htmx 2 to htmx 4. To make things easier, we have provided a command line tool to find places you need to mark as inherited.

Note that attributes like hx-disinherit , etc. are no longer required and should be removed.

Events

The events triggered by htmx 2 had grown organically over the life of the library and were not particularly well organized, making it difficult to know exactly which event was fired when.

In htmx 4, all events now follow htmx:phase:action[:sub-action] :

htmx 2 htmx 4
htmx:beforeRequest htmx:before:request
htmx:afterRequest htmx:after:request
htmx:beforeSwap htmx:before:swap
htmx:afterSwap htmx:after:swap
htmx:configRequest htmx:config:request

In addition, the following changes were made:

  • Most error events collapse into htmx:error . HTTP error responses fire htmx:response:error .
  • The htmx:xhr:* events are removed. htmx 4 uses fetch() .
  • The htmx:validation:* events are removed in favor of native browser form validation.

The full table is in What’s New in htmx 4 .

The command line upgrade checker flags old event names in hx-on attributes and in your JavaScript where it can find them.

History

History support has always been included in htmx, allowing you to implement back-button aware actions with simple attributes. In htmx 2, a cache in localStorage was used to snapshot pages for restoration. Unfortunately a large source of issues was that this snapshot could include DOM mutations by 3rd party JavaScript libraries. When the page was restored, those mutations remained but the underlying JavaScript logic was not.

htmx 4 does not cache pages in localStorage . On back navigation htmx re-fetches the page and swaps it into <body> , or into the [hx-history-elt] element if one is present. This allows 3rd party JavaScript libraries to “just work” in most cases and, with good request caching, is very fast.

If you want local caching instead, we now ship a very complete hx-history-cache extension that restores history from sessionStorage and is designed to integrate well with scripting solutions like Alpine.js, etc.

New Features

There are two big new features in htmx 4, both of which we are really excited about:

Morph Swaps

We now support morphing swaps out of the box with htmx. I created idiomorph and nearly included it in htmx 2.x but decided against it. In htmx 4, Michael has done great work improving on that algorithm and integrating it seamlessly into htmx.

<hx-partial>

Another major new feature is the <hx-partial> tag. This tag is similar to out-of-band swaps , but is much clearer when you want to do something beyond just replacing a single element with a new version of itself:

<hx-partial hx-target="#messages" hx-swap="beforeend">
    <div>New message</div>
</hx-partial>
<hx-partial hx-target="#count">
    <span>5</span>
</hx-partial>

Extensions

Much of the excitement in htmx 4 is in the extensions. Switching to fetch() internally let us rethink how extensions can and should work, and sparked the creation (and recreation) of many new extensions, for example:

  • hx-preload - preload content (e.g. on mouseover ) to speed requests up
  • hx-download - native, fetch-based file downloads
  • hx-alpine-compat - smooths over compatibility issues between htmx and Alpine.js
  • hx-history-cache - caches history in sessionStorage , provides Alpine.js compatibility

Additionally, there are three new or updated streaming HTML extensions:

Finally, we decided it was time to try our hand at our own small front-end scripting solution that tightly integrates with htmx. hx-live is inspired by Alpine.js, jQuery and hyperscript , and makes front end scripting pleasant and fun. It even supports what we are calling DOM-based, HATEOAS-friendly reactivity.

There is a new htmax.js bundle in the distribution which packages htmx with the most popular of these in a single file if you don’t want to think about which ones you want to pick.

Upgrading

For a complete upgrade guide see What’s New in htmx 4 .

As mentioned earlier, we are providing an upgrade tool to help you:

$ npx htmx.org@4.0.0 upgrade-check -- ./templates

File extensions: .html, .php, .js, .ts, .jinja, .jinja2, .j2, .erb, .hbs
Use --ext to add more (e.g. --ext .vue --ext .svelte)

Scanning 1 file(s)...

Found 8 issue(s) in 1 of 1 file(s).
templates/index.html:1: [inheritance] hx-headers needs :inherited suffix (descendant on line 3 has hx-delete) (this looks like a CSRF token; without :inherited the header does not reach child elements and the server rejects the request)
templates/index.html:2: [inheritance] hx-target needs :inherited suffix (descendant on line 3 has hx-delete)
templates/index.html:2: [inheritance] hx-confirm needs :inherited suffix (descendant on line 3 has hx-delete)
templates/index.html:3: [renamed-attr] hx-disable -> rename to hx-ignore (hx-disable now means 'disable during request')
templates/index.html:4: [removed-attr] hx-vars is removed -> use hx-vals with js: prefix
templates/index.html:4: [removed-attr] hx-prompt is removed -> load the hx-prompt extension to keep the same syntax
templates/index.html:9: [old-event] old event name "htmx:afterRequest" -> "htmx:after:request"
templates/index.html:9: [old-api] htmx.addClass() is removed -> use element.classList.add()

We are also shipping an agent skill to assist in upgrading

Installing

htmx 4.0 can be installed via a package manager referencing version 4.0.0 , or can be linked via a CDN:


<script src="https://unpkg.com/htmx.org@4.0.0/dist/htmx.min.js"></script>

or Downloaded

LLMs

Like it or not, a lot of people are using LLMs and we are providing the following skills files for LLMs:

(Let’s leave aside if releasing a new version of a library in the LLM era is a good or bad thing!)

Conclusion

We hope you enjoy htmx 4. htmx 2 will continue to be supported indefinitely so don’t feel any pressure to upgrade.

I’d like to thank the following people for all their help with this release:

  • Michael West - Incredible teammate & grug-brained developer
  • Christian Tanul - Inspired htmx 4 & led the streaming & live extensions
  • Alex Petros - For keeping the ship on an even keel
  • Stephen Mitchell - The genius behind the game
  • Stu Kennedy - Our WebSockets expert
  • André Ahlert Jr. - Providing IDE & Editor Support
  • Dien Hoa Truong - For kicking the tires on early htmx 4 and helping fix many bugs

Upgrade Music

Wouldn’t be an htmx update without upgrade music:

Security updates for Friday

Linux Weekly News
lwn.net
2026-08-28 09:16:19
Security updates have been issued by AlmaLinux (assertj-core, golang, httpd, kernel, and libxml2), Debian (chromium and suricata-update), Fedora (rust-h2), Mageia (avahi and python-django), Oracle (kernel and mingw-openssl), SUSE (c-ares-devel, dracut, gh, gstreamer-plugins-bad, java-11-openjdk, lib...
Original Article
Dist. ID Release Package Date
AlmaLinux ALSA-2026:59372 10 assertj-core 2026-08-28
AlmaLinux ALSA-2026:60306 10 golang 2026-08-28
AlmaLinux ALSA-2026:60004 10 httpd 2026-08-28
AlmaLinux ALSA-2026:59723 9 kernel 2026-08-28
AlmaLinux ALSA-2026:60394 10 libxml2 2026-08-28
Debian DLA-4758-1 LTS chromium 2026-08-27
Debian DSA-6476-1 stable chromium 2026-08-27
Debian DSA-6475-1 stable suricata-update 2026-08-27
Fedora FEDORA-2026-c3233bfa3f F43 rust-h2 2026-08-28
Mageia MGASA-2026-0338 10, 9 avahi 2026-08-27
Mageia MGASA-2026-0339 10 python-django 2026-08-27
Oracle ELSA-2026-59821 OL8 kernel 2026-08-28
Oracle ELSA-2026-59723 OL9 kernel 2026-08-28
Oracle ELSA-2026-60329-0 OL8 mingw-openssl 2026-08-28
SUSE openSUSE-SU-2026:11593-1 TW c-ares-devel 2026-08-27
SUSE openSUSE-SU-2026:21639-1 oS16.0 dracut 2026-08-27
SUSE openSUSE-SU-2026:21663-1 oS16.0 gh 2026-08-27
SUSE openSUSE-SU-2026:21629-1 oS16.0 gstreamer-plugins-bad 2026-08-27
SUSE openSUSE-SU-2026:11594-1 TW java-11-openjdk 2026-08-27
SUSE openSUSE-SU-2026:21634-1 oS16.0 liboqs 2026-08-27
SUSE SUSE-SU-2026:3834-1 SLE15 oS15.6 librest0_7 2026-08-27
SUSE SUSE-SU-2026:3835-1 SLE15 openssl, openssl-3 2026-08-27
SUSE openSUSE-SU-2026:21636-1 oS16.0 pcp 2026-08-27
SUSE openSUSE-SU-2026:11585-1 TW python313-mistune 2026-08-27
SUSE SUSE-SU-2026:3846-1 SLE12 python36-pip 2026-08-27
SUSE openSUSE-SU-2026:21626-1 oS16.0 qt6-svg 2026-08-27
SUSE openSUSE-SU-2026:21640-1 oS16.0 rmt-server 2026-08-27
SUSE openSUSE-SU-2026:21650-1 oS16.0 rsync 2026-08-27
SUSE SUSE-SU-2026:3843-1 SLE5.3 SLE5.4 SLE-m5.3 SLE-m5.4 oS15.4 suseconnect-ng 2026-08-27
SUSE SUSE-SU-2026:3847-1 oS15.4 texlive 2026-08-27
SUSE openSUSE-SU-2026:11590-1 TW tor 2026-08-27
SUSE SUSE-SU-2026:3837-1 SLE12 wicked 2026-08-27
SUSE SUSE-SU-2026:3841-1 SLE15 wicked 2026-08-27
SUSE SUSE-SU-2026:3842-1 SLE15 SLE5.3 SLE5.4 SLE-m5.3 SLE-m5.4 oS15.4 wicked 2026-08-27
SUSE SUSE-SU-2026:3839-1 SLE15 SLE5.5 SLE-m5.5 oS15.5 wicked 2026-08-27
SUSE SUSE-SU-2026:3840-1 SLE15 oS15.6 wicked 2026-08-27
SUSE openSUSE-SU-2026:21633-1 oS16.0 xmlrpc-c 2026-08-27
Ubuntu USN-8644-3 14.04 16.04 18.04 linux-azure, linux-azure-4.15, linux-azure-fips 2026-08-27
Ubuntu USN-8643-5 22.04 24.04 linux-azure-6.8, linux-ibm, linux-ibm-6.8, linux-oracle-6.8, linux-raspi, linux-raspi-realtime 2026-08-27
Ubuntu USN-8658-4 20.04 linux-azure-fde-5.15 2026-08-27
Ubuntu USN-8661-3 22.04 linux-fips, linux-gke 2026-08-27
Ubuntu USN-8666-3 20.04 linux-gcp-fips 2026-08-27
Ubuntu USN-8686-1 22.04 24.04 opencryptoki 2026-08-27
Ubuntu USN-8688-1 18.04 20.04 22.04 24.04 pam 2026-08-27

What are you doing this weekend?

Lobsters
lobste.rs
2026-08-28 09:03:44
Feel free to tell what you plan on doing this weekend and even ask for help or feedback. Please keep in mind it’s more than OK to do nothing at all too!...
Original Article
  1. Resuming doing/learning Rust. I found ownership/borrowing concepts not that that difficult as expected, and iterators are cool! I tried browsing some OSS projects, but Rust code in the wild looks very different than what I feel like I learned ha.

    I'll be trying out the Bevy pong tutorial or the CHIP-8 emulator guide, beside those I'll playing videogames and relaxing hopefully.

    I also did a Zig sidequests and really liked it a lot! Ziglings is a nice resource and the language has a nice balance of features that feels more intuitive to me than Rust. But I'm also not that smart (yet!) to go handle memory close up like that.

    1. I built my first real program in Rust recently. Had explicitly tried picking it up a few times in the past, but it never stuck—this time, I had a real problem to solve and felt it would be the best tool for the job (really wanted nice enums). I'd recommend just trying to build something that works in as janky a way as possible—all sorts of clone s everywhere and everything—and then taking passes back over it to make it idiomatic.

      Or at least, that's what I did. I'm no expert. GLHF!

      1. I'm definitely going to clone() my way out of problems at the start, on my own code! I don't have that much spare time and I'd rather just get a feel of things, and refactor incrementally when possible.

        It's a bit hard to know what exactly good Rust code is tho, the code I've seen has so much variation in error handling and writing style.

        1. That's fair. I've mostly been going for concision—so lots of ? bubbling up errors, which I think is idiomatic, and probably vastly too many filter / map /functional concepts. Now that the first domino has fallen and I've actually written something, I should probably start reading other people's code, contributing to the ecosystem, and thus get a better idea of best practices.

          1. No matter the style I'd imagine it to still be exciting! Hopefully :P.

          2. ? is good to use! And using filter/map stuff is fine, no worries there. match is good to get a handle on, and let...else might help in some more straightforward case, both can either be cleaner or more ergonomic than the functional methods. Most of that boils away to the same or similar lowered code (Rust is all about "cheap or free abstractions") so do what makes sense for your codebase.

            Closures for the functional bits aren't like closures in dynamic languages; they usually get inlined, similar to C++ lambdas.

            Anything by burntsushi is a great starting point for idiomatic rust, if you want a good grounding point.

        2. It's a bit hard to know what exactly good Rust code is tho, the code I've seen has so much variation in error handling and writing style.

          Good question, I don’t think there’s one correct answer, and BTW I think that C has even more variation in the wild. Between GObject and the Win32 API…

          In my opinion Rust is kinda simple if you don’t use futures and async . It’s not the most simple language of the world but it’s okay. However, when you start adding Send futures, it gets… different!

          1. BTW I think that C has even more variation in the wild. Between GObject and the Win32 API…

            Ah, yea I can imagine it to be a natural consequence of having freedom in how to express things and a big userbase

            In my opinion Rust is kinda simple if you don’t use futures and async. It’s not the most simple language of the world but it’s okay. However, when you start adding Send futures, it gets… different!

            yea this is definitely one of the parts where I found it to be harder than I'd like, I'm currently avoiding it because I can(it's just hobby programming), but I do want to practise more with such concepts in Rust.

        3. A decent rule of thumb:

          • library? thiserror ; don't pollute your public API with anyhow or string-based errors
          • binary (executable)? anyhow if thiserror becomes too untenable.
    1. Andrew Kelley will be a featured guest, and two other awesome presenters! You'll enjoy it :D

      There's still a bonus RSVP for latecomers. (And if THAT is full please consider Seattle's Zig Day on Sunday.)

      Let's see, what else...

      • We have a Tokyo meetup tomorrow too, which caught the attention of Maximilien Dagois . Excited he's joined the community as he wrote my favorite Game Boy ASM book.

      • There's a revival for San Francisco meetups. I think they'll be sending an RSVP this weekend. The new host is a Debian package maintainer.

      We have mailing lists for different cities so folks can stay updated. ( Plus an RSS feed.) Happy Friday!

  2. Hosting a Zig Day in Seattle on Sunday. So many people RSVP'd that I had to scramble to find a location with more room. Which I did, so now there's plenty of space for even more people! Zig experience not required if you come with an interest to learn. https://zig.day/usa/seattle/3/

  3. Long weekend in the UK, depending on the weather I'm either doing things inside or outside at home then with a friend off to visit a third friend to catch up for an evening out. Should be fairly relaxing/enjoyable with a bit of life admin thrown in.

    1. Similar relaxation and admin for me, but if the rain holds off I plan to visit the local clay pigeon range with a friend and a pair of century-old French shotguns.

  4. Watching the kiddos both days so my wife can work a side gig.

    My side project game is fun, so I'm adding meat to the bones, building out levels and identifying a path to release. I'm terrible at finishing hobby projects, but I want to release on steam to prove to myself I can ship my own product and maybe make some extra money.

  5. Weirdly (to me), happily reading research papers for my day job, which went from QA to “we would like you to invent our AI QA” a month ago. I don’t remember the last time my brain buzzed like this.

    1. Also, since I took today off and it already the weekend, un-haunting the “haunted” WiFi at my local wings and beers place. This is going to stun all of you when I tell you. Prepare yourselves.

      Ok? It’s always DNS.

      1. I plan to dress up as DNS for Halloween. No, I also don't know what that'll look like.

    2. What is ai qa? Like what kind of thing are you qaing?

  6. If it were up to me, I'd go to sleep and then sleep for the rest of the weekend. Ideally the week too. In fact, let's make it the year. Or the decade. I am so tired.

    More realistically: Playing low-effort video games and worrying about the future. I think the time for creative activities is behind me.

  7. i'm trying to learn Go, i love the fact that there is just 1 way to do one thing, i use python on the daily basis, and we have like 4/5 types of for, i'm searching a programming language that is primitive and easy to remember, maybe i'll try Lua too

  8. Dealing with government bureaucracy and job hunting. The hunt has been exhausting, especially since we're still burned out on our tech career from our last, traumatizing job, never mind how even Starbucks hasn't wanted to interview up for barista positions (and we'd sincerely love to try working in a coffee shop). Sadly didn't make it into a woodworking career training program either. Would've loved that! Any Lobster help with the search, referrals, or contract work would make a huge difference.

    For our recharge, we have more of the wonderfully fun Cloudy with a Chance of Starships to read, co-op to play with our partners (hopefully some ATLYSS ), and more of the hilarious Wander Over Wonder to watch with another partner.

  9. Trying to learn about how I can learn to write a lexer, parser, and type checker.

    1. Have you read "Crafting Interpreters" by Robert Nystrom? I thought it was a really great read and super approachable.

      1. I skimmed through it before. I love the idea. I don't know if it'll help me build the type checker I want to build, but I'll definitely utilize it. Thank you for the recommendation.

  10. Fighting with DPMI.

    I'd previously heard that the original "True" DPMI provided protected mode redirection of DOS services, and on reflection realized Windows 3.x needed this for Windows programs since it has no file API of its own, just int 21h. All 16 bit DPMI is doing is letting command line programs access DOS just like Windows programs do, which means getting a command line program to run in 16 bit DPMI ought to be trivial.

    Unfortunately mine is currently crashing attempting to switch, and debugging across a protected mode switch was never going to be straightforward.

  11. Working on two things:

    A static site generator in Typst. All pages written in Typst, the actual code to put together a site, everything Typst. Though, there will not be any blog posts using the SSG for a while, as I've decided that I'm not allowed to blog about my SSG until I've got at least two other blog posts published.

    The other thing I'm working on is a VHDL implementation of the discrete cosine transform. The ultimate goal is to have a high quality lossy JXL encoder, but for now I'm just trying to make the best cosine implementation. Trying to not use too much area, or have it be too slow, nor use too much memory for a LUT, nor be too inaccurate. It's a lot of fun, I haven't done this much math for a real problem in ages :D

    1. That's so cool! Do I understand correctly you are concerned about area because you'll have many many many instances of this cosine? And do you think you might tape out on a shuttle one day?

  12. Ahh, some cooking for me. I already spent some time thinking about possible spec-level mitigations for the US government ceasing your domain , and talked about art, psychology and ethics under capitalism.

    Next up is a well-deserved watching of a niche anime film I am gambling on... And getting my PC back onto its rightful location on my desk after it was out of service for a few weeks due to needing to RMA the RAM (thank god they let me). Big big unwrapped spool of cables all over the desk since I had to dock my laptops there instead.

  13. In Krakow, visiting Auswitch Birkenau with brother-in-law and our dads. Everything is horrible, on an incomprehensible scale. I worried that I would find the visit difficult, but surprisingly I’m ok 🤷🏼‍♂️

  14. Throwing a cookout for my wife's birthday. Making barbacoa tacos, esquites, black beans, and a few other sides. It's going to be a very busy day cooking and cleaning, but I'm looking forward to eating it all and sharing a meal with our friends.

    Sunday will probably be laying out the couch like a slug recuperating from all that.

  15. Trying to set up the steam index on NixOS again I suppose? I failed to get anything working the last time so I don't have anything new to go on but good vibes from the steam frame being around the corner™ and having an accidental interaction with the dev of a VR mod. I hope it works this time!

  16. Mostly trying to sit still so my clavicle will mend itself. Reading. Watching films. Snugging small dogs.

  17. Working on a research project that aims to investigate the maintainers of the conda-forge ecosystem with the hopes of strengthening and making it more sustainable. Long term I’m hoping it can also contribute to more transparency that will connect packages on conda-forge with the volunteers supporting them.

    First look at the project here: https://github.com/travishathaway/feedstock-maintainers

  18. Off to see Midsummer Night's Dream in our local woods. It's scheduled to be pissing down. Got to love English summertime :-)

    I'm planning on getting DOIs minted for my blog posts, but I need to work out if relicensing everything to CC BY is worth it. Don't suppose anyone knows of a free way to get DOIs do they?

    1. As long as the articles could be reasonably considered very niche research or education materials, you could probably upload a copy to HCommons now that they renamed from Humanities Commons to Knowledge Commons? On research side, there are also Zenodo and Figshare and OSF.io

  19. I'm back at work after two weeks of holidays :'( It's hard right now, but I think this week-end will be fun, since I'm going to start coding on my side project again GitRoot ;)

  20. Hedge trimming and finishing an article.

  21. for the first time in a while, no idea. classes have started again and my research isn't a flaming pile of garbage (for now) so the usual sense of panic has dissipated a little.

    i did pick up a copy of the dragon book, so might start reading through that?

  22. Heading home after a very weird week of vacation in Penn Yan, NY. Very beautiful and lovely time, but just lots of Interpersonal Stuff going on.

  23. Working on my budget, hanging out with the kids, yardwork, and if time permits starting a new Lazarus project.

  24. Going to a Zen ashram in the hills for a short stay this weekend. I don't know but I got some vibes to write and this time I wrote about few of my reflections on Ego - https://nirm.al/notes.html

  25. See if codex can configure my bricked router via serial UART. I successfully soldered UART and can get root shell, remains to be seen if the ISP configuration tools are scrutable.

    I will be looking for a good reason to get a beefy machine for local AI. The 256GB M5 ultra Mac Studio seems to only be able to produce <$1000 per year worth of mid coding model - not great.

    So I decided that I will budget to buy model capacity from openrouter at similar throughput rate / quantization as my desired machine. See what it’s like.

    Also looking into whether other kinds of models are more economically favourable to self host compared to hosted.

  26. I don't know. On Tuesday hopefully I start the official paperwork for the master's degree that qualifies me for secondary school teaching in my neck of the woods.

    Life stuff is not fun lately. I also need to send back one or two work laptops, so I should get started in restoring at least the one I know is going back. (Shame, 3K€ ThinkPad P with 64gb of RAM and an absurd Nvidia GPU... which has decent battery life and is not as heavy as I thought. The other one is a ThinkPad Tablet that I'd like to keep if the price is right, because it has 16gb of RAM and the only other laptop I have only has 8.)

    I would like to have some energy to play with writing DeltaChat bots + webxdc apps. I was kinda thinking that it would be a lightweight way to provide a UI for some stuff without having to worry about networking. (My brother wants a remote control mechanism over his heated/cooled bed that can only be controlled over Bluetooth with an app. I found a Python library that works, but I need to deploy whatever somewhere close to the bed itself.)

    (webxdc has always been fascinating to me. And lately I have enjoyed the convenience of chat apps, which I never believed in. I also love DeltaChat.)

    1. 3K€ ThinkPad P with 64gb of RAM and an absurd Nvidia GPU... which has decent battery life and is not as heavy as I thought

      Which one is it?

      1. This one .

        My main annoyance is that it bothers you with a message during boot if you don't give it 100W, but with my use, 65W worked well enough.

        1. Oh, Arrow Lake, nice. I see it's even lighter than the P1 I have. How is its idle power usage (if you happen to care about that sort of thing)?

          1. Huh, I really have not cared much about it. Just that I think I've been able to go for nearly a full work day without much use.

  27. I've been vibe coding a tool to help me clean up my audiobook collection and now I'm waiting for my weekly limit to reset so I can continue. It makes me wish there was a well documented standard that handled all edge-cases already so I could just copy and use that, but the community has yet to converge on such things. The community really needs the equivalent of IMDB or MusicBrainz to document and aggregate all historical metadata related to audiobooks.

    Honestly I feel like I get blown into so many directions all at once that it's hard to follow through on anything. Recently I'm thinking that I would like to leverage my ability to get addicted to things towards positive goals, but I haven't figured out how to hack that aspect of myself.

The Witcher 3: Songs of the Past – Geralt of Rivia returns after a decade in the sun

Guardian
www.theguardian.com
2026-08-28 09:00:00
Before The Witcher 4 arrives in 2028, CD Projekt Red is returning us to the world of The Witcher 3 for one last foray. Looks like wind’s still howlin’ The game that graced us with Bathtub Geralt, The Witcher 3: Wild Hunt, arrived more than a decade ago. So it was a touch surprising this summer when ...
Original Article

T he game that graced us with Bathtub Geralt , The Witcher 3: Wild Hunt, arrived more than a decade ago. So it was a touch surprising this summer when developers CD Projekt Red announced a new expansion to the venerable adventure, titled Songs of the Past, for next year. It will release alongside a full remaster of the original game, which will be free for anyone who bought it back in 2015. (The studio is also working on a sequel, The Witcher 4, but that’s not due until 2028.)

As it turns out, this is all possible thanks to a partnership with Fool’s Theory, a studio founded by CD Projekt Red veterans, which took on the brunt of the development work. “We’ve had this story in a drawer for many years,” explains Marcin Blacha, VP story director at CD Projekt Red. “Of course, we moved on to Cyberpunk 2077 and now The Witcher 4, as well as our other projects. But because we knew The Witcher 4 would take time, we saw a gap in our release calendar where Songs of the Past could go. Thankfully, we were able to find the right partner to help execute it.”

A screenshot from The Witcher 3: Songs of the Past showing valleys and mountains.
Seemingly idyllic … The Witcher 3: Wild Hunt – Songs of the Past. Photograph: CD Projekt Red

The elephant in the room, though, is that The Witcher 3’s 2016 expansion Blood and Wine felt like a natural conclusion to Geralt’s tale. After decades covered in entrails, the legendary monster slayer hangs up his dual swords for a well-earned life of luxury on his recently acquired vineyard estate. What can he possibly have left to do?

“That is certainly something we thought through,” says Blacha. “Geralt retired in Toussaint – but then his best friend comes calling. I don’t think many of us would turn down that request.”

So, foppish fan favourite Dandelion the bard pulls the witcher back into action, asking Geralt to come to his aid in his homeland of Letten. It’s a seemingly idyllic land of bountiful harvests and rowdy festivals that hides some sinister secrets.

A screenshot from The Witcher 3: Songs of the Past.
Sinister secrets … The Witcher 3: Wild Hunt – Songs of the Past. Photograph: CD Projekt Red

It’s been exciting, and nostalgic. We spent so long with Geralt, but have also learned a lot in the 10-plus years we’ve been away from him,” says Blacha. “With Songs of the Past, we really wanted to return to The Witcher’s roots. That meant drawing on old beliefs and folklore, revisiting landscapes inspired by Poland’s history and countryside, and staying true to the series’ tradition of difficult dilemmas. Going back to all of this has been a pleasure.”

The team has also put to bed rumours that this expansion will be a prequel to The Witcher 4. Songs of the Past is focused on the gruff, grey witcher we’ve already come to love, not Ciri, the younger protagonist of the forthcoming title. Rather, the expansion has all the trappings that seasoned Witcher fans should recognise, with a morally murky narrative brought to life by returning voice actors Doug Cockle and John Schwab, who reprise their roles as Geralt and Dandelion.

There are a few new features to play around with, though: CD Projekt has enhanced Geralt’s combat and skill trees, and he now wields a chain weapon alongside his steel and silver swords. There are also new DNA-modifying mutagens to play around with, tweaking Geralt’s biology and, therefore, his supernatural skills.

The Witcher 3 is a modern classic that has already come to a gratifying end: bringing Geralt out of retirement is a risky move. But when his medallion starts humming, the White Wolf is still ready to answer the call.

U.S. sanctions against the A/I Collective

Hacker News
www.inventati.org
2026-08-28 08:58:53
Comments...
Original Article

U.S. SANCTIONS AGAINST THE A/I COLLECTIVE

A/I (Autistici/Inventati, pronounced [ au’tistiʧi ]-[ iŋ’vɛntati ], or [ iŋvɛn’tati ]) was born in 2001 from an encounter of individuals and collectives of the autonomous anticapitalist movement interested in technology and active in the digital rights struggle. We believe that this world is far from being the best world possible. We react by providing a platform and tools for digital self-defense addressing the need of free communication for activists and other individuals.

All of our services are provided for free, without any form of control or commoditization of the personal user data. We don’t receive any form of compensation for our work. We are volunteers exploiting the experiences we accumulated over years of technological, political and legal research while doing radical activism, and we are motivated and inspired by the principles of solidarity and self organization.

Our financial strategy relies exclusively on voluntary donations.

We provide our services strictly for non-commercial use, in order to provide support exclusively to individuals or groups we feel we have an affinity with. In order to verify the existence of these pre-conditions, each and every service request is processed manually by one of our volunteers and is in a dialogical form. All requests are anonymized and will be destroyed.

If you would like to use our services, please check if you agree with our manifesto , pledge respect to our policy and read carefully our privacy policy .

Don’t send a request without having read these documents!

Request an account

Over 8,300 Gitea servers vulnerable to code execution attacks

Bleeping Computer
www.bleepingcomputer.com
2026-08-28 08:58:43
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...]...
Original Article

Gitea

Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver.

The code injection vulnerability ( CVE-2026-60004 ) targeted in these attacks was reported by Salesforce security researcher Shai Rod , and it allows authenticated attackers to execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches via the diffpatch API endpoint.

While successful exploitation requires repository write access to repositories hosted on vulnerable servers, Gitea comes with self-registration enabled by default, allowing unauthenticated attackers to register an account, create a new repository, and trigger the vulnerability without prior credentials.

image

"Gitea's diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user," Gitea's security team explains . "With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository."

Gitea released version 1.27.1 on July 27 to address CVE-2026-60004 and advised users to upgrade their servers as soon as possible.

On Friday, Internet security watchdog group Shadowserver warned that nearly 8,400 Gitea servers exposed online are still unsecured and remain vulnerable to ongoing attacks.

"We are scanning/reporting Gitea instances vulnerable to CVE-2026-60004 (code injection), with 8393 IPs found vulnerable on 2026-08-27," Shadowserver said .

Vulnerable Gitea intsances
Vulnerable Gitea instances (Shadowserver)

​On Tuesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added the vulnerability to its catalog of actively exploited flaws and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their servers within three days, by August 28, as mandated by Binding Operational Directive (BOD) 26-04 .

While the cybersecurity agency has yet to share further details on attacks targeting this flaw, the move was likely prompted by reports of in-the-wild exploitation, in which the attackers are deploying cryptocurrency mining malware on unpatched Gitea servers.

"This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," CISA warned .

In July, threat actors were also spotted abusing another critical vulnerability ( CVE-2026-20896 ) in the official Gitea Docker image, an authentication bypass flaw affecting Gitea instances with reverse proxy authentication headers enabled.

Gitea is a self-hosted alternative to cloud-hosted GitHub, GitLab, and Bitbucket code hosting and DevOps platforms, with more than 400,000 installations and nearly 1,500 contributors.

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

AI Skeptics: From Mathematics to AI Safety (with Jacob Tsimerman)

Math Babe
mathbabe.org
2026-08-26 08:46:44
We were psyched to talk to Fields Medalist Jacob Tsimerman about his decision to leave his math professorship and move to Silicon Valley to work at OpenAI on the Safety team: Apple Spotify YouTube...
Original Article

Home > Uncategorized > AI Skeptics: From Mathematics to AI Safety (with Jacob Tsimerman)

We were psyched to talk to Fields Medalist Jacob Tsimerman about his decision to leave his math professorship and move to Silicon Valley to work at OpenAI on the Safety team:

Apple

Spotify

YouTube

Categories: Uncategorized

Comments (0) Trackbacks (0) Leave a comment Trackback

  1. No comments yet.
  1. No trackbacks yet.

Leave a Reply

Your email address will not be published. Required fields are marked *

"The Lion King" in Quechua?: New Film "Runa Simi" Profiles Indigenous Artist Keeping Language Alive

Democracy Now!
www.democracynow.org
2026-08-28 08:40:40
Experts estimate that a language is lost every two weeks — and that half of the world’s 7,000 spoken languages could be lost by the end of the century. Quechua is the most widely spoken Indigenous language in the Americas, with approximately 7 to 10 million speakers living primarily in Peru, B...
Original Article

This is a rush transcript. Copy may not be in its final form.

AMY GOODMAN : This is Democracy Now! , democracynow.org. I’m Amy Goodman.

Half of the world’s 7,000 spoken languages could be lost by the end of the century. Experts estimate a language is lost every two weeks. Quechua is the most widely spoken Indigenous language in the Americas, with approximately 7 to 10 million speakers, primarily in Peru, Bolivia and Ecuador. But as with so many Indigenous languages, Quechua is still vulnerable due to broader cultural pressures and discrimination.

We turn now to the documentary film Runa Simi . The film follows Fernando Valencia, a Peruvian voice actor, Indigenous activist, radio host and single dad, who’s dubbed many online clips of animated movies into Quechua from his home in Cusco, Peru. The film follows as Fernando pursues his most ambitious goal yet: to fully dub Disney’s animated classic The Lion King into Quechua, with the help of his 8-year-old son, Dylan. This is the trailer for the film.

DISNEY OPERATOR : Thank you for calling the Walt Disney Company. How may I assist you?

FERNANDO VALENCIA : Hi, my name is Fernando Valencia, and I’m calling from Cusco, Peru, in South America. And I have a project that consists of dubbing a Disney film to a language that has never had a dubbed version. The language I am referring to is Quechua, which is the second official language here in Peru. I know this is a random request, but I was wondering if you can please contact me with the right person, or maybe it’s the legal department that I could approach first.

DISNEY OPERATOR : Yes, sir. I’ll be happy to assist you, and I’ll gladly connect you to our legal department. All right, I’m connecting you now. You have a magical day.

FERNANDO VALENCIA : [translated] There are 10 million Quechua speakers that have never seen a blockbuster movie in their own language. My dream is to show the movie in different communities.

DYLAN VALENCIA : [translated] And this will all be mine?

FERNANDO VALENCIA : [translated] That’s good, but you sound like a teenage Simba.

There are so many great movies we’ve all enjoyed, so why the hell can’t the Quechua children enjoy them, too?

Just don’t do it like this. Let me show you. “And this will all be mine?” Like that.

I will never let this language die. It’s more than a language; it’s a worldview.

He is my motivation. He pushes me to do this. I think that if it wasn’t for him, I probably wouldn’t be here, and none of this would have happened.

Ñoqa means “I.” It comes from the heart.

I’ve been playing around with my voice since I was a kid, and now I want to use it for this.

DYLAN VALENCIA : [translated] And this will all be mine?

FERNANDO VALENCIA : [translated] Exactly!

AMY GOODMAN : That’s the trailer for the documentary film Runa Simi , which will be playing in New York this weekend at the Firehouse Cinema downtown. I had the chance to sit down with the film’s director, Augusto Zegarra, and the film’s subjects, Fernando Valencia and his son Dylan Valencia, in New York this year. I began by asking Augusto about the making of the film, specifically about the meaning of the title, Runa Simi .

AUGUSTO ZEGARRA : Runa Simi means “language of the people” in Quechua. So, that’s how Quechua people would refer to the language themselves.

And yeah, it’s been an amazing journey to work on this film next to Fernando and Dylan and our whole team for the last eight years and half, almost nine years, in the making of this film. And I won’t lie: It took us a little bit longer than we expected. But I wouldn’t change anything of how we’ve done this.

And on the question of why this film is important, this is a film about Quechua. Quechua is a language spoken by 10 million people. It’s the most spoken Indigenous language in all of South American region. Four of them live in Peru. And a lot of people don’t know about this language. So, to me, it was important to shine a light in Fernando’s project, because I feel like, through his project, we use that anecdote to explore bigger themes, such as language discrimination, and we also see the story of Fernando passing his cultural heritage to his son. I think this is an urgent story because people right now in Peru, Indigenous people, they are not, I think, treated fairly in general in Peru. And —

AMY GOODMAN : You yourself are Peruvian, Peruvian American.

AUGUSTO ZEGARRA : I am Peruvian. I am Peruvian. My mother is from Cusco, but I am from Lima. I am not Quechua, and I am not Indigenous. But I’ve had the honor, you know, to be able to tell Fernando’s story. Fernando himself is Quechua.

And I think this story is important and urgent because Indigenous people in Peru are fighting for basic rights, too, you know, like having water, electricity, healthcare, education in their own language. And so, somebody could think that this is not important, but they also have the right to access of entertainment in their own language. So, to me, it was important to shine a light on Fernando’s story and just be able to emphasize the power of film as a medium for oral language and to try to maintain it alive.

AMY GOODMAN : If you, Fernando, can talk about why it’s so important to translate, what you do, these films from Western culture? And not always, because you’re doing things, translating from Spanish into Quechua, as well, in Peru. Talk about where you grew up and why you do what you do.

FERNANDO VALENCIA : Thank you so much. First of all, I want to say ¿Allillanchu, panay? ¿Imaynallan kashanki? Ñoqayku anchakusiskhan kashayku tarikuiku kay Mosoj Yorkniymanchay . It’s like New York but in Quechua. Mosoj York kay llaqtapi, hinaspam willasayki . I am going to tell you my story.

I was born in Cusco city, but I passed my first years with my mother in the countryside. She was a teacher. She is retired. And so, that’s where I learned Quechua, because in the '90s, most kids in the countryside just speak — spoke in Quechua. So, now they speak Spanish, as well. And that's how I learned to speak Quechua.

And then, when I was around 25, I guess, I saw kids watching movies in the countryside, because most of them, they don’t have TV. They don’t have internet. Actually, they just have the TV, the device, and the DVD reproducer. And then they go to the city, sell some stuff, food, potatoes or whatever they harvest, and then the parents bring them — they can’t afford toys or things like that for their entertainment, and they just buy discs of movies. And this is the entertainment. But what I saw, it’s that they saw the movies in Spanish, in Spain-dubbed movies, and then they even don’t understand what was going on in the movie.

AMY GOODMAN : So, they just watch.

FERNANDO VALENCIA : They just watch and laugh with some physical jokes, you know, but they didn’t understand. And then, I asked them, “Hey, what’s going on in the movie?” And they say, “Oh, I don’t know.” Right?

And that’s why I decided to, “Hey, why if I try do the same voices and create the dubbing process for this in a short clip?” And the response of those kids was really, really amazing, because they finally understood, but just a short clip. That’s why we decided to, “Hey, why if we dub a full movie?” Right?

And here is why. Because most of the Indigenous language hasn’t a written; they don’t have the way to write. And Quechua is the same. And then, most of the communication is oral. Right? And then, how I can figure out to preserve the language without writing? It’s — we have this device, the phones, the audiovisual, the media now. And I said, “OK, this is the way how I can preserve the language,” because it’s losing.

AMY GOODMAN : I want to go to clip number two. It’s you describing why, speaking in Quechua, preserving this language is so important.

FERNANDO VALENCIA : [translated] Our language, Quechua, to me, it’s like life itself. In Spanish, I can say many things, but in Quechua, I can say what I really feel, what truly comes from my heart.

There’s the bull!

Quechua speakers have always been treated like second-class citizens. In the past, people would have to speak it in secret. To this day, when you speak Quechua, people will look at you like you are worth less. That’s why people won’t speak it. That’s why we are losing it.

AMY GOODMAN : That’s another clip from Runa Simi , translated into English from Quechua means “the language of the people.” And we’re speaking to Augusto Zegarra, who is the director, but also the voice you just heard, Fernando Valencia, who this film is about. And now we’re also joined by his son Dylan. He was very young at the time. He’s a few years older. It’s hard to recognize him at 14. But, Fernando, before I ask Dylan a question, it is so beautiful the way you describe your Indigenous language being your heart expressing your soul. Talk about how it’s threatened.

FERNANDO VALENCIA : Yes, so each language in the world, especially the Indigenous language, are very attached to the human relationships and also the relationship with the nature. And in Quechua, the most important thing, it’s think in the other before think about yourself. It’s why when you say “hello,” let’s say, “hello” or “good morning” — right? — you say ¿Allillanchu? , which means “Is everything all right?” because I am aware, I am care of you, right? And then, yeah, that’s why the language comes from the heart. And it’s a beautiful thing.

And most people ask me, “Why should I learn Quechua, Runa Simi ?” And I say, “Because you will discover yourself.” That’s why I made. I learned Spanish to communicate in my country, because each document is in Spanish. I learned English to communicate with the world, because English is splitted around the world. And I, fortunately, learned Quechua to talk with myself, with my most basic feelings.

AMY GOODMAN : Dylan, you’re 14 years old now.

DYLAN VALENCIA : Yeah.

AMY GOODMAN : Did you learn Quechua in school?

DYLAN VALENCIA : I didn’t. I didn’t learn Quechua. But they teach it in a very basic way. There’s like one hour a week of Quechua, so it is very hard to actually learn it and not just memorize some, a couple of words.

AMY GOODMAN : So, you learn it from your father?

DYLAN VALENCIA : Yeah, I learned some words, some greetings, yeah. But I have a very good way to pronounce the Quechua, I think, because of this trainments with dubbing —

AMY GOODMAN : Because of your dad training you?

DYLAN VALENCIA : Yeah, like Ñoqa , I can say it a little bit better. Yeah, this was like when I was maybe 7 or 6.

AMY GOODMAN : Well, it’s now preserved for all time.

DYLAN VALENCIA : Yeah.

AMY GOODMAN : Are you concerned about cultural imperialism, bringing it to the Quechua people, the idea of bringing this movie, as opposed to bringing out the voices of the Quechua people to the world?

FERNANDO VALENCIA : Yeah. Most people ask me the same question, is “Why you are bringing imperialism into Quechua, a peaceful country and a peaceful culture?” And I say, “But I’m not bringing them here. I am bringing the Quechua outside. I’m doing the opposite thing. And they don’t even are noticing about this.” What I’m doing is, in the peaceful way, to share the worldwide culture into small culture. And when I translate it, I am sharing our culture to the worldwide culture, taking something very iconic as The Lion King into a Native language, which is not small thing. It’s 10 million people speaking Quechua. And I say, “Why not?”

AMY GOODMAN : I want to go to the final clip we have of Runa Simi . We see Fernando teaching Dylan, a young, young Dylan — he’s already 14 — to jump into a haystack. But really, it’s so much more.

FERNANDO VALENCIA : [translated] OK, Dylan, you have to fly high.

DYLAN VALENCIA : [translated] Dude!

FERNANDO VALENCIA : [translated] You have to fly!

DYLAN VALENCIA : [translated] I don’t know if I want to do this anymore.

FERNANDO VALENCIA : Come on! You can do this! Yeah? Ready? You can jump this high. On three! One, two — ready? Come on! Come on! Come on! Fly! Fly!

DYLAN VALENCIA : [translated] That was intense.

AMY GOODMAN : That’s a clip from Runa Simi . Augusto Zegarra, you’re the director. You filmed him for so many years. Why did you choose this clip?

AUGUSTO ZEGARRA : To me, that clip was always really magical and really special, you know. And that scene means more. It’s more about Fernando teaching Dylan to overcome a fear, just through a game. It’s like something that Fernando used to do when he was a kid, and he’s pushing Dylan, and he’s pushing him, and he’s pushing him, and finally he does it. So, I think it has a lot to do with what Fernando is trying to teach Dylan, in general, throughout the film.

AMY GOODMAN : As we begin to wrap up, Fernando, that scene — the radio audience can’t see it, but you can imagine it — reminds me of the scene where you show the full Lion King to the community in the mountains. Describe where you chose your open-air theater.

FERNANDO VALENCIA : It was an incredible experience to see the final result and the people, because nothing of this could have sense if the Quechuan people don’t enjoy the final movie dubbed into their own language.

AMY GOODMAN : And it was particularly touching to see you with your parents. Describe that experience.

FERNANDO VALENCIA : Oh, my parents, yeah. I think about the kids for the dubbing, but in the way, I discovered the old people liked more, because most of them just saw the cartoons as something very far from them. But when they realized, my father came to me and told me to my ear, “Hey, this movie moves your heart and makes you cry.”

AMY GOODMAN : That was Fernando Valencia and his son Dylan and Augusto Zegarra, the director of the new documentary, Runa Simi , playing in New York this weekend at the Firehouse Cinema at DCTV . I’ll be moderating the Q&A on Monday at 3:30 there.

Tonight, I’ll be in Middlebury , Vermont, for a screening of the documentary Steal This Story, Please! at the Dana theater at 7:15 with Tia Lessin and Carl Deal, the directors. It’s great to be back. I’m Amy Goodman, with Juan González.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

"Who Paid, Who Gained": Juan González on How Chicago Funded Real Estate Instead of Social Services

Democracy Now!
www.democracynow.org
2026-08-28 08:35:54
A team of researchers led by Democracy Now!’s Juan González at the University of Illinois Chicago recently released an in-depth study on how, through a program called Tax Increment Financing (TIF), Chicago has spent some $16 billion in property taxes it collected over the past 40 years to fund...
Original Article

A team of researchers led by Democracy Now! ’s Juan González at the University of Illinois Chicago recently released an in-depth study on how, through a program called Tax Increment Financing ( TIF ), Chicago has spent some $16 billion in property taxes it collected over the past 40 years to fund downtown development. The money was supposed to be used to eliminate urban blight. ” TIF funding has actually exacerbated economic inequities throughout the city, pouring more than half of the billions of dollars that it collected into downtown neighborhoods, while 70 other community areas around the city were left to share the other half,” says González.


Transcript

This is a rush transcript. Copy may not be in its final form.

AMY GOODMAN : Now on with the show, Juan. And if you can tell us about your fabulous new report on Chicago?

JUAN GONZÁLEZ: Yes, Amy. Well, first, it’s great to have you back.

And yes, I spent the past year working with a team of researchers at the University of Illinois Chicago’s Great Cities Institute, tracking how the city of Chicago spent more than $16 billion — that’s billion dollars — in property tax revenues over the past 40 years. Ostensibly, the money was supposed to revitalize the city’s physical infrastructure through an economic development tool most people have never heard of. It’s a financing tool known as Tax Increment Financing, that is supposedly a self-financing tool for — that’s been used by hundreds of local governments across the United States. But Chicago is far and away the biggest user of it among all major cities. The program allows a municipality to fight urban blight by designating an area within its boundary, within the city, as a TIF district, and then using all future increased property taxes in that area to pay for infrastructure like roads, parks, sewer systems, provide incentives for private development.

Well, we found that Chicago’s TIF program became a runaway project, with more than 180 different TIF districts created throughout the city. But, in fact, the program was diverting an extraordinary share of taxes that would normally go to basic services and public schools, and instead went into TIF projects. And it drove up property taxes for all property owners in Chicago by an average of 13.7% over the 10-year period that we studied. We found also that 90% of this increased taxes would have occurred anyway without the TIF program. And meanwhile, the TIF districts took in almost as much in property taxes last year as Chicago’s Corporate Fund did to fund the police, fire, health, housing, with the average homeowner paying hundreds of dollars a year, and thousands over the 10-year period, in extra taxes.

We also found that the past four mayoral administrations, TIF funding has actually exacerbated economic inequities throughout the city, pouring more than half of the billions of dollars that it collected into downtown neighborhoods, while 70 other community areas around the city were left to share the other half. And there was very little accountability to the public and clear reporting on how the money was spent.

So, now we’re faced the situation where the school system is — every year doesn’t have enough money to fund itself. The city itself has funding gaps. But yet, the TIF districts are sitting on $3 billion in cash in their accounts, and they’re flush with cash.

So, this is going to become a big issue, because Chicago is about to enter into another mayoral race early next year. We found that Mayor Brandon Johnson has made some positive reforms to the TIF program, but not enough. And the issue of all this TIF money is going to certainly be a subject of debate as we enter the mayoral season in Chicago next year.

AMY GOODMAN : Well, Juan, we’re going to link to your report , the Great Cities Institute in Chicago, at democracynow.org, “Chicago’s Runaway Development Tool.”

Coming up, a new documentary about preserving language, culture, and dubbing The Lion King into Quechua. It’s called Runa Simi . Stay with us.

[break]

AMY GOODMAN : “Stars of Fire” by Adrian Villanueva.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.


Next story from this daily show

“The Lion King” in Quechua?: New Film “Runa Simi” Profiles Indigenous Artist Keeping Language Alive

"Don't Be Squeamish About Squamous, Get a Checkup!" Amy Goodman's Personal Health Update

Democracy Now!
www.democracynow.org
2026-08-28 08:32:53
Amy Goodman is back to hosting Democracy Now! after taking time off following a medical procedure to remove skin cells on her nose that tested positive for squamous cell cancer. “I think it’s important that … we don’t have to be picture-perfect on TV or video. We are not plastic; w...
Original Article

Amy Goodman is back to hosting Democracy Now! after taking time off following a medical procedure to remove skin cells on her nose that tested positive for squamous cell cancer. “I think it’s important that … we don’t have to be picture-perfect on TV or video. We are not plastic; we are people. And people get by in all sorts of ways around the world,” says Goodman. She reminds listeners and viewers to check in with the dermatologist: “A spot, a bump on their skin, a mole or a blemish anywhere, or just a rough spot, something scaly, might be cancerous.”


Transcript

This is a rush transcript. Copy may not be in its final form.

AMY GOODMAN : This is Democracy Now! , democracynow.org, The War and Peace Report . I’m Amy Goodman, with Juan González.

Before we move on with the show, I wanted to say a few words about my absence from the show this week. I took time off following a minor but important medical procedure known as Mohs surgery — that’s M-O-H-S — microscopic surgery, to remove some skin cells on my nose that tested positive for squamous cell cancer. The procedure was painless, using only minimal local anesthesia, and it went well. I got the stitches out yesterday and now have Steri-Strips across the bridge of my nose, a kind of post-surgical Band-Aid.

But I decided to come back on, because I think it’s important that we are not — you know, we don’t have to be picture-perfect on TV or video. We are not plastic; we are people. And people get by in all sorts of ways around the world, and I think it’s important not to hide.

The good news is, in my case, we caught the problem in time. The medical team that treated me are confident they removed all the cancerous cells. And in medical terms, it means the edges are clear.

And I’m really grateful to everyone here at Democracy Now! for covering me this week, especially my New York-based co-hosts Nermeen Shaikh and Anjali Kamat, our editorial director Mike Burke, who managed everything, Charina Nadura, Tey-Marie Astudillo — thank you so much — Deena Guzder, the whole team. And, Juan, of course, always thank you. It was a real treat watching the show from home with my dog Zazu by my side.

I want to emphasize that the problem was caught in time, but too often people don’t realize that a spot, a bump on their skin, a mole or a blemish anywhere, or just a rough spot, something scaly, might be cancerous. We don’t have to be squeamish about squamous cell carcinoma or basal cell carcinoma, unless it’s not caught in time. Do your dermatology checks every year. And now with climate change, with the Earth heating, with the increased exposure to the sun, there’s an increase in skin cancer.

And, Juan, as you so prophetically warned after the 9/11 attacks here in New York, the level of toxins downtown were devastating. And skin cancers, like squamous cell cancer, went way up, especially downtown. Back then, Democracy Now! was the closest national broadcast to ground zero, broadcasting from the firehouse studios of DCTV .

Well, enough of this story. So, thanks again to everyone. It’s great to be back covering the important stories of the day.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.


Next story from this daily show

“Who Paid, Who Gained”: Juan González on How Chicago Funded Real Estate Instead of Social Services

Inception-style curved map for turn-by-turn directions

Hacker News
www.orbify.eu
2026-08-28 08:29:05
Comments...
Original Article

Orbify web demo

Demo 2 - v72

Controls

Move

W A S D

Pan

Left drag

Rotate

Right drag

Get in touch

Pilot, collaboration or investment?

We are open to pilot projects, technology collaborations, industry partnerships and conversations with investors.

ORBIFY.EU karsten@orbify.eu

Demo versions

Orbify AS

Org. nr. 934606442

© 2026 Orbify. All rights reserved.

Warping technology: Patent Pending · PCT/EP2026/058725

3D rendering powered by PlayCanvas Engine .

Glacier Collapse: 2K Dead or Missing in Nepal-Tibet Flood Is "Glaring Example of Climate Injustice"

Democracy Now!
www.democracynow.org
2026-08-28 08:22:09
We get a report from Nepal, where at least 547 people are confirmed to have died and over 1,500 are still missing after a glacial collapse on Wednesday sent a wall of ice, mud and rock into a Himalayan river, triggering catastrophic flooding in the Nepal-Tibet border region that swept away entire co...
Original Article

This is a rush transcript. Copy may not be in its final form.

AMY GOODMAN : This is Democracy Now! , democracynow.org. I’m Amy Goodman, with Juan González.

We turn now to Nepal, where at least 547 people are confirmed dead, over 1,300 people are still missing, after a glacial collapse sent a wall of ice, mud and rock into a Himalayan river, which triggered catastrophic flooding in the Nepal-Tibet border region, sweeping away entire communities. Water levels along the river at one point rose by as much as 27 feet over half an hour.

As the desperate search for survivors continues, heavy rain and risk of secondary flooding have complicated rescue operations. Chinese authorities warned Friday a lake formed by the landslide could breach its banks and cause another flood downstream in Nepal.

This is David Fisher, who leads the Red Cross in Nepal.

DAVID FISHER : And so, we are operating on still very, very estimated figures, but we believe that at least 93,000 people are — have been affected and are in great need. We’re, of course, very, very concerned about the secondary flood.

AMY GOODMAN : Nepali authorities say they’ve rescued over 3,700 people so far. The bodies of the dead swept away by the floods are being found far downstream. Meanwhile, local morgues are running out of space to store the bodies until they’re identified.

Among the missing are hundreds of foreign tourists, many of whom were on their way to a popular pilgrimage site sacred to Hindus, Buddhists and Jains. There are up to a hundred tourists from the United States missing. This is an evacuated Indian tourist describing her escape from the flood.

ANJANA RAJA : You know, we saw the gush of water all the way, dirty mud, you know, rising all the way, four-story high. We ran for our life. We ran 500 steps all the way up the mountain to be safe.

REPORTER : Did you hear something before —

ANJANA RAJA : Yes.

REPORTER : — you saw the mudslide? What was it? Please explain.

ANJANA RAJA : Like waterfall. It felt like a boulder falling down. Like, when a boulder hits water, what happens? That’s what it was. A big, big rock, when it hits water, what happens? It comes up all in. So, we were thinking it’s an earthquake, right? But we still don’t know, because I was also told that, you know, this is more like a glacier burst. That’s what I think the army folks told us. So, we have to go with what they say, so I don’t know.

AMY GOODMAN : Geologists say the flash floods were set off by a landslide and glacial avalanche so powerful it set off its own seismic signal. Climate scientists warn the region is warming much faster than the global average, leading to the rapid retreat of glaciers.

For the latest on how this catastrophic flooding relates to climate change, we go now to Kathmandu, Nepal, where we’re joined by climate expert Sunil Acharya, the just transition lead at the nonprofit Recourse.

Thank you so much, Sunil, for joining us. I know you’re outside a hospital. If you can describe the scene there and also talk about how all of this relates to climate change? At this point, we have numbers up to 2,000, between the dead and the missing.

SUNIL ACHARYA : So, I’m standing right in front of a government hospital here in Kathmandu, where they are bringing hordes of people who have died or who are severely injured. This is an unprecedented situation in here. The devastation caused by the flood that happened on Wednesday is unimaginable, in the sense that the scale of devastation it has done is huge.

The exact, you know, cause of this flooding, scientists have now started to tell, was because a huge ice mass fell off, and that triggered the flooding, because it carried the huge amount of water, the rocks and debris along the way, washing away hundreds of villages, huge number of bridges and road infrastructure, and also hydropower stations.

Though it seems like it’s unimaginable when we see the footages coming in, however, scientists and civil society have been warning about the very fact that these kind of events might happen in the Himalayas is no news. The scientists and civil society have been telling to the global community that these kind of events can happen because of the climate crisis, and this is the result of the delayed global action to deal with climate change.

JUAN GONZÁLEZ: And Nepal has lost nearly a third of its total ice volume over the last three decades. Could you explain?

SUNIL ACHARYA : Yeah, that’s true. The Nepal Himalaya are, you know, warming at the rate that is higher than the global average. The ice caps in the mountains and the glacier in there are melting in a rapid scale that’s leading to a number of flood disasters every year. For example, this particular flooding event is the third in the row in the same catchment area. There are several other glacial lakes which are on the verge of explosion or melting.

That means we are living in a situation wherein we can say that we — there’s a time bomb attached to Nepal, wherein the communities who didn’t cause anything to cause climate crisis are bearing the brunt of this crisis, wherein the number of people being killed, the number of properties being damaged has been, you know, way beyond what we can adapt to. This also shows that the climate crisis has reached a stage wherein there is a very hard limit to adaptation, and the loss and damage is resulting.

But again, the global community, or the developed countries, which have historically contributed to the climate crisis, are complacent in this, causing the situation like this. They are still, you know, trying to not act upon and deal with the crisis in acting to reduce the greenhouse gas emissions urgently.

JUAN GONZÁLEZ: And given how quickly this unfolded, Nepal has an early flood warning system that relies on a network of river gauges. How well did that work?

SUNIL ACHARYA : So, see, the suddenness of this event was so quick that the ice mass fell off — usually the early warning system that Nepal has are used to monitor the slow surge of water flow. But this was an explosion that happened in a very quick succession. And then, the river, you know, surge that happened was so fast that even the monitoring stations were swept away before they were able to send the early warning situation. That also means that the early warning system that has been installed, despite the fact that Nepal also lacks, you know, sufficient resources to put in place the early warning system, put in place the monitoring system, that’s one fact. But again, another fact is what we’ve witnessed is that these monitoring systems, which were supposed to work at the usual time, no longer work. Because of the climate change, the hazard profile had changed. The behavior of the hazard had changed. That’s why it is very difficult for the existing early warning system to work.

AMY GOODMAN : Our last question to you, Sunil. The U.S. is historically the largest greenhouse gas emitter, China currently the largest greenhouse gas emitter. Nepal, to say the least, contributes almost not at all to greenhouse gases, which lead to the warming of the planet. If you can comment on this and where we go from here, as you face possibly another flood in Nepal?

SUNIL ACHARYA : As you say, it’s a glaring example of climate injustice. Nepal contributes less than 0.1% of — to the global greenhouse gas emissions. However, the number and magnitude of, you know, disasters we are facing is rising day by day. And also the fact that the country, which is already having to force, to shift the very scarce resources it has from health and education to deal with disasters that, you know, come year after year is very bleak. But also, the fact that there’s already a warning up there, the water level has already risen, and there might be another, you know, flooding event that can happen right away as we speak.

But as the crisis is unfolding, we can see that there will be a number of such events that will happen. That also means that people and communities will be left in a situation wherein there is no way to deal with this crisis. And this also reflects the fact that there is loss and damage that is happening, and it is reality. And it also shows to the fact that the historically responsible countries, such as the U.S., need to urgently compensate for the damage that has created because of this crisis.

AMY GOODMAN : Sunil Acharya, our deepest condolences on what has happened to your country on the border with Nepal and Tibet. And, of course, we’ll continue to follow this issue. Climate and public policy specialist, speaking to us from Kathmandu. He’s the just transition lead at the nonprofit Recourse.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

"Shut Down Dilley": Rep. Joaquin Castro on "Abusive" ICE Family Jail, Targeting of Military Families

Democracy Now!
www.democracynow.org
2026-08-28 08:10:29
Calls to shut down the ICE jail known as the Dilley Immigration Processing Center in South Texas continue to grow following the detention and deportation of 5-year-old Liam Tadeo and his father Victor Martinez Nieto to Mexico. According to the family’s lawyer, Nieto had begged officers to let ...
Original Article

This is a rush transcript. Copy may not be in its final form.

AMY GOODMAN : In a moment, we’re going to be going to Nepal to talk about the massive devastation from a glacier that broke off. Now at least 2,000 people are dead or missing. But first, we go to Texas.

Calls to shut down the Dilley Immigration Processing Center in South Texas continue to grow following the detention and deportation of Victor Martinez Nieto, along with his 5-year-old son Liam. The arrest happened just days before Liam was set to start kindergarten. They’ve both been deported to Mexico. According to the family’s lawyer, Liam’s dad begged officers to let his son go as they were arrested on their way to soccer practice in Austin last week. His father wanted Liam to be released to his mom, but ICE reportedly refused.

We go now to San Antonio, Texas, where we’re joined by Democratic Congressmember Joaquin Castro, who requested to visit Liam and his father in custody, but ICE denied the request. Last month, Congressmember Castro led a group of more than 110 Democratic House members in a nationwide call to end the immigration jail in Dilley. He’s joining us now from a car in San Antonio on his way to a meeting.

Congressmember Castro, we thank you for taking these minutes to be with us. Talk about what you’re demanding. Today, you’re headed to Dilley once again.

REP . JOAQUIN CASTRO : Yeah, great to be with y’all.

This will be my ninth inspection of Dilley this year. And I join 110 other Democrats in calling for the United States government to shut down the Dilley detention center. It is — to me, it represents the commodification of child imprisonment. You have kids as young as 2 months old who have been in prison there. And every child that’s put in there — every woman, every person — there are American investors who are making money off of their imprisonment, but most especially the children. So, I got asked by some of ICE leadership to meet with them at Dilley, and I’m going to go do that this morning.

JUAN GONZÁLEZ: And, Congressman, The Texas Tribune reported earlier this month that immigrant children are held in Dilley five times longer than a court order allows. Can you talk about that situation, especially the case of Liam Tadeo, the 5-year-old boy, and his father, Victor Martinez Nieto?

REP . JOAQUIN CASTRO : Yeah, I tried to visit with Liam and his father last Friday and got his mother’s permission to meet with him, and still, ICE refused to let me meet with him. I then told them that I wanted to visit with Liam and his father today during my inspection, and they, of course, deported him in the last few days. And so, this is an agency that has become very abusive, that has absolutely gone rogue and that should be disbanded.

JUAN GONZÁLEZ: And, Congressman, could you comment also about how a a judge has blocked Minnesota’s bid to extradite Christian Castro, an ICE agent accused of firing his gun and wounding a Venezuelan man in the leg?

REP . JOAQUIN CASTRO : Yeah, absolutely. You know, and to finish up on your last question, there’s something known as the Flores settlement agreement, that says that children should only be held in these detention centers for up to 20 days. And ICE right now is going well over that limit. I’ve met with kids who have been there three months, seven months, 10 months. And so, this is really abusive, and it’s traumatizing a lot of kids.

With respect to Christian Castro, who was in the Rio Grande Valley, he was up in Minnesota, was one of the ICE agents from Texas up in Minnesota. And just so we understand what he did, he shot into a closed door of a house where there were six people, including children, and ended up shooting a man. And then, on top of that, he lied about it and got caught. And so, the Texas Rangers, when he came back to Texas, arrested him. And he was in jail awaiting extradition at the request of Minnesota. Governor Greg Abbott, who’s one of the most corrupt governors in the country, refused to do that based purely on politics. And so, unfortunately, that agent was released yesterday from jail and is presumably in Texas, but is also a flight risk.

AMY GOODMAN : Congressman Castro, we also want to ask about yet another case. Earlier this year, you nominated David Garcia to the U.S. Naval Academy. His mother, Maria, is now jailed at Dilley. ICE took her into custody during her green card review. You’re demanding her immediate release. What can you tell us about her?

REP . JOAQUIN CASTRO : Yeah, I mean, you know, the Trump administration, it’s clear, is also targeting military families. We’ve seen this kind of story come up now several times.

David Garcia is an outstanding young man from San Antonio in my congressional district, and I nominated him to the U.S. Naval Academy. And he’s there right now. Unfortunately, his mom had been granted parole in place and showed up for her green card interview, and when she did, ICE took her. And now she’s sitting in that Dilley trailer prison as her son is at the U.S. Naval Academy as we speak.

And so, I’ve been in contact with ICE . I’m working on his mom Maria’s case. And, you know, I’m hoping to see her today, but we were still working out getting all of the privacy and permission forms that we need. But, you know, that’s the thing. You’ve got this young man who is serving his country, who absolutely represents the best of us, his mom that was doing everything right, as they say, and still Donald Trump and his administration, with the help of governors like Greg Abbott, are targeting them.

AMY GOODMAN : And then, also let me ask you about this story that has gotten some attention. The father of the U.S. Navy sailor now in his ninth month of deployment aboard the USS Abraham Lincoln — the father was detained by ICE recently. He’s since been released, but the apprehension of Luis Manuel Aviles in Key West, Florida, is part of a broader effort by the Trump administration to end immigration protections for the families and relatives of U.S. service members. Your response to his son, Joshua Aviles? Remember, I mean, what they have been through on the USS Abraham Lincoln has been unbelievable.

REP . JOAQUIN CASTRO : Right.

AMY GOODMAN : And here, he’s gone through that. Then his father is detained. He writes on social media, “This is heartbreaking for me. I don’t know how I can mentally continue working 12+ hour days knowing my dad is somewhere, possibly being treated like a criminal. My dad’s only 'crime' was coming to this country to give my siblings and me a better life.” There was public outcry. His father was released.

And then you have the story of another active-duty U.S. soldier whose wife was deported to Honduras. Cristy Maryori Villafranca-Trejo, the wife of Army Sergeant Hedar Leonel Turcios Juárez and mother of their 6-year-old daughter, was deported Monday. She had left 10 years ago from Honduras due to violent crime in the country. At least the seventh spouse or parent of an active-duty military member to be removed from the United States, with more than 50 cases of immediate family of U.S. service members placed in federal immigration detention, according to the Associated Press. What are you calling for, Congressmember Castro?

REP . JOAQUIN CASTRO : Well, most of all, I’m calling on the Trump administration to stop targeting military families and the relatives of service members, to stop targeting them. These are folks who are honorably serving our country. And at a minimum — and their families, again, are people who have not committed any crimes, have not done anything wrong. They should be granted those protections. And, you know, so, it’s absolutely shameful and disgusting that Stephen Miller and Donald Trump and these folks are going after their family members.

JUAN GONZÁLEZ: And finally, Congressman, I wanted to ask you also — it’s been two months since the fatal shooting of Lorenzo Salgado Araujo in Houston, the 52-year-old Mexican father of three U.S. citizen sons who was killed by ICE agents as he was commuting to work. Has there been any update in that? We understand that a possible new witness has come forward?

REP . JOAQUIN CASTRO : Yeah, my understanding is the Harris County DA, you know, has compiled a lot of evidence and a lot of the facts surrounding the case. And from what I understand, they may be close to, you know — I think they’re bringing witnesses in to a grand jury and, hopefully, close to an indictment.

You know, I said early on that when ICE , when law enforcement, when they have the facts on their side, when it’s clear from the video evidence that somebody pulled out a gun and was trying to harm them, when they saved somebody from a flooding car successfully, you know, when the evidence supports their case, they tend to put that evidence out, the video evidence out right away. Here, ICE did not put out a single, single second of video evidence. And to me, that was strong — a strong suggestion that they understand that their ICE agents did wrong. And so, I hope that those folks will be held accountable.

AMY GOODMAN : Congressman Joaquin Castro, thank you so much for being with us. You can get out of your car and go to your meeting now. Democratic congressman from Texas representing San Antonio, calling for the Dilley immigration jail to be shut down.

Coming up, we go to Nepal, where a devastating flood from a collapsed glacier has led to hundreds of dead and well over a thousand people missing. We’ll speak with a climate expert. Stay with us.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.